Explaining Intrusion Detection in Industrial Control Systems Through Rule Set Learning

Xinyu Xu, Yingxu Lai, Xiao Yi Zhang · IEEE Networking Letters · 2025

With the increasing openness of network environments in industrial control systems, cybersecurity threats have become increasingly severe. While rule-based intrusion detection remains widely used, such methods are limited by their reliance on expert knowledge and the complexity of rule generation, hindering effective responses. In contrast, deep learning has demonstrated strong capabilities in capturing complex attack patterns from large-scale data, but its lack of interpretability poses significant challenges for deployment in safety-critical industrial settings. To address these challenges, this paper proposes a novel method that integrates deep learning with neuro-symbolic representation to enable automated and high-quality rule generation for intrusion detection. Specifically, the approach leverages a deep neural network to learn a set of candidate rules highly correlated with attack behaviors. A heuristic search strategy is then employed to enhance the interpretability of the rules while maintaining detection effectiveness. Experiments on two public datasets demonstrate that the generated rules achieve high detection accuracy with low false positive rates, while maintaining simplicity and clarity, highlighting its strong potential for deployment in real-world industrial environments.

Read the paper · More papers on PaperTik