Cyber-Physical Attack Detection in Water Distribution Systems Using a Hybrid Ensemble of XGBoost, Isolation Forest, and LSTM Autoencoder on the BATADAL Dataset
Jul 2026· Journal of Intelligent Decision Making and Information Science· Vol 3, pp. 1019-1037· 0 citations· 18 references
TL;DR
A three-model hybrid ensemble that combines a supervised XGBoost classifier, an unsupervised Isolation Forest with principal component analysis (PCA) dimensionality reduction, and an unsupervised LSTM Autoencoder trained on 24-hour sliding windows of sensor sequences provides rapid and reliable detection.
Abstract
Water distribution systems (WDSs) are critical public infrastructures increasingly controlled through cyber-physical layers, making them attractive targets for malicious intrusions. Real-time detection is difficult: confirmed attack data is scarce, sensor readings co-vary across dozens of channels, and well-crafted intrusions are deliberately kept within plausible operating ranges. This paper proposes a three-model hybrid ensemble that combines a supervised XGBoost classifier, an unsupervised Isolation Forest with principal component analysis (PCA) dimensionality reduction, and an unsupervised LSTM Autoencoder trained on 24-hour sliding windows of sensor sequences. All models are evaluated on the BATtle of the Attack Detection Algorithms (BATADAL) training dataset, which contains 4,177 hourly observations from a simulated SCADA-monitored C-Town network spanning July–December 2016, with 219 confirmed attack hours (5.2%) across five distinct attack campaigns. The weighted ensemble (XGBoost 40%, LSTM Autoencoder 50%, Isolation Forest 10%) achieves an F1-score of 0.9336, ROC-AUC of 0.9967, and an average precision of 0.9390, detecting 211 of 219 attack hours with only 22 false positives and a false positive rate of 0.56%. Time-to-detection analysis across all five attack windows confirms that the ensemble provides rapid and reliable detection, identifying four of five attack campaigns within one hour of onset. Results demonstrate that combining complementary detection paradigms substantially outperforms any single-model approach on this benchmark.
Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions of patterns it has already seen rather...
Sebastian Mesca, Emil Pricop, G. Stamatescu· Applied Sciences· 1 citation
The implementation of smart water distribution systems that rely on the Internet of Things (IoT) has substantially increased the need for intrusion detection systems capable of distinguishing among various categories of attackers. Such granularity is essential for timely and appropriate incident response. The nature of...
This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset, finding that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city Io...
E. Okonta, Oluwaseun Bamgbose· ABC2: Journal of Architectur...· 0 citations
Due to the rising frequency as well as complexity of Cyber-attacks the real-time Intrusion Detection Systems (IDS) have a greater demand for reliable. Conventional IDS techniques frequently encounter performance limitations when dealing with high-dimensional data as well as temporal patterns. In order to efficiently de...
B. Deepthi, M. Sreenivasu, Chichari Rajesh· International Conference on...· 0 citations
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations