Cyber-Electromagnetic Anomaly Detection Through Time-Series Analysis

📅 2026-08-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过结合网络和电磁特征,利用随机森林和LSTM自编码器模型检测跨域异常行为,提高军事行动中的态势感知能力。
📝 Abstract
Military operations benefit from the coordination between kinetic and non-kinetic domains. In particular, the coordination of cyber operations and electromagnetic warfare has become increasingly relevant for gaining operational advantage. This coordination is also relevant for Cyber Situational Awareness (CSA), where the Observe-Orient-Decide-Act (OODA) loop requires monitoring and interpreting evidence from heterogeneous sources. In this context, anomalies may appear not only in the physical behavior of signals, but also in the communication behavior observed at the traffic level. However, many existing anomaly detection proposals focus on only one of these perspectives, limiting their ability to characterize events that manifest simultaneously in the electromagnetic spectrum and cyberspace. To address this limitation, this work develops and evaluates two anomaly detection models that combine features from both domains. More specifically, the study uses the ZBDS2023 dataset, which contains traffic from nodes in a mesh network, including benign and attack behaviors. Thus, this dataset provides physical-level features, traffic-level features, and labeled attacks. Two detection approaches are evaluated: a supervised model based on Random Forest and an unsupervised model using LSTM-Autoencoder. The results show that learning-based models can detect patterns combining both levels, especially under a supervised approach, achieving an F1-score of 89.76% with Random Forest and 64.09% with LSTM-Autoencoder. Although these results indicate that the proposed models can support CSA by improving the observation and interpretation of anomalous behavior, the subtle differences between normal and attack samples highlight the need for richer discriminative features.
Problem

Research questions and friction points this paper is trying to address.

anomaly detection
cyber-electromagnetic
heterogeneous sources
Cyber Situational Awareness
combined features
Innovation

Methods, ideas, or system contributions that make the work stand out.

anomaly detection
cyber-electromagnetic coordination
Random Forest
LSTM-Autoencoder
cross-domain features
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
M
María Teresa Guillén Navarro
Department of Information and Communications Engineering, University of Murcia, Campus de Espinardo, 30100, Murcia, Spain
J
Juan Luis Serradilla Tormos
Department of Information and Communications Engineering, University of Murcia, Campus de Espinardo, 30100, Murcia, Spain
Sergio López Bernal
Sergio López Bernal
Postdoctoral researcher, University of Murcia
CybersecurityBrain-Computer InterfacesData analysisArtificial IntelligenceInternet of Things
Daniel Díaz-López
Daniel Díaz-López
Assistant Professor, Universidad del Rosario
CybersecurityThreat intelligencePentestingAIBlockchain
G
Gregorio Martínez Pérez
Department of Information and Communications Engineering, University of Murcia, Campus de Espinardo, 30100, Murcia, Spain