LTR-2026-03 · Technical Report · July 2026
Contextual Evaluation of Industrial Control Actions: Hardware Validation and Learned Operational Grammar
Abstract
Industrial control protocols authenticate neither the sender nor the appropriateness of a command; conventional defences add identity, access, and protocol validation, all of which answer whether an actor is permitted to act. That question is a weakening signal of safety, because a competent adversary arriving through legitimate means issues commands that are individually valid, authorised, and within range, and so indistinguishable, action by action, from a legitimate operator. This report develops and validates a contextual evaluation layer, Liscere, that judges not whether an action is permitted but whether it is appropriate: whether a given write, to a given control artefact, is coherent with the operational phase the process is currently in. The approach is passive and external, recovering process context from observed network traffic without modifying the plant, and it is structural rather than value-based, which distinguishes it from anomaly detection, from process interlocks, and from formal preventive enforcement.
The framework is validated on a physical testbed, a Siemens S7-1200 controlling a tank process over Modbus/TCP, with a strictly passive observer receiving only mirrored traffic, in three increments. The first shows that an identical protocol-valid write receives opposite verdicts, allowed or alerted, according to an operational phase the evaluator infers from observed process state rather than being told. The second makes that phase inference robust to the noise, pauses, and transitions of continuous operation, attaching to each verdict a confidence that separates an action incoherent with a known phase from one whose context is genuinely unsettled. The third replaces the hand-declared artefact-to-phase grammar with one learned from observation, and shows the learning to be genuine and artefact-specific: two control artefacts taught opposite grammars produce mirror-image verdicts, judged through graded rather than binary evaluation. Every result is backed by a decision log and a packet capture, published alongside this report.
The contribution is a validated proposition rather than a finished system. Its bounds are stated explicitly: the evaluator is still told which signal carries process state, learning assumes a clean and representative baseline, the inferred context is not resistant to an adversary who forges the observed telemetry, and validation rests on a single cyclic process, protocol, and controller. Within those bounds, the work establishes that contextual, structural evaluation of control actions is possible, that it occupies a gap left by existing approaches, and that its central dependencies, the operational context and the grammar of legitimate action, can both be lifted from human declaration toward autonomous observation.
Cite this report
@techreport{salmazo_hardware_2026,
author = {Bruno Salmazo},
title = {Contextual Evaluation of Industrial Control Actions: Hardware Validation and Learned Operational Grammar},
institution = {Liscere},
year = {2026},
month = jul,
number = {LTR-2026-03},
type = {Technical Report},
url = {https://liscere.com/research/ltr-2026-03/}
}