kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Liu, Hanxiao
Publications (6 of 6) Show all publications
Liu, H., Ni, Y., Xie, L. & Johansson, K. H. (2022). How vulnerable is innovation-based remote state estimation: Fundamental limits under linear attacks. Automatica, 136, 110079, Article ID 110079.
Open this publication in new window or tab >>How vulnerable is innovation-based remote state estimation: Fundamental limits under linear attacks
2022 (English)In: Automatica, ISSN 0005-1098, E-ISSN 1873-2836, Vol. 136, p. 110079-, article id 110079Article in journal (Refereed) Published
Abstract [en]

This paper is concerned with the problem of how secure the innovation-based remote state estimation can be under linear attacks. A linear time-invariant system equipped with a smart sensor is studied. A metric based on Kullback–Leibler divergence is adopted to characterize the stealthiness of the attack. The adversary aims to maximize the state estimation error covariance while stay stealthy. The maximal performance degradations that an adversary can achieve with any linear first-order false-data injection attack under strict stealthiness for vector systems and ε-stealthiness for scalar systems are characterized. We also provide an explicit attack strategy that achieves this bound and compare this attack strategy with strategies previously proposed in the literature. Finally, some numerical examples are given to illustrate the results. 

Place, publisher, year, edition, pages
Elsevier BV, 2022
Keywords
Invariance, Linear time-invariant system, Time varying control systems, Attack strategies, Error covariances, Estimation errors, False data injection attacks, First order, IS innovations, Kullback Leibler divergence, Performance degradation, Remote state estimations, State estimation
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-313623 (URN)10.1016/j.automatica.2021.110079 (DOI)000820880400028 ()2-s2.0-85120806475 (Scopus ID)
Note

QC 20220609

Available from: 2022-06-09 Created: 2022-06-09 Last updated: 2022-07-21Bibliographically approved
Liu, H., Li, Y., Johansson, K. H., Mårtensson, J. & Xie, L. (2022). Rollout approach to sensor scheduling for remote state estimation under integrity attack. Automatica, 144, Article ID 110473.
Open this publication in new window or tab >>Rollout approach to sensor scheduling for remote state estimation under integrity attack
Show others...
2022 (English)In: Automatica, ISSN 0005-1098, E-ISSN 1873-2836, Vol. 144, article id 110473Article in journal (Refereed) Published
Abstract [en]

We consider the sensor scheduling problem for remote state estimation under integrity attacks. We seek to optimize a trade-off between the energy consumption of communications and the state estimation error covariance when the acknowledgment (ACK) information, sent by the remote estimator to the local sensor, is compromised. The sensor scheduling problem is formulated as an infinite horizon discounted optimal control problem with infinite states. We first analyze the underlying Markov decision process (MDP) and show that the optimal scheduling without ACK attack is of the threshold type. Thus, we can simplify the problem by replacing the original state space with a finite state space. For the simplified MDP, when the ACK is under attack, the problem is modeled as a partially observable Markov decision process (POMDP). We analyze the induced MDP that uses a belief vector as its state for the POMDP. We investigate the properties of the exact optimal solution via contractive models and show that the threshold type of solution for the POMDP cannot be readily obtained. A suboptimal solution is then obtained via a rollout approach, which is a prominent class of reinforcement learning (RL) methods based on approximation in value space. We present two variants of rollout and provide performance bounds of those variants. Finally, numerical examples are used to demonstrate the effectiveness of the proposed rollout methods by comparing them with a finite history window approach that is widely used in RL for POMDP.

Place, publisher, year, edition, pages
Elsevier BV, 2022
National Category
Environmental Sciences Orthopaedics Clinical Medicine
Identifiers
urn:nbn:se:kth:diva-316730 (URN)10.1016/j.automatica.2022.110473 (DOI)000837854100004 ()2-s2.0-85134186564 (Scopus ID)
Note

QC 20220830

Available from: 2022-08-30 Created: 2022-08-30 Last updated: 2025-02-18Bibliographically approved
Liu, H., Mo, Y. & Johansson, K. H. (2021). Active Detection Against Replay Attack: A Survey on Watermark Design for Cyber-Physical Systems. In: Lecture Notes in Control and Information Sciences: (pp. 145-171). Springer Science and Business Media Deutschland GmbH
Open this publication in new window or tab >>Active Detection Against Replay Attack: A Survey on Watermark Design for Cyber-Physical Systems
2021 (English)In: Lecture Notes in Control and Information Sciences, Springer Science and Business Media Deutschland GmbH , 2021, p. 145-171Conference paper, Published paper (Refereed)
Abstract [en]

Watermarking is a technique that embeds digital information, “watermark”, in a carrier signal to identify ownership of the signal or verify the authenticity or integrity of the carrier signal. It has been widely employed in the fields of image and signal processing. In this chapter, we survey some recent physical watermark design approaches for Cyber-Physical Systems (CPS). We focus on how to design physical watermarking to actively detect cyber-attacks, especially replay attacks, thereby securing the CPS. First, the system and the attack model are introduced. A basic physical watermarking scheme, which leverages a random noise as a watermark to detect the attack, is discussed. The optimal watermark signal is designed to achieve a trade-off between control performance and intrusion detection. Based on this scheme, several extensions are also presented, such as watermarks generated by a hidden Markov model and online data-based watermark generation. These schemes all use an additive watermarking signal. A multiplicative watermark scheme is also presented. The chapter is concluded with a discussion on some open problems on watermark design. 

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2021
Keywords
Cyber Physical System, Economic and social effects, Embedded systems, Hidden Markov models, Intrusion detection, Network security, Signal processing, Surveys, Control performance, Cyber-physical systems (CPS), Design approaches, Digital information, Watermark generations, Watermark scheme, Watermark signals, Watermarking schemes, Watermarking
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-309953 (URN)10.1007/978-3-030-65048-3_8 (DOI)2-s2.0-85107928519 (Scopus ID)
Note

QC 20220316

Available from: 2022-03-16 Created: 2022-03-16 Last updated: 2022-06-25Bibliographically approved
Liu, H., Mo, Y., Yan, J., Xie, L. & Johansson, K. H. (2020). An Online Approach to Physical Watermark Design. IEEE Transactions on Automatic Control, 65(9), 3895-3902
Open this publication in new window or tab >>An Online Approach to Physical Watermark Design
Show others...
2020 (English)In: IEEE Transactions on Automatic Control, ISSN 0018-9286, E-ISSN 1558-2523, Vol. 65, no 9, p. 3895-3902Article in journal (Refereed) Published
Abstract [en]

This article considers the problem of designing physical watermark signals in order to optimally detect possible replay attack in a linear time-invariant system, under the assumption that the system parameters are unknown and need to be identified online. We first provide a replay attack model, where an adversary replays the previous sensor data in order to fool the system. A physical watermarking scheme, which leverages a random input as a watermark to detect the replay attack, is then introduced. The optimal watermark signal design problem is cast as an optimization problem, which aims to achieve the optimal trade-off between control performance and intrusion detection. An online watermarking design and system identification algorithm is provided to deal with systems with unknown parameters. We prove that the proposed algorithm converges to the optimal one and characterize the almost sure convergence rate. An industrial process example is provided to illustrate the effectiveness of the proposed strategy.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2020
Keywords
Watermarking, Detectors, Intrusion detection, Mathematical model, Control systems, Convergence, Electronic mail, Cyber-physical system, security, system identification
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-281491 (URN)10.1109/TAC.2020.2971994 (DOI)000565140400013 ()2-s2.0-85090942028 (Scopus ID)
Note

QC 20201021

Available from: 2020-10-21 Created: 2020-10-21 Last updated: 2024-03-18Bibliographically approved
Liu, H., Ni, Y., Xie, L. & Johansson, K. H. (2020). An Optimal Linear Attack Strategy on Remote State Estimation. In: IFAC PAPERSONLINE: . Paper presented at 21st IFAC World Congress on Automatic Control - Meeting Societal Challenges, JUL 11-17, 2020, ELECTR NETWORK (pp. 3527-3532). Elsevier BV, 53(2)
Open this publication in new window or tab >>An Optimal Linear Attack Strategy on Remote State Estimation
2020 (English)In: IFAC PAPERSONLINE, Elsevier BV , 2020, Vol. 53, no 2, p. 3527-3532Conference paper, Published paper (Refereed)
Abstract [en]

This work considers the problem of designing an attack strategy on remote state estimation under the condition of strict stealthiness and 6-stealthiness of the attack. An attacker is assumed to be able to launch a linear attack to modify sensor data. A metric based on Kullback-Leibler divergence is adopted to quantify the stealthiness of the attack. We propose a generalized linear attack based on past attack signals and the latest innovation. We prove that the proposed approach can obtain an attack which can cause more estimation performance loss than linear attack strategies recently studied in the literature. The result thus provides a bound on the tradeoff between available information and attack performance, which is useful in the development of mitigation strategies. Finally, some numerical examples are given to evaluate the performance of the proposed strategy. 

Place, publisher, year, edition, pages
Elsevier BV, 2020
Keywords
Cyber-Physical Systems Security, State Estimation, Integrity Attacks
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-298162 (URN)10.1016/j.ifacol.2020.12.1719 (DOI)000652592500569 ()2-s2.0-85107681522 (Scopus ID)
Conference
21st IFAC World Congress on Automatic Control - Meeting Societal Challenges, JUL 11-17, 2020, ELECTR NETWORK
Note

QC 20210802

Available from: 2021-08-02 Created: 2021-08-02 Last updated: 2022-06-25Bibliographically approved
Liu, H., Li, Y., Mårtensson, J., Xie, L. & Johansson, K. H. (2020). Reinforcement Learning Based Approach for Flip Attack Detection. In: Proceedings of the IEEE Conference on Decision and Control: . Paper presented at 59th IEEE Conference on Decision and Control, CDC 2020, 14 December 2020 through 18 December 2020 (pp. 3212-3217). Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>Reinforcement Learning Based Approach for Flip Attack Detection
Show others...
2020 (English)In: Proceedings of the IEEE Conference on Decision and Control, Institute of Electrical and Electronics Engineers Inc. , 2020, p. 3212-3217Conference paper, Published paper (Refereed)
Abstract [en]

This paper addresses the detection problem of flip attacks to sensor network systems where the attacker flips the distribution of manipulated sensor measurements of a binary state. The detector decides to continue taking observations or to stop based on the sensor measurements, and the goal is to have the flip attack recognized as fast as possible while trying to avoid terminating the measurements when no attack is present. The detection problem can be modeled as a partially observable Markov decision process (POMDP) by assuming an attack probability, with the dynamics of the hidden states of the POMDP characterized by a stochastic shortest path (SSP) problem. The optimal policy of the SSP solely depends on the transition costs and is independent of the assumed attack possibility. By using a fixed-length window and suitable feature function of the measurements, a Markov decision process (MDP) is used to approximate the behavior of the POMDP. The optimal solution of the approximated MDP can then be solved by any standard reinforcement learning methods. Numerical evaluations demonstrates the effectiveness of the method.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2020
Keywords
Learning systems, Markov processes, Numerical methods, Sensor networks, Stochastic systems, Detection problems, Markov Decision Processes, Optimal solutions, Partially observable Markov decision process, Reinforcement learning method, Sensor measurements, Sensor network systems, Stochastic shortest paths, Reinforcement learning
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-301207 (URN)10.1109/CDC42340.2020.9303818 (DOI)000717663402086 ()2-s2.0-85099875545 (Scopus ID)
Conference
59th IEEE Conference on Decision and Control, CDC 2020, 14 December 2020 through 18 December 2020
Funder
Knut and Alice Wallenberg FoundationSwedish Foundation for Strategic ResearchSwedish Research Council
Note

QC 20220201

Available from: 2021-09-07 Created: 2021-09-07 Last updated: 2024-01-10Bibliographically approved
Organisations

Search in DiVA

Show all publications