🤖 AI Summary
This study addresses a critical gap in existing cybersecurity frameworks for critical infrastructure, which predominantly emphasize post-disruption recovery while lacking empirical theory on achieving limited improvements during disturbances. The work proposes the first Antifragility Theory (AFT) tailored to operational technology (OT) environments, integrating a five-state resilience system model with a mathematically rigorous definition of Jensen gain. Validation is conducted using a subset of the CISSM incident database and the HAI hardware-in-the-loop experimental platform. The research establishes two necessary conditions for antifragility verification: heterogeneous vulnerability burdens and process-level disturbance observability. Empirical findings reveal that OT systems are particularly susceptible to disruptive attacks, yet exhibit significantly reduced process-state deviations in subsequent observation windows following such attacks, indicating a measurable adaptive response inherent to the system.
📝 Abstract
Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant subset of the CISSM Cyber Events Database with the HAI hardware-in-the-loop industrial control dataset and tests three confirmatory hypotheses and one exploratory proposition. OT-adjacent sectors show significantly higher shares of disruptive or mixed events than comparison sectors (65.3 percent versus 46.8 percent, p less than 0.001), together with a greater concentration of physical-attack and data-attack subtypes. In HAI, attack-labeled observations were 7.43 times more likely than normal observations to exceed the 95th percentile of baseline deviation (p less than 0.001). Across successive attack windows, mean process-state deviation declined significantly (Spearman rho = -0.688, p = 0.007), indicating measurable response variation rather than proof of adaptive gain. Together, the findings establish two prerequisites for future antifragility testing: differentiated fragility burden and process-level perturbation observability.