Skip to content

Secure intrusion detection system for industrial control systems using digital twins

Jul 2026 · Cluster Computing · Vol 29 · 0 citations · 45 references
Computer Science

TL;DR

A Digital Twin (DT)-enabled IDS framework that combines deep learning with real-time process simulation is proposed that consistently outperforms the evaluated representative baseline IDS methods under identical experimental conditions.

View source

Similar papers

#machine learning Preprint Aug 2026

Digital Twin-Based Intrusion Detection for Vehicle Powertrain CAN Bus Systems

A DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.

Araf Rahman, M. Salek, Mashrur Chowdhury · 0 citations
Open access Jul 2026

Next-generation intrusion detection in cyber-physical systems using an ensemble of quantum-inspired and deep neural models

Cyber-physical systems (CPSs) could cause actuation and safety risks. Intrusion detection is essential for preserving the system's integrity due to growing security issues. Nowadays, deep learning (DL) schemes have been deployed to enhance the detection of cyber-attacks, yet these models are prone to overfitting, which reduces detection performance. Hence, this research proposes a novel deep learning-based Intrusion Detection System (IDS) for CPS to address these limitations. The proposed methodology consists of four key stages, including preprocessing, feature extraction, feature selection, and intrusion detection. Data preprocessing is performed via cleansing, followed by the extraction of statistical [mean, median, and standard deviation (SD)], entropy-based, improved correlation, improved mutual information (MI), flow-based, and Improved Information Gain (IIG) features, which are derived to obtain the important features. The Archimedes Algorithm with Team Work Principle (AA_TWP), integrating the Archimedes Optimization Algorithm (AOA) and the Teamwork Optimization Algorithm (TOA), with modifications to the exploration phase, is employed to efficiently select the most relevant features. The selected features, along with preprocessed data, are fed into an ensemble of Deep Belief Networks (DBNs), Quantum Deep Neural Networks (QDNNs), and optimized Bidirectional Long Short-Term Memory (Bi-LSTM), with Bi-LSTM weights further tuned by AA_TWP. The ensemble outputs are averaged to produce the final intrusion decision. Experimental results demonstrate 91.52% accuracy and 91.76% Matthews Correlation coefficient (MCC), highlighting the effectiveness of the proposed approach, which outperforms existing techniques.

Maloth Sagar, V. C. · 0 citations
Open access 2026

Open-Set Intrusion Detection Solution for Industrial Internet of Things Based on Deep Spiking Q-Networks

This work proposes a deep spiking Q-network-based intrusion detection system (DSQN-IDS) for the IIoT, formulating unknown intrusion detection as a Markov decision process (MDP), and employs a hierarchical multi-stage decision-making framework.

Yimeng Liu, Xinyu Xu, Wangting Xue et al. · 0 citations
Conference Jul 2026

Transformer-based Network Anomaly Detection System for Intelligent Cyber Security Monitoring

As MNI becomes increasingly vulnerable to new kinds of attacks from the cyber world, accurate and timely detection of intrusions becomes a primary key to the power of cybersecurity. More complex attack patterns, complex traffic interactions within large scales are not very collaborable with the typical signature-based detection methods. A Transformer Based Network Anomaly Detection System for intelligent cyber security monitoring based on network flow analysis (NFAs) is proposed in the paper. This framework is derived from the CICIDS2017 data-set and proposes 78 of the statistical flow characteristics, where each flow characteristic impacts the behaviour of a packet, protocol, volume of traffic and temporal communication pattern. The model uses a Transformer Encoder network architecture along with multiple heads of self-attention, which provides greater understanding to deal with complex relationships between features from network traffic. LabelEncoder and StandardScaler have been applied to the columns with values that need to be encoded for categorical variables and scaled to fit the values for models training. A trained model is then applied to progress multiple different categories of cyberattacks including DDoS attacks, PortScan, Brute Force, Botnet, Web Based, etc. and different kinds of traffic, all traffic is considered benign traffic. For providing real-time predictions, confidence interval, prediction of class severity and alerts using trained model an API developed on flask to connect the trained model to a dashboard was built. The experimental results show that the Transformer-based learning could be very effective in achieving successful capturing of the network behavior and conducting realistic detection. The overall proposed system offers an intelligent, scalable and deployment-centric approach to improve the monitoring and proactive detection of threats in contemporary networks in the field of cybersecurity.

S. Nagendrudu, Shaik Mohammed Anays, F. Mahammad et al. · 0 citations
Aug 2026

Resilient control and Markov-enhanced hybrid multi-feature intrusion detection for cyber-physical wind farms under SCADA delays and coordinated cyber-attacks

A Markov-enhanced hybrid IDS that integrates physics-based modeling, data-driven anomaly detection, and statistical sequence analysis to secure a two-turbine cyber-physical wind farm, offering an analytically scalable architectural path toward more secure renewable energy infrastructures, while larger-farm empirical validation remains future work.

Mahdi Esmaeelihesari, M. Davoudi, N. Pariz · 0 citations
Preprint Jul 2026

ProvICS: A Provenance-based Intrusion Detection for Industrial Control Systems

Comparative analysis shows that ProvICS is among the few existing ICS/CPS benchmarks with multi-host kernel-level provenance, real PLC hardware-in-the-loop execution, decoded Modbus traffic, physical process-state measurements, and auxiliary raw PCAP traces in a time-synchronized collection.

Md Neyamul Islam Shibbir, Deepak K. Tosh · 0 citations