针对动态演化的工控系统,提出可增量学习的异常检测方法
iADCPS: Time Series Anomaly Detection for Evolving Cyber-physical Systems via Incremental Meta-learning
- 用时间混叠增强数据泛化,结合单类元学习实现模型自适应
- 在三个公开数据集上分别达到99.0%、93.1%、78.7%的F1分数
- 无需异常标注,通过动态阈值自动调整检测灵敏度
工控系统(CPS)的时序异常检测对识别故障与潜在攻击至关重要,需分析传感器测量与执行器状态的时序数据。然而,现有方法难以应对系统演化带来的时空数据分布偏移。为此,本文提出基于增量元学习的iADCPS方法,仅需少量演化后的正常样本即可持续更新模型,弥合演化前后时序数据的分布差异。首先引入时间混叠策略进行数据级泛化,再结合单类元学习实现模型级泛化;进一步设计非参数动态阈值,根据异常得分的概率密度自适应调整阈值,无需任何异常标注。在PUMP、SWaT和WADI三个公开数据集上验证,iADCPS分别取得99.0%、93.1%、78.7%的F1分数,显著优于当前最先进方法,尤其在动态演化场景下表现优异。
原文摘要 · Abstract (English)
Anomaly detection for cyber-physical systems (ADCPS) is crucial in identifying faults and potential attacks by analyzing the time series of sensor measurements and actuator states. However, current methods lack adaptation to data distribution shifts in both temporal and spatial dimensions as cyber-physical systems evolve. To tackle this issue, we propose an incremental meta-learning-based approach, namely iADCPS, which can continuously update the model through limited evolving normal samples to reconcile the distribution gap between evolving and historical time series. Specifically, We first introduce a temporal mixup strategy to align data for data-level generalization which is then combined with the one-class meta-learning approach for model-level generalization. Furthermore, we develop a non-parametric dynamic threshold to adaptively adjust the threshold based on the probability density of the abnormal scores without any anomaly supervision. We empirically evaluate the effectiveness of the iADCPS using three publicly available datasets PUMP, SWaT, and WADI. The experimental results demonstrate that our method achieves 99.0%, 93.1%, and 78.7% F1-Score, respectively, which outperforms the state-of-the-art (SOTA) ADCPS method, especially in the context of the evolving CPSs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。