Active fuzzing for testing and securing cyber-physical systems
Yuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun, Fan Zhang
Abstract
Cyber-physical systems (CPSs) in critical infrastructure face a pervasive threat from attackers, motivating research into a variety of countermeasures for securing them. Assessing the effectiveness of these countermeasures is challenging, however, as realistic benchmarks of attacks are difficult to manually construct, blindly testing is ineffective due to the enormous search spaces and resource requirements, and intelligent fuzzing approaches require impractical amounts of data and network access. In this work, we propose active fuzzing, an automatic approach for finding test suites of packet-level CPS network attacks, targeting scenarios in which attackers can observe sensors and manipulate packets, but have no existing knowledge about the payload encodings. Our approach learns regression models for predicting sensor values that will result from sampled network packets, and uses these predictions to guide a search for payload manipulations (i.e. bit flips) most likely to drive the CPS into an unsafe state. Key to our solution is the use of online active learning, which iteratively updates the models by sampling payloads that are estimated to maximally improve them. We evaluate the efficacy of active fuzzing by implementing it for a water purification plant testbed, finding it can automatically discover a test suite of flow, pressure, and over/underflow attacks, all with substantially less time, data, and network access than the most comparable approach. Finally, we demonstrate that our prediction models can also be utilised as countermeasures themselves, implementing them as anomaly detectors and early warning systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c17a698-75f1-420f-af55-066a0daeb61bCited by top-tier papers4
- Code integrity attestation for PLCs using black box neural network predictionsYuqi Chen, Christopher M. Poskitt, Jun SunFSE 2021 · 16 citations
- HIFuzz: Human Interaction Fuzzing for Small Unmanned Aerial VehiclesTheodore Chambers, Michael Vierhauser, Ankit Agrawal, Michael Murphy et al.CHI 2024 · 11 citations
- VLATest: Testing and Evaluating Vision-Language-Action Models for Robotic ManipulationZhijie Wang, Zhehua Zhou, Jiayang Song, Yuheng Huang et al.FSE 2025 · 6 citations
- Finding Causally Different Tests for an Industrial Control SystemChristopher M. Poskitt, Yuqi Chen, Jun Sun, Yu JiangICSE 2023 · 6 citations
Builds on7
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer et al.CCS 2016 · 351 citations
- Detecting Attacks Against Robotic Vehicles: A Control Invariant ApproachHongjun Choi, Wen-Chuan Lee, Yousra Aafer, Fan Fei et al.CCS 2018 · 201 citations
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 162 citations
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 135 citations
- Learning from Mutants: Using Code Mutation to Learn and Monitor Invariants of a Cyber-Physical SystemYuqi Chen, Christopher M. Poskitt, Jun SunS&P 2018 · 135 citations
Related papers
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang et al.S&P 2026 · 3 citations
- FIGCPS: Effective Failure-inducing Input Generation for Cyber-Physical Systems with Deep Reinforcement LearningShaohua Zhang, Shuang Liu, Jun Sun, Yuqi Chen et al.ASE 2021 · 13 citations
- Query-Based Black-Box Stealthy Sensor Attacks on Cyber-Physical SystemsShixiong Jiang, Weizhe Xu, Mengyu Liu, Fanxin KongDAC 2025
- PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal FuzzingZhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren et al.NDSS 2026
- Fail-Safe: Securing Cyber-Physical Systems against Hidden Sensor AttacksMengyu Liu, Lin Zhang, Pengyuan Lu, Kaustubh Sridhar et al.RTSS 2022 · 15 citations
