kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Unknown Input Observers Breaking Confidentiality of Controller States
KTH, School of Electrical Engineering and Computer Science (EECS), Intelligent systems, Decision and Control Systems (Automatic Control).ORCID iD: 0009-0000-8399-3172
KTH, School of Electrical Engineering and Computer Science (EECS), Intelligent systems, Decision and Control Systems (Automatic Control).ORCID iD: 0000-0003-1835-2963
2024 (English)In: 2024 IEEE 63rd Conference on Decision and Control, CDC 2024, Institute of Electrical and Electronics Engineers (IEEE) , 2024, p. 2373-2378Conference paper, Published paper (Refereed)
Abstract [en]

Driven by ubiquitous digitalization and cyberattacks on critical infrastructure, there is a high interest in research on the security of cyber-physical systems. If an attacker gains access to protected and sensitive information, such as the internal states of a control system, this is considered a breach of confidentiality. Access to sensitive information can be the first step in a larger cyber-attack scheme, such as a stealthy false data injection attack. Considering process and measurement noise in the plant, existing research investigated when an attacker equipped with a Kalman filter can perfectly estimate the internal controller states if the attacker has access to plant measurements and all model parameters. For this estimate to converge, the controller is required to have stable poles. In this paper, we show that if the attacker has access to the control inputs instead of the plant measurements, the controller needs to have stable zeros. Additionally, we demonstrate that an attacker equipped with an Unknown Input Observer, using tools from delayed system inversion, can get a delayed yet perfect estimate of the controller states from the control inputs without knowledge of the plant's parameters and noise characteristics. Lastly, we present simulation results from a three-tank system to showcase the differences in controller state estimation.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE) , 2024. p. 2373-2378
National Category
Control Engineering
Identifiers
URN: urn:nbn:se:kth:diva-361770DOI: 10.1109/CDC56724.2024.10886707ISI: 001445827202010Scopus ID: 2-s2.0-86000644815OAI: oai:DiVA.org:kth-361770DiVA, id: diva2:1948037
Conference
63rd IEEE Conference on Decision and Control, CDC 2024, Milan, Italy, Dec 16 2024 - Dec 19 2024
Note

Part of ISBN 9798350316339

QC 20250401

Available from: 2025-03-27 Created: 2025-03-27 Last updated: 2025-12-05Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Breukelman, EnnoSandberg, Henrik

Search in DiVA

By author/editor
Breukelman, EnnoSandberg, Henrik
By organisation
Decision and Control Systems (Automatic Control)
Control Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 51 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf