Differential Privacy for Regulatory Compliance in Cyberattack Detection on Critical Infrastructure Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ramanan, Paritosh, Islam, H. M. Mohaimanul, Alugula, Abhiram Reddy
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911267382362112
author Ramanan, Paritosh
Islam, H. M. Mohaimanul
Alugula, Abhiram Reddy
author_facet Ramanan, Paritosh
Islam, H. M. Mohaimanul
Alugula, Abhiram Reddy
contents Industrial control systems are a fundamental component of critical infrastructure networks (CIN) such as gas, water and power. With the growing risk of cyberattacks, regulatory compliance requirements are also increasing for large scale critical infrastructure systems comprising multiple utility stakeholders. The primary goal of regulators is to ensure overall system stability with recourse to trustworthy stakeholder attack detection. However, adhering to compliance requirements requires stakeholders to also disclose sensor and control data to regulators raising privacy concerns. In this paper, we present a cyberattack detection framework that utilizes differentially private (DP) hypothesis tests geared towards enhancing regulatory confidence while alleviating privacy concerns of CIN stakeholders. The hallmark of our approach is a two phase privacy scheme that protects the privacy of covariance, as well as the associated sensor driven test statistics computed as a means to generate alarms. Theoretically, we show that our method induces a misclassification error rate comparable to the non-DP cases while delivering robust privacy guarantees. With the help of real-world datasets, we show the reliability of our DP-detection outcomes for a wide variety of attack scenarios for interdependent stakeholders.
format Preprint
id arxiv_https___arxiv_org_abs_2508_08190
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Differential Privacy for Regulatory Compliance in Cyberattack Detection on Critical Infrastructure Systems
Ramanan, Paritosh
Islam, H. M. Mohaimanul
Alugula, Abhiram Reddy
Cryptography and Security
Industrial control systems are a fundamental component of critical infrastructure networks (CIN) such as gas, water and power. With the growing risk of cyberattacks, regulatory compliance requirements are also increasing for large scale critical infrastructure systems comprising multiple utility stakeholders. The primary goal of regulators is to ensure overall system stability with recourse to trustworthy stakeholder attack detection. However, adhering to compliance requirements requires stakeholders to also disclose sensor and control data to regulators raising privacy concerns. In this paper, we present a cyberattack detection framework that utilizes differentially private (DP) hypothesis tests geared towards enhancing regulatory confidence while alleviating privacy concerns of CIN stakeholders. The hallmark of our approach is a two phase privacy scheme that protects the privacy of covariance, as well as the associated sensor driven test statistics computed as a means to generate alarms. Theoretically, we show that our method induces a misclassification error rate comparable to the non-DP cases while delivering robust privacy guarantees. With the help of real-world datasets, we show the reliability of our DP-detection outcomes for a wide variety of attack scenarios for interdependent stakeholders.
title Differential Privacy for Regulatory Compliance in Cyberattack Detection on Critical Infrastructure Systems
topic Cryptography and Security
url https://arxiv.org/abs/2508.08190