用无监督可解释AI实时识别核反应堆信号中的多重重放攻击
An Unsupervised Deep Explainable AI Framework for Localization of Concurrent Replay Attacks in Nuclear Reactor Signals
- 结合自编码器与定制windowSHAP实现无监督攻击检测
- 在真实数据上对6路并发信号重放攻击识别准确率达95%以上
- 适合核能领域安全团队用于定位复杂攻击源头和时间
下一代先进核反应堆将更小型化,依赖全数字化仪控系统,产生大量多变量时间序列数据,涵盖非线性网络物理、过程、控制、传感器及运行状态。保障数据完整性免受欺骗攻击日益关键。现有重放攻击防御方法多聚焦于加水印或有监督异常检测,缺乏根因分析且依赖合成数据、独立高斯噪声、全状态反馈或单变量信号,难以捕捉未建模系统动态。在受监管的核网络物理系统中,亟需基于真实数据的攻击表征与预测可解释性研究。本文提出一种无监督可解释人工智能框架,融合自编码器与定制windowSHAP算法,实现对动态反应堆过程中复杂重放攻击的全面表征:检测、源定位、持续时间和类型。该XAI框架在普渡大学核反应堆PUR-1的真实数据集上进行测试,最高支持六路信号同时被重放,在所有情况下均以95%及以上准确率成功检测并识别被重放信号来源、数量及伪造时长。
原文摘要 · Abstract (English)
Next generation advanced nuclear reactors are expected to be smaller both in size and power output, relying extensively on fully digital instrumentation and control systems. These reactors will generate a large flow of information in the form of multivariate time series data, conveying simultaneously various non linear cyber physical, process, control, sensor, and operational states. Ensuring data integrity against deception attacks is becoming increasingly important for networked communication and a requirement for safe and reliable operation. Current efforts to address replay attacks, almost universally focus on watermarking or supervised anomaly detection approaches without further identifying and characterizing the root cause of the anomaly. In addition, these approaches rely mostly on synthetic data with uncorrelated Gaussian process and measurement noise and full state feedback or are limited to univariate signals, signal stationarity, linear quadratic regulators, or other linear-time invariant state-space which may fail to capture any unmodeled system dynamics. In the realm of regulated nuclear cyber-physical systems, additional work is needed on characterization of replay attacks and explainability of predictions using real data. Here, we propose an unsupervised explainable AI framework based on a combination of autoencoder and customized windowSHAP algorithm to fully characterize real-time replay attacks, i.e., detection, source identification, timing and type, of increasing complexity during a dynamic time evolving reactor process. The proposed XAI framework was benchmarked on several real world datasets from Purdue's nuclear reactor PUR-1 with up to six signals concurrently being replayed. In all cases, the XAI framework was able to detect and identify the source and number of signals being replayed and the duration of the falsification with 95 percent or better accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。