Abstract: Moving target defense (MTD) against advanced persistent threats (APTs) in industrial control systems (ICS) has well-established game-theoretic formulations, but their practical value hinges on equilibrium computation: full-rank value iteration is prohibitively expensive at industrial state dimensions, and the resulting defense strategies admit no certified robustness against adversarial perturbations. We first reveal that the attack and defense influence matrices of ICS dynamics are intrinsically low-rank: APTs infiltrate through a handful of entry points, and MTD reconfigures only a limited subset of components per cycle. We prove that this structure propagates through the non-smooth Bellman operator of the zero-sum stochastic game: an augmented gradient matrix bridging physical and algorithmic low rank certifies that every Bellman target lies near a low-dimensional subspace, with an explicit error bound on the optimal value function. Because these subspaces drift under value iteration, static low-rank projections are inadequate. We therefore propose dynamical low-rank equilibrium computation (DLR-NE), which augments the rank-r search space at each iteration, regularizes the core matrix spectrum, and retracts via truncated SVD, extracting a Nash equilibrium at every step. Four guarantees follow: explicit approximation error; geometric convergence to a neighborhood with five physically interpretable error sources; per-step cost O(nr^2), a Theta(n/r^2) speedup over full-rank value iteration; and robustness in which a single weight trades accuracy against certified safety. Experiments on a nonlinear power-system testbed confirm each prediction, with 94% parameter compression at 0.16% utility loss.
Read the original article:
