Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity

📅 2026-07-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses a critical gap in existing cybersecurity frameworks for critical infrastructure, which predominantly emphasize post-disruption recovery while lacking empirical theory on achieving limited improvements during disturbances. The work proposes the first Antifragility Theory (AFT) tailored to operational technology (OT) environments, integrating a five-state resilience system model with a mathematically rigorous definition of Jensen gain. Validation is conducted using a subset of the CISSM incident database and the HAI hardware-in-the-loop experimental platform. The research establishes two necessary conditions for antifragility verification: heterogeneous vulnerability burdens and process-level disturbance observability. Empirical findings reveal that OT systems are particularly susceptible to disruptive attacks, yet exhibit significantly reduced process-state deviations in subsequent observation windows following such attacks, indicating a measurable adaptive response inherent to the system.
📝 Abstract
Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant subset of the CISSM Cyber Events Database with the HAI hardware-in-the-loop industrial control dataset and tests three confirmatory hypotheses and one exploratory proposition. OT-adjacent sectors show significantly higher shares of disruptive or mixed events than comparison sectors (65.3 percent versus 46.8 percent, p less than 0.001), together with a greater concentration of physical-attack and data-attack subtypes. In HAI, attack-labeled observations were 7.43 times more likely than normal observations to exceed the 95th percentile of baseline deviation (p less than 0.001). Across successive attack windows, mean process-state deviation declined significantly (Spearman rho = -0.688, p = 0.007), indicating measurable response variation rather than proof of adaptive gain. Together, the findings establish two prerequisites for future antifragility testing: differentiated fragility burden and process-level perturbation observability.
Problem

Research questions and friction points this paper is trying to address.

antifragility
critical infrastructure
cybersecurity
operational technology
resilience
Innovation

Methods, ideas, or system contributions that make the work stand out.

Antifragility
Resilient System Model
Jensen gain
Operational Technology (OT)
Hardware-in-the-loop
🔎 Similar Papers
No similar papers found.