A Robust Hybrid Framework Combining Deductive Temporal Logic and Machine Learning for Fault and Cyber-Attack Detection in the Tennessee Eastman Process
摘要
Industrial control systems (ICS) face both physical faults and stealthy cyber-attacks, yet existing detection methods rarely address both threats comprehensively. Model-based monitors—such as temporal-logic rules—provide interpretable alarms but falter in high-dimensional settings and against novel anomalies, while data-driven approaches—like Random Forest classifiers or autoencoders—adapt to complex patterns but often obscure decision rationale and miss unseen threats such as replay attacks. Alarms are fused using a graded, source-attributed strategy, and a class-balanced Random Forest learns nonlinear fusion, outperforming simple logical-OR baselines. On the Tennessee Eastman Process benchmark, our framework delivers near-perfect \(F_1\) scores on process faults ( \(F_1 \approx 0.99\) ) with only seven false alarms over 24h, and boosts replay-attack detection from \(F_1 < 0.10\) to 0.70 (precision 0.64, recall 0.78, AUC 0.99). These results demonstrate that combining symbolic logic, statistical learning, and temporal similarity detection yields a scalable, interpretable, and resilient solution for comprehensive ICS monitoring.