Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “adversarial attack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Securing Distributed Energy Resource Integration

The penetration of distributed energy resources (DER) is growing at much higher rates than predicted 20 years ago. Far from being used only in residential settings, DER are now installed on distribution and transmission circuits. In this position, they do not have the same properties as traditional generators and are more flexible in many cases. The growing penetration and range of uses for DER motivate the need to reliably and safely integrate them into the grid. Operators must be able to rely on them not only for normal operation, but also during abnormal conditions like black starts or adverse cyber scenarios. To that end, we study the communications, device interfaces, and potential consequences of DER operation under abnormal and adversarial conditions. The weaknesses of communications networks are studied based on the industrial protocols used, and the benefits of security features are examined. The device interfaces are found to be vulnerable to attack based on the requirements in the IEEE-1547 standard for DER interconnection and interoperability, which is expected to be adopted in the next ten years. In addition to exploring the requirements of the standard, we show that these vulnerabilities and others do exist and can be used maliciously in a modern storage system DER. Consequences of these vulnerabilities range from exacerbated grid instability, to simultaneous loss of large portions of DER penetration, to physical damage to inverters or DER themselves and other sensitive equipment. We tie these outcomes to specific attacker actions in an effort to give operators a better threat intelligence view that allows them to prioritize mitigations. Finally, we discuss mitigations that could prevent many of the adversarial scenarios described. Some solutions can be added to existing infrastructure, while others may require longer term planning for grid modernization with consideration for security.

25 ENERGY STORAGE↗

Protecting and Defending against Autonomous Control Systems and Digital Twin Cyber Attacks: Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Models in Nuclear Power Plants (Final)

Navigating through the complex tapestry of technological advancements, "Response Strategy for Hyperparameter attacks of Digital Twin Machine Learning Model in Nuclear Power Plants" stands at the intersection of cybersecurity and nuclear power plant operations, embarking on a journey through the intricacies of securing digital twins against malicious cyber activities. As nuclear power plants progressively integrate digital twin technology and machine learning models to optimize operations and ensure system reliability, they inadvertently expose themselves to a new spectrum of vulnerabilities, notably in the realm of hyperparameter attacks. Hyperparameters, integral in machine learning model tuning and optimal performance of digital twins, have emerged as a target for adversaries aiming to destabilize the predictive capabilities and therefore, the operational accuracy of these digital entities within critical infrastructures like nuclear plants. This paper, therefore, meticulously threads the needle through the development of a robust response strategy, poised to shield these digital reflections against calculated hyperparameter manipulations, ensuring that the digital twin can effectively and securely function as a reliable proxy for its physical counterpart. The ensuing sections delve into the orchestrated maelstrom of multi-rate time-changing intelligent coordinated hyperparameter attacks and the implementation of event-triggered predictive control, laying down a structured, predictive, and responsive framework that safeguards the nexus where the digital and physical realms of nuclear power plants coalesce. The operational integrity of digital twins in nuclear power plants depends critically on the security of machine learning hyperparameters. This study makes two different contributions. First, a decision-based idea known as a multi-rate time changing intelligent coordinated hyperparameter attack is put forth. In this attack, many hyperparameters are repeatedly changed using both random and intelligent optimal techniques by the attacker. These assaults introduce varied rates at different attack steps, compromise various amounts of hyperparameters, and improve stealth and flexibility. Second, a technique is developed for event triggered predictive control to rapidly respond to potential hyperparameter attacks. This control integrates a sliding window framework, retaining a history of previous data points and employing linear regression to predict the next data point from the current dataset. The control gain K is determined using the Lyapunov-Krasovskii method, and subsequently, an action is developed. Finally, the outcome of the simulation demonstrates the viability of the proposed method for defending nuclear power plant digital twins from hyperparameter attacks.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Towards Resilient Design of Leader-following Consensus with Attack Identification and Privacy Preservation Capabilities

This paper considers a leader-following consensus in the presence of unknown but bounded cyber-attacks. Specifically, we consider the following cyber-attack scenarios: (i) an attacker aims to destabilize the consensus dynamics by injecting exogenous signals to both the actuators of the followers and/or the communication network, (ii) an eavesdropper adversary aims to obtain information on the physical state of the agents. To this end, a novel resilient leader-following consensus algorithm based on a competitive interaction method is proposed. In addition, it is demonstrated that by appropriately choosing the information exchanged between the agents, the proposed control framework also enables the cooperative system to either distributively identify the compromised communication links in real-time or to protect the privacy of the physical state of the agents from the eavesdropper. Here, a numerical example is provided to illustrate the proposed resilient control algorithms.

Gusrialdi, Azwirman↗

ProvSec: Open Cybersecurity System Provenance Analysis Benchmark Dataset with Labels

System provenance forensic analysis has been studied by a large body of research work. This area needs fine granularity data such as system calls along with event fields to track the dependencies of events. While prior work on security datasets has been proposed, we found a useful dataset of realistic attacks and details that are needed for high-quality provenance tracking is lacking. We created a new dataset of eleven vulnerable cases for system forensic analysis. It includes the full details of system calls including syscall parameters. Realistic attack scenarios with real software vulnerabilities and exploits are used. For each case, we created two sets of benign and adversary scenarios which are manually labeled for supervised machine-learning analysis. In addition, we present an algorithm to improve the data quality in the system provenance forensic analysis. We demonstrate the details of the dataset events and dependency analysis of our dataset cases.

97 MATHEMATICS AND COMPUTING↗

Detecting False Data Injection Attacks in Smart Grids: A Semi-Supervised Deep Learning Approach

The dependence on advanced information and communication technology increases the vulnerability in smart grids under cyber-attacks. Recent research on unobservable false data injection attacks (FDIAs) reveals the high risk of secure system operation, since these attacks can bypass current bad data detection mechanisms. To mitigate this risk, this paper proposes a data-driven learning-based algorithm for detecting unobservable FDIAs in distribution systems. We use autoencoders for efficient dimension reduction and feature extraction of measurement datasets. Further, we integrate the autoencoders into an advanced generative adversarial network (GAN) framework, which successfully detects anomalies under FDIAs by capturing the unconformity between abnormal and secure measurements. Also, considering that the datasets collected from practical power systems are partially labeled due to expensive labeling costs and missing labels, the proposed method only requires a few labeled measurement data in addition to unlabeled data for training. Numerical simulations in three-phase unbalanced IEEE 13-bus and 123-bus distribution systems validate the detection accuracy and efficiency of this method.

97 MATHEMATICS AND COMPUTING↗

A Graph-Net with Node Embeddings to Detect False Data Injection Attacks in Photovoltaic Systems

Distributed energy resources (DER) contribute to the operational stability of the larger power grid both at utility-scale as well as commercial and residential scales in aggregated forms. These DER in-turn are susceptible to increasing cyber threats. An adversary can plug into the same local network that a field photovoltaic (PV) system uses to interconnect its data loggers and inverters and manipulate certain measurements collected from the network or trick existing irradiance and inverter readings through false data injection attacks (FDIA). Control routines that rely on these measurements can propagate the false data, impacting critical decisions that result in a suboptimal operation or even cause intentional harm leading to inverter-tripping or unscheduled loads that need to be shed. To detect FDIA in PV systems, the paper introduces an attention-based graph neural network with node embeddings and applied it to a simple prototypical DC-coupled microgrid with PV, energy storage, and load. The algorithm shows a detection accuracy of up to 98.95%. The proposed FDIA detection technique will provide micro-grid operators with an effective method to safeguard their systems, guaranteeing the secure and reliable operation.

Parvez, Imtiaz [Utah Valley University]↗

Model-Agnostic Algorithm for Real-Time Attack Identification in Power Grid using Koopman Modes

Malicious activities on measurements from sensors like Phasor Measurement Units (PMUs) can mislead the control center operator into taking wrong control actions resulting in disruption of operation, financial losses, and equipment damage. In particular, false data attacks initiated during power systems transients caused due to abrupt changes in load and generation can fool the conventional model-based detection methods relying on thresholds comparison to trigger an anomaly. In this paper, we propose a Koopman mode decomposition (KMD) based algorithm to detect and identify false data attacks in real-time. The Koopman modes (KMs) are capable of capturing the nonlinear modes of oscillation in the transient dynamics of the power networks and reveal the spatial embedding of both natural and anomalous modes of oscillations in the sensor measurements. The Koopman-based spatio-temporal nonlinear modal analysis is used to filter out the false data injected by an attacker. The performance of the algorithm is illustrated on the IEEE 68-bus test system using synthetic attack scenarios generated on GridSTAGE, a recently developed multivariate spatio-temporal data generation framework for simulation of adversarial scenarios in cyber-physical power systems.

Nandanoori, Sai Pushpak↗

Precursor Analysis Report: Remote Access Attack on Oldsmar Water Treatment Facility 2021

The Remote Access Attack on Oldsmar Water Treatment Facility 2021 Precursor Analysis Report leverages publicly available information about the Oldsmar cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. On 5 February 2021, an adversary gained unauthorized remote access to Bruce T. Haddock Water Treatment Plant in Oldsmar, Florida, which provides treated water to 15,000 customers. The adversary accessed the facility’s Supervisory Control and Data Acquisition (SCADA) workstation and human machine interface (HMI) to change the chemical concentration of sodium hydroxide, commonly referred to as lye and used to regulate acidity levels, from 100 parts per million (PPM) to 11,100 PPM. The chemical was raised to lethal levels that if ingested could lead to serious soft tissue damage, burns, or even death. The facility, however, had redundancies and alarms in place to alert personnel of dangerous chemical levels, and facility officials stated it would have taken 24 to 36 hours for the chemical changes to affect the water supply. Researchers and analysts identified six unique techniques utilized during the attack with a total of 23 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Four of the identified techniques used during the Oldsmar cyber attack were precursors to the triggering event. Analysis identified 21 observables associated with these precursor techniques, 20 of which were assessed to have an increased likelihood of being perceived in the minutes preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Anomaly Detection and Mitigation for Wide-Area Damping Control using Machine Learning

In an interconnected multi-area power system, wide-area measurement based damping controllers are used to damp out inter-area oscillations, which jeopardize grid stability and constrain the power flows below to their transmission capacity. The effect of wide-area damping control (WADC) significantly depends on both power and cyber systems. At the cyber system layer, an adversary can inflict the WADC process by compromising either measurement signals, control signals or both. Stealthy and coordinated cyber-attacks may bypass the conventional cybersecurity measures to disrupt the seamless operation of WADC. This paper proposes an anomaly detection (AD) algorithm using supervised Machine Learning and a model-based logic for mitigation. The proposed AD algorithm considers measurement signals (input of WADC) and control signals (output of WADC) as input to evaluate the type of activity such as normal, perturbation (small or large signal faults), attack and perturbation-and-attack. Upon anomaly detection, the mitigation module tunes the WADC signal and sets the control status mode as either wide-area mode or local mode. The proposed anomaly detection and mitigation (ADM) module works inline with the WADC at the control center for attack detection on both measurement and control signals and eliminates the need for ADMs at the geographically distributed actuators. Here, we consider coordinated and primitive data-integrity attack vectors such as pulse, ramp, relay-trip and replay attacks. The performance of the proposed ADM algorithms was evaluated under these attack vector scenarios on a testbed environment for 2-area 4-machine power system. The ADM module shows effective performance with 96:5% accuracy to detect anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber risk assessment and investment optimization using game theory and ML-based anomaly detection and mitigation for wide-area control in smart grids

The electric power grid is increasingly becoming susceptible to cyber attacks that exploit vulnerabilities in the smart grid control, information, and physical layers. Successful cyber attacks can have catastrophic impacts on the social and economic well-being of any nation all over the globe. It has, thus, become imperative to secure the smart grid against such adversarial actions to ensure stable, secure, and reliable operation of the grid. The existing research and industry practices prove to be inadequate in terms of providing pragmatic and effective defense methodologies and measures for long-term cybersecurity planning and real-time cybersecurity for grid operation. For example, existing works lack models that incorporate uncertain behavior of cyber-attackers and pragmatic defense measures for cyber risk assessment and cybersecurity investment optimization which often provide unreliable and strictly qualitative solutions to these problems. At the same time, with the growing number of cyber incidents in the grid, there still exists a need to develop attack-resilient algorithms for wide-area monitoring, protection, and control (WAMPAC) applications like the wide-area voltage control systems (WAVCS) for Flexible AC Transmissions Systems (FACTS) that lack in scalable and feasible solutions from the cybersecurity perspective. This dissertation proposes novel models and methodologies for: (1) Cybersecurity planning, and (2) Cybersecurity for system operation. The cybersecurity planning is achieved through cyber risk assessment and cybersecurity resource investment optimization for long-term cybersecurity of the grid using game theory and attack-defense trees. Cybersecurity for system operation consists of development of cyber anomaly detection and mitigation algorithms for flexible AC transmission system (FACTS) controller-based wide-area voltage control systems (WAVCS) using machine learning (ML), and software defined networking-based moving target defense network routing for achieving real-time cyber-physical security for grid operations. This is followed by hardware-in-the-loop (HIL) implementation and evaluation of these attack prevention, detection, and mitigation algorithms and methodologies showcasing their feasibility in a close to real-world environment. For cybersecurity planning, a novel approach involving a combination of game theory and attack defense trees (ADT) for optimal cybersecurity resource allocation in the smart grid is proposed. This methodology involves modeling of the cyber-physical smart grid substations as ADTs, defining attacker costs, defense costs, and attack probabilities for attack access points. Using game theoretical formulation, optimal defense strategies for the defender of the system to invest cybersecurity resources in the grid are obtained. Additionally, a game-theoretic framework is developed for quantitative cyber-physical risk assessment of the grid under a dynamically changing cyber threat space and uncertain behavior of cyber attackers which is further used to optimize investments in the smart grid's cybersecurity resources. The attacker, defender, and the smart grid system are modeled while incorporating attacker-stochasticity and federal guidelines for smart grid cybersecurity. This allows quantification of threat, vulnerabilities, and attack impact of the grid for quantitative risk assessment. The defender's budget to invest in the security resources in the grid is optimized based on the strategies leading to minimum system risk. The evaluation of the proposed solutions highlight the feasibility for practical implementation of these methodologies and algorithms in the smart grid, while taking the federal requirements and guidelines for smart grid security into consideration. For achieving cybersecurity for system operation, attack prevention, detection, and mitigation algorithms and methodologies are developed specifically for FACTS-based WAVCS. Anomaly detection and mitigation in the WAVCS are achieved using algorithms based on machine learning which involves offline training and testing of ML models with CPS datasets incorporating physics-based features that allow accurate distinction between system faults and cyber attacks. For attack prevention, a methodology based on software defined network (SDN)-based moving target defense (MTD) network routing is proposed that enables prevention of Denial of Service (DoS) type attacks on the smart grid communication system. Subsequently, these methodologies and algorithms are implemented and evaluated on an HIL testbed that allows for real-time attack prevention, detection, and mitigation of emulated cyber attacks on the WAVCS in a close to real-world environment. The results show highly accurate and efficient performance of the implemented algorithms and methodologies with the smart grid system operating within the NERC's system operation limits even in the presence of DoS and data integrity cyber attacks. This work opens up future research opportunities in other directions such as (1) Expanding cybersecurity planning methodologies to real-time cyber contingency analysis with different game formulations; and (2) Applying the cybersecurity for system operation algorithms to broader categories of wide-area control applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Machine Learning-based False Data Injection Attack Detection and Localization in Power Grids

Cyberattacks on critical infrastructures can be catastrophic and bring nations to their knees. Therefore, detecting these attacks is crucial and challenging. This paper presents a novel approach for detecting and locating cyberattacks affecting an electrical power system. The adversary employs a man-in-the-middle technique to inject false data into the communication between distributed energy resources (DER) and Microgrid Controller (MGC) with the goal of disrupting power delivery. The approach for detection and localization is based on integrating multiple machine learning-based anomaly detection models that combine network traffic data and grid measurements. Experiments are performed to assess the method's performance using a hardware-in-the-loop real-time simulation testbed which includes Modbus TCP/IP communication. Power system topology and operating conditions are based on actual topology and real-world data provided by the Holy Cross Energy utility network. Results confirm that the method can be successfully employed for detecting and localizing cyberattacks.

Leao, Bruno P.↗

HP in Cybersecurity: CyOTE

The U.S. Department of Energy’s (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER), through the Cybersecurity for the Operational Technology Environment (CyOTE) Program, worked with energy sector asset owners and operators (AOOs), partners, and Idaho National Laboratory (INL) to develop capabilities for AOOs to independently detect adversarial tactics, techniques, and procedures (TTPs) within their operational technology (OT) environments. Unlike the approach taken with commercial security solutions, CyOTE seeks to tie anomalies in cyber operations to a cyber-attack. By stringing together multiple techniques in the OT environment, AOOs can identify attack campaigns with ever decreasing impacts. The CyOTE methodology applies fundamental concepts of perception and comprehension to a universe of knowns and unknowns increasingly disaggregated into observables, anomalies, and triggering events. MITRE’s ATT&CK® Framework for Industrial Control Systems (ICS) is used as a common lexicon to identify a set of triggering events related to three Use Cases – Alarm Logs, Human-Machine Interface (HMI), and Remote Logins – which together account for 87 percent of the techniques commonly used by adversaries. The CyOTE methodology is also appropriate for OT-related anomalies perceived outside the three Use Cases, such as through the energy system itself.

99 GENERAL AND MISCELLANEOUS↗

Decentralised Reinforcement Learning for Dynamic Cyberattack Response in Microgrid Networks

Microgrids rely on communication networks for reliable operation, which makes them inherently vulnerable to cyberattacks. Such attacks can destabilise system dynamics and drive states away from their nominal operating trajectories. Although several physics-informed and machine learning-based strategies have been developed to counter these threats, the rapidly evolving cyber landscape enables adversaries to bypass static defences or rules-based mitigation approaches. This paper proposes a dynamic, online-trained and fully decentralised reinforcement learning (RL)-based cyberattack response framework to protect microgrids from evolving cyberattacks. The proposed framework deploys multiple deep Q-networks (DQNs), each associated with a distributed energy resource (DER), to enable localised and adaptive attack mitigation. In this framework, each DQN processes local voltage and frequency measurements—combined with intrusion detection system (IDS) alerts—as observations and rewards to guide decision-making. Extensive simulation studies demonstrate the robustness of the proposed framework under diverse attack scenarios and varying IDS-induced detection delays. Comparative analysis highlights its superiority over existing static or preexisting rules-based mitigation approaches. Finally, we present an analysis that shows the framework's scalability to real-life microgrids with more interacting agents.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Stability Impact of IEEE 1547 Operational Mode Changes Under High DER Penetration in the Presence of Cyber Adversary

The IEEE 1547 standard addresses the integration of Distributed Energy Resources (DER) into Area Electric Power Systems (AEPS). The updated standard, released in 2018 with revisions ongoing, specifies the need for more flexible settings, requiring the DER to remain connected during certain disturbances and provide voltage support via active and reactive power modes. With these increased capabilities comes increased risks, and our analysis of the standard has produced potential settings combinations, which, while allowable under the standard, may actually create instability. This contradicts the main purpose of the revised standard. Since the DER must support a communication interface through which the AEPS operator can change settings, adversarial mode changes are possible via a cyberattack. This concern is heightened as DER penetration increases, where under a reasonable threat model, an attacker could affect multiple DER simultaneously. We have conducted a simulation analysis of potentially adverse combinations of mode change and ridethrough parameters on a hypothetical AEPS with varying degrees of DER penetration. We conclude that certain adverse mode changes, whether through error or cyberattack, can lead to unstable conditions with DER penetrations as low as 24% of the AEPS system capacity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Model Residuals as Shields: A Two-Level Formulation to Defend Smart Grids From Poisoning Attacks

The advancement of smart grids presents both vast opportunities and heightened cybersecurity risks. Data-driven defense mechanisms, though designed as a shield against these threats, can fall prey to poisoning attacks. We delve into regression settings, underscoring the imperative to fortify defenses against a spectrum of poison ratios, notably those above 0.5—an issue scarcely addressed in prior studies. Recognizing the susceptibilities of smart grids and their manipulable sensors, we exploit the very intent of poisoning attacks, compromising model accuracy, as our defense mechanism. Our proposed two-level optimization framework discerns between poisoned and authentic data based on model residuals, outperforming or matching existing methods in 72% to 77% of precision and 75% to 80% of recalls across various poisoning attacks, poison ratios, and datasets. Once the authentic data are identified, the trained model is adaptable for a variety of applications. Comprehensive evaluations on different smart grid datasets, pitted against myriad poisoning schemes, validate our methodology’s edge over existing methods. Here, we also shed light on the implications of model misspecification originating from temporal auto-correlation, a common feature in Internet of Things and smart grid data.

Adversarial machine learning (ML)↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Systematic Evaluation of Backdoor Data Poisoning Attacks on Image Classifiers

Backdoor data poisoning attacks have recently been demonstrated in computer vision research as a potential safety risk for machine learning (ML) systems. Traditional data poisoning attacks manipulate training data to induce unreliability of an ML model, whereas backdoor data poisoning attacks maintain system performance unless the MLmodel is presented with an input containing an embedded“trigger” that provides a predetermined response advantageous to the adversary. Our work builds upon prior back-door data-poisoning research for ML image classifiers and systematically assesses different experimental conditions including types of trigger patterns, persistence of trigger patterns during retraining, poisoning strategies, architectures (ResNet-50, NasNet, NasNet-Mobile), datasets (Flowers, CIFAR-10), and potential defensive regularization techniques (Contrastive Loss, Logit Squeezing, Manifold Mixup,Soft-Nearest-Neighbors Loss). Experiments yield four key findings. First, the success rate of backdoor poisoning at-tacks varies widely, depending on several factors, including model architecture, trigger pattern and regularization technique. Second, we find that poisoned models are hard to detect through performance inspection alone. Third, regularization typically reduces backdoor success rate, although it can have no effect or even slightly increase it, depending on the form of regularization. Finally, backdoors inserted through data poisoning can be rendered ineffective after just a few epochs of additional training on a small set of clean data without affecting the model’s performance.

Truong, Loc T.↗

A Typing Discipline for High-Assurance Control Systems

This poster describes a typing discipline for high-assurance industrial systems based on three novel type systems. The first type system, information flow control (IFC), controls the flow of data through the system. The second system, dependent session types, restricts messages exchanged during the execution of a communication protocol to avoid dangerous states. The third system uses dimensional analysis to avoid subtle bugs that adversaries can exploit to cause the system to enter a dangerous state. This poster describes how a combination of these approaches can prevent sophisticated cyber attacks, such as the infamous Stuxnet incident, from occurring. In addition, we provide experimental evidence to support the claim that these approaches can be applied in control systems that are resource-constrained.

42 - ENGINEERING↗