Trust, but Verify: ByzTwin-Range, a Digital Twin Cyber-Range for Byzantine Faults
Tadeu Freitas, Jo\~ao Soares, Rolando Martins

TL;DR
ByzTwin-Range introduces a dual-layer digital twin architecture for realistic testing and analysis of Byzantine Fault Tolerance protocols in cyber-physical systems, enhancing resilience and security.
Contribution
It presents a practical, industry-compatible cyber range that enables controlled Byzantine fault injection, stress testing, and vulnerability analysis using live operational data.
Findings
Identifies timing vulnerabilities and misconfigurations affecting BFT guarantees.
Enables continuous validation and adaptive hardening of CPS security.
Supports realistic stress testing with live data and fault injection.
Abstract
Critical infrastructures increasingly rely on interconnected and software-driven Cyber-Physical Systems (CPS), exposing operational processes to both accidental failures and sophisticated adversarial behavior. While Byzantine Fault Tolerant (BFT) protocols offer robustness against arbitrary faults, evaluating their behavior under realistic cyber-physical conditions remains challenging: traditional cyber ranges lack timing fidelity, and testing in production environments is unsafe. This paper introduces ByzTwin-Range, a dual-layer architecture that integrates a production-grade BFT deployment with a Digital Twin (DT) to enable controlled experimentation, stress testing, and Byzantine fault injection using live operational data. The DT mirrors real system state, executes "What-if" analyses through co-simulation and emulation, and identifies synchrony vulnerabilities, i.e., misconfigured…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
