{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T01:04:47Z","timestamp":1773795887682,"version":"3.50.1"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2024,3,29]],"date-time":"2024-03-29T00:00:00Z","timestamp":1711670400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,3,29]],"date-time":"2024-03-29T00:00:00Z","timestamp":1711670400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100006769","name":"Russian Science Foundation","doi-asserted-by":"publisher","award":["23-11-20024"],"award-info":[{"award-number":["23-11-20024"]}],"id":[{"id":"10.13039\/501100006769","id-type":"DOI","asserted-by":"publisher"}]},{"name":"St. Petersburg Science Foundation","award":["23-11-20024"],"award-info":[{"award-number":["23-11-20024"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"DOI":"10.1007\/s42979-024-02704-9","type":"journal-article","created":{"date-parts":[[2024,3,29]],"date-time":"2024-03-29T08:01:41Z","timestamp":1711699301000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Dataset Generation Methodology: Towards Application of Machine Learning in Industrial Water Treatment Security"],"prefix":"10.1007","volume":"5","author":[{"given":"Evgenia","family":"Novikova","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6707-9153","authenticated-orcid":false,"given":"Elena","family":"Fedorchenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexandr","family":"Danilov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Saenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,29]]},"reference":[{"key":"2704_CR1","doi-asserted-by":"publisher","unstructured":"Wu R, Keogh EJ. Current time series anomaly detection benchmarks are flawed and are creating the illusion of progress (extended abstract). In: 2022 IEEE 38th international conference on data engineering (ICDE); 2022; 1479\u20131480. https:\/\/doi.org\/10.1109\/ICDE53745.2022.00116","DOI":"10.1109\/ICDE53745.2022.00116"},{"key":"2704_CR2","doi-asserted-by":"crossref","unstructured":"Fedorchenko E, Novikova E, Danilov A, Saenko I. Towards the testbed and dataset for analysis of water treatment systems security. In: Nanda SJ, Yadav RP, Gandomi AH, Saraswat M, editors. Proceedings of ICDSA 2023. Springer; 2024","DOI":"10.1007\/978-981-99-7814-4_37"},{"key":"2704_CR3","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/j.comcom.2022.11.001","volume":"198","author":"Y Guo","year":"2023","unstructured":"Guo Y. A review of machine learning-based zero-day attack detection: challenges and future directions. Comput Commun. 2023;198:5\u2013185. https:\/\/doi.org\/10.1016\/j.comcom.2022.11.001.","journal-title":"Comput Commun"},{"key":"2704_CR4","doi-asserted-by":"crossref","unstructured":"Dong Y, Gong T, Chen H, Li C. Understanding the generalization ability of deep learning algorithms: a kernelized Renyi\u2019s entropy perspective, 2023","DOI":"10.24963\/ijcai.2023\/405"},{"key":"2704_CR5","doi-asserted-by":"crossref","unstructured":"Zhang J, Wu D, Boulet B. Time series anomaly detection for smart grids: A survey. In: 2021 IEEE electrical power and energy conference (EPEC), 2021; 125\u2013130","DOI":"10.1109\/EPEC52095.2021.9621752"},{"issue":"7","key":"2704_CR6","doi-asserted-by":"publisher","first-page":"4047","DOI":"10.1016\/j.jksuci.2020.10.005","volume":"34","author":"S Reddy","year":"2022","unstructured":"Reddy S, Shyam GK. A machine learning based attack detection and mitigation using a secure SAAS framework. J King Saud Univ-Comput Inform Sci. 2022;34(7):4047\u201361. https:\/\/doi.org\/10.1016\/j.jksuci.2020.10.005.","journal-title":"J King Saud Univ-Comput Inform Sci"},{"key":"2704_CR7","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1007\/978-3-030-52683-2_12","volume-title":"Detection of intrusions and malware, and vulnerability assessment","author":"L Leichtnam","year":"2020","unstructured":"Leichtnam L, Totel E, Prigent N, M\u00e9 L. Sec2graph: network attack detection based on novelty detection on graph structured data. In: Maurice C, Bilge L, Stringhini G, Neves N, editors. Detection of intrusions and malware, and vulnerability assessment. Cham: Springer; 2020. p. 238\u201358."},{"issue":"12","key":"2704_CR8","doi-asserted-by":"publisher","first-page":"553","DOI":"10.3390\/info13120553","volume":"13","author":"S Golubev","year":"2022","unstructured":"Golubev S, Novikova E, Fedorchenko E. Image-based approach to intrusion detection in cyber-physical objects. Information. 2022;13(12):553. https:\/\/doi.org\/10.3390\/info13120553.","journal-title":"Information"},{"key":"2704_CR9","doi-asserted-by":"publisher","first-page":"703","DOI":"10.1007\/978-3-030-30490-4_56","volume-title":"Artificial neural networks and machine learning-ICANN 2019: text and time series","author":"D Li","year":"2019","unstructured":"Li D, Chen D, Jin B, Shi L, Goh J, Ng S-K. Mad-GAN: Multivariate anomaly detection for time series data with generative adversarial networks. In: Tetko IV, K\u016frkov\u00e1 V, Karpov P, Theis F, editors. Artificial neural networks and machine learning-ICANN 2019: text and time series. Cham: Springer; 2019. p. 703\u201316."},{"key":"2704_CR10","unstructured":"Shalyga D, Filonov P, Lavrentyev A: Anomaly detection for water treatment system based on neural network with automatic architecture optimization; 2018; CoRR abs\/1807.07282arXiv:1807.07282"},{"key":"2704_CR11","doi-asserted-by":"publisher","first-page":"8897926","DOI":"10.1155\/2020\/8897926","volume":"2020","author":"C Wang","year":"2020","unstructured":"Wang C, Wang B, Liu H, Qu H. Anomaly detection for industrial control system based on autoencoder neural network. Wirel Commun Mob Comput. 2020;2020:8897926\u20131889792610.","journal-title":"Wirel Commun Mob Comput"},{"key":"2704_CR12","doi-asserted-by":"publisher","unstructured":"Su Y, Zhao Y, Niu C, Liu R, Sun W, Pei D. Robust anomaly detection for multivariate time series through stochastic recurrent neural network. In: Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining. KDD \u201919, pp. 2828\u20132837. Association for Computing Machinery, New York, NY, USA; 2019. https:\/\/doi.org\/10.1145\/3292500.3330672 .","DOI":"10.1145\/3292500.3330672"},{"key":"2704_CR13","doi-asserted-by":"publisher","unstructured":"Audibert J, Michiardi P, Guyard F, Marti S, Zuluaga MA. Usad: Unsupervised anomaly detection on multivariate time series. In: Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. KDD \u201920, pp. 3395\u20133404. Association for Computing Machinery, New York, NY, USA (2020). https:\/\/doi.org\/10.1145\/3394486.3403392 .","DOI":"10.1145\/3394486.3403392"},{"key":"2704_CR14","unstructured":"Xia F, Chen X, Yu S, Hou M, Liu M, You L. Coupled attention networks for multivariate time series anomaly detection. Accessed 13 Jul 2023; 2023. arXiv:2306.07114"},{"key":"2704_CR15","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1007\/978-3-319-71368-7_8","volume-title":"Critical information infrastructures security","author":"J Goh","year":"2017","unstructured":"Goh J, Adepu S, Junejo KN, Mathur A. A dataset to support research in the design of secure water treatment systems. In: Havarneanu G, Setola R, Nassopoulos H, Wolthusen S, editors. Critical information infrastructures security. Cham: Springer; 2017. p. 88\u201399."},{"key":"2704_CR16","unstructured":"Xia F, Chen X, Yu S, Hou M, Liu M, You L. Water distribution (WADI) dataset. Accessed 13 Jul 2023; 2023. https:\/\/itrust.sutd.edu.sg\/itrust-labs-home\/itrust-labs_wadi\/"},{"key":"2704_CR17","doi-asserted-by":"publisher","DOI":"10.1145\/3453155","author":"Y Luo","year":"2021","unstructured":"Luo Y, Xiao Y, Cheng L, Peng G, Yao DD. Deep learning-based anomaly detection in cyber-physical systems: progress and opportunities. ACM Comput Surv. 2021. https:\/\/doi.org\/10.1145\/3453155.","journal-title":"ACM Comput Surv"},{"key":"2704_CR18","doi-asserted-by":"publisher","unstructured":"Inoue J, Yamagata Y, Chen Y, Poskitt CM, Sun J. Anomaly detection for a water treatment system using unsupervised machine learning. In: 2017 IEEE international conference on data mining workshops (ICDMW), 2017; pp. 1058\u20131065. https:\/\/doi.org\/10.1109\/ICDMW.2017.149","DOI":"10.1109\/ICDMW.2017.149"},{"key":"2704_CR19","doi-asserted-by":"publisher","first-page":"36639","DOI":"10.1109\/ACCESS.2020.2975066","volume":"8","author":"M Elnour","year":"2020","unstructured":"Elnour M, Meskin N, Khan K, Jain R. A dual-isolation-forests-based attack detection framework for industrial control systems. IEEE Access. 2020;8:36639\u201351. https:\/\/doi.org\/10.1109\/ACCESS.2020.2975066.","journal-title":"IEEE Access"},{"key":"2704_CR20","doi-asserted-by":"publisher","unstructured":"Hundman K, Constantinou V, Laporte C, Colwell I, Soderstrom T. Detecting spacecraft anomalies using lstms and nonparametric dynamic thresholding. In: Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining. KDD \u201918, pp. 387\u2013395. Association for Computing Machinery, New York, NY, USA; 2018. https:\/\/doi.org\/10.1145\/3219819.3219845 .","DOI":"10.1145\/3219819.3219845"},{"key":"2704_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2021.301198","volume":"37","author":"N Neshenko","year":"2021","unstructured":"Neshenko N, Bou-Harb E, Furht B. A behavioral-based forensic investigation approach for analyzing attacks on water plants using GANs. Forensic Sci Int Dig Investig. 2021;37: 301198. https:\/\/doi.org\/10.1016\/j.fsidi.2021.301198.","journal-title":"Forensic Sci Int Dig Investig"},{"key":"2704_CR22","doi-asserted-by":"publisher","unstructured":"Lin Q, Adepu S, Verwer S, Mathur A. Tabor: A graphical model-based approach for anomaly detection in industrial control systems. In: Proceedings of the 2018 on Asia conference on computer and communications security. ASIACCS \u201918, pp. 525\u2013536. Association for computing machinery, New York, NY, USA; 2018. https:\/\/doi.org\/10.1145\/3196494.3196546 .","DOI":"10.1145\/3196494.3196546"},{"issue":"9","key":"2704_CR23","doi-asserted-by":"publisher","first-page":"4207","DOI":"10.3390\/s23094207","volume":"23","author":"C Goetz","year":"2023","unstructured":"Goetz C, Humm B. Decentralized real-time anomaly detection in cyber-physical production systems under industry constraints. Sensors. 2023;23(9):4207. https:\/\/doi.org\/10.3390\/s23094207.","journal-title":"Sensors"},{"issue":"8","key":"2704_CR24","doi-asserted-by":"publisher","first-page":"3910","DOI":"10.3390\/s23083910","volume":"23","author":"Z Xu","year":"2023","unstructured":"Xu Z, Yang Y, Gao X, Hu M. Dcff-mtad: a multivariate time-series anomaly detection model based on dual-channel feature fusion. Sensors. 2023;23(8):3910. https:\/\/doi.org\/10.3390\/s23083910.","journal-title":"Sensors"},{"key":"2704_CR25","doi-asserted-by":"publisher","unstructured":"Oliveira N, Sousa N, Oliveira J, Pra\u00e7a I. Anomaly detection in cyber-physical systems: Reconstruction of a prediction error feature space. In: 2021 14th International Conference on Security of Information and Networks (SIN), 2021; vol. 1, pp. 1\u20135. https:\/\/doi.org\/10.1109\/SIN54109.2021.9699339","DOI":"10.1109\/SIN54109.2021.9699339"},{"key":"2704_CR26","doi-asserted-by":"publisher","first-page":"115179","DOI":"10.1109\/ACCESS.2022.3218624","volume":"10","author":"E Aboah Boateng","year":"2022","unstructured":"Aboah Boateng E, Bruce JW, Talbert DA. Anomaly detection for a water treatment system based on one-class neural network. IEEE Access. 2022;10:115179\u201391. https:\/\/doi.org\/10.1109\/ACCESS.2022.3218624.","journal-title":"IEEE Access"},{"issue":"4","key":"2704_CR27","doi-asserted-by":"publisher","first-page":"1096","DOI":"10.3390\/s18041096","volume":"18","author":"Z Wu","year":"2018","unstructured":"Wu Z, Guo Y, Lin W, Yu S, Ji Y. A weighted deep representation learning model for imbalanced fault diagnosis in cyber-physical systems. Sensors. 2018;18(4):1096. https:\/\/doi.org\/10.3390\/s18041096.","journal-title":"Sensors"},{"key":"2704_CR28","unstructured":"PHM Data Challenge. figshare https:\/\/phmsociety.org\/conference\/annual-conference-of-the-phm-society\/annual-conference-of-the-prognostics-and-health-management-society-2015\/phm-data-challenge-3\/ (2015)"},{"key":"2704_CR29","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1016\/j.neucom.2019.07.034","volume":"363","author":"M Canizo","year":"2019","unstructured":"Canizo M, Triguero I, Conde A, Onieva E. Multi-head CNN\u2013RNN for multi-time series anomaly detection: an industrial case study. Neurocomputing. 2019;363:246\u201360. https:\/\/doi.org\/10.1016\/j.neucom.2019.07.034.","journal-title":"Neurocomputing"},{"issue":"4","key":"2704_CR30","doi-asserted-by":"publisher","first-page":"407","DOI":"10.3390\/electronics10040407","volume":"10","author":"S Mokhtari","year":"2021","unstructured":"Mokhtari S, Abbaspour A, Yen KK, Sargolzaei A. A machine learning approach for anomaly detection in industrial control systems based on measurement data. Electronics. 2021;10(4):407.","journal-title":"Electronics"},{"key":"2704_CR31","unstructured":"Shin H-K, Lee W, Yun J-H, Kim H. Hai 1.0: Hil-based augmented ics security dataset. In: Proceedings of the 13th USENIX conference on cyber security experimentation and test, 2020; pp. 1\u20131"},{"issue":"6","key":"2704_CR32","doi-asserted-by":"publisher","first-page":"1976","DOI":"10.3390\/s21061976","volume":"21","author":"S Park","year":"2021","unstructured":"Park S, Lee K. Improved mitigation of cyber threats in IIoT for smart cities: a new-era approach and scheme. Sensors. 2021;21(6):1976.","journal-title":"Sensors"},{"issue":"4","key":"2704_CR33","first-page":"1011","volume":"24","author":"X Bian","year":"2020","unstructured":"Bian X. Detecting anomalies in time-series data using unsupervised learning and analysis on infrequent signatures. J IKEEE. 2020;24(4):1011\u20136.","journal-title":"J IKEEE"},{"issue":"4","key":"2704_CR34","doi-asserted-by":"publisher","first-page":"2248","DOI":"10.1109\/COMST.2021.3094360","volume":"23","author":"M Conti","year":"2021","unstructured":"Conti M, Donadel D, Turrin F. A survey on industrial control system testbeds and datasets for security research. IEEE Commun Surv Tutor. 2021;23(4):2248\u201394. https:\/\/doi.org\/10.1109\/COMST.2021.3094360.","journal-title":"IEEE Commun Surv Tutor"},{"key":"2704_CR35","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102810","volume":"120","author":"JL Guerra","year":"2022","unstructured":"Guerra JL, Catania C, Veas E. Datasets are not enough: challenges in labeling network traffic. Comput Secur. 2022;120: 102810. https:\/\/doi.org\/10.1016\/j.cose.2022.102810.","journal-title":"Comput Secur"},{"issue":"2","key":"2704_CR36","doi-asserted-by":"publisher","first-page":"85","DOI":"10.3390\/a16020085","volume":"16","author":"O Tushkanova","year":"2023","unstructured":"Tushkanova O, Levshun D, Branitskiy A, Fedorchenko E, Novikova E, Kotenko I. Detection of cyberattacks and anomalies in cyber-physical systems: approaches, data sources, evaluation. Algorithms. 2023;16(2):85. https:\/\/doi.org\/10.3390\/a16020085.","journal-title":"Algorithms"},{"key":"2704_CR37","unstructured":"Lemay A, Fernandez JM. Providing scada network data sets for intrusion detection research. In: Proceedings of the 9th USENIX conference on cyber security experimentation and test. CSET\u201916, p. 6. USENIX Association, USA; 2016"},{"issue":"8","key":"2704_CR38","doi-asserted-by":"publisher","first-page":"116","DOI":"10.3390\/pr6080116","volume":"6","author":"GZ Kyzas","year":"2018","unstructured":"Kyzas GZ, Matis KA. Flotation in water and wastewater treatment. Processes. 2018;6(8):116. https:\/\/doi.org\/10.3390\/pr6080116.","journal-title":"Processes"},{"key":"2704_CR39","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1016\/j.watres.2017.07.005","volume":"123","author":"J Talvitie","year":"2017","unstructured":"Talvitie J, Mikola A, Koistinen A, Set\u00e4l\u00e4 O. Solutions to microplastic pollution-removal of microplastics from wastewater effluent with advanced wastewater treatment technologies. Water Res. 2017;123:401\u20137. https:\/\/doi.org\/10.1016\/j.watres.2017.07.005.","journal-title":"Water Res"},{"key":"2704_CR40","first-page":"905","volume":"60","author":"I Jovanovi\u0107","year":"2015","unstructured":"Jovanovi\u0107 I, Miljanovi\u0107 I. Modelling of flotation processes by classical mathematical methods\u2014a review. Arch Min Sci. 2015;60:905\u201319.","journal-title":"Arch Min Sci"},{"key":"2704_CR41","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2022.103611","volume":"137","author":"M Jbair","year":"2022","unstructured":"Jbair M, Ahmad B, Maple C, Harrison R. Threat modelling for industrial cyber physical systems in the era of smart manufacturing. Comput Ind. 2022;137: 103611. https:\/\/doi.org\/10.1016\/j.compind.2022.103611.","journal-title":"Comput Ind"},{"key":"2704_CR42","doi-asserted-by":"publisher","unstructured":"Adepu S, Mathur A. Generalized attacker and attack models for cyber physical systems. In: 2016 IEEE 40th annual computer software and applications conference (COMPSAC), 2016; vol. 1, pp. 283\u2013292. https:\/\/doi.org\/10.1109\/COMPSAC.2016.122","DOI":"10.1109\/COMPSAC.2016.122"},{"key":"2704_CR43","doi-asserted-by":"publisher","first-page":"784","DOI":"10.1109\/JAS.2022.105548","volume":"9","author":"W Duso","year":"2022","unstructured":"Duso W, Zhou M, Abusorrah A. A survey of cyber attacks on cyber physical systems: recent advances and challenges. IEEE\/CAA J Automatica Sinica. 2022;9:784. https:\/\/doi.org\/10.1109\/JAS.2022.105548.","journal-title":"IEEE\/CAA J Automatica Sinica"},{"key":"2704_CR44","doi-asserted-by":"publisher","unstructured":"Peng Y, Wang Y, Xiang C, Liu X, Wen Z, Chen D, Zhang C. Cyber-physical attack-oriented industrial control systems (ics) modeling, analysis and experiment environment. In: 2015 International Conference on Intelligent Information Hiding and Multimedia Signal Processing (IIH-MSP), 2015; pp. 322\u2013326.https:\/\/doi.org\/10.1109\/IIH-MSP.2015.110","DOI":"10.1109\/IIH-MSP.2015.110"},{"key":"2704_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103028","volume":"125","author":"M Alanazi","year":"2023","unstructured":"Alanazi M, Mahmood A, Chowdhury MJM. Scada vulnerabilities and attacks: a review of the state-of-the-art and open issues. Comput Secur. 2023;125: 103028. https:\/\/doi.org\/10.1016\/j.cose.2022.103028.","journal-title":"Comput Secur"}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-024-02704-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-024-02704-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-024-02704-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,29]],"date-time":"2024-03-29T08:18:22Z","timestamp":1711700302000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-024-02704-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,29]]},"references-count":45,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,4]]}},"alternative-id":["2704"],"URL":"https:\/\/doi.org\/10.1007\/s42979-024-02704-9","relation":{},"ISSN":["2661-8907"],"issn-type":[{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,29]]},"assertion":[{"value":"3 November 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 February 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 March 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to Participate"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for Publication"}}],"article-number":"373"}}