Related Experiment Videos
A closed-loop digital twin for cyber-physical attack analysis and anomaly detection in water distribution networks
Valentine Machaka1, Saioa Arrizabalaga2, Beñat Elduayen-Echave1
1CEIT-Basque Research and Technology Alliance (BRTA), Manuel Lardizabal 15, Donostia/San Sebastian, 20018, Basque Country, Spain; Universidad de Navarra, Tecnun, Manuel Lardizabal 13, Donostia/San Sebastian, 20018, Basque Country, Spain.
Abstract:
Water distribution networks (WDNs) are critical infrastructure governed by legacy industrial protocols and lack inherent security. Assessing exposure requires a testbed where the consequences are computed rather than scripted. Existing EPANET-based platforms declare attacks in advance as fixed perturbations because no protocol carries values that an adversary can act on. This study presents an architectural solution for WDN cybersecurity that removes EPANET's rule engine and reimplements the control logic as IEC 61131-3 programmes that communicate over Modbus/TCP within the Graphical Network Simulator-3. Under a MITRE ATT&CK for Industrial Control Systems-aligned kill chain, an adversary on a compromised device or intercepting on-path, without physical access to pumps, valves, or tanks, can drive chlorine concentrations to 20× the regulatory limit and sustain network-wide exceedance for up to 89 hours, hold tanks at capacity while starving others, and take junction pressure to zero across a distribution zone. A Sentence-BERT and k-nearest-neighbour (k-NN) detection layer is applied to live traffic: each Modbus/TCP transaction is encoded across eight behavioural dimensions, embedded into a semantic vector space, and scored by k-NN distance from a corpus of normal traffic; those beyond a calibrated threshold are declared anomalous. It runs on Wazuh and requires no labelled attack examples. Across 144,158 scored sessions spanning fourteen episodes and four phases, every attack raised a declared episode, at a macro precision of 0.844 under source-attribution labelling and a macro AUPRC of 0.739. Macro recall is 0.592 overall and 0.843 where the declared source is the attacker's own traffic, not a downstream proxy.
Related Concept Videos
Typical Model Studies
Multiple Pipe Systems
Series Configuration
In a series configuration, fluid flows sequentially from one pipe...
Dimensional Analysis
In fluid mechanics, dimensional...
Modeling and Similitude
Design Example: Analyzing Capacity Contours for Flood Risk Assessment
Design Example: Creating a Hydraulic Model of a Dam Spillway