The increasing integration of cyber-physical systems in critical infrastructure like water treatment plants has heightened their vulnerability to sophisticated attacks, necessitating robust anomaly detection mechanisms. This paper presents a Temporal-Enhanced LSTM Autoencoder (TE-LSTM-AE), a novel two-stage deep learning model designed to detect cyber-physical attacks by learning complex temporal patterns and cross-sensor correlations. Our group-aware architecture processes sensor data based on functional characteristics (e.g., hydraulic performance, water quality) in dedicated autoencoders before a fusion stage learns critical inter-group relationships. Evaluated on the Secure Water Treatment (SWaT) testbed, the model achieved state-of-the-art performance with a precision of 0.9910, recall of 0.9244, F1-score of 0.9565, and a near-perfect ROC-AUC of 0.9971. Detailed analysis demonstrates the model's high sensitivity to disruptions in hydraulic correlations and its unique capability to identify a concentrated multi-stage attack campaign. The results establish that a physics-informed, group-based approach is superior for achieving high-fidelity, interpretable, and robust anomaly detection in complex industrial environments.
更多
查看译文
关键词
Critical Infrastructure Security,Industrial Control Systems (ICS),Anomaly Detection,Cyber-Physical Systems (CPS),Deep Learning,LSTM Autoencoder,Secure Water Treatment (SWaT),Time Series Analysis,Sensor Data Correlation,Attack Detection