Information-Theoretic Digital Twins for Stealthy Attack Detection in Industrial Control Systems: A Closed-Form KL Divergence Approach

📅 2026-03-02
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the challenge of detecting stealthy false data injection attacks (FDIAs) in industrial control systems, which manipulate system states within physically plausible bounds and thus evade conventional detection. To overcome the limitations of deep learning methods—prone to overfitting—and traditional approaches—lacking scalability in high-dimensional settings—the authors propose a closed-loop information-theoretic digital twin framework. By integrating N4SID subspace identification with steady-state Kalman filtering, the framework introduces a closed-form KL divergence metric to quantify residual distribution shifts in real time, simultaneously capturing perturbations in both mean and covariance without requiring model training. Evaluated on the SWaT and WADI datasets, the method achieves F1 scores of 0.832 and 0.615, respectively, outperforming deep learning baselines such as TranAD while running approximately 600× faster on CPU with minimal memory footprint, making it suitable for GPU-less industrial edge controllers.

Technology Category

Application Category

📝 Abstract
Digital twins (DTs) are increasingly used to monitor and secure Industrial Control Systems (ICS), yet detecting stealthy False Data Injection Attacks (FDIAs) that manipulate system states within normal physical bounds remains challenging. Deep learning anomaly detectors often over-generalize such subtle manipulations, while classical fault detection methods do not scale well in highly correlated multivariate systems. We propose a closed-loop Information-Theoretic Digital Twin (IT-DT) framework for real-time anomaly detection. N4SID identification is combined with steady-state Kalman filtering to quantify residual distribution shifts via closed-form KL divergence, capturing both mean deviations and malicious cross-covariance shifts. Evaluations on the SWaT and WADI datasets show that IT-DT achieves F1-scores of 0.832 and 0.615, respectively, with better precision than deep learning baselines such as TranAD. Computational profiling indicates that the analytical approach requires minimal memory and provides approximately a 600x inference speedup over transformer-based methods on CPU hardware. This makes the framework suitable for resource-constrained industrial edge controllers without GPU acceleration.
Problem

Research questions and friction points this paper is trying to address.

False Data Injection Attacks
Industrial Control Systems
Stealthy Attack Detection
Digital Twins
Anomaly Detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Information-Theoretic Digital Twin
Closed-Form KL Divergence
False Data Injection Attacks
Industrial Control Systems
Anomaly Detection
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
I
Inda Kreso
dept. Criminal Justice, Criminology and Security Studies, University of Sarajevo
Mehran Tarif
Mehran Tarif
University of Verona
Artificial IntelligenceMachine LearningDeep LearningInternet of ThingsDigital Twins
F
Fatemeh Moradi
dept. Computer Engineering, Islamic Azad University
I
Iman Khazrak
dept. Computer Science, Bowling Green University
M
Mostafa M Rezaee
dept. Computer Science, Bowling Green University
Mohammadhossein Homaei
Mohammadhossein Homaei
PhD student at Extremadura University, Cáceres, Spain
Digital TwinsCybersecurityInternet of ThingsMADMArtificial intelligence.