Papers
Topics
Authors
Recent
Search
2000 character limit reached

Joint Innovation-Watermark Stats

Updated 19 March 2026
  • Joint innovation–watermark statistics is a framework that detects integrity attacks by exploiting statistical dependencies between Kalman filter innovations and randomized watermark signals.
  • The method employs a correlation-based test statistic derived from control system residuals and optimizes parameters to balance detection sensitivity against operational cost.
  • The approach uses convex optimization to fine-tune detection metrics like false-alarm rate and LQG cost, offering a practical balance between performance and security.

Joint innovation–watermark statistics describe a framework designed to detect integrity attacks in control systems by leveraging physical watermarks comprising both additive Gaussian inputs and Bernoulli packet drops. The approach systematically analyzes the statistical dependencies between the innovation sequence (Kalman filter residuals) and a known watermarking process. By employing a correlation-based test statistic and optimizing system parameters for a trade-off between detection sensitivity and control performance, this framework offers an advanced and generalizable intrusion detection mechanism, particularly relevant in networked and cyber-physical control scenarios (Weerakkody et al., 2017).

1. Watermark Component Specification

The detection mechanism centers on two randomized watermark components:

  • Bernoulli Drop Process: Denoted {γk}\{\gamma_k\} and assumed to be i.i.d. for baseline analysis, each γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha), where α[0,1]\alpha \in [0,1] is the drop probability. Thus,

P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})

  • Gaussian Watermark Input: {wk}Rp\{w_k\} \subset \mathbb{R}^p with wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w), Σw0\Sigma_w \succ 0, i.i.d. and independent of both other noise sources and {γk}\{\gamma_k\}.

Their independence yields a joint density: P(γk=i,wkdw)=(1α)iα1i1(2π)p/2det(Σw)1/2exp(12wΣw1w)dwP(\gamma_k=i, w_k \in dw) = (1-\alpha)^i \alpha^{1-i} \frac{1}{(2\pi)^{p/2}\det(\Sigma_w)^{1/2}} \exp\left(-\frac{1}{2} w^\top \Sigma_w^{-1} w\right) dw for i{0,1}i\in\{0,1\}.

2. Innovation Sequence and Its Role

The innovation (one-step residual) sequence under a Kalman-filter-based attack detector is γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)0. In steady-state, and under no-attack conditions, the covariance is given by

γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)1

where γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)2 is the Riccati solution of the Kalman filter. This innovation captures discrepancies due to both process and measurement noise, as well as injected watermark signals.

3. Correlation-Based Test Statistic

The core detection statistic utilizes the empirical correlation between the innovation sequence and the known watermark signal: γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)3 with weighting matrix γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)4.

The distributional behavior of γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)5 is crucial under both hypotheses:

  • Under the null hypothesis γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)6 (no attack), γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)7 are jointly zero-mean Gaussian (correlated via system dynamics), yielding by a multivariate CLT,

γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)8

where \begin{align*} \mu_0 &= (1-\alpha) \operatorname{tr}(L \Sigma_w M), \quad M = \mathbb{E}[\nu_k w_k\top] \ \sigma_02 &= (1-\alpha) \operatorname{tr}!\left(L \Sigma_w M M\top L\top + L \Sigma_w L\top \Sigma_\nu \right) - \mu_02 \end{align*}

  • Under the alternative hypothesis γkBernoulli(1α)\gamma_k \sim \mathrm{Bernoulli}(1-\alpha)9 (attack), the attacker's output is independent of the legitimate watermark:

α[0,1]\alpha \in [0,1]0

4. Detection and Performance Metrics

The decision rule involves comparing α[0,1]\alpha \in [0,1]1 to a threshold α[0,1]\alpha \in [0,1]2, declaring an attack when α[0,1]\alpha \in [0,1]3 (low correlation). Statistical metrics derived under the normal approximations are:

  • False-Alarm Rate:

α[0,1]\alpha \in [0,1]4

  • Detection Probability:

α[0,1]\alpha \in [0,1]5

where α[0,1]\alpha \in [0,1]6 denotes the standard normal CDF.

Long-run control performance under this policy is quantified by the LQG cost: α[0,1]\alpha \in [0,1]7 with α[0,1]\alpha \in [0,1]8 the base cost (no Gaussian watermark) and α[0,1]\alpha \in [0,1]9 the Riccati solution for the optimal cost-to-go.

Security requirements impose that P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})0 and P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})1, with P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})2, P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})3 designer-specified.

5. Optimization of Watermark and Drop Parameters

Optimal tradeoff between detection and system performance involves solving

P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})4

Given the linear/affine structure of P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})5 and P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})6, this is a convex program (an SDP when enforcing P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})7 via LMI constraints).

For Markov-drop models, additional Lyapunov-type linear matrix constraints are imposed: P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})8 These preserve convexity and computational tractability.

6. Numerical Insights and Tradeoff Characterization

Empirical evaluation on a P(γk=1)=1α(input delivered),P(γk=0)=α(input dropped)P(\gamma_k = 1) = 1 - \alpha \quad (\text{input delivered}), \qquad P(\gamma_k = 0) = \alpha \quad (\text{input dropped})9-state/{wk}Rp\{w_k\} \subset \mathbb{R}^p0-input/{wk}Rp\{w_k\} \subset \mathbb{R}^p1-output example demonstrates that at a moderate LQG cost increase {wk}Rp\{w_k\} \subset \mathbb{R}^p2, the correlation detector achieves detection probability {wk}Rp\{w_k\} \subset \mathbb{R}^p3 at {wk}Rp\{w_k\} \subset \mathbb{R}^p4 for {wk}Rp\{w_k\} \subset \mathbb{R}^p5, compared to {wk}Rp\{w_k\} \subset \mathbb{R}^p6 for the purely Gaussian watermark ({wk}Rp\{w_k\} \subset \mathbb{R}^p7)—a 20 percentage point advantage for fixed {wk}Rp\{w_k\} \subset \mathbb{R}^p8.

Observed tradeoff curves (between {wk}Rp\{w_k\} \subset \mathbb{R}^p9 and wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)0 at fixed wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)1) are nearly monotonic: small drop probabilities wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)2 yield low cost but weak detection; as wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)3 increases, detection improves but at higher cost, with performance saturating as wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)4 becomes large.

Packet drops confer the greatest improvement in the regime where the defender restricts to moderate increases in operational cost. For very small or very large wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)5, the marginal benefit of Bernoulli drops diminishes.

Time-to-detection analysis indicates that additional drop-induced randomness can increase detection delay, but this is more than offset by the corresponding improvement in wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)6 at typical parameter settings.

7. Structural Properties and Convexity

Essential attributes of the joint innovation–watermark statistics are:

  1. The innovation covariance wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)7 reaches steady-state under wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)8.
  2. Under wkN(0,Σw)w_k \sim \mathcal{N}(0, \Sigma_w)9, the cross-covariance Σw0\Sigma_w \succ 00 is nonzero and depends linearly on Σw0\Sigma_w \succ 01; under Σw0\Sigma_w \succ 02, it vanishes.
  3. The LQG performance penalty (extra cost due to watermarks and drops) is affine in Σw0\Sigma_w \succ 03 and Σw0\Sigma_w \succ 04 (after accounting for Lyapunov corrections in the Markovian case).
  4. The design optimization—whether for detection gain or security under cost constraints—reduces to convex programs (quadratic or SDP), thus is computationally accessible with standard solvers.

This structure enables systematic and efficient design and tuning of physical watermarking strategies in networked control security applications (Weerakkody et al., 2017).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Joint Innovation-Watermark Statistics.