{"id":"08d496f6-45ca-405e-87f7-133e2b497f31","arxiv_id":"2606.20301","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":7.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"Poisoned data makes standard DeePC non-informative for worst-case guarantees, but Secure DeePC achieves MPC-equivalent performance in finite time almost surely by using only protected data until persistent excitation then reconstructing the rest.","lead":"This paper shows that poisoned offline data cannot be detected from the dataset itself and renders standard data-driven control non-informative for worst-case performance guarantees, then introduces Secure DeePC that phases between protected data and online reconstruction to restore guarantees. Smart generalists and control engineers should read it because data poisoning is a realistic threat to any system that learns controllers from stored measurements.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.3","headline":"Whether output-truncated DeePC (using only protected data) guarantees eventual persistent excitation of the online input is unproven and potentially circular.","rationale":"The reader's weakest assumption is exactly the load-bearing step; the abstract-only review already flags it correctly. Full-text inspection would be needed only to see whether the paper supplies additional conditions that close the gap, but the abstract itself gives no indication that such conditions are stated or verified.","tokens_in":1643,"tokens_out":307,"duration_ms":14522,"concrete_test":"Take the simplest LTI system and protected dataset for which the paper's limitations apply (rank-deficient output data). Simulate the output-truncated DeePC law for 10^4 steps and check whether the online input Hankel matrix ever reaches full row rank; if it remains rank-deficient on a positive-measure set of initial conditions, the reconstruction step cannot be invoked almost surely.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The central claim requires that, while running output-truncated DeePC on the protected subset alone, the closed-loop input sequence eventually becomes persistently exciting (so that the partial offline dataset can be reconstructed from online measurements). The paper's own fundamental limitations section states that unprotected outputs are non-informative for worst-case controller design; the truncated law therefore operates with strictly less information. No argument is supplied showing that this reduced-information feedback law still produces the required rank condition on the input Hankel matrix in finite time for arbitrary plants.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper identifies three fundamental limitations for data-driven control when a subset of offline output measurements can be arbitrarily poisoned: poisoning cannot be detected from the dataset alone, unprotected outputs are non-informative for worst-case controller synthesis, and hard output constraints on unprotected channels cannot be certified. Motivated by these, it proposes Secure DeePC, which first applies output-truncated DeePC using only the protected data subset until the online input sequence becomes persistently exciting, reconstructs the partial offline dataset from online measurements, and then switches to standard full-output DeePC. The central claim is that this procedure achieves MPC-equivalent closed-loop performance in finite time almost surely, under certain (unspecified in the abstract) conditions; efficacy is illustrated via simulations.","tokens_in":1747,"tokens_out":556,"duration_ms":19172,"significance":"If the finite-time almost-sure performance guarantee can be rigorously established, the work would be significant for practical deployment of data-driven predictive control in security-sensitive settings. The explicit cataloguing of fundamental limitations provides a useful conceptual contribution that clarifies why standard DeePC is vulnerable and motivates the truncated-then-reconstruct strategy.","major_comments":[{"comment":"The reconstruction step and the finite-time performance claim both rest on the assertion that output-truncated DeePC (operating with strictly less information) eventually renders the online input persistently exciting. The fundamental-limitations section already shows that unprotected outputs carry no information for worst-case design; no argument, rank condition, or set of plant assumptions is supplied showing that the reduced-information law still produces the required full-row-rank input Hankel matrix in finite time for arbitrary linear systems. This assumption is load-bearing for the entire Secure DeePC procedure.","section":"Abstract / Algorithm description"},{"comment":"The statement that Secure DeePC achieves MPC-equivalent performance in finite time almost surely is presented without any proof sketch, explicit conditions on the plant or noise, or error-bound analysis. The abstract supplies only the high-level claim; the absence of these elements prevents verification of the central theoretical result.","section":"Abstract / Performance claim"}],"minor_comments":[{"comment":"Simulation section should report quantitative metrics (e.g., closed-loop cost, constraint violation frequency) and explicit comparison against both nominal DeePC and MPC under the same attack realizations.","section":"Simulations"},{"comment":"Notation for the protected versus unprotected data partitions and the precise definition of the output-truncated Hankel matrices should be introduced with an equation or table early in the manuscript.","section":"Preliminaries"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the careful reading and constructive comments. We address each major comment below and will revise the manuscript to strengthen the theoretical support for Secure DeePC.","responses":[{"response":"We agree that the manuscript lacks an explicit argument, rank condition, or plant assumptions establishing that output-truncated DeePC produces a persistently exciting input in finite time. The fundamental-limitations section correctly identifies the non-informativeness of unprotected outputs, yet the algorithm relies on this property without dedicated analysis. In the revision we will add a proposition (with proof) specifying the required assumptions, such as controllability of the protected input-output subsystem, under which the truncated controller guarantees full row rank of the input Hankel matrix almost surely; this will be placed in the algorithm description section.","revision_made":"yes","referee_comment":"[Abstract / Algorithm description] The reconstruction step and the finite-time performance claim both rest on the assertion that output-truncated DeePC (operating with strictly less information) eventually renders the online input persistently exciting. The fundamental-limitations section already shows that unprotected outputs carry no information for worst-case design; no argument, rank condition, or set of plant assumptions is supplied showing that the reduced-information law still produces the required full-row-rank input Hankel matrix in finite time for arbitrary linear systems. This assumption is load-bearing for the entire Secure DeePC procedure."},{"response":"The abstract indeed states the performance claim at a high level without conditions or sketch. While the body contains a theorem on finite-time almost-sure equivalence, we acknowledge that a self-contained proof sketch, explicit plant/noise assumptions, and reconstruction error bounds are not provided in sufficient detail. We will revise the abstract to mention the key conditions (linear dynamics, bounded noise, persistent excitation) and add an expanded proof outline together with error-bound analysis in the main text or appendix.","revision_made":"yes","referee_comment":"[Abstract / Performance claim] The statement that Secure DeePC achieves MPC-equivalent performance in finite time almost surely is presented without any proof sketch, explicit conditions on the plant or noise, or error-bound analysis. The abstract supplies only the high-level claim; the absence of these elements prevents verification of the central theoretical result."}],"tokens_in":1408,"tokens_out":485,"duration_ms":21409,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The core contribution is the identification of three concrete limitations: poisoning cannot be detected from the dataset, unprotected outputs give no worst-case guarantees for controller design, and hard constraints on those outputs cannot be certified. From there the authors build Secure DeePC, which runs a truncated version on the protected data only until the online input sequence satisfies the persistent excitation condition, reconstructs the missing offline data from measurements, and then reverts to standard DeePC. This phased structure is a direct response to the limitations and avoids explicit attack detection.\n\nThe approach is practical for cyber-physical settings where some sensor data might be stored unprotected. The claim of MPC-equivalent performance in finite time almost surely is stated clearly, and the simulation results are said to support it.\n\nThe main gap is the missing argument that output-truncated DeePC will produce a persistently exciting input sequence in finite time for arbitrary plants. The paper itself notes that unprotected outputs are non-informative, so the truncated law operates with strictly less information, yet it still needs to meet the rank condition on the input Hankel matrix to enable reconstruction. No derivation or condition is supplied showing this occurs almost surely, which leaves the central recovery step unverified. Without that piece the performance guarantee rests on an assumption that may not hold in general.\n\nThe work is aimed at researchers in data-driven control and CPS security. It raises a security issue that earlier DeePC papers did not treat and gives a concrete algorithm, so it is worth sending to peer review even though the excitation argument needs strengthening.","headline":"The paper flags three real limits from poisoned outputs in DeePC and offers a phased Secure DeePC that switches after online inputs become exciting, but the excitation step under truncated control lacks a supporting argument.","tokens_in":2196,"tokens_out":394,"would_cite":false,"duration_ms":17926,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"Secure DeePC recovers equivalent performance to model predictive control from poisoned offline data in finite time.","keywords":["data-driven control","poisoning attacks","DeePC","secure control","model predictive control","persistent excitation","output constraints"],"falsifier":"An experiment where the online inputs fail to become persistently exciting under the truncated law, preventing reconstruction of the offline data.","tokens_in":2548,"feed_emoji":"🛡️","tokens_out":527,"duration_ms":18691,"temperature":0.7,"pith_summary":"The paper shows that data-driven controllers cannot detect or mitigate poisoning attacks on offline output measurements from the data alone, rendering unprotected data useless for robust design and un-certifiable for hard constraints. To address this, it introduces Secure DeePC, which begins with a truncated version of data-enabled predictive control using only protected data until the online inputs become persistently exciting. It then reconstructs the missing data from online measurements and switches to the full DeePC law, achieving performance equivalent to model predictive control in finite time with probability one under the stated conditions.","feed_headline":"Secure DeePC restores MPC performance from poisoned data","feed_subtitle":"The method switches to a protected truncated controller until inputs allow full data reconstruction, achieving equivalent performance in fin","key_machinery":"The Secure DeePC algorithm, which switches from output-truncated DeePC to full DeePC after reconstructing poisoned data using online persistently exciting inputs.","core_discovery":"Secure DeePC achieves MPC-equivalent performance in finite time almost surely by first applying output-truncated DeePC on the protected dataset until the online input sequence becomes persistently exciting, then reconstructing the partial offline dataset from online measurements, and finally switching back to full-output DeePC.","pith_inferences":["This approach could extend to other data-driven methods beyond DeePC.","It suggests that online data collection can serve as a verification mechanism in adversarial settings.","Future work might explore minimal protection requirements for data storage."],"forward_implications":["Poisoning attacks cannot be detected solely from the offline dataset.","Unprotected data provide no worst-case performance guarantees for controller design.","Hard output constraints cannot be certified when data is unprotected.","The proposed algorithm restores full performance after finite time."],"fun_headline_variants":["Secure DeePC switches to truncated DeePC on protected data","Secure DeePC reconstructs partial dataset from online inputs","Secure DeePC reaches MPC equivalence after persistent excitation","Poisoned data limits addressed by phased Secure DeePC","Secure DeePC attains finite-time MPC performance under attacks"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"The online input sequence will eventually become persistently exciting while the system operates under the output-truncated DeePC controller.","fun_headline_variants_meta":{"raw":{"variants":["Secure DeePC switches to truncated DeePC on protected data","Secure DeePC reconstructs partial dataset from online inputs","Secure DeePC reaches MPC equivalence after persistent excitation","Poisoned data limits addressed by phased Secure DeePC","Secure DeePC attains finite-time MPC performance under attacks"]},"model":"grok-4.3","cost_usd":0.003234,"raw_usage":{"total_tokens":1700,"prompt_tokens":598,"num_sources_used":0,"completion_tokens":74,"cost_in_usd_ticks":32337000,"prompt_tokens_details":{"text_tokens":598,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1028,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":598,"tokens_out":74,"duration_ms":8583,"temperature":1.0,"reasoning_tokens":1028,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-26T16:08:04.981158+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"An experiment where the online inputs fail to become persistently exciting under the truncated law, preventing reconstruction of the offline data.","supporting_citations":[],"review_version":1}