{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T16:11:58Z","timestamp":1786983118466,"version":"3.56.0"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T00:00:00Z","timestamp":1748390400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T00:00:00Z","timestamp":1748390400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"DOI":"10.1007\/s42979-025-04028-8","type":"journal-article","created":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T08:37:20Z","timestamp":1748421440000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["ESML: A Hyperparameter-Tuned Stacking Machine Learning Approach for Anomaly Attack Detection in Water Distribution Systems"],"prefix":"10.1007","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6417-5414","authenticated-orcid":false,"given":"Jaykumar","family":"Lachure","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rajesh","family":"Doriya","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,5,28]]},"reference":[{"key":"4028_CR1","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1016\/j.iotcps.2021.12.002","volume":"1","author":"AK Tyagi","year":"2021","unstructured":"Tyagi AK, Sreenath N. Cyber physical systems: analyses, challenges and possible solutions. Internet Things Cyber-Phys Systems. 2021;1:22\u201333.","journal-title":"Internet Things Cyber-Phys Systems."},{"key":"4028_CR2","doi-asserted-by":"publisher","first-page":"103201","DOI":"10.1016\/j.micpro.2020.103201","volume":"77","author":"JPA Yaacoub","year":"2020","unstructured":"Yaacoub JPA, Salman O, Noura HN, Kaaniche N, Chehab A, Malli M. Cyber-physical systems security: limitations, issues and future trends. Microprocessors Microsyst. 2020;77:103201.","journal-title":"Microprocessors Microsyst."},{"issue":"1","key":"4028_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13673-019-0175-8","volume":"9","author":"DT Ramotsoela","year":"2019","unstructured":"Ramotsoela DT, Hancke GP, Abu-Mahfouz AM. Attack detection in water distribution systems using machine learning. Hum-Centric Comput Inf Sci. 2019;9(1):1\u201322.","journal-title":"Hum-Centric Comput Inf Sci."},{"issue":"9","key":"4028_CR4","doi-asserted-by":"publisher","first-page":"4207","DOI":"10.3390\/s23094207","volume":"23","author":"C Goetz","year":"2023","unstructured":"Goetz C, Humm B. Decentralized real-time anomaly detection in cyber-physical production systems under industry constraints. Sensors. 2023;23(9):4207.","journal-title":"Sensors."},{"issue":"8","key":"4028_CR5","doi-asserted-by":"publisher","first-page":"04018048","DOI":"10.1061\/(ASCE)WR.1943-5452.0000969","volume":"144","author":"R Taormina","year":"2018","unstructured":"Taormina R, Galelli S, Tippenhauer NO, Salomons E, Ostfeld A, Eliades DG, et al. Battle of the attack detection algorithms: disclosing cyber attacks on water distribution networks. J Water Resour Plann Manag. 2018;144(8):04018048.","journal-title":"J Water Resour Plann Manag."},{"key":"4028_CR6","doi-asserted-by":"crossref","unstructured":"Sahin AK, \u00c7avdar B, Dogan R\u00d6, Ayas S, Ozgenc B, Ayas MS. A hybrid CNN-LSTM framework for unsupervised anomaly detection in water distribution plant. In: 2023 Innovations in Intelligent Systems and Applications Conference (ASYU); 2023. p. 1\u20136.","DOI":"10.1109\/ASYU58738.2023.10296546"},{"key":"4028_CR7","doi-asserted-by":"crossref","unstructured":"Park JH, Kim B, Kim H. MENDEL: Time series anomaly detection using transfer learning for industrial control systems. In: 2023 IEEE international conference on Big Data and Smart Computing (BigComp); 2023. p. 261\u2013268.","DOI":"10.1109\/BigComp57234.2023.00049"},{"key":"4028_CR8","doi-asserted-by":"crossref","unstructured":"Li Z, Yang Z, Tang D, Peng S, Li J. Anomaly detection for process industry using class-dependent temperatures loss. In: 2023 8th International Conference on Computer and Communication Systems (ICCCS); 2023. p. 1180\u20131184.","DOI":"10.1109\/ICCCS57501.2023.10150495"},{"key":"4028_CR9","unstructured":"Meza GR, Carre\u00f1o-Alvarado E, Hern\u00e1ndez-Alba M. Multi-objective insights and analysis on data driven classifiers for anomaly detection in water distribution systems. In: Proceedings\u20142nd International Joint Conference on Water Distribution System Analysis (WDSA) & Computing and Control in the Water Industry (CCWI); 2022."},{"key":"4028_CR10","doi-asserted-by":"publisher","DOI":"10.3390\/w16141935","author":"K Joseph","year":"2024","unstructured":"Joseph K, Shetty J, Sharma AK, van Staden R, Wasantha P, Small S, et al. Leak and burst detection in water distribution network using logic- and machine learning-based approaches. Water. 2024. https:\/\/doi.org\/10.3390\/w16141935.","journal-title":"Water."},{"key":"4028_CR11","doi-asserted-by":"crossref","unstructured":"Chien WC, Wang SD. Anomaly detection for multivariate industrial sensor data via decoupled generative adversarial network. In: 2023 IEEE International Conference on Artificial Intelligence and Big Data (ICAIBD); 2023. p. 1028\u20131035.","DOI":"10.5220\/0011894100003393"},{"key":"4028_CR12","doi-asserted-by":"crossref","unstructured":"Zhang Y, Li B, Zhang X. Deep learning-based anomaly detection for time-series data in industrial control systems. In: 2023 42nd Chinese Control Conference (CCC); 2023. p. 8825\u20138829.","DOI":"10.23919\/CCC58697.2023.10241095"},{"key":"4028_CR13","doi-asserted-by":"publisher","first-page":"1633","DOI":"10.3390\/W13121633","volume":"13","author":"E Apostol","year":"2021","unstructured":"Apostol E, Truic\u00e4 CO, Pop F, Esposito C. Change point enhanced anomaly detection for IoT time series data. Water. 2021;13:1633. https:\/\/doi.org\/10.3390\/W13121633.","journal-title":"Water."},{"key":"4028_CR14","doi-asserted-by":"publisher","first-page":"4149","DOI":"10.1109\/TCSS.2024.3360435","volume":"11","author":"L Xu","year":"2024","unstructured":"Xu L, Han Z, Wang Z, Zhao D. Finding component relationships: a deep-learning-based anomaly detection interpreter. IEEE Trans Comput Soc Syst. 2024;11:4149\u201362. https:\/\/doi.org\/10.1109\/TCSS.2024.3360435.","journal-title":"IEEE Trans Comput Soc Syst."},{"key":"4028_CR15","doi-asserted-by":"crossref","unstructured":"Sinha R, Agrawal P, Rasool A. Hyperparameter tuned cloud based cyber physical attack detection using stacking ensemble learning. In: 2024 IEEE International Students\u2019 Conference on Electrical, Electronics and Computer Science (SCEECS); 2024. p. 1\u20136.","DOI":"10.1109\/SCEECS61402.2024.10482067"},{"key":"4028_CR16","doi-asserted-by":"publisher","DOI":"10.3390\/electronics13050939","author":"G Incorvaia","year":"2024","unstructured":"Incorvaia G, Hond D, Asgari H. Uncertainty quantification of machine learning model performance via anomaly-based dataset dissimilarity measures. Electronics. 2024. https:\/\/doi.org\/10.3390\/electronics13050939.","journal-title":"Electronics."},{"key":"4028_CR17","doi-asserted-by":"crossref","unstructured":"\u00d6zgen\u00e7 B, Ayas S, Do\u011fan R\u00d6, \u00c7avdar B, \u015eahin AK, Ayas M\u015e, Anomaly detection in predicted water treatment data using hybrid CNN-LSTM network model. In: 2023 31st Signal Processing and Communications Applications Conference (SIU). IEEE; 2023. p. 1\u20134.","DOI":"10.1109\/SIU59756.2023.10223947"},{"key":"4028_CR18","doi-asserted-by":"publisher","first-page":"818","DOI":"10.3390\/sym13050818","volume":"13","author":"E Dogo","year":"2021","unstructured":"Dogo E, Nwulu N, Twala B, Aigbavboa C. Accessing imbalance learning using dynamic selection approach in water quality anomaly detection. Symmetry. 2021;13:818. https:\/\/doi.org\/10.3390\/sym13050818.","journal-title":"Symmetry."},{"key":"4028_CR19","unstructured":"Khoa TD. Anomaly detection and inlet pressure prediction in water distribution systems using machine learning. In: 2024 International Conference on Machine Learning and Intelligent Systems; 2024."},{"key":"4028_CR20","doi-asserted-by":"publisher","first-page":"102055","DOI":"10.1016\/j.cose.2020.102055","volume":"99","author":"MG Raman","year":"2020","unstructured":"Raman MG, Dong W, Mathur A. Deep autoencoders as anomaly detectors: method and case study in a distributed water treatment plant. Comput Secur. 2020;99:102055.","journal-title":"Comput Secur."},{"key":"4028_CR21","doi-asserted-by":"crossref","unstructured":"Ahmed CM, et\u00a0al. WADI: a water distribution testbed for research in the design of secure cyber-physical systems. In: Proceedings of the 3rd international workshop on cyber-physical systems for smart water networks; 2017.","DOI":"10.1145\/3055366.3055375"},{"issue":"3","key":"4028_CR22","doi-asserted-by":"publisher","first-page":"4815","DOI":"10.1109\/JIOT.2018.2871719","volume":"6","author":"N Moustafa","year":"2018","unstructured":"Moustafa N, Turnbull B, Choo KKR. An ensemble intrusion detection technique based on proposed statistical flow features for protecting network traffic of internet of things. IEEE Internet Things J. 2018;6(3):4815\u201330.","journal-title":"IEEE Internet Things J."},{"issue":"4","key":"4028_CR23","doi-asserted-by":"publisher","first-page":"2179","DOI":"10.1109\/TDSC.2021.3050101","volume":"19","author":"M Kravchik","year":"2022","unstructured":"Kravchik M, Shabtai A. Efficient cyber attack detection in industrial control systems using lightweight neural networks and PCA. IEEE Trans Depend Secure Comput. 2022;19(4):2179\u201397.","journal-title":"IEEE Trans Depend Secure Comput."},{"issue":"2","key":"4028_CR24","first-page":"1117","volume":"10","author":"M Abdelaty","year":"2022","unstructured":"Abdelaty M, Doriguzzi-Corin R, Siracusa D. DAICS: a deep learning solution for anomaly detection in industrial control systems. IEEE Trans Emerg Top Comput. 2022;10(2):1117\u201329.","journal-title":"IEEE Trans Emerg Top Comput."},{"key":"4028_CR25","volume-title":"Handbook of Big Data Analytics and Forensics","author":"AC Chen","year":"2022","unstructured":"Chen AC, Wulff K. Adaptive neural trees for attack detection in cyber physical systems. In: Choo KKR, Dehghantanha A, editors. Handbook of Big Data Analytics and Forensics. Berlin: Springer; 2022."},{"key":"4028_CR26","doi-asserted-by":"publisher","first-page":"106946","DOI":"10.1016\/j.comnet.2019.106946","volume":"165","author":"MR Asghar","year":"2019","unstructured":"Asghar MR. Cybersecurity in industrial control systems: issues, technologies, and challenges. Comput Netw. 2019;165:106946.","journal-title":"Comput Netw."},{"issue":"3","key":"4028_CR27","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1109\/MSP.2011.67","volume":"9","author":"R Langner","year":"2011","unstructured":"Langner R. Stuxnet: dissecting a cyberwarfare weapon. IEEE Secur Priv. 2011;9(3):49\u201351.","journal-title":"IEEE Secur Priv."},{"key":"4028_CR28","unstructured":"ICS-CERT Alert. Cyber-attack against Ukrainian Critical Infrastructure. Cybersecurity and Infrastructure Security Agency, Washington, DC, USA; 2016. ICS Alert (IR-ALERT-H-16-056-01)."},{"key":"4028_CR29","unstructured":"Roberts P. Cyberattacks inflict massive damage on German steel factory. (accessed: February 2021). https:\/\/securityledger.com\/2014\/12\/cyberattack-inflicts-massive-damage-on-german-steel-factory\/."},{"key":"4028_CR30","doi-asserted-by":"publisher","first-page":"9150965","DOI":"10.1155\/2017\/9150965","volume":"2017","author":"M Iturbe","year":"2017","unstructured":"Iturbe M. Towards large-scale, heterogeneous anomaly detection systems in industrial networks: a survey of current trends. Secur Commun Netw. 2017;2017:9150965.","journal-title":"Secur Commun Netw."},{"issue":"6","key":"4028_CR31","first-page":"1793","volume":"2","author":"K Karthikeyan","year":"2010","unstructured":"Karthikeyan K, Indra A. Intrusion detection tools and techniques\u2014a survey. Int J Comput Theory Eng. 2010;2(6):1793\u20138201.","journal-title":"Int J Comput Theory Eng."},{"key":"4028_CR32","unstructured":"Pranggono B, McLaughlin K. Intrusion detection systems for critical infrastructure. In: The state of the art in intrusion prevention and detection. London: CRC Press; 2014. p. 150\u2013170."},{"issue":"7","key":"4028_CR33","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1016\/j.cose.2006.03.001","volume":"25","author":"VM Igure","year":"2006","unstructured":"Igure VM, Laughter SA, Williams RD. Security issues in SCADA networks. Computers & Security. 2006;25(7):498\u2013506.","journal-title":"Computers & Security."},{"key":"4028_CR34","unstructured":"Yeo LH, Che X, Lakkaraju S. Understanding modern intrusion detection systems: a survey. arXiv preprint arXiv:1708.07174; 2017."},{"key":"4028_CR35","volume-title":"Snort 2.1 Intrusion detection","author":"B Caswell","year":"2004","unstructured":"Caswell B, Beale J. Snort 2.1 Intrusion detection. Amsterdam: Elsevier; 2004."},{"issue":"6","key":"4028_CR36","first-page":"901","volume":"2","author":"K Kr","year":"2010","unstructured":"Kr K, Indra A. Intrusion detection tools and techniques\u2014a survey. Int J Comput Theory Eng. 2010;2(6):901.","journal-title":"Int J Comput Theory Eng."},{"key":"4028_CR37","doi-asserted-by":"crossref","unstructured":"Feng Y, Akiyama H, Lu L, Sakurai K. Feature selection for machine learning-based early detection of distributed cyber attacks. In: 2018 IEEE 16th International Conference on Dependable, Autonomic and Secure Computing, 16th International Conference on Pervasive Intelligence and Computing, 4th International Conference on Big Data Intelligence and Computing and Cyber Science and Technology Congress (DASC\/PiCom\/DataCom\/CyberSciTech); 2018. p. 173\u2013180.","DOI":"10.1109\/DASC\/PiCom\/DataCom\/CyberSciTec.2018.00040"},{"key":"4028_CR38","unstructured":"Molina MM, Luna JM, Romero C, Ventura S. Metalearning approach for automatic parameter tuning: A case study with educational datasets. In: Proceedings of the 5th international conference on Educational data mining, EDM 2012; 2012. p. 180\u2013183."},{"key":"4028_CR39","doi-asserted-by":"crossref","unstructured":"Mantovani RG, Horv\u00e1th T, Cerri R, Vanschoren J, de\u00a0Carvalho AC. Hyper-parameter tuning of a decision tree induction algorithm. In: 2016 5th Brazilian Conference on Intelligent Systems (BRACIS); 2016. p. 37\u201342.","DOI":"10.1109\/BRACIS.2016.018"},{"issue":"3","key":"4028_CR40","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1109\/TSMCC.2011.2157494","volume":"42","author":"R Barros","year":"2012","unstructured":"Barros R, Basgalupp M, de Carvalho A, Freitas A. A survey of evolutionary algorithms for decision-tree induction. IEEE Trans Syst Man Cybern Part C Appl Rev. 2012;42(3):291\u2013312.","journal-title":"IEEE Trans Syst Man Cybern Part C Appl Rev."},{"key":"4028_CR41","doi-asserted-by":"crossref","unstructured":"Ige T, Kiekintveld C, Performance comparison and implementation of Bayesian variants for network intrusion detection. In: 2023 IEEE international conference on artificial intelligence, blockchain, and internet of things (AIBThings). IEEE; 2023. p. 1\u20135.","DOI":"10.1109\/AIBThings58340.2023.10292485"},{"issue":"8","key":"4028_CR42","doi-asserted-by":"publisher","first-page":"1262","DOI":"10.1016\/j.micpro.2015.08.013","volume":"39","author":"X Yue","year":"2015","unstructured":"Yue X, Cai H, Yan H, Zou C, Zhou K. Cloud-assisted industrial cyber-physical systems: an insight. Microprocessors Microsyst. 2015;39(8):1262\u201370.","journal-title":"Microprocessors Microsyst."},{"key":"4028_CR43","doi-asserted-by":"crossref","unstructured":"Lachure J, Doriya R. Anomaly detection in industrial control system using FSODCONV method. In: Proceedings of the 2023 6th International Conference on Information Science and Systems. ICISS \u201923. New York: Association for Computing Machinery; 2023. p. 238\u2013244.","DOI":"10.1145\/3625156.3625191"}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-025-04028-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-025-04028-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-025-04028-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T08:37:32Z","timestamp":1748421452000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-025-04028-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,28]]},"references-count":43,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["4028"],"URL":"https:\/\/doi.org\/10.1007\/s42979-025-04028-8","relation":{},"ISSN":["2661-8907"],"issn-type":[{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,28]]},"assertion":[{"value":"29 February 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 May 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 May 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"No Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not Applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to Participate"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for Publication"}}],"article-number":"505"}}