Table of Contents
Fetching ...

Adapting Noise-Driven PUF and AI for Secure WBG ICS: A Proof-of-Concept Study

Devon A. Kelly, Christiana Chamon

TL;DR

This paper addresses the security vulnerability of ICS in the era of wide-bandgap (WBG) power electronics by proposing a dual-use defense that leverages unavoidable switching noise as both a physically unclonable function (PUF) entropy source for sensor authentication and as a real-time feature for anomaly detection. The authors design a noise-driven PUF framework combined with a hybrid ML and adaptive Bayesian filtering pipeline, achieving sub-millisecond processing and about 95% detection accuracy in simulated WBG ICS scenarios, including EMI spoofing, tampering, and node impersonation. Key contributions include (i) introducing a PUF constructed from WBG switching noise, (ii) integrating RL-guided anomaly detection with Bayesian smoothing for real-time robustness, and (iii) demonstrating feasibility via a detailed MATLAB/Simulink PoC with SiC/GaN inverter models. The work lays groundwork for hardware-aware, physics-grounded defenses that can be incrementally validated and benchmarked, potentially enabling scalable, low-overhead security for critical infrastructure. Future hardware validation and standardized EMI benchmark datasets are highlighted as essential next steps toward field deployment and broader industry adoption.

Abstract

Wide-bandgap (WBG) technologies offer unprecedented improvements in power system efficiency, size, and performance, but also introduce unique sensor corruption and cybersecurity risks in industrial control systems (ICS), particularly due to high-frequency noise and sophisticated cyber-physical threats. This proof-of-concept (PoC) study demonstrates the adaptation of a noise-driven physically unclonable function (PUF) and machine learning (ML)-assisted anomaly detection framework to the demanding environment of WBG-based ICS sensor pathways. By extracting entropy from unavoidable WBG switching noise (up to 100 kHz) as a PUF source, and simultaneously using this noise as a real-time threat indicator, the proposed system unites hardware-level authentication and anomaly detection. Our approach integrates hybrid machine learning (ML) models with adaptive Bayesian filtering, providing robust and low-latency detection capabilities resilient to both natural electromagnetic interference (EMI) and active adversarial manipulation. Through detailed simulations of WBG modules under benign and attack scenarios--including EMI injection, signal tampering, and node impersonation--we achieve 95% detection accuracy and sub-millisecond processing latency. These results demonstrate the feasibility of physics-driven, dual-use noise exploitation as a scalable ICS defense primitive. Our findings lay the groundwork for next-generation security strategies that leverage inherent device characteristics, bridging hardware and artificial intelligence (AI) for enhanced protection of critical ICS infrastructure.

Adapting Noise-Driven PUF and AI for Secure WBG ICS: A Proof-of-Concept Study

TL;DR

This paper addresses the security vulnerability of ICS in the era of wide-bandgap (WBG) power electronics by proposing a dual-use defense that leverages unavoidable switching noise as both a physically unclonable function (PUF) entropy source for sensor authentication and as a real-time feature for anomaly detection. The authors design a noise-driven PUF framework combined with a hybrid ML and adaptive Bayesian filtering pipeline, achieving sub-millisecond processing and about 95% detection accuracy in simulated WBG ICS scenarios, including EMI spoofing, tampering, and node impersonation. Key contributions include (i) introducing a PUF constructed from WBG switching noise, (ii) integrating RL-guided anomaly detection with Bayesian smoothing for real-time robustness, and (iii) demonstrating feasibility via a detailed MATLAB/Simulink PoC with SiC/GaN inverter models. The work lays groundwork for hardware-aware, physics-grounded defenses that can be incrementally validated and benchmarked, potentially enabling scalable, low-overhead security for critical infrastructure. Future hardware validation and standardized EMI benchmark datasets are highlighted as essential next steps toward field deployment and broader industry adoption.

Abstract

Wide-bandgap (WBG) technologies offer unprecedented improvements in power system efficiency, size, and performance, but also introduce unique sensor corruption and cybersecurity risks in industrial control systems (ICS), particularly due to high-frequency noise and sophisticated cyber-physical threats. This proof-of-concept (PoC) study demonstrates the adaptation of a noise-driven physically unclonable function (PUF) and machine learning (ML)-assisted anomaly detection framework to the demanding environment of WBG-based ICS sensor pathways. By extracting entropy from unavoidable WBG switching noise (up to 100 kHz) as a PUF source, and simultaneously using this noise as a real-time threat indicator, the proposed system unites hardware-level authentication and anomaly detection. Our approach integrates hybrid machine learning (ML) models with adaptive Bayesian filtering, providing robust and low-latency detection capabilities resilient to both natural electromagnetic interference (EMI) and active adversarial manipulation. Through detailed simulations of WBG modules under benign and attack scenarios--including EMI injection, signal tampering, and node impersonation--we achieve 95% detection accuracy and sub-millisecond processing latency. These results demonstrate the feasibility of physics-driven, dual-use noise exploitation as a scalable ICS defense primitive. Our findings lay the groundwork for next-generation security strategies that leverage inherent device characteristics, bridging hardware and artificial intelligence (AI) for enhanced protection of critical ICS infrastructure.
Paper Structure (49 sections, 6 equations, 6 figures, 4 tables)

This paper contains 49 sections, 6 equations, 6 figures, 4 tables.

Figures (6)

  • Figure 1: Simplified ICS architecture with WBG modules. Our defense framework operates between sensors and controllers, using switching noise as both authentication and anomaly detection input.
  • Figure 2: Spectrogram of a synthesized WBG switching noise signal (100 kHz), illustrating harmonic structure and frequency spread used for entropy feature extraction. The vertical "lines" indicate persistent harmonic tones at multiples of the switching frequency, while broadening and amplitude variations reflect load transients and random noise. This is the empirical entropy source for the PUF: each device’s spectrogram is minutely unique and repeatably measurable, forming the basis for device-specific authenticators.
  • Figure 3: Processing pipeline: Noise-driven entropy extraction enables both (i) sensor authentication via PUF responses and (ii) anomaly detection through ML and Bayesian filtering.
  • Figure 4: ROC curves for anomaly detection: performance across EMI spoofing, tampering, and impersonation attacks (blue, green, orange) compared to baseline (red).
  • Figure 5: ROC curve for anomaly detection, comparing the anomaly detection capability (true positive vs. false positive rate for different thresholds) for a static threshold (red) and the combined PUF+ML+Bayesian pipeline (blue).
  • ...and 1 more figures