Digital Twin-Based Cyber-Attack Detection Framework for Cyber-Physical Manufacturing Systems

被引:29
|
作者
Balta, Efe C. [2 ]
Pease, Michael [1 ]
Moyne, James [2 ]
Barton, Kira [2 ]
Tilbury, Dawn M. [2 ]
机构
[1] Natl Inst Stand & Technol, Gaithersburg, MD USA
[2] Univ Michigan, Dept Mech Engn, Ann Arbor, MI 48109 USA
基金
美国国家科学基金会;
关键词
Cyberattack; Process control; Manufacturing; Monitoring; Scalability; Industrial Internet of Things; Digital twins; Anomaly detection; control systems; cyberattack; cyber-physical systems; data analysis; digital twins; fault detection; intelligent automation; manufacturing automation; model checking; security; FAULT-DETECTION; SENSOR ATTACKS; SUPPORT; MODEL; SELECTION; SERVICE; DRIVEN; FUTURE;
D O I
10.1109/TASE.2023.3243147
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart manufacturing (SM) systems utilize run-time data to improve productivity via intelligent decision-making and analysis mechanisms on both machine and system levels. The increased adoption of cyber-physical systems in SM leads to the comprehensive framework of cyber-physical manufacturing systems (CPMS) where data-enabled decision-making mechanisms are coupled with cyber-physical resources on the plant floor. Due to their cyber-physical nature, CPMS are susceptible to cyber-attacks that may cause harm to the manufacturing system, products, or even the human workers involved in this context. Therefore, detecting cyber-attacks efficiently and timely is a crucial step toward implementing and securing high-performance CPMS in practice. This paper addresses two key challenges to CPMS cyber-attack detection. The first challenge is distinguishing expected anomalies in the system from cyber-attacks. The second challenge is the identification of cyber-attacks during the transient response of CPMS due to closed-loop controllers. Digital twin (DT) technology emerges as a promising solution for providing additional insights into the physical process (twin) by leveraging run-time data, models, and analytics. In this work, we propose a DT framework for detecting cyber-attacks in CPMS during controlled transient behavior as well as expected anomalies of the physical process. We present a DT framework and provide details on structuring the architecture to support cyber-attack detection. Additionally, we present an experimental case study on off-the-shelf 3D printers to detect cyber-attacks utilizing the proposed DT framework to illustrate the effectiveness of our proposed approach. Note to Practitioners-This work is motivated by developing a general-purpose and extensible digital twin-enabled cyber-attack detection framework for manufacturing systems. Existing works in the field consider specialized attack scenarios and models that may not be extensible in practical manufacturing scenarios. We utilize digital twin (DT) technology as a key enabler to develop a systematic and extensible framework where we identify the abnormality of a resource and detect if the abnormality is due to an attack or an expected anomaly. We provide several remarks on how our proposed framework can extend existing industrial control systems (ICS) and can accommodate further extensions. The presented DTs utilize data-driven machine learning models, physics-based models, and subject matter expert knowledge to perform detection and differentiation tasks in the context of expected anomalies and model-based controllers that control the manufacturing process between multiple setpoints. We utilize a model predictive controller on an off-the-shelf 3D printer to run the process, and stage anomalies and cyber-attacks that are successfully detected by the proposed framework.
引用
收藏
页码:1695 / 1712
页数:18
相关论文
共 50 条
  • [1] Digital Twin-Based Cyber-Attack Detection and Mitigation for DC Microgrids
    Lu, Yizhou
    Zhang, Mengfan
    Nordstrom, Lars
    Xu, Qianwen
    IEEE TRANSACTIONS ON SMART GRID, 2025, 16 (02) : 876 - 889
  • [2] A Digital Twin-Based Platform for Medical Cyber-Physical Systems
    Rahim, Messaoud
    Lalouani, Wassila
    Toubal, Elbahi
    Emokpae, Lloyd
    IEEE ACCESS, 2024, 12 : 174591 - 174607
  • [3] Digital Twin-based Anomaly Detection in Cyber-physical Systems
    Xu, Qinghua
    Ali, Shaukat
    Yue, Tao
    2021 14TH IEEE CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2021), 2021, : 205 - 216
  • [4] KCAD: Kinetic Cyber-Attack Detection Method for Cyber-Physical Additive Manufacturing Systems
    Chhetri, Sujit Rokka
    Canedo, Arquimedes
    Al Faruque, Mohammad Abdullah
    2016 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2016,
  • [5] Cyber-Attack Detection for Automotive Cyber-Physical Systems
    Lee, Suyun
    Jung, Sunjae
    Baek, Youngmi
    BUILDSYS'21: PROCEEDINGS OF THE 2021 ACM INTERNATIONAL CONFERENCE ON SYSTEMS FOR ENERGY-EFFICIENT BUILT ENVIRONMENTS, 2021, : 214 - 215
  • [6] An Anomaly Detection Framework for Digital Twin Driven Cyber-Physical Systems
    Gao, Chuanchao
    Park, Heejong
    Easwaran, Arvind
    ICCPS'21: PROCEEDINGS OF THE 2021 ACM/IEEE 12TH INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (WITH CPS-IOT WEEK 2021), 2021, : 44 - 54
  • [7] Digital Twin-based Anomaly Detection with Curriculum Learning in Cyber-physical Systems
    Xu, Qinghua
    Ali, Shaukat
    Yue, Tao
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (05)
  • [8] Attack Detection and Identification in Cyber-Physical Systems
    Pasqualetti, Fabio
    Doerfler, Florian
    Bullo, Francesco
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2013, 58 (11) : 2715 - 2729
  • [9] Replay Attack Detection Based on Parity Space Method for Cyber-Physical Systems
    Zhao, Dong
    Shi, Yang
    Ding, Steven X.
    Li, Yueyang
    Fu, Fangzhou
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2025, 70 (04) : 2390 - 2405
  • [10] LTL-based runtime verification framework for cyber-attack anomaly prediction in cyber-physical systems
    Akande, Ayodeji James
    Hou, Zhe
    Foo, Ernest
    Li, Qinyi
    COMPUTERS & SECURITY, 2025, 155