Skip to main content

Lund University Publications

LUND UNIVERSITY LIBRARIES

An evaluation of deep learning-based models for intrusion detection in industrial control systems

Zamanian, Sahar LU and Kihl, Maria LU orcid (2025) 30th IEEE Symposium on Computers and Communications, ISCC 2025 In Proceedings - IEEE Symposium on Computers and Communications
Abstract

Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated... (More)

Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated Recurrent Unit (MBI-GRU) model outperforms other models in both accuracy and training efficiency.

(Less)
Please use this url to cite or link to this publication:
author
and
organization
publishing date
type
Chapter in Book/Report/Conference proceeding
publication status
published
subject
keywords
Cyber security, Deep learning, Industrial control system, Intrusion detection System, Network attack, Network flow
host publication
30th IEEE Symposium on Computers and Communications, ISCC 2025
series title
Proceedings - IEEE Symposium on Computers and Communications
pages
8 pages
publisher
IEEE - Institute of Electrical and Electronics Engineers Inc.
conference name
30th IEEE Symposium on Computers and Communications, ISCC 2025
conference location
Bologna, Italy
conference dates
2025-07-02 - 2025-07-05
external identifiers
  • scopus:105032720901
ISSN
1530-1346
DOI
10.1109/ISCC65549.2025.11325968
project
Cyber Security for Next Generation Factory (SEC4FACTORY)
Next Generation Communication and Computational Infrastructures and Applications (NextG2Com)
language
English
LU publication?
yes
additional info
Publisher Copyright: © 2025 IEEE.
id
14d51463-6eab-492f-a927-a899368a7dbd
date added to LUP
2026-04-28 14:09:11
date last changed
2026-06-23 18:09:43
@inproceedings{14d51463-6eab-492f-a927-a899368a7dbd,
  abstract     = {{<p>Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated Recurrent Unit (MBI-GRU) model outperforms other models in both accuracy and training efficiency.</p>}},
  author       = {{Zamanian, Sahar and Kihl, Maria}},
  booktitle    = {{30th IEEE Symposium on Computers and Communications, ISCC 2025}},
  issn         = {{1530-1346}},
  keywords     = {{Cyber security; Deep learning; Industrial control system; Intrusion detection System; Network attack; Network flow}},
  language     = {{eng}},
  publisher    = {{IEEE - Institute of Electrical and Electronics Engineers Inc.}},
  series       = {{Proceedings - IEEE Symposium on Computers and Communications}},
  title        = {{An evaluation of deep learning-based models for intrusion detection in industrial control systems}},
  url          = {{http://dx.doi.org/10.1109/ISCC65549.2025.11325968}},
  doi          = {{10.1109/ISCC65549.2025.11325968}},
  year         = {{2025}},
}