{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T02:47:00Z","timestamp":1782960420458,"version":"3.54.5"},"reference-count":39,"publisher":"MDPI AG","issue":"14","license":[{"start":{"date-parts":[[2020,7,8]],"date-time":"2020-07-08T00:00:00Z","timestamp":1594166400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100004826","name":"Beijing Municipal Natural Science Foundation","doi-asserted-by":"publisher","award":["19L2020"],"award-info":[{"award-number":["19L2020"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012558","name":"Foundation of Science and Technology on Information Assurance Laboratory","doi-asserted-by":"publisher","award":["614211204031117"],"award-info":[{"award-number":["614211204031117"]}],"id":[{"id":"10.13039\/501100012558","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Polytechnic Research Fund","award":["2017Z004-008-KXZ"],"award-info":[{"award-number":["2017Z004-008-KXZ"]}]},{"name":"Foundation of Shaanxi Key Laboratory of Network and System Security","award":["NSSOF1900105"],"award-info":[{"award-number":["NSSOF1900105"]}]},{"name":"International Research Cooperation Seed Fund of Beijing University of Technology","award":["2018-B9"],"award-info":[{"award-number":["2018-B9"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Intrusion detection is only the initial part of the security system for an industrial control system. Because of the criticality of the industrial control system, professionals still make the most important security decisions. Therefore, a simple intrusion alarm has a very limited role in the security system, and intrusion detection models based on deep learning struggle to provide more information because of the lack of explanation. This limits the application of deep learning methods to industrial control network intrusion detection. We analyzed the deep neural network (DNN) model and the interpretable classification model from the perspective of information, and clarified the correlation between the calculation process of the DNN model and the classification process. By comparing the normal samples with the abnormal samples, the abnormalities that occur during the calculation of the DNN model compared to the normal samples could be found. Based on this, a layer-wise relevance propagation method was designed to map the abnormalities in the calculation process to the abnormalities of attributes. At the same time, considering that the data set may already contain some useful information, we designed filtering rules for a kind of data set that can be obtained at a low cost, so that the calculation result is presented in a more accurate manner, which should help professionals lock and address intrusion threats more quickly.<\/jats:p>","DOI":"10.3390\/s20143817","type":"journal-article","created":{"date-parts":[[2020,7,8]],"date-time":"2020-07-08T11:47:46Z","timestamp":1594208866000},"page":"3817","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Explaining the Attributes of a Deep Learning Based Intrusion Detection System for Industrial Control Networks"],"prefix":"10.3390","volume":"20","author":[{"given":"Zhidong","family":"Wang","sequence":"first","affiliation":[{"name":"College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingxu","family":"Lai","sequence":"additional","affiliation":[{"name":"College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zenghui","family":"Liu","sequence":"additional","affiliation":[{"name":"Automation Engineering Institute, Beijing Polytechnic, Beijing 100176, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jing","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,7,8]]},"reference":[{"key":"ref_1","first-page":"143","article-title":"Research on intrusion detection of industrial control system","volume":"38","author":"Lai","year":"2017","journal-title":"Tongxin Xuebao J. Commun."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Bernieri, G., Damiani, S., del Moro, F., Faramondi, L., Pascucci, F., and Tambone, F. (2016, January 24\u201327). A multiple-criteria decision making method as support for critical infrastructure protection and intrusion detection system. Proceedings of the IECON 2016, Florence, Italy.","DOI":"10.1109\/IECON.2016.7793111"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","article-title":"Deep learning approach for intelligent intrusion detection system","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Alrawashdeh, K., and Purdy, C. (2016, January 18\u201320). Toward an online anomaly intrusion detection system based on deep learning. Proceedings of the ICMLA 2016, Anaheim, CA, USA.","DOI":"10.1109\/ICMLA.2016.0040"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Faker, O., and Dogdu, E. (2019, January 18\u201320). Intrusion detection using big data and deep learning techniques. Proceedings of the ACMSE 2019, Kennesaw, GA, USA.","DOI":"10.1145\/3299815.3314439"},{"key":"ref_6","first-page":"e2","article-title":"A tutorial survey of architectures, algorithms, and applications for deep learning","volume":"3","author":"Deng","year":"2014","journal-title":"APSIPA Trans. Signal Inf. Process."},{"key":"ref_7","first-page":"93","article-title":"A survey of methods for explaining black box models","volume":"51","author":"Guidotti","year":"2018","journal-title":"ACM Comput. Surv."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Bach, S., Binder, A., Montavon, G., Klauschen, F., M\u00fcller, K.-R., and Samek, W. (2015). On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. PLoS ONE, 10.","DOI":"10.1371\/journal.pone.0130140"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Binder, A., Bach, S., Montavon, G., M\u00fcller, K.-R., and Samek, W. (2016). Layer-wise relevance propagation for deep neural network architectures. Information Science and Applications (ICISA) 2016, Springer.","DOI":"10.1007\/978-981-10-0557-2_87"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1016\/j.jneumeth.2016.10.008","article-title":"Interpretable deep neural networks for single-trial EEG classification","volume":"274","author":"Sturm","year":"2016","journal-title":"J. Neurosci. Methods"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Yang, Y., Tresp, V., Wunderle, M., and Fasching, P.A. (2018, January 4\u20137). Explaining therapy predictions with layer-wise relevance propagation in neural networks. Proceedings of the ICHI 2018, New York, NY, USA.","DOI":"10.1109\/ICHI.2018.00025"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1109\/TII.2010.2099234","article-title":"A multidimensional critical state analysis for detecting intrusions in SCADA systems","volume":"7","author":"Carcano","year":"2011","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"3104","DOI":"10.1109\/TSG.2015.2409775","article-title":"Developing a hybrid intrusion detection system using data mining for power systems","volume":"6","author":"Pan","year":"2015","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_14","unstructured":"Cheung, S., Dutertre, B., Fong, M., Lindqvist, U., Skinner, K., and Valdes, A. (2007, January 24\u201325). Using model-based intrusion detection for scada networks. Proceedings of the SCADA Security Scientific Symposium, Miami Beach, FL, USA."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1109\/LES.2018.2823906","article-title":"Embedding Encryption and Machine Learning Intrusion Prevention Systems on Programmable Logic Controllers","volume":"10","author":"Alves","year":"2018","journal-title":"IEEE Embed. Syst. Lett."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Feng, C., Li, T., and Chana, D. (2017, January 26\u201329). Multi-level Anomaly Detection in Industrial Control Systems via Package Signatures and LSTM Networks. Proceedings of the 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), Denver, CO, USA.","DOI":"10.1109\/DSN.2017.34"},{"key":"ref_17","unstructured":"Had\u017eiosmanovic, D., Simionato, L., Bolzoni, D., Zambon, E., and Etalle, S. (2017). N-Gram against the Machine: On the Feasibility of the N-Gram Network Analysis for Binary Protocols. Research in Attacks, Intrusions, and Defenses, Lecture Notes in Computer Science, Springer."},{"key":"ref_18","unstructured":"Hasan, M.S., Dean, T., Imam, F.T., Garcia, F., Leblanc, S.P., and Zulkernine, M. (September, January 31). A Constraint-based intrusion detection system. Proceedings of the Fifth European Conference on the Engineering of Computer-Based Systems\u2014ECBS\u201917, Larnaca, Cyprus."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., and Zhang, S. (2019). Intrusion detection algorithm based on deep learning for industrial control networks. ACM International Conference Proceeding Series, Association for Computing Machinery.","DOI":"10.1145\/3372047.3372092"},{"key":"ref_20","unstructured":"Ahmad, H., and Jean-Marie, F. (2019, January 26). A deep learning approach for intrusion detection system in industry network. Proceedings of the First International Conference on Big Data and Cybersecurity Intelligence (BDCS Intell\u2019 2018), Beirut, Lebanon."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Yang, H., Cheng, L., and Chuah, M.C. (2019, January 10\u201312). Deep-Learning-Based Network Intrusion Detection for SCADA Systems. Proceedings of the 2019 IEEE Conference on Communications and Network Security, CNS 2019, Washington, DA, USA.","DOI":"10.1109\/CNS.2019.8802785"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"022016","DOI":"10.1088\/1742-6596\/1302\/2\/022016","article-title":"An Intrusion Detection Method for Industrial Control System Based on Gate Recurrent Unit","volume":"1302","author":"Chen","year":"2019","journal-title":"J. Phys. Conf. Ser."},{"key":"ref_23","first-page":"2330","article-title":"Intrusion Detection of Industrial Control System Based on Correlation Information Entropy and CNN-BiLSTM","volume":"56","author":"Shi","year":"2019","journal-title":"Jisuanji Yanjiu yu Fazhan\/Comput. Res. Dev."},{"key":"ref_24","unstructured":"Datta, A., Sen, S., and Zick, Y. (2018, January 21\u201323). Algorithmic transparency via quantitative input influence: Theory and experiments with learning systems. Proceedings of the IEEE Symposium on Security and Privacy (SP\u201916), San Francisco, CA, USA."},{"key":"ref_25","unstructured":"Sundararajan, M., Taly, A., and Yan, Q. (2017). Axiomatic attribution for deep networks. arXiv."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1080\/10618600.2014.907095","article-title":"Peeking inside the black box: Visualizing statistical learning with plots of individual conditional expectation","volume":"24","author":"Goldstein","year":"2015","journal-title":"J. Comput. Graph. Stat."},{"key":"ref_27","unstructured":"Yosinski, J., Clune, J., Nguyen, A., Fuchs, T., and Lipson, H. (2015). Understanding neural networks through deep visualization. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Zeiler, M.D., and Fergus, R. (2014). Visualizing and understanding convolutional networks. European Conference on Computer Vision, Springer.","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"ref_29","unstructured":"Simonyan, K., Vedaldi, A., and Zisserman, A. (2013). Deep inside convolutional networks: Visualising image classification models and saliency maps. arXiv."},{"key":"ref_30","unstructured":"Springenberg, J.T., Dosovitskiy, A., Brox, T., and Riedmiller, M. (2014). Striving for simplicity: The all convolutional net. arXiv."},{"key":"ref_31","unstructured":"Radford, A., Jozefowicz, R., and Sutskever, I. (2017). Learning to generate reviews and discovering sentiment. arXiv."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"166","DOI":"10.1016\/j.cose.2019.03.009","article-title":"Abnormal detection method of industrial control system based on behavior model","volume":"84","author":"Song","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Tishby, N., and Zaslavsky, N. (May, January 26). Deep learning and the information bottleneck principle. Proceedings of the ITW 2015, Jerusalem, Israel.","DOI":"10.1109\/ITW.2015.7133169"},{"key":"ref_34","unstructured":"Koh, P.W., and Liang, P. (2017, January 6\u201311). Understanding black-box predictions via influence functions. Proceedings of the ICML\u201917, Sydney, Australia."},{"key":"ref_35","unstructured":"Nguyen, A., Dosovitskiy, A., Yosinski, J., Brox, T., and Clune, J. (2016, January 9). Synthesizing the preferred inputs for neurons in neural networks via deep generator networks. Proceedings of the NIPS\u201916, Barcelona, Spain."},{"key":"ref_36","unstructured":"Shwartz-Ziv, R., and Tishby, N. (2017). Opening the black box of deep neural networks via information. arXiv."},{"key":"ref_37","unstructured":"Morris, T., and Gao, W. (2014, January 17\u201319). Industrial control system traffic datasets for intrusion detection research. Proceedings of the ICCIP 2014, Arlington, VA, USA."},{"key":"ref_38","unstructured":"MacQueen, J.B. (1967, January 1). Some methods for classification and analysis of multivariate observations. Proceedings of the 5th Berkeley Symposium on Mathematical Statistics and Probability, Berkeley, CA, USA."},{"key":"ref_39","unstructured":"Ester, M., Kriegel, H.P., Sander, J., and Xu, X.-W. (1996). A density-based algorithm for discovering clusters in large spatial databases with noise. Proceedings of the Second International Conference on Knowledge Discovery and Data Mining (KDD-96), Portland, OR, USA, 2\u20134 August 1996, AAAI Press."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/14\/3817\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:49:05Z","timestamp":1760176145000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/14\/3817"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,8]]},"references-count":39,"journal-issue":{"issue":"14","published-online":{"date-parts":[[2020,7]]}},"alternative-id":["s20143817"],"URL":"https:\/\/doi.org\/10.3390\/s20143817","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,8]]}}}