ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:

~ similar to 2606.01691v1· 20 results

cs.CRRecentApr 27, 2026

System-aware contextual digital twin for ICS anomaly diagnosis

Eungyu Woo, Yooshin Kim, Wonje Heo, Donghoon Shin

The paper proposes a system-aware unsupervised framework that combines lightweight online detection with a contextual digital twin and LLM to provide interpretable, actionable anomaly diagnoses for In…

View →
cs.CRRecentApr 4, 2026

Systematic Integration of Digital Twins and Constrained LLMs for Interpretable Cyber-Physical Anomaly Detection

Konstantinos E. Kampourakis, Vasileios Gkioulos, Sokratis Katsikas

The paper proposes a Digital Twin (DT)-driven hybrid system that combines deterministic heuristics and constrained Large Language Model (LLM) reasoning to achieve highly accurate and interpretable rea…

View →
cs.CRRecentApr 23, 2026

On the Challenges of Holistic Intrusion Detection in ICS

Stefan Lenz, Julia Raab, Benedikt Holzbach, Deniz Köller +2 more

This paper discusses the significant challenges in developing a holistic intrusion detection system for Industrial Control Systems (ICS) that must cover all operational dimensions.

View →
cs.CRcs.LGRecentApr 14, 2026

Anomaly Detection in IEC-61850 GOOSE Networks: Evaluating Unsupervised and Temporal Learning for Real-Time Intrusion Detection

Joseph Moore

This paper evaluates unsupervised temporal learning models, specifically recurrent autoencoders, for real-time anomaly detection in vulnerable IEC-61850 GOOSE networks, demonstrating that the GRU mode…

View →
cs.CRcs.LGRecentMar 25, 2026

Toward a Multi-Layer ML-Based Security Framework for Industrial IoT

Aymen Bouferroum, Valeria Loscri, Abderrahim Benslimane

This paper proposes a lightweight, multi-layer Machine Learning-based security framework for Industrial IoT (IIoT) to enhance trust convergence and detect advanced threats.

View →
cs.CRRecentMar 26, 2026

An Approach to Generate Attack Graphs with a Case Study on Siemens PCS7 Blueprint for Water Treatment Plants

Lucas Miranda, Carlos Banjar, Daniel Menasche, Anton Kocheturov +2 more

The paper proposes a semi-automated framework that integrates network topology and vulnerability data to generate and analyze multi-step attack graphs in Industrial Control Systems, demonstrated using…

View →
cs.CRcs.LGRecentMar 19, 2026

Cyber-Resilient Digital Twins: Discriminating Attacks for Safe Critical Infrastructure Control

Mohammadhossein Homaei, Iman Khazrak, Rubén Molano, Andrés Caro +1 more

The paper introduces i-SDT, an intelligent Self-Defending Digital Twin, which enhances cyber-physical security by accurately discriminating various attack types and maintaining safe operation without…

View →
cs.LGcs.AIRecentMay 31, 2026

ChronosAD: Leveraging Time Series Foundation Models for Accurate Anomaly Detection

Uzair Khan, Luigi Capogrosso, Francesco Biondani, Michele Magno +3 more

ChronosAD introduces a novel architecture that uses time series foundation models and a custom Temporal Block to achieve robust and highly accurate anomaly detection across diverse domains.

View →
cs.CRRecentMar 24, 2026

How Far Should We Need to Go : Evaluate Provenance-based Intrusion Detection Systems in Industrial Scenarios

Yue Xiao, Ling Jiang, Sen Nie, Ding Li +3 more

This paper systematically evaluates Provenance-based Intrusion Detection Systems (PIDSes) in real industrial scenarios, revealing that existing systems struggle with data heterogeneity, advanced attac…

View →
cs.CRcs.AIcs.LGRecentMay 26, 2026

Backdoor Attacks on Fault Detection and Localization in Cyber-Physical Systems

Abile Jean, Kuniyilh S

This paper investigates the vulnerability of machine learning-based fault detection and localization systems in Cyber-Physical Systems (CPS) to backdoor attacks, demonstrating that such attacks are su…

View →
cs.CRRecentApr 28, 2026

Large Language Models as Explainable Cyberattack Detectors for Energy Industrial Control Systems

Weiyi Kong, Ahmad Mohammad Saber, Amr Youssef, Deepa Kundur

This paper demonstrates that an off-the-shelf Large Language Model (LLM) can function as a high-performing, explainable, human-in-the-loop layer for detecting cyberattacks in Industrial Control System…

View →
cs.LGcs.AIcs.CRRecentApr 14, 2026

Clustering-Enhanced Domain Adaptation for Cross-Domain Intrusion Detection in Industrial Control Systems

Luyao Wang

The paper proposes a clustering-enhanced domain adaptation method that significantly improves cross-domain intrusion detection in industrial control systems by aligning feature distributions and enhan…

View →
cs.CRcs.AIRecentMay 4, 2026

APIOT: Autonomous Vulnerability Management Across Bare-Metal Industrial OT Networks

Adel ElZemity, Budi Arief, Shujun Li, Calvin Brierley +5 more

The paper introduces APIOT, the first LLM framework capable of autonomously performing the full discovery, exploitation, patching, and verification cycle against bare-metal industrial OT devices.

View →
cs.CRcs.AIcs.MARecentApr 27, 2026

GAMMAF: A Common Framework for Graph-Based Anomaly Monitoring Benchmarking in LLM Multi-Agent Systems

Pablo Mateo-Torrejón, Alfonso Sánchez-Macián

The paper introduces Gammaf, an open-source benchmarking framework designed to standardize the evaluation of graph-based anomaly detection methods for securing Large Language Model Multi-Agent Systems…

View →
cs.CRRecentApr 7, 2026

Towards Securing IIoT: An Innovative Privacy-Preserving Anomaly Detector Based on Federated Learning

Samira Kamali Poorazad, Chafika Benzaïd, Tarik Taleb

The paper proposes a novel Federated Learning framework combined with Homomorphic Encryption and a dynamic agent selection scheme to enhance privacy and efficiency for anomaly detection in the Industr…

View →
cs.CReess.SYRecentApr 14, 2026

Threat Modeling and Attack Surface Analysis of IoT-Enabled Controlled Environment Agriculture Systems

Andrii Vakhnovskyi

This paper provides the first comprehensive threat model for IoT-enabled Controlled Environment Agriculture (CEA) systems, identifying 123 unique threats and proposing a defense-in-depth framework to…

View →
cs.CRcs.LGRecentMar 24, 2026

CSTS: A Canonical Security Telemetry Substrate for AI-Native Cyber Detection

Abdul Rahman

The paper introduces the Canonical Security Telemetry Substrate (CSTS), a standardized, AI-ready foundation designed to harmonize fragmented and heterogeneous cybersecurity data into a unified model f…

View →
cs.CRcs.AIRecentJun 2, 2026

FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems

Maxime Schwarzer, Laurin Holz, Tobias Huerten, Johannes Loevenich +3 more

FlowGuard introduces an identity-independent defense using flow matching to detect data-free model stealing attacks by identifying synthetic queries as out-of-distribution based on their lower-dimensi…

View →
cs.CRRecentApr 16, 2026

Beyond Nodes vs. Edges: A Multi-View Fusion Framework for Provenance-Based Intrusion Detection

Fan Yang, Binyan Xu, Di Tang, Kehuan Zhang

The paper proposes PROVFUSION, a multi-view fusion framework that integrates anomaly signals from attribute, structure, and causality views to overcome the limitations of single node- or edge-centric…

View →
cs.CRRecentMar 24, 2026

An Experimental Study of Machine Learning-Based Intrusion Detection for OPC UA over Industrial Private 5G Networks

Song Son Ha, Kunal Singh, Florian Foerster, Henry Beuster +3 more

This paper experimentally demonstrates the high detection performance of machine learning-based intrusion detection systems for identifying cyberattacks targeting OPC UA applications running over priv…

View →