Detecting Anomalies by using Self-Organizing Maps in Industrial Environments

Detecting Anomalies by using Self-Organizing Maps in Industrial Environments
复制标题

在工业环境中使用自组织映射检测异常

DOI:
10.5220/0007364803360344
复制
发表时间:
2019
期刊:
Water-Resources Investigations Report
影响因子:
--
通讯作者:
Eric Fischer
Eric Fischer
中科院分区:
--
文献类型:
--
作者:
Ricardo Hormann;Eric Fischer

文献摘要

被引文献

相似文献

由于复杂的环境相互依赖和专有的现场总线协议,检测入侵者造成的异常在工业环境中是一个巨大的挑战。本文提出了一种基于网络的无监督人工神经网络异常检测方法,称为自组织映射(SOMS)。因此,我们发布了一种算法来识别SOM中的簇和簇质心,以获取关于底层数据结构的知识。在训练阶段,我们创建了两个神经网络,一个用于对网络数据进行聚类,另一个用于寻找聚类质心。在运行阶段,我们的方法能够通过将新的数据样本与第一个训练好的SOM模型进行比较来检测异常。我们使用一个可信区间来确定样本是否离其最佳匹配单元太远。针对机器学习方法在异常检测中的一个主要缺陷--误报,提出了一种新的第二种自组织映射的附加置信度区间。我们在机器人单元中实现了我们的方法,并像入侵者评估我们的方法一样渗透到网络中。结果,我们使用第二个区间将误警率显著降低到0.07%,同时为网络攻击检测提供了99%的准确率。
Detecting anomalies caused by intruders are a big challenge in industrial environments due to the complex environmental interdependencies and proprietary fieldbus protocols. In this paper, we proposed a network-based method for detecting anomalies by using unsupervised artificial neural networks called Self-Organizing Maps (SOMs). Therefore, we published an algorithm which identifies clusters and cluster centroids in SOMs to gain knowledge about the underlying data structure. In the training phase we created two neural networks, one for clustering the network data and the other one for finding the cluster centroids. In the operating phase our approach is able to detect anomalies by comparing new data samples with the first trained SOM model. We used a confidence interval to decide if the sample is too far from its best matching unit. A novel additional confidence interval for the second SOM is proposed to minimize false positives which have been a major drawback of machine learning methods in anomaly detection. We implemented our approach in a robot cell and infiltrated the network like an intruder would do to evaluate our method. As a result, we significantly reduced the false positive rate to 0.07% using the second interval while providing an accuracy of 99% for the detection of network attacks.