EDBT 2026 Demo / reviewers in the wild / expert
Hengye Zhu
dblp:12/3988
· DBLP profile ↗
8ranked-venue papers
4as first author
6since 2021 · last 2025
0009-0004-3487-7182ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SSTAF: Security Settings-Based Threat Assessment Framework of Programmable Logic ControllersabstractIndustrial control systems (ICSs) govern the production activities of various critical infrastructures, where programmable logic controllers (PLCs) are essential devices for controlling industrial processes. However, PLCs have many vulnerabilities and might be configured inappropriately. With the trend of PLCs connecting to the Internet, such weaknesses will lead to various cyberattacks and have prompted many studies on the threat assessment for PLCs. Previous research has ignored PLCs’ security settings, such as operating mode and read/write authentication etc., which are the general security functionalities significantly affecting PLCs’ security. In this paper, we make the first attempt to propose a security settings-based threat assessment framework (SSTAF) to assess PLCs’ security.SSTAFconsists ofSScanner, a novel scanner to automatically extract the real-time configurations of security settings from PLCs, and the threat assessment criteria, serving to assess the appropriateness of PLC configurations and analyze risk levels of attacks based on PLCs’ security settings. Subsequently, usingSSTAF, we implement an Internet-wide threat assessment for PLCs exposed to the Internet. We deploySScanneron the Internet and interact with 41K ICS devices in cyberspace to acquire their configurations of security settings. Based on the scanning result and the threat assessment criteria, we reveal that 93.32% of PLCs have not appropriately configured their security settings. Additionally, each PLC might be subject to 4.96 attacks on average, of which 3.32 attacks are due to the inappropriate configurations of security settings. Zhenyong Zhang, Hengye Zhu, Zeyu Yang 0001, Ruilong Deng, Peng Cheng 0001, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Reverse Engineering Industrial Protocols Driven By Control FieldsabstractIndustrial protocols are widely used in Industrial Control Systems (ICSs) to network physical devices, thus playing a crucial role in securing ICSs. However, most commercial industrial protocols are proprietary and owned by their vendors, which impedes the implementation of protections against cyber threats. In this paper, we design REInPro to Reverse Engineer Industrial Protocols. REInPro is inspired by the fact that the structure of industrial protocols can be determined by a particular field referred to control field. By applying a probabilistic model of network traffic behavior, REInPro automatically identifies the control field and groups the associated network traffic into clusters. REInPro then infers critical semantics of industrial protocols by differentiating the features of corresponding protocol fields. We have experimentally implemented and evaluated REInPro using 8 different industrial protocols across 6 Programmable Logic Controllers (PLCs) belonging to 5 original equipment manufacturers. The experimental results show REInPro to reverse-engineer the formats and semantics of industrial protocols with an average correctness/perfection of 0.70/0.58 and 0.96/0.39. Zeyu Yang 0001, Yangyang Geng, Hengye Zhu, Peng Cheng 0001, Jiming Chen 0001 |
INFOCOM | 6 |
| 2024 | Physics-Aware Watermarking Embedded in Unknown Input Observers for False Data Injection Attack Detection in Cyber-Physical MicrogridsabstractThe physics-aware watermarking-based detection method has shown great potential in detecting stealthy False Data Injection Attacks (FDIAs) by adding appropriate watermarks to control commands or sensor measurements, especially in industrial control systems and grid-tied Distributed Energy Resources (DERs). However, existing watermarking-based detection methods have limitations in either handling the intricate physical couplings among DERs or characterising the fast changing power electronics dynamics, and thus cannot be directly applied to microgrids. Inspired by the methodology of Unknown Input Observer (UIO), which can be employed for the distributed anomaly monitoring in cyber-physical microgrids but would be easily bypassed once the adversary has the knowledge of certain electrical parameters, this paper makes the first attempt to investigate the physics-aware watermarking embedded in UIOs such that the stealthy FDIAs would be intentionally disrupted by the watermarking scheme. Based on the theoretical analysis of the detection enhancement and performance degradation under watermarking-enhanced UIOs, the watermark strengths, UIO parameters, and control gains are optimally co-designed to significantly enhance the detection effectiveness while not degrading the control performance. The robustness of the watermarking-enhanced UIO to Time Synchronisation Errors (TSEs) is improved by employing a sliding time window with appropriate length. The performance of the proposed method is validated through Matlab/Simulink studies and cyber-physical co-simulation experiments, and the sensitivities of the detection latency and TSE robustness to watermark strength and detection window’s length are comprehensively studied. Mengxiang Liu, Xin Zhang 0028, Hengye Zhu, Zhenyong Zhang, Ruilong Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | HoneyJudge: A PLC Honeypot Identification Framework Based on Device Memory TestingabstractThe widespread use of programmable logic controllers (PLCs) in critical infrastructures has given rise to escalating cybersecurity concerns regarding PLC attacks. As a proactive defense mechanism, PLC honeypots emulate genuine controllers to engage adversaries so as to observe their attack tactics and techniques. As part of the arms race between the offense and defense, multiple PLC honeypot identification tools have been developed. However, many existing tools cannot recognize high-fidelity honeypots, since they rely on identifying common network services and fingerprints. In this paper, we propose an innovative and practical honeypot identification framework calledHoneyJudge, which goes beyond state-of-the-art (SOTA) network fingerprint-based identification tools like Nmap and the PLCScan tool.HoneyJudgetests the suspected target’s special memory content and features. Specifically,HoneyJudgemodels the internal memory of a PLC in three categories, from system-level, user-level, to process-level categories, based on which it extracts six representative memory features. All characteristics are acquired through automated network request messages. Then, we design a weighted voting algorithm to combine the test results over different memory features to reach the final conclusion. We validate the effectiveness ofHoneyJudgein comparison with several SOTA honeypot identification tools, and the results indicate that the memory-related issues have not been well addressed in existing PLC honeypots and still need substantial research efforts. Hengye Zhu, Mengxiang Liu, Binbin Chen 0001, Peng Cheng 0001, Ruilong Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Detection-Performance Tradeoff for Watermarking in Industrial Control SystemsabstractThe watermarking method, which adds unique watermarks to data, has been widely used for integrity attack detection in industrial control systems (ICSs). Existing literature generally designs watermarking mechanisms without considering the existence of noises, which cannot be trivially applied to realistic ICS scenarios in the presence of strong noise interference. On one hand, the low-intensity watermarking will be ineffective under the strong noise environment; while on the other hand, the oversized watermarking can possibly degrade the control performance or even destabilize the system. Therefore, the intensity of watermarks plays a fundamental role in balancing the tradeoff between detection effectiveness and control performance, which, to the best of our knowledge, has never been thoroughly analyzed yet. To this end, in this paper, we for the first time propose an optimal watermarking design method for ICSs considering the detection-performance tradeoff. To begin with, we shift the watermark container from data points to segments and update the detection metrics to reduce the noise impact. Then, we formulate an optimization problem to determine the strength of watermarks to balance the detection-performance tradeoff. Meanwhile, the detection effectiveness and control performance metrics are analytically modeled and theoretically analyzed considering the discrepancy between added watermarks and noises, signal quality, detection latency, as well as estimation of detection metrics. Finally, extensive numerical simulations and systematical experiments based on a practical Ethanol Distillation ICS are conducted to validate the theoretical analysis and demonstrate the outperformance of our proposed watermarking method in comparison with related works. Hengye Zhu, Mengxiang Liu, Chongrong Fang, Ruilong Deng, Peng Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Toward a Trust Evaluation Framework Against Malicious Behaviors of Industrial IoTabstractWith the development of the Industrial Internet of Things (IIoT) technology, edge computing is a promising area to release the sensing and computing burdens from the overloaded center. However, in edge network scenarios, we cannot trust every node’s output since some nodes can behave maliciously by making use of the properties, such as multiple identities, heterogeneous capabilities, and mobility. In that case, trust management is widely used to solve the problem of network trustworthiness. In this article, we propose a trust evaluation framework by comprehensively considering the nodes’ malicious behaviors and heterogeneous characteristics of edge networks. Under the Bayesian framework, we use the semi-ring theory to dynamically establish mobile-edge nodes’ trust models. First, we calculate the trust value for each node with a different identity (service provider or requester). Then, we propose a security-regarded task allocation mechanism to improve the reliability of selected trusted nodes according to the matched relationship between the service requesters’ expected capability and the providers’ actual capability. Further, we conduct extensive analysis and simulations to evaluate the proposed methods in typical IIoT scenarios. The results show that the proposed method has better immunity to abnormal behaviors, including the noncooperation, malicious feedback, on–off attacks, Sybil attacks, whitewashing attack, malicious access, etc., and has higher scheduling accuracy and controllable time complexity compared to existing methods. Mufeng Wang, Zhenyong Zhang, Hengye Zhu |
IEEE Internet Things J. | 4 |
| 2008 | Visualizing HLA-Based Collaborative Simulation System Modeling with a UML Profile
Hengye Zhu |
CDVE | 1 |
| 2007 | WSHLA: Web Services-Based HLA Collaborative Simulation Framework
Hengye Zhu, Lulai Yuan |
CDVE | 1 |