Secure State Estimation and Control of Cyber-Physical Systems: A Survey
This survey reviews recent advances in secure state estimation and control for cyber-physical systems, highlighting developments across centralized, distributed, and resource-aware strategies, with applications in water and power systems, and discusses ongoing challenges to guide future research.
Cyber-physical systems (CPSs) empower the integration of physical processes and cyber infrastructure with the aid of ubiquitous computation resources and communication capabilities. CPSs have permeated modern society and found extensive applications in a wide variety of areas, including energy, transportation, advanced manufacturing, and medical health. The security of CPSs against cyberattacks has been regarded as a long-standing concern. However, CPSs suffer from extendable vulnerabilities that are beyond classical networked systems due to the tight integration of cyber and physical components. Sophisticated and malicious cyberattacks continue to emerge to adversely impact CPS operation, resulting in performance degradation, service interruption, and system failure. Secure state estimation and control technologies play a vital role in warranting reliable monitoring and operation of safety-critical CPSs. This article provides a review of the state-of-the-art results for secure state estimation and control of CPSs. Specifically, the latest development of secure state estimation is summarized in light of different performance indicators and defense strategies. Then, the recent results on secure control are discussed and classified into three categories: 1) centralized secure control; 2) distributed secure control; and 3) resource-aware secure control. Furthermore, two specific application examples of water supply distribution systems and wide-area power systems are presented to demonstrate the applicability of secure state estimation and control approaches. Finally, several challenging issues are discussed to direct future research.
- Research Article
106
- 10.1109/tcyb.2018.2868781
- Dec 18, 2018
- IEEE Transactions on Cybernetics
In this paper, we investigate the distributed secure state estimation and control problems for interconnected cyber-physical systems (CPSs) with some sensors being attacked. First, by exploring the distinct properties of the unidentifiable attacks to a CPS, an explicit sufficient condition that the secure state estimation problem can be solvable is established. Then distributed preselectors and observers are presented to solve the secure state estimation problems. Furthermore, with the obtained state estimation, fractional dynamic surface-based distributed secure controllers are also proposed for the secure control problem. Theoretical analysis shows that, with the proposed distributed secure observers and controllers, not only the state of the CPS under attacks can be obtained in a given finite time but also the dynamic surface can be achieved and maintained in a finite time. Finally, the results are applied to an islanded micro-grid system as an illustration, which verifies the effectiveness of the proposed schemes.
- Research Article
30
- 10.3390/s24123815
- Jun 13, 2024
- Sensors (Basel, Switzerland)
Cyber-physical systems (CPSs), which combine computer science, control systems, and physical elements, have become essential in modern industrial and societal contexts. However, their extensive integration presents increasing security challenges, particularly due to recurring cyber attacks. Therefore, it is crucial to explore CPS security control. In this review, we systematically examine the prevalent cyber attacks affecting CPSs, such as denial of service, false data injection, and replay attacks, explaining their impacts on CPSs' operation and integrity, as well as summarizing classic attack detection methods. Regarding CPSs' security control approaches, we comprehensively outline protective strategies and technologies, including event-triggered control, switching control, predictive control, and optimal control. These approaches aim to effectively counter various cyber threats and strengthen CPSs' security and resilience. Lastly, we anticipate future advancements in CPS security control, envisioning strategies to address emerging cyber risks and innovations in intelligent security control techniques.
- Research Article
6
- 10.1109/tnse.2021.3130081
- Mar 1, 2022
- IEEE Transactions on Network Science and Engineering
Cyber attacks may cause significant damage to cyber-physical systems (CPSs). Secure control is an effective measure to resist cyber attacks. While efforts have been made in developing secure control methods, the secure control problem for fast time-varying cyber attacks has not been well investigated. This paper presents a secure control strategy for mitigating fast time-varying actuator attacks in CPSs. For attacked CPSs, a nonlinear disturbance observer (NDO) is firstly constructed to estimate the lumped uncertainty. Then, to ensure the security of attacked CPSs, a <inline-formula xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"><tex-math notation="LaTeX">$L_2$</tex-math></inline-formula> gain secure controller is designed to guarantee the stability of the CPSs. It is capable of handling not only constant and slow time-varying attacks but also fast time-varying cyber attacks to a certain extent. Compared with existing secure controllers, the secure controller designed in this paper withstands attacks with a wider range of frequencies, thus enhancing the resilience of the CPSs against unknown attacks. Simulations are conducted to verify the effectiveness of the proposed secure control strategy.
- Book Chapter
1
- 10.1201/9781003220664-7
- Dec 27, 2022
Security and Privacy Aspects in Cyber Physical Systems
- Research Article
52
- 10.1109/mnet.011.1900275
- May 1, 2020
- IEEE Network
The cyber-physical system (CPS) has operated, controlled, and coordinated the physical systems integrated by a computing and communication core applied in Industry 4.0. To accommodate CPS services, fog radio and optical networks (F-RON) has become an important supporting physical cyber infrastructure taking advantage of both the inherent ubiquity of wireless technology and the large capacity of optical networks. However, cyber security is the biggest issue in the CPS scenario as there is a trade-off between security control and privacy exposure in F-RON. To deal with this issue, we propose a brain-like distributed control security (BLCS) architecture for F-RON in CPS by introducing a brain-like security (BLS) scheme. BLCS can accomplish the secure cross-domain control among tripartite controllers verification in the scenario of decentralized F-RON for distributed computing and communications, which has no need to disclose the private information of each domain against cyber-attacks. BLS utilizes parts of information to perform control identification through a relation network and a deep learning of behavior library. The functional modules of BLCS architecture are illustrated including various controllers and a brain-like knowledge base. The interworking procedures in distributed control security modes based on BLS are described. The overall feasibility and efficiency of the architecture are experimentally verified on a software defined network testbed in terms of average mistrust rate, path provisioning latency, packet loss probability, and blocking probability. The emulation results are obtained and dissected based on the testbed.
- Conference Article
3
- 10.1109/cscs.2015.13
- May 1, 2015
In a time when technology changes continuously, where things you need today to run a certain system, might not be needed tomorrow anymore, security is a constant requirement. No matter what systems we have, or how we structure them, no matter what means of digital communication we use, we are always interested in aspects like security, safety, privacy. An example of the ever-advancing technology are cyber-physical systems. We propose a complex security architecture that integrates several consecrated methods such as cryptography, steganography and digital signatures. This architecture is designed to not only ensure security of communication by transforming data into secret code, it is also designed to control access to the system and detect and prevent cyber attacks.
- Book Chapter
1
- 10.1007/978-3-030-45453-1_3
- Jan 1, 2020
- Energy internet.
The rapid development of advanced information technologies, for example, the Internet of Things and Big Data techniques, has made the energy internet achieve a deep integration of physical systems and cyber systems and realize an effective combination of energy flow and information flow among various networks. However, with increasing automation of the energy internet, the scale of physical networks, the size of cyber networks and the numbers of smart sensors and decision-making units have greatly increased, resulting in complex external or internal factors directly or indirectly impacting the control and decisions of networks through various approaches. The interaction mechanisms between cyber networks and physical networks are becoming increasingly complex in the energy internet, resulting in the security and reliability analysis of cyber-physical systems becoming more complicated. In this chapter, the security of components in cyber-physical systems is first introduced. Multiple uncertainties in cyber-physical system operation are also developed, including different types of cyber attacks and corresponding mitigation strategies as well as the volatility of energy sources and stochastic energy consumption. Moreover, the correlation and cascading failures in cyber-physical systems are analysed to demonstrate the coupling between cyber systems and physical systems. Furthermore, challenges in the security of cyber-physical systems are provided. This chapter mainly analyses cyber-physical system security in the energy internet considering various uncertainties, which can provide technical support for the planning and operation of the energy internet.
- Research Article
- 10.47941/ijce.3419
- Jan 5, 2026
- International Journal of Computing and Engineering
Purpose: This paper proposes a Secure Unified Data Model (UDM) Approach that enhances data security, trust, and reliability in Cyber-Physical Systems (CPS) by addressing data security risks such as breaches and unauthorized access. Methodology: The methodology involved several steps. Reviewing existing literature to understand the current state of data modeling in Cyber-Physical Systems (CPS) and identify potential vulnerabilities. Supported by threat modeling and risk assessment frameworks, it analyzed data security risks for the Unified Data Model (UDM) in CPS. The focus was on protecting the UDM through strong encryption, access controls, security training, and regular assessments, safeguarding data at rest and in transit. Findings: The findings show that a Secure Unified Data Model (UDM) approach improves data security in Cyber-Physical Systems (CPS) by strengthening access controls, encryption, and anomaly detection, thereby increasing CPS resilience against cyber threats. This promotes adoption in healthcare, smart cities, and governance. The secure UDM in CPS lowers breach risks, protects vendors and organizations, and offers scalable solutions that enhance productivity and reduce analytics costs. It supports safe data visualization, Business Intelligence (BI), and Artificial Intelligence (AI) tools, with potential applications in law enforcement for secure information sharing. The Secure UDM boosts trust, reliability, and compliance with data protection laws, encouraging adoption and innovation in critical sectors. Unique Contribution to Theory, Practice and Policy: involves developing a conceptual Secure UDM framework that combines access controls, encryption, and anomaly detection for CPS. It also enhances understanding of UDM security in CPS contexts. Practically, this study provides actionable strategies for implementing secure UDMs across sectors such as healthcare, smart cities, and governance, thereby improving data security and trust in CPS through practical mitigation measures. Policy-wise, the study informs data protection regulations and standards for CPS and UDMs and encourages the adoption of secure UDM practices in critical sectors.
- Research Article
- 10.47941/ijce.3447
- Jan 15, 2026
- International Journal of Computing and Engineering
Purpose: This paper proposes a Secure Unified Data Model (UDM) Approach that enhances data security, trust, and reliability in Cyber-Physical Systems (CPS) by addressing data security risks such as breaches and unauthorized access. Methodology: The methodology involved several steps. Reviewing existing literature to understand the current state of data modeling in Cyber-Physical Systems (CPS) and identify potential vulnerabilities. Supported by threat modeling and risk assessment frameworks, it analyzed data security risks for the Unified Data Model (UDM) in CPS. The focus was on protecting the UDM through strong encryption, access controls, security training, and regular assessments, safeguarding data at rest and in transit. Findings: The findings show that a Secure Unified Data Model (UDM) approach improves data security in Cyber-Physical Systems (CPS) by strengthening access controls, encryption, and anomaly detection, thereby increasing CPS resilience against cyber threats. This promotes adoption in healthcare, smart cities, and governance. The secure UDM in CPS lowers breach risks, protects vendors and organizations, and offers scalable solutions that enhance productivity and reduce analytics costs. It supports safe data visualization, Business Intelligence (BI), and Artificial Intelligence (AI) tools, with potential applications in law enforcement for secure information sharing. The Secure UDM boosts trust, reliability, and compliance with data protection laws, encouraging adoption and innovation in critical sectors. Unique Contribution to Theory, Practice and Policy: involves developing a conceptual Secure UDM framework that combines access controls, encryption, and anomaly detection for CPS. It also enhances understanding of UDM security in CPS contexts. Practically, this study provides actionable strategies for implementing secure UDMs across sectors such as healthcare, smart cities, and governance, thereby improving data security and trust in CPS through practical mitigation measures. Policy-wise, the study informs data protection regulations and standards for CPS and UDMs and encourages the adoption of secure UDM practices in critical sectors.
- Research Article
22
- 10.1109/jiot.2023.3319703
- Mar 1, 2024
- IEEE Internet of Things Journal
This article is focused on security analysis and control problems of cyber–physical systems (CPSs) under Denial-of-Service (DoS) attacks, which jam the controller-actuator channel. Considering the limited attack energy of malicious adversaries, DoS attacks are described by a periodic model. Different from existing results, both the security analysis and secure controller design problems are addressed based on the characteristics of DoS attack model rather than utilizing the switching system theory to solve the aforementioned problems. First, sufficient conditions are derived to ensure that the resultant closed-loop CPS under DoS attacks can preserve the exponential stability, and the critical value of the attack period is derived, below which the stability is deteriorated. Second, the relation between our proposed conditions and reinforcement learning-based control is established, based on which the security of reinforcement learning-based control can be evaluated effectively. Finally, both DoS attacks and external disturbances are considered in a unified framework, and sufficient conditions are proposed to evaluate the security of the closed-loop CPSs and design a secure controller. Finally, a mobile robot is adopted to validate the efficacy of the proposed methods.
- Research Article
14
- 10.3390/electronics11193161
- Oct 1, 2022
- Electronics
This paper proposes a reinforcement learning (RL) algorithm for the security problem of state estimation of cyber-physical system (CPS) under denial-of-service (DoS) attacks. The security of CPS will inevitably decline when faced with malicious cyber attacks. In order to analyze the impact of cyber attacks on CPS performance, a Kalman filter, as an adaptive state estimation technology, is combined with an RL method to evaluate the issue of system security, where estimation performance is adopted as an evaluation criterion. Then, the transition of estimation error covariance under a DoS attack is described as a Markov decision process, and the RL algorithm could be applied to resolve the optimal countermeasures. Meanwhile, the interactive combat between defender and attacker could be regarded as a two-player zero-sum game, where the Nash equilibrium policy exists but needs to be solved. Considering the energy constraints, the action selection of both sides will be restricted by setting certain cost functions. The proposed RL approach is designed from three different perspectives, including the defender, the attacker and the interactive game of two opposite sides. In addition, the framework of Q-learning and state–action–reward–state–action (SARSA) methods are investigated separately in this paper to analyze the influence of different RL algorithms. The results show that both algorithms obtain the corresponding optimal policy and the Nash equilibrium policy of the zero-sum interactive game. Through comparative analysis of two algorithms, it is verified that the differences between Q-Learning and SARSA could be applied effectively into the secure state estimation in CPS.
- Dissertation
- 10.32657/10356/145864
- Jan 1, 2021
A Cyber-physical system (CPS) is a complex system embedding advanced computation, communication and control techniques into physical spaces, and is usually built up with a set of networked agents such as sensors, actuators, control processing units, and communication devices. Although the development of CPS facilitates efficient and real-time collaboration between elements, the open nature of communication networks makes it rather vulnerable to malicious attacks. Given that the applications of CPSs vary from aerospace, transportation, power grids, which are always safety-critical, researcher have acknowledged the importance of designing the system with secure algorithms. This thesis first characterizes the properties required for a secure system and possible security threats. Driven by the concerns of deception attacks on communication channels, we study secure detection and control in adversarial environment. New designs on the detection and control algorithms will be developed in this thesis, providing acceptable system performance in the presence of attacks.
- Research Article
101
- 10.1016/j.amc.2021.126639
- Sep 7, 2021
- Applied Mathematics and Computation
Cyber-attacks against cyber-physical power systems security: State estimation, attacks reconstruction and defense strategy
- Conference Article
4
- 10.23919/chicc.2018.8483162
- Jul 1, 2018
This paper is concerned with the secure state estimation and event-triggered control problem for continuous-time cyber-physical systems (CPSs) under actuator and sensor attacks. Based on output measurements, an intermediate estimator is constructed to estimate the state and the malicious attacks simultaneously. Furthermore, a compensating controller is designed based on the intermediate estimator via the event-triggered communication. It is proved that the state of the estimation error system and the closed-loop system are both uniformly ultimately bounded. Simulation examples verify the effectiveness of the proposed method.
- Book Chapter
- 10.1201/9781003220664-5
- Dec 27, 2022
New defense problems have arisen with the rapid development of cyber physical systems (CPSs). Some bugs, risks, attacks, and checks were added for the latest generation of CPSs. In particular, it has been challenging to research the problem using one generally used model because of the complexity of the elements of CPSs and the different CPS frameworks. The complexity of construction blocks is a fundamental problem for CPS protection. CPS consists of several cases with other materials. Various components such as sensors, actuators, and integrated systems are available. Various device libraries, proprietary and industrial, are now used for regulation and surveillance. Consequently, each element will contribute to a CPS attack and its integration. Recognizing existing bugs, seizures, and defense measures in CPS security would provide us with a greater understanding of CPS security. Therefore, the shortcomings of the CPS should be identified, allowing them to be subject to various attacks and develop ways to protect themselves against attacks. The sophistication of CPSs and the variability of CPS modules have created severe problems for preserving CPS confidentiality and protection. In particular, dynamic cyber-physical relations make it impossible to determine vulnerabilities and risks, and new issues emerge. The attacks that can arise from switching between and threatening numerous CPS components are often brutal, recognized, tracked, and analyzed. An extensive grasp of vulnerability, risks, or attacks is crucial to improving defense mechanisms. Current CPS protection and privacy checks would also help us find missed components, vulnerable connections, and new scans. This chapter will review and systematize recent CPS security analysis in a cohesive context. Three orthogonal coordinates comprise the framework: (1) from the CPS viewpoint, we are looking at electronic, physical, and cyber-physical components; and (2) from the CPS perspective, we are exploring the basic functionality of CPS applications and symbolic systems. From our defense perspective, we follow a familiar taxonomy of risks, bugs, attacks, and monitoring; (e.g., defense and public safety, medical CPS, and blood diagnostics). The model can be abstract to display general element relationships in a CPS framework and detailed to capture any specifics if necessary. This is the purpose of building a sufficiently conceptual model to apply to different heterogeneous CPS application areas and obtain a modular view of the strongly linked CPS elements. This abstract disconnection enables a systemic knowledge of CPS safety and highlights potential points of attack and means of protecting it. This chapter tries to sum up the cutting-edge in CPS protection to inspire the public to investigate this emerging area further. Next, we have a schematic interface modeling algorithm to prevent interaction with devices and increase droplet route costs. Simulated experiments on three experimental parameters show that the design approach suggested results in a compact structure and provides an execution series for efficiently managing cyber-physical DMFB PCR operations.