conference-paper
DeepICS: Deep Causal Relationship Modeling for Multi-Source Log-Based Anomaly Detection in Industrial Control Systems
Research footprint
At a glance
- Citations
- 1
- References
- 7
- Comments
- 0
Paper overview
Abstract
Industrial Control Systems (ICS) are increasingly targeted by sophisticated cyber attacks, while traditional methods—relying on network analysis and signature-based detection—struggle to detect advanced persistent threats (APTs) and zero-day attacks. We present DeepICS, a novel anomaly detection approach leveraging multi-source log data and deep causal modeling. By integrating system, network, and provenance data, and using a Transformer-based framework, DeepICS captures complex temporal and causal relationships. It achieves a 92% true positive rate (TPR) with low false positives, outperforming traditional ML models and enhancing ICS security against evolving threats.
Record transparency
Publication details
- DOI
- 10.1109/dsn-s65789.2025.00069
- OpenAlex
- W4412130025
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.