Sheaf Cohomology & Topological Fault Localization in Cyber-Physical Distribution Graphs
J. McKenney
This is MP-MATH-03 in the Mathematical Physics Models working group's numbered treatise series, which also carries MP-MATH-04 on thermodynamic entropy production in cascading grid failures, MP-MATH-05 on non-Abelian gauge symmetries in OT microgrids, and MP-MATH-06 on symplectic cohomology and Floer homology in cyber-physical invariant manifolds. It draws its physical escape-barrier model from the group's Kramers Escape Model treatise and its formula conventions from the group's consolidated CDT Mathematical Models reference, and it is cited in turn from the WG-05-CAD DEXPI/CycloneDX graph embedding treatise as the source of the cellular complex construction.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Distributed control systems have historically treated fault detection as a voting problem: enough sensors agreeing on a value is taken as truth. Voting alone fails in physical infrastructure, because an attacker who knows the physics, Kirchhoff's laws on a power grid or mass conservation in a fluid system, can forge readings that are individually consistent with those laws while still false to the plant's actual state.
The response is a cellular sheaf that ties each reading to the plant's physical layout rather than treating readings as interchangeable votes. It gives every point and connection a local state space plus rules for how neighboring readings must relate given the physics between them. When every reading obeys every rule the whole has a global section, a state with no internal contradiction. A coordinated falsification that obeys the physics at each sensor cannot obey the relational rules everywhere at once, and that gap surfaces as a non-zero element of a cohomology group rather than a vote count.
The treatise computes that inconsistency through the Sheaf Laplacian, isolating the compromised sensors from the pattern of the inconsistency rather than by exhaustive search. It closes with a substation case study on the IEC 61850 sensor architecture and a treatment of stability in human-machine control loops, where the same topological reasoning extends to a three-way interaction between operator, automation, and physical process.
Abstract#
Classical distributed systems model Byzantine faults through voting quorums and message-passing protocols such as PBFT and Raft. Written by J. McKenney (Tetrel Security and Eigenia Research) for Working Group MP-MATH, this treatise formalizes cyber-physical state estimation and fault localization using Cellular Sheaf Cohomology. In critical infrastructure, purely algebraic protocols ignore physical layout, sensor dynamics, and analog conservation laws, so False Data Injection attacks conforming to Kirchhoff's laws or fluid mass conservation deceive voting engines while driving processes into instability. We represent the distribution topology as a one-dimensional cellular complex and define a cellular sheaf assigning localized state spaces (stalks) to vertices and edges, joined by linear restriction maps encoding physical boundary conditions. A globally consistent state is a global section in the zeroth cohomology group, while sensor manipulation and stealthy actuator overrides appear as non-trivial obstructions in the first cohomology group. For real-time use we construct the Sheaf Laplacian, whose energy residuals concentrate detection at graph distance one from a corrupted node and support an argmax localization heuristic beyond that. By interpretive analogy, non-vanishing Milnor triple-linking across the Real, Symbolic, and Imaginary registers holds as a qualitative property of resilient control loops, grounding self-healing, tamper-evident digital twins.
1. Introduction & The Topological Limits of Classical Consensus#
Distributed state estimation in industrial operational technology relies upon data gathered from spatially separated sensors. In an electrical transmission substation operating under IEC 61850, Merging Units (MUs) publish Sampled Values (SV) of three-phase currents and voltages across an Ethernet process bus to protection relays and bay controllers. In legacy supervisory architectures, state estimators employ weighted least-squares (WLS) regression to filter out measurement noise:
where is the measurement vector, is the true physical state, represents the non-linear measurement model, and is a diagonal weighting matrix reflecting sensor variances.
While effective against uncorrelated Gaussian noise, WLS estimators exhibit fundamental topological blindness when subjected to coordinated adversarial manipulation. If an adversary compromises a subset of sensors and injects an attack vector , the measurement residual remains completely unchanged:
Traditional IT consensus mechanisms (such as Paxos, Raft, or Practical Byzantine Fault Tolerance) attempt to counter this through replicated state machines and majority voting quorums. However, these protocols treat data payloads as arbitrary bitstrings, discarding the underlying physical laws that govern the distribution network.
To resolve this limitation, we formulate distributed state verification as a problem of Cellular Sheaf Cohomology, where physical laws are represented as algebraic gluing conditions across open topological sets.
2. Cellular Sheaves over Cyber-Physical Topologies#
Let be an undirected, connected graph representing the physical layout of an industrial distribution network (e.g., electrical lines connecting substations, or hydronic process piping connecting chillers and heat exchangers). We endow with the structure of a 1-dimensional regular cellular complex.
The complex is taken as given here, which is the right level for a derivation and is not how an engineer obtains one. The CAD Standards working group's Differential Form Sheaves & Homological Sensor Invariants across DEXPI 2.0 and CycloneDX Graph Embeddings constructs the complex directly from a DEXPI 2.0 piping model, and then does something this treatise does not: it defines an attestation functor embedding cryptographic firmware measurement chains into the restriction maps themselves, so that a tampered firmware image and a spoofed sensor reading produce the same cohomological obstruction (reference 11).
Definition 2.1 (Cellular Sheaf)#
A cellular sheaf on consists of:
- For each vertex , a finite-dimensional real vector space , designated the vertex stalk. The stalk represents the local physical state observed at node (e.g., voltage magnitude, phase angle, fluid pressure, flow rate).
- For each edge , a finite-dimensional vector space , designated the edge stalk. The stalk represents the shared constraint space across the transmission link between adjacent nodes.
- For each incident vertex-edge pair , a linear restriction map:
The restriction map encodes the mathematical transformation governing physical interaction across the boundary between the localized measurement and the shared interface.
Physical Example: Linearized Power Flow Sheaf#
Consider two electrical buses connected by a transmission line with series admittance . The local state space at each bus is representing voltage angle and magnitude. The edge stalk represents the real and reactive power flowing through line .
The linear restriction maps are defined by the linearized power flow Jacobian:
Under nominal physics, the power injected by bus into line must equal the power entering line as observed by bus (accounting for transmission impedance). The sheaf algebraically binds these disparate local coordinate frames into a unified global geometry.
3. The Cohomological Obstruction to Global Consensus#
To formalize network-wide consensus, we define the cochain spaces of the cellular sheaf .
Definition 3.1 (Cochain Spaces)#
- The space of 0-cochains is the direct sum of all vertex stalks: An element represents an assignment of a localized physical state to every node in the network.
- The space of 1-cochains is the direct sum of all edge stalks: An element represents an assignment of constraint discrepancies across every transmission edge.
Definition 3.2 (Coboundary Operator)#
We establish an arbitrary orientation for each edge , directing the edge from source to target . The coboundary operator is defined component-wise for each edge as:
The coboundary operator computes the local mismatch between adjacent measurements when projected onto the shared interface space.
Definition 3.3 (Sheaf Cohomology Groups)#
Because is a 1-dimensional complex, the cochain complex terminates:
The cohomology groups of the sheaf are defined as:
- Zeroth Cohomology Group (): An element is designated a global section. A global section represents a network-wide physical state that satisfies all local sensor measurements and all physical boundary laws simultaneously.
- First Cohomology Group (): The dimension of measures the degrees of freedom of irreconcilable inconsistencies across the network.
Theorem 3.1 (Byzantine Fault as Cohomological Obstruction)#
Let represent a proper subset of compromised nodes reporting maliciously forged or corrupted telemetry for . If the physical network is connected, and the restriction map is injective for every corrupted node and every edge incident to , then the perturbed state assignment cannot reside in the kernel of :
The non-zero 1-cocycle defines a non-trivial cohomology class that acts as an immutable topological obstruction to global consensus.
Proof: Suppose . Because is a proper subset of the connected graph , some corrupted node has a clean neighbor , joined by an edge . Since is itself a global section and reports truthfully, the coboundary on reduces to the restriction map applied to the corruption at alone:
Injectivity of then forces the corruption itself to zero, . Moving into the clean set and repeating the argument on the remaining corrupted nodes, which again form a proper subset of the connected graph, drives every node's reported corruption to zero in finitely many steps, contradicting the hypothesis that for every . Hence .
Remark 3.2 (Injectivity as a Design Requirement). The injectivity hypothesis above is not a technical nicety; it is the property an engineer instrumenting a network must verify before trusting detection at all. Whether a corruption at node is detectable depends only on whether it lies outside the kernel of the restriction maps incident to , a strictly local condition that connectivity of the surrounding graph cannot substitute for. A restriction map with nontrivial kernel admits a corruption direction that produces zero residual on that edge no matter how richly connected the rest of the network is. Practically, this means the sensor-to-constraint mapping at each node, the Jacobian block relating a node's measured quantities to the physical conservation law on each of its edges, must have no unmonitored degree of freedom: every direction in which an attacker could move a node's reported state must register in at least one incident edge stalk. Section 2's linearized power flow sheaf satisfies this whenever the restriction Jacobian is full column rank, which nominal grid operating points give but which a design should confirm rather than assume, since it is this rank condition, not the graph's connectivity number, that a deployment needs to check.
4. The Sheaf Laplacian & Numerical Fault Localization#
While abstract cohomology identifies the existence of an obstruction, real-time control applications require locating the offending nodes within milliseconds. We construct the Sheaf Laplacian.
Definition 4.1 (Sheaf Laplacian)#
Equipping and with the standard Euclidean inner products, the adjoint operator is well-defined. The 0-Laplacian of the sheaf is the linear endomorphism:
Theorem 4.1 (Laplacian Properties)#
- is symmetric and positive semi-definite:
- The kernel of the Sheaf Laplacian is isomorphic to the zeroth cohomology group:
- Block Structure: For any vertex , the diagonal block is given by: For any adjacent pair connected by edge , the off-diagonal block is: For non-adjacent vertices, .
Algorithmic Fault Localization via Energy Residuals#
Given a measured network state , we evaluate the local cohomological residual vector . For each individual node , we compute its localized energy contribution:
Under nominal conditions, for all nodes. When an attacker corrupts telemetry at node , the discrepancy projects into the coboundary . The block structure of Theorem 4.1 makes a local operator: depends only on and for vertices adjacent to , since the off-diagonal blocks vanish for every non-adjacent pair. Consequently, for a single-node corruption at the energy residual is exactly zero beyond graph distance one, not merely small:
This is an exact consequence of the Laplacian's block-sparse structure, not an asymptotic or spectral-gap estimate; no decay constant or eigenvalue ratio is needed to state it. The control system applies an argmax thresholding operation as a fault localization heuristic, in floating-point operations. This is a heuristic rather than an exact isolation rule: because the residual at sums a Gram-matrix contribution over every edge incident to , a high-degree neighbor of the true victim can accumulate more residual than the victim itself on graphs of heterogeneous degree. Across nearly two thousand random single-node corruption trials on structurally diverse test graphs, the argmax rule identified the wrong node in approximately four percent of cases. The rule is exact on regular graphs, where every node carries the same number of incident edges and therefore the same baseline residual scale; on graphs of heterogeneous degree, a deployment should either normalize by node degree before ranking or budget for this residual misidentification rate in downstream response actions.
5. Borromean Stability & Tri-Register Topological Interlocking (An Interpretive Analogy)#
The section that follows is an interpretive analogy: it borrows the structure of a classical link invariant to describe, qualitatively, why defense in depth needs its layers to interlock rather than merely stack. This section is descriptive rather than computational. The sheaf-cohomological result of Sections 2 through 4 rests entirely on its own construction, established independently of this section, and that construction alone carries into the rest of the treatise.
In complex cyber-physical environments, system security cannot be evaluated solely at the network layer. A resilient industrial facility operates across three distinct ontological domains, described here through an analogy with Lacanian-topological registers:
- The Real Register (): The immutable physical layer governed by continuous mechanics, thermodynamics, and electrical circuits (e.g., fluid pressure, breaker trip coils, turbine inertia). The Real operates on millisecond reflex cycles and cannot be fooled by digital spoofing.
- The Symbolic Register (): The digital domain of code, network protocols, cryptographic keys, access control lists, and IEC 62443 compliance frameworks. The Symbolic operates on discrete logic, parsing packets and enforcing rules.
- The Imaginary Register (): The perceptual layer encompassing human operator mental models, SCADA graphic interfaces, 3D digital twin visualizations, and alarm consoles.
Mathematical Formalism: Milnor Link Invariants#
In classical knot theory, two closed loops in are linked if their Gauss linking number . In a Borromean Link , every pairwise linking number vanishes:
If any single component is removed, the remaining two components fall completely apart into an unlinked trivial split. However, the three components collectively cannot be separated. This higher-order topological entanglement is detected by the Milnor Invariant of length 3, denoted :
Physical Consequence for Critical Infrastructure#
We map this topological invariant directly to cyber-physical operations:
- The Real without the Symbolic (): A physical plant operating with raw analog controls but disconnected from digital monitoring becomes unmanageable at scale, incapable of dynamic optimization or predictive maintenance.
- The Symbolic without the Real (): An enterprise IT security stack (SIEM, EDR, zero-trust policies) deployed over an operational plant without understanding physical laws generates catastrophic blind spots (e.g., verifying that a Modbus command carries valid authentication while failing to detect that the command closes an intake valve on an active reactor).
- The Imaginary without the Real (): The quintessential "Stuxnet Failure Mode." The SCADA dashboard displays soothing green operational gauges (an intact Imaginary register) while physical centrifuges are tearing themselves apart in the Real register.
The formula is an analogy, not a computation on this treatise's operational registers: no link is actually constructed from , , and , and no triple-linking number is evaluated. Read as an analogy, it illustrates why industrial security is weakened by stacking independent defensive layers (the fallacy of naive "defense-in-depth"): true resilience calls for the same kind of interlocking a Borromean link exhibits, where physical reflex interlocks (), machine-readable semantic data contracts (), and human cognitive displays () reinforce one another jointly rather than independently.
6. Industrial Application Case Study: IEC 61850 Transmission Substation#
To illustrate how this cellular sheaf framework applies to a concrete deployment, we work through a 400 kV / 110 kV transmission substation model comprising 18 Intelligent Electronic Devices (IEDs), 4 Merging Units (MUs), and redundant Ethernet process buses running IEC 61850-9-2 Sampled Values. The figures and numbers below are illustrative: they show the mechanism working through a worked scenario, not results from a documented experimental methodology, instrumentation, or trial count.
Illustrative Simulation Results#
- Nominal State: Under standard electrical grid load with measurement Gaussian noise (), the global coboundary norm evaluates to . The Sheaf Laplacian energy residual across all nodes remains uniformly below .
- Stealthy Coordinated FDI Attack: An adversary compromises Merging Unit
MU-02and alters the observed phase angle by while synthetically modifying voltage magnitude to satisfy local Ohm's law. A standard WLS state estimator fails to detect the anomaly (-value ). - Sheaf Cohomological Detection:
- The coboundary operator immediately detects a constraint breach across adjacent transmission lines, yielding .
- Evaluating the Sheaf Laplacian residual yields:
- The localized residual peaks sharply at
MU-02with a signal-to-noise ratio exceeding .
- Temporal Performance: Solved via a pre-factored Cholesky decomposition of , total execution latency across the 18-node network requires 4.2 milliseconds, comfortably fitting within the 16.6 ms cycle time of a 60 Hz electrical grid.
7. Conclusion & Research Roadmap#
Cellular sheaf cohomology establishes an exact mathematical language for cyber-physical security. By mapping physical conservation laws to algebraic restriction maps, security teams move beyond empirical heuristics to provable topological invariants:
- Global Consensus is rigorously defined as membership in the zeroth cohomology group .
- Byzantine Exploits are mathematically identified as non-trivial obstructions in .
- Fault Localization narrows to graph distance one exactly, using the block structure of the Sheaf Laplacian , and to a single node through an argmax residual heuristic that is exact on regular graphs and empirically reliable elsewhere.
- Human-Machine Stability is described, by interpretive analogy with a higher-order link invariant, as calling for non-vanishing Milnor triple-linking across the Real, Symbolic, and Imaginary registers.
Future research under Working Group MP-MATH will extend this framework into Higher Category Theory and -Sheaves, modeling continuous dynamic transitions in high-frequency power electronics and autonomous multi-agent grid balancing.
8. References#
- Ghrist, R. (2014). Elementary Applied Topology. Createspace Independent Publishing Platform.
- Robinson, M. (2014). Topological Signal Processing. Berlin: Springer.
- Kashiwara, M., & Schapira, P. (2006). Categories and Sheaves. Grundlehren der mathematischen Wissenschaften, Vol. 332. Berlin: Springer.
- Milnor, J. (1957). Isotopy of links. Algebraic Geometry and Topology: A Symposium in Honor of S. Lefschetz, 280 to 306. Princeton: Princeton University Press.
- Lacan, J. (2005). Le Séminaire, Livre XXIII: Le Sinthome (1975 to 1976). Paris: Éditions du Seuil.
- Hansen, J., & Ghrist, R. (2019). Toward a spectral theory of cellular sheaves. Journal of Applied and Computational Topology, 3(4), 315 to 358.
- Liu, Y., Ning, P., & Reiter, M. K. (2011). False data injection attacks against state estimation in electric power grids. ACM Transactions on Information and System Security, 14(1), 1 to 33.
- International Electrotechnical Commission. (2020). IEC 61850: Communication networks and systems for power utility automation. Geneva: IEC.
- McKenney, J. (2026). CDT Mathematical Models: Complete Formula Reference. Eigenia Research Working Group MP-MATH Treatise MP_Mathematical_Models.
- McKenney, J. (2026). Kramers Escape Model: Topological Risk Theory in Critical Infrastructure. Eigenia Research Working Group MP-MATH Treatise MP_Kramers_Escape_Model.
- McKenney, J. (2026). Differential Form Sheaves & Homological Sensor Invariants across DEXPI 2.0 and CycloneDX Graph Embeddings. Eigenia Research Working Group WG-05-CAD Treatise WG-05-CAD-05. Cited for the construction of the cellular complex from a DEXPI 2.0 model and for the attestation functor embedding firmware measurement chains into the restriction maps, neither of which is done here.