Optimal Stochastic Injection Attack Strategy Against Discrete Time-Varying System via Moment Matrices

Sheng Gao, Dennis Gramlich, Hao Zhang, Huaicheng Yan, Christian Ebenbauer · IEEE Transactions on Automation Science and Engineering · 2025

This paper investigates injection attacks incorporating stochastic noise against linear discrete time-varying system, which is more general but also more challenging to defend than deterministic injection attacks. Based on the optimization theory and novel key defining matrices, an optimal stochastic injection attack strategy is proposed. Unlike existing strategies, this strategy is stochastic, making it harder for defenders to predict. Therefore, the newly designed attack is expected to be widely used to disrupt system performance. By leveraging estimated data from the observer and the attack input, a virtual residual system is established, which more accurately reflects changes in the system error before and after the attack than the traditional error system. Using the state and output residuals along with the stochastic attack input, two performances are defined to ensure the stealthiness and effectiveness of the attack, respectively. Subsequently, an optimal attack problem with non-convex objective function and constraint is formulated. The key to acquiring the designed optimal stochastic injection attack strategy is to apply a semi-definite relaxation involving moment matrices for transforming this non-convex optimization problem into a convex optimization problem and solving it. Finally, the effectiveness of the proposed attack strategy is validated through numerical simulation of a networked mass-spring-damper system and a V-formation experiment involving three quadrotors. Note to Practitioners—The primary objective of this paper is to focus on the cyber security of discrete time-varying systems from the perspective of the attacker, which provides insight into the way of generating attack strategies under the stochastic case. The majority of existing injection attack strategies against intelligent systems are deterministic, and this can make the attacks less effective as the attacked system reconstructs and compensates for the attack signals, and the attack strategies tend to fail or are mostly ineffective. This paper synthesizes state estimation, semi-definite programming, optimization principles, and control theory to propose an optimal stochastic injection attack strategy. Compared with the deterministic injection attack strategies, the latter is harder to defend. Specifically, the operation of the attacker is divided into two phases: initial data eavesdropping and strategy generation. In the initial data eavesdropping phase, the attacker continuously eavesdrops and stores the initial traffic data of the system for a virtual state residual data estimation. In the strategy generation phase, the attacker generates the attack strategy using semi-definite programming with the help of the measured initial data. The mathematical analytical form of the proposed optimal stochastic injection attack strategy is given in detail. Subsequently, the effectiveness is verified by the numerical simulation and experiment based on a leader-following form consisting of three quadcopters, but not yet tested in production. In the future, we plan to design stochastic injection attack strategies with a data-driven framework.

Read the paper · More papers on PaperTik