Binbin Chen 0001

dblp:38/8396-1 · also Bin Bin Chen 0001 · DBLP profile ↗
← Back
69ranked-venue papers
14as first author
35since 2021 · last 2026
0000-0002-9584-0082ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 33 · 7 first-author · 20 since 2021Security and privacy · 15 · 2 first-author · 6 since 2021Systems, architecture and hardware · 8 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 6 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 In-RAN Spectrum Sensing on a 5G AI-RAN Testbed with Uplink Signal Isolation
Tuan V. Ngo, Thanh-Tam Nguyen, Mao V. Ngo, Binbin Chen 0001, Tony Q. S. Quek
INFOCOM4
2026 SLA-Aware Distributed LLM Inference Across Device-RAN-Cloud
Hariz Yet, Nguyen Thanh Tam, Mao V. Ngo, Lim Yi Shen, Jihong Park, Binbin Chen 0001, Tony Q. S. Quek
INFOCOM7
2026 Assuring Service Level Agreements in Open Radio Access Networks: An End-to-End System Design
Yufan He, Tuan V. Ngo, Mao V. Ngo, Binbin Chen 0001, Tony Q. S. Quek, Howard H. Yang
WiOpt4
2026 StreamFP: Fingerprint-guided Data Selection for Efficient Stream Learning
Changwu Li, Tongjun Shi, Shuhao Zhang 0001, Binbin Chen 0001, Bingsheng He, Xiaofei Liao, Hai Jin 0001
WWW4
2026 FlexSatIoE: Flexible Routing and Buffering for Satellite Networks Enabled Internet of Everything Applications
abstract
The rapid advancement of the satellite industry offers unprecedented opportunities for enabling Internet of Everything (IoE) applications over satellite networks. A key characteristic of such applications is that computation cannot begin until the entire application data has been fully received at the destination. To meet strict end-to-end delay constraints, minimizing the total application delay is essential. However, this requirement violates the optimal substructure property commonly assumed in traditional shortest path routing problems. Existing routing solutions often overlook these unique computation constraints and rely on substructure-preserving heuristics, resulting in suboptimal delay performance. Moreover, they lack reliability in producing delay-guaranteed routing solutions, which leads to low task completion ratios under stringent application deadlines. To overcome this problem, we propose FlexSatIoEa routing scheme that allows for flexible buffering data over satellite networks. FlexSatIoE formulates this routing problem as an integer linear programming (ILP) problem, to provide the optimal solution. As the network scales, considering the computational intractability of ILP, FlexSatIoE further modifies the storage time-aggregated graph to comprehensively model the satellite networks’ compute, storage and transmission resources. Based on the graph extension, FlexSatIoE designs an efficient routing algorithm, enabling flexible use of buffer resources by using a flow reassignment mechanism. We conduct extensive experiments over the setting of real-world satellite networks. The results show that FlexSatIoE reduces the average delay and increases the number of completed tasks by up to 50% and 40% respectively, as compared to the existing schemes, demonstrating the superior capability and reliability of FlexSatIoE in ensuring deterministic application delays.
Peng Wang 0044, Suman Sourav, Binbin Chen 0001, Hongyan Li 0001
IEEE Internet Things J.3
2026 Game-Theory-Based Optimal Defense for Cyberspace Attacks in Industrial Cyber-Physical Systems With Information Uncertainties
abstract
When applying the game-theoretic approach to find the optimal strategy for industrial cyber-physical systems defenders, most existing work assumes both the system states (e.g., for a power grid system, the system state captures which buses are compromised) and the attacker’s instant actions are observable and can be used to make the decision for the defender’s next move. Also, the reward and expected utilities are calculated based on the most likely system state and attack action. However, there is uncertainty in determining the system state and attack actions as the attack unfolds in the system in practice. This work shows that such an approximation is non-optimal in determining the defense strategy. Instead, we propose a framework that models the uncertainty in the system state and attack action. We derive the defender’s optimal strategy under such uncertainty by calculating the expected utilities across different action spaces and redefining the immediate reward within the deep learning algorithm based on the expected utilities and our estimation of the probabilistic distribution of the system state and attack action, ultimately employing the agent system for learning and generating the optimal defense strategy. The simulation experiments are carried out based on the generic industrial cyber-physical system testbed and the numerical results confirmed that the proposed solution can improve the defender’s expected utilities by 38.8% compared to the state-of-the-art.
Bingjing Yan, Binbin Chen 0001, Tao Yang 0043, Pengchao Yao, Qiang Yang 0004
IEEE Internet Things J.2
2026 On-Demand Mixed-Timescale Scheduling for Sensing, Communication, Computation, and Control in Air-Ground Cooperative Perception
abstract
In vehicular cooperative perception (CP), numerous resource allocation strategies have been proposed to enhance urban autonomous driving. However, existing studies often overlook the competition between self-perception and cooperative perception, where degrading a ground vehicle's (GV's) self-perception may introduce safety risks and reduce passenger comfort. Moreover, UAV–GV cooperation—which can improve sensing precision, reduce task execution delay, and enhance CP service availability—has received limited attention. It is worth noting that unmanned aerial vehicles (UAVs) are unavailable for cooperative perception during the recharging process. To address these issues, this paper investigates on-demand scheduling strategy in UAV–GV cooperative perception. At the millisecond timescale, resource competition is considered in real-time sensing, communication, and computation (SC2) resource allocation. At the minute timescale, the idle flying period between consecutive tasks is utilized for UAV recharging through attachment to GVs along the route. Specifically, we first develop a model that captures the mutual influence between UAVs and GVs on perception performance under resource constraints. Then, a mixed-timescale solution is proposed: at the small timescale, a multi-agent deep reinforcement learning (MA-DRL) algorithm with gradient-free projection and auxiliary supervision is designed to schedule SC2resources; at the large timescale, a Hungarian-based algorithm is employed to control UAV recharging. Simulation results show that the proposed approach outperforms benchmark schemes by reducing task execution delay and energy consumption, and enhancing CP service availability, while satisfying sensing precision, GV safety, and passenger comfort requirements.
Mengqiu Tian, Changle Li, Yilong Hui, PengCheng Wei, Binbin Chen 0001, Zhu Han 0001
IEEE Trans. Mob. Comput.5
2026 An SFC-Constrained Max-Flow Solver for Satellite Networks Using Flexible Function-Time Expanded Graph
Peng Wang 0044, Suman Sourav, Binbin Chen 0001, Hongyan Li 0001
IEEE Trans. Mob. Comput.3
2025 Adaptive AI Model Partitioning over 5G Networks
abstract
Mobile devices increasingly rely on deep neural networks (DNNs) for complex inference tasks, but running entire models locally drains the device battery quickly. Offloading computation entirely to cloud or edge servers reduces processing load at devices but poses privacy risks and can incur high network bandwidth consumption and long delays. Split computing (SC) mitigates these challenges by partitioning DNNs between user equipment (UE) and edge servers. However, 5G wireless channels are time-varying and a fixed splitting scheme can lead to sub-optimal solutions. This paper addresses the limitations of fixed model partitioning in privacy-focused image processing and explores trade-offs in key performance metrics, including end-to-end (E2E) latency, energy consumption, and privacy, by developing an adaptive ML partitioning scheme based on realtime AI-powered throughput estimation. Evaluation in multiple scenarios demonstrates significant performance gains of our scheme.
Tam Thanh Nguyen, Tuan V. Ngo, Long Thanh Le, Yong-Hao Pua, Mao V. Ngo, Binbin Chen 0001, Tony Q. S. Quek
GLOBECOM6
2025 Accelerating Privacy-Preserving Federated Learning in Large-Scale LEO Satellite Systems
abstract
Large-scale low-Earth-orbit (LEO) satellite systems are increasingly valued for their ability to enable rapid and wide-area data exchange, thereby facilitating the collaborative training of artificial intelligence (AI) models across geographically distributed regions. Due to privacy concerns and regulatory constraints, raw data collected at remote clients cannot be centrally aggregated, posing a major obstacle to traditional AI training methods. Federated learning offers a privacy-preserving alternative by training local models on distributed devices and exchanging only model parameters. However, the dynamic topology and limited bandwidth of satellite systems will hinder timely parameter aggregation and distribution, resulting in prolonged training times. To address this challenge, we investigate the problem of scheduling federated learning over satellite networks and identify key bottle-necks that impact the overall duration of each training round. We propose a discrete temporal graph–based on-demand scheduling framework that dynamically allocates communication resources to accelerate federated learning. Simulation results demonstrate that the proposed approach achieves significant performance gains over traditional statistical multiplexing-based model exchange strategies, reducing overall round times by 14.20% to 41.48%. Moreover, the acceleration effect becomes more pronounced for larger models and higher numbers of clients, highlighting the scalability of the proposed approach.
Binquan Guo, Junteng Cao, Marie Siew, Binbin Chen 0001, Tony Q. S. Quek, Zhu Han 0001
TrustCom4
2025 TSAE: A Service Availability Evaluation Method for IIoT Under Dynamic Recovery
abstract
Service availability (SA) is essential for maintaining productivity and operational continuity in Industrial Internet of Things (IIoT) systems. However, accurately evaluating availability is challenging due to the complexity of dynamic recovery techniques integrated failure detection, localization, and rerouting restoration. These processes involve state-dependent behaviors and interactions across multiple network layers, making it difficult to pre-enumerate all recovery paths before failures occur. Thus, it is crucial to develop availability models that account for the dynamic coupling between service failure and recovery factors to achieve more accurate evaluations. To address this, we propose a novel two-stage state-transition availability evaluation method (TSAE) to quantify dynamic service availability in IIoT systems. In the first stage, fault conditions of network components and service mapping states are sampled to identify events that lead to service outages. In the second stage, a set of transition rules is defined to model the complex interactions between components and services during dynamic recovery processes. The effectiveness and accuracy of the proposed method are validated using two typical network scenarios. Extensive sensitivity experiments on a large-scale network case, considering factors, such as recovery priority, resource demand-supply ratio, and recovery performance, reveal key availability bottlenecks under various deployment configurations. Furthermore, tradeoffs between global and local recovery strategies under varying failure conditions are discussed, providing insights for network designer to select options that balance service continuity and resource efficiency.
Zhiwei Yi, Ning Huang 0004, Zekun Song, Binbin Chen 0001
IEEE Internet Things J.5
2025 Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing
abstract
With the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multi-path routing phenomenon that exists in practice. In this paper, we reveal practical challenges in the context of enabling line-speed model inference in the network dataplane. Furthermore, we propose FCPlane, the forwarding and computing integrated dataplane for zero-trust intrusion detection that aims to enable efficient load balancing while providing reliable traffic analysis results, even against multipath routing. The core idea is to reconcile forwarding and computation to the flowlet level, for which a tailor-made Markov chain model is designed. Based on two public traffic datasets, we evaluate seven state-of-the-art in-network traffic analysis models deployed in four types of topologies (three with multipath routing and one without) to explore performance impact and demonstrate the effectiveness of our proposal.
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Tingting Li 0004, Jiongchi Yu, Fan Zhang 0010, Binbin Chen 0001
IEEE J. Sel. Areas Commun.8
2025 SRLR: Symbolic Regression-Based Logic Recovery to Counter Programmable Logic Controller Attacks
abstract
Programmable Logic Controllers (PLCs) are critical components in Industrial Control Systems (ICSs). Their potential exposure to external world makes them susceptible to cyber-attacks. Existing detection methods against controller logic attacks use either specification-based or learnt models. However, specification-based models require experts’ manual efforts or access to PLC’s source code, while machine learning-based models often fall short of providing explanation for their decisions. We designSRLR— aSymbolic Regression based Logic Recoverysolution to identify the logic of a PLC based only on its inputs and outputs. The recovered logic is used to generate explainable rules for detecting controller logic attacks. SRLR enhances the latest deep symbolic regression methods using the following ICS-specific properties: (1) some important ICS control logic is best represented in frequency domain rather than time domain; (2) an ICS controller can operate in multiple modes, each using different logic, where mode switches usually do not happen frequently; (3) a robust controller usually filters out outlier inputs as ICS sensor data can be noisy; and (4) with the above factors captured, the degree of complexity of the formulas is reduced, making effective search possible. Thanks to these enhancements,SRLRconsistently outperforms all existing methods in a variety of ICS settings that we evaluate. In terms of the recovery accuracy,SRLR’s gain can be as high as 39% in some challenging environment. We also evaluateSRLRon a distribution grid containing hundreds of voltage regulators, demonstrating its stability in handling large-scale, complex systems with varied configurations.
Hao Zhou 0032, Suman Sourav, Binbin Chen 0001, Ke Yu 0001
IEEE Trans. Inf. Forensics Secur.3
2024 DDoSMiner: An Automated Framework for DDoS Attack Characterization and Vulnerability Mining
Xi Ling, Jiongchi Yu, Ziming Zhao 0008, Haitao Xu 0002, Binbin Chen 0001, Fan Zhang 0010
ACNS (2)6
2024 Enhancing Data Processing Throughput in IoT-Edge-Cloud Systems Using Optimized Task Placement
abstract
The rapid growth of Internet-of- Things (IoT) systems demands higher throughput to process sensor data. Existing data processing platforms use simple heuristics for task placement, which perform poorly. We proposed a Permutation-based Task Placement Optimizer (PTPO) that constructs a set of valid task placement permutations to formulate a mixed-integer linear programming problem. PTPO enables efficient real-time task placement for multiple dynamic applications. Our study highlights three key design factors: joint consideration of compute and network constraints, accurate profiling of resource needs, and fine-grained splitting of tasks across nodes. We demonstrate more than 80% throughput gain compared to state-of-the-art schemes using real-world IoT Applications.
Vishal Choudhary, Peng Wang 0044, Suman Sourav, Binbin Chen 0001
ICDCS4
2024 RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed Approaches
abstract
Existing Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network deployment. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., ~99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency.
Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 0010, Binbin Chen 0001
INFOCOM5
2024 Consistent and Repeatable Testing of O-RAN Distributed Unit (O-DU) across Continents
abstract
Open Radio Access Networks (O-RAN) are expected to revolutionize the telecommunications industry with benefits like cost reduction, vendor diversity, and improved network performance through AI optimization. Supporting the O-RAN ALLIANCE’s mission to achieve more intelligent, open, virtualized and fully interoperable mobile networks, O-RAN Open Testing and Integration Centers (OTICs) play a key role in accelerating the adoption of O-RAN specifications based on rigorous testing and validation. One theme in the recent O-RAN Global PlugFest Spring 2024 focused on demonstrating consistent and repeatable Open Fronthaul testing in multiple labs. To respond to this topic, in this paper, we present a detailed analysis of the testing methodologies and results for O-RAN Distributed Unit (O-DU) in O-RAN across two OTICs. We identify key differences in testing setups, share challenges encountered, and propose best practices for achieving repeatable and consistent testing results. Our findings highlight the impact of different deployment technologies and testing environments on performance and conformance testing outcomes, providing valuable insights for future O-RAN implementations.
Tuan V. Ngo, Mao V. Ngo, Binbin Chen 0001, Gabriele Gemmi, Eduardo Baena, Michele Polese, Tommaso Melodia, William Chien, Tony Q. S. Quek
VTC Fall3
2024 Consistent and Repeatable Testing of mMIMO O-RU across labs: A Japan-Singapore Experience
abstract
Open Radio Access Networks (RAN) aim to bring a paradigm shift to telecommunications industry, by enabling an open, intelligent, virtualized, and multi-vendor interoperable RAN ecosystem. At the center of this movement, O-RAN ALLIANCE defines the O-RAN architecture and standards, so that companies around the globe can use these specifications to create innovative and interoperable solutions. To accelerate the adoption of O-RAN products, rigorous testing of O-RAN Radio Unit (O-RU) and other O-RAN products plays a key role. O-RAN ALLIANCE has approved around 20 Open Testing and Integration Centres (OTICs) globally. OTICs serve as vendor-neutral platforms for providing the testing and integration services, with the vision that an O-RAN product certified in any OTIC is accepted in other parts of the world. To demonstrate the viability of such a certified-once-and-use-everywhere approach, one theme in the O-RAN Global PlugFest Spring 2024 is to demonstrate consistent and repeatable testing for the open fronthaul interface across multiple labs. Towards this, Japan OTIC and Asia Pacific OTIC in Singapore have teamed up together with an O-RU vendor and Keysight Technology. Our international team successfully completed all test cases defined by O-RAN ALLIANCE for O-RU conformance testing. In this paper, we share our journey in achieving this outcome, focusing on the challenges we have overcome and the lessons we have learned through this process.
Thanh-Tam Nguyen, Mao V. Ngo, Binbin Chen 0001, Mitsuhiro Kuchitsu, Serena Wai, Seitaro Kawai, Kenya Suzuki, Eng Wei Koo, Tony Q. S. Quek
VTC Fall3
2024 Graph Convolution Network Based State Space Model for Wireless Traffic Prediction
abstract
With the rapid advancement of communication networks, wireless traffic prediction plays a pivotal role in resource allocation and energy management. However, due to the complex spatio-temporal characteristics inherent in real-world traffic data, capturing its intrinsic features accurately has proven to be challenging, leading to unsatisfactory prediction accuracy. In this paper, we propose a Graph Convolution Network based State Space Model (GSSM) aimed at predicting call detail records wireless traffic. We utilize both fixed and adaptive weighted matrices to learn the complex spatial dependencies among base stations. The graph convolution network is conducted to accurately estimate the parameters of the state space model. Additionally, we employ a mixture Gaussian hypothesis to provide more flexibility for the state space model when predicting traffic data. Our experimental results demonstrate that the proposed method outperforms the baseline methods. Furthermore, we conduct extensive visualization, ablation and parameter analysis experiments to confirm the effectiveness of our proposed approach.
Hao Zhou 0032, Dunyuan Yao, Binbin Chen 0001, Ke Yu 0001
WCNC3
2024 HoneyJudge: A PLC Honeypot Identification Framework Based on Device Memory Testing
abstract
The widespread use of programmable logic controllers (PLCs) in critical infrastructures has given rise to escalating cybersecurity concerns regarding PLC attacks. As a proactive defense mechanism, PLC honeypots emulate genuine controllers to engage adversaries so as to observe their attack tactics and techniques. As part of the arms race between the offense and defense, multiple PLC honeypot identification tools have been developed. However, many existing tools cannot recognize high-fidelity honeypots, since they rely on identifying common network services and fingerprints. In this paper, we propose an innovative and practical honeypot identification framework calledHoneyJudge, which goes beyond state-of-the-art (SOTA) network fingerprint-based identification tools like Nmap and the PLCScan tool.HoneyJudgetests the suspected target’s special memory content and features. Specifically,HoneyJudgemodels the internal memory of a PLC in three categories, from system-level, user-level, to process-level categories, based on which it extracts six representative memory features. All characteristics are acquired through automated network request messages. Then, we design a weighted voting algorithm to combine the test results over different memory features to reach the final conclusion. We validate the effectiveness ofHoneyJudgein comparison with several SOTA honeypot identification tools, and the results indicate that the memory-related issues have not been well addressed in existing PLC honeypots and still need substantial research efforts.
Hengye Zhu, Mengxiang Liu, Binbin Chen 0001, Peng Cheng 0001, Ruilong Deng
IEEE Trans. Inf. Forensics Secur.3
2024 CMD: Co-Analyzed IoT Malware Detection and Forensics via Network and Hardware Domains
abstract
With the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. Existing approaches can be roughly categorized into network-side and host-side. However, existing network-side methods are difficult to capture contextual semantics from cross-source traffic, and previous host-side methods could be adversary-perceived and expose risks for tampering. More importantly, a single perspective cannot comprehensively track the multi-stage lifecycle of IoT malware. In this paper, we present${\sf CMD}$, a co-analyzed IoT malware detection and forensics system by combining hardware and network domains. For the network part,${\sf CMD}$proposes a tailored capsule neural network to capture the contextual semantics from cross-source traffic. For the hardware part,${\sf CMD}$designs an entire file operation recovery process in a side-channel manner by leveraging the Serial Peripheral Interface (SPI) signals from on-chip traces. These traffic provenance and operating logs information could benefit the anti-virus countermeasures for security practitioners. By practical evaluation, we demonstrate that${\sf CMD}$realizes outstanding detection effects (e.g.,$\sim$99.88% F1-score) compared with seven state-of-the-art methods, and recovers 96.88%$\sim$99.75% operation commands even if against adaptive adversaries (that could kill processes or tamper with operation log files). A by-product benefit of such an external monitor is${\sf CMD}$introduces zero latency on the IoT device, and incurs negligible IoT CPU utilization. Also, since SPI focuses on file operations, the proposed hardware trace forensics does not have the data explosion problem like previous work,e.g.,recovered logs of${\sf CMD}$only take up limited extra space overhead (e.g.,$\sim$0.2 MB per malware). Furthermore, we provide the model interpretability for the capsule network and develop a case study (Hajime) of the operation logs recovery.
Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Xiaofei Xie, Haitao Xu 0002, Binbin Chen 0001
IEEE Trans. Mob. Comput.7
2024 FOSS: Towards Fine-Grained Unknown Class Detection Against the Open-Set Attack Spectrum With Variable Legitimate Traffic
abstract
Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. By analyzing the popular dataset of network intrusion traces, we show that FOSS significantly outperforms the state-of-the-art methods. Further, we perform an initial deployment of FOSS by working with the Internet Service Provider (ISP) to detect distributed denial of service (DDoS) attacks. With real-world tests and manual analysis, we demonstrate the effectiveness of FOSS to identify previously-unseen attacks in a fine-grained manner.
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang 0010, Rui Zhang 0016, Binbin Chen 0001, Xiangyang Luo 0001, Ming Hu 0003, Wenrui Ma
IEEE/ACM Trans. Netw.7
2024 An Intelligent Coexistence Strategy for eMBB/URLLC Traffic in Multi-UAV Relay Networks via Deep Reinforcement Learning
abstract
Preemptive scheduling efficiently addresses the coexistence of enhanced Mobile Broad Band (eMBB) and Ultra-Reliable Low-Latency Communications (URLLC). While URLLC puncturing influences eMBB performance, further investigation is necessary to study the trade-offs between stability, delay, and efficiency. However, existing studies overlook the imbalance in eMBB/URLLC load distribution and personalized fluctuations in eMBB performance, leading to sub-optimal results. To tackle this, we propose an unmanned aerial vehicle (UAV) relay-assisted eMBB/URLLC multiplexing framework. Specifically, considering the utilization of UAVs for connecting separated next-generation Node Bs (gNBs) and the individual subject experience of services, we first formulate the multiplexing problem as an optimization problem. The objective is to maximize eMBB throughput and minimize personalized fluctuations in eMBB performance and UAV consumption, subject to URLLC constraints. Then, the challenging problem is decomposed into the eMBB problem and the URLLC problem. For the former, we further decompose it into three sub-problems and solve them using optimization methods. For the latter, we propose a deep reinforcement learning-based algorithm to obtain an optimal strategy for relaying and puncturing URLLC into eMBB intelligently. Simulation results demonstrate that our proposals outperform benchmark schemes regarding eMBB throughput, UAV consumption, eMBB performance fluctuation, URLLC satisfaction, and learning efficiency.
Mengqiu Tian, Changle Li, Yilong Hui, Binbin Chen 0001, Wenwei Yue, Yuchuan Fu, Zhu Han 0001
IEEE Trans. Wirel. Commun.4
2023 DNAttest: Digital-twin-based Non-intrusive Attestation under Transient Uncertainty
abstract
Programmable logic controllers (PLCs) are vulnerable to malware, which is a key security risk for Industrial Control Systems (ICSs). Existing attestation solutions are invasive because they require hardware security modules and software upgrades in legacy devices. We propose DNAttest, a Digital-twin-based Noninvasive Attestation solution to attest PLC behaviors in near-real time. DNAttest requires minimal ICS infrastructure changes and does not interfere with normal ICS operations. DNAttest detects PLC deviations by replicating all input messages for a PLC to its digital twin and comparing their output messages. Due to transient uncertainty in the PLC's internal processing state, DNAttest may output an incorrect comparison. To generate all plausible output values for comparison, we instantiate multiple emulated PLCs by replicating input messages with different timing profiles. We demonstrate on a close-to-real-world power grid testbed that DNAttest can provide a timely detection of a wide range of attacks non-invasively and accurately. DNAttest solution is lightweight and scalable. A typical desktop PC can attest more than 20 actual PLCs even if we use 10 emulators to monitor every actual PLC.
Heng Chuan Tan, Binbin Chen 0001, Fan Zhang 0010
DSN3
2023 Machine Learning Assisted Bad Data Detection for High-Throughput Substation Communication
abstract
Electrical substations are becoming more prone to cyber-attacks due to increasing digitalization. Prevailing defence measures based on cyber rules are often inadequate to detect attacks that use legitimate-looking measurements. In this work, we design and implement a bad data detection solution for electrical substations called ResiGate, that effectively combines a physics-based approach and a machine-learning-based approach to provide substantial speed-up in high-throughput substation communication scenarios, while still maintaining high detection accuracy and confidence. While many existing physics-based schemes are designed for deployment in control centers (due to their high computational requirement), ResiGate is designed as a security appliance that can be deployed on low-cost industrial computers at the edge of the smart grid so that it can detect local substation-level attacks in a timely manner. A key challenge for this is to continuously run the computationally demanding physics-based analysis to monitor the measurement data frequently transmitted in a typical substation. To provide high throughput without sacrificing accuracy, ResiGate uses machine learning to effectively filter out most of the non-suspicious (normal) data and thereby reducing the overall computational load, allowing efficient performance even with a high volume of network traffic. We implement ResiGate on a low-cost industrial computer and our experiments confirm that ResiGate can detect attacks with zero error while sustaining a high throughput.
Suman Sourav, Partha P. Biswas, Vyshnavi Mohanraj, Binbin Chen 0001, Daisuke Mashima
ICC4
2023 One Pass is Sufficient: A Solver for Minimizing Data Delivery Time over Time-varying Networks
abstract
How to allocate network paths and their resources to minimize the delivery time of data transfer tasks over time-varying networks? Solving this MDDT (Minimizing Data Delivery Time) problem has important applications from data centers to delay-tolerant networking. In particular, with the rapid deployment of satellite networks in recent years, an efficient MDDT solver will serve as a key building block there.The MDDT problem can be solved in polynomial time by finding the maximum flow in a time-expanded graph. A binary-search-based solver incurs O(N•log N•Γ) time complexity, where N corresponds to time horizon and Γ is the time complexity to solve a maximum flow problem for one snapshot of the network. In this work, we design a one-pass solver that progressively expands the graph over time until it reaches the earliest time interval n to complete the delivery. By reusing the calculated maximum flow results from earlier iterations, it solves the MDDT problem while incurring only O(nΓ) time complexity for algorithms that can apply our technique. We apply the one-pass design to Ford-Fulkerson algorithm and evaluate our solver using a network of 184 satellites from Starlink constellations. We demonstrate >75× speed-up in the running time and show that our solution can also enable advanced applications such as preemptive scheduling.
Peng Wang 0044, Suman Sourav, Hongyan Li 0001, Binbin Chen 0001
INFOCOM4
2023 CyberSAGE: The cyber security argument graph evaluation tool
William G. Temple, Carmen Cheh, Binbin Chen 0001, Zbigniew T. Kalbarczyk, William H. Sanders, David M. Nicol
Empir. Softw. Eng.5
2023 Message Authentication and Provenance Verification for Industrial Control Systems
abstract
Successful attacks against industrial control systems (ICSs) often exploit insufficient checking mechanisms. While firewalls, intrusion detection systems, and similar appliances introduce essential checks, their efficacy depends on the attackers’ ability to bypass such middleboxes. We propose a provenance solution to enable the verification of an end-to-end message delivery path and the actions performed on a message. Fast and flexible provenance verification (F2-Pro) provides cryptographically verifiable evidence that a message has originated from a legitimate source and gone through the necessary checks before reaching its destination. F2-Prorelies on lightweight cryptographic primitives and flexibly supports various communication settings and protocols encountered in ICS thanks to its transparent, bump-in-the-wire design. We provide formal definitions and cryptographically prove F2-Pro’s security. For human interaction with ICS via a field service device, F2-Profeatures a multi-factor authentication mechanism that starts the provenance chain from a human user issuing commands. We compatibility tested F2-Proon a smart power grid testbed and reported a sub-millisecond latency overhead per communication hop using a modest ARM Cortex-A15 processor.
Ertem Esiner, Utku Tefek, Daisuke Mashima, Binbin Chen 0001, Zbigniew T. Kalbarczyk, David M. Nicol
ACM Trans. Cyber Phys. Syst.4
2023 Constructing Cyber-Physical System Testing Suites Using Active Sensor Fuzzing
abstract
Cyber-physical systems (CPSs) automating critical public infrastructure face a pervasive threat of attack, motivating research into different types of countermeasures. Assessing the effectiveness of these countermeasures is challenging, however, as benchmarks are difficult to construct manually, existing automated testing solutions often make unrealistic assumptions, and blindly fuzzing is ineffective at finding attacks due to the enormous search spaces and resource requirements. In this work, we proposeactive sensor fuzzing, a fully automated approach for building test suites without requiring anya priorknowledge about a CPS. Our approach employs active learning techniques. Applied to a real-world water treatment system, our approach manages to find attacks that drive the system into 15 different unsafe states involving water flow, pressure, and tank levels, including nine that were not covered by an established attack benchmark. Furthermore, we successfully generate targeted multi-point attacks which have been long suspected to be possible. We reveal that active sensor fuzzing successfully extends the attack benchmarks generated by our previous work, an ML-guided fuzzing tool, with two more kinds of attacks. Finally, we investigate the impact of active learning on models and the reason that the model trained with active learning is able to discover more attacks.
Fan Zhang 0010, Qianmei Wu, Bohan Xuan, Yuqi Chen 0001, Christopher M. Poskitt, Jun Sun 0001, Binbin Chen 0001
IEEE Trans. Software Eng.8
2022 From Hindsight to Foresight: Enhancing Design Artifacts for Business Logic Flaw Discovery
abstract
Web applications have encroached on our lives, handling important tasks and sensitive information. There are many tools that check application code for implementation-level vulnerabilities but they are often blind to flaws caused by violation of design-level assumptions. Fixing such flaws after code deployment is costly. In this work, we seek to retroactively identify business logic flaws or design-level flaws by generating security tests during the design phase using available software artifacts. Specifically, we take in use case scenarios and automatically generate misuse case scenarios based on user-defined design constraints. By running those misuse case scenarios using already existing testing code written for functional use cases, we can discover potential design flaws during the coding phase. We apply our approach to two widely used open-source applications which have high-quality feature files. Running our generated misuse case scenarios discovers, and hence, potentially prevents seven flaws. Among them, several were only fixed in hindsight after someone stumbled upon a bug, with the remaining being new issues.
Carmen Cheh, Nicholas Tay, Binbin Chen 0001
ACSAC3
2022 FL-Task-aware Routing and Resource Reservation over Satellite Networks
abstract
Earth observation satellites using asynchronous ground-assisted federated learning (FL) can avoid transmitting massive raw image data to ground. However, current FL approach uses only satellite-to-ground-station links, causing long delay for model parameter transfer. A promising direction to reduce delay is to use inter-satellite links. We identify that ground-assisted asynchronous FL requires a satellite to send all data of its model parameter to ground before ground station can start to update the model. This new feature prevents current routing algorithms (e.g., CGR) from being applicable. Therefore, we propose an FL task-aware routing and resource reservation (FLRRS) scheme to optimize the delay of FL model parameter transfer. First, we formulate the problem as an integer linear programming (ILP) problem, which is non-convex and intractable. Thus, we enhance the storage time-aggregated graph to model computing, storage and transmission resources of satellite network, and propose a graph-based routing and resource reservation algorithm. The numerical simulation based on a real-world satellite network shows that FLRRS runs much faster than CVXPY solver. Besides, FLRRS also significantly improves average delay and number of completed tasks, as compared to current routing algorithms.
Peng Wang 0044, Hongyan Li 0001, Binbin Chen 0001
GLOBECOM3
2022 CoToRu: Automatic Generation of Network Intrusion Detection Rules from Code
abstract
Programmable Logic Controllers (PLCs) are the brains of Industrial Control Systems (ICSes), and thus, are often targeted by attackers. While many intrusion detection systems (IDSes) have been adapted to monitor ICS, they cannot detect malicious network packets from a compromised PLC that con-form to the network protocol. A domain expert needs to manually construct IDS rules to model a PLC’s behavior. That approach is time-consuming and error-prone. Alternatively, machine learning can infer a PLC’s behavior model from network traces, but that model may be inaccurate due to a lack of high-quality training data. This paper presents CoToRu - a toolchain that takes in the PLC’s code to automatically generate a comprehensive set of IDS rules. CoToRu comprises (1) an analyzer that parses PLC code to build a state transition table for modeling the PLC’s behavior, and (2) a generator that instantiates IDS rules for detecting deviations in PLC behavior. The generated rules can be imported into Zeek IDS to detect various attacks. We apply CoToRu to a power grid testbed and show that our generated rules provide superior performance compared to existing IDSes, including those based on statistical analysis, invariant-checking, and machine learning. Our prototype with CoToRu’s generated rules provide sub-millisecond detection latency, even for complex PLC logic.
Heng Chuan Tan, Carmen Cheh, Binbin Chen 0001
INFOCOM3
2022 Caching-based Multicast Message Authentication in Time-critical Industrial Control Systems
abstract
Attacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and communication overhead, C(M)MA eliminates all cryptographic operations for the source after the message is given, and all expensive cryptographic operations for the destinations after the message is received. C(M)MA considers the urgency profile (or likelihood) of a set of future messages for even faster verification of the most time-critical (or likely) messages. We demonstrate the feasibility of C(M)MA in an ICS setting based on a substation automation system in smart grids.
Utku Tefek, Ertem Esiner, Daisuke Mashima, Binbin Chen 0001, Yih-Chun Hu
INFOCOM4
2022 Enhancing Earth Observation Throughput Using Inter-Satellite Communication
abstract
Earth observation systems play important roles in many critical applications. The rapid increase of the number of satellites and their sensing capability, however, makes it challenging to send the massive amount of observed data back to the Earth. One promising direction to enhance the earth observation throughput is to use inter-satellite communication. Towards this, we identify two key design factors: 1) the capability to support on-demand scheduling of inter-satellite communication; and 2) the capability to co-optimize the scheduling of observation and transmission missions. For both, rigorous study is needed to determine whether they provide sufficient throughput gain to justify their additional complexity. Our work formulates a generic earth observation and transmission problem to study the maximum network throughput under different settings. By succinctly modeling the different constraints using a generalized time-varying graph representation, we can efficiently find the optimal scheduling solutions. We conduct an extensive study, which shows that using 40 relay satellites from the “starlink” constellation can increase the throughput of 10 sensing satellites from the “Gaofen” constellation by more than 400%. In particular, on-demand scheduling under heavy load and co-optimization of observation/transmission under light but time-critical load can improve the throughput by more than 180% and 100%, respectively.
Peng Wang 0044, Hongyan Li 0001, Binbin Chen 0001, Shun Zhang 0003
IEEE Trans. Wirel. Commun.3
2021 Sublinear-Time Non-Adaptive Group Testing With O(k log n) Tests via Bit-Mixing Coding
abstract
The group testing problem consists of determining a small set of defective items from a larger set of items based on tests on groups of items, and is relevant in applications such as medical testing, communication protocols, pattern matching, and many more. While rigorous group testing algorithms have long been known with runtime at least linear in the number of items, a recent line of works has sought to reduce the runtime to poly(k log n), where n is the number of items and k is the number of defectives. In this paper, we present such an algorithm for non-adaptive group testing termed bit mixing coding (BMC), which builds on techniques that encode item indices in the test matrix, while incorporating novel ideas based on erasure-correction coding. We show that BMC achieves asymptotically vanishing error probability with O(k log n) tests and O(k2· log k · log n) runtime, in the limit as n → ∞ (with k having an arbitrary dependence on n). This closes an open problem of simultaneously achieving poly(k log n) decoding time using O(k log n) tests without any assumptions on k. In addition, we show that the same scaling laws can be attained in a commonly-considered noisy setting, in which each test outcome is flipped with constant probability.
Steffen Bondorf, Binbin Chen 0001, Jonathan Scarlett, Yuda Zhao
IEEE Trans. Inf. Theory2
2020 Identifying Failing Point Machines from Sensor-Free Train System Logs
abstract
A great many train systems worldwide are legacy systems, without modern sensors whose data can be mined to detect and predict failures. In this paper, we show how to support failure identification in a legacy system with no sensors, using alarm and natural-language described event logs as the only data sources. With too few failures in a mass of log data to train a traditional machine learning model, we propose a new approach called SA-HMM (Survival Analysis-Hidden Markov Model). After enriching the event logs with Word2vec, SA-HMM uses HMMs and survival analysis to identify failure trends in individual assets and failure tendencies in types of assets, respectively, then combines the two part in a weighted sum that indicates the priority of each asset for preventative maintenance. Our evaluation of SA-HMM with a large amount of urban train data shows that SA-HMM greatly outperforms naive method, HMM, and one-class SVM methods in terms of precision and recall in identifying failing assets, while also offering a tunable balance between those two aspects of performance.
Xin Lou 0005, Binbin Chen 0001, Marianne Winslett, Zbigniew T. Kalbarczyk
IEEE BigData3
2020 Modeling Adversarial Physical Movement in a Railway Station: Classification and Metrics
abstract
Many real-world attacks on cyber-physical systems involve physical intrusions that directly cause damage or facilitate cyber attacks. Hence, in this work, we investigate the security risk of organizations with respect to different adversarial models of physical movement behavior. We study the case in which an intrusion detection mechanism is in place to alert the system administrator when users deviate from their normal movement behavior. We then analyze how different user behaviors may present themselves as different levels of threats in terms of their normal movement behavior within a given building topology. To quantify the differences in movement behavior, we define a WeightTopo metric that takes into account the building topology in addition to the movement pattern. We demonstrate our approach on a railway system case study and show how certain user roles, when abused by attackers, are especially vulnerable in terms of the physical intrusion detection probability. We also evaluate quantitatively how the similarity between an attacker’s movement behavior and a user’s movement behavior affects the detection probability of the evaluated intrusion detection system. Certain individual users are found to pose a higher threat, implying the need for customized monitoring.
Carmen Cheh, Binbin Chen 0001, William G. Temple, William H. Sanders
ACM Trans. Cyber Phys. Syst.2
2020 Data Integrity Threats and Countermeasures in Railway Spot Transmission Systems
abstract
Modern trains rely on balises (communication beacons) located on the track to provide location information as they traverse a rail network. Balises, such as those conforming to the Eurobalise standard, were not designed with security in mind and are thus vulnerable to cyber attacks targeting data availability, integrity, or authenticity. In this work, we discuss data integrity threats to balise transmission modules and use high-fidelity simulation to study the risks posed by data integrity attacks. To mitigate such risk, we propose a practical two-layer solution: At the device level, we design a lightweight and low-cost cryptographic solution to protect the integrity of the location information; at the system layer, we devise a secure hybrid train speed controller to mitigate the impact under various attacks. Our simulation results demonstrate the effectiveness of our proposed solutions.
Hoon Wei Lim, William G. Temple, Bao Anh N. Tran, Binbin Chen 0001, Zbigniew T. Kalbarczyk, Jianying Zhou 0001
ACM Trans. Cyber Phys. Syst.4
2019 A Closer Look Tells More: A Facial Distortion Based Liveness Detection for Face Authentication
abstract
Face authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%.
Yan Li 0075, Zilong Wang 0001, Yingjiu Li, Robert H. Deng, Binbin Chen 0001, Weizhi Meng 0001, Hui Li 0006
AsiaCCS5
2019 Who's Scanning Our Smart Grid? Empirical Study on Honeypot Data
abstract
In order to implement and fine-tune cyber defense mechanisms, it is crucial to know who are the potential enemies and what tactics they are using. In the general cyber security area, honeypot, a decoy system intended to attract cyber attackers, is considered as an effective measure to collect such threat intelligence. However, publication analysing such data is scarce, especially in industrial control systems and smart grid domain. In this paper, we discuss our findings based on the empirical study with 6-month network traces collected in low-interaction smart grid honeypot systems deployed in geographically different regions on Amazon cloud platform. In particular, we discuss actual attack patterns observed as well as insights from the data-driven study on access/attack patterns, correlations among different locations, and dynamics in access sources, some of which are considered effective when configuring security mechanisms such as firewall and intrusion detection systems.
Daisuke Mashima, Binbin Chen 0001
GLOBECOM3
2019 Cross-sender bit-mixing coding
abstract
Scheduling to avoid packet collisions is a long-standing challenge in networking, and has become even trickier in wireless networks with multiple senders and multiple receivers. In fact, researchers have proved that even perfect scheduling can only achieve R = O(1/lnN). Here N is the number of nodes in the network, and R is the medium utilization rate.
Steffen Bondorf, Binbin Chen 0001, Jonathan Scarlett, Yuda Zhao
IPSN2
2018 RFID Counting over Time-Varying Channels
abstract
For many applications that use RFID technology, it is important to count the number of RFID tags accurately. However, the wireless channel between the RFID tags and readers can introduce communication errors, and the error rate may vary significantly over time. No existing protocol can perform RFID counting robustly (i.e., maintaining the estimation quality) over time-varying channels. In this paper, we design RRC, a Robust RFID Counting protocol that offers provable guarantees on estimation quality over time-varying channels. Specifically, regardless of how the communication errors occur, the final output generated by RRC is always a standard (e, δ) estimate of the correct count n. Furthermore, the expected amount of time needed by RRC is O(Y + 1/2 + (log log n)2) for a constant 6, where Y is the number of communication errors encountered by RRC. This makes the efficiency of RRC asymptotically near-optimal.
Ziling Zhou, Binbin Chen 0001
INFOCOM2
2018 Determining Tolerable Attack Surfaces that Preserves Safety of Cyber-Physical Systems
abstract
As safety-critical systems become increasingly interconnected, a system's operations depend on the reliability and security of the computing components and the interconnections among them. Therefore, a growing body of research seeks to tie safety analysis to security analysis. Specifically, it is important to analyze system safety under different attacker models. In this paper, we develop generic parameterizable state automaton templates to model the effects of an attack. Then, given an attacker model, we generate a state automaton that represents the system operation under the threat of the attacker model. We use a railway signaling system as our case study and consider threats to the communication protocol and the commands issued to physical devices. Our results show that while less skilled attackers are not able to violate system safety, more dedicated and skilled attackers can affect system safety. We also consider several countermeasures and show how well they can deter attacks.
Carmen Cheh, Ahmed M. Fawaz, Mohammad A. Noureddine, Binbin Chen 0001, William G. Temple, William H. Sanders
PRDC4
2018 Attack and Countermeasure on Interlock-Based Device Pairing Schemes
abstract
In recent years, researchers have proposed several secure device pairing schemes that allow mobile devices in close proximity to establish a trusted communication channel between them without sharing any secret in advance. These schemes use the correlation of some physical measurements (magnetic field, acceleration, etc.,) made independently by the two pairing devices to reconcile them. Their security against a Man-in-the-Middle (MitM) attacker relies on the difficulty for the MitM attacker to obtain a measurement data similar to the two pairing devices. As a key step in the reconciliation process, an interlock protocol is used in several recent schemes (e.g., Magpairing and ShaVe) to ensure that the measurement data is not leaked. However, the present paper points out that these schemes apply the interlock protocol improperly, making themselves vulnerable to MitM attacks. The analysis and experimental results show that the proposed MitM attack almost surely succeeds with very low computation overhead. We also propose countermeasures on the presented attack.
Yongdong Wu, Binbin Chen 0001
IEEE Trans. Inf. Forensics Secur.2
2017 Secure and Efficient Software-based Attestation for Industrial Control Devices with ARM Processors
abstract
For industrial control systems, ensuring the software integrity of their devices is a key security requirement. A pure software-based attestation solution is highly desirable for protecting legacy field devices that lack hardware root of trust (e.g., Trusted Platform Module). However, for the large population of field devices with ARM processors, existing software-based attestation schemes either incur long attestation time or are insecure. In this paper, we design a novel memory stride technique that significantly reduces the attestation time while remaining secure against known attacks and their advanced variants on ARM platform. We analyze the scheme's security and performance based on the formal framework proposed by Armknecht et al. [7] (with a necessary change to ensure its applicability in practical settings). We also implement memory stride on two models of real-world power grid devices that are widely deployed today, and demonstrate its superior performance.
Binbin Chen 0001, Xinshu Dong, Guangdong Bai, Sumeet Jauhar, Yueqiang Cheng
ACSAC1
2017 On Train Automatic Stop Control Using Balises: Attacks and a Software-Only Countermeasure
abstract
The components and systems involved in railway operation are subject to stringent reliability and safety requirements, but up until now the cyber security of those same systems has been largely under-explored. In this work, we examine a widely-used railway technology, track beacons or balises, which provide a train with its position on the track and often assist with accurate stopping at stations. Balises have been identified as one potential weak link in train signalling systems. We evaluate an automatic train stop controller that is used in real deployment and show that attackers who can compromise the availability or integrity of the balises' data can cause the trains to stop dozens of meters away from the right position, disrupting train service. To address this risk, we have developed a novel countermeasure that ensures the correct stopping of the trains in the presence of attacks, with only a small extra stopping delay.
William G. Temple, Bao Anh N. Tran, Binbin Chen 0001, Zbigniew T. Kalbarczyk, William H. Sanders
PRDC3
2017 Collaborative cellular tail energy reduction: Feasibility and fairness
Girisha De Silva, Binbin Chen 0001, Mun Choon Chan
Pervasive Mob. Comput.2
2017 Analysis and Design of Low-Duty Protocol for Smartphone Neighbor Discovery
abstract
An effective neighbor discovery service on smartphones is required for many emerging applications—from proximity-based interactions to opportunistic phone-to-phone collaborations. For a smartphone neighbor discovery service to be usable and attractive, it needs to meet two conflicting goals: 1) phones should discover neighbors fast enough (in seconds), and 2) the service’s energy footprint should be negligible so it can be “always on” while incurring little impact on battery life. Researchers have developed an impressive collection of neighbor discovery protocols to meet these two goals. By putting these protocols into concrete smartphones settings, we identify different key factors that limit their performance. Guided by our analysis, we focus on locally synchronized protocols, where phones use time information from nearby Wi-Fi Access Points (APs) to help neighbor discovery. By overcoming the key challenges for such protocols, especially, the scalability problem under increasing number of APs and neighbors, we design a new protocol, R2, that achieves low discovery delay ($<30$seconds for at least 80 percent of all connections) with a low duty cycle (1 percent).
Xiang-Fa Guo, Binbin Chen 0001, Mun Choon Chan
IEEE Trans. Mob. Comput.2
2016 Railway System Failure Scenario Analysis
William G. Temple, Bao Anh N. Tran, Binbin Chen 0001
CRITIS5
2016 Near-optimal communication-time tradeoff in fault-tolerant computation of aggregate functions
Yuda Zhao, Binbin Chen 0001
Distributed Comput.3
2016 Understanding RFID Counting Protocols
abstract
Counting the number of radio frequency identification (RFID) tags, namely RFID counting, is needed by a wide array of important wireless applications. Motivated by its paramount practical importance, researchers have developed an impressive arsenal of techniques to improve the performance of RFID counting (i.e., to reduce the time needed to do the counting). This paper aims to gain deeper and fundamental insights in this subject to facilitate future research on this topic. As our central thesis, we find out that the overlooked key design aspect for RFID counting protocols to achieve near-optimal performance is a conceptual separation of a protocol into two phases. The first phase uses small overhead to obtain a rough estimate, and the second phase uses the rough estimate to further achieve an accuracy target. Our thesis also indicates that other performance-enhancing techniques or ideas proposed in the literature are only of secondary importance. Guided by our central thesis, we manage to design near-optimal protocols that are more efficient than existing ones and simultaneously simpler than most of them.
Ziling Zhou, Binbin Chen 0001
IEEE/ACM Trans. Netw.2
2015 Model-Based Cybersecurity Assessment with NESCOR Smart Grid Failure Scenarios
abstract
The transformation of traditional power systems to smart grids brings significant benefits, but also exposes the grids to various cyber threats. The recent effort led by US National Electric Sector Cybersecurity Organization Resource (NESCOR) Technical Working Group 1 to compile failure scenarios is an important initiative to document typical cybersecurity threats to smart grids. While these scenarios are an invaluable thought-aid, companies still face challenges in systematically and efficiently applying the failure scenarios to assess security risks for their specific infrastructure. In this work, we develop a model-based process for assessing the security risks from NESCOR failure scenarios. We extend our cybersecurity assessment tool, Cyber-SAGE, to support this process, and use it to analyze 25 failure scenarios. Our results show that CyberSAGE can generate precise and structured security argument graphs to quantitatively reason about the risk of each failure scenario. Further, CyberSAGE can significantly reduce the assessment effort by allowing the reuse of models across different failure scenarios, systems, and attacker profiles to perform "what if?" analysis.
Sumeet Jauhar, Binbin Chen 0001, William G. Temple, Xinshu Dong, Zbigniew T. Kalbarczyk, William H. Sanders, David M. Nicol
PRDC2
2014 Near-optimal communication-time tradeoff in fault-tolerant computation of aggregate functions
abstract
This paper considers the problem of computing general commutative and associative aggregate functions (such as Sum) over distributed inputs held by nodes in a distributed system, while tolerating failures. Specifically, there are $N$ nodes in the system, and the topology among them is modeled as a general undirected graph. Whenever a node sends a message, the message is received by all of its neighbors in the graph. Each node has an input, and the goal is for a special root node (e.g., the base station in wireless sensor networks or the gateway node in wireless ad hoc networks) to learn a certain commutative and associate aggregate of all these inputs. All nodes in the system except the root node may experience crash failures, with the total number of edges incidental to failed nodes being upper bounded by f. The timing model is synchronous where protocols proceed in rounds. Within such a context, we focus on the following question: Under any given constraint on time complexity, what is the lowest communication complexity, in terms of the number of bits sent (i.e., locally broadcast) by each node, needed for computing general commutative and associate aggregate functions?
Yuda Zhao, Binbin Chen 0001
PODC3
2014 Automatic Generation of Security Argument Graphs
abstract
Graph-based assessment formalisms have proven to be useful in the safety, dependability, and security communities to help stakeholders manage risk and maintain appropriate documentation throughout the system lifecycle. In this paper, we propose a set of methods to automatically construct security argument graphs, a graphical formalism that integrates various security-related information to argue about the security level of a system. Our approach is to generate the graph in a progressive manner by exploiting logical relationships among pieces of diverse input information. Using those emergent argument patterns as a starting point, we define a set of extension templates that can be applied iteratively to grow a security argument graph. Using a scenario from the electric power sector, we demonstrate the graph generation process and highlight its application for system security evaluation in our prototype software tool, Cyber SAGE.
Nils Ole Tippenhauer, William G. Temple, An Hoa Vu, Binbin Chen 0001, David M. Nicol, Zbigniew T. Kalbarczyk, William H. Sanders
PRDC4
2014 The Cost of Fault Tolerance in Multi-Party Communication Complexity
abstract
Multi-party communication complexity involves distributed computation of a function over inputs held by multiple distributed players. A key focus of distributed computing research, since the very beginning, has been to tolerate failures. It is thus natural to ask “If we want to compute a certain function in a fault-tolerant way, what will the communication complexity be?” For this question, this article will focus specifically on (i) tolerating node crash failures, and (ii) computing the function over general topologies (instead of, e.g., just cliques). One way to approach this question is to first develop results in a simpler failure-free setting, and then “amend” the results to take into account failures' impact. Whether this approach is effective largely depends on how big a difference failures can make. This article proves that the impact of failures is significant, at least for the Sum aggregate function in general topologies: As our central contribution, we prove that there exists (at least) an exponential gap between the non-fault-tolerant and fault-tolerant communication complexity of S um . This gap attests that fault-tolerant communication complexity needs to be studied separately from non-fault-tolerant communication complexity, instead of being considered as an “amended” version of the latter. Such exponential gap is not obvious: For some other functions such as the M ax aggregate function, the gap is only logarithmic. Part of our results are obtained via a novel reduction from a new two-party problem U nion S ize CP that we introduce. U nion S ize CP comes with a novel cycle promise , which is the key enabler of our reduction. We further prove that this cycle promise and U nion S ize CP likely play a fundamental role in reasoning about fault-tolerant communication complexity.
Binbin Chen 0001, Yuda Zhao, Phillip B. Gibbons
J. ACM1
2013 Understanding RFID counting protocols
abstract
Counting the number of RFID tags, or RFID counting, is needed by a wide array of important wireless applications. Motivated by its paramount practical importance, researchers have developed an impressive arsenal of techniques to improve the performance of RFID counting (i.e., to reduce the time needed to do the counting). This paper aims to gain deeper and fundamental insights in this subject to facilitate future research on this topic. As our central thesis, we find out that the overlooked key design aspect for RFID counting protocols to achieve near-optimal performance is a conceptual separation of a protocol into two phases. The first phase uses small overhead to obtain a rough estimate, and the second phase uses the rough estimate to further achieve an accuracy target. Our thesis also indicates that other performance-enhancing techniques or ideas proposed in the literature are only of secondary importance. Guided by our central thesis, we manage to design near-optimal protocols that are more efficient than existing ones and simultaneously simpler than most of them.
Binbin Chen 0001, Ziling Zhou
MobiCom1
2013 Go with the flow: toward workflow-oriented security assessment
abstract
In this paper we advocate the use of workflow---describing how a system provides its intended functionality---as a pillar of cybersecurity analysis and propose a holistic workflow-oriented assessment framework. While workflow models are currently used in the area of performance and reliability assessment, these approaches are designed neither to assess a system in the presence of an active attacker, nor to assess security aspects such as confidentiality. On the other hand, existing security assessment methods typically focus on modeling the active attacker (e.g., attack graphs), but many rely on restrictive models that are not readily applicable to complex (e.g., cyber-physical or cyber-human) systems.
Binbin Chen 0001, Zbigniew T. Kalbarczyk, David M. Nicol, William H. Sanders, Rui Tan 0001, William G. Temple, Nils Ole Tippenhauer, An Hoa Vu, David K. Y. Yau
NSPW1
2012 The cost of fault tolerance in multi-party communication complexity
abstract
Multi-party communication complexity involves distributed computation of a function over inputs held by multiple distributed players. A key focus of distributed computing research, since the very beginning, has been to tolerate crash failures. It is thus natural to ask "If we want to compute a certain function in a fault-tolerant way, what will the communication complexity be?" This natural question, interestingly, has not been formally posed and thoroughly studied prior to this work.
Binbin Chen 0001, Yuda Zhao, Phillip B. Gibbons
PODC1
2012 Using anisotropic magnetoresistive (AMR) sensor arrays for electric sub-metering
abstract
In this demonstration, we present a working prototype that uses an Anisotropic Magnetoresistive (AMR) sensor array to estimate the electricity usage on individual branches of an electricity panel. Our design enables the general public to retrofit an electricity panel: one simply needs to attach a compact AMR sensor array onto the panel. Our system can then exploit the inherent power patterns of electric loads to automatically infer the system parameters and estimate the per-branch currents accurately. Even for branches carrying small loads (e.g., a 30W fan), the estimation error of our system is below 10%.
Sreejaya Viswanathan, Binbin Chen 0001, Hoang Hai Nguyen, Jerry T. Chiang, Deokwoo Jung, David K. Y. Yau
SenSys2
2012 Efficient Error Estimating Coding: Feasibility and Applications
abstract
Motivated by recent emerging systems that can leverage partially correct packets in wireless networks, this paper proposes the novel concept of error estimating coding (EEC). Without correcting the errors in the packet, EEC enables the receiver of the packet to estimate the packet's bit error rate, which is perhaps the most important meta-information of a partially correct packet. Our EEC design provides provable estimation quality with rather low redundancy and computational overhead. To demonstrate the utility of EEC, we exploit and implement EEC in two wireless network applications, Wi-Fi rate adaptation and real-time video streaming. Our real-world experiments show that these applications can significantly benefit from EEC.
Binbin Chen 0001, Ziling Zhou, Yuda Zhao
IEEE/ACM Trans. Netw.1
2011 Secure Aggregation with Malicious Node Revocation in Sensor Networks
abstract
Sensor applications often leverage in-network aggregation to extract aggregates, such as predicate count and average, from the network. With in-network aggregation, a malicious sensor can easily manipulate the intermediate aggregation results and corrupt the final answer. Most existing secure aggregation schemes aim to defend against stealth attacks and can only raise an alarm when the final answer is corrupted, without being able to pinpoint and revoke the malicious sensors. While some recent protocols can pinpoint and revoke malicious sensors, they need to rely on expensive public key cryptography to be robust against certain attacks. Using only symmetric key cryptography, this paper aims to strictly diminish the capability of adversaries whenever they launch a successful attack, so that malicious sensors can only ruin the aggregation result for a small number of times before they are fully revoked. To this end, we propose VMAT (verifiable minimum with audit trail), a novel secure aggregation protocol with malicious sensor revocation capability. VMAT relies on symmetric key cryptography only, and provides provable guarantees that each execution can either produce the correct aggregation result efficiently, or revoke some key held by the adversary.
Binbin Chen 0001
ICDCS1
2010 MobiCent: a Credit-Based Incentive System for Disruption Tolerant Network
abstract
When Disruption Tolerant Network (DTN) is used in commercial environments, incentive mechanism should be employed to encourage cooperation among selfish mobile users. Key challenges in the design of an incentive scheme for DTN are that disconnections among nodes are the norm rather than exception and network topology is time varying. Thus, it is difficult to detect selfish actions that can be launched by mobile users or to pre-determine the routing path to be used. In this paper, we propose MobiCent, a credit-based incentive system for DTN. While MobiCent allows the underlying routing protocol to discover the most efficient paths, it is also incentive compatible. Therefore, using MobiCent, rational nodes will not purposely waste transfer opportunity or cheat by creating non-existing contacts to increase their rewards. MobiCent also provides different payment mechanisms to cater to client that wants to minimize either payment or data delivery delay.
Binbin Chen 0001, Mun Choon Chan
INFOCOM1
2010 Efficient error estimating coding: feasibility and applications
abstract
Motivated by recent emerging systems that can leverage partially correct packets in wireless networks, this paper investigates the novel concept of error estimating codes (EEC). Without correcting the errors in the packet, EEC enables the receiver of the packet to estimate the packet's bit error rate, which is perhaps the most important meta-information of a partially correct packet. Our EEC algorithm provides provable estimation quality, with rather low redundancy and computational overhead. To demonstrate the utility of EEC, we exploit and implement EEC in two wireless network applications, Wi-Fi rate adaptation and real-time video streaming. Our real-world experiments show that these applications can significantly benefit from EEC.
Binbin Chen 0001, Ziling Zhou, Yuda Zhao
SIGCOMM1
2009 MobTorrent: A Framework for Mobile Internet Access from Vehicles
abstract
In this paper, we present MobTorrent, an on- demand, user-driven framework designed for vehicles which have intermittent high speed access to roadside WiFi access points (AP). Mobile nodes in MobTorrent use the WWAN network as a control channel. When a mobile client wants to initiate a download, instead of waiting for contact with the AP, it informs one (or multiple) selected AP(s) to prefetch the content. The scheduling algorithm in MobTorrent then replicates the prefetched data on the mobile helpers so that the total amount of data transferred and the average transfer rate to the mobile clients are maximized. Therefore, instead of limiting high speed data transfer to the short contact periods between APs and mobile clients, high speed transfers among vehicles are opportunistically exploited. Evaluation based on testbed measurement and trace-driven simulation shows that MobTorrent provides substantial improvement over existing architectures. For the case of a single AP, its performance approximates that of an off-line optimal scheduler. In case of multiple APs, our evaluation shows that MobTorrent's performance is robust in a variety of settings.
Binbin Chen 0001, Mun Choon Chan
INFOCOM1
2009 DEAL: Discover and Exploit Asymmetric Links in Dense Wireless Sensor Networks
abstract
Asymmetric links commonly exist in low power wireless sensor networks. However, it is difficult to discover and exploit them efficiently. In this work, we propose DEAL, a link management scheme to Discover and Exploit Asymmetric Links efficiently in dense wireless sensor networks. Equipped with a novel feedback mechanism, DEAL dynamically adapts its link maintenance mechanism based on the estimated link quality, and manages the (small) neighbor table so as to retain the most useful information. We implement DEAL in TinyOS and evaluate its performance using both TOSSIM and testbed. The simulation results show that more than 80% of asymmetric links can be discovered and maintained with minimum overhead. Using a collection tree application and ETX as the routing metric, the average path ETX can be reduced by up to 20%. Testbed evaluation also shows that DEAL improves the network routing performance by identifying useful asymmetric links.
Binbin Chen 0001, Mun Choon Chan, Akkihebbal L. Ananda
SECON1
2009 Flow scheduling and endpoint rate control in GridNetworks
Sebastien Soudan, Binbin Chen 0001, Pascale Vicat-Blanc Primet
Future Gener. Comput. Syst.2
2007 Scheduling deadline-constrained bulk data transfers to minimize network congestion
abstract
Tight coordination of resource allocation among end points in Grid networks often requires a data mover service to transfer a voluminous dataset from one site to another in a specified time interval. With flexibility at its best, the transfer can start from any time after its arrival, use any and even time variant bandwidth value, as long as it is completed before its deadline. Given a set of such tasks, we study the Bulk Data Transfer Scheduling (BDTS) problem, which searches for the optimal bandwidth allocation profile for each task to minimize the overall network congestion. We show that the multi-interval scheduling, which divides the active window of a task into multiple intervals and assigns bandwidth value independently in each of them, is both sufficient and necessary to attain the optimality in BDTS. Specifically, we show that BDTS can be solved in polynomial time as a Maximum Concurrent Flow Problem. The optimal solution attained is in the form of multi-interval scheduling with the number of intervals upper-bounded. Simulations are conducted over several representative topologies to demonstrate the significant advantage of optimal solutions.
Binbin Chen 0001, Pascale Vicat-Blanc Primet
CCGRID1
2007 Supporting Bulk Data Transfers of High-End Applications with Guaranteed Completion Time
abstract
In high-end grid networks, distributed resources (scientific instruments, CPUs, storages, etc.) are interconnected to support computing-intensive and data-intensive applications, which often require reliable and efficient transfer of gigabits or even terabits of data among endpoints. To facilitate the efficient scheduling of endpoint resources, networks should provide a service which guarantees that a specified amount of data is transferred within a strict time window. Existing "FixRate-FixTime" resource reservation architectures such as IntServ/RSVP reserve for each flow a constant amount of resource from a specified starting time. Instead, a bulk data transfer can start at any time after its arrival, use any and even time variant bandwidth value, as long as it is completed before its deadline. This paper proposes a flexible "Multi-Interval" resource reservation approach, which divides the active window of a transfer into multiple sub-intervals, and reserves constant amount of resource in each of them. We identify a possible evolution path towards the proposed architecture, and use simulations to demonstrate the potential performance gain from increasing flexibility.
Binbin Chen 0001, Pascale Vicat-Blanc Primet
ICC1
2006 Proportional Fairness for Overlapping Cells in Wireless Networks
abstract
Coordination of cellular base stations (BS) with overlapping coverage enables joint optimization of radio resource allocation in a multiple cell environment. This paper extends existing Proportional Fairness model for wired networks and single wireless cell, to the context of multiple (probably heterogeneous) wireless cells with overlapping coverage. The proposed fair allocation achieves both global Pareto optimality and inter- cell fairness (load balance). However, the ideal allocation is not practical as it requires a mobile station (MS) be simultaneously associated with multiple BSs. Instead, we use a simple GLS (Greedy Logarithmic Sum) scheme, which associates each new arrival MS with only one BS, to approximate the optimal allocation. Simulation result shows that GLS performs close to optimal scheme in a wide range of network settings.
Binbin Chen 0001, Mun Choon Chan
VTC Fall1