Industrial control system intrusion detection method based on improved ternary loss, medium and equipment

CN120915489APending Publication Date: 2025-11-07EZHOU POWER SUPPLY COMPANY STATE GRID HUBEI ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510937615.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-11-07

Smart Images

  • Figure CN120915489A_ABST
    Figure CN120915489A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial control system intrusion detection method, medium and equipment based on improved ternary loss, and the method comprises the following steps: S1, obtaining a network data packet in an industrial control system, carrying out the standardized preprocessing, and constructing a triple data set; s2, training an intrusion detection twin neural network model by using the constructed triple data set and the loss function of the improved ternary loss; s3, inputting network data packets acquired by the industrial control system in real time into the trained twin neural network model for intrusion detection, performing real-time classification and anomaly detection on the network data packets, and judging whether there is an intrusion behavior; according to the method, the ternary loss function is improved by combining the category distribution characteristics and the normalized feature design output by the model, the minimum tolerance boundary distance between different samples is adaptively adjusted, and the intrusion recognition capability and robustness of the model are remarkably enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of machine learning, in particular to an improved ternary loss-based industrial control system intrusion detection method, medium and device. BACKGROUND

[0002] With the wide application of industrial control systems in modern industrial fields, they play a crucial role in ensuring the stability and security of industrial production. However, with the continuous upgrading of network attack means, industrial control systems are facing more and more network security threats, such as denial of service attacks, command injection, malicious scanning, penetration attacks, etc., resulting in serious system failure, equipment damage or data leakage. Therefore, efficient and real-time intrusion detection of industrial control systems has become a core requirement for ensuring their security.

[0003] With the rapid development of machine learning, especially deep learning technology, neural network-based intrusion detection methods have gradually become a research hotspot, providing more accurate and efficient detection performance. Ternary loss, as an effective deep learning loss function, is widely used in similarity learning and classification identification fields. However, there are still some problems to be solved when applied to industrial control system intrusion detection.

[0004] Firstly, how to effectively adjust the boundary distance in the loss function so that the model can accurately distinguish between normal behavior and various intrusion behaviors is still a challenge.

[0005] Secondly, in order to improve the detection accuracy of the model for intrusion behavior, there is usually a long training process, and the accuracy and robustness of the intrusion detection system are required.

[0006] Therefore, it is necessary to design an improved ternary loss-based industrial control system intrusion detection method, medium and device. SUMMARY

[0007] The present application aims to provide an improved ternary loss-based industrial control system intrusion detection method, medium and device to solve the problem of how to effectively adjust the boundary distance in the loss function so that the model can accurately distinguish between normal behavior and various intrusion behaviors, and to improve the detection accuracy of the model for intrusion behavior, there is usually a long training process, and the accuracy and robustness of the intrusion detection system are required.

[0008] To achieve the above-mentioned purpose, the present application provides the following technical solutions:

[0009] In a first aspect, an improved ternary loss-based industrial control system intrusion detection method is provided, comprising the following steps:

[0010] S1: Obtain network data packets x in the industrial control systemt , standardization preprocessing is performed, and a triple data set: {x a , x p , x n} is constructed;

[0011] wherein x a represents an anchor sample; x p represents a positive sample, which is a sample of the same class as the anchor sample; and x n represents a negative sample, which is a sample of a different class from the anchor sample;

[0012] S2: using the constructed triple data set {x a , x p , x n} and the improved triple loss L tri , a loss function is used to train an intrusion detection twin neural network model, which is composed of two identical shared weight f1 and f2, f1 and f2 are any convolutional neural network, so that the output difference of the intrusion detection twin neural network model for different class samples is as large as possible, and the output of the same class sample is as consistent as possible;

[0013] The calculation of the improved triple loss L tri is as follows:

[0014] L tri = max (d p -d n + β·D diff , 0)

[0015] d p = ||f1(x a )-f2(x p ) ||

[0016] d n = ||f1(x a )-f2(x n )||2

[0017] wherein f1(x a ) represents the output of the convolutional neural network f1 input by the sample anchor x a ;

[0018] dp represents the two-norm distance between the output results of the convolutional neural networks f1 and f2 of the sample anchor x a and the positive sample x p ;

[0019] dn represents the two-norm distance between the output results of the convolutional neural networks f1 and f2 of the sample anchor x a and the negative sample x nThe two-norm distance between the output results of the convolutional neural networks f1 and f2, and β is the approximate maximum Euclidean distance D between different classes of samples diff The balance factor, and the product β·D diff The minimum tolerance distance between different classes of samples, and the balance factor β is introduced to make the minimum tolerance distance β·D diff It is achievable, and dynamic adjustment of β in training can make the model converge quickly, and β∈[0.1,1];

[0020] S3: The network data packet x t Input the trained intrusion detection twin neural network model f1 and f2, and the network data packet x t Real-time classification and anomaly detection are performed to determine whether there is an intrusion behavior.

[0021] As a further technical solution of the present application, in step S1, the network data packet in the industrial control system is obtained, and the network traffic in the system is captured using tools such as wireshark on the key equipment nodes of the industrial control system; the labeled preprocessing is performed on the captured network traffic data to generate a data set suitable for model training, which specifically includes the following steps:

[0022] Data analysis: Extract the key fields of the data packet: source / destination IP, source / destination port number, protocol type and payload data;

[0023] Data cleaning: Remove duplicate packets and abnormal packets;

[0024] Feature extraction: Extract statistical features: packet length, inter-packet time interval and payload byte number, combine the key fields and statistical features, and convert them into a fixed-length vector representation;

[0025] Sample label: According to the communication attributes and actual scene of the data packet, sample labeling is performed, the data packet of normal communication behavior is labeled as “1”; the data packet of intrusion behavior is labeled according to the type and purpose of the intrusion behavior, and different labels are assigned to different intrusion behaviors, so that the model can accurately identify multiple abnormal categories.

[0026] As a further technical solution of the present application, in step S2, training the intrusion detection twin neural network model f1 and f2 includes the following steps:

[0027] 1) Input the anchor sample x a , the positive sample x p and the negative sample x n in the batch triple data set {x a , x p , x n} to the intrusion detection twin neural network model f1 and f2.

[0028] 2) Intrusion detection twin neural network model f1 and f2 output high-dimensional normalized feature vector z a , z p , and z n , the value range of the normalized feature vector z a , z p , and z n [0, 1];

[0029] 3) Based on the feature vector dimension m and the number of packet categories n, the approximate maximum Euclidean distance D diff between each packet category center is calculated;

[0030] 4) Calculate the triplet data set {x a , x p , x n} to improve the triplet loss L tri ;

[0031] 5) Take the mean of the entire triplet data set {x a , x p , x n} to get the batch improved triplet loss L;

[0032] 6) Use gradient back propagation to optimize neural network parameters f1(θ) and f2(θ), complete the training of intrusion detection network model f1 and f2, wherein f2 assists f1 in loss calculation during the training process, helps f1 to better train to mature state, and outputs through the trained f1 in real-time classification process.

[0033] As a further technical solution of the present application, based on the feature vector dimension m and the number of packet categories n, the approximate maximum Euclidean distance D diff between the category centers is calculated:

[0034]

[0035] Where i and j represent category i and category j respectively, C i is the sample feature center of category i, and C j is the sample feature center of category j;

[0036] The approximate maximum Euclidean distance D diff between the category centers can satisfy that the distance between each sample center is maximum, and each sample center is an m-dimensional vector with a value range of [0, 1], and the number of packet categories n is less than or equal to the normalized feature vector dimension m.

[0037] As a further technical solution of the present application, the calculation of the batch improved triplet loss L is as follows:

[0038]

[0039] Wherein, N is the number of samples contained in the batch in the batch training of the model.

[0040] As a further technical solution of the present application, in step S3, the network data packet x t The trained intrusion detection twin neural network model f1 and f2 are input into the network data packet x t Real-time classification and anomaly detection, specifically including the following steps:

[0041] 1) The network data packet x t Real-time acquisition is standardized and pretreated;

[0042] 2) The network data packet x t After standardization pretreatment, input f1 in the intrusion detection twin neural network model, get the normalized feature vector z t ;

[0043] 3) Calculate the normalized feature vector z t The Euclidean distance D of each data packet class center, judge which category the network data packet x t Belongs to.

[0044] As a further technical solution of the present application, the calculation of the normalized feature vector z t The Euclidean distance D of each data packet class center is as follows:

[0045]

[0046] As a further technical solution of the present application, the data packet belongs to three cases: normal behavior, abnormal behavior, and uncertain behavior:

[0047] Normal behavior: the normalized feature vector z t Of the network data packet x t The Euclidean distance D of normal data packet class is closer;

[0048] Abnormal behavior: the normalized feature vector z t Of the network data packet x t The Euclidean distance D of normal data packet class is far, and the Euclidean distance D of certain intrusion class is close, then it is judged as intrusion behavior, classified as the corresponding intrusion class;

[0049] Uncertain behavior: for the ambiguous data packet on the boundary, it is judged as "uncertain" category, and manual intervention is requested.

[0050] As a further technical solution of the present application, the network data packet xt a normalized feature vector z of the network data packet x t The Euclidean distance D of the normal data packet category conforms to the following formula:

[0051]

[0052] wherein 1 is a normal category data packet.

[0053] As a further technical solution of the present application, the abnormal behavior network data packet x t a normalized feature vector z of the network data packet x t The Euclidean distance D of the normal data packet category and the intrusion data packet category respectively conforms to the following formula:

[0054]

[0055] wherein i is an intrusion category data packet.

[0056] In a second aspect, a computer readable medium is provided, which stores a computer program, and the computer program, when executed by a processor, implements the improved ternary loss-based industrial control system intrusion detection method in the first aspect.

[0057] In a third aspect, an electronic device is provided, which includes a processor, a memory, and a computer program stored on the memory, and the computer program, when executed by the processor, implements the improved ternary loss-based industrial control system intrusion detection method in the first aspect.

[0058] Compared with the prior art, the improved ternary loss-based industrial control system intrusion detection method, medium and device have the following beneficial effects: by means of the category distribution characteristics and the geometric principle, the ternary loss boundary is reasonably designed, so that the model can adapt to the complex and diverse industrial control system network environment, and has strong generalization ability and robustness; by adaptively adjusting the boundary distance of the ternary loss, the model can accurately distinguish between normal behavior and multiple types of intrusion behavior, and significantly improve the accuracy and recall rate of anomaly detection. BRIEF DESCRIPTION OF DRAWINGS

[0059] Figure 1 The method flowchart of the present application is shown in the figure;

[0060] Figure 2 The training flowchart of the present application is shown in the figure. DETAILED DESCRIPTION

[0061] The technical solutions in the embodiments of the present application will be described clearly and completely below with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work belong to the protection scope of the present application.

[0062] Please refer to the drawings in the embodiments of the present application Figure 1 , one embodiment provided by the present application: an improved ternary loss-based industrial control system intrusion detection method, comprising the following steps:

[0063] S1: obtaining network data packets x in an industrial control system t , performing standardization preprocessing, and constructing a ternary group data set: {x a ,x p ,x n};

[0064] 1. Obtain network data packets in an industrial control system: use tools such as wireshark on key equipment nodes of the industrial control system to capture network traffic in the system;

[0065] 2. Labeling preprocessing: processing the captured network traffic data to generate a data set suitable for model training, specifically including the following steps:

[0066] Data parsing: extracting key fields of the data packet: source / destination IP, source / destination port number, protocol type and payload data;

[0067] Data cleaning: removing duplicate packets and abnormal packets;

[0068] Feature extraction: extracting statistical features: packet length, inter-packet time interval and payload byte number, combining the key fields and statistical features, and converting them into a fixed-length vector representation;

[0069] Sample labeling: according to the communication attributes of the data packet and the actual scene, the sample is labeled, the data packet of normal communication behavior is labeled as "1", the intrusion behavior data packet is labeled according to the type and purpose of the intrusion behavior, and different labels are assigned to different intrusion behaviors, so that the model can accurately identify multiple abnormal categories;

[0070] 3. Constructing a ternary group data set: based on the preprocessed data, constructing a ternary group data set {x a ,x p ,x n} according to the sample categories, wherein x a represents an anchor sample; x p represents a positive sample, which is a sample of the same class as the anchor sample; and x n represents a negative sample, which is a sample of a different class from the anchor sample.

[0071] S2: training the intrusion detection twin neural network model using the constructed triple data set {x a ,x p ,x n} and the improved triple loss L tri , the intrusion detection twin neural network model consisting of two identical shared weight f1 and f2, f1 and f2 being any convolutional neural network;

[0072] Please refer to the attached Figure 2 , the training of the intrusion detection twin neural network model f1 and f2 includes the following steps:

[0073] 1) input the anchor sample x a , the positive sample x p and the negative sample x n in the batch triple data set {x a ,x p ,x n} into the intrusion detection twin neural network model f1 and f2.

[0074] 2) the intrusion detection twin neural network model f1 and f2 output high-dimensional normalized feature vectors z a , z p and z n , the value range of the normalized feature vectors z a , z p and z n being [0, 1];

[0075] 3) based on the feature vector dimension m and the number of packet categories n, the approximate maximum Euclidean distance D diff between each packet category center is calculated:

[0076]

[0077] where i and j represent category i and category j respectively, C i is the sample feature center of category i, and C j is the sample feature center of category j;

[0078] The approximate maximum Euclidean distance D diff between the category centers can satisfy that the distance between each sample center is maximum, and each sample center is an m-dimensional vector with a value range of [0, 1], the number of packet categories n is less than or equal to the dimension m of the normalized feature vector;

[0079] 4) calculate the improved triple loss L a of the triple data set {x p ,x n};tri :

[0080] L tri = max(d p -d n + β · D diff , 0)

[0081] d p = ||f1(x a )-f2(x p ) ||

[0082] d n = ||f1(x a )-f2(x n )||2

[0083] wherein f1(x a ) represents the output of the sample anchor point x a input convolutional neural network f1;

[0084] dp represents the two-norm distance between the output results of the convolutional neural networks f1 and f2 of the sample anchor point x a and the positive sample x p ;

[0085] dn represents the two-norm distance between the output results of the convolutional neural networks f1 and f2 of the sample anchor point x a and the negative sample x n , β is a balance factor of the approximate maximum Euclidean distance D diff between the heterogeneous samples, and the product β·D diff constitutes the minimum tolerance distance between the heterogeneous samples. The introduction of the balance factor β makes the minimum tolerance distance β·D diff realizable, and the dynamic adjustment of β in the training can make the model converge quickly, and β ∈ [0.1, 1];

[0086] 5) The mean value of the entire triplet data set {x a , x p , x n} is obtained, and the batch improved triplet loss L is obtained:

[0087]

[0088] wherein N is the number of samples contained in the batch in the batch training of the model;

[0089] 6) The neural network parameters f1(θ) and f2(θ) are optimized by gradient back propagation, and the training of the intrusion detection network model f1 and f2 is completed, wherein f2 assists f1 in loss calculation in the training process, helps f1 to be better trained to a mature state, and the trained f1 is output in the real-time classification process;

[0090] S3: obtaining network data packet x in real time by the industrial control system t inputting network data packet x into trained intrusion detection twin neural network model f1 and f2 t performing real-time classification and anomaly detection to determine whether there is an intrusion behavior, which specifically includes the following steps:

[0091] 1) performing standardization preprocessing on network data packet x t obtained in real time;

[0092] 2) inputting network data packet x t after standardization preprocessing into f1 in the intrusion detection twin neural network model to obtain normalized feature vector z t ;

[0093] 3) calculating the Euclidean distance D between normalized feature vector z t and each data packet class center to determine which class network data packet x t belongs to, and the data packet class includes three cases: normal behavior, abnormal behavior, and uncertain behavior;

[0094] the calculation of the Euclidean distance D between normalized feature vector z t and each data packet class center is as follows:

[0095]

[0096] normal behavior: the Euclidean distance D between normalized feature vector z t of network data packet x t and the normal data packet class is relatively close;

[0097] network data packet x t with normal behavior, whose normalized feature vector z t meets the following formula:

[0098]

[0099] wherein, 1 is a normal class data packet;

[0100] abnormal behavior: the Euclidean distance D between normalized feature vector z t of network data packet x t and the normal data packet class is relatively far, and the Euclidean distance D between the normalized feature vector z t and an intrusion class is relatively close, then it is determined as an intrusion behavior and classified as the corresponding intrusion class;

[0101] network data packet x tThe Euclidean distance D of the normal data packet category and the intrusion data packet category is respectively in accordance with the following formula:

[0102]

[0103] Wherein, i is the intrusion category data packet;

[0104] Uncertain behavior: for the ambiguous data packet on the boundary, the "uncertain" category is determined, and manual intervention is requested;

[0105] An embodiment provided by the application: a computer readable medium, which stores a computer program, the computer program is executed by a processor, and the improved ternary loss based industrial control system intrusion detection method is realized;

[0106] An embodiment provided by the application: an electronic device, comprising a processor, a memory and a computer program stored on the memory, the computer program is executed by the processor, and the improved ternary loss based industrial control system intrusion detection method is realized;

[0107] To sum up, the improved ternary loss based industrial control system intrusion detection method, medium and device provided by the application, by means of category distribution characteristics and geometric principles, reasonably design the ternary loss boundary, so that the model can adapt to complex and diverse industrial control system network environment, has strong generalization ability and robustness;By self-adaptive adjustment of the boundary distance of ternary loss, the model can accurately distinguish normal behavior and various types of intrusion behavior, significantly improve the accuracy and recall rate of anomaly detection;The application realizes comprehensive improvement in detection ability, training efficiency and adaptability, and provides efficient and reliable technical support for the safety protection of industrial control system.

[0108] It is apparent to those skilled in the art that the application is not limited to the details of the above exemplary embodiments, but can be implemented in other concrete forms without departing from the spirit or essential characteristics of the application. Therefore, the embodiments should be regarded as exemplary and non-limiting, and the scope of the application is defined by the appended claims rather than the above description, and therefore all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the application. Any reference signs in the claims should not be regarded as limiting the claims involved.

Claims

1. An improved ternary loss-based industrial control system intrusion detection method, comprising the following steps: S1: Obtain network data packet x in the industrial control system t , perform standardization preprocessing, and construct a triple data set: {x a , x p , x n} where x a represents an anchor sample; x p represents a positive sample, a sample of the same class as the anchor sample; x n represents a negative sample, a sample of a different class than the anchor sample; S2: training an intrusion detection twin neural network model using the constructed triple data set {x a ,x p ,x n} and the improved triple loss L tri , the intrusion detection twin neural network model consisting of two identical shared weight f1 and f2, f1 and f2 being any convolutional neural network; The improved triplet loss L tri is calculated as follows: L tri = max(d p - d n + β · D diff , 0) d p = ||f1(x a )-f2(x p )||2 d n = ||f1(x a )-f2(x n )||2 where f1(x a ) denotes the sample anchor point x a the output of the input convolutional neural network f1; dp denotes the sample anchor point x a and the positive sample x p the euclidean distance between the outputs of the convolutional neural networks f1 and f2; dn represents the sample anchor point x a and the negative sample x n The two-norm distance between the output results of the convolutional neural networks f1 and f2, β is the balance factor of the approximate maximum Euclidean distance D between heterogeneous samples diff The product of the two β·D diff The minimum tolerance distance between heterogeneous samples is composed of the balance factor β, so that the minimum tolerance distance β·D diff is achievable, and dynamic adjustment of β during training can make the model converge quickly, β∈[0.1,1]; S3: the network data packet x acquired by the industrial control system in real time t inputting the trained intrusion detection twin neural network model f1 and f2 into the network data packet x t performing real-time classification and anomaly detection to determine whether there is an intrusion behavior.

2. The improved ternary loss based industrial control system intrusion detection method according to claim 1, characterized in that: In step S1, network packets in the industrial control system are obtained, and network traffic in the system is captured using tools such as wireshark on key device nodes of the industrial control system; the labeled preprocessing is performed on the captured network traffic data to generate a data set suitable for model training, specifically including the following steps: Data analysis: extract key fields of the data packet: source / destination IP, source / destination port number, protocol type and payload data; Data cleaning: remove duplicate packets and abnormal packets; Feature extraction: extract statistical features: packet length, inter-packet time interval and payload byte count, combine the key fields and statistical features, and convert them into fixed-length vector representation; Sample labeling: according to the communication attributes and actual scene of the data packet, sample labeling is performed, the data packet of normal communication behavior is labeled as "1"; the data packet of intrusion behavior is labeled according to the type and purpose of the intrusion behavior, and different labels are assigned to different intrusion behaviors to enable the model to accurately identify multiple abnormal categories.

3. The improved ternary loss based industrial control system intrusion detection method according to claim 1, characterized in that: In step S2, training the intrusion detection twin neural network model f1 and f2 includes the following steps: 1) input anchor samples x a , positive samples x p , and negative samples x n in a batch triple dataset {x a , x p , x n} to intrusion detection twin neural network models f1 and f2. 2) Intrusion detection twin neural network model f1 and f2 output high-dimensional normalized feature vector z a , z p , and z n , the value range of normalized feature vector z a , z p , and z n [0, 1] 3) Based on the feature vector dimension m and the number of data packet classes n, calculate the approximate maximum Euclidean distance D between each data packet class center diff ; 4) compute the triple data set {x a ,x p ,x n} improve triple loss L tri ; 5) take the mean over the entire triplet dataset {x a ,x p ,x n} to get the batch-improved triplet loss L; 6) Use gradient back propagation to optimize neural network parameters f1(θ) and f2(θ), and complete the training of intrusion detection network model f1 and f2.

4. The improved ternary loss based industrial control system intrusion detection method according to claim 3, characterized in that: The approximate maximum Euclidean distance D between the class centers is calculated based on the feature vector dimension m and the number of data packet categories n diff : where i, j denote class i and class j, respectively, C i is the sample feature center for class i, C j is the sample feature center for class j. The approximate maximum Euclidean distance D between the category centers diff The calculation method can satisfy that the distances between the n category sample centers are maximum, each sample center is an m-dimensional vector with a value range of [0, 1], and the number n of data packet categories is less than or equal to the normalized feature vector dimension m.

5. The improved ternary loss based industrial control system intrusion detection method according to claim 3, characterized in that: The calculation of the improved ternary loss L is as follows: Where N is the number of samples contained in the batch in the model batch training.

6. The improved ternary loss based industrial control system intrusion detection method according to claim 1, wherein: In the step S3, the network data packet x t The trained intrusion detection twin neural network model f1 and f2 are input into the network data packet x t Real-time classification and anomaly detection, specifically including the following steps: 1) Standardized preprocessing of real-time acquired network packets x t ; 2) normalizing the pre-processed network data packet x t inputting f1 into the intrusion detection twin neural network model to obtain a normalized feature vector z t ; 3) Compute normalized feature vector z t Euclidean distance D to each data packet class center, determine which class network data packet x t belongs to.

7. The improved ternary loss based industrial control system intrusion detection method according to claim 6, characterized in that: The normalized feature vector z t The calculation of the Euclidean distance D from each data packet class center is as follows:

8. The improved ternary loss based industrial control system intrusion detection method according to claim 6, characterized in that: The category of the data packet includes three cases: normal behavior, abnormal behavior and uncertain behavior: Normal behavior: network packet x t normalized feature vector z t closer Euclidean distance D to normal packet class Abnormal behavior: network packet x t Normalized feature vector z of x t If the Euclidean distance D with normal packet category is far and the Euclidean distance D with some intrusion category is close, it is judged as intrusion behavior and classified into the corresponding intrusion category. Uncertain behavior: for the ambiguous data packet on the boundary, it is judged as "uncertain" category and requests manual intervention.

9. The improved ternary loss based industrial control system intrusion detection method according to claim 8, characterized in that: said normal behavior network data packet x t a normalized feature vector z t the euclidean distance D to the normal data packet class is in accordance with the following equation: Where 1 is the normal category data packet.

10. The improved ternary loss based industrial control system intrusion detection method of claim 8, wherein: The abnormal behavior network data packet x t The normalized feature vector z t The Euclidean distances D of the normal data packet category and the intrusion data packet category respectively satisfy the following formulas: Where i is the intrusion category data packet.

11. A computer readable medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the improved ternary loss-based industrial control system intrusion detection method according to any one of claims 1-10.

12. An electronic device comprising a processor, a memory, and a computer program stored on the memory, characterized in that, The computer program, when executed by the processor, implements the improved ternary loss-based industrial control system intrusion detection method according to any one of claims 1-10.