Skip to content
Open access

Cyber-Physical Attack Detection in Water Distribution Systems Using a Hybrid Ensemble of XGBoost, Isolation Forest, and LSTM Autoencoder on the BATADAL Dataset

Jul 2026 · Journal of Intelligent Decision Making and Information Science · Vol 3, pp. 1019-1037 · 0 citations · 18 references

TL;DR

A three-model hybrid ensemble that combines a supervised XGBoost classifier, an unsupervised Isolation Forest with principal component analysis (PCA) dimensionality reduction, and an unsupervised LSTM Autoencoder trained on 24-hour sliding windows of sensor sequences provides rapid and reliable detection.

Abstract

Water distribution systems (WDSs) are critical public infrastructures increasingly controlled through cyber-physical layers, making them attractive targets for malicious intrusions. Real-time detection is difficult: confirmed attack data is scarce, sensor readings co-vary across dozens of channels, and well-crafted intrusions are deliberately kept within plausible operating ranges. This paper proposes a three-model hybrid ensemble that combines a supervised XGBoost classifier, an unsupervised Isolation Forest with principal component analysis (PCA) dimensionality reduction, and an unsupervised LSTM Autoencoder trained on 24-hour sliding windows of sensor sequences. All models are evaluated on the BATtle of the Attack Detection Algorithms (BATADAL) training dataset, which contains 4,177 hourly observations from a simulated SCADA-monitored C-Town network spanning July–December 2016, with 219 confirmed attack hours (5.2%) across five distinct attack campaigns. The weighted ensemble (XGBoost 40%, LSTM Autoencoder 50%, Isolation Forest 10%) achieves an F1-score of 0.9336, ROC-AUC of 0.9967, and an average precision of 0.9390, detecting 211 of 219 attack hours with only 22 false positives and a false positive rate of 0.56%. Time-to-detection analysis across all five attack windows confirms that the ensemble provides rapid and reliable detection, identifying four of five attack campaigns within one hour of onset. Results demonstrate that combining complementary detection paradigms substantially outperforms any single-model approach on this benchmark.

Read PDF

Similar papers

Open access Jul 2026

Rigorous Evaluation of Machine Learning Intrusion Detection for Water Treatment Systems on SWaT Network Traffic

Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions of patterns it has already seen rather...

Sebastian Mesca, Emil Pricop, G. Stamatescu · 1 citation
Open access Aug 2026

Imbalance-resistant multiclass attack classification in real-time IoT water networks using SMOTE-enhanced random forests

The implementation of smart water distribution systems that rely on the Internet of Things (IoT) has substantially increased the need for intrusion detection systems capable of distinguishing among various categories of attackers. Such granularity is essential for timely and appropriate incident response. The nature of...

Anita Anand, Shivangi Surati · 0 citations
Open access Aug 2026

Machine Learning-Based Intrusion Detection for Smart City Internet of Things Networks

This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset, finding that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city Io...

E. Okonta, Oluwaseun Bamgbose · 0 citations
Conference Aug 2026

Intelligent Intrusion Detection System Using Hybrid Swin Transformer-RNN for Efficient Cyber Threat Mitigation

Due to the rising frequency as well as complexity of Cyber-attacks the real-time Intrusion Detection Systems (IDS) have a greater demand for reliable. Conventional IDS techniques frequently encounter performance limitations when dealing with high-dimensional data as well as temporal patterns. In order to efficiently de...

B. Deepthi, M. Sreenivasu, Chichari Rajesh · 0 citations
Open access Aug 2026

AI-Driven Security: Detecting Cyber Attacks in IoT Networks

LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.

Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.