Related Experiment Video
Updated: Jan 15, 2026

Data Communication Based on MQTT in a Polymer Extrusion Process
Published on: July 15, 2022
An Explainable Markov Chain-Machine Learning Sequential-Aware Anomaly Detection Framework for Industrial IoT Systems
Youness Ghazi1,2, Mohamed Tabaa1, Mohamed Ennaji2
1Pluridisciplinary Laboratory of Research and Innovation (LPRI), EMSI, Casablanca 20330, Morocco.
This study introduces a hybrid sequential anomaly detection pipeline for Industrial Control Systems (ICS) using OPC Unified Architecture (OPC UA). The method enhances cyberattack detection by analyzing sequential data, improving accuracy and providing explainable insights.
Area of Science:
- Cybersecurity
- Industrial Control Systems (ICS)
- Network Anomaly Detection
Background:
- Stealth attacks on ICS are hard to detect due to subtle, sequential malicious actions.
- OPC Unified Architecture (OPC UA) adoption in SCADA/ICS increases vulnerability to sophisticated cyberattacks.
- Traditional detection methods fail to capture the temporal dependencies crucial for identifying gradual intrusions.
Purpose of the Study:
- To develop a hybrid sequential anomaly detection pipeline for OPC UA environments.
- To address the limitations of traditional methods in detecting stealthy cyberattacks.
- To enhance the detection of sophisticated threats in critical infrastructures.
Main Methods:
- A hybrid pipeline combining Markov chain modeling for temporal dependencies and machine learning for anomaly detection.
- Integration of SHapley Additive exPlanations (SHAP) for explainability.
- Application of the PC algorithm for causal inference to understand attack root causes.
Main Results:
- A second-order sequential memory significantly improved detection performance.
- F1-score increased by +2.27%, precision by +2.33%, and recall by +3.02% in simulated Man-In-The-Middle (MITM) and denial-of-service (DoS) attacks.
- SHAP analysis identified key influential features and transitions, while causal graphs highlighted deviations from normal system structure.
Conclusions:
- The proposed hybrid sequential anomaly detection pipeline effectively detects stealthy cyberattacks in OPC UA systems.
- Incorporating sequential memory and explainability methods enhances detection accuracy and provides interpretable insights into attack mechanisms.
- This approach offers a more robust solution for securing critical infrastructures against evolving cyber threats.
Related Concept Videos
Sequence Networks of Rotating Machines
Zero-sequence current induces a voltage drop across the generator's neutral impedance and other...
Steps in Outbreak Investigation
Classification of Systems-I
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
Distribution Reliability and Automation
Machines: Problem Solving II
Classification of Systems-II