Skip to main content
QUICK REVIEW

[Paper Review] Optimal Attack Strategies Subject to Detection Constraints Against Cyber-Physical Systems

Yuan Chen, Soummya Kar|arXiv (Cornell University)|Oct 11, 2016
Smart Grid Security and Resilience20 references4 citations
TL;DR

This paper formulates optimal attack strategies for cyber-physical systems (CPS) that minimize deviation from a target state while explicitly constraining the attacker's detection probability. It shows that under a zero-bias constraint, the optimal attack reduces to a linear feedback of the attacker's state estimate, and provides two algorithms—optimal and sub-optimal—for bounded bias cases, validated on a remotely controlled helicopter model.

ABSTRACT

This paper studies an attacker against a cyber-physical system (CPS) whose goal is to move the state of a CPS to a target state while ensuring that his or her probability of being detected does not exceed a given bound. The attacker's probability of being detected is related to the nonnegative bias induced by his or her attack on the CPS' detection statistic. We formulate a linear quadratic cost function that captures the attacker's control goal and establish constraints on the induced bias that reflect the attacker's detection-avoidance objectives. When the attacker is constrained to be detected at the false-alarm rate of the detector, we show that the optimal attack strategy reduces to a linear feedback of the attacker's state estimate. In the case that the attacker's bias is upper bounded by a positive constant, we provide two algorithms -- an optimal algorithm and a sub-optimal, less computationally intensive algorithm -- to find suitable attack sequences. Finally, we illustrate our attack strategies in numerical examples based on a remotely-controlled helicopter under attack.

Motivation & Objective

  • To design optimal attack strategies for cyber-physical systems that achieve a target state while ensuring the probability of detection remains below a specified bound.
  • To model the attacker’s detection avoidance as a hard constraint on the bias of the chi-squared detection statistic, rather than a penalty in the cost function.
  • To ensure recursive feasibility of attack sequences by leveraging geometric control-theoretic properties of the CPS model.
  • To provide computationally tractable solutions for both zero-bias and bounded-bias attack scenarios.
  • To validate the proposed strategies through numerical simulations on a remotely controlled helicopter system under attack.

Proposed method

  • Formulates a linear quadratic cost function that penalizes deviation from the target state and the magnitude of the detection statistic bias.
  • Models the CPS as a linear dynamical system with process and sensor noise, using a Kalman filter and LQG controller, with a chi-squared detector for attack detection.
  • Imposes a hard upper bound on the non-negative bias induced on the detection statistic to control the attacker’s probability of detection.
  • Uses constrained dynamic programming to derive the optimal attack strategy under zero-bias constraint, resulting in a linear feedback law of the attacker’s state estimate.
  • For bounded bias, develops an optimal algorithm based on semi-definite programming and a sub-optimal, computationally efficient algorithm using iterative projection and feedback adjustment.
  • Employs geometric control theory to express the detection bias constraint as a linear constraint on the attack input at each time step, ensuring recursive feasibility.

Experimental results

Research questions

  • RQ1What is the optimal attack strategy for a CPS attacker who seeks to reach a target state while being detected with probability no greater than a given threshold?
  • RQ2How can the attacker’s detection bias be constrained as a hard limit rather than a soft penalty in the cost function, and what are the implications for attack design?
  • RQ3Under what conditions does the optimal attack strategy reduce to a linear feedback of the attacker’s state estimate?
  • RQ4How can optimal and sub-optimal attack sequences be computed efficiently under a bounded bias constraint?
  • RQ5What is the impact of attack constraints on the attacker’s ability to manipulate the system state while remaining stealthy?

Key findings

  • When the attacker’s induced bias is constrained to zero, the optimal attack strategy reduces to a linear feedback of the attacker’s state estimate, ensuring detection only at the false alarm rate.
  • For a positive upper bound on bias, the paper provides an optimal algorithm based on semi-definite programming and a sub-optimal, less computationally intensive algorithm using iterative projection and feedback adjustment.
  • The detection bias constraint is expressed as a linear constraint on the attack input using geometric control-theoretic properties, enabling recursive feasibility of the attack sequence.
  • The optimal attack strategy guarantees a maximum detection probability bounded by the specified threshold, providing stronger security assurances than prior work with unconstrained detection penalties.
  • Numerical evaluation on a remotely controlled helicopter model demonstrates the effectiveness and stealth of the proposed attack strategies under both zero-bias and bounded-bias conditions.
  • The results show that even with strict detection constraints, the attacker can still achieve significant state deviation from the nominal trajectory, highlighting the vulnerability of CPS to targeted, stealthy attacks.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.