用注意力图神经网络分析工业控制系统异常,实现可解释的实时检测。
Spatio-Temporal Attention Graph Neural Network: Explaining Causalities With Attention
- 构建时空注意力图网络,动态建模设备间依赖关系。
- 支持多模态数据融合,检测准确率提升且误报率可控。
- 适合需要可解释性与环境漂移适应性的工业安全场景。
工业控制系统(ICS)支撑关键基础设施,因工控与网络融合面临日益增长的网络物理威胁。尽管基于机器学习的异常检测在理论上表现良好,但实际部署常受限于可解释性差、误报率高及对系统行为演变(基准漂移)敏感等问题。本文提出一种时空注意力图神经网络(STA-GNN),用于无监督且可解释的ICS异常检测,同时建模系统的时序动态与关联结构。将传感器、控制器和网络实体表示为动态学习的图节点,捕捉物理过程与通信模式间的相互依赖。注意力机制揭示关键关系,支持对检测事件背后相关性及潜在因果路径的审查。该方法兼容多种数据模态,包括SCADA点测量值、网络流量特征与载荷特征,实现统一的网络物理分析。为满足实际运维需求,引入置信预测策略以控制误报率,并监测环境漂移下的性能退化。研究揭示了模型评估的潜力与局限性,强调可解释性与漂移感知评估对于学习型安全监控系统可靠部署的重要性。
原文摘要 · Abstract (English)
Industrial Control Systems (ICS) underpin critical infrastructure and face growing cyber-physical threats due to the convergence of operational technology and networked environments. While machine learning-based anomaly detection approaches in ICS shows strong theoretical performance, deployment is often limited by poor explainability, high false-positive rates, and sensitivity to evolving system behavior, i.e., baseline drifting. We propose a Spatio-Temporal Attention Graph Neural Network (STA-GNN) for unsupervised and explainable anomaly detection in ICS that models both temporal dynamics and relational structure of the system. Sensors, controllers, and network entities are represented as nodes in a dynamically learned graph, enabling the model to capture inter-dependencies across physical processes and communication patterns. Attention mechanisms provide influential relationships, supporting inspection of correlations and potential causal pathways behind detected events. The approach supports multiple data modalities, including SCADA point measurements, network flow features, and payload features, and thus enables unified cyber-physical analysis. To address operational requirements, we incorporate a conformal prediction strategy to control false alarm rates and monitor performance degradation under drifting of the environment. Our findings highlight the possibilities and limitations of model evaluation and common pitfalls in anomaly detection in ICS. Our findings emphasise the importance of explainable, drift-aware evaluation for reliable deployment of learning-based security monitoring systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。