← Latest papers
⚡ electrical engineering

Energy-Constrained False Data Injection Attacks in Cyber-Physical Systems Using Wasserstein Distance

This paper proposes an energy-constrained false data injection attack strategy for cyber-physical systems that maximizes terminal estimation error covariance while maintaining stealthiness, quantified by the Wasserstein distance, through an optimized attack signal and scheduling policy.

Original authors: Jiawei Fu, Jianing Xin, Chenghan Wang, Tianju Sui

Published 2026-08-24
📖 5 min read🧠 Deep dive

Original authors: Jiawei Fu, Jianing Xin, Chenghan Wang, Tianju Sui

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Modern infrastructure, from power grids to autonomous vehicles, relies on a delicate marriage between the physical world and digital networks. These systems, known as cyber-physical systems, use sensors to measure real-world conditions like temperature, speed, or pressure and send that data across wireless networks to a central computer. This computer acts as a navigator, constantly calculating the system's true state to make critical decisions. However, this reliance on wireless communication creates a vulnerability: the data stream can be intercepted and altered. An attacker does not need to break down the physical machine; they only need to convince the digital navigator that the machine is behaving differently than it actually is. If the navigator believes a false reality, it may steer a plane off course or shut down a power grid unnecessarily. The challenge for security researchers is to understand how an attacker might hide these lies within the noise of normal data, making the deception so subtle that the system's built-in alarms never ring.

In a new study, researchers Jiawei Fu, Jianing Xin, Chenghan Wang, and Tianju Sui have mapped out a sophisticated way an attacker could exploit these systems while staying hidden. They focused on a specific type of deception called a false data injection attack, where an adversary injects fake numbers into the data stream sent from a sensor to a remote estimator. The goal of such an attack is not to crash the system immediately, but to slowly degrade the accuracy of the computer's calculations until the system is operating on a fundamentally wrong understanding of reality. The researchers were particularly interested in how an attacker could maximize this damage while facing two strict limitations: a limited supply of energy to power the attack and the need to remain undetected by statistical monitors that watch for anomalies.

To solve this, the team developed a strategy that treats the attack as a mathematical optimization problem. They imagined a scenario where a smart sensor sends a stream of data updates, known as innovations, to a remote computer. An attacker, sitting in the middle of the wireless link, must decide at every single moment whether to intercept the message and replace it with a corrupted version. The attacker has a finite battery, meaning they cannot jam or corrupt the signal at every single moment; they must choose the most damaging times to strike. Furthermore, if the corrupted data looks too different from the normal data, the system's detectors will spot the intrusion. The researchers needed a way to measure exactly how "different" the fake data was from the real data without triggering an alarm.

Previous methods for measuring this difference relied on statistical tools that sometimes failed to capture the full picture, especially when comparing complex probability distributions. The authors turned to a more robust mathematical concept called the Wasserstein distance. In simple terms, this metric measures the effort required to transform one distribution of data into another. It provides a precise, geometry-based way to quantify how much the statistical shape of the data has been altered. By using this measure, the researchers could ensure that the fake data remained statistically close enough to the real data to fool the detectors, even as it pushed the system's error to its breaking point.

The core of their discovery is a two-step process for designing the perfect attack. First, they determined the exact shape and intensity of the fake data signal that would cause the maximum possible error in the final calculation, provided it stayed within the stealthiness limit. They found that this optimal signal could be calculated in a precise, closed form, meaning there is a specific formula for the "best" lie to tell at any given moment. Second, they solved the puzzle of when to tell that lie. Since the attacker has a limited energy budget, they cannot lie continuously. The researchers reduced this scheduling problem to a binary choice: at each time step, the attacker either launches the attack or stays silent. By solving this as a specific type of integer programming problem, they identified the exact sequence of moments where launching the attack would cause the most cumulative damage to the system's accuracy.

The team tested their theory using a simulation of a flight vehicle, a system where precise state estimation is critical for safety. They modeled a scenario where the vehicle had three sensors and a remote estimator, and the attacker had a limited number of "attacks" they could launch over a period of one hundred time steps. The results showed that their proposed strategy was significantly more damaging than random attempts to disrupt the system. When the attacker used the calculated optimal signal and the precise schedule, the error in the system's final state estimate grew much larger than in any other scenario. The simulation also revealed a clear trade-off: the more the attacker relaxed their need for stealth (allowing the data to look slightly more different from normal), the more damage they could inflict. Conversely, stricter stealth requirements forced the attacker to be more conservative, reducing the potential harm. Similarly, a larger energy budget allowed the attacker to sustain the degradation for longer, leading to a more severe final error.

This work does not propose a new weapon for attackers, but rather a rigorous blueprint of the worst-case scenario. By proving that an attacker can mathematically determine the most destructive path while staying hidden, the study highlights the fragility of current remote estimation systems. The findings suggest that simply monitoring for obvious anomalies is insufficient, as a sophisticated adversary can craft a deception that is statistically indistinguishable from normal noise until the damage is done. The researchers conclude that understanding these optimal attack paths is essential for designing better defenses, forcing system designers to account for an adversary who is not just guessing, but calculating the perfect moment to strike.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →