# Cyber Blast Radius — 数千万台の DER をどう接続すべきか（再現パッケージ）

記事：https://www.i-s3.com/cyber-resilience-der-blast-radius.html（英語版 `-en.html`）
著者：益田周防海（株式会社I-S3）　版 1.0　2026-10-07
ライセンス：CC BY 4.0（記事・図版・データ・コード）

## 構成

| ディレクトリ | 内容 |
|---|---|
| `article/` | `index.md`（日本語本文）、`index.en.md`（英語）、`references.md`（出典 ID 一覧）、`title_candidates.md` |
| `data/` | `assumptions.csv`（全変数の LOW／BASE／HIGH と出典 ID）、`incidents.csv`（サイバー事例と参照事故）、`der_fleet_japan.csv`（日本の DER 規模） |
| `model/` | `cbr_model.py`（CBR・系統リスク・フリート指標・A+・到達上限）、`grid_sim.py`（単一エリアのスイング方程式）、`correlated_failure.py`（β ファクタと共通原因モンテカルロ）、`monte_carlo.py`（不確実変数のモンテカルロと一変数感度）、`make_figures.py`（図 1〜12） |
| `results/` | 計算結果 CSV／JSON、`figures/`（PNG と `captions.md`）、`parity_cases.json`（JS との一致試験用） |
| `simulator/` | `cbr_core.js`（Python と同じ式の JS 実装）、`simulator.js`／`simulator.css`（記事内 UI）、`parity_test.js` |
| `research/` | `grid_sensitivity_calibration.md`、`prior_art_and_regulation.md`、`jc_star_and_japan_context.md`、`open_problems.md` |
| `review/` | `red_team_report.md`（9 視点）、`final_response_matrix.md`（指摘への応答と版 1.0 での変更） |
| `briefs/` | エグゼクティブサマリー（日英）、FAQ、研究者・メディア向けブリーフ |

## 再現

依存：Python 3.11 以上、`numpy`、`matplotlib`、Node.js 18 以上。乱数シードは固定（`default_rng(7)` 等）。

```
python3 model/cbr_model.py          # results/architecture_comparison.csv, policy_kpis.csv, vendor_share_limit.csv, parity_cases.json ほか
python3 model/grid_sim.py           # results/attack_scenarios.csv, attack_traces.csv, grid_step_sweep.csv, grid_context_cases.csv
python3 model/correlated_failure.py # results/ccf_*.csv, ccf_summary.json
python3 model/monte_carlo.py        # results/mc_samples.csv, monte_carlo_summary.json, tornado_*.csv, mc_winrate_by_p_reduction.csv
python3 model/make_figures.py       # results/figures/*.png, captions.md
node simulator/parity_test.js       # Python と JS の一致（7 ケース、相対 1e-9）
```

全体で 1 分程度。`monte_carlo.py` は 20,000 回 × 4 構成で数秒。

公開 HTML はリポジトリ直下の `scripts/build_cbr_article.py` が `article/index.md` から生成する（HTML を直接編集しない）。

## モデルの要点

- CBR_eff = reach × min(CBR_raw, A_max) × (1 − ρ(1 − e))。e は遠隔命令で到達し得る最低運転点（床）。
- x = max(s·ΔP_step / FCR, ΔP_total / (FCR + FRR))。S(x) = 1 − exp(−(x/x₀)^k)、x₀ = 1.7、k = 3。S は「負荷遮断以上」の確率。
- 制御面経路：R_plane = (1−β)[1 − (1 − p·S(x_domain))^n] + β·p·S(x_all)。
- ベンダー経路：全ファームウェア系統について p_v·S(x_v) を合成。x_v には権限上限を適用せず、床が残る割合 ρ_vendor = ρ × vendor_hw_enforce、変化率制限は残らない（s = 1）。
- A+：サーバー側集計上限 server_cap_mw が API 侵害時に効き、バックエンド侵害（p × p_backend_rel）では効かない。
- 合計 R_total = 1 − (1 − R_plane)(1 − R_vendor)。

## 仮定を変える

`data/assumptions.csv` の `base` 列を書き換えて上の順に再実行する。LOW／HIGH 列はモンテカルロの三角分布の端点。`model/monte_carlo.py` の `DESIGN_B` が分散側の設計変数（固定）。

## 引用

```
益田周防海 (2026)「CybersecurityからCyber-Resilienceへ：完全には守れない世界で、数千万台の分散電源をどう接続すべきか」
株式会社I-S3 特別研究プロジェクト, 版 1.0. https://www.i-s3.com/cyber-resilience-der-blast-radius.html
```

```bibtex
@techreport{masuda2026cbr,
  author = {Masuda, Suomi},
  title  = {From Cybersecurity to Cyber-Resilience: How Should Tens of Millions of DER Be Connected in a World That Cannot Be Fully Defended?},
  institution = {I-S3 Co., Ltd.},
  year   = {2026},
  month  = {10},
  url    = {https://www.i-s3.com/cyber-resilience-der-blast-radius-en.html}
}
```

## 連絡

s_masuda@i-s3.com。誤り・反論・追加データは歓迎する。`review/final_response_matrix.md` の形式で応答を追記する。
