Attack detection and isolation for cyber-physical systems based on structurally-aware normality modeling
By employing a structurally-aware normality model within an online inference platform, the system achieves improved abnormality detection and localization in cyber-physical systems by accounting for spatial and temporal dependencies, thereby enhancing detection accuracy and performance.
Patent Information
- Application Number
- PCT/US2023/078320
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-01
- Publication Date
- 2025-05-08
AI Technical Summary
Existing approaches to abnormality detection and localization in cyber-physical systems (CPS) face challenges due to their inability to effectively account for both spatial and temporal dependencies within the system, leading to suboptimal detection performance and localization accuracy.
The implementation of an online inference platform that utilizes a trained, structurally-aware normality model. This model processes k past feature matrices and an adjacency matrix to predict the current system state, calculate residual matrices, and generate asset detection decisions, while also performing localization when abnormal conditions are detected.
This approach enables rapid, accurate, and automatic abnormality detection and localization in CPS, effectively addressing the limitations of previous methods by integrating spatial and temporal dependencies into the detection and localization processes.
Smart Images

Figure US2023078320_08052025_PF_FP_ABST
Abstract
Description
ATTACK DETECTION AND ISOLATION FOR CYBER-PHYSICAL SYSTEMS BASED ON STRUCTURALLY-AWARE NORMALITY MODELING
[0001] This invention was made with government support under Contract DE- CR0000005 awarded by the US Department of Energy. The government has certain rights in the invention.BACKGROUND
[0002] Almost all cyber-physical systems (e.g., an industrial asset such as a pipeline networks) consist of many distributed yet connected components and devices. Moreover, the system-level behavior of a CPS may contain strong spatial dependence among different components in addition to strong temporal dependence over time. For example, a longer pipeline segment between nodes may have less spatial dependence as compared to a shorter segment. Existing approaches to design abnormality (e.g., due to a cyber-attack or fault) detection and localization have predominately used multiple local models with local (at a components level) measurements only (that is, ignoring inter-component relations) which can result in difficulties achieving a desired detection level of performance (e.g., accuracy and robustness) and may be ineffective for attack localization and isolation. On the other hand, simply building a system level model (e.g., regressive or auto-associative) using all measurements of the entire system without considering the structural (topological) relations within the system itself complicates the model training process. Moreover, such a system level approach may overfit the model and result in poor detection and localization performance.
[0003] It would therefore be desirable to provide abnormality detection and localization in an automatic, rapid, and accurate manner and to take into account both spatial (inter-component) and temporal dependencies of the underlying system.SUMMARY
[0004] According to some embodiments, an online inference platform may obtain k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector (set of node measurements) representing operation of a cyber-physicalasset. The k past feature matrices and an adjacency matrix are provided to a trained, structurally-aware normality model which creates a predicted feature matrix. A residual matrix Rt is obtained by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time Z, and an asset detection decision (e.g., “normal” or “abnormal”) is obtained by thresholding the residual matrix At The online inference platform may also perform a localization process when the asset detection decision is “abnormal.” An offline model training platform may create the normality model based on historical feature matrices of the asset and the adjacency matrix.
[0005] Some embodiments comprise: means for obtaining, by a computer processor of an online inference platform, k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements representing operation of the cyber-physical asset; means for providing, by the online inference platform, the k past feature matrices and an adjacency matrix to a trained, structurally-aware normality model; means for receiving, by the online inference platform, a predicted feature matrix for time t as an output from the trained, structurally-aware normality model; means for obtaining, by the online inference platform, a residual matrix Rt by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time Z; means for generating, by the online inference platform, an asset detection decision by thresholding the residual matrix Rt and means for outputting, by the online inference platform, the asset detection decision.
[0006] Some technical advantages of some embodiments disclosed herein are improved systems and methods to provide abnormality detection and localization in an automatic, rapid, and accurate manner.BRIEF DESCRIPTION OF THE DRAWINGS
[0007] FIG. 1 shows a multi-model system associated with attack detection.
[0008] FIG. 2 is an example of a system arranged as a graph with feature vectors according to some embodiments.
[0009] FIG. 3 is an example of a feature vector in accordance with some embodiments.
[0010] FIG. 4 is an adjacency matrix for the system of FIG. 2 according to some embodiments.
[0011] FIG. 5 is a high-level block diagram of a system in accordance with some embodiments.
[0012] FIG. 6 is an online inference method according to some embodiments.
[0013] FIG. 7 is an offline training method in accordance with some embodiments.
[0014] FIG. 8 is a more detailed online inference method according to some embodiments.
[0015] FIG. 9 illustrates node masking for abnormality localization or isolation in accordance with some embodiments.
[0016] FIG. 10 is an online inference system according to some embodiments.
[0017] FIG. 11 is a more detailed offline training method in accordance with some embodiments.
[0018] FIG. 12 is an offline training system according to some embodiments.
[0019] FIG. 13 is a system for mask-based spatial embedding in accordance with some embodiments.
[0020] FIG. 14 is an offline training system with a mask-based decoder according to some embodiments.
[0021] FIG. 15A is a node level masking scheme in accordance with some embodiments.
[0022] FIG. 15B is a feature level masking scheme according to some embodiments.
[0023] FIG. 16 is a block diagram of a platform according to some embodiments of the present invention.
[0024] FIG. 17 is a tabular portion of a detection results database in accordance with some embodiments.
[0025] FIG. 18 is a display according to some embodiments.DETAILED DESCRIPTION
[0026] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of embodiments. However, it will be understood by those of ordinary skill in the art that the embodiments may be practiced without these specific details. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the embodiments.
[0027] FIG. 1 shows a multi-model system 100 for a plurality of components or nodes 110 associated with attack detection. In particular, the system 100 includes a four-model representation 120 (models 1 through 4), with each model containing information about the nodes 110. A monitoring system 130 may then perform cyber-attack detection 140 and isolation 150 on the representation 120. Note that existing attack detection 140 and attack isolation 150 methods involve building the multiple models with local (at a component or node 110 level) measurements only (while ignoring inter-node relations) which can result in difficulties in achieving desired detection performance (with respect to accuracy and robustness) and may be ineffective for attack isolation 150. As used herein, the term “node” may refer to a physical node, such as when a system is associated with a gas pipeline, a power grid, etc. The term “node” may also refer to a node of a graph associated with components or sub-components of any complex system, such as a those associated with sensor measurements.
[0028] To overcome these drawbacks, FIG. 2 is an example of a system 200 arranged as a graph with feature vectors according to some embodiments. The graph includes four models 210, 220, 230, 240 (models 1 through 4, respectively) along with directional links between nodes (nodes 1 through 9 in FIG. 2). In addition, each node may be associated with a feature vector 250 representing a set of measurements associated with that node. For example, FIG. 3 is an example of a feature vector 300 in accordance with some embodiments. In particular, the feature vector 300 comprises three node measurements that might be associated with a pipeline network: temperature, pressure, and flow rate.
[0029] To capture the structure / dependency relationships between nodes, embodiments may represent an industrial asset, such as a pipeline network, as a directionally- connected graph, G=(V, E, X), where V and E are the vertex or node and directed edge sets, respectively and Xis the node feature set. The number of nodes of the graph may be N = |F|and each of the nodes may have d measurements or features (e.g., pressure, temperature, and flow rate. The topological structure or connectivity of the pipeline network (i.e., the edge set) may be defined as an adjacency matrix, A G 3INxN, where a non-zero value at cell (i, / ) of A indicates that nodes i and j are connected. For example, FIG. 4 is an adjacency matrix 400 that represents the system of FIG. 2 according to some embodiments. The matrix 400 indicates in a binary fashion whether each “From Node” is directionally connected to each “To Node.” Consider, for example, the matrix 400 of FIG. 4 which shows that there is a connection from node 2 to node 5 (as shown by the connection between models 210, 230 in FIG. 2), but the inverse is not true. Although the matrix 400 in this example is binary (with a “1” indicating a connection in that direction and a “0” indicating no connection), note that embodiments may instead have weighted values that indicate how strong of a connection there is between two nodes.
[0030] The instantaneous system status at a given time step t might be captured / represented by the node measurements collected from all pipeline nodes at time t. Hence, the system status representing a feature matrix at time t may be XtG Jl / Vxdand feature matrices for the k past consecutive time-stamps may comprise a tensor X
[0031] FIG. 5 is a high-level architecture of a system 500 in accordance with some embodiments. The system 500 may include an online inference platform 510 and an offline model training platform 520. The online inference platform 510 may perform abnormality detection 512 and abnormality localization 514 based on current operation of a cyberphysical asset and output detection decision and localization results using a Machine Learning (“ML”) model. The ML model may be received from the offline model training platform 520 based on historical industrial time-series data stored in a historical asset operation data store 530 (e.g., storing a plurality of time-series measurements that represent normal or abnormal operation of a cyber-physical system). The historical asset operation data store 530 may contain values (collected during operation of the cyber-physical system) from each of a plurality of “monitoring nodes” (e.g., “MNi,” “MN2,” . . ., “MNN”). AS used herein, the phrase “monitoring node” might refer to, for example, sensor data, signals exchanged with actuators, motors, pumps, and auxiliary equipment, intermediary parameters that are not direct sensor signals, control logical(s), etc. These may represent, for example, threat monitoring nodes that receive data from a threat monitoring system in a continuous fashion in the form of continuous signals or streams of data or combinations thereof. Moreover, thenodes may be used to monitor occurrences of cyber-threats or other abnormal events (e.g., sensor faults). This data path may be designated specifically with encryptions or other protection mechanisms so that the information may be secured and cannot be tampered with via cyber-attacks.
[0032] The offline model training platform 520 may use masked-based spatial embedding 522 and temporal modeling 524 to automatically create a ML model based on information from the historical asset operation data store 530. As used herein, the term “automatically” may refer to a process that requires little or no human intervention. The ML model may then generate an output (e.g., indicating whether an industrial asset is currently under cyber-attack or experiencing a fault).
[0033] As used herein, devices, including those associated with the system 500 and any other device described herein, may exchange information via any communication network which may be one or more of a Local Area Network (“LAN”), a Metropolitan Area Network (“MAN”), a Wide Area Network (“WAN”), a proprietary network, a Public Switched Telephone Network (“PSTN”), a Wireless Application Protocol (“WAP”) network, a Bluetooth network, a wireless LAN network, and / or an Internet Protocol (“IP”) network such as the Internet, an intranet, or an extranet. Note that any devices described herein may communicate via one or more such communication networks.
[0034] The various data sources may be locally stored or reside remote from the online inference platform 510 and the offline model training platform 520. Although a single online inference platform 510 and offline model training platform 520 are shown in FIG. 5, any number of such devices may be included. Moreover, various devices described herein might be combined according to embodiments of the present invention. For example, in some embodiments, the online inference platform 510, the offline model training platform 520, and one or more data sources might comprise a single apparatus. The online inference platform 510 and the offline model training platform 520 functions may be performed by a constellation of networked apparatuses in a distributed processing or cloud-based architecture.
[0035] A user may access the system 500 via a monitoring device (e.g., a Personal Computer (“PC”), tablet, smartphone, or remotely through a remote gateway connection) to view information about and / or manage information in accordance with any of theembodiments described herein. In some cases, an interactive graphical display interface may let a user define and / or adjust certain parameters (e.g., time-series measurement properties or data about a cyber-physical system) and / or provide or receive automatically generated recommendations, alerts, asset performance metrics, or other results from the system 500 (as well as other devices).
[0036] Thus, some embodiments may provide an innovative way to effectively detect and localize (or isolate) attacks or faults. Moreover, embodiments may utilize a strategy of improving attack detection performance by leveraging the various structural relationships that exist within the industrial system or asset. Note that integrated capabilities may be provided for both detecting and localizing cyberattacks and faults. In addition, embodiments may provide a unique way to train a normality model to capture both spatial and temporal dependences of an underlying system.
[0037] For example, FIG. 6 illustrates an online inference method that might be performed by some or all of the elements of the system 500 described with respect to FIG. 5. The flow charts described herein do not imply a fixed order to the steps, and embodiments of the present invention may be practiced in any order that is practicable. Note that any of the methods described herein may be performed by hardware, software, or any combination of these approaches. For example, a computer-readable storage medium may store thereon instructions that when executed by a machine result in performance according to any of the embodiments described herein.
[0038] At S610, a computer processor of an online inference platform may obtain k past feature matrices. Each feature matrix may be, for example, associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements that represent operation of the cyber-physical asset. At S620, the online inference platform may provide the k past feature matrices and an adjacency matrix to a trained, structurally-aware normality model. At S630, the online inference platform may receive a predicted feature matrix for time t as an output from the trained, structurally-aware normality model. At S640, the online inference platform may obtain a residual matrix Rt by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time t.
[0039] At S650, the online inference platform may generate an asset detection decision by thresholding the residual matrix Rt and the asset detection decision may be outputat S660. For example, the asset detection decision may be “normal” when none of the residual values in Rt exceed a corresponding threshold. Similarly, the asset detection decision may “abnormal” when at least one of the residual values in Rt exceed the corresponding threshold. As used herein, the term “abnormal” may refer to an industrial asset that is currently experiencing a cyber-attack or fault (e.g., a faulty node sensor). At S670, the system may further perform a localization process when the asset detection decision is “abnormal” (e.g., as described in connection with FIGS. 8 through 10).According to some embodiments, a cyber-physical asset may be associated with a turbine, a gas turbine, a wind turbine, an engine, a jet engine, a locomotive engine, a refinery, a power grid, an autonomous vehicle, etc. Moreover, node measurements may include information from a sensor monitoring node, an actuator monitoring node, a control monitoring node, etc.
[0040] Embodiments described herein may perform not only attack detection but also attack isolation and achieve high accuracy and robustness. In some embodiments, such improved capabilities may be achieved by leveraging and integrating both spatial and temporal dependence of an underlying system in designing attack detection and localization models. For example, embodiments may characterize an industrial pipeline network as a directionally-connected graph and jointly learn both structural and temporal patterns of the pipeline network’s normal operation by imposing relational inductive bias. The system may then perform attack detection and localization by monitoring the deviations of the pipeline network from the learned normal behavior of the global network (as well as the individual pipeline nodes).
[0041] FIG. 7 is an offline training method in accordance with some embodiments. At S710, an offline model training platform may provide historical feature matrices to a maskbased spatial embedding platform. For example, each historical feature matrix may be associated with a set of nodes and, for each node, a feature vector may include a set of node measurements that represent historical operation of the cyber-physical asset. Note that as used herein, the phrase “historical feature matrix” might refer to, for example, any training samples measured during historical operation data of an industrial asset, simulation data, both operational and simulated data, etc. Moreover, according to some embodiments, the historical training samples are only for normal operation conditions (not abnormal operation conditions). Such a semi-supervised approach may provide effective detection for anyunknown type of future fault or attack (not just those particular abnormalities that have been predicted and simulated). The spatial embedding platform may comprise, for example, multiple masked Graph Convolutional Networks (“GCNs”). The masked GCNs may utilize, in some embodiments, node level masking, feature measurement level masking, an autoregressive setting, an auto-associative setting, etc.
[0042] At S720, the system may also provide an adjacency matrix to the mask-based spatial embedding platform. At S730, the system may create a trained, structurally-aware normality model based on output of the spatial embedding platform. The trained, structurally- aware normality model might be associated with temporal modeling utilizing, by way of examples only, a Neural Network (“NN”) model, a Feed-Forward Multilayer Perceptron (“FF MLP”), a One Dimensional Convolutional Neural Network (“ID CNN”), a Temporal Convolutional Network (“TCN”), a Recurrent Neural Network (“RNN”), a Long Short-Term Memory / Gated Recurrent Unit (“LSTM / GRU”), etc.
[0043] Some embodiments may perform a localization process when an asset detection decision is “abnormal” (indicating a cyber-attack or fault). For example, the localization process may output a localization result representing a first node when only the first node has residual values in Rt that exceed the corresponding threshold. FIG. 8 is a more detailed online inference method according to some embodiments. Note that when multiple nodes have residual values in Rt that exceed the corresponding threshold, the localization process may, for each of the multiple nodes, perform the method of FIG. 8. In particular, at S810 the system may mask that node from all of the k past feature matrices. At S820, the system may provide the masked k past feature matrices to the trained, structurally-aware normality model. At S830, the system may receive a masked predicted feature matrix for time t as an output from the trained, structurally-aware normality model. That is, the system may take the k past feature matrices and the adjacent matrix as inputs and the spatially trained structure-aware normality model will output the predicted feature matrix Xtfor time t.
[0044] At S840, the system may then obtain a masked residual matrix by calculating a difference between the masked predicted feature matrix for time t and the measured feature matrix for time t. If the masked residual matrix is statistically significantly different than Rt, at S8150 the system will mark that node as “abnormal.” That is, the system may make a detection decision by thresholding the residual matrix. If only node level detection is needed, the system may perform aggregation along the feature dimension prior to thresholding. Ifnone of residual values exceed the threshold, the system reports the “normal” status for time t and continues to the next time step. Otherwise, the system may report the “attack” status for time t. When the process is completed for all appropriate nodes, the localization process can output a localization result that identifies all “abnormal” nodes. In some embodiments, the localization result further identifies at least one specific abnormal measurement for each “abnormal” node.
[0045] For example, FIG. 9 illustrates node masking 900 for abnormality localization or isolation in accordance with some embodiments. In particular, the masking 900 is performed in connection with a node graph 910. If only a single node has its residual value exceeding the threshold, then the system may localize the attack to this node and report the localization result. Otherwise, the system may obtain node indices for all nodes whose residual values exceed the threshold; and for each of these nodes, do the following. The system may mask out the node from the all k past feature matrices. For example, node 2 (and the associated feature vector) might be mased-out as illustrated by the masked graph 920 (with masking being shown via cross-hatching in FIG. 9). As used herein, the term “masked” might refer to, for example, any replacement of an actual value for a node, such as by replacement with a random value within a specified range, random noise, an average value based on prior measurements, a fixed value (e.g., “0”), etc. The system may then send the masked k feature matrices to the trained structure-aware normality model and obtain the predicted feature matrix Xt. After obtaining the residual vector for this node, if the residual vector is statistically significantly different from those obtained for all normal operations, that node is marked as the abnormal or attacked node. When completed, the system may report the localization results. According to some embodiments, the detected attack can be further localized to a specific measurement of the node as shown by the attached node indication and attacked measurement indication 930.
[0046] FIG. 10 is an online inference system 1000 according to some embodiments. A set of model inputs 1010 include k past feature matrices 1020 and an adjacency matrix 1030 A E 9iNxN). The model inputs 1010 are provided to a spatially trained structure-aware normality model 1040. The model 1040 outputs a predicted feature matrix (XtE lNxd). The predicted feature matrix is compared to the current feature matrix (XtE ‘Nxd) to create a residual matrix at time t (RtE< Nxd'). The residual matrix is used to make an attack detection decision 1060. If no attack is detected at 1060, the result is output 1070, t is increased to t + 1,and the process continues. If an attack is detected at 1060, attack isolation 1080 is performed. In particular, node masking 1082 is performed on the model inputs 1010 (inputs corruption for nodes and / or feature perturbation), and the resulting model prediction is compared to the current feature matrix. Attack isolation decision is then performed based on the comparison, the result is output 1070, t is increased to t + 1, and the process continues.
[0047] FIG. 11 is a more detailed offline training method in accordance with some embodiments. At SI 110, the system may provide historical feature matrices and an adjacency matrix to an offline training structure. Mask-based spatial embedding may then be performed via a graph neural network at SI 120. In some embodiments, the system may optionally utilize a mask-based decoder at SI 130 (as described in connection with FIG. 14). At SI 140, temporal monitoring is performed with a neural network model. Finally, at SI 150 a trained, structurally-aware normality model may be output (e.g., for use by an online inference platform).
[0048] FIG. 12 is an offline training system 1200 according to some embodiments. A historical asset data store 1210 may contain, for example, thousands of feature vector samples that were measured during operation of an industrial asset. The industrial asset might be associated with, for example, nodes of a natural gas pipeline network. Information 1220 from the historical asset data store 1210 (e.g., A: past feature matrices representing Xt-k, Xt-k+i, . . . Xt- i, Xi) is provided to a mask-based spatial embedding component 1240 along with an adjacency matrix 1230 A E< NxN). The mask-based spatial embedding component 1240 may, for example, leverage neighbor information to reduce a number of required features. The mask-based spatial embedding component 1240 generates an output Z that is provided to temporal modeling 1260 which creates Xtfrom Z. The temporal modeling 1260 may comprise, for example:where fwmight be one of the following NN models: FF MLP, ID CNN, TCN, RNN, LSTM / GRU, etc. A loss function 1270 receives Xtalong with a data sample extracted from the information 1220 from the historical asset data store 1210. According to some embodiments, the structure-aware normality model is trained using only normal (attack-free) data.
[0049] The masked-based spatial embodiment component 1240 may be implemented in a number of different ways to achieve:Z£= {z , z2l, ... , zNl}In particular, for / th node embedding the following may be performed:For example, FIG. 13 is a system 1300 for mask-based spatial embedding in accordance with some embodiments. A set of k past feature matrices 12320 representing Xt-k, Xt-k+i, . . . -i (Xi G are provided to a set of masked Graph Conventional Networks (mGCNi through mGCN / ) 1340 along with an adjacency matrix 1330 (A G 9iNxN). Note that the set of mGCNs 1340 may have either shared or individual weights. The set of mGCNs 1340 may then generate Zi through Zk ZtG SiN xm).
[0050] FIG. 14 is an offline training system 1400 with a mask-based decoder according to some embodiments. In addition to (or instead of) an auto-regressive approach, the optional mask-based decoder may use an autoencoder to reconstruct information:Similar to the system of 1200 of FIG. 12, a historical asset data store 1410 may contain, for example, feature vector samples that were measured during operation of an industrial asset. Information 1420 from the historical asset data store 1410 (e.g., k past feature matrices representing Xt-k, Xt-k+i, . . . X-i, Xi) is provided to a mask-based spatial embedding component 1440 along with an adjacency matrix 1430 (A G< NxN). The mask-based spatial embedding component 1440 generates an output Z that is provided to temporal modeling 1460 which creates Xtfrom Z. In this embodiment, Z is also provided to a mask-based decoder 1480. The mask-based decoder 1480 may operate according to:edded dimension xte ^NxdA loss function 1470 receives Xt, a data sample extracted from the information 1420 from the historical asset data store 1410, and (X£G< Nxd, i = t — k, ... t — 1} from the mask-based decoder 1480. Some embodiments may create a model by iteratively adjusting neural network parameters to minimize loss function 1470 values, such as neural networkparameters associated with mask-based spatial embedding (e.g., element 522 of FIG. 5) and temporal modeling (element 524 of FIG. 5).
[0051] Embodiments may use various masking schemes on feature matrices during training. For example, FIG. 15A is a node level masking scheme 1500 in accordance with some embodiments. In the example, feature matrix masking is illustrated as cross-hatching in the FIGS. Moreover, model inputs and model outputs are shown for an auto-regressive setting. For an auto-associative setting, the model inputs and model outputs may be combined as model inputs. As another example, FIG. 15B is a feature level masking scheme 1510 according to some embodiments.
[0052] The embodiments described herein may be implemented using any number of different hardware configurations. For example, FIG. 16 is a block diagram of a platform 1600 that may be, for example, associated with the system 500 of FIG. 5. The platform 1600 comprises a processor 1610, such as one or more commercially available Central Processing Units (“CPUs”) in the form of one-chip microprocessors, coupled to a communication device 1620 configured to communicate via a communication network (not shown in FIG. 16). The communication device 1620 may be used to communicate, for example, with one or more remote monitoring nodes, user platforms, etc. The platform 1600 further includes an input device 1640 (e.g., a computer mouse and / or keyboard to input model or sensor configuration data, etc.) and / an output device 1650 (e.g., a computer monitor to render a display, provide alerts, transmit recommendations, and / or create reports). According to some embodiments, a mobile device, monitoring physical system, and / or PC may be used to exchange information with the platform 1600.
[0053] The processor 1610 also communicates with a storage device 1630. The storage device 1630 may comprise any appropriate information storage device, including combinations of magnetic storage devices (e.g., a hard disk drive), optical storage devices, mobile telephones, and / or semiconductor memory devices. The storage device 1630 stores a program 1612 and / or abnormality detection engine 1614 for controlling the processor 1610. The processor 1610 performs instructions of the programs 1612, 1614, and thereby operates in accordance with any of the embodiments described herein. For example, the processor 1610 may obtain k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector (set of node measurements) representing operation of a cyber-physical asset. The k past feature matrices and an adjacency matrix may beprovided to a trained, structurally-aware normality model which creates a predicted feature matrix. A residual matrix Rt is obtained by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time / , and an asset detection decision (e.g., “normal” or “abnormal”) is obtained by thresholding the residual matrix Rt. The processor 1610 may also perform a localization process when the asset detection decision is “abnormal.” An offline model training platform may create the normality model based on historical feature matrices of the asset and the adjacency matrix.
[0054] The programs 1612, 1614 may be stored in a compressed, uncompiled and / or encrypted format. The programs 1612, 1614 may furthermore include other program elements, such as an operating system, clipboard application, a database management system, and / or device drivers used by the processor 1610 to interface with peripheral devices.
[0055] As used herein, information may be “received” by or “transmitted” to, for example: (i) the stateful, nonlinear embedding platform 1600 from another device; or (ii) a software application or module within the stateful, nonlinear embedding platform 1600 from another software application, module, or any other source.
[0056] In some embodiments (such as the one shown in FIG. 16), the storage device 1630 further stores historical data 1660 (e.g., operating measurements for an industrial asset), an adjacency matrix 1670, and / or detection results 1700. An example of a database that may be used in connection with the platform 1600 will now be described in detail with respect to FIG. 17. Note that the database described herein is only one example, and additional and / or different information may be stored therein. Moreover, various databases might be split or combined in accordance with any of the embodiments described herein.
[0057] Referring to FIG. 17, a table is shown that represents the detection results 1700 that may be stored at the platform 1600 according to some embodiments. The table may include, for example, entries identifying online inference decisions associated with a cyberphysical system. The table may also define fields 1702, 1704, 1706, 1708, 1710 for each of the entries. The fields 1702, 1704, 1706, 1708, 1710 may, according to some embodiments, specify: an asset identifier 1702, an asset description 1704, a model identifier 1706, a date and time 1708, and a status 1710. The detection results 1700 may be created and updated, for example, when a new physical system is monitored or modeled and / or on-line operational values are received from monitoring nodes.
[0058] The asset identifier 1702 and asset description 1704 may be, for example, unique alphanumeric codes identifying an industrial asset being monitored (e.g., a pipeline, power grid, turbine engine, etc.). The model identifier 1706 may indicate a trained, structurally-aware normality model that has been created for that asset. The date and time 1708 may indicate when a detection decision (and, in some cases, an abnormality localization analysis) was determined. The status 1710 might indicate that the detection was “normal,” “abnormal,” “attack,” “fault,” “localized,” etc.
[0059] Thus, embodiments may provide a means of leveraging both structural relationships and temporal dependence to achieve a cyber resilient system with accurate and robust abnormality detection and isolation capabilities. Embodiments may enhance online feature-based cyber-attack protection, especially with respect to attack detection and isolation performance. Such advancements may enhance an enterprise’s competitive edge in the domain of cyber-physical system security.
[0060] The following illustrates various additional embodiments of the invention. These do not constitute a definition of all possible embodiments, and those skilled in the art will understand that the present invention is applicable to many other embodiments. Further, although the following embodiments are briefly described for clarity, those skilled in the art will understand how to make any changes, if necessary, to the above-described apparatus and methods to accommodate these and other embodiments and applications.
[0061] Although specific hardware and data configurations have been described herein, note that any number of other configurations may be provided in accordance with embodiments of the present invention (e.g., some of the information associated with the databases described herein may be combined or stored in external systems).
[0062] Embodiments may be associated with various types of abnormality detection models. For example, industrial asset control systems that operate physical systems (e.g., associated with power turbines, jet engines, locomotives, autonomous vehicles, etc.) are increasingly connected to the Internet. As a result, these control systems may be vulnerable to threats, such as cyber-attacks (e.g., associated with a computer virus, malicious software, etc.), that could disrupt electric power generation and distribution, damage engines, inflict vehicle malfunctions, etc. Current methods primarily consider threat detection in Information Technology (“IT,” such as, computers that store, retrieve, transmit, manipulate data) andOperation Technology (“OT,” such as direct monitoring devices and communication bus interfaces). Cyber-threats can still penetrate through these protection layers and reach the physical “domain” as seen in 2010 with the Stuxnet attack. Such attacks can diminish the performance of an industrial asset and may cause a total shutdown or even catastrophic damage to a plant. Currently, Fault Detection Isolation and Accommodation (“FDIA”) approaches only analyze sensor data, but a threat might occur even in other types of threat monitoring nodes such as actuators, control logical(s), etc. Also note that FDIA is limited only to naturally occurring faults in one sensor at a time. FDIA systems do not address multiple simultaneously occurring faults as they are normally due to malicious intent. Note that quickly detecting an attack may be important when responding to threats in an industrial asset (e.g., to reduce damage, to prevent the attack from spreading to other assets, etc. . Making such a detection quickly (e.g., at substantially sample speed) can be aided by ML models and cyber-physical systems often have an overwhelmingly large number of physical measurements (which makes attack detection directly based on the physical measurements challenging). FIG. 18 illustrates an interactive Graphical User Interface (“GUI”) display 1800 that provides a current status analysis 1810 for an industrial asset such as a power grid 1820. The analysis 1810 might be based on cyber-physical system information (e.g., including a feature vector 1830 and decision boundaries) 1830. User selection of an “Edit” icon 1840 might let an operator or administration update or adjust the system.
[0063] The present invention has been described in terms of several embodiments solely for the purpose of illustration. Persons skilled in the art will recognize from this description that the invention is not limited to the embodiments described but may be practiced with modifications and alterations limited only by the spirit and scope of the appended claims.
Claims
CLAIMS1. A system associated with cyber-physical asset protection, comprising: an online inference platform including a computer processor and a computer memory storing instructions that, when executed by the computer processor, cause the online inference platform to: obtain k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements representing operation of the cyber-physical asset, provide the k past feature matrices and an adjacency matrix to a trained, structurally-aware normality model, receive a predicted feature matrix for time t as an output from the trained, structurally-aware normality model, obtain a residual matrix Rt by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time / , generate an asset detection decision by thresholding the residual matrix Rt, and output the asset detection decision.
2. The system of claim 1, wherein the asset detection decision is “normal” when none of the residual values in Rt exceed a corresponding threshold.
3. The system of claim 2, wherein the asset detection decision is “abnormal” when at least one of the residual values in Rt exceed the corresponding threshold.
4. The system of claim 3, wherein the online inference platform is further to: perform a localization process when the asset detection decision is “abnormal.”5. The system of claim 4, wherein the localization process outputs a localization result representing a first node when only the first node has residual values in Rt that exceed the corresponding threshold.
6. The system of claim 4, wherein when multiple nodes have residual values in Rt that exceed the corresponding threshold, the localization process is to, for each of the multiple nodes: mask that node from all of the k past feature matrices, provide the masked k past feature matrices to the trained, structurally-aware normality model, receive a masked predicted feature matrix for time t as an output from the trained, structurally-aware normality model, obtain a masked residual matrix by calculating a difference between the masked predicted feature matrix for time t and the measured feature matrix for time / , and if the masked residual matrix is statistically significantly different than Rt, mark that node as “abnormal.”7. The system of claim 6, wherein when localization process is further to: output a localization result that identifies all “abnormal” nodes.
8. The system of claim 7, wherein the localization result further identifies at least one specific abnormal measurement for each “abnormal” node.
9. The system of claim 1, further comprising: an offline model training platform to: provide historical feature matrices to a mask-based spatial embedding platform, each historical feature matrix being associated with a set of nodes and, foreach node, a feature vector that includes a set of node measurements representing historical operation of the cyber-physical asset, provide the adjacency matrix to the mask-based spatial embedding platform, and create the trained, structurally-aware normality model based on output of the spatial embedding platform by iteratively adjusting neural network parameters to minimize loss function values.
10. The system of claim 9, wherein the spatial embedding platform comprises masked Graph Convolutional Networks (“GCNs”).
11. The system of claim 9, wherein the masked GCNs utilize at least one of: (i) node level masking, (ii) feature measurement level masking, (iii) an auto-regressive setting, and (iv) an auto-associative setting.
12. The system of claim 9, wherein the trained, structurally-aware normality model is associated with temporal modeling utilizing at least one of: (i) a Neural Network (“NN”) model, (ii) a Feed-Forward Multilayer Perceptron (“FF MLP”), (iii) a One Dimensional Convolutional Neural Network (“ID CNN”), (iv) a Temporal Convolutional Network (“TCN”), (v) a Recurrent Neural Network (“RNN”), and (vi) a Long Short-Term Memory / Gated Recurrent Unit (“LSTM / GRU”).
13. The system of claim 1, wherein the cyber-physical asset is associated with at least one of: (i) a turbine, (ii) a gas turbine, (iii) a wind turbine, (iv) an engine, (v) a jet engine, (vi) a locomotive engine, (vii) a refinery, (viii) a power grid, and (ix) an autonomous vehicle.
14. The system of claim 13, wherein the node measurements include information from at least one of: (i) a sensor monitoring node, (ii) an actuator monitoring node, and (iii) a control monitoring node.
15. A computerized method associated with cyber-physical asset protection, comprising: obtaining, by a computer processor of an online inference platform, k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements representing operation of the cyberphysical asset; providing, by the online inference platform, the k past feature matrices and an adjacency matrix to a trained, structurally-aware normality model; receiving, by the online inference platform, a predicted feature matrix for time t as an output from the trained, structurally-aware normality model; obtaining, by the online inference platform, a residual matrix Rt by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time / ; generating, by the online inference platform, an asset detection decision by thresholding the residual matrix Rt, and outputting, by the online inference platform, the asset detection decision.
16. The method of claim 15, wherein the asset detection decision is “normal” when none of the residual values in Rt exceed a corresponding threshold and “abnormal” when at least one of the residual values in Rt exceed the corresponding threshold.
17. The method of claim 16, further comprising: performing, by the online inference platform, a localization process when the asset detection decision is “abnormal.”18. The method of claim 17, wherein the localization process outputs a localization result representing a first node when only the first node has residual values in Rt that exceed the corresponding threshold.
19. The method of claim 17, wherein when multiple nodes have residual values in Rt that exceed the corresponding threshold, the localization process is to, for each of the multiple nodes: mask that node from all of the k past feature matrices, provide the masked k past feature matrices to the trained, structurally-aware normality model, receive a masked predicted feature matrix for time t as an output from the trained, structurally-aware normality model, obtain a masked residual matrix by calculating a difference between the masked predicted feature matrix for time t and the measured feature matrix for time / , and if the masked residual matrix is statistically significantly different than Rt, mark that node as “abnormal.”20. The method of claim 19, further comprising: providing, by an offline model training platform, historical feature matrices to a maskbased spatial embedding platform, each historical feature matrix being associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements representing historical operation of the cyber-physical asset; providing, by the offline model training platform, the adjacency matrix to the maskbased spatial embedding platform; and creating, by the offline model training platform, the trained, structurally-aware normality model based on output of the spatial embedding platform by iteratively adjusting neural network parameters to minimize loss function values.
21. A non-transitory, computer-readable medium storing instructions that, when executed by a computer processor, cause the computer processor to perform a method associated with cyber-physical asset protection, the method comprising:obtaining, by a computer processor of an online inference platform, k past feature matrices, each feature matrix being associated with a set of nodes and, for each node, a feature vector that includes a set of node measurements representing operation of the cyberphysical asset; providing, by the online inference platform, the k past feature matrices and an adjacency matrix to a trained, structurally-aware normality model; receiving, by the online inference platform, a predicted feature matrix for time t as an output from the trained, structurally-aware normality model; obtaining, by the online inference platform, a residual matrix Rt by calculating a difference between the predicted feature matrix for time t and a measured feature matrix for time / ; generating, by the online inference platform, an asset detection decision by thresholding the residual matrix Rf, and outputting, by the online inference platform, the asset detection decision.
Citation Information
Patent Citations
Learning method and system for separating independent and dependent attacks
US20190230099A1
Intelligent data augmentation for supervised anomaly detection associated with a cyber-physical system
US20200322366A1
Privacy preservation of data over a shared network
US20220366083A1
Apparatus for inferring cyberattack path based on attention, and apparatus and method for training intelligent attack path prediction model
US20230047450A1
Cited By
Marine oil and gas equipment data monitoring method and system based on enhanced graph learning
CN120492825A
Electric power FDIA detection method and system based on multi-granularity dynamic graph
CN122333189A