An evaluation of deep learning-based models for intrusion detection in industrial control systems
(2025) 30th IEEE Symposium on Computers and Communications, ISCC 2025 In Proceedings - IEEE Symposium on Computers and Communications- Abstract
Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated... (More)
Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated Recurrent Unit (MBI-GRU) model outperforms other models in both accuracy and training efficiency.
(Less)
- author
- Zamanian, Sahar
LU
and Kihl, Maria
LU
- organization
-
- LTH Profile Area: AI and Digitalization
- Secure and Networked Systems
- ELLIIT: the Linköping-Lund initiative on IT and mobile communication
- Department of Electrical and Information Technology
- NEXTG2COM – a Vinnova Competence Centre in Advanced Digitalisation
- LU Profile Area: Natural and Artificial Cognition
- publishing date
- 2025
- type
- Chapter in Book/Report/Conference proceeding
- publication status
- published
- subject
- keywords
- Cyber security, Deep learning, Industrial control system, Intrusion detection System, Network attack, Network flow
- host publication
- 30th IEEE Symposium on Computers and Communications, ISCC 2025
- series title
- Proceedings - IEEE Symposium on Computers and Communications
- pages
- 8 pages
- publisher
- IEEE - Institute of Electrical and Electronics Engineers Inc.
- conference name
- 30th IEEE Symposium on Computers and Communications, ISCC 2025
- conference location
- Bologna, Italy
- conference dates
- 2025-07-02 - 2025-07-05
- external identifiers
-
- scopus:105032720901
- ISSN
- 1530-1346
- DOI
- 10.1109/ISCC65549.2025.11325968
- project
- Cyber Security for Next Generation Factory (SEC4FACTORY)
- Next Generation Communication and Computational Infrastructures and Applications (NextG2Com)
- language
- English
- LU publication?
- yes
- additional info
- Publisher Copyright: © 2025 IEEE.
- id
- 14d51463-6eab-492f-a927-a899368a7dbd
- date added to LUP
- 2026-04-28 14:09:11
- date last changed
- 2026-06-23 18:09:43
@inproceedings{14d51463-6eab-492f-a927-a899368a7dbd,
abstract = {{<p>Industrial Control Systems (ICS) have been compromised by cyber-attacks with the development of computer and network technologies over the past few decades. Intrusion Detection Systems (IDSs) play a significant role in ensuring information security, and the key mechanism is to identify various attacks in the network accurately. One common strategy when implementing an IDS is to use a machine-learning based method. In this paper, we compare five different well-known Recurrent Neural Network (RNN) models to identify the most effective approach for use in an IDS. We evaluate and compare the models using the 'ICSFlow' dataset, based on a simulation of a bottle-filling factory. Our results show that the Multi-layered Bidirectional Gated Recurrent Unit (MBI-GRU) model outperforms other models in both accuracy and training efficiency.</p>}},
author = {{Zamanian, Sahar and Kihl, Maria}},
booktitle = {{30th IEEE Symposium on Computers and Communications, ISCC 2025}},
issn = {{1530-1346}},
keywords = {{Cyber security; Deep learning; Industrial control system; Intrusion detection System; Network attack; Network flow}},
language = {{eng}},
publisher = {{IEEE - Institute of Electrical and Electronics Engineers Inc.}},
series = {{Proceedings - IEEE Symposium on Computers and Communications}},
title = {{An evaluation of deep learning-based models for intrusion detection in industrial control systems}},
url = {{http://dx.doi.org/10.1109/ISCC65549.2025.11325968}},
doi = {{10.1109/ISCC65549.2025.11325968}},
year = {{2025}},
}