Skip to content
Open access

DAYPSCI: Event-based dataset for anomaly detection through fault injection in PLC-controlled industrial cyber-physical systems

Aug 2026 · Data in Brief · Vol 68, pp. 113146 · 0 citations · 5 references
Medicine

TL;DR

DAYPSCI is presented, an event-based dataset generated using an industrial cyber-physical system (CPS) testbed based on a PLC-controlled part marking station with Siemens S7-1200 and S7-1500 devices that supports the development and evaluation of machine learning methods for anomaly detection and fault classification in industrial CPS.

Abstract

This article presents DAYPSCI, an event-based dataset generated using an industrial cyber-physical system (CPS) testbed based on a PLC-controlled part marking station with Siemens S7-1200 and S7-1500 devices. The system integrates real industrial hardware with digital twin technologies, enabling controlled and repeatable experiments. Data acquisition follows an event-based logging approach, where only changes in system variables are recorded rather than using fixed sampling rates, and each event is associated with its corresponding inter-event time (Δt), enabling precise temporal characterization of system dynamics. The dataset also includes scan-level identifiers (scan_id) and event ordering (event_order), preserving the logical execution order within PLC scan cycles. It contains time-stamped records of digital sensors, solenoid valve control signals, and process states under both normal operation and controlled fault injection scenarios affecting sensors, actuators, or both. Ground truth is generated through a hybrid approach combining externally defined labels from the experimental configuration and labels derived at runtime from control system signals (e.g., GEMMA states), ensuring a clear separation between CPS execution and the labeling layer while enabling traceability between injected faults (cause) and observable system behavior (effect), and allowing differentiation between fault activation and observable anomaly manifestation, which may be temporally decoupled. The dataset is organized into independent experimental batches, each including processed data (CSV), network traffic captures (PCAPNG) from a Profinet-based industrial communication network, and detailed documentation, facilitating sequence-based analysis and reproducibility. The dataset supports the development and evaluation of machine learning methods for anomaly detection and fault classification in industrial CPS.

Read PDF

Similar papers

Open access Aug 2026

Real-time anomaly detection in distributed manufacturing: a high-resolution statistical SCADA framework

Real-time anomaly detection in distributed manufacturing environments often relies on rigid timeout thresholds that may fail to identify missing workpieces or abnormal mechanical behavior until a critical failure occurs. This study presents a high-resolution, statistics-based anomaly detection framework for a Fischertechnik 24 V platform coordinated through a centralized Python supervisory control and data acquisition (SCADA) layer with multiple ESP32 microcontrollers. A statistically normal behavior was established from 10 identical production runs at 10 ms resolution using the mean and standard deviation of movement durations and event timing. The real-time SCADA Watchdog was evaluated through repeated intentional physical fault injection across a complex manufacturing process. The results showed that the framework successfully detected missing/stuck expected events and duration-based temporal deviations in real time, provided precise fault localization, stopped the process for critical missing/stuck anomalies, and logged non-terminal duration anomalies under the implemented monitoring configuration. These findings demonstrate that statistical monitoring can provide effective real-time anomaly detection for distributed manufacturing systems.

Anas Abu Al-Haija'a, B. Szekeres, M. Andó · 0 citations
#machine learning Preprint Aug 2026

Digital Twin-Based Intrusion Detection for Vehicle Powertrain CAN Bus Systems

A DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.

Araf Rahman, M. Salek, Mashrur Chowdhury · 0 citations
2026

Data-driven fault detection and diagnosis in automated manufacturing systems

Abstract. The introduction of a data-based fault detection and diagnosis (FDD) has radically changed the concept of automated manufacturing systems as it provides the capability to monitor real-time in an intelligent manner, diagnose faults beforehand, and predictive maintenance schedules. Data-driven methods, in contrast to traditional reactive ones, make use of continuous sensor data streams to anticipate anomalies before they can result in critical failures using advanced analytics. This proactive feature has a great impact in minimizing unplanned downtime, increasing the safety of operations, and enhancing the overall efficiency of equipment. The FDD systems have been made effective with the help of the artificial intelligence (AI) and the Industrial Internet of Things (IoT). Sensors that have the ability to collect data through IoT can easily get data on various changes of the manufacturing facilities and the AI algorithms can help extract meaningful information data and support in making automated decisions. The other technologies such as cloud platform and edge computing, enable real-time processing of data and scalable analytics, thereby improving responsiveness and efficiency in the system. This implies that manufacturing systems are turning to be more adaptable, independent and robust.

V. K. Nassa · 0 citations
2026

Resilient Prediction Event-Triggered Control Based on Attack Detection for Cyber-Physical Systems

This article focuses on cyber-physical systems subject to unknown disturbances and denial-of-service attacks. To ensure input-to-state stability, an event-triggered predictive control update scheme based on attack detection and a predictor is proposed. Firstly, a attack detection strategy is adopted, which makes full use of historical signals to detect whether the system is under attack at the current moment. Then, an attack detection-based control update scheme is proposed to compensate for state loss, and an event-triggered mechanism integrating detection and prediction is established to reduce resource consumption while ensuring system stability. The results show that the closed-loop cyber-physical systems can achieve input-to-state stability under the proposed control update scheme and event-triggered mechanism. An important advantage of the proposed control update scheme is that the cyber-physical systems select different state inputs according to the attack status at the event-triggered moment, thereby enabling the system to tolerate more adverse denial-of-service attacks. Finally, a simulation case is provided to verify the effectiveness of the proposed method.

Zhen Wang, Wei Chen, Ying-Kang Xie et al. · 0 citations
Conference Jul 2026

Industrial Motors Anomaly Detection using IIoT-Based Semi-Supervised Learning

Motors are crucial elements in the industry, where unexpected failures can interrupt production cycles, reduce profits, and raise safety concerns; and therefore an early anomaly detection in motor behavior is highly appreciated. As an extension of the known internet of things (IoT), industrial IoT or IIoT allows connection of motors and their drive units through distributed sensing platforms capable of acquiring operational data related to power, temperature, vibration, and rotational speed. Once these data are transferred through the available IIoT infrastructure and stored appropriately for later off-line processing, the limited availability of labeled fault data remains a major obstacle in practical industrial applications. As a remedy, this study proposes a semi-supervised anomaly detection framework that relies exclusively on non-intrusive three-phase electrical telemetry. Focusing on a commercial offset printing press, high-frequency power measurements were collected from failure-sensitive dryer motors. Time-domain statistical features, including mean, clearance factor, and shape factor extracted from active power, power factor, and current signals, were employed to train an unsupervised One-Class Support Vector Machine (OC-SVM). Experimental results obtained from 84 hours of real industrial telemetry demonstrated the effectiveness of the proposed approach in modeling normal operating behavior, achieving a Recall of 93.79%, a False Positive Rate of 5.12%, and an F1-Score of 94.59%. The developed framework enables early anomaly detection, lowers maintenance expenses, reduces operational downtime, and enhances overall system reliability, supporting the advancement of smart Industry 4.0 environments.

M. Zeidan, S. Aldalahmeh, Z. Haymoor et al. · 0 citations
Open access Sep 2026

AI-Enhanced Anomaly Detection in Water Treatment Plants

Industrial water treatment plants are increasingly dependent on cyber–physical systems (CPS) and automated control processes for their operational safety and efficiency. However, the embedding of digital control networks exposes these critical infrastructures to sophisticated cyber–physical attacks, including malicious tampering with chemical dosing units and physical actuators. This paper proposes a robust, AI-enhanced anomaly detection framework designed to identify multi-stage malicious activities in water treatment systems using real-world industrial datasets. The proposed system is developed and validated on the Secure Water Treatment (SWaT) dataset, which contains multivariate sensor and actuator time-series data collected from a fully operational physical testbed under both normal operations and targeted cyber–physical attacks. First, high-frequency sensor noise is filtered, and cross-channel measurement reliability is maximized using a Kalman filter-based sensor fusion module. Subsequently, the fused-state vector is analyzed using an unsupervised Isolation Forest algorithm optimized for high-dimensional boundary isolation. To eliminate false negatives caused by stealthy, low-amplitude data injections that bypass purely statistical models, a deterministic, rule-based verification layer derived from physical process control logic is integrated. By integrating a discrete linear Kalman filter with an unsupervised Isolation Forest and deterministic physical rules, the framework effectively suppresses high-frequency sensor noise, achieving a 67.8% reduction in root mean square error (RMSE), while maintaining high detection accuracy across complex industrial attack scenarios. Experimental results demonstrate that the proposed hybrid framework yields superior detection capability, achieving a Precision of ≈95%, a Recall of ≈93%, a scenario-level F1-score of 94.1 % (alongside a sample-level F1-score of 21.5 %) and an edge inference latency of 0.6 ms, effectively demonstrating its suitability for deployment within simulated real-time industrial edge computing environments. The findings further confirm that combining statistical machine learning, state-space sensor fusion, and invariant physical process logic provides a resilient defense paradigm for securing critical industrial infrastructure against modern cyber–physical threats.

Ahmad Ihsan Akmal Izram, M. Habaebi, Mohammed Abdullah Salem Al-Hussaini · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.