A Mission-Centric Cyber-Resilience Benchmark for Silent-Watch Operation of Electrified Ground-Platform Power Architectures
This paper introduces a mission-centric cyber-resilience benchmark for silent-watch electrified ground platforms that evaluates SOC spoofing attacks based on their impact on mission outcomes rather than just detection metrics, revealing that defense efficacy depends critically on the depth of fallback shedding strategies.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a military vehicle that needs to operate in total silence, like a ninja sneaking through a forest. To stay quiet, the engine is turned off, and the vehicle must run entirely on its battery. This is called "Silent Watch."
The vehicle has a smart manager (a computer) that decides how to spend its battery. It knows there are essential tasks (like radar and radios) that must always run, and optional tasks (like heating or air conditioning) that can be turned off if the battery gets low.
The Problem: The "Fake Fuel Gauge" Hack
The paper describes a specific type of cyber-attack where a hacker doesn't break the battery itself; instead, they trick the smart manager's fuel gauge.
Imagine the battery is actually at 20% charge, but the hacker sends a fake signal telling the manager, "Hey, we're still at 80%!"
- The Result: The manager thinks there's plenty of energy left. It keeps the air conditioning running and doesn't turn on the "emergency mode" (which would cut off non-essential power) soon enough.
- The Consequence: The vehicle runs out of battery much sooner than it should, potentially leaving the crew without radar or comms before their mission is over.
The Solution: A "Second Opinion" System
The authors created a new way to test how well these vehicles can survive such attacks. Instead of just checking if a computer alarm went off, they measure real-world mission success:
- How long did the mission last? (Endurance)
- Did the important equipment stay on? (Critical-load service)
- Did the voltage drop to dangerous levels? (Unsafe-voltage exposure)
- How fast did the system catch the lie? (Detection delay)
They tested three scenarios:
- Normal: No hacker, no special defense.
- Attacked: A hacker lies about the battery, and the system has no defense.
- Defended: A hacker lies, but the system has a "Second Opinion" detector.
How the "Second Opinion" works:
The system has a backup calculator that estimates the battery level based on how much power is actually being used. If the "Fake Gauge" says 80% but the "Backup Calculator" says 20%, the system realizes something is wrong. It sounds an alarm and immediately cuts off the optional power (like the AC) to save the mission.
The Surprising Discoveries
1. The "Goldilocks" Zone of Lying
The paper found that the hacker's lie has to be just right to cause the most damage:
- Tiny Lies: If the hacker says the battery is 1% higher than it is, the system doesn't notice, but it also doesn't hurt the mission much.
- Huge Lies: If the hacker says the battery is 100% full when it's empty, the system's safety guards eventually kick in based on the actual voltage, or the mission fails quickly anyway.
- The "Danger Zone": The worst lies are the medium-sized ones. They are big enough to trick the manager into delaying safety cuts, but small enough that the system doesn't immediately realize the battery is critically low. In this zone, the mission loses a predictable amount of time.
2. The "Half-Hearted" Defense Trap
This is the most critical finding. The authors discovered that detecting the attack isn't enough; you have to act strongly.
Imagine the system detects the lie and decides to turn off the air conditioning.
- If it only turns off 20% of the optional power, it's not enough to save the battery. The vehicle still runs out of power, and because the system wasted time reacting, it actually ends up in a worse position than if it had done nothing at all.
- The system must turn off at least 40% (and ideally more) of the optional power immediately to actually save the mission. A weak defense is worse than no defense.
The Bottom Line
The paper builds a "scorecard" for these vehicles. It proves that to survive a hacker lying about the battery, you need two things:
- A fast way to spot the lie (the "Second Opinion").
- A strong, decisive reaction (cutting power deeply) once the lie is spotted.
If you spot the lie but hesitate or only take a small action, you might actually lose the mission faster than if you had ignored the hacker entirely. The authors verified this math and simulation logic to ensure it works before testing it on real hardware.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.