{"id":"https://openalex.org/W4317927927","doi":"https://doi.org/10.1145/3560905.3568521","title":"Reverse Engineering Physical Semantics of PLC Program Variables Using Control Invariants","display_name":"Reverse Engineering Physical Semantics of PLC Program Variables Using Control Invariants","publication_year":2022,"publication_date":"2022-11-06","ids":{"openalex":"https://openalex.org/W4317927927","doi":"https://doi.org/10.1145/3560905.3568521"},"language":"en","primary_location":{"id":"doi:10.1145/3560905.3568521","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560905.3568521","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560905.3568521","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3560905.3568521","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5017990705","display_name":"Zeyu Yang","orcid":"https://orcid.org/0000-0003-0253-9053"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Zeyu Yang","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100745391","display_name":"Liang He","orcid":"https://orcid.org/0000-0003-0741-8795"},"institutions":[{"id":"https://openalex.org/I921990950","display_name":"University of Colorado Denver","ror":"https://ror.org/02hh7en24","country_code":"US","type":"education","lineage":["https://openalex.org/I921990950"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Liang He","raw_affiliation_strings":["University of Colorado Denver"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Colorado Denver","institution_ids":["https://openalex.org/I921990950"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029115148","display_name":"Hua Yu","orcid":"https://orcid.org/0000-0002-0399-8959"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hua Yu","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076460898","display_name":"Chengcheng Zhao","orcid":"https://orcid.org/0000-0002-6816-6459"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chengcheng Zhao","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051951845","display_name":"Peng Cheng","orcid":"https://orcid.org/0000-0002-4221-2162"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Peng Cheng","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100726041","display_name":"Jiming Chen","orcid":"https://orcid.org/0000-0003-3155-3145"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiming Chen","raw_affiliation_strings":["Zhejiang University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Zhejiang University","institution_ids":["https://openalex.org/I76130692"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5017990705"],"corresponding_institution_ids":["https://openalex.org/I76130692"],"apc_list":null,"apc_paid":null,"fwci":1.0917,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.76917029,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"548","last_page":"562"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9950000047683716,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/scada","display_name":"SCADA","score":0.829738974571228},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6764654517173767},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.6571889519691467},{"id":"https://openalex.org/keywords/programmable-logic-controller","display_name":"Programmable logic controller","score":0.6149767637252808},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.5347347259521484},{"id":"https://openalex.org/keywords/cyber-physical-system","display_name":"Cyber-physical system","score":0.43298542499542236},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.41032496094703674},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.3601577877998352},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.1888280212879181},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.17929130792617798},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.14402785897254944}],"concepts":[{"id":"https://openalex.org/C113863187","wikidata":"https://www.wikidata.org/wiki/Q17498","display_name":"SCADA","level":2,"score":0.829738974571228},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6764654517173767},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.6571889519691467},{"id":"https://openalex.org/C37374048","wikidata":"https://www.wikidata.org/wiki/Q188674","display_name":"Programmable logic controller","level":2,"score":0.6149767637252808},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.5347347259521484},{"id":"https://openalex.org/C179768478","wikidata":"https://www.wikidata.org/wiki/Q1120057","display_name":"Cyber-physical system","level":2,"score":0.43298542499542236},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.41032496094703674},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3601577877998352},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1888280212879181},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.17929130792617798},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.14402785897254944},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3560905.3568521","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560905.3568521","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560905.3568521","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3560905.3568521","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560905.3568521","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560905.3568521","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.4099999964237213,"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure"}],"awards":[{"id":"https://openalex.org/G2359081299","display_name":null,"funder_award_id":"61833015, U1911401","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320332965","display_name":"University of Colorado Denver","ror":"https://ror.org/02hh7en24"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W2002578057","https://openalex.org/W2068693276","https://openalex.org/W2077699686","https://openalex.org/W2184570813","https://openalex.org/W2594635183","https://openalex.org/W2613412685","https://openalex.org/W2765362015","https://openalex.org/W2796861472","https://openalex.org/W2891240227","https://openalex.org/W2945937333","https://openalex.org/W2947820052","https://openalex.org/W2968326636","https://openalex.org/W2969919026","https://openalex.org/W3029312541","https://openalex.org/W3092287343","https://openalex.org/W3092536363","https://openalex.org/W3106357429","https://openalex.org/W3169925262","https://openalex.org/W3205502046","https://openalex.org/W4243080092","https://openalex.org/W4289038676"],"related_works":["https://openalex.org/W2615977515","https://openalex.org/W2115760278","https://openalex.org/W2146396794","https://openalex.org/W2809162650","https://openalex.org/W2388279172","https://openalex.org/W2807864071","https://openalex.org/W2617238897","https://openalex.org/W2055218442","https://openalex.org/W4386714408","https://openalex.org/W2788308474"],"abstract_inverted_index":{"Semantic":[0],"attacks":[1],"have":[2,168],"incurred":[3],"increasing":[4],"threats":[5],"to":[6,164],"Industrial":[7],"Control":[8,88],"Systems":[9],"(ICSs),":[10],"which":[11],"manipulate":[12],"targeted":[13],"system":[14,47,53,93],"modules":[15,32],"by":[16,34],"identifying":[17,123],"the":[18,30,35,67,83,86,95,104,113,124,133,139,150,159,173],"physical":[19,120,140],"semantics":[20,141],"of":[21,46,52,69,97,106,142,161],"variables":[22,70,105,116],"in":[23,71,153],"Programmable":[24],"Logic":[25],"Controllers":[26],"(PLCs)":[27],"programs,":[28],"i.e.,":[29],"sensing/actuating":[31],"represented":[33],"variables.":[36,144],"This":[37],"is":[38,80],"usually":[39],"(and":[40],"inefficiently)":[41],"achieved":[42],"via":[43],"manual":[44],"examination":[45],"documents":[48],"and":[49,109,112,129,172],"long-term":[50],"observation":[51],"behavior.":[54],"In":[55],"this":[56],"paper,":[57],"we":[58],"design":[59],"ARES,":[60],"a":[61,100],"method":[62],"that":[63,85,157],"Automatically":[64],"Reverse":[65],"Engineers":[66],"Semantics":[68],"PLC":[72,98,127,162],"programs":[73,163],"without":[74],"requiring":[75],"any":[76],"domain":[77],"knowledge.":[78],"ARES":[79,136,145,171],"built":[81],"on":[82,149,177],"fact":[84],"Supervisory":[87],"And":[89],"Data":[90],"Acquisition":[91],"(SCADA)":[92],"monitors":[94],"behavior":[96],"using":[99],"fixed":[101],"mapping":[102,125],"between":[103,126],"program":[107,143],"code":[108,128],"data":[110,114,131],"log,":[111],"log":[115],"are":[117],"marked":[118],"with":[119],"semantics.":[121],"By":[122],"SCADA":[130],"(i.e.,":[132],"code-data":[134],"mapping),":[135],"reverse":[137],"engineers":[138],"also":[146],"sheds":[147],"light":[148],"preferred":[151],"practices":[152,176],"implementing":[154],"control":[155],"rules":[156],"improve":[158],"resistance":[160],"semantic":[165],"attacks.":[166],"We":[167],"experimentally":[169],"evaluated":[170],"recommended":[174],"implementation":[175],"two":[178],"ICS":[179],"platforms.":[180]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":2}],"updated_date":"2026-05-19T21:40:30.786675","created_date":"2025-10-10T00:00:00"}
