Papers
Journal and conference papers, a book chapter, reports and a patent, mostly on cyber-physical security for critical infrastructure (and robotics and AI, very soon).
Journal articles
-
Assessing the Effectiveness of PCAT in Avoiding Process Anomalies in Water Treatment Plants
IEEE Transactions on Industrial Informatics, 2025
PCAT validates the commands a PLC sends, so rogue or mistaken commands get caught before they reach an actuator. This paper measures how early it catches command anomalies in a water treatment plant, and how it avoids disruptions and false positives, on the SWaT testbed.
doibibtex
@article{raman2025pcat, title = {{Assessing the Effectiveness of PCAT in Avoiding Process Anomalies in Water Treatment Plants}}, author = {{Gauthama Raman M R} and Siddhant Shrivastava and {Aditya P. Mathur}}, journal = {IEEE Transactions on Industrial Informatics}, year = {2025}, doi = {10.1109/TII.2025.3585159}, url = {https://ieeexplore.ieee.org/abstract/document/11141556/} } -
Design and Assessment of an Orthogonal Defense Mechanism for a Water Treatment Facility
Robotics and Autonomous Systems, 2018
A cyber-physical defence method for water treatment plants, designed and assessed on a real testbed, with a case for why it applies to public infrastructure in general.
doibibtex
@article{shrivastava2018orthogonal, title = {{Design and Assessment of an Orthogonal Defense Mechanism for a Water Treatment Facility}}, author = {Siddhant Shrivastava and Sridhar Adepu and Aditya Mathur}, journal = {Robotics and Autonomous Systems}, year = {2018}, doi = {10.1016/j.robot.2017.12.005}, url = {https://doi.org/10.1016/j.robot.2017.12.005} } -
IEEE Internet Computing, 2016
Argus, named after the hundred-eyed watchman: a defence framework for public infrastructure facing cyber-physical attacks. Results on a real testbed show attacks getting detected early.
doibibtex
@article{adepu2016argus, title = {{Argus: An Orthogonal Defense Framework to Protect Public Infrastructure against Cyber-Physical Attacks}}, author = {Sridhar Adepu and Siddhant Shrivastava and Aditya Mathur}, journal = {IEEE Internet Computing}, year = {2016}, doi = {10.1109/MIC.2016.104}, url = {https://ieeexplore.ieee.org/abstract/document/7676148/} }
Conference papers
-
Extended Reality for Enhanced Learning beyond the Classroom: Three Pandemic-Proof Prototypes
ICON-BITS Conference (SSRN), 2022
Three XR prototypes for teaching and training when nobody can come to the lab, tried out in university and industry courses on cyber-physical security.
doibibtex
@inproceedings{shrivastava2022xr, title = {{Extended Reality for Enhanced Learning beyond the Classroom: Three Pandemic-Proof Prototypes}}, author = {Siddhant Shrivastava and Oka Kurniawan and Nachamma Sockalingam}, booktitle = {ICON-BITS Conference (SSRN)}, year = {2022}, doi = {10.2139/ssrn.4026964}, url = {https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4026964} } -
The Design of Cyber-Physical Exercises (CPXs)
14th International Conference on Cyber Conflict (CyCon), NATO CCDCOE, 2022
What we learned from running international cyber-physical exercises on live testbeds: objectives, red and blue team tactics, scoring, and how to design an exercise that teaches something.
doibibtex
@inproceedings{shrivastava2022cpx, title = {{The Design of Cyber-Physical Exercises (CPXs)}}, author = {Siddhant Shrivastava and Francisco Furtado and Mark Goh and Aditya Mathur}, booktitle = {14th International Conference on Cyber Conflict (CyCon), NATO CCDCOE}, year = {2022}, doi = {10.23919/CyCon55549.2022.9811000}, url = {https://ieeexplore.ieee.org/abstract/document/9811000/} } -
PCAT: PLC Command Analysis Tool for Automatic Incidence Response in Water Treatment Plants
IEEE International Conference on Big Data, 2021
The first PCAT paper. It validates PLC commands in real time and stops rogue instructions before they reach plant actuators, tested on the SWaT water treatment plant.
doibibtex
@inproceedings{shrivastava2021pcat, title = {{PCAT: PLC Command Analysis Tool for Automatic Incidence Response in Water Treatment Plants}}, author = {Siddhant Shrivastava and {Gauthama Raman M R} and Aditya Mathur}, booktitle = {IEEE International Conference on Big Data}, year = {2021}, doi = {10.1109/BigData52589.2021.9671615}, url = {https://ieeexplore.ieee.org/abstract/document/9671615/} } -
Super Detector: An Ensemble Approach for Anomaly Detection in Industrial Control Systems
Critical Information Infrastructures Security (CRITIS), LNCS, Springer, 2021 Young CRITIS Award (best young researcher paper)
Fuses several anomaly detectors, each fed by different sources, into one ensemble prediction for industrial control systems.
doibibtex
@inproceedings{balaji2021superdetector, title = {{Super Detector: An Ensemble Approach for Anomaly Detection in Industrial Control Systems}}, author = {Madhumitha Balaji and Siddhant Shrivastava and Sridhar Adepu and Aditya Mathur}, booktitle = {Critical Information Infrastructures Security (CRITIS), LNCS, Springer}, year = {2021}, doi = {10.1007/978-3-030-93200-8_2}, url = {https://link.springer.com/chapter/10.1007/978-3-030-93200-8_2} }
Book chapters
-
Next Generation Cyber-Physical Architecture and Training
Cyberdefense: The Next Generation (International Series in Operations Research & Management Science), Springer, 2023
Argues for mixed reality, zero trust and security-by-design in the next generation of cyber-physical defences, and looks at how each would hold up in industrial control settings.
doibibtex
@incollection{shrivastava2023nextgen, title = {{Next Generation Cyber-Physical Architecture and Training}}, author = {Siddhant Shrivastava and {Aditya P. Mathur}}, booktitle = {Cyberdefense: The Next Generation (International Series in Operations Research & Management Science), Springer}, year = {2023}, doi = {10.1007/978-3-031-30191-9_13}, url = {https://link.springer.com/chapter/10.1007/978-3-031-30191-9_13} }
Preprints and reports
-
NFTs for Art and Collectables: Primer and Outlook
SocArXiv (IC3, Cornell University), 2022
A primer on blockchains, smart contracts and NFTs for artists and collectors, and what the technology changes about how creators get paid.
doipdfbibtex
@misc{allen2022nft, title = {{NFTs for Art and Collectables: Primer and Outlook}}, author = {Sarah Allen and Ari Juels and Mukti Khaire and Tyler Kell and Siddhant Shrivastava}, howpublished = {SocArXiv (IC3, Cornell University)}, year = {2022}, doi = {10.31235/osf.io/gwzd7}, url = {https://doi.org/10.31235/osf.io/gwzd7} } -
BlackEnergy: Malware for Cyber-Physical Attacks
iTrust Technical Report, Singapore University of Technology and Design, 2016
A walk through BlackEnergy, the malware family behind the 2015 attack on Ukraine's power grid, written for (and well received by) the Ministry of Defence, Singapore.
bibtex
@techreport{shrivastava2016blackenergy, title = {{BlackEnergy: Malware for Cyber-Physical Attacks}}, author = {Siddhant Shrivastava}, institution = {iTrust Technical Report, Singapore University of Technology and Design}, year = {2016}, url = {https://itrust.sutd.edu.sg/research/reports/} }
Patents
-
Defense System and Method against Cyber-Physical Attacks
US Patent US11431733B2 (filed 2017, granted 2022), Singapore University of Technology and Design, 2022
Sensors, controllers and independent verification devices that together defend a utility against cyber-physical attacks and process anomalies.
bibtex
@misc{mathur2022patent, title = {{Defense System and Method against Cyber-Physical Attacks}}, author = {Aditya Mathur and Sridhar Adepu and Siddhant Shrivastava and {Myat Aung Kaung} and Nils Tippenhauer and Giedre Sabaliauskaite}, howpublished = {US Patent US11431733B2 (filed 2017, granted 2022), Singapore University of Technology and Design}, year = {2022}, url = {https://patents.google.com/patent/US11431733B2/en} }