{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T10:13:36Z","timestamp":1784888016109,"version":"3.55.0"},"reference-count":122,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2021,5,25]],"date-time":"2021-05-25T00:00:00Z","timestamp":1621900800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Commonwealth Cyber Initiative"},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1636107, 61972297"],"award-info":[{"award-number":["U1636107, 61972297"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2022,6,30]]},"abstract":"<jats:p>Anomaly detection is crucial to ensure the security of cyber-physical systems (CPS). However, due to the increasing complexity of CPSs and more sophisticated attacks, conventional anomaly detection methods, which face the growing volume of data and need domain-specific knowledge, cannot be directly applied to address these challenges. To this end, deep learning-based anomaly detection (DLAD) methods have been proposed. In this article, we review state-of-the-art DLAD methods in CPSs. We propose a taxonomy in terms of the type of anomalies, strategies, implementation, and evaluation metrics to understand the essential properties of current methods. Further, we utilize this taxonomy to identify and highlight new characteristics and designs in each CPS domain. Also, we discuss the limitations and open problems of these methods. Moreover, to give users insights into choosing proper DLAD methods in practice, we experimentally explore the characteristics of typical neural models, the workflow of DLAD methods, and the running performance of DL models. Finally, we discuss the deficiencies of DL approaches, our findings, and possible directions to improve DLAD methods and motivate future research.<\/jats:p>","DOI":"10.1145\/3453155","type":"journal-article","created":{"date-parts":[[2021,5,25]],"date-time":"2021-05-25T13:02:30Z","timestamp":1621947750000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":251,"title":["Deep Learning-based Anomaly Detection in Cyber-physical Systems"],"prefix":"10.1145","volume":"54","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5521-2516","authenticated-orcid":false,"given":"Yuan","family":"Luo","sequence":"first","affiliation":[{"name":"Wuhan University, Hubei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ya","family":"Xiao","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Long","family":"Cheng","sequence":"additional","affiliation":[{"name":"Clemson University, Clemson, SC"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guojun","family":"Peng","sequence":"additional","affiliation":[{"name":"Wuhan University, Hubei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danfeng (Daphne)","family":"Yao","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,5,25]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Sebastian Berg. 2020. NumPy. https:\/\/numpy.org\/.  Sebastian Berg. 2020. NumPy. https:\/\/numpy.org\/."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 6th ACM on Cyber-Physical System Security Workshop","author":"Ahmed Chuadhry Mujeeb","unstructured":"Chuadhry Mujeeb Ahmed , Gauthama Raman M. R., and Aditya P. Mathur . 2020. Challenges in machine learning based approaches for real-time anomaly detection in industrial control systems . In Proceedings of the 6th ACM on Cyber-Physical System Security Workshop ( Taipei, Taiwan) (CPSS \u201920). Association for Computing Machinery, New York, NY, 23--29. DOI:https:\/\/doi.org\/10.1145\/3384941.3409588 Chuadhry Mujeeb Ahmed, Gauthama Raman M. R., and Aditya P. Mathur. 2020. Challenges in machine learning based approaches for real-time anomaly detection in industrial control systems. In Proceedings of the 6th ACM on Cyber-Physical System Security Workshop (Taipei, Taiwan) (CPSS \u201920). Association for Computing Machinery, New York, NY, 23--29. DOI:https:\/\/doi.org\/10.1145\/3384941.3409588"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417248"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/DEPCOS-RELCOMEX.2006.38"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 3rd International Workshop on Deep Learning for Mobile Systems and Applications. 1--6.","author":"Almeida Mario","unstructured":"Mario Almeida , Stefanos Laskaridis , Ilias Leontiadis , Stylianos I. Venieris , and Nicholas D. Lane . 2019. EmBench: Quantifying performance variations of deep neural networks across modern commodity devices . In Proceedings of the 3rd International Workshop on Deep Learning for Mobile Systems and Applications. 1--6. Mario Almeida, Stefanos Laskaridis, Ilias Leontiadis, Stylianos I. Venieris, and Nicholas D. Lane. 2019. EmBench: Quantifying performance variations of deep neural networks across modern commodity devices. In Proceedings of the 3rd International Workshop on Deep Learning for Mobile Systems and Applications. 1--6."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/IECON.2018.8591322"},{"key":"e_1_2_1_7_1","unstructured":"CNN. 2020. Car assembly line robot kills worker in Germany. Retrieved from: https:\/\/www.cnn.com\/2015\/07\/02\/europe\/germany-volkswagen-robot-kills-worker\/index.html.  CNN. 2020. Car assembly line robot kills worker in Germany. Retrieved from: https:\/\/www.cnn.com\/2015\/07\/02\/europe\/germany-volkswagen-robot-kills-worker\/index.html."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAS.1979.319407"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2014.7004227"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijepes.2018.11.013"},{"key":"e_1_2_1_11_1","first-page":"171","article-title":"Safety pilot model deployment: Test conductor team report. Report No","volume":"812","author":"Bezzina Debby","year":"2014","unstructured":"Debby Bezzina and James Sayer . 2014 . Safety pilot model deployment: Test conductor team report. Report No . DOT HS 812 (2014), 171 . Debby Bezzina and James Sayer. 2014. Safety pilot model deployment: Test conductor team report. Report No. DOT HS 812 (2014), 171.","journal-title":"DOT HS"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/WoWMoM49955.2020.00073"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33019428"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335388"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.07.034"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3333501"},{"key":"e_1_2_1_17_1","volume-title":"Deep learning for anomaly detection: A survey. arXiv preprint arXiv:1901.03407","author":"Chalapathy Raghavendra","year":"2019","unstructured":"Raghavendra Chalapathy and Sanjay Chawla . 2019. Deep learning for anomaly detection: A survey. arXiv preprint arXiv:1901.03407 ( 2019 ). Raghavendra Chalapathy and Sanjay Chawla. 2019. Deep learning for anomaly detection: A survey. arXiv preprint arXiv:1901.03407 (2019)."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134640"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.09.009"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916)","author":"Cho Kyong-Tak","unstructured":"Kyong-Tak Cho and Kang G. Shin . 2016. Fingerprinting electronic control units for vehicle intrusion detection . In Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916) . 911--927. Kyong-Tak Cho and Kang G. Shin. 2016. Fingerprinting electronic control units for vehicle intrusion detection. In Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916). 911--927."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1198\/jasa.2011.tm09771"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/IECON.2018.8591079"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134015"},{"key":"e_1_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Benedikt Eiteneuer Nemanja Hranisavljevic and Oliver Niggemann. 2019. Dimensionality reduction and anomaly detection for CPPS data using autoencoder. DOI:https:\/\/doi.org\/10.1109\/ICIT.2019.8755116  Benedikt Eiteneuer Nemanja Hranisavljevic and Oliver Niggemann. 2019. Dimensionality reduction and anomaly detection for CPPS data using autoencoder. DOI:https:\/\/doi.org\/10.1109\/ICIT.2019.8755116","DOI":"10.1109\/ICIT.2019.8755116"},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the 4th IEEE\/ACM International Conference on Big Data Computing, Applications and Technologies. 43--52","author":"Ezeme Mellitus","unstructured":"Mellitus Ezeme , Akramul Azim , and Qusay H. Mahmoud . 2017. An imputation-based augmented anomaly detection from large traces of operating system events . In Proceedings of the 4th IEEE\/ACM International Conference on Big Data Computing, Applications and Technologies. 43--52 . Mellitus Ezeme, Akramul Azim, and Qusay H. Mahmoud. 2017. An imputation-based augmented anomaly detection from large traces of operating system events. In Proceedings of the 4th IEEE\/ACM International Conference on Big Data Computing, Applications and Technologies. 43--52."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/RTCSA.2018.00035"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-18305-9_58"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2897122"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.apenergy.2017.12.005"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.34"},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the Workshop on Metrology for Industry 4.0 and IoT (MetroInd4.0 & IoT\u201919)","author":"Ferrari P.","unstructured":"P. Ferrari , S. Rinaldi , E. Sisinni , F. Colombo , F. Ghelfi , D. Maffei , and M. Malara . 2019. Performance evaluation of full-cloud and edge-cloud architectures for industrial IoT anomaly detection based on deep learning . In Proceedings of the Workshop on Metrology for Industry 4.0 and IoT (MetroInd4.0 & IoT\u201919) . IEEE, 420--425. P. Ferrari, S. Rinaldi, E. Sisinni, F. Colombo, F. Ghelfi, D. Maffei, and M. Malara. 2019. Performance evaluation of full-cloud and edge-cloud architectures for industrial IoT anomaly detection based on deep learning. In Proceedings of the Workshop on Metrology for Industry 4.0 and IoT (MetroInd4.0 & IoT\u201919). IEEE, 420--425."},{"key":"e_1_2_1_33_1","unstructured":"FireEye. 2020. A View into the Top 20 Cyber Attacks on ICS Networks | FireEye. Retrieved from: https:\/\/www.fireeye.com\/solutions\/industrial-systems-and-critical-infrastructure-security\/wp-top-20-cyberattacks.html.  FireEye. 2020. A View into the Top 20 Cyber Attacks on ICS Networks | FireEye. Retrieved from: https:\/\/www.fireeye.com\/solutions\/industrial-systems-and-critical-infrastructure-security\/wp-top-20-cyberattacks.html."},{"key":"e_1_2_1_34_1","unstructured":"Flightradar24. 2019. Live Flight Tracker - Real-Time Flight Tracker Map. Retrieved from: https:\/\/www.flightradar24.com\/.  Flightradar24. 2019. Live Flight Tracker - Real-Time Flight Tracker Map. Retrieved from: https:\/\/www.flightradar24.com\/."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47413-7_24"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3203245"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3358121"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the International Conference on Critical Information Infrastructures Security. Springer, 88--99","author":"Goh Jonathan","year":"2016","unstructured":"Jonathan Goh , Sridhar Adepu , Khurum Nazir Junejo , and Aditya Mathur . 2016 . A dataset to support research in the design of secure water treatment systems . In Proceedings of the International Conference on Critical Information Infrastructures Security. Springer, 88--99 . Jonathan Goh, Sridhar Adepu, Khurum Nazir Junejo, and Aditya Mathur. 2016. A dataset to support research in the design of secure water treatment systems. In Proceedings of the International Conference on Critical Information Infrastructures Security. Springer, 88--99."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2017.36"},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the IEEE International Conference on Computer Vision. 1705--1714","author":"Gong Dong","unstructured":"Dong Gong , Lingqiao Liu , Vuong Le , Budhaditya Saha , Moussa Reda Mansour , Svetha Venkatesh , and Anton van den Hengel. 2019. Memorizing normality to detect anomaly: Memory-augmented deep autoencoder for unsupervised anomaly detection . In Proceedings of the IEEE International Conference on Computer Vision. 1705--1714 . Dong Gong, Lingqiao Liu, Vuong Le, Budhaditya Saha, Moussa Reda Mansour, Svetha Venkatesh, and Anton van den Hengel. 2019. Memorizing normality to detect anomaly: Memory-augmented deep autoencoder for unsupervised anomaly detection. In Proceedings of the IEEE International Conference on Computer Vision. 1705--1714."},{"key":"e_1_2_1_41_1","volume-title":"Proceedings of the Military Communications and Information Systems Conference (MilCIS\u201918)","author":"Gunn Lachlan","unstructured":"Lachlan Gunn , Peter Smet , Edward Arbon , and Mark D . McDonnell. 2018. Anomaly detection in satellite communications systems using LSTM networks . In Proceedings of the Military Communications and Information Systems Conference (MilCIS\u201918) . IEEE, 1--6. Lachlan Gunn, Peter Smet, Edward Arbon, and Mark D. McDonnell. 2018. Anomaly detection in satellite communications systems using LSTM networks. In Proceedings of the Military Communications and Information Systems Conference (MilCIS\u201918). IEEE, 1--6."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.07.004"},{"key":"e_1_2_1_43_1","article-title":"Detecting anomalous behavior in cloud servers by nested arc hidden SEMI-Markov model with state summarization","volume":"5","author":"Haider Waqas","year":"2017","unstructured":"Waqas Haider , Jiankun Hu , Yi Xie , Xinghuo Yu , and Qianhong Wu . 2017 . Detecting anomalous behavior in cloud servers by nested arc hidden SEMI-Markov model with state summarization . IEEE Trans. Big Data 5 , 3 (2017). Waqas Haider, Jiankun Hu, Yi Xie, Xinghuo Yu, and Qianhong Wu. 2017. Detecting anomalous behavior in cloud servers by nested arc hidden SEMI-Markov model with state summarization. IEEE Trans. Big Data 5, 3 (2017).","journal-title":"IEEE Trans. Big Data"},{"key":"e_1_2_1_44_1","article-title":"Towards security threats of deep learning systems: A survey","author":"He Y.","year":"2020","unstructured":"Y. He , G. Meng , K. Chen , X. Hu , and J. He . 2020 . Towards security threats of deep learning systems: A survey . IEEE Trans. Softw. Eng. ( Nov. 2020). DOI:https:\/\/doi.org\/10.1109\/TSE.2020.3034721 Y. He, G. Meng, K. Chen, X. Hu, and J. He. 2020. Towards security threats of deep learning systems: A survey. IEEE Trans. Softw. Eng. (Nov. 2020). DOI:https:\/\/doi.org\/10.1109\/TSE.2020.3034721","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.07.011"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2013.6400435"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219845"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2017.149"},{"key":"e_1_2_1_49_1","volume-title":"Proc. Syst. 33","author":"Ismail Aya Abdelsalam","year":"2020","unstructured":"Aya Abdelsalam Ismail , Mohamed Gunady , Hector Corrada Bravo , and Soheil Feizi . 2020 . Benchmarking deep learning interpretability in time series predictions. Adv. Neural Inf . Proc. Syst. 33 (2020). Aya Abdelsalam Ismail, Mohamed Gunady, Hector Corrada Bravo, and Soheil Feizi. 2020. Benchmarking deep learning interpretability in time series predictions. Adv. Neural Inf. Proc. Syst. 33 (2020)."},{"key":"e_1_2_1_50_1","unstructured":"iTrust Labs. 2019. iTrust Labs_Dataset Info. Retrieved from: https:\/\/itrust.sutd.edu.sg\/itrust_labs_datasets\/dataset_info\/#swat.  iTrust Labs. 2019. iTrust Labs_Dataset Info. Retrieved from: https:\/\/itrust.sutd.edu.sg\/itrust_labs_datasets\/dataset_info\/#swat."},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the International Conference on Security for Information Technology and Communications. Springer, 109--125","author":"Jichici Camil","year":"2018","unstructured":"Camil Jichici , Bogdan Groza , and Pal-Stefan Murvay . 2018 . Examining the use of neural networks for intrusion detection in controller area networks . In Proceedings of the International Conference on Security for Information Technology and Communications. Springer, 109--125 . Camil Jichici, Bogdan Groza, and Pal-Stefan Murvay. 2018. Examining the use of neural networks for intrusion detection in controller area networks. In Proceedings of the International Conference on Security for Information Technology and Communications. Springer, 109--125."},{"key":"e_1_2_1_52_1","volume-title":"H1","year":"2019","unstructured":"Kaspersky. 2019. Threat landscape for industrial automation systems , H1 2019 . Retrieved from: https:\/\/ics-cert.kaspersky.com\/reports\/2019\/09\/30\/threat-landscape-for-industrial-automation-systems-h1-2019\/. Kaspersky. 2019. Threat landscape for industrial automation systems, H1 2019. Retrieved from: https:\/\/ics-cert.kaspersky.com\/reports\/2019\/09\/30\/threat-landscape-for-industrial-automation-systems-h1-2019\/."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-019-00074-w"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEsCPS.2019.00014"},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the 19th IEEE International Conference on Mobile Data Management (MDM\u201918)","author":"Kieu Tung","unstructured":"Tung Kieu , Bin Yang , and Christian S. Jensen . 2018. Outlier detection for multidimensional time series using deep neural networks . In Proceedings of the 19th IEEE International Conference on Mobile Data Management (MDM\u201918) . IEEE, 125--134. Tung Kieu, Bin Yang, and Christian S. Jensen. 2018. Outlier detection for multidimensional time series using deep neural networks. In Proceedings of the 19th IEEE International Conference on Mobile Data Management (MDM\u201918). IEEE, 125--134."},{"key":"e_1_2_1_56_1","volume-title":"Kingma and Max Welling","author":"Diederik","year":"2013","unstructured":"Diederik P. Kingma and Max Welling . 2013 . Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114 (2013). Diederik P. Kingma and Max Welling. 2013. Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114 (2013)."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2011.2163807"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3264888.3264896"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/GCIoT.2018.8620158"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30490-4_56"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3018259"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00170-019-03557-w"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procir.2019.02.073"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/1952982.1952995"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.12.006"},{"key":"e_1_2_1_66_1","first-page":"139","article-title":"One-class SVMs for document classification","author":"Manevitz Larry M.","year":"2001","unstructured":"Larry M. Manevitz and Malik Yousef . 2001 . One-class SVMs for document classification . J. Mach. Learn. Res. 2 , Dec. (2001), 139 -- 154 . Larry M. Manevitz and Malik Yousef. 2001. One-class SVMs for document classification. J. Mach. Learn. Res. 2, Dec. (2001), 139--154.","journal-title":"J. Mach. Learn. Res. 2"},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the International Workshop on Cyber-physical Systems for Smart Water Networks (CySWater\u201916)","author":"Aditya","unstructured":"Aditya P. Mathur and Nils Ole Tippenhauer. 2016. SWaT: A water treatment testbed for research and training on ICS security . In Proceedings of the International Workshop on Cyber-physical Systems for Smart Water Networks (CySWater\u201916) . IEEE, 31--36. Aditya P. Mathur and Nils Ole Tippenhauer. 2016. SWaT: A water treatment testbed for research and training on ICS security. In Proceedings of the International Workshop on Cyber-physical Systems for Smart Water Networks (CySWater\u201916). IEEE, 31--36."},{"key":"e_1_2_1_68_1","unstructured":"MATPOWER. 2019. Open-source tools for electric power system simulation and optimization. Retrieved from: https:\/\/matpower.org\/.  MATPOWER. 2019. Open-source tools for electric power system simulation and optimization. Retrieved from: https:\/\/matpower.org\/."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2542049"},{"key":"e_1_2_1_71_1","volume-title":"Preprints of the 1st Workshop on Secure Control Systems. 1--6.","author":"Mo Yilin","year":"2010","unstructured":"Yilin Mo and Bruno Sinopoli . 2010 . False data injection attacks in control systems . In Preprints of the 1st Workshop on Secure Control Systems. 1--6. Yilin Mo and Bruno Sinopoli. 2010. False data injection attacks in control systems. In Preprints of the 1st Workshop on Secure Control Systems. 1--6."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2185505.2185514"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2844341"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2010.2046346"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNSURV.2016.7486356"},{"key":"e_1_2_1_76_1","volume-title":"ABATe: Automatic behavioral abstraction technique to detect anomalies in smartcyber-physical systems","author":"Narayanan Sandeep Nair","year":"2020","unstructured":"Sandeep Nair Narayanan , Anupam Joshi , and Ranjan Bose . 2020. ABATe: Automatic behavioral abstraction technique to detect anomalies in smartcyber-physical systems . IEEE Trans. Depend. Sec. Comput . ( 2020 ). DOI:10.1109\/TDSC.2020.3034331 10.1109\/TDSC.2020.3034331 Sandeep Nair Narayanan, Anupam Joshi, and Ranjan Bose. 2020. ABATe: Automatic behavioral abstraction technique to detect anomalies in smartcyber-physical systems. IEEE Trans. Depend. Sec. Comput. (2020). DOI:10.1109\/TDSC.2020.3034331"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.06.010"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISGT.2019.8791598"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2018.2801475"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00319"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/3056540.3076192"},{"key":"e_1_2_1_82_1","unstructured":"Orbis Research. 2020. Global Cyber Physical System Market 2020 by Company Regions Type and Application Forecast to 2025 | Orbis Research. Retrieved from: https:\/\/www.orbisresearch.com\/reports\/index\/global-cyber-physical-system-market-2020-by-company-regions-type-and-application-forecast-to-2025.  Orbis Research. 2020. Global Cyber Physical System Market 2020 by Company Regions Type and Application Forecast to 2025 | Orbis Research. Retrieved from: https:\/\/www.orbisresearch.com\/reports\/index\/global-cyber-physical-system-market-2020-by-company-regions-type-and-application-forecast-to-2025."},{"key":"e_1_2_1_83_1","volume-title":"Variational inference with normalizing flows. arXiv preprint arXiv:1505.05770","author":"Rezende Danilo Jimenez","year":"2015","unstructured":"Danilo Jimenez Rezende and Shakir Mohamed . 2015. Variational inference with normalizing flows. arXiv preprint arXiv:1505.05770 ( 2015 ). Danilo Jimenez Rezende and Shakir Mohamed. 2015. Variational inference with normalizing flows. arXiv preprint arXiv:1505.05770 (2015)."},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/VTCSpring.2018.8417863"},{"key":"e_1_2_1_85_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Salem Ahmed","year":"2020","unstructured":"Ahmed Salem , Apratim Bhattacharya , Michael Backes , Mario Fritz , and Yang Zhang . 2020 . Updates-leak: Data set inference and reconstruction attacks in online learning . In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920) . 1291--1308. Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, and Yang Zhang. 2020. Updates-leak: Data set inference and reconstruction attacks in online learning. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 1291--1308."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/ECRTS.2016.22"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/3264888.3264890"},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813654"},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/3097983.3098144"},{"key":"e_1_2_1_91_1","volume-title":"Proceedings of the International Conference on Machine Learning. PMLR, 9036--9045","author":"Sivaprasad Prabhu Teja","year":"2020","unstructured":"Prabhu Teja Sivaprasad , Florian Mai , Thijs Vogels , Martin Jaggi , and Francois Fleuret . 2020 . Optimizer benchmarking needs to account for hyperparameter tuning . In Proceedings of the International Conference on Machine Learning. PMLR, 9036--9045 . Prabhu Teja Sivaprasad, Florian Mai, Thijs Vogels, Martin Jaggi, and Francois Fleuret. 2020. Optimizer benchmarking needs to account for hyperparameter tuning. In Proceedings of the International Conference on Machine Learning. PMLR, 9036--9045."},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330672"},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. ACM, 2123--2133","author":"Tariq Shahroz","unstructured":"Shahroz Tariq , Sangyup Lee , Youjin Shin , Myeong Shin Lee , Okchul Jung , Daewon Chung , and Simon S. Woo . 2019. Detecting anomalies in space using multivariate convolutional LSTM with mixtures of probabilistic PCA . In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. ACM, 2123--2133 . Shahroz Tariq, Sangyup Lee, Youjin Shin, Myeong Shin Lee, Okchul Jung, Daewon Chung, and Simon S. Woo. 2019. Detecting anomalies in space using multivariate convolutional LSTM with mixtures of probabilistic PCA. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. ACM, 2123--2133."},{"key":"e_1_2_1_94_1","volume-title":"Capretz","author":"Tasfi Norman L.","year":"2017","unstructured":"Norman L. Tasfi , Wilson A. Higashino , Katarina Grolinger , and Miriam A. M . Capretz . 2017 . Deep neural networks with confidence sampling for electrical anomaly detection. In Proceedings of the IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData). IEEE , 1038--1045. Norman L. Tasfi, Wilson A. Higashino, Katarina Grolinger, and Miriam A. M. Capretz. 2017. Deep neural networks with confidence sampling for electrical anomaly detection. In Proceedings of the IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData). IEEE, 1038--1045."},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA.2016.20"},{"key":"e_1_2_1_96_1","unstructured":"Keras Team. 2019. Keras documentation: About Keras. Retrieved from https:\/\/keras.io\/about\/.  Keras Team. 2019. Keras documentation: About Keras. Retrieved from https:\/\/keras.io\/about\/."},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2019.2906038"},{"key":"e_1_2_1_98_1","volume-title":"Analyzing cyber-physical systems from the perspective of artificial intelligence. arXiv preprint arXiv:1908.11779","author":"Veith Eric","year":"2019","unstructured":"Eric Veith , Lars Fischer , Martin Tr\u00f6schel , and Astrid Nie\u00dfe . 2019. Analyzing cyber-physical systems from the perspective of artificial intelligence. arXiv preprint arXiv:1908.11779 ( 2019 ). Eric Veith, Lars Fischer, Martin Tr\u00f6schel, and Astrid Nie\u00dfe. 2019. Analyzing cyber-physical systems from the perspective of artificial intelligence. arXiv preprint arXiv:1908.11779 (2019)."},{"key":"e_1_2_1_99_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIXSecurity\u201918)","author":"Wang Bolun","unstructured":"Bolun Wang , Yuanshun Yao , Bimal Viswanath , Haitao Zheng , and Ben Y. Zhao . 2018. With great training comes great vulnerability: Practical attacks against transfer learning . In Proceedings of the 27th USENIX Security Symposium (USENIXSecurity\u201918) . 1281--1297. Bolun Wang, Yuanshun Yao, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2018. With great training comes great vulnerability: Practical attacks against transfer learning. In Proceedings of the 27th USENIX Security Symposium (USENIXSecurity\u201918). 1281--1297."},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.energy.2019.03.009"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2018.2859339"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2012.12.017"},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2019.1800286"},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-23597-0_27"},{"key":"e_1_2_1_105_1","unstructured":"Wikipedia. 2020. December 2015 Ukraine power grid cyberattack. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=December_2015_Ukraine_power_grid_cyberattack&oldid=920905638.  Wikipedia. 2020. December 2015 Ukraine power grid cyberattack. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=December_2015_Ukraine_power_grid_cyberattack&oldid=920905638."},{"key":"e_1_2_1_106_1","unstructured":"Wikipedia. 2020. List of self-driving car fatalities. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=List_of_self-driving_car_fatalities&oldid=928100815.  Wikipedia. 2020. List of self-driving car fatalities. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=List_of_self-driving_car_fatalities&oldid=928100815."},{"key":"e_1_2_1_107_1","unstructured":"Wikipedia. 2020. Stuxnet. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=Stuxnet&oldid=939556423.  Wikipedia. 2020. Stuxnet. Retrieved from: https:\/\/en.wikipedia.org\/w\/index.php?title=Stuxnet&oldid=939556423."},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.3390\/s18041096"},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.1601540"},{"key":"e_1_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTGRID.2010.5622048"},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900091"},{"key":"e_1_2_1_112_1","volume-title":"Proceedings of the 46th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN\u201916)","author":"Xu Kui","unstructured":"Kui Xu , Ke Tian , Danfeng Yao , and Barbara G. Ryder . 2016. A sharper sense of self: Probabilistic reasoning of program behaviors for anomaly detection with context sensitivity . In Proceedings of the 46th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN\u201916) . IEEE, 467--478. Kui Xu, Ke Tian, Danfeng Yao, and Barbara G. Ryder. 2016. A sharper sense of self: Probabilistic reasoning of program behaviors for anomaly detection with context sensitivity. In Proceedings of the 46th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN\u201916). IEEE, 467--478."},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.2200\/S00800ED1V01Y201709SPT022"},{"key":"e_1_2_1_114_1","volume-title":"Bruno Lecouat, Gaurav Manek, and Vijay Ramaseshan Chandrasekhar.","author":"Zenati Houssam","year":"2018","unstructured":"Houssam Zenati , Chuan Sheng Foo , Bruno Lecouat, Gaurav Manek, and Vijay Ramaseshan Chandrasekhar. 2018 . Efficient GAN-based anomaly detection. arXiv preprint arXiv:1802.06222 (2018). Houssam Zenati, Chuan Sheng Foo, Bruno Lecouat, Gaurav Manek, and Vijay Ramaseshan Chandrasekhar. 2018. Efficient GAN-based anomaly detection. arXiv preprint arXiv:1802.06222 (2018)."},{"key":"e_1_2_1_115_1","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence. 1409--1416","author":"Zhang Chuxu","unstructured":"Chuxu Zhang , Dongjin Song , Yuncong Chen , Xinyang Feng , Cristian Lumezanu , Wei Cheng , Jingchao Ni , Bo Zong , Haifeng Chen , and Nitesh V. Chawla . 2019. A deep neural network for unsupervised anomaly detection and diagnosis in multivariate time series data . In Proceedings of the AAAI Conference on Artificial Intelligence. 1409--1416 . Chuxu Zhang, Dongjin Song, Yuncong Chen, Xinyang Feng, Cristian Lumezanu, Wei Cheng, Jingchao Ni, Bo Zong, Haifeng Chen, and Nitesh V. Chawla. 2019. A deep neural network for unsupervised anomaly detection and diagnosis in multivariate time series data. In Proceedings of the AAAI Conference on Artificial Intelligence. 1409--1416."},{"key":"e_1_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.01.002"},{"key":"e_1_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00034"},{"key":"e_1_2_1_118_1","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489306"},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2019.2928168"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2019.2907269"},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3133031"},{"key":"e_1_2_1_122_1","volume-title":"Proceedings of the 6th International Conference on Learning Representations (ICLR'18)","author":"Zong Bo","year":"2018","unstructured":"Bo Zong , Qi Song , Martin Renqiang Min , Wei Cheng , Cristian Lumezanu , Daeki Cho , and Haifeng Chen . 2018 . Deep autoencoding Gaussian mixture model for unsupervised anomaly detection . In Proceedings of the 6th International Conference on Learning Representations (ICLR'18) . Bo Zong, Qi Song, Martin Renqiang Min, Wei Cheng, Cristian Lumezanu, Daeki Cho, and Haifeng Chen. 2018. Deep autoencoding Gaussian mixture model for unsupervised anomaly detection. In Proceedings of the 6th International Conference on Learning Representations (ICLR'18)."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3453155","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3453155","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:28:39Z","timestamp":1750195719000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3453155"}},"subtitle":["Progress and Opportunities"],"short-title":[],"issued":{"date-parts":[[2021,5,25]]},"references-count":122,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2022,6,30]]}},"alternative-id":["10.1145\/3453155"],"URL":"https:\/\/doi.org\/10.1145\/3453155","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,25]]},"assertion":[{"value":"2020-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-02-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}