Industrial Control Systems (ICS) face escalating cyber threats to critical infrastructure, yet traditional physics-based intrusion detection methods struggle to capture dynamic sensor interactions or yield interpretable insights. We introduce DynaFlow Logic Transformer (DLT), a neuro-symbolic framework that addresses three core challenges: dynamic temporal-logical dependencies, explainable decision-making, and imbalanced data. DLT integrates: (1) a Transformer-based adjacency estimator to capture evolving sensor couplings, (2) a neuro-symbolic logic module that extracts threshold-based rules for interpretability, and (3) WGAN-GP for synthesizing minority-class attack samples. Experiments on SWaT and WADI validate DLT’s effectiveness, achieving 97.9% and 96.8% F1 in binary anomaly detection, 93.9% and 96.7% in multi-class attack classification, surpassing strong baselines. Ablation studies reveal the necessity of each component, while adjacency visualizations and logic rules offer operational clarity. This work highlights the synergy between dynamic graph learning and symbolic reasoning, providing both machine-grade detection accuracy and explainable intrusion insights.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DynaFlow Logic Transformer: A Neuro-Symbolic Approach to Industrial Control System Intrusion Detection

  • Yuzhe Zhang,
  • Yuhang Du,
  • Linqi Sun,
  • Chenhan Zhang,
  • Yingxu Lai

摘要

Industrial Control Systems (ICS) face escalating cyber threats to critical infrastructure, yet traditional physics-based intrusion detection methods struggle to capture dynamic sensor interactions or yield interpretable insights. We introduce DynaFlow Logic Transformer (DLT), a neuro-symbolic framework that addresses three core challenges: dynamic temporal-logical dependencies, explainable decision-making, and imbalanced data. DLT integrates: (1) a Transformer-based adjacency estimator to capture evolving sensor couplings, (2) a neuro-symbolic logic module that extracts threshold-based rules for interpretability, and (3) WGAN-GP for synthesizing minority-class attack samples. Experiments on SWaT and WADI validate DLT’s effectiveness, achieving 97.9% and 96.8% F1 in binary anomaly detection, 93.9% and 96.7% in multi-class attack classification, surpassing strong baselines. Ablation studies reveal the necessity of each component, while adjacency visualizations and logic rules offer operational clarity. This work highlights the synergy between dynamic graph learning and symbolic reasoning, providing both machine-grade detection accuracy and explainable intrusion insights.