AI 中文总结
本研究提出基于GPML框架的拓扑驱动方法,将供水管网原始流量转换为动态图,提取社区和谱指标,在HITL、SWaT、CrossTest数据集上验证可提升网络与物理攻击检测性能。
AI 中文摘要
供水管网依赖工业控制系统将物理过程与通信网络集成,使其易受改变流量模式和网络行为的网络攻击。传统依赖原始流量或协议信息的检测方法常忽略此类攻击引发的结构变化。本研究提出一种基于Graph Processing for Machine Learning(GPML)框架的拓扑驱动方法,用于检测供水管网中的网络攻击。原始流量被转换为动态图,从中提取社区和谱指标,并分析随时间发生的任何结构和通信变化。所提方法在HITL、SWaT和CrossTest三个工业供水管网数据集上进行评估,谱和社区图指标提升了模型在三个数据集中检测网络攻击与物理攻击的性能。
英文摘要
Water distribution networks depends on industrial control systems to integrate the physical process with communication network, making them vulnerable to cyberattacks that alter the traffic pattern and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often oversee structural changes that are induced by such attacks. In this work, we presents a topology-driven approach for detection of cyberattacks in water distribution networks based on Graph Processing for Machine Learning (GPML) framework. The raw traffic is transformed into dynamic graphs, from which community and spectral metrics are extracted and analyzed for any structural and communication modifications with time. The proposed methodology is evaluated on three industrial water distribution datasets such as HITL, SWaT, and CrossTest. Spectral and community graph metrics improve the model performance in detection of cyber and pyhiscal attacks across the three datasets.
Journal refIEEE/IFIP Network Operations and Management Symposium 2026 / MCT Management of Complex Threats, May 2026, Rome, France