ExplorerComputer ScienceCybersecurity
Research PaperResearchia:202608.03017

Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity

Stephen Flowerday

Abstract

Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant...

Submitted: August 3, 2026Subjects: Cybersecurity; Computer Science

Description / Details

Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant subset of the CISSM Cyber Events Database with the HAI hardware-in-the-loop industrial control dataset and tests three confirmatory hypotheses and one exploratory proposition. OT-adjacent sectors show significantly higher shares of disruptive or mixed events than comparison sectors (65.3 percent versus 46.8 percent, p less than 0.001), together with a greater concentration of physical-attack and data-attack subtypes. In HAI, attack-labeled observations were 7.43 times more likely than normal observations to exceed the 95th percentile of baseline deviation (p less than 0.001). Across successive attack windows, mean process-state deviation declined significantly (Spearman rho = -0.688, p = 0.007), indicating measurable response variation rather than proof of adaptive gain. Together, the findings establish two prerequisites for future antifragility testing: differentiated fragility burden and process-level perturbation observability.


Source: arXiv:2607.29550v1 - http://arxiv.org/abs/2607.29550v1 PDF: https://arxiv.org/pdf/2607.29550v1 Original Link: http://arxiv.org/abs/2607.29550v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Aug 3, 2026
Topic:
Computer Science
Area:
Cybersecurity
Comments:
0
Bookmark