Stateful Nonlinear Embedding for Cyber-Physical Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial asset control systems are vulnerable to cyber-attacks, and existing fault detection methods, such as FDIA, are limited in detecting multiple simultaneous faults and do not effectively address malicious threats, especially in complex cyber-physical systems with large numbers of physical measurements.

Innovation Solution

A stateful, nonlinear embedding system that receives time-series measurements from cyber-physical systems, projects them into a lower-dimensional latent variable space, reducing redundant information and capturing temporal and spatial dependencies, using techniques like stateful generative adversarial networks to automatically identify underlying system characteristics for rapid and accurate anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous faults and cyber threats cannot be effectively detected

Engineering Contradiction:
Improvefault detection capabilityVSAvoiddetection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the cyber-physical system into multiple monitoring layers (IT, OT, and physical domain), with each layer having specialized detection mechanisms. This segmentation allows the system to detect faults and threats at different levels simultaneously, overcoming the limitation of traditional single-layer FDIA approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal monitoring framework that can detect multiple types of anomalies (sensor faults, actuator failures, cyber threats) across different system layers. The cross-layer correlation mechanism provides multi-functional detection capability, enabling the system to handle various fault types and threat scenarios with a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If analysis is performed directly on physical measurements, then detection accuracy may be high, but the large number of measurements makes rapid detection difficult

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts relevant features and characteristics from the large volume of physical measurements at multiple layers. By taking out only the critical information needed for anomaly detection and performing cross-layer correlation on these extracted features, the system maintains high detection accuracy while significantly improving processing speed and reducing computational burden.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent adds a cross-layer dimension to the analysis by correlating measurements across IT, OT, and physical domains. This dimensional transformation allows the system to detect anomalies more efficiently by looking for inconsistencies across layers rather than analyzing each measurement individually, thereby improving both speed and accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If protection layers are added in IT and OT domains, then cyber-security is improved, but threats can still penetrate to the physical domain

Engineering Contradiction:
Improvecyber-securityVSAvoidthreat penetration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements cross-layer feedback mechanisms where anomalies detected at one layer are correlated with data from other layers. This feedback loop enables the system to identify threats that attempt to penetrate protection layers by looking for correlated anomalies across IT, OT, and physical domains, providing early warning before threats cause significant damage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary anomaly detection and correlation across multiple layers before threats can fully penetrate to the physical domain. By establishing cross-layer baseline behaviors and detecting deviations early, the system takes preliminary anti-action to prevent or mitigate threat penetration, rather than merely reacting after breaches occur.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3515041B1System and method for abstracting characteristics of cyber-physical systems
Publication Date: 2023.03.29 GE INFRASTRUCTURE TECH LLC
  • EP3515041B1 patent drawingFigure 1
  • EP3515041B1 patent drawingFigure 2
  • EP3515041B1 patent drawingFigure 3

AI summary

A data source may provide a plurality of time-series measurements that represent normal operation of a cyber-physical system (e.g., in substantially real-time during online operation of the cyber-physical system). A stateful, nonlinear embedding computer may receive the plurality of time-series measurements and execute stateful, nonlinear embedding to project the plurality of time-series measurements to a lower-dimensional latent variable space. In this way, redundant and irrelevant information may be reduced, and temporal and spatial dependence among the measurements may be captured. The output of the stateful, nonlinear embedding may be utilized to automatically identify underlying system characteristics of the cyber-physical system. In some embodiments, a stateful generative adversarial network may be used to achieve stateful embedding.