Making ML-Based Anomaly Detection Effective for Industrial Control Systems
A seminar
Industrial control systems (ICS) govern critical infrastructure and processes, such as power generation, chemical processing, and water treatment. To defend ICS from harm, machine learning (ML) is commonly proposed for detecting anomalies in ICS process values. This talk covers past and future work that evaluates and proposes solutions to apply anomaly detection to an ICS more effectively. First, it is unclear if and how ML-model outputs can be used to diagnose ICS anomalies. We evaluate a variety of explainable AI (XAI) approaches for attributing ICS anomalies to the underlying components that were manipulated. Second, to better understand how ML-based anomaly detection would be used for ICS in practice, we interview practitioners that monitor ICS to understand their needs and suggest opportunities for adopting ML into ICS environments. Finally, based on the lessons learned from these studies, we provide a roadmap for adoption in practice by informing the design and evaluation of ML-based approaches with configurable, diverse, and representative ICS simulations.
About the Speaker.
Dr. Clement Fung (cfung2@umbc.edu) is an assistant professor in the Computer Science and Electrical Engineering Department at the University of Maryland, Baltimore County. His research interests are at the intersection of security, machine learning, and cyber-physical systems. In particular, he focuses on designing machine-learning-based approaches that focus on the technical and operational challenges of securing systems in practice. He earned his PhD in societal computing from Carnegie Mellon University, where he was a member of the CyLab security and privacy institute. Before that, he received his MS in Computer Science from the University of British Columbia, and his B.A.Sc. in Systems Design Engineering from the University of Waterloo.
https://www.csee.umbc.edu/people/tenure-track-faculty/clement-fung/
Host: Dr. Alan T. Sherman, sherman@umbc.edu
Support for this event was provided in part by the National Science Foundation under SFS grant DGE-2438185.
The UMBC Cyber Defense Lab meets biweekly Fridays 12-1pm. All meetings are open to the public.