REVIEW 2 major objections 4 minor 31 references
This paper defines exactly when a critical-infrastructure system counts as antifragile, and shows the two measurements needed to test it.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-03 04:46 UTC pith:VDSOL7L6
load-bearing objection A well-scoped, honest paper that establishes measurable prerequisites for antifragility testing; the HAI layer is solid, the CISSM layer is coding-dependent but acknowledged. the 2 major comments →
Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The central claim is that antifragility in critical infrastructure cybersecurity should be treated as a bounded, safety-constrained property that can be formally tested, not as a metaphor. The proposed criterion requires simultaneous positivity of Jensen gain—bounded volatility improves average performance—and post-disruption gain—the adapted configuration outperforms the original under the same stressor. The empirical results support the two prerequisites for applying this test: OT-adjacent sectors show significantly higher shares of disruptive or mixed events (65.3% vs 46.8%) and of physical or data attacks (40.9% vs 21.4%), and attack-labeled observations in the HAI dataset show larger pr
What carries the argument
The key machinery is a five-state Resilient System Model (fragile, reliable, robust, resilient, antifragile) paired with a bounded mathematical definition. The definition uses a utility or performance function over a bounded stressor distribution, with Jensen gain (Equation 2) measuring whether volatility helps on average and post-disruption gain (Equation 3) measuring whether an adaptation operator leaves the system better off. These feed a normalized Antifragility Score (Equation 6) combining Jensen gain, post-disruption gain, susceptibility reduction, and recovery improvement. The empirical work operationalizes the first two prerequisites—differentiated fragility burden and process-level
Load-bearing premise
The CISSM event labels are assumed to reflect real operational impact rather than reporting or coding artifacts, so the sector-level fragility differences hinge on that coding being accurate.
What would settle it
A re-coding of a random sample of CISSM events by independent coders, blinded to sector, that fails to reproduce the OT-adjacent vs non-OT difference would undermine the fragility-burden finding. Alternatively, if future work with attack-type labels in HAI shows that the declining deviation trend disappears when controlling for attack type, that would refute the suggestion of response variation consistent with adaptation.
If this is right
- If the criterion is adopted, resilience becomes a floor rather than a ceiling: systems that only bounce back are not antifragile, no matter how fast they recover.
- Sector-level fragility burden is not uniform, so improvement pathways likely differ: OT-adjacent sectors need process-aware monitoring and safe fallback, while information-centric sectors may benefit more from identity and recovery improvements.
- Process-level perturbation observability, as demonstrated in the HAI dataset, makes it possible to design adaptation-and-retest experiments where the same stressor is replayed after a documented change.
- Adaptive cybersecurity systems must show bounded improvement on the same stress class, not just that they updated; overfitting to a single event or shifting risk would not qualify.
- A valid antifragility test requires three elements: a bounded and repeatable perturbation, an explicit adaptation step, and a rerun demonstrating measurable improvement in susceptibility or recovery.
Where Pith is reading between the lines
- If the CISSM coding or reporting bias is systematic by sector, the 65.3% vs 46.8% contrast could partially reflect which events get publicly reported rather than true operational fragility; a blinded re-coding of a sample could test this.
- The declining deviation trend across attack windows might be driven by attack type heterogeneity rather than system adaptation; using attack-type labels (currently unavailable) could separate the two explanations.
- The formal criterion suggests a concrete operator practice: baseline telemetry, documented post-incident changes, and replayed perturbations would let any organization measure its own antifragility score without waiting for academic datasets.
- The framework implies that antifragility is domain-bounded—a system could be antifragile to one stressor family and fragile to another—so future tests should specify the stress class rather than claim global antifragility.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper develops a Theory of Antifragility (AFT) for critical infrastructure cybersecurity, anchored in a five-state Resilient System Model and a mathematical definition requiring positive Jensen gain (Eq. 2) and post-disruption gain (Eq. 3). It operationalizes two empirical prerequisites: differentiated fragility burden across sectors and process-level perturbation observability. Using a seven-sector CISSM subset, H1 and H2 show OT-adjacent sectors have higher disruptive/mixed and physical/data attack shares than non-OT sectors. Using the HAI 23.05 dataset, H3 shows attack-labeled windows have significantly larger process-state deviations, and an exploratory H4 documents declining mean deviation across attack windows, explicitly not interpreted as adaptation. The paper explicitly disclaims completed antifragility validation and positions itself as establishing measurable prerequisites.
Significance. If the result holds, the paper provides a rare combination of formal definition, theoretical taxonomy, and empirical grounding for antifragility in OT/ICS security. Strengths include the honest labeling of the HAI trend as exploratory, the use of appropriate nonparametric tests, the explicit separation of chaos engineering from antifragility, and the clear statement that no system is claimed to be antifragile. The layered design (sector-level events + process telemetry) is sensible. The main risk is the CISSM coding assumption, acknowledged in §7.1, which directly underpins the first prerequisite. The HAI layer is well supported and less dependent on coding judgments.
major comments (2)
- [§4.2, §5.1, Table 3] The first prerequisite, differentiated fragility burden, rests entirely on CISSM event-type and subtype labels. The §7.1 acknowledgment of public-event reporting bias and coder judgment is appropriate but insufficient. Without inter-coder reliability, independent validation, or sector-stratified sensitivity analysis, the contrasts (65.3% vs 46.8%; 40.9% vs 21.4%) may reflect reporting or coding artifacts rather than operational differentiation. This is load-bearing for the central claim. Please add a robustness section: blind re-coding of a random event sample, comparison to an independent incident database, and leave-one-sector-out analyses.
- [§4.2, Table 2] The OT-adjacent grouping is a single theory-driven partition, but the within-group heterogeneity is large. Transportation's physical/data share (29.3%) is close to non-OT Healthcare (32.5%), while Utilities and Manufacturing drive the contrast. The grouping is plausible but not validated. Report pairwise sector comparisons or a continuous OT-exposure measure to confirm that the aggregate result is not an artifact of one or two sectors.
minor comments (4)
- [§2.5, Eqs. (1)–(3)] The equations are not legible in the manuscript text (appear as blank placeholders). The formal definition is central to the theory, so the final version must display these equations correctly.
- [§4.3] Clarify whether baseline means and standard deviations are estimated from the training or test normal partition. Also specify the number of normal observations used for the 95th percentile thresholds.
- [§5.2, Figure 1] The figure caption and text should explicitly state axes and units. Currently the reader must infer that the y-axis is mean absolute z-score; make this explicit.
- [Throughout] Several symbols are garbled (e.g., 'Cram eU r's V', 'LoU pez-Corona'). A careful proofread and typesetting pass is needed.
Circularity Check
No significant circularity: the formal criterion is definitional and the empirical tests are independent of it.
full rationale
The paper's central formal criterion (Section 2.5) is presented as a definition of antifragility in terms of Jensen gain and post-disruption gain; it is not derived from the data, and the paper explicitly does not claim to estimate all score components. The CISSM-based hypotheses (H1, H2) test whether predefined sector groupings differ on externally coded event-type and subtype categories; the groupings are theory-driven and stated before the results, so the outcome is not constructed by the hypothesis. The HAI analysis uses baseline means, standard deviations, and a 95th-percentile threshold computed from normal operating data, then compares attack-labeled observations; no parameter is fitted to the attack labels or to the target finding. The declining trend across attack windows is explicitly labeled exploratory and 'not interpreted as evidence of adaptation' (Section 5.2 and Figure 1 caption), so no fitted trend is renamed as a prediction. The only self-citation, Flowerday et al. [15], supplies a five-state conceptual taxonomy that the paper independently restates and that does not do load-bearing work in deriving the empirical results; it is background framing, not a reduction of the evidence to the citation. The limitation noted in Section 7.1 about CISSM reporting bias and coder judgment is a measurement-validity concern, not a circularity concern: it may affect the strength of the empirical conclusion but does not make the derivation equivalent to its inputs.
Axiom & Free-Parameter Ledger
axioms (4)
- standard math Jensen's inequality and the definition of convexity are valid for the utility function U(θ,s) over the bounded stressor domain S
- domain assumption CISSM event-type and subtype fields correspond to actual event impact categories
- domain assumption HAI hardware-in-the-loop testbed data are a valid proxy for OT/ICS process telemetry under cyber-attack
- ad hoc to paper The OT-adjacent grouping (Utilities, Transportation, Manufacturing) captures direct cyber-physical process exposure better than the comparison group (Finance, Healthcare, Information, Public Administration)
invented entities (1)
-
Antifragility Score (AFS)
no independent evidence
read the original abstract
Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant subset of the CISSM Cyber Events Database with the HAI hardware-in-the-loop industrial control dataset and tests three confirmatory hypotheses and one exploratory proposition. OT-adjacent sectors show significantly higher shares of disruptive or mixed events than comparison sectors (65.3 percent versus 46.8 percent, p less than 0.001), together with a greater concentration of physical-attack and data-attack subtypes. In HAI, attack-labeled observations were 7.43 times more likely than normal observations to exceed the 95th percentile of baseline deviation (p less than 0.001). Across successive attack windows, mean process-state deviation declined significantly (Spearman rho = -0.688, p = 0.007), indicating measurable response variation rather than proof of adaptive gain. Together, the findings establish two prerequisites for future antifragility testing: differentiated fragility burden and process-level perturbation observability.
Figures
Reference graph
Works this paper leans on
-
[1]
The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years; CISA: Washington, DC, USA, 2023
Cybersecurity and Infrastructure Security Agency (CISA). The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years; CISA: Washington, DC, USA, 2023. Available online: https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what- weve-done-over-past-two-years (accessed on 10 April 2026)
2023
-
[2]
JBS USA and Pilgrim’s Announce Resolution of Cyberattack; JBS Foods: Greeley, CO, USA, 2021
JBS USA; Pilgrim’s. JBS USA and Pilgrim’s Announce Resolution of Cyberattack; JBS Foods: Greeley, CO, USA, 2021. Available online: https://jbsfoodsgroup.com/articles/jbs-usa-and-pilgrim-s-announce- resolution-of-cyberattack (accessed on 10 April 2026)
2021
-
[3]
Guide to Operational Technology (OT) Security; NIST Special Publication 800-82 Rev
Stouffer, K.; Pease, M.; Tang, C.; Zimmerman, T.; Pillitteri, V.; Lightman, S.; Hahn, A.; Saravia, S.; Sherule, A.; Thompson, M. Guide to Operational Technology (OT) Security; NIST Special Publication 800-82 Rev. 3; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2023. https://doi.org/10.6028/NIST.SP.800-82r3
-
[4]
Ross, R.; Pillitteri, V.; Graubart, R.; Bodeau, D.; McQuaid, R. Developing Cyber-Resilient Systems: A Systems Security Engineering Approach; NIST Special Publication 800-160 Vol. 2 Rev. 1; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2021. https://doi.org/10.6028/NIST.SP.800-160v2r1
-
[5]
Resilience and Stability of Ecological Systems
Holling, C.S. Resilience and Stability of Ecological Systems. Annu. Rev. Ecol. Syst. 1973, 4, 1–23. https://doi.org/10.1146/annurev.es.04.110173.000245
arXiv 1973
-
[6]
Four Concepts for Resilience and the Implications for the Future of Resilience Engineering
Woods, D.D. Four Concepts for Resilience and the Implications for the Future of Resilience Engineering. Reliab. Eng. Syst. Saf. 2015, 141, 5–9. https://doi.org/10.1016/j.ress.2015.03.018
-
[7]
Munoz, A.; Billsberry, J.; Ambrosini, V. Resilience, Robustness, and Antifragility: Towards an Appreciation of Distinct Organizational Responses to Adversity. Int. J. Manag. Rev. 2022, 24, 181–187. https://doi.org/10.1111/ijmr.12289
-
[8]
Antifragile: Things That Gain from Disorder; Random House: New York, NY, USA, 2012
Taleb, N.N. Antifragile: Things That Gain from Disorder; Random House: New York, NY, USA, 2012
2012
-
[9]
Antifragility’ as a Mathematical Idea
Taleb, N.N. Antifragility’ as a Mathematical Idea. Nature 2013, 494, 430. https://doi.org/10.1038/494430e.‘
-
[10]
Mathematical Definition, Mapping, and Detection of (Anti)Fragility
Taleb, N.N.; Douady, R. Mathematical Definition, Mapping, and Detection of (Anti)Fragility. Quant. Finance 2013, 13, 1677–1689. https://doi.org/10.1080/14697688.2013.800219
arXiv 2013
-
[11]
Antifragility Analysis and Measurement Framework for Systems of Systems
Johnson, J.; Gheorghe, A.V. Antifragility Analysis and Measurement Framework for Systems of Systems. Int. J. Disaster Risk Sci. 2013, 4, 159–168. https://doi.org/10.1007/s13753-013-0017-7
-
[12]
Chaos Engineering: System Resiliency in Practice; O’Reilly Media: Sebastopol, CA, USA, 2020
Rosenthal, C.; Jones, N. Chaos Engineering: System Resiliency in Practice; O’Reilly Media: Sebastopol, CA, USA, 2020
2020
-
[13]
Getting Started with Chaos Engineering: Design of an Implementation Framework in Practice
Jernberg, H.; Runeson, P.; Engström, E. Getting Started with Chaos Engineering: Design of an Implementation Framework in Practice. In Proceedings of the ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) Industry Track; ACM: New York, NY, USA, 2020; Article 43. https://doi.org/10.1145/3382494.3421464
arXiv 2020
-
[14]
Principles of Antifragile Software
Monperrus, M. Principles of Antifragile Software. In Companion Proceedings of the 1st International Conference on the Art, Science, and Engineering of Programming; ACM: New York, NY, USA, 2017; pp. 32:1–32:4. https://doi.org/10.1145/3079368.3079412
arXiv 2017
-
[15]
Cybersecurity in the Age of Uncertainty: A Call for Resilient and Antifragile Systems
Flowerday, S.V.; Tilbury, J.L.; Higgs, J. Cybersecurity in the Age of Uncertainty: A Call for Resilient and Antifragile Systems. In AMCIS 2024 Proceedings; Association for Information Systems: Salt Lake City, UT, USA, 2024. Available online: https://aisel.aisnet.org/amcis2024/security/security/26 (accessed on 10 April 2026)
2024
-
[16]
Antifragility in Complex Dynamical Systems
Axenie, C.; LoU pez-Corona, O.; Makridis, M.A.; Akbarzadeh, M.; Saveriano, M.; Stancu, A.; West, J. Antifragility in Complex Dynamical Systems. npj Complexity 2024, 1, 12. https://doi.org/10.1038/s44260-024-00014-y
-
[17]
Antifragility as a Design Criterion for Modelling Dynamic Systems
de Bruijn, H.; Grö ler, A.; Videira, N. Antifragility as a Design Criterion for Modelling Dynamic Systems. ß Syst. Res. Behav. Sci. 2020, 37, 23–37. https://doi.org/10.1002/sres.2574
-
[18]
Classifying Cyber Events
Harry, C.; Gallagher, N. Classifying Cyber Events. J. Inf. Warf. 2018, 17(3), 17–31
2018
-
[19]
Cyber Events Database Codebook; Center for International and Security Studies at Maryland, University of Maryland: College Park, MD, USA, 2023
Harry, C.; Gallagher, N.; Samuelsen, L. Cyber Events Database Codebook; Center for International and Security Studies at Maryland, University of Maryland: College Park, MD, USA, 2023
2023
-
[20]
Two ICS Security Datasets and Anomaly Detection Contest on the HIL-Based Augmented ICS Testbed
Shin, H.-K.; Lee, W.; Yun, J.-H.; Min, B.-G. Two ICS Security Datasets and Anomaly Detection Contest on the HIL-Based Augmented ICS Testbed. In Cyber Security Experimentation and Test Workshop (CSET ’21); ACM: New York, NY, USA, 2021; pp. 36–40. https://doi.org/10.1145/3474718.3474719
arXiv 2021
-
[21]
HIL-Based Augmented ICS (HAI) Security Dataset; GitHub repository
icsdataset. HIL-Based Augmented ICS (HAI) Security Dataset; GitHub repository. Available online: https://github.com/icsdataset/hai (accessed on 10 April 2026)
2026
-
[22]
Known Exploited Vulnerabilities Catalog; CISA: Washington, DC, USA
Cybersecurity and Infrastructure Security Agency (CISA). Known Exploited Vulnerabilities Catalog; CISA: Washington, DC, USA. Available online: https://www.cisa.gov/known-exploited-vulnerabilities- catalog (accessed on 10 April 2026)
2026
-
[23]
ATT&CK for ICS Matrix; MITRE ATT&CK
MITRE. ATT&CK for ICS Matrix; MITRE ATT&CK. Available online: https://attack.mitre.org/matrices/ics/ (accessed on 10 April 2026)
2026
-
[24]
ATT&CK STIX Data and Tools; MITRE ATT&CK
MITRE. ATT&CK STIX Data and Tools; MITRE ATT&CK. Available online: https://github.com/mitre-attack/attack-stix-data (accessed on 10 April 2026)
2026
-
[25]
DNP3 Intrusion Detection Dataset; ELECTRON Project (H2020): 2022
ELECTRON Project. DNP3 Intrusion Detection Dataset; ELECTRON Project (H2020): 2022. Available online: https://electron-project.eu/news/dnp3-intrusion-detection-dataset/ (accessed on 10 April 2026)
2022
-
[26]
Gaggero, G.B.; Armellin, A.; Portomauro, G.; Marchese, M. Industrial Control System-Anomaly Detection Dataset (ICS-ADD) for Cyber-Physical Security Monitoring in Smart Industry Environments. IEEE Access 2024, 12, 64140–64149. https://doi.org/10.1109/ACCESS.2024.3395991
arXiv 2024
-
[27]
Shifting towards Antifragile Critical Infrastructure Systems
Bangui, H.; Buhnova, B.; Rossi, B. Shifting towards Antifragile Critical Infrastructure Systems. In Proceedings of the 7th International Conference on Internet of Things, Big Data and Security (IoTBDS 2022); SciTePress: SetuU bal, Portugal, 2022; pp. 78–87. https://doi.org/10.5220/0011086400003194
-
[28]
RESMETRIC: Analyzing Resilience to Enable Research on Antifragility
Koenig, F.; Carwehl, M.; Imrie, C. RESMETRIC: Analyzing Resilience to Enable Research on Antifragility. arXiv 2025, arXiv:2501.18245
Pith/arXiv arXiv 2025
-
[29]
Ecosystem Antifragility: Beyond Integrity and Resilience
Equihua, M.; Espinosa Aldama, M.; Gershenson, C.; LoU pez-Corona, O.; MunguiU a, M.; PeU rez-Maqueo, O.; RamiU rez-Carrillo, E. Ecosystem Antifragility: Beyond Integrity and Resilience. PeerJ 2020, 8, e8533. https://doi.org/10.7717/peerj.8533
-
[30]
Pineda, O.K.; Kim, H.; Gershenson, C. A Novel Antifragility Measure Based on Satisfaction and Its Application to Random and Biological Boolean Networks. Complexity 2019, 3728621. https://doi.org/10.1155/2019/3728621
-
[31]
A Multilayer Structure Facilitates the Production of Antifragile Systems in Boolean Network Models
Kim, H.; Pineda, O.K.; Gershenson, C. A Multilayer Structure Facilitates the Production of Antifragile Systems in Boolean Network Models. Complexity 2019, 2783217. https://doi.org/10.1155/2019/2783217. Disclaimer/Publisher s Note: ’ The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor...
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.