Papers for

industrial control system security teams

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Physics attested federated learning secures water system anomaly detection

Physics-Attested Federated Learning: Securing Collaborative Anomaly Detection in Critical Water Infrastructure

Abstract: Federated learning enables industrial operators to train shared intrusion detection models without disclosing proprietary operational telemetry. However, existing defenses operate strictly in update space, leaving aggregators blind to data poisoning; model updates derived from fabricated telemetry remain indistinguishable from honest contributions. We repurpose cyber-physical process invariants, such as conservation laws and actuator couplings, from runtime detection heuristics into a verifiable admission requirement for federated updates, mined automatically from clean operational data. We evaluate this admission gate across two physical water testbeds (SWaT, WADI) and a distribution benchmark (BATADAL), testing seven aggregation rules against telemetry fabrication, exposure-only replay poisoning, and an invariant-aware adaptive adversary. Across three testbeds the mined invariants reject none of 100 honest shards and all naively fabricated ones, including optimised perturbations that FoolsGold admits in full. On real telemetry, five mined invariants detect 12 of SWaT's 35 attacks, while nine invariants detect 20, with no honest shard rejected. With nine rules, the physics gate recovers 69--100% of the targeted-attack recall lost to replay poisoning, and 54--100% of that lost to fabricated telemetry, across five standard aggregators. To reconcile physical admission control with federated data privacy, we show invariant compliance using zero-knowledge proofs (zk-SNARKs) to allow clients to prove batch adherence without revealing operational telemetry.

Mon 28 SeptCryptography and SecurityMachine Learning
The gist
Detecting attacks on critical water systems is important but sharing data between operators risks privacy. The authors show how to use the natural physical laws and rules governing water systems to check if data updates are genuine without revealing sensitive information. This approach blocks fake or poisoned data during collaborative machine learning, improving security in water network monitoring. They tested this method on real water system datasets and found it effectively detects attacks while keeping honest data safe.
Open → 2609.34804v1

AI improves layered cyber defense but full human review reduces accuracy

Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration

Abstract: Cybersecurity literature has extensively documented the operational benefits of artificial intelligence (AI) for threat detection, incident response, and prevention, while raising qualitative concerns about over-automation, algorithmic bias, and analyst-skill erosion. What remains largely absent is a formal, falsifiable model connecting three constructs that recur across this literature: Defense-in-Depth Theory, the Artificial Intelligence Theory of Pattern Recognition, and human-AI collaboration in security operations. This paper develops such a model. We formalize layered defense as a Bernoulli detection cascade in which AI augmentation enters multiplicatively across layers; we formalize each layer's pattern-recognition behavior as a Neyman-Pearson/Bayesian detector with a derived closed-form optimal threshold; and we formalize human-AI triage as a capacity-constrained cascade with an explicit, quantifiable trade-off between detection probability and false-alarm ("alert fatigue") rate. A Monte Carlo/analytical simulation evaluated at illustrative but realistic operating points shows that (i) AI augmentation compounds across defense layers, delivering its largest marginal gains exactly where traditional layering saturates, and (ii) full human review of AI-flagged alerts is not optimal: increasing analyst capacity toward 100% coverage cuts false alarms by roughly 20-fold but simultaneously lowers system-level detection probability, because imperfect analyst accuracy is then applied to every alert rather than a filtered subset. These results give the widely repeated qualitative recommendation of "balanced human-AI collaboration" a precise, testable form and suggest an interior-optimum capacity ratio as a concrete design target for security operations centers (SOCs), including those securing IT/OT-converged critical infrastructure.

Tue 22 SeptCryptography and SecurityArtificial Intelligence
The gist
Detecting and stopping cyber attacks is hard and often uses multiple layers of security. This paper shows how using AI in these layers can multiply the chances of catching threats, especially where traditional defenses stop improving. However, having humans review every AI alert can actually lower overall detection because humans make mistakes, and reviewing fewer, filtered alerts strikes a better balance. The authors provide a clear model to find the best mix of AI and human effort in cybersecurity teams.
Open → 2609.25921v1

Electric vehicle charging station software needs stronger security checks

Wicked Problem, Parsimonious Solution: Securing Electric Vehicle Charging Station Software

Abstract: Electric vehicle charging infrastructure presents a suite of novel cyber-physical threats. Among this infrastructure, charging stations are the most vulnerable elements. The software in the charging station supply equipment is particularly vulnerable. Currently, the software is an attack surface that is largely unprotected and poorly characterized. To represent the vulnerabilities in this attack surface, we advocate for applying modern software quality assurance to characterize vulnerabilities in electric vehicle charging station software. Specifically, we advocate for the application of hierarchical software quality assurance (HSQA) to specialized electric vehicle charging station software. HSQA provides a comprehensive view of the code quality and security -- from the level of individual vulnerabilities (e.g., CVEs) to high level characteristics (e.g., CIA Triad). HSQA incorporates quality and security considerations throughout the software development lifecycle. Thus, our position is that HSQA is an excellent approach for assessing electrical vehicle charging station software.

Wed 9 SeptCryptography and SecuritySoftware Engineering
The gist
Electric vehicle charging stations face new kinds of cyber risks because their software is often weak and not well studied. The authors suggest using a detailed method called hierarchical software quality assurance (HSQA) to better understand and fix these software weaknesses. HSQA looks at the software from tiny bugs to big security goals, throughout its creation process. This approach can help make charging stations safer against cyber attacks.
Open → 2609.10502v1