[论文解读] iSTRICT: An Interdependent Strategic Trust Mechanism for the Cloud-Enabled Internet of Controlled Things
iSTRICT 提出了一种面向云赋能的受控物联网(IoCT)的博弈论互依信任机制,整合了 FlipIt 博弈用于 APT 建模、信号博弈用于设备-云交互,以及最优控制用于物理层效用量化。该机制通过格拉斯曼纳什均衡(GNE)实现最坏情况下的妥协概率保障,在自动驾驶应用中相比朴素策略的性能损失至少降低六倍。
The cloud-enabled Internet of controlled things (IoCT) envisions a network of sensors, controllers, and actuators connected through a local cloud in order to intelligently control physical devices. Because cloud services are vulnerable to advanced persistent threats (APTs), each device in the IoCT must strategically decide whether to trust cloud services that may be compromised. In this paper, we present iSTRICT, an interdependent strategic trust mechanism for the cloud-enabled IoCT. iSTRICT is composed of three interdependent layers. In the cloud layer, iSTRICT uses FlipIt games to conceptualize APTs. In the communication layer, it captures the interaction between devices and the cloud using signaling games. In the physical layer, iSTRICT uses optimal control to quantify the utilities in the higher level games. Best response dynamics link the three layers in an overall "game-of-games," for which the outcome is captured by a concept called Gestalt Nash equilibrium (GNE). We prove the existence of a GNE under a set of natural assumptions and develop an adaptive algorithm to iteratively compute the equilibrium. Finally, we apply iSTRICT to trust management for autonomous vehicles that rely on measurements from remote sources. We show that strategic trust in the communication layer achieves a worst-case probability of compromise for any attack and defense costs in the cyber layer.
研究动机与目标
- 为解决云赋能 IoCT 中的战略信任困境,即设备必须在潜在被高级持续性威胁(APTs)攻陷的情况下决定信任哪些云信号。
- 对三个层级的相互依赖决策进行建模:云层(APT 攻陷)、通信层(信任信号)和物理层(控制性能)。
- 提出统一的均衡概念——格拉斯曼纳什均衡(GNE),以捕捉跨层级的战略互动,并确保对最坏情况攻击的鲁棒性。
- 在自动驾驶网络中展示该机制的有效性,其中远程传感器数据可能被攻击者操纵。
提出的方法
- 使用 FlipIt 博弈对云层中的 APT 进行建模,以表示攻击者和防御者对云服务的战略夺取与再夺取。
- 在通信层使用信号博弈,以基于对云信号的风险评估来建模设备的信任决策。
- 在物理层应用最优控制理论,以量化受污染控制信号带来的效用和性能损失。
- 将三个层级整合到博弈之博弈框架中,通过最佳响应动态将它们链接为统一的战略互动。
- 在自然假设下证明格拉斯曼纳什均衡(GNE)的存在性,并开发一种自适应算法以迭代方式计算该均衡。
- 采用创新门和基于观测器的最优控制,以拒绝来自被攻陷传感器的大偏差项,同时使用混合策略应对自适应攻击者。
实验结果
研究问题
- RQ1在云服务可能被 APT 攻陷的云赋能 IoCT 中,如何对战略信任进行建模?
- RQ2何种均衡概念能够捕捉网络物理系统中云层、通信层和物理层之间相互依赖的战略决策?
- RQ3当设备无法完全拒绝来自潜在被攻陷云服务的信号时,设备能否保证最坏情况下的妥协概率?
- RQ4在信号博弈中引入混合策略如何提升对自适应攻击者的弹性?
- RQ5在自动驾驶等现实应用中,所提机制相较于非战略或朴素信任策略,性能提升如何?
主要发现
- 所提出的 iSTRICT 机制在任何攻击与防御成本配置下,均能保证网络层的最坏情况妥协概率,即使设备无法完全拒绝来自被攻陷云服务的信号。
- 在自然假设下,格拉斯曼纳什均衡(GNE)存在,且可通过自适应算法迭代计算,确保三个层级间的战略稳定性。
- 在自动驾驶仿真中,iSTRICT 相较基线策略,将成本准则降低了至少六倍,无论面对战略或非战略攻击者。
- 信号博弈中的混合策略可防止重复妥协与信任的极限环,使系统稳定于唯一均衡点,使攻击者无法通过偏离策略获益。
- 创新门能有效拒绝恶意信号中的大偏差项,而战略风险阈值可确保仅低风险信号被信任,即使存在噪声。
- GNE 框架的模块化设计允许在设备加入或离开 IoCT 时进行增量更新,而无需重新计算整个均衡。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。