XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security
Industrial control system attacks are usually documented in terms of the plant where they occurred: its sensors, actuators, process stages, and control logic. Yet many attacks express a more general physical pattern--such as suppressing flow, corrupting chemical dosing, or driving a vessel toward overflow--that may also matter in a different plant. The challenge is deciding when such a threat remains meaningful on a new system rather than relying on similar component names or broad semantic labels. We present XPhysICS, a methodology for grounding documented cyber-physical threats onto a specific target system. XPhysICS converts source evidence into a provenance-linked description of what is manipulated, what physical consequence is expected, and what observations the evidence calls for. Once this analyst-guided abstraction, its vocabulary and schema version, and a target contract are fixed, XPhysICS applies deterministic grounding checks. An accepted result can be represented as a validation slice that records the mapped roles, signals, dependencies, and context intended to support later evaluation. We study 83 threat abstractions across continuous-process and manufacturing sources using separate evaluation denominators. The continuous-process study evaluates 78 abstractions against target contracts spanning water treatment, water distribution, hydropower, and chemical processes. Selected cases are exercised through controlled perturbations of simulator-role signals. We also test compatibility with several analysis styles, including the released upstream GeCo implementation, and conduct a three-objective, one-target realizability study using a paper-derived search reproduction. Across these evaluated settings, the results support treating explicit target checks and traceable evidence as separate from semantic similarity alone.