Machine Learning-Based IDS Enhanced Operational Efficiency in ICS but Exposed to AML Attacks

Cybersecurity experts are sounding the alarm as machine learning-based Intrusion Detection Systems (IDS) have significantly improved operational efficiency in Industrial Control Systems (ICS), but are increasingly vulnerable to Adversarial Machine Learning (AML) attacks. Researchers from Texas A&M University have introduced Reactive Autoencoder Defense for Industrial Adversarial Network Threats (RADIANT), a novel IDS that mitigates AML attacks without relying on retraining. RADIANT demonstrated its robustness against adversarial threats, achieving an F1 score of 85.9% under Zeroth-Order Optimization (ZOO) attacks and 91.4% under HopSkipJump attacks.

Key Takeaways:

  • Machine learning-based IDS have enhanced operational efficiency in ICS, but face growing threats from AML attacks.
  • AML attacks exploit vulnerabilities in IDS, leading to delayed threat detection, infrastructure compromise, financial losses, and service disruptions.
  • Traditional approaches to AML attacks, such as adversarial retraining, are resource-intensive and suffer from limited generalization.
  • Reactive Autoencoder Defense for Industrial Adversarial Network Threats (RADIANT) is a novel IDS that mitigates AML attacks without retraining.
  • RADIANT reconstructs input data and analyzes three distinct reconstruction errors to reduce the impact of adversarial perturbations.
  • RADIANT outperformed state-of-the-art defenses and undefended baseline classifiers in real-world ICS data, achieving an F1 score of 85.9% under ZOO attacks and 91.4% under HopSkipJump attacks.
  • RADIANT demonstrated robustness against AML attacks, offering reliable protection for ICS while addressing the increasing sophistication of AML attacks.
  • Syed Wali, Irfan Khan, and Yasir Ali Farrukh contributed to this research, highlighting the cross-disciplinary nature of machine learning and cybersecurity.
  • This research has far-reaching implications for the development of more robust and secure machine learning-based IDS systems.

Statistics:

  • 85.9% F1 score achieved by RADIANT under Zeroth-Order Optimization (ZOO) attacks.
  • 91.4% F1 score achieved by RADIANT under HopSkipJump attacks.
  • 17.1% F1 score achieved by the baseline classifier under ZOO attacks.
  • 20.5% F1 score achieved by the baseline classifier under HopSkipJump attacks.

Sources:

  • Radiant: Reactive Autoencoder Defense for Industrial Adversarial Network Threats. Computers & Security, 2025; 154.
  • Elsevier Advanced Technology, Oxford Fulfillment Centre The Boulevard, Langford Lane, Kidlington, Oxford OX5 1GB, Oxon, England.
  • Syed Wali, Texas A&M University, Dept. of Electrical and Computer Engineering, Clean & Resilient Energy Syst Lab Cares, College Stn, TX 77843, United States.