Temporal state-aware unsupervised anomaly detection for industrial control system

dc.contributor.advisorChakrabarty, Amitabha
dc.contributor.authorAnik, Khandoker Wahiduzzaman
dc.contributor.authorOntu, Md. Rakib Hossain
dc.contributor.authorSohag, Md. Mehedi Hasan
dc.contributor.authorBadhon, Fardin Jahan
dc.date.accessioned2026-04-21T03:52:18Z
dc.date.available2026-04-21T03:52:18Z
dc.date.issued2026-01
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 56-58).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2026.
dc.description.abstractThe increasing interrelationship with Information Technology infrastructure between the Industrial Control Systems (ICS) and critical infrastructure has presented advanced cyber-attacks to critical infrastructure, which not only places data security at risk but also threatens the physical safety, to operational continuity. The thesis will visit the issue of creating an efficient, interpretable and computationally efficient intrusion detection system in an ICS environment through a proposed novel LSTM auto-encoder architecture, specifically trained with edge deployment in mind. The article takes a rigorous approach where physics-conscious feature engineering is embraced, deep-learning architecture creation, and thorough assessment of the WADI (Water Distribution) benchmark data. The proposed system achieves a score of 0.7018 in F1 (Precision=0.7196, Recall=0.7149) by performing the dimensionality reduction of 127 sensors to 30 (which is a reduction of 76 per cent), and by adding the zero-crossing-rate features to the frequency-domain analysis, which is drastically higher than more traditional statistical methods, including Isolation Forest (0.58 F1), or the current state-of-the-art methods, including STADN. To be practical, the system is edge-compatible with an inference latency of 1.84ms, a million parameters, and consumes 5.38W of power when run on simulated NVIDIA Jetson Nano hardware, which is a ten-fold faster inference time than graph-based algorithms. Unsupervised approach, which learns only based on normal operational data, helps to detect novel, zero-day attacks, therefore overcoming the limitation of labelled attack data in operational settings. The study establishes that advanced deep-learning systems can be deployed on the tight computational requirements of industrial edge devices, thus creating a reproducible model of secure and real-time secure critical infrastructure protection.
dc.identifier.otherID 24141115
dc.identifier.otherID 22101879
dc.identifier.otherID 22101883
dc.identifier.otherID 22101876
dc.identifier.otherhttps://dspace.bracu.ac.bd/server/api/core/items/4c061a4e-5468-4228-bb3d-5e3fff20b03e
dc.identifier.urihttp://hdl.handle.net/10361/27983
dc.language.isoen
dc.publisherBRAC University
dc.sourceBRAC University Institutional Repository
dc.subjectIndustrial Control Systems (ICS)
dc.subjectAnomaly detection
dc.subjectZero-crossing rate
dc.subjectMachine learning
dc.subjectIntrusion Detection System (IDS)
dc.titleTemporal state-aware unsupervised anomaly detection for industrial control system
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
24141115, 22101879, 22101883, 22101876_CSE.pdf
Size:
1.05 MB
Format:
Adobe Portable Document Format