[论文解读] Compensation of Linear Attacks to Cyber Physical Systems through ARX System Identification
本文提出了一种针对受线性欺骗攻击的网络物理系统(CPS)的入侵检测与补偿框架,采用ARX系统辨识技术。通过持续比较实时系统输出与在线辨识器预测的输出,系统可检测异常,并触发重新辨识与控制器重设计,以在攻击下恢复系统稳定性。
Cyber-Physical Systems (CPSs) are vastly used in today's cities critical infrastructure. The cyber part of these systems usually has a network component through which cyber attacks can be launched. In this paper, we first design an intrusion detection system (IDS) by identifying the plant. We assume the initial operation period of the CPS is attack-free and learn the plant model. Then, we compare the expected output found via the identifier with the real one coming through the feedback link. Any difference greater than a threshold is deemed to be an anomaly. To compensate, once the IDS flags a change in the loop, we restart the system identification to find the new transfer function. With the estimation of the new transfer function at hand, a new controller is designed to keep the system stable. To test the idea, we took a DC motor as the plant and employed ARX identifier. MATLAB Simulink environment was used to test the proposed intrusion detection and compensation framework. We applied a set of deception attacks to the forward channel in our experiments. The obtained results prove that our detection strategy works well and timely reacts to anomalies. Moreover, they show that the compensation strategy is also effective and keeps the system stable under such attacks.
研究动机与目标
- 解决网络物理系统(CPS)在控制回路中易受线性欺骗攻击的漏洞。
- 在正常运行期间基于系统辨识开发一种实时入侵检测机制。
- 设计一种动态补偿策略,在检测到攻击后恢复系统稳定性。
- 通过使用直流电机装置的仿真CPS环境验证该框架的有效性。
提出的方法
- 在初始无攻击阶段使用ARX(带外生输入的自回归)模型辨识技术学习被控对象动态特性。
- 将实时反馈输出与ARX模型预测输出进行比较以检测异常。
- 当预测误差超过预设阈值时触发基于阈值的报警,表明可能存在攻击。
- 在检测到异常后,重新启动系统辨识,以估计攻击条件下的新被控对象传递函数。
- 利用更新后的ARX模型重新设计控制器,以在受控条件下稳定系统。
- 在MATLAB/Simulink中实现并测试该框架,采用直流电机作为CPS被控对象。
实验结果
研究问题
- RQ1基于ARX的系统辨识能否有效检测CPS控制回路中的线性欺骗攻击?
- RQ2系统辨识模块在多快且多准确地检测到由攻击引起的偏差?
- RQ3重新辨识与控制器重设计过程能否在攻击后恢复系统稳定性?
- RQ4该检测与补偿框架在各种类型的线性攻击下表现如何?
- RQ5基于阈值的异常检测机制如何在灵敏度与误报率之间取得平衡?
主要发现
- 入侵检测系统成功识别出对前向信道的欺骗攻击,并实现了及时响应。
- 在攻击期间,ARX模型与实际系统输出之间的预测误差超过阈值,证实了异常检测的有效性。
- 在检测到异常后,系统重新辨识了被控对象模型,并重新设计了控制器以稳定系统。
- 仿真结果证实,补偿策略能有效在攻击下恢复系统稳定性。
- 该框架在控制回路中存在线性攻击时,表现出维持系统性能的鲁棒性。
- ARX建模的使用实现了精确且计算高效的系统辨识,适用于实时应用。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。