EDBT 2026 Demo / reviewers in the wild / expert
Xin Chen 0123
dblp:24/1518-123
· DBLP profile ↗
14ranked-venue papers
0as first author
12since 2021 · last 2026
0009-0000-2918-7006ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Computer networks · 5 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An LLM-Driven Fuzzing Framework for Detecting Logic Instruction Bugs in PLCs
Jiaxing Cheng, Ming Zhou 0010, Haining Wang 0001, Xin Chen 0123, Yibo Qu, Limin Sun 0001 |
NDSS | 4 |
| 2026 | TLCFI-PLC: Trampoline-Based Lightweight Control Flow Integrity Scheme for Protecting PLC
Kaixiang Liu, Junjiao Liu, Zhiwen Pan, Shichao Lv, Xin Chen 0123, Zhi Li 0018, Yuqi Chen 0001, Limin Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | PNetGPT: Proprietary Protocol Network Traffic Generation with Pre-trained TransformerabstractGenerative pre-trained transformers are exceedingly effective as generative models and classifiers, widely used in natural language processing and computer vision. This work contributes to the exploration of generative pre-trained transformer-based models in the proprietary protocol network traffic. However, building a pre-trained model for proprietary protocol network traffic is non-trivial due to the heterogeneous unknown formats and the extreme scarcity of proprietary protocol network traffic datasets. In this paper, we present PNetGPT, a pre-trained transformer-based model for generating proprietary protocol network traffic. We have constructed the inaugural dataset of 2 real-world proprietary protocols. After training on this dataset, PNetGPT possesses the capacity to generate high-quality proprietary protocol network traffic to support various applications of proprietary protocols, including reverse analysis, protocol fuzzy testing, intrusion detection, etc. We evaluated PNetGPT with two real proprietary protocols and demonstrated state-of-the-art (SOTA) performance in handling heterogeneous unknown formats. The code and datasets are available at: https://github.com/Snail1502/PNetGPT Zedong Li, Dongliang Fang, Xin Chen 0123, Zhanwei Song, Zhi Li 0018, Shichao Lv, Limin Sun 0001 |
ICASSP | 4 |
| 2025 | Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationabstractProtocol reverse engineering (PRE) aims to infer the protocol formats of unknown protocols. Existing techniques, whether Network-Trace based or Execution-Trace based methods, face two main limitations: a reliance on the quality and scale of traffic datasets, which often leads to low accuracy and poor generalization; and a failure to adequately consider the multi-format characteristic prevalent in real-world protocols (i.e., the same protocol may support multiple different formats).To address these challenges, we propose ProbePRE—a PRE tool that performs multi-format extraction on protocol handlers by autonomously generating packets. ProbePRE employs three key techniques: (1) an execution tracing strategy enhanced with implicit data flow analysis to obtain more detailed execution information; (2) constraint extraction methods tailored for different program structures to pass protocol validation; and (3) an innovative constraint combination algorithm to construct effective packets that guide the protocol handler to execute diverse protocol parsing paths. In our experimental evaluation, we compared ProbePRE with 4 state-of-the-art PRE tools in terms of field segmentation accuracy. The results demonstrated that ProbePRE achieved an F1 score of 0.88, significantly outperforming existing methods. Furthermore, evaluations on 6 protocol handlers indicated that ProbePRE attained 83% completeness in multi-format extraction tasks. Notably, in basic block coverage tests, ProbePRE achieved a 67% improvement over traditional traffic dataset methods, which fully validates the effectiveness of its path exploration capabilities. Dingzhao Xue, Yibo Qu, Xin Chen 0123, Shuaizong Si, Shichao Lv, Zhiqiang Shi, Limin Sun 0001 |
ASE | 4 |
| 2025 | SFACIF: A safety function attack and anomaly industrial condition identified framework
Kaixiang Liu, Yongfang Xie, Yuqi Chen 0001, Shiwen Xie, Xin Chen 0123, Dongliang Fang, Limin Sun 0001 |
Comput. Networks | 5 |
| 2025 | SecureSIS: Securing SIS Safety Functions With Safety Attributes and BPCS InformationabstractIn high-stakes process industries, the Basic Process Control System (BPCS) relies on conventional control to enhance productivity, while the Safety Instrumented System (SIS) uses safety functions to maintain safety. Compared to the BPCS, attackers targeting the SIS can modify safety function activation conditions to trigger them prematurely or to evade the activation of the safety function. While various attack detection methods focus on the BPCS, they often overlook the SIS. This can lead to undetected safety breaches, significantly increasing the risk of catastrophic fault. Recent methods face three key limitations that hinder their practical application to SIS. First, both attackers and engineers can exploit the hot update mechanism of SIS to add or modify control logic. However, current methods lack verification for the newly added or modified logic. Second, current methods are unable to assess the rationality of dangerous value ranges. Third, these methods struggle to distinguish between faults and attacks, making it difficult to determine the appropriate time to activate the SIS’s safety function. To overcome these limitations, we propose SecureSIS, a method for securing SIS safety functions by leveraging the safety attributes of the SIS and incorporating information from the BPCS. The core of SecureSIS includes: 1) using the safety attributes of the SIS to verify automatically extracted candidate control logic detection rules; 2) utilizing information from the BPCS to verify automatically extracted candidate value range detection rules; and 3) distinguishing between safety function attacks and industrial process faults with validated rules and integration of process data from BPCS. Our scheme was evaluated using a Tricon SIS controller deployed on a gas pipeline network platform. The results indicate that SecureSIS achieved 97.3% accuracy in detecting data injection attacks and a detection accuracy of 96.0% for control logic modification attacks. Compared with the other representative detection approaches, our scheme has better detection performance. Kaixiang Liu, Yongfang Xie, Shiwen Xie, Yuqi Chen 0001, Xin Chen 0123, Limin Sun 0001, Zhiwen Pan |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | MSGFuzzer: Message Sequence Guided Industrial Robot Protocol FuzzingabstractIndustrial robots are widely used in industrial control systems (ICS). Once compromised, it could be maliciously controlled by attackers, endangering manufacturing processes or even human lives. Therefore, timely discovery of vulnerabilities in industrial robots is essential. Protocol fuzzing is a popular method for discovering protocol implementation vulnerabilities. However, the intricate workflow of industrial robots imposes strict message sequence constraints on message execution. Moreover, the overhead of sequence constraint satisfaction is exacerbated by the redundant messages in message sequences and the inherent delays in physical domain execution. These challenges make it difficult for fuzzers to penetrate deep code paths for fuzzing effectively. In this paper, we propose MSGFuzzer, a message sequence-guided industrial robot protocol fuzzer. Specifically, we filter the original traffic based on message byte characteristics and gener-ate message sequences. After that, we distinguish the sequence constraints for each message through the feedback mechanism of the industrial robot. To reduce state-guidance time, we construct the minimal message sequence based on the constraint conditions of messages. We evaluated MSGFuzzer on a real industrial robot. The results show that MSGFuzzer discovered 12 unique crashes. Note that this is at least 71.4% more effective than state-of-the-art protocol fuzzers in crash discoveries Yang Zhang 0145, Dongliang Fang, Puzhuo Liu, Laile Xi, Xin Chen 0123, Shuaizong Si, Limin Sun 0001 |
ICST | 6 |
| 2024 | SSAD: State Space-Based Anomaly Detection in Industrial Control SystemsabstractIndustrial Control Systems (ICS) are increasingly facing the threat of False Data Injection (FDI) attacks. Process-based anomaly detection is an emerging intrusion detection approach for I CS that effectively identifies anomalies induced by FDI attacks. Anomaly detection models are constructed to describe the normal patterns of industrial processes and subsequently perform real-time evaluation of process data. However, this approach suffers from low detection accuracy due to the complex nonlinear spatiotemporal correlations in industrial pro-cess data, which are difficult to explicitly describe using anomaly detection models. Additionally, noise and interference within the process data prevent these models from recognizing genuine anomalous events. This paper proposes a State Space-based Anomaly Detection (SSAD) approach. Specifically, to explicitly describe the spatiotemporal correlations in process data, we introduce a deep learning-based state estimation model that employs Convolutional Neural Networks (CNNs) for temporal modeling and utilizes a Selective State Space (SSS) for spatial modeling. To detect anomalies in the presence of noise and interference, we design a robust anomaly identification model that combines maximum deviation and threshold strategies to analyze the outputs of the state estimation model. Extensive experiments on two benchmark I CS security datasets demonstrate the effectiveness of SSAD. Ziqi Wei 0001, Fei Lv 0010, Xin Chen 0123, Shichao Lv, Limin Sun 0001 |
MSN | 4 |
| 2024 | Detecting Cyber-Attacks Against Cyber-Physical Manufacturing System: A Machining Process Invariant ApproachabstractThe era of the Industrial Internet of Things has led to an escalating menace of Cyber-Physical Manufacturing Systems (CPMS) to cyber-attacks. Presently, the field of intrusion detection for CPMS has significant advancements. However, current methodologies require significant costs for collecting historical data to train detection models, which are tailored to specific machining scenarios. Evolving machining scenarios in the real world challenge the adaptability of these methods. In this paper, We found that the machining code of the CPMS contains a complete machining process, which is an excellent detection basis. Therefore we propose MPI-CNC, an intrusion detection approach based on Machining Process Invariant in the machining code. Specifically, MPI-CNC automates the analysis of the machining codes to extract machining process rules and key parameter rules, which serve as essential detection rules. Then, MPI-CNC actively acquires runtime status from the CPMS and matches the detection rules to identify cyber-attacks behavior. MPI-CNC was evaluated using two FANUC CNC machine tools across ten real machining scenarios. The experiment demonstrated the exceptional adaptability capability of MPI-CNC. Furthermore, MPI-CNC showed superior accuracy in detecting cyber-attacks against CPMS compared to existing state-of-the-art detection methods while ensuring normal machining operations. Zedong Li, Xin Chen 0123, Yuqi Chen 0001, Hangyu Wang, Shichao Lv, Limin Sun 0001 |
IEEE Internet Things J. | 2 |
| 2024 | PowerGuard: Using Power Side-Channel Signals to Secure Motion Controllers in ICSabstractMotion control systems, extensively utilized in domains like 3D printing, CNC machining, and robotic arm operations, are pivotal in modern manufacturing and automation processes. Consequently, a specific category of attacks, designed to target these systems, can manipulate the movements of controlled objects while replaying false sensor readings to evade existing tools, thereby severely disrupting these essential operations without being detected. To make things worse, the limited computing resources of embedded devices in these systems constrain the implementation of robust security protections and monitoring mechanisms locally. To solve this, we propose a novel side-channel method that leverages current signals emitted by motors to reconstruct trajectories for attack detection. In this paper, we design and implement a two-stage detection framework, dubbed PowerGuard. In the offline learning stage, PowerGuard first captures the current signals emitted by the servo motors and models the correlation between these signals and corresponding movement trajectories. In the real-time monitoring stage, PowerGuard finds outliers that deviate from the desired trajectory described in the benign G-code file. We have evaluated PowerGuard using a typical motion control system that contains CNC machine tools from different vendors (e.g., Siemens 828D, 840D-sl, Fanuc 0i-md, 0i-tf). We conducted extensive experiments to evaluate the reconstruction accuracy and attack detection performance. Experimental results show that PowerGuard can reconstruct movement trajectories with an error of 0.047mm, and detect 93.35% of various trajectory anomalies. Yuqi Chen 0001, Xin Chen 0123, Zedong Li, Dongliang Fang, Kaixiang Liu, Shichao Lv, Limin Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | IPSpex: Enabling Efficient Fuzzing via Specification Extraction on ICS Protocol
Shichao Lv, Jianzhou You, Yuyan Sun, Xin Chen 0123, Yaowen Zheng, Limin Sun 0001 |
ACNS | 5 |
| 2022 | ShadowPLCs: A Novel Scheme for Remote Detection of Industrial Process Control AttacksabstractIndustrial Control System (ICS) security has become increasingly important as attacks targeting ICSs are more prominent. Although many off-the-shelf industrial network intrusion detection mechanisms have been presented in the past, attackers have always found unique disguisable ways to bypass detections and disrupt actual industrial control processes. To mitigate this deficiency, we present a novel scheme for the detection of industrial process control attacks, calledShadowPLCs. Specifically, the scheme first automatically analyzes the PLC control code, then extracts key parameters of the PLCs including valid register addresses, valid range of values, and control logic rules as a basis for evaluating attacks. The attack behavior is detected in real-time from different perspectives through active communication with PLCs and passive monitoring of the network traffic. We implemented a prototype system with Siemens S7-300 series PLCs as a case study. Our scheme was evaluated using two Siemens S7-300 PLCs deployed on a gas pipeline network platform. Experiments demonstrate that the presented scheme can accurately detect process control attacks in real-time without affecting the normal operations of PLCs. Compared with the other four representative detection models, our scheme has better detection performance with detection accuracy of 97.3 percent. Junjiao Liu, Xiaodong Lin 0001, Xin Chen 0123, Hui Wen 0001, Hong Li 0004, Zhiqiang Shi, Limin Sun 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | iFinger: Intrusion Detection in Industrial Control Systems via Register-Based FingerprintingabstractNowadays, the industrial control system (ICS) plays a vital role in critical infrastructures like the power grid. However, there is an increasing security concern that ICS devices are being vulnerable to malicious users/attackers, where any subtle changing or tampering attack would cause significant damage to industrial manufacturing. In this paper, we propose the iFinger, a novel detection approach designed to mitigate ICS attacks adapting to various industrial scenes. We take advantage of an important insight that industrial protocol packets include register status values that are used to reflect the physical characteristics of ICS controllers. The iFinger utilizes register states to generate ICS fingerprints to detect malicious attacks on industrial networks. Specifically, the boolean logic represents every register state sequence of the ICS controller, and the deterministic finite automaton (DFA) generates a device fingerprint. To discover the ICS attacks, we propose two detection approaches based on device fingerprints, including passive and active detection. We present a prototype of the iFinger and conduct real-world experiments to validate its performance. Results show that our approach achieves 97.1% F1 score in ICS device identification. Furthermore, we simulate two typical ICS attacks (replacement and code modification) to validate the effectiveness of our iFinger in industrial networks. Our device fingerprints would detect those malicious attacks within 2s latency at 98.0% recall. Kai Yang 0037, Qiang Li 0007, Xiaodong Lin 0001, Xin Chen 0123, Limin Sun 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2019 | SCTM: A Multi-View Detecting Approach Against Industrial Control Systems AttacksabstractOff-the-shelf machine learning based intrusion detection systems (IDS) have proved not suitable for protecting industrial control systems (ICS), as they do not consider cooperative regularities between controllers of control loops, and the serious shortage of attacking training sets. We study the consensus and complementary (2C) features which are widely observed in control loops. Subsequently, a multi-view learning framework is proposed to boost the effectiveness of detecting attacks on ICS by using a large number of unlabeled examples with 2C features. Comprehensive attacks of ICS are designed and implemented on a physical testbed, and the experimental data are collected from the historical sequences and IDS alerts. The experimental results demonstrate that the framework is highly adaptive, and it can rapidly match the dynamics of ICS operating environment. Meanwhile, the effectiveness of the method is discussed when parameters take different values, and it exhibits low false-positive rates but high precision. In addition, the case of error propagation of the framework is analyzed. Ming Zhou 0010, Shichao Lv, Libo Yin, Xin Chen 0123, Hong Li 0004, Limin Sun 0001 |
ICC | 4 |