Source-linked AI summary
Resilient Control under Denial-of-Service:Robust Design
Shuai Feng, Pietro Tesi
TL;DR
DoS attacks interrupt communication in networked control systems and can threaten closed-loop stability. This paper develops analog and digital predictor-based controllers with state resetting for a general class of frequency-and-duration-constrained DoS signals. The paper reports that these predictors maximize the amount of DoS that can be tolerated, with digital implementations requiring a suitable sampling rate.
Problem
The paper studies how to preserve closed-loop stability when DoS attacks interrupt plant-controller communication, under attack patterns unlike ordinary packet losses.
Method
The paper designs analog and digital predictor-based controllers using dynamical observers with state resetting to reconstruct missing measurements during DoS periods.
Results
Impulsive-like predictors make it possible to maximize the tolerable DoS amount for signals constrained by attack frequency and duration.
Takeaways & Limitations
Both analog and digital predictor-based implementations achieve the control objective for a general class of DoS signals, with digital versions requiring a suitable sampling rate.
Abstract
from arXiv · showhide
In this paper, we study networked control systems in the presence of Denial-of-Service (DoS) attacks, namely attacks that prevent transmissions over the communication network. The control objective is to maximize frequency and duration of the DoS attacks under which closed-loop stability is not destroyed. Analog and digital predictor-based controllers with state resetting are proposed, which achieve the considered control objective for a general class of DoS signals. An example is given to illustrate the proposed solution approach.
I. INTRODUCTION
The paper addresses DoS attacks that interrupt network communication in cyber-physical control systems, creating stability challenges beyond ordinary packet-loss models. It proposes predictor-based controllers with state resetting to maximize tolerable DoS for a general frequency-and-duration-constrained attack class.
- Motivation: DoS attacks compromise data availability by interrupting plant-controller communication, potentially destabilizing cyber-physical systems.Unlike attacks limited to the cyber realm, CPS attacks can affect physical processes, especially when the controlled process is open-loop unstable.
- Related work: Existing DoS models include optimal attack-control strategies, zero-sum games, pulse-width-modulated attacks, and strategy-independent frequency-and-duration constraints.The strategy-independent framework characterizes attack conditions under which state-feedback can preserve closed-loop stability.
- Paper approach: Static feedback updates control only when measurements arrive, motivating dynamic predictors that reconstruct missing measurements during DoS periods.The paper focuses on impulsive-like predictors implemented as dynamical observers with measurement-triggered state resetting.
- Contribution: Impulsive-like predictors maximize the tolerable DoS amount for the general class of signals defined by attack-frequency and attack-duration constraints.The paper develops both analog and digital predictor-based controllers and illustrates the approach with an example.
A. Process dynamics and network
The controlled process is a disturbed, noisy continuous-time system whose measurements travel over a periodically sampled network subject to DoS failures. Successful measurements occur only at a subset of transmission attempts.
- Process dynamics: The plant follows ẋ(t) = Ax(t) + Bu(t) + d(t), with measurements y(t) = x(t) + n(t).The state, input, and measurement dimensions are n, m, and p; disturbances and noise are unknown but bounded, and (A, B) is stabilizable.
- Network model: Measurements are transmitted over a networked channel, and DoS can cause transmission attempts to fail.The paper does not distinguish failures caused by channel unavailability from failures caused by DoS-induced packet corruption.
- Transmission policy: Transmission attempts occur periodically at times {t_k}, with period Δ and t_0 = 0.Aperiodic transmission policies are identified as a possible extension.
- Successful transmissions: The successful-transmission sequence {z_m} records the times at which samples of y are received.These successful samples provide the measurement updates used by the controller.
B. Control objective
The control objective is to maintain closed-loop stability despite DoS periods. Stability requires bounded closed-loop signals for all initial states and bounded disturbances and noise, with convergence to zero when those exogenous signals vanish.
- Control objective: The controller and transmission period Δ must be designed so closed-loop stability persists despite DoS periods.The controller may be dynamic.
C. Assumptions −Time-constrained DoS
The paper constrains DoS attacks by their timing rather than their underlying strategy, limiting both attack frequency and cumulative duration. These assumptions allow intermittent rapid attacks while bounding their long-term rate and occupied time.
- General DoS model: The DoS model imposes no assumption on the attacker's underlying strategy and constrains attack action through frequency and duration limits.The problem is otherwise unsolvable if the total DoS amount is arbitrary.
- DoS representation: DoS intervals are represented through off/on transition times and the subsets of time during which the network remains unavailable.The quantity n(τ,t) counts DoS transitions over an interval, while the DoS set records unavailable times.
- DoS frequency: Assumption 1 limits DoS frequency using η and an average inter-attack parameter τ_D greater than the transmission period Δ.The model permits occasional attack rates faster than Δ while constraining the long-term number of triggers.
- DoS duration: Assumption 2 limits DoS duration using κ and T greater than 1, bounding the average fraction of time for which communication is interrupted.The parameter κ acts as a regularization term, while T specifies the duration constraint.
D. Previous work and paper contribution
Prior work characterized DoS tolerance for static feedback, while this paper uses prediction to overcome static feedback’s limited update opportunities and attain the best possible robustness bound.
- Previous work: The earlier static-feedback result guarantees stability for DoS sequences satisfying the assumptions and a suitable condition on τD and T.The condition includes arbitrary η and κ.
- Previous work: Static feedback stability depends on an explicit inequality relating DoS parameters, transmission period, and control-system parameters.The parameters ω1 and ω2 depend on the chosen state-feedback matrix K.
- Previous work: Static feedback can struggle to tolerate large DoS amounts because it generates control updates only when new measurements arrive.Prediction is proposed to reconstruct missing measurements during DoS periods.
- Paper contribution: Predictor-based control achieves the best possible DoS-tolerance bound for signals satisfying the stated frequency and duration assumptions.If the bound is violated, the admissible class contains DoS signals that destroy stability.
III. MAIN RESULTS
The paper develops analog and digital predictor-based controllers, analyzes their stability and sampling conditions, and illustrates the approach with an example.
- III-A. Key technical result: The paper first designs analog predictor-based controllers and derives conditions under which stability is guaranteed.It then extends the design to digital predictor-based controllers and characterizes sampling-rate and stability conditions.
- IV. Example: The paper includes an example and concludes with remarks and possible extensions.The example appears in Section IV.
A. Key lemma
The key lemma links DoS constraints to successful-transmission timing, ensuring that successful transmissions occur within bounded intervals when condition (11) holds.
- Key lemma: When condition (11) holds, the first successful transmission occurs by Q and successive successful transmissions are at most Q + ∆ apart.This result applies to transmission policies and DoS signals satisfying Assumptions 1 and 2.
- Proof idea: The proof prolongs each DoS interval by one sampling period to account for transmission attempts affected by the attack.The prolonged interval is denoted by H̄n.
- Proof idea: A positive DoS-free interval of length greater than ∆ contains at least one successful transmission.This observation drives the contradiction argument establishing the timing bound.
- Proof conclusion: The proof concludes the timing bounds by considering whether the initial or subsequent transmission attempts are successful.If an attempt fails, a DoS interval must occur before the next relevant attempt.
B. Analog predictor-based controller
The analog controller combines an impulsive predictor with state feedback, resetting its predicted state at successful measurements to bound prediction error and preserve stability under admissible DoS.
- Controller design: The predictor-based controller combines prediction with state feedback, using an impulsive predictor for its prediction dynamics.The predictor’s state is reset when measurements arrive.
- Controller design: The feedback matrix K is chosen so that every eigenvalue of Φ = A + BK has negative real part.The control input is applied to both the process and the predictor.
- Prediction mechanism: Unlike a classical asymptotic observer, the predictor has measurement-triggered jumps in its state.These jumps allow the prediction error to be reset whenever a new measurement becomes available.
- Prediction mechanism: Stability depends on the prediction error magnitude, whose boundedness follows from state resetting and the finite-time transmission guarantee.Lemma 1 ensures that a reset occurs within a finite time.
- Stability result: The analog closed loop is stable for any DoS sequence satisfying the assumptions and condition (11), with arbitrary η and κ.This result follows from Lemma 2.
- Stability result: The controller provides global exponential stability with linear disturbance-and-noise-to-state bounds.When disturbance and noise converge to zero, the process and predictor states also converge to zero.
C. Digital predictor-based controller
The digital predictor-based controller uses sampled updates, an auxiliary state-resetting variable, and a sampling-rate constraint to preserve stability under the considered DoS signals. With a suitable sampling rate, it achieves the same robustness properties as the analog implementation.
- Digital implementation: Digital control actions update at a finite rate, so stability requires constraints on the controller sampling rate.The extra sampling-related term prevents the analog boundedness argument from applying directly.
- Controller architecture: The digital controller uses an auxiliary variable α to implement state resetting in the discrete update equations.Between successful transmissions, α coincides with the predicted state, which evolves as a linear time-invariant discrete-time system.
- Stability analysis: Lemma 3 gives sampling-rate conditions under which the predictor error remains bounded for DoS sequences satisfying the stated frequency and duration assumptions.The bound is established both at controller sampling instants and between successive controller updates.
- Stability result: Theorem 3 states that choosing the sampling rate as in Lemma 3 guarantees closed-loop stability for any DoS sequence satisfying the assumptions and condition (11).The result permits arbitrary η and κ within those assumptions.
- Comparison with analog control: The digital implementation requires a proper sampling-rate choice but achieves the same robustness properties as the analog implementation, with admissible rates computable from system parameters.A submultiple of the network transmission period can synchronize controller updates with transmissions.
IV. EXAMPLE
The numerical example evaluates analog and digital predictor-based controllers on an open-loop unstable system under sustained, randomly varying DoS. Both predictor-based controllers satisfy the stability requirement and maintain high performance, while pure static feedback becomes unstable in the same attack scenario.
- Setup: The example uses an open-loop unstable system with bounded random disturbance and noise uniformly distributed in [−0.1, 0.1].The network transmission period is Δ = 0.1s, and the digital controller uses δ = 0.01s under the derived constraint δ < 0.1508.
- DoS scenario: The 50s simulation applies a sustained DoS attack with 38.8s of disruption, 52 attack events, and approximately 80% transmission failures.The corresponding averaged parameters are τD ≈ 0.96 and T ≈ 1.29.
- Results: The predictor-based controllers satisfy the stability requirement under the simulated DoS parameters.Figure 1 compares the analog and digital predictor-based controllers with pure static feedback.
- Results: The pure static feedback law fails its stability requirement for the simulated DoS parameters, whereas predictor-based control maintains very high performance despite the sustained attack.The static-feedback theoretical bound is conservative: simulations show stability only up to approximately 40% transmission failures for this system.
- Noise sensitivity: Stability is independent of disturbance and noise magnitude, but performance is not; noise significantly affects state-estimate accuracy and closed-loop behavior during DoS.Figure 2 examines the analog and digital controllers when disturbance and noise are uniform in [−0.01, 0.01].
V. CONCLUDING REMARKS
The paper concludes that dynamical observers with state resetting can maximize tolerated DoS for a general class of attack signals, with analog and digital implementations. Future work includes partial-state measurements and robustness to measurement noise.
- Conclusions: Dynamical observers with state resetting maximize the amount of DoS tolerated for a general class of DoS signals.This is the paper’s central concluding claim about DoS-resilient control.
- Conclusions: Both analog and digital implementations are presented, with the digital version requiring a suitable controller sampling rate.The conclusion distinguishes the implementation requirement without changing the stated robustness objective.
- Extensions: Future extensions include similar control architectures for partial state measurements and studies of performance robustness against measurement noise.Measurement noise is identified as the main factor affecting process-state estimation quality.