Adversarial Reinforcement Learning Applications in Cyber-Physical Systems Security

Doctoral Dissertation Defense at College of Information Sciences and Technology, Pennsylvania State University , University Park, PA (February 20, 2026)
Penn State Doctoral Dissertation Defense
Event Link

Abstract / Overview

This doctoral dissertation addresses the evolving challenges in computer and network security, establishing a comprehensive framework that integrates proactive prevention, effective detection, and adaptive mitigation strategies using adversarial reinforcement learning. To bolster cybersecurity defenses across critical cyber-physical systems, this research introduces: (1) domain-specific prevention using automated Moving Target Defense (MTD) with game-theoretic Double Oracle solvers, (2) robust anomaly detection against strategic False Data Injection (FDI) attacks in crowdsourced transportation networks using Policy Space Response Oracles, and (3) attack-resilient reinforcement learning control policies for mitigating physical process disruption in Industrial Control Systems (ICS).

Prevention of Threats using Moving Target Defense

Traditional security measures are augmented by a proactive strategy known as Moving Target Defense (MTD). MTD introduces continuous and random alterations to system configurations, making reconnaissance computationally expensive for adversaries or trapping them in exploration loops. Manual deployment of MTD configurations poses challenges, necessitating automated approaches that balance security benefits and system efficiency. The goal is to render cyber-attacks economically and logistically infeasible for adversaries.

Detection of False Data Injection in Transportation Networks

Strategic False Data Injection (FDI) attacks on navigation applications and transportation networks can lead to severe consequences, such as traffic congestion and disruption of essential services. Detecting such attacks requires automated mechanisms capable of identifying changes in traffic patterns. In the absence of public data, strategic decision-making algorithms are crucial to generating worst-case attack scenarios, informing the development of countermeasures, and enhancing detection mechanisms.

ICS Attack Mitigation Through Resilient Control

The remote control of Industrial Control Systems (ICS) provides efficiency but also widens the attack surface. Traditional responses involve resetting compromised software components, but this is not always feasible in case of critical infrastructure that needs to be highly available. Time gaps between detection and patching allow adversaries to exploit vulnerabilities, demanding automated mitigation strategies. The research concentrates on FDI attacks, particularly 0-stealthy attacks, where adversaries change sensor and actuator values to destabilize physical processes.