Attack-resilient state estimation with intermittent data authentication

Attack-resilient state estimation with intermittent data authentication
复制标题

具有间歇性数据认证的抗攻击状态估计

DOI:
10.1016/j.automatica.2021.110035
复制
发表时间:
2022
期刊:
影响因子:
6.4
通讯作者:
Pajic, Miroslav
Pajic, Miroslav
中科院分区:
计算机科学2区
文献类型:
--
作者:
Khazraei, Amir;Pajic, Miroslav

文献摘要

相似文献

对控制系统的基于网络的攻击可能会改变传递到控制器的传感器数据,从而有效地导致控制性能的下降。因此,即使在存在对传感器测量的攻击的情况下,也能够获得准确的状态估计是至关重要的。在这项工作中,我们分析弹性状态估计器(RSE)的性能时,任何子集的传感器可能会受到一个隐形攻击者。具体来说,我们考虑系统与著名的10-基于RSE和两个常用的声音入侵检测器(ID)。对于具有有界噪声的线性时不变植物,我们定义了完美可攻击性(PA)的概念,当攻击可能导致无限的估计误差,同时保持未被所采用的ID检测到(即隐身)。我们推导出必要和充分PA条件,表明即使植物是稳定的,系统也可以完全攻击。虽然PA可以通过使用标准的加密机制(例如,消息认证)来防止,这些机制可以确保基于网络的攻击下的数据完整性,但它们的连续使用会带来显著的通信和计算开销。因此,我们还研究了在存在隐形攻击的情况下,即使是间歇性使用数据认证对RSE性能保证的影响。我们表明,如果从一些传感器的消息,甚至间歇性认证,隐形攻击不会导致无界的状态估计误差。
Network-based attacks on control systems may alter sensor data delivered to the controller, effectively causing degradation in control performance. As a result, having access to accurate state estimates, even in the presence of attacks on sensor measurements, is of critical importance. In this work, we analyze performance of resilient state estimators (RSEs) when any subset of sensors may be compromised by a stealthy attacker. Specifically, we consider systems with the well-known l 0-based RSE and two commonly used sound intrusion detectors (IDs). For linear time-invariant plants with bounded noise, we define the notion of perfect attackability (PA) when attacks may result in unbounded estimation errors while remaining undetected by the employed ID (ie, stealthy). We derive necessary and sufficient PA conditions, showing that a system can be perfectly attackable even if the plant is stable. While PA can be prevented with the use the standard cryptographic mechanisms (eg, message authentication) that ensure data integrity under network-based attacks, their continuous use imposes significant communication and computational overhead. Consequently, we also study the impact that even intermittent use of data authentication has on RSE performance guarantees in the presence of stealthy attacks. We show that if messages from some of the sensors are even intermittently authenticated, stealthy attacks could not result in unbounded state estimation errors.