Solving the Cross-Sector Generalization Gap: A Generalizable AI Framework for Detecting Known and Unseen Cyberattacks in Critical Infrastructure
This paper proposes and evaluates a single, sector-agnostic AI framework using a Random Forest classifier on a 15-dimensional feature space that successfully detects both known and zero-day cyberattacks across five heterogeneous critical infrastructure domains while distinguishing them from physical faults, thereby demonstrating that a unified, explainable model can replace multiple sector-specific intrusion-detection systems.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The modern world runs on a vast, invisible nervous system of machines and networks. From the water treatment plants that keep our taps clean to the power grids lighting our cities, the railways moving our trains, the ships navigating our oceans, and the factories building our goods, these systems rely on operational technology. This is the specialized software and hardware that monitors and controls physical processes. For decades, security experts have treated each of these sectors as a separate island. They built custom defenses for the water plant, different ones for the power grid, and yet others for the railways, assuming that the unique language of sensors in one industry could not be understood by a system designed for another. This approach has created a fragmented landscape where securing the interconnected world requires a different tool for every job, a method that is expensive and difficult to scale as these systems become more linked.
A team of researchers from the International Islamic University Chittagong has challenged this long-held assumption. They asked a simple but profound question: could a single artificial intelligence system learn to recognize the universal signs of a cyberattack across all these different industries, even if it had never seen that specific industry before? Their work suggests that the answer is yes. By training a computer model to look at the behavior of data rather than the specific names of the sensors, they created a unified detector that can spot both known attacks and brand-new, unseen threats across five distinct critical infrastructure sectors. The results indicate that a single, adaptable system could eventually replace a fleet of specialized detectors, offering a more efficient and understandable way to protect the essential services society depends on.
The researchers focused on five diverse sectors: water and wastewater treatment, the electrical power grid, railway signaling, maritime navigation, and industrial manufacturing. In the real world, these systems speak different languages. A water plant might monitor pressure and water clarity, while a power grid tracks voltage and electrical frequency. A railway system watches brake pressure and train speed, and a ship monitors its engine speed and rudder angle. Traditionally, an artificial intelligence trained on water data would be useless for a power grid because it would not understand the specific numbers involved. The researchers realized that while the names of the sensors differ, the way a machine behaves when it is under attack might share common patterns.
To test this, they built a framework that translates the raw data from each sector into a common, simplified language. Instead of feeding the computer the raw sensor readings, they calculated a set of statistical summaries for every window of time. They looked at how fast the numbers were changing, how much they were bouncing around, and how spread out the values were. These summaries created a single, fixed list of numbers for every sector, stripping away the specific vocabulary of water or electricity and leaving only the mathematical shape of the data. This allowed them to train one single computer model, a type of decision-making system known as a random forest, on data from all five sectors at once.
The team put this single model through a rigorous series of tests to see if it could truly generalize. First, they checked if it could detect attacks within the sector it was trained on. The model succeeded, correctly identifying attacks in water, power, rail, maritime, and industrial systems with accuracy rates ranging from roughly 79 percent to 86 percent. This proved that the model could learn the specific nuances of each industry. But the real test came when they tried to transfer that knowledge. They trained the model on four sectors and then asked it to identify attacks in the fifth sector, a domain it had never seen before. Remarkably, the model performed just as well in these new environments, achieving accuracy between 80 and 86 percent. This demonstrated that the system had learned the underlying logic of an attack, rather than just memorizing the specific sensor names of one industry.
Perhaps the most significant finding was the system's ability to detect attacks it had never encountered. In the world of cybersecurity, the most dangerous threats are "zero-day" attacks, which are new and unknown to defenders. The researchers tested their model by withholding a specific type of stealthy attack from the training data entirely. When they presented this unseen attack to the model, it still managed to identify it with high confidence, achieving a detection rate of over 82 percent. This suggests that the model had learned to recognize the subtle, erratic behavior that characterizes a cyber intrusion, regardless of whether it had seen that specific trick before.
The researchers also addressed a critical operational problem: distinguishing between a malicious cyberattack and a simple, harmless machine fault. In the past, security systems often confused a sensor that was drifting due to age or a motor that was wearing out with a deliberate attack, leading to false alarms that eroded trust. Their framework was able to tell the difference between a cyberattack and a physical fault with nearly 90 percent accuracy. This is a vital capability, as it ensures that operators are alerted to genuine threats rather than being distracted by routine equipment wear and tear.
Finally, the team ensured that the system was not a "black box" that gave answers without explanation. They analyzed which statistical features the model relied on most to make its decisions. They found that the system was driven primarily by the volatility of the rate of change—essentially, how wildly and quickly the data was jumping around. This makes intuitive sense, as a cyberattack often disrupts the smooth, predictable flow of machine data, causing sudden, erratic spikes. Because the model is built on these clear, understandable statistical rules, security operators can see exactly why an alert was triggered, providing a transparent trail of evidence rather than a mysterious label.
The study does have its boundaries. The data used to train and test the system was generated by computer simulations designed to mimic real-world physics, rather than coming from live, operational networks. While the simulations were carefully crafted to include realistic noise and complexity, the researchers acknowledge that real-world systems contain additional layers of unpredictability that simulations cannot fully capture. They also note that their current system provides a general explanation for its decisions but does not yet explain the reasoning behind every single individual alert. Despite these limitations, the results offer a compelling vision for the future of critical infrastructure security. Instead of building a new, custom defense for every new industry or every new type of sensor, a single, adaptable intelligence could learn the universal language of machine behavior, protecting our water, power, transport, and industry with a unified, transparent, and effective shield.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.