security//cyber-physical security//physical watermarking

Physical watermarking is a defence for control systems that adds a small secret random signal to the actuator commands and checks that its expected effect appears in the sensor measurements, and it exists to detect a replay attack, in which an attacker feeds the operators and the monitoring system recordings of the plant running normally. A recording made before the watermark was drawn cannot contain the plant's response to it, so its absence gives the attack away.


Physical watermarking is a defence for control systems that adds a small secret random signal to the actuator commands and checks that its expected effect appears in the sensor measurements, and it exists to detect a replay attack, in which an attacker feeds the operators and the monitoring system recordings of the plant running normally. A recording made before the watermark was drawn cannot contain the plant's response to it, so its absence gives the attack away.

The mechanism uses the plant as the authenticator. At each step the controller adds a zero-mean pseudo-random term wkw_kwk​, known only to it, to the command it would have sent; the plant responds to the sum, and through the model the controller knows what that response should look like in the outputs. A detector correlates the measured outputs, or the residuals of a state estimator, with the recent watermark. While the data are live the correlation is there; when the attacker swaps in a recording, the residuals stay small (each replayed value was once true) but the correlation with www vanishes, and a test such as a χ2\chi^2χ2 on the residuals or a CUSUM flags it after enough samples.

The watermark trades a little performance for a test the recording cannot pass.

The deliberate disturbance moves the plant, so a larger watermark detects faster and controls worse; the design problem is choosing its size and spectrum so that the detection delay and the cost in tracking both stay acceptable.

It answers an attacker who knows the detector. A replay leaves every residual perfect, because it controls both terms of the subtraction (stealthy attack); an ordinary detection threshold tuned for random faults never fires, and only a signal the attacker cannot predict breaks the symmetry.

It is mostly research. Mo and Sinopoli proposed it for replay attacks in 2009 and later work extended it to stronger attackers who can also read the live channel; industrial practice relies first on segmentation, authenticated messages and independent physical measurements (cyber-physical security).

Its limits are those of the secret and of the model. An attacker who learns the watermark sequence, or who can inject in real time instead of replaying, defeats it, and a plant model too poor to predict the watermark's effect gives a correlation too weak to test.