On minimal tests of sensor veracity for dynamic watermarking-based defense of cyber-physical systems

On minimal tests of sensor veracity for dynamic watermarking-based defense of cyber-physical systems
复制标题

DOI:
10.1109/comsnets.2017.7945354
复制
发表时间:
2017
期刊:
2017 9th International Conference on Communication Systems and Networks (COMSNETS)
影响因子:
--
通讯作者:
Bharadwaj Satchidanandan;P. Kumar
Bharadwaj Satchidanandan;P. Kumar
中科院分区:
其他
文献类型:
--
作者:
Bharadwaj Satchidanandan;P. Kumar

文献摘要

被引文献

相似文献

我们解决了某些传感器可能是恶意的网络物理系统安全性的问题。 (ii)将这些输入应用于植物的执行器以及(iii)测量植物的输出的传感器可能是恶意的。恶意传感器不会向控制器报告真实的测量,他们报告了他们制造的虚假测量值最近,已经表明,在某些条件下,“动态水印”的方法可以在某种意义上确保这种随机线性动态系统,以至于恶意的存在检测到系统中的传感器,或者将恶意传感器限制为添加一个仅在输入系统的噪声的失真,本文的第一个贡献是将此结果推广到部分观察到的MIMO系统。过程和观察噪声,该模型涵盖了以前的一些模型,以确保该结果与先前的结果相似。受试者报告的测量顺序是两个特定的真实性测试。传感器真实性的测试被删除,因此提出的方法没有任何潜在的应用,包括智能电网,自动运输和过程控制。
We address the problem of security of cyber-physical systems where some sensors may be malicious. We consider a multiple-input, multiple-output stochastic linear dynamical system controlled over a network of communication and computational nodes which contains (i) a controller that computes the inputs to be applied to the physical plant, (ii) actuators that apply these inputs to the plant, and (iii) sensors which measure the outputs of the plant. Some of these sensors, however, may be malicious. The malicious sensors do not report the true measurements to the controller. Rather, they report false measurements that they fabricate, possibly strategically, so as to achieve any objective that they may have, such as destabilizing the closed-loop system or increasing its running cost. Recently, it was shown that under certain conditions, an approach of “dynamic watermarking” can secure such a stochastic linear dynamical system in the sense that either the presence of malicious sensors in the system is detected, or the malicious sensors are constrained to adding a distortion that can only be of zero power to the noise already entering the system. The first contribution of this paper is to generalize this result to partially observed MIMO systems with both process and observation noises, a model which encompasses some of the previous models for which dynamic watermarking was established to guarantee security. This result, similar to the prior ones, is shown to hold when the controller subjects the reported sequence of measurements to two particular tests of veracity. The second contribution of this paper is in showing, via counterexamples, that both of these tests are needed in order to secure the control system in the sense that if any one of these two tests of sensor veracity is dropped, then the above guarantee does not hold. The proposed approach has several potential applications, including in smart grids, automated transportation, and process control.