{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T22:24:28Z","timestamp":1782858268065,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3564633","type":"proceedings-article","created":{"date-parts":[[2022,12,3]],"date-time":"2022-12-03T01:01:29Z","timestamp":1670029289000},"page":"412-426","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["Assessing Model-free Anomaly Detection in Industrial Control Systems Against Generic Concealment Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2631-8829","authenticated-orcid":false,"given":"Alessandro","family":"Erba","sequence":"first","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany and Saarbr\u00fccken Graduate School of Computer Science, Saarland University, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8424-2602","authenticated-orcid":false,"given":"Nils Ole","family":"Tippenhauer","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"1","article-title":"Ghost in the plc designing an undetectable programmable logic controller rootkit via pin control attack","volume":"2016","author":"Abbasi Ali","year":"2016","unstructured":"Ali Abbasi and Majid Hashemi . 2016 . Ghost in the plc designing an undetectable programmable logic controller rootkit via pin control attack . Black Hat Europe 2016 (2016), 1 \u2013 35 . Ali Abbasi and Majid Hashemi. 2016. Ghost in the plc designing an undetectable programmable logic controller rootkit via pin control attack. Black Hat Europe 2016(2016), 1\u201335.","journal-title":"Black Hat Europe"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCSPW.2016.7509557"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196532"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243781"},{"key":"e_1_3_2_1_5_1","unstructured":"Batadal attacks description [n.d.]. Batadal attacks description. https:\/\/www.batadal.net\/images\/Attacks_TrainingDataset2.png.  Batadal attacks description [n.d.]. Batadal attacks description. https:\/\/www.batadal.net\/images\/Attacks_TrainingDataset2.png."},{"key":"e_1_3_2_1_6_1","unstructured":"Batadal attacks description [n.d.]. Batadal attacks description. https:\/\/www.batadal.net\/images\/Attacks_TrainingDataset2.png.  Batadal attacks description [n.d.]. Batadal attacks description. https:\/\/www.batadal.net\/images\/Attacks_TrainingDataset2.png."},{"key":"e_1_3_2_1_7_1","volume-title":"Time series: theory and methods: theory and methods","author":"Brockwell J","unstructured":"Peter\u00a0 J Brockwell , Richard\u00a0 A Davis , and Stephen\u00a0 E Fienberg . 1991. Time series: theory and methods: theory and methods . Springer Science & Business Media . Peter\u00a0J Brockwell, Richard\u00a0A Davis, and Stephen\u00a0E Fienberg. 1991. Time series: theory and methods: theory and methods. Springer Science & Business Media."},{"key":"e_1_3_2_1_8_1","volume-title":"Linear System Theory and Design","author":"Chen Chi-Tsong","unstructured":"Chi-Tsong Chen . 1998. Linear System Theory and Design ( 3 rd ed.). Oxford University Press, Inc. , USA. Chi-Tsong Chen. 1998. Linear System Theory and Design(3rd ed.). Oxford University Press, Inc., USA.","edition":"3"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00016"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243752"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427660"},{"key":"e_1_3_2_1_12_1","unstructured":"Cheng Feng Tingting Li Zhanxing Zhu and Deeph Chana. 2017. A deep learning-based framework for conducting stealthy attacks in industrial control systems. arXiv preprint arXiv:1709.06397(2017).  Cheng Feng Tingting Li Zhanxing Zhu and Deeph Chana. 2017. A deep learning-based framework for conducting stealthy attacks in industrial control systems. arXiv preprint arXiv:1709.06397(2017)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23265"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46131-1_8"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23313"},{"key":"e_1_3_2_1_16_1","volume-title":"International Conference on Critical Information Infrastructures Security (CRITIS). Springer, 88\u201399","author":"Goh Jonathan","year":"2016","unstructured":"Jonathan Goh , Sridhar Adepu , Khurum\u00a0Nazir Junejo , and Aditya Mathur . 2016 . A dataset to support research in the design of secure water treatment systems . In International Conference on Critical Information Infrastructures Security (CRITIS). Springer, 88\u201399 . Jonathan Goh, Sridhar Adepu, Khurum\u00a0Nazir Junejo, and Aditya Mathur. 2016. A dataset to support research in the design of secure water treatment systems. In International Conference on Critical Information Infrastructures Security (CRITIS). Springer, 88\u201399."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2017.36"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3140241.3140254"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664277"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"e_1_3_2_1_21_1","unstructured":"ICS concealment attacks repository [n.d.]. ICS concealment attacks repository. https:\/\/github.com\/scy-phy\/ICS-Evasion-Attacks.  ICS concealment attacks repository [n.d.]. ICS concealment attacks repository. https:\/\/github.com\/scy-phy\/ICS-Evasion-Attacks."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818184"},{"key":"e_1_3_2_1_23_1","volume-title":"Centre for Research in Cyber Security","year":"2017","unstructured":"iTrust , Centre for Research in Cyber Security , Singapore University of Technology and Design . 2017 . WADI datatset. https:\/\/itrust.sutd.edu.sg\/research\/dataset\/dataset_characteristics\/#wadi, Last accessed on: 2019-01-30. iTrust, Centre for Research in Cyber Security, Singapore University of Technology and Design. 2017. WADI datatset. https:\/\/itrust.sutd.edu.sg\/research\/dataset\/dataset_characteristics\/#wadi, Last accessed on: 2019-01-30."},{"key":"e_1_3_2_1_24_1","unstructured":"Kaspersky. [n.d.]. Kaspersky Machine Learning for Anomaly Detection. https:\/\/mlad.kaspersky.com\/ Last accessed on: 2022-03-30.  Kaspersky. [n.d.]. Kaspersky Machine Learning for Anomaly Detection. https:\/\/mlad.kaspersky.com\/ Last accessed on: 2022-03-30."},{"key":"e_1_3_2_1_25_1","volume-title":"ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478(2018).","author":"Keliris Anastasis","year":"2018","unstructured":"Anastasis Keliris and Michail Maniatakos . 2018 . ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478(2018). Anastasis Keliris and Michail Maniatakos. 2018. ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478(2018)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1951365.1951370"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3264888.3264896"},{"key":"e_1_3_2_1_28_1","volume-title":"Efficient cyber attack detection in industrial control systems using lightweight neural networks and pca","author":"Kravchik Moshe","year":"2021","unstructured":"Moshe Kravchik and Asaf Shabtai . 2021. Efficient cyber attack detection in industrial control systems using lightweight neural networks and pca . IEEE Transactions on Dependable and Secure Computing ( 2021 ). Moshe Kravchik and Asaf Shabtai. 2021. Efficient cyber attack detection in industrial control systems using lightweight neural networks and pca. IEEE Transactions on Dependable and Secure Computing (2021)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664290"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.20"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3453155"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CySWater.2016.7469060"},{"key":"e_1_3_2_1_33_1","volume-title":"47th Annual Allerton Conference on. 911\u2013918","author":"Mo Yilin","unstructured":"Yilin Mo and B. Sinopoli . 2009. Secure control against replay attacks. In Communication, Control, and Computing, 2009. Allerton 2009 . 47th Annual Allerton Conference on. 911\u2013918 . Yilin Mo and B. Sinopoli. 2009. Secure control against replay attacks. In Communication, Control, and Computing, 2009. Allerton 2009. 47th Annual Allerton Conference on. 911\u2013918."},{"key":"e_1_3_2_1_34_1","volume-title":"Blackhat Conference Europe, Vol.\u00a01045","author":"Ornaghi Alberto","year":"2003","unstructured":"Alberto Ornaghi and Marco Valleri . 2003 . Man in the middle attacks . In Blackhat Conference Europe, Vol.\u00a01045 . Alberto Ornaghi and Marco Valleri. 2003. Man in the middle attacks. In Blackhat Conference Europe, Vol.\u00a01045."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1061\/(ASCE)WR.1943-5452.0000191"},{"key":"e_1_3_2_1_36_1","volume-title":"Proc. of the USENIX Security Symposium","author":"Quinonez Raul","year":"2020","unstructured":"Raul Quinonez , Jairo Giraldo , Luis Salazar , Erick Bauman , Alvaro Cardenas , and Zhiqiang Lin . 2020 . SAVIOR: Securing Autonomous Vehicles with Robust Physical Invariants . In Proc. of the USENIX Security Symposium . Boston, MA. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/quinonez Raul Quinonez, Jairo Giraldo, Luis Salazar, Erick Bauman, Alvaro Cardenas, and Zhiqiang Lin. 2020. SAVIOR: Securing Autonomous Vehicles with Robust Physical Invariants. In Proc. of the USENIX Security Symposium. Boston, MA. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/quinonez"},{"key":"e_1_3_2_1_37_1","volume-title":"Critical Infrastructure Protection","author":"Rrushi L","unstructured":"Julian\u00a0 L Rrushi . 2012. SCADA protocol vulnerabilities . In Critical Infrastructure Protection . Springer , 150\u2013176. Julian\u00a0L Rrushi. 2012. SCADA protocol vulnerabilities. In Critical Infrastructure Protection. Springer, 150\u2013176."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384730"},{"key":"e_1_3_2_1_39_1","volume-title":"Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Sun Jiachen","year":"2020","unstructured":"Jiachen Sun , Yulong Cao , Qi\u00a0Alfred Chen , and Z.\u00a0 Morley Mao . 2020 . Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures. In 29th USENIX Security Symposium (USENIX Security 20) . USENIX Association, 877\u2013894. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/sun Jiachen Sun, Yulong Cao, Qi\u00a0Alfred Chen, and Z.\u00a0Morley Mao. 2020. Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures. In 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 877\u2013894. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/sun"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1061\/(ASCE)WR.1943-5452.0000983"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.envsoft.2018.11.008"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1061\/(ASCE)WR.1943-5452.0000969"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354195"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411498.3419961"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978388"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-617-0-75"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/0005-1098(94)90230-5"},{"key":"e_1_3_2_1_48_1","volume-title":"Computer security: Is this the start of cyberwarfare?Nature 174 (June","author":"Weinberger Sharon","year":"2011","unstructured":"Sharon Weinberger . 2011. Computer security: Is this the start of cyberwarfare?Nature 174 (June 2011 ), 142\u2013145. Sharon Weinberger. 2011. Computer security: Is this the start of cyberwarfare?Nature 174 (June 2011), 142\u2013145."},{"key":"e_1_3_2_1_49_1","volume-title":"The Purdue enterprise reference architecture. Computers in industry 24, 2-3","author":"Williams J","year":"1994","unstructured":"Theodore\u00a0 J Williams . 1994. The Purdue enterprise reference architecture. Computers in industry 24, 2-3 ( 1994 ), 141\u2013158. Theodore\u00a0J Williams. 1994. The Purdue enterprise reference architecture. Computers in industry 24, 2-3 (1994), 141\u2013158."},{"key":"e_1_3_2_1_50_1","unstructured":"Chen Yan Wenyuan Xu and Jianhao Liu. 2016. Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle. DEF CON 24(2016).  Chen Yan Wenyuan Xu and Jianhao Liu. 2016. Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle. DEF CON 24(2016)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00121"}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564633","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564633","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:11Z","timestamp":1750183751000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564633"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":51,"alternative-id":["10.1145\/3564625.3564633","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3564633","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}