DAN: Neural network based on dual attention for anomaly detection in ICS

被引:1
|
作者
Xu, Lijuan [1 ,2 ,3 ]
Wang, Bailing [1 ]
Zhao, Dawei [2 ,3 ]
Wu, Xiaoming [2 ,3 ]
机构
[1] Harbin Inst Technol, Sch Comp Sci & Technol, Weihai 264209, Peoples R China
[2] Shandong Acad Sci, Key Lab Comp Power Network & Informat Secur, Minist Educ,Shandong Comp Sci Ctr, Natl Supercomp Ctr Jinan,Qilu Univ Technol, Jinan 250014, Shandong, Peoples R China
[3] Shandong Fundamental Res Ctr Comp Sci, Shandong Prov Key Lab Comp Networks, Jinan 250014, Peoples R China
基金
中国国家自然科学基金;
关键词
Industrial control systems; Anomaly detection; Multivariate time series; Dual attention;
D O I
10.1016/j.eswa.2024.125766
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the interpretability research on anomalies of Industrial Control Systems (ICS) with Graph Convolutional Neural Networks (GCN), the causality between the equipment components is a non-negligible factor. Nonetheless, few existing interpretable anomaly detection methods keeps a good balance of detection and interpretation, because of inadequate insufficient learning of causality and improper representation of nodes in GCN. In this paper, we propose a Dual Attention Network (DAN) for a multivariate time series anomaly detection approach, in which temporal causality based on attention is used for representing the relationship of device components. With this condition, the performance of detection is hardly satisfactory. In addition, in the existing graph neural networks, hyperparameters are used to construct an adjacency matrix, so that the detection accuracy is greatly affected. To address the above problems, we introduce a graph neural network based on an attention mechanism to further learn the causal relationship between device components, and propose an adjacency matrix construction method based on the median, to break through the constraint of hyperparameters. In terms of interpretation and detection effect, the performed experiments using the SWaT and WADI datasets from highly simulated real water plants, demonstrate the validity and universality of the DAN.1
引用
收藏
页数:13
相关论文
共 50 条
  • [21] Network Anomaly Detection Using a Graph Neural Network
    Kisanga, Patrice
    Woungang, Isaac
    Traore, Issa
    Carvalho, Glaucio H. S.
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 61 - 65
  • [22] Graph Attention Network and Informer for Multivariate Time Series Anomaly Detection
    Zhao, Mengmeng
    Peng, Haipeng
    Li, Lixiang
    Ren, Yeqing
    SENSORS, 2024, 24 (05)
  • [23] An Attention-Based GRU Network for Anomaly Detection from System Logs
    Xie, Yixi
    Ji, Lixin
    Cheng, Xiaotao
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2020, E103D (08) : 1916 - 1919
  • [24] Hyperspectral Anomaly Detection Based on a Beta Wavelet Graph Neural Network
    Ruhan, A.
    Shen, Danyao
    Liu, Lijing
    Yin, Juanjuan
    Lin, Renpu
    IEEE MULTIMEDIA, 2024, 31 (02) : 69 - 79
  • [25] Anomaly Detection of Processes Behavior in Container Based on LSTM Neural Network
    Chen X.-S.
    Jin Y.-L.
    Wang Y.-L.
    Jiang C.
    Wang Q.-X.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2021, 49 (01): : 149 - 156
  • [26] Network Traffic Anomaly Detection Based on Spatiotemporal Feature Extraction and Channel Attention
    Ji, Changpeng
    Yu, Haofeng
    Dai, Wei
    PROCESSES, 2024, 12 (07)
  • [27] BGP Anomaly Detection Based on Automatic Feature Extraction by Neural Network
    Xu, Mengying
    Li, Xing
    PROCEEDINGS OF 2020 IEEE 5TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2020), 2020, : 46 - 50
  • [28] Anomaly detection analysis based on correlation of features in graph neural network
    Ko, Hoon
    Praca, Isabel
    Choi, Seong Gon
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (09) : 25487 - 25501
  • [29] Anomaly detection analysis based on correlation of features in graph neural network
    Hoon Ko
    Isabel Praca
    Seong Gon Choi
    Multimedia Tools and Applications, 2024, 83 : 25487 - 25501
  • [30] DualAttlog: Context aware dual attention networks for log-based anomaly detection
    Yang, Haitian
    Sun, Degang
    Huang, Weiqing
    NEURAL NETWORKS, 2024, 180