[Paper Review] Deep Learning-Based Anomaly Detection in Cyber-Physical Systems: Progress and Opportunities
A comprehensive survey of deep learning-based anomaly detection methods in cyber-physical systems, proposing a taxonomy to classify attacks, faults, data inputs, models, and evaluation metrics, and providing guidance for future research.
Anomaly detection is crucial to ensure the security of cyber-physical systems (CPS). However, due to the increasing complexity of CPSs and more sophisticated attacks, conventional anomaly detection methods, which face the growing volume of data and need domain-specific knowledge, cannot be directly applied to address these challenges. To this end, deep learning-based anomaly detection (DLAD) methods have been proposed. In this paper, we review state-of-the-art DLAD methods in CPSs. We propose a taxonomy in terms of the type of anomalies, strategies, implementation, and evaluation metrics to understand the essential properties of current methods. Further, we utilize this taxonomy to identify and highlight new characteristics and designs in each CPS domain. Also, we discuss the limitations and open problems of these methods. Moreover, to give users insights into choosing proper DLAD methods in practice, we experimentally explore the characteristics of typical neural models, the workflow of DLAD methods, and the running performance of DL models. Finally, we discuss the deficiencies of DL approaches, our findings, and possible directions to improve DLAD methods and motivate future research.
Motivation & Objective
- Systematically review deep learning-based anomaly detection methods for CPS to detect faults and attacks.
- Propose a taxonomy based on anomaly type, detection strategies, and evaluation metrics to organize existing work.
- Identify domain-specific characteristics and trends across ICS, smart grid, ITS, and aerial systems.
- Discuss limitations, open problems, and practical guidance for building DLAD solutions.
- Experimentally explore neural models and workflows to provide practical insights into DLAD performance.
Proposed method
- Propose a taxonomy organized by (i) type of anomalies (attacks vs faults), (ii) detection strategies (input data, neural network designs, anomaly scores), and (iii) implementation and evaluation metrics.
- Review and categorize peer-reviewed CPS DLAD papers from conferences and journals under the taxonomy.
- Experimentally explore typical neural models to characterize CPS data and illustrate the DLAD workflow and running performance of models.
- Provide discussion on deficiencies of DL approaches in CPS and propose directions to improve DLAD methods.
Experimental results
Research questions
- RQ1What are the characteristics of existing DLAD approaches and how can they be categorized by threat model, detection strategy, implementation, and evaluation metrics?
- RQ2How can a DL model be applied to CPS anomaly detection, including the characteristics of neural models and the DLAD workflow?
- RQ3What are the limitations and deficiencies of DLAD methods when applied to CPS anomaly detection?
- RQ4How can researchers address these limitations and improve DLAD methods?
Key findings
- The authors present a taxonomy for DLAD in CPS based on anomaly type, detection strategy, and implementation/evaluation metrics.
- They identify representative CPS domains (ICS, smart grid, ITS, aerial systems) and summarize domain-specific characteristics and trends.
- They experimentally explore typical neural models and outline the DLAD workflow and running performance to provide practical guidance.
- The survey discusses limitations and open problems of DL approaches and highlights directions for improving DLAD methods.
- The work synthesizes progress, challenges, and future research directions to motivate further study in DL-based CPS anomaly detection.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.