Explainable correlation-based anomaly detection for Industrial Control Systems

被引:0
|
作者
Birihanu, Ermiyas [1 ]
Lendak, Imre [1 ]
机构
[1] Eotvos Lorand Univ, Fac Informat, Data Sci & Engn Dept, Budapest, Hungary
来源
关键词
anomaly detection; correlation; explainable; Industrial Control System; root cause analysis;
D O I
10.3389/frai.2024.1508821
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Anomaly detection is vital for enhancing the safety of Industrial Control Systems (ICS). However, the complicated structure of ICS creates complex temporal correlations among devices with many parameters. Current methods often ignore these correlations and poorly select parameters, missing valuable insights. Additionally, they lack interpretability, operating efficiently with limited resources, and root cause identification. This study proposes an explainable correlation-based anomaly detection method for ICS. The optimal window size of the data is determined using Long Short-Term Memory Networks-Autoencoder (LSTM-AE) and the correlation parameter set is extracted using the Pearson correlation. A Latent Correlation Matrix (LCM) is created from the correlation parameter set and a Latent Correlation Vector (LCV) is derived from LCM. Based on the LCV, the method utilizes a Multivariate Gaussian Distribution (MGD) to identify anomalies. This is achieved through an anomaly detection module that incorporates a threshold mechanism, utilizing alpha and epsilon values. The proposed method utilizes a novel set of input features extracted using the Shapley Additive explanation (SHAP) framework to train and evaluate the MGD model. The method is evaluated on the Secure Water Treatment (SWaT), Hardware-in-the-loop-based augmented ICS security (HIL-HAI), and Internet of Things Modbus dataset using precision, recall, and F-1 score metrics. Additionally, SHAP is used to gain insights into the anomalies and identify their root causes. Comparative experiments demonstrate the method's effectiveness, achieving a better 0.96% precision and 0.84% F1-score. This enhanced performance aids ICS engineers and decision-makers in identifying the root causes of anomalies. Our code is publicly available at a GitHub repository: https://github.com/Ermiyas21/Explainable-correlation-AD.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] An improved autoencoder-based approach for anomaly detection in industrial control systems
    Aslam, Muhammad Muzamil
    Tufail, Ali
    De Silva, Liyanage Chandratilak
    Haji Mohd Apong, Rosyzie Anna Awg
    Namoun, Abdallah
    SYSTEMS SCIENCE & CONTROL ENGINEERING, 2024, 12 (01)
  • [32] Dynamic Data Abstraction-Based Anomaly Detection for Industrial Control Systems
    Cho, Jake
    Gong, Seonghyeon
    ELECTRONICS, 2024, 13 (01)
  • [33] A real-time network based anomaly detection in industrial control systems
    Zare, Faeze
    Mahmoudi-Nasr, Payam
    Yousefpour, Rohollah
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2024, 45
  • [34] Anomaly Detection on Industrial Time Series Based on Correlation Analysis
    Ding X.-O.
    Yu S.-J.
    Wang M.-X.
    Wang H.-Z.
    Gao H.
    Yang D.-H.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (03): : 726 - 747
  • [35] Explainable anomaly detection for Hot-rolling industrial process
    Jakubowski, Jakub
    Stanisz, Przemyslaw
    Bobek, Szymon
    Nalepa, Grzegorz J.
    2021 IEEE 8TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND ADVANCED ANALYTICS (DSAA), 2021,
  • [36] An explainable unsupervised anomaly detection framework for Industrial Internet of Things
    Abudurexiti, Yilixiati
    Han, Guangjie
    Zhang, Fan
    Liu, Li
    COMPUTERS & SECURITY, 2025, 148
  • [37] A Deep Learning Approach for Anomaly Detection for Industrial Control Systems
    Giracca, Damian Martinez
    Pires, Fabio Lopez
    Baran, Benjamin
    Jara, Eustaquio Alcides Martinez
    2024 L LATIN AMERICAN COMPUTER CONFERENCE, CLEI 2024, 2024,
  • [38] Unsupervised Learning Approach for Anomaly Detection in Industrial Control Systems
    Choi, Woo-Hyun
    Kim, Jongwon
    APPLIED SYSTEM INNOVATION, 2024, 7 (02)
  • [39] Anomaly detection for industrial control systems using process mining
    Myers, David
    Suriadi, Suriadi
    Radke, Kenneth
    Foo, Ernest
    COMPUTERS & SECURITY, 2018, 78 : 103 - 125
  • [40] Machine Learning Methods for Anomaly Detection in Industrial Control Systems
    Tai, Johnathan
    Alsmadi, Izzat
    Zhang, Yunpeng
    Qiao, Fengxiang
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 2333 - 2339