Researchers developed an adaptive cyberattack that exposes hidden vulnerabilities in time-critical systems, helping engineers strengthen cyber defences for transport, healthcare and industrial infrastructure.

Researchers from Washington State University, working with the University of Colorado Colorado Springs and Metro State University, have developed an adaptive cyberattack called NosyNeighbor to identify weaknesses in time-critical computing systems before malicious hackers can exploit them. The project aims to help engineers build stronger cyber defences for safety-critical infrastructure.
Rather than disrupting a system directly, NosyNeighbor performs a side-channel attack, gathering timing information from outside a system to infer what is happening inside. The researchers designed it to reveal vulnerabilities in partitioned computing systems, where separate software components must complete tasks within strict time limits.
The attack targets systems used in aviation, medical devices, autonomous vehicles and industrial control applications. In these environments, even delays of a few milliseconds can lead to failures, making robust cyber protection essential.
During testing, NosyNeighbor bypassed several existing cyber defences and successfully inferred which software task was running with approximately 73% accuracy under normal operating conditions. According to the researchers, that level of precision could allow attackers to predict system behaviour and interfere with safety-critical operations if such weaknesses remain unaddressed.
The researchers argue that understanding how attackers exploit timing information enables engineers to design more resilient protection mechanisms. By adopting an adversarial perspective, developers can identify security gaps before they are discovered and abused in real-world attacks.
The work also highlights growing cybersecurity challenges in modern partitioned systems, where software from multiple suppliers is integrated into a single platform. Such multi-vendor environments increase the complexity of securing interconnected components and expand potential attack surfaces.
The findings were published in ACM Transactions on Cyber-Physical Systems. The research team believes the study provides valuable insights for improving cyber resilience in critical infrastructure, supporting the development of safer computing systems for transportation, healthcare and other sectors where reliability and security are paramount.





