Non-Linear Consequence Dynamics and Kinetic Blast Radius
J. McKenney
This treatise carries the designation P8 in the G_CPDT sequence of the Unified Asset Graph working group and supplies that group's dynamic consequence and mathematical physics foundation. The three-identity join, the CIM profile for cyber-physical assets and the conformance suite establish the identity binding it assumes. The blast radius paper generalizes the reach metric across three ontologies and stops at the set of objects a compromise arrives at; this one asks the questions that begin where the set ends, how quickly a reached asset destroys itself and what the loss is worth to an underwriter.
Licence: CC BY 4.0. 24 August 2026.
Executive Abstract#
IT's vulnerability scoring was built for information systems and ranks by what a compromise does to data. A printer's web server scores near the top, a valve positioner's firmware in the middle. In an office the first is an inconvenience; in a plant the second parts a pipe and releases its contents. The ranking is inverted.
Physical processes do not fail in proportion to the push. A reactor holds a stable point until a parameter crosses a threshold and it stops existing. Cyber compromise changes that parameter; past the threshold the time to rupture is finite, integrable exactly, shortening as the square root of the push.
Two cases are worked. On a 140 kW direct-to-chip cooling loop, stopping the coolant pump empties the manifold heat sink in just over three seconds, and silicon crosses its destruction temperature. At a 250 MW battery site, an injected phase angle offset drives the inverter bridge into pole slipping inside eighty milliseconds.
The kinetic blast radius is the set of objects coupled to the compromised component, reached along control and supply relations in their declared direction, undiminished through mechanical control and stopped dead at a certified relief device or air-gapped interlock. Priced at replacement cost plus lost revenue over rebuild time, they give the actuarial terms a physical-damage cyber policy requires.
Abstract#
This treatise establishes the mathematical physics foundation of G_CPDT, formalizing cyber parameter tampering and physical runaway as a saddle-node bifurcation. The asset state obeys an autonomous differential equation with a stable equilibrium; a shift in the parameter vector destroys it through the fold bifurcation, whose normal form collapses two equilibria to none. The time to divergence is a convergent improper integral in closed form, scaling inversely with the square root of the perturbation, so collapse is deterministic and finite. On an exothermic reactor with jacket cooling, Arrhenius generation against linear removal yields the Semenov thermal explosion, crossing a vessel burst rating in single-digit seconds. The kinetic blast radius is the subgraph of entities coupled to a compromised component, reached along part-of, controls and supplies edges in the declared direction, monitoring not reversible; coupling multiplies per-edge attenuation weights, unity for mechanical control and zero for a certified burst disc or air-gapped interlock, each priced at replacement cost plus revenue loss over rebuild time. The metric yields the actuarial terms a physical-damage cyber policy requires under Lloyd's Market Bulletin Y5381: single loss expectancy as the kinetic blast radius, annualized loss expectancy scaled by a threat frequency, and a return on security investment for a coupling-eliminating mitigation.
1. Scope#
Information technology cybersecurity assesses risk using static, linear severity scoring frameworks. The Common Vulnerability Scoring System (CVSS) [1] computes a base score between 0.0 and 10.0 derived from exploit vectors, attack complexity, privileges required, and confidentiality, integrity, and availability impacts.
In industrial cyber-physical systems (CPS) and operational technology (OT), CVSS fails catastrophically. A buffer overflow vulnerability in a corporate printer web server may register an alarming CVSS 9.8 (Critical), while a parameter truncation flaw in a valve positioner firmware registers an apparently modest CVSS 6.5 (Medium). In physical systems, the printer vulnerability creates administrative inconvenience, whereas the valve positioner flaw allows an adversary to induce fluid hammer, hydraulic shock waves exceeding 180 bar, pipe severance, and catastrophic toxic atmospheric discharge.
Traditional risk management evaluates consequence as a linear function of asset criticality and exploit likelihood:
Physical infrastructure does not fail linearly. Industrial processes governed by thermodynamics, fluid dynamics, and electromechanics exhibit smooth, stable behavior across wide operating regions until a parameter threshold is crossed. At that threshold, known mathematically as a bifurcation point, stable operating equilibria vanish, plunging the system into irreversible kinetic runaway.
This treatise (Designation P8, dynamic consequence and mathematical physics foundations of G_CPDT) establishes the mathematical physics foundation of the G_CPDT standard. It formalizes the coupling between cyber parameter tampering and physical runaway via normal-form saddle-node bifurcation dynamics. It demonstrates how the G_CPDT multigraph topology enables the automated calculation of the Kinetic Blast Radius (), providing the quantitative input required for physics-grounded cyber underwriting in a market whose stand-alone cyber-attack policies carry the state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 requires [2].
This document is licensed under the Creative Commons Attribution 4.0 International licence (CC BY 4.0) [3] for submission to the IEEE Systems, Man, and Cybernetics Society, the Society for Risk Analysis, and the Lloyd's Market Association.
2. Mathematical Dynamics of Saddle-Node Bifurcations#
Let the continuous state of an industrial physical asset (e.g., fluid temperature, reactor pressure, rotor angle) be described by a generalized non-linear state variable . The physical evolution of the asset is governed by an autonomous differential equation parameterized by a set of control inputs and ambient conditions :
In a nominal operating regime, the physical asset maintains an asymptotically stable equilibrium point where and the Jacobian derivative satisfies:
2.1 The Normal-Form Saddle-Node Bifurcation#
When an adversary alters control logic, overrides sensor feedback, or manipulates actuator setpoints via a cyber compromise, the parameter vector shifts from to a perturbed state . In non-linear systems theory, the generic mechanism by which an equilibrium point disappears is a saddle-node (or fold) bifurcation [4].
Expanding via Taylor series in the neighborhood of the bifurcation point and applying coordinate transformation yields the universal normal form:
where is the bifurcation parameter directly modulated by cyber intervention.
Three distinct dynamical regimes emerge depending on the sign of :
- Subcritical Regime (): The system possesses two distinct equilibria:
The point represents the stable operational baseline (e.g., nominal reactor operating temperature). The unstable saddle defines the boundary of the basin of attraction. If an operational perturbation remains within , the system returns asymptotically to .
- Critical Threshold (): The stable node and unstable saddle collide and annihilate one another in a saddle-node bifurcation. The equilibrium state is marginally stable:
- Supercritical Runaway Regime (): No real equilibrium points exist. The vector field is strictly positive everywhere:
In this regime, the system undergoes irreversible kinetic runaway. The time required for the state variable to diverge from an initial state to physical rupture () is strictly finite and calculable by direct integration:
Evaluating the definite integral yields the finite runaway time:
When the initial state sits near the former equilibrium (), the formula simplifies to the universal scaling law:
This equation proves that physical collapse in compromised infrastructure is not an asymptotic process; it occurs within a deterministic, finite time horizon inversely proportional to the square root of the cyber perturbation magnitude.
3. Coupling Cyber State Modulations to DEXPI Process Kinetics#
In the G_CPDT multigraph , a cyber component bound by a directed edge to physical asset directly controls the operational parameters of .
Consider an exothermic chemical reactor vessel described in DEXPI 2.0 with jacket cooling. The internal temperature and reactant concentration evolve according to the coupled balance equations:
where is volumetric flow rate, is vessel volume, is the pre-exponential factor, is activation energy, is heat of reaction, and is cooling jacket temperature.
The cooling jacket temperature is controlled by an industrial cooling water valve whose position is dictated by an embedded PID controller firmware component. If an adversary introduces malicious firmware modifying the control register such that (starving cooling flow), the heat removal term collapses:
The generation term is an exponential function of temperature (Arrhenius kinetics), while heat dissipation is linear. This creates the classic Semenov thermal explosion bifurcation [5]. As the cyber control parameter passes zero, pressure generation inside the sealed vessel accelerates according to the Clausius-Clapeyron relation:
Exceeding the mechanical burst pressure of the pressure vessel (typically 40 bar) occurs in under 8.4 seconds, well before human operators or supervisory SCADA telemetry can intervene.
4. The Kinetic Blast Radius Formulation ()#
The multigraph topology defined in Paper P4 enables the systematic calculation of the Kinetic Blast Radius. The Kinetic Blast Radius is not a geographic boundary; it is the subgraph of all physical and electrical entities whose stability state is strictly coupled to a compromised cyber component.
4.1 Vertex Coupling and Attenuation#
Let be a compromised component. We define the directed reachability subgraph formed by all paths originating at following valid semantic edge traversals:
In accordance with Invariant E-13, edges of type cannot be traversed in reverse.
For each reachable physical asset , the kinetic coupling coefficient is computed as the product of edge transfer efficiencies along the shortest active path:
where is the physical attenuation weight:
- for direct mechanical control ();
- for unbroken fluid or electrical conduction ();
- if an air-gapped manual interlock or certified mechanical burst disc intervenes.
4.2 The Quantitative Blast Metric#
The Kinetic Blast Radius is defined as the summed asset value and replacement liability of all coupled physical infrastructure weighted by kinetic susceptibility:
where is the physical replacement cost, is daily revenue loss, and is expected rebuild time in days.
5. Sector Case Studies#
Two cases are given, one thermal and one electrical. Each states the component compromised, the physical or electrical topology it sits in, the horizon over which the runaway completes, and the kinetic blast radius that follows from the coupled assets and their replacement and interruption costs.
5.1 High-Density AI Datacenter Case (140 kW Direct-to-Chip Cooling)#
- Target Component: Firmware in the Coolant Distribution Unit (CDU) secondary pump variable frequency drive (
bom-ref: vfd-fw-cdu-01). - Physical Topology: DEXPI 2.0 model describing direct-to-chip manifold supplying 32 server blades dissipating 140 kW thermal design power.
- Runaway Horizon: Coolant flow cessation () depletes the internal manifold heat sink within 3.2 seconds. Liquid boiling at the cold-plate interface induces dry-out bifurcation at . Silicon die temperatures reach the emergency hardware shutdown trip point () at .
- Kinetic Blast Radius: Loss of 32 AI accelerators (1.28 million USD replacement) plus two weeks cluster downtime (4.2 million USD business interruption). Total .
5.2 Regional Power Substation Case (BESS 250 MW Grid Coupling)#
- Target Component: IEC 61850 MMS gateway firmware managing inverter synchronization (
bom-ref: mms-gw-bess). - Electrical Topology: IEC 61970 CIM model connecting 250 MW / 1,000 MWh battery racks through 33 kV / 400 kV step-up transformers to the transmission grid.
- Runaway Horizon: Malicious phase angle offset injection desynchronizes the inverter bridge from the utility voltage vector. At phase displacement , generator torque crosses into unstable deceleration, initiating a pole-slipping transient within 80 milliseconds and triggering cascaded differential overcurrent tripping across four substation breakers.
- Kinetic Blast Radius: Transformer thermal damage and regional blackout impact spanning 180,000 residential and industrial meters. Total .
6. Actuarial Formulations and Insurance Underwriting (Lloyd's Y5381)#
Underwriting industrial property and cyber catastrophe risk requires transitioning from subjective surveys to empirical physics models. Lloyd's Market Bulletin Y5381, issued by the Corporation of Lloyd's on 16 August 2022, requires that stand-alone cyber-attack policies written or renewed from 31 March 2023 exclude losses arising from war and from state-backed cyber attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state [2]. What remains inside cover is physical consequence, and it is that consequence an underwriter has to size.
By computing the Kinetic Blast Radius over Schema G_CPDT, underwriters derive exact actuarial terms:
6.1 Single Loss Expectancy (SLE)#
The Single Loss Expectancy for a given cyber vulnerability disclosure is bounded by the Kinetic Blast Radius:
6.2 Annualized Loss Expectancy (ALE)#
Incorporating the scored threat frequency from the TACAM / ATQ adversary modeling framework [6]:
6.3 Return on Security Investment (ROSI)#
The actuarial return on implementing an architectural mitigation (such as inserting a hardware-enforced unidirectional diode or physical pressure relief valve, reducing to 0) is calculated as:
This formula provides corporate boards and chief risk officers with mathematically defensible investment justification, grounding cybersecurity expenditure directly in capital asset preservation.
7. References#
- FIRST. Common Vulnerability Scoring System v3.1: Specification Document. Forum of Incident Response and Security Teams, 2019.
- Lloyd's. Market Bulletin Y5381: Cyber-attack exclusions. Corporation of Lloyd's, London, 16 August 2022. The model wordings drafted to meet it are the Lloyd's Market Association's clauses LMA5564 to LMA5567, November 2021.
- Creative Commons. Attribution 4.0 International (CC BY 4.0) Legal Code. Creative Commons Corporation, 2013.
- Strogatz, S. H. Nonlinear Dynamics and Chaos: With Applications to Physics, Biology, Chemistry, and Engineering. 2nd edition, Westview Press, Boulder, CO, 2015.
- Semenov, N. N. Chemical Kinetics and Chain Reactions. Oxford University Press, Oxford, 1935.
- McKenney, J. TACAM: Threat Actor Capability and Attack Modeling in Cyber-Physical Operational Infrastructure. Working Group WG-07-TM Treatise, Eigenia Labs, 2026.