SearcharxivSearch

arXiv subjects

Lovisa Eriksson

Publications and source records attributed to Lovisa Eriksson.

2 recordsLinked to original sources

Adversarial Training of Linear Models under Stealthy Attacks

Predictive models are widely used in many fields, but are vulnerable to false data injection attacks. To address this, detection schemes and adversarial training have been proposed, but such approaches lack guarantees against stealthy attacks. We therefore propose a detector-based switched model, in which optimal attack strategies are stealthy. For linear prediction models, we derive a convex formulation of the resulting adversarial risk. The model incorporates protected features and introduces a hyperparameter modelling attack probability, enabling an explicit performance trade-off between clean and attacked data regimes. Numerical simulations on real and synthetic data show improved performance on partially attacked data, even for misspecified attack probabilities.

cs.LG

Detecting Feedback-path Delay Injection Attacks Using Interacting Multiple Model Filtering

Time-delays are known to have a detrimental effect on feedback systems. In the context of networked cyber-physical systems, delays can be injected by malicious adversaries. Detecting them early is an important challenge. This paper proposes a novel variation of Interacting Multiple Model filtering to detect delay injection attacks in feedback control systems, when hidden in an open loop setting. The detection scheme is formalised by treating delay as alternative modes of the system, and theoretical analysis of the stationary distribution informs a reduction to a three parameter model as well as the choices of hyper parameter values. The method is evaluated on a cruise control application, and shows detection within a few seconds and a low false alarm probability.

eess.SY