Skip to content

Adaptive utility-aware event-triggered reinforcement learning for hybrid attack scheduling against remote state estimation.

Jul 2026 · ISA transactions · 0 citations · 41 references
Medicine

TL;DR

Results indicate that the proposed event-triggered reinforcement learning framework can improve the adaptability and resource efficiency of hybrid attack scheduling under time-varying wireless channels.

Abstract

Remote state estimation plays an important role in connected vehicle platoons, industrial automation systems, and other networked Cyber-Physical Systems (CPSs), where reliable state information is essential for monitoring, feedback control, and decision-making. However, due to the openness and unreliability of wireless communication links, remote estimation systems are vulnerable to eavesdropping and Denial-of-Service (DoS) attacks, which may cause information leakage, packet loss, and estimation performance degradation. This issue becomes more critical in time-varying wireless environments, where channel conditions and attack opportunities evolve dynamically over time, making conventional static or periodic attack models insufficient for characterizing practical security risks. To address this problem, this paper investigates a utility-aware event-triggered reinforcement learning framework for hybrid attack scheduling against remote state estimation over time-varying wireless channels. The attacker can select among eavesdropping, DoS, and silence actions to balance estimation disruption, information acquisition, and attack resource consumption. The hybrid attack scheduling problem is formulated as a partially observable Markov decision process (POMDP), and a utility-aware event-triggered mechanism is designed to activate attack decisions only when the estimated attack utility is sufficiently significant. At the triggered decision instants, a proximal policy optimization (PPO) algorithm is employed to learn an adaptive hybrid attack mode selection policy. The structural properties of the resulting policy are also analyzed theoretically, showing that the optimal belief-space policy has a piecewise constant structure and that the proposed adaptive threshold preserves a monotone triggering property with respect to the attack utility indicator. Simulation results in a connected vehicle platoon scenario demonstrate that, compared with several benchmark methods, the proposed method achieves a better trade-off among remote estimation degradation, attacker-side information acquisition, and energy consumption. These results indicate that the proposed event-triggered reinforcement learning framework can improve the adaptability and resource efficiency of hybrid attack scheduling under time-varying wireless channels. The study also provides useful insights for security vulnerability assessment, resilient estimation design, and defense strategy development for practical remote estimation systems.

View source

Similar papers

2026

Resilient Observer-Triggered Adaptive Control for Cyber-Physical Systems Under Time-Vary Stealthy FDI Attacks

Cyber-physical systems (CPSs) are widely used in safety-critical applications, where both control reliability and communication efficiency are essential. However, open networks make CPSs vulnerable to false data injection (FDI) attacks, which threaten system stability. Existing event-triggered control methods often fail to simultaneously ensure attack resilience, stability, and $H_\infty$ performance. This paper addresses the secure control problem of CPSs under FDI attacks by proposing an observer-based dynamic event-triggered control framework. To counteract the adversarial disturbances, a novel attack-resilient observer is designed to simultaneously estimate both the system states and the injected attack signals, enabling the synthesis of a secure observer-based controller. An advanced dynamic event-triggered mechanism (DETM) is developed by incorporating an internal dynamic variable, which adaptively adjusts triggering thresholds to significantly reduce communication frequency while avoiding Zeno behavior. Through Lyapunov-Razumikhin analysis, the closed-loop system is proven to achieve asymptotic stability and guaranteed $H_\infty$ performance, ensuring robustness against bounded FDI attacks. Theoretical results are validated via numerical simulations, demonstrating the effectiveness of the proposed method in mitigating attack impacts and conserving network resources.

Lei Liu, Ruonan Ren, Baoling Miao · 0 citations
Open access Aug 2026

Adaptive Event-Triggered Security Control for Nonlinear CPSs Under Coexisting FDI Attacks and Actuator Faults

This study addresses an integrated security control and communication co-design problem for nonlinear CPSs subject to coexisting FDI attacks and actuator faults. A novel adaptive discrete event-triggered communication scheme (ADETCS) is proposed. Its triggering threshold adapts to the system state. State estimation, fault estimation, and attack detection are all migrated to the control unit. Based on this framework, a closed-loop T–S fuzzy model is established for active defense against actuator faults and dual-end FDI attacks. A robust augmented observer is then developed via Lyapunov stability theory to jointly estimate system states, actuator faults, and FDI attacks. Sufficient conditions are further derived for an integrated security controller that unifies attack tolerance and fault tolerance. Simulation results on a quadruple-tank system show that the proposed method effectively counteracts coexisting attacks and faults while significantly reducing resource consumption. Over an 800-s horizon, data transmissions drop to 712 (8.9% transmission rate). The sensor-node computational load is also reduced from 8000 time-triggered executions to 712 event-triggered ones.

Li Zhao, Wei Li, Nani Han · 0 citations
2026

Event-Triggered Observer-Based Secure Fault Estimation and Fault-Tolerant Control for Markov Jump Systems

This paper investigates the secure fault estimation (FE) and fault-tolerant control (FTC) problems for Markov jump systems (MJSs) under limited communication resource. First, a dynamic event-triggered mechanism (ETM) is introduced into the sensor-observer channel to alleviate communication burden. Simultaneously, to ensure network security, a class of deception attacks described by Bernoulli random variables is considered during the transmission of sampled outputs. Based on these, a novel dynamic event-triggered intermediate observer (IO) is constructed, which utilizes the sampled outputs corrupted by attack signals to estimate states, faults and disturbances of MJSs. This observer not only reduces data transmission but is also capable of resisting deception attacks. Furthermore, a fault-tolerant controller is designed to maintain system stability. Second, with the aid of augmentation methods, linear matrix inequality techniques and stochastic stability theory, a joint design method for the observer, fault-tolerant controller and dynamic ETM is developed by constructing a model-dependent Lyapunov function that incorporates a dynamic variable. Third, it is proven that the introduced dynamic ETM is free from Zeno behavior. Finally, the effectiveness of the proposed method is validated on an F-404 aircraft engine model. Note to Practitioners—MJSs, as a class of stochastic switching systems, are capable of accurately describing abrupt variations in system structures or parameters that commonly occur in practical engineering scenarios. This capability has enabled their widespread application in critical fields such as aerospace, power and communications. In these fields, frequent equipment faults pose a significant threat to system safety. On the other hand, with the increasing prevalence of networked systems, continuous data transmission imposes heavy communication burdens and increases energy consumption. Meanwhile, data transmitted over networks is vulnerable to cyber attacks. To address these issues, this paper proposes a FTC method based on a dynamic event-triggered observer. Specifically, a dynamic ETM is incorporated into the observer design, which determines whether data should be transmitted according to real-time system states, thereby avoiding unnecessary communication. Moreover, the designed observer is capable of accurately estimating system states, disturbances and faults using measurements corrupted by deception attacks. Finally, the estimated information is integrated into the fault-tolerant controller for online compensation. In summary, this paper provides a practical FTC solution for MJSs subject to communication resource constraints and deception attacks.

Zhijie Han, Hua-guang Zhang, Zhihong Liang et al. · 0 citations
Aug 2026

Network-based event-triggered security control for cascade switched systems under hybrid attacks.

This paper presents a resilient control framework for networked cascade systems (NCCSs) subject to transmission delays and hybrid cyber-attacks involving false data injection (FDI) and Denial-of-Service (DoS) attacks. The hybrid attack model is defined by the asynchronous operation of these two threats: DoS attacks disrupt data availability by blocking the communication channel, while FDI attacks compromise data integrity by injecting false signals during the DoS dormant periods. Accordingly, an event-triggered mechanism and a neural network-based estimator are co-designed to reduce the network transmission burden and identify and compensate for unstructured FDI attack signals. The closed-loop system is modeled as a switched system, and sufficient stability conditions under hybrid attacks are derived through a Lyapunov-based neural network approach to facilitate the design of an H∞ controller with guaranteed robust performance. Simulations on a steam temperature cascade control system validate the effectiveness of the proposed method, demonstrating 20% faster convergence and a 67% reduction in oscillations compared with a conventional method while maintaining stability and security under hybrid attacks.

Hangli Ren, Yuanyuan Cheng, Hui Shang · 0 citations
Open access Jul 2026

Multi-Agent Reinforcement Learning-Based Automated Incident Response for Secure Digital Twin Environments

The DT environment allows for real-time synchronization between the physical and virtual world, which makes it extremely vulnerable to advanced cyber-attacks. Most of the security techniques used so far emphasize the ability to detect attacks but are weak when it comes to responding to them in an automated and dynamic manner. To tackle this challenge, in this research, we propose an MARL-based automated response solution for Digital Twin security applications. The MARL model uses a decentralized agent architecture where the agents learn how to respond optimally under different circumstances. We formulate the problem as a multi-agent markov decision process, and use the Q-learning approach combined with the idea of experience replay. Performance of the developed solution will be measured with various criteria, such as accuracy, threat mitigation rate, attack success rate, response time, system downtime, cumulative rewards, and system resilience. The findings from the experiments clearly show that the suggested model is able to obtain an accuracy of 94.4%, threat mitigation capability of 93.1%, and lower response times than previous models. Moreover, the learning curve clearly illustrates that stable convergence and better optimization of policies are obtained over episodes. The suggested MARL-based framework is efficient in providing automated incident response for Digital Twin ecosystems. 

Raghavendra Babu T. M., Harish Kumar K. S. · 0 citations
Open access Aug 2026

Adaptive Event-Triggered Distributed Estimation for a Class of Non-Linear Systems over Sensor Networks with Replay Attacks: The Finite-Horizon Case

This work investigates the adaptive event-triggered distributed estimation problem for discrete time-varying nonlinear stochastic systems over sensor networks exposed to replay attacks within a finite-horizon setting. The sensor network comprises multiple nodes whose interaction structure is described by two randomly switching directed graphs. The plant under consideration is formulated as a discrete time-varying nonlinear stochastic system obeying a sector-bounded condition. To mitigate communication overhead, an adaptive event-triggered scheme is employed, where the triggering threshold is dynamically updated based on the triggering error. In addition, replay attacks are considered, wherein an adversary randomly replaces current data packets with previously recorded ones. A compensation mechanism is devised to neutralize the impact of such attacks. By building a distributed estimator and formulating an augmented estimation error system, sufficient criteria are established via Lyapunov theory and stochastic analysis to ensure the prescribed average H∞ performance level is attained. The estimator gains are computed recursively by solving a sequence of recursive linear matrix inequalities (RLMIs). A design algorithm for the distributed estimator is also provided to support online implementation. Finally, a numerical simulation example is given to demonstrate the effectiveness of the proposed estimation approach.

Xianye Bu, Tao Lu, Wenbo Dong et al. · 0 citations