Hostile hackers and rogue states could disrupt networks of self-driving vehicles or the national power grid by attacking their most isolated, least-connected components, turning the system’s smallest links into gateways to catastrophic failure.
The study, titled “Extreme vulnerability to intruder attacks destabilizes network dynamics,” found that what the researchers did not expect lurks within interconnected systems. Instead of focusing on the most connected parts of a network, attackers may be able to cause serious disruption by targeting agents with the fewest incoming connections.
Francesco Sorrentino, a professor of mechanical engineering at UNM, and Amirhossein Nazerian, who recently earned his Ph.D. from the university, led the research published in Nature Communications.
Other researchers involved in the study included Sahand Tangerami of K. N. Toosi University of Technology, Malbor Asllani of Florida State University, David Phillips of UNM, and Hernán Makse of the City College of New York.
Weakness hiding at the edge of the network
Cyber-physical systems, which are everywhere, are complex networks in which software communicates with physical components, such as sensors, hardware, and actuators, to monitor and control real-world processes.
Take the case of autonomous vehicles, where each of them relies on software and hardware and exchanges information with other vehicles to coordinate movement, avoid collisions, and travel safely.
Similarly, power grids are another enormous and complex example.
Until now, researchers have largely assumed the biggest threat would come from attacks on the network’s hubs through which vast amounts of information flow. But Sorrentino and his colleagues discovered that the weakest links lie in the least-connected agents.
The research examined what scientists call ‘intruder attacks,’ in which a physical component remains intact but its cyber component has been compromised. Approaching from the attacker’s perspective, the researchers wanted to determine how quickly a network could become unstable if just one of its agents were compromised.
Using mathematical models, they discovered that agents receiving fewer incoming connections have fewer reliable information sources. That translated to fewer signals being available to counteract or overwhelm malicious information.
In other words, a poorly connected part of the network may be less able to recognize when something has gone wrong. And that could make it an unexpectedly attractive target.
How about the power grid?
The researchers used power grids as one of their key examples.
Modern electrical grids have protective mechanisms to prevent localized disruptions from snowballing into catastrophic blackouts. One of those mechanisms is load shedding, which disconnects selected electrical loads when the system becomes unstable.
The goal is to sacrifice part of the system to save the rest. But the new research suggests that understanding how an attacker might exploit vulnerabilities within the network could help engineers develop stronger defenses.
Engineers may also need to pay closer attention to the quieter, less-connected corners of a network rather than simply focusing protection on the system’s largest hubs.
The research’s findings could ultimately help researchers design cyber-physical systems capable of surviving hostile or unpredictable environments.

