Automated Anomaly Detection for Cyber-Physical Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anomaly detection systems for cyber-physical systems, such as utilities systems, are inadequate in automatically and efficiently detecting anomalies caused by cyberattacks, especially in large and complex systems, as they rely on manual generation of invariants or require operational data for machine learning, which is not always accurate or feasible.

Innovation Solution

A computerized method for automatically generating an anomaly detection system by obtaining a directed graph of the cyber-physical system, deriving invariants based on physical and chemical properties, and configuring them as an executable program to detect anomalies, allowing for real-time monitoring and alerting of deviations from normal conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual generation of invariants is used for anomaly detection, then detection accuracy can be improved, but system complexity and time consumption increase significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service by automatically generating invariants through AI/ML algorithms that learn from historical operational data. The anomaly detection system autonomously identifies patterns and creates detection rules without requiring manual expert intervention, thereby maintaining high detection accuracy while reducing system complexity and deployment time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes of invariant generation with automated computational systems. AI and machine learning models substitute the manual expert analysis process, automatically processing operational data to generate invariants. This substitution dramatically reduces the complexity and time associated with manual invariant generation while preserving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Extent of automation

If machine learning with operational data is used, then automation is improved, but data accuracy and availability become critical limitations

Engineering Contradiction:
Improveanomaly detection automationVSAvoiddata accuracy
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system performs preliminary action by pre-processing and validating operational data before feeding it to machine learning models. Data cleaning, normalization, and quality assessment are conducted in advance to ensure high-quality input data. This preliminary preparation mitigates the reliability issues of operational data, enabling effective automation without being constrained by data quality problems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces data preprocessing and validation mechanisms as intermediaries between raw operational data and machine learning algorithms. These intermediary layers clean, transform, and verify data quality before analysis, acting as a buffer that protects the automation system from unreliable or inaccurate operational data while maintaining high automation levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional network-centric defense systems are used, then security against unauthorized access is improved, but vulnerability to advanced cyberattacks increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the defense approach into multiple layers: traditional network-centric security for access control, and AI-driven behavioral analysis for detecting advanced threats. By dividing the security system into complementary segments, it maintains protection against unauthorized access while simultaneously addressing vulnerability to sophisticated cyberattacks that bypass traditional defenses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security system combining traditional network-centric defense mechanisms with modern AI-based anomaly detection. This composite approach integrates the strengths of both methodologies: the proven reliability of traditional access control with the advanced threat detection capabilities of machine learning, thereby maintaining security against unauthorized access while reducing vulnerability to advanced cyberattacks.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS20230185986A1Anomaly detection system for a cyber-physical system
Publication Date: 2023.06.15 SINGAPORE UNIVERSITY OF TECHNOLOGY AND DESIGN
  • US20230185986A1 patent drawing
  • US20230185986A1 patent drawing
  • US20230185986A1 patent drawing

AI summary

A method for automatically generating an anomaly detection system for a cyber-physical system. A directed graph is obtained from the cyber-physical system's design. The directed graph has nodes representing control components of the cyber-physical system that control physical processes. The directed graph is traversed to determine associated control components from the nodes and edges based on predefined parameters. Invariants are derived from the associated control components based on physical/chemical properties governing them. The invariants define conditions for detecting anomalies of the physical processes and are configured as an executable invariant computer program. Upon execution, the anomalies are detectable in response to determining that measurements from the control components have violated the invariant conditions.