Safety of Linear Systems under Severe Sensor Attacks
Summary
Attacked is omniscient and can spoof several system sensors at will.
Existing results have derived necessary and sufficient conditions under which the state estimation problem has a unique solution.
This paper considers severe attacking scenario when such conditions do not hold.
Derive exact characterisation of set of all possible state estimates.
Use framework of Control Barrier Functions to propose design principles for system safety in offline and online phases.
- Offline phase derive conditions on safe sets for all possible sensor attacks encounterable during system deployments.
- Online phase quadratic program-based safety filter is proposed to enforce system safety.
Illustrated with 2D-vehicle example.
Only theoretical results.
Introduction
In this paper:
- certain measurements of CPS are compromised by attacker.
- general attack model in setting of linear systems, imposes no limitations on the magnitude, statistical properties, or temporal evolution requirements on the attack signal.
- only assuming upper bound on the number of attacked sensors.
Existing results focus on recovering system state from compromised measurement data (AKA secure state reconstruction problem).
To derive necessary and sufficient conditions to find unique solutions to this problem:
- In discrete time linear system a condition is posed as a sparse observability property of CPS.
- Equivalent condition for continuous time LS shows that finding unique solution is NP-hard in general.
"can we ensure safety of the system, and thereby avoid catastrophic results through active control, even when certain sensors are compromised?"
Here, safety refers to the property to limit control system trajectories to remain with in a safe set via feedback
Compromised sensor measures negatively effect or mislead state estimates.
Control Barrier Functions have been applied to use cases of privacy preservation and safety in presence of faulty sensors. But in case of adversarial omniscient attacker, state estimation error does not satisfy assumptions of CBFs.
This work tries to patch this shortcoming.
Safety guarantee for CPS subject to general sensor attacks described above. We consider scenarios where the solution to the secure state reconstruction problem may not be unique.
Contributions:
- Provide exact characterisation of set of possible solutions to the secure state reconstruction problem in linear DT systems.
- Outline design principles for safe sets in offline phase. For worst-case attacking scenario under mild sparse observability assumption.
- Propose only safe control scheme that provides safety guarantees in presence of possibly unbounded state estimation error.
Notation
Set Notation
Combinations
Matrix Operations
For a matrix
Norm and Set Notation
Given a point
Minkowski Summation
Vector and Singleton Set
Problem Formulation
Applied to a discrete-time linear system under sensor attacks:
Dynamics:
Measurement:
Here
It is non-zero whenever a sensor
Safe set:
Assumption
Attacker has full knowledge of system including state, dynamics, and defense strategy.
Attacker may choose
Attacker can set
Problem
Worst-case sensor attack - Derive condition on
Fixed yet unknown sensor attack - Derive conditions on
2-D Example Use Case
System Dynamics and Control
The vehicle is modeled with position and velocity components in both
The system's dynamics are expressed in continuous-time, which are then discretized using a Zero-Order Hold Method with a 0.01s sampling time for digital control implementation.
The output of the system includes a component representing an attacking signal (
Safety Guarantees and Sensor Attacks
The system's safety verification involves checking for Sparse Observability, ensuring that even with a single sensor attack, the system's state can be inferred from the remaining sensors.
A safe region (
Online Safety and Control
An online control strategy is outlined where the controller dynamically adjusts based on sensor data to mitigate any effects from tampered sensors. The control is designed to maintain the vehicle's state within the predefined safe bounds.
During attacks, the system asesses sensor integrity by comparing sensor outputs against expected values from a set of plausible vehicle states, adjusted for potential tampering.
Key Features
Dynamic Safety Set ( )
The system uses a dynamic definition of a safe set, denoted as
This set ensures that even under the influence of malicious inputs or sensor errors, the control strategy can realign the vehicle back to a safe trajectory.
Sensor Attack Handling
Sensors are susceptible to attacks where their outputs are altered to mislead the control system. In response, the system evaluates the integrity of sensor data by comparing against a model of expected outputs derived from known vehicle dynamics and previously verified states.
By considering multiple combinations of sensor outputs and comparing them against theoretical trajectories, the system identifies which sensors are likely compromised.
State Estimation Under Uncertainty
Using a brute-force approach, the system examines all possible combinations of sensor data to estimate the vehicle's state. This involves calculating the least squares solution to the equations representing sensor outputs and checking if the solutions meet predefined error thresholds.
These plausible states are then projected forward using the vehicle dynamics model to predict future states, which helps in planning safe control actions.
Adaptive Control Strategy
The control inputs (
The system employs a parameter (
Real-time Validation
As part of its ongoing operation, the system continually checks whether the initially estimated plausible states (from when the system was first compromised) remain within the safe bounds over time.
This involves recalculating and projecting the states every few time steps (e.g.,
Simulation and Results
Simulations show the system maintaining safety constraints despite different attack scenarios, though some attacks lead to safety breaches when they cause confusion about certain state variables (e.g.,
The control adjustments closely mirror nominal (intended) controls unless adjustments are necessary to maintain safety.
Overall System Performance
The system effectively handles sensor attacks by adjusting control inputs to ensure that both real and potential (fake) states of the vehicle remain within safety limits.
The approach includes robust measures to verify sensor integrity and dynamically adapt to ensure continuous safe operation under potential cyber-attacks.