H-CLAIR: Physical Safety Under a Compromised Automation Plane

Published:

  • Shows that detector-gated automation can catch faults, avoid false alarms, defer on almost every attacked sample, and still drive water tanks out of their safe range.
  • Moves the safety decision to actuation time: a small shield mediates the only path to the actuator and treats every request from the detector, learned controller, and fallback as untrusted.
  • Maintains the set of plant states consistent with authenticated sensor records and the commands actually executed, and admits a command only if every reachable successor stays in a certified safe region.
  • Proves invariant preservation against arbitrary adaptive requests, and derives an assurance horizon that marks when stale trusted state can no longer guarantee a safe command.
  • Evaluated over Modbus/TCP, on a held-out nonlinear plant, on SWaT/WADI adaptive evasion, and in closed-loop BATADAL C-Town hydraulics.

Read the full project write-up

Direct Link