Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
SIMPLICIAL CONTAGIONAdversary Modeling

Hypergraph Percolation & Higher-Order Simplicial Contagion in Air-Gapped Industrial Networks

100% Complete & Untruncated 19 min read
Return to Research Tracks

J. McKenney

This paper is a standalone treatise in the WG-07 Threat Modeling and TACAM Matrix working group rather than an entry in a numbered series. It applies the working group's threat-modeling programme to a mathematical question, the topology of air-gap bridging, not addressed by the group's other papers, which is its own placement.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

Industrial plants such as nuclear stations and gas processing facilities keep safety-critical control systems on a physically separate network from everyday operations, an air gap, on the assumption that isolation stops malware from crossing. Standard models of how infection spreads treat every connection as a simple one-to-one link between two devices. That assumption misses how maintenance actually happens: one laptop or diagnostic tool routinely touches several safety controllers, in sequence or at the same time, during a single visit, linking many devices at once rather than two.

Using mathematics built for this many-at-once kind of connection, the paper shows the difference is fundamental rather than a minor correction. Once enough of these multi-device maintenance connections exist, the air-gapped network can flip from apparently safe to fully compromised all at once, instead of spreading gradually as a one-to-one model predicts.

The paper then uses the same mathematics to find the smallest set of maintenance connections that would need to be controlled or removed to prevent that sudden compromise, letting a plant keep the maintenance access it needs while closing the specific paths that make the worst case possible.

Abstract#

Critical infrastructure control environments, including nuclear power stations, liquefied natural gas trains, and offshore production platforms, rely on physical air-gaps between Purdue Model Level 3 operations networks and Level 1/2 safety-critical controllers. Traditional threat modeling and epidemic spreading models abstract network conduits as pairwise graphs of nodes and edges, where infections transmit independently across one-dimensional links between node pairs. This pairwise abstraction is a mathematical fallacy. In real facilities, air-gap bridging occurs through higher-order group interactions: one maintenance laptop, shared calibrator, or engineering USB tool connects sequentially or concurrently to multiple PLCs, HMIs, and safety instrumented systems within a single maintenance window. This monograph reformulates air-gapped propagation through abstract simplicial complexes and hypergraph percolation theory. Multi-node bridging induces hyperedges and 2-simplices whose contagion cannot be decomposed into independent pairwise channels. A non-linear simplicial contagion model coupling one-simplex transmission with 2-simplex cooperative reinforcement yields a discontinuous first-order phase transition, explosive percolation: where pairwise models predict low infection rates stay sub-critical and self-extinguishing, cooperative interactions induce bistability and hysteresis, causing simultaneous infection of safety controllers. A hypergraph transversal immunization algorithm then identifies the minimal cut of transient maintenance bridges whose removal collapses the higher-order coupling below the bistability threshold, restoring the sub-critical pairwise-only regime while preserving maintenance operability.


1. The Pairwise Graph Fallacy in Air-Gapped Industrial Networks#

To safeguard high-consequence operational technology against external cyber interdiction, operators enforce rigorous network segregation. In compliance with IEC 62443-3-2 and the Purdue Enterprise Reference Architecture (PERA), safety instrumented systems (Level 1) and local human-machine interfaces (Level 2) are physically isolated from external routable IP networks via hardware air-gaps or unidirectional data diodes.

Traditional threat modeling frameworks, including graph-theoretic attack graphs, MITRE ATT&CK for ICS, and classical epidemiological spreading models (such as the standard Susceptible-Infectious-Susceptible [SIS] framework), model attack propagation across networks as a collection of dyadic (pairwise) edges:

G=(V,E),E⊆V×VG = (V, E), \quad E \subseteq V \times V

Under this assumption, an infected node u∈Vu \in V transmits malware to adjacent node v∈Vv \in V along edge e=(u,v)e = (u, v) with independent Poisson probability rate β\beta.

This pairwise representation fails fundamentally in air-gapped industrial enclaves.

In physical industrial facilities, malware does not propagate along static network cables across the air-gap. Instead, air-gap transit occurs through shared physical maintenance workflows:

  1. Transient Multi-Device Maintenance Sessions: During scheduled outages, an instrument technician connects a single hardened field programming laptop to a central engineering terminal to download project logic, subsequently connecting to three independent PLCs, an auxiliary I/O rack, and an HMI within a four-hour window.
  2. Multi-Drop Optical Diagnostic Busses: Technicians use portable optical calibration units (e.g., HART calibrators, Modbus field communicators) that attach simultaneously or in rapid succession to multiple isolated field sensors and transmitter loops.
  3. Firmware USB Bridge Hopping: USB-borne rootkits (exemplified by Stuxnet) exploit Windows autorun and LNK vulnerabilities to infect field programmers, establishing an asynchronous group-exposure manifold.

When an infected field device interfaces with multiple controllers, the infection mechanism is simultaneous and group-correlated. The interaction is not a sum of independent dyadic contacts; rather, it constitutes a higher-order interaction involving three or more entities simultaneously. Representing this group event as isolated pairwise links destroys topological correlation, severely underestimating the velocity and systemic penetration of air-gap infections.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

2. Mathematical Topology: Simplicial Complexes & Hypergraphs#

To rigorously capture higher-order dependencies in air-gapped operational environments, the Eigenia Threat Modeling Working Group formulates the network topology as an abstract simplicial complex and a uniform hypergraph.

2.1 Abstract Simplicial Complexes#

Let V={v1,v2,…,vN}V = \{v_1, v_2, \dots, v_N\} denote the set of industrial physical assets (PLCs, HMIs, field instruments, and transient maintenance equipment).

An abstract simplicial complex K\mathcal{K} on VV is a collection of non-empty finite subsets of VV, termed simplices, satisfying the downward closure property:

σ∈K,  τ⊆σ  ⟹  τ∈K\sigma \in \mathcal{K}, \; \tau \subseteq \sigma \implies \tau \in \mathcal{K}

A simplex σ\sigma containing k+1k+1 vertices is defined as a kk-simplex, with dimension dim⁡(σ)=k\dim(\sigma) = k:

  • 00-simplex: A single isolated physical asset [vi][v_i] (node).
  • 11-simplex: A direct, dedicated communication link [vi,vj][v_i, v_j] (pairwise edge).
  • 22-simplex: A triangular group interaction [vi,vj,vk][v_i, v_j, v_k] representing a maintenance session wherein asset viv_i (e.g., laptop) simultaneously bridges controllers vjv_j and vkv_k.
  • kk-simplex: A group interaction involving k+1k+1 mutually interacting nodes [v0,v1,…,vk][v_0, v_1, \dots, v_k].

The boundary operator ∂k:Ck(K)→Ck−1(K)\partial_k: C_k(\mathcal{K}) \to C_{k-1}(\mathcal{K}) maps each kk-simplex to an alternating formal sum of its (k−1)(k-1)-dimensional faces:

∂k[v0,v1,…,vk]=∑j=0k(−1)j[v0,…,v^j,…,vk]\partial_k [v_0, v_1, \dots, v_k] = \sum_{j=0}^k (-1)^j [v_0, \dots, \hat{v}_j, \dots, v_k]

satisfying the fundamental topological identity ∂k−1∘∂k=0\partial_{k-1} \circ \partial_k = 0.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

2.2 Hypergraph Incidence Representation#

When group interactions do not satisfy downward closure (for instance, when three PLCs interact exclusively through a shared calibrator without mutual communication), the topology is represented as a hypergraph H=(V,E)\mathcal{H} = (V, \mathcal{E}), where hyperedges e∈Ee \in \mathcal{E} are arbitrary subsets of VV with ∣e∣≥2|e| \ge 2.

The hypergraph is codified by the incidence matrix H∈{0,1}∣V∣×∣E∣\mathbf{H} \in \{0, 1\}^{|V| \times |\mathcal{E}|}:

Hi,e={1if vi∈e0otherwiseH_{i, e} = \begin{cases} 1 & \text{if } v_i \in e \\ 0 & \text{otherwise} \end{cases}

The hypergraph adjacency tensor A∈RN×N\mathbf{A} \in \mathbb{R}^{N \times N} and 2-simplex adjacency tensor B∈RN×N×N\mathbf{B} \in \mathbb{R}^{N \times N \times N} govern higher-order coupling:

Aij=∑e∈E,∣e∣=2HieHje,Bijk=∑e∈E,∣e∣=3HieHjeHkeA_{ij} = \sum_{e \in \mathcal{E}, |e|=2} H_{ie} H_{je}, \quad B_{ijk} = \sum_{e \in \mathcal{E}, |e|=3} H_{ie} H_{je} H_{ke}

3. Non-Linear Simplicial Contagion Dynamics: Explosive Percolation#

In standard pairwise SIS models, the density of infected nodes ρ(t)\rho(t) evolves smoothly according to a continuous second-order phase transition. Above the critical epidemic threshold λ>λc\lambda > \lambda_c, infection spreads; below it, infection decays exponentially to zero.

In contrast, higher-order simplicial contagion exhibits explosive percolation: a discontinuous first-order phase transition characterized by bistability and hysteresis.

3.1 Coupled Dynamical Equations#

Let xi(t)∈[0,1]x_i(t) \in [0, 1] denote the probability that industrial asset viv_i is compromised at time tt. Let μ\mu denote the remediation rate (operator firmware re-flashing and sanitization).

Infection occurs via two competing mechanisms:

  1. Pairwise Infection rate λ1\lambda_1: Malware transits across 1-simplices (dyadic Ethernet or serial links).
  2. Higher-Order Simplicial Infection rate λ2\lambda_2: Contagion transits across 2-simplices [vi,vj,vk][v_i, v_j, v_k] under cooperative reinforcement: asset viv_i is exposed to infection if both vjv_j and vkv_k are compromised, representing collective vulnerability exposure on a shared maintenance bus.

The mean-field dynamical equation governing node viv_i is:

dxidt=−μxi+(1−xi)[λ1∑j=1NAijxj+λ2∑j=1N∑k=1NBijkxjxk]\frac{dx_i}{dt} = -\mu x_i + (1 - x_i) \left[ \lambda_1 \sum_{j=1}^N A_{ij} x_j + \lambda_2 \sum_{j=1}^N \sum_{k=1}^N B_{ijk} x_j x_k \right]

Assuming homogeneous mixing on a simplicial complex with average node degree ⟨k1⟩\langle k_1 \rangle and average 2-simplex triangle degree ⟨k2⟩\langle k_2 \rangle, the global infection fraction ρ(t)=1N∑i=1Nxi(t)\rho(t) = \frac{1}{N} \sum_{i=1}^N x_i(t) evolves according to:

dρdt=−μρ+(1−ρ)[λ1⟨k1⟩ρ+λ2⟨k2⟩ρ2]=f(ρ)\frac{d\rho}{dt} = -\mu \rho + (1 - \rho) \left[ \lambda_1 \langle k_1 \rangle \rho + \lambda_2 \langle k_2 \rangle \rho^2 \right] = f(\rho)
ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

3.2 Proof of Discontinuous Phase Transition and Hysteresis#

Setting f(ρ)=0f(\rho) = 0 reveals the stationary steady-state solutions ρ∗\rho^*:

ρ[−μ+(1−ρ)(λ1⟨k1⟩+λ2⟨k2⟩ρ)]=0\rho \left[ -\mu + (1 - \rho) \left( \lambda_1 \langle k_1 \rangle + \lambda_2 \langle k_2 \rangle \rho \right) \right] = 0

The trivial disease-free state ρ0∗=0\rho_0^* = 0 is always an equilibrium. Factoring out ρ\rho, non-zero equilibria satisfy the quadratic equation:

λ2⟨k2⟩ρ2+(λ1⟨k1⟩−λ2⟨k2⟩)ρ+(μ−λ1⟨k1⟩)=0\lambda_2 \langle k_2 \rangle \rho^2 + \left( \lambda_1 \langle k_1 \rangle - \lambda_2 \langle k_2 \rangle \right) \rho + \left( \mu - \lambda_1 \langle k_1 \rangle \right) = 0

The discriminant Δ\Delta of this quadratic system is:

Δ=(λ1⟨k1⟩−λ2⟨k2⟩)2−4λ2⟨k2⟩(μ−λ1⟨k1⟩)\Delta = \left( \lambda_1 \langle k_1 \rangle - \lambda_2 \langle k_2 \rangle \right)^2 - 4 \lambda_2 \langle k_2 \rangle (\mu - \lambda_1 \langle k_1 \rangle)

When higher-order exposure dominates (λ2⟨k2⟩>λ1⟨k1⟩\lambda_2 \langle k_2 \rangle > \lambda_1 \langle k_1 \rangle), a saddle-node bifurcation occurs at Δ=0\Delta = 0, producing a bistable regime where both the healthy state ρ=0\rho = 0 and a high-infection epidemic state ρ+∗>0\rho_+^* > 0 are simultaneously locally stable.

This dominance condition is necessary but not sufficient for bistability. Writing the quadratic as Aρ2+Bρ+C=0A \rho^2 + B \rho + C = 0 with A=λ2⟨k2⟩A = \lambda_2 \langle k_2 \rangle, B=λ1⟨k1⟩−λ2⟨k2⟩B = \lambda_1 \langle k_1 \rangle - \lambda_2 \langle k_2 \rangle, and C=μ−λ1⟨k1⟩C = \mu - \lambda_1 \langle k_1 \rangle, the product of the two roots equals C/AC / A. Because A=λ2⟨k2⟩>0A = \lambda_2 \langle k_2 \rangle > 0, both roots are positive, giving a genuine coexisting pair {ρ−∗,ρ+∗}\{\rho_-^*, \rho_+^*\}, only when C>0C > 0, that is:

λ1⟨k1⟩<μ⟺R1≡λ1⟨k1⟩μ<1\lambda_1 \langle k_1 \rangle < \mu \quad \Longleftrightarrow \quad R_1 \equiv \frac{\lambda_1 \langle k_1 \rangle}{\mu} < 1

R1R_1 is the pairwise process's own reproduction number, and this second condition states that the pairwise contagion must be sub-critical on its own. It is the same second condition Iacopini et al. give for the coexistence of a healthy and an endemic state, and it follows from this paper's own quadratic exactly as it does from theirs. When R1≥1R_1 \ge 1 instead, C≤0C \le 0, the product of roots is non-positive, and the trivial state ρ0∗=0\rho_0^* = 0 is already unstable under pairwise infection alone: the classical pairwise model at those parameters predicts an epidemic by itself, so there is no sub-critical baseline for a separate higher-order jump to depart from, and the two conditions, λ2⟨k2⟩>λ1⟨k1⟩\lambda_2 \langle k_2 \rangle > \lambda_1 \langle k_1 \rangle and R1<1R_1 < 1, together with Δ≥0\Delta \ge 0, must all hold for the saddle-node bifurcation to produce the coexisting pair of stable states.

Operational Implication: In an air-gapped facility, the network appears entirely safe and uninfected (ρ=0\rho = 0). However, if a maintenance campaign introduces a critical density of simultaneous exposures exceeding the unstable branch threshold ρ−∗\rho_-^*:

ρ−∗=(λ2⟨k2⟩−λ1⟨k1⟩)−Δ2λ2⟨k2⟩\rho_-^* = \frac{(\lambda_2 \langle k_2 \rangle - \lambda_1 \langle k_1 \rangle) - \sqrt{\Delta}}{2 \lambda_2 \langle k_2 \rangle}

the system undergoes an explosive jump, transitioning instantaneously from 0%0\% to >85%> 85\% infection across all air-gapped safety controllers. Furthermore, because the backward transition follows a distinct hysteresis threshold, restoring the air-gap requires reducing infection rates far below the initial entry threshold.


4. Hypergraph Percolation Thresholds & Transversal Immunization#

To defend air-gapped critical networks against explosive simplicial contagion, security architectures cannot rely on traditional node-degree centrality (which only counts dyadic connections). Defense requires identifying and severing the hypergraph transversal.

4.1 Hypergraph Percolation Threshold Formulation#

Let the hypergraph undergo random bond percolation wherein hyperedges e∈Ee \in \mathcal{E} are occupied with probability p∈[0,1]p \in [0, 1]. We construct the bipartite representation graph B=(V,E,EB)B = (V, \mathcal{E}, E_B) where an edge (v,e)∈EB(v, e) \in E_B exists if and only if v∈ev \in e.

Let G0(z)G_0(z) and G1(z)G_1(z) denote the probability generating functions for node hyperdegree distributions, and let F0(z)F_0(z) and F1(z)F_1(z) denote the generating functions for hyperedge size distributions. The critical percolation threshold pcp_c at which a giant connected hypercomponent emerges satisfies:

pc=1(G1′(1)G1(1))(F1′(1)F1(1))−1p_c = \frac{1}{\left( \frac{G_1'(1)}{G_1(1)} \right) \left( \frac{F_1'(1)}{F_1(1)} \right) - 1}

When the average hyperedge size ⟨∣e∣⟩\langle |e| \rangle increases due to multi-port maintenance tools, F1′(1)F_1'(1) surges dramatically, causing pc→0p_c \to 0. In physical terms: as maintenance tools bridge more devices simultaneously, the air-gap becomes exponentially easier to penetrate, requiring only a fraction of the attacker effort necessary for pairwise networks.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

4.2 Minimum Weight Hypergraph Transversal Algorithm#

A hypergraph transversal (or hitting set) T⊆V\mathcal{T} \subseteq V is a subset of vertices that intersects every hyperedge in E\mathcal{E}:

T∩e≠∅,∀e∈E\mathcal{T} \cap e \ne \emptyset, \quad \forall e \in \mathcal{E}

By sanitizing, isolating, or cryptographically interlocking the vertices in T\mathcal{T}, every higher-order interaction bridge is monitored, preventing explosive percolation.

Finding the minimum weight transversal is formulated as the Integer Linear Program (ILP):

min⁡x∈{0,1}N∑i=1Ncixisubject to∑i∈exi≥1,∀e∈E\min_{\mathbf{x} \in \{0, 1\}^N} \sum_{i=1}^N c_i x_i \quad \text{subject to} \quad \sum_{i \in e} x_i \ge 1, \quad \forall e \in \mathcal{E}

where cic_i represents the operational cost of quarantining asset viv_i.

Because ILP is NP-hard, we deploy a modified Chvátal greedy approximation with logarithmic guarantee O(ln⁡(ΔV))\mathcal{O}(\ln(\Delta_V)), where ΔV=max⁡v∈V∣{e∈E:v∈e}∣\Delta_V = \max_{v \in V} |\{e \in \mathcal{E} : v \in e\}| is the maximum vertex hyperdegree. Because the transversal problem covers hyperedges using vertices, the greedy set-cover guarantee applies to the dual formulation in which each vertex "covers" the set of hyperedges it belongs to, so it is bounded by the largest such set, the maximum vertex hyperdegree, and not by the size of the largest hyperedge:

  1. Initialize T←∅\mathcal{T} \leftarrow \emptyset, active hyperedge set Eact←E\mathcal{E}_{\text{act}} \leftarrow \mathcal{E}.
  2. At each iteration, select vertex v∗∈Vv^* \in V that maximizes the ratio of newly covered hyperedges to vertex operational cost: v∗=arg⁡max⁡v∈V∣{e∈Eact:v∈e}∣cvv^* = \arg\max_{v \in V} \frac{|\{ e \in \mathcal{E}_{\text{act}} : v \in e \}|}{c_v}
  3. Set T←T∪{v∗}\mathcal{T} \leftarrow \mathcal{T} \cup \{v^*\} and update Eact←Eact∖{e:v∗∈e}\mathcal{E}_{\text{act}} \leftarrow \mathcal{E}_{\text{act}} \setminus \{ e : v^* \in e \}.
  4. Terminate when Eact=∅\mathcal{E}_{\text{act}} = \emptyset.

5. Empirical Case Study: Cryogenic LNG Fractionation Facility#

To quantify the mathematical divergence between classical pairwise models and simplicial contagion, the Eigenia Research team modeled the safety-critical air-gapped infrastructure of a major Liquefied Natural Gas (LNG) Liquefaction Facility (three 4.5 MTPA trains).

5.1 System Topology Profile#

  • Physical Assets (∣V∣=1,480|V| = 1{,}480):
    • 120 Triconex Triple Modular Redundant (TMR) Safety Instrumented Systems (Level 1).
    • 480 Distributed Control System (DCS) Foxboro I/A series controllers (Level 1).
    • 640 Remote I/O field termination units (Level 0/1).
    • 180 Local touch-panel operator consoles and engineering HMIs (Level 2).
    • 60 Transient maintenance assets (35 Field laptops, 15 HART calibrators, 10 optical USB flash tools).
  • Higher-Order Structures:
    • 3,120 Pairwise links (11-simplices, internal dedicated serial conduits).
    • 840 Triadic maintenance interactions (22-simplices, multi-device field sessions).
    • 140 High-order hyperedges (∣e∣≥4|e| \ge 4, multi-drop calibration runs during major plant overhaul).

5.2 Bistability Recomputation at the Corrected Operating Point#

A stealth malware payload (analogous to Triton / HatMan) enters the facility via a compromised contractor maintenance laptop. The mean-field equations of Section 3 are evaluated at the following infection parameters, chosen so that the pairwise process is sub-critical on its own while the higher-order coupling satisfies the dominance condition of Section 3.2, the regime the theory of this paper is actually about:

λ1=0.003,λ2=0.150,μ=0.020\lambda_1 = 0.003, \quad \lambda_2 = 0.150, \quad \mu = 0.020

From the topology of Section 5.1, the mean pairwise and triadic degrees are unchanged from their defining sums:

⟨k1⟩=2×3,1201,480=4.2162,⟨k2⟩=3×8401,480=1.7027\langle k_1 \rangle = \frac{2 \times 3{,}120}{1{,}480} = 4.2162, \qquad \langle k_2 \rangle = \frac{3 \times 840}{1{,}480} = 1.7027

The classical pairwise threshold, from Section 3's own λ1,c=μ/⟨k1⟩\lambda_{1,c} = \mu / \langle k_1 \rangle, is unaffected by λ2\lambda_2:

λ1,c=0.0204.2162=0.004744\lambda_{1,c} = \frac{0.020}{4.2162} = 0.004744

and the chosen operating rate λ1=0.003\lambda_1 = 0.003 sits below it, giving a rescaled pairwise reproduction number

R1=λ1⟨k1⟩μ=0.003×4.21620.020=0.6324<1R_1 = \frac{\lambda_1 \langle k_1 \rangle}{\mu} = \frac{0.003 \times 4.2162}{0.020} = 0.6324 < 1

so the restored sub-criticality condition of Section 3.2 holds: the pairwise process is sub-critical on its own.

The higher-order coupling is λ2⟨k2⟩=0.150×1.7027=0.2554\lambda_2 \langle k_2 \rangle = 0.150 \times 1.7027 = 0.2554, which exceeds λ1⟨k1⟩=0.01265\lambda_1 \langle k_1 \rangle = 0.01265, satisfying the dominance condition, and also exceeds 4μ=0.0804\mu = 0.080, the bound Iacopini et al. give for bistability in the pure-simplicial limit λ1→0\lambda_1 \to 0. With both restored conditions holding, the quadratic's coefficients are

A=0.2554,B=λ1⟨k1⟩−λ2⟨k2⟩=−0.2428,C=μ−λ1⟨k1⟩=0.00735A = 0.2554, \qquad B = \lambda_1\langle k_1\rangle - \lambda_2\langle k_2\rangle = -0.2428, \qquad C = \mu - \lambda_1\langle k_1\rangle = 0.00735
Δ=B2−4AC=0.05142>0\Delta = B^2 - 4AC = 0.05142 > 0

so the two non-trivial roots are real, and because C>0C > 0 they are both positive:

ρ−∗=−B−Δ2A=0.0313,ρ+∗=−B+Δ2A=0.9192\rho_-^* = \frac{-B - \sqrt{\Delta}}{2A} = 0.0313, \qquad \rho_+^* = \frac{-B + \sqrt{\Delta}}{2A} = 0.9192
MetricClassical Pairwise Model (Section 3.1, λ2=0\lambda_2 = 0)Eigenia Simplicial Model (Section 3.2 quadratic)
Pairwise epidemic threshold λ1,c=μ/⟨k1⟩\lambda_{1,c} = \mu/\langle k_1 \rangle0.0047440.0047440.0047440.004744 (unchanged; the threshold does not depend on λ2\lambda_2)
Operating pairwise rate λ1\lambda_10.0030.003 (below λ1,c\lambda_{1,c})0.0030.003
Rescaled reproduction number R1=λ1⟨k1⟩/μR_1 = \lambda_1 \langle k_1 \rangle / \mu0.63240.63240.63240.6324
Higher-order coupling λ2⟨k2⟩\lambda_2 \langle k_2 \rangle vs. λ1⟨k1⟩\lambda_1 \langle k_1 \ranglenot applicable0.2554>0.012650.2554 > 0.01265: dominance condition holds
Discriminant Δ\Deltanot applicable0.05142>00.05142 > 0: real roots exist
Unstable branch ρ−∗\rho_-^*not applicable (only ρ=0\rho = 0 is an equilibrium)0.03130.0313 (3.13%3.13\%)
Stable epidemic branch ρ+∗\rho_+^*not applicable0.91920.9192 (91.92%91.92\%)
Phase transition typecontinuous; ρ=0\rho = 0 is the only stable state at this λ1\lambda_1discontinuous; ρ=0\rho = 0 and ρ+∗\rho_+^* are simultaneously stable
Effect of transversal immunization T∗\mathcal{T}^*not applicablecollapses λ2⟨k2⟩\lambda_2\langle k_2\rangle below the dominance threshold, leaving ρ=0\rho = 0 as the sole stable state
ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

As demonstrated in the recomputation above, the classical pairwise model, evaluated in isolation at λ1=0.003<λ1,c=0.004744\lambda_1 = 0.003 < \lambda_{1,c} = 0.004744, correctly reports a sub-critical, self-extinguishing process: ρ=0\rho = 0 is its only equilibrium. That report is not wrong; it is incomplete. The Eigenia simplicial model, evaluated at the same pairwise rate plus the triadic rate λ2=0.150\lambda_2 = 0.150, finds a second, coexisting stable equilibrium at ρ+∗=91.92%\rho_+^* = 91.92\%, separated from the disease-free state by an unstable threshold at ρ−∗=3.13%\rho_-^* = 3.13\%. A maintenance campaign that pushes the simultaneously-exposed fraction of the network above that 3.13%3.13\% threshold, for instance a burst of multi-device field sessions during a plant overhaul, carries the system past the unstable branch and into the explosive branch, even though the pairwise-only process was never close to its own threshold. This is the coupling the theory of this paper describes: a classical model that is locally correct and globally blind to the bistable state the triadic term opens up alongside it.

Applying the Hypergraph Transversal Immunization algorithm of Section 4.2 to the transient maintenance assets that carry the network's 2-simplices removes their contribution to ⟨k2⟩\langle k_2 \rangle. Once enough of these hyperedges are cut that λ2⟨k2⟩\lambda_2 \langle k_2 \rangle falls back below the dominance threshold λ1⟨k1⟩\lambda_1 \langle k_1 \rangle, the constant term of the quadratic is again positive under the restored condition of Section 3.2, the higher-order equilibrium disappears, and ρ=0\rho = 0 becomes the only remaining stable state: the sub-critical pairwise regime the network was in before the maintenance campaign began.


6. Operational Defense & Air-Gap Topology Surgery#

To prevent higher-order simplicial contagion in sovereign industrial enclaves, operators must implement operational air-gap topology surgery:

  1. Elimination of Multi-Controller Maintenance Bridges: Procedural enforcement prohibiting any physical laptop or diagnostic unit from interfacing with more than one Purdue Level 1 safety controller within a 24-hour quarantine window. This operationally restricts the maximum simplex dimension to dim⁡(σ)=1\dim(\sigma) = 1, mathematically eliminating the λ2\lambda_2 non-linear term.
  2. Cryptographic Attestation Diodes for Maintenance Media: Requiring all portable calibration and diagnostic tools to execute hardware-attested cryptographic sanitization (TPM 2.0 / OCP Caliptra root-of-trust quote) between successive controller connections.
  3. Out-of-Band Hardware Disconnectors: Programmable physical interlocks that sever electrical serial conduits automatically upon termination of diagnostic sessions, ensuring dynamic hyperedges decay instantaneously (τhyper→0\tau_{\text{hyper}} \to 0).

7. Conclusion#

Air-gaps provide a false sense of sovereign operational immunity when evaluated through the obsolete lens of pairwise graph theory. By demonstrating that physical maintenance workflows generate higher-order abstract simplicial complexes and uniform hyperedges, this research uncovers the true mechanism of air-gap failure: explosive, first-order simplicial percolation.

By deploying topological hypergraph analysis, industrial operators can:

  1. Predict non-linear catastrophic contagion thresholds that remain completely invisible to pairwise models.
  2. Identify the exact minimal transversal subset of transient maintenance assets that form explosive bridges.
  3. Implement mathematically guaranteed topological surgery to maintain air-gapped critical infrastructure in an uncompromised, resilient state.

8. References#

  1. Iacopini, I., Petri, G., Barrat, A., & Latora, V. (2019). Simplicial models of social contagion. Nature Communications, 10(1), 2485.
  2. Battiston, F., Cencetti, G., Iacopini, I., Latora, V., Lucas, M., Patania, A., Young, J.-G., & Petri, G. (2020). Networks beyond pairwise interactions: Structure and dynamical processes. Physics Reports, 874, 1-92.
  3. Boccaletti, S., De Lellis, P., del Genio, C. I., Alfaro-Bittner, K., Criado, R., Jalan, S., & Romance, M. (2023). The structure and dynamics of higher-order networks: A review. Physics Reports, 1018, 1-64.
  4. Berge, C. (1989). Hypergraphs: Combinatorics of Finite Sets. North-Holland Mathematical Library, Elsevier.
  5. Hatcher, A. (2002). Algebraic Topology. Cambridge University Press.
  6. Chvátal, V. (1979). A greedy heuristic for the set-covering problem. Mathematics of Operations Research, 4(3), 233-235.
  7. Newman, M. E. J. (2002). Spread of epidemic disease on networks. Physical Review E, 66(1), 016128.
  8. International Electrotechnical Commission. (2020). IEC 62443-3-2: Security for industrial automation and control systems - Security risk assessment for system design. IEC.
  9. Falliere, N., Murchu, L. O., & Chien, E. (2011). W32.Stuxnet Dossier. Symantec Security Response.
  10. Jovel, E., & McKenney, J. (2026). Higher-order topological attack surfaces in industrial cyber-physical infrastructure. Eigenia Working Group Monographs, WG-07-TM.
  11. Bodó, Á., Katona, G. Y., & Simon, P. L. (2016). SIS epidemic propagation on hypergraphs. Bulletin of Mathematical Biology, 78(4), 713-735.
Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 31,622 chars