Search papers, labs, and topics across Lattice.
This paper addresses the challenge of anomaly detection in cyber-physical systems (CPS) by modeling normal behavior through a jointly learned latent representation and explicit Gaussian-mixture mode clustering, rather than relying on traditional point-adjusted evaluations. The authors introduce the Massive, Implicit, Imbalanced Multimodality (MIIM) framework, which captures the complex structure of normal behavior across various operating regimes. Their approach outperforms existing deep learning detectors on three real CPS datasets, achieving notable AUROC scores, particularly in multimodal contexts, thereby demonstrating the effectiveness of their methodology in accurately identifying anomalies in challenging scenarios.
Anomaly detection in cyber-physical systems can be dramatically improved by modeling normal behavior as a complex, multimodal distribution rather than a simplistic blob.
Faults on a cyber-physical system (CPS) are too rare and unrepresentative to characterise, or even to select a model on, so detection must instead model normal behaviour; the standard point-adjusted evaluation, however, rewards detectors that never do. CPS normal behaviour is the union of many imbalanced, curved, thin-fringed operating regimes rather than a single blob; we state this structure as ten assumptions (A1-A10), abbreviated Massive, Implicit, Imbalanced Multimodality (MIIM). We model the normal law with a jointly learned latent representation plus explicit Gaussian-mixture mode clustering, scored in the latent rather than by a global density or a reconstruction residual, and evaluate under a deliberately fair protocol: raw point-wise metrics with no point adjustment, a trivial-detector difficulty split, prevalence-matched F1, and train-normal-only calibration. On three real CPS datasets (WADI, HAI, SKAB), the detector wins both the combined column and the difficult correlation/dynamics-fault column on all three, reaching difficult-subset AUROC 0.831 on HAI, 0.726 on WADI, and 0.610 on SKAB. The margin is largest on the two multimodal datasets the MIIM assumptions target and slimmest on the near-unimodal one, tracking multimodality as the thesis predicts, and it holds against three deep detectors (USAD, TranAD, GDN) re-computed with the same raw metrics, all of which collapse on the difficult subset. The methodological contributions are the MIIM assumption set, the difficulty-stratified fair protocol, and a latent-only score that drops reconstruction because a flexible decoder rebuilds the hard faults faithfully.