The findings highlight the importance of training-data integrity in ML-enabled ICS monitoring, subject to the evaluated dataset, models, and threat assumptions, and show that robustness is strongly model-dependent and cannot be predicted from clean-data performance alone.
Abstract
Machine-learning-based anomaly detection is increasingly used in industrial control systems (ICS), yet most studies assume that detector training data is trustworthy. In practice, training data may be corrupted through compromised logs, labeling errors, manipulated historian records, or unsafe retraining processes. This paper evaluates the robustness of offline ICS anomaly-detection pipelines on the Secure Water Treatment (SWaT) benchmark under training-time contamination. We assess 11 heterogeneous anomaly detectors under three contamination strategies: random injection, similarity-targeted injection, and feature-noise injection. The first two insert attack samples into the nominal training pool, while the third adds bounded Gaussian noise to selected normal training samples. These attacks are contamination-based rather than gradient-driven poisoning methods. Contamination budgets from 1% to 10% are evaluated using clean validation and test sets under a unified offline protocol. The results show that robustness is strongly model-dependent and cannot be predicted from clean-data performance alone. Injection-based contamination causes the greatest degradation, particularly for local-density and distance-based detectors, whereas feature-noise contamination has a comparatively limited effect. PCA, SVM, HBOS, and IForest remain relatively stable, while the tuned neural detectors demonstrate intermediate robustness. Overall, the findings highlight the importance of training-data integrity in ML-enabled ICS monitoring, subject to the evaluated dataset, models, and threat assumptions.
This study develops and evaluates an AI-based analytical system for detecting anomalies in industrial processes. The work reviews major sources of risk in industrial control systems, distinguishes point, contextual, and collective anomalies, and summarizes the principal machine-learning approaches used for industrial a...
Mehdiyeva Almaz, Ahmedov Elmar, Uzakov Gulom et al.· 2026 International Conferenc...· 0 citations
A comparative evaluation of unsupervised anomaly detection techniques using the PyOD Python library, applied to three representative industrial scenarios: Intrusion Detection, Fault Detection, and Predictive Maintenance, offers valuable guidance for selecting robust anomaly detection models in industrial applications b...
Henry O. Velesaca, Melissa Ayllon Gutierrez, Luis Barrera Muñoz et al.· Manufacturing Review· 0 citations
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
Wenxuan Cao· Science and Technology of En...· 0 citations
This work explores the application of pre-trained time-series foundation models (FMs) for detecting anomalies in industrial processes and introduces a new time-series forecasting method that filters out suspicious data and uses previously predicted data as input, called Forecast Fallback (FF).
During the last decade or so, isolation in SCADA systems has been largely replaced by significant networking, which not only enabled remote operation but also opened up an entirely new threat class. Signature-based IDS systems were not designed for the challenges that follow. Our contribution is a classifier, based on...
R. R, R. Venkatesan, Riya William· 2026 7th International Confe...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.