arXiv AI

Digital Twin Degradation: Detecting Cyber Physical Attacks via Temporal Inconsistencies

arXiv:2608. 16159v1 Announce Type: cross Abstract: Digital Twins (DTs) are increasingly used to monitor and analyze Cyber Physical Systems (CPS).

arXiv Machine Learning
Aug 19

Digital Twin-Based Intrusion Detection for Vehicle Powertrain CAN Bus Systems

The paper presents a digital‑twin (DT) based intrusion detection system (IDS) for vehicle powertrain CAN bus traffic, modeling physical relationships among decoded signals to detect payload‑manipulation attacks that preserve normal timing and sequencing. Using a shared‑encoder LSTM trained on 17 Hyundai/Kia CAN signals, the DT flags anomalies when residuals exceed a threshold, achieving high detection rates (up to 94.6%) for stealthy attacks such as continuous drift and masquerade, while a range‑and‑plausibility baseline fails to detect them. The study demonstrates that learning coupled vehicle dynamics enables detection of payload‑level attacks that evade traditional timing‑based IDSs, though false positives remain a challenge.

By Araf Rahman, M Sabbir Salek, Mashrur Chowdhury
arXiv AI
3d ago

LogiC-Diff: Embedding Security Properties Into AI-Enabled Cyber-Physical Systems

The paper introduces LogiC-Diff, a logic-conditioned bi-stage diffusion framework that embeds Signal Temporal Logic (STL) specifications into AI-enabled cyber‑physical system (CPS) forecasting models. By using STL as a conditioning signal, the method repairs inputs and refines outputs to jointly mitigate adversarial perturbations and enforce desired temporal behaviors. Experiments on two real‑world CPS datasets show that LogiC-Diff consistently improves robustness and specification compliance across various sensor faults and cyber attacks, outperforming reconstruction‑based defenses.

By Ziyan An, John Stankovic, Meiyi Ma
arXiv AI
Sep 10

Towards a Resilience-Theoretic Foundation for Adversarial Robustness in Industrial Control System Anomaly Detection

The paper argues that adversarial robustness of anomaly detectors in industrial control systems (ICS) is a specific form of system resilience. It maps resilience concepts—disturbance class, absorption capacity, recovery trajectory, and degradation function—to adversarial machine learning, deriving a compositional resilience bound that identifies the coupling‑adjusted absorption capacity of nodes along an attack path as the key constraint. Empirical tests on the BATADAL water distribution benchmark reveal operationally significant effects, such as absorption‑degradation divergence under adversarial training and a paradox where hardening the most vulnerable node alone can reduce overall resilience.

By Branka Stojanovi\'c, Andreas Flatscher, Michael Somma