用多层AI架构在真实反应堆中实时区分网络攻击与运行异常。
Experimental Assessment of a Multi-Class AI/ML Architecture for Real-Time Characterization of Cyber Events in a Live Research Reactor
- 融合IT与OT数据流构建多层级AI模型
- 在13.8万条数据上实现正常/异常/攻击事件准确识别
- 适合关注核能网络安全的工程师与研究人员
核工业对人工智能与机器学习(AI/ML)的应用兴趣日益增长。有效应用可提升异常检测、故障预判与运行优化能力,但现有研究较少评估其在真实核反应堆中的可行性。本文提出一种多层AI/ML架构,整合信息科技(IT)与运营技术(OT)数据流,以识别、表征并区分(1)多种网络攻击事件,(2)网络攻击与其他运行异常。基于普渡大学研究堆PUR-1,通过一个包含多类并发虚假数据注入与复杂递增型拒绝服务攻击的典型场景进行验证。该场景涵盖14种系统状态(1种正常,13种异常),处理超过1380万条多变量操作与信息技术数据点。结果表明,即使在拒绝服务攻击等复杂条件下,该架构仍能有效区分正常、异常及网络攻击事件。结合IT与OT数据提升了分类精度,但在部分网络攻击期间面临数据同步与采集挑战。研究显示AI/ML在核网络安全中前景广阔,但需进一步优化复杂事件辨识与多类分类架构。
原文摘要 · Abstract (English)
There is increased interest in applying Artificial Intelligence and Machine Learning (AI/ML) within the nuclear industry and nuclear engineering community. Effective implementation of AI/ML could offer benefits to the nuclear domain, including enhanced identification of anomalies, anticipation of system failures, and operational schedule optimization. However, limited work has been done to investigate the feasibility and applicability of AI/ML tools in a functioning nuclear reactor. Here, we go beyond the development of a single model and introduce a multi-layered AI/ML architecture that integrates both information technology and operational technology data streams to identify, characterize, and differentiate (i) among diverse cybersecurity events and (ii) between cyber events and other operational anomalies. Leveraging Purdue Universitys research reactor, PUR-1, we demonstrate this architecture through a representative use case that includes multiple concurrent false data injections and denial-of-service attacks of increasing complexity under realistic reactor conditions. The use case includes 14 system states (1 normal, 13 abnormal) and over 13.8 million multi-variate operational and information technology data points. The study demonstrated the capability of AI/ML to distinguish between normal, abnormal, and cybersecurity-related events, even under challenging conditions such as denial-of-service attacks. Combining operational and information technology data improved classification accuracy but posed challenges related to synchronization and collection during certain cyber events. While results indicate significant promise for AI/ML in nuclear cybersecurity, the findings also highlight the need for further refinement in handling complex event differentiation and multi-class architectures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。