The controller drives real rotor speed toward whatever setpoint it currently trusts. A compromised controller can silently swap that setpoint for a malicious one — spinning the centrifuge past its safe limit — while separately intercepting the sensor feed sent to the operator's HMI and replacing it with fabricated "everything normal" numbers.
- ICS Attack — issues a hidden high-speed command to the rotor and, unless the integrity-verified channel is on, freezes the operator dashboard at a fake safe reading.
- Integrity-verified sensor — a separate, cryptographically-signed channel the attacker cannot forge without detection; switching it on makes the dashboard show the real, dangerous state again.
- Rotor stress — accumulates only while real RPM exceeds the safe limit and never heals on its own — mechanical fatigue is permanent, even after the attack stops.
- Emergency shutdown — the operator's only real lever: cuts the malicious command and drives the setpoint back to zero.
Real-world relevance: this is the core mechanism behind Stuxnet's attack on Iranian centrifuges — physical sabotage paired with falsified telemetry so operators saw nothing wrong until physical symptoms were undeniable.