Source-linked AI summary

The Vulnerability of Cyber-Physical System under Stealthy Attacks

Tianju Sui, Yilin Mo, Damián Marelli, Ximing Sun, Minyue Fu

arXiv:2002.01557v1eess.SY

TL;DR

The paper asks when stealthy sensor or actuator attacks can destabilize stochastic linear CPSs while remaining difficult or impossible to detect. It characterizes these conditions and bounds attack-induced performance differences for invulnerable systems, with simulations illustrating the criteria.

  • Problem

    The paper addresses how malicious input or output injections in stochastic linear CPSs can evade detection and destabilize the system.

  • Method

    The paper defines stealthy and strictly stealthy attacks, analyzes vulnerability and strict vulnerability, and derives conditions and a performance bound using a stochastic linear CPS model.

  • Results

    Necessary and sufficient conditions characterize vulnerability and strict vulnerability, while invulnerable systems receive a bound on the difference between healthy and attacked behavior.

  • Takeaways & Limitations

    The criteria identify vulnerable sensor or actuator channels, and the performance bound helps designers evaluate attack-induced damage.

Abstract

from arXiv · show

In this paper, we study the impact of stealthy attacks on the Cyber-Physical System (CPS) modeled as a stochastic linear system. An attack is characterised by a malicious injection into the system through input, output or both, and it is called stealthy (resp.~strictly stealthy) if it produces bounded changes (resp.~no changes) in the detection residue. Correspondingly, a CPS is called vulnerable (resp.~strictly vulnerable) if it can be destabilized by a stealthy attack (resp.~strictly stealthy attack). We provide necessary and sufficient conditions for the vulnerability and strictly vulnerability. For the invulnerable case, we also provide a performance bound for the difference between healthy and attacked system. Numerical examples are provided to illustrate the theoretical results.

I. INTRODUCTION

The paper examines how deliberately stealthy cyber attacks threaten stochastic linear CPSs, where malicious input or output injections can evade conventional detection. It develops vulnerability criteria and performance guarantees to characterize when such attacks destabilize systems.

  • Stealthy CPS attacks can inject malicious signals through system inputs, outputs, or both, increasing vulnerability in networked physical applications.
  • Traditional robust control and fault detection are insufficient because CPS attacks can be purposefully stealthy, destructive, and informed by system dynamics.
  • The paper studies stochastic linear systems under sensor and actuator attacks, distinguishing bounded-residue stealthy attacks from zero-residue strictly stealthy attacks.
  • It provides necessary and sufficient conditions for vulnerability and strict vulnerability, identifying when stealthy attacks can destabilize the system.
  • For invulnerable systems, the paper gives a universal performance bound to evaluate the difference between healthy and attacked behavior.

A. System Model

The CPS is modeled as a linear discrete-time stochastic state-space system with state feedback and a Luenberger estimator. Stability constraints are imposed on the controller and estimator dynamics.

  • The system uses a linear discrete-time stochastic state-space model with state, measurement, control input, process noise, and measurement noise.
  • The system matrix pair (A, C) is assumed observable, while (A, B) is assumed controllable.
  • A steady-state state-feedback controller uses the estimated state, with L selected so that A + BL is stable.
  • A linear time-invariant Luenberger estimator is deployed, with K selected so that A − KCA is stable.
  • The innovation signal is defined as part of the estimation and detection model.

B. Attack Model

The attack model allows an adversary to inject external control inputs and manipulate selected sensor measurements. Differences between attacked and healthy trajectories connect detectability to attack damage.

  • The adversary can inject an external control input and manipulate a subset of sensory data.
  • The model represents actuator attacks through an attack matrix and sensor attacks through selected compromised measurement channels.
  • Attack signals are constrained only by the stealthy or strictly stealthy requirements introduced later.
  • The attacker is assumed to know the full system model, representing a worst-case attack scenario.
  • Differences in innovation and measurement signals characterize detectability, while state and estimation-error differences quantify attack damage.

III. CLASSIFICATIONS FOR SYSTEMS AND ATTACKS

The paper classifies attacks by their effect on detection residues and systems by whether such attacks can produce unbounded state or estimation errors. It then links resilience to bounded estimation-error differences.

  • A stealthy attack has bounded residue influence, whereas a strictly stealthy attack produces no residue change.
  • The difference dynamics depend only on attack signals, enabling analysis of stealthiness and system damage independently of the healthy trajectory.
  • Resilience is equivalent to bounded state deviation, because stable controller dynamics make bounded estimation-error and state differences equivalent.
  • A system is vulnerable or strictly vulnerable when a corresponding stealthy or strictly stealthy attack can produce arbitrarily large instability effects.
  • Strict invulnerability means stability under attacks with no residue influence, while invulnerability covers attacks with bounded residue influence.

IV. THE NECESSARY AND SUFFICIENT CONDITION FOR STRICT VULNERABILITY

Strict vulnerability is characterized by non-invertibility of an associated linear system, which permits a strictly stealthy attack to destabilize the system while leaving the residue unchanged.

  • Verification: Invertibility can be checked using rank conditions for a finite-dimensional linear system.The rank test is stated for the system in Proposition 1, with n denoting the state dimension.
  • Strict vulnerability condition: The system is strictly vulnerable if and only if the associated system is not invertible.Non-invertibility means a nonzero input can produce zero output for all time.
  • Strict vulnerability condition: A strictly stealthy attack can make the state unbounded while the detection-residue change remains zero.The result follows from an input sequence producing zero output in the associated system.
  • Equivalent criterion: The strict-vulnerability test can be simplified to checking non-invertibility of an equivalent system.The equivalence is established by the corollary and its proof.

V. THE NECESSARY AND SUFFICIENT CONDITION FOR VULNERABILITY

Vulnerability occurs exactly when an unstable, reachable system direction can remain hidden through the attack channels; the paper expresses this using an unstable reachable zero-dynamic.

  • Zero-dynamic interpretation: An unstable reachable zero-dynamic combines bounded output, an unstable state direction, and reachability of that direction.These three properties respectively hide the attack, drive state divergence, and make the direction attainable.
  • Vulnerability condition: The system is vulnerable if and only if there exist v and Q satisfying instability, attack-output alignment, and reachability conditions.The conditions require an unstable eigenvector of A + BaQ, Cv in span(Γa), and reachability for the attacked closed-loop dynamics.
  • Sufficiency: The sufficient conditions produce a stealthy input that destabilizes the system.The proof links the three conditions to the existence of a destabilizing stealthy attack.
  • Scaling property: The stealthy bound δ does not affect vulnerability because attack scaling can reduce residue changes while preserving state divergence.This scaling property follows from linearity.
  • Scope of structural checks: Structural information can check the output-nulling invariant-subspace condition, but not the remaining instability and reachability conditions.Therefore, structural information supplies a necessary condition rather than a complete vulnerability test.

VI. A PERFORMANCE BOUND FOR INVULNERABLE SYSTEM

For an invulnerable system, the paper derives a bound on the difference between healthy and attacked states under stealthy attacks, using the bounded residue change as an input to the bound.

  • Performance guarantee: Invulnerability implies that the bias between healthy and attacked systems is bounded under stealthy attacks.The performance-bound section focuses on bounding Δe when the vulnerability condition is not satisfied.
  • Performance guarantee: The bound depends on the stealthy residue limit δ.Here δ is the bound specified in the stealthy-attack definition.
  • Bound mechanism: The transfer function T(z)S†(z) can be viewed as mapping residue differences to state-estimation differences.This interpretation explains how bounded residue changes enter the performance analysis.
  • Bound mechanism: The state difference is bounded by combining the estimation-error bound with the bound on the remaining state component.The paper explicitly uses ∥Δx_t∥2 ≤ ∥Δx̂_t∥2 + ∥Δe_t∥2.

VII. SIMULATION

Simulations verify the theoretical vulnerability criteria and show that the universal performance bound remains effective for invulnerable systems, including a Tennessee Eastman Process model.

  • The strict-vulnerability simulation destabilizes the system while keeping the residue bias zero, confirming the strict vulnerability criterion.
  • The vulnerability-only simulation makes estimation error bias diverge while keeping residual bias bounded, confirming vulnerability without strict vulnerability.
  • For the double-integrator example, the estimation error bias remains bounded under all stealthy attacks, and the universal bound is tight and effective.
  • The Tennessee Eastman Process simulation projects its 8-dimensional reachable set onto two plant dimensions and finds the universal bound effective.

VIII. CONCLUSION

The supplied conclusion material establishes constructions connecting non-invertibility, invariant-set inputs, and reachable unstable modes to stealthy destabilization.

  • A non-invertible system admits a nonzero input sequence producing zero output, establishing the basis for a stealthy attack construction.
  • For each state in the relevant invariant set, a unique input is represented by a matrix Q, enabling zero-output trajectories within that set.
  • When an unstable reachable eigenvector is available, constructed inputs can make the state unbounded while keeping outputs bounded or zero.
  • The proof also handles complex-valued constructions by using their real or imaginary parts to obtain a real input that preserves divergence in one component.
  • A finite nonzero stealthy input sequence can be combined so that the resulting state returns to zero at a later time.

APPENDIX E PROOF OF LEMMA 7

The proof constructs an invariant reachable subspace from normalized states, then shows the induced dynamics are unstable, establishing the required unstable reachable zero-dynamic condition. It also derives bounded normalized input and uses contradiction arguments for the invulnerable case.

  • The proof obtains a uniform bound U such that ||u_k||/(||x_k||+1) ≤ U for every k.
  • The clustered stealthy trajectories produce unbounded state norms along every selected time offset.
  • The constructed subspace V is invariant and reachable, so it is contained in the maximal relevant subspace V*.
  • Assuming stability of A + BQ contradicts the peak-state construction, so A + BQ has an unstable eigenvector in V*.
  • The resulting unstable eigenvector satisfies the conditions for an unstable reachable zero-dynamic, completing the lemma.
  • For an invulnerable system, contradiction arguments establish finiteness of the reconstruction bound ||R||_1,sp.
Loading 2002.01557v1…