{"title":"关于保护关键基础设施的调查:攻击、人工智能安全和未来方向","authors":"Khushi Jatinkumar Raval , Nilesh Kumar Jadav , Tejal Rathod , Sudeep Tanwar , Vrince Vimal , Nagendar Yamsani","doi":"10.1016/j.ijcip.2023.100647","DOIUrl":null,"url":null,"abstract":"<div><p><span><span>Technologies such as artificial intelligence<span><span> (AI), blockchain, and the </span>Internet of Things (IoT) have converged in driving the next wave of digital revolution. Amalgamating the aforementioned advancements with critical infrastructure (CI) can significantly help society by offering a quality of life and boosting the nation’s economy and productivity. However, the lack of cybersecurity in CI gave rise to advanced threats and vulnerabilities that hindered the aforementioned societal benefits. In this vein, the paper provides an in-depth analysis of cyber threats and risks associated with different critical infrastructures, such as the financial, agriculture, energy, and </span></span>healthcare sectors. Further, we thoroughly investigate the staggering benefits of AI and, based on it, present an exhaustive solution taxonomy to showcase the competency of AI mechanisms in confronting cyberattacks on CI. The taxonomy specifically addresses issues like data privacy, algorithmic bias, and human-AI collaboration for CI. Further, we proposed an AI-based secure data exchange framework for smart grid CI, where we attempt to secure the sensor’s data (i.e., </span>power consumption<span>, energy readings, and network data) from malicious adversaries<span>. The proposed framework is evaluated using statistical measures, such as accuracy, training time, and receiver operating characteristic (ROC) curve, and anomaly detection. Further, the paper examines the research challenges that still adhere to the critical systems and require stringent AI-based mechanisms to tackle them.</span></span></p></div>","PeriodicalId":49057,"journal":{"name":"International Journal of Critical Infrastructure Protection","volume":"44 ","pages":"Article 100647"},"PeriodicalIF":4.1000,"publicationDate":"2023-12-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A survey on safeguarding critical infrastructures: Attacks, AI security, and future directions\",\"authors\":\"Khushi Jatinkumar Raval , Nilesh Kumar Jadav , Tejal Rathod , Sudeep Tanwar , Vrince Vimal , Nagendar Yamsani\",\"doi\":\"10.1016/j.ijcip.2023.100647\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p><span><span>Technologies such as artificial intelligence<span><span> (AI), blockchain, and the </span>Internet of Things (IoT) have converged in driving the next wave of digital revolution. Amalgamating the aforementioned advancements with critical infrastructure (CI) can significantly help society by offering a quality of life and boosting the nation’s economy and productivity. However, the lack of cybersecurity in CI gave rise to advanced threats and vulnerabilities that hindered the aforementioned societal benefits. In this vein, the paper provides an in-depth analysis of cyber threats and risks associated with different critical infrastructures, such as the financial, agriculture, energy, and </span></span>healthcare sectors. Further, we thoroughly investigate the staggering benefits of AI and, based on it, present an exhaustive solution taxonomy to showcase the competency of AI mechanisms in confronting cyberattacks on CI. The taxonomy specifically addresses issues like data privacy, algorithmic bias, and human-AI collaboration for CI. Further, we proposed an AI-based secure data exchange framework for smart grid CI, where we attempt to secure the sensor’s data (i.e., </span>power consumption<span>, energy readings, and network data) from malicious adversaries<span>. The proposed framework is evaluated using statistical measures, such as accuracy, training time, and receiver operating characteristic (ROC) curve, and anomaly detection. Further, the paper examines the research challenges that still adhere to the critical systems and require stringent AI-based mechanisms to tackle them.</span></span></p></div>\",\"PeriodicalId\":49057,\"journal\":{\"name\":\"International Journal of Critical Infrastructure Protection\",\"volume\":\"44 \",\"pages\":\"Article 100647\"},\"PeriodicalIF\":4.1000,\"publicationDate\":\"2023-12-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Critical Infrastructure Protection\",\"FirstCategoryId\":\"5\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S1874548223000604\",\"RegionNum\":3,\"RegionCategory\":\"工程技术\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Critical Infrastructure Protection","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1874548223000604","RegionNum":3,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
摘要
人工智能(AI)、区块链和物联网(IoT)等技术已汇聚在一起,推动下一波数字革命。将上述先进技术与关键基础设施(CI)相结合,可以极大地帮助社会提高生活质量,促进国家经济和生产力的发展。然而,由于 CI 缺乏网络安全,导致高级威胁和漏洞的出现,阻碍了上述社会效益的实现。为此,本文深入分析了与金融、农业、能源和医疗保健等不同关键基础设施相关的网络威胁和风险。此外,我们还深入研究了人工智能的惊人优势,并在此基础上提出了详尽的解决方案分类法,以展示人工智能机制在应对对 CI 的网络攻击方面的能力。该分类法特别解决了诸如数据隐私、算法偏差和人类与人工智能在 CI 方面的协作等问题。此外,我们还为智能电网 CI 提出了一个基于人工智能的安全数据交换框架,试图确保传感器数据(即功耗、能量读数和网络数据)免受恶意对手的攻击。本文通过准确度、训练时间、接收器工作特性曲线(ROC)和异常检测等统计指标对所提出的框架进行了评估。此外,本文还探讨了关键系统仍然面临的研究挑战,这些挑战需要基于人工智能的严格机制来应对。
A survey on safeguarding critical infrastructures: Attacks, AI security, and future directions
Technologies such as artificial intelligence (AI), blockchain, and the Internet of Things (IoT) have converged in driving the next wave of digital revolution. Amalgamating the aforementioned advancements with critical infrastructure (CI) can significantly help society by offering a quality of life and boosting the nation’s economy and productivity. However, the lack of cybersecurity in CI gave rise to advanced threats and vulnerabilities that hindered the aforementioned societal benefits. In this vein, the paper provides an in-depth analysis of cyber threats and risks associated with different critical infrastructures, such as the financial, agriculture, energy, and healthcare sectors. Further, we thoroughly investigate the staggering benefits of AI and, based on it, present an exhaustive solution taxonomy to showcase the competency of AI mechanisms in confronting cyberattacks on CI. The taxonomy specifically addresses issues like data privacy, algorithmic bias, and human-AI collaboration for CI. Further, we proposed an AI-based secure data exchange framework for smart grid CI, where we attempt to secure the sensor’s data (i.e., power consumption, energy readings, and network data) from malicious adversaries. The proposed framework is evaluated using statistical measures, such as accuracy, training time, and receiver operating characteristic (ROC) curve, and anomaly detection. Further, the paper examines the research challenges that still adhere to the critical systems and require stringent AI-based mechanisms to tackle them.
期刊介绍:
The International Journal of Critical Infrastructure Protection (IJCIP) was launched in 2008, with the primary aim of publishing scholarly papers of the highest quality in all areas of critical infrastructure protection. Of particular interest are articles that weave science, technology, law and policy to craft sophisticated yet practical solutions for securing assets in the various critical infrastructure sectors. These critical infrastructure sectors include: information technology, telecommunications, energy, banking and finance, transportation systems, chemicals, critical manufacturing, agriculture and food, defense industrial base, public health and health care, national monuments and icons, drinking water and water treatment systems, commercial facilities, dams, emergency services, nuclear reactors, materials and waste, postal and shipping, and government facilities. Protecting and ensuring the continuity of operation of critical infrastructure assets are vital to national security, public health and safety, economic vitality, and societal wellbeing.
The scope of the journal includes, but is not limited to:
1. Analysis of security challenges that are unique or common to the various infrastructure sectors.
2. Identification of core security principles and techniques that can be applied to critical infrastructure protection.
3. Elucidation of the dependencies and interdependencies existing between infrastructure sectors and techniques for mitigating the devastating effects of cascading failures.
4. Creation of sophisticated, yet practical, solutions, for critical infrastructure protection that involve mathematical, scientific and engineering techniques, economic and social science methods, and/or legal and public policy constructs.