Joint Innovation-Watermark Stats
- Joint innovation–watermark statistics is a framework that detects integrity attacks by exploiting statistical dependencies between Kalman filter innovations and randomized watermark signals.
- The method employs a correlation-based test statistic derived from control system residuals and optimizes parameters to balance detection sensitivity against operational cost.
- The approach uses convex optimization to fine-tune detection metrics like false-alarm rate and LQG cost, offering a practical balance between performance and security.
Joint innovation–watermark statistics describe a framework designed to detect integrity attacks in control systems by leveraging physical watermarks comprising both additive Gaussian inputs and Bernoulli packet drops. The approach systematically analyzes the statistical dependencies between the innovation sequence (Kalman filter residuals) and a known watermarking process. By employing a correlation-based test statistic and optimizing system parameters for a trade-off between detection sensitivity and control performance, this framework offers an advanced and generalizable intrusion detection mechanism, particularly relevant in networked and cyber-physical control scenarios (Weerakkody et al., 2017).
1. Watermark Component Specification
The detection mechanism centers on two randomized watermark components:
- Bernoulli Drop Process: Denoted and assumed to be i.i.d. for baseline analysis, each , where is the drop probability. Thus,
- Gaussian Watermark Input: with , , i.i.d. and independent of both other noise sources and .
Their independence yields a joint density: for .
2. Innovation Sequence and Its Role
The innovation (one-step residual) sequence under a Kalman-filter-based attack detector is 0. In steady-state, and under no-attack conditions, the covariance is given by
1
where 2 is the Riccati solution of the Kalman filter. This innovation captures discrepancies due to both process and measurement noise, as well as injected watermark signals.
3. Correlation-Based Test Statistic
The core detection statistic utilizes the empirical correlation between the innovation sequence and the known watermark signal: 3 with weighting matrix 4.
The distributional behavior of 5 is crucial under both hypotheses:
- Under the null hypothesis 6 (no attack), 7 are jointly zero-mean Gaussian (correlated via system dynamics), yielding by a multivariate CLT,
8
where \begin{align*} \mu_0 &= (1-\alpha) \operatorname{tr}(L \Sigma_w M), \quad M = \mathbb{E}[\nu_k w_k\top] \ \sigma_02 &= (1-\alpha) \operatorname{tr}!\left(L \Sigma_w M M\top L\top + L \Sigma_w L\top \Sigma_\nu \right) - \mu_02 \end{align*}
- Under the alternative hypothesis 9 (attack), the attacker's output is independent of the legitimate watermark:
0
4. Detection and Performance Metrics
The decision rule involves comparing 1 to a threshold 2, declaring an attack when 3 (low correlation). Statistical metrics derived under the normal approximations are:
- False-Alarm Rate:
4
- Detection Probability:
5
where 6 denotes the standard normal CDF.
Long-run control performance under this policy is quantified by the LQG cost: 7 with 8 the base cost (no Gaussian watermark) and 9 the Riccati solution for the optimal cost-to-go.
Security requirements impose that 0 and 1, with 2, 3 designer-specified.
5. Optimization of Watermark and Drop Parameters
Optimal tradeoff between detection and system performance involves solving
4
Given the linear/affine structure of 5 and 6, this is a convex program (an SDP when enforcing 7 via LMI constraints).
For Markov-drop models, additional Lyapunov-type linear matrix constraints are imposed: 8 These preserve convexity and computational tractability.
6. Numerical Insights and Tradeoff Characterization
Empirical evaluation on a 9-state/0-input/1-output example demonstrates that at a moderate LQG cost increase 2, the correlation detector achieves detection probability 3 at 4 for 5, compared to 6 for the purely Gaussian watermark (7)—a 20 percentage point advantage for fixed 8.
Observed tradeoff curves (between 9 and 0 at fixed 1) are nearly monotonic: small drop probabilities 2 yield low cost but weak detection; as 3 increases, detection improves but at higher cost, with performance saturating as 4 becomes large.
Packet drops confer the greatest improvement in the regime where the defender restricts to moderate increases in operational cost. For very small or very large 5, the marginal benefit of Bernoulli drops diminishes.
Time-to-detection analysis indicates that additional drop-induced randomness can increase detection delay, but this is more than offset by the corresponding improvement in 6 at typical parameter settings.
7. Structural Properties and Convexity
Essential attributes of the joint innovation–watermark statistics are:
- The innovation covariance 7 reaches steady-state under 8.
- Under 9, the cross-covariance 0 is nonzero and depends linearly on 1; under 2, it vanishes.
- The LQG performance penalty (extra cost due to watermarks and drops) is affine in 3 and 4 (after accounting for Lyapunov corrections in the Markovian case).
- The design optimization—whether for detection gain or security under cost constraints—reduces to convex programs (quadratic or SDP), thus is computationally accessible with standard solvers.
This structure enables systematic and efficient design and tuning of physical watermarking strategies in networked control security applications (Weerakkody et al., 2017).