arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

测量攻击下的运行时保障:无线接入网络中学习控制的必要且充分可观测性条件

Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks

Yasser Al Eryani

arXiv 2610.00285首次发表:更新:

发表机构

NeuroBazar Inc.(NeuroBazar公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对无线接入网络中学习控制器的运行时保障,提出测量攻击下保障存活的必要且充分条件为2q-稀疏可观测性,并证明逆命题攻击及预算提升机制,为安全部署提供理论界限。

AI 中文摘要

运行时保障将经过验证的备用控制器与不受信任的控制器及切换监视器配对,是接纳学习策略进入安全相关的网络控制的主要途径。其保障依赖于一个它假设而非要求的前提条件:监视器的估计误差为零,或至多是具有可表征速率的随机误差。在移动网络中,许多测量源自不受信任的端点,那里的误差既非零也非随机。我们阐述了这一保障前提并证明了它:在零测量噪声下,当且仅当被控对象相对于安全相关输出是2q-稀疏可观测时,保障才能在对手控制q个信道的情况下幸存。这是攻击支撑集上的功能可观测性,严格弱于全状态可观测性:在我们的拓扑上,每小区中断条件使预算翻倍,而基于总负载的表述使其增至三倍。其逆命题是一种构造性攻击,使安全轨迹与不安全轨迹在观测上不可区分;它击败的是那些信道上的所有监视器,而非单个检测器,且在任何噪声水平下均如此。由于信任划分在部署前是静态且已知的,将对手限制在一个家族内可产生一个限制阈值,高于该阈值时,仅受信任信道即可确定状态,所有不受信任信道可同时被破坏。此处三个不可影响的计数器跨越该阈值,将预算从二提升至六,使放置成为主导杠杆。低于该前提时,监视器面临的是一个前沿而非二分法;集值监视器是最优的,并在残差检验的误拒率下将充分性带入非零噪声。达到触发半径的对手无论如何都拥有开关。同样的论证也适用于任何读取智能体消息而非测量的监视器。秩检验决定预算,且辨识不保留预算,因此已发布的预算必须指明其裕度下限。

英文摘要

Runtime assurance pairs a verified fallback with an untrusted controller and a switching monitor, and is the leading route to admitting learned policies into safety-relevant network control. Its guarantee rests on a condition it assumes rather than requires: that the monitor's estimation error is zero, or at worst stochastic with a characterisable rate. In mobile networks many measurements originate at untrusted endpoints, where the error is neither. We state this assurance precondition and prove it: at zero measurement noise the guarantee survives an adversary controlling $q$ channels if and only if the plant is $2q$-sparse observable with respect to the safety-relevant output. This is functional observability over attack supports, strictly weaker than full-state observability: on our topology a per-cell outage condition doubles the budget and one stated over total offered load triples it. The converse is a constructive attack making a safe and an unsafe trajectory observationally identical; it defeats every monitor on those channels, not one detector, at any noise level. As the trust split is static and known before deployment, confining the adversary to one family yields a confinement threshold, above which trusted channels alone resolve the state and all untrusted channels may be corrupt at once. Three uninfluenceable counters cross it here, lifting the budget from two to six and making placement the dominant lever. Below the precondition the monitor faces a frontier, not a dichotomy; a set-valued monitor is optimal and carries sufficiency into non-zero noise at the residual test's false-rejection rate. An adversary reaching the trigger radius owns the switch regardless. The same argument bounds any monitor reading agent messages rather than measurements. A rank test decides the budget and identification does not preserve it, so a published budget must name its margin floor.

Comments17 pages, 6 figures, 9 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑