OCSYSYMar 1, 2018

Sequential Detection of Deception Attacks in Networked Control Systems with Watermarking

arXiv:1803.001709 citationsh-index: 38
Originality Synthesis-oriented
AI Analysis

For control system security, this work provides a theoretical analysis of the tradeoff between attack detection speed and control performance when using watermarking.

This paper studies quickest detection of deception attacks in networked control systems using a physical watermarking signal. It shows that a sequential CUSUM test based on joint distributions of residue and watermarking signal achieves higher Kullback-Leibler divergence and reduced average detection delay compared to using residue alone, at the cost of increased LQG control cost.

In this paper, we investigate the role of a physical watermarking signal in quickest detection of a deception attack in a scalar linear control system where the sensor measurements can be replaced by an arbitrary stationary signal generated by an attacker. By adding a random watermarking signal to the control action, the controller designs a sequential test based on a Cumulative Sum (CUSUM) method that accumulates the log-likelihood ratio of the joint distribution of the residue and the watermarking signal (under attack) and the joint distribution of the innovations and the watermarking signal under no attack. As the average detection delay in such tests is asymptotically (as the false alarm rate goes to zero) upper bounded by a quantity inversely proportional to the Kullback-Leibler divergence(KLD) measure between the two joint distributions mentioned above, we analyze the effect of the watermarking signal variance on the above KLD. We also analyze the increase in the LQG control cost due to the watermarking signal, and show that there is a tradeoff between quick detection of attacks and the penalty in the control cost. It is shown that by considering a sequential detection test based on the joint distributions of residue/innovations and the watermarking signal, as opposed to the distributions of the residue/innovations only, we can achieve a higher KLD, thus resulting in a reduced average detection delay. Numerical results are provided to support our claims.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes