1. Introduction
In many practical scenarios, it is essential to consider the behavior of networked control systems (NCSs) operating under malicious cyber threats over a finite period. For instance, in complex industrial automation or chemical processes, maintaining system states within prescribed safe bounds is critical despite unpredictable network interruptions. To address such challenges, De Persis and Tesi [
1] introduced the foundational concept of ISS control under DoS attacks. Dolk et al. [
2] further emphasized that DoS attacks pose a significantly more severe challenge to closed-loop stability compared to traditional time-triggered control, primarily because they interrupt system operations aperiodically. Recently, the concept of DoS resilience—defined as the capability to preserve ISS despite prolonged communication blockages—has been extensively explored in literature such as [
3,
4]. A great variety of research has been devoted to this field due to its wide range of practical applications, where resilient event-triggered schemes and switching signal reconstruction are utilized to mitigate attack-induced instability.
Event-triggered control (ETC) has emerged as an indispensable methodology for investigating NCSs with limited communication bandwidth, such as satellite orbit transitions and secure communication systems [
5,
6]. By updating control inputs only when specific state-dependent conditions are violated, the event-triggered mechanism (ETM) provides a natural framework for managing systems with discontinuous control updates. Since the foundational results presented by Tabuada [
5], the domain of ETC has been a focal point of research for decades, particularly regarding the stability and resource efficiency of networked dynamics. Current research generally branches into two categories: approaches utilizing fixed-threshold impulses [
7] and those focusing on mode-dependent or dynamic event-triggered mechanisms [
8]. The integration of ETC with impulsive control has yielded significant breakthroughs, such as the Lyapunov stability analysis for impulsive systems via ETC and the investigation of nonlinear delay systems using comparison principles [
7]. In the context of ETC, various fundamental methodologies have been proposed, including event-separation properties [
9] and co-design perspectives for efficient communication [
10]. Multiagent consensus via ETC has also drawn significant attention [
11,
12,
13]. Furthermore, Zeno-free dynamic surface control and impulsive mechanisms have been tailored to address continuous-time nonlinear networks [
14,
15].
Robust control approaches for perturbed nonlinear systems—including sliding-mode extremum seeking with barrier functions [
16] and observer-based designs for electric-vehicle drives under unmatched load disturbances [
17]—further motivate the need for systematic NCS frameworks that simultaneously handle cyber threats and unmatched disturbances.
Asynchronous behavior is a critical concept used to depict the scenario where system mode switching and impulsive updates are mutually independent and generally do not coincide. Switched systems, as a vital class of hybrid systems, exhibit intermittent state jumps during their continuous evolution [
18]. To systematically handle the resulting asynchrony, the average dwell time (ADT) approach [
19] and its generalization, the AED-ADT [
20], have become indispensable analytical tools. Since the initial inception of the ADT framework [
21], it has been vastly adapted for hybrid systems experiencing cyber-attacks [
22]. Exploring the resilience of NCSs, extensive literature now focuses on
synchronization [
23], resilient mechanisms under periodic blockages [
24], quantized tracking [
25], and comprehensive security control surveys [
26] under DoS attacks. In complex real-world environments, systems frequently endure multimodal switching and malicious attacks simultaneously. Under DoS attacks, the blocked impulses force the system state to depend heavily on the historical trajectory during the attack’s active period [
27]. While early literature modeled impulsive delays as fixed or integral-based, recent studies recognize that attack-induced blockages vary dynamically across different triggering instants [
27,
28]. This operational need led to the development of the MDETM [
29], where triggering thresholds adapt based on the active system mode and attack status. Related work. Several closely related lines of research deserve detailed discussion. Regarding ISS under DoS attacks, De Persis and Tesi [
1] laid the foundations for stabilizing control under denial-of-service, while Dolk et al. [
2] extended this to event-triggered control systems. More recent contributions [
3,
4] address resilient event-triggered schemes for switched systems under DoS blockages, yet both assume synchronous triggering mechanisms without mode-dependent threshold adaptation. On the impulsive control side, existing studies [
7,
8] provide Lyapunov stability criteria for event-triggered impulsive systems, but do not consider network attacks. The hybrid schemes in [
27,
28] handle DoS attacks with impulsive components, yet are restricted to multi-agent consensus topologies and do not cover the ISS of general single switched systems. The MDETM was introduced in [
29] for mode-dependent dynamic event-triggered impulsive control, but that work operates under classical average dwell-time assumptions with synchronous switching-impulse interactions. In the broader security control literature, comprehensive surveys [
26] identify fully asynchronous nonlinear impulsive switched systems as an open class that current frameworks do not subsume. The present paper fills this gap, as detailed below.
However, existing works such as [
3,
4] primarily address ISS under DoS attacks for systems without mode-dependent triggering mechanisms. Although refs. [
27,
28] investigate hybrid event-triggered and impulsive control under cyber-attacks, their cluster of results is restricted to multi-agent consensus topologies rather than the explicit ISS analysis of general single switched systems. Furthermore, ref. [
29] introduces the MDETM yet operates under the assumption of synchronous switching-impulse interactions or classical dwell-time frameworks, failing to capture the fully asynchronous decoupling between mode-switching and impulse updates characterized by the AED-ADT framework. To the best of the authors’ knowledge, a comprehensive theoretical framework simultaneously integrating MDETM, asynchronous switching via AED-ADT, and DoS resilience for continuous-time nonlinear impulsive switched systems remains largely unexplored.
Hinted by the above discussion, we investigate the problem of event-triggered impulsive control for continuous-time nonlinear impulsive switched systems subject to aperiodic DoS attacks. The main contributions of this paper are explicitly summarized as follows:
Unified nonlinear framework: This paper is the first to simultaneously integrate MDETM, asynchronous mode switching via AED-ADT and aperiodic DoS resilience for continuous-time nonlinear impulsive switched systems. Specifically, [
3,
4] achieve ISS under DoS without mode-dependent triggering; [
27,
28] combine event-triggered impulses with DoS but are confined to cooperative multi-agent networks; and [
29] introduces MDETM yet restricts it to synchronous switching or classical ADT. The proposed framework simultaneously handles all three challenges in a single general nonlinear continuous-time setting.
Zeno-free MDETM with explicit lower bound: Under the adopted MDETM (
2)–(
3), the triggering threshold adapts to both the active Lyapunov function and a class-
upper bound on disturbances. A positive uniform inter-event lower bound
is derived analytically (Theorem 1), confirming Zeno-free operation without requiring smoothness assumptions on inter-event intervals.
Explicit ISS decay-rate formula: Through impulsive differential equations [
30] and the AED-ADT approach, the Lyapunov function is estimated under the simultaneous influence of asynchronous switching and aperiodic DoS blockages. Condition (VI) yields a closed-form exponential decay rate (see Theorem 2) that makes the trade-offs among the AED-ADT limit, the DoS frequency/duration parameters, and the triggering coefficients fully transparent.
Tractable LMI criteria for linear systems: The nonlinear framework is specialized to linear impulsive switched systems (Theorem 3), yielding LMI conditions amenable to standard solvers (e.g., YALMIP/MOSEK) and facilitating direct controller design.
The rest of this article is structured as follows.
Section 2 formulates the problem and introduces essential definitions regarding the DoS model and AED-ADT;
Section 3 details the rigorous analysis of Zeno behavior exclusion and establishes the ISS criteria for both nonlinear and linear cases;
Section 4 provides a comprehensive numerical example to validate the theoretical findings; and
Section 5 concludes the paper together with future work.
2. Problem Formulation and Preliminaries
Consider the following continuous-time nonlinear impulsive switched system:
where
is the system state with the initial value
;
is the bounded external continuous disturbance input;
is a right-continuous, piecewise constant switching signal, where
is a finite index set. The switching time sequence is denoted as
, satisfying
. The switching instants
and the triggering impulsive instants
are independent of each other and generally do not coincide. The continuous dynamics
and state jumps
satisfy the local Lipschitz condition, with
and
.
For system (
1), the following MDETM is adopted:
The overall structure of the proposed control system is illustrated in
Figure 1, where the triggering function is defined as
with
as triggering parameters,
the Lyapunov function of the
i-th subsystem, and
a class-
function. The interval
is the last successful triggering instant, initially
.
Remark 1. The switching signal is generated by an external scheduler and evolves independently of the MDETM. Specifically, the triggering mechanism in (
2)
uses to select the active Lyapunov function but does not influence the switching sequence . This one-way dependence ensures that the asynchronous interaction between mode switches and impulsive events is well-posed: at any switching instant , the state is continuous, no jump occurs due to the switch alone, while the MDETM clock continues from the last successful impulse instant. Definition 1. System (
1)
is ISS if there exist and such that for any bounded disturbance and : Definition 2. An aperiodic DoS attack is characterized by active intervals and sleeping intervals . The total active and sleeping subsets over are: During , event-triggered impulses are invalidated. The continuous dynamics remain subject to , and evolves independently.
Definition 3. The number of DoS attacks within satisfies: Definition 4. The total duration of active periods satisfies: Definition 5. Let denote the switches from subsystem j to i over , and the running time of i after switching from j. If there exist and such thatthen is the AED-ADT with chatter bound . Definition 6. Let M be the total triggers over , and N the failed triggers due to DoS. The successful impulse ratio is: Remark 2. The proposed framework handles both matched and unmatched external disturbances. In the nonlinear setting (
1)
, the disturbance input enters through . In the linear setting (
17)
, the input matrix is not required to equal the control input matrix; it can represent an unmatched disturbance channel. The LMI condition (VII) absorbs directly via the Schur complement, so no structural assumption on the disturbance channel is needed. Notation. Throughout this paper, we adopt the following conventions. denotes the n-dimensional Euclidean space; denotes the Euclidean norm of a vector. For a measurable signal , we write for its -norm on the interval . For two real numbers , we write . The triggering parameter controls the decay threshold: it scales the Lyapunov value at the previous trigger instant, determining how much the Lyapunov function may grow before a new trigger is required. The triggering parameter controls the disturbance tolerance: it scales the disturbance upper bound in the triggering condition. The impulse decay parameter (distinct from ) characterizes the stabilizing effect of each impulse via condition condition (V).
The switching time sequence
uses the superscript
k to index the triggering interval and the subscript
s to index the switching instant within that interval;
with no superscript denotes the
k-th successful impulsive triggering instant. Constants
(no-DoS case) and
(with-DoS case) in the ISS proof are distinct composite bounds defined in Cases 1 and 2 of the Theorem 2 proof, respectively;
is a special case of
when
. The overall implementation procedure of the proposed MDETM-based impulsive control under aperiodic DoS attacks is summarized in Algorithm 1.
| Algorithm 1 MDETM-based Event-Triggered Impulsive Control under Aperiodic DoS Attacks |
Require: System matrices, Lyapunov matrices , parameters , DoS model parameters Ensure: State trajectory satisfying ISS
- 1:
Initialize: , - 2:
whiledo - 3:
Observe current state and active mode - 4:
Evaluate: - 5:
if or then - 6:
Trigger attempt at - 7:
if then ▹ DoS sleeping: channel available - 8:
Apply impulse: - 9:
Update: ; - 10:
else ▹ DoS active: channel blocked - 11:
Discard impulse; state evolves under - 12:
end if - 13:
end if - 14:
Integrate to next event or - 15:
end while
|
4. Example
In this section, we present a numerical example on a realistic dual-tank liquid-level system (
Figure 2) to illustrate the effectiveness and practical applicability of the proposed mode-dependent event-triggered impulsive control strategy under aperiodic DoS attacks.
The system matrices, input matrices, and impulsive jump matrices are formulated as follows:
To provide physical grounding, the two-subsystem linear impulsive switched system (
17) (
) is interpreted as a dual-tank liquid-level system under switching pump configurations [
18]. Specifically,
denotes the liquid level deviation (cm) in Tank 1 from the desired setpoint, and
denotes the liquid level deviation (cm) in Tank 2 from the desired setpoint. The two subsystems correspond to different valve-and-pump operating modes (e.g., different pump speeds or valve openings), with dwell times uniformly distributed in
s.
The impulsive actions represent instantaneous fluid injections or drains via a networked actuator, subject to aperiodic DoS blockages. The system is subject to bounded disturbance (sensor noise in the level measurements) and initial condition , representing a severe upset (e.g., a sudden supply surge to Tank 1 simultaneously with a drain in Tank 2).
The complete MATLAB code (LMI setup via YALMIP [
34]/MOSEK [
35], RK4 integrator, and DoS sequence generation with seed 42) is provided as
Supplementary Material.
To implement the proposed control scheme, the triggering mechanism and controller parameters defined in Theorem 3 are selected as follows: the expected decay rates are
and
; the switching parameters are
; the event-triggered coefficients are given by
and
; and the impulse intensity is set to
for all
. Additionally, to ensure regular state updates, the maximum forced triggering interval is bounded by
. For the aperiodic DoS attacks, the governing parameters are established as
and
. The active durations of the attacks are randomly generated within
, while the subsequent sleep durations are distributed over
. By utilizing the MATLAB YALMIP toolbox equipped with the MOSEK solver, the feasible solutions for the LMIs derived in Theorem 3 are successfully obtained. The corresponding symmetric positive-definite matrices are calculated as:
Concurrently, the optimal disturbance attenuation gain is found to be .
Substituting these values into Theorem 1 yields the Zeno-free lower bounds for both cases:
Case 1 (no switching within : .
Case 2 (with switching within ): With and , the limit . Since condition (III) requires , but , Case 2 is structurally excluded by the AED-ADT constraint : at most one mode switch can occur in any interval shorter than . Hence, for s, Case 2 does not apply, and the effective Zeno-free lower bound is .
The global ISS decay rate is , confirming condition (VI).
To assess robustness to random DoS profiles, 50 independent Monte Carlo runs are performed with different random seeds (seeds 101–150).
Table 1 and
Figure 3 summarizes the minimum inter-event times observed across all runs; all observed values strictly exceed
, corroborating the Zeno-free guarantee.
The numerical simulation is executed over a total time span of
, utilizing the fourth-order Runge–Kutta method with an integration step of
. The dynamic performance of the system is illustrated in
Figure 4,
Figure 5 and
Figure 6.
Figure 4 depicts the state trajectories of the closed-loop system under aperiodic DoS attacks, where the red-shaded areas highlight the active periods of the cyber threats.
Physically, within the dual-tank interpretation adopted in this example, represents the liquid level deviation (in cm) of Tank 1 from its desired setpoint, and represents the liquid level deviation (in cm) of Tank 2 from its desired setpoint. The initial condition () encodes a severely antagonistic upset: Tank 1 is overfilled by 100 cm above its setpoint while Tank 2 is simultaneously 100 cm below its setpoint, placing the two liquid levels in opposing extremes and maximally stressing the coupled inter-tank dynamics.
Three distinct behavioral phases are identifiable in
Figure 4.
Phase I (rapid transient),: Both
and
decay sharply in magnitude. This is driven by the high density of event-triggered impulses generated during this interval (blue triangles in
Figure 5), because the Lyapunov function
greatly exceeds the MDETM threshold
for such a large initial error. Physically, the networked actuator delivers rapid successive fluid injections and drains that aggressively correct the liquid level deviations in both tanks. The slightly higher decay rate of subsystem 1 (
) compared to subsystem 2 (
) means that the Lyapunov energy dissipates marginally faster under mode 1, so the level deviation of Tank 1 approaches zero slightly before that of Tank 2, consistent with the asymmetric settling visible in the figure.
Phase II (DoS-perturbed settling),: During each red-shaded DoS interval the communication channel is blocked and no impulsive correction can be delivered. The two states therefore undergo a brief free drift governed purely by the open-loop dynamics . Because both and possess a positive eigenvalue (approximately and , respectively), the uncontrolled continuous dynamics are mildly unstable, causing small but visible rebounds in and within each attack window. These rebounds are nevertheless bounded because condition (VI) ensures that the cumulative impulse-induced decay during sleeping periods dominates the open-loop growth accumulated during DoS active periods, yielding the positive net decay rate . Once each attack ceases, the MDETM immediately resumes triggering, and both states are rapidly pulled back toward the origin.
Phase III (steady state),: Both liquid level deviations remain in an extremely small neighborhood of zero (
), maintained by sparse forced-triggered impulses issued at the maximum permissible interval
(green squares in
Figure 5). The non-zero residual is entirely attributable to the persistent external disturbance
, which physically models small persistent sensor noise in the liquid-level measurements of both tanks. This residual is consistent with the ISS bound
derived in Theorem 2, confirming that the ISS gain correctly quantifies the steady-state error floor induced by measurement noise.
It is worth noting that despite the massive initial state deviation and the presence of intermittent communication blockages, the system states converge swiftly to a small neighborhood of the origin within approximately . The terminal error is recorded at , providing compelling evidence that the proposed impulsive control strategy effectively neutralizes the adverse impacts of aperiodic DoS attacks.
Visual inspection of
Figure 5 reveals the evolution of the Lyapunov function
on a logarithmic scale, perfectly illustrating the adaptive nature of the adopted MDETM. During the initial transient phase, the mechanism generates event-triggered impulses densely (denoted by blue triangles) to rapidly suppress the large system error. When DoS attacks become active, triggered impulses are maliciously intercepted (marked by red crosses), which inevitably causes a temporary swell in
. However, the system swiftly recovers its stability margin once the attack ceases. Furthermore, as the system enters the steady-state phase, the control scheme automatically shifts to forced triggering (green squares) at the maximum permissible interval
, thereby avoiding unnecessary data transmission and significantly conserving communication bandwidth.
Figure 6 illustrates the asynchronous interactions between the random switching signal
and the inter-event times. The red crosses accurately pinpoint the moments when impulsive instants fail due to DoS interceptions. Crucially, all actual inter-event times are observed to be strictly greater than the theoretical lower bound
(represented by the red dashed line) and are firmly bounded within
(the green dashed line). This distribution provides solid numerical evidence verifying the complete exclusion of Zeno behavior, as further quantified in
Figure 7.
To further verify the triggering condition, we record the first five inter-event intervals between consecutive successful impulse instants (intervals spanning DoS-blocked periods may exceed ): s, s, s, s, s—all strictly above the theoretical lower bound s. A Monte Carlo study over 50 independent random DoS realizations (seeds 101–150) yielded a mean terminal error with standard deviation , confirming robustness across attack patterns.
Comparison with baselines. Table 2 and
Figure 8 compare the proposed scheme with three baselines under identical conditions.
Stress test: high DoS duty cycle (≈51%). To assess the boundary of the theoretical guarantee, the simulation is repeated with a DoS duty cycle of ≈51%. In this regime, condition (VI) yields
, so the ISS guarantee no longer applies.
Figure 9 shows that for this particular DoS realization the state trajectory still converges, suggesting that the sufficient condition may be conservative. Practitioners should verify condition (VI) with worst-case DoS statistics before deployment; once the feasibility boundary is exceeded, stability can no longer be theoretically certified.
In summary, the simulation results corroborate the theoretical analysis, confirming that the proposed control strategy, bolstered by the adopted MDETM, not only guarantees the ISS property of linear impulsive switched systems under aperiodic DoS attacks but also achieves an optimal balance between control performance and communication resource utilization.
5. Conclusions
This paper has established a unified framework for ISS analysis of continuous-time nonlinear impulsive switched systems subject to aperiodic DoS attacks, by integrating the MDETM with the AED-ADT approach. The principal theoretical contributions are: (i) a constructive proof of Zeno-free behavior with an explicit uniform inter-event lower bound
(Theorem 1); (ii) global ISS with an explicit closed-form decay rate (Theorem 2) that makes all design trade-offs among the AED-ADT limit, DoS parameters, and triggering coefficients explicit; and (iii) tractable LMI conditions for linear systems (Theorem 3). Numerical experiments on a dual-tank model confirm these results:
,
s, a terminal state norm of
after 10 s from a large initial upset, and a
reduction in trigger count compared with a fixed time-triggered baseline. Under a
DoS duty cycle, condition (VI) yields
, marking the boundary of the theoretical guarantee; empirical convergence is still observed, confirming that the sufficient condition is conservative (
Figure 9 and
Figure 10).
The current framework has two main limitations. First, the DoS parameters are assumed to be known a priori; in practice, they must be estimated from historical traffic data or bounded conservatively. Second, network-induced transmission delays are not modeled; the framework assumes instantaneous impulse execution upon successful channel access.
These limitations suggest two concrete directions for future work:
Adaptive DoS estimation: Replacing fixed bounds with online estimates of via sliding-window statistics, combined with anomaly-detection filters.
Time-delay extension: Incorporating variable network-induced delays into the impulsive model, requiring generalized Lyapunov–Krasovskii functionals and a revised AED-ADT construction.
The current numerical validation, while confirming the theoretical predictions under controlled simulation conditions, does not capture network-induced jitter, sensor quantization noise, or actuator saturation present in physical testbeds. A natural extension is hardware-in-the-loop (HIL) validation on an embedded platform (e.g., an STM32-class microcontroller communicating over an Ethernet/CAN channel with software-emulated DoS jamming), using the same sampling step ( s) adopted in the simulation. Such a platform would allow direct measurement of inter-event times under realistic timing jitter, providing an empirical stress test of the Zeno-free guarantee (Theorem 1) beyond the idealized simulation setting.