A new paper proposes a way to check whether an industrial control system attack documented at one plant would actually work at another, not just whether it sounds similar on paper.
The method, called XPhysICS, separates an analyst's abstraction of a known threat from a deterministic check of whether that threat maps onto a specific target system. It scores candidate mappings against five criteria - role compatibility, type compatibility, stage coherence, slice viability, and rule-surface applicability - before ever asking whether the attack would run in practice. The team tested it across 83 threat abstractions spanning water treatment, water distribution, hydro and water-energy, and chemical-process systems, including controlled transfers between the SWaT and WADI testbeds and nine cases on Hydro/GRFICS rigs. They also compared results against an existing tool called GeCo and a reproduction of a prior physics-guided search method.
ICS security teams routinely reuse threat intelligence across sectors on the assumption that similar-looking plants carry similar risk - a substation and a water plant both run sensors and actuators, so an attack pattern from one gets recycled as a warning for the other. XPhysICS's results suggest that shortcut is shakier than it looks: outcomes ranged from clean transfers to near-threshold and confounded ones, meaning some threats only partly apply, or don't apply the way analysts assumed.
This is a research paper, not a shipped product, and its testing stays within four industrial sub-domains - so read it as a case for more rigor in threat sharing, not as an audit checklist ready for your own plant.