[论文解读] Attack-Resilient Supervisory Control of Discrete-Event Systems.
本文提出了一种针对离散事件系统(DES)在传感器和执行器遭受一般性对抗性攻击下的监督控制框架,将系统与攻击均建模为有限状态转移器(FSTs)。通过引入新的可控制性条件与合成算法,实现了抗攻击的监督控制器,确保在观测数据被污染或执行命令被篡改的情况下仍能实现安全控制,并将该方法扩展至非确定性系统,同时保证非阻塞性。
In this work, we study the problem of supervisory control of discrete-event systems (DES) in the presence of attacks that tamper with inputs and outputs of the plant. We consider a very general system setup as we focus on both deterministic and nondeterministic plants that we model as finite state transducers (FSTs); this also covers the conventional approach to modeling DES as deterministic finite automata. Furthermore, we cover a wide class of attacks that can nondeterministically add, remove, or rewrite a sensing and/or actuation word to any word from predefined regular languages, and show how such attacks can be modeled by nondeterministic FSTs; we also present how the use of FSTs facilitates modeling realistic (and very complex) attacks, as well as provides the foundation for design of attack-resilient supervisory controllers. Specifically, we first consider the supervisory control problem for deterministic plants with attacks (i) only on their sensors, (ii) only on their actuators, and (iii) both on their sensors and actuators. For each case, we develop new conditions for controllability in the presence of attacks, as well as synthesizing algorithms to obtain FST-based description of such attack-resilient supervisors. A derived resilient controller provides a set of all safe control words that can keep the plant work desirably even in the presence of corrupted observation and/or if the control words are subjected to actuation attacks. Then, we extend the controllability theorems and the supervisor synthesizing algorithms to nondeterministic plants that satisfy a nonblocking condition. Finally, we illustrate applicability of our methodology on several examples and numerical case-studies.
研究动机与目标
- 解决离散事件系统在受到传感与执行环节任意、非确定性攻击时的监督控制挑战。
- 利用有限状态转移器(FSTs)对确定性与非确定性系统以及广泛类别的攻击进行建模,实现对真实且复杂攻击行为的精确表达。
- 开发新的可控制性条件与合成算法,用于构建抗攻击的监督控制器,确保在观测数据被污染或执行命令被篡改的情况下仍能实现安全行为。
- 将该框架扩展至非确定性系统,并在非阻塞条件下运行,确保受控系统的活性与正确性。
- 通过示意性案例与数值实验,展示所提方法的适用性与有效性。
提出的方法
- 将系统与攻击均建模为有限状态转移器(FSTs),实现对确定性与非确定性系统及攻击的统一表示。
- 提出新的可控制性条件,以考虑传感器与/或执行器受到攻击的情形,确保控制行为始终安全且有效。
- 设计合成算法,生成基于FST的抗攻击监督控制器描述,表示在攻击场景下所有安全的控制动作。
- 通过引入非阻塞条件,将可控制性与合成框架扩展至非确定性系统,以保持系统活性。
- 利用正则语言定义对传感与执行动作序列可能的攻击修改(如添加、删除、重写),实现对攻击行为的系统化建模。
- 利用FST形式化方法,实现对复杂、真实攻击模式及其对系统控制影响的可扩展、精确建模。
实验结果
研究问题
- RQ1当传感器观测与执行器指令均遭受任意、非确定性篡改时,如何设计监督控制策略以保持其有效性?
- RQ2在存在此类对抗性攻击时,何种形式化条件可确保DES的可控制性?这些条件如何实现算法化验证?
- RQ3如何将抗攻击监督控制器作为有限状态转移器进行合成,以确保在输入数据被污染或执行被篡改时仍能保证安全行为?
- RQ4所提出的框架在何种方式下可扩展至非确定性系统,同时保持非阻塞行为?
- RQ5所提出的模型与算法如何处理对传感与执行序列进行修改的复杂、真实攻击模式?
主要发现
- 本文建立了专门针对传感器与执行器攻击的新型可控制性条件,支持在输入/输出被污染的对抗性环境下对安全控制进行形式化验证。
- 开发了一种合成算法,可生成基于FST的抗攻击监督控制器描述,完整表示在攻击场景下的所有安全控制动作。
- 该框架成功扩展至非阻塞条件下的非确定性系统,确保受控系统保持活性与正常运行。
- FST的使用使得对涉及传感与执行动作字任意修改的复杂、真实攻击模式实现精确且可扩展的建模。
- 案例研究验证了该方法在处理多样化攻击模式的同时,仍能保持系统安全与期望行为的实用性。
- 该方法为设计对广泛类别的动态与非确定性攻击具有鲁棒性的监督控制器提供了形式化基础。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。