黑客可植入隐蔽后门,让电力系统故障检测模型失效。
Backdoor Attacks on Fault Detection and Localization in Cyber-Physical Systems

- 在训练数据中注入恶意触发器,诱导模型误判。
- 仅10%污染数据即可使攻击成功率超过90%。
- 适合关注工业系统安全的研究者与工程师。
网络物理系统(CPS)融合感知、通信、计算与控制,支撑智能电网、工业自动化等关键基础设施。在电力领域,各类控制器用于实时检测电压波动等故障并实现负荷均衡。近年来,基于机器学习与深度学习的故障检测与定位框架因其实时性受到广泛关注。然而,这些智能模型易受对抗性攻击,尤其是后门攻击:攻击者在训练数据中注入恶意模式,使模型平时表现正常,但遇到特定触发信号时输出攻击者控制的结果。本文研究了针对现代CPS中故障检测与定位机制的后门攻击威胁,定义其形式并设计触发器,在真实场景下评估其有效性。实验表明,即使仅有10%的样本被污染,攻击仍能成功,且隐蔽性强,极具现实风险。
原文摘要 · Abstract (English)
Cyber-Physical Systems (CPS) integrate sensing, communication, computation, and control to support critical infrastructure, including smart grids, industrial automation, and control systems. In the electrical utility domain, various controllers are used in CPS to ensure the system detects and recovers from faults, such as voltage fluctuations, and to perform load balancing in distribution systems. Machine learning- and deep learning-based fault detection and localization frameworks have recently gained significant attention in CPS for their ability to identify anomalies and operational failures in real time. However, these intelligent models are vulnerable to adversarial machine learning attacks, particularly backdoor attacks. In a backdoor attack, an adversary injects malicious patterns into the training data so that the model behaves normally most of the time but produces attacker-controlled outputs when triggered by specific patterns. This paper investigates the threat of backdoor attacks against fault detection and localization mechanisms in recent ML pipelines used in modern CPS systems. We define these threats and explore how they can be realized by designing triggers and evaluating their success in the CPS domain. Our experiments show the attack is successful even with 10\% of poisoning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。