A Bilevel Optimization Framework for Adversarial Control of Gas Pipeline Operations

TL;DR

Proposes a bi-level optimization framework combining hydraulic modeling, state estimation, and stealthy FDI attacks to analyze cyber-physical threats in gas pipelines.

eess.SY 🔴 Advanced 2025-10-03 68 views
Tejaswini Sanjay Katale Lu Gao Yunpeng Zhang Alaa Senouci
cybersecurity pipeline control bi-level optimization physics-based modeling attack detection

Key Findings

Methodology

This study develops a comprehensive framework integrating pipeline hydraulic dynamics, SCADA-based state estimation via extended Kalman filter (EKF), model predictive control (MPC), and a bi-level attack optimization modeled through Karush-Kuhn-Tucker (KKT) conditions. The pipeline network is represented as a directed graph with nodal pressure evolution equations and Weymouth-type flow relations, including control devices like valves and compressors. The attacker formulates a stealthy false-data injection (FDI) attack as an upper-level optimization, perturbing sensor data to degrade throughput while evading bad-data detection. The attack is optimized via a mixed-integer quadratic program (MIQP) derived from KKT reformulation, enabling efficient solution. Simulations demonstrate that such attacks can reduce throughput by over 15% with minimal instantaneous deviations, highlighting vulnerabilities.

Key Results

  • The optimized stealth attack achieves over 15% throughput reduction in simulated pipeline networks, with perturbations below 1%, remaining undetected by standard bad-data detectors.
  • Attack duration exceeds 24 hours, causing sustained service degradation, validated across various load scenarios and device constraints.
  • Sensitivity analysis indicates sensor placement and device parameters significantly influence attack effectiveness, emphasizing the need for integrated detection and control strategies.

Significance

This work bridges the gap between hydraulic modeling and cyber-physical security analysis, providing a novel simulation platform for assessing pipeline resilience. It reveals systemic vulnerabilities to covert attacks, guiding the development of robust detection and mitigation mechanisms. The integration of physics-based models with bi-level optimization offers a powerful tool for both researchers and operators to evaluate and enhance infrastructure security, addressing a critical need in modern energy systems. The framework’s ability to simulate attack propagation and system response advances the state-of-the-art in cyber-physical security assessment.

Technical Contribution

The primary technical innovation lies in coupling nonlinear hydraulic dynamics with a bi-level attack optimization solved via KKT conditions, transforming a complex problem into a tractable MIQP. This approach enables efficient computation of stealthy attack strategies that maximize impact while remaining undetectable. The framework also incorporates state estimation via EKF and MPC-based control, creating a closed-loop simulation environment. This integration allows for detailed analysis of attack effects on operational performance, providing a foundation for designing resilient control schemes and detection algorithms. The methodology advances existing techniques by handling nonlinearities, device constraints, and attack stealthiness simultaneously.

Novelty

This research is the first to formulate a comprehensive, physics-informed bi-level optimization model for stealthy cyberattacks on gas pipeline networks that includes hydraulic dynamics, state estimation, and control interactions. Unlike prior works focusing solely on detection or isolated attack models, this approach captures the full system response, enabling realistic simulation of covert disruptions. The use of KKT reformulation to solve the attack optimization efficiently is a key novelty, facilitating large-scale, real-time applicable analysis. It significantly extends the understanding of vulnerabilities in cyber-physical pipeline systems.

Limitations

  • The model assumes static device parameters and demand profiles, which may not reflect real-time environmental fluctuations, potentially affecting attack effectiveness.
  • MIQP solving complexity limits scalability for very large networks or real-time deployment without further optimization.
  • The current framework considers a single attacker and does not explore multi-agent or adaptive attack strategies, which could pose additional risks.

Future Work

Future research will focus on integrating machine learning techniques for adaptive attack and defense strategies, developing real-time anomaly detection algorithms, and extending the framework to multi-agent attack scenarios. Additionally, efforts will be made to improve computational efficiency for large-scale networks and incorporate dynamic demand and device parameter variations. The ultimate goal is to create a comprehensive, real-time cyber-physical security platform capable of proactive threat mitigation and system resilience enhancement.

AI Executive Summary

As energy infrastructure becomes increasingly digitalized, gas pipeline networks face mounting cyber-physical threats. Traditional detection methods struggle against stealthy false-data injection (FDI) attacks that subtly degrade system performance without triggering alarms. This research introduces a novel bi-level optimization framework that models the entire pipeline control loop, from hydraulic dynamics to attack strategies, providing a powerful tool for vulnerability assessment.

The core of the approach combines physics-based modeling of pipeline hydraulics with advanced state estimation via extended Kalman filters (EKF) and model predictive control (MPC). The attack model formulates a stealthy FDI as an upper-level optimization problem, designed to maximize throughput loss while evading bad-data detectors. This problem is efficiently solved through a KKT-based reformulation into a mixed-integer quadratic program (MIQP), enabling practical application.

Simulation results demonstrate that attackers can reduce throughput by over 15% with perturbations less than 1%, lasting over 24 hours without detection. These findings expose critical vulnerabilities in current pipeline control systems, emphasizing the need for integrated detection and resilient control strategies. The framework’s flexibility allows for scenario analysis under various load and device constraints, guiding the development of more robust defenses.

Overall, this work advances the understanding of cyber-physical security in energy systems, providing a scalable, physics-informed platform for resilience testing. It underscores the importance of holistic approaches combining hydraulic modeling, optimization, and cybersecurity to safeguard vital infrastructure against covert threats. Future directions include real-time adaptive defense mechanisms and expanding the model to multi-agent attack scenarios, aiming to elevate the security posture of critical energy networks.

Deep Dive

⚠️

Limitations & Outlook

What gaps remain?

The framework assumes static device parameters and demand profiles, which may not fully capture environmental variability. The MIQP solution process, while efficient, may face scalability issues for very large networks or real-time applications. Additionally, the current model considers a single attacker scenario, lacking exploration of multi-agent or adaptive attack strategies, which could present more complex threats in practice.

Abstract

Cyberattacks on pipeline operational technology systems pose growing risks to energy infrastructure. This study develops a physics-informed simulation and optimization framework for analyzing cyber-physical threats in petroleum pipeline networks. The model integrates networked hydraulic dynamics, SCADA-based state estimation, model predictive control (MPC), and a bi-level formulation for stealthy false-data injection (FDI) attacks. Pipeline flow and pressure dynamics are modeled on a directed graph using nodal pressure evolution and edge-based Weymouth-type relations, including control-aware equipment such as valves and compressors. An extended Kalman filter estimates the full network state from partial SCADA telemetry. The controller computes pressure-safe control inputs via MPC under actuator constraints and forecasted demands. Adversarial manipulation is formalized as a bi-level optimization problem where an attacker perturbs sensor data to degrade throughput while remaining undetected by bad-data detectors. This attack-control interaction is solved via Karush-Kuhn-Tucker (KKT) reformulation, which results in a tractable mixed-integer quadratic program. Test gas pipeline case studies demonstrate the covert reduction of service delivery under attack. Results show that undetectable attacks can cause sustained throughput loss with minimal instantaneous deviation. This reveals the need for integrated detection and control strategies in cyber-physical infrastructure.

eess.SY cs.CR