SearcharxivSearch

arXiv subjects

Shiyi Zhao

Publications and source records attributed to Shiyi Zhao.

2 recordsLinked to original sources

PLCBench: Can Autonomous LLM Agents Turn PLC Access into Sustained Physical Impact?

Industrial control systems (ICSs) rely on programmable logic controllers (PLCs) to connect networked computation with physical control. Tool-using large language model (LLM) agents represent an emerging attack threat: can an autonomous agent convert a network-reachable PLC into sustained adverse physical impact? However, existing evaluations focus on digital tasks or individual stages of PLC testing. In ICSs, evaluations that stop at software exploitation, an accepted write, or tool access may therefore mischaracterize physical risk. We present PLCBENCH, to our knowledge, the first real-PLC hardware-in-the-loop (HIL) framework for characterizing this cyber-to-physical capability and its boundaries. It combines vendor-native interaction, commercial PLC execution, closed-loop reduced-order process simulation, and independent outcome verification. A deterministic evaluator applies fixed rules to runner, communication, PLC-object, and process records to assign six hidden diagnostic flags, distinguishing usable PLC interaction, process-linked manipulation, and sustained physical impact. We instantiate PLCBENCH on four commercial PLCs crossed with four closed-loop workloads. Across five LLM families and 240 real-PLC episodes, 75 episodes (31.3%) sustain their respective physical objectives. Stagewise results show that 98 episodes stop before a valid native read, whereas 62 reach a process-linked write but do not sustain the final objective. Notably, richer process observation is associated with an increase in conditional objective attainment after a process-linked write from 44.2% to 64.0%. These measurements localize failure in configured PLC-process deployments and identify intervention points for future defense evaluation. To support reproducibility, we release the safely disclosable PLCBENCH code and a software-only reproduction pipeline through the accompanying artifact.

cs.CR

Hierarchical Sensor-Spoofing Defence Framework for Networked DC Microgrids via Cyber-Physical Coordination

In parallel to the cyber attack that manipulates the reference points of distributed energy resources (DERs) by maliciously accessing the remote monitoring and control system, the vulnerability of voltage/current sensors to electromagnetic interference (EMI) in the physical domain has been widely discussed. Existing research efforts against sensor spoofing attacks can be classified into physical prevention and cyber detection/mitigation. These defence methods each have strengths and weaknesses in balancing cost, security, and performance in a single DER, yet systematic research on their multi-layer efficient coordination across DERs remains limited. Towards this end, this paper proposes a hierarchical framework to detect and mitigate sensor spoofing attacks in networked microgrids (NMGs) via {multi-layer cyber-physical coordination}. It requires only to deploy physical prevention technologies at critical points, i.e., the local points of common coupling (PCC) of MGs, such that cyber detection/mitigation algorithms can be adopted based on the secured sensor readings to counter sensor spoofing attacks in DERs. The framework employs an MG-DER coordinated proactive detection scheme to strategically trigger parameter perturbations, under which the intelligent sensor spoofing attacks can be {effectively} disclosed. Afterwards, mitigation schemes based on MG-DER coordination are activated to recursively and accurately estimate sensor biases. Experiments on a cyber-physical DC NMG testbed confirm the framework's effectiveness across diverse attack scenarios.

eess.SY