通过因果图差异检测工控系统异常,提升对抗攻击的鲁棒性。
Causal Graph Profiling via Structural Divergence for Robust Anomaly Detection in Cyber-Physical Systems
- 基于动态贝叶斯网络学习正常与攻击状态的因果图结构。
- 利用图拓扑差异识别异常,在四组工业数据上F1与AUC显著优于基线。
- 适合关注工控安全、高不平衡时序数据异常检测的研究者。
随着针对水处理等关键基础设施的网络攻击日益复杂,亟需能应对系统漏洞和攻击模式演变的鲁棒异常检测策略。传统方法——统计、密度及图模型在多变量时间序列中面临分布偏移和类别不平衡问题,常导致误报率过高。为此,我们提出CGAD框架,一种基于因果图的异常检测方法,用于公共基础设施中的可靠网络攻击检测。CGAD采用两阶段监督框架:首先利用动态贝叶斯网络学习正常与攻击状态下系统的因果不变图结构;其次通过结构差异度量,基于因果图随时间的拓扑偏离实现异常检测。借助因果结构,该方法在非平稳与不平衡时序环境中表现出更强适应性与准确性,相比传统机器学习方法显著提升性能。通过对波动传感器数据中因果关系的挖掘,该框架不仅以更高精度检测攻击,更重新定义了异常检测的鲁棒性,在类别不平衡与分布漂移下仍保持稳定。在四个工业数据集上,其F1与ROC-AUC得分均显著超越最优基线,成功识别延迟及结构复杂的异常。
原文摘要 · Abstract (English)
With the growing complexity of cyberattacks targeting critical infrastructures such as water treatment networks, there is a pressing need for robust anomaly detection strategies that account for both system vulnerabilities and evolving attack patterns. Traditional methods -- statistical, density-based, and graph-based models struggle with distribution shifts and class imbalance in multivariate time series, often leading to high false positive rates. To address these challenges, we propose CGAD, a Causal Graph-based Anomaly Detection framework designed for reliable cyberattack detection in public infrastructure systems. CGAD follows a two-phase supervised framework -- causal profiling and anomaly scoring. First, it learns causal invariant graph structures representing the system's behavior under "Normal" and "Attack" states using Dynamic Bayesian Networks. Second, it employs structural divergence to detect anomalies via causal graph comparison by evaluating topological deviations in causal graphs over time. By leveraging causal structures, CGAD achieves superior adaptability and accuracy in non-stationary and imbalanced time series environments compared to conventional machine learning approaches. By uncovering causal structures beneath volatile sensor data, our framework not only detects cyberattacks with markedly higher precision but also redefines robustness in anomaly detection, proving resilience where traditional models falter under imbalance and drift. Our framework achieves substantial gains in F1 and ROC-AUC scores over best-performing baselines across four industrial datasets, demonstrating robust detection of delayed and structurally complex anomalies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。