arrow
Return

Security verification against covert learning attackers

delete2025-07-01
delete0
PRE
AI
R
Ruochen Tai
L
Liyong Lin *
R
Rong Su
DOI:10.1016/j.automatica.2025.112344delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
This work investigates the security verification problem against covert learning attackers. These are attackers that do not know the supervisor model and thus may require passive learning by collecting observations of the system's runs. From the attacker's point of view, any supervisor consistent with the set of observations may have been deployed; thus, a successful attacker needs to remain covert and inflict damage against every supervisor consistent with the set of observations. In such a setting, a supervisor is said to be secure if no covert learning attacker can be successful. We then consider two different setups for the security verification. In the first setup, the attacker can only observe plant events. It is shown that the security verification in this setup can be reduced to verifying the existence of an attacker that is covert and damage-reachable against every supervisor that is consistent with the monitor language (without an explicit tracking of control commands). This is then solved by extending the existing observation-assisted covert attacker synthesis algorithm to the case where the set of observations is a regular set captured by a finite-state automaton. In the second setup, the attacker can observe both plant events and control commands. For this setup, we construct a new structure called unique monitor-embedded bipartite supervisor and prove that the security verification problem can be reduced to checking the existence of an attacker that is covert and damage-reachable against the unique monitor-embedded bipartite supervisor, which can be solved by invoking the existing covert attacker synthesis algorithm against a given supervisor whose model is known to the attacker. (c) 2025 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
Keywords:
Security verification
Learning attacker
Covertness
Unknown supervisor
Observations

Journal

Automatica cover
Automatica
IF:
5.9
Papers:
1.1W
Citations:
5.2W

Organization

H
huazhong univ sci technol
Scholars:
7.7K
Papers: 2.6K
Citations: 3