Journal of Computer Applications ›› 2024, Vol. 44 ›› Issue (4): 1158-1165.DOI: 10.11772/j.issn.1001-9081.2023050566

Special Issue: 网络空间安全

• Cyber security • Previous Articles     Next Articles

Domain transfer intrusion detection method for unknown attacks on industrial control systems

Haoran WANG, Dan YU, Yuli YANG, Yao MA, Yongle CHEN()   

  1. College of Computer Science and Technology (College of Data Science),Taiyuan University of Technology,Taiyuan Shanxi 030000,China
  • Received:2023-05-09 Revised:2023-07-28 Accepted:2023-07-31 Online:2023-08-03 Published:2024-04-10
  • Contact: Yongle CHEN
  • About author:WANG Haoran, born in 1998, M. S. candidate. His research interests include IoT security.
    YU Dan, born in 1983, Ph. D., lecturer. Her research interests include IoT security.
    YANG Yuli, born in 1979, Ph. D., lecturer. Her research interests include cloud security, blockchain.
    MA Yao, born in 1982, Ph. D., lecturer. His research interests include IoT security.
    CHEN Yongle, born in 1983, Ph. D., professor. His research interests include IoT security.
  • Supported by:
    Basic Research Program of Shanxi Province(20210302123131)


王昊冉, 于丹, 杨玉丽, 马垚, 陈永乐()   

  1. 太原理工大学 计算机科学与技术学院(大数据学院),太原 030000
  • 通讯作者: 陈永乐
  • 作者简介:王昊冉(1998—),男,山西临汾人,硕士研究生,CCF会员,主要研究方向:物联网安全
  • 基金资助:


Aiming at the problems of lack of Industrial Control System (ICS) data and poor detection of unknown attacks by industrial control intrusion detection systems, an unknown attack intrusion detection method for industrial control systems based on Generative Adversarial Transfer Learning network (GATL) was proposed. Firstly, causal inference and cross-domain feature mapping relations were introduced to reconstruct the data to improve its understandability and reliability. Secondly, due to the data imbalance between source domain and target domain, domain confusion-based conditional Generative Adversarial Network (GAN) was used to increase the size and diversity of the target domain dataset. Finally, the differences and commonalities of the data were fused through domain adversarial transfer learning to improve the detection and generalization capabilities of the industrial control intrusion detection model for unknown attacks in the target domain. The experimental results show that on the standard dataset of industrial control network, GATL has an average F1-score of 81.59% in detecting unknown attacks in the target domain while maintaining a high detection rate of known attacks, which is 63.21 and 64.04 percentage points higher than the average F1-score of Dynamic Adversarial Adaptation Network (DAAN) and Information-enhanced Adversarial Domain Adaptation (IADA) method, respectively.

Key words: transfer learning, Industrial Control System (ICS), unknown attack, Generative Adversarial Network (GAN), hybrid attention



关键词: 迁移学习, 工业控制系统, 未知攻击, 生成对抗网络, 混合注意力

CLC Number: