Dual Detection Framework for Faults and Integrity Attacks in Cyber-Physical Control Systems
Xixing Xue, Dong Shen, Steven X. Ding, Dong Zhao
TL;DR
The paper tackles the challenge of detecting and distinguishing faults and integrity attacks in cyber-physical control systems by proposing a dual-detection framework with detectors on both the controller and plant sides. By exploiting the closed-loop dynamics and kernel-space properties of stealthy attacks, it derives a closed-loop stealthiness condition and designs residual-based detectors that operate in complementary spaces, enabling discrimination between faults and attacks. A two-stage optimization jointly tunes detector configurations and the controller gain to maximize detection performance without sacrificing control quality, and simulations on UAV/RLC models demonstrate enhanced detection—especially against kernel attacks like zero-dynamics, covert, and replay attacks. This framework offers a practical, non-invasive approach to improving CPS security and resilience, with potential extensions to nonlinear and data-driven settings.
Abstract
Anomaly detection plays a vital role in the security and safety of cyber-physical control systems, and accurately distinguishing between different anomaly types is crucial for system recovery and mitigation. This study proposes a dual detection framework for anomaly detection and discrimination. By leveraging the dynamic characteristics of control loops and the stealthiness features of integrity attacks, the closed-loop stealthiness condition is first derived, and two dedicated detectors are designed and deployed on the controller side and the plant side, respectively, enabling joint plant fault and cyber attack detection. Moreover, by jointly analyzing the residual response of the two detectors corresponding to different anomalies, it is proved that the proposed method can distinguish between faults and integrity attacks due to the detectors' individual residual spaces. According to the detector's residual space, the fault and attack detection performance is further improved by a two-stage optimization scheme. Simulation results validate the effectiveness of the proposed approach.
