CORTEXA
← Browse
crossrefApplied Sciences2026-07-18Cited by 0

Rigorous Evaluation of Machine Learning Intrusion Detection for Water Treatment Systems on SWaT Network Traffic

Sebastian Mesca, Emil Pricop, Grigore Stamatescu

Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions of patterns it has already seen rather than its ability to detect novel attacks. We revisit supervised and unsupervised machine-learning IDSs on the Secure Water Treatment (SWaT) dataset’s network-traffic modality, extending a prior conference study, and quantify the effect of more rigorous evaluation protocols. We evaluate five model families (XGBoost, a convolutional–MLP hybrid, a bidirectional LSTM classifier, an unsupervised LSTM-Autoencoder, and a temporal convolutional network) under three protocols: stratified random, attack-held-out, and leave-one-attack-out (LOO). Under LOO on a 30-file subsample, every supervised classifier scores below random on the majority of held-out attacks; the unsupervised LSTM-Autoencoder retains the best solo mean of 0.550 with a strongly bimodal per-attack distribution spanning 0.046 to 0.894. A sign-adjusted oracle-bound ensemble flips members whose per-attack AUROC inverts achieves a mean LOO AUROC of 0.844; adding the TCN as a fourth ensemble member does not improve the result, providing evidence that what is needed is an additional detection mode rather than another supervised classifier. We additionally report recall at a 5% false-positive-rate budget, paired Wilcoxon significance tests, and bootstrap confidence intervals. The full preprocessing, evaluation, and ensemble pipeline is released, and we argue that attack-held-out and LOO should be standard protocols for network-traffic IDS benchmarks on SWaT.

View free PDFSource page

Related papers

crossrefApplied Sciences2023-06-16Cited by 5

Designing Theoretical Shipborne ADCP Survey Trajectories for High-Frequency Radar Based on a Machine Learning Neural Network

Langfeng Zhu, Fan Yang, Yufan Yang, Zhaomin Xiong, Jun Wei

A machine learning neural network-based design for shipborne ADCP navigation is proposed to improve the quality of high-frequency radar measurements. In traditional inversion algorithms for HF radars, sea surface velocity is directly extracted from electromagnetic echoes without…

View free PDFSource page
crossrefApplied Sciences2023-08-21Cited by 2

Developing an Integrated Framework for Securing Internet of Things Traffic in Smart Cities Using Machine Learning Techniques

Moody Alhanaya, Khalil Al-Shqeerat

Internet of Things technology opens the horizon to a broader scope of intelligent applications in smart cities. However, the massive amount of traffic exchanged among devices may cause security risks, especially when devices are compromised or vulnerable to cyberattack. An intrus…

View free PDFSource page
crossrefApplied Sciences2023-10-23Cited by 20

Improving Automated Machine-Learning Systems through Green AI

Dagoberto Castellanos-Nieves, Luis García-Forte

Automated machine learning (AutoML), which aims to facilitate the design and optimization of machine-learning models with reduced human effort and expertise, is a research field with significant potential to drive the development of artificial intelligence in science and industry…

View free PDFSource page
crossrefApplied Sciences2024-08-12Cited by 1

A Unified Seismicity Catalog Development for Saudi Arabia: Multi-Network Fusion and Machine Learning-Based Anomaly Detection

Sayed S. R. Moustafa, Mohamed H. Yassien, Mohamed Metwaly, Ahmad M. Faried, Basem Elsaka

This investigation concentrates on refining the accuracy of earthquake parameters as reported by various Saudi seismic networks, addressing the significant challenges arising from data discrepancies in earthquake location, depth, and magnitude estimations. The application of soph…

View free PDFSource page
crossrefApplied Sciences2023-09-19Cited by 12

An Intrusion Detection Method Based on Hybrid Machine Learning and Neural Network in the Industrial Control Field

Duo Sun, Lei Zhang, Kai Jin, Jiasheng Ling, Xiaoyuan Zheng

Aiming at the imbalance of industrial control system data and the poor detection effect of industrial control intrusion detection systems on network attack traffic problems, we propose an ETM-TBD model based on hybrid machine learning and neural network models. Aiming at the prob…

View free PDFSource page
crossrefApplied Sciences2023-06-30Cited by 12

Leveraging Graph-Based Representations to Enhance Machine Learning Performance in IIoT Network Security and Attack Detection

Bader Alwasel, Abdulaziz Aldribi, Mohammed Alreshoodi, Ibrahim S. Alsukayti, Mohammed Alsuhaibani

In the dynamic and ever-evolving realm of network security, the ability to accurately identify and classify portscan attacks both inside and outside networks is of paramount importance. This study delves into the underexplored potential of fusing graph theory with machine learnin…

View free PDFSource page