[论文解读] Cyber Attack and Machine Induced Fault Detection and Isolation Methodologies for Cyber-Physical Systems
本文提出了一种基于双滤波器与未知输入观测器(UIO)的方法,用于在信息物理系统(CPS)中同时检测与隔离网络攻击(如隐蔽攻击、零动态攻击、重放攻击)和机器引起的故障。通过在系统端与指挥与控制(C&C)端采用非对称滤波器,并利用基于UIO的残差信号,该方法即使在通信链路被攻破、攻击者掌握完整系统知识(但无法访问所有通信信道)的情况下,仍能实现有效检测。
In this paper, the problem of simultaneous cyber attack and fault detection and isolation (CAFDI) in cyber-physical systems (CPS) is studied. The proposed solution methodology consists of two filters on the plant and the command and control (C\&C) sides of the CPS and an unknown input observer (UIO) based detector on the plant side. Conditions under which the proposed methodology can detect deception attacks, such as covert attacks, zero dynamics attacks, and replay attacks are characterized. An advantage of the proposed methodology is that one does not require a fully secured communication link which implies that the communication link can be compromised by the adversary while it is used to transmit the C\&C side observer estimates. Also, it is assumed that adversaries have access to parameters of the system, filters, and the UIO-based detector, however, they do not have access to all the communication link channels. Conditions under which, using the communication link cyber attacks, the adversary cannot eliminate the impact of actuator and sensor cyber attacks are investigated. To illustrate the capabilities and effectiveness of the proposed CAFDI methodologies, simulation case studies are provided and comparisons with detection methods that are available in the literature are included to demonstrate the advantages and benefits of our proposed solutions.
研究动机与目标
- 解决现有CPS中同时检测网络攻击与机器故障的集成解决方案不足的问题。
- 克服现有故障检测方法无法区分智能网络攻击与物理故障的局限性。
- 实现在无需完全安全通信链路的条件下,检测诸如隐蔽攻击与零动态攻击等不可检测攻击。
- 确保在攻击者掌握系统参数、滤波器与检测器全部信息的前提下仍具备弹性,只要其无法访问所有通信信道。
- 开发一种可同时隔离执行器与传感器故障以及多种网络攻击类型的框架。
提出的方法
- 在系统端部署动态特性与C&C端滤波器故意不同的滤波器,以防止攻击者识别系统端滤波器参数。
- 在系统端实施未知输入观测器(UIO),以生成对故障与网络攻击敏感的残差信号。
- 采用基于残差的检测机制,结合由系统不确定性边界导出的自适应阈值,以区分异常情况。
- 利用Rosenbrock系统矩阵分析,为执行器与传感器网络攻击分别设计残差生成器,确保无非最小相位零动态。
- 施加矩阵秩条件与系统矩阵左可逆性条件,以确保攻击与故障的可检测性。
- 利用非对称滤波器设计,防止攻击者将攻击伪装为正常行为,即使其掌握完整系统知识。
实验结果
研究问题
- RQ1CPS中的CAFDI框架是否能在无需完全安全通信链路的条件下,检测诸如隐蔽攻击与零动态攻击等不可检测网络攻击?
- RQ2当攻击者掌握系统参数与检测器全部信息时,系统如何检测并隔离机器故障与智能网络攻击?
- RQ3何种设计条件可确保网络攻击无法被伪装为正常系统行为或故障?
- RQ4如何生成残差信号以同时检测执行器与传感器故障以及多种网络攻击类型?
- RQ5非对称滤波器设计在阻止攻击者消除其攻击影响方面发挥何种作用?
主要发现
- 所提方法在通信链路受损条件下,成功检测并隔离了执行器与传感器网络攻击,包括隐蔽攻击、零动态攻击与重放攻击。
- 在仿真案例研究中,系统对执行器故障的检测准确率达到96%,对传感器故障的检测准确率也达到96%。
- 即使攻击者掌握系统参数、滤波器与基于UIO的检测器全部信息,只要其无法访问所有通信信道,该方法仍保持有效性。
- 在系统端与C&C端采用非对称滤波器,可防止攻击者复现系统端动态特性,从而阻断攻击伪装。
- 该框架可在无需额外安全通信基础设施的条件下,检测可检测与不可检测攻击。
- 仿真结果表明,该方法性能优于现有方法,尤其在区分网络攻击与物理故障方面表现更优。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。