Provable Moving-Target Defense for Cyber-Physical Networks: From the Security–Performance Frontier to No-Regret Defense

The paper makes CPS moving-target defense quantitative and provable. It formalizes randomization as a game with an explicit physical-cost term and proves a security–performance frontier J⋆(p) attained by interpretable capped water-filling — a full convex curve rather than the single equilibrium point of prior grid-MTD work. Generalizing the idealized exact-match model to a graded confusion kernel yields the paper’s sharpest result: feasibility only above val(K), a matrix-game security floor that no physical budget can buy past (≈ 0.21 on the grid). A no-regret mirror-descent defender then reaches that frontier against an adaptive attacker with unknown payoffs, the novelty being the reduction rather than the standard √T rate. Because cost and security both derive from the same IEEE 14-bus physics, the price of security is stated in megawatts.