Zhenyong Zhang

dblp:89/6855 · DBLP profile ↗
← Back
35ranked-venue papers
13as first author
29since 2021 · last 2026
0000-0003-0950-1525ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 7 first-author · 14 since 2021Security and privacy · 12 · 3 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 FedCLD: A Federated Contrastive Learning Approach for Detecting Stealthy Attacks on Smart Grid With Unlabeled Data
abstract
The smart grid is a critical infrastructure that must function reliably in a geographically decentralized structure. However, this structure renders the smart grid vulnerable to stealthy cyberattacks, and data silos further limit the sharing of datasets needed to train an effective attack-detection model. Moreover, most existing methods rely on the availability of enormous amounts of labeled data, which is scarce due to the need for domain knowledge. To address these issues, we propose FedCLD, a federated contrastive learning approach for detecting stealthy attacks using unlabeled data. FedCLD leverages Bootstrap Your Own Latent (BYOL), a contrastive learning model, to enhance its ability to learn robust representations from unlabeled data. With the federated learning paradigm, FedCLD enables local centers in different areas to collaboratively train local models without sharing raw datasets. Although the global representation is enhanced, the regional characteristics should be preserved. Therefore, a strategic local update scheme based on the exponential moving average is proposed. Furthermore, we theoretically prove the convergence of FedCLD with this modified update strategy. Experiments are conducted in the industry-level PowerWorld simulator to evaluate the performance of FedCLD.
Xiaohan Huang 0014, Zhenyong Zhang, Chao Ren 0006, David K. Y. Yau, Ruilong Deng
IEEE Internet Things J.2
2026 An Automated Semantic Analysis Framework for Controller Variables Based on Network Traffic
abstract
Programmable logic controllers (PLCs) play a crucial role in various industrial manufacturing processes. Recent attack events show that attackers have a strong interest in controller variables of PLCs, including the device status and internal program logic. Detecting anomalous messages targeting PLC controller variables, which relies on the analysis of controller variable semantics, has proven to be an effective method for identifying such attacks. However, the proprietary nature of industrial control protocols (ICPs) poses a challenge to extracting the required semantics. In this paper, we propose an automated framework namedSePannerto extract the semantics of controller variables from proprietary ICPs based on network traffic. Specifically, we first collect multiple groups of interaction traffic of PLCs and perform the starting-aligned comparisons on them to locate the semantic fields directly. Then, we identify and investigate a new problem in semantic extraction — interference resulting from misordered messages — and propose a set of filtering criteria to eliminate it effectively. We evaluate SePanner using the S7COMM protocol, and the results indicate that SePanner can successfully extract the semantics of controller variables with 100% accuracy. Additionally, we employ SePanner to analyze 7 proprietary ICPs, successfully extracting the semantics of 63 controller variables and their 134 states. Additionally, we demonstrate the extensive applications of SePanner in multiple ICS security scenarios and present its better performance compared with existing ICP semantic analyzing tools.
Zeyu Yang 0001, Zhenyong Zhang, Yangyang Geng, Ruilong Deng, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Disguised Attack in the Metaverse: A New Threat to Avatar-Based Identity Security
abstract
Metaverse is a virtual world parallel to reality, where users can socialize with others in the form of the digital avatars. However, due to the excessive reliance on the avatar in the interaction process, there are vulnerabilities such as identity forgery. Attackers can steal the appearance and voice of the victim’s avatar and create a similar disguised avatar. Unlike fake identities on traditional social platforms, identity forgery in the Metaverse requires imitation of appearance and voice, and interactive behaviors must be synchronized in real time. To study this threat, an avatar disguise attack in the Metaverse scenario is proposed, and the effectiveness of the attack is verified. With the utilization of avatar creation tools and the Generative Pre-trained Transformer for the Speech-to-Video Voice Transformation System (GPT-SoVITS) model combined with Convolutional Recurrent Neural Networks (CRNN), appearance imitation and voice cloning are carried out. Then we manipulate the disguised avatar to deceive the victim into providing sensitive information and/or inducing behavior that harms virtual assets. The experimental results conducted on the Xirang and VSVR Metaverse platforms confirmed the feasibility of the disguised attack. The misrecognition rate of blind tests of appearance imitation is as high as 77%, and the success rate of the disguised attack after voice cloning can reach up to 60%. This attack poses a serious threat to identity security in the Metaverse.
Zhenyong Zhang, Ruilong Deng
TrustCom2
2025 Small-Signal-Stability-Guaranteed Moving Target Defense Against Load Redistribution Attack on IoT-Based Smart Grid
abstract
Moving target defense (MTD) is a promising approach to defend against load redistribution attacks on the Internet of Things (IoT)-based smart grid networks by probing the distorted state estimates with the distributed flexible AC transmission system. However, existing studies mainly focus on optimizing the performance of MTD and ignore the safety effect of it on the system’s operation. In this article, we fill this gap by deeply analyzing the effect of MTD on the small signal stability and aim to alleviate the negative impact and guarantee its defending performance simultaneously. First, the stability is formally described using the eigenvalue sensitivity. The relationship between the MTD-induced perturbation (MTDper) and the stability criteria is derived. Second, a new indicator is proposed to measure the effectiveness of MTDper. Third, a constrained optimization problem is formulated to compute the bound of MTDper for guaranteeing the small signal stability. In addition, a surprising finding is that the stability margin can be improved and enhanced by optimizing the value of MTDper without losing the MTD’s effectiveness. Finally, we evaluate the performance of MTDper and its impact on the small signal stability with extensive simulations on the IEEE 30-bus, 39-bus, and 68-bus test power systems.
Bingdong Wang, Zhenyong Zhang, Mufeng Wang, Mengxiang Liu, Ruilong Deng, Xin Zhang 0028
IEEE Internet Things J.2
2025 A Traceable Continuous Authentication Scheme for Avatars in Large-Scale Commercial Activities
abstract
Metaverse allows users to immersively interact with millions of partners, breaking through the constraints of the physical world. To ensure the traceability of malicious avatars, provers in large-scale commercial activities need to periodically submit identity parameters to the verifier as interaction evidence, imposing a disastrous communication and storage burden on both parties. In this article, we propose a traceable and efficient continuous authentication scheme for large-scale avatars. First, we construct a continuous authentication framework, where the prover’s device locally checks its manipulator to submit the starting and ending identities as interaction evidence. Second, we propose a transitive signature scheme with path verifiability to ensure the relevance and unforgeability of the starting and ending identities. Finally, we design a traceable authentication protocol based on the proposed signature scheme to reduce communication and storage costs while guaranteeing traceability. Security analysis shows that the protocol not only defends against the attacks of device hijacking and false accusations but also supports virtual-to-physical tracking. Extensive evaluations show that the communication cost and storage costs are reduced by 95.97% and 98.35%, respectively, which can be used for avatar authentication and tracking in large-scale commercial activities.
Kedi Yang, Zhenyong Zhang, Youliang Tian, Jianfeng Ma 0001
IEEE Internet Things J.2
2025 FDTA: A Value-Guaranteed Fair Data Trading Approach With a Three-Stage Stackelberg Game
abstract
With the merging of the Internet of Things and artificial intelligence, the data becomes valuable stuff and can be traded between utilities. Unfortunately, low-value data and conflicting interests among participants hinder the progress of data trading. To facilitate trading, assessing the data value and balancing the interests of each party gained widespread attention. In this article, we propose a value-guaranteed data trading approach using a three-stage Stackelberg game (SG), i.e., fair data trading approach (FDTA). Specifically, a consignment contract is negotiated between the trusted platform and data providers, which helps to release the cost of sale for both parties. A data-value quantification approach is developed based on the data size, completeness, and usability. Combined with the consignment contract, the data value is transparent to all parties before trading. Furthermore, a three-stage SG model is constructed to simulate the interactions between the trusted platform, data provider, and data consumer regarding data value. The trusted platform and data provider are the leaders, while the consumer is the follower. Besides, we prove that there is a unique Nash equilibrium in this game, ensuring that the interests of all participants are balanced. Finally, we conduct extensive experiments to evaluate the performance of FDTA. The results show that FDTA can effectively guarantee the effectiveness of data-value assessment and the fairness of trading.
Junyan Zhu, Zhenyong Zhang, Bingdong Wang, Kuan Shao, Zheqiu Hetu, Xin Wang 0044
IEEE Internet Things J.2
2025 Black-box adversarial attacks on deep reinforcement learning-based proportional-integral-derivative controllers for load frequency control
abstract
Load frequency control (LFC) is usually managed by traditional proportional–integral–derivative (PID) controllers. Recently, deep reinforcement learning (DRL)-based adaptive controllers have been widely studied for their superior performance. However, the DRL-based adaptive controller exhibits inherent vulnerability due to adversarial attacks. To develop more robust control systems, this study conducts a deep analysis of DRL-based adaptive controller vulnerability under adversarial attacks. First, an adaptive controller is developed based on the DRL algorithm. Subsequently, considering the limited capability of attackers, the DRL-based LFC is evaluated under adversarial attacks using the zeroth-order optimization (ZOO) method. Finally, we use adversarial training to enhance the robustness of DRL-based adaptive controllers. Extensive simulations are conducted to evaluate the performance of the DRL-based PID controller with and without adversarial attacks.
Zhenyong Zhang, Xin Wang 0044, Xuguo Jiao
Frontiers Inf. Technol. Electron. Eng.2
2025 SSTAF: Security Settings-Based Threat Assessment Framework of Programmable Logic Controllers
abstract
Industrial control systems (ICSs) govern the production activities of various critical infrastructures, where programmable logic controllers (PLCs) are essential devices for controlling industrial processes. However, PLCs have many vulnerabilities and might be configured inappropriately. With the trend of PLCs connecting to the Internet, such weaknesses will lead to various cyberattacks and have prompted many studies on the threat assessment for PLCs. Previous research has ignored PLCs’ security settings, such as operating mode and read/write authentication etc., which are the general security functionalities significantly affecting PLCs’ security. In this paper, we make the first attempt to propose a security settings-based threat assessment framework (SSTAF) to assess PLCs’ security.SSTAFconsists ofSScanner, a novel scanner to automatically extract the real-time configurations of security settings from PLCs, and the threat assessment criteria, serving to assess the appropriateness of PLC configurations and analyze risk levels of attacks based on PLCs’ security settings. Subsequently, usingSSTAF, we implement an Internet-wide threat assessment for PLCs exposed to the Internet. We deploySScanneron the Internet and interact with 41K ICS devices in cyberspace to acquire their configurations of security settings. Based on the scanning result and the threat assessment criteria, we reveal that 93.32% of PLCs have not appropriately configured their security settings. Additionally, each PLC might be subject to 4.96 attacks on average, of which 3.32 attacks are due to the inappropriate configurations of security settings.
Zhenyong Zhang, Hengye Zhu, Zeyu Yang 0001, Ruilong Deng, Peng Cheng 0001, Jianying Zhou 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Variational Quantum Circuit and Quantum Key Distribution-Based Quantum Federated Learning: A Case of Smart Grid Dynamic Security Assessment
abstract
This paper proposes a hybrid Quantum Federated Learning (QFL) method, called QQFL, a revolutionary approach for Dynamic Security Assessment (DSA) optimized for modern smart grids. Built on the synergy of measurement-device-independent QKD (MDI-QKD) and Variational Quantum Circuit (VQC), QQFL uniquely addresses the challenges of centralized structures and vulnerabilities in existing ML-based DSA techniques. It enables accurate label predictions for quantum states encoded from classical DSA data while ensuring data security via QKD networks. A novel mechanism, the DNN-based MDI-QKD optimizer, ensures optimal secret key exchange. Unlike traditional methods reliant solely on classical CPUs, QQFL integrates QPUs for executing computational tasks. Given the imperative of frequent data transmission in modern rapidly changing smart grid environment, QQFL emphasizes swift online learning and dynamic deployment. Testing on the synthetic Illinois 49-machine 200-bus system affirms QQFL's superior the DSA accuracy while upholding the data privacy of smart grids. Ultimately, QQFL enhances the security, reliability, confidentiality, and robustness of sophisticated smart grids.
Chao Ren 0006, Minrui Xu, Han Yu 0001, Zehui Xiong, Zhenyong Zhang, Dusit Niyato
ICC5
2024 Poisoning Attack on Federated Learning with Non-IID Data: A Historical-Global-Model-Based Approach
Yaqi Sun, Xin Wang 0044, Zhenyong Zhang, Ming Yang 0023, Yunpeng He
SecureComm (4)3
2024 Traceable AI-driven Avatars Using Multi-factors of Physical World and Metaverse
abstract
Metaverse allows users to delegate their AI models to an AI engine, which builds corresponding AI-driven avatars to provide immersive experience for other users. Since current authentication methods mainly focus on human-driven avatars and ignore the traceability of AI-driven avatars, attackers may delegate the AI models of a target user to an AI proxy program to perform impersonation attacks without worrying about being detected.In this paper, we propose an authentication method using multi-factors to guarantee the traceability of AI-driven avatars. Firstly, we construct a user’s identity model combining the manipulator’s iris feature and the AI proxy’s public key to ensure that an AI-driven avatar is associated with its original manipulator. Secondly, we propose a chameleon proxy signature scheme that supports the original manipulator to delegate his/her signing ability to an AI proxy. Finally, we design three authentication protocols for avatars based on the identity model and the chameleon proxy signature to guarantee the virtual-to-physical traceability including both the human-driven and AI-driven avatars.Security analysis shows that the proposed signature scheme is unforgeability and the authentication method is able to defend against false accusation. Extensive evaluations show that the designed authentication protocols complete user login, avatar delegation, mutual authentication, and avatar tracing in about 1s, meeting the actual application needs and helping to mitigate impersonation attacks by AI-driven avatars.
Kedi Yang, Zhenyong Zhang, Youliang Tian
TrustCom2
2024 Vulnerability of Machine Learning Approaches Applied in IoT-Based Smart Grid: A Review
abstract
Machine learning (ML) sees an increasing prevalence of being used in the internet-of-things (IoT)-based smart grid. However, the trustworthiness of ML is a severe issue that must be addressed to accommodate the trend of ML-based smart grid applications (MLsgAPPs). The adversarial distortion injected into the power signal will greatly affect the system’s normal control and operation. Therefore, it is imperative to conduct vulnerability assessment for MLsgAPPs applied in the safety-critical power systems. In this paper, we provide a comprehensive review of the recent progress in designing attack and defense methods for MLsgAPPs. Unlike the traditional survey about ML security, this is the first review work about the security of MLsgAPPs that focuses on the characteristics of power systems. We first highlight the specifics for constructing adversarial attacks on MLsgAPPs. Then, the vulnerability of MLsgAPP is analyzed from the perspective of the power system and ML model, respectively. Afterward, a comprehensive survey is conducted to review and compare existing studies about the adversarial attacks on MLsgAPPs in scenarios of generation, transmission, distribution, and consumption, and the countermeasures are reviewed according to the attacks that they defend against. Finally, the future research directions are discussed on the attacker’s and defender’s side, respectively. We also analyze the potential vulnerability of large language model-based (e.g., ChatGPT) smart grid applications. Overall, our purpose is to encourage more researchers to contribute to investigating the adversarial issues of MLsgAPPs.
Zhenyong Zhang, Mengxiang Liu, Ruilong Deng, Peng Cheng 0001, Dusit Niyato, Mo-Yuen Chow, Jiming Chen 0001
IEEE Internet Things J.1
2024 Limitation of Reactance Perturbation Strategy Against False Data Injection Attacks on IoT-Based Smart Grid
abstract
With the goal of defending against false data injection attacks (FDIAs) on state estimation (SE) of the Internet of Things (IoT)-based smart grid, recently, the reactance perturbation strategy (RPS) has been proposed by actively perturbing the branch reactances of transmission lines. Satisfied defending performance as it shows, the limitations have not been sufficiently studied by pioneer works. In this article, by exploring the vulnerability implied by the transmission network structure, we deeply investigate the limitations of RPS with both theoretical and numerical results. First, we prove that improperly selecting the branches to perturb can make RPS fail to prevent the SE from FDIAs. Second, by exploiting the properties of the system topology, we classify the branches and buses into different types and derive the limitations of RPS with analytical results. Third, an enhanced RPS is proposed to defend against FDIAs with a complete defense goal. Finally, extensive simulations are conducted in IEEE test power systems to verify the correctness of analytical results and validate the effectiveness of the enhanced RPS.
Zhenyong Zhang, Bingdong Wang, Mengxiang Liu, Youliang Tian, Jianfeng Ma 0001
IEEE Internet Things J.1
2024 The Potential Harm of Email Delivery: Investigating the HTTPS Configurations of Webmail Services
abstract
Webmail, protected by the HTTPS protocol, only works correctly if both the server and client implement HTTPS-related features without vulnerability. Nevertheless, the deployment situation of these features in the webmail world is still unclear. To this end, we perform the first end-to-end and large-scale measurement of webmail service. For the server side, we first build an email address set with a size of 2.2 billion. Then we construct two webmail domain datasets: one contains 21 k domains filtered from the email address set; the other only includes 34 domains but supports more than 75% of the 2.2 billion email addresses. After performing a comprehensive measurement on these two webmail domain datasets, we find that some features are poorly deployed. Furthermore, we also rank servers by analyzing the properties of HTTPS-related features. For the client side, we investigate implement of HTTPS-related features in 50 different combinations of web browsers and operating systems (OSes). We find that even the latest browsers have poor support for some features. For example, Firefox in all OSes does not support CT. Our findings highlight that the full deployment of the security features for the HTTPS ecosystem is still a challenge, even in the webmail service.
Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Xiaoqi Jia, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.2
2024 Physics-Aware Watermarking Embedded in Unknown Input Observers for False Data Injection Attack Detection in Cyber-Physical Microgrids
abstract
The physics-aware watermarking-based detection method has shown great potential in detecting stealthy False Data Injection Attacks (FDIAs) by adding appropriate watermarks to control commands or sensor measurements, especially in industrial control systems and grid-tied Distributed Energy Resources (DERs). However, existing watermarking-based detection methods have limitations in either handling the intricate physical couplings among DERs or characterising the fast changing power electronics dynamics, and thus cannot be directly applied to microgrids. Inspired by the methodology of Unknown Input Observer (UIO), which can be employed for the distributed anomaly monitoring in cyber-physical microgrids but would be easily bypassed once the adversary has the knowledge of certain electrical parameters, this paper makes the first attempt to investigate the physics-aware watermarking embedded in UIOs such that the stealthy FDIAs would be intentionally disrupted by the watermarking scheme. Based on the theoretical analysis of the detection enhancement and performance degradation under watermarking-enhanced UIOs, the watermark strengths, UIO parameters, and control gains are optimally co-designed to significantly enhance the detection effectiveness while not degrading the control performance. The robustness of the watermarking-enhanced UIO to Time Synchronisation Errors (TSEs) is improved by employing a sliding time window with appropriate length. The performance of the proposed method is validated through Matlab/Simulink studies and cyber-physical co-simulation experiments, and the sensitivities of the detection latency and TSE robustness to watermark strength and detection window’s length are comprehensively studied.
Mengxiang Liu, Xin Zhang 0028, Hengye Zhu, Zhenyong Zhang, Ruilong Deng
IEEE Trans. Inf. Forensics Secur.4
2024 An Anti-Disguise Authentication System Using the First Impression of Avatar in Metaverse
abstract
Metaverse is a vast virtual world parallel to the physical world, where the user acts as an avatar to enjoy various services that break through the temporal and spatial limitations of the physical world. Metaverse allows users to create arbitrary digital appearances as their own avatars by which an adversary may disguise his/her avatar to fraud others. In this paper, we propose an anti-disguise authentication method that draws on the idea of the first impression from the physical world to recognize an old friend. Specifically, the first meeting scenario in the metaverse is stored and recalled to help the authentication between avatars. To prevent the adversary from replacing and forging the first impression, we construct a chameleon-based signcryption mechanism and design a ciphertext authentication protocol to ensure the public verifiability of encrypted identities. The security analysis shows that the proposed signcryption mechanism meets not only the security requirement but also the public verifiability. Besides, the ciphertext authentication protocol has the capability of defending against the replacing and forging attacks on the first impression. Extensive experiments show that the proposed avatar authentication system is able to achieve anti-disguise authentication at a low storage consumption on the blockchain.
Zhenyong Zhang, Kedi Yang, Youliang Tian, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.1
2023 SePanner: Analyzing Semantics of Controller Variables in Industrial Control Systems based on Network Traffic
abstract
Programmable logic controllers (PLCs), the essential components of critical infrastructure, play a crucial role in various industrial manufacturing processes. Recent attack events show that attackers have a strong interest in tampering with the controller variables, such as the device status and internal program logic. A typical attack strategy is that the attackers just send malicious network traffic of industrial control protocols (ICPs) to change the controller variables of PLCs. To defend against this attack, a lot of countermeasures have been proposed to detect anomalies in network traffic based on the semantic analysis.
Zeyu Yang 0001, Zhenyong Zhang, Yangyang Geng, Ruilong Deng, Peng Cheng 0001, Jiming Chen 0001, Jianying Zhou 0001
ACSAC3
2023 Cybersecurity Analysis of Data-Driven Power System Stability Assessment
abstract
Machine learning-based intelligent systems enhanced with Internet of Things (IoT) technologies have been widely developed and exploited to enable the real-time stability assessment of a large-scale electricity grid. However, it has been extensively recognized that the IoT-enabled communication network of power systems is vulnerable to cyberattacks. In particular, system operating states, critical attributes that act as input to the data-driven stability assessment, can be manipulated by malicious actors to mislead the system operator into making disastrous decisions and thus cause major blackouts and cascading events. In this article, we explore the vulnerability of the data-driven power system stability assessment, with a special emphasis on decision tree-based stability assessment (DTSA) approaches, and investigate the feasibility of constructing a physics-constrained adversarial attack (PCAA) to undermine the DTSA. The PCAA is formulated as a nonlinear programming problem considering the misclassification constraint, power limits, and bad data detection, computing potential adversarial perturbations that reverse the “stable/unstable” prediction of the real-time input while remaining invisible/stealthy. Extensive experiments based on the IEEE 68-bus system are conducted to evaluate the impact of PCAAs on predictions of DTSA and their transferability.
Zhenyong Zhang, Ke Zuo, Ruilong Deng, Fei Teng 0005
IEEE Internet Things J.1
2023 A Secure Authentication Framework to Guarantee the Traceability of Avatars in Metaverse
abstract
Metaverse is a vast virtual environment parallel to the physical world in which users enjoy a variety of services acting as an avatar. To build a secure living habitat, it’s vital to ensure the virtual-physical traceability that tracking a malicious player in the physical world via his avatars in virtual space. In this paper, we propose a two-factor authentication framework based on biometric-based authentication and chameleon signature. First, aiming at disguise in virtual space, we design an avatar’s two-factor identity model to ensure the verifiability of avatar’s virtual identity and physical identity. Second, facing at authentication efficiency and keys holding cost, we propose a chameleon collision signature algorithm to efficiently ensure that the avatar’s virtual identity is associated with its physical identity. Finally, aiming at impersonation in the physical world, we design two decentralized authentication protocols based on the avatar’s identity model and the chameleon collision signature to achieve real-time authentication on the avatar’s identity. Security analysis indicates that the proposed authentication framework guarantees the consistency and traceability of the avatar’s identity. Simulation experiments show that the framework not only completes the decentralized authentication between avatars but also achieves virtual-physical tracking.
Kedi Yang, Zhenyong Zhang, Youliang Tian, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.2
2023 SPMA: Stealthy Physics-Manipulated Attack and Countermeasures in Cyber-Physical Smart Grid
abstract
As a critical infrastructure, the traditional power system has transformed into a cyber-physical integrated smart grid. However, the vulnerabilities exposed in either the cyber or physical layer might be exploited by adversaries to construct complicated and coordinated attacks consequent in destructive impacts. In this paper, we propose a stealthy physics-manipulated attack (SPMA) by masking the physical attacks on the flexible AC transmission system (FACTS) with strategic cyberattacks. To construct the SPMA, we first manipulate the control command sent to the FACTS device to change the reactance and then tamper with the sensor measurements to conceal it. The SPMA is constructed with complete-informed and incomplete-informed attackers, noisy sensor measurements, and a nonlinear AC model, respectively. The impact of the physics manipulation on the real-time economic dispatch and the system’s operation security are formulated and numerically analyzed. Furthermore, we also provide potential countermeasures from three aspects to defend against SPMAs. Finally, extensive experiments are conducted with the IEEE test power systems to evaluate the stealthiness of SPMAs and the economic losses and potential cascading failures caused by SPMAs using real-world load profiles.
Zhenyong Zhang, Ruilong Deng, Youliang Tian, Peng Cheng 0001, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.1
2023 A Longitudinal and Comprehensive Measurement of DNS Strict Privacy
abstract
The DNS privacy protection mechanisms, DNS over TLS (DoT) and DNS over HTTPS (DoH), only work correctly if both the server and client support the Strict Privacy profile and no vulnerability exists in the implemented TLS/HTTPS. A natural question then arises: what is the landscape of DNS Strict Privacy? To this end, we provide the first longitudinal and comprehensive measurement of DoT/DoH deployments in recursive resolvers, authoritative servers, and browsers. With the collected data, we find the number of DoT/DoH servers increased substantially during our ten-month-long scan. However, around 60% of DoT and 44% of DoH recursive resolver certificates are invalid. Worryingly, our measurements confirm the centralization problem of DoT/DoH. Furthermore, we classify DNS Strict Privacy servers into four levels according to daily scanning results on TLS/HTTPS-related security features. Unfortunately, around 25% of DoH Strict Privacy recursive resolvers fail to meet the minimum level requirements. To help the Internet community better perceive the landscape of DNS Strict Privacy, we implement a DoT/DoH server search engine and recommender system. Additionally, we investigate five popular browsers across four operating systems and find some inconsistent behavior with their DNS privacy implementations. For example, Firefox in Windows, Linux, and Android allows DoH communication with the server without the SAN certificate. At last, we advocate that all participants head together for a bright DNS Strict Privacy landscape by discussing current hindrances and controversies in DNS privacy.
Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Jingqiang Lin 0001, Xiaoqi Jia, Guiyi Wei
IEEE/ACM Trans. Netw.3
2023 Security Enhancement of Power System State Estimation With an Effective and Low-Cost Moving Target Defense
abstract
Moving target defense (MTD) is a new defensive mechanism developed in power systems to thwart false data injection attacks (FDIAs). However, since the MTD works by perturbing the branch parameters with the distributed flexible ac transmission system (D-FACTS), it might cause additional infrastructure and operation costs and affect the system dynamics. This is a complicated problem because it is closely related to which branches should be perturbed and how much they are changed. In this article, we analyze the essentials of MTD and construct an effective and low-cost MTD. To begin with, we provide a sufficient and necessary condition for MTD to protect a bus from being affected by the intended FDIA. Based on this result, we propose a new metric to quantify the protection level of MTD and an efficient algorithm to minimize the number of required D-FACTS devices for protecting a specific set of buses. To reduce the operation cost, we develop two strategies to make the increasing operation cost zero for activating the MTD. Furthermore, we analyze the impact of MTD on the system dynamics with a special emphasize on small signal stability. Finally, we conduct extensive simulations to validate our findings with the test cases of power systems in MATPOWER.
Zhenyong Zhang, Ruilong Deng, David K. Y. Yau, Peng Cheng 0001, Mo-Yuen Chow
IEEE Trans. Syst. Man Cybern. Syst.1
2022 Toward a Trust Evaluation Framework Against Malicious Behaviors of Industrial IoT
abstract
With the development of the Industrial Internet of Things (IIoT) technology, edge computing is a promising area to release the sensing and computing burdens from the overloaded center. However, in edge network scenarios, we cannot trust every node’s output since some nodes can behave maliciously by making use of the properties, such as multiple identities, heterogeneous capabilities, and mobility. In that case, trust management is widely used to solve the problem of network trustworthiness. In this article, we propose a trust evaluation framework by comprehensively considering the nodes’ malicious behaviors and heterogeneous characteristics of edge networks. Under the Bayesian framework, we use the semi-ring theory to dynamically establish mobile-edge nodes’ trust models. First, we calculate the trust value for each node with a different identity (service provider or requester). Then, we propose a security-regarded task allocation mechanism to improve the reliability of selected trusted nodes according to the matched relationship between the service requesters’ expected capability and the providers’ actual capability. Further, we conduct extensive analysis and simulations to evaluate the proposed methods in typical IIoT scenarios. The results show that the proposed method has better immunity to abnormal behaviors, including the noncooperation, malicious feedback, on–off attacks, Sybil attacks, whitewashing attack, malicious access, etc., and has higher scheduling accuracy and controllable time complexity compared to existing methods.
Mufeng Wang, Zhenyong Zhang, Hengye Zhu
IEEE Internet Things J.3
2022 On Feasibility of Coordinated Time-Delay and False Data Injection Attacks on Cyber-Physical Systems
abstract
With the widespread adoption of Internet of Things (IoT) technologies, cyber–physical systems (CPSs) are facing threats from cyberattacks due to the vulnerabilities exposed in IoT devices. In this article, we analyze the feasibility of a coordinated attack, named TD-FDIA, on CPS by the synchronizing the time-delay attack (TDA) and false data injection attack (FDIA). It seems that the coordinated attack is more powerful than either one. But the analysis of its stealthiness and effectiveness is challenging. In the context of the networked control system, we first propose a general formulation for the impact of TD-FDIA on the system’s stability. Then, we analyze whether the combination of TDA and FDIA can destabilize the system and remain stealthy or not with different setups when the controller is with and without an observer, and the communication protocol between the controller and actuator is UDP and TCP, respectively. The conditions required to make TD-FDIA stealthy are given in some cases. Finally, we conduct extensive experiments to evaluate the impact of TDA, FDIA, and TD-FDIA on the system’s stability with three different CPS scenarios.
Zhenyong Zhang, Ruilong Deng, Peng Cheng 0001
IEEE Internet Things J.1
2022 A Double-Benefit Moving Target Defense Against Cyber-Physical Attacks in Smart Grid
abstract
The smart grid (SG), as one of the largest evolutionary critical infrastructures, witnesses the deep integration of electricity facilities and Internet of Things (IoT). But recent events show that the vulnerabilities exposed in IoT devices can be exploited by adversaries to construct the cyberattacks on SG. To address this threat, plenty of countermeasures have been proposed to enhance the SG’s security. However, the additional costs introduced by some countermeasures make the utilities hesitate to implement them practically. To alleviate this concern, in this article, we propose a double-benefit moving target defense (dB-MTD) to protect the SG from cyber–physical attacks (CPAs) and also gain generation-cost benefits. The dB-MTD enables the prevention of stealthy CPAs on the transmission lines by perturbing the reactances with the distributed flexible AC transmission system (D-FACTS). To reduce the infrastructure cost, we minimize the number of required D-FACTS devices for a specific protection goal. Although it needs investment on D-FACTS, we find that the utility can make profits from the generation costs by appropriately setting the reactance perturbations. Therefore, we formulate an optimization problem to compute the optimal reactance perturbations to maximize the generation-cost benefits, without sacrificing the protection performance of dB-MTD. Finally, using the real-world load profiles, we conduct extensive simulations to evaluate the impact of CPA on the system operation and the benefits obtained by the dB-MTD from the aspects of the D-FACTS deployment and the generation-cost profits.
Zhenyong Zhang, Youliang Tian, Ruilong Deng, Jianfeng Ma 0001
IEEE Internet Things J.1
2022 Detection and localization of cyber attacks on water treatment systems: an entropy-based approach
abstract
With the advent of Industry 4.0, water treatment systems (WTSs) are recognized as typical industrial cyber-physical systems (iCPSs) that are connected to the open Internet. Advanced information technology (IT) benefits the WTS in the aspects of reliability, efficiency, and economy. However, the vulnerabilities exposed in the communication and control infrastructure on the cyber side make WTSs prone to cyber attacks. The traditional IT system oriented defense mechanisms cannot be directly applied in safety-critical WTSs because the availability and real-time requirements are of great importance. In this paper, we propose an entropy-based intrusion detection (EBID) method to thwart cyber attacks against widely used controllers (e.g., programmable logic controllers) in WTSs to address this issue. Because of the varied WTS operating conditions, there is a high false-positive rate with a static threshold for detection. Therefore, we propose a dynamic threshold adjustment mechanism to improve the performance of EBID. To validate the performance of the proposed approaches, we built a high-fidelity WTS testbed with more than 50 measurement points. We conducted experiments under two attack scenarios with a total of 36 attacks, showing that the proposed methods achieved a detection rate of 97.22% and a false alarm rate of 1.67%.
Mufeng Wang, Rongkuan Ma, Zhenyong Zhang
Frontiers Inf. Technol. Electron. Eng.4
2022 A Trust Management Method Against Abnormal Behavior of Industrial Control Networks Under Active Defense Architecture
abstract
Trusted computing is a typical active defense technology. Trust management is a core support technology of trusted computing. However, when trust management is applied in the industrial control systems, how to identify malicious behavior effectively, model trust relationships, and make a decision based on behavior trustworthiness, meanwhile how to ensure deployed trust mechanism does not affect the control network’s availability, is a significant issue that has not been solved in the previous literature. This paper proposes a trust management method against abnormal behavior of industrial control networks under active defense architecture. Firstly, we review the difficulties of trust management when applied to industrial control networks and analyze abnormal behaviors of the control operations under unknown threats. Then we extract trust information, model the trust relationship of abnormal behaviors, and establish a trust update and decision-making mechanism under the availability constraints of industrial control networks. Furthermore, we provide a deployment method of the proposed trust management in a distributed control network. Finally, we take five typical abnormal operations on control instruction in an industrial control network as an example and perform a detailed analysis and experimental verification of the proposed method. The results prove that the proposed trust management method has good immunity to abnormal behaviors of the control flow and can be deployed in an industrial control system with availability constraints.
Zhenyong Zhang, Mufeng Wang
IEEE Trans. Netw. Serv. Manag.2
2021 Zero-Parameter-Information Data Integrity Attacks and Countermeasures in IoT-Based Smart Grid
abstract
Data integrity attack (DIA) is one class of threatening cyber attacks against the Internet-of-Things (IoT)-based smart grid. With the assumption that the attacker is capable of obtaining complete or incomplete information of the system topology and branch parameters, it has been widely recognized that the highly synthesized DIA can evade being detected and undermine the smart grid state estimation. However, the branch parameters cannot be easily obtained or inferred by the attacker in practice. They can be changed or disturbed with time. In this article, we complete the class of DIA by designing the zero-parameter-information DIA (ZDIA), which makes it possible for the attacker to execute stealthy data tampering attacks without any information of the branch parameters. Only the topology information about the cut line is required to construct such attack. We prove that, the attacker can arbitrarily modify the state estimate of a one-degree bus, which is connected to the outside only by a single cut line; and modify the state estimates of all buses, with the same arbitrary bias, in a one-degree super-bus, which is a group of buses that is connected to the outside only by a single cut line. Besides, we extend ZDIA to the cases where a bus and super-bus are connected to the outside only by several cut lines. Moreover, we propose two countermeasures to address the topology vulnerability exploited by ZDIA, and present a branch perturbation strategy to defend against general DIAs. Finally, we conduct extensive simulations with the IEEE standard power systems to validate the theoretical results.
Zhenyong Zhang, Ruilong Deng, David K. Y. Yau, Peng Cheng 0001
IEEE Internet Things J.1
2021 HRPDF: A Software-Based Heterogeneous Redundant Proactive Defense Framework for Programmable Logic Controller
Jing-Yi Wang, Zhenyong Zhang, Rongkuan Ma, Ruilong Deng
J. Comput. Sci. Technol.4
2020 On Hiddenness of Moving Target Defense against False Data Injection Attacks on Power Grid
abstract
Recent studies have exploited moving target defense (MTD) for thwarting false data injection (FDI) attacks against the state estimation (SE) by actively perturbing branch parameters (i.e., impedance or admittance) in power grids. To hide the activation of MTD from attackers, a new strategy named hidden MTD has been proposed by the latest literature. A hidden MTD can increase the defender’s chance to detect FDI attacks and avoid the attacker from inferring new branch parameters. However, by using an MTD-confirming detector like the bad data detection (BDD) checker in SE, we observe that it is still possible for the attacker to detect this hidden MTD when the power flows change with time. To uncover the insight of MTD’s hiddenness, we study the conditions needed for achieving a hidable MTD. We find that the hiddenness of MTD is closely related to the branch perturbations, system topology, and attacker’s knowledge. From the attacker’s perspective, we prove that an MTD can be detected by the attacker only if he/she knows the previous parameters of a set of branches that forms a circle and the measurements corresponding to those branches after MTD. But once the attacker has full knowledge of branch parameters before MTD and has obtained all measurements after MTD, it is proved that we can never achieve a hidable and effective MTD. From the defender’s perspective, since it is impossible to know the attacker’s capability, we cannot determine whether a constructed MTD is hidable or not by purely depending on the MTD design. To address this issue, we propose that, by protecting a basic set of measurements, we always can achieve a hidable and effective MTD regardless of the changes of power flows, the attacker’s knowledge, and the branch perturbations. Furthermore, we validate our findings with the IEEE standard test power systems.
Zhenyong Zhang, Ruilong Deng, David K. Y. Yau, Peng Cheng 0001, Jiming Chen 0001
ACM Trans. Cyber Phys. Syst.1
2020 Analysis of Moving Target Defense Against False Data Injection Attacks on Power Grid
abstract
Recent studies have considered thwarting false data injection (FDI) attacks against state estimation in power grids by proactively perturbing branch susceptances. This approach is known as moving target defense (MTD). However, despite of the deployment of MTD, it is still possible for the attacker to launch stealthy FDI attacks generated with former branch susceptances. In this paper, we prove that, an MTD has the capability to thwart all FDI attacks constructed with former branch susceptances only if (i) the number of branches l in the power system is not less than twice that of the system states n (i.e., l ≥ 2n, where n + 1 is the number of buses); (ii) the susceptances of more than n branches, which cover all buses, are perturbed. Moreover, we prove that the state variable of a bus that is only connected by a single branch (no matter it is perturbed or not) can always be modified by the attacker. Nevertheless, in order to reduce the attack opportunities of potential attackers, we first exploit the impact of the susceptance perturbation magnitude on the dimension of the stealthy attack space, in which the attack vector is constructed with former branch susceptances. Then, we propose that, by perturbing an appropriate set of branches, we can minimize the dimension of the stealthy attack space and maximize the number of covered buses. Besides, we consider the increasing operation cost caused by the activation of MTD. Finally, we conduct extensive simulations to illustrate our findings with IEEE standard test power systems.
Zhenyong Zhang, Ruilong Deng, David K. Y. Yau, Peng Cheng 0001, Jiming Chen 0001
IEEE Trans. Inf. Forensics Secur.1
2020 A Self-Evolving WiFi-based Indoor Navigation System Using Smartphones
abstract
Given a wide spectrum of demands for indoor location-based service, great research effort has been devoted to developing indoor navigation systems. Nevertheless, due to high engineering complexity and expensive infrastructure and labor cost, scalable indoor navigation is still an unsolved problem. In this paper, we present SWiN, a Self-evolving WiFi-based Indoor Navigation system. SWiN provides plug-and-play and light-weight indoor navigation in a sharing manner. To alleviate the impact of the environmental change and device diversity, SWiN extracts both the static and dynamic properties of WiFi signals including scanned AP list, variations of signal strength, and AP's relative strength order. SWiN exploits the leader-follower structure, navigating following users by tracking their motion patterns to provide real-time navigation guidance. In specific, during navigation, SWiN utilizes a light-weight synchronization algorithm to synchronize multi-dimensional WiFi measurements between leader and follower traces. Furthermore, a trace updating mechanism is developed to guarantee the long-term utility of SWiN by extracting useful information in followers' traces. Consolidating these techniques, we implement SWiN on commodity smartphones, and evaluate its performance in a five-story office building and a newly opened two-story shopping mall with test areas over 8000 m2and 6000 m2, respectively. Our experimental results show that 95 percent of the tracking offsets during navigation are less than 2 m and 3.2 m in these two environments.
Zhenyong Zhang, Shibo He, Yuanchao Shu, Zhiguo Shi 0001
IEEE Trans. Mob. Comput.1
2019 Stealthy Attack Against Redundant Controller Architecture of Industrial Cyber-Physical System
abstract
In an industrial cyber-physical system (iCPS), the controller plays a critical role in guaranteeing reliability and stability. Therefore, redundant controller architecture is a well-adopted approach by distributed control systems (DCS), supervisory control and data acquisition (SCADA), and other typical iCPSs. They monitor and control the critical industrial process, such as power generation, chemical industry, water treatment plant, etc. Redundant controller architecture has been designed and largely implemented in response to unpredictable mechanical failures. However, this structure initially proposed for guaranteeing reliability and safety may expand the cyber-attack surface, posing the risk that an attacker may take advantage of this architecture for stealthy attacks. In this article, we analyze the vulnerability arising from the redundant controller architecture and propose a combined attack methodology against these redundant controller architecture systems in a stealthy manner. We find several 0-day vulnerabilities of the real-world devices from three manufacturers and further implement the combined attack over these devices. Our experimental results over various types of real-world devices show that the redundant controller architecture can be exploited to compromise all tested systems stealthily. We also present guidelines for mitigating this risk.
Rongkuan Ma, Peng Cheng 0001, Zhenyong Zhang
IEEE Internet Things J.3
2017 Indoor Navigation Leveraging Gradient WiFi Signals
abstract
In this demo, we propose I-Navi, an Indoor Navigation system which leverages the gradient WiFi signal. To be more adaptive to time-variant RSSI and enrich information dimension, I-Navi exploits a three-step backward gradient binary method. Meanwhile, we adopt a lightweight online dynamic time warping (DTW) algorithm to achieve real-time navigation. We fully implemented I-Navi on smartphones and conducted extensive experiments in a five-story campus building and a newly opened two-floor shopping mall with a 90% accuracy of 2m and 3.2m achieved at two places.
Zhuoying Shi, Zhenyong Zhang, Yuanchao Shu, Peng Cheng 0001, Jiming Chen 0001
SenSys2
2007 A Segmented Data-Weighted-Averaging Technique
abstract
This paper proposes a new dynamic element matching (DEM) technique, segmented date weighted averaging (SeDWA), for application in a multi-bit delta-sigma modulator (DSM). In SeDWA , the DAC elements are divided into several subsets with DWA applied in each set. This allows a simpler and faster implementation, and the selecting sequences for the DAC elements are more randomized than in conventional DWA. This reduces pattern tones, but still provides mismatch error shaping. In the simulated power spectra density (PSD), no in-band pattern tones were observed, and only a moderate rise of the noise floor. Therefore, higher spurious-free dynamic range (SFDR) was achieved. The implementation of SeDWA can be simpler and faster than that of conventional DWA, making it suitable for high-speed applications
Zhenyong Zhang, Gabor C. Temes
ISCAS1