RuleTwin: Physics-Constrained Rule Induction for Anomaly Detection in Industrial Multivariate Time Serie
Jingzheng Mao, Runjie Pu, Zhen Song, Yanbin Sun, Mohan Li, Zhihong Tian
Abstract
With the deep integration of industrial internet technologies, industrial control systems are increasingly exposed to cyber attacks, where malicious behaviors in cyberspace can propagate into physical processes and induce system anomalies. Existing data-driven anomaly detection methods can identify abnormal patterns but remain limited in attack localization and anomaly interpretation. We propose RuleTwin, a physics-constrained rule induction framework that integrates data-driven modeling with domain-specific physical constraints through dual-view rule learning. RuleTwin induces event-view logical rules to capture control semantics and state-view physical consistency rules to constrain multivariate sensor dynamics, enabling unified anomaly detection, localization, and interpretation. Experiments on industrial benchmark datasets against twelve baseline methods demonstrate that RuleTwin achieves superior detection performance while accurately localizing the compromised actuators or sensors in the majority of cyber attack scenarios.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9ed237bd-04e5-4e2d-ad2f-08d8e7e15d06Related papers
- GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion DetectionKonrad Wolsing, Eric Wagner, Luisa Lux, Klaus Wehrle et al.USENIX Security 2025
- Attributions for ML-based ICS Anomaly Detection: From Theory to PracticeClement Fung, Eric Zeng, Lujo BauerNDSS 2024
- Drift-Aware Memory-Augmented Spatio-Temporal Graph Attention for Industrial Anomaly DetectionYooshin Kim, Donghoon ShinKDD 2026
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 135 citations
- Scaphy: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsicalMoses Ike, Kandy Phan, Keaton Sadoski, Romuald Valme et al.S&P 2023
