Enhancing SCADA Security: AI Based Approaches for Attack Detection
DOI:
https://doi.org/10.24425/mper.2025.157213Abstract
In the industrial sector, Supervisory Control and Data Acquisition (SCADA) systems are essential for managing Industrial Internet of Things (IIoT) networks. However, these systems have become increasingly exposed to cyberattacks targeting the communication layers embedded in industrial processes. Such vulnerabilities can cause severe disruptions in manufacturing and production environments. The ongoing digitalization of Industrial Control Systems (ICS) has further amplified these risks, emphasizing the need for robust security mechanisms such as Intrusion Detection Systems (IDS). This research aims to develop a high-precision AI-based IDS capable of protecting SCADA systems from evolving cyber threats. To achieve this, three categories of machine learning algorithms were evaluated: Deep Learning models (CNN, RNN, LSTM), Boosting algorithms (XGBoost, GBoost, AdaBoost), and classical methods (RF, DT, KNN). Extensive experiments were conducted using two benchmark SCADA datasets, WUSTL-IIoT-2018 and WUSTL-IIoT-2021. The results demonstrated outstanding detection performance, with all models achieving accuracy rates above 99.91%. Specifically, RF, DT, KNN, and XGBoost reached perfect accuracy (100%) on the WUSTL-IIoT-2018 dataset, while XGBoost, LSTM, and CNN achieved 99.99% accuracy on WUSTL-IIoT-2021. Additional evaluation metrics, including precision, recall, and F1-score, confirmed the robustness of the models. The findings highlight the potential of AI-driven IDS solutions to enhance the security and resilience of industrial SCADA infrastructures.References
Al-Abassi, A., Karimipour, H., Dehghantanha, A., & Parizi, R. M. (2020). An Ensemble Deep Learningbased CyberAttack Detection in Industrial Control System. Proceedings of the IEEE.
Alzahrani, A., & Aldhyani, T. H. H. (2023). Design of Efficient Based Artificial Intelligence Approaches for Sustainable of Cyber Security in Smart Industrial Control System. Sustainability, 15 (10), 8076. DOI: 10.3390/su15108076
Basak, J. (2006). Online adaptive decision trees: Pattern classification and function approximation. Neural Computation, 18 (9), 2062–2101.
Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 785–794. DOI: 10.1145/2939672.2939785
Chen, T., Zhang, H., & Li, W. (2017). Security challenges and solutions in SCADA systems: A survey. Journal of Computer Security, 25 (1), 1–30. DOI: 10.3233/JCS160771
Cui, L., Qu, Y., Gao, L., Xie, G., & Yu, S. (2020). Detecting False Data Attacks Using Machine Learning Techniques in Smart Grid: A Survey. Journal of Network and Computer Applications, 102808.
Cutler, A., Cutler, D.R., & Stevens, J.R. (2012). Random forests. Ensemble Machine Learning: Methods and Applications, 157–175.
Daneels, A., & Salter, W. (1999). What is SCADA? International Conference on Accelerator and Large Experimental Physics Control Systems, 1999, Trieste, Italy
Dehlaghi-Ghadim, A., Moghadam, M.H., Balador, A., & Hansson, H. (2023). Anomaly Detection Dataset for Industrial Control Systems. ArXiv Preprint, 2305.09678.
Dina, A.S., Siddique, A.B., & Manivannan, D. (2023). A Deep Learning Approach for Intrusion Detection in Internet of Things Using Focal Loss Function. Internet of Things, 22, 100699.
Freund, Y., & Schapire, R.E. (1996). Experiments with a new boosting algorithm. Proceedings of the Thirteenth International Conference on Machine Learning (ICML-96), 148–156.
Friedman, J.H. (2001). Greedy function approximation: A gradient boosting machine. Proceedings of the 13th International Conference on Neural Information Processing Systems (NIPS-01), 1026–1034.
Gao, J., & colleagues. (2023). Detection of Temporally Correlated and Uncorrelated Attacks in SCADA Systems Using FNN-LSTM Model. Journal of Industrial Cybersecurity, 12 (4), 102–115.
Gao, J., Gan, L., Buschendorf, F., Zhang, L., Liu, H., Li, P., Dong, X., & Lu, T. (2020). Omni SCADA Intrusion Detection Using Deep Learning Algorithms. IEEE Internet of Things Journal, 8 (2), 951–961.
Gao, X., & colleagues. (2023). Enhancing SCADA System Security Using Deep Learning Techniques. Journal of Industrial Cybersecurity.
Gungor, V.C., & Hancke, G.P. (2009). Industrial wireless sensor networks: Challenges, design principles, and technical approaches. IEEE Transactions on Industrial Electronics, 56 (10), 4258–4265. DOI: 10.1109/TIE.2009.2015754
Hochreiter, S., & Schmidhuber, J. (1997). Long shortterm memory. Neural Computation, 9 (8), 1735–1780. DOI: 10.1162/neco.1997.9.8.1735
Huma, Z.E., Latif, S., Ahmad, J., Idrees, Z., Ibrar, A., Zou, Z., Alqahtani, F., & Baothman, F. (2021). A Hybrid Deep Random Neural Network for Cyberattack Detection in the Industrial Internet of Things. IEEE Access, 9, 55595–55605. DOI: 10.1109/ACCESS.2021.3071766
in St. Louis, W.U. (2018). WUSTL-IIOT-2018: Industrial Internet of Things Dataset.
in St. Louis, W.U. (2021). WUSTL-IIOT-2021: Industrial Internet of Things Dataset.
Jmila, M., & Houda, A. (2022). Evaluating the Robustness of Shallow Classifiers in Intrusion Detection Systems Against Adversarial Attacks. Journal of Cybersecurity and Machine Learning, 15 (3), 250–265.
Kalech, M. (2019). Cyber-Attack Detection in SCADA Systems Using Temporal Pattern Recognition Techniques. Computers & Security, 84, 225–238.
Karami, M., & Shamsi, S. (2019). A survey of cyberattacks on SCADA systems and their countermeasures. Journal of Computer Networks and Communications, 2019, 1–17. DOI: 10.1155/2019/7472493
Krishnan, S., & Wei, M. (2019). SCADA Testbed for Vulnerability Assessments, Penetration Testing and Incident Forensics. Proceedings of the 7th International Symposium on Digital Forensics and Security.
LeCun, Y., Bengio, Y., & Hinton, G. (2015). Deep learning. Nature, 521 (7553), 436–444. DOI: 10.1038/nature14539
Lu, Y., Xu, X., & Wang, L. (2019). The industrial Internet of Things: A survey. Computer Networks, 148, 258– 277. DOI: 10.1016/j.comnet.2018.11.014
Morris, T., & colleagues. (2023). Investigating Security Vulnerabilities and Cyberattacks in SCADA Systems Using Neural Network Methods. Mississippi State University SCADA Security Lab Research
of Automation, I.S. (2022). ISA100 Wireless Standard.
Patel, V., Patel, K., & Patel, K. (2019). A review on SCADA systems and their applications in industrial automation. International Journal of Engineering and Technology, 7 (4), 62–68. DOI: 10.7763/IJET.2019. V7.867
Qaiser, G., Chandrasekaran, S., Chai, R., & Zheng, J. (2023). Classifying DDoS Attack in Industrial Internet of Services Using Machine Learning. Proceedings of the 15th International Conference on Computer and Automation Engineering (ICCAE), 546–550.
Quincozes, S.E., Albuquerque, C., Passos, D., & Mosse, D. (2021). A Survey on Intrusion Detection and Prevention Systems in Digital Substations. Computers and Networks, 184, 107679.
Radoglou-Grammatikis, P.I., & Sarigiannidis, P.G. (2019). Securing the Smart Grid: A Comprehensive Compilation of Intrusion Detection and Prevention Systems. IEEE Access, 7, 46595–46620.
Rahman, M.M., Al Shakil, S., & Mustakim, M.R. (2025). A survey on intrusion detection system in IoT networks. Cyber Security and Applications, 3, 100082.
Rakas, S.V.B., Stojanovic, M.D., & MarkovicPetrovic, J.D. (2020). A Review of Research Work on Network-Based SCADA Intrusion Detection Systems. IEEE Access, 8, 93083–93108.
Riggins, F.J., & Wamba, S.F. (2015). Research directions on the adoption, usage, and impact of the Internet of Things through the use of Big Data analytics. Proceedings of the 48th Hawaii International Conference on System Sciences (HICSS), 1531–1540. DOI: 10.1109/HICSS.2015.186
Rovatti, R., Ragazzoni, R., Kovacs, Z.M., & Guerrieri, R. (1995). Adaptive voting rules for k-nearest neighbors classifiers. Neural Computation, 7 (3), 594–605.
Rumelhart, D.E., Hinton, G.E., & Williams, R.J. (1986). Learning representations by backpropagating errors. Nature, 323 (6088), 533–536. DOI: 10.1038/323533a0
Smith, J., & Brown, T. (2018). Vulnerabilities in SCADA Systems: A Survey. Journal of Industrial Security, 5 (2), 123–135.
Stouffer, K., Falco, J., & Scarfone, K. (2015). Guide to Industrial Control Systems (ICS) Security. National Institute of Standards and Technology (NIST). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf
Tamy, S., Belhadaoui, H., Rabbah, M., Rabbah, N., & Rifi, M. (2019). Select the best machine learning algorithms for prediction and classification of intrusions using kdd99 intrusion detection dataset. Indian Journal of Science and Technology, 12 (37), 1–6.
Tesfahun, A., & Bhaskari, D.L. (2016). A SCADA Testbed for Investigating Cyber Security Vulnerabilities in Critical Infrastructures. Automatic Control and Computer Sciences, 50, 54–62.
Trivedi, S., Tran, T.A., Faruqui, N., & Hassan, M.M. (2023). An Exploratory Analysis of Effect of Adversarial Machine Learning Attack on IoT-enabled Industrial Control Systems. Proceedings of the International Conference on Smart Computing and Application (SCA), 1–8.
Wang, W., Harrou, F., Bouyeddou, B., Senouci, S.M., & Sun, Y. (2022). Cyber-Attacks Detection in Industrial Systems Using Artificial Intelligence-Driven Methods. International Journal of Critical Infrastructure Protection, 38, 100542.
Williams, A., & Zhang, L. (2020). Detection of Reconnaissance Attacks in SCADA Systems Using Network Traffic Analysis. IEEE Transactions on Industrial Informatics, 10 (4), 1827–1836.
Wu, Y., & colleagues. (2023). Advancements in Deep Learning for SCADA System Protection. Journal of Cybersecurity and Automation.
Xu, Z., Li, Y., & Zhang, H. (2020). Artificial intelligence for cybersecurity in critical infrastructure protection: A review. Future Generation Computer Systems, 106, 719–734. DOI: 10.1016/j.future.2019.12.024
Yalçın, N., Çakır, S., & Ünaldı, S. (2024). Attack Detection Using Artificial Intelligence Methods for SCADA Security. IEEE Internet of Things Journal. DOI: 10.1109/JIOT.2024.3447876
Yang, J., & Chen, L. (2019). Deep Learning Approaches for Enhancing SCADA System Security. International Journal of Critical Infrastructure Protection, 22, 15-28.
Zainudin, A., Ahakonye, L.A.C., Akter, R., Kim, D.-S., & Lee, J.-M. (2022). An efficient hybrid-dnn for ddos detection and classification in software-defined iiot networks. IEEE Internet of Things Journal, 10 (10), 8491–8504.
Zeng, P., & Zhou, P. (2018). Intrusion Detection in SCADA System: A Survey. In Intelligent Computing and Internet of Things (pp. 342–351). Springer.
Zolanvari, M., Teixeira, M.A., Gupta, L., Khan, K.M., & Jain, R. (2019). Machine Learning-Based Network Vulnerability Analysis of Industrial Internet of Things. IEEE Internet of Things Journal, 6(4), 6822–6834. DOI: 10.1109/JIOT.2019.2918437