Skip to main content
QUICK REVIEW

[论文解读] Sequential detection of Replay attacks

Arunava Naha, André Teixeira|arXiv (Cornell University)|Dec 19, 2020
Smart Grid Security and Resilience被引用 4
一句话总结

本文提出一种基于水印和累积和(CUSUM)检验的序列检测方法,用于在信息物理系统中检测重放攻击。通过推导攻击前后联合分布之间的Kullback-Leibler散度(KLD),该方法实现了渐近最优检测,检测延迟最小化,同时在控制成本增加固定的前提下,优化水印方差以最大化KLD。

ABSTRACT

One of the most studied forms of attacks on the cyber-physical systems is the replay attack. The statistical similarities of the replay signal and the true observations make the replay attack difficult to detect. In this paper, we have addressed the problem of replay attack detection by adding watermarking to the control inputs and then performed resilient detection using cumulative sum (CUSUM) test on the joint statistics of the innovation signal and the watermarking signal. We derive the expression of the Kullback-Liebler divergence (KLD) between the two joint distributions before and after the replay attack, which is asymptotically inversely proportional to the detection delay. We perform structural analysis of the derived KLD expression and suggest a technique to improve the KLD for the systems with relative degree greater than one. A scheme to find the optimal watermarking signal variance for a fixed increase in the control cost to maximize the KLD under the CUSUM test is presented. We provide various numerical simulation results to support our theory. The proposed method is also compared with a state-of-the-art method.

研究动机与目标

  • 解决在重放攻击信号与正常系统行为难以区分的背景下,检测隐蔽重放攻击的挑战。
  • 通过在控制输入上引入水印,并对创新信号与水印信号进行联合统计检验,提升检测的鲁棒性。
  • 通过优化预攻击与后攻击联合分布之间的Kullback-Leibler散度(KLD),最小化检测延迟。
  • 设计最优水印方差,以在控制成本增加受限的前提下,最大化攻击可检测性。
  • 对相对阶大于1的系统,提供KLD的结构化分析,以提升检测性能。

提出的方法

  • 提出一种基于创新信号与水印信号联合概率分布的CUSUM检验,用于序列化检测重放攻击。
  • 推导攻击前后联合分布之间的Kullback-Leibler散度(KLD),其与渐近检测延迟成反比。
  • 采用添加到控制输入中的水印信号,该信号为独立同分布(i.i.d.),以保持统计可检测性。
  • 对KLD表达式进行结构化分析,以识别在相对阶大于1的系统中提升检测性能的条件。
  • 提出一种优化框架,用于计算在控制成本增加固定的前提下,使KLD最大化的最优水印方差。
  • 采用基于卡尔曼滤波的状态估计器生成创新信号,该信号与水印联合进行统计检验。
Figure 1: Schematic diagram of the system during normal operation.
Figure 1: Schematic diagram of the system during normal operation.

实验结果

研究问题

  • RQ1如何为创新与水印信号的攻击前后联合分布之间的Kullback-Leibler散度(KLD)推导出最优检测所需的表达式?
  • RQ2KLD表达式的哪些结构性特征可使相对阶大于1的系统的检测性能得到提升?
  • RQ3如何优化水印信号方差,以在控制成本增加受限的前提下,最大化检测性能?
  • RQ4在所提出的基于CUSUM的检测框架中,KLD与渐近检测延迟之间存在何种关系?
  • RQ5在相同控制成本约束下,所提出方法与现有最先进重放攻击检测技术相比,性能如何?

主要发现

  • 创新与水印信号联合分布之间的Kullback-Leibler散度(KLD)与检测延迟呈渐近反比关系,从而实现最优检测性能。
  • 对于相对阶大于1的系统,KLD表达式的结构化分析揭示了通过系统特定信号设计提升检测性能的条件。
  • 推导出最优水印方差,以在控制成本增加固定的前提下最大化KLD,确保检测性与系统能耗之间的最佳权衡。
  • 数值仿真表明,在相同控制成本约束下,所提方法的检测延迟显著低于现有最先进方法。
  • 该方法在误报前保持了1000的高平均运行长度(ARL),表明对误报具有强鲁棒性。
  • 基于联合创新-水印统计量的CUSUM检验优于批处理方法,实现了低延迟的实时序列检测。
Figure 2: Schematic diagram of the system under replay attack.
Figure 2: Schematic diagram of the system under replay attack.

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。