arXiv:2605. 28912v2 Announce Type: replace Abstract: The rapid growth of AI-driven data centers and large-scale energy storage systems is increasing the reliance of power system operation on real-time measurement data and automated decision-making.
By Xin Li, Chenhan Xiao, Jonathan Cohen, Aviad Elyashar, Yang Weng, Rami Puzis
arXiv:2608. 16159v1 Announce Type: cross Abstract: Digital Twins (DTs) are increasingly used to monitor and analyze Cyber Physical Systems (CPS).
By Konstantinos E. Kampourakis, Vasileios Gkioulos, Sokratis Katsikas
arXiv:2606.
By Farhin Farhad Riya, Shahinul Hoque, Yingyuan Yang, Jinyuan Sun, Kevin Tomsovic
arXiv:2608. 11802v1 Announce Type: cross Abstract: Methods to increase the resilience of systems to cyber-attacks become increasingly important.
By Martin Sachenbacher, Martin Leucker, Alexander Weiss, Aliyu Tanko Ali
arXiv:2606. 18599v1 Announce Type: cross Abstract: The Controller Area Network (CAN) protocol is the primary communication standard for Electronic Control Units (ECUs) in modern vehicles, but its lack of encryption and authentication exposes it to a range of security threats.
By Qiqi Liu, Runhan Song, Lei Cui, Heng Zhang, Yuyan Sun, Limin Sun
arXiv:2606. 03381v1 Announce Type: cross Abstract: Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority.
By Maxime Schwarzer, Johannes F. Loevenich, Gustavo S\'anchez, Laurin Holz, Thies M\"ohlenhof, Tobias H\"urten, Roberto Rigolin F. Lopes, Veit Hagenmeyer
The paper introduces LogiC-Diff, a logic-conditioned bi-stage diffusion framework that embeds Signal Temporal Logic (STL) specifications into AI-enabled cyber‑physical system (CPS) forecasting models. By using STL as a conditioning signal, the method repairs inputs and refines outputs to jointly mitigate adversarial perturbations and enforce desired temporal behaviors. Experiments on two real‑world CPS datasets show that LogiC-Diff consistently improves robustness and specification compliance across various sensor faults and cyber attacks, outperforming reconstruction‑based defenses.
By Ziyan An, John Stankovic, Meiyi Ma
Existing automotive intrusion detection systems (IDSs) for the Controller Area Network (CAN) largely target discrepancies in message timing, frequency, or sequencing and cannot detect attacks that pre...
The paper presents a digital‑twin (DT) based intrusion detection system (IDS) for vehicle powertrain CAN bus traffic, modeling physical relationships among decoded signals to detect payload‑manipulation attacks that preserve normal timing and sequencing. Using a shared‑encoder LSTM trained on 17 Hyundai/Kia CAN signals, the DT flags anomalies when residuals exceed a threshold, achieving high detection rates (up to 94.6%) for stealthy attacks such as continuous drift and masquerade, while a range‑and‑plausibility baseline fails to detect them. The study demonstrates that learning coupled vehicle dynamics enables detection of payload‑level attacks that evade traditional timing‑based IDSs, though false positives remain a challenge.
By Araf Rahman, M Sabbir Salek, Mashrur Chowdhury
arXiv:2606. 08473v1 Announce Type: new Abstract: False data injection attacks (FDIAs) introducing small measurement perturbations can still cause large deviations in power system state estimation when the injected signals align with the pseudo-null space of the system model.
By Xin Li, Chenhan Xiao, Jonathan Cohen, Aviad Elyashar, Yang Weng, Rami Puzis
arXiv:2608. 11286v1 Announce Type: cross Abstract: Cyberattack detection in electric vehicle charging infrastructure is complicated by legitimate post-activation revisions to requested energy and departure time.
By Hannan Chen, Roshni Anna Jacob, Jie Zhang
The paper presents a formal model for responding to cyber intrusions in Operational Technology (OT) systems using a Partially Observable Markov Decision Process (POMDP) framework. It incorporates realistic partial observability derived from traffic measurements and develops learning‑based solution methods based on Proximal Policy Optimization (PPO). The resulting response strategies are evaluated on an emulated OT system and shown to be effective against several MITRE attack types for the studied use case.
By Duc Huy Le, Rolf Stadler