article · Discover Mechanical Engineering
Modern manufacturing systems rely heavily on cyber-physical networks, making them susceptible to diverse cyber attacks. Conventional intrusion detection methods often fail when handling high-dimensional sensor readings, imbalanced data, and evolving threat patterns. To address this, a hybrid detection architecture merges dynamic feature convolution with a transformer structure. The dynamic feature convolution component uses gated convolutional layers with sigmoid and tanh activations to extract local temporal features, whilst the transformer relies on self-attention to capture long-term sequence dependencies. Evaluated on the benchmark Water Distribution dataset representing industrial attack scenarios, the model delivered consistent results across five training runs and cross-validation folds. It achieved average scores exceeding 97% for accuracy, precision, recall, and F1-score. These findings show that the hybrid model provides balanced class learning and repeatable detection performance for industrial time-series data.
Industrial facilities and manufacturing plants face rising cyber threats as operational machinery connects to digital networks. Detecting intrusions reliably without missing rare or novel attacks is difficult when dealing with massive sensor streams. This method offers a dependable way to identify malicious interference, helping operators safeguard critical infrastructure and reduce the risk of costly industrial disruptions.
The framework addresses real-time cyber intrusion monitoring for manufacturing and industrial cyber-physical systems. Prospective users include industrial plant operators and providers of operational technology cybersecurity software. Currently at an applied and tested stage using benchmark simulation data, moving toward commercial deployment would require validating the algorithm on live industrial control feeds and integrating it within existing plant monitoring platforms.
AI-generated from the published abstract. Always read the original work before citing.
Intrusion detection is essential in contemporary manufacturing systems. These are vulnerable to various cyber threats due to the integration of cyber-physical systems and continuous data exchange. Traditional intrusion detection systems include statistical models and standard machine learning (ML) approaches. They struggle with high-dimensional sensor data, imbalanced datasets, and fast-changing attack patterns. To overcome these challenges, we propose a hybrid intrusion detection model. It combines Dynamic Feature Convolution (DFC) with a Transformer-based temporal modelling structure. The DFC component uses gated convolutional layers with sigmoid and tanh activations to learn localized temporal features. The Transformer component applies self-attention mechanisms to capture long-term dependencies. This hybrid model learns both local feature dynamics and global temporal dependencies in industrial time series data. We evaluated the proposed model using the publicly available Water Distribution (WADI) dataset. This dataset simulates realistic industrial processes under both normal and attack scenarios. Experimental results demonstrate robust detection performance. Over five independent training runs and 5-fold cross-validation, the model achieved an average accuracy of 97.34% ± 0.23. It also reached a precision of 97.47% ± 0.24, a recall of 97.14% ± 0.22, and an F1-score of 97.30% ± 0.23. The close values of precision and recall, further supported by confusion matrix analysis and low variance across folds, indicate balanced class learning rather than precision inflation. These results demonstrate robust and repeatable intrusion detection performance rather than isolated success. Our findings suggest that the proposed hybrid framework offers a robust and efficient solution for real-time intrusion detection in manufacturing systems.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1007/s44245-026-00337-1
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.