Safety of Linear Systems under Severe Sensor Attacks

Summary

Attacked is omniscient and can spoof several system sensors at will.

Existing results have derived necessary and sufficient conditions under which the state estimation problem has a unique solution.

This paper considers severe attacking scenario when such conditions do not hold.

Derive exact characterisation of set of all possible state estimates.

Use framework of Control Barrier Functions to propose design principles for system safety in offline and online phases.

Illustrated with 2D-vehicle example.

Only theoretical results.

Introduction

In this paper:

Existing results focus on recovering system state from compromised measurement data (AKA secure state reconstruction problem).

To derive necessary and sufficient conditions to find unique solutions to this problem:

"can we ensure safety of the system, and thereby avoid catastrophic results through active control, even when certain sensors are compromised?"

Here, safety refers to the property to limit control system trajectories to remain with in a safe set via feedback

Compromised sensor measures negatively effect or mislead state estimates.

Control Barrier Functions have been applied to use cases of privacy preservation and safety in presence of faulty sensors. But in case of adversarial omniscient attacker, state estimation error does not satisfy assumptions of CBFs.

This work tries to patch this shortcoming.

Safety guarantee for CPS subject to general sensor attacks described above. We consider scenarios where the solution to the secure state reconstruction problem may not be unique.

Contributions:

Notation

Set Notation

[w] := 1,2,...,w : Denotes the set containing all natural numbers from 1 to w .

∣I∣ : Denotes the cardinality (number of elements) of the set.

Combinations

Ckw : Represents the set of all k -combinations from the set [ w ], where a k -combination is a subset of [ w ] with cardinality k .

Matrix Operations

For a matrix C of size w×n and an index set Γ that is a subset of [ w ], CΓ represents a matrix obtained from C by removing all the rows with indices not in Γ .

Norm and Set Notation

Given a point x in Rn , a set X that is a subset of Rn , and a matrix A in Rn×n , the notation ||x||X represents the minimum distance of x to any point v in X . A(X) represents the set of all points in Rn that can be obtained by multiplying any point x in X by the matrix A .

Minkowski Summation

X1+X2: Represents the Minkowski sum of two sets X1 and X2, defined as the set containing all possible sums of elements where one element is chosen from X1 and another from X2 .

Vector and Singleton Set

x∈Rn : Denotes a vector in n -dimensional real space.

Problem Formulation

Applied to a discrete-time linear system under sensor attacks:

Dynamics: x(τ+1)=Ax(τ)+Bu(τ)

Measurement: y(τ)=Cx(τ)+e(τ)

Here e(τ) refers to the attacking signal.

It is non-zero whenever a sensor i∈[p] is under attack at that particular τ.

Safe set: C={x∈Rn:h(x):=Hx+q≥0}

Assumption

Attacker has full knowledge of system including state, dynamics, and defense strategy.

Attacker may choose s out of p sensors to attack. And this choice remains unchanged for duration considered.

Attacker can set ei(τ) to any value for any of these sensors.

Problem

Worst-case sensor attack - Derive condition on H and q s.t. system can be rendered safe under all possible sensor attacks.

Fixed yet unknown sensor attack - Derive conditions on H , q and input sequence {u(τ)}τ≥t s.t. the system is safe.

2-D Example Use Case

System Dynamics and Control

The vehicle is modeled with position and velocity components in both x and y directions ( x1,x2,x3,x4 ), controlled by acceleration inputs ( u1,u2 ).

The system's dynamics are expressed in continuous-time, which are then discretized using a Zero-Order Hold Method with a 0.01s sampling time for digital control implementation.

The output of the system includes a component representing an attacking signal ( e ), indicating potential tampering with sensor data.

Safety Guarantees and Sensor Attacks

The system's safety verification involves checking for Sparse Observability, ensuring that even with a single sensor attack, the system's state can be inferred from the remaining sensors.

A safe region ( C ) is defined using constraints on the position and velocity states of the vehicle. The system maintains safety by ensuring the state stays within this region even under sensor attacks.

Online Safety and Control

An online control strategy is outlined where the controller dynamically adjusts based on sensor data to mitigate any effects from tampered sensors. The control is designed to maintain the vehicle's state within the predefined safe bounds.

During attacks, the system asesses sensor integrity by comparing sensor outputs against expected values from a set of plausible vehicle states, adjusted for potential tampering.

Key Features

Dynamic Safety Set (C)

The system uses a dynamic definition of a safe set, denoted as C , where the boundaries are defined such that all components of the vehicle's state (position and velocity in both x and y directions) must remain within specified limits (e.g., −4≤xi≤4 for each state variable).

This set ensures that even under the influence of malicious inputs or sensor errors, the control strategy can realign the vehicle back to a safe trajectory.

Sensor Attack Handling

Sensors are susceptible to attacks where their outputs are altered to mislead the control system. In response, the system evaluates the integrity of sensor data by comparing against a model of expected outputs derived from known vehicle dynamics and previously verified states.

By considering multiple combinations of sensor outputs and comparing them against theoretical trajectories, the system identifies which sensors are likely compromised.

State Estimation Under Uncertainty

Using a brute-force approach, the system examines all possible combinations of sensor data to estimate the vehicle's state. This involves calculating the least squares solution to the equations representing sensor outputs and checking if the solutions meet predefined error thresholds.

These plausible states are then projected forward using the vehicle dynamics model to predict future states, which helps in planning safe control actions.

Adaptive Control Strategy

The control inputs ( u(t) ) are adjusted based on the estimated states and the requirement to keep the vehicle within the safe set. This involves solving a quadratic programming (QP) problem where the objective is to minimize the deviation from nominal control inputs (based on simple functions like sine and cosine) while ensuring that all calculated future states fall within the safety constraints.

The system employs a parameter ( γ ), possibly representing a safety margin or confidence level, which adjusts the strictness of the safety constraint adherence.

Real-time Validation

As part of its ongoing operation, the system continually checks whether the initially estimated plausible states (from when the system was first compromised) remain within the safe bounds over time.

This involves recalculating and projecting the states every few time steps (e.g., t−3 , t−2 , t−1 , t ) to ensure ongoing compliance with the safety requirements.

Simulation and Results

Simulations show the system maintaining safety constraints despite different attack scenarios, though some attacks lead to safety breaches when they cause confusion about certain state variables (e.g., y -axis velocity).

The control adjustments closely mirror nominal (intended) controls unless adjustments are necessary to maintain safety.

Overall System Performance

The system effectively handles sensor attacks by adjusting control inputs to ensure that both real and potential (fake) states of the vehicle remain within safety limits.

The approach includes robust measures to verify sensor integrity and dynamically adapt to ensure continuous safe operation under potential cyber-attacks.