Source-linked AI summary
Cyber-Physical Systems Security: a Systematic Mapping Study
Yuriy Zacchia Lun, Alessandro D'Innocenzo, Ivano Malavolta, Maria Domenica Di Benedetto
TL;DR
CPS security research lacks a holistic, systematic view despite the importance and multidisciplinary nature of the field. This paper conducts a systematic mapping study of existing research and develops a classification framework, yielding a structured comparison of methods, models, attacks, defenses, and validation strategies. The study is limited to peer-reviewed English-language literature.
Problem
The multidisciplinary CPS-security literature lacks a holistic systematic view of its trends, characteristics, and validation strategies.
Method
The paper systematically maps CPS-security research using a comparison framework covering methods, system aspects, attacks, defenses, and validation information.
Results
The map organizes CPS-security research across formal methods, theoretical foundations, simulation systems, and validation practices.
Takeaways & Limitations
The systematic map provides a comparison framework and supports identification of research trends, gaps, and future directions for CPS security.
Takeaways & Limitations
The study excludes grey literature and non-English publications, potentially omitting relevant primary studies.
Abstract
from arXiv · showhide
Cyber-physical systems are integrations of computation, networking, and physical processes. Due to the tight cyber-physical coupling and to the potentially disrupting consequences of failures, security here is one of the primary concerns. Our systematic mapping study sheds some light on how security is actually addressed when dealing with cyber-physical systems. The provided systematic map of 118 selected studies is based on, for instance, application fields, various system components, related algorithms and models, attacks characteristics and defense strategies. It presents a powerful comparison framework for existing and future research on this hot topic, important for both industry and academia.
I. INTRODUCTION
Cyber-physical systems tightly integrate computation, networking, software, hardware, and physical processes, making security a primary scientific challenge. The study addresses the fragmented CPS-security literature through a systematic mapping of 118 studies and a reusable comparison framework.
- A. Cyber-physical systems: CPS integrate computation, networking, and physical processes through co-designed hardware and software resources.
- I. INTRODUCTION: Security is a primary concern because tight cyber-physical coupling makes failures potentially disruptive and attracts research from multiple independent areas.
- I. INTRODUCTION: The study identifies, classifies, and analyzes existing CPS-security research to clarify how security is addressed in cyber-physical systems.
- I. INTRODUCTION: The systematic mapping selected 118 peer-reviewed primary studies and classified them using more than 40 comparison parameters.
- I. INTRODUCTION: The paper contributes a reusable comparison framework, a systematic review for researchers and practitioners, and discussion of emerging research challenges.
- I. INTRODUCTION: The resulting map provides a comprehensive and replicable picture of CPS-security research, including trends, characteristics, and validation strategies.
B. Security of CPS
CPS security must address attacks, device errors, environmental uncertainty, and real-time constraints that distinguish CPS from conventional IT systems. The review uses systematic-mapping principles to organize prior work and identify gaps, including limited systematic coverage beyond specialized surveys.
- B. Security of CPS: Environmental uncertainty, security attacks, and physical-device errors make overall CPS security a critical challenge.
- B. Security of CPS: CPS security differs from conventional IT security through real-time requirements, tight delay constraints, emergency responsiveness, and resource limitations.
- B. Security of CPS: Existing approaches address availability, integrity, and confidentiality through security-aware design, security mechanisms, intrusion detection, and automatic response or recovery.
- B. Security of CPS: Systematic mapping is designed to answer research questions objectively by finding, classifying, and counting relevant outcomes across defined categories.
- B. Security of CPS: The study aims to help researchers and practitioners identify limitations, gaps, and applicability of CPS-security research in real-world projects.
- B. Security of CPS: Earlier surveys covered smart-grid security or CPS intrusion detection, but the smart-grid surveys were domain-specific and informal rather than systematic literature reviews.
1) Planning:
The planning phase established the study’s research questions, protocol, search and selection procedures, comparison framework, and data-analysis plan. These elements were organized around publication trends, CPS-security characteristics, and validation strategies.
- 1) Planning:: The researchers identified a lack of systematic CPS-security studies and created a review protocol refined through independent expert evaluation.
- 1) Planning:: The protocol planned study search, selection, comparison-framework definition, data extraction, and quantitative and qualitative data synthesis.
- 1) Planning:: The comparison framework was implemented as a data-extraction form whose parameters and meanings were documented for comparing primary studies.
- 1) Planning:: The study’s research questions address publication trends, CPS-security characteristics and focus, and validation strategies.
- 1) Planning:: The resulting classification was intended to provide a foundation for comparing existing and future CPS-security solutions.
B. Search strategy
The study sought broad coverage through complementary automatic, manual, and snowballing searches, then merged and deduplicated the resulting studies. This process produced 1,848 potentially relevant studies before subsequent filtering.
- Search strategy: Three complementary methods—automatic search, manual search, and snowballing—were used to maximize coverage.
- Automatic search: The search string was iteratively refined against a quasi-gold standard until quasi-sensitivity exceeded 80%.
- Automatic search: The automatic search used six electronic databases and indexing systems, with a search string combining CPS terms and security-related terms.
- Automatic search: The automatic search identified 1,559 potentially relevant studies after removing false positives.
- Manual search: The manual search examined selected venues and identified 289 potentially relevant studies.
- Search strategy: 1,848 potentially relevant studies remained after merging automatic and manual searches and removing duplicates.The merged set was then narrowed to 63 studies for snowballing.
C. Selection strategy
Studies were selected using predefined inclusion and exclusion criteria, adaptive reading depth, and researcher agreement procedures. The resulting comparison framework classified CPS-security research by positioning, characterization, and validation.
- Selection criteria: Studies had to address CPS security, propose a security-enforcing or breaching method, and provide some form of validation.
- Selection procedure: Two researchers classified studies, resolved disagreements with administrator intervention when necessary, and used adaptive reading depth to reduce selection effort.
- Comparison framework: The comparison framework grouped extracted parameters into Positioning, Characterisation, and Validation dimensions.
- Comparison framework: Positioning captured what each method addressed, including application field, security attributes, and CPS components.
- Comparison framework: Characterization captured how CPS security was addressed through theoretical foundations and defense strategies such as detection, mitigation, and prevention.
- Comparison framework: Validation included test systems and repeatability, with high repeatability requiring sufficient details to reproduce evaluation procedures and resources.
E. Data synthesis
The synthesis combined quantitative and qualitative analyses to characterize publication trends and venues in CPS-security research. Publications increased sharply after 2011, with recent studies dominating the selected set and spanning diverse research communities.
- Data synthesis: The synthesis used separate quantitative and qualitative methods, including line-of-argument synthesis for qualitative data.
- Publication timeline: 61.8% of selected studies were published in 2014 and 2015, following continuous growth from 2011 onward.The study reports zero publications from 2006 through 2009 and five by 2010.
- Publication timeline: 117 of 118 selected studies, or 99.2%, were published during the last five years covered by the study.The number rose from 18 studies in 2013 to 43 in 2014.
- Publication venues: Journals and conferences accounted for 59 and 50 studies, respectively, while book chapters and workshops accounted for 6 and 3.
- Publication venues: 84 of 118 studies were journal or conference papers published between 2013 and 2015, while five of six book chapters appeared in that period.
- Publication venues: The 118 studies appeared across 53 venues spanning smart grids, automatic control, communications, networked systems, and other areas.
- Publication venues: IEEE Transactions on Smart Grid led the venues with 19 studies, followed by IEEE CDC with 11 and IEEE Transactions on Automatic Control with 9.
C. Research institutions
CPS security research spans many institutions and application domains, but selected studies are concentrated in power grids. The field also shows substantial institutional collaboration and limited coverage of medical CPS.
- C. Research institutions: 127 institutions contributed to the selected studies, averaging 1.79 institutions per study, indicating broad participation and collaboration.
- C. Research institutions: Cornell University led the top institutions with 9 publications, followed by UC Berkeley and KTH with 8 each.
- C. Research institutions: 65 of 118 studies focused exclusively on power grids, while 28 addressed generic linear dynamical systems.
- C. Research institutions: The remaining 25 studies covered applications including ground vehicles, aerial systems, hydro-systems, and building automation.
- C. Research institutions: No selected study addressed the cyber-physical security of medical CPS.
B. Point of view
Most selected studies examine defensive approaches to CPS security, with integrity and sensor protection receiving the greatest attention. Power-grid models, especially DC power-flow models, are prominent in the analyzed work.
- B. Point of view: 62 studies focused exclusively on defense, 28 exclusively on attacks, and 28 addressed both perspectives.
- B. Point of view: More than 90% of studies considered integrity, whereas only two focused solely on availability and confidentiality.
- B. Point of view: Sensor attacks and protection dominated component coverage, with actuators and networks receiving much less attention.
- B. Point of view: The DC power-flow approximation appeared in 53 studies, compared with 16 using AC power-flow models and 51 using other LTI models.
F. Process noise
CPS security studies commonly use noiseless or Gaussian process-noise models and predominantly assume Gaussian measurement noise. Bounded noise models remain less common but have gained recent attention.
- F. Process noise: Measurement-only studies were excluded from the process-noise distribution because process noise was not applicable to their analyses.
- F. Process noise: 30 studies used noiseless process noise and 25 used Gaussian process noise, while bounded non-stochastic noise appeared in 8 studies and recently gained attention.
- F. Process noise: 78 studies used Gaussian measurement noise, 38 assumed noiseless measurements, and 8 used bounded non-stochastic measurement noise.
- F. Process noise: State estimation appeared in 89 studies, with weighted least squares used in 54, Kalman filtering in 21, and Luenberger observers in 10.
- F. Process noise: Resilient state estimation under measurement attacks was characterized as an active research topic with potential for further development.
I. Anomaly detector
Anomaly detection research relies heavily on performance-index and normalized-residual tests, while a substantial minority of studies use novel or no anomaly detector. The literature remains fragmented and lacks agreed comparison benchmarks.
- I. Anomaly detector: 58 approaches used performance-index tests, 22 used normalized-residual tests, and 13 used both.
- I. Anomaly detector: 36 studies did not address anomaly detection, while 26 proposed other novel approaches and 5 used CUSUM-based schemes.
- I. Anomaly detector: The literature includes distributed, application-specific, statistical, algebraic, graph-based, and formal-methods approaches to anomaly detection.
- I. Anomaly detector: The field remains fragmented because agreed comparison metrics and academic or industrial benchmarks have not yet been established.
J. Controller
The mapping shows that many CPS security studies omit controllers and communication details, while attacks concentrate on a few dominant models and remain theoretically oriented.
- J. Controller: 82 studies (69.49%) do not specify a controller, while generic linear feedback controllers appear in 13 studies and LQR and H∞ controllers each in 12.The controller distribution covers the remaining 36 studies, with PID variants in 7 works and fewer event-triggered, self-triggered, and sliding-mode controllers.
- J. Controller: The literature reports interesting theoretical results, but substantial practical challenges remain in CPS security.This limitation is stated as a general comment on the reviewed studies.
- K. Communication aspects and network-induced imperfections: 100 studies (84.75%) omit communication aspects or network imperfections, and only 6 studies (5.08%) address more than one aspect.Only one study explicitly models communication standards such as WirelessHART and ISA-100, indicating limited protocol modeling.
- L. Time-scale model: Discrete-time models appear in 50 studies (42.37%), quasi-static models in 48 (40.68%), continuous-time models in 13 (11.02%), and hybrid models in only 3.All quasi-static studies concern power-system state estimation, and quasi-static analysis is mainly used for SCADA architectures providing steady-state setpoints.
- M. Attacks and their characteristics: False data injection, generic deception, and denial-of-service attacks account for 74.8% of considered attacks, with 57, 33, and 20 occurrences respectively.Variable structure switching, packet scheduling, and bias injection attacks occur only once each.
- M. Attacks and their characteristics: Attack studies mainly use generic deception models, while false data injection is the most studied specific deception attack against state estimation.False data injection manipulates sensor measurements to alter state variables while bypassing bad-data detection schemes.
N. Attack scheme
Attack-scheme studies overwhelmingly assume centralized, near-omniscient adversaries, whereas distributed and local attack strategies receive little attention.
- N. Attack scheme: 102 studies (86.44%) consider only near-omniscient adversaries capable of compromising several system components centrally.Only 6 studies examine distributed attacks and 13 examine local attacks.
- N. Attack scheme: Distributed and local attack solutions require more research attention according to the mapping.This conclusion follows directly from their limited representation among the selected studies.
O. Plant model used by the attacker
Most studies assume attackers possess the same plant model as the operator, while defenses are predominantly centralized and online approaches commonly emphasize detection.
- O. Plant model used by the attacker: 101 studies (85.59%) assume the attacker uses the operator’s plant model, while 14 studies (11.86%) assume no plant model.Only 3 studies use a simpler attacker model than the operator’s model.
- Q. Defense strategy: Among 90 studies with defenses, 74 use only centralized schemes, while local defenses appear in 4 works and distributed approaches in 13.The mapping therefore identifies distributed and local defense solutions as needing more attention.
- Q. Defense strategy: The study classifies defenses into prevention, detection, mitigation, and isolation, extending detection-oriented classifications with isolation.Prevention covers offline actions, whereas online approaches operate after adversarial events occur.
- Q. Defense strategy: Protection-based prevention includes sensor-allocation methods for preventing undetectable false-data-injection attacks, but selecting minimum protected measurements is NP-hard.Greedy algorithms are used in some studies to select measurements for protection.
- Q. Defense strategy: Online defenses comprise detection in 16 studies, detection plus isolation in 16, detection, isolation, and mitigation in 8, mitigation alone in 9, and isolation plus mitigation in 2.Online defenses are examined in 51 studies overall.
R. Theoretical foundation
CPS security studies draw on diverse theoretical foundations, led by graph theory, with control theory present throughout and newer formal methods appearing in a small number of studies.
- R. Theoretical foundation: Control theory is used in every study, while zero-sum game theory is the most common game-theoretic foundation, appearing in 7 studies.The reported zero-sum games do not allow cooperation because one player’s gain is the other’s loss.
- R. Theoretical foundation: Graph theory is the most used theoretical foundation, appearing in 34 studies (28.81%), including 26 studies on power-transmission-network security.Its use reflects the suitability of graphs for representing networks.
- R. Theoretical foundation: Computational complexity theory is used in 11 works, information theory in 8, and dimensionality-reduction or latent-variable methods in 7 studies.These applications are concentrated largely in power-grid and generic dynamical-system studies.
- R. Theoretical foundation: Signal temporal logic and satisfiability modulo theories appear in 3 studies since 2014, supporting anomaly detection and resilient state estimation.These formal methods are applied to generic CPS and power-grid settings.
- R. Theoretical foundation: Optimization appears across several subfields, including convex optimization in 19 studies, linear programming in 16, and dynamic and integer programming in 10 each.Nonlinear, quadratic, and semidefinite programming appear in 6, 5, and 3 studies respectively.
VI. RESULTS - VALIDATION STRATEGIES (RQ3)
Validation research dominates the mapped CPS security literature, with most studies relying on formal proofs and simulations rather than practical evaluation. Power-system studies use standardized test systems extensively, while realistic benchmarks remain missing.
- A. Research type and related research methods: 87 studies (73.73%) use validation research, while 30 studies (25.42%) present solution proposals and only one performs evaluation research in practice.Validation methods include formal proofs, case studies, lab experiments, and simulations; the sole evaluation study demonstrates stealthy deception attacks on a water SCADA system.
- A. Research type and related research methods: Formal mathematical proofs appear in 63 studies (53.39%), including 18 combining proofs with numerical examples and 14 applying proofs to simulation test systems.
- C. Simulation test system: 85 studies (72.03%) use simulation test systems, with MatPower used in all but one power-systems study.IEEE 14-bus is used in 38 works, IEEE 118-bus in 29, and IEEE 30-bus in 17.
- C. Simulation test system: Power-system studies use a broad range of standardized test cases, spanning IEEE networks, MatPower cases, reliability systems, and Kundur multi-area models.IEEE 14-bus and IEEE 118-bus are among the most frequently adopted systems, with 38 and 29 studies respectively.
- C. Simulation test system: Other simulations cover irrigation canals, unstable batch reactors, Tennessee Eastman process control, haptic devices, rotorcraft, and ad hoc systems for robotics, traffic, trains, and aerial navigation.Eight studies use ad hoc simulation test systems, including a 1000-run Monte Carlo evaluation for an unmanned aerial system.
- C. Simulation test system: Although power-network research uses the most advanced and realistic validation methods, the domain still lacks a benchmark for comparing solutions.
D. Repeatability and availability of replication package
The study evaluates repeatability through the detail available for reproducing experiments and finds that most experimental studies score highly, although replication packages are absent. It advocates stronger repeatability and workability practices and notes persistent comparison and application gaps.
- D. Repeatability and availability of replication package: Repeatability means reproducing evaluation or validation results, whereas workability means exploring changes to experiment parameters.High repeatability requires sufficient details about evaluation steps, software, testbeds, and other resources.
- D. Repeatability and availability of replication package: No primary study provides a replication package, although standard test systems and well-known experimental testbeds generally receive high repeatability scores.Ad hoc simulation test systems are associated with low repeatability scores.
- D. Repeatability and availability of replication package: 82 studies (69.49%) have high repeatability, 5 (4.24%) have low repeatability, and 31 (26.27%) cannot be assessed because they report no experiment, case study, or simulation.
- D. Repeatability and availability of replication package: The study advocates replication packages and repeatability best practices so other researchers can build on published contributions and accelerate scientific and technological progress.
- VII. IMPLICATIONS FOR FUTURE RESEARCH: Comparing CPS security solutions remains difficult because studies span diverse application domains, architectures, problem formulations, and theoretical foundations.The authors identify academic or industrial benchmarks, testbeds, and demonstrators as needed comparison infrastructure.
- VII. IMPLICATIONS FOR FUTURE RESEARCH: The literature does not yet show strong synergy between realistic industrial or societal problems and theoretical research, and formal certification against international standards is absent.
VIII. THREATS TO VALIDITY
The study addresses validity threats through a documented, externally reviewed protocol, systematic searching and screening, and defined extraction and analysis procedures. Its scope is limited to peer-reviewed English-language studies, excluding grey literature and potentially non-English evidence.
- Study quality: The study achieved a 54% quality-checklist score, described as outstanding, and used a protocol reviewed externally three times.The study also followed updated systematic review and mapping guidelines.
- Conclusion and internal validity: The protocol and extraction form were defined systematically to support replication and reduce data-extraction bias, while descriptive statistics and sensitivity analysis supported data analysis.
- Selection validity: Screening was documented and supervised, with both researchers assessing a random sample to evaluate selection-process agreement.
- External validity: Automatic database searching, snowballing, and defined inclusion criteria were used to reduce threats to the representativeness of the primary-study set.The combined search strategy was intended to mitigate external-validity threats.
- Scope limitations: The evidence base excludes grey literature and non-English studies, potentially omitting relevant work outside peer-reviewed English-language publications.The authors regard the language-related bias as minimal because English is widely used in scientific papers.
APPENDIX A RESEARCH TEAM
The study was conducted by four researchers with distinct methodological, technical, and advisory responsibilities. The team was locally distributed in Italy, while the appendix also lists the cited CPS-security literature.
- Research team: Four researchers shared the study, with roles spanning principal investigation, secondary support, methodology, and senior advisory decisions.
- Research team: The principal researcher led most activities, while the secondary researcher supported comparison-framework definition, data synthesis, and study execution.
- Research team: The methodologist supported planning and reviewed the extraction form, selected studies, extracted data, and reports; the advisor resolved conflicts and supported synthesis.
- Research team: The team was geographically distributed within Italy, which the paper associates with low communication overhead and fewer misunderstandings.
- Referenced literature: The appendix bibliography includes studies on smart-grid attacks, networked-control security, attack detection, and secure state estimation.