VLDB 2026 Research / reviewers in the wild / expert
Yuan Zhou 0005
dblp:40/7018-5
· DBLP profile ↗
39ranked-venue papers
5as first author
28since 2021 · last 2026
0000-0002-1583-7570ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 1 first-author · 6 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 9 since 2021Systems, architecture and hardware · 6 · 1 first-author · 5 since 2021Security and privacy · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fuzzy-DDPG: Integrating fuzzy logic with continuous deep reinforcement learning for mobile robot motion planning
Fenghua Wu, Wenbing Tang 0001, Yuan Zhou 0005, Hesuan Hu, Yang Liu 0003, Zuohua Ding |
Fuzzy Sets Syst. | 3 |
| 2026 | SSD: A State-Based Stealthy Backdoor Attack for IMU/GNSS Navigation System in UAV Route PlanningabstractUnmanned aerial vehicles (UAVs) are increasingly employed to perform high-risk tasks that require minimal human intervention. However, they face escalating cybersecurity threats, particularly from GNSS spoofing attacks. While previous studies have extensively investigated the impacts of GNSS spoofing on UAVs, few have focused on its effects on specific tasks. Moreover, the influence of UAV motion states on the assessment of cybersecurity risks is often overlooked. To address these gaps, we first provide a detailed evaluation of how motion states affect the effectiveness of network attacks. We demonstrate that nonlinear motion states not only enhance the effectiveness of position spoofing in GNSS spoofing attacks but also reduce the probability of detecting speed-related attacks. Building upon this, we propose a state-triggered backdoor attack method (SSD) to deceive GNSS systems and assess its risk to trajectory planning tasks. Extensive validation of SSD’s effectiveness and stealthiness is conducted. Experimental results show that, with appropriately tuned hyperparameters, SSD significantly increases positioning errors and the risk of task failure, while maintaining high stealthy rates across three state-of-the-art detectors. Zhaoxuan Wang, Yang Li 0055, Jie Zhang 0073, Xingshuo Han, Kangbo Liu, Yang Lyu, Yuan Zhou 0005, Tianwei Zhang 0004, Quan Pan 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2026 | Causality-Aware Safety Testing for Autonomous Driving SystemsabstractSimulation-based testing is essential for evaluating the safety of Autonomous Driving Systems (ADSs). Comprehensive evaluation requires testing across diverse scenarios that can trigger various types of violations under different conditions. While existing methods typically focus on individual diversity metrics, such as input scenarios, ADS-generated motion commands, and system violations, they often fail to capture the complex interrelationships among these elements. For instance, identical motion commands can produce different collision risks in varying scenes, and the same collision may result from different commands under different scenarios. This oversight leads to gaps in testing coverage, potentially missing critical issues in the ADS under evaluation. In this paper, we proposeCausal-Fuzzer, the first causality-aware fuzzing technique that enables efficient and comprehensive testing of ADSs by constructing causal graphs to model the interrelationships among scenarios, actions, and violations. Unlike existing methods that treat diversity metrics independently, we recognize these elements are causally interconnected and use their relationships to identify more diverse violations triggered by fundamentally different causal mechanisms. Specifically,Causal-Fuzzerproposes (1) a causality-based feedback mechanism that quantifies the combined diversity of test scenarios by assessing whether they activate new causal relationships, and (2) a causality-driven mutation strategy that prioritizes mutations on input scenario elements with higher causal impact on ego action changes and violation occurrence to enable interpretable and efficient test generation. We evaluatedCausal-Fuzzeron an industry-grade ADS Apollo, with a high-fidelity simulator LGSVL. Our empirical results demonstrate thatCausal-Fuzzersignificantly outperforms existing methods in (1) identifying a greater diversity of violations (96.5 violations on average, compared to 66.9 for the best baseline method), (2) providing enhanced testing sufficiency with improved coverage of causal relationships (13.6 unique sceneaction- violation patterns on average, compared to 8.6 for the best baseline method), and (3) achieving greater efficiency in detecting critical scenarios, strong robustness under noise conditions, and good generalizability across varying scenario complexities and violation types. Our source code and experimental results are available athttps://sites.google.com/view/causal-fuzzer. Wenbing Tang 0001, Mingfei Cheng, Yuan Zhou 0005, Yang Liu 0003, Zuohua Ding |
IEEE Trans. Software Eng. | 4 |
| 2025 | An LLM-Empowered Adaptive Evolutionary Algorithm for Multi-Component Deep Learning SystemsabstractMulti-objective evolutionary algorithms (MOEAs) are widely used for searching optimal solutions in complex multi-component applications. Traditional MOEAs for multi-component deep learning (MCDL) systems face challenges in enhancing the search efficiency while maintaining the diversity. To combat these, this paper proposes the first LLM-empowered adaptive evolutionary search algorithm to detect safety violations in MCDL systems. Inspired by the context-understanding ability of Large Language Models (LLMs), our approach promotes the LLM to comprehend the optimization problem and generate an initial population tailed to evolutionary objectives. Subsequently, it employs adaptive selection and variation to iteratively produce offspring, balancing the evolutionary efficiency and diversity. During the evolutionary process, to navigate away from the local optima, our approach integrates the evolutionary experience back into the LLM. This utilization harnesses the LLM's quantitative reasoning prowess to generate differential seeds, breaking away from current optimal solutions. We evaluate our approach in finding safety violations of MCDL systems, and compare its performance with state-of-the-art MOEA methods. Experimental results show that our approach can significantly improve the efficiency and diversity of the evolutionary search. Haoxiang Tian 0001, Xingshuo Han, Guoquan Wu, An Guo 0002, Yuan Zhou 0005, Jie Zhang 0073, Jun Wei 0001, Tianwei Zhang 0004 |
AAAI | 5 |
| 2025 | Decictor: Towards Evaluating the Robustness of Decision-Making in Autonomous Driving SystemsabstractAutonomous Driving System (ADS) testing is crucial in ADS development, with the current primary focus being on safety. However, the evaluation of non-safety-critical performance, particularly the ADS's ability to make optimal decisions and produce optimal paths for autonomous vehicles (AVs), is also vital to ensure the intelligence and reduce risks of AVs. Currently, there is little work dedicated to assessing the robustness of ADSs' path-planning decisions (PPDs), i.e., whether an ADS can maintain the optimal PPD after an insignificant change in the environment. The key challenges include the lack of clear oracles for assessing PPD optimality and the difficulty in searching for scenarios that lead to non-optimal PPDs. To fill this gap, in this paper, we focus on evaluating the robustness of ADSs' PPDs and propose the first method, Decictor, for generating nonoptimal decision scenarios (NoDSs), where the ADS does not plan optimal paths for AVs. Decictor comprises three main components: Non-invasive Mutation, Consistency Check, and Feedback. To overcome the oracle challenge, Non-invasive Mutation is devised to implement conservative modifications, ensuring the preservation of the original optimal path in the mutated scenarios. Subsequently, the Consistency Check is applied to determine the presence of nonoptimal PPDs by comparing the driving paths in the original and mutated scenarios. To deal with the challenge of large environment space, we design Feedback metrics that integrate spatial and temporal dimensions of the AV's movement. These metrics are crucial for effectively steering the generation of NoDSs. Therefore, Decictor can generate NoDSs by generating new scenarios and then identifying NoDSs in the new scenarios. We evaluate Decictor on Baidu Apollo, an open-source and production-grade ADS. The experimental results validate the effectiveness of Decictor in detecting non-optimal PPDs of ADSs. It generates 63.9 NoDSs in total, while the best-performing baseline only detects 35.4 NoDSs. Mingfei Cheng, Xiaofei Xie, Yuan Zhou 0005, Junjie Wang 0007, Guozhu Meng, Kairui Yang |
ICSE | 3 |
| 2025 | Stealthiness Assessment of Adversarial Perturbation: From a Visual PerspectiveabstractAssessing the stealthiness of adversarial perturbations is challenging due to the lack of appropriate evaluation metrics. Existing evaluation metrics, e.g.,$L_{p}$norms or Image Quality Assessment (IQA), fall short of assessing the pixel-level stealthiness of subtle adversarial perturbations since these metrics are primarily designed for traditional distortions. To bridge this gap, we present the first comprehensive study on the subjective and objective assessment of the stealthiness of adversarial perturbations from a visual perspective at a pixel level. Specifically, we propose new subjective assessment criteria for human observers to score adversarial stealthiness in a fine-grained manner. Then, we create a large-scale adversarial example dataset comprising 10586 pairs of clean and adversarial samples encompassing twelve state-of-the-art adversarial attacks. To obtain the subjective scores according to the proposed criterion, we recruit 60 human observers, and each adversarial example is evaluated by at least 15 observers. The mean opinion score of each adversarial example is utilized for labeling. Finally, we develop a three-stage objective scoring model that mimics human scoring habits to predict adversarial perturbation’s stealthiness. Experimental results demonstrate that our objective model exhibits superior consistency with the human visual system, surpassing commonly employed metrics like PSNR and SSIM. Hangcheng Liu, Yuan Zhou 0005, Ying Yang 0019, Qingchuan Zhao, Tianwei Zhang 0004, Tao Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Adaptive Communications in Collaborative Perception with Domain Alignment for Autonomous DrivingabstractCollaborative perception among multiple connected and autonomous vehicles (CAVs) can greatly enhance perceptive capabilities by allowing vehicles to exchange supplementary information. Despite significant advances, many design challenges still remain due to channel variations and data heterogeneity among collaborative vehicles. To address these issues, we propose ACC-DA, a channel-aware collaborative perception framework to dynamically adjust the communication graph to minimize the average transmission delay while mitigating the impacts caused by data heterogeneity. More specifically, we first construct the communication graph to minimize the transmission delay according to different channel information state. We then propose an adaptive data reconstruction mechanism to dynamically adjust the rate-distortion trade-off to enhance perception efficiency while reducing the temporal redundancy during data transmissions. Finally, we conceive a domain alignment scheme to align the data distribution from different vehicles to mitigate the domain gap between different vehicles and improve the performance of the target task. Comprehensive experiments demonstrate the effectiveness of our method in comparison to the existing state-of-the-art works. Senkang Hu, Zhengru Fang, Haonan An 0001, Guowen Xu, Yuan Zhou 0005, Xianhao Chen, Yuguang Fang |
GLOBECOM | 5 |
| 2024 | SmartCooper: Vehicular Collaborative Perception with Adaptive Fusion and Judger MechanismabstractIn recent years, autonomous driving has garnered significant attention due to its potential for improving road safety through collaborative perception among connected and autonomous vehicles (CAVs). However, time-varying channel variations in vehicular transmission environments demand dynamic allocation of communication resources. Moreover, in the context of collaborative perception, it is important to recognize that not all CAVs contribute valuable data, and some CAV data even have detrimental effects on collaborative perception. In this paper, we introduce SmartCooper, an adaptive collaborative perception framework that incorporates communication optimization and a judger mechanism to facilitate CAV data fusion. Our approach begins with optimizing the connectivity of vehicles while considering communication constraints. We then train a learnable encoder to dynamically adjust the compression ratio based on the channel state information (CSI). Subsequently, we devise a judger mechanism to filter the detrimental image data reconstructed by adaptive decoders. We evaluate the effectiveness of our proposed algorithm on the OpenCOOD platform. Our results demonstrate a substantial reduction in communication costs by 23.10% compared to the non-judger scheme. Additionally, we achieve a significant improvement on the average precision of Intersection over Union (AP@IoU) by 7.15% compared with state-of-the-art schemes. Haonan An 0001, Zhengru Fang, Guowen Xu, Yuan Zhou 0005, Xianhao Chen, Yuguang Fang |
ICRA | 5 |
| 2024 | SoVAR: Build Generalizable Scenarios from Accident Reports for Autonomous Driving TestingabstractAutonomous driving systems (ADSs) have undergone remarkable development and are increasingly employed in safety-critical applications. However, recently reported data on fatal accidents involving ADSs suggests that the desired level of safety has not yet been fully achieved. Consequently, there is a growing need for more comprehensive and targeted testing approaches to ensure safe driving. Scenarios from real-world accident reports provide valuable resources for ADS testing, including critical scenarios and high-quality seeds. However, existing scenario reconstruction methods from accident reports often exhibit limited accuracy in information extraction. Moreover, due to the diversity and complexity of road environments, matching current accident information with the simulation map data for reconstruction poses significant challenges. An Guo 0002, Yuan Zhou 0005, Haoxiang Tian 0001, Chunrong Fang, Yunjian Sun, Weisong Sun, Anh Tuan Luu, Yang Liu 0003, Zhenyu Chen 0001 |
ASE | 2 |
| 2024 | LeGEND: A Top-Down Approach to Scenario Generation of Autonomous Driving Systems Assisted by Large Language ModelsabstractAutonomous driving systems (ADS) are safety-critical and require comprehensive testing before their deployment on public roads. While existing testing approaches primarily aim at the criticality of scenarios, they often overlook the diversity of the generated scenarios that is also important to reflect system defects in different aspects. To bridge the gap, we propose LeGEND, that features a top-down fashion of scenario generation: it starts with abstract functional scenarios, and then steps downwards to logical and concrete scenarios, such that scenario diversity can be controlled at the functional level. However, unlike logical scenarios that can be formally described, functional scenarios are often documented in natural languages (e.g., accident reports) and thus cannot be precisely parsed and processed by computers. To tackle that issue, LeGEND leverages the recent advances of large language models (LLMs) to transform textual functional scenarios to formal logical scenarios. To mitigate the distraction of useless information in functional scenario description, we devise a two-phase transformation that features the use of an intermediate language; consequently, we adopt two LLMs in LeGEND, one for extracting information from functional scenarios, the other for converting the extracted information to formal logical scenarios. We experimentally evaluate LeGEND on Apollo, an industry-grade ADS from Baidu. Evaluation results show that LeGEND can effectively identify critical scenarios, and compared to baseline approaches, LeGEND exhibits evident superiority in diversity of generated scenarios. Moreover, we also demonstrate the advantages of our two-phase transformation framework, and the accuracy of the adopted LLMs. Shuncheng Tang, Zhenya Zhang 0001, Jixiang Zhou, Yuan Zhou 0005, Yinxing Xue |
ASE | 5 |
| 2024 | Backdooring Multimodal LearningabstractDeep Neural Networks (DNNs) are vulnerable to backdoor attacks, which poison the training set to alter the model prediction over samples with a specific trigger. While existing efforts mainly focus on unimodal scenarios, modern AI systems usually employ multiple modalities to improve the model performance, making multimodal backdoor attacks more practical but structurally more complex due to inherent modality interactions, multiple attack surfaces, unbalanced modality contributions, etc. These factors affect the effectiveness of backdooring multimodal learning significantly but have not been fully investigated yet.To bridge this gap, we present the first data and computation efficient backdoor attacks towards multimodal learning. Our solution consists of two innovations. First, we propose a novel backdoor gradient-based score (BAGS), which can accurately quantify the contribution of each data sample to the backdoor learning at a very early training stage. Therefore, it can greatly save time and computational resources for the attacker. Second, we introduce a searching strategy with two attack modes to efficiently determine the optimal poisoning modalities and data samples.Our methodology leads to the following research outcomes. First, we comprehensively evaluate the proposed solution over state-of-the-art multimodal tasks, models, datasets and settings, to verify its effectiveness, efficiency and transferability. For instance, we only need to poison 0.005% of training samples to attack the Visual Question Answering task with the success rate of >96%. For the Audio Video Speech Recognition task, we poison 0.05% of samples to achieve the success rate of >93%. Second, we disclose several interesting findings during our experiments: (1) poisoning all modalities is not always better than individual ones, sometimes even making the attack worse; (2) modality competition and complementarity coexist in multimodal learning backdoor attacks; (3) A dominant modality in multimodal learning may not dominate the backdoor attacks. We hope this work will spur future research in improving the security of multimodal learning. Code is available at https://github.com/multimodalbags/BAGS_Multimodal. Xingshuo Han, Yutong Wu 0009, Yuan Zhou 0005, Yuan Xu 0033, Han Qiu 0001, Guowen Xu, Tianwei Zhang 0004 |
SP | 4 |
| 2024 | Robust Motion Planning for Multi-Robot Systems Against Position Deception AttacksabstractDeep reinforcement learning (DRL) is widely applied in motion planning for multi-robot systems as DRL leverages the offline training process to improve the real-time computation efficiency. In DRL-based methods, the DRL models compute an action for a robot based on the states of its surrounding obstacles, including other robots in the system. They always assume that the number of obstacles is fixed and the obtained obstacles’ states are reliable. However, in the real world, a multi-robot system may suffer from various attacks, such as remote control attacks and network attacks, that cause wrong positions of the surrounding obstacles received by a robot. In this paper, we propose a robust motion planning methodDAE-Crit-LSTM, integrating a denoising autoencoder (DAE) with DRL models, to mitigate such position deception attacks in environments with a different number of obstacles.DAE-Crit-LSTMshows the following two advantages. First,DAE-Crit-LSTMcan be applied in benign and attacked scenarios and thus does not require any detector. It learns an encoder and a decoder to approximate the accurate positions of the obstacles, no matter under attack or not. Second,DAE-Crit-LSTMapplies an LSTM (Long Short-Term Memory)-based DRL model to deal with a variable number of obstacles in the environment. It is worth noting thatDAE-Crit-LSTMis method-agnostic and can be easily implemented in state-of-the-art motion planning methods. Comprehensive experiments show thatDAE-Crit-LSTMcan mitigate position deception attacks and guarantee safe motion. We also demonstrate the effectiveness and generalization ofDAE-Crit-LSTM. Wenbing Tang 0001, Yuan Zhou 0005, Yang Liu 0003, Zuohua Ding, Jing Liu 0012 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Causality-Guided Counterfactual Debiasing for Anomaly Detection of Cyber-Physical SystemsabstractMachine learning has become a promising technology for anomaly detection of cyber-physical systems (CPSs). However, the trained anomaly detection models always suffer from bias due to the scarcity of anomaly data in CPSs and the biased data collection process, which may poison the models' generalization ability. Recent debiasing methods are proposed to deal with the bias via resampling the training dataset, reweighting during the training phase, or adjusting the classification threshold. However, they may lose valuable information, need extra knowledge of the models, or lead to overfitting. Especially, they lack a causal understanding of the debiasing process, so they cannot point out the source and propagation of the bias and, thus, cannot deal with it in an explainable way. In this article, we propose a counterfactual debiasing framework to mitigate the bias in a well-trained model. First, we formalize the model's training and inference processes using causal graphs. Thus, we can understand the source and propagation of the model's bias through causal inference. Then, we use counterfactual inference to estimate the bias's detrimental causal effect on the prediction and remove it from the total causal effect. Therefore, we can conduct unbiased inferences with a biased model. The proposed method can remove the bias in an explainable way by incorporating causal graphs. Comprehensive experiments are conducted on seven real-world CPS datasets, i.e., IDA, MFP, ACS, SPF, UNS, NSL, and ICS. The results demonstrate the effectiveness, compatibility, and unbiasedness of the proposed approach. Wenbing Tang 0001, Jing Liu 0012, Yuan Zhou 0005, Zuohua Ding |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | Distributed Motion Control for Multiple Mobile Robots Using Discrete-Event Systems and Model Predictive ControlabstractDistributed motion control is critical in multiple mobile robot systems (MMRSs). Current research usually focuses on either discrete approaches, which aim to deal with high-level collisions and deadlocks without considering the low-level motion commands, or continuous approaches, which can optimize low-level continuous commands to mobile robots but cannot deal with deadlocks efficiently. In this article, by combining discrete and continuous methods, we design a hybrid motion control method for MMRSs where each robot should move along a predefined path. First, each robot’s motion is modeled as a discrete transition system, based on which a real-time supervisory control policy is illustrated to avoid collisions and deadlocks. Second, according to the discrete decisions, the continuous speed at each discrete state is computed using model predictive control and sequential convex programming. The proposed hybrid approach brings two advantages. First, the discrete control component guarantees collision and deadlock avoidance and reduces the scale of the optimization problems. Second, continuous control optimizes the continuous speed in real time and fulfills other performance requirements like time and energy costs. To move in a fully distributed way, each robot needs to predict the motion of its neighbors by retrieving their immediately available information through communications. The simulation and real-world experimental results show the effectiveness of our approach. Yuan Zhou 0005, Hesuan Hu, Gelei Deng, Shangwei Lin 0001, Yang Liu 0003, Zuohua Ding |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2023 | FLYOVER: A Model-Driven Method to Generate Diverse Highway Interchanges for Autonomous Vehicle TestingabstractIt has become a consensus that autonomous vehicles (AVs) will first be widely deployed on highways. However, the complexity of highway interchanges becomes the bottleneck for their deployment. An AV should be sufficiently tested under different highway interchanges, which is still challenging due to the lack of available datasets containing diverse highway interchanges. In this paper, we propose a model-driven method, Flyover, to generate a dataset of diverse interchanges with measurable diversity coverage. First, Flyover uses a labeled digraph to model interchange topology. Second, Flyover takes real-world interchanges as input to guarantee topology practicality and extracts different topology equivalence classes by classifying corresponding topology models. Third, for each topology class, Flyover identifies the corresponding geometrical features for the ramps and generates concrete interchanges using k-way combinatorial coverage and differential evolution. To illustrate the diversity and applicability of the generated interchange dataset, we test the built-in traffic flow control algorithm in SUMO and the fuel-optimization trajectory tracking algorithm deployed to Alibaba's autonomous trucks on the dataset. The results show that except for the geometrical difference, the interchanges are diverse in throughput and fuel consumption under the traffic flow control and trajectory tracking algorithms, respectively. Yuan Zhou 0005, Gengjie Lin, Yun Tang 0003, Kairui Yang, Junbo Chen, Yang Liu 0003 |
ICRA | 1 |
| 2023 | EvoScenario: Integrating Road Structures into Critical Scenario Generation for Autonomous Driving System TestingabstractAutonomous Driving Systems (ADS) are safety-critical and require comprehensive testing before their deployment on public roads. Most existing testing approaches consist in generating scenarios that vary the behaviors of dynamic objects, while leaving a predefined road environment unchanged. Consequently, these approaches overlook the influence of different road structures on ADS safety, e.g., collisions can happen more frequently than usual on a merging road, because of the specific road structure. In this paper, we propose EvoScenario, a novel approach that integrates road structures into the generation of critical scenarios for exposing safety risks of ADS. Specifically, EvoScenario models a driving road as a sequence of road segments characterized in different aspects, such as their shapes and widths. Then, a test case is defined by concatenating the sequence of road segments and the sequence of dynamic object maneuvers. Inspired by EvoSuite that generates sequential method calls for Java unit testing, EvoScenario leverages the sequential models of test cases and constructs a multi-objective optimization framework to search for critical scenarios. We implement and demonstrate EvoScenario on an ADS provided by our industrial partner. Evaluation results show that EvoScenario can identify 6 types of safety violations, and outperform existing baseline testing approaches. Shuncheng Tang, Zhenya Zhang 0001, Jixiang Zhou, Yuan Zhou 0005, Yan-Fu Li, Yinxing Xue |
ISSRE | 4 |
| 2023 | BehAVExplor: Behavior Diversity Guided Testing for Autonomous Driving SystemsabstractTesting Autonomous Driving Systems (ADSs) is a critical task for ensuring the reliability and safety of autonomous vehicles. Existing methods mainly focus on searching for safety violations while the diversity of the generated test cases is ignored, which may generate many redundant test cases and failures. Such redundant failures can reduce testing performance and increase failure analysis costs. In this paper, we present a novel behavior-guided fuzzing technique (BehAVExplor) to explore the different behaviors of the ego vehi- cle (i.e., the vehicle controlled by the ADS under test) and detect diverse violations. Specifically, we design an efficient unsupervised model, called BehaviorMiner, to characterize the behavior of the ego vehicle. BehaviorMiner extracts the temporal features from the given scenarios and performs a clustering-based abstraction to group behaviors with similar features into abstract states. A new test case will be added to the seed corpus if it triggers new behav- iors (e.g., cover new abstract states). Due to the potential conflict between the behavior diversity and the general violation feedback, we further propose an energy mechanism to guide the seed selec- tion and the mutation. The energy of a seed quantifies how good it is. We evaluated BehAVExplor on Apollo, an industrial-level ADS, and LGSVL simulation environment. Empirical evaluation results show that BehAVExplor can effectively find more diverse violations than the state-of-the-art. Mingfei Cheng, Yuan Zhou 0005, Xiaofei Xie |
ISSTA | 2 |
| 2023 | A survey on cybersecurity attacks and defenses for unmanned aerial systems
Zhaoxuan Wang, Yang Li 0055, Yuan Zhou 0005, Libin Yang, Yuan Xu 0033, Tianwei Zhang 0004, Quan Pan 0001 |
J. Syst. Archit. | 4 |
| 2023 | ADS-Lead: Lifelong Anomaly Detection in Autonomous Driving SystemsabstractAutonomous Vehicles (AVs) are closely connected in the Cooperative Intelligent Transportation System (C-ITS). They are equipped with various sensors and controlled by Autonomous Driving Systems (ADSs) to provide high-level autonomy. The vehicles exchange different types of real-time data with each other, which can help reduce traffic accidents and congestion, and improve the efficiency of transportation systems. However, when interacting with the environment, AVs suffer from a broad attack surface, and the sensory data are susceptible to anomalies caused by faults, sensor malfunctions, or attacks, which may jeopardize traffic safety and result in serious accidents. In this paper, we proposeADS-Lead, an efficient collaborative anomaly detection methodology to protect the lane-following mechanism of ADSs.ADS-Leadis equipped with a novel transformer-based one-class classification model to identify time series anomalies (GPS spoofing threat) and adversarial image examples (traffic sign and lane recognition attacks). Besides, AVs inside the C-ITS form a cognitive network, enabling us to apply the federated learning technology to our anomaly detection method, where the vehicles in the C-ITS jointly update the detection model with higher model generalization and data privacy. Experiments on Baidu Apollo and two public data sets (GTSRB and Tumsimple) indicate that our method can not only detect sensor anomalies effectively and efficiently but also outperform state-of-the-art anomaly detection methods. Xingshuo Han, Yuan Zhou 0005, Kangjie Chen, Han Qiu 0001, Meikang Qiu, Yang Liu 0003, Tianwei Zhang 0004 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Specification-Based Autonomous Driving System TestingabstractAutonomous vehicle (AV) systems must be comprehensively tested and evaluated before they can be deployed. High-fidelity simulators such as CARLA or LGSVL allow this to be done safely in very realistic and highly customizable environments. Existing testing approaches, however, fail to test simulated AVs systematically, as they focus on specific scenarios and oracles (e.g., lane following scenario with the “no collision” requirement) and lack any coverage criteria measures. In this paper, we propose$\mathtt {AVUnit}$, a framework for systematically testing AV systems against customizable correctness specifications. Designed modularly to support different simulators,$\mathtt {AVUnit}$consists of two new languages for specifying dynamic properties of scenes (e.g. changing pedestrian behaviour after waypoints) and fine-grained assertions about the AV's journey.$\mathtt {AVUnit}$further supports multiple fuzzing algorithms that automatically search for test cases that violate these assertions, using robustness and coverage measures as fitness metrics. We evaluated the implementation of$\mathtt {AVUnit}$for the LGSVL+Apollo simulation environment, finding 19 kinds of issues in Apollo, which indicate that the open-source Apollo does not perform well in complex intersections and lane-changing related scenarios. Yuan Zhou 0005, Yang Sun 0008, Yun Tang 0003, Yuqi Chen 0001, Jun Sun 0001, Christopher M. Poskitt, Yang Liu 0003, Zijiang Yang 0006 |
IEEE Trans. Software Eng. | 1 |
| 2022 | On the (In)Security of Secure ROS2abstractRobot Operating System (ROS) has been the mainstream platform for research and development of robotic applications. This platform is well-known for lacking security features and efficiency for distributed robotic computations. To address these issues, ROS2 is recently developed by utilizing the Data Distribution Service (DDS) to provide security support. Integrated with DDS, ROS2 is expected to establish the basis for trustworthy robotic ecosystems. Gelei Deng, Guowen Xu, Yuan Zhou 0005, Tianwei Zhang 0004, Yang Liu 0003 |
CCS | 3 |
| 2022 | Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingabstractModern autonomous vehicles adopt state-of-the-art DNN models to interpret the sensor data and perceive the environment. However, DNN models are vulnerable to different types of adversarial attacks, which pose significant risks to the security and safety of the vehicles and passengers. One prominent threat is the backdoor attack, where the adversary can compromise the DNN model by poisoning the training samples. Although lots of effort has been devoted to the investigation of the backdoor attack to conventional computer vision tasks, its practicality and applicability to the autonomous driving scenario is rarely explored, especially in the physical world. Xingshuo Han, Guowen Xu, Yuan Zhou 0005, Xuehuan Yang, Jiwei Li 0001, Tianwei Zhang 0004 |
ACM Multimedia | 3 |
| 2022 | Online adaptation for autonomous unmanned systems driven by requirements satisfaction model
Yixing Luo, Yuan Zhou 0005, Haiyan Zhao 0001, Zhi Jin 0001, Tianwei Zhang 0004, Yang Liu 0003, Danny Barthaud, Yijun Yu 0001 |
Softw. Syst. Model. | 2 |
| 2021 | Route Coverage Testing for Autonomous Vehicles via Map ModelingabstractAutonomous vehicles (AVs) play an important role in transforming our transportation systems and relieving traffic congestion. To guarantee their safety, AVs must be sufficiently tested before they are deployed to public roads. Existing testing often focuses on AVs’ collision avoidance on a given route. There is little work on the systematic testing for AVs’ route planning and tracking on a map. In this paper, we propose CROUTE, a novel testing method based on a new AV testing criterion called route coverage. First, the map is modeled as a labeled Petri net, where roads, junctions, and traffic signs are modeled as places, transitions, and labels, respectively. Second, based on the Petri net, we define junctions’ topology features and route features for junction classification. The topology feature describes the topology of roads forming the junction, and the route feature identifies the actions that a vehicle can take to follow a route. They can characterize route types on a map. Hence, route coverage measures how many route types are covered. We then propose a systematic method that aims to cover all route types for a well-designed AV system with a small number of test cases. We implement and evaluate CROUTE on Baidu Apollo running with the LGSVL simulator. We carry out testing on the map from a section of San Francisco and find six different types of issues in Apollo. The experiment results show the validity of route coverage and the efficiency of CROUTE. Yun Tang 0003, Yuan Zhou 0005, Fenghua Wu, Yang Liu 0003, Jun Sun 0001, Wuling Huang |
ICRA | 2 |
| 2021 | Collision Avoidance Testing for Autonomous Driving Systems on Complete MapsabstractCollision avoidance is one of the crucial functions of autonomous driving systems (ADSs) to guarantee the safety of autonomous vehicles (AVs). It requires extensive testing before an AV is deployed to public roads. Most of the current ADS testing methods generate test cases either from real traffic data or manually designed for some specific scenarios. There is little work on systematic methods to generate test cases from a complete map where an AV operates. Systematic testing on such a map is challenging due to the enormous scenarios. In this paper, we propose a collision-avoidance testing method for ADSs running on a map, which aims to reduce the scenario space while maintaining scenario diversity. The method consists of test case classification and test case generation. First, we build the topology structure of a map, based on which we classify possible scenarios into different classes. Second, we divide test cases into different classes using the topology-based scenario classification and fuzzy number-based motion evaluation. Third, we implement a bisection method to generate test cases that can efficiently expose ADSs' failures. We evaluate our method on one of the state-of-the-art ADSs, Baidu Apollo. The experiment results show that our method discovers Apollo's issues effectively while reducing the number of generated test cases by 77.36%, compared with the random method. Yun Tang 0003, Yuan Zhou 0005, Yang Liu 0003, Jun Sun 0001 |
IV | 2 |
| 2021 | Systematic Testing of Autonomous Driving Systems Using Map Topology-Based Scenario ClassificationabstractAutonomous Driving Systems (ADSs), which replace humans to drive vehicles, are complex software systems deployed in autonomous vehicles (AVs). Since the execution of ADSs highly relies on maps, it is essential to perform global map-based testing for ADSs to guarantee their correctness and AVs’ safety in different situations. Existing methods focus more on specific scenarios rather than global testing throughout the map. Testing on a global map is challenging since the complex lane connections in a map can generate enormous scenarios. In this work, we propose ATLAS, an approach to ADSs’ collision avoidance testing using map topology-based scenario classification. The core insight of ATLAS is to generate diverse testing scenarios by classifying junction lanes according to their topology-based interaction patterns. First, ATLAS divides the junction lanes into different classes such that an ADS can execute similar collision avoidance maneuvers on the lanes in the same class. Second, for each class, ATLAS selects one junction lane to construct the testing scenario and generate test cases using a genetic algorithm. Finally, we implement and evaluate ATLAS on Baidu Apollo with the LGSVL simulator on the San Francisco map. Results show that ATLAS exposes nine types of real issues in Apollo 6.0 and reduces the number of junction lanes for testing by 98%. Yun Tang 0003, Yuan Zhou 0005, Tianwei Zhang 0004, Fenghua Wu, Yang Liu 0003 |
ASE | 2 |
| 2021 | An Investigation of Byzantine Threats in Multi-Robot SystemsabstractMulti-Robot Systems (MRSs) show significant advantages to deal with complex tasks efficiently. However, the system complexity inevitably enlarges the attack surface and adds difficulty in guaranteeing the security and safety of MRSs. In this paper, we present an in-depth investigation about the Byzantine threats in MRSs, where some robot is untrusted. We design a practical methodology to identify potential Byzantine risks in a given MRS workload built from the Robot Operating System (ROS). It consists of three novel steps (requirement specification using signal temporal logic, attack surface determination via data-flow analysis, attack identification using requirement-driven fuzzing) to thoroughly assess MRS workloads. We use this fuzzing method to inspect five typical MRS workloads from past works and the ROS platform, and identify three novel kinds of attacks that can be launched with five attack strategies. We conduct comprehensive experiments in the Gazebo simulator and a real-world MRS with three TurtlBot3 robots to validate these attacks, which can remarkably decrease the system’s performance, or even cause task failures. Gelei Deng, Yuan Zhou 0005, Yuan Xu 0033, Tianwei Zhang 0004, Yang Liu 0003 |
RAID | 2 |
| 2021 | Guardauto: A Decentralized Runtime Protection System for Autonomous DrivingabstractDue to the broad attack surface and the lack of runtime protection, potential safety and security threats hinder the real-life adoption of autonomous vehicles. Although efforts have been made to mitigate some specific attacks, there are few works on the protection of the autonomous driving system, i.e., the control software system performing such as perception, decision making, and motion tracking. This article presents a decentralized self-protection framework called Guardauto to protect the autonomous driving system against runtime threats. First, Guardauto proposes an isolation model to decouple the autonomous driving system and isolate its components with a set of partitions. Second, Guardauto provides self-protection mechanisms for each target component, which combines different methods to monitor the target execution and plan adaption actions accordingly. Third, Guardauto provides cooperation among local self-protection mechanisms to identify the root-cause component in the case of cascading failures affecting multiple components. A prototype has been implemented and evaluated on the open-source autonomous driving system Autoware. Results show that Guardauto could effectively mitigate runtime failures and attacks, and protect the control system with acceptable performance overhead. Yuan Zhou 0005, Bihuan Chen 0001, Rui Wang 0014, Yuebin Bai, Yang Liu 0003 |
IEEE Trans. Computers | 2 |
| 2020 | Privacy-Aware UAV Flights through Self-Configuring Motion PlanningabstractDuring flights, an unmanned aerial vehicle (UAV) may not be allowed to move across certain areas due to soft constraints such as privacy restrictions. Current methods on self-adaption focus mostly on motion planning such that the trajectory does not trespass predetermined restricted areas. When the environment is cluttered with uncertain obstacles, however, these motion planning algorithms are not flexible enough to find a trajectory that satisfies additional privacy-preserving requirements within a tight time budget during the flights. In this paper, we propose a privacy risk aware motion planning method through the reconfiguration of privacy-sensitive sensors. It minimises environmental impact by re-configuring the sensor during flight, while still guaranteeing the safety and energy hard constraints such as collision avoidance and timeliness. First, we formulate a model for assessing privacy risks of dynamically detected restricted areas. In case the UAV cannot find a feasible solution to satisfy both hard and soft constraints from the current configuration, our decision making method can then produce an optimal reconfiguration of the privacy-sensitive sensor with a more efficient trajectory. We evaluate the proposal through various simulations with different settings in a virtual environment and also validate the approach through real test flights on DJI Matrice 100 UAV. Yixing Luo, Yijun Yu 0001, Zhi Jin 0001, Yao Li 0011, Zuohua Ding, Yuan Zhou 0005, Yang Liu 0003 |
ICRA | 6 |
| 2019 | A Cyclic Scheduling Approach to Single-Arm Cluster Tools With Multiple Wafer Types and Residency Time ConstraintsabstractWith the reduction of wafer batch size on account of the diversification and individuation of consumption demands, increasing importance has been attached to the schedulability and controllability of the cluster tools with multiple wafer types being concurrently processed, while the corresponding research is seldom and still open. This paper is devoted to addressing the steady-state scheduling of single-arm cluster tools with multiple wafer types and residency time constraints. Inspired by the definition of wafer flow pattern for the single wafer type, a novel description for the multiple wafer types is introduced. For the sake of efficiency and simplicity, the multiplex backward sequence is proposed. To balance the workload of process steps, a virtual module technology with a two-tiered architecture is implemented. Furthermore, several sufficient and necessary conditions are derived to verify the schedulability of the system. Finally, an efficient algorithm is presented to find the periodic steady-state schedule, and its practicability and availability are validated by the given illustrative examples.Note to Practitioners—Cluster tools are a kind of highly automated, flexible, and integrated equipment applied widely in diversified semiconductor fabrication processes. Due to the strictness of processing constraints and unavailability of in-built buffers, it is challenging to effectively operate cluster tools. For a higher utilization of processing modules, fabs tend to concurrently process several kinds of wafers with dissimilar recipes in a cluster tool. However, the related scheduling and control problems remain open. With residency time constraints, this paper addresses the scheduling problems of single-arm cluster tools with multiple wafer types. By dissecting the mechanism of mixed-processing of multiple wafer types, several formal conditions are obtained to test the schedulability. Based on the multiplex backward sequence, a cyclic scheduling approach to single-arm cluster tools with multiple wafer types is presented. With the proposed method, schedulability conditions can be readily checked and a periodic schedule can be found easily. Thus, it can be applied to solve practical application problems. Hesuan Hu, Liang Li 0020, Yuan Zhou 0005 |
IEEE Trans Autom. Sci. Eng. | 5 |
| 2019 | A Real-Time and Fully Distributed Approach to Motion Planning for Multirobot SystemsabstractMotion planning is one of the most critical problems in multirobot systems. The basic target is to generate a collision-free trajectory for each robot from its initial position to the target position. In this paper, we study the trajectory planning for the multirobot systems operating in unstructured and changing environments. Each robot is equipped with some sensors of limited sensing ranges. We propose a fully distributed approach to planning trajectories for such systems. It combines the model predictive control (MPC) strategy and the incremental sequential convex programming (iSCP) method. The MPC framework is applied to detect the local running environment real-timely with the concept of receding horizon. For each robot, a nonlinear programming is built in its current prediction horizon. To construct its own optimization problem, a robot first needs to communicate with its neighbors to retrieve their current states. Then, the robot predicts the neighbors' future positions in the current horizon and constructs the problem without waiting for the prediction information from its neighbors. At last, each robot solves its problem independently via the iSCP method such that the robot can move autonomously. The proposed method is polynomial in its computational complexity. Yuan Zhou 0005, Hesuan Hu, Yang Liu 0003, Shangwei Lin 0001, Zuohua Ding |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2018 | Modeling Self-Adaptive Software Systems by Fuzzy Rules and Petri NetsabstractA self-adaptive software system is one that can autonomously modify its behavior at runtime in response to changes in the system and its environment. It is a challenge to model such a kind of systems since it is hard to predict runtime environmental changes at the design phase. In this paper, a formal model called intelligent Petri net (I-PN) is proposed to model a self-adaptive software system. I-PN is formed by incorporating fuzzy rules to a regular Petri net. The proposed net has the following advantages. 1) Since fuzzy rules can express the behavior of a system in an interpretable way and their variables can be reconfigured by the runtime data, the proposed model can model runtime environment and system behavior. 2) Since a fuzzy inference system with well-defined semantics can be used in a complementary way with other model languages for the analysis, thus the proposed model can be analyzed, even though it is described in two different languages: component behaviors in Petri nets while logic control in fuzzy rules. 3) The proposed model has self-adaption ability and can make adaptive decisions at runtime with the help of fuzzy inference reasoning. We adopt a manufacturing system to show the feasibility of the proposed model. Zuohua Ding, Yuan Zhou 0005, MengChu Zhou |
IEEE Trans. Fuzzy Syst. | 2 |
| 2018 | Online Failure Prediction for Railway Transportation Systems Based on Fuzzy Rules and Data AnalysisabstractNowadays, software systems have been more and more complex, which causes great challenges to maintain the availability of the systems. Online failure prediction provides an effective approach to guaranteeing the validity of the systems. Most of the current technologies for online failure prediction require some prior knowledge, such as the model of the system or failure patterns. This paper proposes a new method based on fuzzy rules and time series analysis. Specifically, fuzzy rules are used to model the relationships among different variables, whereas univariate time series analysis is used to describe the evolution of each variable. Thus, for a dependent variable, we have two predicted values: one is from the time series model, and the other is computed from fuzzy rules with fuzzy inference. If the difference between the two values exceeds a threshold, then we declare that there would be a failure in some time period ahead. Different from the existing methods, the proposed method considers not only the evolutionary trend of each variable but also the relationships among different variables. Moreover, we do not need any prior knowledge such as system model or failure patterns. We use a railway transportation system as an example to illustrate our method. Zuohua Ding, Yuan Zhou 0005, Geguang Pu, MengChu Zhou |
IEEE Trans. Reliab. | 2 |
| 2017 | Collision and Deadlock Avoidance in Multirobot Systems: A Distributed ApproachabstractCollision avoidance is a critical problem in motion planning and control of multirobot systems. Moreover, it may induce deadlocks during the procedure to avoid collisions. In this paper, we study the motion control of multirobot systems where each robot has its own predetermined and closed path to execute persistent motion. We propose a real-time and distributed algorithm for both collision and deadlock avoidance by repeatedly stopping and resuming robots. The motion of each robot is first modeled as a labeled transition system, and then controlled by a distributed algorithm to avoid collisions and deadlocks. Each robot can execute the algorithm autonomously and real-timely by checking whether its succeeding state is occupied and whether the one-step move can cause deadlocks. Performance analysis of the proposed algorithm is also conducted. The conclusion is that the algorithm is not only practically operative but also maximally permissive. A set of simulations for a system with four robots are carried out in MATLAB. The results also validate the effectiveness of our algorithm. Yuan Zhou 0005, Hesuan Hu, Yang Liu 0003, Zuohua Ding |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2016 | Online Prediction and Improvement of Reliability for Service Oriented SystemsabstractReliability is an important metric for measuring the quality of software. Many methods have been proposed for online predicting and improving software reliability, but most of them have the following weakness: they are not able to predict software reliability on different time intervals and to locate the faulty components that cause the declining of the reliability either. This paper proposes a new method for online improvement of reliability of service composition. We use monitored failure data at ports of services to predict the reliabilities of service composition on different time intervals. If the predicted reliability is lower than the expected value, then we locate the faulty components that cause the declining of the reliability by using an improved spectrum-fault-localization (SFL) technique. The system can be automatically reconfigured to improve the system reliability by adding a component replica or replacing the faulty component. An Online Shop example is used to demonstrate the effectiveness of our method. Zuohua Ding, Tiantian Ye, Yuan Zhou 0005 |
IEEE Trans. Reliab. | 4 |
| 2016 | Modeling Self-Adaptive Software Systems With Learning Petri NetsabstractTraditional models unable to model adaptive software systems since they deal with fixed requirements only, but cannot handle the behaviors that change at runtime in response to environmental changes. In this paper, an adaptive Petri net (APN) is proposed to model a self-adaptive software system. It is an extension of hybrid Petri nets by embedding a neural network algorithm into them at some special transitions. The proposed net has the following advantages: 1) it can model a runtime environment; 2) the components in the model can collaborate to make adaption decisions while the system is running; and 3) the computation is done at the local component, while the adaption is for the whole system. We illustrate the proposed APN by modeling a manufacturing system. Zuohua Ding, Yuan Zhou 0005, MengChu Zhou |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2015 | A Polynomial Algorithm to Performance Analysis of Concurrent Systems Via Petri Nets and Ordinary Differential EquationsabstractIn this paper, a new method is proposed to evaluate the performance of concurrent systems. A concurrent system consisting of multiple processes that communicate via message passing mechanisms is modeled by a Petri net, which is in turn represented by a set of ordinary differential equations (ODEs) of a restricted type. The equations describe the system state changes, and the solutions, also called state measures, can be used for the performance analysis such as estimating response time, throughput and efficiency. This method can avoid a state explosion problem encountered by the conventional methods based on Continuous-Time Markov Chains. Its application to an IBM business system is given as an example. Zuohua Ding, Yuan Zhou 0005, MengChu Zhou |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2015 | A New Class of Petri Nets for Modeling and Property Verification of Switched Stochastic SystemsabstractSwitched stochastic systems (SSS) can be used to describe hybrid systems with randomness. However, the languages to describe their discrete switching logic and stochastic dynamic processes are different, and this difference makes their design and analysis hard. This paper proposes a new Petri net model, namely stochastic-differential Petri net (S-DPN), to describe both discrete switching logic, represented by a Markov chain, and stochastic dynamic processes, represented by a set of stochastic differential equations. We then apply a model checking technique to S-DPN to check the correctness of the requirements of SSS. A temperature control system is used to demonstrate the effectiveness of our method. Zuohua Ding, Yuan Zhou 0005, Mingyue Jiang, MengChu Zhou |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2014 | Stability Analysis of Switched Fuzzy Systems Via Model CheckingabstractSwitched fuzzy systems can be used to describe the hybrid systems with fuzziness. Their stability issue is the most important one and has received significant attention. Most of the existing methods to study it are based on Lyapunov functions. However, the existence of such functions is difficult to establish. This paper presents a new method to analyze the stability. A switched fuzzy system with a Takagi–Sugeno (T–S) fuzzy model is first transformed to a hybrid automaton (HA) that is linearized. The reachability of this linearized one is then checked by the model checker PHAVer. Finally, the stability is obtained by analyzing the reachability. It is shown that a switched fuzzy system and its corresponding HA have the same behavior and that the linearization does not affect the stability analysis. We demonstrate the effectiveness of our method through a case study on a differential-drive two-wheeled mobile robot. Zuohua Ding, Yuan Zhou 0005, MengChu Zhou |
IEEE Trans. Fuzzy Syst. | 2 |