数字孪生退化:通过时间不一致性检测网络物理攻击
Digital Twin Degradation: Detecting Cyber Physical Attacks via Temporal Inconsistencies
浏览论文内容
中文总结 AI 辅助
该研究提出一种基于多时间范围特征与无监督密度模型的检测框架,利用数字孪生与物理系统的时间不一致性,在无需攻击标签的情况下实现工业控制系统的可靠攻击检测,误报率低且对数字孪生退化场景有效。
中文摘要 AI 辅助
数字孪生(Digital Twins, DTs)正越来越多地用于监控和分析网络物理系统(Cyber Physical Systems, CPS)。然而,在对抗环境中,不能假设数字孪生的保真度。通信延迟、数据操纵、传感器退化或部分信息丢失可能导致数字孪生状态与其所代表的物理过程产生偏差。这种偏差会产生时间不一致性,可能揭示网络物理攻击。本文提出一种检测框架,用于监控物理系统与潜在退化的数字孪生视图之间的时间一致性。专门在正常系统行为上训练数字孪生预测器,以建模短期系统动态。运行期间,将预测状态与观测状态之间的差异转换为多时间范围的时间特征,捕捉预测残差的幅度、持续性和演变。无监督密度模型表征正常一致性模式,而序列变化检测机制识别指示攻击的持续偏差。该方法在三个广泛使用的工业控制系统(Industrial Control System, ICS)数据集——SWaT、HAI和BATADAL上,在多种数字孪生退化场景(包括时间失步和部分可观测性丢失)下进行评估。结果表明,时间不一致性模式能够实现可靠的事件级攻击检测,且具有有界误报率和低检测延迟。所提方法在SWaT上实现高达98%的检测可靠性,误报率低于2%。与传统异常检测方法不同,该框架不需要攻击特征或带标签的攻击数据,即使在数字孪生视图退化时仍保持有效。这些结果表明,通常被视为局限性的数字孪生退化,反而可作为网络物理安全监控的有用信号。
英文摘要
Digital Twins (DTs) are increasingly used to monitor and analyze Cyber Physical Systems (CPS). However, in adversarial environments, the fidelity of a DT cannot be assumed. Communication delays, data manipulation, sensor degradation, or partial information loss may cause the DT state to diverge from the physical process it represents. Such divergence creates temporal inconsistencies that may reveal cyber physical attacks. This paper proposes a detection framework that monitors temporal consistency between the physical system and a potentially degraded DT view. A DT predictor is trained exclusively on normal system behavior to model short-term system dynamics. During operation, discrepancies between predicted and observed states are transformed into multi-horizon temporal features capturing the magnitude, persistence, and evolution of prediction residuals. An unsupervised density model characterizes normal consistency patterns, while a sequential change detection mechanism identifies sustained deviations indicative of attacks. The approach is evaluated on three widely used Industrial Control System (ICS) datasets, SWaT, HAI, and BATADAL, under multiple DT degradation scenarios, including time desynchronization and partial observability loss. Results show that temporal inconsistency patterns enable reliable event-level attack detection with bounded false alarm rates and low detection latency. The proposed method achieves up to 98% detection reliability on SWaT and false alarm rates below 2%. Unlike conventional anomaly detection methods, the proposed framework does not require attack signatures or labeled attack data and remains effective even when the DT view is degraded. These results suggest that DT degradation, often treated as a limitation, can instead serve as a useful signal for cyber physical security monitoring.
发表机构
- Norwegian University of Science and Technology (NTNU)(挪威科技大学)
机构由 AI 辅助整理,请以论文原文为准。