Finding Component Relationships: A Deep-Learning-Based Anomaly Detection Interpreter

Lijuan Xu, Ziyu Han, Zhen Wang, Dawei Zhao

Research output: Contribution to journalArticlepeer-review

1 Scopus citations

Abstract

While the interpretability of deep learning (DL)-based models has been extensively explored in academia, applying existing interpretation methods to anomaly detection in industrial control systems (ICSs) poses challenges for two primary reasons. First, security experts in ICS have distinct interpretive priorities, emphasizing the need for stability and readability. Second, there are various types of device components in ICS, and the potential interactions between sensors and actuators are yet to be explored. To tackle the above challenges, we propose DeepINT, an interpreter for anomaly detection in ICS. In DeepINT, we adopt a search optimization algorithm to find the reference and capture feature importance by the backpropagation gradient to improve interpretation performance and reliability. In addition, we construct a finite difference-based interaction detection, which tests the interaction of different device components, in order to address the problem that actuators in ICS are not easily interpreted, meanwhile improving the comprehensiveness and accuracy of the interpretation results. In comprehensive experiments on two real water treatment datasets [secure water treatment (SWaT) and water distribution (WADI)], DeepINT shows excellent interpretation performance compared to the six state-of-the-art baseline methods, especially on the SWaT dataset, with a 60% improvement in interpretation accuracy. In addition, our method significantly improves the efficiency of interaction detection, which balances interpretation performance and time efficiency.

Original languageEnglish
Pages (from-to)4149-4162
Number of pages14
JournalIEEE Transactions on Computational Social Systems
Volume11
Issue number3
DOIs
StatePublished - 1 Jun 2024

Keywords

  • Anomaly detection
  • industrial control system (ICS)
  • interaction detection
  • interpretability

Fingerprint

Dive into the research topics of 'Finding Component Relationships: A Deep-Learning-Based Anomaly Detection Interpreter'. Together they form a unique fingerprint.

Cite this