Skip to main content
QUICK REVIEW

[Paper Review] The Vulnerability of Cyber-Physical System under Stealthy Attacks

Tianju Sui, Yilin Mo|arXiv (Cornell University)|Feb 4, 2020
Smart Grid Security and Resilience30 references4 citations
TL;DR

This paper analyzes the vulnerability of stochastic linear Cyber-Physical Systems (CPS) to stealthy and strictly stealthy attacks, where attackers inject malicious signals into sensors or actuators to evade detection. It provides necessary and sufficient conditions for system destabilization under such attacks and establishes performance bounds for invulnerable systems, demonstrating that stealthy attacks can destabilize otherwise stable systems despite bounded residue changes.

ABSTRACT

In this paper, we study the impact of stealthy attacks on the Cyber-Physical System (CPS) modeled as a stochastic linear system. An attack is characterised by a malicious injection into the system through input, output or both, and it is called stealthy (resp.~strictly stealthy) if it produces bounded changes (resp.~no changes) in the detection residue. Correspondingly, a CPS is called vulnerable (resp.~strictly vulnerable) if it can be destabilized by a stealthy attack (resp.~strictly stealthy attack). We provide necessary and sufficient conditions for the vulnerability and strictly vulnerability. For the invulnerable case, we also provide a performance bound for the difference between healthy and attacked system. Numerical examples are provided to illustrate the theoretical results.

Motivation & Objective

  • To investigate the vulnerability of Cyber-Phyiscal Systems (CPS) to stealthy and strictly stealthy attacks that evade detection residue monitoring.
  • To determine necessary and sufficient conditions under which a CPS can be destabilized by such attacks.
  • To quantify the performance degradation in invulnerable systems under attack, providing a bound on the difference between healthy and attacked system states.

Proposed method

  • Models the CPS as a stochastic linear system with process and measurement noise.
  • Defines stealthy attacks as those causing bounded changes in the detection residue, and strictly stealthy attacks as those causing zero changes.
  • Uses transfer function analysis and spectral norm bounds to characterize system behavior under attack.
  • Applies the Moore-Penrose pseudoinverse of system transfer functions to analyze the inverse dynamics of attack signals.
  • Employs contradiction-based proofs using $ \ell_1 $-sparsity norms of impulse responses to establish boundedness of system responses.
  • Derives conditions on the system transfer functions $ S(z) $, $ T(z) $, and $ R(z) $ to determine vulnerability or invulnerability.

Experimental results

Research questions

  • RQ1Under what conditions can a stochastic linear CPS be destabilized by a stealthy attack that produces bounded changes in the detection residue?
  • RQ2When is a CPS vulnerable to strictly stealthy attacks that produce no detectable residue changes?
  • RQ3What performance bounds exist for the difference between the healthy and attacked system states in the case of an invulnerable system?
  • RQ4How do system transfer functions $ S(z) $, $ T(z) $, and $ R(z) $ influence the detectability and impact of stealthy attacks?
  • RQ5What mathematical conditions ensure that the system remains stable under attack despite bounded residue perturbations?

Key findings

  • A CPS is vulnerable to stealthy attacks if and only if the spectral norm of the transfer function $ T(e^{j\omega})\mu $ exceeds that of $ S(e^{j\omega})\mu $ for some $ \mu $, indicating destabilization potential.
  • A system is strictly vulnerable if the residue remains zero under attack, which occurs only when the attack signal lies in the null space of the detection residual map.
  • For invulnerable systems, the ratio of the $ \ell_2 $-norm of the error $ \Delta e_t $ to the $ \ell_2 $-norm of the attack signal $ \Delta z_t $ is bounded by a finite value, ensuring system stability.
  • The inverse $ z $-transform of $ S(z)S^\dagger(z) $ has finite $ \ell_1 $-sparsity norm, implying that the system's response to attack signals remains bounded.
  • The proof establishes that if the impulse response of the error transfer function $ R(z) $ has infinite $ \ell_1 $-sparsity norm, the system becomes vulnerable, contradicting the invulnerability assumption.
  • The analysis confirms that stealthy attacks can destabilize a system even when they are not detectable by standard residual-based methods, highlighting a critical security gap.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.