Anomaly Detection in Cyber-Physical Systems Using Long-Short Term Memory Autoencoders: A Case Study with Man-in-the-Middle (MiTM) Attack
Shining Sun, Khandaker Akramul Haque, Xiang Huo, Abhijeet Sahu, Ana Goulart, Katherine Davis · 2025
Large-scale power cyber-physical systems (CPSs) have many factors that contribute to uncertainties in their data. When intrusions occur, they will cause anomalies in the system's cyber-physical data. However, the traditional anomaly detection methods often rely on static thresholds or simple statistical models which are not accurate enough to identify the outlier, leading to a higher risk of false positives or missed detections. Recent advances in deep-learning based detection of stealth false data injection attacks offers a number of improvements, but the cohesive use of cyber-physical time domain data from real world systems to detect and validate the detection with a ground truth model from an emulation testbed and their incorporation in real world energy management systems remains in its infancy. Hence, this paper aims to model and capture temporal dependencies with emulation data, enabling unsupervised anomaly detection by reconstructing expected behavior and identifying deviations that suggest potential attacks as recent methods have fallen short in identifying subtle, long-term dependencies. This study proposes a Long Short-Term Memory (LSTM) autoencoder-based approach to detect Man-in-the-Middle (MiTM) attacks in power systems by leveraging multi-sensor temporal datasets [1]. Additionally, feature reduction and data normalization techniques are imple-mented to improve model performance. Simulations using a Texas 2000- bus grid case demonstrate the effectiveness of our approach in identifying and mitigating cyber threats, effectively enhancing intrusion detection capabilities.