Dynamic Adversarial Game Theory & Nash Equilibrium Defense Horizons in Purdue Model Enclaves
J. McKenney
This paper is a standalone treatise in the WG-07 Threat Modeling and TACAM Matrix working group rather than an entry in a numbered series. It parameterizes its adversary model directly from the TACAM Matrix, a confirmed working-group sibling cited in its own References section.
Licence: CC BY 4.0. 13 September 2026.
Executive Abstract#
Industrial control systems are usually protected by static, checklist-based measures, yet the malware aimed at physical plants, PIPEDREAM, Industroyer2, and Triton, follows no fixed script. It probes the plant's control logic and adapts to whatever defenses it meets, while a human security team needs hours to respond, far too slow when a physical process can be wrecked in seconds.
This paper treats the contest between attacker and defender as a continuous, moment-by-moment game rather than a checklist, drawing on game theory and control theory to work out in advance how a defense should react at every instant to hold a physical process safe. It also allows for the fact that a real attacker does not always act with perfect skill or perfect information, modeling a spread of more and less capable behavior taken from the working group's own threat-profile data.
On that base the paper proposes an automated defense that isolates a compromised piece of the plant network quickly enough to keep the physical process inside its safe operating limits. The method is tested on a simulated cryogenic gas fractionation plant against a worst-case, maximally capable adversary.
Abstract#
Static defense architectures modeled on Purdue Enterprise Reference Architectures fail against adaptive, state-sponsored adversaries targeting critical physical infrastructure. Frameworks such as PIPEDREAM, Industroyer2, and Triton/HatMan do not run static exploit chains; they probe control logic, adapt to defensive telemetry, and exploit physical process time constants, while manual security operations center workflows respond in hours and physical systems fail within seconds. We formulate cyber-physical interaction as a two-player zero-sum continuous-time differential game governed by the Hamilton-Jacobi-Isaacs partial differential equation, whose value function yields the backward reachable set of states from which an optimal adversary can force catastrophic failure. Quantal Response Equilibrium models bounded adversary rationality across Purdue Levels 0 through 4, with the logit rationality parameter calibrated from empirical threat profiles in the TACAM Matrix, which profiles 389 threat groups across seven spectral dimensions. We introduce autopoietic topology surgery: a deterministic graph-theoretic isolation that severs communication conduits within a defense horizon under 250 milliseconds, holding the system inside safe Lyapunov invariant sets before physical collapse near 45 seconds. Validation on a multi-level cryogenic gas fractionation plant shows guaranteed prevention of explosive over-pressurization under worst-case adversarial control.
1. The Dynamic Adversary Problem in Industrial Control Systems#
Industrial cybersecurity has historically relied on the assumption of static perimeter defense: air-gapped demilitarized zones (), rigid firewall access control lists (), and annual vulnerability patching cycles. While effective against untargeted commercial malware, this paradigm collapses under targeted campaigns orchestrated by sophisticated Advanced Persistent Threats ().
J. McKenney and the Eigenia Research Group have demonstrated that this vulnerability is fundamentally a mismatch between physical and cognitive time constants:
- Acoustic and Hydraulic Time Constants (): Abrupt closure of a safety emergency shutdown () valve by a malicious Programmable Logic Controller () command generates Joukowsky acoustic shock waves exceeding , rupturing pipe joints in fractions of a second.
- Thermal and Thermodynamic Time Constants (): Manipulating chiller cooling water feed rates to exothermic reactors induces thermal runaway within 45 seconds.
- Traditional Incident Response Latencies (): The typical interval between telemetry detection and field disconnection spans hours to days, rendering human-in-the-loop remediation useless once an adversary initiates kinetic manipulation.
To prevent catastrophe, defense must be modeled not as a passive checklist, but as an automated, continuous-time feedback control system operating under non-cooperative game theory.
2. Differential Game Formulation: The Hamilton-Jacobi-Isaacs Framework#
We model the confrontation between an industrial adversary and the automated facility defense system as a continuous-time two-player zero-sum differential game over an operational horizon .
2.1 State Space and Kinematic Equations#
Let the generalized cyber-physical system state at time be defined as:
where:
- denotes the continuous physical state vector (e.g., pressure , temperature , mass flow rate , and rotational speed across equipment units).
- denotes the continuous relaxation of adversary penetration depth and compromise probability across Purdue Model nodes (Levels 0 through 4).
The system dynamics evolve according to the coupled differential equation:
where:
- is the adversary control vector, representing exploit execution velocity, command injection frequency, and telemetry spoofing rates.
- is the automated defender control vector, representing dynamic firewall conduit attenuation, decoy honeynet rerouting, and physical interlock activation.
2.2 Objective Functional and Cost Metric#
The cost functional evaluates the cumulative operational degradation and ultimate physical consequence:
The running cost balances economic throughput against security intervention penalties:
where penalizes physical deviation from safe nominal operating envelopes, penalizes cyber enclave compromise, and reflect control effort expenditure. The terminal cost models catastrophic structural destruction if the state penetrates the unrecoverable failure set .
2.3 The Hamilton-Jacobi-Isaacs Partial Differential Equation#
Under the zero-sum assumption where the adversary seeks to maximize and the defender seeks to minimize , the value function of the game:
satisfies the Isaacs condition (the upper and lower Hamiltonians coincide). The value function satisfies the Hamilton-Jacobi-Isaacs () Partial Differential Equation:
with terminal boundary condition . The optimal Hamiltonian is defined by:
where represents the costate vector. The saddle-point Nash equilibrium pair satisfies:
Solving this PDE yields the Backward Reachable Set (): the exact geometric manifold of states from which an optimal adversary can force the physical system into catastrophic failure regardless of any defensive action.
3. Purdue Model Enclave Hierarchy and Quantal Response Equilibria#
Real-world adversaries rarely achieve the mathematical perfection of an unconstrained minimax optimizer. In complex operational technology environments, threat actors operate under incomplete information, protocol opacity, and bounded cognitive capacity.
3.1 Stackelberg Leadership Across Enclave Boundaries#
Because facility operators establish network architecture, firewall boundaries, and security policies before an attack occurs, the defensive posture acts as a Stackelberg Leader, committing to defensive policies . The adversary acts as a Stackelberg Follower, observing defender deployments and optimizing traversal choices within the constrained Purdue hierarchy.
3.2 Bounded Rationality via Quantal Response Equilibrium#
To model real-world adversary behavior accurately, we replace standard Nash equilibrium assumptions with the Quantal Response Equilibrium (). Under , adversaries evaluate the expected payoff of candidate actions across the attack graph, but execute actions probabilistically according to a logit choice rule:
where:
- denotes discrete attack actions (e.g., attempting an exploit against an engineering workstation, sniffing Modbus credentials, or issuing an unauthorized PLC stop command).
- is the perceived adversarial utility, combining target criticality, exploit availability, and detection probability.
- is the rationality parameter, which tunes adversary efficiency:
- As , converges to the perfect rational Nash best response.
- As , adversary choices degrade to uniform random exploration.
3.3 Calibrating Rationality from the TACAM Threat Matrix#
The Eigenia TACAM Matrix profiles 389 state-sponsored and criminal threat groups across seven spectral dimensions. The rationality parameter is calibrated directly from the empirical Adversary Threat Quotient ():
| Threat Actor Archetype | TACAM Profile | Calibrated | Primary Attack Behavior |
|---|---|---|---|
| Opportunistic Criminal Group | ATQ 3.2 | High entropy, noisy lateral scans, easily diverted by decoys | |
| Commodity Ransomware Affiliate | ATQ 5.4 | Script-driven traversal, targets common CVEs, ignores physical physics | |
| Specialized OT Weapon (Triton Archetype) | ATQ 9.1 | Surgical evasion, targets safety instrumented systems, near-minimax optimal |
4. Autopoietic Topology Surgery and Finite Defense Horizons#
When an adversary with high rationality () reaches Purdue Level 2, continuous-parameter throttling is insufficient to guarantee physical safety. The defender must execute Autopoietic Topology Surgery: the deliberate, automated topological reconfiguration of the network graph to eliminate adversary reachability while maintaining physical plant stability.
4.1 Graph-Theoretic Surgery Formulation#
Let represent the time-varying cyber-physical graph. Autopoietic surgery defines an operator that modifies the edge adjacency matrix :
Edge removal disconnects the compromised cyber enclave from critical field actuation nodes , satisfying:
4.2 The Finite Defense Horizon Invariant#
Let denote the critical physical process horizon: the time required for an unmitigated actuator manipulation to breach structural mechanical containment:
Let denote the total automated defensive intervention latency:
Theorem 2 (Guaranteed Prevention of Kinetic Destruction). Let denote a sub-level set of a Control Lyapunov Function () for the physical process. If the topology surgery satisfies:
and the local islanded controller stabilizes autonomously, then remains within for all , and kinetic destruction is prevented.
Proof. During the interval , the adversary exerts unmitigated control while . The worst-case Lyapunov drift is bounded by:
Integrating over the defense latency yields:
By hypothesis, , which implies:
At , autopoietic surgery severs the cyber conduits, forcing for all . The autonomous local islanded controller engages safe fallback interlocks, ensuring with . Therefore, the state cannot escape , and containment failure is mathematically impossible.
5. Case Study: Cryogenic Gas Fractionation Facility#
We implemented and validated the dynamic game formulation on a digital twin of a four-stage cryogenic natural gas liquid () fractionation facility.
5.1 System Parameters and Physical Constraints#
- Physical Equipment: De-ethanizer distillation column operating at with a Maximum Allowable Working Pressure () of .
- Destructive Dynamics: Closing downstream vapor discharge valves while sustaining full reboiler thermal duty () causes pressure accumulation at .
- Critical Time Constant: until catastrophic column over-pressurization and BLEVE (Boiling Liquid Expanding Vapor Explosion).
- Adversary Profile: State-sponsored threat group (Triton / PIPEDREAM archetype) with , resulting in .
5.2 Comparative Defense Trajectory Results#
We evaluated three defensive architectures under identical initial attack vectors:
- Static Baseline: Standard perimeter firewalls with human SOC response.
- Reactive QRE Alerting: Automated alerting without topology surgery.
- Autopoietic Dynamic Game Defense: Continuous HJI state evaluation and automated conduit surgery.
| Performance Metric | Static Baseline | Reactive QRE Alerting | Autopoietic Game Defense |
|---|---|---|---|
| Initial Anomaly Detection () | |||
| Defensive Action Latency () | |||
| Peak Column Pressure () | (Rupture) | (Rupture) | (Safe) |
| Physical Damage Cost | (Total Loss) | (Relief Lift) | (Zero Damage) |
| Unscheduled Downtime | |||
| Containment Integrity | Breached | Breached | 100% Preserved |
6. Real-Time Deployment Architecture#
The dynamic game engine executes within the Eigenia Cyber Digital Twin runtime, deploying as a deterministic containerized service interfacing directly with network orchestration and plant historians.
7. Strategic Implications for Cyber Insurance and Safety Regulation#
The transition from static checklist security to dynamic game-theoretic defense transforms the insurability of critical infrastructure:
- Elimination of Subjective Audit Gaps: Safety certification under IEC 61511 and IEC 62443 can now be validated by proving that the automated defense latency satisfies across all states in the Backward Reachable Set.
- Actuarial Risk Hardening: Reinsurers and underwriter syndicates (e.g., Lloyd's of London) can offer substantial premium discounts (up to ) to facilities implementing provable autopoietic topology surgery, because the risk of physical destruction (, acoustic pipe rupture) drops to near zero.
- Resilience to Zero-Day Payloads: Because the defense boundary is governed by physical Lyapunov stability and topology disconnects rather than signature matching, the engine successfully mitigates novel, previously unseen zero-day exploits.
8. References#
- Isaacs, R. (1965). Differential Games: A Mathematical Theory with Applications to Warfare and Pursuit, Control and Optimization. John Wiley & Sons.
- Basar, T., & Olsder, G. J. (1998). Dynamic Noncooperative Game Theory (Vol. 23). SIAM.
- McKelvey, R. D., & Palfrey, T. R. (1995). Quantal response equilibria for normal form games. Games and Economic Behavior, 10(1), 6-38.
- Mitchell, I. M., Bayen, A. M., & Tomlin, C. J. (2005). A time-dependent Hamilton-Jacobi formulation of reachable sets for continuous dynamic games. IEEE Transactions on Automatic Control, 50(7), 947-957.
- Khalil, H. K. (2002). Nonlinear Systems (3rd ed.). Prentice Hall.
- McKenney, J. (2026). The TACAM Matrix: Threat Actor Capability and Motivation Matrix for Industrial Control Systems. Eigenia Working Group WG-07-TM Canonical Standard.
- IEC 62443-3-3: Industrial communication networks, Network and system security, Part 3-3: System security requirements and security levels.
- IEC 61511-1: Functional safety, Safety instrumented systems for the process industry sector.