arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

LogiC-Diff:将安全属性嵌入人工智能赋能的网络物理系统

LogiC-Diff: Embedding Security Properties Into AI-Enabled Cyber-Physical Systems

Ziyan An, John Stankovic, Meiyi Ma

arXiv 2609.38381首次发表:更新:

发表机构

Vanderbilt University; University of Virginia(范德堡大学; 弗吉尼亚大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出逻辑条件双阶段扩散框架,将STL规范嵌入CPS预测,同时修复输入与细化输出,提升对抗鲁棒性和规范符合性。

AI 中文摘要

人工智能赋能的网络物理系统(CPS)极易受到对抗性和异常输入的影响,其中微小的扰动可能引发级联错误和不安全的控制动作。现有方法,如基于规则的过滤、训练时正则化或基于扩散的重建,要么在模型外部运行,要么缺乏将形式化安全规范纳入预测过程的机制。在本文中,我们迈出了将安全属性直接嵌入人工智能赋能的CPS的第一步,使预测模型能够在推理期间执行系统级约束,而不是依赖外部防御。我们引入了一个逻辑条件双阶段扩散框架,将信号时序逻辑(STL)规范集成到预测中。STL作为一等条件信号,指导输入修复阶段和输出细化阶段,使模型能够共同缓解对抗性扰动并强制执行所需的时序行为,以满足安全关键属性。我们在两个真实世界的多变量CPS预测数据集上,针对多种物理传感器和网络攻击评估了我们的方法。在传感器故障、基于梯度的攻击、自适应攻击以及不同攻击强度下,我们的方法持续提高了鲁棒性和规范符合性,随着攻击强度的增加而更优雅地退化,并且对未见过的攻击具有更好的泛化能力。关于规范覆盖率和质量的消融研究进一步表明,嵌入逻辑安全属性所获得的收益是仅基于重建的方法无法实现的,这突显了将形式化方法与生成模型集成在安全CPS中的新方向。

英文摘要

AI-enabled Cyber-Physical Systems (CPS) are highly vulnerable to adversarial and anomalous inputs, where small perturbations can induce cascading errors and unsafe control actions. Existing approaches, such as rule-based filtering, training-time regularization, or diffusion-based reconstruction, either operate outside the model or lack mechanisms to incorporate formal security specifications into the prediction process. In this paper, we take the first step toward embedding security properties directly into AI-enabled CPS, enabling predictive models to enforce system-level constraints during inference rather than relying on external defenses. We introduce a logic-conditioned bi-stage diffusion framework that integrates Signal Temporal Logic (STL) specifications into forecasting. STL serves as a first-class conditioning signal that guides both an input repair stage and an output refinement stage, allowing the model to jointly mitigate adversarial perturbations and enforce desired temporal behaviors to satisfy security-critical properties. We evaluate our approach on two real-world multivariate CPS forecasting datasets under a diverse set of physical sensor and cyber attacks. Across sensor faults, gradient-based attacks, adaptive attacks, and varying attack strengths, our method consistently improves robustness and specification compliance, degrades more gracefully as attack strength increases, and generalizes better to unseen attacks. Ablation studies on specification coverage and quality further show that embedding logical security properties yields gains unattainable by reconstruction-based methods alone, highlighting a new direction for integrating formal methods with generative models in secure CPS.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑