André Teixeira 0001

dblp:01/8773 · also André M. H. Teixeira · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0001-5491-4068ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 since 2021Systems, architecture and hardware · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Kullback-Leibler Divergence-Based Observer Design Against Sensor Bias Injection Attacks in Single-Output Systems
abstract
This paper considers observer-based detection of sensor bias injection attacks (BIAs) on linear cyber-physical systems with single output driven by white Gaussian noise. Despite their simplicity, BIAs pose a severe risk to systems with integrators, which we refer to as integrator vulnerability. Specifically, the residual generated by any linear observer is indistinguishable under attack and normal operation at steady state, making BIAs detectable only during transients. To address this, we propose a principled method based on Kullback-Leibler divergence to design a residual generator that significantly increases the signal-to-noise ratio against BIAs. For systems without integrator vulnerability, our method also enables a trade-off between transient and steady-state detectability. The effectiveness of the proposed method is demonstrated through numerical comparisons with three state-of-the-art residual generators.
Fatih Emre Tosun, André Teixeira 0001, Jingwei Dong, Anders Ahlén, Subhrakanti Dey
IEEE Trans. Inf. Forensics Secur.2
2024 GNN-IDS: Graph Neural Network based Intrusion Detection System
abstract
Intrusion detection systems (IDSs) are widely used to identify anomalies in computer networks and raise alarms on intrusive behaviors. ML-based IDSs generally take network traces or host logs as input to extract patterns from individual samples, whereas the inter-dependencies of network are often not captured and learned, which may result in large amounts of uncertain predictions, false positives, and false negatives. To tackle the challenges in intrusion detection, we propose a graph neural network-based intrusion detection system (GNN-IDS), which is data-driven and machine learning-empowered. In our proposed GNN-IDS, the attack graph and real-time measurements that represent static and dynamic attributes of computer networks, respectively, are incorporated and associated to represent complex computer networks. Graph neural networks are employed as the inference engine for intrusion detection. By learning network connectivity, graph neural networks can quantify the importance of neighboring nodes and node features to make more reliable predictions. Furthermore, by incorporating an attack graph, GNN-IDS could not only detect anomalies but also identify the malicious actions causing the anomalies. The experimental results on a use case network with two synthetic datasets (one generated from public IDS data) show that the proposed GNN-IDS achieves good performance. The results are analyzed from the aspects of uncertainty, explainability, and robustness.
Zhenlu Sun, André Teixeira 0001, Salman Zubair Toor
ARES2
2024 Centrality-Based Security Allocation in Networked Control Systems
Anh Tung Nguyen, Andreas Hertzberg, André Teixeira 0001
CRITIS3
2023 Probability elicitation for Bayesian networks to distinguish between intentional attacks and accidental technical failures
abstract
Both intentional attacks and accidental technical failures can lead to abnormal behaviour in components of industrial control systems. In our previous work, we developed a framework for constructing Bayesian Network (BN) models to enable operators to distinguish between those two classes, including knowledge elicitation to construct the directed acyclic graph of BN models. In this paper, we add a systematic method for knowledge elicitation to construct the Conditional Probability Tables (CPTs) of BN models, thereby completing a holistic framework to distinguish between attacks and technical failures. In order to elicit reliable probabilities from experts, we need to reduce the workload of experts in probability elicitation by reducing the number of conditional probabilities to elicit and facilitating individual probability entry. We utilise DeMorgan models to reduce the number of conditional probabilities to elicit as they are suitable for modelling opposing influences i.e., combinations of influences that promote and inhibit the child event. To facilitate individual probability entry, we use probability scales with numerical and verbal anchors. We demonstrate the proposed approach using an example from the water management domain.
Sabarathinam Chockalingam, Wolter Pieters, André Teixeira 0001, Pieter H. A. J. M. van Gelder
J. Inf. Secur. Appl.3
2021 A Game-theoretic Approach to Covert Communications in the Presence of Multiple Colluding Wardens
abstract
In this paper, we address the problem of covert communication under the presence of multiple wardens with a finite blocklength. The system consists of Alice, who aims to covertly transmit to Bob with the help of a jammer. The system also consists of a Fusion Center (FC), which combines all the wardens' information and decides on the presence or absence of Alice. Both Alice and jammer vary their signal power randomly to confuse the FC. In contrast, the FC randomly changes its threshold to confuse Alice. The main focus of the paper is to study the impact of employing multiple wardens on the trade-off between the probability of error at the FC and the outage probability at Bob. Hence, we formulate the probability of error and the outage probability under the assumption that the channels from Alice and jammer to Bob are subject to Rayleigh fading, while we assume that the channels from Alice and jammer to the wardens are not subject to fading. Then, we utilize a two-player zero-sum game approach to model the interaction between joint Alice and jammer as one player and the FC as the second player. We derive the pay-off function that can be efficiently computed using linear programming to find the optimal distributions of transmitting and jamming powers as well as thresholds used by the FC. The benefit of using a cooperative jammer is shown by means of analytical results and numerical simulations to neutralize the advantage of using multiple wardens at the FC.
Abbas Arghavani, Anders Ahlén, André Teixeira 0001, Subhrakanti Dey
WCNC3
2021 Bayesian network model to distinguish between intentional attacks and accidental technical failures: a case study of floodgates
abstract
Abstract Water management infrastructures such as floodgates are critical and increasingly operated by Industrial Control Systems (ICS). These systems are becoming more connected to the internet, either directly or through the corporate networks. This makes them vulnerable to cyber-attacks. Abnormal behaviour in floodgates operated by ICS could be caused by both (intentional) attacks and (accidental) technical failures. When operators notice abnormal behaviour, they should be able to distinguish between those two causes to take appropriate measures, because for example replacing a sensor in case of intentional incorrect sensor measurements would be ineffective and would not block corresponding the attack vector. In the previous work, we developed the attack-failure distinguisher framework for constructing Bayesian Network (BN) models to enable operators to distinguish between those two causes, including the knowledge elicitation method to construct the directed acyclic graph and conditional probability tables of BN models. As a full case study of the attack-failure distinguisher framework, this paper presents a BN model constructed to distinguish between attacks and technical failures for the problem of incorrect sensor measurements in floodgates, addressing the problem of floodgate operators. We utilised experts who associate themselves with the safety and/or security community to construct the BN model and validate the qualitative part of constructed BN model. The constructed BN model is usable in water management infrastructures to distinguish between intentional attacks and accidental technical failures in case of incorrect sensor measurements. This could help to decide on appropriate response strategies and avoid further complications in case of incorrect sensor measurements.
Sabarathinam Chockalingam, Wolter Pieters, André Teixeira 0001, Pieter H. A. J. M. van Gelder
Cybersecur.3
2020 Computer-aided curriculum analysis and design: existing challenges and open research directions
abstract
This Research-to-Practice Full Paper investigates the emerging perspectives for the 21st engineering curriculum, and discusses the crucial role that digital technologies will have in facilitating the management, evaluation, and development of such a curriculum. First, a vision for future engineering curricula is distilled from modern curricular perspectives and trends of future engineering professions, where the integration of non-cognitive competences and the increased individualization of study paths are central. Core requirements for future curricula are outlined, which pose significant barriers to curricular changes. Then, the role of technology in mitigating these barriers is discussed, by outlining key aspects of a data-driven digital approach to the management of future curricula. To illustrate the proposed approach, the paper presents a case example of a digital tool that analyzes curriculum coherency at the content level. The paper concludes with a discussion of future research directions regarding the conceptualization and management of future engineering curricula through digital technologies.
André Teixeira 0001, Aida O. P. D. C. Guerra, Steffi Knorn, Kjell Staffas, Damiano Varagnolo
FIE1
2017 Data attacks on power system state estimation: Limited adversarial knowledge vs. limited attack resources
abstract
It has shown that with perfect knowledge of the system model and the capability to manipulate a certain number of measurements, the false data injection (FDI) attacks, as a class of data integrity attacks, can coordinate measurements corruption to keep stealth against the bad data detection schemes. However, a more realistic attack is essentially an attack with limited adversarial knowledge of the system model and limited attack resources due to various reasons. In this paper, we generalize the data attacks that they can be pure FDI attacks or combined with availability attacks (e.g., DoS attacks) and analyze the attacks with limited adversarial knowledge or limited attack resources. The attack impact is evaluated by the proposed metrics and the detection probability of attacks is calculated using the distribution property of data with or without attacks. The analysis is supported with results from a power system use case. The results show how important the knowledge is to the attacker and which measurements are more vulnerable to attacks with limited resources.
Kaikai Pan, André Teixeira 0001, Milos Cvetkovic, Peter Palensky
IECON2
2016 Integrated Safety and Security Risk Assessment Methods: A Survey of Key Characteristics and Applications
Sabarathinam Chockalingam, Dina Hadziosmanovic, Wolter Pieters, André Teixeira 0001, Pieter H. A. J. M. van Gelder
CRITIS4
2016 Cybersecurity as a Politikum: implications of security discourses for infrastructures
abstract
In the cybersecurity community it is common to think of security as a design feature for systems and infrastructures that may be difficult to balance with other requirements. What is less studied is how security requirements come about, for which reasons, and what their influence is on the actions the system facilitates. Security is for example often used as an argument for or against granting access rights that are of importance to stakeholders, such as in the discussion on counterterrorism and privacy. This paper argues that the ongoing politicization of security issues calls for a paradigm to study cybersecurity as a Politikum: a matter of political concern, embedded in existing and future infrastructures. We summarize literature which inspired this paper and explain the role of security arguments for infrastructure governance. Then we outline the new paradigm and its core concepts and contribution, including the notion of framing. Finally, we present discourse analysis and infrastructure ethnography as research methods and discuss cases in which discourses (may) shape infrastructures, in particular smart cities.
Laura Fichtner, Wolter Pieters, André Teixeira 0001
NSPW3
2015 Voltage control for interconnected microgrids under adversarial actions
abstract
In this paper, we study the impact of adversarial actions on voltage control schemes in interconnected microgrids. Each microgrid is abstracted as a power inverter that can be controlled to regulate its voltage magnitude and phase-angle independently. Moreover, each power inverter is modeled as a single integrator, whose input is given by a voltage droop-control policy that is computed based on voltage magnitude and reactive power injection measurements. Under mild assumptions, we then establish important properties of the nominal linearized closed-loop system, such as stability, positivity, and diagonal dominance. These properties play an important role when characterizing the potential impact of different attack scenarios. In particular, we discuss two attack scenarios where the adversary corrupts measurement data and reference signals received by the voltage droop controllers. The potential impact of instances of each scenario is analyzed using control-theoretic tools, which may be used to develop methodologies for identifying high-risk attack scenarios, as is illustrated by numerical examples.
André Teixeira 0001, Kaveh Paridari, Henrik Sandberg, Karl Henrik Johansson
ETFA1
2014 Distributed Fault Detection and Isolation Resilient to Network Model Uncertainties
abstract
The ability to maintain state awareness in the face of unexpected and unmodeled errors and threats is a defining feature of a resilient control system. Therefore, in this paper, we study the problem of distributed fault detection and isolation (FDI) in large networked systems with uncertain system models. The linear networked system is composed of interconnected subsystems and may be represented as a graph. The subsystems are represented by nodes, while the edges correspond to the interconnections between subsystems. Considering faults that may occur on the interconnections and subsystems, as our first contribution, we propose a distributed scheme to jointly detect and isolate faults occurring in nodes and edges of the system. As our second contribution, we analyze the behavior of the proposed scheme under model uncertainties caused by the addition or removal of edges. Additionally, we propose a novel distributed FDI scheme based on local models and measurements that is resilient to changes outside of the local subsystem and achieves FDI. Our third contribution addresses the complexity reduction of the distributed FDI method, by characterizing the minimum amount of model information and measurements needed to achieve FDI and by reducing the number of monitoring nodes. The proposed methods can be fused to design a scalable and resilient distributed FDI architecture that achieves local FDI despite unknown changes outside the local subsystem. The proposed approach is illustrated by numerical experiments on the IEEE 118-bus power network benchmark.
André Teixeira 0001, Iman Shames, Henrik Sandberg, Karl Henrik Johansson
IEEE Trans. Cybern.1
2012 Fault Detection and Mitigation in Kirchhoff Networks
abstract
In this letter, we study the problem of fault detection and mitigation in networks where the measurements satisfy Kirchhoff's voltage law. First, we characterise the class of faults appearing as an additive fault vector (injected by a malicious adversary or due to equipment failures) that can be detected by taking into account the topology of the network. Second, we consider the problem of estimating the fault vector via tools from compressive sensing. Moreover, we comment on the applicability of the developed methods to the case where the measurements satisfy Kirchhoff's current law. The proposed methods are validated via numerical examples with application to time synchronization networks.
Iman Shames, André Teixeira 0001, Henrik Sandberg, Karl Henrik Johansson
IEEE Signal Process. Lett.2