article
Industrial Control Systems are increasingly exposed to cyber threats due to growing interconnectivity and their critical role in infrastructure. However, many existing AI-based IDS oversimplify the problem by using outdated datasets and binary classification schemes, limiting their real-world applicability. In this work, we propose a TabNet a deep learning framework for robust multi-class attack detection in ICS environments. TabNet's sequential attention and sparse feature selection mechanisms make it particularly well-suited for heterogeneous tabular data. The model was evaluated on two recent and structurally aligned datasets, ICS-Flow and Westermo. Our approach achieved robust performance for 5-class classification within the ICS-Flow dataset and 4-class identification within the Westermo dataset, attaining F1-scores of 96.70% and 98.38%, respectively, effectively detecting both frequent and rare attack types. Confusion matrix analysis highlights the model's reliability in accurately identifying normal traffic with a very low false positive rate, while also minimizing the misclassification of attacks as normal a critical factor in securing ICS environments. These results demonstrate the suitability of TabNet for real-world ICS defense, offering a balance of accuracy, generalization, and interpretability with minimal preprocessing.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/sita67914.2025.11273377
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.