Resilient control and Markov-enhanced hybrid multi-feature intrusion detection for cyber-physical wind farms under SCADA delays and coordinated cyber-attacks
Aug 2026· International Journal of Dynamics and Control· Vol 14· 0 citations· 36 references
TL;DR
A Markov-enhanced hybrid IDS that integrates physics-based modeling, data-driven anomaly detection, and statistical sequence analysis to secure a two-turbine cyber-physical wind farm, offering an analytically scalable architectural path toward more secure renewable energy infrastructures, while larger-farm empirical validation remains future work.
Cloud-enabled Intelligent Transportation Systems (ITS) leverage Vehicle-to-Everything (V2X) communications to support scalable data processing and real-time traffic management. However, this integration significantly expands the cyber-physical attack surface. Conventional intrusion detection systems (IDSs) that rely on static signatures or offline-trained models are often ill-suited to counter adaptive attackers. This paper presents the Adaptive Stackelberg Defense Scheme (ASDS), a proactive intrusion detection system that models attacker-defender interactions as a hierarchical Bayesian Stackelberg game with incomplete information. ASDS employs Bayesian filtering to jointly estimate system states and attacker types in real time, enabling adaptive defense strategies. Evaluated against False Data Injection (FDI), Denial-of-Service (DoS), and spoofing attacks, ASDS achieves detection accuracy between 94% and 98%, false positive rates ranging from 0.02 to 0.08, and response latency under 50 ms. These results underscore its effectiveness in securing cloud-enabled ITS environments.
Emmanuel Kigmo Yonga, Mounirah Djam-Doudou, J. Emati et al.· 2026 6th International Confe...· 0 citations
A DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.
Araf Rahman, M. Salek, Mashrur Chowdhury· 0 citations
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication bandwidth, making conventional security mechanisms difficult to deploy consistently at scale. Intrusion detection systems (IDSs) provide an important defensive layer; however, many machine-learning-based IDSs are developed under static assumptions and may experience performance degradation as traffic distributions evolve due to firmware changes, device onboarding, protocol updates, user behavior variation, or adaptive attacks. This paper presents a hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring. In the experimental pipeline, Isolation Forest is trained exclusively on benign traffic to ensure that the anomaly detector models normal behavior rather than an attack-dominated training distribution. The evaluation uses a large-scale chronologically sampled subset of the CICIoT2023 dataset containing 3,890,621 records while preserving the natural class distribution of 2.35% benign traffic and 97.65% attack traffic. The chronological 80/20 train/test split is established first at the file level, followed by systematic sampling within each split to reduce the risk of leakage across the evaluation boundary. On the 746,094-record test set, the proposed hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, and a false positive rate of 4.77%. The corresponding confusion matrix contains TN = 16,683, FP = 836, FN = 1205, and TP = 727,370, yielding 95.23% specificity and 97.53% balanced accuracy. Standalone Random Forest marginally outperformed the hybrid model in raw accuracy and false positive rate; therefore, the contribution of the proposed framework is centered on deployment-oriented anomaly monitoring, drift awareness, and generalization rather than absolute superiority in static classification metrics. A leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training showed that the hybrid model detected 85.26% of the unseen attack-family samples, compared with 85.18% for Random Forest alone and 7.05% for Isolation Forest alone. These findings provide initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability. The framework is therefore positioned as a competitive IDS that combines supervised detection with anomaly monitoring and concept drift awareness for deployment-oriented IoT security.
Muath A. Obaidat, Meryem Abouali, Aneeza Shakeel· Italian National Conference...· 0 citations
Reliable battery state awareness is essential for energy management and power allocation in hybrid electric ships. However, battery management systems are increasingly exposed to False Data Injection Attacks (FDIAs) in intelligent connected environments, which can distort State of Charge (SOC) estimation and compromise the operational reliability of shipboard power systems. To address this challenge, this paper proposes a closed-loop “Modeling-Detection-Defense” framework for secure SOC estimation in marine cyber-physical energy systems. First, a stealthy FDIA model is developed based on battery dynamics and physical consistency constraints. Second, a hybrid detection method combining unsupervised and supervised learning is proposed to identify attacks. Finally, a long short-term memory network is employed to reconstruct compromised measurements and provide reliable SOC information for continuous energy management. Experimental results demonstrate that the proposed framework mitigates SOC estimation deviations caused by FDIAs. In addition, it effectively reduces power allocation errors and energy losses, thereby improving the cyber-resilience, operational reliability, and energy efficiency of hybrid ship power systems.
Hao Sun, Na Li, Mo Guo et al.· Journal of Marine Science an...· 0 citations
Cyber-physical systems (CPSs) are widely used in safety-critical applications, where both control reliability and communication efficiency are essential. However, open networks make CPSs vulnerable to false data injection (FDI) attacks, which threaten system stability. Existing event-triggered control methods often fail to simultaneously ensure attack resilience, stability, and $H_\infty$ performance. This paper addresses the secure control problem of CPSs under FDI attacks by proposing an observer-based dynamic event-triggered control framework. To counteract the adversarial disturbances, a novel attack-resilient observer is designed to simultaneously estimate both the system states and the injected attack signals, enabling the synthesis of a secure observer-based controller. An advanced dynamic event-triggered mechanism (DETM) is developed by incorporating an internal dynamic variable, which adaptively adjusts triggering thresholds to significantly reduce communication frequency while avoiding Zeno behavior. Through Lyapunov-Razumikhin analysis, the closed-loop system is proven to achieve asymptotic stability and guaranteed $H_\infty$ performance, ensuring robustness against bounded FDI attacks. Theoretical results are validated via numerical simulations, demonstrating the effectiveness of the proposed method in mitigating attack impacts and conserving network resources.
Lei Liu, Ruonan Ren, Baoling Miao· IEEE Transactions on Industr...· 0 citations