[Paper Review] Sequential detection of Replay attacks
This paper proposes a sequential detection method for replay attacks in cyber-physical systems using watermarking and cumulative sum (CUSUM) tests on joint innovation and watermark statistics. By deriving the Kullback-Leibler divergence (KLD) between pre- and post-attack joint distributions, the method enables asymptotically optimal detection with minimal delay, while optimizing watermark variance to maximize KLD under a fixed control cost increase.
One of the most studied forms of attacks on the cyber-physical systems is the replay attack. The statistical similarities of the replay signal and the true observations make the replay attack difficult to detect. In this paper, we have addressed the problem of replay attack detection by adding watermarking to the control inputs and then performed resilient detection using cumulative sum (CUSUM) test on the joint statistics of the innovation signal and the watermarking signal. We derive the expression of the Kullback-Liebler divergence (KLD) between the two joint distributions before and after the replay attack, which is asymptotically inversely proportional to the detection delay. We perform structural analysis of the derived KLD expression and suggest a technique to improve the KLD for the systems with relative degree greater than one. A scheme to find the optimal watermarking signal variance for a fixed increase in the control cost to maximize the KLD under the CUSUM test is presented. We provide various numerical simulation results to support our theory. The proposed method is also compared with a state-of-the-art method.
Motivation & Objective
- To address the challenge of detecting stealthy replay attacks in cyber-physical systems where attack signals mimic normal system behavior.
- To improve detection resilience by leveraging watermarking on control inputs and joint statistical testing of innovation and watermark signals.
- To minimize detection delay by optimizing the Kullback-Leibler divergence (KLD) between pre- and post-attack joint distributions.
- To design an optimal watermarking variance that maximizes attack detectability while constraining the increase in control cost.
- To provide a structural analysis of KLD for systems with relative degree > 1 to enhance detection performance.
Proposed method
- Introduces a CUSUM test based on the joint probability distribution of the innovation signal and the watermarking signal to detect replay attacks sequentially.
- Derives the Kullback-Leibler divergence (KLD) between the joint distributions before and after a replay attack, which is inversely proportional to the asymptotic detection delay.
- Uses a watermarking signal added to the control input that is independent and identically distributed (i.i.d.) to preserve statistical detectability.
- Applies structural analysis to the KLD expression to identify conditions for improving detection performance in systems with relative degree greater than one.
- Proposes an optimization framework to compute the optimal watermarking variance that maximizes KLD for a fixed increase in control cost.
- Employs a Kalman filter-based state estimator to generate the innovation signal, which is combined with the watermark for joint statistical testing.

Experimental results
Research questions
- RQ1How can the Kullback-Leibler divergence (KLD) between pre- and post-attack joint distributions of innovation and watermark signals be derived for optimal detection?
- RQ2What structural properties of the KLD expression allow for improved detection performance in systems with relative degree greater than one?
- RQ3How can the watermarking signal variance be optimized to maximize detection performance while limiting the increase in control cost?
- RQ4What is the relationship between the KLD and the asymptotic detection delay in the proposed CUSUM-based detection framework?
- RQ5How does the proposed method compare in performance to state-of-the-art replay attack detection techniques under the same control cost constraints?
Key findings
- The Kullback-Leibler divergence (KLD) between the joint distributions of innovation and watermark signals is asymptotically inversely proportional to the detection delay, enabling optimal detection performance.
- For systems with relative degree greater than one, structural analysis of the KLD expression reveals conditions under which detection performance can be enhanced through system-specific signal design.
- The optimal watermarking variance is derived to maximize the KLD under a fixed increase in control cost, ensuring the best trade-off between detectability and system energy consumption.
- Numerical simulations show that the proposed method achieves significantly lower detection delay compared to existing state-of-the-art approaches under identical control cost constraints.
- The method maintains a high average run length (ARL) of 1000 before false alarms, indicating strong resilience to false positives.
- The CUSUM test based on joint innovation-watermark statistics outperforms batch-processing methods by enabling real-time, sequential detection with minimal delay.

Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.