Search papers, labs, and topics across Lattice.
This paper introduces a topology-driven approach for detecting cyberattacks in water distribution networks using a Graph Processing for Machine Learning (GPML) framework. By transforming raw traffic data into dynamic graphs and analyzing community and spectral metrics, the authors identify structural changes indicative of cyber threats. The approach demonstrates improved detection performance across three industrial datasets, highlighting the effectiveness of graph-based metrics in enhancing cybersecurity in critical infrastructure.
Transforming raw traffic into dynamic graphs reveals hidden vulnerabilities in water distribution networks, significantly enhancing cyberattack detection.
Water distribution networks depends on industrial control systems to integrate the physical process with communication network, making them vulnerable to cyberattacks that alter the traffic pattern and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often oversee structural changes that are induced by such attacks. In this work, we presents a topology-driven approach for detection of cyberattacks in water distribution networks based on Graph Processing for Machine Learning (GPML) framework. The raw traffic is transformed into dynamic graphs, from which community and spectral metrics are extracted and analyzed for any structural and communication modifications with time. The proposed methodology is evaluated on three industrial water distribution datasets such as HITL, SWaT, and CrossTest. Spectral and community graph metrics improve the model performance in detection of cyber and pyhiscal attacks across the three datasets.