SYSYJun 18

Data-Driven Control from Poisoned Data: Fundamental Limitations and Secure DeePC

arXiv:2606.203011.7
Predicted impact top 93% in SY · last 90 daysOriginality Incremental advance
AI Analysis

For control systems relying on data-driven methods, this work provides both theoretical limitations and a practical algorithm to ensure resilience against data poisoning attacks.

This paper studies data-driven control under arbitrary data poisoning attacks, establishing fundamental limitations such as undetectability and non-informativeness of poisoned data. It proposes Secure DeePC, which achieves MPC-equivalent performance in finite time almost surely under certain conditions.

We study a data-driven control problem in the presence of arbitrary data poisoning attacks. We assume that a subset of offline output data is stored in unprotected locations and may be poisoned by an adversary. We first establish fundamental limitations for data-driven control arising from such poisoned data: poisoning attacks are not detected/identified from the dataset alone; unprotected data are non-informative for controller design with worst-case guarantees; and hard constraints on unprotected outputs are not certifiable. Motivated by these limitations and the data-enabled predictive control (DeePC) technique, we propose Secure DeePC, a data-driven control algorithm that is resilient against poisoning attacks. It first runs output-truncated DeePC using only the protected dataset until the online input becomes persistently exciting. It then uses online measurements to reconstruct the partial offline dataset, and finally returns to full-output DeePC. Secure DeePC achieves MPC-equivalent performance in finite time almost surely under certain conditions. Simulation results illustrate the efficacy of the proposed framework against poisoning attacks.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes