<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>industrial control systems &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/industrial-control-systems/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Tue, 22 Sep 2026 14:13:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>industrial control systems &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>AI Spots Power Plant Faults Before Disaster Strikes Using Graph Neural Networks</title>
		<link>https://scienmag.com/ai-spots-power-plant-faults-before-disaster-strikes-using-graph-neural-networks/</link>
		
		<dc:creator><![CDATA[Cassandra Pierce]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 14:13:40 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[bidirectional GRU]]></category>
		<category><![CDATA[Class imbalance in industrial datasets]]></category>
		<category><![CDATA[cyber-physical system security]]></category>
		<category><![CDATA[cyber-physical systems]]></category>
		<category><![CDATA[Cyberattack detection in power plants]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data mining for power plant safety]]></category>
		<category><![CDATA[deep learning]]></category>
		<category><![CDATA[Deep learning models for anomaly detection]]></category>
		<category><![CDATA[Fault detection in critical infrastructure]]></category>
		<category><![CDATA[fault diagnosis]]></category>
		<category><![CDATA[GE-BiGRU for fault prediction]]></category>
		<category><![CDATA[graph attention network]]></category>
		<category><![CDATA[Graph Neural Networks]]></category>
		<category><![CDATA[Graph neural networks for industrial systems]]></category>
		<category><![CDATA[HAI dataset]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[Interpretable AI for industrial monitoring]]></category>
		<category><![CDATA[Machine learning for cyber-physical security]]></category>
		<category><![CDATA[multivariate time series]]></category>
		<category><![CDATA[power generation]]></category>
		<category><![CDATA[Power plant fault detection]]></category>
		<category><![CDATA[Real-time fault identification in power generation]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=205723</guid>

					<description><![CDATA[Researchers have developed a graph-enhanced bidirectional GRU model that detected 44 of 45 simulated anomalies in a realistic power generation testbed while revealing which sensor relationships drive fault propagation.]]></description>
										<content:encoded><![CDATA[<p>Power plants and industrial control systems are among the most critical infrastructures in modern society, and they are increasingly under threat from both mechanical failure and sophisticated cyberattacks. A team of researchers from Kwangwoon University, LG Electronics, and the University of Queensland has now unveiled a new deep learning framework that catches simulated attacks and anomalies with remarkable precision, identifying 44 out of 45 abnormal events in a realistic power generation testbed. The study, published in the journal Data Mining and Knowledge Discovery, introduces a model called GE-BiGRU that fuses graph neural networks with a bidirectional gated recurrent unit, offering an efficient and interpretable route to protecting the cyber-physical systems that keep electricity flowing.</p>
<p>The challenge the researchers set out to solve is deceptively simple to describe but notoriously difficult in practice. Industrial systems spend nearly all of their time operating normally, with genuine faults appearing only in fleeting moments. As the authors illustrate, a factory that malfunctions for just five seconds in a day produces a dataset in which normal data overwhelmingly dominates, creating severe class imbalance that cripples conventional binary classification approaches. Signals in these environments also tend to be erratic rather than seasonal, making them hard for machine learning models to segment and learn. Rather than trying to classify each moment as normal or abnormal, the team adopted a prediction-based strategy: train the model exclusively on normal data to forecast future sensor values, then flag anomalies whenever reality diverges sharply from prediction.</p>
<p>Architecturally, the framework stacks three complementary components. At its core sits a three-layer bidirectional gated recurrent unit, or Bi-GRU, which processes sequences of sensor readings in both forward and backward directions. The GRU itself is a streamlined variant of the recurrent neural network that tamed the vanishing gradient problem through reset and update gates, requiring fewer parameters than the better-known LSTM and therefore training faster and generalizing more easily. By making the network bidirectional, the researchers allowed it to interpret the full context at every point in a sequence, capturing complex temporal dependencies and converging more quickly during training thanks to gradients flowing from both directions. A residual skip connection further eased gradient flow through the deep stack.</p>
<p>Temporal modeling alone, however, ignores a crucial truth about industrial plants: sensors do not operate in isolation. Boilers, turbines, valves, pumps, and tanks interact through physical process flows, and an anomaly at one component often propagates to its neighbors. To capture this spatial dimension, the team wired a graph neural network into the predictive model. The graph&#8217;s adjacency matrix was not learned from statistical correlations, which the authors caution can introduce spurious edges when anomalies are rare, but instead derived directly from the piping and instrumentation diagrams of the testbed. Each entry in the matrix encodes whether a direct process-flow path exists between two sensors or actuators, embedding physically grounded causal pathways into the model&#8217;s structure from the outset.</p>
<p>On top of this structural backbone, the researchers layered a graph attention network, or GAT, a relatively recent architecture that has proven exceptionally powerful for graph-structured data. Unlike graph convolution, which applies uniform weights to all neighboring nodes, the attention mechanism learns normalized coefficients that quantify the relative influence of each connected sensor. Through multi-head attention, the model can simultaneously attend to multiple aspects of each node&#8217;s neighborhood, stabilizing learning and enriching feature extraction. The attention weights multiply the input data before it reaches the bidirectional GRU, ensuring that the temporal model processes information in alignment with the underlying system topology. Crucially, these weights are also interpretable, allowing operators to see exactly which sensor relationships drive detection decisions.</p>
<p>The experimental platform was anything but a toy. The team evaluated the framework on the HAI 21.03 dataset, recorded at one sample per second from 79 sensors and actuators spanning a hardware-in-the-loop industrial control system testbed that replicates steam turbine generation and pumped-storage hydroelectric power. The testbed comprises four integrated processes: a boiler process handling heat transfer through water, a turbine process simulating rotating machinery, a water treatment process moving water between reservoirs, and a hardware-in-the-loop simulation layer synchronizing the whole, built on real industrial controllers from Emerson, GE, and Siemens. The test set contained 50 simulated attack scenarios, of which five were reserved for validation and 45 for final evaluation, with anomalies making up just 2.23 percent of the data.</p>
<p>The results demonstrated clear benefits from each design decision. Among unidirectional models, the plain LSTM baseline fared worst, while GRU-based models with graph neural network modules led the field with an F1 score of 0.912. Switching to bidirectional architectures pushed performance further: Bi-LSTM+GNN and Bi-GRU+GNN achieved F1 scores of 0.879 and 0.924 respectively, with the GE-BiGRU configuration emerging as the best overall performer. The gains were especially pronounced in sensitivity and time-series-aware precision, metrics that directly reflect missed-detection risk and operator alarm burden in continuous monitoring. Notably, the bidirectional extension added negligible computational cost, with even the most expensive variant requiring less than half a millisecond per sample, comfortably within the one-second budget imposed by the testbed&#8217;s sampling rate.</p>
<p>Perhaps the most striking finding concerns interpretability. The attention weights learned by the GAT revealed three exceptionally strong sensor connections, and each corresponded precisely to documented actuator-sensor pairs in the plant&#8217;s feedback control loops: a flow control valve linked to return-tank water levels, a level control valve linked to tank level measurements, and an auto speed demand linked to turbine RPM. These same channel pairs coincided with the primary targets of the testbed&#8217;s attack scenarios and exhibited markedly elevated prediction errors during attack intervals. In practical terms, this means operators can trace fault-propagation paths through the plant, identifying, for example, that a valve malfunction is likely when an anomaly coincides with abrupt changes in the relationship between a flow control valve and downstream water levels. Such insights can inform troubleshooting and preventive maintenance strategies.</p>
<p>The authors are candid about limitations. The adjacency matrix is constructed statically from simulator configuration documents and remains fixed during training, so topology changes such as adding or removing sensors would require full retraining, an expensive prospect in continuously operating plants. The evaluation also relies on simulator-based data, which, despite incorporating genuine industrial controllers, cannot fully reproduce sensor degradation, environmental variability, or adaptive adversarial attacks seen in the field. The team notes that sensitivity values remained below 0.75 across most models, reflecting a threshold selection procedure that balances precision and recall rather than minimizing missed detections; in safety-critical deployments where a missed fault costs far more than a false alarm, operators might weight recall more heavily. Future work will pursue dynamic graph construction, broader benchmark evaluation, and latency optimization for resource-constrained edge devices.</p>
<p>Even with these caveats, the study marks a meaningful advance in the race to secure critical infrastructure. By learning what normal looks like, exploiting the physical topology of the plant, and explaining its own reasoning through attention weights, the GE-BiGRU framework offers a blueprint for anomaly detection systems that are simultaneously accurate, efficient, and transparent. As power grids, water treatment facilities, and transportation networks grow ever more interconnected through the Internet of Things, tools that can spot a five-second anomaly buried in a sea of normal data, and tell engineers exactly where to look, may prove indispensable to keeping the lights on.</p>
<p><strong>Subject of Research:</strong> A graph neural network and bidirectional GRU framework for detecting anomalies in multivariate time-series data from power generation cyber-physical systems.</p>
<p><strong>Article Title:</strong> Graph-enhanced bidirectional GRU for anomaly detection in power generation environments</p>
<p><strong>Article References:</strong> Kwon, D., Kang, Y., Lee, J., Nam, Y., Won, J., Kim, K. K., Kim, D. D., &amp; Park, C. (2026). Graph-enhanced bidirectional GRU for anomaly detection in power generation environments. <em>Data Mining and Knowledge Discovery, 40</em>(6), Article 102. <a href="https://doi.org/10.1007/s10618-026-01262-3" rel="noopener noreferrer">https://doi.org/10.1007/s10618-026-01262-3</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10618-026-01262-3" rel="noopener noreferrer">10.1007/s10618-026-01262-3</a></p>
<p><strong>Keywords:</strong> anomaly detection, graph neural networks, graph attention network, bidirectional GRU, cyber-physical systems, power generation, industrial control systems, multivariate time series, cybersecurity, deep learning, fault diagnosis, HAI dataset</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">205723</post-id>	</item>
		<item>
		<title>Information Theory Meets Machine Learning to Catch Industrial Cyberattacks</title>
		<link>https://scienmag.com/information-theory-meets-machine-learning-to-catch-industrial-cyberattacks/</link>
		
		<dc:creator><![CDATA[Teresa Odom]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 22:23:38 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anomaly detection in industrial environments]]></category>
		<category><![CDATA[anomaly detection in power grids]]></category>
		<category><![CDATA[Applied Intelligence]]></category>
		<category><![CDATA[applying information theory to anomaly detection]]></category>
		<category><![CDATA[chemical plant cybersecurity]]></category>
		<category><![CDATA[cyberattack prevention in manufacturing]]></category>
		<category><![CDATA[data-driven cybersecurity methods]]></category>
		<category><![CDATA[early detection of industrial cyber threats]]></category>
		<category><![CDATA[Gaussian kernel]]></category>
		<category><![CDATA[high-dimensional data]]></category>
		<category><![CDATA[Industrial control system cybersecurity]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[industrial cybersecurity]]></category>
		<category><![CDATA[information content]]></category>
		<category><![CDATA[information entropy]]></category>
		<category><![CDATA[information theory applications in machine learning]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[machine learning for cyberattack detection]]></category>
		<category><![CDATA[machine learning techniques for industrial safety]]></category>
		<category><![CDATA[one-class support vector machine]]></category>
		<category><![CDATA[One-Class Support Vector Machine limitations]]></category>
		<category><![CDATA[SWaT dataset]]></category>
		<category><![CDATA[WADI dataset]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=199204</guid>

					<description><![CDATA[Researchers in Xi'an have developed an information-theory-based anomaly detection method that outperforms state-of-the-art algorithms on critical industrial control system benchmarks.]]></description>
										<content:encoded><![CDATA[<p>Industrial control systems quietly run the modern world. They purify drinking water, route electricity through power grids, manage chemical plants, and keep assembly lines moving. When something goes wrong in these systems—whether through mechanical failure or a deliberate cyberattack—the consequences can cascade from a single factory floor to entire cities. Detecting anomalies in these environments before they escalate is therefore one of the most consequential challenges in modern cybersecurity. A new study published in Applied Intelligence by researchers at Xi&#8217;an University of Posts and Telecommunications introduces a method that could significantly sharpen that detection capability, and it does so by borrowing one of the oldest and most elegant ideas in science: information theory.</p>
<p>The research, led by Zhongmin Wang, Zhongjian Yuan, Cong Gao, and Yanping Chen, addresses a long-standing weakness in a classical machine learning technique known as the One-Class Support Vector Machine, or OCSVM. The OCSVM has been a workhorse of anomaly detection since its introduction in the early 2000s. Its appeal lies in its ability to learn from a single class of data—normally, it needs to see only examples of healthy behavior to build a model of what &#8216;normal&#8217; looks like. Anything that falls outside that learned boundary is flagged as an anomaly. This is crucial in industrial settings, where attack examples are rare, dangerous to stage, and endlessly varied, making conventional supervised learning impractical.</p>
<p>Yet the OCSVM carries two stubborn Achilles&#8217; heels. First, its performance depends heavily on the choice of kernel function and, in particular, on the parameters of the Gaussian kernel that defines how similarity between data points is measured. Getting these parameters right often requires laborious trial and error or expensive cross-validation, and a poor choice can gut the model&#8217;s accuracy. Second, industrial sensor data is increasingly high-dimensional, with hundreds or thousands of measurements streaming from pumps, valves, and controllers. As dimensionality rises, data points spread farther apart, distributions become sparse, and the notion of distance itself loses meaning—a phenomenon statisticians call the curse of dimensionality. The Gaussian kernel, which relies on Euclidean distances, struggles to capture the true distribution of normal samples in this sparse high-dimensional space, and detection performance degrades.</p>
<p>The Xi&#8217;an team&#8217;s answer, which they call Information Clustering One-Class Support Vector Machine (IC-OCSVM), tackles both problems in a single framework built on information-theoretic foundations. The method begins with a preprocessing stage that treats each feature dimension of the industrial data as if it were a separate information system. For every dimension, the researchers compute the Shannon information entropy—a measure of the uncertainty or unpredictability carried by that variable. Dimensions with low information content contribute little to distinguishing between samples and are treated as redundant and removed. This entropy-based pruning reduces dimensionality in a principled way, concentrating the model&#8217;s attention on the sensors and signals that actually carry meaningful variability, and simultaneously softening the effects of sparsity before the learning stage even begins.</p>
<p>The second and more novel stage replaces the conventional Gaussian kernel entirely. Instead of measuring similarity through Euclidean distance, IC-OCSVM introduces the concept of information content to characterize the differences between samples. Information content, a concept descending from Claude Shannon&#8217;s mathematical theory of communication, quantifies how surprising or informative one sample is relative to another. The researchers design an explicit mapping function based on this information-content measure, which serves the same mathematical role as the implicit feature mapping performed by a kernel trick—but with a crucial advantage. Because the mapping is explicit and constructed directly from information theory, the method no longer depends on the delicate selection of Gaussian kernel parameters. The model essentially builds its own geometry from the information structure of the data rather than relying on a pre-chosen distance metric.</p>
<p>This design choice has a second benefit that matters greatly for industrial deployments. By measuring the distance between samples through information content rather than raw coordinate differences, the constructed OCSVM is far less susceptible to the sparsity problem that plagues high-dimensional data. Samples that would appear arbitrarily far apart in a high-dimensional Euclidean space may share substantial information structure, allowing the model to recognize the common signature of normal behavior even when the raw feature space is vast and thinly populated. In effect, the method asks a more meaningful question of the data: not &#8216;how far apart are these points?&#8217; but &#8216;how much do these observations tell us about each other?&#8217;</p>
<p>To test the approach, the team turned to two of the most demanding and widely respected benchmark datasets in industrial control system security: SWaT and WADI. SWaT, the Secure Water Treatment testbed developed at the Singapore University of Technology and Design, simulates a full-scale water purification process complete with realistic cyberattack scenarios, while WADI extends the same experimental philosophy to water distribution networks. Both datasets feature multivariate time series from dozens of sensors and actuators, injected attacks of varying sophistication, and the noisy, correlated measurements that make real industrial anomaly detection so difficult. The researchers compared IC-OCSVM against a roster of state-of-the-art anomaly detection algorithms, including deep-learning approaches built on autoencoders, generative adversarial networks, and graph neural networks.</p>
<p>The results were striking. IC-OCSVM achieved an F1-score of 85.91 percent on SWaT and 68.28 percent on WADI, outperforming the best competing baseline by 3.2 and 3.3 percentage points respectively. In a field where incremental gains of a fraction of a percentage point frequently justify publication, improvements of this size—particularly on the notoriously difficult WADI dataset—are significant. The F1-score, which balances precision and recall into a single number, is especially meaningful in industrial security, where a detector that cries wolf too often wastes operator attention and one that stays silent too long allows attacks to proceed. IC-OCSVM&#8217;s edge on both fronts suggests that the information-theoretic framing genuinely captures structure that Gaussian-kernel and deep-learning baselines miss.</p>
<p>The implications extend well beyond water treatment. Any setting where anomalies must be learned from normal data alone—power grid monitoring, manufacturing quality control, aircraft engine health tracking, building automation—faces the same twin burdens of kernel tuning and high-dimensional sparsity. A method that sidesteps kernel parameter selection removes a costly and error-prone step from the deployment pipeline, while entropy-based dimension reduction offers a computationally light alternative to heavyweight deep architectures. Notably, IC-OCSVM achieves its results without the massive training datasets and GPU resources that deep learning methods typically demand, which could make sophisticated anomaly detection accessible to smaller operators and resource-constrained facilities that cannot maintain large labeled datasets or dedicated machine learning infrastructure.</p>
<p>The work also represents a broader and somewhat counterintuitive trend in machine learning research: the return of classical theory to solve problems that modern deep learning has struggled with. Shannon&#8217;s information theory, formulated in the 1940s, provides tools that are interpretable, mathematically grounded, and robust in ways that black-box neural networks often are not. By fusing information-theoretic feature analysis with the boundary-learning power of support vector machines, the Xi&#8217;an researchers have demonstrated that careful mathematical design can still beat brute-force complexity in the right domain. As industrial systems become ever more connected and the attack surface for critical infrastructure continues to expand, tools like IC-OCSVM point toward a future in which the sentinels guarding our water, power, and factories are built not just on more data, but on a deeper understanding of what information itself reveals.</p>
<p><strong>Subject of Research:</strong> A hybrid information clustering and one-class support vector machine method for anomaly detection in industrial control systems</p>
<p><strong>Article Title:</strong> A hybrid method integrating information clustering and one-class support vector machine for industrial anomaly detection</p>
<p><strong>Article References:</strong> Wang, Z., Yuan, Z., Gao, C., &amp; Chen, Y. (2026). A hybrid method integrating information clustering and one-class support vector machine for industrial anomaly detection. <em>Applied Intelligence, 56</em>(14), Article 418. <a href="https://doi.org/10.1007/s10489-026-07447-z" rel="noopener noreferrer">https://doi.org/10.1007/s10489-026-07447-z</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10489-026-07447-z" rel="noopener noreferrer">10.1007/s10489-026-07447-z</a></p>
<p><strong>Keywords:</strong> anomaly detection, industrial control systems, one-class support vector machine, information entropy, information content, SWaT dataset, WADI dataset, industrial cybersecurity, machine learning, high-dimensional data, Gaussian kernel, Applied Intelligence</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">199204</post-id>	</item>
	</channel>
</rss>
