MARATTO

article · IEEE Access

CPS-IIoT-P2Attention: Explainable Privacy-Preserving With Scaled Dot-Product Attention in Cyber-Physical System-Industrial IoT Network

202533 citationsOpen accessNorth-West University

In plain language

Industrial cyber-physical networks and Internet of Things environments face rising security threats, where a vulnerability in a single device can risk entire operational systems. A new framework addresses these challenges by combining privacy-preserving data processing with deep learning to detect cyber-attacks. The architecture uses Pearson correlation and agglomerative clustering alongside bidirectional long short-term memory networks and a scaled dot-product attention mechanism. This setup dynamically allocates computational focus to network traffic segments most likely to contain anomalies. Model decisions are made interpretable through explainable artificial intelligence techniques using SHAP values. Evaluated on benchmark datasets and an industrial emulation testbed, the system achieved over 99.9% accuracy on realistic industrial data. While it demands 11% more energy than lightweight alternatives such as TinyLSTM, it delivers improved accuracy suited for critical infrastructure.

Key takeaways

  • The system pairs agglomerative clustering and Pearson correlation with bidirectional LSTM networks and scaled dot-product attention to detect industrial cyber-attacks while preserving privacy.
  • Explainable artificial intelligence via SHAP values was incorporated to make network intrusion detections interpretable and reliable.
  • Testing on the realistic X-IIoTID dataset demonstrated 99.99% accuracy and a 100% area under the curve.
  • Validation on a simulated industrial facility testbed confirmed the model achieved 2.7% higher accuracy than TinyLSTM at an 11% higher energy cost.

Why it matters

Modern factories and infrastructure depend on interconnected devices where a single compromised sensor can trigger widespread failures. Detecting attacks without exposing sensitive operational data or overwhelming network resources is vital. By combining privacy safeguards with explainable threat detection, this approach gives operators clearer insights into potential attacks, helping safeguard critical industrial operations against sophisticated disruptions.

Commercialisation angle

The framework is designed for industrial facilities and critical infrastructure operators running cyber-physical Internet of Things networks. Potential applications include automated threat detection and network traffic monitoring. Having been validated as a proof of concept on an emulation testbed and benchmark datasets, the technology sits at an applied research stage. Further testing in live, operational production settings would be required before commercial deployment.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

The field of Cyber-Physical Industrial Internet of Things (CPS-IIoT) is rapidly developing, raising significant concerns about cyber-attacks due to the susceptibility of its devices and networking protocols. A breach in one device can compromise the entire system, necessitating robust security solutions. Existing methods fail to address the diversity and compatibility of CPS-IIoT environments. In this research, we propose a new privacy-preservation via Pearson correlation coefficient and agglomerative clustering with Bidirectional long short-term memory (BiLSTM) integrated with a scaled dot-product attention for cyber-attacks detection in CPS-IIoT. The inclusion of agglomerative clustering and scaled dot product attention mechanism in our proposed system is a unique characteristic, specifically tailored for CPS-IIoT contexts. These mechanisms adaptively modify their emphasis to prioritize crucial features within the CPS-IIoT network traffic data, providing additional computational resources to data segments that are likely to include abnormalities and patterns that indicate security issues. This research is the first to investigate cyber-threats within CPS-Industrial IoT. We evaluated the performance of our proposed model by conducting experiments on two relevant datasets: UNSW-NB15, and a novel IIoT dataset named X-IIoTID. The X-IIoTID is a versatile intrusion data designed to accommodate the diversity and compatibility of Industrial IoT systems, regardless of their connectivity and device specifications. The data encompasses the actions of emerging IIoT connectivity protocols, recent device activities, a range of attack types and situations, as well as multiple attack protocols. We used a CPS-IIoT testbed that emulates a real industrial facility to demonstrate our proof of concept. Our system exhibits outstanding performance attaining 99.60% of accuracy, 100% of AUC, 97.98% of recall, 100% of precision, F1 of 98.23%, kappa of 96.07%, and Mathew correlation coefficient of 96.54% on UNSW-NB15. On the representative and realistic X-IIoTID data, our proposed system exhibits outstanding performance attaining 99.99% of accuracy, 100% of AUC, recall of 99.97%, 99.98% of precision, 99.87% of F1-score, 99.97% of kappa, and Mathew correlation coefficient of 99.98%. Additionally, we design SHAPley Additive exPlanations from eXplainable AI to enhance our proposed model interpretability and reliability. The findings revealed that the scaled dot product attention mechanism dramatically boosts model performance, while Pearson correlation and agglomerative clustering safeguard data privacy in CPS-IIoT, surpassing the performance of existing state-of-the-art (SOTA) models. Our model achieves 2.7% higher accuracy than TinyLSTM at only 11% higher energy cost, justifying its use in accuracy-critical CPS-IIoT scenarios.

Research topics

  • Privacy-Preserving Technologies in Data
  • Adversarial Robustness in Machine Learning

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/access.2025.3566980

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.