Skip to content
Preprint

Robustness of Anomaly Detection Models for Industrial Control Systems under Training-Time Data Contamination

Aug 2026 · 0 citations · 39 references
Computer Science

TL;DR

The findings highlight the importance of training-data integrity in ML-enabled ICS monitoring, subject to the evaluated dataset, models, and threat assumptions, and show that robustness is strongly model-dependent and cannot be predicted from clean-data performance alone.

Abstract

Machine-learning-based anomaly detection is increasingly used in industrial control systems (ICS), yet most studies assume that detector training data is trustworthy. In practice, training data may be corrupted through compromised logs, labeling errors, manipulated historian records, or unsafe retraining processes. This paper evaluates the robustness of offline ICS anomaly-detection pipelines on the Secure Water Treatment (SWaT) benchmark under training-time contamination. We assess 11 heterogeneous anomaly detectors under three contamination strategies: random injection, similarity-targeted injection, and feature-noise injection. The first two insert attack samples into the nominal training pool, while the third adds bounded Gaussian noise to selected normal training samples. These attacks are contamination-based rather than gradient-driven poisoning methods. Contamination budgets from 1% to 10% are evaluated using clean validation and test sets under a unified offline protocol. The results show that robustness is strongly model-dependent and cannot be predicted from clean-data performance alone. Injection-based contamination causes the greatest degradation, particularly for local-density and distance-based detectors, whereas feature-noise contamination has a comparatively limited effect. PCA, SVM, HBOS, and IForest remain relatively stable, while the tuned neural detectors demonstrate intermediate robustness. Overall, the findings highlight the importance of training-data integrity in ML-enabled ICS monitoring, subject to the evaluated dataset, models, and threat assumptions.

View source

Similar papers

Conference Jul 2026

AI-based Analytical System for Anomaly Detection in Industrial Processes

This study develops and evaluates an AI-based analytical system for detecting anomalies in industrial processes. The work reviews major sources of risk in industrial control systems, distinguishes point, contextual, and collective anomalies, and summarizes the principal machine-learning approaches used for industrial a...

Mehdiyeva Almaz, Ahmedov Elmar, Uzakov Gulom et al. · 0 citations
Open access 2026

Comparative analysis of unsupervised anomaly detection techniques in industrial systems

A comparative evaluation of unsupervised anomaly detection techniques using the PyOD Python library, applied to three representative industrial scenarios: Intrusion Detection, Fault Detection, and Predictive Maintenance, offers valuable guidance for selecting robust anomaly detection models in industrial applications b...

Henry O. Velesaca, Melissa Ayllon Gutierrez, Luis Barrera Muñoz et al. · 0 citations
Review

ma-Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.

Wenxuan Cao · 0 citations
Review Open access Aug 2026

Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.

Wenxuan Cao · 0 citations

On the Application of Time-Series Foundation Models for Detecting Long-Context Anomalies in Industrial Control Systems

This work explores the application of pre-trained time-series foundation models (FMs) for detecting anomalies in industrial processes and introduces a new time-series forecasting method that filters out suspicious data and uses previously predicted data as input, called Forecast Fallback (FF).

A. Lowe, Clement Fung, Lujo Bauer · 0 citations
Conference Jul 2026

Anomaly Detection and Cybersecurity Monitoring in Industrial Control Networks using SCADA Systems

During the last decade or so, isolation in SCADA systems has been largely replaced by significant networking, which not only enabled remote operation but also opened up an entirely new threat class. Signature-based IDS systems were not designed for the challenges that follow. Our contribution is a classifier, based on...

R. R, R. Venkatesan, Riya William · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.