Antifragility in Critical Infrastructure
Abstract
Critical infrastructure cybersecurity increasingly needs frameworks that move beyond recovery toward bounded improvement under disruption, but empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition built around Jensen gain and post-disruption gain. A two-layer empirical design pairs a CI-relevant subset of the CISSM Cyber Events Database with the HAI hardware-in-the-loop industrial control dataset and tests three confirmatory hypotheses and one exploratory proposition. OT-adjacent sectors show significantly higher shares of disruptive or mixed events than comparison sectors (65.3% versus 46.8%, p < 0.001) and a heavier concentration of physical attack and data-attack subtypes. In HAI, attack-labeled observations were 7.43 times more likely than normal observations to exceed the 95th percentile of baseline deviation (p < 0.001). Across successive attack windows, mean process-state deviation declined significantly (Spearman = 0.688, p = 0.007), providing evidence of measurable response variation rather than proof of adaptive gain. Together, the findings establish two prerequisites for future antifragility testing: differentiated fragility burden and process-level perturbation observability.