EFFECTIVE TIME-SERIES ANOMALY DETECTION MODEL FOR INDUSTRY CONTROL SYSTEM USING IOT AND MACHINE LEARNING TECHNIQUES
S.S. Subashka Ramesh, Subashka Ramesh S S, R. Lakshmi, N. Meenakshi, R. Rajesh Kanna · Telecommunications and Radio Engineering · 2025
Some examples of essential infrastructure that could be targeted by malicious actors include power plants, water treatment facilities, and manufacturing systems. These actions are the target of industrial control systems (ICS)-based attack detection. By exploiting control logic and communication techniques, these types of attacks can cause operational chaos. To identify instances of suspicious behavior, detection systems employ anomaly detection, machine learning, and signature-based approaches. To prevent operational failures, financial losses, and safety hazards, rapid detection is essential. Recognizing these irregularities properly is crucial to ensuring the safety and reliability of operations. In this article, a hybrid classical model is suggested by combining long short-term memory (LSTM), k-nearest neighbor (KNN), and Pelican Optimization Algorithm (POA) (LSTM-KNN-POA). This model takes the advantage of both KNN classifier and LSTM networks' capacity to learn features over time. POA enhances detection accuracy while lowering false alarms by modifying crucial KNN parameters such as number of neighbors, distance metric, and weight mechanism. To evaluate the model by comparing it to classic classifiers they include naïve Bayes, random forest, AdaBoost, CNN, standalone LSTM, and hybrid LSTM-KNN. The ICS-Anomaly Detection Dataset (ICS-ADD) is utilized for this purpose. The proposed model surpasses competitors with a 97.2% accuracy rate, 96.8% precision, 96.6% recall, 96.7% F1-score, 1.65% false alarm rate (FAR), and 0.986 area under curve (AUC). Additional tests include robustness to noisy input, accuracy during cross-validation, loss curves, and receiver-operating characteristic (ROC) curves. The LSTM-KNN-POA model is a real-world ICS application due to its high predictive accuracy, resilience to input disturbances, and wide generalizability. Findings indicate that the proposed model has the potential to serve as a solid basis for anomaly detection in smart industrial settings.