Adaptable and Interpretable Framework for Anomaly Detection in SCADA-based industrial systems

被引:9
作者
Wadinger, Marek [1 ]
Kvasnica, Michal [1 ]
机构
[1] Slovak Univ Technol Bratislava, Inst Informat Engn Automat & Math, Radlinskeho 9, Bratislava 81237, Slovakia
关键词
Anomaly detection; Root cause isolation; Iterative learning; Statistical learning; Self-supervised learning;
D O I
10.1016/j.eswa.2024.123200
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In this paper, we introduce an Adaptable and Interpretable Framework for Anomaly Detection (AID) designed for industrial systems utilizing IoT data streams on top of well -established SCADA systems. AID leverages dynamic conditional probability distribution modeling to capture the normal operation of dynamic systems and isolate the root causes of anomalies at the level of individual inputs. The self -supervised framework dynamically updates parameters of underlying model, allowing it to adapt to non-stationarity. AID interprets anomalies as significant deviations from conditional probability, encompassing interactions as well as both spatial and temporal irregularities by exposing them as features. Crucially, AID provides dynamic operating limits to integrate with existing alarm handling mechanisms in SCADA-based IoT systems. Two industrial -scale case studies demonstrate AID's capabilities. The first study showcases AID's effectiveness on energy storage system, adapting to changes, setting context -aware limits for SCADA, and ability to leverage a physics -based model. The second study monitors battery module temperatures, where AID identifies hardware faults, emphasizing its relevance to energy storage safety. A benchmark evaluation on real data shows that AID delivers comparable performance to other self -learning adaptable anomaly detection methods, with the significant advancement in diagnostic capabilities for improved system reliability and performance.
引用
收藏
页数:15
相关论文
共 48 条
[31]  
Salehi Mahsa, 2018, ACM SIGKDD Explorations Newsletter, V20, P13, DOI 10.1145/3229329.3229332
[32]   Do not let your safe operating limits leave you S-O-L (out of luck) [J].
Stauffer, Todd ;
Chastain-Knight, Denise .
PROCESS SAFETY PROGRESS, 2021, 40 (01)
[33]   FLAGS: A methodology for adaptive anomaly detection and root cause analysis on sensor data streams by fusing expert knowledge with machine learning [J].
Steenwinckel, Bram ;
De Paepe, Dieter ;
Hautte, Sander Vanden ;
Heyvaert, Pieter ;
Bentefrit, Mohamed ;
Moens, Pieter ;
Dimou, Anastasia ;
Van Den Bossche, Bruno ;
De Turck, Filip ;
Van Hoecke, Sofie ;
Ongenae, Femke .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 116 :30-48
[34]   Adaptive Anomaly Detection and Root Cause Analysis by Fusing Semantics and Machine Learning [J].
Steenwinckel, Bram .
SEMANTIC WEB: ESWC 2018 SATELLITE EVENTS, 2018, 11155 :272-282
[35]   Anomaly Detection in High-Dimensional Data [J].
Talagala, Priyanga Dilini ;
Hyndman, Rob J. ;
Smith-Miles, Kate .
JOURNAL OF COMPUTATIONAL AND GRAPHICAL STATISTICS, 2021, 30 (02) :360-374
[36]   Efficient Computer Network Anomaly Detection by Changepoint Detection Methods [J].
Tartakovsky, Alexander G. ;
Polunchenko, Aleksey S. ;
Sokolov, Grigory .
IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2013, 7 (01) :4-11
[37]   Anomaly detection in streaming data: A comparison and evaluation study [J].
Vazquez, Felix Iglesias ;
Hartl, Alexander ;
Zseby, Tanja ;
Zimek, Arthur .
EXPERT SYSTEMS WITH APPLICATIONS, 2023, 233
[38]   Real-Time Outlier Detection with Dynamic Process Limits [J].
Wadinger, Marek ;
Kvasnica, Michal .
2023 24TH INTERNATIONAL CONFERENCE ON PROCESS CONTROL, PC, 2023, :138-143
[39]   NOTE ON A METHOD FOR CALCULATING CORRECTED SUMS OF SQUARES AND PRODUCTS [J].
WELFORD, BP .
TECHNOMETRICS, 1962, 4 (03) :419-&
[40]   Unsupervised Anomaly Alerting for IoT-Gateway Monitoring using Adaptive Thresholds and Half-Space Trees [J].
Wetzig, Rene ;
Gulenko, Anton ;
Schmidt, Florian .
2019 SIXTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2019, :161-168