发表机构
Shenyang Jianzhu University; Guangzhou Institute of Industrial Intelligence; Shenyang Institute of Automation, Chinese Academy of Sciences; Shenyang University; Donghua University(沈阳建筑大学; 广州工业智能研究院; 中国科学院沈阳自动化研究所; 沈阳大学; 东华大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
HydroJEV提出用免训练模型Jev在一秒内对供水管网SCADA警报进行四类归因分流,匹配规则树性能、超越监督分类器,并比LLM快20-40倍,门控级联可减少约三分之一的LLM审查负载。
AI 中文摘要
当供水管网中触发SCADA警报时,操作员必须迅速判断警报反映的是网络攻击、物理故障、正常瞬态过程还是传感器故障。监督式分类器需要公用事业公司很少拥有的标记事件,而前沿大型语言模型(LLM)每次决策需耗时数十秒。我们测试了Jev——一种免训练、约一秒内返回类别概率的模型——能否作为此分流流程的第一层。在基于EPANET中C-Town网络构建的四类原因归因基准上,Jev与手写规则树、监督式分类器及七个云端LLM在四轮密封、预注册的相同证据上进行了比较。仅通过无标签先验校正,Jev在所有四轮中均匹配规则树的性能(分布内宏F1为0.62-0.64,对比规则树的0.56-0.61),并在其标签中缺失的事件子类型上超过监督式分类器0.36-0.42;当每类可用标记事件少于约四个时,Jev始终优于分类器。Jev的决策速度还比前沿LLM快20-40倍。仅接受由规则树确认的良性Jev判定,可使LLM审查员在全新密封集上减少35-38%的窗口处理量,且不损失宏F1。将这一门控级联流程原样迁移至另外两个管网后,在所有四组数据上均保持在审查员非劣效性边界之内。因此,一种快速、免训练的筛查方法可在SCADA异常分流中接管约三分之一的审查负载,同时保持审慎审查的准确性。
英文摘要
When a SCADA alarm is raised in a water distribution network, operators must decide quickly whether it reflects a cyberattack, a physical fault, a normal transient or a faulty sensor. Supervised classifiers need labelled incidents that utilities rarely have, and frontier large language models (LLMs) take tens of seconds per decision. We tested whether Jev, a training-free model that returns class probabilities in about one second, can serve as the first tier of this triage. On a four-class cause-attribution benchmark built on the C-Town network in EPANET, Jev was compared with a hand-written rule tree, a supervised classifier and seven cloud LLMs on identical evidence in four sealed, pre-registered rounds. With only a label-free prior correction, Jev matched the rule tree (macro-F1 0.62-0.64 against 0.56-0.61 in distribution) and exceeded the supervised classifier by 0.36-0.42 on event subtypes absent from its labels, in all four rounds, and it outperformed the classifier whenever fewer than about four labelled events per class were available. Jev also decided 20-40 times faster than frontier LLMs. Accepting only benign Jev verdicts confirmed by the rule tree spared an LLM reviewer 35-38% of windows on fresh sealed sets without loss of macro-F1. Transferred unchanged to two further networks, this gated cascade stayed within the non-inferiority margin of its reviewer on all four sets. A fast, training-free screen can therefore take over about a third of the review load in SCADA anomaly triage while preserving the accuracy of deliberate review.
Comments41 pages, 19 figures