发表机构
Daw Alfada Company; University of Misan(达夫阿尔法达公司; 米桑大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过物理信息数字孪生与梯度提升分类器,在油田模拟中联合归因传感器偏差原因,实现高F1分数和低成本决策,但攻击归因准确率有限。
AI 中文摘要
当油田数字孪生与其仪器读数不一致时,操作员必须判断原因是硬件退化、恶劣天气影响还是恶意数据操纵。现有的数字孪生研究似乎将这些原因分开处理:传感器验证架构针对故障,而攻击聚焦的数字孪生已在供水部门测试台上进行评估。我们在一个模拟的四井井场(包含15个耦合仪器、合法操作瞬态和天气)上研究联合原因归因。一个仅从正常数据识别的物理信息孪生模型产生解析冗余残差;窗口化特征输入梯度提升分类器,其后验驱动具有固定误报率和基于成本的决策规则的报警门,该规则可能将决策推迟给分析师。在三个独立生成的场地上,分类器在注入偏差可观测的窗口上达到宏F1为0.818(在主场地包括潜伏发作后窗口时为0.723)。物理孪生几乎完全解释了这一性能:移除数据驱动孪生使宏F1变化小于0.01,而移除所有孪生则将其降至约0.58。攻击被快速检测(中位时间1.7小时),但在报警时正确归因仅42%的时间,六小时后升至73%。一项成本感知策略(推迟模糊案例)在测试的所有144种成本和先验设置中,每种设置下预期成本最低,有时仅以微小优势胜出;该结果依赖于说明性成本和分析师解决推迟案例。一个具有孪生意识的攻击者在45%的情节中被检测到,但几乎从未归因于攻击。这些结果以模拟器的生成假设为条件,尚未在现场数据上验证。
英文摘要
When an oilfield digital twin disagrees with its instruments, the operator must decide whether the cause is hardware degradation, harsh-weather effects, or malicious data manipulation. Existing digital-twin work appears to treat these causes separately: sensor-validation architectures target faults, and attack-focused twins have been evaluated on water-sector testbeds. We study joint cause attribution on a simulated four-well wellpad with 15 coupled instruments, legitimate operating transients, and weather. A physics-informed twin, identified from normal data only, produces analytical-redundancy residuals; windowed features feed a gradient-boosted classifier whose posterior drives an alarm gate with a fixed false-alarm rate and a cost-based decision rule that may defer to an analyst. On three independently generated sites, the classifier reaches macro-F1 of 0.818 on windows where the injected deviation is observable (0.723 when latent post-onset windows are included at the primary site). The physics twin accounts for essentially all of this: removing the data-driven twin changes macro-F1 by less than 0.01, whereas removing all twins drops it to about 0.58. Attacks are detected quickly (median 1.7 h) but attributed correctly at alarm time only 42% of the time, rising to 73% six hours later. A cost-aware policy that defers ambiguous cases had the lowest expected cost among all policies in every one of 144 cost and prior settings tested, sometimes by a small margin; the result depends on illustrative costs and on analysts resolving deferred cases. A twin-aware attacker was detected in 45% of episodes yet almost never attributed to attack. These results are conditional on the simulator's generative assumptions and have not been validated on field data.
Comments15 pages, 8 figures, 8 tables. Simulation study; code: https://github.com/nawaralseelawi/oilfield-dt-attribution