{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/157861"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/157861","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Coevolving Cybersecurity Adversaries for Industrial Control Systems in Failure-Prone Environments","abstract":"As industrial control systems become universally integrated with software and connected to the internet, they have become targets for cyberattacks and sabotage. Detecting cyberattacks on these networks is difficult because existing datasets on attacks is minimal and the bulk of intrusion detection systems are designed for enterprise environments rather than industrial environments. In industrial environments, mechanical failures, stress states, and electrical problems are expected, with repairs included in daily operations. In enterprise environments, such failures are rarer and more high-impact as a result. We investigate the extent to which this mismatch in the impact of physical stressors failures degrades the ability of traditional intrusion detection algorithms to perform in the industrial environment. In the sub-area that this thesis focuses on, power microgrids, such disturbances can come in the form of line-line faults, line-ground faults, lack of generation capacity to meet demand, and unintentional islanding, among many others. Microgrids must be resilient to these events, and this thesis investigates to what extent they are currently and if they can be improved. Specifically, this thesis asks: do traditional IDSs cause false alarms when placed in a failure-prone environment? How do these intrusion detectors perform overall? Can they be improved with additional training? And finally, can intrusion detection systems be tricked by attacks which appear to be \"benign\" failure modes? This thesis answers these questions by comparing the performance of different anomaly detection methods on cyberattack datasets with varying levels of stressor complexity and severity, and finds that stress on an industrial system can degrade anomaly-based intrusion detector performance. Expanding on this idea, an attacker is then trained to adversarially mask a dataset, and a detector is co-evolved alongside it to detect the attacks. Finally, the coevolution is brought into the hardware-in-theloop simulation environment, where attackers and defenders act in real time to change the state of a realistic microgrid simulation. From these experiments, it is found that attackers can leverage grid disturbances to hide their actions, and that accurate realtime simulations are highly useful for identifying vulnerabilities in a cyberphysical system.","abstract_html":"As industrial control systems become universally integrated with software and connected to the internet, they have become targets for cyberattacks and sabotage. Detecting cyberattacks on these networks is difficult because existing datasets on attacks is minimal and the bulk of intrusion detection systems are designed for enterprise environments rather than industrial environments. In industrial environments, mechanical failures, stress states, and electrical problems are expected, with repairs included in daily operations. In enterprise environments, such failures are rarer and more high-impact as a result. We investigate the extent to which this mismatch in the impact of physical stressors failures degrades the ability of traditional intrusion detection algorithms to perform in the industrial environment. In the sub-area that this thesis focuses on, power microgrids, such disturbances can come in the form of line-line faults, line-ground faults, lack of generation capacity to meet demand, and unintentional islanding, among many others. Microgrids must be resilient to these events, and this thesis investigates to what extent they are currently and if they can be improved. Specifically, this thesis asks: do traditional IDSs cause false alarms when placed in a failure-prone environment? How do these intrusion detectors perform overall? Can they be improved with additional training? And finally, can intrusion detection systems be tricked by attacks which appear to be &quot;benign&quot; failure modes? This thesis answers these questions by comparing the performance of different anomaly detection methods on cyberattack datasets with varying levels of stressor complexity and severity, and finds that stress on an industrial system can degrade anomaly-based intrusion detector performance. Expanding on this idea, an attacker is then trained to adversarially mask a dataset, and a detector is co-evolved alongside it to detect the attacks. Finally, the coevolution is brought into the hardware-in-theloop simulation environment, where attackers and defenders act in real time to change the state of a realistic microgrid simulation. From these experiments, it is found that attackers can leverage grid disturbances to hide their actions, and that accurate realtime simulations are highly useful for identifying vulnerabilities in a cyberphysical system.","abstract_has_math":false,"creators":["Wicks, Kathryn"],"institution":"Massachusetts Institute of Technology","degree_name":"Master","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","school":null,"contributors":[],"advisors":["O’Reilly, Una-May","Hemberg, Erik"],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-06","date_published":"2023-06","updated_at":"2026-07-22T22:21:34Z","subjects":[],"languages":[],"rights":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"],"rights_urls":["https://rightsstatements.org/page/InC-EDU/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/157861","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["O’Reilly, Una-May","Hemberg, Erik"]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"]},{"key":"dc:creator","label":"Author","values":["Wicks, Kathryn"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2024-12-18T18:16:36Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2024-12-18T18:16:36Z"]},{"key":"dc:date.issued","label":"Date","values":["2023-06"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master","Master of Engineering in Electrical Engineering and Computer Science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"]},{"key":"dc:rights.uri","label":"Rights URI","values":["https://rightsstatements.org/page/InC-EDU/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/157861"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["As industrial control systems become universally integrated with software and connected to the internet, they have become targets for cyberattacks and sabotage. Detecting cyberattacks on these networks is difficult because existing datasets on attacks is minimal and the bulk of intrusion detection systems are designed for enterprise environments rather than industrial environments. In industrial environments, mechanical failures, stress states, and electrical problems are expected, with repairs included in daily operations. In enterprise environments, such failures are rarer and more high-impact as a result. We investigate the extent to which this mismatch in the impact of physical stressors failures degrades the ability of traditional intrusion detection algorithms to perform in the industrial environment. In the sub-area that this thesis focuses on, power microgrids, such disturbances can come in the form of line-line faults, line-ground faults, lack of generation capacity to meet demand, and unintentional islanding, among many others. Microgrids must be resilient to these events, and this thesis investigates to what extent they are currently and if they can be improved. Specifically, this thesis asks: do traditional IDSs cause false alarms when placed in a failure-prone environment? How do these intrusion detectors perform overall? Can they be improved with additional training? And finally, can intrusion detection systems be tricked by attacks which appear to be \"benign\" failure modes? This thesis answers these questions by comparing the performance of different anomaly detection methods on cyberattack datasets with varying levels of stressor complexity and severity, and finds that stress on an industrial system can degrade anomaly-based intrusion detector performance. Expanding on this idea, an attacker is then trained to adversarially mask a dataset, and a detector is co-evolved alongside it to detect the attacks. Finally, the coevolution is brought into the hardware-in-theloop simulation environment, where attackers and defenders act in real time to change the state of a realistic microgrid simulation. From these experiments, it is found that attackers can leverage grid disturbances to hide their actions, and that accurate realtime simulations are highly useful for identifying vulnerabilities in a cyberphysical system."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M.Eng."]},{"key":"dc:title","label":"Title","values":["Coevolving Cybersecurity Adversaries for Industrial Control Systems in Failure-Prone Environments"]}]}],"canonical_facts":{"dc:contributor.advisor":["O’Reilly, Una-May","Hemberg, Erik"],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"],"dc:creator":["Wicks, Kathryn"],"dc:date.accessioned":["2024-12-18T18:16:36Z"],"dc:date.available":["2024-12-18T18:16:36Z"],"dc:date.issued":["2023-06"],"dc:description.abstract":["As industrial control systems become universally integrated with software and connected to the internet, they have become targets for cyberattacks and sabotage. Detecting cyberattacks on these networks is difficult because existing datasets on attacks is minimal and the bulk of intrusion detection systems are designed for enterprise environments rather than industrial environments. In industrial environments, mechanical failures, stress states, and electrical problems are expected, with repairs included in daily operations. In enterprise environments, such failures are rarer and more high-impact as a result. We investigate the extent to which this mismatch in the impact of physical stressors failures degrades the ability of traditional intrusion detection algorithms to perform in the industrial environment. In the sub-area that this thesis focuses on, power microgrids, such disturbances can come in the form of line-line faults, line-ground faults, lack of generation capacity to meet demand, and unintentional islanding, among many others. Microgrids must be resilient to these events, and this thesis investigates to what extent they are currently and if they can be improved. Specifically, this thesis asks: do traditional IDSs cause false alarms when placed in a failure-prone environment? How do these intrusion detectors perform overall? Can they be improved with additional training? And finally, can intrusion detection systems be tricked by attacks which appear to be \"benign\" failure modes? This thesis answers these questions by comparing the performance of different anomaly detection methods on cyberattack datasets with varying levels of stressor complexity and severity, and finds that stress on an industrial system can degrade anomaly-based intrusion detector performance. Expanding on this idea, an attacker is then trained to adversarially mask a dataset, and a detector is co-evolved alongside it to detect the attacks. Finally, the coevolution is brought into the hardware-in-theloop simulation environment, where attackers and defenders act in real time to change the state of a realistic microgrid simulation. From these experiments, it is found that attackers can leverage grid disturbances to hide their actions, and that accurate realtime simulations are highly useful for identifying vulnerabilities in a cyberphysical system."],"dc:description.degree":["M.Eng."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/157861"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"],"dc:rights.uri":["https://rightsstatements.org/page/InC-EDU/1.0/"],"dc:title":["Coevolving Cybersecurity Adversaries for Industrial Control Systems in Failure-Prone Environments"],"dc:type":["Thesis"],"thesis:degree_name":["Master","Master of Engineering in Electrical Engineering and Computer Science"]},"updated_at":"2026-07-22T22:21:34Z"}