{"title":"传感器攻击下标签 Petri 网的可诊断性验证与执行","authors":"Shaopeng Hu;Zhiwu Li;Ding Liu","doi":"10.1109/TSMC.2025.3545756","DOIUrl":null,"url":null,"abstract":"This article formalizes and solves the problems of diagnosability verification and enforcement in discrete event systems modeled with labeled Petri nets (LPNs) under sensor attacks. Given a plant, attackers work as a group in the framework of a coordinated distributed architecture and have the ability to edit some sensor readings to conceal the faults to confuse the operator. Furthermore, attackers necessarily remain furtive, i.e., their presence should not be discovered by the operator. In order to describe the set of all possible furtive attacks, a joint furtive diagnoser is established. We prove that an LPN under the above attacks is diagnosable if and only if its joint furtive diagnoser does not have the cycles composed of pairs of either faulty states and normal states, or faulty states and uncertain states. A new labeling function is proposed to enforce a plant to be diagnosable against as many attacks as possible. Examples are provided to illustrate the proposed method.","PeriodicalId":48915,"journal":{"name":"IEEE Transactions on Systems Man Cybernetics-Systems","volume":"55 5","pages":"3654-3667"},"PeriodicalIF":8.6000,"publicationDate":"2025-03-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Diagnosability Verification and Enforcement in Labeled Petri Nets Under Sensor Attacks\",\"authors\":\"Shaopeng Hu;Zhiwu Li;Ding Liu\",\"doi\":\"10.1109/TSMC.2025.3545756\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This article formalizes and solves the problems of diagnosability verification and enforcement in discrete event systems modeled with labeled Petri nets (LPNs) under sensor attacks. Given a plant, attackers work as a group in the framework of a coordinated distributed architecture and have the ability to edit some sensor readings to conceal the faults to confuse the operator. Furthermore, attackers necessarily remain furtive, i.e., their presence should not be discovered by the operator. In order to describe the set of all possible furtive attacks, a joint furtive diagnoser is established. We prove that an LPN under the above attacks is diagnosable if and only if its joint furtive diagnoser does not have the cycles composed of pairs of either faulty states and normal states, or faulty states and uncertain states. A new labeling function is proposed to enforce a plant to be diagnosable against as many attacks as possible. Examples are provided to illustrate the proposed method.\",\"PeriodicalId\":48915,\"journal\":{\"name\":\"IEEE Transactions on Systems Man Cybernetics-Systems\",\"volume\":\"55 5\",\"pages\":\"3654-3667\"},\"PeriodicalIF\":8.6000,\"publicationDate\":\"2025-03-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Transactions on Systems Man Cybernetics-Systems\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10929735/\",\"RegionNum\":1,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"AUTOMATION & CONTROL SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Systems Man Cybernetics-Systems","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10929735/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"AUTOMATION & CONTROL SYSTEMS","Score":null,"Total":0}
Diagnosability Verification and Enforcement in Labeled Petri Nets Under Sensor Attacks
This article formalizes and solves the problems of diagnosability verification and enforcement in discrete event systems modeled with labeled Petri nets (LPNs) under sensor attacks. Given a plant, attackers work as a group in the framework of a coordinated distributed architecture and have the ability to edit some sensor readings to conceal the faults to confuse the operator. Furthermore, attackers necessarily remain furtive, i.e., their presence should not be discovered by the operator. In order to describe the set of all possible furtive attacks, a joint furtive diagnoser is established. We prove that an LPN under the above attacks is diagnosable if and only if its joint furtive diagnoser does not have the cycles composed of pairs of either faulty states and normal states, or faulty states and uncertain states. A new labeling function is proposed to enforce a plant to be diagnosable against as many attacks as possible. Examples are provided to illustrate the proposed method.
期刊介绍:
The IEEE Transactions on Systems, Man, and Cybernetics: Systems encompasses the fields of systems engineering, covering issue formulation, analysis, and modeling throughout the systems engineering lifecycle phases. It addresses decision-making, issue interpretation, systems management, processes, and various methods such as optimization, modeling, and simulation in the development and deployment of large systems.