Source-linked AI summary
Resilient Control under Denial-of-Service
Claudio De Persis, Pietro Tesi
TL;DR
The paper asks how to control networked linear systems when an intelligent adversary interrupts measurement and control communication. It models DoS explicitly and designs sampling updates that adapt to the process and attacks. Stability is preserved when DoS is active for no more than a suitable average-time percentage, under stated assumptions.
Problem
The paper addresses how to preserve global exponential stability in networked control when malicious DoS attacks interrupt communication and cannot be modeled as random packet losses.
Method
The paper models a sampled-data linear system with simultaneous DoS on both communication channels and uses control update rules that adapt sampling to the process and attack occurrence.
Results
DoS signals preserve asymptotic stability when their active duration remains below a suitable average percentage of time and the stated stability conditions hold.
Takeaways & Limitations
Resilient control can preserve stability under sufficiently limited DoS by adapting the sampling rate to the process state and attack occurrence.
Takeaways & Limitations
The paper does not investigate disturbances, quantization, or delays, and leaves output-feedback and nonlinear extensions for future work.
Abstract
from arXiv · showhide
We investigate resilient control strategies for linear systems under Denial-of-Service (DoS) attacks. By DoS attacks we mean interruptions of communication on measurement (sensor-to-controller) and/or control (controller-to-actuator) channels carried out by an intelligent adversary. We characterize the duration of these interruptions under which stability of the closed-loop system is preserved. The resilient nature of the control descends from its ability to adapt the sampling rate to the occurrence of the DoS.
1. INTRODUCTION
The paper studies resilient control for networked linear systems when intelligent DoS attacks disrupt communication. It seeks update rules that preserve closed-loop stability when jamming is sufficiently limited on average.
- Related work: Event/self-triggering control has addressed output feedback, disturbances, large-scale systems, and distributed coordination, but robustness against malicious attacks has fewer results.
- Motivation: DoS attacks disrupt sensor and control communication, causing packet losses and potentially forcing the process to evolve under out-of-date control.Unlike random packet losses, DoS must be analyzed without assuming a stochastic attack model because the attacker is malicious and intelligent.
- Problem: The paper considers a continuous-time linear process with a digital controller while an unknown attacker can interrupt both sensor and control channels.
- Contribution: Suitable control update rules exist when the average ratio between active and sleeping jamming periods is sufficiently small.
- Related work: The framework differs from prior finite-horizon optimal control and attack-strategy formulations because the controller may use any suitable design method rather than optimizing control and attacks.
2. FRAMEWORK AND PROBLEM OVERVIEW
The framework models a sampled-data linear system whose sensor and actuator communications can be simultaneously interrupted by DoS. The problem is to adapt control updates so global exponential stability is preserved for attack sequences satisfying regularity and average-duration conditions.
- Framework: The process is a continuous-time linear system with a state-feedback matrix K chosen so A + BK has eigenvalues with negative real parts.
- Framework: Control updates occur at a generated sequence {t_k}, and a sample-and-hold device applies the latest computed control action between updates.
- DoS model: DoS simultaneously blocks sensor-to-controller and controller-to-actuator communication, so the actuator uses the most recently received control signal during each DoS interval.
- Problem overview: The control problem is whether update mechanisms can preserve global exponential stability for selected DoS signals, rather than for arbitrary attacks.
- DoS assumptions: The DoS model requires a positive lower bound on interval durations and imposes a slow-on-the-average condition on cumulative DoS time.This regularity excludes Zeno behavior and allows startup DoS when the corresponding constant is positive.
- Problem overview: Without DoS, sufficiently small inter-sampling times can ensure stability, whereas arbitrary DoS can destroy stability for open-loop unstable systems.
3. MAIN RESULTS
The proposed control update rule preserves global exponential stability under DoS signals satisfying a duration constraint, while adapting communication behavior when attacks interrupt transmissions. The analysis also characterizes implementation trade-offs involving sampling rate, update frequency, and DoS tolerance.
- 3. MAIN RESULTS: The update rule enforces a state-error condition during communication availability and switches to repeated transmission attempts after a packet loss.Once communication is restored, the sampled measurement is transmitted immediately so the update condition is enforced.
- 3. MAIN RESULTS: The ideal continuous-transmission mechanism requires finite-sampling-rate extensions because repeated attempts during DoS cannot be implemented directly on digital platforms.Theorem 2 extends the stability conclusions to update sequences with a finite sampling rate.
- 3.1 Stability analysis: The stability proof bounds state evolution separately over communication-available intervals and DoS intervals, combining nominal decay with attack-induced growth.The derivation uses bounds on the closed-loop matrix exponential and on the process dynamics during DoS.
- 3.1 Stability analysis: Theorem 1 establishes global exponential stability when the control update rule and DoS sequence satisfy the stated constraints.The result assumes exponentially stable nominal dynamics and imposes conditions on update timing and admissible DoS duration.
- 3.1 Stability analysis: The admissible DoS condition limits the total duration of DoS intervals relative to time, while stability without DoS still requires sufficiently frequent control updates.For κ = 0, the paper states |Ξ(t)| ≤ t/τ; the update-frequency constraint remains necessary even when communication is always available.
- 3.1 Stability analysis: Increasing the nominal decay rate can improve DoS tolerance, but may require larger overshoots and more frequent control updates.The paper notes that controller redesign can tolerate a prescribed DoS-time fraction at these costs.
4. IMPLEMENTATION AND RESILIENT CONTROL LOGICS
The paper extends stability guarantees to finite sampling rates and develops event-driven, time-driven, and self-triggering resilient control logics that adapt updates during DoS.
- 4.1 Stability under finite sampling rate: Finite sampling rates introduce additional control-update delays after DoS intervals, which Theorem 2 incorporates through ∆∗ and τ∗.The enlarged intervals model the time between DoS recovery and the next available sampling instant.
- 4.1 Stability under finite sampling rate: Theorem 2 preserves global exponential stability when the finite-rate update sequence and DoS signal satisfy its stated conditions.The stability bounds explicitly depend on the finite-rate delay and DoS parameters.
- 4.1 Stability under finite sampling rate: More frequent DoS intervals are more critical than fewer intervals with the same total duration because they can deny more communication attempts.The required DoS constraint becomes more restrictive as the minimum DoS duration decreases.
- 4.2 Implementation and resilient control logics: Event/time-driven logic switches to periodic attempts during DoS, while purely time-driven implementation embeds the logic in the control unit.The periodic update prevents continuous updating when the state is zero.
- 4.2 Implementation and resilient control logics: Self-triggering logic adapts the next update interval to predicted state magnitude, using shorter intervals when the predicted state is larger.This increases the sampling rate as the process moves farther from the origin while retaining the stability conditions.
5. CONCLUSIONS
The paper establishes resilient control strategies for linear systems under DoS by adapting sampling to the process state and attack occurrence. It also identifies unaddressed information constraints and extensions for future work.
- 5. CONCLUSIONS: The proposed strategies preserve asymptotic stability when DoS signals remain active for no more than a certain average percentage of time.The conclusion summarizes the main stability requirement for the considered DoS signals.
- 5. CONCLUSIONS: Resilience comes from adapting the sampling rate to both the process state and the occurrence of DoS attacks.The conclusion identifies this adaptation as the source of the strategy’s resilient nature.
- 5. CONCLUSIONS: The analysis does not investigate disturbances, quantization, or delays, and leaves output-feedback and nonlinear-system extensions for future work.Distributed coordination and large-scale event-based control are also identified as future research directions.
Appendix A. LYAPUNOV-BASED APPROACH
The appendix provides an alternative Lyapunov-based analysis of the DoS-resilient closed loop. It uses a quadratic Lyapunov function to establish global exponential stability and compute explicit bounds.
- Appendix A. LYAPUNOV-BASED APPROACH: The Lyapunov function V(x)=x⊤Px is built from the positive-definite solution P of Φ⊤P+PΦ+Q=0.The matrix Φ=A+BK is the stable nominal closed-loop matrix.
- Appendix A. LYAPUNOV-BASED APPROACH: The proof separates intervals without DoS from DoS intervals and combines their bounds through the accumulated attack and non-attack durations.The identity |Θ(t)|=t−|Ξ(t)| links the two portions of the time axis.
- Appendix A. LYAPUNOV-BASED APPROACH: Theorem 3 establishes global exponential stability for DoS sequences satisfying the assumed duration and average-activity conditions.The result uses a quadratic Lyapunov function associated with the nominal closed-loop matrix.
- Appendix A. LYAPUNOV-BASED APPROACH: Under the stated conditions, the stability estimate has constants α=eκ(ω1+ω2)α2/α1 and β=[ω1−(ω1+ω2)/τ]/2.The parameters ω1 and ω2 summarize the Lyapunov bounds associated with non-DoS and DoS evolution.
Appendix B. PROOFS
Appendix B proves the main stability results by applying a generalized Gronwall-type inequality to bounds on the process state across DoS-induced discontinuities. The proofs also establish how successful control updates and DoS-interval geometry support the stated conclusions.
- Theorem 1: For h_0 = 0, the proof uses x(t_k(h_0)) = 0 and rewrites the bound using ω_1 = μξ(0), obtaining the same result through Lemma 2.The condition μ ∈ R≥1 provides the bound needed to apply the lemma with ℓ_n = h_n.
- Lemma 2: Lemma 2 extends the standard Gronwall-Bellman inequality to piecewise continuous functions with nondecreasing discontinuity terms δ_k(t).When all δ_k(t) vanish, the result reduces to the standard Gronwall-Bellman inequality.
- Theorem 1: Theorem 1 is proved by applying Lemma 2 to a transformed state norm, with the sequence {h_n} representing discontinuities caused by DoS.The transformation is ξ(t) := e^{λt}∥x(t)∥, and the inequality combines bounds from (13), (14), and (24).
- Theorem 1: The proof handles h_0 > 0 by setting ℓ_0 = 0 and ℓ_{n+1} = h_n, then applies Lemma 2 after substituting the relevant variables and parameters.This construction uses the nondecreasing functions δ_n(t) and yields the desired bound.
- Theorem 2 and Proposition 1: Theorem 2 follows by transferring Theorem 1's proof to modified DoS and non-DoS sets, while Proposition 1 ensures a successful control update when separated DoS intervals leave sufficient time.If consecutive modified DoS intervals do not overlap, an update occurs within a period of length Δ_1.