Skip to Content
SensorsSensors
  • Review
  • Open Access

10 February 2026

33 Pages

Recent Advances in Fault Diagnosis and Opacity Analysis in Discrete Event Systems

,
,
,
and
1
Department of Electrical and Information Engineering (DEI), Polytechnic University of Bari, 70126 Bari, Italy
2
School of Electro-Mechanical Engineering, Xidian University, Xi’an 710071, China
*
Author to whom correspondence should be addressed.
This article belongs to the Special Issue Feature Review Papers in Fault Diagnosis & Sensors

Abstract

This paper continues the historical and technical trajectory of fault diagnosis and opacity analysis in discrete event systems (DESs). Whereas the previous work reviewed the foundational developments of event diagnosis and opacity, this survey focuses on recent advances over the past decade by addressing modern challenges such as communication losses, delays, distributed architectures, and cyber-attack scenarios. Specifically, we present a structured overview of diagnosability verification and enforcement across automata, Petri nets, and other DES models under these scenarios. In parallel, we review contemporary results on opacity verification and enforcement, including complexity findings, reduction techniques, and robust or attack-resilient formulations. In addition, this survey provides an updated picture of the evolving research landscape and highlights emerging themes and open problems in diagnosis and opacity for DESs.

1. Introduction

Discrete event systems (DESs) have provided a fundamental modeling framework for reasoning about logical behavior, coordination, and information flow in networked systems. As cyber–physical infrastructures, autonomous vehicles, robotic platforms, and large-scale networked control architectures grow in complexity, understanding what can or cannot be inferred from limited observations becomes increasingly critical. Two major research themes have emerged around this issue: fault diagnosis, i.e., to reveal hidden faults (usually assumed to be unobservable events) fast and accurately, and opacity, i.e., to conceal confidential behavior from an external observer. Although they originate from different practical concerns, i.e., safety and reliability in the case of diagnosis and security and privacy in the case of opacity, their theoretical foundations are deeply intertwined. Both rely on partial observations, both model inference through state estimators or state-based structures, and both reason about how information propagates through system dynamics [1].
Over the past decades, extensive survey papers have documented the evolution of fault diagnosis in DESs [2,3,4], reflecting both the theoretical maturity of the field and its growing practical relevance. Fault diagnosis and diagnosability analysis [5,6] form the foundation for monitoring and ensuring the safe operation of complex infrastructures such as automated manufacturing systems [7,8] and urban transportation networks. In such systems, sensing capabilities are often constrained by cost, placement limitations, or physical inaccessibility. As a result, only partial observations of system behavior are available, and certain components may remain completely sensorless. While sensorless designs can help protect critical modules from malicious tampering, faults occurring in these components may lead to severe consequences if not detected in time. This tension between limited observability and the need for timely fault localization has driven much of the research in fault diagnosis. Related work on fault identification, which aims at reconstructing DES models for fault detection, addresses a complementary problem and is therefore not covered in depth in this survey [9,10,11,12].
Diagnosability, in this context, is the system property that determines whether the occurrence of a fault can always be detected within a finite delay based solely on observable outputs. Classical diagnosis methods [13,14] aim to infer hidden faults from observed event sequences, while diagnosability verification assesses whether the system structure guarantees such inference in principle. Beyond verification, diagnosability enforcement seeks to modify or constrain system behavior so that faults become detectable, even when uncertainties or malicious behaviors are present.
Recent developments have broadened the notion of diagnosability to accommodate different fault specifications. For instance, the authors of [15] revisit repeated fault diagnosability and propose a diagnoser-based algorithm for verifying k-diagnosability. The work in [16] extends classical approaches to event-pattern diagnosability and reduces the problem to checking a linear-time property over a time Petri net via model-checking techniques. These extensions illustrate the increasing expressive power required to capture complex fault behaviors in modern applications. In contrast to the classical supervisory control methods or the approaches that incorporate timing information to prevent deadlocks [17,18,19,20,21,22,23,24,25], a different line of work introduces quiescent information [26,27,28]. Building on this idea, the authors of [29] generalize the classical notion of diagnosability in labeled Petri nets (LPNs) to systems that may contain potential deadlocks.
Meanwhile, diagnosability has been reconsidered in the presence of adversarial manipulation [30,31,32]. Attackers may attempt to conceal faults by altering or fabricating sensor readings. While many studies assume that attackers have access to the same observations as operators, real-world adversaries typically observe or compromise only part of the system. As a result, their perception of what has been successfully hidden may differ from the actual information available to an operator or monitoring algorithm. This motivates a richer investigation of diagnosis under partial, asymmetric, or corrupted information flows, linking the topic naturally to the broader theme of opacity analysis and DES-based information-security modeling. In addition, diagnosability has also been investigated under other sources of uncertainty, such as communication delays, packet losses, and intermittent observation failures, which further complicate fault inference in networked and cyber–physical systems.
Opacity was initially formalized as a qualitative indistinguishability requirement for finite-state automata: an intruder observing a system through a projection map must never be able to determine that a secret state or behavior has occurred [33,34,35,36]. Foundational works introduced and analyzed current-state opacity (CSO), initial-state opacity (ISO), initial-and-final-state opacity (IFSO), as well as language-based opacity (LBO) and various K-step and infinite-step variants [33,35,36,37,38,39,40].
Over the past two decades, opacity has been extended far beyond the finite-automaton setting. Petri-net models allow explicit representation of concurrency, synchronization, and resource constraints and have led to observer-like, basis-reachability-graph, and verifier-net-based verification techniques for CSO, ISO, and LBO [41,42,43]. Timed DES further augment transitions with timing information, enabling the study of timed current-state opacity, opaque time, and related notions in timed stochastic DES and time LPNs [44,45,46,47]. Networked DESs explicitly incorporate communication delays, packet losses, and reordering, providing a natural framework to reason about opacity under realistic communication imperfections and networked supervisory structures [48,49,50,51]. Stochastic DES, Markovian and probabilistic automata, and fuzzy or approximate models bring in randomness and graded uncertainty, leading to probabilistic, fuzzy, approximate, and metric-based opacity notions that quantify rather than merely decide information leakage [44,52,53,54,55].
In parallel with these modeling advances, opacity verification has developed into a technically rich area spanning automata, Petri nets, timed models, and probabilistic or fuzzy systems. Classical observer-based constructions for finite automata remain central [33,35,36,37], while Petri-net approaches rely on basis reachability graphs, verifier nets, and structural or algebraic characterizations [41,42,43]. Timed Petri nets require abstractions such as marking-class graphs, whereas probabilistic opacity is analyzed via belief-state dynamics and Markov chain semantics [44,52,53].
Beyond verification, a substantial body of work now focuses on opacity enforcement: the synthesis of mechanisms that modify the plant behavior or its observation channel so that opacity is guaranteed. Channel-based methods use edit and insertion functions to alter the observation stream, injecting fictitious or suppressed events so that secret executions remain indistinguishable from at least one nonsecret counterpart [56,57,58,59,60,61,62,63,64,65,66]. Control-based approaches instead synthesize supervisors that disable controllable events leading to secret-revealing behaviors [67,68,69,70,71,72]. These ideas have been extended to decentralized settings with multiple supervisors or intruders [48,49,50,69,73] and to non-logical opacity frameworks that combine secrecy with probabilities, fuzziness, or strategic information release [44,52,53,54,55,74,75].
Taken together, this survey offers a unified, cross-model perspective on opacity and its relationship to diagnosis. By integrating foundational definitions, methodological developments, and emerging frontiers across DES theory, we aim to provide researchers with a coherent view of how inference, knowledge, and information flow shape the behavior, security, and privacy of DES.
Although this survey focuses on formal models and theoretical developments, the reviewed results are strongly motivated by practical challenges arising in industrial automation and cyber–physical systems. Fault diagnosis frameworks directly address monitoring and fault isolation problems in automated manufacturing systems, robotic production lines, transportation networks, and networked control architectures, where partial observability, sensor placement constraints, and fault criticality are inherent design limitations. Likewise, opacity analysis provides a formal foundation for protecting sensitive operational information in Industrial Control Systems (ICSs) and smart grids, where revealing internal modes or system configurations may expose vulnerabilities to adversaries. Throughout this paper, the presented theoretical constructs are therefore interpreted as abstractions of real engineering constraints.
The remainder of this survey is organized to guide the reader from foundational concepts to advanced developments and emerging challenges. Section 2 reviews the necessary preliminaries on finite-state automata and Petri nets, establishing the modeling and observation frameworks used throughout the paper. In Section 3, we present a comprehensive overview of fault diagnosis, covering modeling assumptions, classical approaches, and recent extensions under uncertainty and adversarial settings. Section 4 focuses on diagnosability verification, including classical criteria, complexity results, and verification techniques developed for systems with communication losses, delays, or attacks. Section 5 then discusses diagnosability enforcement, examining how supervisory control, event relabeling, and timing regulations can be used to ensure diagnosability in both untimed and timed DES models. Section 6 introduces the modeling foundations of opacity, including system models, observation structures, and intruder knowledge representations, and situates these elements within the broader DES literature. Section 7 formalizes the principal opacity notions, clarifying the distinction between logical opacity properties and their non-logical, quantitative extensions. Section 8 reviews verification methods across automata, Petri nets, and timed and stochastic models, highlighting how classical observer-based approaches have evolved into symbolic, structural, and probabilistic techniques. Section 9 surveys enforcement mechanisms, ranging from channel-based editing to supervisory control and distributed enforcement in networked DES, with emphasis on both logical and quantitative opacity. Section 10 examines the conceptual and methodological duality between opacity and fault diagnosis, showing how tools developed for revealing faults can be reinterpreted for concealing secrets. Finally, Section 11 outlines open problems and future research directions, including scalable verification, decentralized and networked enforcement, quantitative secrecy, and the integration of opacity with other security and performance objectives. A technical roadmap of the survey is provided in Figure 1.
Figure 1. Technical roadmap of the survey.

2. Preliminaries

Let Σ denote a finite event set, and let Σ * be the set of all finite strings over Σ , including the empty string ε . For any string λ Σ * , | λ | denotes its length, with | ε | = 0 . A language is a subset L Σ * . For u , v Σ * , the concatenation is written as u v .

2.1. Automaton

A system is modeled as a finite-state automaton [6] G = ( X , Σ , f , x 0 ) , where X is a finite set of states, Σ is a finite set of events, f : X × Σ X is the (partial) transition function, and x 0 X is the initial state. The transition function extends to strings λ Σ * in the usual manner [6,76]. The language generated by G is defined as L ( G ) = { λ Σ * f ( x 0 , λ ) is defined}.
To characterize partial observation of a system G, its event set Σ is partitioned into the subset of observable events E o and that of unobservable events Σ u o , i.e., Σ = Σ o Σ u o . The natural projection that captures the observations generated by G is defined as P : Σ * Σ o * , where P ( ε ) = ε , P ( α ) = α if α E o , P ( α ) = ε if α Σ u o , and P ( λ α ) = P ( λ ) P ( α ) for all λ Σ * and α Σ .

2.2. Petri Net

A Petri net [5] is a quadruple N = ( P , T , P r e , P o s t ) , where P (resp. T) is a finite and non-empty set of places (resp. transitions), graphically represented by circles (resp. bars) with P T = . P r e : P × T N and P o s t : P × T N are the pre- and post-incidence functions that specify the arcs directed from places to transitions, and transitions to places, respectively, where N = { 0 , 1 , 2 , } is the set of non-negative integers. C = P o s t P r e is called the incidence matrix of a Petri net N .
A marking of a Petri net is a mapping M : P N , and M ( p ) presents the number of tokens in p at marking M. N ,   M 0 is called a net system with an initial marking M 0 . Let n = | T | be the cardinality of set T and T * be the Kleene closure of transition set T. A transition t is enabled at a marking M if for all p P   M ( p ) P r e ( p , t ) holds. An enabled transition t can fire, yielding a marking M = M + C ( · , t ) , denoted by M [ t M . Given a transition sequence σ = t 1 t 2 t n T * , σ is said to be enabled at a marking M if there exist markings M 1 , M 2 , …, M n such that M [ t 1 M 1 [ t 2 M 2 M n 1 [ t n M n holds, denoted by M [ σ M n . In this case, M n is said to be reachable from M. Write M [ σ if M n is of no interest. The set of all markings reachable from M 0 , denoted by R ( N , M 0 ) , defines the reachability set of N , M 0 , i.e., R ( N , M 0 ) = { M N | P | σ T * : M 0 [ σ M } .
From a sensing perspective, partial observation provides an abstract representation of practical sensing constraints in DESs. Observable event sets correspond to sensor outputs, logged signals, or communicated measurements, whereas unobservable events model sensing blind spots, limited measurement resolution intermittent sensor availability.

3. Fault Diagnosis

Fault diagnosis in DESs was first formally introduced in [77,78,79], where the authors established a model-based framework for detecting and identifying faults based on partially observed event sequences. Since, in practical applications, sensors are typically limited and only a subset of events can be observed, DES models naturally operate under partial observation. This observation constraint motivates the need for diagnosis algorithms capable of inferring fault occurrences from observable behaviors. Over the past decades, fault diagnosis has evolved into a rich research area encompassing various modeling frameworks and increasingly complex system specifications. In the following parts, we provide a structured overview of fault diagnosis approaches across different DES models. We begin with classical automaton-based methods, which form the theoretical foundation of diagnosability analysis. We then discuss fault diagnosis for bounded and unbounded Petri nets, where concurrency and resource-sharing introduce new computational challenges.

3.1. Automaton Based Fault Diagnosis

Fault diagnosis in DESs seeks to determine whether an unobservable fault has occurred based on the partial information generated by the system. In the automaton framework, the problem was first formalized in [13], where the system behavior is described by a finite-state automaton and observations correspond to projections of event sequences onto the set of observable events. A fault is modeled as an unobservable event whose execution alters the system state. The goal of diagnosis is to decide, after a finite number of subsequent observations, whether such a fault has taken place. Research on online fault diagnosis in automata-based DESs develops systematic procedures that use partial observation to infer hidden events [13,77,78]. A common approach constructs an estimator structure that tracks the set of all states compatible with the observation sequence. When all states in this estimate correspond either exclusively to faulty behavior or exclusively to non-faulty behavior, the system is considered diagnosable at that point. This estimator forms the foundation for many verification methods.
Another widely studied method introduces a diagnoser automaton, which evolves deterministically with the observation sequence and explicitly records whether the fault status is certain, uncertain, or normal. The diagnoser allows the identification of cycles in which the fault status remains ambiguous. Such cycles signal a violation of diagnosability because they represent observation-consistent behaviors in which the system may alternate indefinitely between faulty and non-faulty states without revealing the true status. Identifying the existence or absence of such cycles provides a practical criterion for diagnosability verification.
In the presence of the attacks, Kang et al. [80] introduce the stealthy joint diagnoser, which reveals how an attacker can mislead or obscure fault diagnosis and can also be used for online diagnosis under attacks. Lin et al. [81] propose the cyber-attack diagnoser (CA-diagnoser), which addresses diagnosability verification in the presence of attacks and supports online diagnostic decision making based on the constructed structure.

3.2. Petri Net Based Fault Diagnosis

Petri nets (PNs) provide a compact and expressive modeling framework for capturing concurrency, causality, and resource constraints in DESs. Due to their ability to represent complex industrial processes more naturally than automata, a substantial body of work has focused on fault diagnosis in PN and labeled PN (LPN) models. Existing diagnostic techniques can be broadly categorized into (i) ILP-based methods, which formulate the online diagnosis problem as an integer linear programming problem without enumerating the entire reachable state space, and (ii) structure-based methods, which rely on the construction of specialized diagnosers or abstractions derived from the underlying PN structure. This subsection reviews these two main methodological directions and summarizes their recent advances.

3.2.1. ILP

Several studies have addressed the fault diagnosis problem for Petri nets (PNs) using optimization-based techniques. The work in [14] introduces a marking abstraction method that enables the diagnosis problem to be efficiently analyzed. Building on this idea, an online diagnosis scheme based on integer linear programming (ILP) is proposed in [82]. This ILP-based method is later extended to labeled Petri nets (LPNs) in [83], allowing multiple transitions to share the same observable label. Further improvements are reported in [84], where the approach in [83] is optimized to yield a more computationally efficient online diagnosis algorithm for LPNs. Unlike graphical or structure-based approaches, another line of research avoids constructing reachability graphs or enumerating markings. Instead, online diagnosis is achieved by solving ILP problems [82,83,84,85] or by performing state-estimation–based computations [86,87,88]. These methods are typically more scalable for large or unbounded PNs. A more recent study [89] investigates diagnosis under a specific class of cyber attacks, namely replacement–removal attacks, which delete or manipulate sensor readings. Such attacks may cause existing ILP-based diagnosers [83,84] to produce incorrect decisions. To address this issue, ref. [89] strengthens both the structural components and reasoning mechanisms of the diagnoser. Even under worst-case attack scenarios, the proposed augmented diagnoser guarantees that the diagnosis outcome remains uncertain rather than incorrect. The method applies to both bounded and unbounded LPNs and provides diagnosis results that explicitly reflect the uncertainty introduced by the attack.

3.2.2. Structure-Based Techniques

Another major direction relies on structure-based techniques. Using the basis reachability diagnoser, ref. [90] proposes an online fault diagnosis approach for LPNs based on a compact representation of the reachable basis markings. In the context of networked DESs, ref. [91] studies robust fault diagnosis for LPN-modeled systems subject to communication delays and losses. The notion of networked diagnosability is introduced to characterize whether every fault can be identified after a bounded number of observations. To solve the diagnosis problem, a networked basis diagnoser is developed, together with a necessary and sufficient condition for verifying networked diagnosability. Other works incorporate adversarial behaviors into the diagnosis framework.

3.3. Other Models

Beyond automata- and Petri net-based approaches, several studies investigate fault diagnosis problems within alternative modeling frameworks. Researchers have examined decentralized architectures [92,93], in which multiple local diagnosers with partial observations cooperate to infer fault occurrences. In distributed settings, coordination among diagnosers is achieved through information exchange or consensus mechanisms, as explored in [94,95]. In particular, ref. [95] proposes a distributed diagnosis method based on iterative set-intersection refinements, enabling local components to collaboratively narrow down the set of possible system states. Fault diagnosis has also been extended to timed DESs, where timing constraints and clock information play crucial roles in characterizing diagnosability [96]. Moreover, stochastic DES models have been utilized to handle uncertainty in event occurrences and system behaviors, leading to probabilistic formulations of diagnosability and robust diagnosis strategies [97,98]. These alternative models broaden the applicability of fault diagnosis techniques and address practical challenges inherent in large-scale, uncertain, or time-sensitive systems. Building on recent advances in fluid-model representations [99,100], one may further explore how such scalable frameworks can be extended to address fault diagnosis while avoiding the large state space of discrete models. Figure 2 shows that fault diagnosis studies predominantly rely on Petri net models and automata, while timed Petri nets remain comparatively underrepresented. This suggests a promising research direction in developing fault diagnosis approaches for timed Petri nets and other expressive models.
Figure 2. Distribution of fault diagnosis-related publications by primary modeling formalism.
In contrast to DESs with regular languages, fault diagnosis problems are also solved in unbounded Petri nets that may generate nonregular languages [101,102,103,104].

4. Diagnosability Verification

Diagnosability verification is a fundamental problem in the area of fault-tolerant DESs. It concerns determining whether every fault occurring in a system can be detected within a finite number of observable events, despite partial observation. In other words, diagnosability ensures that faults cannot remain permanently ambiguous when only limited sensor information is available. This section reviews several major lines of research on diagnosability verification. We begin with the classical diagnosability analysis framework, which provides the foundational definitions and verification methods. We then discuss diagnosability under communication imperfections, such as observation losses and delays, followed by diagnosability in adversarial environments, where attackers intentionally manipulate observations. These settings extend the classical theory to more realistic and challenging scenarios commonly encountered in networked and cyber–physical systems.
As diagnosability analysis grows more sophisticated across different modeling frameworks, computational complexity becomes an important consideration. The work in [105] provides a systematic study of the complexity of diagnosability (and opacity) verification for Petri nets. The results show that, in the presence of concurrency and unboundedness, diagnosability verification may require extremely high computational resources, revealing intrinsic limitations of brute-force state space exploration. These findings highlight the necessity of scalable analysis techniques, especially for large or structurally complex systems.
To mitigate this complexity, several model simplification strategies have been proposed. The study in [106] introduces a set of reduction rules for LPNs that allow the removal of certain unobservable transitions and specific observable transitions before diagnosability analysis is performed. When the structural conditions of these rules are satisfied, the reduced model preserves diagnosability, ensuring that no essential diagnostic information is lost. These reduction rules help decrease the size of the underlying state space, yielding significant computational savings while retaining the correctness of verification results. Together, complexity analysis and reduction techniques form an important complement to the various diagnosability verification methods reviewed in this section.
In practical terms, diagnosability verification characterizes whether the available sensor information associated with event occurrences is sufficient to distinguish faulty from non-faulty behavior within a bounded delay. Diagnosers and verifiers can thus be viewed as logical monitoring layers built on top of sensor streams, whose effectiveness depends on sensor placement and reliability.

4.1. Classic Diagnosability

Diagnosability verification for DESs under ideal conditions, meaning no observation losses, delays, or adversarial attacks, has been extensively studied using two main approaches: integer linear programming (ILP) and graph-based analysis. The ILP-based method in [107] formulates diagnosability verification as an optimization problem. Although effective, solving ILP problems is known to be NP-hard, which limits scalability for large systems. The majority of classical works rely on graph-based analysis. The diagnoser approach, introduced in [77,78,79,108], constructs an auxiliary automaton that tracks the evolution of the system under partial observation. A DES is diagnosable if and only if its diagnoser contains no indeterminate cycles. However, computing the diagnoser requires exploring the entire state space, yielding exponential complexity with respect to the system size. To reduce computational effort, verifier-based approaches were proposed in [79,108,109], where the verification task can be performed in polynomial time with respect to the state dimension, providing a significantly more scalable alternative. Besides ILP and diagnoser techniques, formal verification methods have also been applied. The work in [110] encodes diagnosability as a linear temporal logic (LTL) formula over transition systems and verifies it using model-checking tools such as SPIN and NuSMV. Comparative experiments highlight the competitiveness of model-checking-based verification relative to DES-specific tools like DESLab and Supremica. More recently, ref. [111] proposed a unified framework for verifying several observational properties—including diagnosability—in partially observed DESs, further consolidating the theoretical foundations of classic diagnosability analysis. Some works [26,112] study the problem of asynchronous diagnosability enforcement in DESs based on supervisory control theory. In addition, several studies have investigated diagnosability verification in time-dependent models. Specifically, ref. [113] addresses the verification of codiagnosability for DESs modeled by constant-time automata, while ref. [114] focuses on pattern diagnosability.

4.2. Under Loss and Delay

In many practical networked DESs, communication between sensors, measurement sites, and diagnosers may suffer from packet losses, transmission delays, or temporary disconnections. Such imperfections can compromise classical diagnosability and motivate the study of robust diagnosability and networked codiagnosability. The work in [115] examines weak diagnosability under both communication delays and packet losses. It shows that while delays do not affect weak diagnosability, packet losses can negatively impact the ability to determine fault occurrences. In decentralized networked systems subject to delays and intermittent losses, ref. [116,117] introduce the notion of network codiagnosability, providing necessary and sufficient conditions for ensuring that faults can be detected by at least one local diagnoser despite unreliable communication. Intermittent communication failures that lead to observation loss are systematically studied in [118], which develops a robust diagnosability framework for LPNs. Similar problems involving transient sensor failures are considered in [119,120]. Timing aspects are incorporated in [121], which proposes a timed NDES model with maximal communication delays and intermittent losses. The timed model is then converted into an equivalent untimed structure for verification. More recently, ref. [122] proposed a delay-resilient diagnosis method using sequence numbers to mitigate the ambiguous effects caused by delays in networked DESs. Beyond delays and losses, sensor unreliability may arise from nondeterministic readings due to noise or partial failures. The study in [123] introduces a uniform diagnosability framework based on LTL over infinite traces, capable of addressing a broad class of unreliable sensor behaviors. The work in [124] formalizes and studies diagnosability verification and enforcement in LPNs under observation and control delays.

4.3. Under Attack

In cyber–physical systems, adversaries may intentionally manipulate sensor readings or communication channels to obscure fault occurrences. Diagnosability verification under such attack scenarios has recently become an important research direction. Considering multiple attackers with limited observation capabilities, Lin et al. [81] developed a cyber-attack diagnoser (CA-diagnoser) for verifying diagnosability in the presence of malicious interference. Kang et al. [32] construct a joint diagnoser that captures coordinated attack strategies capable of misleading operators or preventing correct diagnosis. A broader body of work studies the impact of sensor-reading attacks on diagnosability [30,125,126,127,128,129]. The decentralized diagnosis method in [128] ensures correct inference despite local attacks. The notion of tamper-tolerant diagnosability, introduced in [126], formalizes the requirement that faults must be detectable even under adversarial manipulation. Subsequent works [32,130,131,132] investigate attack strategies capable of concealing faults, employing specialized structures such as unfolded verifiers and stealthy joint diagnosers. Denial-of-service and deception attacks are addressed in [125] using a robust test diagnoser, while ref. [30,81] develop equivalent-automaton-based methods to detect both faults and attacks concurrently. Extensions of diagnosability under uncertainty include stochastic DESs [133] and new variants such as epistemic diagnosability [134], which concerns whether a system user can detect information leakage to an intruder within bounded delay. Pattern-based diagnosability and decentralized variants are explored in [135,136]. The work in [137] focuses on the active diagnosis for LPNs that may enter deadlocks under coordinated sensor and actuator attacks.

5. Diagnosability Enforcement

Diagnosability enforcement concerns modifying the behavior or structure of a discrete-event system (DES) so that the system becomes diagnosable when diagnosability is not satisfied initially. Unlike diagnosability verification, which only checks whether faults can be detected within finite delay, enforcement actively ensures that ambiguous behaviors are eliminated or restricted. Two mainstream approaches have been widely studied: supervisory control-based enforcement, where a supervisor disables or restricts certain controllable events to guarantee diagnosability, and event relabeling-based enforcement, where selected events are reassigned observable labels to enhance distinguishability between normal and faulty behaviors. These methods aim to minimally modify the system while ensuring diagnosability. In the following subsections, we separately discuss diagnosability enforcement for untimed models, where the system dynamics are governed solely by discrete event sequences, and for timed models, where timing constraints or clocks influence enforceability. Each setting introduces different challenges and solution techniques.

5.1. Untimed Model

In the framework of untimed DESs without attacks, the diagnosability enforcement problem is typically addressed by modifying either the observation structure or the control behavior of the system. Several works focus on adjusting the observation structure [138,139,140,141,142,143,144]. In [144], diagnosability is enforced by selecting an optimal set of observations based on a Markov decision formulation that minimizes sensing cost. In stochastic DESs, diagnosability is achieved by dynamically enabling or disabling sensors depending on the system conditions [139,140]. Other studies [141,142,143,145] introduce relabeling functions and formulate integer linear programs to enforce diagnosability when relabeling operations are associated with numerical costs. Another line of research uses supervisory control to prevent diagnosability violations by disabling specific controllable events [27,29,138,146,147]. The works in [146,147] address diagnosability enforcement for deadlock-free systems, while refs. [27,29] extend the approach to plants that may contain deadlocks. More recent developments consider systems under sensor manipulations. The study in [31] investigates enforcement under replacement, deletion, and insertion of sensor readings, thereby addressing a form of robust diagnosability under observation tampering.

5.2. Timed Model

In timed DESs, each observation includes not only the sequence of events but also their occurrence times. Consequently, two observation strings containing the same events may still be distinguishable if their timing information differs. This inherent expressiveness allows timing constraints to play a direct role in diagnosing faults. As a result, diagnosability enforcement in timed models often requires regulating not only the enabled behavior of the system but also the timing of controllable events. The study in [148] investigates diagnosability enforcement from the perspective of active diagnosis. When a system is not diagnosable, supervisory control can be used to prevent faults from occurring silently by appropriately restricting the system’s evolution. In the timed setting, such enforcement may involve adjusting the permissible time intervals of controllable transitions so that timing information becomes sufficiently informative to distinguish faulty and non-faulty behaviors. Motivated by this idea, ref. [148] first constructs a verifier for time-interval automata to check diagnosability. Based on the verifier, diagnosability is enforced by regulating the occurrence times of selected controllable events—by tightening their time intervals—and by disabling certain controllable events when necessary. This line of work illustrates that, in timed DESs, timing regulation becomes an additional and powerful mechanism for diagnosability enforcement, complementing traditional approaches that rely solely on event disabling, relabeling, or observation restructuring in untimed models.

5.3. Similar Work

Several related studies investigate problems closely connected to diagnosability enforcement, particularly focusing on how diagnosability can be violated or compromised through adversarial behaviors. Kang et al. [32] construct a joint diagnoser structure for diagnosability verification, providing insights into circumstances under which diagnosability can fail. A series of works [130,131,132] analyze diagnosability in networked DESs modeled by LPN under malicious external attacks. In particular, ref. [131] examines the opposite perspective of codiagnosability enforcement [149] and robust codiagnosability [120,123,125], studying how an attacker can intentionally violate codiagnosability. The motivation is to design attack strategies capable of concealing the occurrence of critical faults and compromising the system’s ability to diagnose them. For example, an intruder manipulating sensor readings in communication channels may prevent a security-critical system, such as a banking network, from detecting abnormal or faulty behaviors, rendering the system non-diagnosable under attack.
Table 1 highlights the fundamental trade-offs between automata-based and Petri net-based fault diagnosis frameworks. Automata-based approaches benefit from conceptual clarity and mature verification techniques but suffer from state-space explosion and limited ability to represent concurrency. Petri net-based methods provide a more faithful modeling of concurrent and resource-sharing systems and enable diagnosis of unbounded plants, at the cost of higher structural complexity. The table clarifies that no single framework dominates. Instead, method selection depends on the desired balance between modeling capability and scalability.
Table 1. Comparative analysis of fault diagnosis frameworks and methods.

6. Opacity Analysis

Opacity is an information-flow property that characterizes what an external observer (the intruder) can or cannot infer about the secret behavior of the system under partial observation, as shown in Figure 3. Any formal treatment of opacity begins with a precise specification of the following:
1.
What the system does (the underlying system model);
2.
What the intruder sees (the manner in which observations are generated);
3.
What the intruder knows (the representation of what an intruder can infer).
Figure 3. Illustration of opacity.
This tripartite structure appears throughout the opacity literature beginning with early formulations of security and opacity in DESs [33,34] and remains the basis of modern extensions.

6.1. System Models

Opacity has been investigated under a wide range of modeling formalisms, reflecting the increasing complexity of modern cyber–physical systems. The dominant framework uses classical finite state automata, which form the backbone of the literature and underpin many of the foundational results on verification and enforcement of opacity [56,57,58,61,62,63,64,67,68].
Beyond finite state automata, Petri net models provide expressive representations for concurrent and resource-constrained systems. Opacity verification in this setting often relies on symbolic state-space abstractions, such as basis reachability graphs and LPNs verifiers [41,42,43], and is particularly useful when concurrency cannot be encoded compactly in automata.
Timed automata/Petri nets incorporate timing information into transitions or markings, enabling the study of opacity notions that depend on temporal patterns, which includes opaque time, time-bounded opacity, and timed current-state opacity [44,45,46,47]. In parallel, networked DES models augment the underlying automaton or Petri net representation with explicit channel states to capture communication delays, packet losses, and reordering, allowing opacity to be analyzed under realistic communication imperfections [48,49,50].
Markov chains and probabilistic automata introduce randomness into transitions, leading to probabilistic or quantitative opacity formulations that assess secrecy in terms of belief or likelihood rather than binary predicates [52,53]. Fuzzy and approximate automata generalize further by accommodating imprecision and metric-based reasoning, yielding graded opacity notions suitable for systems subject to uncertainty or approximate sensing [54,55].
Taken together, these models show how opacity theory has evolved from classical automata to a diverse family of formalisms capable of capturing concurrency, timing, communication irregularities, stochasticity, and fuzziness. Automata remain the core definitional platform, but alternative formalisms offer specialized expressive power and model-specific verification tools [1,150]. Figure 4 shows that opacity-related studies predominantly rely on automata-based models, followed by LPNs, while timed Petri nets and other uncertainty-aware formalisms remain comparatively underrepresented. This suggests a promising research direction toward extending opacity analysis to concurrency, timing, and uncertainty enriched modeling frameworks.
Figure 4. Distribution of opacity-related publications by primary modeling formalism.

6.2. Observation Structure

The system is in general considered under partial observation, that is, the set of events is partitioned into the subset of observable events and the subset of unobservable events Σ = Σ o Σ u o . The intruder observes only the projection P : Σ * Σ o * . Thus, the intruder sees only the observable part of the execution; many different real traces may generate the same observation; opacity exploits this ambiguity to hide secret behavior. If the observation of the intruder were complete ( Σ o = Σ ), opacity would typically be violated.
Over the years, several observation models have been considered in the literature to capture more realistic sensing and communication phenomena:
1.
Classical partial observation: the intruder sees exactly P ( s ) , as in [33,34], and opacity depends solely on the erasure of unobservable events.
2.
Timed observations: events carry timestamps or are associated with timing constraints, which allows the intruder to refine inference based on temporal patterns and can endanger opacity [44,45,46,47].
3.
Delayed observation: the intruder receives observations subject to communication delays, packet losses, or disorder, as in networked settings [48,49,50,51].
4.
Probabilistic observations: the observation process is subject to random erasures or channel effects; the observer receives events according to some probability law, as in probabilistic opacity frameworks [52,53].
5.
Asymmetric observations: different agents (e.g., user/defender and intruder) see different subsets of events, with no inclusion relation between them, as in [65,151].
These observation structures enrich the classical projection model and reveal how communication, sensing imperfections, and timing can significantly affect the feasibility and robustness of opacity.

6.3. Intruder Knowledge Representation

Once a plant model and an observation structure are fixed, the knowledge representation formalizes how the intruder interprets observations, updates its internal belief about the system’s possible states or behaviors, and decides whether a secret conclusion can be drawn [1,150].

6.3.1. Knowledge as Set-Valued State Estimation

In the classical DES literature, the intruder is modeled as a passive state estimator [33,34,35,37,40]. Given an observation α Σ o * , the estimate of the intruder is
E ( α ) = { x X s L ( G ) : δ ( x 0 , s ) = x , P ( s ) = α } ,
which contains all states of the plant that are consistent with at least one execution whose projected observation matches α . This set-valued representation is foundational to state-based opacity notions: opacity typically requires that E ( α ) always contains at least one nonsecret state whenever secret states are possible.

6.3.2. Knowledge via Language Semantics

In language-based opacity, the intruder reasons about execution strings rather than internal states. For an observable sequence α Σ o * , the intruder considers the set of all system strings whose projection equals α ,
L G ( α ) = { λ L ( G ) P ( λ ) = α } .
A secret is specified as a subset L s L ( G ) , and opacity requires that after any observation α , the intruder cannot conclude that all strings in L G ( α ) lie in L s . This language-based perspective is used, for example, in runtime validation and enforcement of various opacity properties [150,152].

6.3.3. Other Knowledge Models

In stochastic DES representations, the intruder maintains a probability distribution (belief vector) over the state space, which is updated using Bayes-style filtering conditioned on observed events. Such probabilistic knowledge models are appropriate when transitions or observations are inherently random, and they underlie probabilistic opacity formulations [52,53].
Timed DESs introduce observations with timestamps or timing constraints. In these models, intruder knowledge is represented over time-region or marking-class structures, allowing executions to be distinguished based on their temporal patterns [44,45,46,47].
More recent works consider epistemic extensions, where the secret concerns what an agent knows about another agent’s knowledge, leading to notions such as high-order opacity and pre-opacity [74,153]. In fuzzy and approximate settings, knowledge may be represented by fuzzy sets or metric neighborhoods rather than crisp subsets of states [54,55].
Opacity notions in later Section formalize this requirement by specifying, for each type of knowledge representation, the conditions under which the intruder’s knowledge remains sufficiently ambiguous to preserve the secrecy specification.
To structure the developments in the literature, we classify existing work into four complementary categories that reflect the evolution of the field, as shown in Figure 5. The first category concerns pure logical opacity notions, where opacity is defined as a qualitative indistinguishability property on automata or Petri nets (e.g., CSO, ISO, IFO, K-step opacity, and language-based opacity). The second category captures opacity in complex system contexts, where classical definitions are extended to networked DESs, distributed or modular systems, and timed models. The third category comprises adversarial and strategic settings, in which opacity is treated as a security problem involving an active intruder. The final category concerns quantitative and probabilistic opacity, including probabilistic, fuzzy, approximate, and metric-based opacity, as well as quantitative leakage measures such as exposure time and revelation time.
Figure 5. Evolution of opacity research across four complementary directions.
This four-way classification illuminates the trajectory of opacity research: early work focused on defining and verifying qualitative notions, whereas recent work increasingly addresses complex architectures, adversarial interactions, and quantitative assessments of information leakage.
In cyber–physical and industrial control systems, opacity captures fundamental security and privacy requirements, such as preventing external observers or attackers from inferring system operating modes, production schedules, fault states, or control strategies. For example, in ICS and smart grid applications, the disclosure of internal states or event sequences may reveal system vulnerabilities, facilitate targeted attacks, or compromise operational confidentiality. Opacity notions therefore formalize information-flow constraints that arise naturally in secure monitoring, intrusion-aware supervision, and privacy-preserving control architectures.

7. Opacity Notions

Opacity formalizes the requirement that an external intruder, equipped with the partial observations and knowledge representations introduced earlier, must remain unable to determine whether a designated secret behavior has occurred. A variety of opacity notions have been developed, depending on whether the secret is specified as a state, a set of executions, a temporal property, or a probabilistic or epistemic condition. This section reviews the main notions in a unified manner and groups them into logical and non-logical opacity.

7.1. Logical Opacity

Logical opacity refers to secrecy properties defined purely through set-based indistinguishability under the intruder’s observation mapping. Such properties are qualitative: the system either satisfies the opacity condition or it does not, and no intermediate degrees of secrecy are considered. These notions form the classical foundation of the field and underpin most early work on opacity.

7.1.1. Language-Based Opacity (LBO)

Language-based opacity concerns secrecy of entire behaviors. Given a secret language L s L ( G ) , the intruder observes an observation word α Σ o * and considers all system executions whose projection equals α . Opacity holds if the intruder never encounters an observation whose only possible preimages are secret executions [34,150,152]. This notion is central in runtime monitoring and trace-based validation tasks.

7.1.2. Current-State Opacity (CSO)

Current-state opacity focuses on the plant’s possible states after an observed execution. Let X s X denote the set of secret states. After observing α , the intruder forms a state estimate E ( α ) consisting of all states reachable by some execution with projection α . CSO requires that whenever the system actually reaches only secret states, the corresponding estimate E ( α ) must still include at least one nonsecret state. Thus, the intruder can never conclude, based on observation alone, that the current state lies entirely inside the secret region. CSO is the most extensively studied opacity notion [33,37,41,42,43,67,68].

7.1.3. Initial-State Opacity (ISO)

Initial-state opacity protects confidentiality of the initial configuration. When different initial states have indistinguishable observable behavior, the intruder must never be able to infer that the system began in a secret initial state, even after observing arbitrarily long executions [36]. This notion is particularly relevant when the initial condition encodes private information.

7.1.4. Initial-and-Final-State Opacity (IFSO)

Initial-and-final-state opacity generalizes ISO by simultaneously requiring ambiguity about both the system’s starting and ending state [154]. Even after observing a complete execution, the intruder must be unable to determine whether the system started from a secret initial state or terminated in a secret final state. Recent work refines this notion by introducing stronger temporal variants that enforce secrecy at all intermediate points [39,40].

7.1.5. K-Step and Infinite-Step Opacity

K-step opacity requires ambiguity about whether the system visited a secret state within the last K events prior to the current observation [35]. Infinite-step opacity strengthens this requirement so that the intruder must never become certain about any past secret visit, regardless of how long ago it occurred [155]. These notions impose temporal depth on secrecy and are widely used in attack detection and privacy-preserving diagnosis.

7.1.6. High-Order and Epistemic Opacity

Epistemic extensions of opacity capture settings where the secret concerns not only the system state but also what one agent knows about another agent’s knowledge. High-order opacity ensures that the intruder cannot deduce that another agent has inferred the secret [153]. Pre-opacity protects future intentions rather than past or present behavior, requiring the intruder to remain uncertain about whether the system is guaranteed to reach a secret state in all future continuations [74]. These extensions connect opacity with epistemic logic and multi-agent reasoning.

7.2. Non-Logical Opacity Notions

Non-logical opacity generalizes the classical notions by incorporating timing, probability, fuzziness, communication effects, or continuous leakage metrics. Rather than a Boolean yes/no condition, secrecy is evaluated in terms of how robustly the system maintains ambiguity under realistic conditions.

7.2.1. Timed Opacity

In timed automata/Petri nets, timestamps and timing constraints can enable the intruder to distinguish executions that are observationally identical in the untimed sense. Timed opacity therefore requires preserving ambiguity in both the discrete event sequence and the temporal evolution [44,45,46,47]. This has led to notions such as opaque time, time-bounded opacity, and timed current-state opacity.

7.2.2. Probabilistic Opacity

In probabilistic opacity, the intruder maintains a belief distribution over the state space. Opacity requires that the posterior probability assigned to secret behavior remains below a specified threshold or that the intruder never reaches certainty about the secret. Additional continuous leakage metrics, such as exposure or revelation time, quantify the rate at which information accumulates [44,52,53].

7.2.3. Fuzzy and Approximate Opacity

Fuzzy and approximate opacity arise when states or observations have graded membership or metric uncertainty rather than crisp boundaries. Opacity is expressed as an approximate indistinguishability requirement: the observed behavior must remain sufficiently close (in a fuzzy or metric sense) to at least one nonsecret behavior [54,55]. These notions are motivated by noisy sensors, approximate measurements, or hybrid cyber–physical settings.
Remark 1.
Logical opacity demands binary secrecy: the intruder must never be able to rule out all nonsecret alternatives. Non-logical opacity broadens this framework by allowing secrecy to be quantified (probabilistic or fuzzy), distorted (due to timing or network effects), or epistemic (involving multi-agent knowledge). Despite these differences, all opacity notions share the same essential requirement: every observation must preserve enough ambiguity to prevent the intruder from conclusively inferring the secret.
From a sensing standpoint, opacity formalizes the requirement that sensor observations, logs, or communicated measurements should not allow an external observer to infer sensitive system states or execution histories. In this sense, opacity captures information-flow security constraints induced by sensing architectures. Opacity violations thus correspond to information leakage through sensor exposure, while opacity enforcement mechanisms aim to regulate or distort sensor-visible behavior to preserve confidentiality.

8. Opacity Verification Approaches

Opacity verification has evolved into a technically rich research area spanning automata, Petri nets, timed models, and stochastic or fuzzy formalisms. Despite the diversity of these models, the core question is always the same: whether an external observer, based solely on its partial observations, can uniquely infer that a secret state or behavior has occurred. Over the past two decades, verification techniques have progressed from classical observer constructions for finite automata to sophisticated symbolic abstractions for concurrent and timed systems and to quantitative frameworks that measure information leakage. This section reviews these developments in a unified manner.

8.1. Opacity Verification in Automata

Finite state automata remain the foundational setting for opacity verification, owing to their regular-language structure and compatibility with observer-based reasoning. Most classical opacity notions, including CSO, ISO, and LBO, were first formalized in this framework.
The verification of CSO was established in [33] using an observer automaton that tracks state-estimate evolution under partial observation. A violation occurs when an estimate becomes a subset of the secret states. While the observer construction is polynomial in the number of transitions, its size is exponential in the number of states due to the subset construction.
LBO was studied extensively by Lin [34], which provided verification methods for strong and weak variants by constructing synchronized products that compare strings sharing the same observation. These constructions also incur exponential complexity.
Saboori and Hadjicostis later developed the verification framework for ISO [36]. Their initial-state estimator aggregates all initial states consistent with an observed word, and ISO is violated when an estimate contains no nonsecret initial state. This approach leads to PSPACE-complete complexity even for deterministic automata.
Temporal opacity extensions required more elaborate estimators. K-step opacity and infinite-step opacity, introduced in [35,155], rely on estimators that track both current and past states, resulting in doubly exponential worst-case complexity. A significant breakthrough came with the two-way observer of Yin and Lafortune [156], which separates forward and backward information propagation and yields far more scalable verification for K-step and infinite-step opacity.
Across these developments, the common technique is the construction of an observer-like structure that encodes all states consistent with a given observation. The challenge lies in controlling the exponential growth of these structures while preserving completeness.

8.2. Opacity Verification Using Petri Nets

Petri nets provide a natural modeling formalism for concurrent and distributed DESs, where multiple transitions may fire independently. This concurrency makes traditional observer constructions infeasible, and opacity verification methods have therefore diverged considerably from their automata counterparts.
Opacity in Petri nets was first addressed by Bryans et al. [157], which established that while certain opacity notions are decidable for bounded nets, opacity becomes undecidable in general. This motivated the development of symbolic abstractions that avoid explicit reachability-graph construction.
Tong et al. adopted the basis reachability graph (BRG) [41,158,159] in opacity problems. The BRG compactly represents reachable markings using equivalence classes based on minimal explanations of unobservable transitions. This symbolic abstraction supports verification of CSO and ISO without constructing the full reachability graph such that scalability is improved. For LBO, Tong et al. [160] developed the verifier-net method, which avoids enumerating all firing sequences and yields efficient verification for bounded nets whose unobservable subnet is acyclic.
Beyond BRG-based approaches, Basile and Tommasi [161] proposed an algebraic method for language-based opacity based on integer linear programming (ILP). This method applies even to unbounded nets, eliminating the need for reachability analysis and instead checking opacity through structural constraints encoded as linear inequalities.
Cong et al. further extended opacity verification to online settings [162,163], where ILP queries are evaluated at runtime, enabling on-the-fly CSO and ISO verification. Recent work also considers decentralized and distributed observers, allowing multiple intruders to infer secrecy collaboratively.
Overall, Petri-net verification emphasizes symbolic reachability, structure-based abstractions, and algebraic characterizations—techniques needed to handle concurrency and large state spaces.

8.3. Quantitative Verification

Binary opacity verification is often too restrictive in systems where partial information leakage is unavoidable or acceptable up to a threshold. This led to the development of quantitative opacity measures that evaluate secrecy along probabilistic, fuzzy, or metric dimensions.
Foundational work by Lakhnech and Mazaré introduced probabilistic opacity and cryptographic interpretations of secrecy [164]. Bryans et al. [165] later formalized probabilistic opacity in transition systems, laying the groundwork for quantitative leakage analysis.
A major advance came from Bérard et al. [166], which introduced the dual measures of Liberal Probabilistic Opacity (LPO); the probability that the intruder can confirm the secret; and Restrictive Probabilistic Opacity (RPO), the expected uncertainty preserved about the secret. These metrics allow fine-grained assessment of information leakage.
Saboori and Hadjicostis defined probabilistic current-state opacity and developed Markov chain estimators [167]. Keroglou and Hadjicostis extended this to probabilistic initial-state opacity and provided a polynomial-time algorithm for a class of probabilistic systems [52,168]. Yin et al. [53] introduced infinite-step and K-step probabilistic opacity using belief-state abstractions.
Fuzzy opacity [54] generalizes secrecy to settings with graded membership, requiring that the possibility degree of secret behaviors never dominates that of nonsecret behaviors. Approximate opacity [55] uses metrics on state trajectories to ensure that observations remain “close enough” to nonsecret behavior in cyber–physical systems subject to noise.
Timing further complicates opacity verification. Temporal information can distinguish executions that are otherwise observationally identical, requiring region graphs, zone graphs, or marking-class graphs for analysis. Early timed opacity notions were refined in [44], which introduced exposure and revelation time metrics for timed stochastic DESs. Recent work in networked systems examines opacity under communication delays, losses, and reordering [49]. Time LPNs [45,46,47] support fine-grained reasoning about timing intervals and have inspired new verification procedures based on time-expanded state-space analysis.
Across all quantitative frameworks, verification reduces to analyzing the intruder’s evolving belief or possibility distribution. While conceptually straightforward, these belief spaces are often continuous or high-dimensional, making abstraction and convexity tools essential.
In summary, opacity verification has progressed from observer-based automata techniques to symbolic Petri-net abstractions and quantitative frameworks for timed, probabilistic, and fuzzy systems. Despite major advances, the computational complexity of verifying opacity remains high (often PSPACE-hard or exponential), which highlights the need for scalable abstractions, compositional reasoning, and data-driven verification techniques.

9. Opacity Enforcement Approaches

Opacity enforcement concerns modifying either the system’s behavior or the information revealed to the intruder so that, under the given observation structure and knowledge representation, the secret cannot be deduced. Whereas verification asks whether the plant already satisfies the opacity requirement, enforcement aims to transform the system without violating admissibility or correctness constraints so that opacity holds for all executions consistent with the enforced behavior. Enforcement strategies mainly differ according to whether they modify the information revealed to the intruder or constrain the evolution of the system through supervisory control. Across these diverse approaches, the unifying goal is to restore or preserve indistinguishability whenever the system’s natural behavior would otherwise expose the secret.

9.1. Channel-Based Enforcement: Edit and Insertion Mechanisms

One of the most extensively studied enforcement paradigms is based on edit functions, insertion functions, and related obfuscation mechanisms that act directly on the observation channel between the plant and the intruder (shown in Figure 6). The key idea is that the intruder no longer sees the observations generated by the system, but rather a modified observation outputted by an obfuscation mechanism. This line of research originates from the seminal work of Wu and Lafortune [56], who introduced insertion functions to enforce opacity by augmenting observable traces with fictitious events so that every secret-revealing observation becomes indistinguishable from a nonsecret alternative. Their subsequent development of optimal insertion functions incorporated cost criteria and showed how to synthesize minimally disruptive policies that preserve opacity while adhering to constraints on the allowed insertions [57]. Edit functions, introduced in [169], generalize this idea by allowing insertion, deletion, and substitution.
Figure 6. Obfuscation-based enforcement architecture acting on the observation channel.
Building on this foundation, Ji et al. [170] further investigated scenarios in which insertion functions may be known to the intruder. Moreover, they introduced nondeterministic publicly known edit functions [58], in which the additional nondeterminism enlarges the set of edited behaviors and can make opacity enforcement feasible in cases where deterministic insertion would fail. Keroglou and Lafortune proposed embedded insertion functions, where the enforcer is integrated within the plant model and must satisfy structural constraints on when and how insertions can occur [60]. These ideas were further refined in the work of Li et al., who developed extended insertion functions capable of handling constraints on the inserted language and later proposed modification functions that unify insertion and deletion within a single enforcement framework [61,62,66].
To address scalability, Mohajerani et al. introduced a compositional and abstraction-based synthesis method for edit functions [59], which enables enforcement in large-scale composed systems by working on abstract models and refining the resulting editors back to the original plant. More recently, Liu et al. [63,64] investigated greedy synthesis of privately and publicly known insertion functions and proposed improved constructions for nondeterministic publicly known editors, focusing on complexity reduction and practical implementability. Duan et al. introduced event concealment and concealability enforcement, which address opacity at the level of events rather than states and show how obfuscation mechanisms can be used to enforce event-level secrecy in an efficient manner [72].
A central challenge throughout this line of work is to guarantee that the editing process is realizable and does not introduce blocking or inconsistencies in the modified observation stream. This motivated the synthesis of edit mechanisms as finite automata whose accepted language matches the set of all edited observations consistent with some plant execution, so that every edit corresponds to a feasible continuation of at least one system trajectory. More recent work has examined enforcement under uncertain or degraded observation on the editor side, where the edit mechanism operates with its own (possibly incomparable) observation structure relative to the intruder [65]. In such settings, the editor must guarantee opacity even though it does not fully know what the intruder sees.
Overall, channel-based enforcement is attractive because it preserves the plant’s behavior, requires no control authority over events, and is compatible with the original systems. Its limiting factor is the need for realizability and linguistic consistency between the edited output and the plant’s observable language.

9.2. Control-Based Enforcement: Supervisory and Structural Approaches

A complementary paradigm constrains the plant execution rather than modifying observations. In this view, opacity enforcement is cast as a supervisory control problem (shown in Figure 7): the supervisor observes the system (under its own partial observation) and disables selected controllable events so that no secret-revealing behavior remains reachable.
Figure 7. Opacity-enforcing supervisory control architecture.
The earliest systematic treatment of this idea appears in the work of Dubreil et al. [67], who formulated opacity enforcement as a supervisory control problem and characterized conditions for the existence of supervisors enforcing language-based opacity. Saboori and Hadjicostis [68] subsequently developed a state-estimator-based synthesis method that constructs opacity-enforcing supervisors from an observer-like structure, thereby connecting opacity enforcement with classical DES supervision.
Later contributions extended these ideas to decentralized and more complex architectures. Tong et al. considered decentralized opacity enforcement, where multiple local supervisors with limited observation and control must cooperate to enforce a global opacity specification [69]. Xie et al. introduced nondeterministic supervisors for opacity enforcement, showing that nondeterministic control laws can enlarge the class of enforceable opacity requirements compared to deterministic supervisors [70]. Moulton et al. proposed using subobservers to synthesize opacity-enforcing supervisors, emphasizing the reduction in state-space explosion by working on compressed observer structures [71].
Petri-net and distributed DES models require analogous but structurally richer control-based enforcement strategies. In labeled and time LPNs, secret-revealing markings may arise due to independent or concurrent firings, and opacity-preserving control laws are typically derived from symbolic structures such as labeled Petri-net observers, verifier nets, basis reachability graphs, or marking-class graphs [41,42,43,45,46,47].
In distributed or modular systems, different components may have distinct observability and controllability profiles, motivating decentralized or cooperative opacity enforcement schemes. Paoli and Lin studied decentralized opacity for DESs and highlighted fundamental limitations when local observers lack sufficient information [73].
In networked DESs, the communication channel itself becomes an adversarial element: delays, losses, or reordering can create or eliminate ambiguity. Control-based enforcement may therefore need to regulate not only plant-level transitions but also communication behavior, for instance by shaping the timing or acknowledgment patterns of transmitted events [49]. Recent work on online opacity verification and enforcement for networked Petri nets and automation systems further develops this perspective, with Li et al. proposing online opacity verification algorithms for networked Petri-net models that naturally suggest online enforcement mechanisms [50]. In such frameworks, enforcement decisions are updated as events are produced and transmitted, ensuring that opacity is maintained in real time despite channel uncertainties and network dynamics.
In summary, control-based enforcement is powerful when control authority exists, and it aligns well with standard DES supervision. Its limitations stem from controllability restrictions, decentralized information structures, and scalability of estimator-based synthesis.

9.3. Comparison Between Channel-Based and Control-Based Enforcement

Channel-based and control-based opacity enforcement represents fundamentally different strategies for preserving confidentiality under partial observation. Control-based enforcement relies on supervisory control to restrict or modify system behavior so that opacity is maintained. Such an approach provides strong formal guarantees and integrates naturally with existing control architectures but may reduce system permissiveness or performance due to behavior disabling or restriction.
In contrast, channel-based enforcement mechanisms, such as edit and insertion functions, aim to preserve the original plant behavior by manipulating the information revealed through observation channels. These methods are particularly attractive when direct control over the system is limited or undesirable and when confidentiality must be enforced without altering physical behavior. However, channel-based approaches introduce additional challenges related to realizability, boundedness, and computational complexity of obfuscation mechanisms, and often rely on assumptions about communication capabilities and attacker models.
From a practical standpoint, control-based enforcement is well suited to settings where supervisory authority is available and behavioral modification is acceptable, while channel-based enforcement is more appropriate in monitoring or auditing contexts where behavior preservation is critical. In many applications, hybrid approaches combining control and channel manipulation may offer a favorable trade-off between confidentiality, performance, and implementability.

9.4. Enforcement for Non-Logical Opacity

Non-logical opacity introduces probabilistic, fuzzy, metric, or timed dimensions, for which classical editing or supervisory control techniques must be adapted or generalized.
Probabilistic opacity requires that the intruder’s posterior probability of secret behavior remain below a desired threshold. Foundational work by Keroglou and Hadjicostis [52] and later by Yin et al. [53] showed how belief distributions propagate in stochastic DESs, leading to infinite-step and K-step probabilistic opacity definitions. Enforcement may modify transition probabilities, randomize event occurrences, or introduce probabilistic editing policies so that the probability of revealing the secret remains acceptably low.
In fuzzy opacity [54], states and observations have degrees of membership. Enforcement must preserve the ordering of secret versus nonsecret possibility levels. Approximate opacity [55] replaces crisp equality with metric closeness: the enforcer ensures that every observed behavior lies within an ε -ball of some nonsecret behavior, relevant in CPSs subject to noise.
Exposure and revelation metrics [44] quantify how long secrets remain protected before becoming inferable. Enforcement strategies may slow down secret-related transitions or synchronize timing to reduce distinguishability. Network-induced uncertainty, including delays and reordering, adds another layer where enforcement regulates transmission timing or acknowledgment patterns.
Table 2 summarizes the key differences between observer-based and structural or algebraic approaches to opacity verification and enforcement. Observer-based methods offer a conceptually unified framework for reasoning about intruder knowledge evolution, but often suffer from severe state-space explosion. Structural and algebraic techniques exploit concurrency and system structure to improve scalability, particularly for Petri net models, at the cost of stronger modeling assumptions. The table also clarifies the complementary roles of control-based and channel-based enforcement: the former modifies system behavior to ensure opacity, while the latter preserves behavior by manipulating information exposed through observation channels.
Table 2. Comparative analysis of opacity verification and enforcement paradigms.

10. Diagnosis vs. Opacity

10.1. Diagnosis and Opacity Analysis

Fault diagnosis and opacity are both concerned with reasoning about hidden information in a partially observed DES. In fault diagnosis, the goal is to determine, from observable behavior, whether an unobservable fault has occurred. In opacity, the aim is to prevent an external observer from determining whether a confidential behavior has occurred. Thus, although the motivations differ, the two problems share a common informational structure.
This connection becomes evident when comparing their core definitions. A system is diagnosable if every faulty execution eventually becomes distinguishable from all nonfaulty ones; that is, the diagnoser’s estimate must ultimately collapse to the fault set. Opacity requires the opposite evolution: every secret execution must remain indistinguishable from at least one nonsecret execution, so the intruder’s estimate must never collapse to the secret set.
Despite this inverted objective, the technical machinery is largely shared. Both problems rely on state estimators that track the set of states consistent with the observed sequence, and both verify conditions on the reachability of designated subsets of this estimate. Observer automata, twin-plant constructions, and symbolic Petri-net abstractions (e.g., BRGs ad verifier nets) appear in both diagnosis and opacity analysis. In probabilistic settings, the same belief-update mechanisms underpin probabilistic diagnosability and probabilistic opacity.
The duality extends naturally to enforcement. Fault-tolerant control seeks to guarantee that faults can be detected or mitigated; opacity-enforcing mechanisms seek to prevent disclosure of secret-revealing behaviors. In both cases, feasibility depends on how controllability and observability constraints influence the evolution of the observer’s knowledge.
Conceptually, diagnosis and opacity can therefore be viewed as complementary information-flow problems. Diagnosis requires that the system become sufficiently informative for an observer to infer the fault, while opacity requires that the system remains sufficiently ambiguous to hide the secret. By presenting them side by side, their shared methodological roots and opposing operational objectives become clear, highlighting that both are instances of reasoning about knowledge evolution in partially observed DESs.
Advanced constructs such as K-step opacity, basis reachability graphs, and verifier nets should be interpreted as scalability-enabling abstractions rather than purely theoretical refinements. In real industrial systems, concurrency, timing constraints, and large or unbounded state spaces make explicit state enumeration infeasible. Symbolic structures like basis reachability graphs and verifier nets allow opacity and diagnosability properties to be verified and enforced without constructing the full reachability graph, thereby enabling analysis of complex manufacturing systems, transportation networks, and networked automation architectures. Similarly, K-step opacity reflects practical requirements where only recent system behavior is considered sensitive, aligning with sliding-window monitoring and limited-memory intrusion detection mechanisms used in practice.
While fault diagnosis and opacity originate from different application goals, their verification and enforcement procedures rely on closely related observer-based constructions. To complement the conceptual discussion, Table 3 summarizes the main technical correspondence between diagnosis and opacity by aligning their main analysis tasks and associated constructs. This comparison highlights that many mathematical tools are structurally similar yet are used for opposite purposes: diagnosis aims to eliminate ambiguity about faults, whereas opacity aims to preserve ambiguity about secrets.
Table 3. Main technical correspondence between fault diagnosis and opacity analysis.

10.2. Computational Complexity and Scalability Considerations

A recurring challenge in both fault diagnosis and opacity analysis is the combinatorial explosion caused by partial observation, concurrency, and temporal extensions. While many verification and enforcement problems are known to be PSPACE-complete or exponential in the worst case, the practical applicability of a method depends critically on the chosen modeling formalism, abstraction strategy, and structural assumptions. In this subsection, we provide a comparative perspective on the computational characteristics of representative approaches, with the aim of clarifying which methods are suitable for medium-scale systems and which primarily serve as theoretical benchmarks.
Observer-based methods for automata-based models, while conceptually simple, suffer from exponential state-space growth due to subset construction and are typically limited to small or moderately sized systems. Verifier-based and twin-plant approaches reduce complexity by avoiding full observer construction and are often applicable to medium-scale automata under reasonable observability assumptions.
In Petri net models, reachability-graph-based techniques quickly become infeasible due to unboundedness and concurrency. Symbolic abstractions such as basis reachability graphs and verifier nets significantly improve scalability by exploiting structural properties of unobservable subnets and are among the few approaches applicable to medium-scale concurrent systems
Algebraic and ILP-based methods avoid explicit state enumeration and are therefore well suited for large or unbounded Petri nets; however, they typically shift complexity to solving integer programs, which may affect online applicability.
Quantitative opacity and timed extensions introduce additional sources of complexity, often leading to doubly exponential constructions. These methods are primarily applicable to small systems or offline analysis, although abstraction and compositional techniques can mitigate complexity in specific cases.
Moreover, Table 4 provides a comparative overview of verification and enforcement methods, highlighting which approaches are primarily of theoretical interest and which are commonly applicable to medium-scale industrial systems under reasonable modeling assumptions.
Table 4. Comparison of verification and enforcement approaches in terms of computational complexity and practical scalability.

11. Future Directions and Open Problems

As DESs increasingly underpin cyber–physical systems, communication infrastructures, and distributed autonomous platforms, understanding what observers can infer and how such inference can be constrained becomes both more essential and more difficult. This section highlights several key research directions (shown in Figure 8) where substantial opportunities remain across modeling, verification, and enforcement.
Figure 8. A compact roadmap of major research directions in opacity and diagnosis.

11.1. Scalability and Complexity

Even with significant advances in observer reduction, symbolic Petri-net abstractions, and timed DES approximations [41,42,43,44,47], diagnosis/opacity verification remains computationally intensive for systems with large state spaces. Knowledge estimates may grow exponentially, and product-based verification may be infeasible in practice. Promising directions include compositional and concurrency-aware abstractions, on-the-fly search, and learning-based reductions. However, a unifying verification theory that ensures both soundness and tractability across heterogeneous models is still lacking.

11.2. Decentralized and Distributed Settings

Many real systems rely on asynchronous communication and heterogeneous sensing. Editors and supervisors may not know precisely what other agents observe, and opacity under incomparable or asymmetric observation structures remains largely open [65]. Online enforcement becomes particularly difficult when decisions must be taken without knowledge of current channel delays, losses, or reorderings [48,50]. Understanding how network-induced uncertainty interacts with opacity-enforcing mechanisms calls for new theoretical tools and architectural designs capable of maintaining secrecy without degrading performance.

11.3. Non-Logical Diagnosis/Opacity Frameworks

While quantitative verification methods exist [52,53,54], general and scalable enforcement mechanisms remain underdeveloped. A rigorous theory for shaping belief evolution, manipulating possibility distributions, or controlling epistemic relations is still missing. Epistemic opacity, in particular, introduces multi-agent interactions where the secret may concern not only system states but also what one observer knows about another’s knowledge. Extending diagnosis/opacity to strategic or adversarial multi-agent scenarios is a promising frontier connecting DES with epistemic logic, game theory, and distributed systems.

11.4. Hybrid Model-Based and Data-Driven Approaches

Another interesting research direction concerns the integration of logical DES frameworks with machine learning and data-driven techniques. Learning-based methods may help address model uncertainty, scalability, and adaptivity, while formal DES-based approaches provide correctness guarantees. Open questions include how to combine learning with diagnosability and opacity-related enforcement analysis, and how to ensure interpretability in hybrid model-based and data-driven architectures.
In summary, while the foundational theory of opacity and diagnosis is well-established, their application to autonomous, networked, uncertain, and data-driven systems raises significant new challenges. Progress will require new models, scalable algorithms, enriched information structures, and interdisciplinary methods drawing from control theory, computer science, information theory, and game theory. Inference under partial observation remains at the core of these efforts, ensuring that secrecy can be preserved when desired and revealed when necessary.

12. Conclusions

This survey has presented a comprehensive overview of recent advances in fault diagnosis and opacity analysis for discrete event systems. We reviewed classical foundations together with modern developments in diagnosability verification and enforcement, covering automata, Petri net, and extended DES modeling frameworks. Special attention was given to challenges introduced by communication losses, delays, distributed architectures, timing constraints, and various classes of cyber attacks. Parallel to fault diagnosis, we examined opacity verification and enforcement techniques, highlighting their conceptual links to information security, privacy protection, and critical state confidentiality.
Despite significant progress, important challenges remain. Key directions include improving the scalability of verification and enforcement algorithms; integrating diagnosis and opacity considerations within unified frameworks; and designing robust, attack-resilient methodologies suitable for increasingly networked and adversarial environments. By consolidating the current state of the art and identifying open problems, this survey aims to provide a valuable reference for researchers and practitioners and to help shape future work on resilient and secure DESs.

Author Contributions

W.D.: conceptualization, formal analysis, writing—original draft. R.L. and S.Z.: formal analysis, methodology, writing and editing. A.M.M. and M.P.F.: project administration, supervision. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

Enquiries about data availability should be directed to the authors.

Conflicts of Interest

The authors declare that they have no conflicts of interest.

References

  1. Jacob, R.; Lesage, J.J.; Faure, J.M. Overview of discrete event systems opacity: Models, validation, and quantification. Annu. Rev. Control 2016, 41, 135–146. [Google Scholar] [CrossRef] [Scilit]
  2. Lafortune, S.; Lin, F.; Hadjicostis, C.N. On the history of diagnosability and opacity in discrete event systems. Annu. Rev. Control 2018, 45, 257–266. [Google Scholar] [CrossRef] [Scilit]
  3. Zaytoon, J.; Lafortune, S. Overview of fault diagnosis methods for discrete event systems. Annu. Rev. Control 2013, 37, 308–320. [Google Scholar] [CrossRef] [Scilit]
  4. Boussif, A.; Ghazel, M.; Basilio, J.C. Intermittent fault diagnosability of discrete event systems: An overview of automaton-based approaches. Discret. Event Dyn. Syst. 2021, 31, 59–102. [Google Scholar] [CrossRef] [Scilit]
  5. Murata, T. Petri nets: Properties, analysis and applications. Proc. IEEE 2002, 77, 541–580. [Google Scholar] [CrossRef] [Scilit]
  6. Hadjicostis, C.N. Estimation and Inference in Discrete Event Systems; Springer: Berlin/Heidelberg, Germany, 2020. [Google Scholar]
  7. Zhang, S.; Liu, R.; Chen, Y.; Cong, X.; Fanti, M.P. Modeling and Analysis of Time Dependent Petri Nets. In Proceedings of the 2024 IEEE 20th International Conference on Automation Science and Engineering (CASE), Bari, Italy, 28 August–1 September 2024; pp. 2140–2145. [Google Scholar]
  8. Zhang, S.; Liu, R.; Chen, Y.; Fanti, M.P.; Li, Z. Modeling and Analysis of Dual-Time Petri Nets with Application to Semiconductor Manufacturing Systems. IEEE Trans. Autom. Sci. Eng. 2025, 22, 23769–23783. [Google Scholar] [CrossRef] [Scilit]
  9. Zhu, G.; Li, Z.; Wu, N.; Al-Ahmari, A. Fault identification of discrete event systems modeled by Petri nets with unobservable transitions. IEEE Trans. Syst. Man Cybern. Syst. 2017, 49, 333–345. [Google Scholar] [CrossRef] [Scilit]
  10. Moreira, M.V.; Lesage, J.J. Discrete event system identification with the aim of fault detection. Discret. Event Dyn. Syst. 2019, 29, 191–209. [Google Scholar] [CrossRef] [Scilit]
  11. Machado, T.H.d.M.C.; Viana, G.S.; Moreira, M.V. Event-based automaton model for identification of discrete-event systems for fault detection. Control Eng. Pract. 2023, 134, 105474. [Google Scholar] [CrossRef] [Scilit]
  12. Estrada-Vargas, A.P.; Lopez-Mellado, E.; Lesage, J.J. A Comparative Analysis of Recent Identification Approaches for Discrete-Event Systems. Math. Probl. Eng. 2010, 2010, 453254. [Google Scholar] [CrossRef] [Scilit]
  13. Sampath, M.; Sengupta, R.; Lafortune, S.; Sinnamohideen, K.; Teneketzis, D.C. Failure diagnosis using discrete-event models. IEEE Trans. Control Syst. Technol. 1996, 4, 105–124. [Google Scholar] [CrossRef] [Scilit]
  14. Cabasino, M.P.; Giua, A.; Seatzu, C. Fault detection for discrete event systems using Petri nets with unobservable transitions. Automatica 2010, 46, 1531–1539. [Google Scholar] [CrossRef] [Scilit]
  15. Basilio, J.C.; Silva, G.M.O. A Diagnoser-based Approach to Diagnosis and Diagnosability of Repeated Faults of Discrete-Event Systems. IEEE Trans. Autom. Control 2025, 70, 5491–5498. [Google Scholar] [CrossRef] [Scilit]
  16. Pencolé, Y.; Subias, A. Diagnosability of event patterns in safe labeled time Petri nets: A model-checking approach. IEEE Trans. Autom. Sci. Eng. 2021, 19, 1151–1162. [Google Scholar] [CrossRef] [Scilit]
  17. Zhang, Z.; Liu, G.; Li, Z. Adaptive Supervisory Control of Automated Manufacturing Systems with Unreliable Resources Based on Smart Switch Controllers. IEEE Trans. Autom. Sci. Eng. 2024, 21, 5445–5456. [Google Scholar] [CrossRef] [Scilit]
  18. Liu, G.; Li, P.; Wu, N.; Yin, L. Two-step approach to robust deadlock control in automated manufacturing systems with multiple resource failures. J. Chin. Inst. Eng. 2018, 41, 452–462. [Google Scholar] [CrossRef] [Scilit]
  19. Boucheneb, H.; Barkaoui, K.; Xing, Q.; Wang, K.; Liu, G.; Li, Z. Time based deadlock prevention for Petri nets. Automatica 2022, 137, 110119. [Google Scholar] [CrossRef] [Scilit]
  20. Liu, G.Y.; Chao, D.Y.; Uzam, M. A merging method for the siphon-based FMS maximally permissive controllers with simpler structures. IMA J. Math. Control Inf. 2014, 31, 551–573. [Google Scholar] [CrossRef] [Scilit]
  21. Chen, Y.; Liu, G. Computation of minimal siphons in Petri nets by using binary decision diagrams. ACM Trans. Embed. Comput. Syst. (TECS) 2013, 12, 1–15. [Google Scholar] [CrossRef] [Scilit]
  22. Liu, G.; Chao, D.Y. Further reduction of minimal first-met bad markings for the computationally efficient synthesis of a maximally permissive controller. Int. J. Control 2015, 88, 1423–1428. [Google Scholar] [CrossRef] [Scilit]
  23. Abubakar, U.S.; Liu, G. Adaptive supervisory control for automated manufacturing systems using borrowed-buffer slots. Inf. Sci. 2024, 667, 120460. [Google Scholar] [CrossRef] [Scilit]
  24. Abubakar, U.S.; Liu, G.; Barkaoui, K.; Li, Z. Adaptive supervisory control for a class of Petri nets with bimodal transitions. Inf. Sci. 2023, 650, 119683. [Google Scholar] [CrossRef] [Scilit]
  25. Li, X.; Liu, G.; Qin, M.; Li, Z. Robust liveness enforcement of Petri nets with uncontrollable and unobservable transitions based on structural analysis. IET Control Theory Appl. 2023, 17, 477–492. [Google Scholar] [CrossRef] [Scilit]
  26. Hu, Y.; Ma, Z.; Liu, R.; Pia Fanti, M.; Li, Z. Supervisor Synthesis Using Labeled Petri Nets for Forbidden State Specifications. IEEE Trans. Syst. Man Cybern. Syst. 2024, 54, 6242–6254. [Google Scholar] [CrossRef] [Scilit]
  27. Hu, Y.; Ma, Z.; Li, Z. Design of supervisors for active diagnosis in discrete event systems. IEEE Trans. Autom. Control 2020, 65, 5159–5172. [Google Scholar] [CrossRef] [Scilit]
  28. Hu, Y.; Ma, Z.; Li, Z. Design of supervisors for partially observed discrete event systems using quiescent information. IEEE Trans. Autom. Sci. Eng. 2023, 21, 4778–4789. [Google Scholar] [CrossRef] [Scilit]
  29. Hu, Y.; Ma, Z.; Li, Z.; Giua, A. Diagnosability enforcement in labeled Petri nets using supervisory control. Automatica 2021, 131, 109776. [Google Scholar] [CrossRef] [Scilit]
  30. Lin, F.; Lafortune, S.; Wang, C. Diagnosability of discrete event systems under sensor attacks. IFAC-PapersOnLine 2023, 56, 3572–3578. [Google Scholar] [CrossRef] [Scilit]
  31. Hu, S.; Li, Z.; Liu, D. Diagnosability Verification and Enforcement in Labeled Petri Nets Under Sensor Attacks. IEEE Trans. Syst. Man Cybern. Syst. 2025, 55, 3654–3667. [Google Scholar] [CrossRef] [Scilit]
  32. Kang, T.; Seatzu, C.; Li, Z.; Giua, A. A joint diagnoser approach for diagnosability of discrete event systems under attack. Automatica 2025, 172, 112004. [Google Scholar] [CrossRef] [Scilit]
  33. Saboori, A.; Hadjicostis, C.N. Notions of security and opacity in discrete event systems. In Proceedings of the 2007 46th IEEE Conference on Decision and Control, New Orleans, LA, USA, 12–14 December 2007. [Google Scholar]
  34. Lin, F. Opacity of discrete event systems and its applications. Automatica 2011, 47, 496–503. [Google Scholar] [CrossRef] [Scilit]
  35. Saboori, A.; Hadjicostis, C.N. Verification of K-Step Opacity and Analysis of Its Complexity. IEEE Trans. Autom. Sci. Eng. 2011, 8, 549–559. [Google Scholar] [CrossRef] [Scilit]
  36. Saboori, A.; Hadjicostis, C.N. Verification of initial-state opacity in security applications of discrete event systems. Inf. Sci. 2013, 246, 115–132. [Google Scholar] [CrossRef] [Scilit]
  37. Balun, J.; Masopust, T. Verifying weak and strong k-step opacity in discrete-event systems. Automatica 2023, 155, 111153. [Google Scholar] [CrossRef] [Scilit]
  38. Balun, J.; Masopust, T. Comparing the notions of opacity for discrete-event systems. Discret. Event Dyn. Syst. 2021, 31, 553–582. [Google Scholar] [CrossRef] [Scilit]
  39. Miao, S.; Lai, A.; Komenda, J. Always guarding you: Strong initial-and-final-state opacity of discrete-event systems. Automatica 2025, 173, 112085. [Google Scholar] [CrossRef] [Scilit]
  40. Masopust, T.; Osička, P. On algorithms verifying initial-and-final-state opacity: Complexity, special cases, and comparison. Automatica 2025, 174, 112171. [Google Scholar] [CrossRef] [Scilit]
  41. Tong, Y.; Li, Z.; Seatzu, C.; Giua, A. Verification of state-based opacity using Petri nets. IEEE Trans. Autom. Control 2016, 62, 2823–2837. [Google Scholar] [CrossRef] [Scilit]
  42. Dong, Y.; Li, Z.; Wu, N. Symbolic Verification of Current-State Opacity of Discrete Event Systems Using Petri Nets. IEEE Trans. Syst. Man Cybern. Syst. 2022, 52, 7628–7641. [Google Scholar] [CrossRef] [Scilit]
  43. Dong, Y.; Wu, N.; Li, Z. State-Based Opacity Verification of Networked Discrete Event Systems Using Labeled Petri Nets. IEEE/CAA J. Autom. Sin. 2024, 11, 1274–1291. [Google Scholar] [CrossRef] [Scilit]
  44. Lefebvre, D.; Hadjicostis, C.N. Exposure and Revelation Times as a Measure of Opacity in Timed Stochastic Discrete Event Systems. IEEE Trans. Autom. Control 2021, 66, 5802–5815. [Google Scholar] [CrossRef] [Scilit]
  45. Wang, Y.; Li, L.; Li, Z. Verification of current-state opacity and opaque time for labeled time Petri net systems. Automatica 2025, 176, 112241. [Google Scholar] [CrossRef] [Scilit]
  46. Dong, Y.; Lefebvre, D.; Li, Z. K-Step Opacity Verification and Enforcement of Time Labeled Petri Net Systems. IEEE Trans. Autom. Control 2025, 70, 5848–5863. [Google Scholar] [CrossRef] [Scilit]
  47. Qin, T.; Yin, L.; Liu, G.; Wu, N.; Li, Z. Strong Current-State Opacity Verification of Discrete-Event Systems Modeled with Time Labeled Petri Nets. IEEE/CAA J. Autom. Sin. 2025, 12, 54–68. [Google Scholar] [CrossRef] [Scilit]
  48. Yang, J.; Deng, W.; Qiu, D.; Jiang, C. Opacity of networked discrete event systems. Inf. Sci. 2021, 543, 328–344. [Google Scholar] [CrossRef] [Scilit]
  49. Yang, S.; Hou, J.; Yin, X.; Li, S. Opacity of Networked Supervisory Control Systems Over Insecure Communication Channels. IEEE Trans. Control Netw. Syst. 2021, 8, 884–896. [Google Scholar] [CrossRef] [Scilit]
  50. Li, T.; Ren, H.; Liu, R.; Pia Fanti, M.; Li, Z. Online Opacity Verification of Networked Discrete Event Systems Modeled with Labeled Petri Nets. IEEE Trans. Autom. Sci. Eng. 2025, 22, 22686–22698. [Google Scholar] [CrossRef] [Scilit]
  51. Wang, J.; Baldi, S.; Yu, W.; Yin, X. Enforcing Opacity in Discrete Event Systems via Delayed Observations. IEEE Control Syst. Lett. 2025, 9, 2411–2416. [Google Scholar] [CrossRef] [Scilit]
  52. Keroglou, C.; Hadjicostis, C.N. Probabilistic system opacity in discrete event systems. Discret. Event Dyn. Syst. 2017, 28, 289–314. [Google Scholar] [CrossRef] [Scilit]
  53. Yin, X.; Li, Z.; Wang, W.; Li, S. Infinite-step opacity and K-step opacity of stochastic discrete-event systems. Automatica 2019, 99, 266–274. [Google Scholar] [CrossRef] [Scilit]
  54. Deng, W.; Qiu, D.; Yang, J. Opacity Measures of Fuzzy Discrete Event Systems. IEEE Trans. Fuzzy Syst. 2021, 29, 2612–2622. [Google Scholar] [CrossRef] [Scilit]
  55. Yin, X.; Zamani, M.; Liu, S. On Approximate Opacity of Cyber-Physical Systems. IEEE Trans. Autom. Control 2021, 66, 1630–1645. [Google Scholar] [CrossRef] [Scilit]
  56. Wu, Y.C.; Lafortune, S. Synthesis of insertion functions for enforcement of opacity security properties. Automatica 2014, 50, 1336–1348. [Google Scholar] [CrossRef] [Scilit]
  57. Wu, Y.C.; Lafortune, S. Synthesis of Optimal Insertion Functions for Opacity Enforcement. IEEE Trans. Autom. Control 2016, 61, 571–584. [Google Scholar] [CrossRef] [Scilit]
  58. Ji, Y.; Yin, X.; Lafortune, S. Opacity Enforcement Using Nondeterministic Publicly Known Edit Functions. IEEE Trans. Autom. Control 2019, 64, 4369–4376. [Google Scholar] [CrossRef] [Scilit]
  59. Mohajerani, S.; Ji, Y.; Lafortune, S. Compositional and Abstraction-Based Approach for Synthesis of Edit Functions for Opacity Enforcement. IEEE Trans. Autom. Control 2020, 65, 3349–3364. [Google Scholar] [CrossRef] [Scilit]
  60. Keroglou, C.; Lafortune, S. Embedded Insertion Functions for Opacity Enforcement. IEEE Trans. Autom. Control 2021, 66, 4184–4191. [Google Scholar] [CrossRef] [Scilit]
  61. Li, X.; Hadjicostis, C.N.; Li, Z. Extended Insertion Functions for Opacity Enforcement in Discrete-Event Systems. IEEE Trans. Autom. Control 2022, 67, 5289–5303. [Google Scholar] [CrossRef] [Scilit]
  62. Li, X.; Hadjicostis, C.N.; Li, Z. Opacity Enforcement in Discrete Event Systems Using Extended Insertion Functions Under Inserted Language Constraints. IEEE Trans. Autom. Control 2023, 68, 6797–6803. [Google Scholar] [CrossRef] [Scilit]
  63. Liu, R.; Lu, J.; Liu, Y.; Yin, X.; Hadjicostis, C.N. Opacity Enforcement via Greedy Privately-and-Publicly Known Insertion Functions. IEEE Trans. Autom. Control 2024, 69, 2500–2506. [Google Scholar] [CrossRef] [Scilit]
  64. Liu, R.; Hadjicostis, C.N. Improved Synthesis of Nondeterministic Publicly Known Edit Functions for Opacity Enforcement. IEEE Trans. Autom. Control 2025, 70, 6921–6928. [Google Scholar] [CrossRef] [Scilit]
  65. Duan, W.; Liu, R.; Fanti, M.P.; Hadjicostis, C.N.; Li, Z. Edit Mechanism Synthesis for Opacity Enforcement Under Uncertain Observations. IEEE Control Syst. Lett. 2023, 7, 2041–2046. [Google Scholar] [CrossRef] [Scilit]
  66. Li, X.; Hadjicostis, C.N.; Li, Z. Opacity Enforcement in Discrete Event Systems Using Modification Functions. IEEE Trans. Autom. Sci. Eng. 2025, 22, 3252–3264. [Google Scholar] [CrossRef] [Scilit]
  67. Dubreil, J.; Darondeau, P.; Marchand, H. Supervisory Control for Opacity. IEEE Trans. Autom. Control 2010, 55, 1089–1100. [Google Scholar] [CrossRef] [Scilit]
  68. Saboori, A.; Hadjicostis, C.N. Opacity-Enforcing Supervisory Strategies via State Estimator Constructions. IEEE Trans. Autom. Control 2012, 57, 1155–1165. [Google Scholar] [CrossRef] [Scilit]
  69. Tong, Y.; Cai, K.; Giua, A. Decentralized Opacity Enforcement in Discrete Event Systems Using Supervisory Control. In Proceedings of the 2018 57th Annual Conference of the Society of Instrument and Control Engineers of Japan (SICE), Nara, Japan, 11–14 September 2018. [Google Scholar]
  70. Xie, Y.; Yin, X.; Li, S. Opacity Enforcing Supervisory Control Using Nondeterministic Supervisors. IEEE Trans. Autom. Control 2022, 67, 6567–6582. [Google Scholar] [CrossRef] [Scilit]
  71. Moulton, R.H.; Hamgini, B.B.; Khouzani, Z.A.; Meira-Góes, R.; Wang, F.; Rudie, K. Using Subobservers to Synthesize Opacity-Enforcing Supervisors. Discret. Event Dyn. Syst. 2022, 32, 611–640. [Google Scholar] [CrossRef] [Scilit]
  72. Duan, W.; Hadjicostis, C.N.; Li, Z. Event Concealment and Concealability Enforcement in Discrete Event Systems Under Partial Observation. IEEE Trans. Autom. Control 2024, 69, 7263–7269. [Google Scholar] [CrossRef] [Scilit]
  73. Paoli, A.; Lin, F. Decentralized opacity of discrete event systems. In Proceedings of the 2012 American Control Conference (ACC), Montreal, QC, Canada, 27–29 June 2012; pp. 6083–6088. [Google Scholar]
  74. Yang, S.; Yin, X. Secure Your Intention: On Notions of Pre-Opacity in Discrete-Event Systems. IEEE Trans. Autom. Control 2023, 68, 4754–4766. [Google Scholar] [CrossRef] [Scilit]
  75. Behinaein, B.; Lin, F.; Rudie, K. Optimal Information Release for Mixed Opacity in Discrete-Event Systems. IEEE Trans. Autom. Sci. Eng. 2019, 16, 1960–1970. [Google Scholar] [CrossRef] [Scilit]
  76. Cassandras, C.G.; Lafortune, S. Introduction to Discrete Event Systems; Springer Nature: Berlin/Heidelberg, Germany, 2021. [Google Scholar]
  77. Lin, F. Diagnosability of discrete event systems and its applications. Discret. Event Dyn. Syst. 1994, 4, 197–212. [Google Scholar] [CrossRef] [Scilit]
  78. Sampath, M.; Sengupta, R.; Lafortune, S.; Sinnamohideen, K.; Teneketzis, D. Diagnosability of discrete-event systems. IEEE Trans. Autom. Control 2002, 40, 1555–1575. [Google Scholar] [CrossRef] [Scilit]
  79. Yoo, T.S.; Lafortune, S. Polynomial-time verification of diagnosability of partially observed discrete-event systems. IEEE Trans. Autom. Control 2002, 47, 1491–1495. [Google Scholar]
  80. Kang, T.; Seatzu, C.; Li, Z.; Giua, A. Fault diagnosis of discrete event systems under attack. In Proceedings of the 2023 62nd IEEE Conference on Decision and Control (CDC), Singapore, 13–15 December 2023; pp. 7923–7929. [Google Scholar]
  81. Lin, F.; Lafortune, S.; Wang, C. Diagnosability and attack detection for discrete event systems under sensor attacks. Discret. Event Dyn. Syst. 2024, 34, 465–495. [Google Scholar] [CrossRef] [Scilit]
  82. Dotoli, M.; Fanti, M.P.; Mangini, A.M.; Ukovich, W. On-line fault detection in discrete event systems by Petri nets and integer linear programming. Automatica 2009, 45, 2665–2672. [Google Scholar] [CrossRef] [Scilit]
  83. Fanti, M.P.; Mangini, A.M.; Ukovich, W. Fault detection by labeled Petri nets in centralized and distributed approaches. IEEE Trans. Autom. Sci. Eng. 2012, 10, 392–404. [Google Scholar] [CrossRef] [Scilit]
  84. Zhu, G.; Feng, L.; Li, Z.; Wu, N. An efficient fault diagnosis approach based on integer linear programming for labeled Petri nets. IEEE Trans. Autom. Control 2020, 66, 2393–2398. [Google Scholar] [CrossRef] [Scilit]
  85. Basile, F.; Chiacchio, P.; De Tommasi, G. An efficient approach for online diagnosis of discrete event systems. IEEE Trans. Autom. Control 2009, 54, 748–759. [Google Scholar] [CrossRef] [Scilit]
  86. Cabasino, M.P.; Giua, A.; Pocci, M.; Seatzu, C. Discrete event diagnosis using labeled Petri nets. An application to manufacturing systems. Control Eng. Pract. 2011, 19, 989–1001. [Google Scholar] [CrossRef] [Scilit]
  87. Genç, Ş.; Lafortune, S. A distributed algorithm for on-line diagnosis of place-bordered petri nets. IFAC Proc. Vol. 2005, 38, 68–73. [Google Scholar] [CrossRef] [Scilit]
  88. Genc, S.; Lafortune, S. Distributed diagnosis of place-bordered Petri nets. IEEE Trans. Autom. Sci. Eng. 2007, 4, 206–219. [Google Scholar] [CrossRef] [Scilit]
  89. Li, T.; Ren, H.; Liu, R.; Fanti, M.P.; Li, Z. Fault Diagnosis of Labeled Petri Nets Under Attacks Using Integer Linear Programming. IEEE Trans. Autom. Sci. Eng. 2025, 22, 11881–11893. [Google Scholar] [CrossRef] [Scilit]
  90. Cabasino, M.P.; Giua, A.; Seatzu, C. Diagnosability of discrete-event systems using labeled Petri nets. IEEE Trans. Autom. Sci. Eng. 2013, 11, 144–153. [Google Scholar] [CrossRef] [Scilit]
  91. Hu, Y.; Liu, R.; Fanti, M.P.; Li, Z. Robust fault diagnosis of networked discrete event systems using labeled Petri nets. IEEE Trans. Syst. Man Cybern. Syst. 2025, 55, 5853–5864. [Google Scholar] [CrossRef] [Scilit]
  92. Cong, X.; Fanti, M.P.; Mangini, A.M.; Li, Z. Decentralized diagnosis by Petri nets and integer linear programming. IEEE Trans. Syst. Man Cybern. Syst. 2017, 48, 1689–1700. [Google Scholar] [CrossRef] [Scilit]
  93. Mancer, S.; Bennoui, H. Distributed diagnostic problem solving with colored behavioral Petri nets. IEEE Trans. Syst. Man Cybern. Syst. 2019, 51, 3380–3391. [Google Scholar] [CrossRef] [Scilit]
  94. Wang, J.; Baldi, S.; Yu, W.; Yin, X. Distributed fault diagnosis in discrete event systems with transmission delay impairments. IEEE Trans. Autom. Control 2024, 69, 5508–5515. [Google Scholar] [CrossRef] [Scilit]
  95. Keroglou, C.; Hadjicostis, C.N. Distributed fault diagnosis in discrete event systems via set intersection refinements. IEEE Trans. Autom. Control 2018, 63, 3601–3607. [Google Scholar] [CrossRef] [Scilit]
  96. Basile, F.; Cabasino, M.P.; Seatzu, C. State estimation and fault diagnosis of labeled time Petri net systems with unobservable transitions. IEEE Trans. Autom. Control 2014, 60, 997–1009. [Google Scholar] [CrossRef] [Scilit]
  97. Lefebvre, D.; Rachidi, S.; Leclercq, E.; Pigné, Y. Diagnosis of Structural and Temporal Faults for k-Bounded Non-Markovian Stochastic Petri Nets. IEEE Trans. Syst. Man Cybern. Syst. 2018, 50, 3369–3381. [Google Scholar] [CrossRef] [Scilit]
  98. Yin, X.; Chen, J.; Li, Z.; Li, S. Robust fault diagnosis of stochastic discrete event systems. IEEE Trans. Autom. Control 2019, 64, 4237–4244. [Google Scholar] [CrossRef] [Scilit]
  99. Liu, R.; Ammour, R.; Brenner, L.; Demongodin, I. ON/OFF control for reaching a steady state attractive region in batches Petri nets. IFAC-PapersOnLine 2023, 56, 9618–9623. [Google Scholar] [CrossRef] [Scilit]
  100. Liu, R.; Ammour, R.; Brenner, L.; Demongodin, I. Event-driven control of hybrid systems using Batches Petri nets: Application to high throughput manufacturing systems. IEEE Trans. Autom. Sci. Eng. 2025, 22, 11906–11919. [Google Scholar] [CrossRef] [Scilit]
  101. Yin, X.; Lafortune, S. On the decidability and complexity of diagnosability for labeled Petri nets. IEEE Trans. Autom. Control 2017, 62, 5931–5938. [Google Scholar] [CrossRef] [Scilit]
  102. Chouchane, A.; Ghazel, M.; Boussif, A. K-diagnosability analysis of bounded and unbounded Petri nets using linear optimization. Automatica 2023, 147, 110689. [Google Scholar] [CrossRef] [Scilit]
  103. Hu, S.; Hu, Y.; Liu, D.; Fanti, M.P.; Li, Z. Diagnosability verification and enforcement for unbounded Petri nets by online supervisors. IEEE Trans. Autom. Sci. Eng. 2024, 22, 9061–9074. [Google Scholar] [CrossRef] [Scilit]
  104. Cabasino, M.P.; Giua, A.; Lafortune, S.; Seatzu, C. A new approach for diagnosability analysis of Petri nets using verifier nets. IEEE Trans. Autom. Control 2012, 57, 3104–3117. [Google Scholar] [CrossRef] [Scilit]
  105. Bérard, B.; Haar, S.; Schmitz, S.; Schwoon, S. The complexity of diagnosability and opacity verification for Petri nets. Fundam. Inform. 2018, 161, 317–349. [Google Scholar] [CrossRef] [Scilit]
  106. Li, B.; Khlif-Bouassida, M.; Toguyéni, A. Reduction rules for diagnosability analysis of complex systems modeled by labeled Petri nets. IEEE Trans. Autom. Sci. Eng. 2019, 17, 1061–1069. [Google Scholar] [CrossRef] [Scilit]
  107. Basile, F.; Chiacchio, P.; De Tommasi, G. On K-diagnosability of Petri nets via integer linear programming. Automatica 2012, 48, 2047–2058. [Google Scholar] [CrossRef] [Scilit]
  108. Jiang, S.; Huang, Z.; Chandra, V.; Kumar, R. A polynomial algorithm for testing diagnosability of discrete-event systems. IEEE Trans. Autom. Control 2001, 46, 1318–1321. [Google Scholar] [CrossRef] [Scilit]
  109. Liu, R.; Hu, S.; Hu, Y.; Mangini, A.M.; Fanti, M.P. On Diagnosability Consistency of Composed Labeled Petri Nets via Buffer Places. IEEE Internet Things J. 2026, 13, 2775–2788. [Google Scholar] [CrossRef] [Scilit]
  110. Tuxi, T.M.; Carvalho, L.K.; Nunes, E.V.; Cunha, A.E.d. Diagnosability verification using LTL model checking. Discret. Event Dyn. Syst. 2022, 32, 399–433. [Google Scholar] [CrossRef] [Scilit]
  111. Zhao, J.; Li, S.; Yin, X. A unified framework for verification of observational properties for partially-observed discrete-event systems. IEEE Trans. Autom. Control 2024, 69, 4710–4717. [Google Scholar] [CrossRef] [Scilit]
  112. Hu, Y.; Cao, S. Asynchronous diagnosability enforcement in discrete event systems based on supervisory control. IEEE Sensors J. 2023, 23, 10071–10079. [Google Scholar] [CrossRef] [Scilit]
  113. Miao, S.; Lai, A.; Komenda, J.; Lahaye, S. Decentralized Fault Diagnosis for Constant-Time Automata. IEEE Control Syst. Lett. 2025, 8, 3392–3397. [Google Scholar] [CrossRef] [Scilit]
  114. Liang, Y.; Lefebvre, D.; Li, Z. Polynomial-time verification of pattern diagnosability for timed discrete event systems. Inf. Sci. 2025, 706, 121997. [Google Scholar] [CrossRef] [Scilit]
  115. Cao, L.; Shu, S.; Lin, F.; Chen, Q.; Liu, C. Weak diagnosability of discrete-event systems. IEEE Trans. Control Netw. Syst. 2021, 9, 184–196. [Google Scholar] [CrossRef] [Scilit]
  116. Viana, G.S.; Alves, M.S.; Basilio, J.C. Codiagnosability of timed networked discrete-event systems subject to event communication delays and intermittent loss of observation. In Proceedings of the 2017 IEEE 56th Annual Conference on Decision and Control (CDC), Melbourne, Australia, 12–15 December 2017; pp. 4211–4216. [Google Scholar]
  117. Nunes, C.E.; Moreira, M.V.; Alves, M.V.; Carvalho, L.K.; Basilio, J.C. Codiagnosability of networked discrete event systems subject to communication delays and intermittent loss of observation. Discret. Event Dyn. Syst. 2018, 28, 215–246. [Google Scholar] [CrossRef] [Scilit]
  118. Li, S.; Uzam, M.; Yin, L.; Zhong, Z.; Zheng, L.; Wu, N. Robust diagnosability analysis of discrete event systems using labeled Petri nets. IEEE Access 2021, 9, 163504–163515. [Google Scholar] [CrossRef] [Scilit]
  119. Oliveira, V.S.; Cabral, F.G.; Moreira, M.V. K-loss robust diagnosability of discrete-event systems. IFAC-PapersOnLine 2020, 53, 250–255. [Google Scholar] [CrossRef] [Scilit]
  120. Oliveira, V.d.S.L.; Cabral, F.G.; Moreira, M.V. K-loss robust codiagnosability of discrete-event systems. Automatica 2022, 140, 110222. [Google Scholar] [CrossRef] [Scilit]
  121. Viana, G.S.; Alves, M.V.; Basilio, J.C. Codiagnosability of networked discrete event systems with timing structure. IEEE Trans. Autom. Control 2021, 67, 3933–3948. [Google Scholar] [CrossRef] [Scilit]
  122. Alves, M.V.; Nunes, C.E.; Ferrari, P.; Brandão, D.; Moreira, M.V. Delay-Resilient Fault Diagnosis of Networked Discrete-Event Systems Using Sequence Numbers. IEEE Trans. Autom. Control 2025. [Google Scholar] [CrossRef] [Scilit]
  123. Dong, W.; Yin, X.; Li, S. A uniform framework for diagnosis of discrete-event systems with unreliable sensors using linear temporal logic. IEEE Trans. Autom. Control 2023, 69, 145–160. [Google Scholar] [CrossRef] [Scilit]
  124. Hu, S.; Duan, W.; Liu, D.; Li, Z. Supervisory Control for Active Diagnosis in Labeled Petri Nets Under Observation and Control Delays. IEEE Trans. Autom. Control 2026. [Google Scholar] [CrossRef] [Scilit]
  125. Alves, M.V.; Barcelos, R.J.; Carvalho, L.K.; Basilio, J.C. Robust decentralized diagnosability of networked discrete event systems against dos and deception attacks. Nonlinear Anal. Hybrid Syst. 2022, 44, 101162. [Google Scholar] [CrossRef] [Scilit]
  126. Li, Y.; Hadjicostis, C.N.; Wu, N. Tamper-tolerant diagnosability under bounded or unbounded attacks. IFAC-PapersOnLine 2022, 55, 52–57. [Google Scholar] [CrossRef] [Scilit]
  127. Liu, R.; Mangini, A.M.; Fanti, M.P. Optimal Attack Strategy Compromising Diagnosability of Automated Manufacturing Systems in Labeled Petri Nets. In Proceedings of the 2025 IEEE Conference on Control Technology and Applications (CCTA), San Diego, CA, USA, 25–27 August 2025; pp. 616–621. [Google Scholar]
  128. Li, Y.; Hadjicostis, C.N.; Wu, N. Error-and tamper-tolerant decentralized diagnosability of discrete event systems under cost constraints. In Proceedings of the 2021 European Control Conference (ECC), Rotterdam, The Netherlands, 29 June–2 July 2021; pp. 42–47. [Google Scholar]
  129. Li, Y.; Hadjicostis, C.N.; Wu, N.; Li, Z. Tamper-tolerant diagnosability analysis and tampering detectability in discrete event systems under cost constraints. Automatica 2025, 171, 111971. [Google Scholar] [CrossRef] [Scilit]
  130. Liu, R.; Mangini, A.M.; Fanti, M.P. K-corruption intermittent attacks for violating the diagnosability. IFAC-PapersOnLine 2023, 56, 1847–1852. [Google Scholar] [CrossRef] [Scilit]
  131. Liu, R.; Hu, Y.; Mangini, A.M.; Fanti, M.P. K-Corruption Intermittent Attacks for Violating the Codiagnosability. IEEE/CAA J. Autom. Sin. 2025, 12, 159–172. [Google Scholar] [CrossRef] [Scilit]
  132. Liu, R.; Mangini, A.M.; Fanti, M.P. Synthesis of optimal stealthy attacks against diagnosability in labeled Petri nets. IEEE/CAA J. Autom. Sin. 2025, 12, 1661–1672. [Google Scholar] [CrossRef] [Scilit]
  133. Liu, F.; Yang, P.; Zhao, R.; Dziong, Z. Verification of safe diagnosability of stochastic discrete-event systems. Int. J. Control 2022, 95, 372–379. [Google Scholar] [CrossRef] [Scilit]
  134. Cui, B.; Ma, Z.; Giua, A.; Yin, X. Better Late than Never: On Epistemic Diagnosability of Discrete Event Systems. IFAC-PapersOnLine 2024, 58, 174–179. [Google Scholar] [CrossRef] [Scilit]
  135. Ma, Z.; Tong, Y.; Seatzu, C. Verification of pattern–pattern diagnosability in partially observed discrete event systems. IEEE Trans. Autom. Control 2023, 69, 2044–2051. [Google Scholar] [CrossRef] [Scilit]
  136. Liang, Y.; Liu, G.; El-Sherbeeny, A.M. Polynomial-time verification of decentralized fault pattern diagnosability for discrete-event systems. Mathematics 2023, 11, 3998. [Google Scholar] [CrossRef] [Scilit]
  137. Hu, S.; Hu, Y.; Komenda, J.; Li, Z. Supervisory Control for Active Diagnosis in Labeled Petri Nets Under Coordinated Sensor and Actuator Attacks. IEEE Trans. Autom. Control 2025. [Google Scholar] [CrossRef] [Scilit]
  138. Hu, S.; Li, Z. A digital twin approach for enforcing diagnosability in Petri nets. IEEE Trans. Autom. Sci. Eng. 2023, 21, 6068–6080. [Google Scholar] [CrossRef] [Scilit]
  139. Cassez, F.; Tripakis, S. Fault diagnosis with static and dynamic observers. Fundam. Informaticae 2008, 88, 497–540. [Google Scholar]
  140. Thorsley, D.; Teneketzis, D. Active acquisition of information for diagnosis and supervisory control of discrete event systems. Discret. Event Dyn. Syst. 2007, 17, 531–583. [Google Scholar] [CrossRef] [Scilit]
  141. Hu, S.; Li, Z.; Wisniewski, R. Optimal sensor selection for diagnosability enforcement in labeled Petri nets. IEEE Trans. Syst. Man Cybern. Syst. 2024, 54, 2965–2977. [Google Scholar] [CrossRef] [Scilit]
  142. Ran, N.; Giua, A.; Seatzu, C. Enforcement of diagnosability in labeled Petri nets via optimal sensor selection. IEEE Trans. Autom. Control 2018, 64, 2997–3004. [Google Scholar] [CrossRef] [Scilit]
  143. Cabasino, M.P.; Lafortune, S.; Seatzu, C. Optimal sensor selection for ensuring diagnosability in labeled Petri nets. Automatica 2013, 49, 2373–2383. [Google Scholar] [CrossRef] [Scilit]
  144. Debouk, R.; Lafortune, S.; Teneketzis, D. On an optimization problem in sensor selection. Discret. Event Dyn. Syst. 2002, 12, 417–445. [Google Scholar] [CrossRef] [Scilit]
  145. Hu, S.; Zhang, J.; Wang, J.; Wu, N.; Li, Z. Optimal sensor selection for diagnosability enforcement of discrete event systems using labeled Petri net. IET Control Theory Appl. 2024, 18, 2307–2321. [Google Scholar] [CrossRef] [Scilit]
  146. Rohloff, K.R.; Khuller, S.; Kortsarz, G. Approximating the minimal sensor selection for supervisory control. Discret. Event Dyn. Syst. 2006, 16, 143–170. [Google Scholar] [CrossRef] [Scilit]
  147. Stremersch, G.; Boel, R.K. Decomposition of the supervisory control problem for Petri nets under preservation of maximal permissiveness. IEEE Trans. Autom. Control 2002, 46, 1490–1496. [Google Scholar] [CrossRef]
  148. Miao, S.; Komenda, J.; Lai, A. Active Diagnosis of Time-Interval Automata: Time Perspectives. IEEE Trans. Autom. Sci. Eng. 2025, 22, 11239–11249. [Google Scholar] [CrossRef] [Scilit]
  149. Ran, N.; Li, T.; He, Z.; Seatzu, C. Codiagnosability enforcement in labeled Petri nets. IEEE Trans. Autom. Control 2022, 68, 2436–2443. [Google Scholar] [CrossRef] [Scilit]
  150. Wintenberg, A.; Blischke, M.; Lafortune, S.; Ozay, N. A general language-based framework for specifying and verifying notions of opacity. Discret. Event Dyn. Syst. 2022, 32, 253–289. [Google Scholar] [CrossRef] [Scilit]
  151. Tong, Y.; Li, Z.; Seatzu, C.; Giua, A. Current-state opacity enforcement in discrete event systems under incomparable observations. Discret. Event Dyn. Syst. 2017, 28, 161–182. [Google Scholar] [CrossRef] [Scilit]
  152. Falcone, Y.; Marchand, H. Enforcement and validation (at runtime) of various notions of opacity. Discret. Event Dyn. Syst. 2014, 25, 531–570. [Google Scholar] [CrossRef] [Scilit]
  153. Cui, B.; Yin, X.; Li, S.; Giua, A. You Don’t Know What I Know: On Notion of High-Order Opacity in Discrete-Event Systems. IFAC-PapersOnLine 2022, 55, 135–141. [Google Scholar] [CrossRef] [Scilit]
  154. Wu, Y.C.; Lafortune, S. Comparative analysis of related notions of opacity in centralized and coordinated architectures. Discret. Event Dyn. Syst. 2013, 23, 307–339. [Google Scholar] [CrossRef] [Scilit]
  155. Saboori, A.; Hadjicostis, C.N. Verification of infinite-step opacity and complexity considerations. IEEE Trans. Autom. Control 2011, 57, 1265–1269. [Google Scholar] [CrossRef] [Scilit]
  156. Yin, X.; Lafortune, S. A new approach for the verification of infinite-step and K-step opacity using two-way observers. Automatica 2017, 80, 162–171. [Google Scholar] [CrossRef] [Scilit]
  157. Bryans, J.W.; Koutny, M.; Ryan, P.Y. Modelling opacity using Petri nets. Electron. Notes Theor. Comput. Sci. 2005, 121, 101–115. [Google Scholar] [CrossRef] [Scilit]
  158. Tong, Y.; Li, Z.; Seatzu, C.; Giua, A. Verification of initial-state opacity in Petri nets. In Proceedings of the 2015 54th IEEE Conference on Decision and Control (CDC), Osaka, Japan, 15–18 December 2015; pp. 344–349. [Google Scholar]
  159. Tong, Y.; Li, Z.; Seatzu, C.; Giua, A. Verification of current-state opacity using Petri nets. In Proceedings of the 2015 American Control Conference (ACC), Chicago, IL, USA, 1–3 July 2015; pp. 1935–1940. [Google Scholar]
  160. Tong, Y.; Ma, Z.; Li, Z.; Seactzu, C.; Giua, A. Verification of language-based opacity in Petri nets using verifier. In Proceedings of the 2016 American Control Conference (ACC), Boston, MA, USA, 6–8 July 2016; pp. 757–763. [Google Scholar]
  161. Basile, F.; De Tommasi, G. An algebraic characterization of language-based opacity in labeled Petri nets. IFAC-PapersOnLine 2018, 51, 329–336. [Google Scholar] [CrossRef] [Scilit]
  162. Cong, X.; Fanti, M.; Mangini, A.; Li, Z. On-line algorithm for current state opacity enforcement in a Petri net framework. IFAC-PapersOnLine 2018, 51, 349–354. [Google Scholar] [CrossRef] [Scilit]
  163. Cong, X.; Fanti, M.P.; Mangini, A.M.; Li, Z. On-line verification of initial-state opacity by Petri nets and integer linear programming. ISA Trans. 2019, 93, 108–114. [Google Scholar] [CrossRef] [Scilit]
  164. Lakhnech, Y.; Mazaré, L. Probabilistic Opacity for a Passive Adversary and Its Application to Chaum’s Voting Scheme. Cryptol. ePrint Arch. 2005. Available online: https://eprint.iacr.org/2005/098 (accessed on 11 December 2025).
  165. Bryans, J.W.; Koutny, M.; Mazaré, L.; Ryan, P.Y. Opacity generalised to transition systems. In Proceedings of the International Workshop on Formal Aspects in Security and Trust, Newcastle upon Tyne, UK, 18–19 July 2005; Springer: Berlin/Heidelberg, Germany, 2005; pp. 81–95. [Google Scholar]
  166. Bérard, B.; Mullins, J.; Sassolas, M. Quantifying opacity. Math. Struct. Comput. Sci. 2015, 25, 361–403. [Google Scholar] [CrossRef] [Scilit]
  167. Saboori, A.; Hadjicostis, C.N. Current-state opacity formulations in probabilistic finite automata. IEEE Trans. Autom. Control 2013, 59, 120–133. [Google Scholar] [CrossRef] [Scilit]
  168. Keroglou, C.; Hadjicostis, C.N. Initial state opacity in stochastic DES. In Proceedings of the 2013 IEEE 18th Conference on Emerging Technologies & Factory Automation (ETFA), Cagliari, Italy, 10–13 September 2013; pp. 1–8. [Google Scholar]
  169. Wu, Y.C.; Raman, V.; Rawlings, B.C.; Lafortune, S.; Seshia, S.A. Synthesis of obfuscation policies to ensure privacy and utility. J. Autom. Reason. 2018, 60, 107–131. [Google Scholar] [CrossRef] [Scilit]
  170. Ji, Y.; Wu, Y.C.; Lafortune, S. Enforcement of opacity by public and private insertion functions. Automatica 2018, 93, 369–378. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.