Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control Systems
Burak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang, Brendan Saltaformaggio, Saman A. Zonouz
摘要
Industrial Control Systems (ICS) operate essential physical processes in critical infrastructure sectors such as energy, water, and transportation. Existing ICS fuzzing techniques often assume white-box access or modify controller firmware, and black-box methods uncover only corrupted inputs, leaving a critical gap in detecting physical security violations that emerge gradually from valid commands on locked-down controllers. We present ICSFlux, the first physics-aware black-box fuzzing framework that systematically discovers physical security violations. ICSFlux leverages physical models and physical security constraints (defined during the ICS design phase) to infer the temporal evolution of physical states. By estimating potential trajectories that converge toward unsafe physical states, ICSFlux partitions the physical space by proximity to violation and directs test generation toward high-risk partitions. This physics-guided approach generalizes across heterogeneous ICS deployments and eliminates reliance on application-specific heuristics. We evaluate ICSFlux on 11 industrial testbeds (e.g., chemical manufacturing plant and water treatment utility) and discover 20 physical security violations.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Active fuzzing for testing and securing cyber-physical systemsYuqi Chen, Bohan Xuan, Christopher M. Poskitt, Jun Sun 等ISSTA 2020 · 被引用 25 次
- Finding Causally Different Tests for an Industrial Control SystemChristopher M. Poskitt, Yuqi Chen, Jun Sun, Yu JiangICSE 2023 · 被引用 6 次
- ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control TheoryJinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark 等CCS 2025
- PhyFuzz: Detecting Sensor Vulnerabilities with Physical Signal FuzzingZhicong Zheng, Jinghui Wu, Shilin Xiao, Yanze Ren 等NDSS 2026
- An LLM-Driven Fuzzing Framework for Detecting Logic Instruction Bugs in PLCsJiaxing Cheng, Ming Zhou, Haining Wang, Xin Chen 等NDSS 2026 · 被引用 3 次
