Supervised Anomaly Detection via Synthesized Abnormal Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems lack effective methods to automatically detect cyber-attacks at the domain layer, where sensors, controllers, and actuators are located, and existing protection schemes fail to accurately differentiate between faults and malicious attacks, especially when multiple monitoring nodes are involved.
Innovation Solution
The implementation of supervised anomaly detection methods augmented by synthesized abnormal data generation using generative models, which learn the characteristics of normal data to generate complementary abnormal data, enabling the creation of decision boundaries for accurate detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If supervised anomaly detection methods are used with limited abnormal data, then detection accuracy deteriorates, but using synthesized abnormal data increases device complexity
Solution Approach 1:
The system performs preliminary actions by synthesizing abnormal data in advance using generative models before actual anomaly detection is needed. This pre-computed synthesized abnormal data is then used during supervised anomaly detection to improve accuracy without increasing real-time computational complexity
Solution Approach 2:
The system creates copies of abnormal operation patterns through generative models that learn from normal data characteristics. These synthesized copies serve as training data for supervised anomaly detection, enabling accurate detection without requiring actual abnormal data samples
2Reliability
If multiple monitoring nodes are analyzed to improve detection reliability, then the quantity of data increases, but differentiation between faults and attacks becomes more difficult
Solution Approach 1:
The system segments the analysis by creating separate synthesized abnormal data sets for different attack types and fault conditions. Each monitoring node's data is processed independently through the generative model, allowing differentiated detection patterns to be learned and applied to distinguish between various abnormal conditions
Solution Approach 2:
The system applies local quality by tailoring the synthesized abnormal data generation to specific monitoring nodes and their individual characteristics. Each node receives customized synthesized data that reflects its local operational patterns, enabling more accurate local differentiation between faults and attacks
3Reliability
If passive monitoring is used to reduce system complexity, then detection capability against sophisticated attacks deteriorates, but active synthesized data generation increases computational requirements
Solution Approach 1:
The system performs computationally intensive data synthesis in advance during off-line periods when energy consumption is less critical. The generative model learns from normal data and synthesizes abnormal patterns beforehand, so that during actual monitoring, the system only needs to compare against pre-computed synthesized data, reducing real-time computational energy requirements
Data Source
AI summary
A Cyber-Physical System (“CPS”) may have monitoring nodes that generate a series of current monitoring node values representing current operation of the CPS. A normal space data source may store, for each monitoring node, a series of normal monitoring node values representing normal operation of the CPS. An abnormal data generation platform may utilize information in the normal space data source and a generative model to create generated abnormal to represent abnormal operation of the CPS. An abnormality detection model creation computer may receive the normal monitoring node values (and generate normal feature vectors) and automatically calculate and output an abnormality detection model including information about a decision boundary created via supervised learning based on the normal feature vectors and the generated abnormal data.


