Source-linked AI summary
Networked Control under Random and Malicious Packet Losses
Ahmet Cetinkaya, Hideaki Ishii, Tomohisa Hayakawa
TL;DR
The paper studies stabilization of a linear networked control system exposed to random packet losses and malicious attacks. It proposes a probabilistic failure model and an event-triggered Lyapunov-like control analysis, then derives stabilization and attack-induced instability conditions.
Problem
The paper addresses how random transmission losses and malicious attacks jointly affect stabilization of networked linear control systems.
Method
It models packet failures probabilistically, uses Lyapunov-like functions for event-triggered exchange times, and analyzes both controller and attacker perspectives.
Results
The analysis provides sufficient conditions for almost-sure asymptotic stability and conditions under which combined random and malicious losses destabilize the closed loop.
Takeaways & Limitations
The unified characterization supports analysis of random losses, malicious attacks, and their combination within the same networked-control framework.
Abstract
from arXiv · showhide
We study cyber security issues in networked control of a linear dynamical system. Specifically, the dynamical system and the controller are assumed to be connected through a communication channel that face malicious attacks as well as random packet losses due to unreliability of transmissions. We provide a probabilistic characterization for the link failures which allows us to study combined effects of malicious and random packet losses. We first investigate almost sure stabilization under an event-triggered control law, where we utilize Lyapunov-like functions to characterize the triggering times at which the plant and the controller attempt to exchange state and control data over the network. We then provide a look at the networked control problem from the attacker's perspective and explore malicious attacks that cause instability. Finally, we demonstrate the efficacy of our results with numerical examples.
I. INTRODUCTION
The paper models networked control of a linear system under random losses, malicious attacks, and their combination. It develops probabilistic failure characterization, event-triggered stabilization analysis, and attacker-side instability conditions.
- Cyber threats and unreliable communication channels can disrupt industrial control services and cause financial or environmental damage.
- The proposed stochastic representation unifies random losses, malicious attacks, and their combined effects through a tail-probability condition on average packet failures.
- Random losses are modeled with a binary-valued time-inhomogeneous Markov chain, while attacks may occur arbitrarily subject to an almost-sure bound on attacked exchange attempts.
- The event-triggered controller uses Lyapunov-like functions to schedule state and control-data exchanges before the function exceeds prescribed limits.
- The analysis addresses both almost-sure stabilization and attacker strategies that cause instability through sufficiently frequent packet losses.
- The networked system targets stabilization of x(t) ≡0, with lost exchanges causing the plant-side control input to be set to 0.
1) Random Packet Losses:
The random-loss model represents transmission failures with a time-inhomogeneous Markov chain whose failure probabilities depend on prior exchange outcomes and may vary over time.
- 1) Random Packet Losses:: The binary Markov state lR(i)=1 denotes a random packet-loss failure at exchange attempt τi.
- 1) Random Packet Losses:: Transition probabilities between success and failure states are time-dependent, and success or failure depends on previous exchange attempts.
- 1) Random Packet Losses:: The model uses upper bounds p1 and p0 for transmission failure and success probabilities in the characterization of random losses.
- 1) Random Packet Losses:: For random packet losses, Assumption 2.1 holds for every ρ∈(p1,1).
- 2) Packet Losses Due to Malicious Activity:: The malicious-loss model bounds the number of attacked exchange attempts by a ratio of total attempts, allowing attacks to occur irregularly.
- 2) Packet Losses Due to Malicious Activity:: The generalized attack characterization covers stochastic attacks beyond models that impose a fixed upper bound on consecutive losses.
3) Combination of Random and Malicious Packet Losses (independent case):
The independent combined-loss model forms failures from random Markov losses and malicious attacks, then derives a sufficient range for the aggregate failure-rate parameter.
- 3) Combination of Random and Malicious Packet Losses (independent case):: The combined failure indicator equals one when either the random-loss process or the malicious-attack process equals one.
- 3) Combination of Random and Malicious Packet Losses (independent case):: Proposition 2.4 establishes Assumption 2.1 for all ρ∈(p1+p0ρM,1).
- 3) Combination of Random and Malicious Packet Losses (independent case):: In the independent case, random losses and attacks are modeled by mutually independent processes.
- 3) Combination of Random and Malicious Packet Losses (independent case):: The derivation bounds the aggregate failure event by the union of random-loss and attack-related excess-failure events.
4) Combination of Random and Malicious Packet Losses (dependent case):
The dependent-loss analysis treats malicious attacks and random packet losses jointly, including a worst-case attacker informed about both network losses and transmitted data. This dependence narrows the admissible range of the failure-rate parameter and can introduce conservativeness.
- Proposition 2.5 establishes (4) for all ρ ∈(p1 + ρM, 1) when p1 satisfies (6).
- The proof combines bounds for random and malicious failures through intermediate parameters ρ1 and ρ2.
- The dependent-case range of ρ is more restricted than in Proposition 2.4 because Proposition 2.5 addresses a worst-case attacker.
- The worst-case attacker may know all random losses and transmitted state and control vectors, and may avoid attacking already-lost transmissions to increase total failures.
- Additional information about the dependence can reduce conservativeness and establish ρ < 1 even when p1 + ρM ≥ 1.
- With limited attacker knowledge, including partial state access or no knowledge of random losses and transmitted vectors, Proposition 2.4 may apply.
III. EVENT-TRIGGERED CONTROL DESIGN
The event-triggered design schedules packet-exchange attempts using a quadratic Lyapunov-like function and a maximum inter-attempt interval. The resulting scheme coordinates state and control updates despite successful or failed transmissions.
- III. EVENT-TRIGGERED CONTROL DESIGN: Event-triggered control is studied over an unreliable and potentially attacked network characterized by Assumption 2.1.
- III. EVENT-TRIGGERED CONTROL DESIGN: The triggering scheme uses V(x) = x^T P x to determine packet-exchange times τ_i between the plant and controller.
- III. EVENT-TRIGGERED CONTROL DESIGN: The condition V(Ax(t)+Bu(τ_i)) > βV(x(τ_i)) triggers communication, while t ≥ τ_i + θ imposes the timing bound.
- III. EVENT-TRIGGERED CONTROL DESIGN: The timing rule guarantees τ_i+1 − τ_i ≤ θ, ensuring every triggering time and sampled Lyapunov value are well-defined.
- III. EVENT-TRIGGERED CONTROL DESIGN: Figure 1 depicts successful and failed packet transmissions alongside the Lyapunov-like function response during event-triggered operation.
A. Stability Analysis
The analysis uses probabilistic bounds on packet failures and Lyapunov-like functions to establish sufficient conditions for almost sure asymptotic stability under event-triggered control. It also specializes the result to Markov packet losses and compares the resulting condition with a second-moment criterion.
- Stability Analysis: The packet-loss analysis bounds the long-run average number of failed exchanges almost surely by ρ under the stated probabilistic condition.This bound follows from the Borel-Cantelli lemma and underpins the stability analysis.
- Stability Analysis: The framework permits non-ergodic packet-loss processes whose long-run failure-rate limits may differ across sample paths, while using a worst-case upper bound.An example randomizes attack periods between every 2 and every 4 exchange attempts, with 1/2 as the worst-case long-run bound.
- Stability Analysis: The proof tracks a Lyapunov-like function V(x)=x^TPx, using β for successful exchanges and ϕ for failed exchanges.The resulting bounds distinguish contraction under feedback from possible growth during packet failures.
- Stability Analysis: The argument derives almost sure convergence by showing the Lyapunov bound η(k) tends to zero and then transferring this result to the sampled state sequence.The state remains bounded over triggering intervals through the β and ϕ growth bounds.
- Stability Analysis: For irreducible time-homogeneous Markov packet losses, the failure ratio is ρ=p0,1/(p0,1+p1,0), yielding the same almost sure stability guarantee when the matrix conditions hold.The paper identifies this condition as tighter than the corresponding second-moment criterion for the same setting.
B. Feedback Gain Design for Event-Triggered Control
The feedback-design procedure searches for controller and Lyapunov variables satisfying linear matrix inequalities over selected β and ϕ values. It restricts the search to a curve near the stability boundary without conservatism under the stated monotonicity argument.
- Feedback Gain Design for Event-Triggered Control: The design seeks a feedback gain K, positive-definite matrix P, and β∈(0,1) for the event-triggered control law.An equivalent formulation searches for M and Q with P=Q^-1 and K=MQ^-1.
- Feedback Gain Design for Event-Triggered Control: For fixed β and ϕ, the design inequalities are linear in M and Q, enabling feasible-solution searches through linear matrix inequalities.The resulting feasible variables are converted back to the controller and Lyapunov matrix used in the stability result.
- Feedback Gain Design for Event-Triggered Control: The search iterates over β and ϕ satisfying (1−ρ) ln β+ρ ln ϕ=−∆ for a small ∆>0.This curve lies near the boundary of the admissible region defined by the stability condition.
- Feedback Gain Design for Event-Triggered Control: Restricting the search to larger β and ϕ near the boundary is nonconservative because feasibility for smaller values implies feasibility for larger values.The method therefore need not search the entire region satisfying the stability inequality.
IV. ATTACKER’S PERSPECTIVE
The paper examines how an attacker can induce almost-sure instability by causing sufficiently frequent packet-exchange failures, and derives failure-frequency conditions for random and malicious losses under several dependence structures.
- Attacker’s objective: The attacker seeks to cause sufficiently frequent packet losses while potentially minimizing the number of attacks, because frequent failures can destabilize closed-loop dynamics.The analysis treats instability from the attacker’s perspective and connects attack frequency with packet-exchange failure frequency.
- Instability conditions: Under the stated Lyapunov conditions, the closed-loop state diverges almost surely when the packet-failure process satisfies the instability criteria.The proof uses a Lyapunov-like function whose growth implies limt→∞∥x(t)∥=∞ almost surely.
- Instability conditions: The instability conditions complement the paper’s stability conditions, although tightness may fail for multidimensional systems and when long-run loss ratios do not converge.For scalar systems with fixed asymptotic loss ratios, the stability and instability conditions can be tight.
- Random and malicious losses: With independent random and malicious losses, the admissible failure-frequency range is σ ∈ (0, 1 − p0(1 − σM)).Here p0 characterizes the random-loss process and σM the malicious-loss process under the proposition’s assumptions.
- Random and malicious losses: For dependent attacks and random losses, Proposition 4.5 gives σ ∈ (0, max{1 − p0, σM}), a smaller range reflecting worst-case temporal overlap.When attacks avoid random losses, Proposition 4.6 instead gives σ ∈ (0, 1 − p0 + σM) when 1 − p0 + σM ≤ 1.
- Design implication: If σ is statistically large, controller gain and event-triggering parameters should be redesigned to preserve stability.The paper points to Theorem 3.5 and Corollary 3.8 for redesign conditions.
V. NUMERICAL EXAMPLES
The numerical examples illustrate stabilization under random and malicious packet losses, and show how attack frequency and selectivity can instead produce instability. They also demonstrate that redesigning the feedback gain can restore almost sure asymptotic stability.
- Example 1: 250 sample trajectories converge to the origin under the event-triggered controller, while the Lyapunov-like function converges to zero without being monotonically decreasing.The function can increase after failed packet exchanges, but triggering occurs before it leaves the prescribed bound.
- Example 1: The Markov-chain random-loss model and selected controller parameters satisfy the sufficient conditions for almost sure asymptotic stabilization.The construction uses β = 0.55, ϕ = 2.4516, and ρ = 0.4.
- Example 2: Independent attacks: With τ = 3, the independent attacker blocks one packet exchange every three steps, yet the closed-loop system remains stable.The analysis uses ρM = 0.3334 and establishes almost sure asymptotic stabilization with K = −1.75.
- Example 2: Independent attacks: With τ = 2, blocking every other exchange makes the closed-loop system unstable and raises the long-run packet-failure average to at least σ = 0.68.This contrasts with the stable τ = 3 case, where the corresponding upper bound is ρ = 0.62.
- Example 2: Selective attacks: At τ = 3, the selective attack destabilizes the system even though the independent strategy with the same period cannot.The selective attacker uses random-loss information and avoids attacking when random packet loss has already occurred; simulations report σ = 0.7.
- Example 2: Selective attacks: The extended selective strategy keeps the state near ln V (x(t)) = ζ rather than allowing divergence, while the long-run packet-failure average approaches 2/3.The reported simulation uses ζ = 50 and τ = 3.
3. We remark that 2
The example identifies thresholds separating convergence from divergence and shows that feedback redesign can restore stability under the selective attack.
- Threshold conditions: ρ < 2/3 implies convergence of the state, whereas σ > 2/3 implies divergence under the stated conditions.The two inequalities are used as stability and instability thresholds in the example.
- Feedback redesign: Redesigning the feedback gain to K = −1.9 reensures almost sure asymptotic stability with β = 0.01.The result applies to the selective attack and its extension despite their dependence on random packet losses.
VI. CONCLUSION
The paper characterizes networked control with random and malicious packet losses, deriving stabilization conditions and attacker-side destabilization conditions. It also positions the framework for output-feedback control and future wireless-network settings.
- The study addresses linear-system control over networks subject to random packet losses and malicious attacks.
- The authors obtain sufficient conditions for almost sure asymptotic stabilization and a method for selecting stabilizing feedback and event-trigger parameters.
- The attacker perspective yields conditions under which combined random and malicious packet losses destabilize the closed-loop system.
- The probabilistic characterization has also been used to model packet losses in output-feedback control between plant sensors and the controller-side estimator.
- Future work considers wireless networks with multiple communication nodes and routers, including potentially compromised components, as well as system and measurement noise.
APPENDIX
The appendix establishes tail-probability bounds for sums involving binary-valued Markov chains and related binary processes. It uses induction, conditional expectations, and Markov/Chernoff-type arguments to obtain a summable bound.
- Lemma A.1 considers a time-inhomogeneous binary-valued Markov chain and an independent binary-valued process under stated transition and parameter assumptions.
- Markov’s inequality and the Chernoff construction bound tail probabilities for sums involving products of dependent Markov-chain states and binary-process values.
- Lemma A.2 supplies an auxiliary bound for an adapted binary-valued Markov chain at ordered indices.
- The proof establishes the target inequality first for s = 1 and s = 2, then extends it inductively from s = ˜s to s = ˜s + 1.
- Conditional Markov-chain expectations and the chain property are used to derive the intermediate inequalities required by the induction.
- The resulting bounds are shown to hold across the relevant k values, and the associated series is established as convergent using geometric-series arguments.