CluSAD: Self-Supervised Learning-Based Anomaly Detection for Industrial Control Systems
Wuqiang Shen, Tao Dai, Zhaopeng Chen, Jiaxiao Meng · 2024
With the deep integration of the industrialization process and information technology, the Industrial Control System (ICS) gradually breaks the traditional closed system and is embedded in the highly interconnected modern cyberspace, and its security protection is facing unprecedented challenges. Intruders are waiting for the opportunity to launch attacks by utilizing the weak links of the system, which makes ensuring the operational security of ICS a key issue to be solved urgently. Anomaly detection technology, as an effective means of identifying potential threats in ICS networks, aims to realize real-time protection of ICS by revealing anomalous events that significantly deviate from normal behavior. However, the ICS anomaly detection task often encounters difficulties such as uneven data distribution and scarcity of labeled samples in practice, which seriously constrains the performance and applicability of existing methods. In this paper, we propose a novel self-supervised learning detection model, CluSAD (Clustered Self-Supervised Anomaly Detection for ICS) which aims to break through the dependence on large-scale labeled data and fully explore the intrinsic value of unlabeled ICS data. CluSAD integrates deep clustering and feature learning strategies to automatically capture and accurately distinguish the complex and variable anomaly patterns in ICS, and improve the detection system's ability to accurately recognize and adapt to the environment. Experiments show that the detection model is required to use a small amount of data to have good detection performance on ICS datasets.