With the rapid development of sixth-generation (6G) wireless networks, ensuring secure and covert communication has become increasingly important. Meanwhile, autoencoder (AE)-based communication systems have emerged as a promising paradigm due to their ability to jointly optimize the transmitter and receiver in an end-to-end manner. This paper aims to propose an AE-based covert communication system that generates transmission signals with low autocorrelation (ACF), making them difficult for eavesdroppers to detect, while maintaining the block error rate (BLER) performance for the intended communication. To address the scalability limitation of conventional AE systems, where input dimensionality grows exponentially with message size, we develop an AE architecture that integrates error-correction coding (ECC). The source message is first encoded into a binary sequence and fed into the AE, while an ECC decoder at the receiver recovers the original message, enabling efficient binary-input processing and improved BLER performance. Besides, to reduce ACF and detection probability without compromising intended communication performance, we propose a novel training mechanism that incorporates a Kullback-Leibler (KL) divergence term into the conventional cross-entropy loss. Simulation results show that the proposed communication system achieves BLER performance comparable to that of conventional AE-based systems over both AWGN and Rayleigh fading channels. Meanwhile, under the ACF-based detection framework, the proposed AE system trained with the proposed loss exhibits a notably lower detection rate than the conventional AE system. In particular, with a false alarm rate of 10-3, the proposed AE-based system can achieve a detection probability of 0.0457, compared to 0.9089 for the conventional AE-based system, under an AE setting where each 4-bit message block is modulated into 10 transmitter symbols by the AE encoder.
Embodied AI requires sub-second inference near the Radio Access Network (RAN), but deployments span heterogeneous tiers (on-device, RAN-edge, cloud) and must not disrupt real-time baseband processing. We report measurements from a 5G Standalone (SA) AI-RAN testbed using a fixed baseline policy for repeatability. The setup includes an on-device tier, a three-node RAN-edge cluster co-hosting a containerized 5G RAN, and a cloud tier. We find that on-device execution remains multi-second and fails to meet sub-second budgets. At the RAN edge, SLA feasibility is primarily determined by model variant choice: quantized models concentrate below 0.5 s, while unquantized and some larger quantized models incur deadline misses due to stalls and queuing. In the cloud tier, meeting a 0.5 s deadline is challenging on the measured WAN path (up to 32.9% of requests complete within 0.5 s), but all evaluated variants meet a 1.0 s deadline (100% within 1.0 s). Under saturated downlink traffic and up to N=20 concurrent inference clients, Multi-Instance GPU (MIG) isolation preserves baseband timing-health proxies, supporting safe co-location under fixed partitioning.
The O-RAN ALLIANCE promotes an open Radio Access Network (RAN) vendor ecosystem by defining O-RAN architecture and interfaces. The open fronthaul (O-FH) interface is a crucial interface between the O-RAN Radio Unit (O-RU) and the O-RAN Distributed Unit (O-DU), allowing mobile network operators to select best-of-breed O-RUs among multiple vendors. However, O-FH also introduces new security risk. In this work, we present 5G-Muffler, a set of covert DoS attacks over the O-FH interface. 5G-Muffler disrupts the random access process, the initial step for a user equipment (UE) to connect to the network. By preventing UEs from completing this step, 5G-Muffler makes the 5G network inaccessible. Furthermore, the attack is invisible to anomaly detection mechanisms above PHY layer. Our first variant, 5G-Muffler-1, introduces a man-in-the-middle device between O-RU and O-DU by manipulating an O-FH switch's configurations. The second variant, 5G-Muffler-2, targets the common 5G shared-cell setup, where a cell uses multiple O-RUs to enhance its coverage and signal quality. 5G-Muffler-2 only needs to control a single O-RU and it leverages weakness in the shared-cell signal aggregation process to amplify the attack to the whole cell. We demonstrate 5G-Muffler on commercial O-RAN systems and propose countermeasures to mitigate these attacks.
Artificial intelligence (AI) techniques, particularly autoencoders (AEs), have gained significant attention in wireless communication systems. This paper investigates using an AE to generate featureless signals with a low probability of detection and interception (LPD/LPI). Firstly, we introduce a novel loss function that adds a KL divergence term to the categorical cross entropy, enhancing the noise like characteristics of AE-generated signals while preserving block error rate (BLER). Secondly, to support long source message blocks for the AE's inputs, we replace one-hot inputs of source blocks with binary inputs pre-encoded by conventional error correction coding schemes. The AE's outputs are then decoded back to the source blocks using the same scheme. This design enables the AE to learn the coding structure, yielding superior BLER performance on coded blocks and the BLER of the source blocks is further decreased by the error correction decoder. Moreover, we also validate the AE based communication system in the over-the-air communication. Experimental results demonstrate that our proposed methods improve the featureless properties of AE signals and significantly reduce the BLER of message blocks, underscoring the promise of our AE-based approach for secure and reliable wireless communication systems.
Communication network dependencies for microgrid’s operations increases cybersecurity risks, where vulnerabilities found in communication protocols can be exploited for malicious intent. In this paper, we enumerate important attack techniques on multiple communication protocols and investigate their impacts on the microgrid dispatch function. We also show that an attacker can leverage multiple protocols to launch coordinated attacks that offers longer-term, stealthier, and larger adversarial impact, an advanced persistent threat. Our main contribution in this work is a detailed case study carried out on Electrical Power and Intelligent Control (EPIC) testbed located in Singapore. Through a series of experiments, we demonstrated individual protocols’ vulnerability, verified their negative impacts on several microgrid’s dispatch functions, and also illustrated the practicality of coordinated attacks through the manipulation of multiple protocols.
Given the rapid growth in microgrid deployment and its associated cybersecurity risks, many stakeholders begin to recognize the importance of conducting close-to-real-world cyber exercises to train their workforce. In this paper, we present the design consideration and implementation details of a recent cyber exercise conducted on the Electric Power and Intelligent Control (EPIC) microgrid testbed located in Singapore University of Technology and Design (SUTD). The proposed cyber exercise is part of the Critical Infrastructure Security Showdown (CISS) event 2022 organized by the iTrust centre in SUTD. As part of the design and control team of this cyber exercise, we aim to provide the attackers (red team participants) with realistic attacking experiences that are close to real-world circumstances. In particular, exposing EPIC’s IT/OT infrastructure with realistic vulnerabilities that attackers can use to achieve a variety of attack objectives. Our proposed list of attack objectives form an attack blueprint that guides the attackers with interim attacking steps before achieving the ultimate goal.
Cyber-physical systems (CPSs) automating critical public infrastructure face a pervasive threat of attack, motivating research into different types of countermeasures. Assessing the effectiveness of these countermeasures is challenging, however, as benchmarks are difficult to construct manually, existing automated testing solutions often make unrealistic assumptions, and blindly fuzzing is ineffective at finding attacks due to the enormous search spaces and resource requirements. In this work, we propose active sensor fuzzing, a fully automated approach for building test suites without requiring any a prior knowledge about a CPS. Our approach employs active learning techniques. Applied to a real-world water treatment system, our approach manages to find attacks that drive the system into 15 different unsafe states involving water flow, pressure, and tank levels, including nine that were not covered by an established attack benchmark. Furthermore, we successfully generate targeted multi-point attacks which have been long suspected to be possible. We reveal that active sensor fuzzing successfully extends the attack benchmarks generated by our previous work, an ML-guided fuzzing tool, with two more kinds of attacks. Finally, we investigate the impact of active learning on models and the reason that the model trained with active learning is able to discover more attacks.
Programmable logic controllers (PLCs) are vulnerable to malware, which is a key security risk for Industrial Control Systems (ICSs). Existing attestation solutions are invasive because they require hardware security modules and software upgrades in legacy devices. We propose DNAttest, a Digital-twin-based Non-invasive Attestation solution to attest PLC behaviors in near-real time. DNAttest requires minimal ICS infrastructure changes and does not interfere with normal ICS operations. DNAttest detects PLC deviations by replicating all input messages for a PLC to its digital twin and comparing their output messages. Due to transient uncertainty in the PLC's internal processing state, DNAttest may output an incorrect comparison. To generate all plausible output values for comparison, we instantiate multiple emulated PLCs by replicating input messages with different timing profiles. We demonstrate on a close-to-real-world power grid testbed that DNAttest can provide a timely detection of a wide range of attacks non-invasively and accurately. DNAttest solution is lightweight and scalable. A typical desktop PC can attest more than 20 actual PLCs even if we use 10 emulators to monitor every actual PLC.
As demonstrated by the past real-world incidents, sophisticated attackers targeting our critical infrastructure may be hiding in the system, perhaps at this moment, in order to collect information and prepare for massive attacks. If an attacker is mostly passive and monitoring SCADA communication traffic or is clever enough to act under the radar of intrusion/anomaly detection systems, it is challenging to counter them. In this direction, deception technology is an effective cybersecurity tool, by deploying a large number of dummy and decoy devices throughout the system infrastructure to be protected, for capturing probing attempts and lateral movement of persistent attackers and malware. In this paper, we discuss the practical design and implementation of high-fidelity deception devices for smart power grid systems, named DecIED. DecIED imitates the device characteristics and communication models of IEC 61850-compliant IEDs (intelligent electronic devices) and thus realize k-anonymous smokescreen, which virtually shows k-1 indistinguishable decoy devices, to protect our critical infrastructure. Based on our prototype implementation, a single industry PC can host over 200 deception devices, which demonstrates DecIED's scalability and feasibility of integration into the existing systems.
The smart grid system is exposed to cyberattacks, as demonstrated by the number of real-world incidents in the last few years. The attack strategies keep evolving, and security mechanisms must identify novel attack vectors ideally before they actually hit the system. In this direction, honeypot systems for smart grid infrastructure are considered effective. While use of honeypot systems for general IT security has a history already, implementations for smart grid systems, and industrial control systems in general, are not mature yet. In this paper, we summarize our efforts for designing, implementing, and evaluating our smart grid honeypot system. We started with a prototype implementation of the virtual smart grid infrastructure using open-source tools, evaluate the realism of it from an attacker’s perspective through collaboration with cybersecurity experts. We then refined the honeypot system to offer better realism as well as logging features for capture attackers’ behaviours.
Recently, flash memory is becoming a popular data storage device in most of the electronic consumer devices. It has lots of attractive features such as small size and light weight nature, zero noise, solid-state reliability, low power consumption, and better shock resistant. To make it suitable for real-time embedded applications, this paper presents the design of an object based file system that uses parallel operations to guarantee bounded read-write access latencies to real-time tasks, in the presence of requests from non real-time tasks. The proposed scheme requires minimal support from the underlying operating system.
Data replication is a key way to design a disaster tolerance system and to achieve reliability and availability. It is difficult for a replication protocol to deal with the diverse and complex environment. This means that data is less well replicated than it ought to be. To reduce data loss and to optimize replication protocols, we (1) present a finite state machine, (2) run it to manage an asynchronous replication protocol and (3) report a simple evaluation of the asynchronous replication protocol based on our state machine. It's proved that our state machine is applicable to guarantee the asynchronous replication protocol running in the proper state to the largest extent in the event of various possible events. It also can helpful to build up replication-based disaster tolerance systems to ensure the business continuity.
Disaster recovery solutions have gained popularity in the past few years because of their ability to tolerate disasters and to achieve the reliability and availability. Data replication is one of the most key disaster recovery solutions. While there are a number of mechanisms to restore data after disasters, the efficiency of the recovery process is not ideal yet. Providing the efficiency guarantee in replication systems is important and complex because the services must not be interrupted and the availability and continuity of businesses must be kept after disasters. To recover the data efficiently, we (1) present a fast disaster recovery mechanism, (2) implement it in a volume replication system, and (3) report an evaluation for the recovery efficiency of the volume replication system. It’s proved that our disaster recovery mechanism can recover the data at the primary system as fast as possible and achieve the ideal recovery efficiency. Fast disaster recovery mechanism can also be applicable to other kinds of replication systems to recover the data in the event of disasters.