Source-linked AI summary

Zonotope-Based Active Exposure of Stealthy Deception Attacks in Sensor-Fusion Systems

Meiqi Tian, Shuo Li, Bingzhuo Zhong

arXiv:2609.02587v1eess.SY

TL;DR

Stealthy deception attacks can compromise multiple sensors in sensor-fusion systems while remaining consistent with detector tolerances. The paper constructs secure and attack output sets, then uses bounded receding-horizon control perturbations to separate them; UAV simulations under GNSS and LiDAR attacks validate the method.

  • Problem

    The paper addresses stealthy deception detection in sensor-fusion systems where multiple suspicious sensors may be compromised simultaneously.

  • Method

    It constructs defender-side admissible and hypothesis-dependent attack output sets, then designs bounded auxiliary control inputs through receding-horizon optimization to enlarge their separation.

  • Results

    UAV simulations under stealthy GNSS and LiDAR attacks validated the effectiveness of the proposed exposure framework.

  • Takeaways & Limitations

    Set separation provides a sufficient condition for detecting compromised sensors, while offline budget guidance supports exposure-input selection before online exposure.

Abstract

from arXiv · show

This paper investigates the stealthy attack detection for sensor-fusion cyber-physical systems with unknown-but-bounded noises through the control channel. The detection framework is particularly applicable to sensor-fusion scenarios in which multiple suspicious sensors contributing to the fused estimate may be compromised simultaneously. First, we construct an admissible output set using secure sensors and an attack output set for each attack hypothesis. Then, we introduce a receding-horizon optimization framework to design exposure inputs, namely bounded auxiliary control perturbations injected through the control channel, so as to enlarge the separation between the admissible output set and the attack output sets according to the separation tendency. A sufficient detection condition is further derived, showing that set separation guarantees detectability of the compromised sensors. Moreover, an offline exposure budget guidance is developed to support budget selection before online exposure starts. Simulations on a UAV navigation system under stealthy GNSS and LiDAR attacks validate the proposed method.

I. INTRODUCTION

Sensor fusion improves state estimation but expands exposure to stealthy deception attacks, especially when multiple suspicious sensors may be compromised. The paper addresses this gap with zonotope-based active exposure using bounded control perturbations and set separation.

  • Sensor fusion integrates heterogeneous sensing information for accurate and consistent state estimation but enlarges the attack surface through sensor feedback and vulnerable communication channels.
  • Existing secure-control methods mainly tolerate attack effects rather than actively revealing stealthy attacks, allowing malicious behavior to remain hidden.
  • Active detection methods inject designed perturbations, but representative packet-modification and dynamic-watermarking schemes often require trusted sender–receiver processing architectures.
  • Cross-modal and state-consistency methods are typically tailored to specific sensor pairings and mainly address single compromised sensors, leaving simultaneous multi-sensor attacks less explored.
  • The paper proposes zonotope-based active exposure that enlarges separation between admissible and hypothesis-dependent attack output sets without special sensing or communication requirements.
  • The framework establishes a sufficient set-separation detection condition, receding-horizon exposure with hypothesis updating, and offline lower and sufficient exposure-budget thresholds.

B. System Model

The system is modeled as a discrete-time linear time-invariant process with bounded zonotopic disturbances, sensor attacks, generic fusion, and an omniscient attacker. Suspicious sensors generate hypotheses over possible compromised subsets.

  • The plant evolves according to linear dynamics with process noise, while each sensor output includes measurement noise and an additive attack vector.
  • Process and measurement noises are assumed to belong to known zonotopes, providing unknown-but-bounded uncertainty descriptions.
  • A fixed-gain feedback controller uses the desired state and fused state estimate, whose fusion architecture is not restricted.
  • A generic residual-, innovation-, or consistency-based detector triggers an alarm when its statistic exceeds a prescribed threshold.
  • The suspicious sensor set yields 2^|A| attack hypotheses, each specifying a subset that may be arbitrarily manipulated while the true hypothesis remains unknown.
  • The attacker is modeled as white-box and omniscient, knowing system dynamics, uncertainty sets, feedback control, and detector threshold well enough to emulate nominal behavior and remain stealthy.

D. Problem of Interest

The problem is to identify truly attacked sensors within a prescribed horizon despite unknown attack hypotheses. The proposed formulation designs bounded exposure inputs that exclude inconsistent hypotheses and reveal stealthy attacks.

  • The objective is to identify the true attacked sensors within a prescribed horizon using the secure, suspicious, attacker, and defender models.
  • The method seeks a bounded exposure-input sequence that excludes inconsistent attack hypotheses and makes stealthy attacks detectable.
  • A secure state set is constructed by combining a predicted state set with secure-sensor measurements.
  • The secure measurement state set contains states consistent with stacked secure measurements and their bounded noise set.
  • The intersection of predicted and secure measurement state sets is over-approximated by a zonotope whose parameters are recursively computed.
  • The correction matrix is chosen to minimize the Frobenius norm of the secure-state zonotope generator matrix.

B. Detection Criterion

The framework first tests individual suspicious-sensor outputs against admissible sets, then designs exposure at the hypothesis level by separating defender-side and attacker-side output sets. This separation supports hypothesis exclusion and attack detection.

  • B. Detection Criterion: A sufficient detection theorem declares a suspicious sensor attacked when its received output lies outside its sensor-level admissible output set.
  • C. Hypothesis-Level Output Set Construction: Hypothesis-level exposure considers candidate attacked subsets simultaneously, separating admissible output sets from corresponding attack output sets to exclude inconsistent hypotheses.
  • C. Hypothesis-Level Output Set Construction: The admissible output set collects outputs consistent with the secure state set, whereas the attack output set contains outputs generated by the hypothesis-specific attack reachable set.
  • C. Hypothesis-Level Output Set Construction: Bounded exposure inputs enlarge set separation, making attacked sensors more likely to violate sensor-level admissibility and enabling hypothesis narrowing as sensors are detected.

IV. EXPOSURE INPUT DESIGN

The paper designs bounded control-channel exposure inputs to separate admissible and attack output sets, using separation tendency to expose stealthy attacks. It also requires input visibility across hypotheses and provides offline guidance for choosing the exposure budget.

  • Exposure input formulation: Exposure inputs are bounded auxiliary control perturbations injected into the nominal control channel to enlarge separation between admissible and attack output sets.The composite input is u_s(k) = u*(k) + d(k), with ||d(k)||∞ ≤ ū; ū is the available exposure budget.
  • Budget guidance: An offline budget-guidance procedure provides lower and sufficient exposure-budget thresholds before online exposure, avoiding unnecessarily large control perturbations.The guidance is intended to support practical selection of the exposure-input magnitude.
  • Separation objective: Separation tendency measures the smallest common generator scaling that makes two zonotopes intersect; values above 1 indicate disjoint sets.Values at or below 1 indicate that overlap remains possible under the original uncertainty bounds.
  • Separation objective: The exposure objective is to find an input sequence over the horizon that achieves disjoint admissible and attack output sets, equivalently requiring separation tendency above 1 for every hypothesis.The paper presents set separation as a sufficient condition for detecting compromised sensors.
  • Visibility assumption: Assumption 3 requires each attack hypothesis to have some horizon index r_h satisfying ||C_hA^r_hB||∞ > 0, ensuring exposure inputs affect its associated outputs.This supports online design that enlarges separation across all attack hypotheses.

A. Online Exposure Input Generation

Online exposure uses a receding-horizon strategy that increases worst-case separation over remaining attack hypotheses while updating those hypotheses as sensors are identified. Exposure stops when the hypotheses are resolved, all remaining hypotheses are separated, or the horizon ends.

  • Online exposure input generation: The receding-horizon design selects exposure inputs to increase the worst-case separation tendency over the remaining attack hypotheses.Weights w_h prioritize hypotheses, while ε specifies the desired per-step increase.
  • Hypothesis update: When sensor i is identified as attacked, hypotheses excluding sensor i are removed from the remaining hypothesis set.The update is H(k + 1) = {h ∈ H(k) : i ∈ F(h)}.
  • Stopping rule: Exposure terminates when a singleton hypothesis has separation tendency above 1, all remaining hypotheses exceed 1, or the prescribed horizon is exhausted.These conditions distinguish successful exposure from an unresolved horizon limit.
  • Stopping rule: A singleton remaining hypothesis means the attacked sensor subset is uniquely identified, whereas multiple separated hypotheses imply that their associated sensors are not attacked.If the horizon is exhausted, sensors associated with the remaining hypotheses remain undetectable.

B. Offline Budget Guidance

The section develops offline guidance for selecting an exposure budget that can certify predicted separation across attack hypotheses without unnecessarily large control perturbations. Lower and sufficient thresholds support budget selection, while online inputs remain responsible for actual exposure.

  • Budget guidance: Offline budget guidance selects an exposure magnitude that balances effective attack exposure against limited impact on nominal control performance.The guidance avoids directly solving a nested horizon optimization by using predicted sets and a surrogate separation tendency.
  • Surrogate separation: The surrogate separation tendency measures center mismatch relative to aggregated output-set uncertainty and depends on the exposure budget through the stacked input sequence.The uncertainty radius characterizes the two output sets, while the budget enters through exposure-input propagation.
  • Separation condition: If the surrogate separation tendency exceeds 1 for a hypothesis and horizon step, the corresponding predicted admissible and attack output sets are disjoint.This proposition converts predicted set separation into a threshold condition for offline budget selection.
  • Necessary threshold: If the exposure budget is below the necessary lower threshold, at least one attack hypothesis prevents certification of predicted separation.The lower threshold is therefore a necessary condition for certifying separation across all hypotheses.
  • Algorithm: Algorithm 1 computes the lower and sufficient thresholds offline, then updates secure sets and attack hypotheses while generating bounded exposure inputs online.The online loop constructs sensor-level admissible sets, removes inconsistent hypotheses, optimizes exposure inputs, and stops when the separation criteria are met.
  • Sufficient threshold: If the budget exceeds the sufficient threshold, an excitation direction guarantees predicted separation for all attack hypotheses under the stated visibility condition.The sufficient threshold relies on a common normalized direction whose propagated output effect is nonzero for every hypothesis.

V. CASE STUDIES

The case study simulates a UAV navigation system with LiDAR, GNSS, IMU, and barometer sensors under simultaneous stealthy GNSS and LiDAR attacks. The reported trajectories show visible deviation despite the attacks remaining undetected by a χ2 detector.

  • Simulation setup: Simulations use a UAV navigation system equipped with LiDAR, GNSS, IMU, and a barometer under simultaneous GNSS and LiDAR attacks.The study evaluates the proposed framework in a sensor-fusion setting with multiple compromised sensors.
  • Trajectory results: Fig. 3 presents 3D UAV trajectories under different attack scenarios.The figure is used to visualize trajectory behavior during the simulated attacks.

A. UAV Model

The UAV navigation experiments use a Kalman-filter sensor-fusion setup with stealthy GNSS and LiDAR attacks, then evaluate zonotope-based exposure through separation tendency and detection timing.

  • UAV model: The model is a discrete-time 3D UAV navigation system with position and velocity states and three-axis acceleration inputs.The sampling period is dt = 0.1.
  • Sensor fusion and detection: A Kalman filter with a χ2 detector fuses LiDAR, GNSS, IMU, and barometer measurements using specified detection thresholds.The LiDAR and GNSS thresholds are 7.81 and 12.59 at significance level 0.05.
  • Attack setting: Stealthy attacks of intensities 0.6 and 0.9 are launched during 60–160 s, visibly deviating the trajectory without triggering χ2 alarms.The larger intensity represents stronger measurement tampering while remaining undetected by the detector.
  • Exposure design: At 60 s, the experiment considers GNSS-only, LiDAR-only, and simultaneous GNSS–LiDAR hypotheses with a 50-step exposure horizon and chosen budget ¯u = 2.Offline guidance gives ¯umin = 1.47 and ¯usuf = 2.94; the optimization weights are.
  • Exposure results: Higher attack intensity increases separation tendency faster, exposing GNSS and LiDAR at steps 7 and 14 for intensity 0.9 versus 17 and 46 for intensity 0.6.The hollow circles in Fig. 4 mark the first detection time for each sensor.
  • Exposure results: Simulation results on UAV navigation under GNSS and LiDAR attacks validate the effectiveness of the proposed active exposure framework.The framework enlarges separation between defender-side admissible output sets and hypothesis-dependent attack output sets using bounded auxiliary inputs.

APPENDIX

The appendix uses zonotopic output-set relations to connect measurement inconsistency with detection and to derive a contradiction from sufficient separation.

  • Set construction: The constructed secure state set over-approximates states consistent with defender dynamics, secure measurements, and bounded uncertainties.This over-approximation supports constructing attack-free output sets for sensor consistency checks.
  • Detection criterion: If an attack-free sensor measurement lies outside its compatible output set, the measurement is inconsistent with all attack-free states and the sensor is detected as attacked.The criterion is expressed through yi(k) ∉ Yi(k).
  • Proof relation: For an attack hypothesis with intersecting output sets, the zonotopic representations yield an error expression used in the proof.The expression relates the hypothesis output, secure-state output, and measurement-noise generators.
  • Proof relation: Taking infinity norms produces a bound that contradicts the condition ¯δh(j⋆) > 1.The contradiction establishes incompatibility between the assumed intersection and the stated separation condition.
  • Input effect: The proof bounds the effect of the exposure input through the term ∥ChMj∥∞¯u when analyzing a hypothesis.This term appears in the infinity-norm inequality used to compare error and radius.

D. Proof of Theorem 3

The proof constructs a budget-feasible exposure input by scaling a bounded direction vector.

  • Input construction: The proof defines the exposure direction as dj⋆ = ¯u rj⋆.The direction vector rj⋆ satisfies ∥rj⋆∥∞ ≤ 1.
  • Budget feasibility: Because ∥rj⋆∥∞ ≤ 1, the resulting input sequence satisfies the budget constraint ∥d(k)∥∞ ≤ ¯u.The constraint applies for k = t0, . . . , t0 + j⋆ − 1.
  • Theorem condition: The budget-feasibility result is used to establish the corresponding theorem condition.The passage states that this implies condition (31) by (23).
Loading 2609.02587v1…