Zero-Day Attack Detection in Industrial Control Systems Based on Siamese Neural Networks
DOI:
https://doi.org/10.64972/jaat.2024v2.277p22e:307-319Keywords:
Siamese Neural Network, Industrial Control System, Metric Learning, Cyber-physical SecurityAbstract
Industrial Control Systems are responsible for regulating the conditions in a particular area, and the reliability of this regulation depends on sensors, controllers, actuators and supervisory networks. Zero-day attacks are difficult to detect as they do not have known signatures and can maintain protocol validity by modifying process-state relationships. A Siamese Neural Network Framework for Zero-Day Attack Detection in Industrial Control Systems. Encode multi-source cyber-physical observations as paired process-state windows, map each window into a metric embedding space, and determine whether a suspicious window is close to the normal reference behaviour. To reduce false alarms and keep the sensitivity to unseen attacks, a safety-weighted contrastive objective, an adaptive open-set threshold and a temporal consistency filter are added. As shown in the example experimental data from an ICS testbed scenario, the proposed method has achieved 98.4% accuracy, 97.6% F1-score, 96.9% zero-day recall, and a false alarm rate of 1.8%, thereby surpassing the performance of autoencoder, one-class SVM, LSTM, CNN-LSTM and standard Siamese baselines. Ablation experiments show that the largest increase in performance for unknown attacks comes from safety-aware weighting and adaptive thresholding. A system for identifying new industrial attacks by means of similarity learning, rather than learning attack signatures.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2024 Tadeusz Zając, Edmund Sowa

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.