Learning-Based Simultaneous Detection and Characterization of Time Delay Attack in Cyber-Physical Systems

被引:26
作者
Ganesh, Prakhar [1 ]
Lou, Xin [1 ]
Chen, Yao [1 ]
Tan, Rui [2 ]
Yau, David K. Y. [3 ]
Chen, Deming [4 ]
Winslett, Marianne [5 ]
机构
[1] Illinois Singapore, Adv Digital Sci Ctr, Singapore, Singapore
[2] Nanyang Technol Univ, Sch Comp Sci & Engn, Singapore, Singapore
[3] Singapore Univ Technol & Design, Informat Syst Technol & Design Pillar, Singapore, Singapore
[4] Univ Illinois, ECE Dept, Urbana, IL 61801 USA
[5] Univ Illinois, Dept Comp Sci, Urbana, IL 61801 USA
基金
新加坡国家研究基金会;
关键词
Delays; Automatic generation control; Mathematical model; Generators; Cyber-physical systems; Computer crime; Computational modeling; Smart grid; cyber-physical system; time delay attack; attack detection; attack characterization; deep learning; SECURITY; IMPACT;
D O I
10.1109/TSG.2021.3058682
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Control and communication technologies are key building blocks of cyber-physical systems (CPSes) that can improve the efficiency of the physical processes. However, they also make a CPS vulnerable to cyberattacks that can cause disruptions or even severe damage. This article focuses on one particular type of CPS cyberattack, namely the time delay attack (TDA), which exploits vulnerabilities in the communication channels to cause potentially serious harm to the system. Much work proposed for TDA detection is tested offline only and under strong assumptions. In order to construct a practical solution to deal with real-world scenarios, we propose a deep learning-based method to detect and characterize TDA. Specifically, we design a hierarchical long short-term memory model to process raw data streams from relevant CPS sensors online and continually monitor embedded signals in the data to detect and characterize the attack. Moreover, various strategies of interpreting the outputs of the model are proposed, which allow the user to tune the performance based on different objectives. We evaluate our model on two representative types of CPS, namely power plant control system (PPCS) and automatic generation control (AGC).Code and dataset can be found at: https://github.com/prakharg24/tda For TDA detection, our solution achieves an accuracy of 92% in PPCS, compared with 81% by random forests (RFs) and 72% by k-nearest neighbours (kNNs). For AGC, our solution achieves 98% accuracy, compared with 74% by RFs and 71% by kNNs. It also reduces the mean absolute error in the delay value characterization from about six to two seconds in the PPCS, and from about three seconds to half a second in the AGC, with about 3x to 4x shorter reaction latency in both systems.
引用
收藏
页码:3581 / 3593
页数:13
相关论文
共 46 条
[1]   A Neural Network-based Approach for Detection of Time Delay Switch Attack on Networked Control Systems [J].
Abbasspour, Alireza ;
Sargolzaei, Arman ;
Victorio, Mauro ;
Khoshavi, Navid .
COMPLEX ADAPTIVE SYSTEMS, 2020, 168 :279-288
[2]  
Ali H, 2012, IFIP ADV INF COMM TE, V390, P139
[3]  
Amin S, 2009, LECT NOTES COMPUT SC, V5469, P31, DOI 10.1007/978-3-642-00602-9_3
[4]  
Annessi R., ENCRYPTION IS FUTILE
[5]  
[Anonymous], 2014, P IEEE PES INN SMART
[6]  
[Anonymous], 2001, FIELD GUIDE DYNAMICA
[7]   An online identification algorithm of unknown time-varying delay and internal multimodel control for discrete non-linear systems [J].
Ben Atia, Samah ;
Messaoud, Anis ;
Ben Abdennour, Ridha .
MATHEMATICAL AND COMPUTER MODELLING OF DYNAMICAL SYSTEMS, 2018, 24 (01) :26-43
[8]  
Cardenas A. A., 2008, P 3 C HOT TOP SEC SA, P1
[9]   Modelling of thermo-hydraulic power generation processes using Modelica [J].
Casella, F ;
Leva, A .
MATHEMATICAL AND COMPUTER MODELLING OF DYNAMICAL SYSTEMS, 2006, 12 (01) :19-33
[10]   Which of Our Modeling Predictions Are Robust? [J].
De Boer, Rob J. .
PLOS COMPUTATIONAL BIOLOGY, 2012, 8 (07)