Task 1.1 Resilient Cooperative Distributed Iterative CG Schemes
The goal of this task is the study and development of a cooperative distributed CG scheme for the supervision of constrained CPSS. Each cooperative node supervises a physical subsystem and computes the commands by solving, with local and other data provided by the neighboring nodes, an optimization problem that reflects the global performance of the whole CPS and not only that of the local node. Typically, the optimization is performed cooperatively and iteratively by the involved nodes and requires performing some data exchange with the neighbors, where the privacy issues can be prevalent in some applications. The optimization procedure has to be proved to converge to a suitable global optimal solution and the applications of the corresponding optimal commands have to ensure the global stability of the CPS. The problem is complicated by the presence of malicious nodes that can adversely affect the solution and the CPS performance.
Two classical distributed optimization approaches that have gained interest in the literature will be investigated and customized to the CG specificity: 1) primal decompositions based on penalty methods [21] and 2) dual decompositions based on the Lagrangian duality theory [22] for general separable convex constrained multi-agent optimization problems. Both classes of methods allow one to decompose the given problem into smaller subproblems, which can then be coordinated by a master problem or solved with a fully distributed logic [23]. Both classes of optimization schemes find the solution by an iterating procedure with a bargaining scheme among nodes that requires data exchange and produces primal feasible solutions in the limit or approximate epsilon-admissible primal solutions when early terminated. It is important to note that the global cost used in CG action computation is convex and separable, being exactly the sum of the local costs of the single agents that are simple Quadratic Programming problems with linear inequality constraints. As a consequence, distributed cooperative CG schemes are easily derivable and interesting properties are expected.
Many forms of adverse behaviors can be envisaged in the system. The one of interest here is referred to in the literature as non-compliance [24]. In particular, in the case of cooperative optimization, this might happen when one or more agents in the network do not cooperate because they selfishly want to have better performance. In other words, the adversarial agents might optimize a local cost with the goal to steer the iterates to a point that serves their own interest despite possible global performance worsening. Thus, the properties of the cooperative distributed CG in supervising and coordinating the nodes of a constrained CPS will be investigated and, in particular, its ability to detect and isolate the malicious agent whenever possible. An analysis of the running costs can be of help to detect non-compliant behavior of some agents. E.g., if its running cost decreases more quickly and reaches lower values than the others, it could be an indication that it is behaving not cooperatively.
Task 1.2 Adaptive Robustification in Distributed CG Schemes in the Presence of Non-Compliant Agents
The design of distributed control schemes for cyber-physical systems is influenced by real-world factors, such as motor issues, sensor failure, and wind disturbances. These factors cause the appearance of faulty agents. In a distributed control context, sharing incorrect information from faulty agents would lead to undesired control behaviors, such as agents’ disconnection and incorrect interpretation of control specifications. In these cases, a further form of non-compliance (different from that described in the previous task) can result because the expected system response at some command before and after the fault doesn’t comply with the given healthy model.
This task aims at designing novel distributed CG schemes capable of dealing with the previously described critical situations where agents are involved in coupled constraints/dynamics. In this scenario, the feasibility of the distributed CG scheme is usually ensured if the shared information is perfectly known. Uncertainty can be introduced in the optimization problem to increase the robustness property of the schemes against adversarial behaviors. The uncertainty can be in the admissibility ranges of the exogenous signals acting on the CPS that can be represented, which can be larger than necessary to accommodate discrepancies. Robust CG schemes have been proposed in [25] and have been proved to ensure the typical properties of the CG solution robustly. Also, the reconfiguration properties of CG schemes under faults have been analyzed in [26] for a non-cooperative distributed CG scheme and will be here investigated if they hold also in the cooperative approach under analysis.
In principle, to preserve constraint satisfaction during online operations, such a modus operandi can be adopted even in presence of malicious agents that convey false data. Anyway, this project aims at reducing the intrinsic conservativeness of these traditional robust schemes by providing each agent with the capability of modifying the degree of robustification on the basis of the level of confidence (trust) related to each neighbor. To this end, a first challenge consists in determining specific trust models that account for possible mismatches between the predicted evolutions computed on the basis of the shared information and the actual evolution (measured). Moreover, the inter-agent trust relies on the reputation that each agent gains in the network. The core of the methodology relies on the mapping from trust levels into degrees of the uncertainty of shared variables.
A further challenge of this task will rely on the definition of a distributed version of the above described adaptive CG scheme to cope with interacting agents sharing coupled constraints/dynamics. In fact, a typical way to deal with coupling terms appearing in the local agent dynamics is to consider them as exogenous not-manipulable input signals (disturbances) presenting time-varying levels of uncertainty. The resulting control scheme would guarantee local performance even when neighboring controllers are not complying with the requirements of the algorithm (e.g., they are malicious or faulty). Within this scheme, each shared variable is associated with a degree of uncertainty that depends on a reputation mechanism that aims at assessing neighbor behavior on the basis of a trust model. The resulting local adaptation of the scheme would be sufficient to mitigate adversary actions by increasing the robustification level.


