Pengchao Yao

dblp:306/3589 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
7since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Game-Theory-Based Optimal Defense for Cyberspace Attacks in Industrial Cyber-Physical Systems With Information Uncertainties
abstract
When applying the game-theoretic approach to find the optimal strategy for industrial cyber-physical systems defenders, most existing work assumes both the system states (e.g., for a power grid system, the system state captures which buses are compromised) and the attacker’s instant actions are observable and can be used to make the decision for the defender’s next move. Also, the reward and expected utilities are calculated based on the most likely system state and attack action. However, there is uncertainty in determining the system state and attack actions as the attack unfolds in the system in practice. This work shows that such an approximation is non-optimal in determining the defense strategy. Instead, we propose a framework that models the uncertainty in the system state and attack action. We derive the defender’s optimal strategy under such uncertainty by calculating the expected utilities across different action spaces and redefining the immediate reward within the deep learning algorithm based on the expected utilities and our estimation of the probabilistic distribution of the system state and attack action, ultimately employing the agent system for learning and generating the optimal defense strategy. The simulation experiments are carried out based on the generic industrial cyber-physical system testbed and the numerical results confirmed that the proposed solution can improve the defender’s expected utilities by 38.8% compared to the state-of-the-art.
Bingjing Yan, Binbin Chen 0001, Tao Yang 0043, Pengchao Yao, Qiang Yang 0004
IEEE Internet Things J.4
2025 A Rotational Modulation Method for the Rotational Inertial Navigation System of Long-Endurance Underwater Vehicle
abstract
In long endurance underwater vehicle rotational inertial navigation system, the rotation strategy significantly impacts navigation accuracy. To address the limitations of the dual-axis 16-position rotation modulation scheme, specifically, its large rotation angles and inability to modulate errors arising from the coupling of scale factors and Earth’s rotation rate. This paper proposes a geocentric frame based triaxial 32-position rotation modulation method. This method suppresses navigation errors by altering the direction of the rotation axis and increasing the rotation sequence. It simultaneously isolates the Earth’s rotation rate, thereby eliminating the coupling error between inertial sensor scale factors and Earth rotation, and enhancing system navigation accuracy. Experimental results demonstrate that the system achieves a navigation positioning accuracy of approximately 2.2 nautical miles (n mile) over 72 hours. Compared to a single-axis RINS, positioning accuracy is improved by a factor of 8. Compared to a dual-axis RINS, positioning accuracy is enhanced by 0.75 n mile. These results validate the effectiveness of the proposed method in improving navigation accuracy.
Pengchao Yao, Dongjie Wu, Dongsheng Xu 0003, Tianyu Chen 0014, Gongliu Yang, Yongqiang Tu
IEEE Internet Things J.1
2025 Game Theoretical Decision-Making of Dynamic Defense in Cyber-Physical Power Systems under Cyber-Attacks
abstract
The reliable and safe operation of the Cyber-Physical Power System (CPPS) consisting of power generation and transmission highly depends on the security of the underlying communication infrastructure. The facilities of the CPPS are often geographically distributed and vulnerable to coordinated cyber-attacks. This demands proactive security management solutions considering the various security situation of CPPS facilities to protect them. This article presents a game theory-based dynamic decision-making solution for collaboratively securing critical facilities to minimize system performance degradation under cyber-attacks. We take the essential generation facility (i.e., power plant) as the research object to validate the solution. An analysis of the attack penetration process described by the Bayesian Attack Graph (BAG) is carried out to assess the security situation of each power plant. Then, a stochastic game model is developed to characterize the interaction of the attacker and the defender considering the varying situation of every power plant. A novel reinforcement learning algorithm is presented to solve the Nash equilibrium and obtain the dynamic optimal security strategies that defend the most important power plants. The proposed solution is extensively evaluated through a range of experiments based on the IEEE 57-bus test system, and the numerical results demonstrated the effectiveness of the proposed solution.
Pengchao Yao, Bingjing Yan, Qiang Yang 0004
ACM Trans. Cyber Phys. Syst.1
2024 Statistical knowledge and game-theoretic integrated model for cross-layer impact assessment in industrial cyber-physical systems
Pengchao Yao, Zebang Zhang, Bingjing Yan, Qiang Yang 0004, Wenhai Wang
Adv. Eng. Informatics1
2024 Security-Enhanced Operational Architecture for Decentralized Industrial Internet of Things: A Blockchain-Based Approach
abstract
The remarkable development of the Industrial Internet of Things (IIoT) has undoubtedly elevated industrial operations to a more intelligence and efficiency level, yet it has also introduced a range of security challenges. The widespread of intelligent IoT devices has greatly expanded the attack surface for cyber-attacks. Additionally, the cloud-based centralized management architecture of traditional IIoT is susceptible to single-point-of-failure, which exacerbates the security risks. Nowadays, the secure and decentralized nature of blockchain has been considered a promising solution to address the security and privacy challenges in IIoT. This article proposes a blockchain-based operational architecture for IIoT (SecureArchi- IIoT) to enhance security and privacy in IIoT operations. Under this architecture, a set of smart contracts are designed to provide operational functionalities that are suitable for actual industrial demands. An operational control policy is designed to realize precise and effective management of the operation permissions with distinct granularity. Furthermore, a reputation-based behavioral punishment mechanism is developed to enhance the security performance of the proposed architecture. The prototype of the proposed architecture is implemented in a private IIoT environment to demonstrate its feasibility and effectiveness. Experimental results confirm that the proposed architecture outperforms the traditional architecture in aspects of security and privacy and maintains acceptable real-time performance.
Pengchao Yao, Bingjing Yan, Tao Yang 0043, Qiang Yang 0004, Wenhai Wang
IEEE Internet Things J.1
2024 Bayesian and stochastic game joint approach for Cross-Layer optimal defensive Decision-Making in industrial Cyber-Physical systems
Pengchao Yao, Zhengze Jiang, Bingjing Yan, Qiang Yang 0004, Wenhai Wang
Inf. Sci.1
2022 Industrial Cyber-Physical System Defense Resource Allocation Using Distributed Anomaly Detection
abstract
An industrial cyber–physical system (ICPS) tightly integrating both physical processes and information and communication technologies (ICTs) leads to increasing cyberspace threats and attacks for the critical electrical infrastructure. With the limited defense resources availability, the efficient threat perception and mitigation of potential impacts of cyber attacks are essential to enhance the ICPS operational security. This article proposes an optimal defense resource allocation solution to prioritize the ICPS asset protection based on the distributed network traffic anomaly detection. The traffic anomalies and attack paths can be timely detected simultaneously over multiple security zones of the electrical infrastructure through local computing devices. The defense resource allocation is formulated as a multiobjective optimization (MOO) problem considering the tradeoff among the asset vulnerability, cost, and criticality, and solved by the Pareto optimal solution generation approach. The proposed solution is extensively evaluated using a realistic electrical CPS (ECPS) testbed for a range of cyber-attack scenarios. The numerical results confirm the effectiveness of the proposed distributed anomaly detection model and defense resource allocation strategy for varying defense resource availabilities.
Weijie Hao, Pengchao Yao, Tao Yang 0043, Qiang Yang 0004
IEEE Internet Things J.2