arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

先检测,后解释:面向ICS的免训练时间记忆数字孪生异常检测与事后大语言模型解释

Detect First, Explain Later: Training-Free Temporal-Memory Digital Twin Anomaly Detection with Post-Hoc LLM Interpretation for ICS

Konstantinos E. Kampourakis, Vasileios Gkioulos, Sokratis Katsikas

arXiv 2609.29704首次发表:更新:

发表机构

Norwegian University of Science and Technology (NTNU)(挪威科技大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出免训练的时间记忆数字孪生异常检测方法,结合DT约束与时间聚合,在HAI和BATADAL上有效减少误报,并用门控LLM提供事后解释。

AI 中文摘要

工业控制系统(ICS)日益面临网络物理攻击,这些攻击表现为过程行为中细微且随时间演变的偏差。检测此类异常需要对持续性、跨信号依赖关系以及过程级约束进行推理。数字孪生(DT)通过信号之间的物理和逻辑关系编码系统知识,但现有的基于DT的方法依赖于瞬时规则违反,缺乏随时间聚合微弱证据的机制。本文提出了一种免训练的异常检测方法,将确定性DT约束与显式时间记忆相结合。DT监控过程信号并根据约束违反情况产生异常分数,而轻量级记忆机制捕获跨时间的持续性和上下文关系。该方法在HAI和BATADAL数据集上进行了评估。消融实验结果表明,无记忆检测器完全失效,证明时间聚合对于基于DT的检测至关重要。在HAI上,具有记忆能力的DT实现了稳定检测,仅出现4次误报警事件;在BATADAL上,它在无需重新训练的情况下保持有效,在域偏移下出现21次误报警。相比之下,孤立森林(IF)产生明显更多的误报警(在HAI上为328次,在BATADAL上为127次),而自编码器(AE)表现出依赖数据集的行为,在BATADAL上实现高精确率,但召回率低且整体性能不一致。采用门控大语言模型(LLM)进行事后解释,提供结构化解释而不影响检测性能。我们的研究结果强调了时间记忆在基于约束的检测中的重要性,并支持在ICS监控中使用解耦推理来实现可解释性。

英文摘要

Industrial Control Systems (ICS) are increasingly exposed to cyber-physical attacks that manifest as subtle and temporally evolving deviations in process behavior. Detecting such anomalies requires reasoning over persistence, cross-signal dependencies, and process-level constraints. Digital Twins (DTs) encode system knowledge through physical and logical relationships between signals, but existing DT-based approaches rely on instantaneous rule violations and lack mechanisms to aggregate weak evidence over time. This paper proposes a training-free anomaly detection method that combines deterministic DT constraints with explicit temporal memory. The DT monitors process signals and produces anomaly scores based on constraint violations, while a lightweight memory mechanism captures persistence and contextual relationships across time. The approach is evaluated on the HAI and BATADAL datasets. Ablation results show that the memory-less detector fails completely, demonstrating that temporal aggregation is essential for DT-based detection. On HAI, the memory-aware DT achieves stable detection with only 4 false alarm events, and on BATADAL, it remains effective without retraining, with 21 false alarms under domain shift. In comparison, Isolation Forest (IF) produces substantially more false alarms (328 on HAI and 127 on BATADAL), while Autoencoder (AE) exhibits dataset-dependent behavior, achieving high precision on BATADAL but low recall and inconsistent performance overall. A gated LLM is used for post-hoc interpretation, providing structured explanations without affecting detection performance. Our findings highlight the importance of temporal memory in constraint-based detection and support the use of decoupled reasoning for interpretability in ICS monitoring.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑