VLDB 2026 Research / reviewers in the wild / expert
Chao Sang
dblp:284/2250
· DBLP profile ↗
8ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0003-4587-9162ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DualFPT: Handling Data Heterogeneity in Federated Prompt Tuning from both Generalized and Personalized PerspectiveabstractFederated Prompt Tuning (FPT) integrates large pre-trained Vision Transformers (ViT) into Federated Learning (FL) by leveraging Visual Prompt Tuning (VPT), achieving state-of-the-art performance with enhanced efficiency across various visual downstream tasks. However, data heterogeneity, such as feature shift and class imbalance, limits prompts' transferability and robustness in FPT. Existing methods primarily focus on generalized FPT (GFPT) or personalized FPT (PFPT), while only a few methods make initial attempts to integrate both approaches. In this paper, we propose a new FPT framework, dubbed DualFPT, which handles data heterogeneity from both generalized and personalized perspectives. Specifically, DualFPT divides the learnable prompts into global and local prompts to jointly capture general and client-specific information, achieving the harmonization of GFPT and PFPT. The generalization of DualFPT is realized by the Feature Sharing (FS) mechanism, which effectively narrows the distribution gap by allowing clients to securely share a portion of sensitive features. The key feature for improving personalization is the Prompt Composition Scheme (PCS), which weights local prompts with distribution similarity to generate composite prompts, thus achieving automatic distribution adaptation. Extensive experiments under feature shift and class imbalance scenarios demonstrate the superior performance of DualFPT. On DomainNet and CIFAR-100 (D (0.1)), DualFPT surpasses SGPT by 4.35% and 5.89% for generalization along with 7.89% and 9.09% for personalization. Ablation studies further validate the effectiveness, efficiency, and security of DualFPT. Yuliang Chen, Xi Lin 0003, Chao Sang, Xiu Su |
ACM Multimedia | 3 |
| 2024 | A Binary Level Verification Framework for Real-Time Performance of PLC Program in Backhaul/Fronthaul NetworksabstractPLC control programs are vulnerable to real-time threats, where attackers can disrupt the backhaul/front-end network of industrial production by creating numerous loops or I/O operations, leading to severe consequences. Therefore, formal verification of PLC control logic at the binary level is essential. In this study, we introduce a framework designed for formal verification of PLC control logic at the binary level. Our verification framework is based on simulation execution, which extracts the core control logic from PLC binary code. Initially, we develop an efficient framework for automating the parsing of PLC programs at the binary level and constructing their control flow graphs (CFGs). Next, we devise an algorithm to transform the reversed PLC assembly program into an smv model, a widely accepted formal verification tool. Subsequently, we generate real-time requirements relevant to industrial production and perform formal verification on the constructed models. To assess the real-time performance of our framework in safeguarding PLC systems, we implement a prototype and evaluated it across various representative ICS scenarios. The evaluation results demonstrate the capability of our proposed approach to effectively detect synchronization threats in PLC logic control programs. Xuankai Zhang, Jun Wu 0001, Jianhua Li 0001, Ali Kashif Bashir, Chao Sang, Bei Pei, Marwan Omar |
ICC | 5 |
| 2024 | Binary Rewritten based Control Flow Integrity Protection for Wireless Industrial Communication SystemabstractIndustrial communication system (ICS) is widely used in critical infrastructure. As the scale of ICS increases, more and more devices are equipped with wireless capabilities which widen the scope of attack vectors. Therefore, its security has draw significant attention in recent years. As a key component of ICS, the security of Programmable Logic Controller (PLC) is directly related to ICS security. However, due to PLC's special mechanism, as long as the attack successfully break into the PLC, conventional control flow integrity (CFI) mechanism can't effectively protect its control flow. To address this problem, we propose a novel CFI mechanism to enhance the security of PLC. First, we design an instrumentation framework, with which we can add custom features such as CFI to enhance the PLC. Second, to effectively protect the control flow, we design a CFI mechanism based on sensitive memory protection using hash check. Last, to ensure the instrumented binary can be correctly loaded and match the constraint of runtime, we design a control binary reconstruction method. To evaluate the correctnessof our CFI mechanism, we perform experiments in two different PLCs using 15 different control binaries. The result shows that our CFI mechanism can successfully protect PLC's control flow. Besides, according to our evaluation, the size of the generated control binary instrumented with CFI mechanism code merely grow a little compared with its original size. As for the dynamically cost, our instrumented code does influence the count of the instructions non-ignorable but is within the acceptable range. Rongwei Zhang, Jun Wu 0001, Bei Pei, Chao Sang, Quanhai Zhang |
ICC | 4 |
| 2024 | From Control Application to Control Logic: PLC Decompile Framework for Industrial Control SystemabstractIndustrial Control System (ICS) depends on the underlying Programmable Logical Controllers (PLCs) to run. As such, the security of the internal control logic of the PLCs is the top concern of ICS. Reversing analysis and forensic work against PLC require extracting control logic from the control application running inside PLC, which is still an unresolved problem. To address the challenge, we propose a PLC decompile framework named CLEVER, which can analyze the control application and extract the control logic. First, we propose a simulation execution based code extraction method, which is utilized to filter the control logic related data. Then, to normalize the control application decompile process, an intermediate representation (IR) is designed, which can simplify the analysis process and enhance the extensibility of CLEVER. Finally, a heuristic data flow analysis algorithm is proposed to find variable dependency, and a sequential parsing method is utilized to reconstruct the source code from the control application. To evaluate our work, real world PLC hardware and programming software are used for the experiment. We use 22 real-world, 58 hand-written, and 150 auto-generated control applications to demonstrate the usability, correctness, and operational efficiency of CLEVER. Chao Sang, Jun Wu 0001, Jianhua Li 0001, Mohsen Guizani |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | ECADA: An Edge Computing Assisted Delay-Aware Anomaly Detection Scheme for ICSabstractToday, with more and more devices in the industrial control system (ICS), the risk becomes higher and brings more attack surfaces. The need for reliable anomaly detection systems is increasing. Traditional SCADA-based detection systems deployed are difficult to assess large-scale control systems accurately, and novel AI-based technologies struggle to ensure timely response. In this paper, we propose an edge computing assisted delay-aware anomaly detection (ECADA) scheme for ICS, which considers both the accuracy and timeliness, and ensures that abnormal conditions can be accurately detected and handled in a short time. First, we model the components in ICS as three layers, taking network resources, delay, and reliability into consideration. Second, we convert the anomaly detection procedure into a decision making problem. By dividing the warning capabilities into various levels, the flexibility of the anomaly detection system is enhanced. Third, we cast a mixed-integer linear programming (MILP) problem to find the efficient anomaly detection mechanism, so that it can be dynamically scheduled to achieve the tradeoff between reliability and timeliness. We use an real-world industrial system dataset for experimental evaluation. By comparing with various traditional anomaly detection methods, it is proved that ECADA can always ensure reliable response of anomaly detection system in various network environments. Chao Sang, Jianhua Li 0001, Jun Wu 0001, Wu Yang 0001 |
MSN | 1 |
| 2023 | Heterogeneous Differential-Private Federated Learning: Trading Privacy for Utility TruthfullyabstractDifferential-private federated learning (DP-FL) has emerged to prevent privacy leakage when disclosing encoded sensitive information in model parameters. However, the existing DP-FL frameworks usually preserve privacy homogeneously across clients, while ignoring the different privacy attitudes and expectations. Meanwhile, DP-FL is hard to guarantee that uncontrollable clients (i.e., stragglers) have truthfully added the expected DP noise. To tackle these challenges, we propose a heterogeneous differential-private federated learning framework, named HDP-FL, which captures the variation of privacy attitudes with truthful incentives. First, we investigate the impact of the HDP noise on the theoretical convergence of FL, showing a tradeoff between privacy loss and learning performance. Then, based on the privacy-utility tradeoff, we design a contract-based incentive mechanism, which encourages clients to truthfully reveal private attitudes and contribute to learning as desired. In particular, clients are classified into different privacy preference types and the optimal privacy-price contracts in the discrete-privacy-type model and continuous-privacy-type model are derived. Our extensive experiments with real datasets demonstrate that HDP-FL can maintain satisfactory learning performance while considering different privacy attitudes, which also validate the truthfulness, individual rationality, and effectiveness of our incentives. Xi Lin 0003, Jun Wu 0001, Jianhua Li 0001, Chao Sang, Shiyan Hu 0001, M. Jamal Deen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | 3MCor: an integrative web server for metabolome-microbiome-metadata correlation analysisabstractMOTIVATION: The metabolome and microbiome disorders are highly associated with human health, and there are great demands for dual-omics interaction analysis. Here, we designed and developed an integrative platform, 3MCor, for metabolome and microbiome correlation analysis under the instruction of phenotype and with the consideration of confounders. RESULTS: Many traditional and novel correlation analysis methods were integrated for intra- and inter-correlation analysis. Three inter-correlation pipelines are provided for global, hierarchical and pairwise analysis. The incorporated network analysis function is conducive to rapid identification of network clusters and key nodes from a complicated correlation network. Complete numerical results (csv files) and rich figures (pdf files) will be generated in minutes. To our knowledge, 3MCor is the first platform developed specifically for the correlation analysis of metabolome and microbiome. Its functions were compared with corresponding modules of existing omics data analysis platforms. A real-world dataset was used to demonstrate its simple and flexible operation, comprehensive outputs and distinctive contribution to dual-omics studies. AVAILABILITYAND IMPLEMENTATION: 3MCor is available at http://3mcor.cn and the backend R script is available at https://github.com/chentianlu/3MCorServer. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Mengci Li, Xiangtian Yu, Dandan Liang, Guoxiang Xie, Chao Sang, Wei Jia 0002, Tianlu Chen |
Bioinform. | 6 |
| 2020 | RALaaS: Resource-Aware Learning-as-a-Service in Edge-Cloud Collaborative Smart Connected CommunitiesabstractAs increasingly advanced data collection and computing abilities are equipped by devices at the network edge, accompanying the vigorous development of machine learning, edge devices become both the consumer and provider of data. Due to the timeliness of some learning demands and the necessity of learning results, learning resources such as data collection, transmission, and learning should be unified and converged to meet timely learning needs. In this paper, we propose a framework to implement a distributed Learning-as-a-Service function by edge-cloud collaboratively integrating resources required by a learning task. First, the architecture of RALaaS and underlying information interaction are proposed. We then formulate the learning-resource allocation problem and propose a deep reinforcement learning based solution to minimize the required learning resource and achieve better accuracy. More precisely, an A3C algorithm is presented to schedule tasks among smart connected communities and aggregate models. Finally, evaluation results show that our proposed framework can improve the accuracy by 10% compared with conventional algorithms and save about 50% edge resources when 30 nodes participate in the learning task. Chao Sang, Jun Wu 0001, Jianhua Li 0001, Ali Kashif Bashir, Rupak Kharel |
GLOBECOM | 1 |