Daoqing Yang

dblp:408/7918 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0009-0003-8668-7447ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Network security · 100%
Computer networks
2 papers
Network measurement and analytics · 62% Internet of things and sensor networks · 38%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics › protocol analysis
protocol reverse engineering
0.912025
InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation Learning · IEEE Trans. Dependable Secur. Comput. 2025
Network security
protocol reverse engineering
0.912025
Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control Protocols · IEEE Trans. Inf. Forensics Secur. 2025
Network security
traffic analysis
0.912025
Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control Protocols · IEEE Trans. Inf. Forensics Secur. 2025
Internet of things and sensor networks › industrial network › industrial wireless networks
industrial control systems
0.522025
Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control Protocols · IEEE Trans. Inf. Forensics Secur. 2025
InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation Learning · IEEE Trans. Dependable Secur. Comput. 2025

Methods — techniques the papers use, named apart from their topics

pattern series · 1.7classification · 1.7pairwise classification · 0.9message clustering · 0.9graph representation learning · 0.9
YearPublicationVenuePosition
2026 A generalizable anomaly detection framework with dynamic concept drift suppression for non-stationary time series
Licheng Yang 0002, Yu Yao 0002, Daoqing Yang, Wei Yang 0044, Yuming Hao
Knowl. Based Syst.3
2025 InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation Learning
abstract
Industrial control protocols (ICPs) play a significant role in ensuring dependable interconnection among devices in industrial environments. Protocol reverse engineering (PRE) techniques are commonly used to analyze a large number of agnostic and proprietary protocols based on network traffic traces or programs. However, conventional PRE methods face several challenges in reversing ICPs with complex data representations that contain rich structural features. In this work, we present a new perspective on message representation using the graph, and design a syntax inference framework for ICPs reverse analysis (InSyfer). Specifically, we propose a novel method to construct a single message graph for entire traces, automatically extracting syntactical similarity features. We also design an adaptive message clustering model that abstracts the clustering problem into a binary pairwise-classification framework to judge whether pairs of messages belong to the same groups and jointly optimizes it with feature extraction. The above design enables InSyfer to accurately identify message types and greatly improves the correctness of protocol format inference. We conduct extensive experiments to verify the effectiveness of InSyfer. Evaluations of four standard ICPs and two unknown protocols demonstrate that InSyfer outperforms the state-of-the-art PRE methods.
Daoqing Yang, Yu Yao 0002, Yao Shan, Xiaoli Lin, Wei Yang 0044, Licheng Yang 0002
IEEE Trans. Dependable Secur. Comput.1
2025 Patty: Pattern Series-Based Semantics Analysis for Agnostic Industrial Control Protocols
abstract
Reverse engineering of agnostic industrial control protocols (ICPs) based on traffic traces is significant for the security analysis of industrial control systems. Field semantics deduction is an essential step in protocol reverse engineering following the discovery of the message field. Most existing methods rely on knowledge-based analysis for specific fields of common protocols, which require too numerous assumptions and lack semantic knowledge about ICPs. In this paper, we propose a new concept, pattern series, and design the first classification framework for inferring the semantic types of unknown ICPs. Specifically, we first present the definition of pattern series and design the field pattern series generation algorithm for building training data, then develop a field semantics classification model to learn and apply semantic features from known protocols to predict semantic types in unknown protocols. Lastly, we implement a probability-maximizing selection algorithm to obtain optimal semantic types. We demonstrate the effectiveness of the proposed method through extensive experiments with five popular ICPs, including their mixed protocols. Evaluations show that our approach significantly outperforms baseline methods in field semantic recognition, achieving ≥90.8% F1-score.
Daoqing Yang, Yu Yao 0002, Yao Shan, Licheng Yang 0002, Wei Yang 0044, Fuyi Liu
IEEE Trans. Inf. Forensics Secur.1