Yingxu Lai

dblp:40/3387 · DBLP profile ↗
← Back
52ranked-venue papers
6as first author
43since 2021 · last 2026
0000-0001-9844-1717ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 1 first-author · 17 since 2021Security and privacy · 14 · 3 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 6 · 5 since 2021Systems, architecture and hardware · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 ADMZ: Adaptive Dynamic Mix Zone pseudonym change strategy for location privacy in Vehicular Ad-hoc Networks
Yingxu Lai, Congai Zeng
Ad Hoc Networks2
2026 A timeslot-based method for learner profiling
Pengzhan Ma, Junxi Zhuang, Yingxu Lai, Jinghao Bai, Tianrun Zhan
Appl. Intell.3
2026 Eliminating false positives in static ROP attack detection with ROPSpy: A cost-effective solution
Yingxu Lai
Comput. Secur.2
2026 MFIR: Model-Free Intrusion Response for Partially Observable Industrial Control Systems
abstract
The increasing number of multi-stage attacks has brought severe cybersecurity threats to industrial control system (ICS), making it crucial to develop autonomous and effective intrusion response systems (IRS). Most existing IRS approaches depend on the idealized assumption that the system state is perfectly known and directly available for intelligent control decisions. However, this assumption is rarely satisfied in practice, as state information is typically incomplete and only partially observable, which severely limits the applicability and effectiveness of these methods. To address this challenge, we propose a model-free intrusion response approach (MFIR) tailored to ICS with partially observable states. We formulate intrusion response as a partially observable Markov decision process and construct a simulated ICS with incomplete state observations. Then we use a recurrent neural network to infer the hidden complete states from historical observation sequences, thereby avoiding reliance on prior knowledge such as transition or observation probabilities. Based on the inferred states, we develop a deep reinforcement learning algorithm with a dual-branch neural network to make response decisions. Experiments on a Tennessee Eastman-based ICS testbed demonstrate that MFIR outperforms existing approaches, achieving up to 32.86% higher total reward, fewer compromised nodes, and lower defense cost under various observability levels. These results verify that the proposed approach is well-suited for intrusion response in partially observable ICS environments.
Yingxu Lai, Peng Zhao 0013
IEEE Internet Things J.1
2026 Unknown Attack Detection Based on Class Incremental Learning in Vehicular Networks
Tengjiao Yin, Yingxu Lai, Congai Zeng
IEEE Internet Things J.2
2026 Renounce Darkness: Employing Cache Attack for Defending Against Information Leakage in Socket-Based IPC
abstract
Socket-based IPC is widely adopted by local applications, yet it remains vulnerable to Man-in-the-Machine (MitMa) attacks, in which local unprivileged users can intercept or tamper with sensitive information. To reduce the attack surface of MitMa, we present CACHE CABLE, which transmits sensitive information covertly to defend against leakage. CACHE CABLE is the first defense-oriented use of cache covert channels, repurposed as secure endpoints for transmitting sensitive information. It integrates with socket-based IPC and dynamically activates a covert cache channel, referred to as acable, only when sensitive information needs to be sent. We design a secure and noiseresilient communication protocol, along with an application-layer protocol that ensures the reliable establishment ofcables. Our implementation demonstrates that CACHE CABLE achieves reliable, error-free transmission rates of up to 497 KB/s with minimal overhead. It effectively resists impersonation, wiretapping, tampering, and jamming attacks under the strong MitMa threat model. Evaluations show that CACHE CABLE enhances data confidentiality without sacrificing compatibility or introducing significant overhead, making it suitable for protecting sensitive interactions in widely used local applications.
Yingxu Lai
IEEE Trans. Computers2
2026 RRFuzzer: A Fuzzing Framework for Proprietary Industrial Control System Protocols Using a Combination Strategy
Yingxu Lai, Yutong Dang, Huimin Fang, Shen Lu, Jing Liu 0028
IEEE Trans. Dependable Secur. Comput.1
2026 ICSploit: A Fuzzing Framework for Proprietary Industrial Control System Protocols Driven by Function Codes
Shen Lu, Yingxu Lai, Yutong Dang, Huimin Fang, Peng Zhao 0013, Baoshan Xie
IEEE Trans. Inf. Forensics Secur.2
2026 MUFFIN: A Meta-Knowledge Decoupling-Based Approach to Few-Shot IoT Traffic Classification
abstract
Traditional machine learning-based approaches to Internet of Things (IoT) traffic classification are hindered by the need for a large number of labeled flows in real-world network environments. To cope with this problem, some few-shot traffic classification approaches have been proposed to achieve accurate classification by comparing the similarity of flows to the given labeled flows. These approaches train neural networks to concurrently learn feature extraction and feature comparison meta-knowledge from sufficient labeled flows. However, they conflate these two types of meta-knowledge and ignore their differences. We propose MUFFIN, a meta-knowledge decoupling-based approach to few-shot IoT traffic classification. MUFFIN is based on our key insight that feature extraction and feature comparison meta-knowledge are two different types of meta-knowledge with distinct learning goals. Therefore, MUFFIN decouples their learning in the meta-knowledge phase and introduces a masked autoencoder as its feature extractor to enhance the learning of feature extraction meta-knowledge. Extensive experiments conducted on three publicly available datasets demonstrate the classification ability and robustness of MUFFIN. Furthermore, a comparison with five state-of-the-art few-shot traffic classification approaches reveals that MUFFIN outperforms them in classification accuracy and requires only 20 labeled flows.
Yipeng Wang 0001, Yingxu Lai, Shui Yu 0001, Jinqiao Shi
IEEE Trans. Netw.3
2026 Review on network situation awareness to cloud computing security in Industry 4.0
Baoshan Xie, Yingxu Lai, Peng Zhao 0013
Wirel. Networks2
2025 A Sybil Attack Traceability Detection Scheme Adapted to Vehicle Pseudonym Change Strategy
Ye Chen 0009, Yingxu Lai
Networking2
2025 GECAT: A Graph-Enhanced Causality-Aware Transformer for Industrial Control System Intrusion Detection
abstract
Modern Industrial Control Systems (ICS) have become prime targets for cyberattacks due to the increasing connectivity and complexity of operational infrastructures. These attacks can have severe consequences, making intrusion detection crucial. Recent deep learning approaches have steadily improved intrusion detection accuracy. However, they often fail to model the relationships between multiple sensors and actuators, lack the integration of physical priors, and demonstrate limited adaptability to varying conditions. In this paper, we propose GECAT (Graph-Enhanced Causality-Aware Transformer), a novel intrusion detection framework tailored for ICS data streams. Our approach combines graph-based sensor relationship modeling, causal inference principles, and a specially designed temporal transformer backbone to robustly detect and classify complex attacks.We integrate physical domain knowledge with data-driven graph learning modules to create an adaptive representation that adapts to diverse scenarios and enforces realistic process constraints. Experimental results on SWaT and WADI demonstrate that GECAT significantly outperforms a comprehensive set of state-of-the-art baselines across multiple metrics, indicating its effectiveness in defending ICS against sophisticated adversaries. Additionally, extensive ablation studies confirm the distinct contributions of each core component in our design.
Wan Wei, Yingxu Lai
SMC4
2025 MER-GCN: Reasoning about attacking group behaviors using industrial control system attack knowledge graphs
Yingxu Lai, Xinrui Dong
Comput. Secur.2
2025 Sybil attack detection and traceability scheme based on temporal heterogeneous graph attention networks
Ye Chen 0009, Yingxu Lai, Congai Zeng
J. Netw. Comput. Appl.2
2025 Reliable Open-Set Network Traffic Classification
abstract
The widespread use of modern network communications necessitates effective resource control and management in TCP/IP networks. However, most existing network traffic classification methods are limited to labeled known classes and struggle to handle open-set scenarios, where known classes coexist with significant volumes of unknown classes of traffic. To solve this problem more accurately and reliably, we propose RoNeTC. This method achieves high-precision classification by enhancing feature extraction and quantifying the reliability of classification decisions through uncertainty estimation. For feature extraction, we divide each packet of a flow into three views for parallel training, integrating both local and global feature representations across multiple packets to enhance accuracy. We devise a second-order classification probability to quantify the reliability of the classifier’s results and to visualize the reliability of open-set flow classification in terms of uncertainty. Additionally, we dynamically fuse classification decisions from multiple views, evaluating decision uncertainty to classify known and unknown flows and ensure robust, reliable results. We compare RoNeTC with four state-of-the-art (SOTA) methods in six open-set scenarios. RoNeTC outperforms the other methods by an average of 25.94% in F1 across all open-set scenarios, indicating its superior performance in open-set network traffic classification.
Xueman Wang, Yipeng Wang 0001, Yingxu Lai, Zhiyu Hao, Alex X. Liu
IEEE Trans. Inf. Forensics Secur.3
2025 Counteracting New Attacks in CPS: A Few-Shot Class-Incremental Adaptation Strategy for Intrusion Detection System
abstract
The deep integration of physical devices and communication networks has increased the security risks of cyber-physical systems (CPSs) compared to traditional control systems. Deep learning-based intrusion detection systems (IDSs) play a crucial role in ensuring CPSs security. However, the existing IDSs often rely on known attack features, rendering them unable to withstand emerging new attacks arising from the dynamic evolution of intrusion behaviors. This paper aims to develop an IDSs with high adaptability and strong generalization capabilities, which is capable of rapidly adapting to new attack classes with only a few new samples. To achieve this objective, we propose CAT-IDS, a few-shot class-incremental adaptation strategy for an IDS to counteract new attacks on CPSs. We design a highly symmetric classifier structure for CAT-IDS that can flexibly adjust the classification space to adapt to new attacks. Furthermore, we calibrate the biased distribution formed by a few training samples through statistical feature transfer. In order to prevent the model from forgetting old attack information during the adaptation process, we devise hybrid features for attack detection. These features contain essential information for both old and new class classifications. We demonstrate the effectiveness of CAT-IDS through multiple experiments on three CPSs datasets. The results show that CAT-IDS achieves an average accuracy improvement of approximately 4. 5% compared to the state-of-the-art methods, demonstrating its superior ability to adapt to new attacks while maintaining high performance in classifying existing attacks.
Xinrui Dong, Yingxu Lai
IEEE Trans. Netw. Serv. Manag.2
2024 MVDetector: Malicious Vehicles Detection Under Sybil Attacks in VANETs
Weiye Qi, Zechuan Li, Yufan Han, Yingxu Lai
ISC (2)5
2024 Improving Knowledge Tracing Through Learning Processes and Concept Similarity Map
abstract
Knowledge Tracing (KT) aims to track the evolving knowledge states of students based on their historical performance, playing a vital role in online intelligent education systems. While deep learning-based knowledge tracing achieves impressive predictive performance, existing methods suffer from two main shortcomings. Firstly, storing massive amounts of historical information introduces irrelevant noise during the training process. Additionally, individual differences may prevent the model from accurately capturing students comprehensive states. Secondly, deep learning models lack interpretability, failing to provide precise descriptions of students knowledge states. This paper proposes an improved knowledge tracing method through learning processes and concept similarity map (LCKT). We incorporate diverse features, including exercise, exercise difficulty, concept, response time, response, and interval time, to measure the diversity of exercise interactions. Additionally, we utilize a forgetting gate to simulate the decline of students knowledge over time during the learning process. Furthermore, we introduce a concept similarity map as a constraint for model training, which clearly delineates students mastery across different knowledge points. Extensive experiments on three real-world datasets demonstrate that LCKT outperforms state-of-the-art KT methods and exhibits interpretability to some extent.
Yingxu Lai, Xinrui Dong, Junxi Zhuang, Jing Liu 0028
SMC1
2024 An adaptive classification and updating method for unknown network traffic in open environments
Siqi Le, Yingxu Lai, Yipeng Wang 0001, Huijie He
Comput. Networks2
2024 AGCM: A multi-stage attack correlation and scenario reconstruction method based on graph aggregation
Hongshuo Lyu, Jing Liu 0028, Yingxu Lai, Beifeng Mao, Xianting Huang
Comput. Commun.3
2024 NCMFuzzer: Using non-critical field mutation and test case combination to improve the efficiency of ICS protocol fuzzing
Hanxiao Wanyan, Yingxu Lai, Jing Liu 0028, Hao Chen 0164
Comput. Secur.2
2024 Interpretable Cross-Layer Intrusion Response System Based on Deep Reinforcement Learning for Industrial Control Systems
abstract
Owing to the increasing number of cybersecurity threats targeting industrial control systems (ICSs), intrusion response systems (IRSs) have become essential. However, the current IRSs exhibit several limitations, such as neglecting physical domain security policies and relying significantly on expert input. While deep reinforcement learning (DRL) methods yield superior outcomes, they suffer from low interpretability and unreliability. This study introduces an interpretable cross-layer intrusion response system (ICL-IRS), which is a decision-tree-based IRS. It offers a robust understanding of cyberattacks and industrial control logic specific to ICSs. ICL-IRS employs a DRL model, tailored to the characteristics of physical process control, to refine policies. It then scrutinizes the optimized intrusion response policy and generates decision trees. Our experimental results reveal a 21% enhancement in the success rate of the proposed ICL-IRS over competing methods. The effectiveness of ICL-IRS was further validated through a case study on a simulated process-control system.
Hao Chen 0164, Yingxu Lai, Jing Liu 0028, Hanxiao Wanyan
IEEE Trans. Ind. Informatics2
2024 Abnormal Logical Representation Learning for Intrusion Detection in Industrial Control Systems
abstract
As security threats to industrial control systems become more prevalent, it is imperative to deploy effective intrusion-detection systems. However, the existing methods are insufficient for addressing contemporary attacks. Rule-based methods are heavily dependent on manual settings, and the covertness of attacks poses challenges to rule effectiveness. Machine and deep learning methods exhibit low interpretability owing to their complex designs, and the semantic gap between the model and the actual operational interpretation limits their applicability. To mitigate these shortcomings, we propose an abnormal logical representation learning (ALRL) intrusion detection method for industrial control systems. ALRL contains a specific lightweight neural network and employs knowledge distillation to achieve high classification ability. More importantly, it can generate effective and concise intrusion detection rules directly from the learned knowledge of the model. The hierarchical model structure and residual connections ensure high interpretability of the rules. Experiments conducted on two publicly available industrial control datasets demonstrate that ALRL can classify attacks with an excellent performance. In addition, the logical rules generated by ALRL can effectively detect all types of attacks and exhibit good interpretability.
Yingxu Lai, Xinrui Dong
IEEE Trans. Ind. Informatics2
2023 Intrusion Detection System for Industrial Control Systems Based on Imbalanced Data
abstract
The integration of industrialization and informatization has exposed industrial control systems (ICSs) to increasingly serious security challenges. Currently, the mainstream method to protect the security of ICSs is intrusion detection system (IDS) based on deep-learning. However, these methods depend on a massive amount of high-quality data. Owing to the characteristics and protocol limitations, ICSs data usually experience low-quality and data imbalance problems, which significantly affects the accuracy of IDS.In this study, an IDS for ICS that combines data expansion algorithm and CNN was proposed. A novel normalized neighborhood weighted convex combined random sample (NNW-CCRS) oversampling algorithm was designed, which automatically attenuates the effects of noise and expanding imbalanced data to produce balanced ICS datasets. By reducing the impact of imbalanced ICS data on IDSs, our system effectively protects the security of ICS. Secure Water Treatment dataset (SWaT) was used for experimental validation. The experimental results confirmed that the accuracy of the proposed system improved by approximately 20%, compared to the ICS without data expansion.
Xinrui Dong, Yingxu Lai
ISADS2
2023 Mining of Potential Relationships based on the Knowledge Graph of Industrial Control Systems
abstract
Industrial Control System(ICS) security is one of the lifebloods of national development. Fully understanding of its vulnerabilities plays an important role in the actual application scenarios. Meanwhile, an attacker may also exploit multiple vulnerabilities to achieve the final malicious purpose, such as the Stuxnet worm. In order to solve the above problems, we construct a Knowledge Graph(KG) of heterogeneous ICSs, and propose a potential relationship mining method (R-HetGNN) based on this graph. The method solves the multi-modality problem in KG aggregation and KG-heterogeneity problem. Besides, we use random walk algorithm to solve the ulti-level neighbor problem. Experimental results on a real-world dataset show that R-HetGNN achieved 83.0% on the F1 score, superior to other knowledge reasoning modules, such as GAT and TransE.
Yingxu Lai
ISADS2
2023 Fast tracing method for Sybil attack in VANETs
abstract
In VANETs, malicious nodes launch Sybil attacks using false traffic information by forging basic safety messages, leading to erroneous decisions and ultimately causing traffic accidents that threaten the lives of passengers. Existing Sybil attack detection methods can only mitigate the impact of Sybil attacks and cannot trace the attack back to find malicious nodes. Meanwhile, malicious nodes can suppress the performance of tracing methods with the help of pseudonym exchange policy. This study proposes a fast Sybil attack tracing method in VANETs to address the above challenges. The method quickly identifies suspicious BSMs through cascading operations. Finally, the results of cascading operations are used to perform source estimation and complete the attack tracing. Experimental results show the method’s precision ≥97% and recall ≥96%.
Yingxu Lai, Jingwen Wei
VTC Fall2
2023 Detection method to eliminate Sybil attacks in Vehicular Ad-hoc Networks
Yingxu Lai, Ye Chen 0009, Jingwen Wei, Yuhang Wang 0034
Ad Hoc Networks2
2023 MDFD: A multi-source data fusion detection framework for Sybil attack detection in VANETs
Ye Chen 0009, Yingxu Lai, Hanmei Li, Yuhang Wang 0034
Comput. Networks2
2023 Relational reasoning-based approach for network protocol reverse engineering
abstract
Extracting the protocol format specifications from packets plays a critical role in many applications, such as application protocol parsing, vulnerability scanning, as well as malware behaviour analysis. In this study, we propose RelaNet, a novel relational reasoning-based method for network protocol reverse engineering. It is based on the key insight that n-grams of packets have context relations. Such relations are especially informative between keywords and can be used to infer protocol formats. RelaNet contains three modules to mimic the analysis strategy used by experts: coarse structure generation, relation learning and fine structure generation. In coarse structure generation, RelaNet first constructs a coarse-grained structure based on the occurrence frequency of n-grams. Relation learning is then performed to discover the context relations between the n-grams in the structure. By using such relations, we can eventually discover the strong context relations that exist between keywords, which can be used to accurately generate a fine-grained structure, namely the protocol format. We implement RelaNet and evaluate it on two publicly available datasets, the experimental results demonstrate the effectiveness and efficiency of RelaNet for protocol format inference. Furthermore, we compare RelaNet with state-of-the-art methods, and the results show our approach outperforms those methods.
Yingxu Lai, Yipeng Wang 0001
Comput. Networks2
2023 Selective forwarding attack detection and network recovery mechanism based on cloud-edge cooperation in software-defined wireless sensor network
Shiyao Luo, Yingxu Lai, Jing Liu 0028
Comput. Secur.2
2023 A data skew-based unknown traffic classification approach for TLS applications
Huijie He, Yingxu Lai, Yipeng Wang 0001, Siqi Le
Future Gener. Comput. Syst.2
2023 MSGAN: multi-stage generative adversarial network-based data recovery in cyber-attacks
Bitao Tian, Yingxu Lai, Samuel S. M. Sun, Yipeng Wang 0001, Jing Liu 0028
Neural Comput. Appl.2
2023 Transfer learning-based self-learning intrusion detection system for in-vehicle networks
Yuhang Wang 0034, Yingxu Lai, Ye Chen 0009, Jingwen Wei
Neural Comput. Appl.2
2023 EEFED: Personalized Federated Learning of Execution&Evaluation Dual Network for CPS Intrusion Detection
abstract
In the modern interconnected world, intelligent networks and computing technologies are increasingly being incorporated in industrial systems. However, this adoption of advanced technology has resulted in increased cyber threats to cyber-physical systems. Existing intrusion detection systems are continually challenged by constantly evolving cyber threats. Machine learning algorithms have been applied for intrusion detection. In these techniques, a classification model is trained by learning cyber behavior patterns. However, these models typically require considerable high-quality datasets. Limited attack samples are available because of the unpredictability and constant evolution of cyber threats. To address these problems, we propose a novel federated Execution & Evaluation dual network framework (EEFED), which allows multiple federal participants to personalize their local detection models undermining the original purpose of Federated Learning. Thus, a general global detection model was developed for collaboratively improving the performance of a single local model against cyberattacks. The proposed personalized update algorithm and the optimizing backtracking parameters replacement policy effectively reduced the negative influence of federated learning in imbalanced and non-i.i.d distribution of data. The proposed method improved model stability. Furthermore, extensive experiments conducted on a network dataset in various cyber scenarios revealed that the proposed method outperformed single model and state-of-the-art methods.
Xianting Huang, Jing Liu 0028, Yingxu Lai, Beifeng Mao, Hongshuo Lyu
IEEE Trans. Inf. Forensics Secur.3
2023 Intrusion Detection System Based on In-Depth Understandings of Industrial Control Logic
abstract
In industrial control systems (ICSs), intrusion detection is a vital task. Conventional intrusion detection systems (IDSs) rely on manually designed rules. These rules heavily depend on professional experience, thereby making it challenging to represent the increasingly complicated industrial control logic. Although deep learning-based approaches provide better accuracy than other methods, they can only provide alerts. However, they cannot provide administrators with detailed information. In this study, we propose the logic understanding IDS (LU-IDS), which is a rule-based IDS with in-depth understandings of industrial control logic. Our proposed LU-IDS uses a specially designed deep learning-based model to capture features automatically and carry out attack classification. More importantly, it analyzes the knowledge learned from the classification of attacks to understand the abnormal industrial control logic and generate rules. The experimental results indicate that our proposed LU-IDS demonstrates excellent performance on intrusion detection. The rules generated by our proposed LU-IDS can be used to successfully detect all types of attacks on two public datasets.
Motong Sun, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Beifeng Mao, Haoran Gu
IEEE Trans. Ind. Informatics2
2023 A Two-Phase Approach to Fast and Accurate Classification of Encrypted Traffic
abstract
Encryption technology has been widely used in today’s network communications. The early classification of encrypted flows is of great value to the control, allocation and management of resources in TCP/IP networks. In this paper, we propose TaTic, an early classification method for encrypted traffic, which aims to reduce the time spent observing the encrypted flows to be classified, and at the same time ensure the flow classification accuracy. TaTic is based on our key observation that the majority of encrypted flows can be classified accurately using only the first few packets, and we call such flows “easy flows”, whereas the rest of encrypted flows requires more packets for fine-grained analysis to achieve accurate traffic classification, and we call such flows “hard flows”. Given an encrypted flow, in the first phase, we use only the first few packets to quickly determine whether it is an easy flow or a hard flow; if it is an easy flow, we directly classify it in this phase; otherwise, we use more packets to perform traffic classification in the second phase. Therefore, we can greatly reduce the time spent in observing the flows without sacrificing the classification accuracy. Our experimental results show that TaTic can greatly reduce the unnecessary time spent in observing the flow to be classified, and at the same time ensure high classification accuracy. We compare our experimental results of TaTic with four existing methods. TaTic is superior to the existing methods in terms of both classification accuracy and average waiting time.
Yipeng Wang 0001, Huijie He, Yingxu Lai, Alex X. Liu
IEEE/ACM Trans. Netw.3
2022 Zen-tor: A Zero Knowledge Known-Unknown Traffic Classification Method
abstract
Home smart devices are widely used today, but due to their inherent drawbacks, one's home might be in danger if the home network has too many unknown traffic where malicious traffic hides. We present a conceptually new method called Zero Knowledge Known-unknown Traffic Classification(Zen-tor) which utilizes Generative Adversarial Networks(GAN) and con-volutional network. Zen-tor can classify unknown network traffic from known one under the situation of knowing zero knowledge of unknown traffic, thus it can be trained to protect private home network with only known traffic. We evaluate Zen-tor on a publicly available dataset, and the results show that Zen-tor has excellent unknown classification accuracy and outperforms the state-of-the-art unknown traffic classification methods.
Yizhe Gu, Yingxu Lai, Yipeng Wang 0001
GLOBECOM2
2022 FITIC: A Few-shot Learning Based IoT Traffic Classification Method
abstract
With the rapid development and wide application of Internet of Things (IoT) technology, Internet Service Providers need to accurately classify IoT traffic to provide hierarchical network management and network protection for highly het-erogeneous IoT devices. Currently, popular traditional machine learning and deep learning-based approaches to IoT traffic classification require large amounts of labeled traffic to build classification models. However, in practice simple IoT traffic with simple operating modes can be identified with only a small amount of labeled traffic and some classes of IoT devices only generate a limited amount of traffic, therefore, the aforementioned methods is not applicable in such scenarios. In this paper, we propose FITIC, a novel IoT traffic classification method based on few-shot learning. FITIC proposes a feature construction method for IoT traffic characteristics and can classify IoT traffic with only a limited number of labeled traffic samples. We evaluate FITIC on two publicly available datasets, and the experimental results show that FITIC has excellent classification accuracy and outperforms the state-of-the-art traffic classification methods.
Wenxu Jia, Yipeng Wang 0001, Yingxu Lai, Huijie He, Ruiping Yin
ICCCN3
2022 Identifying malicious nodes in wireless sensor networks based on correlation detection
abstract
The wireless sensor network (WSN) is a multi-hop wireless network that comprises multiple sensor nodes arranged in a self-organized manner. It is usually deployed in unattended areas where sensor nodes can easily be infiltrated by attackers who can affect the detection results by injecting false data. This paper proposes a malicious-node identification method based on correlation theory that prevents fault data injection attacks. First, anomalies among similar types of sensor data are detected based on time correlation. Second, malicious nodes are identified based on spatial correlation. Third, the identified malicious nodes are verified based on event correlation. The experimental results and their comparison with those of existing methods show that the proposed scheme has better recall with lower false-positive and false-negative rates than those of the traditional fuzzy reputation model and weighted-trust-based methods.
Yingxu Lai, Liyao Tong, Jing Liu 0028, Yipeng Wang 0001, Hua Qin
Comput. Secur.1
2022 Stealthy attack detection method based on Multi-feature long short-term memory prediction model
Jiexi Wang, Yingxu Lai, Jing Liu 0028
Future Gener. Comput. Syst.2
2022 DEIDS: a novel intrusion detection system for industrial control systems
abstract
Abstract Owing to the development of industrial production, the hidden danger in industrial control systems (ICSs) has considerably increased, causing challenges in traditional safety defense methods. The combination of machine-learning or deep-learning algorithms and intrusion detection systems (IDSs) has become the mainstream method for solving this problem. However, these methods depend on a massive amount of high-quality attack traffic data, which cannot be obtained easily owing to the independence and unique characteristics of ICSs. In this study, we apply the reconstructed convolutional neural network and a data expansion algorithm named CenterBorderline_SMOTE (CB_SMOTE) to an IDS and propose data expansion intrusion detection system (DEIDS). The DEIDS is an end-to-end detection model that learns representative attack features from raw traffic and classifies them in a unified framework. Moreover, we adopt the classification activation map structure, which can deeply mine the potential characteristics of traffic and enhance the effectiveness of attack features. While enhancing the data quality, we introduce the designed CB_SMOTE algorithm into DEIDS to expand the data and solve the problem of insufficient attack data in the system. Our comprehensive experiments on different open datasets indicate that DEIDS achieves an excellent performance (97 $$\%$$ % detection accuracy) and outperforms the state-of-the-art methods. The experimental results also show that our method has high efficiency and high accuracy in processing ICSs datasets.
Haoran Gu, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Motong Sun, Beifeng Mao
Neural Comput. Appl.2
2022 Correction to: DEIDS: a novel intrusion detection system for industrial control systems
Haoran Gu, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Motong Sun, Beifeng Mao
Neural Comput. Appl.2
2021 MIF: A multi-step attack scenario reconstruction and attack chains extraction method based on multi-information fusion
abstract
Most attacks on the Internet are progressive attacks and exploit multiple nodes. Traditional Intrusion Detection Systems (IDS) cannot detect the original attack node, making it difficult to block the attack at its source. This paper focuses on using IDS’ alerts corresponding to abnormal traffic to correlate attacks detected by the IDS, reconstruct multi-step attack scenarios and discover attack chains. Due to many false positives in the information provided by IDS, accurate reconstruction of the attack scenario and extraction of the most critical attack chain is challenging. Therefore, we propose a method to reconstruct multi-step attack scenarios in the network based on multiple information fusion of attack time, risk assessment and attack node information. First, we propose a Convolution and Agent Decision Tree Network (CTnet), a convolutional neural network that evaluates the attacks detected by the IDS and gives an alert with an attack risk assessment. Then, we reconstruct the weighted attack scenario by applying Graph-based Fusion Module (GM) on the captured attacks’ risk assessment and time information. Finally, we extract the high-risk attack chain by Depth First Search with Time and Weight (TW-DFS) algorithm. The experimental results show that the proposed method can accurately reconstruct multi-step attack scenarios and trace them back to the original host. It can help administrators to deploy security measures more effectively to ensure the overall security of the network.
Beifeng Mao, Jing Liu 0028, Yingxu Lai, Motong Sun
Comput. Networks3
2020 Protection of Sensitive Data in Industrial Internet Based on Three-Layer Local/Fog/Cloud Storage
abstract
Industrial Internet technology has developed rapidly, and the security of industrial data has received much attention. At present, industrial enterprises lack a safe and professional data security system. Thus, industries urgently need a complete and effective data protection scheme. This study develops a three-layer framework with local/fog/cloud storage for protecting sensitive industrial data and defines a threat model. For real-time sensitive industrial data, we use the improved local differential privacy algorithm M-RAPPOR to perturb sensitive information. We encode the desensitized data using Reed–Solomon (RS) encoding and then store them in local equipment to realize low cost, high efficiency, and intelligent data protection. For non-real-time sensitive industrial data, we adopt a cloud-fog collaborative storage scheme based on AES-RS encoding to invisibly provide multilayer protection. We adopt the optimal solution of distributed storage in local equipment and the cloud-fog collaborative storage scheme in fog nodes and cloud nodes to alleviate the storage pressure on local equipment and to improve security and recoverability. According to the defined threat model, we conduct a security analysis and prove that the proposed scheme can provide stronger data protection for sensitive data. Compared with traditional methods, this approach strengthens the protection of sensitive information and ensures real-time continuity of open data sharing. Finally, the feasibility of our scheme is validated through experimental evaluation.
Jing Liu 0028, Changbo Yuan, Yingxu Lai, Hua Qin
Secur. Commun. Networks3
2019 Industrial Control Intrusion Detection Approach Based on Multiclassification GoogLeNet-LSTM Model
abstract
Intrusion detection is essential for ensuring the security of industrial control systems. However, conventional intrusion detection approaches are unable to cope with the complexity and ever-changing nature of industrial intrusion attacks. In this study, we propose an industrial control intrusion detection approach based on a combined deep learning model for communication processes that use the Modbus protocol. Initially, the network packets are classified as carrying information and noncarrying information based on key fields according to the communication protocol used. Next, a template comparison approach is employed to detect the network packets that do not carry any information. Furthermore, an approach based on a GoogLeNet-long short-term memory model is used to detect the network packets that do carry information. This approach involves network packet sequence construction, feature extraction, and time-series level detection. Subsequently, the detected intrusions are classified into multiple categories through a Softmax classifier. A gas pipeline dataset of the Modbus protocol is used to evaluate the proposed approach and compare it with existing strategies. The accuracy, false-positive rate, and miss rate are 97.56%, 2.42%, and 2.51%, respectively, thus confirming that the proposed approach is suitable for intrusion detection in industrial control systems.
Ankang Chu, Yingxu Lai, Jing Liu 0028
Secur. Commun. Networks2
2019 Industrial Anomaly Detection and Attack Classification Method Based on Convolutional Neural Network
abstract
The massive use of information technology has brought certain security risks to the industrial production process. In recent years, cyber-physical attacks against industrial control systems have occurred frequently. Anomaly detection technology is an essential technical means to ensure the safety of industrial control systems. Considering the shortcomings of traditional methods and to facilitate the timely analysis and location of anomalies, this study proposes a solution based on the deep learning method for industrial traffic anomaly detection and attack classification. We use a convolutional neural network deep learning representation model as the detection model. The original one-dimensional data are mapped using the feature mapping method to make them suitable for model processing. The deep learning method can automatically extract critical features and achieve accurate attack classification. We performed a model evaluation using real network attack data from a supervisory control and data acquisition (SCADA) system. The experimental results showed that the proposed method met the anomaly detection and attack classification needs of a SCADA system. The proposed method also promotes the application of deep learning methods in industrial anomaly detection.
Yingxu Lai, Zenghui Liu
Secur. Commun. Networks1
2017 Intrusion Detection of Industrial Control System Based on Modbus TCP Protocol
abstract
Modbus over TCP/IP is one of the most popular industrial network protocol that are widely used in critical infrastructures. However, vulnerability of Modbus TCP protocol has attracted widely concern in the public. The traditional intrusion detection methods can identify some intrusion behaviors, but there are still some problems. In this paper, we present an innovative approach, SD-IDS (Stereo Depth IDS), which is designed for perform real-time deep inspection for Modbus TCP traffic. SD-IDS algorithm is composed of two parts: rule extraction and deep inspection. The rule extraction module not only analyzes the characteristics of industrial traffic, but also explores the semantic relationship among the key field in the Modbus TCP protocol. The deep inspection module is based on rule-based anomaly intrusion detection. Furthermore, we use the online test to evaluate the performance of our SD-IDS system. Our approach get a low rate of false positive and false negative.
Kefeng Fan, Yingxu Lai, Zenghui Liu, Ruikang Zhou, Xiangzhen Yao
ISADS3
2015 Analysis of Industrial Control Systems Traffic Based on Time Series
abstract
With the growing demand of location-independent access to Industrial Control Systems (ICS), anomaly detection scheme for industrial Ethernet which highly satisfied with demanding real-time and reliable industrial applications becomes one of the problems in ICS. In this paper, we present an innovative approach to build a traffic model based on structural time series model. Basic structural model which decomposes time series into four factors is established by the stationary analysis of industrial traffic. Parameters in the model are identified by state space model which is conducted from the training sequence using standard Kalman filter recursions and EM algorithm. Furthermore, performance of state space model is evaluated by the experimental comparative results that confirm significant improvement in detection accuracy and the validity of abnormal data localization.
Yingxu Lai, Liu Jing
ISADS1
2015 Study on Authentication Protocol of SDN Trusted Domain
abstract
Currently Software Define Network (SDN) architecture has become a hot topic. Aiming at the authentication security issues of SDN network architecture, we introduce an authentication protocol based on SDN network architecture without any trusted third party between trusted domains. By applying AVISPA security analysis system of network interaction protocol, we can guarantee protocol security and provide complete safety tests. Our work fill the gap of mutual trust between different trusted domains and provide security foundation for interaction between different trusted domains.
Ruikang Zhou, Yingxu Lai, Zenghui Liu, Jing Liu 0028
ISADS2
2015 Sensational Headline Identification By Normalized Cross Entropy-Based Metric
abstract
Nowadays multimedia social networks are fueled by sensational coverage of sex, violence and crime. In this paper, we provide a normalized cross entropy metric to determine whether a headline is a sensational headline or not by the literal consistency between the headline and its corresponding document. Experiments on a Chinese data set show that the traditional relevancy measurements—vector cosine, relative entropy, likelihood and cross entropy—suffer from strong dependence on text length and are unable to effectively identify sensational headline. The experimental results on both Chinese data sets and English data sets show that our metric can cover the positive effects of high-frequency words and overcome the negative effects of the lengths of the title and the document.
Zhen Yang 0004, Kaiming Gao, Kefeng Fan, Yingxu Lai
Comput. J.4
2009 Trusted Computing Based Mobile DRM Authentication Scheme
abstract
Rapid development of mobile communications business leads to greater focus on effective mobile DRM (digital right management) for providing improved content protection. To be able to guarantee DRM policies enforcement, the trusted mobile working environment based on a tamper-resistant hardware module is needed. In this paper, firstly, a construction of the trusted mobile computing based on TPM/TPCM is introduced. Thereafter, an example of DRM authentication scheme in user domain integrated with trusted mobile platform is discussed. Based on the new characters provided by trusted computing platform, the authentication scheme can be simplified, which is safe enough to increase the security of latest mobile DRM framework and promote its interoperability and compatibility.
Zhen Yang 0004, Kefeng Fan, Yingxu Lai
IAS3
2009 Design and Implementation of Distributed Intelligent Firewall Based on IPv6
abstract
IPv6, as the alternative of IPv4, contains numerous features and improvements that make it attractive from a security perspective, but it is by no means the panacea for security. This paper presents the design and implementation of a distributed intelligent firewall system based on IPv6, which is able to secure the network layer and application layer of IPv6 networking. By the system, the typical attacks coexisting in both IPv4 and IPv6, the emerging IPv6 specific ones such as security threats related to ICMPv6, can be blocked by the rule set of network layer, similarly, with the rule set of application layer, any illegal or reactionary Web page content in HTML source codes can be totally prevented from sneaking into the Intranet. The Initiative Drift mechanism ensures the legitimacy and civilization of the Web environment within the whole IPv6 networking. Finally, we conduct the performance evaluation of the system and a decent result is gotten.
Yingxu Lai, Guangzhi Jiang
ISDA2