Adaptive anomaly detection and classification in critical infrastructure systems: A real-time privacy-preserving multi-model framework

Hafiz Bilal Ahmad, Haichang Gao, Naila Latif · High-Confidence Computing · 2025

The increasing digitization of critical infrastructure has exposed these essential systems to sophisticated cyber threats, creating an urgent need for advanced security solutions to protect them. However, a significant gap exists, as current intrusion detection systems (IDS) often lack the ability to adapt to new threats in real time and typically fail to integrate privacy preservation, resulting in fragmented and static defenses. This study addresses this gap by proposing an innovative, adaptive, and privacy-preserving framework that holistically unifies these critical capabilities into a single cohesive pipeline for real-time anomaly detection, classification, and adaptation. Our methodology employs a multi-layer hybrid architecture, where a stacking ensemble fuses temporal anomaly cues from a Recurrent Autoencoder (RAE) with structural outlier scores from an Isolation Forest (IF) into a Random Forest meta-classifier. To ensure long-term robustness and data protection, a Deep Q-Learning (DQL) agent dynamically refines the detection policy against evolving threats, whereas the Laplace mechanism provides formal ϵ -differential privacy guarantees. Key findings demonstrate the framework’s exceptional performance, with the proposed ensemble model achieving 99.90% detection accuracy, a remarkably low false-positive rate of 0.001, and 99% classification accuracy on the UNSW-NB15 dataset. The framework’s robustness and generalizability were further confirmed through extensive evaluations on multiple diverse benchmarks, including the SWaT industrial control system dataset, and the superiority of our architectural choices was validated through a comprehensive ablation study. The implementation of this framework presents a comprehensive, real-time, and privacy-aware IDS solution that significantly advances the state-of-the-art adaptive cybersecurity for critical infrastructure.

Read the paper · More papers on PaperTik