Detection-threshold selection for delay-attack detection

Determine a principled method for selecting the detection threshold of the IMM-based feedback-path delay-attack detector, beyond the stationary-distribution and simulation-based guidelines used in the cruise-control application.

Background

The detector declares a delay attack when the posterior probability of the nominal zero-delay mode falls below a threshold. The paper gives heuristic guidance: the no-attack stationary distribution should not trigger detection, while the stationary distribution under attack should trigger it. In the experiments, the threshold is selected using simulated attack behavior and a safety margin.

The authors explicitly state that threshold selection is unresolved in general and suggest that more sophisticated threshold-design methods are needed, making this a methodological open problem for controlling the trade-off between false alarms and detection delay.

References

The choice of detection threshold of detectors is an open question in general, and this paper does not claim to solve it.

Detecting Feedback-path Delay Injection Attacks Using Interacting Multiple Model Filtering  (2608.18824 - Eriksson et al., 19 Aug 2026) in Section 3, subsection “Setting Parameters via the Stationary Distribution”

It is hypothesised that this delay has a very minor effect on the observations, which makes it hard to detect. Understanding this better and improving the method for small delays is left as future work.

Detecting Feedback-path Delay Injection Attacks Using Interacting Multiple Model Filtering  (2608.18824 - Eriksson et al., 19 Aug 2026) in Section 4.3, subsection “Simulation Results”