Security and trustworthiness challenges in cyber-physical-human systems
摘要
Cyber-physical-human systems (CPHS) integrate human inputs, behaviors, and interfaces for a more effective utilization of artificial intelligence (AI) assisted cyber and physical systems. However, the growing reliance on Agentic AI, coupled with the inherent variability of human actions, can introduce unforeseen security challenges. Studies have reported that any security compromise can result in catastrophic failures, safety hazards, and data breaches, disrupting the day-to-day operations of CPHS. Given the scale and complexity of typical CPHS, robust security measures are essential. This paper investigates the security requirements of CPHS encompassing confidentiality, integrity, availability, authentication, and authorization, in the context of CPHS. We also emphasize the role of formal verification methods to establish and guarantee the trustworthiness of agents, which are increasingly integral to these systems. Considering the inherent mutual dependency, we systematically categorize and analyze attack vectors across three dimensions: data, agents, and human actors that can impact the security and trustworthiness of CPHS. Using unmanned aerial vehicles (UAVs) in the defense sector as a prototypical CPHS engineering application, we present a typical mission scenario involving a remotely piloted Medium-Altitude, Long-Endurance (MALE) aircraft designed for Intelligence, Surveillance, Target Acquisition, and Reconnaissance (ISTAR) to conduct threat assessments. Our comprehensive analysis illustrates how these attack vectors can compromise each dimension, providing actionable insights for security engineers and system architects to design robust security measures in CPHS.