A machine that can sense its surroundings, software that can make decisions, and hardware that can respond within milliseconds may sound like a straightforward combination. In reality, bringing these elements together creates one of the most difficult testing challenges in modern engineering. These are cyber-physical systems (CPS)—systems in which software, electronics, communication networks and physical processes continuously interact.
From smart factories and autonomous vehicles to healthcare equipment, robotics, smart grids and aerospace systems, CPSs are increasingly responsible for decisions that can have consequences in the physical world. A software error in an ordinary application may crash a program. The same error in a cyber-physical system could stop a production line, disrupt a power network or compromise safety.
That is why testing CPSs is no longer simply about checking whether software produces the expected output. Engineers must determine whether the entire system behaves correctly when software, hardware, networks, sensors, actuators and the physical environment interact in real time. Research has identified reliability, safety, security and dependable operation as central concerns, particularly as CPSs become larger, more connected and more autonomous.[1]
Why CPS Testing is Different
The defining characteristic of a cyber-physical system is its connection to the physical world. Sensors collect information such as temperature, pressure, speed, position or vibration. Software interprets that information, makes a decision and sends commands to actuators. The physical system then changes, generating new sensor data and starting the cycle again.
This continuous loop makes testing considerably more complicated than testing software in isolation.
Consider an automated manufacturing machine. A controller may work perfectly under normal temperature and network conditions. But what happens when a sensor becomes noisy, communication is delayed, the machine experiences vibration, a component starts degrading, or an attacker manipulates the data reaching the controller? A meaningful test must reproduce these situations rather than simply verify whether the software works under ideal conditions.
This is where test and measurement (T&M) become critical. Measurements provide the evidence needed to determine whether the physical system is behaving as expected, while testing provides controlled conditions under which its limits can be explored.
Traditional testing approaches still have an important role. Conformance testing checks whether the system behaves according to an expected model or specification. Robustness testing examines whether the system can continue operating when conditions change. Security testing looks for vulnerabilities that could alter system behaviour or expose information. Fragility testing, meanwhile, explores whether small changes in inputs or environmental conditions can cause disproportionately large failures.
But CPS testing increasingly needs to go beyond these individual approaches.
From Simulation to Hardware-in-the-Loop
One of the important steps in the evolution of CPS testing has been hardware-in-the-loop (HIL) testing. Instead of building and operating an entire physical system for every experiment, HIL combines a real hardware component with a simulated environment.
For example, an actual controller can be connected to a computer-generated model representing a vehicle, motor, power system or industrial process. The hardware behaves as though it is connected to the real system, while engineers can control and repeat the surrounding conditions.
This approach offers an important advantage: engineers can test real hardware under conditions that may be expensive, dangerous or difficult to reproduce physically. The approach has therefore become an important precursor to more advanced digital and cyber-physical testing techniques.
The next step is to make the virtual representation more closely connected to the physical asset.
Digital Twins Change the Testing Equation
A digital twin can be thought of as a living digital representation of a physical asset or process. Unlike a conventional simulation that may operate independently, a digital twin can receive information from the physical system and, depending on its design, interact with it and even help predict future behaviour.
The distinction matters. A digital model may simply represent a machine. A digital shadow can receive real-time information from the machine. A digital twin goes further by creating a two-way relationship between the physical and digital worlds.
This creates an interesting opportunity for testing.
If the digital representation knows what the physical system should be doing, engineers can compare real behaviour with the twin’s expected behaviour. A deviation may indicate anything from a sensor problem to component degradation or an unexpected operating condition.
A systematic literature review by Somers and colleagues examined 480 studies and identified 26 relevant studies on digital-twin-based testing of CPSs. The review found that digital twins were increasingly being used for CPS testing, although much of the work remained focused on passive monitoring rather than active or predictive testing. The researchers also highlighted the continuing lack of consensus around exactly what should qualify as a digital twin.[1]
That limitation is important. A digital twin is only as useful as the data, models and assumptions behind it. If the virtual representation does not accurately reflect the physical system, comparing the two can create a false sense of confidence.
The Measurement Problem
The quality of CPS testing ultimately depends on the quality of measurement.
A modern CPS may involve hundreds of sensors generating data at different speeds and with different levels of accuracy. Temperature may change slowly, while vibration or electrical signals may need to be captured at extremely high sampling rates. Communication networks can also introduce latency, packet loss or timing variations.
This makes synchronisation a fundamental T&M challenge.
Researchers working on CPS applications have highlighted the importance of data acquisition, real-time transmission and uncertainty management. In applications involving complex physical processes, simply collecting more data does not automatically make the system easier to test. Engineers also need to understand where that data came from, how accurate it is and how uncertainty affects the final decision.[2]
The problem becomes even more pronounced when CPSs are distributed across networks. A system may have sensors at one location, controllers at another and cloud or edge computing resources somewhere else. Communication delays can change system behaviour, particularly when decisions have to be made within strict time limits.
Consequently, a realistic CPS test environment must measure not only what happened, but also when, where and under what conditions it happened.
Testing the System Under Stress
Normal operation is only one part of the story. A reliable CPS must also cope with abnormal conditions.
Engineers therefore need to deliberately introduce faults, disturbances and unexpected events. Sensor errors, communication delays, component failures, abnormal loads and environmental changes can all be injected into a test environment to observe how the system reacts.
This is one of the strongest arguments for advanced testbeds.
A recent example comes from the Human-Centered Autonomous Resilient Space Habitat (HARSH) testbed developed by the Resilient Extra-Terrestrial Habitats Institute. The facility combines physical components with numerical and cyber models to recreate disruption scenarios for complex space-habitat systems. Researchers can introduce faults, communication delays, uncertainties and disruptions while observing how the system detects, diagnoses and responds to them.[3]
The significance goes beyond space exploration. The same principle applies to factories, transportation networks, energy infrastructure and other environments where testing every failure condition in the real world would be impractical.
A good testbed essentially creates a controlled laboratory for uncontrolled reality.
Security Cannot Be Tested Separately
As CPS connectivity grows, cybersecurity becomes inseparable from system testing.
Traditional IT security testing often focuses on protecting information systems and networks. CPS security has an additional dimension: an attack can ultimately influence physical behaviour.
For example, manipulating a sensor reading may cause a controller to make an incorrect decision. Delaying a control signal may destabilise a time-sensitive process. A denial-of-service attack may prevent an operator or controller from accessing critical information.
Recent research on cyber-physical power systems highlights threats including denial-of-service attacks, false-data injection, replay attacks, man-in-the-middle attacks and supply-chain compromises. Such attacks can affect not only confidentiality but also the integrity and availability of physical infrastructure.[4]
Testing therefore needs to ask a broader question: What happens to the physical system when the cyber system is attacked?
That question is particularly important for smart grids, industrial control systems, connected vehicles and other critical infrastructure.
Cybersecurity testbeds are emerging as a practical way of answering it. Research on federated smart-grid testbeds, for example, has explored environments combining physical devices, simulated power systems and cybersecurity infrastructure so that attacks and system responses can be studied under more realistic conditions.[5]
AI Adds Another Layer of Uncertainty
Artificial intelligence is making CPSs more capable, but it is also making them harder to test.
An AI-enabled system may not behave according to a simple fixed rule. Its decisions can depend on training data, environmental conditions and patterns that are difficult to anticipate. Testing therefore has to consider not just whether an output is technically correct, but whether the system remains reliable when it encounters situations that differ from its training or design assumptions.
This is especially relevant as CPSs move toward Industry 5.0, where humans, machines and intelligent systems increasingly work together. A study of cyber-physical human-centred systems for Industry 5.0 demonstrated how edge and mist computing can support real-time industrial safety applications, including detecting human presence around machinery. In the reported system, thermal-image processing was performed on low-power hardware with fast response times, illustrating how sensing, computation and physical action increasingly form a single operational loop.[6]
For T&M engineers, this means the test environment must increasingly reproduce not just physical conditions, but also realistic data and decision-making conditions.
Toward More Intelligent Test Strategies
The future of CPS testing is unlikely to belong to a single testing method.
Instead, testing is moving toward combinations of simulation, HIL, software testing, physical measurement, digital twins, cybersecurity testing, AI-based analysis and real-world validation. The 2018 review of CPS testing methods and testbeds similarly concluded that future testing needs to combine different paradigms and technologies while incorporating areas such as IoT, big data, cloud computing and AI.[7]
The direction is also becoming more strongly connected to resilience and sustainability. A 2026 systematic review of sustainable and resilient cyber-physical production systems found that CPPSs are increasingly associated with real-time monitoring, predictive maintenance, self-diagnosis and intelligent decision-making. At the same time, it identified a need for more integrated approaches that consider resilience and sustainability together rather than treating them as separate objectives.[8]
This has an important implication for testing. Tomorrow’s test plan may not simply ask, “Does the system work?” It may ask: Can it continue working after a fault? Can it recover? Can it detect an attack? Can it adapt to changing conditions? Can it maintain performance while using fewer resources? And can we prove all of this with reliable measurements?
The Road Ahead
Cyber-physical systems are becoming the nervous systems of modern industry. They sense the physical world, process information and act upon it, often with little or no human intervention.
That makes testing one of the most important engineering disciplines in their development.
The challenge is that the physical world does not behave like a clean software environment. Sensors drift. Networks introduce delays. Components age. Environments change. Humans behave unpredictably. Cyberattacks exploit weaknesses. AI encounters situations that designers may not have anticipated.
The role of T&M is therefore evolving from simply measuring performance to building confidence in increasingly autonomous systems.
The most effective testing environments will combine real hardware with realistic simulations, high-quality measurement with intelligent analysis, and controlled experiments with the unpredictability of real-world conditions. Digital twins can help engineers observe and predict behaviour; HIL can bring real hardware into simulated scenarios; advanced testbeds can recreate complex failures; and cybersecurity testing can expose weaknesses before they become operational incidents.
Ultimately, the goal is not to make testing more complicated. It is to make the real world safer by discovering complexity before the system reaches it.
References
[1] Somers, R. J., Douthwaite, J. A., Wagg, D. J., Walkinshaw, N. D., & Hierons, R. M. (2023). Digital-twin-based testing for cyber–physical systems: A systematic literature review. Information and Software Technology, 156, 107145. DOI: 10.1016/j.infsof.2022.107145.
[2] Patil, T., Rebaioli, L., & Fassi, I. (2022). Cyber-physical systems for end-of-life management of printed circuit boards and mechatronics products in home automation: A review. Sustainable Materials and Technologies, 32.
[3] Silva, C. E., et al. (2025). Development of a Cyber–Physical Testbed for Smart and Resilient Space Habitats. ASCE OPEN: Multidisciplinary Journal of Civil Engineering, 3(1). DOI: 10.1061/AOMJAH.AOENG-0061.
[4] Olasehinde, D. O., et al. (2026). Cybersecurity in cyber-physical power systems: analyzing vulnerabilities, threats, and control structures. Cluster Computing. DOI: 10.1007/s10586-025-05894-w.
[5] Singh, et al. (2022). NEFTSec: Networked federation testbed for cyber-physical security of smart grid: Architecture, applications, and evaluation. IET Cyber-Physical Systems: Theory & Applications.
[6] Fraga-Lamas, P., Barros, D., Lopes, S. I., & Fernández-Caramés, T. M. (2022). Mist and Edge Computing Cyber-Physical Human-Centered Systems for Industry 5.0: A Cost-Effective IoT Thermal Imaging Safety System. Sensors, 22(21), 8500. DOI: 10.3390/s22218500.
[7] Zhou, X., et al. (2018). Review on Testing of Cyber Physical Systems: Methods and Testbeds. IEEE Access, 6, 52179–52194.
[8] Barrero-Arciniegas, H. A., Bataleblu, A. A., Rauch, E., & Matt, D. T. (2026). Sustainable and resilient cyber-physical production systems: A systematic literature review. Journal of Computational Design and Engineering, 13(5), 215–249. DOI: 10.1093/jcde/qwag043.
[9] Tovkun, Y., Semerenska, V., & Adamov, A. (2026). An overview of cyber attacks on critical cyber-physical systems and government infrastructures. Security and Safety, 5, 2026002. DOI: 10.1051/sands/2026002.


















