Skip to main content
QUICK REVIEW

[论文解读] A Zero-stealthy Attack for Sampled-data Control Systems via Input Redundancy

Jihan Kim, Gyunghoon Park|arXiv (Cornell University)|Jan 11, 2018
Smart Grid Security and Resilience参考文献 18被引用 5
一句话总结

本文提出了一种针对采样数据控制系统的零隐蔽性执行器攻击,利用输入冗余技术,使攻击者能够操纵执行器输入,使系统的采样输出始终保持为零,同时导致采样间状态无界增长。该攻击对离散时间异常检测器保持隐蔽,因为输出测量值始终正常,即使物理系统已变得不稳定。

ABSTRACT

In this paper, we introduce a new vulnerability of cyber-physical systems to malicious attack. It arises when the physical plant, that is modeled as a continuous-time LTI system, is controlled by a digital controller. In the sampled-data framework, most anomaly detectors monitor the plant's output only at discrete time instants, and thus, nothing abnormal can be detected as long as the sampled output behaves normal. This implies that if an actuator attack drives the plant's state to pass through the kernel of the output matrix at each sensing time, then the attack compromises the system while remaining stealthy. We show that this type of attack always exists when the sampled-data system has an input redundancy, i.e., the number of inputs being larger than that of the outputs or the sampling rate of the actuators being higher than that of the sensors. Simulation results for the X-38 vehicle and for the other numerical examples illustrate this new attack strategy possibly brings disastrous consequences.

研究动机与目标

  • 识别采样数据控制系统中新型隐蔽性网络物理攻击,使攻击者能完全避开基于输出的异常检测器。
  • 分析具有输入冗余的多速率或多输入系统在恶意执行器攻击下的脆弱性。
  • 证明此类攻击可在不改变采样输出测量值的前提下,破坏系统的采样间行为稳定性。
  • 提出一种系统化方法,利用提升系统表示和基于核的态控制技术构造此类攻击。
  • 强调需要增强检测机制(如间歇采样)以应对此类隐蔽攻击。

提出的方法

  • 通过将采样数据系统建模为扩展的提升系统,使用多个采样周期内的堆叠状态向量来设计攻击。
  • 攻击者确保在每个采样时刻系统状态均位于输出矩阵的核空间中,从而使采样输出为零,即使内部状态发生发散。
  • 利用输入冗余(通过更高的执行频率或输入数多于输出数)生成满足核条件的攻击信号。
  • 通过时变增益矩阵 $ H_k $ 和固定向量 $ \eta \in \ker \mathcal{C}\Pi $ 构造攻击信号,确保采样时刻的状态轨迹保持在输出矩阵的零空间中。
  • 该方法依赖于对系统矩阵的完整知识,以及以高于传感器采样率的速率注入信号的能力。
  • 通过X-38飞行器和其他数值示例的仿真验证了攻击设计,结果显示在采样输出保持为零的同时,状态持续发散且未被检测到。

实验结果

研究问题

  • RQ1在何种条件下,执行器攻击可在采样数据系统中完全避开离散时间异常检测器?
  • RQ2如何利用多速率或多输入系统中的输入冗余,构造一种能破坏采样间行为稳定性的隐蔽攻击?
  • RQ3即使系统不存在不稳定零点,此类攻击是否仍可设计?(与传统零动态攻击不同)
  • RQ4采样比 $ R = T_s / T_a $ 的估计误差对攻击隐蔽性及检测延迟有何影响?
  • RQ5何种检测机制可有效应对此类零隐蔽性攻击?

主要发现

  • 攻击在所有采样时刻均成功将采样输出保持为零,确保对任何基于输出的异常检测器完全隐蔽。
  • 尽管采样输出为零,连续时间状态轨迹 $ \tilde{x}(t) $ 仍发生发散,表明系统出现严重不稳定。
  • 连续时间输出 $ \tilde{y}(t) $ 变得无界,但其采样值始终保持为零,仿真图11和图12已证实此现象。
  • 当真实采样比 $ R $ 略不同于估计值时(例如 $ R = 0.4004 $ 对比假设的 $ R = 0.4 $),攻击可长时间保持隐蔽,检测延迟至造成显著损害后才被发现。
  • 即使系统不存在不稳定零点,该攻击仍有效,从而与零动态攻击形成鲜明区别。
  • 引入间歇输出采样可检测该攻击,因为输出信号中会出现非零采样值,从而破坏其隐蔽性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。