AIセキュリティポータル K Program
System-aware contextual digital twin for ICS anomaly diagnosis
Share
Abstract
Industrial Control Systems (ICS) integrate computing, physical processes, and communication to operate critical infrastructures such as power grids, water treatment plants, and oil and gas facilities. As ICS become increasingly targeted by cyberattacks, timely and reliable anomaly diagnosis is essential for protecting operational safety. However, existing ICS anomaly detection approaches face practical limitations: supervised methods require extensive labeled attack data and suffer from class imbalance, while model-based detectors often lack the ability to provide deep insight into the root causes of anomalies, leading to elevated false alarms and making it difficult for operators to initiate a timely response. In this work, we propose a system-aware unsupervised framework for ICS anomaly diagnosis that combines lightweight online detection with contextual explanation. The system identifies deviations from observed normal behaviors without prior knowledge of system topology. To support actionable response, we further concatenate a contextual digital twin augmented with an Large Language Model (LLM) to enhance interpretability, which translates detection evidence into grounded diagnostic hypotheses and verification steps for operators. Experiments on public ICS benchmarks demonstrate that the proposed framework achieves real-time detection efficiency and provides consistent, interpretable anomaly diagnoses, enabling low-latency warning and practical deployment in complex industrial environments.
Cyber-physical systems security—a survey
Abdulmalik Humayed, Jingqiang Lin, Fengjun Li, Bo Luo
Published: 2017
Stuxnet: Dissecting a cyberwarfare weapon
Ralph Langner
Published: 2011
Machine learning for intrusion detection in industrial control systems: challenges and lessons from experimental evaluation
Gauthama Raman MR, Chuadhry Mujeeb Ahmed, Aditya Mathur
Published: 2021
Machine learning in industrial control system (ics) security: current landscape, opportunities and challenges
Abigail MY Koay, Ryan K L Ko, Hinne Hettema, Kenneth Radke
Published: 2023
An explainable deep learning-enabled intrusion detection framework in IoT networks
M. Keshk, N. Koroniotis, N. Pham, N. Moustafa, B. Turnbull, A. Y. Zomaya
Published: 2023
Ics anomaly detection based on sensor patterns and actuator rules in spatiotemporal dependency
Jun Cai, Zeheng Wei, Jianzhen Luo
Published: 2024
A dataset to support research in the design of secure water treatment systems
J. Goh, S. Adepu, K.N. Junejo, A. Mathur
Published: 2017
A systematic framework to generate invariants for anomaly detection in industrial control systems
Cheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph Chana
Published: 2019
Allhands :ask me anything on large-scale verbatim feedback via large language models
Chaoyun Zhang, Zicheng Ma, Yuhao Wu, Shilin He, Si Qin, Minghua Ma, Xiaoting Qin, Yu Kang, Yuyi Liang, Xiaoyu Gou, Yajie Xue, Qingwei Lin, Saravan Rajmohan, Dongmei Zhang, Qi Zhang
Published: 2025
Large language models are zero-shot time series forecasters
Nate Gruver, Marc Finzi, Shikai Qiu, Andrew Gordon Wilson
Published: 2023
A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions
Huang, L., Yu, W., Ma, W.
Published: 2025
Fast outlier detection in high dimensional spaces
Fabrizio Angiulli, Clara Pizzuti
Published: 2002
Estimating the support of a high-dimensional distribution
Bernhard Scholkopf, John C Platt, John Shawe-Taylor, Alex J Smola, Robert C Williamson
Published: 2001
Learning internal representations by error propagation
David E Rumelhart, Geoffrey E Hinton, Ronald J Williams
Published: 1985
Deep Autoencoding Gaussian Mixture Model for Unsupervised Anomaly Detection
B. Zong, Q. Song, M. Renqiang Min, W. Cheng, C. Lumezanu, D. Cho, H. Chen
Published: 2018
A multimodal anomaly detector for robot-assisted feeding using an lstm-based variational autoencoder
Daehyung Park, Yuuna Hoshi, Charles C. Kemp
Published: 2018
Mad-gan: Multivariate anomaly detection for time series data with generative adversarial networks
Dan Li, Dacheng Chen, Baihong Jin, Lei Shi, Jonathan Goh, See-Kiong Ng
Published: 2019
Ai explainability methods in digital twins: A model and a use case
Tim Kreuzer, Panagiotis Papapetrou, Jelena Zdravkovic
Published: 2025
Attackllm: Llm-based attack pattern generation for an industrial control system
Chuadhry Mujeeb Ahmed
Published: 2025
Uniform manifold approximation and projection
John Healy, Leland McInnes
Published: 2024
Density-based clustering based on hierarchical density estimates
Ricardo JGB Campello, Davoud Moulavi, Jörg Sander
Published: 2013
On the generalized distance in statistics
Prasanta Chandra Mahalanobis
Published: 2018
Share