[Paper Review] Switching and Data Injection Attacks on Stochastic Cyber-Physical Systems: Modeling, Resilient Estimation and Attack Mitigation
This paper proposes a multiple-model inference approach for resilient state estimation in stochastic cyber-physical systems under switching attacks and false data injection on actuators and sensors. By modeling the system as a hidden mode switched linear system with unknown inputs, the method enables real-time attack detection, identification, and mitigation, achieving asymptotically unbiased state estimates even under unbounded stochastic noise and multiple simultaneous attacks.
In this paper, we consider the problem of attack-resilient state estimation, that is to reliably estimate the true system states despite two classes of attacks: (i) attacks on the switching mechanisms and (ii) false data injection attacks on actuator and sensor signals, in the presence of unbounded stochastic process and measurement noise signals. We model the systems under attack as hidden mode stochastic switched linear systems with unknown inputs and propose the use of a multiple-model inference algorithm to tackle these security issues. Moreover, we characterize fundamental limitations to resilient estimation (e.g., upper bound on the number of tolerable signal attacks) and discuss the topics of attack detection, identification and mitigation under this framework. Simulation examples of switching and false data injection attacks on a benchmark system and an IEEE 68-bus test system show the efficacy of our approach to recover resilient (i.e., asymptotically unbiased) state estimates as well as to identify and mitigate the attacks.
Motivation & Objective
- Address the critical need for resilient state estimation in safety-critical cyber-physical systems (CPS) exposed to both switching attacks (on topology/mode) and false data injection on sensors and actuators.
- Tackle the challenge of unbounded stochastic process and measurement noise, which limits the applicability of existing bounded-error or deterministic approaches.
- Develop a unified framework that enables simultaneous attack detection, identification, and mitigation while maintaining asymptotically unbiased state estimates.
- Characterize fundamental limits on the number of tolerable signal attacks and the number of required models for resilient estimation.
- Design an attack-mitigating feedback controller that maintains system stability and performance despite active attacks.
Proposed method
- Model the attacked CPS as a hidden mode stochastic switched linear system with unknown inputs, representing both switching attacks and false data injection as unmodeled inputs.
- Adapt the multiple-model inference algorithm from [Yong et al., 2016a] to jointly estimate system states and infer the current attack mode in real time.
- Use Bayesian inference to compute posterior probabilities over possible attack modes, enabling rapid detection and identification of switching and data injection attacks.
- Formulate the resilient state estimation problem as a simultaneous input and state estimation task, leveraging stability and strong detectability properties for convergence.
- Design a feedback controller that uses estimated attack signals to counteract their effects, ensuring system regulation despite adversarial inputs.
- Discretize continuous-time dynamics and measurement models for compatibility with real-time estimation, using a sampling time of Δt = 0.01 s.
Experimental results
Research questions
- RQ1What is the maximum number of false data injection attacks on sensors and actuators that can be asymptotically corrected under unbounded stochastic noise?
- RQ2How can switching attacks on system topology or mode (e.g., transmission lines or control logic) be detected and identified in real time?
- RQ3What are the sufficient conditions for attack detectability and identifiability in stochastic switched linear systems with unknown inputs?
- RQ4How can a resilient state estimator be designed to maintain asymptotically unbiased estimates despite multiple simultaneous attacks and unbounded noise?
- RQ5Can an attack-mitigating controller be synthesized to maintain system stability and performance under active attacks?
Key findings
- The proposed multiple-model inference approach successfully detects switching attacks and false data injection attacks within milliseconds, as shown in the IEEE 68-bus test case.
- The method achieves asymptotically unbiased state estimates even under unbounded Gaussian process and measurement noise, demonstrating resilience to stochastic disturbances.
- The attack mode is identified with high accuracy within 0.5 seconds after mode switching, as evidenced by posterior mode probability convergence in Figure 8(a).
- The actuator attack signal is accurately estimated in real time, with the estimated signal closely tracking the true injected attack signal (Figure 8b).
- The attack-mitigating controller successfully maintains phase angles at the desired 10 rad despite active attacks, whereas unmitigated systems show significant deviation (Figure 9).
- An upper bound on the number of tolerable signal attacks is derived, and the number of required models for the multiple-model approach is shown to scale with the number of possible attack modes.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.