EDBT 2026 Demo / reviewers in the wild / expert
Zeyu Yang 0001
dblp:196/8203-1
· DBLP profile ↗
14ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0002-1596-6890ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 8 since 2021Computer networks · 5 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AIAF: An Automated ICP-Based Attack Framework for Industrial Control SystemsabstractRecently reported attacks against Programmable Logic Controllers (PLCs) have shown that the exploitation of Industrial Control Protocols (ICPs), i.e., ICP-based attacks, poses significant threats to industrial control systems. ICP-based attacks include two essential steps: generating tailored attack payloads and breaking through the session-ID-based PLC defenses. Traditional approaches to performing the two steps rely on laborious manual analysis. To analyze the threats posed by ICP-based attacks to commercial-off-the-shelf PLCs, we propose AIAF, an Automated ICP-based Attack Framework leveraging proprietary binary protocols, which operates automatically through an offline construction of effective attack payloads and an online ICP-based attack test. We have evaluated AIAF with 9 mainstream PLCs, covering 9 protocols, showing that AIAF can reverse engineer 12 kinds of session-ID negotiation (6 value-changed and 6 value-same), generate attack payloads, and execute 35 ICP-based attacks with a 94.29% success rate. Our further Internet-wide evaluation reveals that over 28K PLCs exposed to the Internet are vulnerable to ICP-based attacks. Zeyu Yang 0001, Ruilong Deng, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001 |
IEEE Internet Things J. | 2 |
| 2026 | An Automated Semantic Analysis Framework for Controller Variables Based on Network TrafficabstractProgrammable logic controllers (PLCs) play a crucial role in various industrial manufacturing processes. Recent attack events show that attackers have a strong interest in controller variables of PLCs, including the device status and internal program logic. Detecting anomalous messages targeting PLC controller variables, which relies on the analysis of controller variable semantics, has proven to be an effective method for identifying such attacks. However, the proprietary nature of industrial control protocols (ICPs) poses a challenge to extracting the required semantics. In this paper, we propose an automated framework namedSePannerto extract the semantics of controller variables from proprietary ICPs based on network traffic. Specifically, we first collect multiple groups of interaction traffic of PLCs and perform the starting-aligned comparisons on them to locate the semantic fields directly. Then, we identify and investigate a new problem in semantic extraction — interference resulting from misordered messages — and propose a set of filtering criteria to eliminate it effectively. We evaluate SePanner using the S7COMM protocol, and the results indicate that SePanner can successfully extract the semantics of controller variables with 100% accuracy. Additionally, we employ SePanner to analyze 7 proprietary ICPs, successfully extracting the semantics of 63 controller variables and their 134 states. Additionally, we demonstrate the extensive applications of SePanner in multiple ICS security scenarios and present its better performance compared with existing ICP semantic analyzing tools. Zeyu Yang 0001, Zhenyong Zhang, Yangyang Geng, Ruilong Deng, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Mismatched Control and Monitoring Frequencies: Vulnerability, Attack, and MitigationabstractStealthy attacks manipulate the operation of Industrial Control Systems (ICSs) without being undetected, allowing persistent manipulation of system operation and thus the potential to cause destructive damage. This paper introduces a new vulnerability of ICS that can be exploited to mount stealthy attacks without requiring any domain knowledge. This vulnerability is caused by a common practice in system monitoring, i.e., the SCADA monitors ICS operation at a much lower frequency than system execution, causing a loss of precision when the SCADA tries to cross-validate the issued control commands using the collected sensory data. Exploiting this vulnerability, an attack calledPLC-SAGEis designed to stealthily manipulate the system operation by identifying and injecting malicious control commands that will not be concluded as abnormal by the SCADA. This paper further discusses a preferred ICS engineering practice and an attestation strategy to mitigate the above vulnerability and protect ICS fromPLC-SAGE. BothPLC-SAGEand the proposed mitigations have been experimentally validated on two ICS platforms. Zeyu Yang 0001, Liang He 0002, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Unveiling Physical Semantics of PLC Variables Using Control InvariantsabstractThe security risk of semantic attacks to Industrial Control Systems (ICSs) is increasing. Semantic attacks manipulate targeted system modules by identifying the physical semantics of variables in Programmable Logic Controllers (PLCs) programs, i.e., the sensing/actuating modules represented by the variables, which is usually and inefficiently achieved via manual examination of system documents and long-term observation of system behavior. In this paper, we designARES, a method thatAutomaticallyReverseEngineers theSemantics of variables in PLC programs without requiring any domain knowledge.ARESis built on the fact that the Supervisory Control And Data Acquisition (SCADA) system monitors the behavior of PLC using a fixed mapping between the variables of program code and data log, and the data log variables are marked with physical semantics. By identifying the mapping between PLC code and SCADA data (i.e., the code-data mapping),ARESreverse engineers the physical semantics of program variables.ARESalso sheds light on the preferred defense strategies in implementing control rules that improve the resistance of PLC programs to semantic attacks, as well as in detecting and responding to semantics attacks in real time. We have experimentally evaluatedARESand the recommended defending practices on two ICS platforms. Zeyu Yang 0001, Liang He 0002, Yucheng Ruan, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | SSTAF: Security Settings-Based Threat Assessment Framework of Programmable Logic ControllersabstractIndustrial control systems (ICSs) govern the production activities of various critical infrastructures, where programmable logic controllers (PLCs) are essential devices for controlling industrial processes. However, PLCs have many vulnerabilities and might be configured inappropriately. With the trend of PLCs connecting to the Internet, such weaknesses will lead to various cyberattacks and have prompted many studies on the threat assessment for PLCs. Previous research has ignored PLCs’ security settings, such as operating mode and read/write authentication etc., which are the general security functionalities significantly affecting PLCs’ security. In this paper, we make the first attempt to propose a security settings-based threat assessment framework (SSTAF) to assess PLCs’ security.SSTAFconsists ofSScanner, a novel scanner to automatically extract the real-time configurations of security settings from PLCs, and the threat assessment criteria, serving to assess the appropriateness of PLC configurations and analyze risk levels of attacks based on PLCs’ security settings. Subsequently, usingSSTAF, we implement an Internet-wide threat assessment for PLCs exposed to the Internet. We deploySScanneron the Internet and interact with 41K ICS devices in cyberspace to acquire their configurations of security settings. Based on the scanning result and the threat assessment criteria, we reveal that 93.32% of PLCs have not appropriately configured their security settings. Additionally, each PLC might be subject to 4.96 attacks on average, of which 3.32 attacks are due to the inappropriate configurations of security settings. Zhenyong Zhang, Hengye Zhu, Zeyu Yang 0001, Ruilong Deng, Peng Cheng 0001, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | ADIS: Detecting and Identifying Manipulated PLC Program Variables Using State-Aware Dependency GraphabstractThe increasing network integration of industrial control systems amplifies the risk of cyberattacks on Programmable Logic Controllers (PLCs). In particular, the weak authentication of industrial communication protocols makes PLC program variables vulnerable to manipulation. Current defensive methods cannot reliably identify manipulated variables, even after PLC program manipulations have been detected. To bridge this gap, we presentADIS, a cross-domain Attack Detection and Identification System designed to detect and identify manipulated PLC program variables. Building on a novel state-aware graph representation of the PLC program,ADISdetects variable manipulations by comparing SCADA monitoring data with the control logic defined by the PLC program.ADISfurther identifies suspiciously manipulated program variables by excluding cascading failures from the detected anomalies and tracking suspicious variables based on the edges of the state-aware dependency graph. We have implemented and evaluatedADISon two platforms. The results demonstrate thatADISdetects attacks with a true positive rate exceeding 99% and a false positive rate of less than$0.04{\unicode {0x2030}}$. Furthermore, it successfully identifies manipulated program variables with up to a 71.3% reduction in suspicious variables compared to a baseline method. Zeyu Yang 0001, Liang He 0002, Yujiao Hu, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Verifying PLC Control Logic for Physical Module Integrity Guided by Wiring DiagramsabstractPhysical modules are the basic functional units of industrial control systems, governed by Programmable Logic Controllers (PLCs) according to predefined control logic. Attackers can compromise the integrity of physical modules by tampering with control logic, potentially disrupting production or causing physical damage. While model checking can detect logic bugs that violate module integrity requirements, it depends heavily on domain-specific knowledge, which is traditionally summarized by human experts, limiting both scalability and completeness. This paper proposes DGVerifier, a wiring diagram-guided framework that automatically verifies two general integrity requirements of physical modules: action integrity and state transition integrity. DGVerifier can extract module-related information from PLC wiring diagrams, mine domain-specific knowledge to generate specifications, and also model PLC programs as automata for verification. Evaluation on two real-world systems — an Elevator Control System and an Automated Assembly Line Control System — shows DGVerifier can recover 89.3% (25/28) of the required specifications and identify four hidden logic bugs violating physical module integrity. Chengtao Yao, Chengcheng Zhao, Zeyu Yang 0001, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | PicaCAN: Reverse Engineering Physical Semantics of Signals in CAN Messages Using Physically-Induced CausalitiesabstractWith the rapid development of Connected and Autonomous Vehicles, In-Vehicle Network attacks have garnered heightened research scrutiny due to vehicles’ increasing connectivities to the external environment. The common characteristic among these attacks is to tamper with targeted powertrain-related signals in the Powertrain Controller Area Network (PT-CAN) and further physically threaten vehicles’ safety. These powertrain-related signals are encoded within CAN messages grounded by the syntax specification, which is proprietary to Original Equipment Manufacturers and publicly unavailable. Thus, to undertake comprehensive security analysis and strategies, reverse engineering PT-CAN to the semantic level is urgently needed. However, the existing methods rely on interactions (injecting challenge signals/actions) with the targeted vehicle, and certain manual efforts are required. To fill this gap, we proposePicaCAN, a novel framework to extract signals from CAN messages and reverse engineer their physical semantics based on physically induced causality. Once access to the CAN traffic,PicaCANoffers the researcher an eye on the vehicle’s powertrain system, decoding binaries flows into powertrain-related signals automatically. We experimentally evaluatePicaCANon PT-CAN of three automobiles containing two power types. The experimental results show thatPicaCANcould successfully extract physical signals representing all targeted semantics (pedals, engine speed, etc.) from two Internal Combustion Engine Vehicles and one Hybrid Electric Vehicle under EV mode. Yucheng Ruan, Chengcheng Zhao, Zeyu Yang 0001, Yuanchao Shu, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Reverse Engineering Industrial Protocols Driven By Control FieldsabstractIndustrial protocols are widely used in Industrial Control Systems (ICSs) to network physical devices, thus playing a crucial role in securing ICSs. However, most commercial industrial protocols are proprietary and owned by their vendors, which impedes the implementation of protections against cyber threats. In this paper, we design REInPro to Reverse Engineer Industrial Protocols. REInPro is inspired by the fact that the structure of industrial protocols can be determined by a particular field referred to control field. By applying a probabilistic model of network traffic behavior, REInPro automatically identifies the control field and groups the associated network traffic into clusters. REInPro then infers critical semantics of industrial protocols by differentiating the features of corresponding protocol fields. We have experimentally implemented and evaluated REInPro using 8 different industrial protocols across 6 Programmable Logic Controllers (PLCs) belonging to 5 original equipment manufacturers. The experimental results show REInPro to reverse-engineer the formats and semantics of industrial protocols with an average correctness/perfection of 0.70/0.58 and 0.96/0.39. Zeyu Yang 0001, Yangyang Geng, Hengye Zhu, Peng Cheng 0001, Jiming Chen 0001 |
INFOCOM | 2 |
| 2024 | Deception-Resistant Stochastic Manufacturing for Automated Production LinesabstractThe advancement of Industrial Internet-of-Things (IIoT) magnifies the cyber risk of automated production lines, especially to deception attacks that tamper with the monitoring data to prevent the manipulated operation of production lines from being detected. To address this issue, we propose Stochastic Manufacturing (StoM), a new paradigm of manufacturing that is resistant to deception by design. StoM voids the foundation of deception attacks — i.e., the highly predictable operation data due to the cyclical manufacturing process — by injecting controlled stochasticity into the operation of production lines without degrading manufacturing efficiency or quality. StoM then examines if this stochasticity can be observed from the operation data and triggers an alarm of deception attack if not. We have experimentally evaluated StoM on two production line platforms, showing StoM to detect deception attacks with a detection rate exceeding 99.1%, a false alarm rate below 0.1%, and a latency of less than 1.2 manufacturing cycles. Our empirical analysis also shows that it is highly impractical for attackers to spoof the controlled stochasticity. Zeyu Yang 0001, Hongyi Pu, Liang He 0002, Chengtao Yao, Jianying Zhou 0001, Peng Cheng 0001, Jiming Chen 0001 |
RAID | 1 |
| 2023 | SePanner: Analyzing Semantics of Controller Variables in Industrial Control Systems based on Network TrafficabstractProgrammable logic controllers (PLCs), the essential components of critical infrastructure, play a crucial role in various industrial manufacturing processes. Recent attack events show that attackers have a strong interest in tampering with the controller variables, such as the device status and internal program logic. A typical attack strategy is that the attackers just send malicious network traffic of industrial control protocols (ICPs) to change the controller variables of PLCs. To defend against this attack, a lot of countermeasures have been proposed to detect anomalies in network traffic based on the semantic analysis. Zeyu Yang 0001, Zhenyong Zhang, Yangyang Geng, Ruilong Deng, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001 |
ACSAC | 2 |
| 2022 | Reverse Engineering Physical Semantics of PLC Program Variables Using Control InvariantsabstractSemantic attacks have incurred increasing threats to Industrial Control Systems (ICSs), which manipulate targeted system modules by identifying the physical semantics of variables in Programmable Logic Controllers (PLCs) programs, i.e., the sensing/actuating modules represented by the variables. This is usually (and inefficiently) achieved via manual examination of system documents and long-term observation of system behavior. In this paper, we design ARES, a method that Automatically Reverse Engineers the Semantics of variables in PLC programs without requiring any domain knowledge. ARES is built on the fact that the Supervisory Control And Data Acquisition (SCADA) system monitors the behavior of PLC using a fixed mapping between the variables of program code and data log, and the data log variables are marked with physical semantics. By identifying the mapping between PLC code and SCADA data (i.e., the code-data mapping), ARES reverse engineers the physical semantics of program variables. ARES also sheds light on the preferred practices in implementing control rules that improve the resistance of PLC programs to semantic attacks. We have experimentally evaluated ARES and the recommended implementation practices on two ICS platforms. Zeyu Yang 0001, Liang He 0002, Chengcheng Zhao, Peng Cheng 0001, Jiming Chen 0001 |
SenSys | 1 |
| 2022 | Detecting PLC Intrusions Using Control InvariantsabstractProgrammable logic controllers (PLCs), i.e., the core of control systems, are well-known to be vulnerable to a variety of cyber attacks. To mitigate this issue, we designPLC-Sleuth, a novel noninvasive intrusion detection/localization system for PLCs, which is built on a set of control invariants—i.e., the correlations between sensor readings and the concomitantly triggered PLC commands—that exist pervasively in all control systems. Specifically, taking the system’s supervisory control and data acquisition log as input,PLC-Sleuthabstracts/identifies the system’s control invariants as a control graph using data-driven structure learning, and then monitors the weights of graph edges to detect anomalies thereof, which is in turn, a sign of intrusion. We have implemented and evaluatedPLC-Sleuthusing both a platform of ethanol distillation system (EDS) and a realistically simulated Tennessee Eastman (TE) process. The results show thatPLC-Sleuthcan: 1) identify control invariants with 100%/98.11% accuracy for EDS/TE; 2) detect PLC intrusions with 98.33%/0.85 ‰ true/false positives (TPs/FPs) for EDS and 100%/0% TP/FP for TE; and 3) localize intrusions with 93.22%/96.76% accuracy for EDS/TE. Zeyu Yang 0001, Liang He 0002, Chengcheng Zhao, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Internet Things J. | 1 |
| 2020 | PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants
Zeyu Yang 0001, Liang He 0002, Peng Cheng 0001, Jiming Chen 0001, David K. Y. Yau, Linkang Du |
RAID | 1 |