Physics attested federated learning secures water system anomaly detection

Physics-Attested Federated Learning: Securing Collaborative Anomaly Detection in Critical Water Infrastructure

Cryptography and SecurityMachine Learning

Summary

Detecting attacks on critical water systems is important but sharing data between operators risks privacy. The authors show how to use the natural physical laws and rules governing water systems to check if data updates are genuine without revealing sensitive information. This approach blocks fake or poisoned data during collaborative machine learning, improving security in water network monitoring. They tested this method on real water system datasets and found it effectively detects attacks while keeping honest data safe.

What this means in practice

Authors

Jeff Nijsse, Shu Su, Benjamin Oholeguy, Sreenivas Sremath Tirumala

Abstract

Federated learning enables industrial operators to train shared intrusion detection models without disclosing proprietary operational telemetry. However, existing defenses operate strictly in update space, leaving aggregators blind to data poisoning; model updates derived from fabricated telemetry remain indistinguishable from honest contributions. We repurpose cyber-physical process invariants, such as conservation laws and actuator couplings, from runtime detection heuristics into a verifiable admission requirement for federated updates, mined automatically from clean operational data. We evaluate this admission gate across two physical water testbeds (SWaT, WADI) and a distribution benchmark (BATADAL), testing seven aggregation rules against telemetry fabrication, exposure-only replay poisoning, and an invariant-aware adaptive adversary. Across three testbeds the mined invariants reject none of 100 honest shards and all naively fabricated ones, including optimised perturbations that FoolsGold admits in full. On real telemetry, five mined invariants detect 12 of SWaT's 35 attacks, while nine invariants detect 20, with no honest shard rejected. With nine rules, the physics gate recovers 69--100% of the targeted-attack recall lost to replay poisoning, and 54--100% of that lost to fabricated telemetry, across five standard aggregators. To reconcile physical admission control with federated data privacy, we show invariant compliance using zero-knowledge proofs (zk-SNARKs) to allow clients to prove batch adherence without revealing operational telemetry.