Disconnection-aware Attack Detection and Isolation with Separation-based Detector Reconfiguration
Hampei Sasahara, Takayuki Ishizaki, Jun-ichi Imura, Henrik, Sandberg

TL;DR
This paper proposes a method for maintaining attack detection and isolation capabilities in networked control systems even after subsystem disconnection, using a separation-based detector reconfiguration approach grounded in retrofit control techniques.
Contribution
It introduces a disconnection-aware attack detection and isolation scheme with a novel separation-based reconfiguration method utilizing retrofit control.
Findings
The proposed method preserves detection capabilities under disconnection scenarios.
Numerical examples demonstrate effectiveness in power distribution networks.
The approach ensures stability despite network topology changes.
Abstract
This study addresses incident handling during an adverse event for dynamical networked control systems. Incident handling can be divided into five steps: detection, analysis, containment, eradication, and recovery. For networked control systems, the containment step can be conducted through physical disconnection of an attacked subsystem. In accordance with the disconnection, the equipped attack detection unit should be reconfigured to maintain its detection capability. In particular, separating the detection subunit associated with the disconnected subsystem is considered as a specific reconfiguration scheme in this study. This paper poses the problem of disconnection-aware attack detection and isolation with the separation-based detector reconfiguration. The objective is to find an attack detection unit that preserves its detection and isolation capability even under any possible…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Infrastructure Resilience and Vulnerability Analysis · Network Security and Intrusion Detection
