• Home
  • Search
  • Deep Learning Framework for Online Alarm Flood Classification and Fault-Cyberattack Discrimination
  • https://doi.org/10.7939/84040Copy DOI Icon

Deep Learning Framework for Online Alarm Flood Classification and Fault-Cyberattack Discrimination

Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

Industrial control systems rely on alarm systems to alert operators to abnormal conditions. These systems frequently generate alarm floods, periods of intense alarm activities that overwhelm operators and compromise situational awareness. The root causes of alarm floods range from operational faults arising from equipment failures to sophisticated cyberattacks deliberately designed to manipulate process controls. Despite their appearance as periods of intense alarm activities, alarm floods resulting from operational faults and cyberattacks are fundamentally different. Recognition of this distinction is essential, as each category requires its own diagnostic approach and response protocols. This thesis addresses the dual challenge of classifying alarm floods and identifying their originating fault types. It also detects anomalous patterns indicative of previously unseen cyber intrusions. This research presents two complementary deep learning frameworks for alarm flood analysis. First, a convolutional neural network (CNN) architecture is developed for online alarm flood classification that transforms temporal alarm sequences into spatial-temporal heatmap representations. This visual pattern recognition system captures alarm activation patterns across process variables and time, enabling real-time fault classification. The framework incorporates multi-channel input encoding to distinguish valid alarm data from padded regions, progressive feature extraction through hierarchical convolutional layers, and demonstrates early classification capability using partial alarm information as floods evolve. Second, a class-conditioned autoencoder (C2AE) framework is introduced for open-set recognition, enabling the system to distinguish between known operational faults and previously unseen cyberattack patterns. C2AE employs a maximum separation training strategy that explicitly maximizes the reconstruction quality gap between matched and mismatched class conditions. This approach enables robust detection of cyberattacks as out-of-distribution samples through reconstruction-based anomaly scoring, while simultaneously classifying known faults. The framework addresses the critical limitation of closed-set classifiers that force unknown cyberattack patterns into known fault categories. Both methodologies are validated on the Tennessee Eastman Process benchmark, a widely adopted testbed for process control research. The CNN-based classifier achieves high accuracy in distinguishing between five operational fault scenarios, with classification performance improving as alarm floods evolve over time. The C2AE framework demonstrates effective open-set recognition by successfully identifying four types of cyber attacks as unknown patterns while maintaining accurate classification of known operational faults. Comprehensive evaluation includes closed-set fault classification performance, open-set cyber attack detection capabilities, and analysis of reconstruction error patterns that enable discrimination between legitimate faults and malicious intrusions. The proposed frameworks provide operators with enhanced situational awareness and enable appropriate emergency response strategies in safety-critical industrial environments facing both operational disturbances and evolving cyber security threats.

Similar Papers
  • Dissertation
  • Citations1

Digital Dictators: How Different Types of Authoritarian Regimes Use Cyber Attacks to Legitimize Their Rule

  • Jan 01, 2022
  • Casey Babb
  • Conference Article
  • Citations6

Detecting Cyber Attacks in Smart Grids with Massive Unlabeled Sensing Data

  • Oct 25, 2022
  • Hanyu Zeng +5
  • Research Article
  • Citations2

Review Paper on Cyber Security and Types of Cyber Attacks

  • Aug 29, 2022
  • International Journal of Advanced Research in Science, Communication and Technology
  • Mr Pradeep Nayak +4
  • Book Chapter
  • Citations2

Chapter 12 - Can Cyber Warfare Leave a Nation in the Dark? Cyber Attacks Against Electrical Infrastructure

  • Jan 01, 2013
  • Introduction to Cyber-Warfare
  • Paulo Shakarian +2
  • Conference Article
  • Citations4

Eyes on the Road: A Survey on Cyber Attacks and Defense Solutions for Vehicular Ad-Hoc Networks

  • Mar 08, 2023
  • Amber Hankins +3
  • PDF
  • Research Article
  • Citations44

Dynamic State Estimation of Generators Under Cyber Attacks

  • Jan 01, 2019
  • IEEE Access
  • Yang Li +2
  • Research Article

Применение математических моделей процесса обучения нейронной сети для контроля защищённости от кибератак

  • Oct 04, 2025
  • Modeling of systems and processes
  • Mihail Titov +1
  • Research Article

사이버공격시 게임이론을 활용한 집단지성간 전략결정 모델 연구 - 한수원 해킹사건을 중심으로 -

  • Feb 29, 2016
  • Journal of the Korea Institute of Information Security and Cryptology
  • Sang-Min Park +2
  • Research Article
  • Citations63

Vulnerability analysis of demand-response with renewable energy integration in smart grids to cyber attacks and online detection methods

  • Mar 11, 2023
  • Reliability Engineering & System Safety
  • Daogui Tang +2
  • Conference Article
  • Citations9

Improved Convolutional Neural Network Based on Multi-head Attention Mechanism for Industrial Process Fault Classification

  • Nov 20, 2020
  • Wenzhi Cui +2
  • Research Article

Development of software for network traffic generation in computer networks for cybersecurity tasks

  • Dec 29, 2025
  • Вісник Приазовського Державного Технічного Університету. Серія: Технічні науки
  • O.I Pronina +1
  • Book Chapter
  • Citations3

Research of Snort Rule Extension and APT Detection Based on APT Network Behavior Analysis

  • Jan 01, 2019
  • Yan Cui +4
  • Research Article

Cybercrime

  • May 07, 2025
  • Security science journal
  • Jaroslav Klátik +1
  • Conference Article

ThreatBased Security Risk Evaluation in the Cloud

  • Jan 01, 2018
  • Armstrong Nhlabatsi +5
  • Book Chapter
  • Citations2

Chapter 16 - Exploring cyber attacks in blockchain technology enabled green smart city

  • Jan 01, 2023
  • Green Blockchain Technology for Sustainable Smart Cities
  • D Helen
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.