Source-linked AI summary

On the performance analysis of resilient networked control systems under replay attacks

Minghui Zhu, Sonia Martinez

arXiv:1307.2790v1math.OC

TL;DR

The paper addresses the uncharacterized performance degradation of receding-horizon control under communication unreliability and replay attacks. It proposes a variation of the receding-horizon control law, analyzes stability and performance degradation, and studies competitive and cooperative resource allocation problems.

  • Problem

    Prior work does not characterize the performance degradation of receding-horizon control induced by communication unreliability.

  • Method

    The paper studies a variation of receding-horizon control under replay attacks and analyzes the resulting system stability and performance degradation.

  • Results

    The analysis establishes asymptotic stability and derives a simple, explicit relation involving the infinite-horizon cost.

  • Takeaways & Limitations

    The paper extends resilient receding-horizon control analysis to replay and denial-of-service attacks and considers competitive and cooperative resource allocation problems.

Abstract

from arXiv · show

This paper studies a resilient control problem for discrete-time, linear time-invariant systems subject to state and input constraints. State measurements and control commands are transmitted over a communication network and could be corrupted by adversaries. In particular, we consider the replay attackers who maliciously repeat the messages sent from the operator to the actuator. We propose a variation of the receding-horizon control law to deal with the replay attacks and analyze the resulting system performance degradation. A class of competitive (resp. cooperative) resource allocation problems for resilient networked control systems is also investigated.

I. INTRODUCTION

The paper addresses resilient control for networked systems whose communications are vulnerable to cyberattacks, focusing on replay attacks. It proposes and analyzes a replay-resilient receding-horizon controller and associated resource-allocation formulations.

  • System setting: Networked control systems connect spatially distributed plants, sensors, actuators, and operators through communication networks.State measurements travel from sensors to operators, while generated control commands travel to actuators.
  • Problem: Replay attacks maliciously repeat transmitted messages, creating a cybersecurity concern for networked control systems.The paper assumes attacks can be detected and focuses on designing resilient controllers against them.
  • Research gap: Existing receding-horizon approaches address robustness to certain denial-of-service and replay attacks under respective assumptions, but do not characterize degradation caused by communication unreliability.The stated gap concerns performance degradation of receding-horizon control under unreliable communication.
  • Contributions: The paper studies a variation of receding-horizon control under replay attacks and provides sufficient conditions for asymptotical and exponential stability.These conditions are part of the proposed resilient-control analysis.
  • Contributions: A simple explicit relation between infinite-horizon cost and computing and attacking horizons supports analysis of resilient networked control.The relation is also used to formulate competitive resource allocation as convex games and cooperative allocation as convex programs.
  • Contributions: The paper also investigates a class of competitive and cooperative resource allocation problems for resilient networked control systems.These are characterized respectively as convex games and convex programs.

II. ATTACK-RESILIENT RECEDING-HORIZON CONTROL

The paper models a constrained discrete-time linear system connected to a remote operator through a network where replay attacks repeat previously transmitted commands. It defines attack duration and energy assumptions, then focuses on attack detection and resilient control design.

  • A. Description of the controlled system: The controlled plant is a discrete-time linear time-invariant system with constrained states and inputs.The state and input belong to constraint sets X and U, while the pair (A, B) is assumed stabilizable.
  • A. Description of the controlled system: The auxiliary controller is u = Kx, with K chosen so the closed-loop matrix A + BK has spectrum strictly inside the unit circle.The constraint assumption requires Kx ∈ U for x ∈ X.
  • B. The closed-loop system with the replay attacker: The plant, sensor, actuator, and operator are spatially separated and connected through communication channels.State measurements and control commands are transmitted through the network linking these entities.
  • B. The closed-loop system with the replay attacker: During a replay attack, the adversary erases current operator data, sends previously stored data to the actuator, and keeps its memory unchanged.When idle, the adversary intercepts and stores the operator's transmitted data instead.
  • B. The closed-loop system with the replay attacker: The variable s(k) records the number of consecutive replay attacks up to time k.It increments when an attack occurs and resets to zero otherwise.
  • B. The closed-loop system with the replay attacker: The adversary is assumed to have limited energy and can launch at most S consecutive attacks.This bound is formalized as the maximum number of consecutive attacks.
  • B. The closed-loop system with the replay attacker: Replay attacks are assumed detectable, and the paper focuses on designing and analyzing resilient controllers against them.The text notes that attaching a timestamp to each control command can detect this attack class.

C. Attack-resilient receding-horizon control law

The paper proposes AR-RHC, a replay-resilient variation of receding-horizon control, and characterizes its stability and infinite-horizon cost under attack conditions. The law stores and reuses control sequences, with stability guarantees determined by the horizon and replay duration.

  • AR-RHC modifies receding-horizon control to address replay attacks and analyze the resulting system performance degradation.
  • The plant stores the whole control sequence for later use in response to future attacks.
  • At each iteration, the operator solves an N-horizon quadratic program subject to system dynamics, state constraints, input constraints, and a terminal-state constraint.
  • When no replay is detected, the actuator receives a new sequence and implements its first control; under replay, it implements the corresponding previously received control.
  • Stability and performance: For N ≥ max{ˆN∗(S) + 1, S + 1}, AR-RHC is asymptotically stable from X0, while ˆN∗(S) ≤ N∗(S).
  • Stability and performance: For N ≥ max{N∗(S) + 1, S + 1}, AR-RHC yields exponential stability from X0 and an upper bound on infinite-horizon cost.

III. DISCUSSION AND SIMULATIONS

The attack-resilient receding-horizon controller extends to DoS and measurement attacks, with explicit horizon bounds quantifying stability requirements and computational cost as attack duration grows.

  • The AR-RHC and Theorem 2.1 extend to DoS attacks, measurement attacks, and combinations of these attacks.
  • The explicit bound ΠE(S) provides a sufficient horizon for exponential stability, while ΠA(S) provides one for asymptotic stability.
  • Larger S requires larger N, indicating higher computational complexity when the adversary is less energy constrained.
  • ΠA(S) can be upper bounded by an affine function because its second term approaches a constant as S grows.
  • For large S, the second term in ΠE(S) dominates, so exponential stability demands much higher cost than asymptotic stability.

C. A reverse scenario

The reverse scenario characterizes the maximum attack horizon tolerated by a fixed control horizon, while the resource-management formulation models security investment and its convex cost structure.

  • C. A reverse scenario: For any horizon N, largest integers S∗(N) and ˆS∗(N) bound attack durations for which γN,S and ˆγN,S remain below one.
  • C. A reverse scenario: Theorem 2.1 therefore characterizes the algorithm’s security level, or amount of resilience, in the reverse setting.
  • D. Optimal resilience management: The resilience-management model assigns each player a bounded security investment Mi and a fixed computational horizon Ni.
  • D. Optimal resilience management: The aggregate security level S(1^TM) is nonnegative, convex, non-decreasing, and smooth as a function of the investment vector.
  • D. Optimal resilience management: The player cost Ci is convex in M, supporting convex formulations for resilience management.

1) Competitive resource allocation scenario:

The paper formulates competitive and cooperative security-investment problems for resilient networked control systems and identifies distributed computational approaches for each.

  • 1) Competitive resource allocation scenario:: In the competitive game, each player minimizes Ci(M) subject to common and private investment constraints.
  • 1) Competitive resource allocation scenario:: Convexity of Ci and S makes the resilience-management game a generalized convex game.
  • 1) Competitive resource allocation scenario:: Distributed algorithms can numerically compute a Nash equilibrium and tolerate transmission delays and packet dropouts.
  • 2) Cooperative resource allocation scenario:: The cooperative formulation is a convex program whose global minimizer can be computed using distributed algorithms robust to changing inter-player topologies.
  • 1) Competitive resource allocation scenario:: Simulations vary attacking horizons S=0, 2, 5; larger S increases convergence time and pre-equilibrium oscillation, while N=15 suffices for stabilization.

V. APPENDIX: TECHNICAL PROOFS

The appendix establishes feasibility, constraint invariance, value-function properties, and Lyapunov decrease needed to prove stability of the attack-resilient controller.

  • The Lyapunov candidate VN−s(k−1)(x(k)) exponentially diminishes under the theorem’s horizon conditions, establishing asymptotic stabilization.
  • The auxiliary controller Kx keeps X0 forward invariant while satisfying the control constraint U.
  • For every x∈X0, the auxiliary control sequence is feasible for the N-QP.
  • The optimal value function VN is quadratically bounded above and below on X0.
  • VN is monotonic in the horizon N, with VN′(x)≤VN(x) for N′<N, and has diminishing ratios as N increases.
Loading 1307.2790v1…