arXiv ScienceSearch

arXiv · 2509.00770

Bayesian and Multi-Objective Decision Support for Incident Mitigation in Cyber-Physical Systems

Abstract

Cyber-physical systems increasingly rely on interconnected physical and digital systems whose security incidents can escalate rapidly into safety and operational failures. Existing decision-support approaches struggle to support incident response because they rely on static assumptions, incomplete vulnerability data, and single-objective risk models that do not adequately capture trade-offs between attack success likelihood, impact severity, and system availability. This paper proposes an adaptive decision-support framework for incident mitigation in cyber-physical systems that integrates hierarchical Bayesian Network modelling, confidence-calibrated exposure estimation, and multi-objective optimisation into a unified, adaptive pipeline. The framework constructs probabilistic models from system architecture and vulnerability data, incorporating complementary vulnerability scores under epistemic uncertainty as conservative, uncertainty-aware reporting metrics for supporting downstream risk assessment. Mitigation strategies are explored as countermeasure portfolios and refined using multi-objective optimisation to identify Pareto-optimal trade-offs suitable for incident response scenarios. Frequency-based heuristics are applied to prioritise mitigation actions across optimisation runs. The framework is evaluated on three representative cyber-physical attack scenarios, demonstrating its ability to adapt to evolving threats and provide actionable decision support under operational constraints, with the aim of enhancing the resilience of cyber-physical systems.

Explore related subjects

Keep this discovery

BibTeXRIS

Shaofei Huang, Christopher M. Poskitt, Lwin Khin Shar. 2026-09-01. Bayesian and Multi-Objective Decision Support for Incident Mitigation in Cyber-Physical Systems. https://arxiv.org/abs/2509.00770

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

The Security Feature Location Problem

Software security must be realized through security features such as authentication and encryption, but which features does a system implement, and where? We present security feature location: the task of relating code locations to security features, enabling developers to understand security implementations and assess whether intended security properties are enforced.

cs.CR

The Impact of Magma: A Ground-Truth Fuzzing Benchmark

Magma is an open-source and ground-truth fuzzing benchmark that enables uniform fuzzer evaluation and comparison. Magma was originally released with a research paper published at ACM SIGMETRICS 2021. This short paper explains the motivation, the design, and the impact of Magma, with a description of extensions to the original benchmark.

cs.CR

Security Science (SecSci), Basic Concepts and Mathematical Foundations

This textbook compiles the lecture notes from security courses taught at Oxford in the 2000s, at Royal Holloway in the 2010s, and currently in Hawaii. The early chapters are suitable for a first course in security. The middle chapters have been used in advanced courses. Towards the end there are also some research problems.

cs.CR