Resilient Cyber-Attack Detection via Latent Feature Estimation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, and existing methods fail to automatically detect such attacks at the domain layer where sensors and actuators are located, especially when multiple attacks occur simultaneously.

Innovation Solution

A dynamic, resilient estimator constructs a latent feature space using normal monitoring node values to detect abnormalities and computes optimal values to minimize reconstruction error, replacing compromised sensor measurements with estimated values from healthy sensors, thus providing continuous operation without the need for redundant components or major system changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual sensing is used to estimate compromised sensor measurements, then system functionality is maintained during cyber-attacks, but the development time increases due to the need to develop and store substantial numbers of estimation models for different attack scenarios

Engineering Contradiction:
Improvesystem functionality during attackVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic model selection that adapts to current system conditions and attack scenarios. The estimator dynamically determines which estimation models to apply based on real-time monitoring of sensor data patterns and attack detection, eliminating the need to pre-develop and store all possible estimation models for every conceivable attack scenario. This dynamic approach maintains reliability during attacks while significantly reducing development time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of the estimation process based on detected attack characteristics. When different types of cyber-attacks are detected (e.g., sensor compromise, actuator manipulation), the system adjusts the estimation parameters and model selection accordingly. This parameter-based adaptation allows a single flexible estimation framework to handle multiple attack scenarios without requiring separate pre-developed models for each scenario.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple estimation models are developed to cover all possible attack scenarios, then detection accuracy improves, but device complexity increases due to the substantial number of models that must be developed and stored

Engineering Contradiction:
Improveattack detection accuracyVSAvoidnumber of estimation models
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal estimation framework that can handle multiple attack scenarios through a single flexible architecture. The system uses a core set of estimation models combined with dynamic parameter adjustment and model selection capabilities, allowing one universal system to perform the function of what would otherwise require many specialized models. This universality maintains detection accuracy while reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer between the sensors and the control system that acts as a smart mediator. This intermediary (the virtual estimator) uses a compact set of base models combined with real-time adaptation mechanisms to process sensor data, detect attacks, and provide accurate estimates. This intermediary approach achieves high detection accuracy without requiring the control system to directly manage complex arrays of specialized estimation models.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If traditional failure diagnostic technologies are used to detect attacks, then existing system components are utilized, but detection capability is insufficient for multiple simultaneous attacks and stealthy attacks at the domain layer

Engineering Contradiction:
Improveuse of existing componentsVSAvoidattack detection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces traditional mechanical/failure-based diagnostic approaches with a software-based virtual sensing and estimation system. Instead of relying on physical redundancy or traditional failure detection mechanisms, the system uses computational estimation models that can detect and compensate for multiple simultaneous attacks and stealthy attacks. This substitution maintains ease of implementation using existing sensors while dramatically improving detection capability through advanced algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11411983B2Dynamic, resilient sensing system for automatic cyber-attack neutralization
Publication Date: 2022.08.09 GE INFRASTRUCTURE TECH LLC
  • US11411983B2 patent drawing
  • US11411983B2 patent drawing
  • US11411983B2 patent drawing

AI summary

An industrial asset may have monitoring nodes that generate current monitoring node values. An abnormality detection computer may determine that an abnormal monitoring node is currently being attacked or experiencing fault. A dynamic, resilient estimator constructs, using normal monitoring node values, a latent feature space (of lower dimensionality as compared to a temporal space) associated with latent features. The system also constructs, using normal monitoring node values, functions to project values into the latent feature space. Responsive to an indication that a node is currently being attacked or experiencing fault, the system may compute optimal values of the latent features to minimize a reconstruction error of the nodes not currently being attacked or experiencing a fault. The optimal values may then be projected back into the temporal space to provide estimated values and the current monitoring node values from the abnormal monitoring node are replaced with the estimated values.