The proposed detection method in this study, which involves smooth watermarking, encoding, and decoding, aims to address replay attacks in time-delay systems during communication. Implementing an event-triggered technique helps save communication resources and cut down on unnecessary information transmission. A weighted sliding average method is employed to smooth the system’s watermark influenced by time delay, decreasing unnecessary fluctuations and boosting anti-attack resilience. The encoding and decoding systems were ingeniously designed to increase the invisibility of the smooth watermarking, making it more sensitive in detecting replay attacks. Multiple attack scenarios are meticulously examined, after which rigorous simulation tests are carried out to prove the proposed scheme’s reliability, effectiveness, and substantial superiority.
In the modern information society, the normal operation of systems inevitably relies on network-based wireless or wired communication. It also provides an opportunity for potential attackers to elaborate and implement attacks to undermine the system’s integrity, operability, and information security (Sourav and Chen, 2023), such as malware (Gaber et al., 2024), Denial-of-service (DoS) attacks (Jiang et al., 2024), man-in-the-middle attacks (Jena et al., 2023), false data injection (FDI) attacks (Jafari et al., 2023), and replay attacks (Jelil et al., 2024). The central theme of this paper is to delve into one of the attack types, namely replay attacks. A replay attack, as a common form of network security attack, refers to a security threat in which attackers use unauthorized methods to hijack legitimate data and send it repeatedly to the server maliciously to deceive the system (Liu et al., 2023).
In recent years, scholars have conducted in-depth research on replay attacks in many practical fields (Yu et al., 2023). Scholars focusing on supervisory control and data acquisition (SCADA) systems are particularly interested in how replay attacks can be applied in industrial sites. A comprehensive data-driven framework was established for detecting device failures and preventing the malicious replay attack (Li et al., 2021). But this framework is mainly limited to linear time-invariant stochastic state space models. Thanks to the Diffie-Hellman key exchange mechanism, field devices were able to swiftly and securely generate new shared keys (Cebe et al., 2019). Another focal point for scholars is to study replay attacks in networked control systems (NCSs). In response to replay attacks, Tahoun and Arafa (2021) developed a distributed adaptive master-slave security controller, and Trapiello and Puig (2022) brought in a zonotopically bounded watermark signal. Simultaneously, a wealth of labor has been accomplished in cyber-physical systems (CPS) to combat a replay attack. Li et al. (2023) introduced a dynamic encryption technology that showed no decline in performance. Yet its periodic detection typically relies on the system clock. If attackers are aware of the period interval’s periodicity, they can manipulate it to avoid detection or disrupt the watermark. The constraint of dynamic watermarking to LTI systems was explored (Porter et al., 2021), and Yang et al. (2023) offered a novel detection mechanism covering PI controller watermarking. However, few current detection studies discuss the detection of replay attacks in time-delay systems. Some researchers are more inclined to explore the delay caused by replay attacks. Both Fang et al. (2020) and Gargoum et al. (2024) tackled the issue of replay delay in attack detection. When discussing replay delay, we are referring to the time interval between the attacker collecting the information and launching the attack (Bian et al., 2024). Another part of the research addresses the challenge of controlling the time-delay system when it is under attack. For example, Xu et al. (2021) deeply discussed robust control techniques for uncertain time-varying delay systems under replay attacks. A decentralized observer based on the predictor was recommended for time-delay systems, offering the ability to predict replay data in the presence of a replay attack (Yang and Zhai, 2024). Accurate detection and recognition of replay attacks are crucial for the systems to meet these goals. Our research’s significance in detecting replay attacks in time-delay systems is emphasized here.
This paper introduces a method for detecting replay attacks in time-delay systems that combines smooth watermarking with coding and decoding processes. Utilizing state space expansion helps transform the system with time delay into a delay-free system. By adopting a flexible communication strategy, we are able to transmit information based on an event-triggered mechanism, thereby avoiding the challenge of overcommunication (Wu et al., 2013). Additionally, by smoothing the watermark signal, the noise immunity of the watermark is enhanced to increase its invisibility. The encoded and decoded data are fed into the Kalman estimator to estimate the state values. It shows a lower performance loss compared to the model with the unprocessed watermark signal. By formulating an optimization problem, the ideal balance between sliding window size, watermark signal variance, detection rate, and performance loss is attained. Finally, simulation results validate the effectiveness of the designed scheme.
Notation: stands for n-dimensional Euclidean space, is diagonal matrix, represents the trace of the given matrix, and are the two-norm and the Hölder infinity-norm, respectively. is a Gaussian random distribution with expectation and covariance , and signifies a uniform distribution with an expected value of and a covariance of . The superscripts “T” and “-1” stand for the transpose of a matrix and inverse matrices, respectively. The n-dimensional identity matrix is expressed by , while the n-dimension zero matrix is represented by . In sequence, the symbols , , and are assigned to the mathematical expectation, variance, and covariance of the variable.
Preliminaries
Model
A discrete time-delay system in the form of the following equations is considered:
where , , and indicate the state vector, the control input vector, and the output vector of the system, respectively. , , , and are the known matrices with appropriate dimensions. The constant time delay is symbolized by . The process noise is , and means the measurement noise. They are Gaussian random variables and independent of each other. and are the corresponding non-negative definite covariance matrices.
The delay-free system
Solving the time-delay problem in the system model is crucial, prompting the revision of the original model to remove delays. Extending the system variables creates a larger state space for achieving the delay-free system, which attenuates the system’s complexity due to time delay, making it easier to handle and analyze. Let , ; then equation (1) can be reconstructed as
where , , , , , , and are mutually independent. and the symmetric positive definite covariance matrix is .
Event-triggered Kalman filter estimation
The data need to be transferred via LANs, WANs, and even the Internet. The Kalman filter (Li et al., 2024) is integrated with the event-triggered communication strategy (Li et al., 2021) to optimize transmission efficiency and improve resource utilization.
According to Liu et al. (2017), there exists a unitary matrix satisfying the following conditions:
where is the eigenvalue of at time . Set . The is determined for each moment based on the preceding formula, and define the measurement update as . Let ; the event-triggered mechanism can be set as
where is the triggering parameter and the data set of the actual communication at time is . By evaluating the stated conditions, is obtained. Once , the latest data is transmitted to the estimator, causing the filter to become a conventional Kalman filter. In the case of , the state estimation is replaced by , subsequently influencing the measurement update. The detailed procedure of Kalman estimation based on equation (4) is as follows:
(1) Time update
Taking into account the triggering condition, if the posterior estimate and the posterior covariance of the Kalman filter at time are and , the prior estimation and prior covariance after time update can be expressed as (Huang et al., 2024):
(2) Measurement update
When , , the posterior estimate can be characterized as
is transmitted by the sensor to the estimator, resulting in the estimation error being . As indicated in Liu et al. (2017), it is evident that
Let the partial derivative of to be zero, and we can deduce
and
When , the posterior estimate is .
Following the calculation, it became clear that
where , .
Combined with the preceding content, the event-triggered Kalman estimation is
The following equation is chosen as the linear quadratic Gaussian (LQG) cost (Su et al., 2020):
where and are the corresponding positive definite weight matrices. Define ; satisfies the Riccati difference equation. The optimal control law at steady state can be achieved:
where is the gain matrix of optimal control. The optimal control performance loss is (Mo et al., 2014)
where is the trace of the corresponding matrix and and are the steady-state values of filter gain and prediction error covariance corresponding to the system at steady state, respectively.
Replay attack detection
Smoothing of watermark
A replay attack is a well-known threat that is often found on stable systems (Li et al., 2022). During message delivery, the communication link may be threatened by a potential replay attack. The watermark signal is viewed as a successful tool in defending against attacks. The watermark signals, labeled as , consist of Gaussian random noises with the same probability distribution and being mutually independent (Naha et al., 2023). is the diagonal variance matrix of normal distribution. Using a weighted sliding average method helps keep the watermark signal steady when faced with sudden changes such as system disruptions, abnormal occurrences, or external influences.
where is the watermark signal after smoothing, represents weight and is independent of , . As is uniformly distributed between (0,1), the observed value obtained after weighting calculation is typically lower than the true value. The preceding equation is modified by incorporating a correction factor to address this deviation:
where and signifies the radius of the sliding window.
Coding and decoding
The watermark signal, through encoding, boosts data security and allows traceability, reducing chances of tampering. Before being transmitted to the Kalman estimator, the data must be encoded. The coding model can be specified as
The model of the system after adding the smoothed watermark signal and the coded signal is
where the initial state is and . Decode the encoded data at the state estimator receiver side to restore the original system model. The decoded signal can be written as
The initial values of the states of the encoded and decoded signals satisfy . During stable operation of the system, the signal received by the Kalman estimator receiver is
The final output signal can be accurately restored to the output signal of the original system model. The state prior estimation after adding smooth watermarking, encoding, and decoding is recorded as . Comparing the priori estimates with , it can be seen that
where . The invisibility of a replay attack is discussed in depth by Mo et al. (2014). When is unstable, the detector can accurately identify the attack signal. If is stable, the detector has trouble spotting anomalies as the attacker inserts legitimate historical messages, enabling the replay attack to evade detection. The following analyzes how the detector identifies a replay attack while remains stable. After adding the smoothing watermark, coding signal, and decoding signal to the system, the state prior estimation is equal to the initial state prior estimation when the system is running smoothly. Figure 1 presents a comprehensive overview of the proposed methodology.
The system frame diagram.
Detectability of replay attack
Provided that the system operates stably, the residual signal after Kalman state estimation is
It is apparent from the preceding equation that the residual signal in the current case is consistent with the residual signal when no signal has been added, thus preserving the stability of the system.
Lemma 1. (Mo et al., 2014) In an LTI system, it is presumed that the model constructed from equation (2) exists. If it uses an LQG controller as well as a Kalman estimator, in this case the estimated system residual is subject to multivariate normal distribution , and the covariance matrix .
The detection function following Kalman estimation can be outlined as
where serves as the primary detection signal, follows distribution, the degree of freedom is , and is the detection threshold. When the communication link is not subjected to a replay attack, that is, is satisfied, it stays within the range of the set detection threshold. If is satisfied, it indicates that the communication link is vulnerable to a replay attack. If the false alarm rate is set to , then we can get (Guan and Ge, 2018).
Assume that the communication link is exposed to a replay attack in the time domain of and the attacker opts to replay legitimate historical data . The corresponding state and watermark are and . is the residual signal after decoding, while reflects the state prior estimation.
Theorem 1. With smoothed watermarking (17), encoding (18), and decoding (20) methods used, if the injected watermark signal at time does not match the historical legitimate watermark signal replayed by the attacker, that is, , it can be determined that the communication link is subject to a replay attack, that is, the attack can be detected.
Proof. When the replay attack occurs, it is known that the attacker’s historical legitimate data satisfies , , and . The actual residual is
where . The attacker conducted a replay attack, replacing real data with historical data, leading to , . The system’s consistent stability over time suggests that .
where . Let ; the injected data from the attacker contains the encoding model. The decoding model’s independence prevents it from being susceptible to replay attacks, as it belongs to an external system. From , we can get
The residual of the system subjected to a replay attack can be described as
where is the historically legitimate residual. can be reformulated as
where is a legitimate history detection value. Based on , when a replay attack is implemented on the communication link, it holds that , indicating the detector’s capability to capture the hacker’s replay attack.
Suppose that after adding the smooth watermarking, the state variables of the system satisfy and is the difference between the state with and without smooth watermarking. Let ; the LQG cost is restated as
where and the additional performance loss is . The additional performance loss that injects the unsmoothed watermark signal is . and after adding the smoothed watermark signal are and .
It can be concluded that as increases, the variance of the smooth watermarking decreases, ultimately reducing . In recognizing the replay attack, aim for a high variance in the smooth watermark signal. The larger the variance, the better the detector’s indicator and the easier it is to recognize anomalies. Obviously, cannot be set to infinity in real production. This means that needs to be enlarged to minimize while ensuring that the watermark signal is large enough for the system to sense replay attacks in time. The proof is complete.
Remark 1. The proposed technique results in a substantially smaller performance loss for the system compared to the performance loss incurred by an unsmoothed watermark.
The system performance
The best LQG performance can be calculated by thoroughly assessing the sliding window radius, watermark signal variance, residual covariance, detection rate, and false alarm rate in the event of a replay attack. The aim is to strike a balance between system stability and the capacity to detect anomalies, guaranteeing efficient and orderly system operation during an attack.
where is the upper bound of caused by adding the smooth watermark signal and ∂ is a lower bound of the mathematical expectation of . Let .
The asymptotic expectation of the detection function under attack is
Let the parameter conform to , so if , that is, the value of the detection function exceeds the preset threshold, the detector is triggered, indicating that the communication link is under a replay attack.
Given that the false alarm rate is under , it is acknowledged:
In the case where holds, obeys the distribution, and the preceding equation is equivalent to . Let’s use to symbolize the detection rate of the attack. When it is certain that the detection rate is not lower than , it is recognized that
As a result, the inequality below is valid:
where the smallest eigenvalues of and are denoted as and , respectively, while represents the largest eigenvalue of . The calculation gives .
Furthermore, the inequality holds.
Simulation verification
Consider the continuous stirred tank reactor (CSTR) system as shown in Figure 2.
CSTR system model.
The reactor temperature and the outlet concentration are the controlled variables. Coolant temperature and feed temperature are operating variables. The reaction process can be articulated as
where and the cycle time is . Table 1 provides the values and physical interpretations of the other parameters:
Parameter settings and physical significance of the CSTR system.
Parameters
Physical interpretations
Values
Parameters
Physical interpretations
Values
Feed concentration
Feed flow rate
Material density
Reactor volume
Specific heat capacity
Reaction frequency factor
Heat of reaction
Exponential factor
Heat transfer term
Feed temperature
Set the state as and the input is . Following the steps of linearization and discretization, we obtain , , , . With the time-delay parameter and the noises in mind, they are , , and . Set , , , and . The detection rate is set to be and the false alarm rate to be . By computing the optimization problem of equation (31), , , and can be obtained. Consequently, is obtained.
As can be seen from the comparison of the detection rates in Figure 3, the addition of the watermarked signal causes to rise dramatically. With a constant , is proportional to , and the smoothed watermark’s detection rate outperforms the original watermark by a significant margin. While stays the same, goes up as gets higher. However, once exceeds a certain level, begins to grow more slowly. The performance loss from the watermarked signal has been substantially mitigated in Figure 4 following the smoothing process. is inversely proportional to , and is proportional to it, supporting equation (31).
The relationship between , , and .
The relationship between , , and .
The LQG cost of the system can be known from Figure 5. The proposed method yields a smaller than both Ahmed et al. (2022) and unsmoothed watermarks, having minimal impact on the system. Over-averaging occurred by a too-large can distort the watermarked signal and negative impact control performance. The ratio diagram representing the optimal performance loss and is constructed for . Observing the trend, it is evident that a higher value of results in fewer optional original watermark signals and substantial data fluctuations. The results displayed in Figures 4 and 5 suggest that increasing can alleviate the additional performance loss, but an excessively high causes considerable data fluctuations that compromise the stability of the system. Finding a more efficient method for choosing the correct while ensuring control performance and detection effectiveness is a future priority.
The LQG cost and performance ratio.
It is believed that the system model can go back to its normal state after being attacked. Different attack scenarios are considered to evaluate the performance of the detection function according to the characteristics of the replay attack: (a) The attacker replicates the information from 0∼150s and launches the attack at 151s, keeping it active until 300s; (b) data is copied by the attacker within 50s∼100s, with the attack being executed only between 200s∼250s; (c) at 50s∼100s, the attacker duplicates the data and proceeds to launch attacks at 150s∼200s and 250s∼300s; (d) the intruder illicitly acquires data during the 50s∼80s and 150s∼180s and then carries out attacks at the 100th and 200th seconds, each lasting 31 seconds.
The results presented in Figure 6 highlight the capability of the proposed detector to quickly detect anomalies when facing a replay attack. Observations show that in the absence of an attack, there is a notable decrease in false alarms when compared to Ahmed et al. (2022), thanks to the smoothing mechanism of the proposed method that diminishes the impact of random noise. Detection of Ahmed et al. (2022) experiences delay in various attack scenarios, with instances where attacks are not detected. In contrast, the proposed method excels in promptly detecting anomalies as soon as an attack begins and throughout its duration, yielding a markedly superior detection capability. The key strength of our design solution lies in its sensitive detection mechanism, which effectively safeguards the system against replay attacks.
Attack detection in different scenarios.
Conclusion
An approach has been developed to recognize replay attacks, employing both the smoothing watermark and the coding-decoding framework. By employing the weighted sliding average method, the watermark signal in the time-delay system is smoothed, resulting in improved robustness against noise and jitter. It has increased the challenge for malicious attackers to detect and remove the watermark signal, helping make the watermark more hidden. The introduction of the event-triggered mechanism aims to eliminate data redundancy and mitigate network congestion. The simulation results of the CSTR system have further validated the feasibility and robustness of the designed method in many different scenarios, laying a solid foundation for practical applications.
It is crucial to emphasize that smoothing may ignore some signal details, potentially resulting in distortion or loss of the watermark signal. During the early phase, a boundary effect may arise from limited data. Invaders may also craft attacks tailored to bypass the detection of smooth watermarks. The underlying premise of this paper is that the system noise exhibits a Gaussian distribution, although the actual circumstances are often more variable. More exploration is needed to extend these findings and pave the way for additional research efforts.
Footnotes
Acknowledgements
Throughout the entire writing process, I was fortunate to have received continuous support and help in the preliminary preparations, research, and overall writing.
First of all, I would like to thank my supervisor, Prof. Li, whose profound knowledge has directed my research toward the right direction and propelled it to a more advanced stage.
A special thank-you to the other teachers who bestowed upon me valuable advice and instilled a wealth of useful knowledge.
Additionally, I attribute much of my success to the guidance and support of my classmates.
Finally, I am deeply grateful to my parents for their unwavering support and the love that has shaped me into a stronger person.
A careful review indicates that this segment may be repeated in the following content. Kindly re-evaluate; if not, please ignore this revision.
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This work was supported by the National Natural Science Foundation of China under Grants 62203080, 62203166, 62273068, 52471374, the China Postdoctoral Science Foundation under Grant 2023M740467, the Natural Science Foundation of Liaoning Province under Grants 2023-BS-073 and 2023-MS-120.
ORCID iD
Ping Li
Data availability statement
The data that support the findings of this study are available from the corresponding author on reasonable request.
References
1.
AhmedCMPalletiVRMishraVK (2022) A practical physical watermarking approach to detect replay attacks in a CPS. Journal of Process Control, 116: 136–146.
2.
BianGLongYLiT, et al. (2024) Watermark-Based Replay Attack Detection for Unmanned Marine Vehicles. IEEE Transactions on Intelligent Vehicles pp.1–10.
3.
FangCQiY, et al. (2020) Optimal periodic watermarking schedule for replay attack detection in cyber-physical systems. Automatica112:108698.
4.
GaberMGAhmedMJanickeH (2024) Malware detection with artificial intelligence: A systematic literature review. ACM Computing Surveys56(6):1–33.
5.
GargoumSYassaieN, et al. (2024) A data-driven framework for verified detection of replay attacks on industrial control systems. IEEE Transactions on Automation Science and Engineering.
6.
GuanYGeX (2018) Distributed attack detection and secure estimation of networked cyber-physical systems against false data injection attacks and jamming attacks. IEEE Transactions on Signal and Information Processing over Networks4(1): 48–59.
7.
HuangJYangWHoDWC, et al. (2024) Security analysis of distributed consensus filtering under replay attacks. IEEE Transactions on Cybernetics56(6):3526–3539.
8.
JafariMRahmanMAPaudyalS (2023) Optimal false data injection attack against load-frequency control in power systems. IEEE Transactions on Information Forensics and Security18:5200–5212.
9.
JelilSSinhaRPrasannaSRM (2024) Spectro-Temporally Compressed Source Features for Replay Attack Detection. IEEE Signal Processing Letters31: 721–725.
10.
JenaSPadhyNPGuerreroJM (2024) Multi-layered coordinated countermeasures for DC microgrid clusters under man in the middle attack. IEEE Transactions on Industry Applications60(2): 2127–2141.
11.
JiangYNiuBZhaoX, et al. (2024) Intelligent consensus asymptotic tracking control for nonlinear multiagent systems under denial-of-service attacks. IEEE Transactions on Automation Science and Engineering pp.1–12.
12.
LiDGebraeelNPaynabarK (2021) Detection and differentiation of replay attack and equipment faults in SCADA systems. IEEE Transactions on Automation Science and Engineering18(4):1626–1639.
13.
LiSLiZLiJ Y, et al. (2021) Application of event-triggered cubature Kalman filter for remote nonlinear state estimation in wireless sensor network. IEEE Transactions on Industrial Electronics68: 5133–5145.
14.
LiTWangZZouL, et al. (2023). A dynamic encryption-decryption scheme for replay attack detection in cyber-physical systems. Automatica, 151:110926.
15.
LiWQianHZhangM, et al. (2022) Stealthy replay attack detection of 3-DOF helicopter benchmark system using dynamic watermarking approach. Transactions of the Institute of Measurement and Control.
16.
LiXLeiAZhuLBanM (2024) Improving Kalman filter for cyber physical systems subject to replay attacks: An attack-detection-based compensation strategy. Applied Mathematics and Computation466: 128444.
17.
LiuQLongYLiT, et al. (2023) Fault detection for unmanned marine vehicles under replay attack. IEEE Transactions on Fuzzy Systems31(5):1716–1728.
18.
LiuX HMoYGaroneE (2017) Secure dynamic state estimation by decomposing Kalman filter. IFAC-PapersOnLine50 (1):7351–7356.
19.
MoYChabukswarRSinopoliB (2014) Detecting integrity attacks on SCADA systems. IEEE Transactions on Control Systems Technology22 (4):1396–1407.
20.
NahaATeixeiraAMAhlénA, et al. (2023) Quickest detection of deception attacks on cyber-physical systems with a parsimonious watermarking policy. Automatica155: 111147.
21.
PorterMHespanholPAswaniA, et al. (2021) Detecting generalized replay attacks via time-varying dynamic watermarking. IEEE Transactions on Automatic Control66 (8):3502–3517.
22.
SouravSChenB (2023) Exposing hidden attackers in industrial control systems using micro-distortions. IEEE Transactions on Smart Grid15(2): 2089–2101.
23.
SuLYeDZhaoX (2020) Static output feedback secure control for cyber-physical systems based on multisensor scheme against replay attacks. International Journal of Robust and Nonlinear Control30:8313–8326.
24.
TahounAHArafaM (2021) Cooperative control for cyber-physical multi-agent networked control systems with unknown false data-injection and replay cyber-attacks. ISA transactions110:1–14.
25.
TrapielloCPuigV (2022) A zonotopic-based watermarking design to detect replay attacks. IEEE/CAA Journal of Automatica Sinica9 (11):1924–1938.
26.
WuJJiaQ SJohanssonK H, et al. (2013) Event-based sensor data scheduling: trade-off between communication rate and estimation quality. IEEE Transactions on automatic control58 (4):1041–1046.
27.
XuXLiX, et al. (2021) Robust reset speed synchronization control for an integrated motor-transmission powertrain system of a connected vehicle under a replay attack. IEEE Transactions on Vehicular Technology70: 5524–5536.
28.
YangCChuZMaL, et al. (2023) Joint watermarking-based replay attack detection for industrial process operation optimization cyber-physical systems. IEEE Transactions on Industrial Informatics2023; 19 (8):8910–8922.
29.
YangMZhaiJ. (2024) Predictor-based decentralized event-triggered secure control for nonlinear cyber-physical systems under replay attacks and time delay. IEEE Transactions on Control of Network Systems11: 150–160.
30.
YuYYangWDingW, et al. (2023) Reinforcement learning solution for cyber-physical systems security against replay attacks. IEEE Transactions on Information Forensics and Security18:2583–2595.