security//cyber-physical security//false data injection

False data injection is an attack that alters the measurements a control or monitoring system receives, or the commands it sends, by adding values the attacker chooses, and it is the basic weapon against any system that decides from sensor data: a grid operator's state estimator, a plant's control loop, a fleet's shared map. The alteration can happen anywhere on the path, in a compromised sensor, a field bus without authentication, a gateway, or the server itself.


False data injection is an attack that alters the measurements a control or monitoring system receives, or the commands it sends, by adding values the attacker chooses, and it is the basic weapon against any system that decides from sensor data: a grid operator's state estimator, a plant's control loop, a fleet's shared map. The alteration can happen anywhere on the path, in a compromised sensor, a field bus without authentication, a gateway, or the server itself.

Written as an equation, the system receives y~k=yk+ak\tilde y_k = y_k + a_ky~​k​=yk​+ak​ instead of the true reading yky_kyk​, with aka_kak​ chosen by the attacker. A crude injection (a pressure reading jumping by half a bar) is a sensor fault with intent, and a model-based detector sees it at once. The dangerous version is shaped. Power grids estimate their state, the voltage angles at every bus, by weighted least squares from hundreds of meters, and flag bad data when the fitting residual is too large. If the attacker knows the measurement matrix HHH and adds an attack of the form a=Hca = Hca=Hc for any vector ccc, the falsified readings are perfectly consistent with a different grid state, the residual does not change at all, and the operator sees a state shifted by ccc1.

1Liu, Ning and Reiter, False data injection attacks against state estimation in electric power grids, ACM CCS, 2009.

Bad-data detection checks consistency, and a consistent lie passes it.

Residual tests catch falsifications that break the physics the model encodes; an attacker who stays inside that physics is invisible to them, which is why protection rests on data the attacker cannot reach or cannot make consistent (stealthy attack).

The attacker's cost is the number of meters to compromise: an attack consistent with the grid's equations typically needs many at once, and protecting a well-chosen few (with authentication, or with independent phasor measurement units) can make every such attack impossible.

Commands can be falsified as well as readings. A command injected between the controller and the drive is invisible to an operator who sees only measured outputs until the plant moves, which is why critical limits are also enforced by hardware the network cannot write to (cyber-physical security).

Injecting recorded true values instead of invented ones needs no model at all, the replay attack.