Skip to content

Author

Hao-Zhe Zhou

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

ZTSafe: Safety-Certified Risk-Adaptive Scheduling for Zero-Trust Time-Sensitive Industrial Networks

Zero-trust security continuously re-evaluates the trustworthiness of industrial devices and reacts by rerouting, isolating, or rescheduling traffic. In a time-sensitive network (TSN) that carries feedback control loops, however, every such reaction is itself a control-plane disturbance: a reroute that meets every deadline can still deliver stale measurements, and an optimizer that crashes mid-reconfiguration can leave the network in an undefined state. This paper presents ZTSafe, a scheduling architecture that treats physical safety—not attack blocking—as the object of guarantee. The guarantee has two distinct layers: compliance with the communication contract yields a deterministic invariance result conditional on the stated plant, disturbance, synchronization, and trusted-base assumptions, whereas the risk bound’s 1−δ coverage is an empirical probabilistic calibration result. ZTSafe (i) synthesizes, offline and per control loop, a communication safety contract that bounds delay, age of information (AoI), consecutive losses, jitter, and path risk such that the physical state remains in its safe set under those assumptions; (ii) converts zero-trust evidence into conservative risk upper bounds and couples the admissible path-risk budget to the runtime safety margin of the plant; and (iii) places the scheduling optimizer outside the trusted computing base: an independent runtime shield checks every proposed schedule against the contracts, and on solver timeout, crash, or infeasibility the system atomically switches to a pre-checked fallback instead of executing an unverified approximate solution. Here, “verified” means independently checked by the shield, not machine-verified; a systematic shield defect or compromise of the remaining trusted computing base voids the deterministic claim. On a hardware TSN testbed with three physical control loops and fourteen attack and fault scenarios, ZTSafe reduces safe-set violations by 92.9% relative to the strongest baseline (12.8% to 0.9%; two-proportion z=39.4, p<10−15) while sustaining 94.3% on-time completion of critical traffic, recovers within three control periods, and executes zero unverified configurations across 10,000 injected solver failures.

Hao-Zhe Zhou, Hang Lei, Mao-Lin Yang · 0 citations
Open access Sep 2026

EviGuard: Machine-Verifiable Evidence Grounding for LLM-Based Industrial Incident Reasoning

Large language models (LLMs) can turn a flood of cross-layer industrial logs into a fluent incident narrative, but a narrative that cites only real, resolvable events can still be wrong in every relation that matters: the login came from a different workstation, the write command occurred after the physical change it supposedly caused, the action fell inside a planned maintenance window, and the controller does not even actuate the affected process. A cited event is not necessarily supporting evidence. When such a narrative drives automated response, the error propagates into isolating the wrong controller or revoking a legitimate operator. We present EviGuard, a system that decides when an LLM’s understanding is trustworthy enough to act on. EviGuard stores auditable cross-layer evidence in a provenance graph, lets the LLM propose only hypotheses, compiles each hypothesis into atomic machine-checkable claims in an Incident Claim Language, and has an ensemble of deterministic verifiers label every claim supported, contradicted, or unknown against the graph—honoring interval time, event-time policy and credential versions, network reachability, and physical control dependencies. A response gate forbids any high-impact action whose critical preconditions are not all supported. On EviCPS-Bench (42 hardware-in-the-loop attack chains, 9600 claim-level labels, κ=0.87), EviGuard cuts the unsupported-claim rate from 12.6% to 1.7%, raises relation-edge F1 from 0.64 to 0.89, holds prompt-injection success to 0.4%, and executes zero unverified high-impact actions across 3200 response decisions, at a median end-to-end latency of 0.44 s.

Hao-Zhe Zhou, Hang Lei, Mao-Lin Yang · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.