EDBT 2026 Demo / reviewers in the wild / expert
Mengxiang Liu
dblp:218/2878
· DBLP profile ↗
9ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0002-2663-4787ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Small-Signal-Stability-Guaranteed Moving Target Defense Against Load Redistribution Attack on IoT-Based Smart GridabstractMoving target defense (MTD) is a promising approach to defend against load redistribution attacks on the Internet of Things (IoT)-based smart grid networks by probing the distorted state estimates with the distributed flexible AC transmission system. However, existing studies mainly focus on optimizing the performance of MTD and ignore the safety effect of it on the system’s operation. In this article, we fill this gap by deeply analyzing the effect of MTD on the small signal stability and aim to alleviate the negative impact and guarantee its defending performance simultaneously. First, the stability is formally described using the eigenvalue sensitivity. The relationship between the MTD-induced perturbation (MTDper) and the stability criteria is derived. Second, a new indicator is proposed to measure the effectiveness of MTDper. Third, a constrained optimization problem is formulated to compute the bound of MTDper for guaranteeing the small signal stability. In addition, a surprising finding is that the stability margin can be improved and enhanced by optimizing the value of MTDper without losing the MTD’s effectiveness. Finally, we evaluate the performance of MTDper and its impact on the small signal stability with extensive simulations on the IEEE 30-bus, 39-bus, and 68-bus test power systems. Bingdong Wang, Zhenyong Zhang, Mufeng Wang, Mengxiang Liu, Ruilong Deng, Xin Zhang 0028 |
IEEE Internet Things J. | 4 |
| 2025 | Cyber Recovery From Dynamic Load Altering Attacks: Linking Electricity, Transportation, and Cyber NetworksabstractThe dynamic load alternating attack (DLAA) that manipulates the load demands in power grid by compromising internet of things (IoT) home appliances has posed significant threats to the grid’s stable and safe operation. Current effort is mainly devoted to the investigation of detecting and mitigating DLAAs, while, for a holistic cyber-resiliency-enhancement process, the last but not least cyber recovery from DLAAs (CRDA) has not been paid enough attention yet. Considering the interconnection among electricity, transportation, and cyber networks, this paper presents the first exploration of the CRDA, where two essential sub-tasks are formulated: i) Optimal design of repair crew routes to remove installed malware and ii) Robust adjustment of system operation to eliminate the mitigation costs with stability guarantee. Towards this end, linear stability constraints are established by utilising a sensitivity-based eigenvalue estimation method, where the eigenvalue sensitivity information is appropriately ordered and strategically selected to guarantee the estimation accuracy. Moreover, to assure the CRDA solution’s robustness to the adversary’s follow-up movement, the worst-case attack strategies in all attack scenarios during the recovery process are integrated. A mixed-integer linear programming (MILP) problem is subsequently developed for the CRDA with the primary objective to restore the secure but cost-inefficient mitigation operation mode to the cost-efficient one and secondarily to repair compromised IoT home appliances. Case studies are performed in IEEE power system cases to validate the eigenvalue estimation’s accuracy, the CRDA solution’s effectiveness and robustness, as well as the proposed CRDA’s extensibility. Mengxiang Liu, Zhongda Chu, Fei Teng 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Submodularity-Based False Data Injection Attack Strategy in DC MicrogridsabstractDespite significantly enhancing system flexibility and reliability, the adoption of distributed secondary control in DC microgrids (DCmGs) introduces new vulnerabilities to false data injection (FDI) attacks. As a typical FDI attack, the zero trace stealthy (ZTS) attack has been recently disclosed for DCmGs, which can deteriorate the control objective while keeping stealthy to unknown input observer (UIO)-based detectors. In this work, we investigate the optimal deployment of ZTS attacks, where the adversary with limited resources aims to compromise a set of communication links such that the system state convergence error can be maximized. Specifically, we formulate the optimal ZTS attack deployment problem as a combinatorial optimization problem and unveil its NP-hard characteristic. Then, we discover the submodularity in the state convergence error function, enabling us to transform the original NP-hard problem into a tractable submodular maximization problem. Furthermore, based on the submodular optimization theory, we propose a novel distributed algorithm for the optimal ZTS attack deployment in DCmGs, which effectively balances the attack benefits and computation cost. Finally, comparisons between the centralized and distributed algorithms are illustrated through extensive simulations. Chengcheng Zhao, Mengxiang Liu, Ruilong Deng, Peng Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Optimal Defense Resource Allocation Considering Nonlinear Attack Cost in Power SystemsabstractIn recent years, numerous studies have explored how to allocate limited defense resource among meters to increase difficulties for launching attacks in power systems. However, existing studies often simplify this problem by assuming the linearity of attack cost functions, which creates an inevitable gap between theoretical analysis and practical scenarios. In this article, general nonlinear attack cost functions are considered in the formulation of the optimal defense resource problem, resulting in a mixed-integer nonlinear programming problem. This poses a challenging task for numerical methods or popular commercial solvers. To address this issue, an advanced slime mould algorithm with specialized initialization and evolutionary schemes is proposed. Specifically, a customized initialization strategy is designed such that the population can be easily initialized within the nonconvex feasible region aligning with the nonlinear constraints. Besides, in the evolutionary process, the fitness function is well-designed to encourage the individuals violating nonlinear constraints to evolve toward feasible directions. Comprehensive case studies verify that, compared to the state-of-the-art solvers, the proposed approach can achieve satisfactory defense resource allocation results in terms of feasibility, optimality, and real-time performance. Mengxiang Liu, Rui Zhong 0004, Ke Zuo, Ruilong Deng |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Vulnerability of Machine Learning Approaches Applied in IoT-Based Smart Grid: A ReviewabstractMachine learning (ML) sees an increasing prevalence of being used in the internet-of-things (IoT)-based smart grid. However, the trustworthiness of ML is a severe issue that must be addressed to accommodate the trend of ML-based smart grid applications (MLsgAPPs). The adversarial distortion injected into the power signal will greatly affect the system’s normal control and operation. Therefore, it is imperative to conduct vulnerability assessment for MLsgAPPs applied in the safety-critical power systems. In this paper, we provide a comprehensive review of the recent progress in designing attack and defense methods for MLsgAPPs. Unlike the traditional survey about ML security, this is the first review work about the security of MLsgAPPs that focuses on the characteristics of power systems. We first highlight the specifics for constructing adversarial attacks on MLsgAPPs. Then, the vulnerability of MLsgAPP is analyzed from the perspective of the power system and ML model, respectively. Afterward, a comprehensive survey is conducted to review and compare existing studies about the adversarial attacks on MLsgAPPs in scenarios of generation, transmission, distribution, and consumption, and the countermeasures are reviewed according to the attacks that they defend against. Finally, the future research directions are discussed on the attacker’s and defender’s side, respectively. We also analyze the potential vulnerability of large language model-based (e.g., ChatGPT) smart grid applications. Overall, our purpose is to encourage more researchers to contribute to investigating the adversarial issues of MLsgAPPs. Zhenyong Zhang, Mengxiang Liu, Ruilong Deng, Peng Cheng 0001, Dusit Niyato, Mo-Yuen Chow, Jiming Chen 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Limitation of Reactance Perturbation Strategy Against False Data Injection Attacks on IoT-Based Smart GridabstractWith the goal of defending against false data injection attacks (FDIAs) on state estimation (SE) of the Internet of Things (IoT)-based smart grid, recently, the reactance perturbation strategy (RPS) has been proposed by actively perturbing the branch reactances of transmission lines. Satisfied defending performance as it shows, the limitations have not been sufficiently studied by pioneer works. In this article, by exploring the vulnerability implied by the transmission network structure, we deeply investigate the limitations of RPS with both theoretical and numerical results. First, we prove that improperly selecting the branches to perturb can make RPS fail to prevent the SE from FDIAs. Second, by exploiting the properties of the system topology, we classify the branches and buses into different types and derive the limitations of RPS with analytical results. Third, an enhanced RPS is proposed to defend against FDIAs with a complete defense goal. Finally, extensive simulations are conducted in IEEE test power systems to verify the correctness of analytical results and validate the effectiveness of the enhanced RPS. Zhenyong Zhang, Bingdong Wang, Mengxiang Liu, Youliang Tian, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Physics-Aware Watermarking Embedded in Unknown Input Observers for False Data Injection Attack Detection in Cyber-Physical MicrogridsabstractThe physics-aware watermarking-based detection method has shown great potential in detecting stealthy False Data Injection Attacks (FDIAs) by adding appropriate watermarks to control commands or sensor measurements, especially in industrial control systems and grid-tied Distributed Energy Resources (DERs). However, existing watermarking-based detection methods have limitations in either handling the intricate physical couplings among DERs or characterising the fast changing power electronics dynamics, and thus cannot be directly applied to microgrids. Inspired by the methodology of Unknown Input Observer (UIO), which can be employed for the distributed anomaly monitoring in cyber-physical microgrids but would be easily bypassed once the adversary has the knowledge of certain electrical parameters, this paper makes the first attempt to investigate the physics-aware watermarking embedded in UIOs such that the stealthy FDIAs would be intentionally disrupted by the watermarking scheme. Based on the theoretical analysis of the detection enhancement and performance degradation under watermarking-enhanced UIOs, the watermark strengths, UIO parameters, and control gains are optimally co-designed to significantly enhance the detection effectiveness while not degrading the control performance. The robustness of the watermarking-enhanced UIO to Time Synchronisation Errors (TSEs) is improved by employing a sliding time window with appropriate length. The performance of the proposed method is validated through Matlab/Simulink studies and cyber-physical co-simulation experiments, and the sensitivities of the detection latency and TSE robustness to watermark strength and detection window’s length are comprehensively studied. Mengxiang Liu, Xin Zhang 0028, Hengye Zhu, Zhenyong Zhang, Ruilong Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | HoneyJudge: A PLC Honeypot Identification Framework Based on Device Memory TestingabstractThe widespread use of programmable logic controllers (PLCs) in critical infrastructures has given rise to escalating cybersecurity concerns regarding PLC attacks. As a proactive defense mechanism, PLC honeypots emulate genuine controllers to engage adversaries so as to observe their attack tactics and techniques. As part of the arms race between the offense and defense, multiple PLC honeypot identification tools have been developed. However, many existing tools cannot recognize high-fidelity honeypots, since they rely on identifying common network services and fingerprints. In this paper, we propose an innovative and practical honeypot identification framework calledHoneyJudge, which goes beyond state-of-the-art (SOTA) network fingerprint-based identification tools like Nmap and the PLCScan tool.HoneyJudgetests the suspected target’s special memory content and features. Specifically,HoneyJudgemodels the internal memory of a PLC in three categories, from system-level, user-level, to process-level categories, based on which it extracts six representative memory features. All characteristics are acquired through automated network request messages. Then, we design a weighted voting algorithm to combine the test results over different memory features to reach the final conclusion. We validate the effectiveness ofHoneyJudgein comparison with several SOTA honeypot identification tools, and the results indicate that the memory-related issues have not been well addressed in existing PLC honeypots and still need substantial research efforts. Hengye Zhu, Mengxiang Liu, Binbin Chen 0001, Peng Cheng 0001, Ruilong Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Detection-Performance Tradeoff for Watermarking in Industrial Control SystemsabstractThe watermarking method, which adds unique watermarks to data, has been widely used for integrity attack detection in industrial control systems (ICSs). Existing literature generally designs watermarking mechanisms without considering the existence of noises, which cannot be trivially applied to realistic ICS scenarios in the presence of strong noise interference. On one hand, the low-intensity watermarking will be ineffective under the strong noise environment; while on the other hand, the oversized watermarking can possibly degrade the control performance or even destabilize the system. Therefore, the intensity of watermarks plays a fundamental role in balancing the tradeoff between detection effectiveness and control performance, which, to the best of our knowledge, has never been thoroughly analyzed yet. To this end, in this paper, we for the first time propose an optimal watermarking design method for ICSs considering the detection-performance tradeoff. To begin with, we shift the watermark container from data points to segments and update the detection metrics to reduce the noise impact. Then, we formulate an optimization problem to determine the strength of watermarks to balance the detection-performance tradeoff. Meanwhile, the detection effectiveness and control performance metrics are analytically modeled and theoretically analyzed considering the discrepancy between added watermarks and noises, signal quality, detection latency, as well as estimation of detection metrics. Finally, extensive numerical simulations and systematical experiments based on a practical Ethanol Distillation ICS are conducted to validate the theoretical analysis and demonstrate the outperformance of our proposed watermarking method in comparison with related works. Hengye Zhu, Mengxiang Liu, Chongrong Fang, Ruilong Deng, Peng Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |