Covert attacks significantly threaten the safety of nuclear reactors’ liquid zone control systems (LZCSs). Successful covert attacks require an accurate model of the target system and the ability to exit without leaving traces after the attack. This paper proposes a four-stage covert attack method for LZCSs. First, in the attack preparation stage, a dual-mode H2 optimal unbiased finite impulse response (FIR) is offline designed via maximizing the likelihood estimation. This FIR is used to estimate the system states in the state estimation stage. In the attack execution stage, specific attack sequences are designed and injected into the system signal transmission channels to complete a covert attack, considering the anticipated goals and system states. Finally, in the attack exit stage, a constrained optimization problem is constructed based on the system state offsets to provide the optimal attack exit sequences, allowing for an unnoticed exit. The feasibility of the proposed covert attack method is simulated and verified in different situations, taking into account the system noise intensity and attack model accuracy. The experimental results demonstrate that the proposed attack method can covertly achieve its goals and exit without a trace, under the influence of the above factors individually or combined.
False data injection (FDI) attacks represent a serious threat to securing nuclear reactor operation. Efficient FDI attack detection is essential to prevent related unforeseen nuclear accidents. However, owing to their design principles, the existing detection methods are limited in their ability to detect multiple types of FDI attacks. To address this issue, we propose a detection scheme for FDI attacks on a nuclear reactor based on the chaotic time/frequency-hopping (TH/FH) spread spectrum. The proposed scheme uses frequency hopping modulation, demodulation, and filtering of the signal based on hyper-chaotic sequences to limit the attacker's access to the system's real data and eliminate the adverse effects of attacks on the system. Furthermore, theoretical analysis derives the stability constraint of the frequency hopping frequency and demonstrates the detectability and defendability of the proposed scheme. Experimental simulations demonstrated that our proposed scheme can detect two typical FDI attacks, replay attacks and covert attacks, without compromising system operation, and defend against and reproduce covert attack signals.