Automated Identification and Interpretation of Anomalous Cases in Industrial Control Systems

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Industrial control systems (ICS), which manage critical infrastructure such as power grids and water treatment, are increasingly exposed to cyber threats and operational faults as their connectivity to external networks grows. AI-based anomaly detection has emerged as a key defense, yet three limitations restrict its practical deployment: (i) detected anomalies are treated uniformly without distinguishing between transient faults and intentional attacks, hindering tailored incident response; (ii) the trade-off between detection accuracy and the false-positive rate burdens experts with extensive manual triage and delays prompt action; and (iii) prevailing feature-attribution Explainable AI (XAI) techniques such as SHAP and LIME produce fragmented sensor-level explanations and fail to capture correlations among sensors in time-series data, undermining trust in model decisions. To address these gaps, this paper proposes a graph-based deep learning framework that (a) defines anomaly types in terms of the anomalous-sensor ratio measured before and after smoothing-which operationalizes the correlation-maintenance principle that faults keep coupled sensors jointly anomalous while attacks isolate them-enabling explicit separation of faults, attacks, false positives, and false negatives; (b) identifies ambiguous decisions near the detection threshold as candidate false alarms via dynamic threshold smoothing; and (c) provides correlation-aware graph visualizations for intuitive interpretation. Experiments on the Secure Water Treatment (SWaT) dataset center on this post-detection layer: built on a standard graph-based detector (F1-score 0.787 at Top-K = 10) that serves only as the substrate, the categorization separates faults from attacks, and the subsequent ambiguity analysis identifies false negatives with 83% precision and false positives with 73% precision. By separating attacks from faults and surfacing high-likelihood false alarms together with intuitive sensor-correlation explanations, the proposed approach reduces analyst workload and supports more reliable, prioritized incident response in ICS environments.

키워드

anomaly detectiongraphcorrelationattackfaultfalse alarmNETWORKAI
제목
Automated Identification and Interpretation of Anomalous Cases in Industrial Control Systems
저자
Lee, SeonwooLim, SeungbeomLee, Taejin
DOI
10.3390/electronics15122705
발행일
2026-06
유형
Article
저널명
ELECTRONICS
15
12