Source-linked AI summary

Dynamic Watermarking: Active Defense of Networked Cyber-Physical Systems

Bharadwaj Satchidanandan, P. R. Kumar

arXiv:1606.08741v1eess.SYmath.DS

TL;DR

The paper addresses how to secure networked cyber-physical systems when sensors or actuators interfacing with the plant may be malicious. It proposes dynamic watermarking, in which actuators inject private excitations whose effects reveal tampering; under appropriate conditions, undetected malicious distortion has mean-square zero.

  • Problem

    Networked CPS security must address malicious sensors and actuators at the physical layer, not only attacks on the communication network.

  • Method

    Actuators inject private, independently drawn excitation signals into control inputs and test whether sensor reports exhibit the expected transformed correlations.

  • Results

    Under appropriate conditions, malicious sensors that remain undetected can add only zero average-power distortion, including when all sensors are malicious and actuators have no direct measurements.

  • Takeaways & Limitations

    Dynamic watermarking provides an active-defense procedure for tracing signal tampering and detecting malicious sensor behavior in networked control systems.

Abstract

from arXiv · show

The coming decades may see the large scale deployment of networked cyber-physical systems to address global needs in areas such as energy, water, healthcare, and transportation. However, as recent events have shown, such systems are vulnerable to cyber attacks. Being safety critical, their disruption or misbehavior can cause economic losses or injuries and loss of life. It is therefore important to secure such networked cyber-physical systems against attacks. In the absence of credible security guarantees, there will be resistance to the proliferation of cyber-physical systems, which are much needed to meet global needs in critical infrastructures and services. This paper addresses the problem of secure control of networked cyber-physical systems. This problem is different from the problem of securing the communication network, since cyber-physical systems at their very essence need sensors and actuators that interface with the physical plant, and malicious agents may tamper with sensors or actuators, as recent attacks have shown. We consider physical plants that are being controlled by multiple actuators and sensors communicating over a network, where some sensors could be "malicious," meaning that they may not report the measurements that they observe. We address a general technique by which the actuators can detect the actions of malicious sensors in the system, and disable closed-loop control based on their information. This technique, called "watermarking," employs the technique of actuators injecting private excitation into the system which will reveal malicious tampering with signals. We show how such an active defense can be used to secure networked systems of sensors and actuators.

I. INTRODUCTION

Networked cyber-physical systems integrate communication, computation, control, and physical interaction, but attacks can disrupt safety-critical operations. The paper targets physical-layer security by using private actuator excitations to expose malicious sensor behavior.

  • Motivation: Cyber-physical systems connect embedded devices that communicate with one another while interacting with the physical world.Examples include smart energy grids, intelligent transportation, telesurgical systems, and robotics.
  • Motivation: Because CPS applications can be safety-critical, security breaches may cause economic loss, injury, or death.
  • Problem: Securing a CPS requires protecting both its communication network and the sensors and actuators that interface with the physical plant.The paper focuses on the latter problem.
  • Problem: Physical-layer security is difficult because any authorized party interfacing with the plant can also be a potential adversary.
  • Approach: Actuators can inject undisclosed probing signals and use expected plant responses to infer whether sensor reports are malicious.
  • Contribution: Dynamic watermarking uses private excitation to detect malicious tampering and can limit undetected additional distortion to mean-square zero under appropriate conditions.The approach is presented as active defense for networked systems of sensors and actuators.

II. PRIOR WORK

Prior secure-control research addresses adversary models, unreliable observations, malicious sensors, replay attacks, and other defenses. The paper distinguishes its approach as active defense because it deliberately injects signals rather than only limiting damage from anticipated attacks.

  • Secure control: Earlier work defined secure-control goals such as closed-loop stability and acceptable performance degradation under attack.
  • Attack models: Communication-layer threats include denial-of-service attacks that block useful data and deception attacks that cause incorrect actuation signals.
  • Unreliable observations: Research on intermittent observations develops estimation and control methods for packet drops caused by network conditions or adversaries.
  • Existing defenses: Other techniques recover state estimates with malicious sensors or counter replay attacks by injecting actuation components unknown in advance.
  • Novelty: The paper classifies estimation, suspicious-measurement filtering, and fault-tolerant methods as passive techniques that minimize damage from malicious signals.

III. PROBLEM FORMULATION

The problem formulation models a networked CPS as a stochastic linear plant with communicating actuators, controllers, and sensors, some of which may be malicious. The objective is to protect regulation performance while detecting or limiting malicious behavior.

  • System model: The system contains a physical plant with m inputs and n outputs, independently controlled by actuators and measured by sensors.
  • System model: Controllers compute actuation signals from sensor measurements and communicate them to actuators over a complete network.Nodes are assumed to have communication and computational capabilities, allowing controllers to be collocated with actuators.
  • Adversary model: Malicious sensors may report distorted measurements, while malicious nodes may collude and honest nodes do not know which nodes are malicious.
  • Assumptions: The cyber layer is assumed secure and reliable, with authenticated, tamper-detecting, delay-guaranteed communication between node pairs.
  • Plant model: The plant is modeled as a time-invariant stochastic linear dynamical system to enable tractable analysis and transferable design insights.The state equation is x[t + 1] = Ax[t] + Bu[t] + w[t + 1].
  • Objective: The security objective is to prevent malicious nodes from causing excessive distortion while remaining undetected, with detection enabling disconnection and restored stable behavior in specified settings.Fundamental limits on undetected distortion apply to stable and unstable systems.

IV. DYNAMIC WATERMARKING: AN ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS

Dynamic watermarking actively defends a networked CPS by adding private actuator excitations whose realizations are undisclosed to other nodes. These excitations create traceable signal correlations that expose sensor tampering and restrict undetected distortion.

  • Watermark construction: Each actuator adds an independently drawn private excitation to its control-policy input, while the excitation distribution is public but its realization remains secret.The applied input is u_i[t] + e_i[t].
  • Why watermarking: Without private excitation, a malicious sensor can simulate the stochastic system using reported measurements and plausible process noise.
  • Detection mechanism: Private excitation forces sensor reports to correlate with the actuator’s secret sequence, making undetected distortion essentially zero in mean-square terms.
  • Interpretation: Dynamic watermarking parallels digital watermarking because altering the hidden process component also alters the embedded signal and reveals tampering.
  • Distortion measure: The paper defines a distortion sequence whose interpretation is the additive disturbance introduced by malicious sensors into process noise or, for partial observations, innovations.
  • Guarantee: The fundamental guarantee is that malicious sensors’ additive distortion power is zero when they remain undetected across several linear control-system settings.

V. ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS: THE SISO CASE WITH GAUSSIAN NOISE

The SISO Gaussian case uses private actuator excitation and statistical tests to detect sensor manipulation. Undetected manipulation has zero mean-square distortion and cannot degrade closed-loop mean-square performance under the stated stability condition.

  • Model and defense: The actuator adds private i.i.d. excitation to the control input while applying the intended policy to sensor-reported measurements.The resulting closed-loop evolution includes both the private excitation and process noise.
  • Detection tests: The actuator tests whether reported measurements satisfy variance conditions implied by honest sensing, with finite-window statistical versions possible.The paper introduces two asymptotic tests based on the true output’s statistical properties.
  • Detection guarantee: A malicious sensor that passes both tests can remain undetected only with zero additive distortion power.The theorem characterizes undetectable reporting through the sensor-added distortion sequence.
  • Detection guarantee: The actuator can compute the combined process-noise and distortion sequence, while private excitation forces malicious reports to remain correlated with the hidden excitation.This constraint drives the undetected distortion to zero in the mean-square sense.
  • Performance guarantee: The private excitation variance can be reduced to support detection within a specified delay and an acceptable false-alarm probability.This provides a practical tuning condition for the active defense.
  • Performance guarantee: If |a| < 1, an undetected malicious sensor cannot change the system’s mean-square performance from the reported performance.Under a stabilizing control law, the achieved performance remains the designed value, apart from the private excitation’s cost.

VI. ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS: THE SISO ARX CASE

The watermarking defense extends from the SISO Gaussian model to strictly minimum-phase ARX systems. Pre-equalization makes the plant’s private-excitation component i.i.d., preserving the testing and performance guarantees.

  • ARX model: The ARX extension addresses strictly minimum-phase SISO systems whose outputs depend on past inputs and private excitations.The model is represented using polynomial dynamics and a unit delay.
  • ARX model: Because past private excitations affect later outputs, directly injecting i.i.d. noise would not produce an i.i.d. output component.The temporal dependence distinguishes ARX systems from the simpler SISO model.
  • Pre-equalization: The actuator uses a pre-equalizer that filters private excitation using known past excitations and the plant transfer function.The effective input includes the pre-equalizer output together with the reported-measurement sequence.
  • Pre-equalization: The filtered plant-output component becomes i.i.d. Gaussian with mean 0 and variance b2_0σ2_e.Strict minimum phase ensures stable generation of this excitation sequence.
  • ARX guarantees: The ARX actuator performs two honesty tests, and the paper extends the earlier detection and performance theorems to these tests.Theorem 3 defines the ARX distortion sequence and states the corresponding guarantees.
  • ARX guarantees: If an ARX malicious sensor remains undetected, the actual mean-square output performance equals the performance believed by the actuator.Thus, a control law designed for a specified mean-square performance attains that value.

VII. ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS: THE SISO ARMAX CASE

For Gaussian ARMAX systems with finite delay, Dynamic Watermarking matches private-excitation and process-noise spectra, enabling actuator tests that constrain undetected sensor distortion to zero power.

  • Watermarking design: The actuator injects private excitation whose spectrum matches the colored process noise in the ARMAX system.The excitation is incorporated into the control input while remaining undisclosed in realization to other nodes.
  • Actuator tests: The actuator filters reported measurements and tests whether their prediction-error sequence has the appropriate statistics.The proposed tests are constructed so honest measurements produce zero distortion and can be checked by the actuator.
  • Guarantee: A malicious sensor that passes the tests can introduce no distortion beyond a zero-power signal added to the process noise.The theorem applies to the general ARMAX model with arbitrary but finite delay.
  • Guarantee: The filtered distortion measure behaves like the white-noise case, and minimum-phase C(q^-1) transfers the conclusion to the original distortion sequence.The proof relies on the minimum-phase property of C(q^-1).

VIII. ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS: SISO SYSTEMS WITH PARTIAL OBSERVATIONS

For partially observed SISO systems, actuators apply private excitation and use Kalman-filter-based tests on reported measurements to detect malicious sensor behavior.

  • System and excitation: The section models a pth-order SISO system with state dynamics, noisy measurements, and measurements z[t] that may differ from the true output y[t].The actuator has known system matrices and applies a control-policy input plus private Gaussian excitation.
  • Actuator tests: The actuator runs a Kalman filter on reported measurements and computes faulty innovations from the reported sequence.The corresponding filter on true measurements is unavailable to the actuator because it may not receive y[k].
  • Actuator tests: For an honest sensor, reported and true innovations coincide, making the actuator’s distortion sequence identically zero.The actuator then applies two tests to detect maliciousness.
  • Guarantee: Under observability and the stated test conditions, a malicious sensor can remain undetected only with zero additive distortion power.This is the guarantee stated by Theorem 5.

IX. ACTIVE DEFENSE FOR NETWORKED CYBER-PHYSICAL SYSTEMS: MIMO SYSTEMS WITH GAUSSIAN NOISE

For MIMO linear systems with Gaussian noise, actuators use private excitation and two admissible tests to prevent malicious sensors from remaining undetected while introducing excessive distortion.

  • MIMO setting: MIMO systems add collusion challenges because malicious sensors may coordinate to prevent other nodes from detecting them.The section considers linear stochastic systems with Gaussian process noise and perfectly observed state.
  • Watermarking design: Each honest actuator superimposes undisclosed, independent private excitation on the control-policy input while publicly specifying its distribution.The actual excitation values remain hidden from other nodes.
  • Actuator tests: Each actuator checks reported measurements using two tests that are observable to the participating nodes and satisfied when all parties are honest.The second test directly checks the quantity important for the distortion guarantee.
  • Guarantee: Malicious sensors that pass the tests can remain undetected only with zero additive distortion power, assuming B has rank n.The result prevents undetected sensors from introducing excessive distortion under the stated rank condition.

X. EXTENSION TO NON-GAUSSIAN SYSTEMS

The Gaussian process-noise assumption is relaxed for SISO systems by matching private-excitation output to process-noise statistics and adapting actuator tests.

  • Scope: The non-Gaussian extension considers a SISO system whose process noise need not be Gaussian.The section illustrates how the earlier assumption can be relaxed to a certain extent.
  • Watermarking design: The actuator chooses private excitation so its output has the same distribution as the process noise.The system evolves with the control-policy input, private excitation, and process noise.
  • Actuator tests: The actuator tests whether the reported measurement sequence satisfies the required conditions, with honest reporting yielding zero residual distortion.The tests are adapted to the non-Gaussian setting.
  • Guarantee: The generalized result states that only a malicious sensor with zero effective power can remain undetected.The theorem extends the earlier guarantee to the considered non-Gaussian setting.
  • Cost and trade-off: Matching private-excitation noise to process noise amplifies the process-noise standard deviation by 2, whereas Gaussian systems can make the extra cost arbitrarily small.The Gaussian reduction trades smaller extra cost against delayed detection for an acceptable false-alarm probability.

XI. STATISTICAL TESTS FOR ACTIVE DEFENSE

The paper develops finite-time statistical tests for detecting malicious activity from dynamic-watermarking signals while controlling false alarms. A likelihood-based sequential procedure raises an alarm when recent observations become inconsistent with the no-attack model.

  • Statistical test design: Asymptotic detection characterizations support finite-time statistical tests with acceptable false alarm rates.These tests translate asymptotic results into procedures that can reveal malicious activity within a finite period.
  • Statistical test design: Because no distribution is specified for attack observations, the procedure rejects the no-attack hypothesis or continues observing rather than comparing two fully specified hypotheses.The null hypothesis is that the control system is not under attack; a sleeper adversary also prevents accepting that null forever.
  • Statistical test design: The proposed test differs from the classical sequential probability ratio test, which compares a likelihood ratio with two thresholds and accepts either the null or alternative hypothesis.Here, the alternative attack distribution is unavailable, so a likelihood ratio against a specified alternative cannot be defined.
  • Statistical test design: Under the null, the sample covariance follows a Wishart distribution, enabling a threshold τ(α) for the likelihood of the l most recent observations at false alarm rate α.An alarm is raised whenever the likelihood exceeds the threshold; otherwise testing continues at the next time instant.
  • Simulation example: At attack epoch 4500, the windowed negative log likelihood steadily increases after remaining within limits beforehand, indicating attack onset.The detection threshold can be selected according to tolerable false alarm rates.

XII. CONCLUSION

The paper concludes that dynamic watermarking secures networked cyber-physical systems by tracing private excitation through the control loop to detect malicious sensor behavior. The authors note that broader plant classes and finite-time test performance remain open areas for study.

  • XII. CONCLUSION: Dynamic watermarking imposes private excitation on actuation signals and traces its presence around the loop to detect malicious sensor behavior.The procedure addresses security of networked cyber-physical systems rather than communication networks alone.
  • XII. CONCLUSION: The procedure has been explored only in an initial range of contexts, although it may apply to more general plants such as process-control systems.The conclusion specifically identifies nonlinear models as a possible broader setting.
  • XII. CONCLUSION: Further study of finite-time tests for dynamic watermarking would be practically useful.The paper distinguishes these finite-time tests from the asymptotic characterizations developed earlier.
  • XII. CONCLUSION: The authors identify substantial remaining work before cyber-physical-system applications can proliferate for critical infrastructural and societal needs.This conclusion is framed as an ongoing research need rather than a completed deployment result.

ADDENDUM

The addendum defines the paper’s notation for scalars, vectors, matrices, and indexed components or submatrices. It also specifies deletion notation for rows, columns, and vector components.

  • Notation: Scalars use lowercase symbols, vectors use lowercase boldface, and matrices use uppercase symbols.These conventions establish the basic visual distinction among scalar, vector, and matrix quantities.
  • Notation: The notation x_i denotes the ith component of vector x, while A·i and A_i· denote the ith column and ith row of matrix A.Subscripts and centered dots distinguish vector components from matrix columns and rows.
  • Notation: A_i:j,p:q denotes the submatrix formed by rows i through j and columns p through q.The notation selects a contiguous rectangular block of matrix A.
  • Notation: A·(−i), A(−i)·, and x−i denote matrix A with column i removed, matrix A with row i removed, and vector x with component i removed.The superscript-like minus notation indicates deletion of the specified indexed element or line.
Loading 1606.08741v1…