Related Experiment Video
Updated: Aug 30, 2025

05:11
High-precision Electromagnetic Flowmeter with Empty Pipe Detection via Complex Programmable Logic Device-based Waveform Recognition
Published on: June 27, 2025
188
Detecting and Localizing Cyber-Physical Attacks in Water Distribution Systems without Records of Labeled Attacks
Mashor Housh1, Noy Kadosh2, Jack Haddad2
1Department of Natural Resources and Environmental Management, University of Haifa, Haifa 3498838, Israel.
Sensors (Basel, Switzerland)
|August 26, 2022
Summary
This study introduces a new semi-supervised method for detecting cyber-attacks in water distribution systems (WDSs) using only normal operational data. The approach effectively identifies and locates threats without needing labeled attack examples.
Area of Science:
- Cybersecurity in critical infrastructure
- Water distribution system (WDS) operations
- Machine learning for anomaly detection
Background:
- Modern water distribution systems (WDSs) increasingly use automation for efficiency and reliability.
- Automated WDSs are vulnerable to cyber-attacks, necessitating robust detection mechanisms.
- Existing cyber-attack detection methods often require labeled attack data, which is scarce in real-world WDSs.
Purpose of the Study:
- To develop a practical cyber-attack detection and localization model for WDSs that does not rely on labeled attack data.
- To propose a semi-supervised approach utilizing only attack-free datasets for training.
- To address the challenge of detecting novel and unknown cyber threats in WDSs.
Main Methods:
- A semi-supervised learning approach is employed, trained exclusively on normal, attack-free WDS data.
- Dimensionality reduction is achieved using Maximum Canonical Correlation Analysis (MCCA).
- Cyber-attack detection and localization are performed using Support Vector Data Description (SVDD).
Main Results:
- The developed algorithm demonstrated consistently high performance in detecting cyber-attacks across multiple datasets.
- The approach proved effective in localizing cyber-attack events within the WDS.
- Validation was performed on two distinct case studies, confirming the model's robustness.
Conclusions:
- The proposed semi-supervised method offers a practical solution for cyber-attack detection in WDSs, overcoming the limitation of unavailable labeled attack data.
- The combination of MCCA and SVDD provides an effective framework for identifying and localizing cyber threats in automated WDSs.
- This approach enhances the security and reliability of critical water infrastructure against sophisticated cyber-attacks.

