arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向工业控制系统异常检测中对抗鲁棒性的韧性理论基础

Towards a Resilience-Theoretic Foundation for Adversarial Robustness in Industrial Control System Anomaly Detection

Branka Stojanović, Andreas Flatscher, Michael Somma

arXiv 2609.07244首次发表:更新:

发表机构

JOANNEUM RESEARCH Forschungsgesellschaft mbH; TU Graz(约阿尼姆研究有限责任公司; 格拉茨工业大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出韧性理论框架,将ICS异常检测的对抗鲁棒性形式化为系统韧性实例,推导组合韧性界,并在BATADAL基准上验证,揭示对抗训练下的吸收-降级分歧及强化约束节点的悖论。

AI 中文摘要

工业控制系统(ICS)和操作技术(OT)环境中的基于异常的入侵检测系统日益需要满足正式的韧性标准:吸收对抗性扰动、在持续攻击下优雅降级以及经过认证的系统级保证。现有的针对信息物理系统的韧性框架在架构层面定义了吸收-恢复-适应轨迹,但未将机器学习异常检测器视为一等组件,在组件级鲁棒性评估与系统级韧性认证之间留下了空白。在本文中,我们确立了ICS异常检测中的对抗鲁棒性是系统韧性的一个具体实例,并通过将四个韧性构造(即扰动类别、吸收能力、恢复轨迹和降级函数)映射到对抗机器学习设置中,形式化了这一联系。我们为异构ICS检测网络推导出一个组合韧性界,表明系统级韧性的约束条件是攻击路径上每个节点的耦合调整吸收能力,而非每节点能力——因此约束节点不一定是最弱节点。在BATADAL供水系统基准上的实证验证表明,所得指标揭示了标准基准无法观察到的具有操作意义的现象:对抗训练下的吸收-降级分歧,以及单独强化约束节点会降低系统级韧性的悖论。本文还讨论了对ICS架构设计和认证标准的影响。

英文摘要

Anomaly-based intrusion detection systems in industrial control systems (ICS) and operational technology (OT) environments are increasingly required to meet formal resilience criteria: absorbed adversarial disturbances, graceful degradation under sustained attack, and certified system-level guarantees. Existing resilience frameworks for cyber-physical systems define absorb-recover-adapt trajectories at the architectural level but do not treat machine learning anomaly detectors as first-class components, leaving a gap between component-level robustness evaluation and system-level resilience certification. In this paper, we establish that adversarial robustness in ICS anomaly detection is a specific instantiation of system resilience, and formalise this connection by mapping four resilience constructs, i.e. disturbance class, absorption capacity, recovery trajectory, and degradation function, onto the adversarial machine learning setting. We derive a compositional resilience bound for heterogeneous ICS detection networks, showing that the binding constraint on system-level resilience is the coupling-adjusted absorption capacity of each node along the attack path, not the per-node capacity -- so the binding node need not be the weakest one. Empirical validation on the BATADAL water distribution system benchmark demonstrates that the resulting metrics surface operationally significant phenomena invisible to standard benchmarks: the absorption-degradation divergence under adversarial training, and the paradox that hardening the binding node in isolation reduces system-level resilience. Implications for ICS architecture design and certification standards are discussed.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑