DAN: Neural network based on dual attention for anomaly detection in ICS

被引:1
|
作者
Xu, Lijuan [1 ,2 ,3 ]
Wang, Bailing [1 ]
Zhao, Dawei [2 ,3 ]
Wu, Xiaoming [2 ,3 ]
机构
[1] Harbin Inst Technol, Sch Comp Sci & Technol, Weihai 264209, Peoples R China
[2] Shandong Acad Sci, Key Lab Comp Power Network & Informat Secur, Minist Educ,Shandong Comp Sci Ctr, Natl Supercomp Ctr Jinan,Qilu Univ Technol, Jinan 250014, Shandong, Peoples R China
[3] Shandong Fundamental Res Ctr Comp Sci, Shandong Prov Key Lab Comp Networks, Jinan 250014, Peoples R China
基金
中国国家自然科学基金;
关键词
Industrial control systems; Anomaly detection; Multivariate time series; Dual attention;
D O I
10.1016/j.eswa.2024.125766
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the interpretability research on anomalies of Industrial Control Systems (ICS) with Graph Convolutional Neural Networks (GCN), the causality between the equipment components is a non-negligible factor. Nonetheless, few existing interpretable anomaly detection methods keeps a good balance of detection and interpretation, because of inadequate insufficient learning of causality and improper representation of nodes in GCN. In this paper, we propose a Dual Attention Network (DAN) for a multivariate time series anomaly detection approach, in which temporal causality based on attention is used for representing the relationship of device components. With this condition, the performance of detection is hardly satisfactory. In addition, in the existing graph neural networks, hyperparameters are used to construct an adjacency matrix, so that the detection accuracy is greatly affected. To address the above problems, we introduce a graph neural network based on an attention mechanism to further learn the causal relationship between device components, and propose an adjacency matrix construction method based on the median, to break through the constraint of hyperparameters. In terms of interpretation and detection effect, the performed experiments using the SWaT and WADI datasets from highly simulated real water plants, demonstrate the validity and universality of the DAN.1
引用
收藏
页数:13
相关论文
共 50 条
  • [31] Anomaly Detection System Based on Classifier Fusion in ICS Environment
    Vavra, Jan
    Hromada, Martin
    2017 INTERNATIONAL CONFERENCE ON SOFT COMPUTING, INTELLIGENT SYSTEM AND INFORMATION TECHNOLOGY (ICSIIT), 2017, : 32 - 38
  • [32] ANOMALY DETECTION FOR NETWORK TRAFFIC OF I&C SYSTEMS BASED ON NEURAL NETWORK
    Si, Wen
    Li, Jianghai
    Qu, Ronghong
    Huang, Xiaojin
    PROCEEDINGS OF THE 2020 INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING (ICONE2020), VOL 3, 2020,
  • [33] Few-shot Network Traffic Anomaly Detection Based on Siamese Neural Network
    Xu, Simin
    Han, Xueying
    Tian, Tian
    Jiang, Bo
    Lu, Zhigang
    Zhang, Chen
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 3012 - 3017
  • [34] Airway Anomaly Detection by Prototype-Based Graph Neural Network
    Zhao, Tianyi
    Yin, Zhaozheng
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION - MICCAI 2021, PT V, 2021, 12905 : 195 - 204
  • [35] A Stacking-Based Deep Neural Network Approach for Effective Network Anomaly Detection
    Nkenyereye, Lewis
    Tama, Bayu Adhi
    Lim, Sunghoon
    CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 66 (02): : 2217 - 2227
  • [36] Learning Neural Representations for Network Anomaly Detection
    Van Loi Cao
    Nicolau, Miguel
    McDermott, James
    IEEE TRANSACTIONS ON CYBERNETICS, 2019, 49 (08) : 3074 - 3087
  • [37] Graph neural network approach for anomaly detection
    Xie, Lingqiang
    Pi, Dechang
    Zhang, Xiangyan
    Chen, Junfu
    Luo, Yi
    Yu, Wen
    MEASUREMENT, 2021, 180
  • [38] DuSAG: An Anomaly Detection Method in Dynamic Graph Based on Dual Self-attention
    Lin, Weiqin
    Bao, Xianyu
    Li, Mark Junjie
    Gao, Zukang
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2022, PT I, 2022, 13529 : 121 - 132
  • [39] CloudPAD: Managed Anomaly Detection for ICS
    Rao, Sanjeev
    Ghaderi, Majid
    Zhang, Hongwen
    PROCEEDINGS OF THE 4TH WORKSHOP ON CPS & IOT SECURITY AND PRIVACY, CPSIOTSEC 2022, 2022, : 55 - 61
  • [40] Multidomain neural process model based on source attention for industrial robot anomaly detection
    Yang, Bo
    Huang, Yuhang
    Jiao, Jian
    Xu, Wenlong
    Liu, Lei
    Xie, Keqiang
    Dong, Nan
    ADVANCED ENGINEERING INFORMATICS, 2024, 62