Enrico Barbierato
Modern cyber–physical infrastructures rely heavily on alarm and notification systems to direct human attention when abnormal conditions occur. These mechanisms support timely and safe responses by informing operators and occupants about potential hazards. At the same time, research in human factors has shown that repeated or excessive alerts can weaken vigilance, slow reactions, and reduce confidence in warning systems. This behavioral pattern is commonly described as alarm fatigue. This paper examines how that vulnerability can be exploited intentionally. We refer to this adversarial strategy as alarm poisoning: the deliberate injection of false or misleading alerts in order to increase alarm pressure, erode trust in the monitoring infrastructure, and degrade organizational responsiveness over time. To study this process, we develop a stochastic Cybersecurity Dynamics model representing the interaction among attackers, defenders, alarm infrastructure, and a population of employees. Employee behavior is modeled through evolving trust and fatigue levels, while the overall system is formulated as a continuous–time Markov chain and simulated using the Gillespie Stochastic Simulation Algorithm. A Monte–Carlo campaign is used to analyze the resulting socio–technical dynamics under alternative attacker strategies. The study evaluates time-dependent trust, fatigue, and alarm-pressure trajectories, the distribution of times to behavioral collapse, and defender timing through Trust–Resilience–Agility–Mitigation (TRAM) metrics. The revised analysis also includes replication-sufficiency diagnostics, one-at-a-time sensitivity analysis, and threshold-robustness checks for the collapse criterion. The results show that false alarms with high perceived severity drive alarm pressure upward and degrade trust faster than nuisance-dominated campaigns, even when the total fake-alarm intensity is held constant across strategies. Collapse timing remains highly variable across stochastic realizations, and a non-negligible fraction of runs do not reach the collapse threshold within the simulation horizon. Sensitivity analysis indicates that the main qualitative ranking of attacker strategies is robust across most tested perturbations, with fatigue recovery and defender escalation emerging as particularly influential mechanisms. Overall, the findings support the view that alarm poisoning is a credible socio–technical attack vector and highlight the importance of rapid mitigation, robust alarm management, and human-centered defensive design in cyber–physical security systems.