Attributions for ML-based ICS Anomaly Detection: From Theory to Practice
Clement Fung, Eric Zeng, Lujo Bauer
摘要
—Industrial Control Systems (ICS) govern critical infrastructure like power plants and water treatment plants. ICS can be attacked through manipulations of its sensor or actuator values, causing physical harm. A promising technique for detecting such attacks is machine-learning-based anomaly detection, but it does not identify which sensor or actuator was manipulated and makes it difficult for ICS operators to diagnose the anomaly’s root cause. Prior work has proposed using attribution methods to identify what features caused an ICS anomaly-detection model to raise an alarm, but it is unclear how well these attribution methods work in practice. In this paper, we compare state-of-the-art attribution methods for the ICS domain with real attacks from multiple datasets. We find that attribution methods for ICS anomaly detection do not perform as well as suggested in prior work and identify two main reasons. First, anomaly detectors often detect attacks either immediately or significantly after the attack start; we find that attributions computed at these detection points are inaccurate. Second, attribution accuracy varies greatly across attack properties, and attribution methods struggle with attacks on categorical-valued actuators. Despite these challenges, we find that ensembles of attributions can compensate for weaknesses in individual attribution methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Recovering Process Variables from Industrial Network Traffic via Search-Based OptimizationChuan Sheng, Shan Jiang, Jianming Zhao, Yu YaoCCS 2026
- GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion DetectionKonrad Wolsing, Eric Wagner, Luisa Lux, Klaus Wehrle 等USENIX Security 2025
它引用的顶会 Paper16
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Graph Neural Network-Based Anomaly Detection in Multivariate Time SeriesAilin Deng, Bryan HooiAAAI 2021 · 被引用 1,306 次
- Kitsune: An Ensemble of Autoencoders for Online Network Intrusion DetectionYisroel Mirsky, Tomer Doitshman, Yuval Elovici, Asaf ShabtaiNDSS 2018 · 被引用 945 次
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer 等CCS 2016 · 被引用 351 次
- LEMNA: Explaining Deep Learning based Security ApplicationsWenbo Guo, Dongliang Mu, Jun Xu, Purui Su 等CCS 2018 · 被引用 336 次
相关 Paper
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 被引用 135 次
- RuleTwin: Physics-Constrained Rule Induction for Anomaly Detection in Industrial Multivariate Time SerieJingzheng Mao, Runjie Pu, Zhen Song, Yanbin Sun 等KDD 2026
- ORTHRUS: Achieving High Quality of Attribution in Provenance-based Intrusion Detection SystemsBaoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khaldoun Al Agha 等USENIX Security 2025
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan 等USENIX Security 2024 · 被引用 9 次
- Who's in Control of Your Control System? Device Fingerprinting for Cyber-Physical SystemsDavid Formby, Preethi Srinivasan, Andrew M. Leonard, Jonathan D. Rogers 等NDSS 2016 · 被引用 171 次
