Supervised Anomaly Detection via Synthesized Abnormal Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems lack effective methods to automatically detect cyber-attacks at the domain layer, where sensors, controllers, and actuators are located, and existing protection schemes fail to accurately differentiate between faults and malicious attacks, especially when multiple monitoring nodes are involved.

Innovation Solution

The implementation of supervised anomaly detection methods augmented by synthesized abnormal data generation using generative models, which learn the characteristics of normal data to generate complementary abnormal data, enabling the creation of decision boundaries for accurate detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If supervised anomaly detection methods are used with limited abnormal data, then detection accuracy deteriorates, but using synthesized abnormal data increases device complexity

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by synthesizing abnormal data in advance using generative models before actual anomaly detection is needed. This pre-computed synthesized abnormal data is then used during supervised anomaly detection to improve accuracy without increasing real-time computational complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of abnormal operation patterns through generative models that learn from normal data characteristics. These synthesized copies serve as training data for supervised anomaly detection, enabling accurate detection without requiring actual abnormal data samples

Inventive Principle:
Principle #26Copying

2Reliability

If multiple monitoring nodes are analyzed to improve detection reliability, then the quantity of data increases, but differentiation between faults and attacks becomes more difficult

Engineering Contradiction:
Improvedetection reliabilityVSAvoidfault differentiation difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments the analysis by creating separate synthesized abnormal data sets for different attack types and fault conditions. Each monitoring node's data is processed independently through the generative model, allowing differentiated detection patterns to be learned and applied to distinguish between various abnormal conditions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring the synthesized abnormal data generation to specific monitoring nodes and their individual characteristics. Each node receives customized synthesized data that reflects its local operational patterns, enabling more accurate local differentiation between faults and attacks

Inventive Principle:
Principle #3Local quality

3Reliability

If passive monitoring is used to reduce system complexity, then detection capability against sophisticated attacks deteriorates, but active synthesized data generation increases computational requirements

Engineering Contradiction:
Improveattack detection capabilityVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs computationally intensive data synthesis in advance during off-line periods when energy consumption is less critical. The generative model learns from normal data and synthesizes abnormal patterns beforehand, so that during actual monitoring, the system only needs to compare against pre-computed synthesized data, reducing real-time computational energy requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11252169B2Intelligent data augmentation for supervised anomaly detection associated with a cyber-physical system
Publication Date: 2022.02.15 GE INFRASTRUCTURE TECH LLC
  • US11252169B2 patent drawing
  • US11252169B2 patent drawing
  • US11252169B2 patent drawing

AI summary

A Cyber-Physical System (“CPS”) may have monitoring nodes that generate a series of current monitoring node values representing current operation of the CPS. A normal space data source may store, for each monitoring node, a series of normal monitoring node values representing normal operation of the CPS. An abnormal data generation platform may utilize information in the normal space data source and a generative model to create generated abnormal to represent abnormal operation of the CPS. An abnormality detection model creation computer may receive the normal monitoring node values (and generate normal feature vectors) and automatically calculate and output an abnormality detection model including information about a decision boundary created via supervised learning based on the normal feature vectors and the generated abnormal data.