Skip to content

Towards a Resilience-Theoretic Foundation for Adversarial Robustness in Industrial Control System Anomaly Detection

Sep 2026 · 0 citations · 40 references
Computer Science

TL;DR

It is established that adversarial robustness in ICS anomaly detection is a specific instantiation of system resilience, and a compositional resilience bound for heterogeneous ICS detection networks is derived, showing that the binding constraint on system-level resilience is the coupling-adjusted absorption capacity of each node along the attack path, not the per-node capacity.

Abstract

Anomaly-based intrusion detection systems in industrial control systems (ICS) and operational technology (OT) environments are increasingly required to meet formal resilience criteria: absorbed adversarial disturbances, graceful degradation under sustained attack, and certified system-level guarantees. Existing resilience frameworks for cyber-physical systems define absorb-recover-adapt trajectories at the architectural level but do not treat machine learning anomaly detectors as first-class components, leaving a gap between component-level robustness evaluation and system-level resilience certification. In this paper, we establish that adversarial robustness in ICS anomaly detection is a specific instantiation of system resilience, and formalise this connection by mapping four resilience constructs, i.e. disturbance class, absorption capacity, recovery trajectory, and degradation function, onto the adversarial machine learning setting. We derive a compositional resilience bound for heterogeneous ICS detection networks, showing that the binding constraint on system-level resilience is the coupling-adjusted absorption capacity of each node along the attack path, not the per-node capacity -- so the binding node need not be the weakest one. Empirical validation on the BATADAL water distribution system benchmark demonstrates that the resulting metrics surface operationally significant phenomena invisible to standard benchmarks: the absorption-degradation divergence under adversarial training, and the paradox that hardening the binding node in isolation reduces system-level resilience. Implications for ICS architecture design and certification standards are discussed.

View source

Similar papers

Preprint Sep 2026

MDRC: A Deployable State-Recovery Defense for Traffic Signal Control under Sensor Corruption

Traffic Signal Control (TSC) is a safety-critical cyber-physical system that relies on real-time sensing. Corrupted observations caused by adversarial perturbations or sensor failures can propagate from the sensing layer into the controller and degrade traffic efficiency. Existing robust Reinforcement Learning (RL)-bas...

Ming-Yuan Li, Chun-Yu Liu, Xiao Liu et al. · 0 citations
#artificial intelligence Preprint Sep 2026

LogiC-Diff: Embedding Security Properties Into AI-Enabled Cyber-Physical Systems

AI-enabled Cyber-Physical Systems (CPS) are highly vulnerable to adversarial and anomalous inputs, where small perturbations can induce cascading errors and unsafe control actions. Existing approaches, such as rule-based filtering, training-time regularization, or diffusion-based reconstruction, either operate outside...

Zi-Yan An, John Stankovic, Mei-Yi Ma · 0 citations
Open access 2026

AI-Assisted Resilience Monitoring for Industrial Control System Security

Industrial control-system anomaly alarms are most useful when they distinguish unusual telemetry from loss of safety or recovery margin. This paper presents RACER-ICS, an operator-oriented framework that combines a one-step predictive residual, rolling physical invariants, held-out empirical block-quantile calibration,...

Shilpi Mittal, Vivek Kumar Polurouthu, Ankit Gupta · 0 citations
2026

Adaptive Learning-Based Resilient Automation for Switched Systems Under FDI Attacks and Actuator Faults

Automated systems operating across multiple modes increasingly rely on networked sensing and feedback, which makes them vulnerable to abrupt actuator faults and false-data-injection (FDI) attacks. This paper studies resilient estimation and control for continuous-time switched automation systems under these two coupled...

Yong-Hong Chen, Qi-Long Xie, Mei Yan et al. · 0 citations
Review Open access Sep 2026

Sustainability–Resilience Trade-Offs in Edge-Enabled Systems: A Comprehensive Survey

This survey introduces a cyber attack-driven Sustainability–Resilience (S-R) framework that positions cyber threats as the primary stressor forcing a bilateral trade-off between operational efficiency and continuity in edge-enabled IoT systems.

Nithya Nedungadi, S. Sankaran · 1 citation

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.