DeepICS: Deep Causal Relationship Modeling for Multi-Source Log-Based Anomaly Detection in Industrial Control Systems
Seong-Su Yoon, Dong-Hyuk Shin, Ieck-Chae Euom · 2025
Industrial Control Systems (ICS) are increasingly targeted by sophisticated cyber attacks, while traditional methods—relying on network analysis and signature-based detection—struggle to detect advanced persistent threats (APTs) and zero-day attacks. We present DeepICS, a novel anomaly detection approach leveraging multi-source log data and deep causal modeling. By integrating system, network, and provenance data, and using a Transformer-based framework, DeepICS captures complex temporal and causal relationships. It achieves a 92% true positive rate (TPR) with low false positives, outperforming traditional ML models and enhancing ICS security against evolving threats.