EDBT 2026 Demo / reviewers in the wild / expert
Yu Yao 0002
dblp:230/9622
· DBLP profile ↗
20ranked-venue papers
1as first author
19since 2021 · last 2026
0000-0001-5458-541XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 9 since 2021Security and privacy · 6 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-scale hierarchical causality-inspired graph network for interpretable anomaly detection in industrial time series
Yushan Fang, Yu Yao 0002, Wei Yang 0044, Xiaoli Lin, Chuan Sheng |
Eng. Appl. Artif. Intell. | 2 |
| 2026 | Precise defense method against low-magnitude poisoning attack in industrial internet of things
Ziyong Ran, Yu Yao 0002, Yao Shan, Wei Yang 0044, Yuming Hao |
Expert Syst. Appl. | 2 |
| 2026 | A Real-Time Hacker Group Identification Method for Industrial Control Systems Based on Gaussian Self-Organizing Incremental Neural NetworkabstractSeveral methods have been proposed to identify hacker groups targeting Industrial Control Systems (ICS); however, real-time identification of complex hacker groups with new data distributions, different attack patterns and Internet Protocol (IP) prefixes remains to be accomplished. This paper utilises the honeynet data to propose a hacker group identification method, Hacker-Identifier, which focuses on identifying hacker groups targeting ICS. To effectively distinguish attack patterns with different temporal features, we present a novel attack pattern temporal feature modelling method, which combines temporal feature extraction and learning. On this basis, we propose an improved genetic algorithm-based feature selection method to further improve the accuracy of attack pattern classification. To accurately identify attack patterns and hacker groups with new data distributions in real time, we propose a Gaussian self-organising incremental neural network, which can not only effectively distinguish highly overlapping classes, but also prevent excessive segmentation of homogeneous classes. To accurately identify hacker groups with different attack patterns and IP prefixes, we propose an improved hacker group identification method that effectively fuses the attribute and structural features of hackers through heterogeneous graph node embedding. Take the Modbus protocol as an example, we implement a prototype of Hacker-Identifier, and use 2.5 years of real-world honeynet dataset to evaluate its performance. The experimental results demonstrate its effectiveness and superiority compared with existing state-of-the-art hacker group identification methods. It achieves weighted F1-score of 98.86% and accuracy of 99.12%, outperforming the state-of-the-art work by 8.12% and 6.86% respectively, while reducing the total error rate by 17.11%. Xiaoli Lin, Yu Yao 0002, Yushan Fang, Boxue Song, Wei Yang 0044 |
IEEE Internet Things J. | 2 |
| 2026 | A generalizable anomaly detection framework with dynamic concept drift suppression for non-stationary time series
Licheng Yang 0002, Yu Yao 0002, Daoqing Yang, Wei Yang 0044, Yuming Hao |
Knowl. Based Syst. | 2 |
| 2026 | RL-ACID: Reinforcement Learning-Optimized Adaptive Causal Discovery for Robust Anomaly Detection in Industrial SystemsabstractAnomaly detection is essential for the security of industrial control systems. However, dynamic operating conditions introduce nonstationarity and time-varying causal structures, degrading performance and undermining interpretability. To address this, we propose RL-ACID, a lightweight reinforcement learning framework for adaptive causal discovery. It reformulates anomaly detection as sequential causal discovery, introducing the first unified architecture that integrates lightweight reinforcement learning-based search with causal clustering to resolve the adaptability, efficiency, and interpretability tradeoff. Our framework employs a joint time-frequency encoder to extract and construct candidate causal graphs. Building upon this, we design the causal reinforcement learning-based lightweight search algorithm, which formulates graph exploration as a sequential decision process under sparsity and acyclicity constraints, enabling iterative causal structure optimization. To further enhance adaptability in dynamic environments, we introduce a causal clustering module that softly assigns time-varying graphs to latent operational modes through structural experts, thereby distinguishing normal operational fluctuations from true anomalies. Extensive experiments on multiple industrial benchmarks demonstrate the superior performance of RL-ACID. Our framework not only achieves higher accuracy than baselines but also provides interpretable anomaly analysis through causal path tracing. Hechen Yang, Yu Yao 0002, Licheng Yang 0002, Wei Yang 0044 |
IEEE Trans. Ind. Informatics | 2 |
| 2026 | IMADP: Imputation-Based Anomaly Detection in SCADA Systems via Adversarial Diffusion ProcessabstractAs the confrontation of the industrial cybersecurity upgrades, multi-dimensional variables measured by the SCADA multi-sensor are critical for assessing security risks in industrial field devices. While Deep Learning (DL) methods based on generative models have demonstrated effectiveness, the impact of missing features in samples and temporal window size on modeling and detection processes has been consistently overlooked. To address these challenges, this work proposes an IMADP framework that integratively solves two tasks of missingness patching and anomaly detection. Firstly, the Window-based Adaptive Selection Strategy (WASS) is also designed to intelligently window samples, reducing reliance on prior settings. Secondly, an imputer is constructed under WASS to restore sample integrity, which is implemented by a fully-connected network centered on Neural Controlled Differential Equations (NCDEs). Thirdly, a adversarial diffusion detection model with the variant Transformer as the inverse solver is proposed. Additionally, the Adaptive Dynamic Mask Mechanism (ADMM) is built upon to bolster the model’s comprehension of inter-dependencies between time and sensor nodes. Simultaneously, adversarial training is introduced to optimize training and detection latency caused by the excessive diffusion step size during the native Conditional Diffusion process. The experimental results validate that the proposed framework has the capability to build detectors using missing training samples, and its overall detection performance, tested across six datasets, is superior to existing methods. Yu Yao 0002, Chuan Sheng, Ziyong Ran, Wei Yang 0044 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | IPv6 active address detection model based on diffusion model
Wei Yang 0044, Qianyi Wang, Yu Yao 0002 |
Comput. Networks | 3 |
| 2025 | A Real-Time Anomaly Detection Method for Industrial Control Systems Based on Long-Short Period Deterministic Finite AutomatonabstractAnomaly detection has proven effective in detecting cyber-attacks in industrial control systems (ICS). However, most existing anomaly detection methods suffer from low accuracy because they ignore the effects of packet loss and network delay on time features, the sequential nature of transition time, masquerade transitions, and system recovery. Meanwhile, current cyber-physical model (CPM) construction methods struggle to effectively address the state explosion problem and properly balance the removal and retention of low frequency states (LFS). In this article, we propose a novel baseline model for ICS to detect anomalies through learning device-level polling time patterns and system-level CPM. The polling time pattern learning method reduces the effects of packet loss and network delay on time features by extracting only matching packets and replacing outliers. The CPM construction method mitigates state explosion through mixed-event discretization, reduces the effects of network delay on transition/action times through outlier replacement, and captures the sequential nature of transition times with circular permutation sets (CPSets). CPM model optimization uses a post-pruning algorithm to balance the removal and retention of LFSs, and a CPM periodicity detection method that mitigates the effects of network delay to ensure that all industrial process periods are detected. A real-time anomaly detection method with a two-layer defence mechanism is proposed using the baseline model. Experimental results from two lab-scale ICSs with six process-related attacks confirm the effectiveness and superiority of the proposed method. It achieves average F1 scores of 98.81% and accuracy of 99.24%, outperforming the state-of-the-art work by 18.51% and 13.96%, respectively. Xiaoli Lin, Yu Yao 0002, Wei Yang 0044, Xiaoming Zhou, Guangao Li |
IEEE Internet Things J. | 2 |
| 2025 | Precise Defense Approach Against Small-Scale Backdoor Attacks in Industrial Internet of ThingsabstractWith the exceptional ability of deep learning to extract high-dimensional structures from massive datasets, its application in the industrial Internet of Things (IIoT) has become increasingly prevalent. However, the inherent security vulnerabilities of deep learning pose a significant threat to IIoT systems, particularly in the form of backdoor attacks. Current defense methods are primarily designed for image processing tasks, and due to the uniqueness of industrial environments, their effectiveness is significantly reduced because of the lack of precision when applied directly to the IIoT applications. To address these challenges, this article proposes a trigger detection method tailored for industrial environments, capable of precisely calculating the values of triggers during the detection process. Building on this, we introduce a saliency map-based trigger pruning method to further refine the triggers. Finally, utilizing these refined triggers, we perform trigger recovery to complete the backdoor defense against the IIoT model. Furthermore, by integrating these approaches, we construct a comprehensive detection-pruning-recovery defense framework against backdoor attacks in industrial settings. Experimental results across multiple industrial scenarios demonstrate that our method enhances the robustness of industrial applications against backdoor attacks, outperforming existing defense mechanisms. Ziyong Ran, Yu Yao 0002, Wei Yang 0044 |
IEEE Internet Things J. | 2 |
| 2025 | InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation LearningabstractIndustrial control protocols (ICPs) play a significant role in ensuring dependable interconnection among devices in industrial environments. Protocol reverse engineering (PRE) techniques are commonly used to analyze a large number of agnostic and proprietary protocols based on network traffic traces or programs. However, conventional PRE methods face several challenges in reversing ICPs with complex data representations that contain rich structural features. In this work, we present a new perspective on message representation using the graph, and design a syntax inference framework for ICPs reverse analysis (InSyfer). Specifically, we propose a novel method to construct a single message graph for entire traces, automatically extracting syntactical similarity features. We also design an adaptive message clustering model that abstracts the clustering problem into a binary pairwise-classification framework to judge whether pairs of messages belong to the same groups and jointly optimizes it with feature extraction. The above design enables InSyfer to accurately identify message types and greatly improves the correctness of protocol format inference. We conduct extensive experiments to verify the effectiveness of InSyfer. Evaluations of four standard ICPs and two unknown protocols demonstrate that InSyfer outperforms the state-of-the-art PRE methods. Daoqing Yang, Yu Yao 0002, Yao Shan, Xiaoli Lin, Wei Yang 0044, Licheng Yang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control ProtocolsabstractReverse engineering of agnostic industrial control protocols (ICPs) based on traffic traces is significant for the security analysis of industrial control systems. Field semantics deduction is an essential step in protocol reverse engineering following the discovery of the message field. Most existing methods rely on knowledge-based analysis for specific fields of common protocols, which require too numerous assumptions and lack semantic knowledge about ICPs. In this paper, we propose a new concept, pattern series, and design the first classification framework for inferring the semantic types of unknown ICPs. Specifically, we first present the definition of pattern series and design the field pattern series generation algorithm for building training data, then develop a field semantics classification model to learn and apply semantic features from known protocols to predict semantic types in unknown protocols. Lastly, we implement a probability-maximizing selection algorithm to obtain optimal semantic types. We demonstrate the effectiveness of the proposed method through extensive experiments with five popular ICPs, including their mixed protocols. Evaluations show that our approach significantly outperforms baseline methods in field semantic recognition, achieving ≥90.8% F1-score. Daoqing Yang, Yu Yao 0002, Yao Shan, Licheng Yang 0002, Wei Yang 0044, Fuyi Liu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | A feature selection based on genetic algorithm for intrusion detection of industrial control systems
Yushan Fang, Yu Yao 0002, Xiaoli Lin |
Comput. Secur. | 2 |
| 2024 | ALOC: Attack-Aware by Utilizing the Adversarially Learned One-Class Classifier for SCADA SystemabstractAs the volume of network attacks on Supervisory Control and Data Acquisition (SCADA) systems increases, the existing supervised methods that over-rely on priori knowledge can hardly cope with increasingly stealthy and legitimate unknown protocol attacks for heterogeneous industrial scenarios. In this paper, we present an anomaly-based deep learning attack-aware method called ALOC, which constitutes the dual Frequency Domain Transform (FDT) and implicit Generative Adversarial Networks (GANs). The former is proposed that reduces the cost of hand-designed features and normalizes raw traffic bytes as the input under different protocol types. With the assistance of a Deep Auto-Encoder (DAE) with 1D Convolutional Neural Networks (1D-CNNs), the latter can automatically build a behavioral baseline based on the multi-scale distribution of transformed raw bytes. The potential SCADA anomalies or intrusions can be effectively detected, which enables field operators to avoid security risks in a timely manner. Essentially, the trained model conveniently determines the anomaly boundaries by augmenting the representation capabilities of raw session information in high-dimensional space. In response, adversarial training with different loss functions is introduced to constrain the reconstruction of anomalous samples extremely, which in turn improves the detection performance and analyzes anomaly attributes. The experimental results show that the proposed approach is more effective and generalized than existing state-of-the-art baselines. Yu Yao 0002, Chuan Sheng, Wei Yang 0044 |
IEEE Internet Things J. | 2 |
| 2024 | CFL-IDS: An Effective Clustered Federated Learning Framework for Industrial Internet of Things Intrusion DetectionabstractThe Industrial Internet of Things (IIoT) offers the manufacturing sector opportunities for transformation and upgrade but also carries significant security risks. Traditional federated learning (FL) as a potential security solution is challenging in complicated application environments with heterogeneous data, imbalanced data, and poisoning attacks. To address these challenges, we construct a clustered FL Framework for IIoT intrusion detection (CFL-IDS) based on local models’ evaluation metrics (EMs). First, we designed an intrusion detection model with a dynamic focal loss (DFL) for all edge nodes (ENs). This model’s performance is enhanced under various imbalanced data partitions by dynamically altering the focus on samples during the loss minimization training process. Second, the time series of EMs of local models to reflect the data distribution of ENs implicitly, and use clustering algorithms to facilitate knowledge sharing among those ENs with similar data distribution to co-optimize a common model for them. Finally, an intelligent cooperative model aggregation mechanism (ICMAM) adaptively adjusts each local model’s weight distribution, which substantially improves the benefits of FL and alleviates subpar models’ alleviates interference from subpar models to FL. Experiments demonstrate that CFL-IDS has stronger robustness and displays superior performance under data imbalance and non-independent and identically distributed (non-IID) situations while being effective against poisoning attacks. Yao Shan, Yu Yao 0002, Xiaoming Zhou |
IEEE Internet Things J. | 2 |
| 2024 | Scanner-Hunter: An Effective ICS Scanning Group Identification SystemabstractAs the precursor of cyber-attacks, the campaigns of scanning groups are able to reflect the attack target and attack trend to a great extent, which provide highly valuable threat intelligence for cyber defenders to understand the current cyber security situation. However, how to identify scanning groups in the context of limited information, especially in the absence of relevant threat intelligence, remains a challenging problem. In this paper, we utilize the honeynet as the unique data source to propose a scanning group identification system, Scanner-Hunter, which focuses on identifying scanning groups targeting ICS devices. To better characterize scanning patterns, a novel traffic representation scheme for scanning traffic is proposed, which is composed of a set of feature vectors to describe all the ICS request packets. On this basis, we propose a novel self-expanding multi-class classification (SEMCC) model and the IP prefix judgment, which are deliberately integrated to cope with sophisticated scanning groups. Take the Modbus protocol as an example, we implement a prototype of Scanner-Hunter, and use six years of real-world honeynet datasets to evaluate its performance. The experimental results illustrate its effectiveness and superior performance compared with some popular machine learning methods and existing SOTA scanning group identification methods. In addition, Scanner-Hunter is further leveraged to investigate the group distribution and maliciousness of 506 unknown scanners, and some suspicious attack groups with APT characteristics are analyzed. Furthermore, accurate scanning group information will contribute to revealing potential attack organizations and supporting decision making to prevent or interrupt cyber-attacks in time. Chuan Sheng, Yu Yao 0002, Lianxiang Zhao, Peng Zeng 0001, Jianming Zhao |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | NeuPot: A Neural Network-Based Honeypot for Detecting Cyber Threats in Industrial Control SystemsabstractHoneypots have proven to be an effective defense method for industrial control systems (ICSs). However, as attacker skills become more sophisticated, it becomes increasingly difficult to develop honeypots that can effectively recognize and respond to such attacks. In this article, we propose a neural network-based ICS honeypot scheme named NeuPot that improves security from two aspects: 1) honeypot interaction; and 2) cyber threats detection capability. NeuPot can respond to attacker requests depending on a specific industrial scenario without constant communication with the ICS and detect malicious traffic. To create this honeypot scheme, a new seq2seq time-series forecast model guided by Huber loss is designed to simulate the long-term changes in actual ICS physical processes. Second, a Modbus honeypot framework is created to react to changes in these ICS physical processes in their interactions with attackers and to capture various cyber threats against the ICS. Further, a novel loss function for industrial protocol-level malicious traffic detection is devised to identify known and unknown threats. According to our experiments, the proposed honeypot scheme is highly effective and outperforms state-of-the-art schemes in terms of interactivity and in detecting cyber threats. Yao Shan, Yu Yao 0002, Wei Yang 0044 |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Unknown Attack Traffic Classification in SCADA Network Using Heuristic Clustering TechniqueabstractAttack Traffic Classification (ATC) technique is an essential tool for Industrial Control System (ICS) network security, which can be widely used in active defense, situational awareness, attack source traceback and so on. At present, the state-of-the-art ATC methods are usually based on traffic statistical features and machine learning techniques, including supervised classification methods and unsupervised clustering methods. However, it is difficult for these methods to overcome the problems of lack of attack samples and high real-time requirement in ATC in Supervisory Control and Data Acquisition (SCADA) networks. In order to address the above problems, we propose a self-growing ATC model based on a new density-based heuristic clustering method, which can continuously and automatically detect and distinguish different kinds of unknown attack traffic generated by various attack tools against SCADA networks in real time. An effective representation method of SCADA network traffic is proposed to further improve the performance of ATC. In addition, a large number of experiments are conducted on a compound dataset consisting of the SCADA network dataset, the attack tool dataset and the ICS honeypot dataset, to evaluate the proposed method. The experimental results show that the proposed method outperforms existing state-of-the-art ATC methods in the crucial situation of only normal SCADA network traffic. Chuan Sheng, Yu Yao 0002, Wei Yang 0044 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | A cyber-physical model for SCADA system and its intrusion detection
Chuan Sheng, Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044 |
Comput. Networks | 2 |
| 2021 | Study on the intelligent honeynet model for containing the spread of industrial viruses
Chuan Sheng, Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044 |
Comput. Secur. | 2 |
| 2018 | An Epidemic Model of Computer Worms with Time Delay and Variable Infection RateabstractWith rapid development of Internet, network security issues become increasingly serious. Temporary patches have been put on the infectious hosts, which may lose efficacy on occasions. This leads to a time delay when vaccinated hosts change to susceptible hosts. On the other hand, the worm infection is usually a nonlinear process. Considering the actual situation, a variable infection rate is introduced to describe the spread process of worms. According to above aspects, we propose a time-delayed worm propagation model with variable infection rate. Then the existence condition and the stability of the positive equilibrium are derived. Due to the existence of time delay, the worm propagation system may be unstable and out of control. Moreover, the threshold τ0 of Hopf bifurcation is obtained. The worm propagation system is stable if time delay is less than τ0 . When time delay is over τ0 , the system will be unstable. In addition, numerical experiments have been performed, which can match the conclusions we deduce. The numerical experiments also show that there exists a threshold in the parameter a , which implies that we should choose appropriate infection rate β(t) to constrain worm prevalence. Finally, simulation experiments are carried out to prove the validity of our conclusions. Yu Yao 0002, Qiang Fu 0005, Wei Yang 0044, Chuan Sheng |
Secur. Commun. Networks | 1 |