Shin-Ming Cheng
Shin-Ming Cheng 鄭欣明
Professor · NTUST CSIE
Connectivity Lab group photo
Section

Lab Members

Connectivity Lab at NTUST CSIE — three research themes: 5G/6G, IoT, and AI Security.

Curious about build · break · reason in security? Find us. 歡迎好奇心強的同學來信聊聊。

5G/6G Group

PhD · MS · UG NTN · O-RAN · Base Station security
PhD Candidates

Bing-Kai Hong 洪稟凱 PhD NICT18SumNICT19Intern

Cohort 2019 · Expected graduation 學年度 114 · Senior PhD candidate
5G Base Station security · rogue Base Station detection · MEC-based attack detection · O-RAN security
★ 2019 MOST Excellent PhD Scholarship · 2021 TANET Best Paper · 2023 WPMC Travel Grant

Guang-Jhe Lin 林廣哲 PhD

Incoming PhD · joining 學年度 114
O-RAN security · Near-RT RIC · E2 interface attacks · race condition analysis
★ 2026 ICBIR Best Paper Award
Master's (Senior) · 碩二
Master's (Junior) · 碩一
Master's (Incoming) · 碩零
Undergraduate Researchers · 大學專題
Research Themes · 研究主軸
Overview of O-RAN architecture with anomaly traffic detector framework — Near-RT RIC, SMO, RMR messaging infrastructure, E2 interface, xApp threats (IEEE OJCOMS 2025)
O-RAN defense
O-RAN 攻擊面分析與防禦機制
Systematic study of O-RAN's open interfaces (E2, F1AP, xApps, rApps) — building both threat models and defensive primitives across Near-RT RIC, Non-RT RIC, and the SMO.
  • Anomaly detection on Near-RT RIC for xApp / E2 threats — IEEE OJCOMS 2025
  • F1AP conformance testing — IEEE OJCOMS 2026
  • Low-rate DoS detection via federated learning — IEEE VTM 2025
  • Malicious rApp eavesdropping & exfiltration on Non-RT RIC — CANDAR 2025
  • Race condition on E2 subscription — ICBIR 2026
IEEE Top O-RAN Paper 2024–2025ICBIR 2026 Best Paper
Rogue Base Station attacks & defenses
惡意基地台攻擊與偵測
Software-defined radio + open-source 5G stack + lightweight container virtualization to realize and detect rogue / MITM Base Stations in 5G private networks. Detection runs on the MEC edge.
  • Signaling forgery via virtualized rogue Base Station containers — CISC 2020 Best Paper
  • MEC-based rogue Base Station detection APP for 5G private networks — TANET 2021 Best Paper
  • xApp-driven rogue Base Station detection on SDR-enabled O-RAN — INFOCOM NGOPERA 2023
  • 5G NSA ML-based rogue Base Station classifier — CISC 2022 Best Student Paper
  • MEC + AIoT integration — IEEE IoT Mag 2022
CISC 2020 + TANET 2021 Best Paper
🛰️
Looking ahead · 未來方向

NTN (Non-Terrestrial Network) Security

Extending O-RAN attack-model + SDR detection platform to satellite / 5G-NTN — UE ↔ satellite ↔ ground signalling threats, rogue-satellite detection, inter-satellite routing resilience.

3GPP Rel-17/18 NTN spoofed satellite signalling inter-satellite routing MEC-edge detection

IoT Group

PhD · MS · UG firmware emulation · vulnerability discovery · honeynets
PhD Candidate (cross-listed)

Bing-Kai Hong 洪稟凱 PhD

Cohort 2019 · Cross-listed (5G/IoT)
IoT endpoint detection & response · firmware emulation · digital twins
Master's (Senior) · 碩二
Master's (Junior) · 碩一
Master's (Incoming) · 碩零
Undergraduate Researchers · 大學專題
Research Themes · 研究主軸
Guided concolic execution system design — Static Analysis, Concrete Execution, and Symbolic Execution components for IoT firmware authentication-bypass discovery (NDSS 2024 poster)
Vulnerability discovery
IoT 漏洞挖掘
Concolic execution, hybrid static-dynamic analysis, and LLM-assisted exploit generation to discover authentication-bypass and protocol-level vulnerabilities in IoT firmware across architectures.
  • Guided concolic execution for auth bypass in IoT — NDSS 2024 poster
  • AngrySpider hybrid multi-binary vulnerability discovery — CISC 2026 (finalist)
  • Firmulti Fuzzer multi-process vulns via full-system emulation + VMI — CCS CPSIoTSec 2023
  • MQTT fuzzing with Trampoline OTA — MOST UG 2025
CCISA 2022 Best Master Thesis
Framework for Digital Twins — Payload Extractor, Malicious Behavior Detector, Emulated Device, and System-level Monitoring layers replicating the Actual IoT Endpoint with blocking response (IEEE IoT Magazine 2024)
Firmware emulation & virtual patching
IoT 韌體模擬與虛擬修補
Digital-twin–based firmware emulation enables edge-level endpoint detection & response (EDR) and virtual patching — fixing vulnerable IoT devices via gateway-side mitigation instead of OTA flashing.
  • Digital twin EDR via firmware emulation — IEEE IoT Mag 2024
  • Mobility-based epidemic model for IoT malware spread — IEEE Access 2022
  • Hybrid edge threat detection for O-RAN private networks — IEEE CNS Cyber Resilience 2025
  • Firmware NVRAM dependency parsing (FirmFE) — IEEE WPMC 2023
MOST 前瞻資安 2 期計畫CHT IoT Honeypot

AI Group

MS · UG adversarial ML · backdoor attacks · NICT collaboration
Master's (Senior) · 碩二
Master's (Junior) · 碩一
Master's (Incoming) · 碩零
Undergraduate Researchers · 大學專題
Research Themes · 研究主軸
Execution order analysis framework — Reverse Engineering (CFG + Disassembly), Node Embedding, Graph Embedding (WL Algorithm), Execution Order Embedding for Detect/Classify IoT malware families (ACM TECS 2025)
IoT malware analysis
IoT 惡意程式分析
A multi-representation pipeline — function call graphs · byte sequences · printable strings · P-Code IR — for cross-architecture IoT malware classification, with NICT Japan as long-term collaborator.
  • Execution-order analysis for malware robustness — ACM TECS 2025
  • FCG-reinterpreted system calls — Computers & Security 2023; ICISC 2024 Best Paper
  • P-Code pretraining few-shot cross-architecture — CISC 2026 Best Presentation
  • Printable strings classifier — IEEE TrustCom 2020 Best Paper
  • TOM-Net few-shot open-set transductive meta-learning — PST 2025
ICISC 2024 + TrustCom 2020 Best Paperw/ NICT Japan
Proposed adversarial attack framework against ML-based IoT malware detection — feature extraction with SHAP/LIME explainability, payload set, iterative payload injection, evaluation against RF/SVM/XGBoost/DNN detectors (IEEE Consumer Electronics Magazine 2025)
Adversarial and poisoning attacks
機器學習對抗式與資料中毒攻擊
Building black-box attacks, stealthy backdoors, and explainability-driven adversarial samples against ML-driven security models; co-developed with IBM Watson Trusted AI Group.
  • AutoZOOM autoencoder-based zeroth-order black-box attack — AAAI 2019 · 557 citations
  • Backdoor attack on malware classifiers — CISC 2021 Best Paper
  • Graph-feature adversarial sample generation — CISC 2022 Best Paper
  • Robustness evaluation framework for IoT-based detectors — CISC 2022 Best Student Paper
  • Adversarial attacks on consumer-IoT AI malware detection — IEEE Consumer Electronics Mag 2025
CISC 2021 + 2022 Best Paperw/ IBM Pin-Yu Chen