AI-Enhanced Anomaly Detection in Water Treatment Plants
Industrial water treatment plants are increasingly dependent on cyber–physical systems (CPS) and automated control processes for their operational safety and efficiency. However, the embedding of digital control networks exposes these critical infrastructures to sophisticated cyber–physical attacks, including malicious tampering with chemical dosing units and physical actuators. This paper proposes a robust, AI-enhanced anomaly detection framework designed to identify multi-stage malicious activities in water treatment systems using real-world industrial datasets. The proposed system is developed and validated on the Secure Water Treatment (SWaT) dataset, which contains multivariate sensor and actuator time-series data collected from a fully operational physical testbed under both normal operations and targeted cyber–physical attacks. First, high-frequency sensor noise is filtered, and cross-channel measurement reliability is maximized using a Kalman filter-based sensor fusion module. Subsequently, the fused-state vector is analyzed using an unsupervised Isolation Forest algorithm optimized for high-dimensional boundary isolation. To eliminate false negatives caused by stealthy, low-amplitude data injections that bypass purely statistical models, a deterministic, rule-based verification layer derived from physical process control logic is integrated. By integrating a discrete linear Kalman filter with an unsupervised Isolation Forest and deterministic physical rules, the framework effectively suppresses high-frequency sensor noise, achieving a 67.8% reduction in root mean square error (RMSE), while maintaining high detection accuracy across complex industrial attack scenarios. Experimental results demonstrate that the proposed hybrid framework yields superior detection capability, achieving a Precision of ≈95%, a Recall of ≈93%, a scenario-level F1-score of 94.1 % (alongside a sample-level F1-score of 21.5 %) and an edge inference latency of 0.6 ms, effectively demonstrating its suitability for deployment within simulated real-time industrial edge computing environments. The findings further confirm that combining statistical machine learning, state-space sensor fusion, and invariant physical process logic provides a resilient defense paradigm for securing critical industrial infrastructure against modern cyber–physical threats.