arXiv:2512.14422cs.CRcs.LG2025-12被引 3

融合多种模型提升供水系统攻击检测准确率

Hybrid Ensemble Method for Detecting Cyber-Attacks in Water Distribution Systems Using the BATADAL Dataset

  • 用随机森林、梯度提升和LSTM三类模型组合,结合堆叠学习增强检测能力
  • 混合堆叠模型在攻击类上达F1=0.7205,AUC=0.9826,显著优于单一模型
  • 适合关注工业控制系统安全、时间序列异常检测的研究与工程人员

随着数字互联扩展,管理关键基础设施如供水系统的工业控制系统网络安全日益重要。BATADAL基准数据是测试入侵检测技术的良好资源,但存在类别不平衡、多变量时序依赖及隐蔽攻击等挑战。本文提出一种混合集成学习模型,利用机器学习与深度学习模型的互补优势,提升供水系统中的网络攻击检测能力。比较了随机森林、eXtreme Gradient Boosting(XGBoost)和长短期记忆网络(LSTM)三种基础模型,并构建了七种集成方式,包括简单平均与使用逻辑回归元学习器的堆叠学习。通过分析随机森林识别出关键预测因子,转化为时序与统计特征,并采用合成少数类过采样技术(SMOTE)缓解类别不平衡问题。结果表明,单个LSTM模型表现差(F1=0.000,AUC=0.4460),而树基模型尤其是XGBoost表现优异(F1=0.7470,AUC=0.9684)。最终,由随机森林、XGBoost和LSTM组成的混合堆叠集成模型表现最佳,攻击类F1得分为0.7205,AUC达0.9826,证明异质模型间的精度与泛化能力融合有效。该框架为具有时序依赖性的工业系统提供了一种鲁棒且可扩展的网络安全检测方案。

原文摘要 · Abstract (English)

The cybersecurity of Industrial Control Systems that manage critical infrastructure such as Water Distribution Systems has become increasingly important as digital connectivity expands. BATADAL benchmark data is a good source of testing intrusion detection techniques, but it presents several important problems, such as imbalance in the number of classes, multivariate time dependence, and stealthy attacks. We consider a hybrid ensemble learning model that will enhance the detection ability of cyber-attacks in WDS by using the complementary capabilities of machine learning and deep learning models. Three base learners, namely, Random Forest , eXtreme Gradient Boosting , and Long Short-Term Memory network, have been strictly compared and seven ensemble types using simple averaged and stacked learning with a logistic regression meta-learner. Random Forest analysis identified top predictors turned into temporal and statistical features, and Synthetic Minority Oversampling Technique (SMOTE) was used to overcome the class imbalance issue. The analyics indicates that the single Long Short-Term Memory network model is of poor performance (F1 = 0.000, AUC = 0.4460), but tree-based models, especially eXtreme Gradient Boosting, perform well (F1 = 0.7470, AUC=0.9684). The hybrid stacked ensemble of Random Forest , eXtreme Gradient Boosting , and Long Short-Term Memory network scored the highest, with the attack class of 0.7205 with an F1-score and a AUC of 0.9826 indicating that the heterogeneous stacking between model precision and generalization can work. The proposed framework establishes a robust and scalable solution for cyber-attack detection in time-dependent industrial systems, integrating temporal learning and ensemble diversity to support the secure operation of critical infrastructure.

攻击检测集成学习供水系统时序数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。