XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge in cross-domain threat reuse for industrial control systems, where semantic similarity does not guarantee physically verifiable structures. To resolve this, it proposes a provenance-aware and target-conditioned approach that decouples source-domain abstraction from deterministic grounding. The work introduces a novel multi-layered evidence framework that explicitly distinguishes among grounding acceptance, slice sufficiency, and dynamic realizability. Furthermore, machine-verifiable target contracts, role/type compatibility checks, and phase consistency analysis techniques are incorporated to ensure mapping feasibility. Evaluation across 83 water and chemical treatment scenarios demonstrates that integrating provenance semantics with rigorous grounding criteria effectively enables structured and verifiable cross-domain security transfer.
📝 Abstract
Industrial control system (ICS) threats documented for one plant can express cyber-physical effects relevant to another, but semantic similarity alone does not establish whether those effects are structurally admissible or evaluable on a target. We present XPhysICS, a provenance-aware, target-conditioned method that separates analyst-guided source abstraction from deterministic grounding into target-specific validation slices. Given a fixed source abstraction, vocabulary and schema, and machine-validated target contract, XPhysICS evaluates candidate mappings using five eligibility criteria: role compatibility, implemented type compatibility, stage coherence, slice viability, and rule-surface applicability. Grounding acceptance, slice adequacy, dynamic realizability, consumer applicability, and consumer outcome remain distinct evidence layers. We evaluate 83 structured source-threat abstractions across water treatment, water distribution, hydro/water-energy, and chemical-process targets. Controlled target-side studies of SWaT-to-water-treatment and WADI-to-water-distribution groundings produce clean, nominal-confounded, and near-threshold consumer outcomes; nine Hydro/GRFICS cases extend bounded validation-slice execution. We also evaluate bounded predictive, state-aware, and phase-aware consumer lanes, the unmodified upstream GeCo implementation, and a paper-derived reproduction of a physics-guided search method over three frozen groundings. Results show that cross-domain ICS threat reuse requires traceable source semantics, explicit target-conditioned grounding criteria, and careful separation of subsequent target-side evidence.
Problem

Research questions and friction points this paper is trying to address.

Industrial Control Systems
Cross-Physical-Domain
Threat Grounding
Cyber-Physical Security
Threat Reuse
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cross-Physical-Domain Threat Grounding
Industrial Control Systems Security
Provenance-Aware Abstraction
Target-Conditioned Validation Slices
Threat Reuse