arXiv:2608.16159cs.CRcs.AI2026-08

通过检测物理系统与数字孪生的时间不一致性,实现无需攻击样本的实时安全监测。

Digital Twin Degradation: Detecting Cyber Physical Attacks via Temporal Inconsistencies

论文配图:Digital Twin Degradation: Detecting Cyber Physical Attacks via Temporal Inconsistencies
图 1 · 摘自论文原文
  • 用正常数据训练预测器,捕捉短期系统动态变化。
  • 在SWaT等数据集上达98%检测率,误报率低于2%。
  • 适合工业控制系统中数字孪生受损时的安全监控场景。

数字孪生(DT)被广泛用于监控和分析网络物理系统(CPS)。但在对抗环境下,其真实性无法保证。通信延迟、数据篡改、传感器退化或部分信息丢失均可能导致数字孪生状态与物理过程偏离,产生时间不一致现象,暴露网络物理攻击。本文提出一种检测框架,通过监测物理系统与潜在退化的数字孪生视图间的时间一致性来识别攻击。利用仅基于正常行为训练的数字孪生预测器建模短期系统动态;运行时将预测与观测状态差异转化为多时域时间特征,表征残差幅度、持续性和演化趋势。采用无监督密度模型刻画正常一致性模式,结合序列变化检测机制识别持续偏差。在三个常用工业控制系统数据集(SWaT、HAI、BATADAL)上评估,涵盖时间不同步和部分可观测性丧失等多种数字孪生退化场景。结果表明,时间不一致性模式可实现可靠的事件级攻击检测,具有有限误报率与低延迟。该方法在SWaT上最高达98%检测可靠性,误报率低于2%。不同于传统异常检测,本框架无需攻击特征或标注数据,即使数字孪生退化仍有效。这表明数字孪生退化常被视为缺陷,实则可作为网络安全监测的有用信号。

原文摘要 · Abstract (English)

Digital Twins (DTs) are increasingly used to monitor and analyze Cyber Physical Systems (CPS). However, in adversarial environments, the fidelity of a DT cannot be assumed. Communication delays, data manipulation, sensor degradation, or partial information loss may cause the DT state to diverge from the physical process it represents. Such divergence creates temporal inconsistencies that may reveal cyber physical attacks. This paper proposes a detection framework that monitors temporal consistency between the physical system and a potentially degraded DT view. A DT predictor is trained exclusively on normal system behavior to model short-term system dynamics. During operation, discrepancies between predicted and observed states are transformed into multi-horizon temporal features capturing the magnitude, persistence, and evolution of prediction residuals. An unsupervised density model characterizes normal consistency patterns, while a sequential change detection mechanism identifies sustained deviations indicative of attacks. The approach is evaluated on three widely used Industrial Control System (ICS) datasets, SWaT, HAI, and BATADAL, under multiple DT degradation scenarios, including time desynchronization and partial observability loss. Results show that temporal inconsistency patterns enable reliable event-level attack detection with bounded false alarm rates and low detection latency. The proposed method achieves up to 98% detection reliability on SWaT and false alarm rates below 2%. Unlike conventional anomaly detection methods, the proposed framework does not require attack signatures or labeled attack data and remains effective even when the DT view is degraded. These results suggest that DT degradation, often treated as a limitation, can instead serve as a useful signal for cyber physical security monitoring.

数字孪生安全检测异常检测工业控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。