security//cyber-physical security//stealthy attack
A stealthy attack is an attack on a monitored control system designed to keep every residual inside its healthy band while it pushes the physical system toward a state the attacker chooses, and it is the threat that makes fault detection built for random faults insufficient against an opponent. A worn bearing produces a residual by accident; an attacker who knows the detector, its thresholds and the model behind it produces exactly the readings the detector expects. The name for the idea is stealth; the mechanism is observability.
A stealthy attack is an attack on a monitored control system designed to keep every residual inside its healthy band while it pushes the physical system toward a state the attacker chooses, and it is the threat that makes fault detection built for random faults insufficient against an opponent. A worn bearing produces a residual by accident; an attacker who knows the detector, its thresholds and the model behind it produces exactly the readings the detector expects. The name for the idea is stealth; the mechanism is observability.
For linear systems the condition is exact. An attack is undetectable by any detector that sees only the system's outputs if and only if the outputs it produces could also have come from the healthy system started from a different initial state1. No residual can separate two histories that produce identical measurements, so the attack hides in the directions the sensors cannot see. A slower, practical version exploits the band instead: a GPS position dragged a few centimetres per second stays within what the filter considers normal noise, while the drone drifts metres from where it believes it is (GNSS spoofing).
1Pasqualetti, Dörfler and Bullo, Attack detection and identification in cyber-physical systems, IEEE Transactions on Automatic Control, 2013.
A stealthy attack and a fault in an unobservable direction are the same phenomenon seen from two sides.
That is why an independent sensor is usually worth more than any algorithm: it changes what can be seen, and with it the set of attacks that can hide (observability).
The attacker's power grows with knowledge and access: the model, the detector's settings, and which sensors and actuators can be altered. An attacker who controls every measurement can replay a healthy history and need not model anything at all (replay attack); one who controls a few must solve for values consistent with the rest, which is the subject of false data injection.
The defences change the conditions of the theorem: measurements the attacker cannot reach, physical relations the attacker must also satisfy, secret signals added to the actuation whose trace a fake output lacks, and tests that accumulate evidence over hours, such as CUSUM, against slow drags (cyber-physical security).