MARATTO

article · Discover Mechanical Engineering

Hybrid dynamic feature convolution with transformer fusion model for the detection of intrusion during manufacturing process

2026Open accessGondar University

In plain language

Modern manufacturing systems rely heavily on cyber-physical networks, making them susceptible to diverse cyber attacks. Conventional intrusion detection methods often fail when handling high-dimensional sensor readings, imbalanced data, and evolving threat patterns. To address this, a hybrid detection architecture merges dynamic feature convolution with a transformer structure. The dynamic feature convolution component uses gated convolutional layers with sigmoid and tanh activations to extract local temporal features, whilst the transformer relies on self-attention to capture long-term sequence dependencies. Evaluated on the benchmark Water Distribution dataset representing industrial attack scenarios, the model delivered consistent results across five training runs and cross-validation folds. It achieved average scores exceeding 97% for accuracy, precision, recall, and F1-score. These findings show that the hybrid model provides balanced class learning and repeatable detection performance for industrial time-series data.

Key takeaways

  • A hybrid architecture integrates gated dynamic feature convolution and transformer self-attention to process complex industrial time-series data.
  • The system captures both localized temporal dynamics and broader long-term sequence dependencies across sensor readings.
  • Evaluations on the Water Distribution dataset yielded an average accuracy of 97.34% and an F1-score of 97.30% across multiple validation runs.
  • Close precision and recall metrics demonstrate balanced class identification without precision inflation under attack conditions.

Why it matters

Industrial facilities and manufacturing plants face rising cyber threats as operational machinery connects to digital networks. Detecting intrusions reliably without missing rare or novel attacks is difficult when dealing with massive sensor streams. This method offers a dependable way to identify malicious interference, helping operators safeguard critical infrastructure and reduce the risk of costly industrial disruptions.

Commercialisation angle

The framework addresses real-time cyber intrusion monitoring for manufacturing and industrial cyber-physical systems. Prospective users include industrial plant operators and providers of operational technology cybersecurity software. Currently at an applied and tested stage using benchmark simulation data, moving toward commercial deployment would require validating the algorithm on live industrial control feeds and integrating it within existing plant monitoring platforms.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Intrusion detection is essential in contemporary manufacturing systems. These are vulnerable to various cyber threats due to the integration of cyber-physical systems and continuous data exchange. Traditional intrusion detection systems include statistical models and standard machine learning (ML) approaches. They struggle with high-dimensional sensor data, imbalanced datasets, and fast-changing attack patterns. To overcome these challenges, we propose a hybrid intrusion detection model. It combines Dynamic Feature Convolution (DFC) with a Transformer-based temporal modelling structure. The DFC component uses gated convolutional layers with sigmoid and tanh activations to learn localized temporal features. The Transformer component applies self-attention mechanisms to capture long-term dependencies. This hybrid model learns both local feature dynamics and global temporal dependencies in industrial time series data. We evaluated the proposed model using the publicly available Water Distribution (WADI) dataset. This dataset simulates realistic industrial processes under both normal and attack scenarios. Experimental results demonstrate robust detection performance. Over five independent training runs and 5-fold cross-validation, the model achieved an average accuracy of 97.34% ± 0.23. It also reached a precision of 97.47% ± 0.24, a recall of 97.14% ± 0.22, and an F1-score of 97.30% ± 0.23. The close values of precision and recall, further supported by confusion matrix analysis and low variance across folds, indicate balanced class learning rather than precision inflation. These results demonstrate robust and repeatable intrusion detection performance rather than isolated success. Our findings suggest that the proposed hybrid framework offers a robust and efficient solution for real-time intrusion detection in manufacturing systems.

Research topics

  • Anomaly Detection Techniques and Applications
  • Industrial Vision Systems and Defect Detection
  • Fault Detection and Control Systems

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1007/s44245-026-00337-1

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.