Cyber-physical robotic systems are vulnerable to false data injection attacks (FDIAs), in which an adversary corrupts sensor signals while evading residual-based passive anomaly detectors such as the chi-squared test. Such stealthy attacks can induce substantial end-effector deviations without triggering alarms. This paper studies the resilience of redundant manipulators to stealthy FDIAs and advances the architecture from passive monitoring to active defence. We formulate a closed-loop model comprising a feedback-linearized manipulator, a steady-state Kalman filter, and a chi-squared-based anomaly detector. Building on this passive monitoring layer, we propose an active control-level defence that attenuates the control input through a monotone function of an anomaly score generated by a novel actuation-projected, measurement-free state predictor. The proposed design provides probabilistic guarantees on nominal actuation loss and preserves closed-loop stability. From the attacker perspective, we derive a convex QCQP for computing one-step optimal stealthy attacks. Simulations on a 6-DOF planar manipulator show that the proposed defence significantly reduces attack-induced end-effector deviation while preserving nominal task performance in the absence of attacks.
It is a standard engineering practice to design feedback-based control to have a system follow a given trajectory. While the trajectory is continuous-time, the sequence of references is varied at discrete times, which may not be periodic. In this paper, we propose a method to determine the discrete-time references which minimizes a weighted L2 distance between the achieved trajectory and the target trajectory. Also, we consider any arbitrary sequence of sampling instants. The proposed method is then assessed over different simulation results, analyzing the design parameters' effects, and over an unmanned aerial vehicle (UAV) use case. (c) 2025 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
This paper presents DCGUARD, a unified security approach for detecting and isolating misbehaving computing and forwarding nodes in multi-tenant virtualized cloud data centers. DCGUARD employs technological advancements in Virtual Machine Introspection (VMI), Software-Defined Networking (SDN), and secure probabilistic sketching to detect and isolate parts of the Virtual Machines (VMs) and network switches experiencing malicious behavior dynamically. The main contribution lies in designing a divide-and-conquer strategy that utilizes VMI and network programmability to apply focused distributed task and packet probing mechanisms on portions of the data center network rather than focusing the security functions on the entire physical network. The processing VMs and network switches are recursively partitioned into independent logical groups inspected individually to localize abnormal/malicious computing and switching nodes incrementally. This remarkably enhances the efficiency of the detection mechanisms, which opportunistically approaches a logarithmic time complexity in the number of protocol steps towards convergence (compared to a linear time complexity in traditional intrusion detection systems) when a relatively low number of hostile VMs and switches are present. Real experiments are evaluated, and a test-bed blueprint of the proposed design is emulated in a virtualized cloud environment using the Mininet emulator. The performance, convergence, and accuracy benchmarks corroborate the analytical advantage of the proposed security approach.
In scheduling real-time tasks, we face the challenge of meeting hard deadlines while optimizing for some other objective, such as minimizing energy consumption. Formulating the optimization as a Multi-Armed Bandit (MAB) problem allows us to use MAB strategies to balance the exploitation of good choices based on observed data with the exploration of potentially better options. In this paper, we integrate hard real-time constraints with MAB strategies for resource management of a Stochastic Parallel Synchronous Task. On a platform with M cores available for the task, m≤ M cores are initially assigned. Prior work has shown how to compute a virtual deadline such that assigning all M cores to the task if it has not completed by this virtual deadline guarantees that the deadline will be met. An MAB strategy is used to select the value of m . A Dynamic Power Management (DPM) energy model considering CPU sockets and sleep states is described. Experimental evaluation shows that MAB strategies learn consistently suitable m , and perform well compared to binary exponential search and greedy methods.
Computationally demanding tasks with highly variable execution times may require parallel processing. Scheduling such tasks with low deadline miss rates but without significant overprovisioning is challenging. This issue arises in applications like nonlinear optimization for Model Predictive Control (MPC). The Constant Bandwidth Server (CBS) provides timing isolation, supporting both hard and soft real-time tasks. However, scheduling parallel, time-varying jobs across multiple CBS instances requires static job-to-server assignments, which can lead to resource underutilization due to queued jobs awaiting specific servers. This paper introduces the Job Acceptance Multi-Server (JAMS), a mechanism in which multiple CBS instances share a common job queue, enabling flexible job dispatching for parallel workloads. JAMS incorporates a job dismissal mechanism to address overloads, ensuring that only jobs with guaranteed resource availability are accepted. Each CBS instance checks if it can complete a job by its deadline, given probabilistic knowledge on its execution times, dismissing unfeasible jobs to avoid excessive tardiness across queued tasks. Implemented in Linux, JAMS is evaluated with computation times drawn from an MPC task and synthetic datasets. The extensive experimental results we provide demonstrate that JAMS effectively controls the deadline miss rate, maintaining it below a specified design threshold.
The integration of control applications into cloud and edge expands the capabilities of modern control systems, but also introduces variability in shared resource availability and competition with other applications, posing new challenges for control design. This paper presents a multi-mode Model Predictive Control (MPC) framework tailored for resource-aware systems. By treating the controller period as a scalable parameter, our approach dynamically adjusts control accuracy and computational complexity in response to changing resource and state-space conditions. Unlike existing event- and self-triggered strategies, our multi-mode design allows users to actively manage trade-offs between computational load and control quality. We provide feasibility and stability guarantees for the proposed control framework and demonstrate its effectiveness in a simulated cart-pole system, showcasing significant improvements in computational resource efficiency without compromising control performance.
This paper addresses the control of the state of charge (SoC) of a Battery Energy Storage System (BESS) in a microgrid, considering uncertainties in load and Renewable Energy Sources (RES) generated power estimations. To achieve this objective, we propose RubPC, a novel rule-based Model Predictive Control (MPC). We partition the feasible operation space of the microgrid into two subzones, referred to as the white and yellow zones. The yellow zone represents the boundary space between the feasible and unfeasible operation spaces. In RubPC, we initially implement MPC on a predefined optimization window to determine the optimal SoC of the BESS, aiming to keep the microgrid within the white zone. Noting that mismatches between estimated and actual load and generated power may lead to constraint violations, we introduce a rule-based controller as a supervisory control. This controller monitors the microgrid's state, and if the microgrid enters the yellow zone, it adjusts the control to maintain the microgrid within the white zone. We validate our proposed method by simulating it using data from an electrified quarry site in Sweden.
This paper introduces a novel approach, which we refer to as hybrid moving controller, designed to ensure closed-loop stability while eliminating the requirement for synchronization between the plant and control unit. In our proposed method, the controller is time-varying and moves the closed-loop eigenvalues along radial trajectories originating from the origin. The sequence of controllers is assumed to be kept confidential from potential adversaries. Given that this moving controller renders the overall closed-loop system time-varying, maintaining the eigenvalues within the unit circle alone is insufficient to guarantee stability. As a result, we explore stability through the lens of contraction theory and present criteria for the sequence of controllers to ensure stability.
The users of cloud services prioritize cost and performance, but they increasingly demand sustainable practices. Sustainability is no longer a choice for businesses but a strategic imperative that shapes global industries. This paper presents a new system for utilizing the render farms in cloud data centers. The system aims to reduce energy consumption and costs in cloud data centers while maintaining a specific level of performance, particularly when rendering images and videos. The system can be described as a cloud-based expert system that offers rendering as a service, while considering user preferences for performance, cost, and energy efficiency. The system reads different scene rendering parameters and accordingly chooses the most suitable GPUs that fit the user's requirements. In other words, the system inputs are the scene complexity and user preferences. The output is the optimal GPU for rendering. Scene complexity is determined based on several parameters, such as the number of frames and polygons, resulting in one scene-related value. The user preferences are also normalized to a preferences-related value. Then, these values are aggregated to determine the optimal available GPU to render the scene at the lowest cost, minimum possible energy consumption, and highest performance.
This study is based on a Moving Target Defence (MTD) algorithm designed to introduce uncertainty into the controller and another layer of uncertainty to intrusion detection. This randomness complicates the adversary's attempts to craft stealthy attacks while concurrently minimizing the impact of false-data injection attacks. Leveraging concepts from state observer design, the method establishes an optimization framework to determine the parameters of the random signals. These signals are strategically tuned to increase the detectability of stealthy attacks while reducing the deviation resulting from false data injection attempts. We propose here to use two different state observers and two associated MTD algorithms. The first one optimizes the parameters of the random signals to reduce the deviation resulting from false data injection attempts and maintain the stability of the closed-loop system with the desired level of performance. In contrast, the second one optimizes the parameters of the random signals to increase the detectability of stealthy attacks. Dividing the optimization problem into two separate optimization processes simplifies the search process and makes it possible to have higher values of the detection cost function. To illustrate the effectiveness of our approach, we present a case study involving a generic linear time-invariant system and compare the results with a recently published algorithm.
In real-time systems analysis, probabilistic models, particularly Markov chains, have proven effective for tasks with dependent executions. This paper improves upon an approach utilizing Gaussian emission distributions within a Markov task execution model that analyzes bounds on deadline miss probabilities for tasks in a reservation-based server. Our method distinctly addresses the issue of runtime complexity, prevalent in existing methods, by employing a state merging technique. This not only maintains computational efficiency but also retains the accuracy of the deadline-miss probability estimations to a significant degree. The efficacy of this approach is demonstrated through the timing behavior analysis of a Kalman filter controlling a Furuta pendulum, comparing the derived deadline miss probability bounds against various benchmarks, including real-time Linux server metrics. Our results confirm that the proposed method effectively upper-bounds the actual deadline miss probabilities, showcasing a significant improvement in computational efficiency without significantly sacrificing accuracy.
In order to facilitate the adoption of Time Sensitive Networking (TSN) by the industry, it is necessary to develop tools to integrate legacy systems with TSN. In this article, we propose a solution for the coexistence of different time domains from different legacy systems, each with its corresponding synchronization protocol, in a single TSN network. To this end, we experimentally identified the effects of replacing the communications subsystem of a legacy Ethernet-based network with TSN in terms of synchronization. Based on the results, we propose a solution called TALESS (TSN with Legacy End-Stations Synchronization). TALESS can identify the drift between the TSN communications subsystem and the integrated legacy devices (end-stations) and then modify the TSN schedule to adapt to the different time domains to avoid the effects of the lack of synchronization between them. We validate TALESS through both simulations and experiments on a prototype. We demonstrate that thanks to TALESS, legacy systems can synchronize through TSN and even improve features such as their reception jitter or their integrability with other legacy systems.
Industrial controllers constitute the core of numerous automation solutions. Continuous control system operation is crucial in certain sectors, where hardware duplication serves as a strategy to mitigate the risk of unexpected operational halts due to hardware failures. Standby controller redundancy is a commonly adopted strategy for process automation. This approach involves an active primary controller managing the process while a passive backup is on standby, ready to resume control should the primary fail. Typically, redundant controllers are paired with redundant networks and devices to eliminate any single points of failure. The process automation domain is on the brink of a paradigm shift towards greater interconnectivity and interoperability. OPC UA is emerging as the standard that will facilitate this shift, with OPC UA PubSub as the communication standard for cyclic real-time data exchange. Our work investigates standby redundancy using OPC UA PubSub, analyzing a system with redundant controllers and devices in publisher-subscriber roles. The analysis reveals that failovers are not subscriber-transparent without synchronized publisher states. We discuss solutions and experimentally validate an internal stack state synchronization alternative.
Container-based virtualization is a promising deployment model in fog and edge computing applications, because it allows a seamless co-existence of virtualized applications in a heterogeneous environment without introducing significant overhead. Certain application domains (e.g., industrial automation, automotive, or aerospace) mandate that applications exhibit a certain degree of temporal predictability. Container-based virtualization cannot be easily used for such applications, since the technology is not designed to support real-time properties and handle temporal disturbances. This article proposes a framework consisting of a static offline and a dynamic online phase for resource allocation and adaptive re-dimensioning of real-time containers. In the offline phase, the optimal initial deployment and dimensioning of containers are decided based on ideal system models. Additionally, to adapt to dynamic variations caused by changing workloads or interferences, the online phase adapts the CPU usage and limits of real-time containers at runtime to improve the real-time behavior of the real-time containerized applications while optimizing resource usage. We implement the framework in a real Linux-based system and show through a series of experiments that the proposed framework is able to adjust and re-distribute computing resources between containers to improve the real-time behavior of containerized applications in the presence of temporal disturbances while optimizing resource usage.
In the era of the IoT revolution, applications are becoming ever more sophisticated and accompanied by diverse functional and non-functional requirements, including those related to computing resources and performance levels. Such requirements make the development and implementation of these applications complex and challenging. Computing models, such as cloud computing, can provide applications with on-demand computation and storage resources to meet their needs. Although cloud computing is a great enabler for IoT and endpoint devices, its limitations make it unsuitable to fulfill all design goals of novel applications and use cases. Instead of only relying on cloud computing, leveraging and integrating resources at different layers (like IoT, edge, and cloud) is necessary to form and utilize a computing continuum. The layers’ integration in the computing continuum offers a wide range of innovative services, but it introduces new challenges (e.g., monitoring performance and ensuring security) that need to be investigated. A better grasp and more profound understanding of the computing continuum can guide researchers and developers in tackling and overcoming such challenges. Thus, this paper provides a comprehensive and unified view of the computing continuum. The paper discusses computing models in general with a focus on cloud computing, the computing models that emerged beyond the cloud, and the communication technologies that enable computing in the continuum. In addition, two novel reference architectures are presented in this work: one for edge-cloud computing models and the other for edge-cloud communication technologies. We demonstrate real use cases from different application domains (like industry and science) to validate the proposed reference architectures, and we show how these use cases map onto the reference architectures. Finally, the paper highlights key points that express the authors’ vision about efficiently enabling and utilizing the computing continuum in the future.
Time-Sensitive Networking (TSN) has become one of the most relevant communication networks in many application areas. Among several traffic classes supported by TSN networks, Audio-Video Bridging (AVB) traffic requires a Worst-Case Response Time Analysis (WCRTA) to ensure that AVB frames meet their time requirements. In this paper, we evaluate the existing WCRTAs that cover various features of TSN, including Scheduled Traffic (ST) interference and preemption. When considering the effect of the ST interference, we detect optimism problems in two of the existing WCRTAs, namely (i) the analysis based on the busy period calculation and (ii) the analysis based on the eligible interval. Therefore, we propose a new analysis including a new ST interference calculation that can extend the analysis based on the eligible interval approach. The new analysis covers the effect of the ST interference, the preemption by the ST traffic, and the multi-hop architecture. The resulting WCRTA, while safe, shows a significant improvement in terms of pessimism level compared to the existing analysis approaches relying on either the concept of busy period or the Network Calculus model.
In this work, we address the problem of balancing an autonomous bicycle using direct data-driven control. Firstly, we demonstrate that a direct implementation of data-driven approaches may not guarantee reliable performance, and is highly dependent on how the parameters are selected. To address this issue, we make the reasonable assumption that we have access to some inaccurate information about the system. We use this inaccurate information to design a feedback linearization, based on a simplified point mass model of the bicycle, which does not accurately represent the dynamics of the system. Next, we suggest an inner and outer-loop control strategy. In the inner loop, we implement the aforementioned feedback linearization controller. Subsequently, in the outer loop, we consider the combination of the autonomous bicycle and the feedback controller as a black box, and we design a direct data-driven controller from acquired data. We use a SolidWorks model of a real autonomous bicycle to evaluate the performance of our proposed control approach and to compare it with the direct data-driven controller design derived from acquired data of the bicycle without feedback linearization. The results show that our proposed strategy significantly improves the performance and makes the data-driven control approach more reliable across a broader range of parameter choices compared to a data-driven controller designed based on data from the system without feedback linearization. Finally, we show that introducing an additional integral-like state further enhances the system’s performance.
Control systems are often an integral part of automation solutions where high reliability is crucial due to the high cost of downtime. The risk of unplanned downtime is typically reduced with redundant solutions. Additionally, safety-critical automation functions require high-integrity controllers. Today, the prevalent redundancy solution is a standby scheme, where one active primary controller drives the process while a standby backup controller is ready to take over in case of primary failure. This redundant controller pair can consist of high - integrity controllers. The automation industry is trending towards Ethernet as the sole communication medium. Our work presents an initial study of a high-integrity realization of a redundancy failure detection mechanism that guarantees only one primary controller, even in the case of network partitioning between the redundant controller pair. The failure detection is a lease-based function that leases the primary role from a central lease broker. This work discusses a high-integrity realization of the primary redundancy role leasing. We deduce and present the high-integrity-related requirements and a high-level design as an initial step towards a high-integrity realization of the redundancy role leasing.
Maria Prandini合作论文数Dipartimento di Elettronica, Informazione e Bioingegneria, Politecnico di Milano7