Cross-domain method improves industrial control system threat validation
XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security
Cryptography and SecurityArtificial Intelligence
Summary
Industrial control systems like water treatment plants face cyber-physical threats that can affect multiple types of systems. The authors present XPhysICS, a new method to check if threat patterns identified in one system can be meaningfully applied and tested in another. Their method uses clear rules to decide which threats can be safely transferred between different industrial setups, helping analysts understand risks better across various plants. They tested XPhysICS on several kinds of water and energy systems and showed it supports careful and traceable threat evaluation across different environments.
What this means in practice
- •For industrial security teams: Evaluate if cyber-physical threat scenarios found in one plant apply and can be tested in another, improving cross-plant security assessments.
- •For water infrastructure operators: Assess and validate threats across different water treatment and distribution systems using a unified framework to guide protective measures.
Authors
Sangshin Park, Jainta Paul, Lawrence Ponce, Md Raihan Ahmed, Mu Zhang, Luis Garcia
Abstract
Industrial control system (ICS) threats documented for one plant can express cyber-physical effects relevant to another, but semantic similarity alone does not establish whether those effects are structurally admissible or evaluable on a target. We present XPhysICS, a provenance-aware, target-conditioned method that separates analyst-guided source abstraction from deterministic grounding into target-specific validation slices. Given a fixed source abstraction, vocabulary and schema, and machine-validated target contract, XPhysICS evaluates candidate mappings using five eligibility criteria: role compatibility, implemented type compatibility, stage coherence, slice viability, and rule-surface applicability. Grounding acceptance, slice adequacy, dynamic realizability, consumer applicability, and consumer outcome remain distinct evidence layers. We evaluate 83 structured source-threat abstractions across water treatment, water distribution, hydro/water-energy, and chemical-process targets. Controlled target-side studies of SWaT-to-water-treatment and WADI-to-water-distribution groundings produce clean, nominal-confounded, and near-threshold consumer outcomes; nine Hydro/GRFICS cases extend bounded validation-slice execution. We also evaluate bounded predictive, state-aware, and phase-aware consumer lanes, the unmodified upstream GeCo implementation, and a paper-derived reproduction of a physics-guided search method over three frozen groundings. Results show that cross-domain ICS threat reuse requires traceable source semantics, explicit target-conditioned grounding criteria, and careful separation of subsequent target-side evidence.