Source-linked AI summary
Data-Injection Attacks in Stochastic Control Systems: Detectability and Performance Tradeoffs
Cheng-Zong Bai, Fabio Pasqualetti, Vijay Gupta
TL;DR
Malicious control-channel injections create a tradeoff between attack-induced degradation and detectability, while prior stochastic-system analyses often depend on specific detectors. The paper defines detector-independent ε-stealthiness, bounds Kalman-filter degradation, and characterizes optimal attacks, achieving the bound for right-invertible systems and a lower bound for non-right-invertible systems.
Problem
Stochastic attack detectability and the stealthiness–performance tradeoff remain incompletely characterized because existing analyses often rely on specific detectors or systems.
Method
The paper uses detector-independent ε-stealthiness and information-theoretic analysis to bound and construct attacks that degrade Kalman-filter estimation.
Results
The analysis characterizes the largest degradation from an ε-stealthy attack, achieves the upper bound for right-invertible systems, and lower-bounds achievability for non-right-invertible systems.
Takeaways & Limitations
For right-invertible systems, the nominal control input is the only critical information needed to induce the largest performance degradation.
Takeaways & Limitations
The analysis assumes steady-state Kalman filtering and focuses on actuation-channel attacks, with measurement-channel extensions treated separately.
Abstract
from arXiv · showhide
Consider a stochastic process being controlled across a communication channel. The control signal that is transmitted across the control channel can be replaced by a malicious attacker. The controller is allowed to implement any arbitrary detection algorithm to detect if an attacker is present. This work characterizes some fundamental limitations of when such an attack can be detected, and quantifies the performance degradation that an attacker that seeks to be undetected or stealthy can introduce.
1 Introduction
The paper studies how malicious control-channel injections can evade detection while degrading cyber-physical-system performance. It introduces a detector-independent stealthiness notion and characterizes degradation limits and achievable attacks in stochastic systems.
- Scope: The paper extends a preliminary conference version to multiple-input, multiple-output systems, fuller proofs, and additional insight into optimal stealthy-attack design.The preliminary version appeared in Bai et al. (2015).
- Motivation: Attack detectability in stochastic systems remains open because prior tradeoff analyses generally assume specific detectors or systems.The paper targets fundamental limitations that arbitrary controller detection tests cannot capture under detector-specific analyses.
- Scope: The analysis is limited to linear time-invariant plants, asymptotic Kalman-filter-based controllers, and attacks against the actuation channel.The paper notes that measurement-channel attacks receive more attention and that the framework can be extended to them in related work.
- Contributions: The paper proposes ε-stealthiness as a universal, information-theoretic measure of attack detectability independent of the controller’s detection mechanism.The metric is motivated by the Chernoff-Stein Lemma.
- Contributions: It bounds degradation of the minimum-mean-square estimation error caused by ε-stealthy attacks using system parameters, noise statistics, and attacker information.The analysis concerns stochastic cyber-physical systems with malicious control-channel injections.
- Contributions: For right-invertible systems, the paper characterizes optimal stealthy attacks and gives a closed-form expression for optimal ε-stealthy attacks.For non-right-invertible systems, it proposes a sub-optimal attack with an analytical degradation expression.
2 Problem Formulation
The problem formulation models an LTI stochastic process whose actuation input can be replaced by an informed attacker. Stealthiness is defined through sequential hypothesis testing while performance is measured by corrupted Kalman-filter estimation.
- System model: The process is modeled as a linear time-invariant state-space system with Gaussian process and measurement noise.The state, control input, and sensor output are represented by x_k, u_k, and y_k, respectively.
- System model: The controller uses a Kalman filter for minimum-mean-squared-error state estimation, with steady-state covariance P and gain K.The steady-state assumption follows convergence to the unique solution of a discrete-time algebraic Riccati equation.
- Attack model: The attacker replaces the nominal control sequence with an arbitrary sequence, knows system parameters and control inputs, and does not know noise vectors.The attacker has perfect memory and causal information independent of future process noise.
- Stealthiness: Detection is posed as sequential hypothesis testing between no attack and attack using false-alarm and correct-detection probabilities.Stealthiness compares arbitrary detectors with a detector that ignores measurements and randomly guesses between the hypotheses.
- Performance metric: The performance objective is the worst degradation an unaware controller experiences when its Kalman filter processes corrupted measurements.Under attack, the resulting estimate is sub-optimal because the filter assumes the nominal control input, and the attacked innovation need not be zero mean, white, or Gaussian.
3 Stealthiness in Stochastic systems
The paper formalizes stochastic attack stealthiness through the Kullback-Leibler divergence between nominal and attacked observation sequences. It then relates stealthiness loss to temporal dependence and marginal innovation deviations.
- Stealthiness criterion: The first result gives conditions for verifying whether an attack is strictly stealthy or ε-stealthy.The characterization is stated in terms of the Kullback-Leibler divergence of the corresponding observation sequences.
- Reference process: The nominal innovation sequence is i.i.d. Gaussian with covariance Σ_z, providing the reference distribution for the stealthiness analysis.The attacked innovation sequence is compared against this nominal behavior.
- Interpretation: For an ergodic attacker, stealthiness can degrade when attacked innovations become autocorrelated or their marginals deviate from N(0, Σ_z).The two effects correspond respectively to temporal dependence and changes in the marginal innovation distributions.
- Interpretation: The Kullback-Leibler divergence measures dissimilarity between probability distributions, while mutual information measures how much information past attacked innovations provide about later ones.These quantities expose distributional and memory-based departures from nominal innovations.
4 Fundamental Performance Limitations
The paper bounds the degradation an ϵ-stealthy attacker can induce and establishes when that bound is achievable. Strict stealth prevents degradation, while the bound grows with the allowed stealthiness level.
- Converse: Theorem 7 gives an upper bound on weighted mean-square error degradation for any ϵ-stealthy attack.The bound depends on system and noise parameters through the function ¯δ and the no-attacker weighted MSE.
- Converse: The upper bound increases monotonically with ϵ, quantifying a trade-off between attack stealthiness and induced error.As ϵ →∞, the bound increases linearly.
- Converse: A strictly stealthy attacker cannot induce any performance degradation.Strict stealthiness corresponds to ϵ = 0.
- Achievability for Right Invertible Systems: For right-invertible systems, attack A1 achieves the converse bound and is ϵ-stealthy.Its controller-side innovation sequence is i.i.d. Gaussian, enabling equality in the performance bound.
- Attacker Information Pattern: The optimal attack requires the nominal control input as its only critical information piece.The result does not require the attacker to have extensive state-variable information.
- Achievability for Non-Right-Invertible Systems: When the system is not right invertible, the converse bound may not be achievable; attack A2 instead provides a lower bound.A2 is constructed heuristically for this setting.
Step 1 (Limiting the memory of the innovation sequence
Attack A2 is designed in stages to suppress innovation-memory effects, shape the induced covariance, and then select its stealthiness level.
- Step 1: The feedback matrix L is selected to eliminate memory in the controller’s innovation sequence by targeting A − KC − BL = 0.When exact cancellation is unavailable, the paper proposes a cheap LQG-based heuristic.
- Step 2: The covariance matrix Σζ is chosen so that CΣ˜eC^T is close to a scalar multiple of Σz.Σ˜e is determined through a Lyapunov equation and pseudoinverse-based construction.
- Step 2: If the covariance construction is indefinite, negative eigenvalues are set to zero to obtain a positive semidefinite Σζ.If B and C are invertible, the covariance can instead be set directly to satisfy CΣ˜eC^T = α^2Σz.
- Step 3: The parameter α is selected using an explicit stealthiness expression for attack A2.The resulting α determines the desired ϵ-stealthiness level and induced estimation error.
5 Numerical Results
The numerical examples compare the fundamental performance-degradation bound with achievable attacks for right-invertible and non-right-invertible systems. The bound is achieved in the right-invertible case but remains separated from the heuristic attack in the non-right-invertible case.
- Right-invertible system: The right-invertible example plots the upper bound on weighted MSE degradation against the attacker’s stealthiness level ϵ.The example uses Σw = 0.5I and Σv = I.
- Right-invertible system: The upper bound is achievable by a suitably designed ϵ-stealthy attack, making it a fundamental limitation for such attacks.This follows from Theorem 14.
- Right-invertible system: The plotted degradation is approximately linear as ϵ becomes large, as predicted by Corollary 10.
- Non-right-invertible system: The non-right-invertible example compares the Theorem 7 upper bound with weighted MSE degradation achieved by heuristic attack A2.This example also uses Σw = 0.5I and Σv = I.
- Non-right-invertible system: A gap remains between the upper bound and the performance degradation achieved by heuristic attack A2, although the bound is fairly tight.
6 Conclusion
The paper characterizes limits and achievability for degradation caused by stealthy attackers in stochastic control systems. It gives tight results for right-invertible systems and lower-bound achievability results for systems that are not right invertible.
- The paper quantifies attack detectability through ϵ-stealthiness and characterizes the largest degradation of Kalman filtering induced by an ϵ-stealthy attack.
- For right-invertible systems, the nominal control input is the only critical information needed to induce the largest performance degradation.
- For the right non-invertible system, the converse and achievability are represented using the weighted MSE ˜PW induced by heuristic algorithm A2.
- For systems that are not right invertible, the paper provides an achievability result that lower bounds the degradation attainable by an optimal ϵ-stealthy attack.
A Proof of Theorem 1
The proof establishes stealthiness properties by combining hypothesis-testing bounds with Chernoff–Stein analysis and contradiction arguments. It concludes that violating the stated condition makes an attack detectable, while the constructed sequence is ϵ-stealthy.
- The first statement follows directly from the Neyman–Pearson Lemma.
- Chernoff–Stein analysis gives the best achievable false-alarm decay exponent for ergodic measurements under a fixed attack sequence.
- The proof obtains detector performance bounds for the attack sequence and uses them to establish ϵ-stealthiness by Definition 1.
- A contradiction argument applies a log-likelihood ratio test and shows that violating condition (8) prevents the attack from being stealthy.
- Chernoff’s inequality, Jensen’s inequality, and intermediate algebraic bounds are used in deriving the required condition.
B Proof of Lemma 4
The proof bounds the relevant information quantity using differential-entropy inequalities and identifies equality conditions. Equality requires Gaussian, independent innovation-related variables with a covariance proportional to Σz.
- The Kullback–Leibler divergence is rewritten in an equivalent form as the starting point of the bound.
- The innovation sequence without an attack is an independent and identically distributed Gaussian sequence with mean zero.
- Sub-additivity of differential entropy and the maximum differential entropy lemma upper-bound the entropy term for multivariate variables.
- Equality requires the relevant sequence to be independent, with each variable Gaussian distributed with mean zero.
- The covariance equality condition requires E[˜zn˜zT_n] = αΣz for some scalar α, together with the stated trace condition.