arXiv:2603.13003cs.ROcs.SY2026-03中稿 · ICRA被引 1

提出主动防御机制,让机械臂在遭隐蔽攻击时仍能稳定运行并减少误差。

From Passive Monitoring to Active Defence: Resilient Control of Manipulators Under Cyberattacks

  • 用新型无测量状态预测器生成异常评分,动态调整控制输入
  • 仿真显示6自由度机械臂攻击导致的末端偏差大幅降低
  • 适合关注机器人安全与抗攻击能力的研究者

网络物理机器人系统易受虚假数据注入攻击(FDIA)影响,攻击者篡改传感器信号却避开基于残差的被动检测机制(如卡方检验),导致末端执行器出现显著偏差而不触发警报。本文研究冗余机械臂对这类隐蔽攻击的鲁棒性,推动从被动监测转向主动防御。构建包含反馈线性化机械臂、稳态卡尔曼滤波器和卡方检验异常检测器的闭环模型。在此基础上,提出一种控制层主动防御策略:通过一个单调函数对由新型执行器投影、无测量状态预测器生成的异常评分进行处理,抑制控制输入。该设计提供名义控制损失的概率保证,并保持闭环稳定性。从攻击者视角,推导出求解单步最优隐蔽攻击的凸二次约束二次规划(QCQP)。在6自由度平面机械臂上的仿真表明,所提防御方法显著降低攻击引发的末端偏差,同时在无攻击时维持正常任务性能。

原文摘要 · Abstract (English)

Cyber-physical robotic systems are vulnerable to false data injection attacks (FDIAs), in which an adversary corrupts sensor signals while evading residual-based passive anomaly detectors such as the chi-squared test. Such stealthy attacks can induce substantial end-effector deviations without triggering alarms. This paper studies the resilience of redundant manipulators to stealthy FDIAs and advances the architecture from passive monitoring to active defence. We formulate a closed-loop model comprising a feedback-linearized manipulator, a steady-state Kalman filter, and a chi-squared-based anomaly detector. Building on this passive monitoring layer, we propose an active control-level defence that attenuates the control input through a monotone function of an anomaly score generated by a novel actuation-projected, measurement-free state predictor. The proposed design provides probabilistic guarantees on nominal actuation loss and preserves closed-loop stability. From the attacker perspective, we derive a convex QCQP for computing one-step optimal stealthy attacks. Simulations on a 6-DOF planar manipulator show that the proposed defence significantly reduces attack-induced end-effector deviation while preserving nominal task performance in the absence of attacks.

机器人安全对抗攻击主动防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。