EDBT 2026 Demo / reviewers in the wild / expert
Chengcheng Zhao
dblp:175/9537
· DBLP profile ↗
25ranked-venue papers
4as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 2 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MoiréEar: Moiré Can See What You Cannot HearabstractEavesdropping poses a critical threat to the confidentiality and integrity of voice communications. In recent years, techniques have advanced beyond traditional microphone-based methods toward more intelligent approaches, such as leveraging millimeter-wave sensing to detect the subtle vibrations induced by speakers and reconstruct voice information without direct audio capture. Despite their technical feasibility, these methods remain constrained by limited working ranges—typically only several meters—rendering them impractical for real-world stealthy eavesdropping. In this work, we propose MoiréEar, the first long-range passive eavesdropping system based on moiré patterns. The key idea is to exploit the amplification capability of moiré patterns, which amplify the minute vibrations induced by acoustic signals by hundreds of times, enabling long-range eavesdropping. To make the proposed method even more practical and stealthy, we develop new theoretical foundations that relax the strict requirements for generating moiré patterns. Specifically, our approach enables the use of irregular stripe structures (e.g., commonly seen barcodes) instead of standard moiré gratings to generate moiré patterns. We implement our design using a low-cost photodiode instead of cameras, achieving real-time eavesdropping with lightweight signal processing. Comprehensive experiments show that the system can extract intelligible audio at a distance of up to 90 m, outperforming the state of the art by an order of magnitude in range. We believe this new eavesdropping modality can inspire a wide range of IoT applications. Hongqiang Zhang, Lupeng Zhang, Chengcheng Zhao, Yuanchao Shu, Peng Cheng 0001, Jiming Chen 0001, Jie Xiong 0001 |
SenSys | 3 |
| 2026 | mmProjector: Low-Cost mmWave Reflector for Mobile Industrial Robot CommunicationabstractMillimeter-wave (mmWave) technology offers significant potential for high-bandwidth, low-latency communication industrial applications. However, mmWave faces several challenges, such as limited range, susceptibility to blockage, and slow beam alignment. For this, mmWave access points (APs) are often deployed at high densities, which leads to increased costs. In this paper, we introduce mmProjector, the first cost-effective reflector, which is non-reconfigurable with a static structure but can serve mobile industrial robots. The key idea is to reshape the reflected waves only along the robots’ movement trajectories using mmProjector and make the phase of reflected wave constructively added along the trajectories, improving reflection gain with limited incident waves. To achieve this, we develop an analytical model grounded in electromagnetic theory and propose sub-optimal algorithms for the deployment and shape design of reflectors. We prototype mmProjector and deploy it in a real-world airplane assembly factory. Experiments demonstrate that mmProjector operates effectively at 60 GHz, delivering up to 1.8 Gbps of bandwidth in non-line-of-sight (NLOS) scenarios, while achieving up to 75% reduction in costs. Hongqiang Zhang, Chengcheng Zhao, Yuanchao Shu, Peng Cheng 0001 |
IEEE Internet Things J. | 2 |
| 2026 | PolarFix: Fixing Polarization Mismatch for UAV mmWave Communication EnhancementabstractMillimeter-wave (mmWave) communication offers a promising solution for high-throughput, low-latency unmanned aerial vehicle (UAV) networks. However, maintaining strong received signal strength (RSS) remains a challenge due to UAV mobility. While existing studies have largely focused on beam alignment, they often overlook another critical issue: polarization mismatch caused by UAV orientation changes. This problem is particularly severe in cost-sensitive commercial off-the-shelf (COTS) mmWave devices, which typically employ linearly polarized (LP) antenna arrays. Our measurements reveal that even with perfect beam alignment, UAV orientation can still cause significant signal degradation due to polarization mismatch. To address this challenge, we propose PolarFix, a practical metasurface solution that enables real-time polarization matching without requiring any modifications to existing transceiver hardware. Specifically, we design a linear-to-circular polarization (L2C) metasurface that transforms linearly polarized (LP) waves into circularly polarized signals, allowing LP antennas to maintain consistent signal power despite changes in UAV orientation. Hongqiang Zhang, Chengcheng Zhao, Yuanchao Shu, Jie Xiong 0001, Peng Cheng 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Dynamic Adaptive Deployment of Network Slice for Industrial Internet of ThingsabstractWith the advancement and maturation of 5G technology, its network slicing capabilities play a crucial role in delivering high-quality network services for industrial Internet of Things (IoT). However, effectively applying 5G network slicing to meet continuously changing network demands remains a challenging endeavor. We propose a heuristic-based dynamic adaptive network slicing deployment algorithm aimed at addressing both resource utilization efficiency and dynamics of network service requests during deployment. We first establish a system model for the network slicing deployment process, framing the deployment issue as a nonlinear integer programming problem. Subsequently, we introduce a two-stage deployment algorithm designed to accommodate the variability of network requests. Finally, we conduct numerical simulations and experiments to assess the algorithm based on criteria such as average deployment cost, number of Virtual Network Functions, and service acceptance rate. Results demonstrate that the proposed algorithm effectively manages resource utilization efficiency and dynamic issues of network service requests. Hongqiang Zhang, Chengcheng Zhao |
ICC | 3 |
| 2025 | A Logic-Based Approach to Causal Discovery: Signal Temporal Logic PerspectiveabstractCausal discovery in time-series datasets is critical for understanding complex systems, especially when the \textit{effectiveness} of causal relationships depends on both the \textit{duration} and \textit{magnitude} of the cause. We introduce a novel framework for causal discovery based on \textbf{Signal Temporal Logic (STL)}, enabling the extraction of interpretable causal diagrams (STL-CD) that explicitly capture these temporal dynamics. Our method first identifies statistically meaningful time intervals, then infers STL formulas that classify system behaviors, and finally employs transfer entropy to determine direct causal relationships among the formulas. This approach not only uncovers causal structure but also identifies the temporal persistence required for causal influence—an insight missed by existing methods. Experimental results on synthetic and real-world datasets demonstrate that our method achieves superior structural accuracy over state-of-the-art baselines, providing more informative and temporally precise causal models. Nasim Baharisangari, Yucheng Ruan, Chengcheng Zhao, Zhe Xu 0005 |
IJCAI | 3 |
| 2025 | mmFlower: A Low-Cost mmWave Tracking System for Industrial Robot via Mechanically Reconfigurable ReflectorabstractMillimeter-wave (mmWave) communication has great potential for high rates and low latency but suffers from severe non-line-of-sight (NLOS) blockage and high cost of beam alignment. These problems exacerbate for mobile industrial robots. Most existing methods use reconfigurable intelligent surface (RIS) to change the channel environment, whose practical applications are hindered by high cost. This paper introduces low-cost mmFlower, consisting of an array of 3D-printing reflector units whose orientation can be adjusted mechanically. We first construct a theoretical reflection model, bridging the mechanical parameters and communication metrics. mmFlower works in two modes according to whether it needs real-time reconfiguration. On the one hand, based on our uniform-RSS (received signal strength) projection algorithm, mmFlower remains static and reshapes mmWave into arbitrary projection trajectory along the robot movement. It maximizes mmWave allocation to the more frequently visited areas and realizes seamless mmWave coverage. On the other hand, mmFlower can dynamically track mmWave pencil beams on robots, providing higher reflection gain. Extensive evaluations in an airplane assembly factory show the superiority of mmFlower on reflection gain (supporting up to 1.8 Gbps in NLOS), flexibility to different trajectories of robots, robustness to deployment deviation, etc. Hongqiang Zhang, Chengcheng Zhao, Yuanchao Shu, Peng Cheng 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Submodularity-Based False Data Injection Attack Strategy in DC MicrogridsabstractDespite significantly enhancing system flexibility and reliability, the adoption of distributed secondary control in DC microgrids (DCmGs) introduces new vulnerabilities to false data injection (FDI) attacks. As a typical FDI attack, the zero trace stealthy (ZTS) attack has been recently disclosed for DCmGs, which can deteriorate the control objective while keeping stealthy to unknown input observer (UIO)-based detectors. In this work, we investigate the optimal deployment of ZTS attacks, where the adversary with limited resources aims to compromise a set of communication links such that the system state convergence error can be maximized. Specifically, we formulate the optimal ZTS attack deployment problem as a combinatorial optimization problem and unveil its NP-hard characteristic. Then, we discover the submodularity in the state convergence error function, enabling us to transform the original NP-hard problem into a tractable submodular maximization problem. Furthermore, based on the submodular optimization theory, we propose a novel distributed algorithm for the optimal ZTS attack deployment in DCmGs, which effectively balances the attack benefits and computation cost. Finally, comparisons between the centralized and distributed algorithms are illustrated through extensive simulations. Chengcheng Zhao, Mengxiang Liu, Ruilong Deng, Peng Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Verifying PLC Control Logic for Physical Module Integrity Guided by Wiring DiagramsabstractPhysical modules are the basic functional units of industrial control systems, governed by Programmable Logic Controllers (PLCs) according to predefined control logic. Attackers can compromise the integrity of physical modules by tampering with control logic, potentially disrupting production or causing physical damage. While model checking can detect logic bugs that violate module integrity requirements, it depends heavily on domain-specific knowledge, which is traditionally summarized by human experts, limiting both scalability and completeness. This paper proposes DGVerifier, a wiring diagram-guided framework that automatically verifies two general integrity requirements of physical modules: action integrity and state transition integrity. DGVerifier can extract module-related information from PLC wiring diagrams, mine domain-specific knowledge to generate specifications, and also model PLC programs as automata for verification. Evaluation on two real-world systems — an Elevator Control System and an Automated Assembly Line Control System — shows DGVerifier can recover 89.3% (25/28) of the required specifications and identify four hidden logic bugs violating physical module integrity. Chengtao Yao, Chengcheng Zhao, Zeyu Yang 0001, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | PicaCAN: Reverse Engineering Physical Semantics of Signals in CAN Messages Using Physically-Induced CausalitiesabstractWith the rapid development of Connected and Autonomous Vehicles, In-Vehicle Network attacks have garnered heightened research scrutiny due to vehicles’ increasing connectivities to the external environment. The common characteristic among these attacks is to tamper with targeted powertrain-related signals in the Powertrain Controller Area Network (PT-CAN) and further physically threaten vehicles’ safety. These powertrain-related signals are encoded within CAN messages grounded by the syntax specification, which is proprietary to Original Equipment Manufacturers and publicly unavailable. Thus, to undertake comprehensive security analysis and strategies, reverse engineering PT-CAN to the semantic level is urgently needed. However, the existing methods rely on interactions (injecting challenge signals/actions) with the targeted vehicle, and certain manual efforts are required. To fill this gap, we proposePicaCAN, a novel framework to extract signals from CAN messages and reverse engineer their physical semantics based on physically induced causality. Once access to the CAN traffic,PicaCANoffers the researcher an eye on the vehicle’s powertrain system, decoding binaries flows into powertrain-related signals automatically. We experimentally evaluatePicaCANon PT-CAN of three automobiles containing two power types. The experimental results show thatPicaCANcould successfully extract physical signals representing all targeted semantics (pedals, engine speed, etc.) from two Internal Combustion Engine Vehicles and one Hybrid Electric Vehicle under EV mode. Yucheng Ruan, Chengcheng Zhao, Zeyu Yang 0001, Yuanchao Shu, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Differentially Private No-regret Exploration in Adversarial Markov Decision ProcessesabstractWe study learning adversarial Markov decision process (MDP) in the episodic setting under the constraint of differential privacy (DP). This is motivated by the widespread applications of reinforcement learning (RL) in non-stationary and even adversarial scenarios, where protecting users’ sensitive information is vital. We first propose two efficient frameworks for adversarial MDPs, spanning full-information and bandit settings. Within each framework, we consider both Joint DP (JDP), where a central agent is trusted to protect the sensitive data, and Local DP (LDP), where the information is protected directly on the user side. Then, we design novel privacy mechanisms to privatize the stochastic transition and adversarial losses. By instantiating such privacy mechanisms to satisfy JDP and LDP requirements, we obtain near-optimal regret guarantees for both frameworks. To our knowledge, these are the first algorithms to tackle the challenge of private learning in adversarial MDPs. Shaojie Bai, Lanting Zeng, Chengcheng Zhao, Xiaoming Duan, Mohammad Sadegh Talebi, Peng Cheng 0001, Jiming Chen 0001 |
UAI | 3 |
| 2024 | Towards resilient average consensus in multi-agent systems: a detection and compensation approachabstractConsensus is one of the fundamental distributed control technologies for collaboration in multi-agent systems such as collaborative handling in intelligent manufacturing. In this paper, we study the problem of resilient average consensus for multi-agent systems with misbehaving nodes. To protect consensus value from being influenced by misbehaving nodes, we address this problem by detecting misbehaviors, mitigating the corresponding adverse impact, and achieving the resilient average consensus. General types of misbehaviors are considered, including attacks, accidental faults, and link failures. We characterize the adverse impact of misbehaving nodes in a distributed manner via two-hop communication information and develop a deterministic detection compensation based consensus (D-DCC) algorithm with a decaying fault-tolerant error bound. Considering scenarios wherein information sets are intermittently available due to link failures, a stochastic extension named stochastic detection compensation based consensus (S-DCC) algorithm is proposed. We prove that D-DCC and S-DCC allow nodes to asymptotically achieve resilient accurate average consensus and unbiased resilient average consensus in a statistical sense, respectively. Then, the Wasserstein distance is introduced to analyze the accuracy of S-DCC. Finally, extensive simulations are conducted to verify the effectiveness of the proposed algorithms. Chongrong Fang, Wenzhe Zheng, Zhiyu He 0002, Jianping He 0001, Chengcheng Zhao |
Frontiers Inf. Technol. Electron. Eng. | 5 |
| 2024 | Plug-and-Play Distributed Estimation of Driving States in an Open Vehicle PlatoonabstractThe information regarding the driving states of all vehicles is crucial for achieving optimal group performance in a vehicle platoon. This article focuses on the fully distributed driving state estimation problem in open vehicle platoons, which frequently experience arrivals and departures of vehicles. To address this problem, we propose a distributed driving state observer inspired by the leader–follower consensus technique. This observer can reconstruct the global driving state of the platoon, including the positions, velocities, and accelerations of all vehicles. We also derive the necessary and sufficient conditions to ensure the stability of its estimation error dynamics. The proposed observer is highly flexible in platoons with a strongly connected communication network, as it can be constructed and operated using the local knowledge of each vehicle only, without relying on global information of a platoon such as the number of vehicles. We demonstrate the observer's plug-and-play operations in the face of platoon merging and splitting and analyze its estimation stability. Extensive simulation results demonstrate the effectiveness of our theoretical results and the potential of the proposed observer for platoon control. Shuaiting Huang, Chengcheng Zhao, Lingying Huang, Peng Cheng 0001, Junfeng Wu 0001, Lin Cai 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Safeguard Vehicle Platooning Based on Resilient Control Against False Data Injection AttacksabstractThis paper investigates secure control for homogeneous vehicle platoons in the presence of false data injection attacks with low communication and computation costs. We consider a scenario where each vehicle within the platoon transmits a local state vector to multiple neighboring vehicles. By leveraging these shared vectors from both preceding and following vehicles, we propose a novel and effective resilient controller for vehicle platoons against node/communication link attacks. More specifically, each vehicle determines the local state deviation vectors from neighboring vehicles. It then eliminates the vectors that are farthest from the origin, with the number of removed vectors equivalent to the maximum number of attacks. This approach offers a considerable advantage by mitigating the effects of abnormality and manipulation, making it robust against arbitrary information tampering within a pre-defined upper boundary for manipulated broadcast information. Importantly, we establish specific conditions for the proposed resilient design to guarantee the internal stability of the vehicle platoon under attacks. Extensive simulations and experiments involving four TurtleBot3s are conducted to demonstrate the effectiveness of the proposed resilient controller. Chengcheng Zhao, Ruijie Ma 0001, Mengzhi Wang, Jinming Xu 0002, Lin Cai 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | LFVeri: Network Configuration Verification for Virtual Private Cloud NetworksabstractThe Virtual Private Cloud (VPC) service enables users to configure shared resources within public clouds on demand, providing isolation between users. However, configuring the VPC network is a complex and error-prone task, and misconfiguration has been the leading cause of cloud network security issues. The large number of complex network components and configurations makes it difficult to perform scalable, efficient, and accurate fault verification of the network behavior. To address this issue, we design a comprehensive and automated fault diagnosis and localization tool, calledLFVeri, which is built upon an innovative modular network model that accurately captures the logic functions of real components within VPC networks, and propose eleven functions to verify network reachability and security requirements. We conduct performance testing ofLFVerion various datasets and compared it with other verification tools. The experiments show thatLFVerioutperforms in modeling and analyzing real VPC scenarios while also possessing the fastest verification speed. It can model and analyze large VPC networks with tens of thousands of components and millions of configuration rules in less than half an hour. Kun Wang 0023, Chengcheng Zhao, Jinpei Chu, Yiping Shi, Jianyuan Lu, Biao Lyu, Shunmin Zhu, Peng Cheng 0001, Jiming Chen 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | SemSBA: Semantic-perturbed Stealthy Backdoor Attack on Federated Semi-supervised LearningabstractFederated semi-supervised learning (FSSL) has been perceived as a promising approach that leverages semi-supervised learning and federated learning (FL) to provide powerful privacy preservation while reducing the burden on human supervision. However, due to the lack of strict participant identification and the significant proportion of unlabeled samples, FSSL is more susceptible to covert backdoor attacks than traditional machine learning. To validate this speculation, a novel semantic-perturbed stealthy backdoor attack (SemSBA) scheme is proposed for FSSL-based systems. In SemSBA, we select original natural semantic features in the unlabeled training samples as backdoor triggers and then generate poisoned samples by adding adversarial perturbations that move them across the model decision boundary. With SemSBA, the adversary can trigger the hidden backdoor in the victim model during the inference stage without any deliberate modifications on testing samples. To further improve the strength and robustness of the attack, a pseudo label steering enhancement strategy is also designed to perturb the weakly-augmented version of unlabeled samples to induce target pseudo label allocations. Additionally, to improve the attack success rate, we amplify the weight of the local backdoored model during FSSL’s model aggregation process to manipulate the game between benign clients and malicious clients. Extensive experiments based on two benchmark datasets demonstrate that the proposed SemSBA scheme can achieve comparable stealthiness against existing attacks. Yingrui Tong, Jun Feng 0007, Gaolei Li, Xi Lin 0003, Chengcheng Zhao, Xiaoyu Yi 0003, Jianhua Li 0001 |
ICPADS | 5 |
| 2023 | Periodic Event-Triggered Robust Distributed Model Predictive Control for Multiagent Systems With Input and Communication DelaysabstractThis article investigates the problem of event-triggered distributed model predictive control (DMPC) for continuous-time nonlinear multiagent systems (MASs) subject to bounded disturbances, input and communication delays simultaneously. The compensation schemes for input and communication delays are proposed, respectively. A new optimal control problem (OCP) to achieve consensus among all agents is formulated under the proposed delay compensation schemes. To alleviate the communication burden and sensing cost, a novel input delay-related periodic event-triggering condition is proposed based on the state error to determine when to calculate the new control input. Sufficient condition guaranteeing the feasibility of the OCP is achieved with the proposed event-triggered control scheme. In stability analysis, a novel time-varying Lyapunov function is constructed, and the input-to-state practical stability of the MASs is derived by using the quasi-Lipschitz continuous property of the Lyapunov function. Numerical results related to vehicle platooning demonstrate the effectiveness of the proposed event-triggered DMPC. Mengzhi Wang, Chengcheng Zhao, Jinhui Xia, Jian Sun 0003 |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Neural Network Based Adaptive Robust Control of a Single-Axis Hydraulic Shaking TableabstractThe shaking table has been used extensively in the structure test field to verify the structure’s performance against various vibrations, e.g., earthquakes. In order to replicate the vibrations, which are measured by the acceleration signal specifically, the model of the shaking table should be thoroughly constructed to design the controller. However, parametric uncertainty and strong nonlinearity, such as the nonlinear friction, make it an obstacle to obtaining an accurate model. A neural network-based controller is designed in this paper to address this issue, and the nonlinear systems are estimated by the neural network’s universal approximation characteristics. Furthermore, a robust sliding mode controller is utilized to compensate for the residual error of the neural network and other uncertainties. The semi-global asymptotic stability of the controller is proved by Lyapunov analysis. Comparative experimental results indicate the superiority of the proposed controller. Jiabao Wen, Chengcheng Zhao, Zhiguo Shi 0001 |
IECON | 2 |
| 2022 | Reverse Engineering Physical Semantics of PLC Program Variables Using Control InvariantsabstractSemantic attacks have incurred increasing threats to Industrial Control Systems (ICSs), which manipulate targeted system modules by identifying the physical semantics of variables in Programmable Logic Controllers (PLCs) programs, i.e., the sensing/actuating modules represented by the variables. This is usually (and inefficiently) achieved via manual examination of system documents and long-term observation of system behavior. In this paper, we design ARES, a method that Automatically Reverse Engineers the Semantics of variables in PLC programs without requiring any domain knowledge. ARES is built on the fact that the Supervisory Control And Data Acquisition (SCADA) system monitors the behavior of PLC using a fixed mapping between the variables of program code and data log, and the data log variables are marked with physical semantics. By identifying the mapping between PLC code and SCADA data (i.e., the code-data mapping), ARES reverse engineers the physical semantics of program variables. ARES also sheds light on the preferred practices in implementing control rules that improve the resistance of PLC programs to semantic attacks. We have experimentally evaluated ARES and the recommended implementation practices on two ICS platforms. Zeyu Yang 0001, Liang He 0002, Chengcheng Zhao, Peng Cheng 0001, Jiming Chen 0001 |
SenSys | 4 |
| 2022 | Detecting PLC Intrusions Using Control InvariantsabstractProgrammable logic controllers (PLCs), i.e., the core of control systems, are well-known to be vulnerable to a variety of cyber attacks. To mitigate this issue, we designPLC-Sleuth, a novel noninvasive intrusion detection/localization system for PLCs, which is built on a set of control invariants—i.e., the correlations between sensor readings and the concomitantly triggered PLC commands—that exist pervasively in all control systems. Specifically, taking the system’s supervisory control and data acquisition log as input,PLC-Sleuthabstracts/identifies the system’s control invariants as a control graph using data-driven structure learning, and then monitors the weights of graph edges to detect anomalies thereof, which is in turn, a sign of intrusion. We have implemented and evaluatedPLC-Sleuthusing both a platform of ethanol distillation system (EDS) and a realistically simulated Tennessee Eastman (TE) process. The results show thatPLC-Sleuthcan: 1) identify control invariants with 100%/98.11% accuracy for EDS/TE; 2) detect PLC intrusions with 98.33%/0.85 ‰ true/false positives (TPs/FPs) for EDS and 100%/0% TP/FP for TE; and 3) localize intrusions with 93.22%/96.76% accuracy for EDS/TE. Zeyu Yang 0001, Liang He 0002, Chengcheng Zhao, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Fingerprinting Movements of Industrial Robots for Replay Attack DetectionabstractIndustrial robots are prototypical cyber-physical systems widely deployed in (smart) manufacturing, which operate according to the operation code uploaded by the human operator and are monitored in real-time based on their movement data. However, industrial robots suffer from replay attacks, via which attackers can manipulate the robot operation without being observed by the monitoring system. To mitigate this vulnerability, we design a novel intrusion detection system for industrial robots using their power fingerprint, calledPIDS(Power-basedIntrusionDetectionSystem), and deliverPIDSas abump-in-the-wiremodule installed at the powerline of commodity robots. The foundation ofPIDSis the physically-induced dependency between the robot movement and the concomitant power consumption, whichPIDScaptures via joint physical analysis and (cyber) data-driven modeling.PIDSthen fingerprints the robot movements observed by the monitoring system using their expected power consumption, and cross-validates the fingerprints with empirically collected power information — a mismatch thereof flags anomalies of the observed movements (i.e., evidence of replay attack). We have evaluatedPIDSusing three models of robots from different vendors — i.e., ABB IRB120, KUKA KR6 R700, and Universal Robots UR5 robots — with over 2,000 operation cycles. Experimental results show thatPIDSdetects replay attacks at an average rate of 96.5 percent (up to 99.9 percent) and a 0.1s latency. Hongyi Pu, Liang He 0002, Chengcheng Zhao, David K. Y. Yau, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Stability Analysis of Vehicle Platooning With Limited Communication Range and Random Packet LossesabstractControl performance of vehicle platooning relies on the information flow topology and quality of wireless communications. In this article, we investigate the constant-time-headway-spacing-policy-based vehicle platooning problem, where multiple predecessors' information is used by the following vehicles and communication impairments, i.e., limited communication range and random packet losses, are considered. In this article, first, when the leading vehicle moves at a constant speed, we obtain the sufficient and necessary conditions on sampling time, control gains, and internal lag, to ensure the stability of the vehicle platoon based on matrix polynomials' stability for ideal communications. Second, for time-independent homogeneous random packet losses, we provide the upper bound for the loss rate to maintain convergence in expectation by matrix eigenvalue perturbation theory when no input is set for lossy information. We also provide sufficient conditions to guarantee mean-square convergence for heterogeneous time-independent random packet losses and show the convergence time for any given accuracy and probability. Third, when historically latest information is used for input, the sufficient and necessary conditions are provided to ensure the internal stability and string stability by Markov jump linear system theory. Furthermore, we discuss the controller design when no feasible solution exists to guarantee the string stability. Extensive numerical results validate our analysis. Chengcheng Zhao, Lin Cai 0001, Peng Cheng 0001 |
IEEE Internet Things J. | 1 |
| 2020 | Detecting replay attacks against industrial robots via power fingerprintingabstractIndustrial robots have been shown to suffer from replay attacks, via which adversaries not only manipulate the robot operation by downloading malicious code, but also prevent the detection of this manipulation by replaying recorded (and normal) movement data to the monitoring system. To protect industrial robots from replay attacks, we design a novel intrusion detection system using the power fingerprint of robots, called PIDS (Power-based Intrusion Detection System), and deliver PIDS as a bump-in-the-wire module installed at the powerline of commodity robots. The foundation of PIDS is the physically-induced dependency between the robot movement and the concomitant electrical power consumption, which PIDS captures via joint physical analysis and (cyber) data-driven modeling. PIDS then fingerprints the robot movements observed by the monitoring system using their expected power consumption, and cross-validates the fingerprints with empirically collected power information --- a mismatch thereof flags anomalies of the observed movements (i.e., evidence of replay attack). We have evaluated PIDS using three models of robots from different vendors --- i.e., ABB IRB120, KUKA KR6 R700, and Universal Robots UR5 robots --- with over 2, 000 operation cycles. The experimental results show that PIDS detects replay attacks with an average rate of 96.5% (up to 99.9%) and a 0.1s latency. Hongyi Pu, Liang He 0002, Chengcheng Zhao, David K. Y. Yau, Peng Cheng 0001, Jiming Chen 0001 |
SenSys | 3 |
| 2020 | Directed Percolation Routing for Ultra-Reliable and Low-Latency Services in Low Earth Orbit (LEO) Satellite NetworksabstractWith tens of thousands Low Earth Orbit (LEO) satellites covering Earth, LEO satellite networks can provide coverage and services that are otherwise not possible using terrestrial communication systems. The regular and dense LEO satellite constellation also provides new opportunities and challenges for network architecture and protocol design. In this paper, we propose a new routing strategy named Directed Percolation Routing (DPR), aiming to provide Ultra-Reliable and Low-Latency Communication (URLLC) services over long distances. Given the long propagation delay and uncertainty of LEO communication links, using DPR, each satellite routes a packet over several Inter-Satellite-Links (ISLs) towards the destination, without relying on link-layer retransmissions. Considering the link redundancy overhead and delay/reliability tradeoff, DPR can control the size of percolation. Using the Starlink as an example, we demonstrate that with the proposed DPR, the inter-continent propagation delay can be reduced by about 4 to 21 ms, while the reliability can be several orders higher than single-path optimal routing. Lin Cai 0001, Chengcheng Zhao, Jianping Pan 0001 |
VTC Fall | 3 |
| 2020 | Analysis of Consensus-Based Economic Dispatch Algorithm Under Time DelaysabstractUnder consensus-based economic dispatch (ED) algorithm, multiple agents, which control local generation units, cooperatively minimize the total generation cost subject to the balance of the generation and expected demand in smart grids. As ubiquitous time delays on communication links exist in communication networks, studying the effect of delays on the dispatch performance is of both theoretical merit and practical value for the efficient and stable operation of smart grids. In this paper, we consider a well-developed consensus-based ED protocol under constant time delays. We find that there always exists a sufficiently small learning gain parameter under finite constant delays such that the convergence of the consensus-based algorithm is guaranteed. Further, an analytical expression of the upper bound is established for the learning gain parameter, which is determined by the largest delay, the weight matrix and the parameters of generation cost functions. In order to guarantee the optimality of the final solution, we propose the updating rule for iterations when initial states are not received by their neighbors due to time delays. The optimality of the final solution under the proposed updating rule is analyzed. We validate our theoretical results through extensive simulation studies. Chengcheng Zhao, Xiaoming Duan, Yang Shi 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2018 | MapReduce Enabling Content Analysis Architecture for Information-Centric Networks Using CNNabstractInformation Centric Network (ICN) is one of the promising architectures in the next generation networks. The content-based routing in ICN can satisfy the content distribution of large-scale data. For prompt content obtainment, it is important to realize the content analysis before the content reaches application layer. The novel characteristics of data naming in ICN make it possible to search and analyse content during the transmission of content, which can directly get the critical content without the process of the application layer. In this paper, we propose a MapReduce enabling content analysis architecture for ICN. MapReduce framework can realize the parallelization of content collection and analysis during the routing process. For more efficient content collection, we put forward an optimal selection for mapper nodes. Moreover, Convolutional Neural Network (CNN) is deployed in the MapReduce architecture providing further analysis for ICN content. The simulation result shows the advantages of the proposed architecture. Chengcheng Zhao, Mianxiong Dong, Kaoru Ota, Jun Wu 0001, Jianhua Li 0001, Gaolei Li |
ICC | 1 |