用时间序列大模型检测网络攻击,无需系统模型也能有效识别异常。
Attack Detection using Time Series Foundation Models

- 基于TimesFM构建零样本残差生成器,不依赖系统结构和模型。
- 在IEEE 14节点电力系统上实现与传统方法相当或更优的检测性能。
- 可替代受损数据,适合缺乏冗余设计的工业系统应用。
本文研究在未知系统模型或结构的情况下,对网络物理系统中的攻击进行检测。远程部署的系统通过受攻击网络向操作员传输传感器数据,面临无模型重放攻击和基于模型的隐蔽攻击两类威胁。针对后者,推导出线性和非线性系统下对抗χ²检测器的最优隐蔽攻击策略闭式表达式。随后提出一种基于Google Research开发的时间序列基础模型TimesFM的模型-结构无关检测器,作为零样本残差生成器运行。实验表明,该方法在检测性能上达到或优于传统方法。数值验证在IEEE 14节点电力系统上完成,并证明了TimesFM预测可作为被破坏测量值的替代方案,为经典冗余假设失效时提供实用缓解手段。
原文摘要 · Abstract (English)
This paper addresses the problem of attack detection in cyber-physical systems without any knowledge of the plant model or its structure. A remotely located plant transmits sensor measurements to an operator over a network that is assumed to be under attack. We consider two classes of attacks: model-free replay attacks and model-based stealthy attacks. For the latter, we derive closed-form expressions for the optimal stealthy attack policy against a $χ^2$ detector, for both linear and nonlinear systems. We then propose a model-structure-free detector based on TimesFM, a time-series foundation model developed by Google Research, which serves as a surrogate residual generator operating in a zero-shot fashion. We show empirically that the TimesFM-based detector achieves a comparable or superior attack detection performance. The efficacy of the proposed approach is demonstrated numerically on the IEEE 14-bus power system. We also demonstrate that TimesFM predictions can serve as a substitute for corrupted measurements, a practical mitigation technique when classical redundancy assumptions fail.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。