Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “embedded and cyber-physical systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Generative Vulnerability Assessment for Cyber-Physical Systems

Cyber-physical systems (CPS) are highly susceptible to malicious attacks due to their complex dynamics and interconnectivity. A comprehensive understanding of their vulnerabilities is essential for designing effective resilience measures. This paper presents a data-driven attack generative system for evaluating the vulnerability of CPS. The proposed approach formulates the vulnerability assessment problem as determining the feasibility of a specific attack set based on two boundary functions that represent the effectiveness and stealthiness of attacks. The attack generative model is trained using a custom loss function, with two universal approximators designed to learn the effectiveness and stealthiness functions simultaneously. Theoretical results for successful generation and asymptotic convergence of the resulting training algorithm are given. As a result, the proposed approach is evaluated via numerical simulation of an IEEE 14-bus system and gas pipeline systems, demonstrating its viability in learning how to attack nonlinear CPS and identify potential vulnerabilities.

Computer systems organization↗

Hypergames and Cyber-Physical Security for Control Systems

The identification of the Stuxnet worm in 2010 provided a highly publicized example of a cyber attack that physically damaged an industrial control system. This raised public awareness about the possibility of similar attacks against other industrial targets—including critical infrastructure. Here, we use hypergames to analyze how strategic perturbations of sensor readings and calibrated parameters can be used to manipulate a system that employs optimal control. Hypergames form an extension of game theory that enables us to model strategic interactions where the players may have significantly different perceptions of the game(s) they are playing. Past work with hypergames has focused on relatively simple interactions consisting of a small set of discrete choices for each player. Here, we apply single-stage hypergames to larger systems with continuous variables. We find that manipulating constraints can be a more effective attacker strategy than manipulating objective function parameters. Moreover, the attacker need not change the underlying system to carry out a successful attack—it may be sufficient to deceive the defender controlling the system. It is possible to scale our approach up to even larger systems, but this will depend on the characteristics of the system in question, and we identify several characteristics that will make those systems amenable to hypergame analysis.

97 MATHEMATICS AND COMPUTING↗

A Self-Sustained CPS Design for Reliable Wildfire Monitoring

Continuous monitoring of areas nearby the electric grid is critical for preventing and early detection of devastating wildfires. Existing wildfire monitoring systems are intermittent and oblivious to local ambient risk factors, resulting in poor wildfire awareness. Ambient sensor suites deployed near the gridlines can increase the monitoring granularity and detection accuracy. However, these sensors must address two challenging and competing objectives at the same time. First, they must remain powered for years without manual maintenance due to their remote locations. Second, they must provide and transmit reliable information if and when a wildfire starts. The first objective requires aggressive energy savings and ambient energy harvesting, while the second requires continuous operation of a range of sensors. To the best of our knowledge, this paper presents the first self-sustained cyber-physical system that dynamically co-optimizes the wildfire detection accuracy and active time of sensors. The proposed approach employs reinforcement learning to train a policy that controls the sensor operations as a function of the environment (i.e., current sensor readings), harvested energy, and battery level. Here, the proposed cyber-physical system is evaluated extensively using real-life temperature, wind, and solar energy harvesting datasets and an open-source wildfire simulator. In long-term (5 years) evaluations, the proposed framework achieves 89% uptime, which is 46% higher than a carefully tuned heuristic approach. At the same time, it averages a 2-minute initial response time, which is at least 2.5× faster than the same heuristic approach. Furthermore, the policy network consumes 0.6 mJ per day on the TI CC2652R microcontroller using TensorFlow Lite for Micro, which is negligible compared to the daily sensor suite energy consumption.

54 ENVIRONMENTAL SCIENCES↗

CYDRES: CYber Defense and REsilient System for securing grid-interactive efficient buildings

Smart buildings, especially Grid-interactive Efficient Buildings (GEBs), suffer from cyber-attacks and physical faults due to the integration of a large number of sensors and controls, connected devices, and associated communication networks. This study demonstrated a real-time advanced building resilient platform, called CYber Defense and REsilient System (CYDRES), which is deployable for existing and emerging Building Automation Systems (BASs). CYDRES aims to empower GEBs with cyber-attack-immune capabilities through multi-layer prevention and adaptation mechanisms to monitor, detect, and respond to cyber-attacks and physical operational faults. CYDRES is demonstrated through real-time experiments in a Hardware-in-the-Loop (HIL) testbed.

Building automation system, Cyber-attacks, Physica↗

Runtime Analysis with R2U2: A Tool Exhibition Report

We present R2U2 (Realizable, Responsive, Unobtrusive Unit), a hardware- supported tool and framework for the continuous monitoring of safetycritical and embedded cyber-physical systems.With the widespread advent of autonomous systems such as Unmanned Aerial Systems (UAS), satellites, rovers, and cars, real-time, on-board decision making requires unobtrusive monitoring of properties for safety, performance, security, and system health. R2U2 models combine past-time and future-time Metric Temporal Logic, “mission time” Linear Temporal Logic, probabilistic reasoning with Bayesian Networks, and modelbased prognostics. The R2U2 monitoring engine can be instantiated as a hardware solution, running on an FPGA, or as a software component. The FPGA realization enables R2U2 to monitor complex cyber-physical systems without any overhead or instrumentation of the flight software. In this tool exhibition report, we present R2U2 and demonstrate applications on system runtime monitoring, diagnostics, software health management, and security monitoring for a UAS. Our tool demonstration uses a hardware-based processor-in-the-loop “iron-bird” configuration.

Johann Martin Schumann↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Unobtrusive Software and System Health Management with R2U2 on a Parallel MIMD Coprocessor

Dynamic monitoring of software and system health of a complex cyber-physical system requires observers that continuously monitor variables of the embedded software in order to detect anomalies and reason about root causes. There exists a variety of techniques for code instrumentation, but instrumentation might change runtime behavior and could require costly software re-certification. In this paper, we present R2U2E, a novel realization of our real-time, Realizable, Responsive, and Unobtrusive Unit (R2U2). The R2U2E observers are executed in parallel on a dedicated 16-core EPIPHANY co-processor, thereby avoiding additional computational overhead to the system under observation. A DMA-based shared memory access architecture allows R2U2E to operate without any code instrumentation or program interference.

Schumann, Johann↗

Cybersecurity Platform and Certification Framework Development for Extreme Fast Charging (XFC)-Integrated Charging Ecosystem (Final Project Report)

This report summarizes a pioneering effort in Electric Vehicle charging infrastructure ecosystem cybersecurity requirements, assessment methodologies, functional verification, as well as embodiment of the key technologies in the form of hardware and software tools being made available to the public. EPRI led a team of experts, as well as a stakeholder coalition encompassing all key actors in the EV charging infrastructure ecosystem that includes eXtreme Fast Charging (XFC) equipment (defined as 200kW or above). EV charging infrastructure in the United States is a patchwork of networks that have continued to grow organically and have been designed to serve the charging needs of the EV owners, who are their customers. In doing so, each network provider, as well as their connected entities such as the cloud Electric Vehicle Service Providers or EVSPs, utility back office, utility AMI networks, payment networks, as well as Original Equipment Manufacturer (EV manufacturer) telematics networks, have designed systems that may work well individually, but no single entity is responsible for the entire ecosystem to be secure in terms of data exchange. Furthermore, there is no uniformity in how each actor has implemented the cybersecurity requirements since no system-wide cybersecurity requirements existed prior to this project. The final project report describes the technical approach guided by the EV charging infrastructure cybersecurity working group, convened specifically for this project. The technical approach included definition of requirements at the ecosystem level, treated as a ‘system of systems’, and then passed down to individual systems (EVSE, EV, cloud EVSP, utility, and the payment networks), followed by developing the cybersecurity risk and vulnerability assessment methods, that were later applied to real-world cyber-physical systems at EPRI, ANL, and NREL laboratories, to validate both the process and the results. Finally, in a spotlight over the most vulnerable equipment, which is the EV charge station (AC or DC), the team developed a multi-layer cybersecurity implementation in the embedded domain embodied by the open-source Secure Network Interface Card (SNIC) demonstrating the various ways in which the infrastructure can be secured protecting against the identified attack surfaces. Finally, the entire process of EV infrastructure cybersecurity assessment was encapsulated in the Electric Vehicle Charging Cybersecurity Management (EVC2M) online GUI-based tool, that is expected to be released to the public. The report presents the objectives, the technical approach, the key results, and recommendations for future work.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Secure Firmware Update and Device Authentication for Smart Inverters using Blockchain and Physically Uncloable Function (PUF)-Embedded Security Module

Cybersecurity of inverters has been significantly important as inverters become smarter in cyber-physical environments. However, firmware security of smart inverters against firmware attacks from various attack vectors has been less studied. Furthermore, this paper proposes a secure firmware update and device authentication method using a blockchain-based public key infrastructure (PKI) management system and a physically unclonable function (PUF)-embedded security module in a smart inverter. The proposed method is validated by experiments.

blockchain↗

Model-Agnostic Algorithm for Real-Time Attack Identification in Power Grid using Koopman Modes

Malicious activities on measurements from sensors like Phasor Measurement Units (PMUs) can mislead the control center operator into taking wrong control actions resulting in disruption of operation, financial losses, and equipment damage. In particular, false data attacks initiated during power systems transients caused due to abrupt changes in load and generation can fool the conventional model-based detection methods relying on thresholds comparison to trigger an anomaly. In this paper, we propose a Koopman mode decomposition (KMD) based algorithm to detect and identify false data attacks in real-time. The Koopman modes (KMs) are capable of capturing the nonlinear modes of oscillation in the transient dynamics of the power networks and reveal the spatial embedding of both natural and anomalous modes of oscillations in the sensor measurements. The Koopman-based spatio-temporal nonlinear modal analysis is used to filter out the false data injected by an attacker. The performance of the algorithm is illustrated on the IEEE 68-bus test system using synthetic attack scenarios generated on GridSTAGE, a recently developed multivariate spatio-temporal data generation framework for simulation of adversarial scenarios in cyber-physical power systems.

Nandanoori, Sai Pushpak↗

R2U2: Tool Overview

R2U2 (Realizable, Responsive, Unobtrusive Unit) is an extensible framework for runtime System HealthManagement (SHM) of cyber-physical systems. R2U2 can be run in hardware (e.g., FPGAs), or software; can monitorhardware, software, or a combination of the two; and can analyze a range of different types of system requirementsduring runtime. An R2U2 requirement is specified utilizing a hierarchical combination of building blocks: temporal formula runtime observers (in LTL or MTL), Bayesian networks, sensor filters, and Boolean testers. Importantly, the framework is extensible; it is designed to enable definitions of new building blocks in combination with the core structure. Originally deployed on Unmanned Aerial Systems (UAS), R2U2 is designed to run on a wide range of embedded platforms, from autonomous systems like rovers, satellites, and robots, to human-assistive ground systems and cockpits. R2U2 is named after the requirements it satisfies; while the exact requirements vary by platform and mission, the ability to formally reason about realizability, responsiveness, and unobtrusiveness is necessary for flight certifiability, safety-critical system assurance, and achievement of technology readiness levels for target systems. Realizability ensures that R2U2 is suficiently expressive to encapsulate meaningful runtime requirements while maintaining adaptability to run on different platforms, transition between different mission stages, and update quickly between missions. Responsiveness entails continuously monitoring the system under test, real-time reasoning, reporting intermediate status, and as-early-as-possible requirements evaluations. Unobtrusiveness ensures compliance with the crucial properties of the target architecture: functionality, certifiability, timing, tolerances, cost, or other constraints.

Rozier, Kristin Y.↗

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS↗

Analysis and Monitoring of Cyber-Physical Systems via Environmental Domain Knowledge & Modeling

While verifying adherence to a specification (i.e., specification-based testing) is important, the results are only as valid as the specification itself. Problematically, verifying a system specification must be done within the context of changing or even unknown environmental domain knowledge that could render the specification ineffective or incorrect. This issue is even more apparent in the context of self-adaptive systems, where uncertainty in both the system configuration and environment can impact the validity of the system. This paper introduces a method to explicitly model domain knowledge of the environment as a secondary system to enable design-time verification against documented environmental assumptions (i.e., those elements external to the system). In addition, run-time monitors are used to detect scenarios in the actual environment not specified by the modeled environmental domain knowledge. Rather than simply identifying unexpected inputs, our approach is able to identify run-time violations of the environmental domain knowledge, even when inputs appear valid based on the domain assumptions embedded in the system specification. These violations can then be used to correspondingly update the system and environmental specifications via automated run-time adaptation or subsequent design-time revisions. We illustrate our approach by applying our method to a running example of a goal-based model of a baby monitor.

Byron DeVries↗

Swarm Mentality: Toward Automatic Swarm State Awareness with Runtime Verification

Cyber-Physical Systems (CPSs) already exhibit impressive performance in all areas of human life, and swarms of CPSs promise to increase their capabilities even further. However, to effectively utilize CPS swarms their complexity of operation has to scale sub-linearly with the number of swarm members. Presenting the swarm to an operator as a single entity almost eliminates the additional per-member overhead entirely. To operate a swarm as one entity, and/or to increase the swarm’s autonomy, the operator and the swarm members need to reason and communicate at the same level of abstraction, i.e. the swarm needs a sense of “self.” Therefore, we require the ability to specify whole swarm properties yet monitor them at the member level. We examine one architecture for achieving this awareness by: 1) Defining a taxonomy for comparing techniques that synthesize this belief-state 2) Propose use of the Runtime Verification formal method to fill this role 3) Present preliminary designs for extending and embedding such a system in the Distributed Spacecraft Autonomy architecture to generate per-member monitors from swarm level specification.

Runtime Verification↗

Parameter Estimation for Decoding Sensor Signals

This paper introduces a parameter estimation approach for decoding digital sensor signals in a cyber-physical system. For unknown or not fully characterized digital sensor data, it can be difficult to decipher a desired signal from background or noise. In a cyber-physical system with networked sensors, we can leverage knowledge of the physical system to inform the decoding of the digital signals. This work in progress is a case study on deciphering commercial vehicle on-board sensor networks that communicate through the Controller Area Network (CAN). By understanding the stock vehicle sensor network, a vehicle can be extended into a scalable research platform with minimal instrumentation. Our challenge was to localize desired sensor signals encoded in network traffic that included other sensor data, control messages, as well as encoding and security overhead. Due to the vehicle’s unknown sensor network, our approach developed methods to efficiently analyze and identify key signals despite the large state-space for potential signal embeddings.

Nice, Matthew↗

Automated Adversary-in-the-Loop Cyber-Physical Defense Planning

Security of cyber-physical systems (CPS) continues to pose new challenges due to the tight integration and operational complexity of the cyber and physical components. To address these challenges, this article presents a domain-aware, optimization-based approach to determine an effective defense strategy for CPS in an automated fashion—by emulating a strategic adversary in the loop that exploits system vulnerabilities, interconnection of the CPS, and the dynamics of the physical components. Our approach builds on an adversarial decision-making model based on a Markov Decision Process (MDP) that determines the optimal cyber (discrete) and physical (continuous) attack actions over a CPS attack graph. The defense planning problem is modeled as a non-zero-sum game between the adversary and defender. We use a model-free reinforcement learning method to solve the adversary’s problem as a function of the defense strategy. We then employ Bayesian optimization (BO) to find an approximate best-response for the defender to harden the network against the resulting adversary policy. This process is iterated multiple times to improve the strategy for both players. We demonstrate the effectiveness of our approach on a ransomware-inspired graph with a smart building system as the physical process. Numerical studies show that our method converges to a Nash equilibrium for various defender-specific costs of network hardening.

97 MATHEMATICS AND COMPUTING↗

Hazard Contribution Modes of Machine Learning Components

Amongst the essential steps to be taken towards developing and deploying safe systems with embedded learning-enabled components (LECs) i.e., software components that use ma- chine learning (ML)—are to analyze and understand the con- tribution of the constituent LECs to safety, and to assure that those contributions have been appropriately managed. This paper addresses both steps by, first, introducing the notion of hazard contribution modes (HCMs) a categorization of the ways in which the ML elements of LECs can contribute to hazardous system states; and, second, describing how argumentation patterns can capture the reasoning that can be used to assure HCM mitigation. Our framework is generic in the sense that the categories of HCMs developed i) can admit different learning schemes, i.e., supervised, unsupervised, and reinforcement learning, and ii) are not dependent on the type of system in which the LECs are embedded, i.e., both cyber and cyber-physical systems. One of the goals of this work is to serve a starting point for systematizing L analysis towards eventually automating it in a tool.

Smith, Colin↗

Development of a Reference Design for a Cyber-Physical System

The purpose of this thesis is to develop a reference design to assist in the selection of security practices in power electronics design. A prototype will be developed from this reference design for evaluation. This evaluation will include a brief cost/benefit analysis to gauge the efficacy of implementing each layer of security throughout the power electronics design process. This thesis will also describe the obstacles and effectiveness of integrating a Trusted Platform Module (TPM) into a cyber-hardened grid-connected device. The TPM device is a secured crypto processor that assists in generating, storing, and restricting the use of cryptographic keys. The emphasis of this research is to establish integrity, authenticity, and confidentiality within a system by providing a baseline of security concerns for segments of the system. This research considers communication, control, and hardware level securities. The scope of this thesis will review the necessary security methods as well as consider the effects these methods have on the embedded system, to assess the desired security to responsiveness trade off. Applying this approach to a design process will alleviate various unknowns of appending security to a power electronics design. This thesis describes the specific vulnerabilities introduced within this grid-edge environment, and how the liabilities within the system can be mitigated. Initially, common security techniques will be considered to establish a guideline to benchmark performance and resource costs of the system. The foundation will be a non-hardened power electronic system platform with industry standard communication protocols. Several security techniques and attack vectors will then be evaluated to contribute to the base level platform. Other fail-safe features take place to gauge progress of the selected approach, non-inclusive to the TPM. Collectively, this investigation will determine a valid experiment by appraising and categorizing resource allocation, performance overhead, and monetary cost analysis results into a reference design. The prototype will then demonstrate methods to relieve common threats that are purposefully implemented into the design.

Blair, Nicholas Paul↗