Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control Systems
Burak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang, Brendan Saltaformaggio, Saman A. Zonouz
Abstract
Industrial Control Systems (ICS) operate essential physical processes in critical infrastructure sectors such as energy, water, and transportation. Existing ICS fuzzing techniques often assume white-box access or modify controller firmware, and black-box methods uncover only corrupted inputs, leaving a critical gap in detecting physical security violations that emerge gradually from valid commands on locked-down controllers. We present ICSFlux, the first physics-aware black-box fuzzing framework that systematically discovers physical security violations. ICSFlux leverages physical models and physical security constraints (defined during the ICS design phase) to infer the temporal evolution of physical states. By estimating potential trajectories that converge toward unsafe physical states, ICSFlux partitions the physical space by proximity to violation and directs test generation toward high-risk partitions. This physics-guided approach generalizes across heterogeneous ICS deployments and eliminates reliance on application-specific heuristics. We evaluate ICSFlux on 11 industrial testbeds (e.g., chemical manufacturing plant and water treatment utility) and discover 20 physical security violations.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ca237b38-7fed-4af8-b3e9-417fa9ffe0c4Related papers
- Active fuzzing for testing and securing cyber-physical systemsYuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun et al.ISSTA 2020 · 25 citations
- Finding Causally Different Tests for an Industrial Control SystemChristopher M. Poskitt, Yuqi Chen, Jun Sun, Yu JiangICSE 2023 · 6 citations
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark et al.CCS 2025
- PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal FuzzingZhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren et al.NDSS 2026
- An LLM-Driven Fuzzing Framework for Detecting Logic Instruction Bugs in PLCsJiaxing Cheng, Ming Zhou, Haining Wang, Xin Chen et al.NDSS 2026 · 3 citations
