Skip to content
Paula Livingstone writing · projects · tools

Projects

Attestable

When probabilistic AI feeds safety-critical systems, unproven output can drive physical action unchecked. Attestable is a discipline for marking a claim's basis, so it cannot.

OT SecurityCyber-Physical AssuranceIEC 62443ProvenanceSafety CaseLLM Agents

Readings: Supply Chain and OT

5 entries

Readings on where software integrity becomes physical, and the learned OT boundary. Feeds the review chapter's fourth section.

  1. Reading: Supply-Chain Integrity and Its Limit The first of the two intertwined field surveys. Software supply-chain security is organized around transparency, validity, and separation. Its validity property establishes an unchanged, authorized artefact, not a correct or fit one, which leaves admissibility open in the field's own words.
  2. Reading: Where Integrity Becomes Physical The second field survey and the point of fusion. OT security inverts IT priorities (safety first) because its actions are physical and irreversible. It meets supply-chain integrity at the safety boundary, where the Triton case records an unverified diagnosis promoted to fact and acted on.
  3. Reading: Where Attestable Sits in OT Security A positioning entry, not another OT survey. OT security is layered perimeter defence built on Purdue zones, and it asks one question: is this crossing authorised. Admissibility is orthogonal to it, asking whether a value's basis suffices to act on. Attestable is not a perimeter layer but a gate at the cyber-physical boundary the perimeter waves values through.
  4. Reading: The Learned Perimeter OT segregation is increasingly enforced by machine learning: the boundary monitor is a learned intrusion detector or anomaly scorer, and the state estimate is guarded by ML false-data-injection detectors. But a learned perimeter emits a score, not a basis, and can be walked across by adversarial design (Random Forest and J48 accuracy fell 16 and 20 points under attack). Moving the firewall to ML relocates the admissibility gap; it does not close it.
  5. Reading: When the Model Makes the Decision When machine learning makes or shapes an OT control decision, every safeguard the field reaches for lands somewhere other than admissibility. Safe reinforcement learning constrains actions probabilistically but cannot warrant a single one; state estimation can be corrupted beneath the controller without tripping its checks; and the trust layer bolted on top is post-hoc explanation, which describes the model rather than justifying the irreversible act it triggers.