Abstract
This paper presents a novel control strategy framework using adaptive fuzzy support vector machine (FSVM) for enhancing the detection and resilience of Uncertain Nonlinear Markov Jump Cyber-Physical Systems (UNMJCPS) under replay attacks. At first, an introduction to FSVM method is given. Then, the dynamic of UMJCPS with replay attack is presented. In such condition, a resilient adaptive FSVM control mechanism for stabilization of system in condition of abnormal behavior due to replay attacks is proposed. The proposed new approach ensures system stability and performance during and after the attack. Simulation results demonstrate the effectiveness of the control design in mitigating the effects of replay attacks and maintaining system functionality.
Keywords
Introduction
Cyber-Physical Systems (CPS) have become an integral part of modern infrastructures, with applications in sectors such as transportation, energy, healthcare, and industrial automation. These systems seamlessly integrate computational elements with physical processes, enabling real-time data collection, analysis, and control (Duo et al., 2022; Tan et al., 2020). Because many real-world phenomena have stochastic, uncertain and nonlinear nature, Uncertain Nonlinear Markov Jump Cyber-Physical Systems (UNMJCPS) has attracted many attentions in dynamical modeling of CPS. UNMJCPSs are challenging to analyze and control due to the interplay of nonlinearity, Markovian switching, and uncertainties. Specifically, the nonlinearity introduces complexities in stability analysis and controller design, while the Markovian switching introduces randomness and requires handling the system’s evolution across different modes. These systems characterized by discrete modes that switch according to a Markov chain, involve both continuous dynamics within each mode and stochastic switching behavior. On the other hand, these systems are often subject to cyber-attacks, uncertainties, and external disturbances, making their analysis and control challenging.
In general, cyber-attacks imposed on CPS are divided into three general categories: (1) false data injection (FDI) or deception attack, (2) denial of service (DoS) attack, and (3) Replay attack. FDI attacks alter the integrity of data, replay attacks retransmit captured data to deceive systems, and DoS attacks overwhelm systems to make them unavailable. FDI attacks compromise the accuracy of data, while DoS attacks aim to disrupt availability. Replay attacks can be used to compromise both, depending on the context. In this study, replay attack will be considered in the dynamic of UNMJCPS.
As an example for replay attack, in this attack, previous recorded valid sensor data is re-injected into the system, causing the controller to operate based on outdated information, potentially leading to catastrophic consequences (Naha et al., 2022). Replay attacks can have devastating consequences on CPS performance, leading to significant operational disruptions, resource wastage, and even safety hazards. If such cyber threats are not effectively countered, they can lead to significant degradation in system performance and potentially cause severe consequences. A common other example of a replay attack is seen in the remote keyless entry systems used in vehicles (Merco et al., 2018). These systems are designed to enhance user convenience but are vulnerable to this type of attack. By positioning a device that can intercept and send radio signals near the vehicle, the attacker disrupts the legitimate unlocking signal, stores it, and replays an earlier signal. This creates a sequence that stays ahead of the vehicle’s system, allowing the attacker to unlock the vehicle using the stored code. Traditional detection mechanisms, such as anomaly detection and signature-based methods, often fall short in identifying such attacks, especially in nonlinear and stochastic environments that characterize many real-world CPS (Makkar and Jong, 2022; Chu et al., 2024).
Based on aforementioned explanations, because of importance of subjects of MJCPS and cyber-attacks, recently, some researchers have studied in this area. For instance, in Jiyang Wang et al. (2025b), observer-based asynchronous sliding mode control (SMC) strategy has been proposed for MJCPS against DoS attack. Deteng Wang et al. (2025a) proposed dynamic event-triggering asynchronous dissipative control for MJCPS with DoS and deception attack. In Ye et al. (2023), event-triggered-based control for MJCPS against DoS attacks has been investigated. Cao et al. (2024) proposed observer-based adaptive neural H∞ synchronous control for fuzzy MJCPS under FDI attacks. Xu et al. (2023) considered the security-based passivity problem for a class of discrete-time MJCPS in the presence of deception attacks. In Zeng et al. (2022), the event-triggered resilient L∞ control problem for MJCPS in the presence of DoS jamming attacks has been discussed. Neural network (NN)-based event-triggered control problem for discrete-time MJCPS with DoS and deception attacks has been considered in Gao et al. (2023). Wang et al. (2024) discussed the problem of composite H∞ control for hidden Markov jump systems subject to replay attacks. Dynamic-event-based reachable set synthesis for nonlinear delayed MJCPS has been developed in Zhang et al. (2025). Yao et al. (2024) investigated the security control of a class of discrete-time Markov jump systems (DMJS) against DoS and deception attack via switching-Like Adaptive Law. In Liu et al. (2023), security control for MJCPS against actuator failures, FDI attack, and inaccessible states by virtue of state estimator-based adaptive SMC strategy has been developed. Gu et al. (2025) developed dynamic event-triggered H∞ filtering for fuzzy Markov Jump systems subject to mismatched quantization that compromises the data integrity of system.
As per examples of the mentioned papers in the fields of MJCPS and cyber-attacks, one can find that although this area has been very applicable with high potential of development in modeling and control strategy, research studies in this area are limited and bounded in few methods such as robust, adaptive, or neural networks. To mitigate the impact of cyber-attacks like replay attacks, various control strategies have been developed. Among them, Support Vector Machine (SVM) can be integrated with Markov models to enhance their predictive capabilities. Also, SVMs are a powerful machine learning technique widely used for attack detection in various systems. In addition, Fuzzy SVM (FSVM) offer advantages over traditional SVM by being more robust to noisy data and outliers. FSVM assigns fuzzy membership values to data points, making it less sensitive to noise near the decision boundary. In addition, by adding adaptive term to proposed controller, the effects of unknown nonlinearity of system can be eliminated. On the other hands, adaptive FSVM has advantages against methods that until now has proposed for control of MJCPS (see Remark 3 of this paper). Such issues, motivated us to present this work.
Per aforementioned explanations, this paper proposes an adaptive FSVM controller for UNMJCPS. The innovations of this research are:
Designing an FSVM classifier to enhance the detection of replay attacks in UNMJCPS.
Developing a resilient adaptive FSVM control strategy that ensures UNMJCPS stability and performance during and after an attack. Until know, this subject has not been reported in any paper.
The remainder of this paper is structured as follows: The Preliminaries section introduces required Lemmas and the FSVM framework. The Problem formulation section provides a mathematical model of UNMJCPS. In the Resilient controller design section, the proposed mechanism is proved. The Simulation section presents simulation results to validate the effectiveness of the proposed approach. Finally, the Conclusion and Future work direction sections conclude the paper with a discussion on future research directions and potential improvements.
Preliminaries
Applied lemmas
In this work, we use some Lemmas as:
Then if there exist a matrix
(a) There exist a symmetric and positive definite matrix P satisfying:
(b) There exist a symmetric and positive definite matrix P and matrix Y satisfying:
Support vector machine
Consider a set S of labeled training points
where w and b define the hyper-plane, allowing us to classify points based on the function
with
These inequalities must hold for all elements in S. For linearly separable data, it is possible to find a unique optimal hyper-plane that maximizes the margin between the projections of points from the two classes. When the data set S is not linearly separable, classification errors are allowed, and the SVM approach must be modified. This generalization introduces non-negative variables
Non-zero values of
The task of determining the optimal hyper-plane can be structured as follows (Liu, 2021)
Here, C is a regularization parameter that controls the trade-off between maximizing the margin and minimizing classification error. This problem can be solved via the Lagrangian method, which leads to the following dual optimization problem
The Kuhn-Tucker conditions are essential in this context. According to these conditions, the solution
These conditions imply that non-zero
To find the optimal hyper-plane, the following expression is used
The bias term b is derived using the Kuhn-Tucker conditions. Thus, the decision function is written as
On the other hand, one of the strengths of SVM is that a kernel function
Any function that satisfies Mercer’s theorem can serve as a kernel. For example, the polynomial kernel of degree d is expressed as
To create an SVM classifier, the following optimization problem is solved (Oyetade et al., 2022)
The decision function for classifying new data points is given by
Fuzzy property of input
SVMs are a powerful tool for solving classification problems, but they have some limitations. Traditionally, each training point is assigned to one of two classes, and all points in a class are treated equally. However, in real-world situations, the importance of training points can vary. Some points are more critical for classification, while others, such as noisy data, are less significant.
In practice, a training point may not entirely belong to a single class. For instance, a point might be 90% relevant to one class and 10% irrelevant, or 20% relevant to one class and 80% irrelevant. This introduces the concept of fuzzy membership, represented as
To address this, we extend the SVM framework to account for fuzzy membership, creating what is known as Fuzzy Support Vector Machines (FSVMs).
Combination of fuzzy and SVM
Consider a set S of labeled training points with associated fuzzy memberships
Each training point
The optimization problem for determining the optimal hyper-plane in this FSVM framework is formulated as (Wang et al., 2022)
Here, C is a regularization parameter, and
The parameters must satisfy the following conditions to find the saddle point of the Lagrangian
To solve the optimization problem, we need to maximize the objective function
The Kuhn-Tucker conditions for the optimization problem are given by
Here,
Dependence on fuzzy membership
In standard SVM, the parameter C controls the balance between maximizing the margin and minimizing misclassification errors. A larger C reduces misclassifications but narrows the margin, while a smaller C increases the margin but allows for more misclassifications. In FSVM, adjusting the fuzzy membership values
Generating fuzzy memberships
To assign appropriate fuzzy memberships for a given problem, follow these steps: First, set the lower bound for fuzzy memberships. Then, identify the main characteristic of the dataset and link this characteristic to the fuzzy memberships.
For example, in a sequential learning problem, start by establishing a lower bound
where
By applying boundary conditions, you can determine
For a quadratic membership function, you can use
By applying the boundary conditions, we can derive the following equation for fuzzy membership
Problem formulation
Replay attack mechanism
The mechanism of replay attack is clearly shown in Figure 1 (Ilyin, 2025):

Mechanism of replay attack (Ilyin, 2025).
As shown in above figure, a replay attack usually follows a three-phase protocol:
Capturing: Here, the assailant ensnares the data while it is being relayed. This data could take several forms, for instance, login credentials, particulars of a transaction, or any other classified information.
Registering: The snared data is enumerated and hoarded by the miscreant. This data is typically ciphered, making it a herculean task to sniff out the attack in this phase.
Reiteration: The inventoried data is re-broadcast afterward. The system that receives the data assumes it to be a valid request culminating in unsanctioned actions.
As the protocol explains, this attack causes data from previous system times to be intentionally applied to the system in the form of online data; as if the attacker had intentionally delayed sending data to the process. For this reason, replay attack can be formulated mathematically as a system-tolerable delay (Franzè et al., 2019; Huang et al., 2020).
UNMJCPS model description
Let the system be modeled by a state vector
The evolution of the system state depends on the current mode
The switching between different system modes is modeled by a discrete-time Markov process
The process satisfies the Markov property
The proposed control input is as
Replay attack model
As reported in Huang et al. (2020), Franzè et al. (2019), replay attack is a type of cyber-attack that a valid data transmission is maliciously or fraudulently repeated or delayed. Therefore, similar to mentioned papers, in this article, replay attack is considered as delay imposed to input controller as
where
The behavior of the nonlinear MJCPS states, as specified in (25), when subjected to a replay attack can be characterized as
The goal is to design a control law
Resilient controller design
The fuzzy SVM controller is a hybrid approach that combines fuzzy logic and SVM-based control strategies to handle uncertainties and nonlinearities which is applied to the NMJCPS in this paper. In each mode
Let the FSVM control law in mode
where:
L is the number of fuzzy rules.
The SVM controller generates a decision boundary that separates secure and unsecure system as (Figure 2):
while the fuzzy logic system in combination of SVM handles the nonlinearities and uncertainties by blending different control actions.

Secure and unsecure system classification with SVM.
In this work, to compensate the delay introduced by the replay attack, the control input
The FSVM classifier is trained to output control actions based on both the current and delayed states of the system, minimizing the impact of the replay attack on system performance.
In this section, resiliency of UNMJCPS by proposed controller in (32) is proved. The following theorem shows the main result:
where
and utilizing Jesens inequality, we have
where:
for a matrix
where
substituting (35–37) in (34) and using Lemma 2 in Moon et al. (2010) yields
where
applying Shur-complement to (39)
On the other hand, based on Lemma 2, the following inequality holds
and finally applying Lemma 3 and Shur-complement to (41), we reach at
Where
Therefore, if LMI in (42) is satisfied, by positive selected Lyapunov function in (33), we have
Until now, the stabilization of system in each sub-system (it means in each θ Markov jumping) has been proved. In order to prove the stabilization of total system, Generalized Itô Formula is applied in sequel.
By defining expectancy of a function as “E”, we have
Such that
That means

Attack detections algorithm using FSVM.

Flowchart of the proposed resilient algorithm.
In the end of this section, the summary of this work has been presented as flowcharts in Figure 3 (attack detection) and Figure 4 (resilient control):
Comparison this work with other similar papers.
As per Table 1, until now, methods proposed in this area for MJCPS are robust (SMC, H∞), adaptive, event-triggered, and NN. Advantages of this work (adaptive FSVM) against such methods is explained in sequel:
Adaptive FSVM is an online method, while robust mechanism is usually considered as an offline method. Also, it excels at dealing with time-varying or poorly known parameters by dynamically adjusting controller parameters, while robust control focuses on maintaining stability and performance despite a fixed set of uncertainties. FSVM can achieve better performance in highly variable systems, but robust control offers guaranteed stability within defined uncertainty bounds.
While event-triggered control has its merits, the adaptive FSVM approach offers a more comprehensive solution for CPS. The adaptive FSVMs with their integration, high availability, scalability, and automated operations provide a more robust and efficient way than a purely event-triggered approach. In general, time-triggered systems excel in predictability and determinism due to their fixed schedule, making them suitable for safety-critical applications.
Adaptive FSVMs offer several advantages over traditional adaptive control methods, particularly in handling uncertainty and noise in complex systems. FSVMs excel in situations with limited data, nonlinearity, and high dimensionality, providing better generalization and anti-interference capabilities. They can reduce the influence of outliers and noise through fuzzy membership functions, leading to more robust and accurate classifications.
SVMs are often preferred over neural networks (NN) for their robustness to overfitting, efficiency in training, and ability to handle high-dimensional data, especially with smaller datasets. Also, FSVMs offer several advantages over traditional NNs, particularly in scenarios with smaller datasets, higher dimensionality, and the need for interpretable results. FSVMs excel in handling noisy or uncertain data due to their fuzzy nature and can provide more robust solutions than NNs, especially when dealing with limited data.
Simulation
In this section, a numerical case study of a single-link robotic arm (Figure 5) along with a simulation is presented to validate the effectiveness of the obtained results.

Single-link robotic arm.
The mathematical model for the single-link arm, as defined in Tan et al. (2024) is
where
Let
The parameters of the model are given as:
The mode transitions over time represent the switching between two dynamic modes of the system, determined by a Markov chain. This phenomenon is illustrated in Figure 6. This helps visualize the stochastic behavior of the system as it randomly switches between these modes, which can affect its performance and behavior. This plot shows a series of discrete mode transitions, with the system switching between modes 1 and 2 at regular intervals. The duration spent in each mode appears to be roughly equal. The plot suggests a periodic switching behavior or a Markov process governing the mode transitions. However, a more definitive interpretation would require additional context about the system and its dynamics.

Mode transitions over time.
The system output with replay attack plot is shown in Figure 7 which visualizes the behavior of the system’s output under both normal and attack conditions. It compares the original system output (without the attack) to the output that is affected by the replay attack. The blue line represents the system’s output when it is operating normally, without any interference and the red dashed line represents the system’s output when it is under attack. The replay attack replaces the actual output with previously recorded values. It is noteworthy that the attack was applied at the 50th second and lasted for 20 seconds.

System output with replay attack.
By comparing two lines, the impact of the replay attack on the system’s behavior can be observed. It can be seen how the attack deviates the output from its normal trajectory. The plot reveals that the replay attack introduces noticeable deviations from the normal output, suggesting its effectiveness in disrupting the system’s behavior.
The state trajectory (State 1 and 2) with replay attack plots visualizes the evolution of the system’s internal states (State 1 and State 2) under both normal and attack conditions. These figures are shown in Figures 8 and 9, respectively. By comparing the normal and attacked state trajectories, the impact of the replay attack on the system’s internal behavior can be seen. If the attack is successful, the state trajectories will deviate significantly from their normal paths, indicating a compromised system. It is observed that by applying FSVM control, the attack effect is eliminated, and the system states under normal and attack conditions are approximately equivalent, showing no deviation.

State 1 trajectory with replay attack.

State 2 trajectory with replay attack.
The primary purpose of the SVM in this context is to differentiate between normal operational data and data affected by a replay attack. By training on labeled data (normal operation vs attack), the SVM can learn the distinguishing features of each class. The SVM model is trained with the training data composed of outputs from normal operation and attack scenarios.
After training, the SVM model is used to predict anomalies in the output data during the replay attack: The predictions are based on the attack data, which includes manipulated output values during the attack phase. The SVM predicts whether each output value belongs to normal operation or indicates an anomaly.
In the prediction phase, the predictions from the FSVM are initially in the form of
The role of control action using fuzzy logic in this context is to provide a resilient control strategy that can mitigate the effects of the replay attack. This control action is provided in Figure 10. The plot shows a series of spikes in the control action, indicating that the controller is actively adjusting its output to counteract the effects of the replay attack. The specific shape and timing of the spikes would depend on the fuzzy logic rules and membership functions used in the controller’s design. This illustrates how the control action changes in response to the system’s state and the detection of anomalies. The plot may show a significant increase in control action values during the attack, indicating a stronger response to mitigate the detected anomaly.

Control action using fuzzy logic.
The tracking error with replay attack serves as a critical metric for evaluating the system’s performance and resilience against replay attacks. This metric is shown in Figure 11.

Tracking error with replay attack.
After the attack ends, the tracking error may gradually decrease as the system recovers from the attack’s effects. However, the extent of recovery depends on the system’s resilience and the severity of the attack.
This plot is valuable for assessing the impact of the replay attack on the system’s performance and evaluating the effectiveness of the implemented detection and resilience mechanisms. A significant increase in tracking error during the attack indicates that the system’s performance is compromised, while a successful recovery suggests that the resilience mechanisms are working as intended.
The State 2 vs State 1 plot serves several important roles in visualizing and analyzing the system’s behavior during both normal operation and under a replay attack. This plot is shown in Figure 12.

State 2 vs State 1.
Plotting State 2 vs State 1 shows the convergence of the curve to the system equilibrium point
In the end of this section and in order to show advantages of FSVM against SVM, we have applied SVM without fuzzy logic to system (45). Table 2 show the advantages of results when fuzzy logic is combined with SVM:
SVM vs fuzzy SVM results.
According to Table 2, in this example, by applying FSVM method, the results in some parameters such as nonlinear term strength, upper bound of the delay imposed by the attacker, and settling time were improved by 40%, 29%, and 12% compared to the SVM method, respectively.
Conclusion
In this paper, a novel control strategy using a Robust Adaptive FSVM-based framework was proposed to enhance the detection and resilience of uncertain nonlinear Markov jump cyber-physical systems (UNMJCPS) under replay attacks. Through the integration of adaptive mechanism with FSVM, a robust detection mechanism capable of handling the stochastic and unknown nonlinear nature of UNMJCPS was developed, while ensuring system stability and performance during and after an attack. The Markov jump model captured the system’s mode transitions effectively, and the FSVM classifier provided accurate anomaly detection, allowing the system to mitigate the effects of replay attacks in real time. Also, adaptive mechanism was designed to eliminate the effect of the unknown nonlinear term of the system. Simulation results demonstrated the efficacy of the proposed approach.
Future work direction
While the proposed framework has been effective as a new subject in this area, there are some points that require further exploration to enhance the capabilities and adapt to future challenges and can improve results in this work:
Integration of robust control that has good results in system with external disturbance (Shen et al., 2021) can be considered as next future work in this subject.
In a control system when states are not directly measurable or when sensor data is noisy or unreliable, an observer design is considered to estimate the internal states of system (Shen et al., 2022). Adding observer design to the results of this research can be considered as a topic for further study in this area.
The upper and lower bound of delay imposed to the system (because of attack) is assumed to be known that is conservative assumption. Considering other assumptions such as stochastic delay or unbounded delay, can help to improve results obtained in this work.
Footnotes
Author contributions
All study conception and designs, material preparation, data collection and analysis of this work were performed by the author.
Funding
The author received no financial support for the research, authorship, and/or publication of this article.
Declaration of conflicting interests
The author declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Data availability statement
Data sharing is not applicable to this article, as no data sets were generated or analyzed during the current study.
