Adaptive learning anomaly detection and classification model for cyber and physical threats in industrial control systems

Gabriela Ahmadi‐Assalemi, Haider Al‐Khateeb*, Vladlena Benson, Bogdan Adamyk, Meryem Ammi

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

A surge of digital technologies adopted into Industrial Control Systems (ICS) exposes critical infrastructures to increasingly hostile and well-organised cybercrime. The increased need for flexibility and convenient administration expands the attack surface. Likewise, an insider with authorised access reveals a difficult-to-detect attack vector. Because of the range of critical services that ICS provide, disruptions to operations could have devastating consequences making ICS an attractive target for sophisticated threat actors. Hence, the authors introduce a novel anomalous behaviour detection model for ICS data streams from physical plant sensors. A model for one-class classification is developed, using stream rebalancing followed by adaptive machine learning algorithms coupled with drift detection methods to detect anomalies from physical plant sensor data. The authors’ approach is shown on ICS datasets. Additionally, a use case illustrates the model's applicability to post-incident investigations as part of a defence-in-depth capability in ICS. The experimental results show that the proposed model achieves an overall Matthews Correlation Coefficient score of 0.999 and Cohen's Kappa score of 0.9986 on limited variable single-type anomalous behaviour per data stream. The results on wide data streams achieve an MCC score of 0.981 and a K score of 0.9808 in the prevalence of multiple types of anomalous instances.
Original languageEnglish
Article numbere70004
Number of pages17
JournalIET Cyber-Physical Systems: Theory & Applications
Volume10
Issue number1
Early online date14 Feb 2025
DOIs
Publication statusE-pub ahead of print - 14 Feb 2025

Bibliographical note

Copyright © 2025 The Author(s). IET Cyber-Physical Systems: Theory & Applications published by John Wiley & Sons Ltd on behalf of The Institution of Engineering and Technology. This is an open access article under the terms of the Creative Commons Attribution License, which permits use, distribution and reproduction in any medium, provided the original work is properly cited.

Data Access Statement

The data that support the findings of this study are openly available from:

Elsevier at https://doi.org/10.1016/j.dib.2017.07.038, reference number https://ars.els-cdn.com/content/image/1-s2.0-S2352340917303402-mmc2.zip in the Supporting Information S1 published with the article.

IEEEDataPort at https://dx.doi.org/10.21227/rbvf-2h90, reference number Water Distribution Testbed (WDT) dataset as dataset. zip.

Kaggle at https://www.kaggle.com/datasets/icsdataset/hai-security-dataset, reference number HAI20.07.

Keywords

  • adaptive control
  • cyber-physical systems
  • human factors
  • internet of things
  • learning (artificial intelligence)
  • sensors
  • smart cities

Fingerprint

Dive into the research topics of 'Adaptive learning anomaly detection and classification model for cyber and physical threats in industrial control systems'. Together they form a unique fingerprint.

Cite this