Out of Sync, Out of Sight: Phantom State Attacks against IIoT Intrusion Detection
This study addresses the vulnerability of Industrial Internet of Things (IIoT) intrusion detection systems that rely on time-window aggregation to temporal synchronization attacks. We propose the Phantom State Attack (PSA), which injects bounded temporal drifts to push observations toward window boundaries, thereby inducing erroneous state reconstruction. Operating in a zero-query passive mode, PSA requires neither packet tampering nor model fitting, exploiting solely the vulnerabilities inherent in temporal aggregation. Analytical evaluations under both sliding and tumbling window configurations, along with empirical assessments on the ToN-IoT and CIC datasets, demonstrate that PSA significantly degrades detection rates for targeted traffic. Compared to baseline methods, the proposed attack achieves superior efficiency and stealthiness, revealing a novel attack surface for IIoT security.