Detection of attacks and faults
How can we recognise when the data used by a sequential system has been manipulated or when the system is behaving abnormally? My work includes detection of delay-injection attacks, where observations or feedback are deliberately delayed, as well as related problems such as replay attacks. I use methods from statistical signal processing and control, including Interacting Multiple Model (IMM) filtering, to detect attacks while keeping false alarms low. My research considers both how detection methods can be improved, how their presence affects the system, and how they should be evaluated.