Tool Demo: Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks
This study addresses the limitations of conventional traffic- or protocol-based detection methods in identifying topology changes induced by cyberattacks in water distribution systems. To overcome this challenge, the authors propose a novel approach that transforms raw network traffic into dynamic graphs and integrates, for the first time, the Graph-based Machine Learning (GPML) framework with dynamic graph modeling. By leveraging community detection and spectral graph features, the method effectively captures temporal topological anomalies caused by attacks. Experimental evaluation on three industrial datasets—HITL, SWaT, and CrossTest—demonstrates that the proposed technique significantly enhances detection performance for both cyber and physical attacks, thereby surpassing the constraints inherent in traditional traffic analysis approaches.