AI & Computational Science

AI Detects Cyberattacks on Smart Systems by Spotting Time Glitches

How the science connects

Digital twinAnomaly detectionCyber-physical sys…

AI Insight

This paper presents a framework for detecting cyber-physical attacks on Industrial Control Systems by monitoring temporal inconsistencies between physical systems and their digital twins. The method trains a predictor on normal behavior and uses multi-horizon temporal features to identify sustained deviations from expected states, without requiring labeled attack data. Testing on three ICS datasets (SWaT, HAI, and BATADAL) achieved up to 98% detection reliability with false alarm rates below 2%, even when the digital twin view was degraded through time delays or partial information loss.


This approach addresses critical infrastructure security by turning digital twin degradation from a limitation into a detection advantage. The unsupervised method could help protect industrial control systems, power grids, and water treatment facilities without needing prior knowledge of attack signatures, making it adaptable to emerging threats.


Understand the Science

Digital twin Concept coming soon Anomaly detection Concept coming soon Cyber-physical systems Concept coming soon

⚠️ Preprint – Noch nicht peer-reviewed

Dieser Artikel wurde noch nicht von unabhängigen Experten begutachtet. Die Ergebnisse sind vorläufig und sollten mit Vorsicht interpretiert werden.

Abstract: Digital Twins (DTs) are increasingly used to monitor and analyze Cyber Physical Systems (CPS). However, in adversarial environments, the fidelity of a DT cannot be assumed. Communication delays, data manipulation, sensor degradation, or partial information loss may cause the DT state to diverge from the physical process it represents. Such divergence creates temporal inconsistencies that may reveal cyber physical attacks. This paper proposes a detection framework that monitors temporal consistency between the physical system and a potentially degraded DT view. A DT predictor is trained exclusively on normal system behavior to model short-term system dynamics. During operation, discrepancies between predicted and observed states are transformed into multi-horizon temporal features capturing the magnitude, persistence, and evolution of prediction residuals. An unsupervised density model characterizes normal consistency patterns, while a sequential change detection mechanism identifies sustained deviations indicative of attacks. The approach is evaluated on three widely used Industrial Control System (ICS) datasets, SWaT, HAI, and BATADAL, under multiple DT degradation scenarios, including time desynchronization and partial observability loss. Results show that temporal inconsistency patterns enable reliable event-level attack detection with bounded false alarm rates and low detection latency. The proposed method achieves up to 98% detection reliability on SWaT and false alarm rates below 2%. Unlike conventional anomaly detection methods, the proposed framework does not require attack signatures or labeled attack data and remains effective even when the DT view is degraded. These results suggest that DT degradation, often treated as a limitation, can instead serve as a useful signal for cyber physical security monitoring.

Source: Digital Twin Degradation: Detecting Cyber Physical Attacks via Temporal Inconsistencies