OT/ICS Intrusion Detector (Autoencoder)

A deep autoencoder that detects cyber-physical attacks on industrial control systems from sensor/actuator telemetry. Trained on the HAI (HIL-based Augmented ICS) turbine/boiler testbed using only normal operation β€” so it needs no labeled attacks β€” and flags a reading as an intrusion when its reconstruction error exceeds a learned threshold.

What it does

Takes a reading of the 59 real HAI sensor/actuator tags, reconstructs it, and compares the reconstruction error to the trained threshold (0.009223). Missing tags are filled from a real recorded normal reading, so partial live feeds still score sensibly.

  • Architecture: 59 β†’ 128 β†’ 64 β†’ 32 (encoding) β†’ 64 β†’ 128 β†’ 59, ReLU
  • Detection: reconstruction MSE > threshold β‡’ anomaly

Quick start

pip install -r requirements.txt
python example.py
from otics_score import score_reading, BASELINE_READING
score_reading(BASELINE_READING)                 # normal -> is_anomaly False
score_reading({**BASELINE_READING, "P1_FT01": 900.0})   # tampered -> anomaly

Serving API (Docker)

docker run -p 8082:8080 ghcr.io/samuelgtetteh/otics-anomaly:0.1
curl -s localhost:8082/example | curl -s localhost:8082/score -H 'Content-Type: application/json' -d @-  # (or POST {"readings": {...}})

GET /example returns a real normal reading; POST /score {"readings": {...}} scores one.

Files

  • autoencoder_hai.pth β€” trained weights Β· scaler_hai.pkl β€” fitted StandardScaler
  • autoencoder_hai_meta.txt β€” input_dim / encoding_dim / threshold / 59 feature order
  • otics_score.py β€” model + scoring Β· serve.py β€” FastAPI wrapper

Intended use & limitations

Assistive monitoring for OT/ICS: a high reconstruction error flags a reading worth investigating, not a confirmed attack. The threshold is tuned to this HAI testbed; deploying on a different plant requires re-fitting the scaler/threshold on that plant's normal data. Trained on 59 specific HAI tags β€” inputs must use those tag names.

Data & license

Trained on the HAI dataset (iTrust/HIL testbed; subject to its terms). Code and released weights: Apache-2.0 (LICENSE).

Citation

Tetteh, S. G. OT/ICS Intrusion Detection with a Physics-Aware Autoencoder. Jarvis College of Computing and Digital Media, DePaul University.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support

Space using stetteh/otics-anomaly 1