EDBT 2026 Demo / reviewers in the wild / expert
Jing Liu 0028
dblp:72/2590-28
· DBLP profile ↗
17ranked-venue papers
1as first author
14since 2021 · last 2026
0000-0002-7495-4419ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RRFuzzer: A Fuzzing Framework for Proprietary Industrial Control System Protocols Using a Combination Strategy
Yingxu Lai, Yutong Dang, Huimin Fang, Shen Lu, Jing Liu 0028 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Improving Knowledge Tracing Through Learning Processes and Concept Similarity MapabstractKnowledge Tracing (KT) aims to track the evolving knowledge states of students based on their historical performance, playing a vital role in online intelligent education systems. While deep learning-based knowledge tracing achieves impressive predictive performance, existing methods suffer from two main shortcomings. Firstly, storing massive amounts of historical information introduces irrelevant noise during the training process. Additionally, individual differences may prevent the model from accurately capturing students comprehensive states. Secondly, deep learning models lack interpretability, failing to provide precise descriptions of students knowledge states. This paper proposes an improved knowledge tracing method through learning processes and concept similarity map (LCKT). We incorporate diverse features, including exercise, exercise difficulty, concept, response time, response, and interval time, to measure the diversity of exercise interactions. Additionally, we utilize a forgetting gate to simulate the decline of students knowledge over time during the learning process. Furthermore, we introduce a concept similarity map as a constraint for model training, which clearly delineates students mastery across different knowledge points. Extensive experiments on three real-world datasets demonstrate that LCKT outperforms state-of-the-art KT methods and exhibits interpretability to some extent. Yingxu Lai, Xinrui Dong, Junxi Zhuang, Jing Liu 0028 |
SMC | 6 |
| 2024 | AGCM: A multi-stage attack correlation and scenario reconstruction method based on graph aggregation
Hongshuo Lyu, Jing Liu 0028, Yingxu Lai, Beifeng Mao, Xianting Huang |
Comput. Commun. | 2 |
| 2024 | NCMFuzzer: Using non-critical field mutation and test case combination to improve the efficiency of ICS protocol fuzzing
Hanxiao Wanyan, Yingxu Lai, Jing Liu 0028, Hao Chen 0164 |
Comput. Secur. | 3 |
| 2024 | Interpretable Cross-Layer Intrusion Response System Based on Deep Reinforcement Learning for Industrial Control SystemsabstractOwing to the increasing number of cybersecurity threats targeting industrial control systems (ICSs), intrusion response systems (IRSs) have become essential. However, the current IRSs exhibit several limitations, such as neglecting physical domain security policies and relying significantly on expert input. While deep reinforcement learning (DRL) methods yield superior outcomes, they suffer from low interpretability and unreliability. This study introduces an interpretable cross-layer intrusion response system (ICL-IRS), which is a decision-tree-based IRS. It offers a robust understanding of cyberattacks and industrial control logic specific to ICSs. ICL-IRS employs a DRL model, tailored to the characteristics of physical process control, to refine policies. It then scrutinizes the optimized intrusion response policy and generates decision trees. Our experimental results reveal a 21% enhancement in the success rate of the proposed ICL-IRS over competing methods. The effectiveness of ICL-IRS was further validated through a case study on a simulated process-control system. Hao Chen 0164, Yingxu Lai, Jing Liu 0028, Hanxiao Wanyan |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Selective forwarding attack detection and network recovery mechanism based on cloud-edge cooperation in software-defined wireless sensor network
Shiyao Luo, Yingxu Lai, Jing Liu 0028 |
Comput. Secur. | 3 |
| 2023 | MSGAN: multi-stage generative adversarial network-based data recovery in cyber-attacks
Bitao Tian, Yingxu Lai, Samuel S. M. Sun, Yipeng Wang 0001, Jing Liu 0028 |
Neural Comput. Appl. | 5 |
| 2023 | EEFED: Personalized Federated Learning of Execution&Evaluation Dual Network for CPS Intrusion DetectionabstractIn the modern interconnected world, intelligent networks and computing technologies are increasingly being incorporated in industrial systems. However, this adoption of advanced technology has resulted in increased cyber threats to cyber-physical systems. Existing intrusion detection systems are continually challenged by constantly evolving cyber threats. Machine learning algorithms have been applied for intrusion detection. In these techniques, a classification model is trained by learning cyber behavior patterns. However, these models typically require considerable high-quality datasets. Limited attack samples are available because of the unpredictability and constant evolution of cyber threats. To address these problems, we propose a novel federated Execution & Evaluation dual network framework (EEFED), which allows multiple federal participants to personalize their local detection models undermining the original purpose of Federated Learning. Thus, a general global detection model was developed for collaboratively improving the performance of a single local model against cyberattacks. The proposed personalized update algorithm and the optimizing backtracking parameters replacement policy effectively reduced the negative influence of federated learning in imbalanced and non-i.i.d distribution of data. The proposed method improved model stability. Furthermore, extensive experiments conducted on a network dataset in various cyber scenarios revealed that the proposed method outperformed single model and state-of-the-art methods. Xianting Huang, Jing Liu 0028, Yingxu Lai, Beifeng Mao, Hongshuo Lyu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Intrusion Detection System Based on In-Depth Understandings of Industrial Control LogicabstractIn industrial control systems (ICSs), intrusion detection is a vital task. Conventional intrusion detection systems (IDSs) rely on manually designed rules. These rules heavily depend on professional experience, thereby making it challenging to represent the increasingly complicated industrial control logic. Although deep learning-based approaches provide better accuracy than other methods, they can only provide alerts. However, they cannot provide administrators with detailed information. In this study, we propose the logic understanding IDS (LU-IDS), which is a rule-based IDS with in-depth understandings of industrial control logic. Our proposed LU-IDS uses a specially designed deep learning-based model to capture features automatically and carry out attack classification. More importantly, it analyzes the knowledge learned from the classification of attacks to understand the abnormal industrial control logic and generate rules. The experimental results indicate that our proposed LU-IDS demonstrates excellent performance on intrusion detection. The rules generated by our proposed LU-IDS can be used to successfully detect all types of attacks on two public datasets. Motong Sun, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Beifeng Mao, Haoran Gu |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Identifying malicious nodes in wireless sensor networks based on correlation detectionabstractThe wireless sensor network (WSN) is a multi-hop wireless network that comprises multiple sensor nodes arranged in a self-organized manner. It is usually deployed in unattended areas where sensor nodes can easily be infiltrated by attackers who can affect the detection results by injecting false data. This paper proposes a malicious-node identification method based on correlation theory that prevents fault data injection attacks. First, anomalies among similar types of sensor data are detected based on time correlation. Second, malicious nodes are identified based on spatial correlation. Third, the identified malicious nodes are verified based on event correlation. The experimental results and their comparison with those of existing methods show that the proposed scheme has better recall with lower false-positive and false-negative rates than those of the traditional fuzzy reputation model and weighted-trust-based methods. Yingxu Lai, Liyao Tong, Jing Liu 0028, Yipeng Wang 0001, Hua Qin |
Comput. Secur. | 3 |
| 2022 | Stealthy attack detection method based on Multi-feature long short-term memory prediction model
Jiexi Wang, Yingxu Lai, Jing Liu 0028 |
Future Gener. Comput. Syst. | 3 |
| 2022 | DEIDS: a novel intrusion detection system for industrial control systemsabstractAbstract Owing to the development of industrial production, the hidden danger in industrial control systems (ICSs) has considerably increased, causing challenges in traditional safety defense methods. The combination of machine-learning or deep-learning algorithms and intrusion detection systems (IDSs) has become the mainstream method for solving this problem. However, these methods depend on a massive amount of high-quality attack traffic data, which cannot be obtained easily owing to the independence and unique characteristics of ICSs. In this study, we apply the reconstructed convolutional neural network and a data expansion algorithm named CenterBorderline_SMOTE (CB_SMOTE) to an IDS and propose data expansion intrusion detection system (DEIDS). The DEIDS is an end-to-end detection model that learns representative attack features from raw traffic and classifies them in a unified framework. Moreover, we adopt the classification activation map structure, which can deeply mine the potential characteristics of traffic and enhance the effectiveness of attack features. While enhancing the data quality, we introduce the designed CB_SMOTE algorithm into DEIDS to expand the data and solve the problem of insufficient attack data in the system. Our comprehensive experiments on different open datasets indicate that DEIDS achieves an excellent performance (97 $$\%$$ % detection accuracy) and outperforms the state-of-the-art methods. The experimental results also show that our method has high efficiency and high accuracy in processing ICSs datasets. Haoran Gu, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Motong Sun, Beifeng Mao |
Neural Comput. Appl. | 4 |
| 2022 | Correction to: DEIDS: a novel intrusion detection system for industrial control systems
Haoran Gu, Yingxu Lai, Yipeng Wang 0001, Jing Liu 0028, Motong Sun, Beifeng Mao |
Neural Comput. Appl. | 4 |
| 2021 | MIF: A multi-step attack scenario reconstruction and attack chains extraction method based on multi-information fusionabstractMost attacks on the Internet are progressive attacks and exploit multiple nodes. Traditional Intrusion Detection Systems (IDS) cannot detect the original attack node, making it difficult to block the attack at its source. This paper focuses on using IDS’ alerts corresponding to abnormal traffic to correlate attacks detected by the IDS, reconstruct multi-step attack scenarios and discover attack chains. Due to many false positives in the information provided by IDS, accurate reconstruction of the attack scenario and extraction of the most critical attack chain is challenging. Therefore, we propose a method to reconstruct multi-step attack scenarios in the network based on multiple information fusion of attack time, risk assessment and attack node information. First, we propose a Convolution and Agent Decision Tree Network (CTnet), a convolutional neural network that evaluates the attacks detected by the IDS and gives an alert with an attack risk assessment. Then, we reconstruct the weighted attack scenario by applying Graph-based Fusion Module (GM) on the captured attacks’ risk assessment and time information. Finally, we extract the high-risk attack chain by Depth First Search with Time and Weight (TW-DFS) algorithm. The experimental results show that the proposed method can accurately reconstruct multi-step attack scenarios and trace them back to the original host. It can help administrators to deploy security measures more effectively to ensure the overall security of the network. Beifeng Mao, Jing Liu 0028, Yingxu Lai, Motong Sun |
Comput. Networks | 2 |
| 2020 | Protection of Sensitive Data in Industrial Internet Based on Three-Layer Local/Fog/Cloud StorageabstractIndustrial Internet technology has developed rapidly, and the security of industrial data has received much attention. At present, industrial enterprises lack a safe and professional data security system. Thus, industries urgently need a complete and effective data protection scheme. This study develops a three-layer framework with local/fog/cloud storage for protecting sensitive industrial data and defines a threat model. For real-time sensitive industrial data, we use the improved local differential privacy algorithm M-RAPPOR to perturb sensitive information. We encode the desensitized data using Reed–Solomon (RS) encoding and then store them in local equipment to realize low cost, high efficiency, and intelligent data protection. For non-real-time sensitive industrial data, we adopt a cloud-fog collaborative storage scheme based on AES-RS encoding to invisibly provide multilayer protection. We adopt the optimal solution of distributed storage in local equipment and the cloud-fog collaborative storage scheme in fog nodes and cloud nodes to alleviate the storage pressure on local equipment and to improve security and recoverability. According to the defined threat model, we conduct a security analysis and prove that the proposed scheme can provide stronger data protection for sensitive data. Compared with traditional methods, this approach strengthens the protection of sensitive information and ensures real-time continuity of open data sharing. Finally, the feasibility of our scheme is validated through experimental evaluation. Jing Liu 0028, Changbo Yuan, Yingxu Lai, Hua Qin |
Secur. Commun. Networks | 1 |
| 2019 | Industrial Control Intrusion Detection Approach Based on Multiclassification GoogLeNet-LSTM ModelabstractIntrusion detection is essential for ensuring the security of industrial control systems. However, conventional intrusion detection approaches are unable to cope with the complexity and ever-changing nature of industrial intrusion attacks. In this study, we propose an industrial control intrusion detection approach based on a combined deep learning model for communication processes that use the Modbus protocol. Initially, the network packets are classified as carrying information and noncarrying information based on key fields according to the communication protocol used. Next, a template comparison approach is employed to detect the network packets that do not carry any information. Furthermore, an approach based on a GoogLeNet-long short-term memory model is used to detect the network packets that do carry information. This approach involves network packet sequence construction, feature extraction, and time-series level detection. Subsequently, the detected intrusions are classified into multiple categories through a Softmax classifier. A gas pipeline dataset of the Modbus protocol is used to evaluate the proposed approach and compare it with existing strategies. The accuracy, false-positive rate, and miss rate are 97.56%, 2.42%, and 2.51%, respectively, thus confirming that the proposed approach is suitable for intrusion detection in industrial control systems. Ankang Chu, Yingxu Lai, Jing Liu 0028 |
Secur. Commun. Networks | 3 |
| 2015 | Study on Authentication Protocol of SDN Trusted DomainabstractCurrently Software Define Network (SDN) architecture has become a hot topic. Aiming at the authentication security issues of SDN network architecture, we introduce an authentication protocol based on SDN network architecture without any trusted third party between trusted domains. By applying AVISPA security analysis system of network interaction protocol, we can guarantee protocol security and provide complete safety tests. Our work fill the gap of mutual trust between different trusted domains and provide security foundation for interaction between different trusted domains. Ruikang Zhou, Yingxu Lai, Zenghui Liu, Jing Liu 0028 |
ISADS | 4 |