Universität Paderborn

09/28/2026 | Press release | Distributed by Public on 09/28/2026 05:11

Protection against cyber-attacks: New DFG Research Unit investigates the resilience of integrated technical systems to attacks

Attacks on substations, cyber-attacks on public authorities, drones flying over airports: critical infrastructure is increasingly becoming a target for criminals. So-called cyber-physical systems - technical devices in which software and machines communicate with one another in real time via the internet - are particularly at risk. Examples include modern industrial plants, cars and smart power stations. As digitalisation advances, so does the risk: hackers can infiltrate such systems and cause enormous damage. In September, a new research group was launched at Paderborn University to address the security of such systems.'MODID'¹ - as the project is titled - aims to tackle the threats at the interface between the 'cyber world' and Mechanical Engineering. The team, comprising computer scientists, mechanical engineers and economists, is funded by the German Research Foundation (DFG) with around four million euros for an initial period of four years.

Cyber-physical systems can adapt and optimise themselves - which boosts efficiency and competitiveness. In production, however, targeted attacks can disrupt manufacturing processes or even bring them to a complete standstill. The consequences: downtime, costs and reputational damage. This is where the DFG Research Unit comes in. "Our aim is to incorporate security right from the design stage of the systems. To this end, we are developing defence strategies in which we factor in attacks on subsystems at an early stage," explains Prof. Dr Eric Bodden from the Heinz Nixdorf Institute at Paderborn University, who leads the research group together with his colleague Prof. Dr Iris Gräßler. The team therefore focuses not on the systems themselves, but on their production and thus on the relevant manufacturing facilities.

At the kick-off meeting, the researchers agreed that all sub-projects should further develop their respective approaches so that they can be tested in the second year of the project using a shared evaluation object. Prof. Gräßler comments: "We are using a realistic example that fulfils safety-critical functions in our UPBracing team's Formula Student racing car: the wheel and braking system, including the associated software." The aim is to thwart potential attacks on the production process of the wheel carrier - which is 'printed' in a complex additive manufacturing facility - through appropriate 'by design' security measures. The development of the software that interacts with the wheel carrier in the vehicle is also being investigated. "Cars today are excellent examples of cyber-physical systems: sensor data, for example, is shared via the internet and evaluated in fractions of a second to generate hazard alerts," adds Prof. Bodden.

In parallel, an architecture-based assessment of the attack resilience of cyber-physical systems is being carried out. To this end, the experts are developing security metrics at the level of system architecture and programme code, which are intended to enable an assessment of the system's security.

Ultimately, the results are intended not only to advance research but, above all, to be directly applied in industrial practice. The aim is to better protect businesses and administrative bodies against attacks and to ensure they can use technical products more safely in future.

  1. ^ Full title of the research group: "Attack-resistant development of cyber-physical systems using model-based defence in depth"

    This text was translated automatically.
Universität Paderborn published this content on September 28, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 28, 2026 at 11:11 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]