Artículo: Distinguishing Cyber-Attacks from Physical Faults in Water Systems Using Counterfactual Reasoning
Archivos
Fecha
Editor
Publicado en
Licencia Creative Commons
Resumen
A critical challenge in Water Cyber-Physical Systems (CPS) is the ambiguity between mechanical failures (e.g., pump efficiency degradation) and cyber-attacks (e.g., command spoofing). Standard anomaly detection models, such as Auto-encoders, classify both events merely as anomalies without identifying the root cause. This paper presents a root cause analysis method utilizing Structural Causal Models (SCM). By computing the counterfactual trajectory of the system, we evaluate the causal consistency of sensor residuals. This mathematical approach structurally separates physical faults (which propagate causally) from cyber-manipulations (which isolate physically). We apply this logic to the BATADAL dataset to demonstrate the distinguishability of attack vectors.


