{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T04:37:35Z","timestamp":1783744655052,"version":"3.55.0"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2024,3,21]],"date-time":"2024-03-21T00:00:00Z","timestamp":1710979200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,3,21]],"date-time":"2024-03-21T00:00:00Z","timestamp":1710979200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No.62072109"],"award-info":[{"award-number":["No.62072109"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003392","name":"Natural Science Foundation of Fujian Province","doi-asserted-by":"publisher","award":["No.2021J01625"],"award-info":[{"award-number":["No.2021J01625"]}],"id":[{"id":"10.13039\/501100003392","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Science and Technology project of Fujian Province","award":["No.2021HZ022007"],"award-info":[{"award-number":["No.2021HZ022007"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1007\/s11227-024-06018-8","type":"journal-article","created":{"date-parts":[[2024,3,21]],"date-time":"2024-03-21T04:01:51Z","timestamp":1710993711000},"page":"14600-14621","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Semi-supervised attack detection in industrial control systems with deviation networks and feature selection"],"prefix":"10.1007","volume":"80","author":[{"given":"Yanhua","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wentao","family":"Deng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhihuang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fanhao","family":"Zeng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,21]]},"reference":[{"issue":"11s","key":"6018_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3510410","volume":"54","author":"H Kayan","year":"2022","unstructured":"Kayan H, Nunes M, Rana O, Burnap P, Perera C (2022) Cybersecurity of industrial cyber-physical systems: a review. ACM Comput Surv (CSUR) 54(11s):1\u201335","journal-title":"ACM Comput Surv (CSUR)"},{"key":"6018_CR2","doi-asserted-by":"crossref","unstructured":"Adepu S, Palleti VR, Mishra G, Mathur A (2020) Investigation of cyber attacks on a water distribution system. In: Applied Cryptography and Network Security Workshops: ACNS 2020 Satellite Workshops, AIBlock, AIHWS, AIoTS, Cloud S &P, SCI, SecMT, and SiMLA, Rome, Italy, October 19\u201322, 2020, Proceedings 18, pp 274\u2013291. Springer","DOI":"10.1007\/978-3-030-61638-0_16"},{"issue":"8","key":"6018_CR3","doi-asserted-by":"publisher","first-page":"155014771879461","DOI":"10.1177\/1550147718794615","volume":"14","author":"Y Hu","year":"2018","unstructured":"Hu Y, Yang A, Li H, Sun Y, Sun L (2018) A survey of intrusion detection on industrial control systems. Int J Distrib Sens Netw 14(8):1550147718794615","journal-title":"Int J Distrib Sens Netw"},{"key":"6018_CR4","doi-asserted-by":"publisher","first-page":"102675","DOI":"10.1016\/j.cose.2022.102675","volume":"116","author":"Z Yang","year":"2022","unstructured":"Yang Z, Liu X, Li T, Wu D, Wang J, Zhao Y, Han H (2022) A systematic literature review of methods and datasets for anomaly-based network intrusion detection. Comput Secur 116:102675","journal-title":"Comput Secur"},{"key":"6018_CR5","doi-asserted-by":"crossref","unstructured":"Ahmed CM, MR GR, Mathur AP (2020) Challenges in machine learning based approaches for real-time anomaly detection in industrial control systems. In: Proceedings of the 6th ACM on Cyber-Physical System Security Workshop, pp 23\u201329","DOI":"10.1145\/3384941.3409588"},{"issue":"01","key":"6018_CR6","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1109\/TDSC.2021.3131531","volume":"20","author":"D Tang","year":"2023","unstructured":"Tang D, Wang X, Li X et al (2023) AKN-FGD: adaptive kohonen network based fine-grained detection of LDoS attacks. IEEE Trans Dependable Secure Comput 20(01):273\u2013287","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"4","key":"6018_CR7","doi-asserted-by":"publisher","first-page":"407","DOI":"10.3390\/electronics10040407","volume":"10","author":"S Mokhtari","year":"2021","unstructured":"Mokhtari S, Abbaspour A, Yen KK, Sargolzaei A (2021) A machine learning approach for anomaly detection in industrial control systems based on measurement data. Electronics 10(4):407","journal-title":"Electronics"},{"issue":"8","key":"6018_CR8","doi-asserted-by":"publisher","first-page":"2886","DOI":"10.3390\/s22082886","volume":"22","author":"D F\u00e4hrmann","year":"2022","unstructured":"F\u00e4hrmann D, Damer N, Kirchbuchner F, Kuijper A (2022) Lightweight long short-term memory variational auto-encoder for multivariate time series anomaly detection in industrial control systems. Sensors 22(8):2886","journal-title":"Sensors"},{"key":"6018_CR9","doi-asserted-by":"crossref","unstructured":"Kravchik M, Shabtai A (2018) Detecting cyber attacks in industrial control systems using convolutional neural networks. In: Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and Privacy, pp 72\u201383","DOI":"10.1145\/3264888.3264896"},{"key":"6018_CR10","first-page":"1","volume":"2020","author":"C Wang","year":"2020","unstructured":"Wang C, Wang B, Liu H, Qu H (2020) Anomaly detection for industrial control system based on autoencoder neural network. Wireless Commun Mobile Comput 2020:1\u201310","journal-title":"Wireless Commun Mobile Comput"},{"key":"6018_CR11","doi-asserted-by":"crossref","unstructured":"Dutta AK, Mukhoty B, Shukla SK (2021) Catchall: a robust multivariate intrusion detection system for cyber-physical systems using low rank matrix. In: Proceedings of the 2th Workshop on CPS &IoT Security and Privacy, pp 47\u201356","DOI":"10.1145\/3462633.3483978"},{"key":"6018_CR12","doi-asserted-by":"crossref","unstructured":"Ullah I, Mahmoud QH (2017) A hybrid model for anomaly-based intrusion detection in SCADA networks. In: 2017 IEEE International Conference on Big Data (Big Data), pp 2160\u20132167. IEEE","DOI":"10.1109\/BigData.2017.8258164"},{"key":"6018_CR13","doi-asserted-by":"crossref","unstructured":"Kiss I, Genge B, Haller P, Sebesty\u00e9n G (2014) Data clustering-based anomaly detection in industrial control systems. In: 2014 IEEE 10th International Conference on Intelligent Computer Communication and Processing (ICCP), pp 275\u2013281. IEEE","DOI":"10.1109\/ICCP.2014.6937009"},{"issue":"10","key":"6018_CR14","doi-asserted-by":"publisher","first-page":"8153","DOI":"10.1109\/TIE.2018.2798605","volume":"65","author":"K Huang","year":"2018","unstructured":"Huang K, Zhou C, Tian Y-C, Yang S, Qin Y (2018) Assessing the physical impact of cyberattacks on industrial cyber-physical systems. IEEE Trans Ind Electron 65(10):8153\u20138162","journal-title":"IEEE Trans Ind Electron"},{"issue":"1","key":"6018_CR15","doi-asserted-by":"publisher","first-page":"650","DOI":"10.1109\/TII.2020.2964704","volume":"17","author":"A Kavousi-Fard","year":"2020","unstructured":"Kavousi-Fard A, Su W, Jin T (2020) A machine-learning-based cyber attack detection model for wireless sensor networks in microgrids. IEEE Trans Ind Inform 17(1):650\u2013658","journal-title":"IEEE Trans Ind Inform"},{"issue":"11","key":"6018_CR16","doi-asserted-by":"publisher","first-page":"7618","DOI":"10.1109\/TII.2021.3053304","volume":"17","author":"K-D Lu","year":"2021","unstructured":"Lu K-D, Zeng G-Q, Luo X, Weng J, Luo W, Wu Y (2021) Evolutionary deep belief network for cyber-attack detection in industrial automation and control system. IEEE Trans Ind Inform 17(11):7618\u20137627","journal-title":"IEEE Trans Ind Inform"},{"issue":"1","key":"6018_CR17","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1504\/IJSNET.2021.115440","volume":"36","author":"J-Y Song","year":"2021","unstructured":"Song J-Y, Paul R, Yun J-H, Kim HC, Choi Y-J (2021) CNN-based anomaly detection for packet payloads of industrial control system. Int J Sens Netw 36(1):36\u201349","journal-title":"Int J Sens Netw"},{"key":"6018_CR18","doi-asserted-by":"publisher","first-page":"102055","DOI":"10.1016\/j.cose.2020.102055","volume":"99","author":"MG Raman","year":"2020","unstructured":"Raman MG, Dong W, Mathur A (2020) Deep autoencoders as anomaly detectors: method and case study in a distributed water treatment plant. Comput Secur 99:102055","journal-title":"Comput Secur"},{"key":"6018_CR19","doi-asserted-by":"publisher","first-page":"4303","DOI":"10.1007\/s00521-019-04363-x","volume":"32","author":"K Demertzis","year":"2020","unstructured":"Demertzis K, Iliadis L, Bougoudis I (2020) Gryphon: a semi-supervised anomaly detection system based on one-class evolving spiking neural network. Neural Comput Appl 32:4303\u20134314","journal-title":"Neural Comput Appl"},{"issue":"8","key":"6018_CR20","doi-asserted-by":"publisher","first-page":"5244","DOI":"10.1109\/TII.2019.2952917","volume":"16","author":"D Wu","year":"2019","unstructured":"Wu D, Jiang Z, Xie X, Wei X, Yu W, Li R (2019) LSTM learning with Bayesian and Gaussian processing for anomaly detection in industrial IoT. IEEE Trans Ind Inform 16(8):5244\u20135253","journal-title":"IEEE Trans Ind Inform"},{"issue":"1","key":"6018_CR21","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/TASE.2021.3073396","volume":"20","author":"W Hao","year":"2021","unstructured":"Hao W, Yang T, Yang Q (2021) Hybrid statistical-machine learning for real-time anomaly detection in industrial cyber-physical systems. IEEE Trans Autom Sci Eng 20(1):32\u201346","journal-title":"IEEE Trans Autom Sci Eng"},{"key":"6018_CR22","doi-asserted-by":"crossref","unstructured":"Yan Y, Qi L, Wang J, Lin Y, Chen L (2020) A network intrusion detection method based on stacked autoencoder and lSTM. In: ICC 2020-2020 IEEE International Conference on Communications (ICC), pp 1\u20136. IEEE","DOI":"10.1109\/ICC40277.2020.9149384"},{"key":"6018_CR23","doi-asserted-by":"publisher","first-page":"100516","DOI":"10.1016\/j.ijcip.2022.100516","volume":"38","author":"MA Umer","year":"2022","unstructured":"Umer MA, Junejo KN, Jilani MT, Mathur AP (2022) Machine learning for intrusion detection in industrial control systems: applications, challenges, and recommendations. Int J Crit Infrastruct Protect 38:100516","journal-title":"Int J Crit Infrastruct Protect"},{"key":"6018_CR24","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1016\/j.asoc.2018.04.033","volume":"69","author":"S Jadhav","year":"2018","unstructured":"Jadhav S, He H, Jenkins K (2018) Information gain directed genetic algorithm wrapper feature selection for credit rating. Appl Soft Comput 69:541\u2013553","journal-title":"Appl Soft Comput"},{"issue":"4","key":"6018_CR25","doi-asserted-by":"publisher","first-page":"2179","DOI":"10.1109\/TDSC.2021.3050101","volume":"19","author":"M Kravchik","year":"2021","unstructured":"Kravchik M, Shabtai A (2021) Efficient cyber attack detection in industrial control systems using lightweight neural networks and PCA. IEEE Trans Dependable Secure Comput 19(4):2179\u20132197","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"6018_CR26","unstructured":"Ruff L, Vandermeulen RA, G\u00f6rnitz N, Binder A, M\u00fcller E, M\u00fcller K-R, Kloft M (2019) Deep semi-supervised anomaly detection. arXiv:1906.02694"},{"key":"6018_CR27","unstructured":"Ruff L, Vandermeulen R, Goernitz N, Deecke L, Siddiqui SA, Binder A, M\u00fcller E, Kloft M (2018) Deep one-class classification. In: International Conference on Machine Learning, pp 4393\u20134402. PMLR"},{"key":"6018_CR28","doi-asserted-by":"crossref","unstructured":"Pang G, Shen C, Hengel A (2019) Deep anomaly detection with deviation networks. In: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp 353\u2013362","DOI":"10.1145\/3292500.3330871"},{"issue":"6","key":"6018_CR29","doi-asserted-by":"publisher","first-page":"2454","DOI":"10.1109\/TNNLS.2021.3086137","volume":"33","author":"Y Zhou","year":"2021","unstructured":"Zhou Y, Song X, Zhang Y, Liu F, Zhu C, Liu L (2021) Feature encoding with autoencoders for weakly supervised anomaly detection. IEEE Trans Neural Netw Learn Syst 33(6):2454\u20132465","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"issue":"11","key":"6018_CR30","doi-asserted-by":"publisher","first-page":"13122","DOI":"10.1007\/s11227-022-04390-x","volume":"78","author":"J Li","year":"2022","unstructured":"Li J, Zhang H, Liu Y, Liu Z (2022) Semi-supervised machine learning framework for network intrusion detection. J Supercomput 78(11):13122\u201313144","journal-title":"J Supercomput"},{"key":"6018_CR31","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1016\/j.comnet.2018.11.010","volume":"148","author":"F Salo","year":"2019","unstructured":"Salo F, Nassif AB, Essex A (2019) Dimensionality reduction with IG-PCA and ensemble classifier for network intrusion detection. Comput Netw 148:164\u2013175","journal-title":"Comput Netw"},{"issue":"3","key":"6018_CR32","doi-asserted-by":"publisher","first-page":"324","DOI":"10.1109\/TRO.2004.837239","volume":"21","author":"Y Li","year":"2005","unstructured":"Li Y, Liu Z (2005) Information entropy-based viewpoint planning for 3-d object reconstruction. IEEE Trans Robot 21(3):324\u2013337","journal-title":"IEEE Trans Robot"},{"issue":"1","key":"6018_CR33","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1109\/TPAMI.2004.1261097","volume":"26","author":"J Yang","year":"2004","unstructured":"Yang J, Zhang D, Frangi AF, Yang J-Y (2004) Two-dimensional PCA: a new approach to appearance-based face representation and recognition. IEEE Trans Pattern Anal Mach Intell 26(1):131\u2013137","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"issue":"2","key":"6018_CR34","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/S1525-1578(10)60455-2","volume":"5","author":"C Cheadle","year":"2003","unstructured":"Cheadle C, Vawter MP, Freed WJ, Becker KG (2003) Analysis of microarray data using z score transformation. J Mol Diagn 5(2):73\u201381","journal-title":"J Mol Diagn"},{"key":"6018_CR35","unstructured":"Morris T, Gao W (2014) Industrial control system traffic data sets for intrusion detection research. In: 8th IFIP WG 11.10 International Conference on Critical Infrastructure Protection VIII: ICCIP 2014, Arlington, VA, USA, March 17-19, 2014, Revised Selected Papers 8, pp. 65\u201378. Springer"},{"key":"6018_CR36","doi-asserted-by":"crossref","unstructured":"Goh J, Adepu S, Junejo KN, Mathur A (2017) A dataset to support research in the design of secure water treatment systems. In: 11th International Conference on Critical Information infrastructures Security: CRITIS 2016, Paris, France, October 10\u201312, 2016, Revised Selected Papers 11, pp 88\u201399. Springer","DOI":"10.1007\/978-3-319-71368-7_8"},{"key":"6018_CR37","doi-asserted-by":"crossref","unstructured":"Ahmed CM, Palleti VR, Mathur AP (2017) Wadi: a water distribution testbed for research in the design of secure cyber physical systems. In: Proceedings of the 3rd International Workshop on Cyber-Physical Systems for Smart Water Networks, pp 25\u201328","DOI":"10.1145\/3055366.3055375"},{"issue":"5","key":"6018_CR38","doi-asserted-by":"publisher","first-page":"103459","DOI":"10.1016\/j.ipm.2023.103459","volume":"60","author":"H Xu","year":"2023","unstructured":"Xu H, Wang Y, Pang G, Jian S, Liu N, Wang Y (2023) Rosas: deep semi-supervised anomaly detection with contamination-resilient continuous supervision. Inf Process Manag 60(5):103459","journal-title":"Inf Process Manag"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-024-06018-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11227-024-06018-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-024-06018-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,10]],"date-time":"2024-06-10T07:08:18Z","timestamp":1718003298000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11227-024-06018-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,21]]},"references-count":38,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2024,7]]}},"alternative-id":["6018"],"URL":"https:\/\/doi.org\/10.1007\/s11227-024-06018-8","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-3101948\/v1","asserted-by":"object"}]},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,21]]},"assertion":[{"value":"20 February 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 March 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Written informed consent for publication of this paper was obtained from Fuzhou University and all authors. The authors declare that the research in this paper is oriented toward intrusion detection in industrial control systems and does not involve any research related to ethics.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}