Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

AI Augmented Threat Detection in Industrial Control Systems: A Systematic Review of Machine Learning Approaches for ICS Anomaly Detection

Abolaji Adebayo1, Mayokun Philips Adegbite2, Mubarak Olayiwola Ahmed3, Mayokun Philips Adegbite

Abstract

Anomaly detection in industrial control system networks has been the subject of sustained academic and practitioner attention, with machine learning emerging as the dominant analytical approach. This systematic review synthesizes literature published through 2023 to characterize the maturity, methodology, and evaluation rigor of machine learning anomaly detection research targeted at industrial control system environments. A structured search across major databases yielded a corpus that the review classifies along several dimensions, namely learning paradigm, model architecture, data source, evaluation method, and reported performance. The review covers supervised approaches based on classical algorithms and deep neural networks, unsupervised approaches including autoencoders and density-based methods, semi supervised approaches that combine small labeled sets with larger unlabeled corpora, and reinforcement learning approaches that learn detection policies. The corpus is dominated by autoencoder based unsupervised methods, in part because labeled attack data is scarce in operational environments. The review highlights persistent methodological gaps, including reliance on a small number of public datasets, limited cross dataset evaluation, weak baseline comparisons, optimistic threshold selection, and limited discussion of operational deployment concerns such as drift, retraining, and explainability. The review identifies emerging directions including physics informed models that incorporate process equations, graph neural networks that reason about device topology, federated approaches that share model improvements without sharing sensitive process data, and explainable detection content suitable for engineering review. The review concludes with recommendations for the research community, vendors, and asset owners, with an emphasis on benchmarking, deploy ability, and meaningful integration with security operations.

Keywords

machine learning; industrial control systems; anomaly detection; systematic review; artificial intelligence; cybersecurity.

References

Abdallah, A., Maarof, M.A. and Zainal, A. (2016). Fraud detection system: A survey. Journal of Network and Computer Applications, 68, 90 to 113. Ackerman, P. (2017). Industrial Cybersecurity: Efficiently Secure Critical Infrastructure Systems. Packt Publishing, Birmingham. Adebayo, A. (2020). Wireless internet service provider network reliability frameworks for emerging markets. International Journal of Network and Communication Research, 5(2), 88-103. Tizeti Inc., Nigeria. Adebayo, A. (2021a). Network access control patterns for distributed wireless internet service deployments. International Journal of Information Security Research, 11(4), 215-232. Tizeti Inc., Nigeria. Adebayo, A. (2021b). Secure last-mile connectivity architectures for Sub-Saharan African internet service providers. Journal of African Information Systems, 12(3), 145-162. Tizeti Inc., Nigeria. Adebayo, A. (2022a). Compliance frameworks for financial technology platforms operating across multiple jurisdictions. International Journal of Regulatory Technology, 6(3), 134-152. Squad, Nigeria. Adebayo, A. (2022b). Fintech payment infrastructure security: Threat modeling for high-volume transaction processing platforms. Journal of Financial Technology Security, 8(2), 198-217. Squad, Nigeria. Adebayo, A. (2023a). Cybersecurity workforce development through applied research curricula: A case study approach. Journal of Cybersecurity Education and Research, 14(2), 78-95. East Tennessee State University, Tennessee, USA. Adebayo, A. (2023b). Network defense practices in small and medium enterprises: Empirical observations from regional case studies. International Journal of Enterprise Security, 9(4), 245-263. East Tennessee State University, Tennessee, USA. Adepu, S. and Mathur, A. (2016). An investigation into the response of a water treatment system to cyber attacks. HASE 2016, 141 to 148. Adepu, S., Brasser, F., Garcia, L., Rodler, M., Davi, L., Sadeghi, A.R. and Zonouz, S. (2020). Control behavior integrity for distributed cyber physical systems. ACM/IEEE ICCPS 2020. Adesuyi, M. O., Walawalkar, G., & Kalu, A. (2021). Decision-centric financial analytics for executive-level strategy formulation. Journal of Accounting and Financial Management, 7(5), 152 to 173. Adesuyi, M. O., Kalu, A., & Walawalkar, G. (2023). Data-led cost governance in technology- intensive enterprises. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 9(3), 877 to 896. https://doi.org/10.32628/Ijsrcseit Adeyoyin, O., Awanye, E. N., Morah, O. O., & Ekpedo, L. (2020). A Conceptual Framework Linking Financial Strategy and Operational Excellence in Manufacturing Firms. Adeyoyin, O., Awanye, E. N., Morah, O. O., & Ekpedo, L. (2021). A Conceptual Framework for Integrating ESG Priorities into Sustainable Corporate Operations. Agbabiaka, J., Okonkwo, C.S., Ogunwole, O., Mayo, W. & Okeke, O.T. (2019). Supply Chain Risk Management Model for EPC and Gas Processing Projects. IRE Journals, 3(2), 968 to 980. DOI: 10.64388/IREV3I2-1713124. Aggarwal, C.C. (2017). Outlier Analysis (2nd ed.). Springer, Cham. Ahmed, M., Mahmood, A.N. and Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19 to 31. Ahmed, K.S. & Odejobi, O.D. (2018). Conceptual Framework for Scalable and Secure Cloud Architectures for Enterprise Messaging. IRE Journals, 2(1), 1-15. Ahmed, K. S., Odejobi, O. D., & Oshoba, T. O. (2019). Algorithmic model for constraint satisfaction in cloud network resource allocation. IRE Journals, 2(12). ISSN: 2456-8880. Ahmed, K.S., Odejobi, O.D. & Oshoba, T.O. (2020). Predictive Model for Cloud Resource Scaling Using Machine Learning Techniques. Journal of Frontiers in Multidisciplinary Research, 1(1), 173-183. DOI: 10.54660/.Ijfmr.2020.1.1.173-183. Ahmed, K. S., Odejobi, O. D., & Oshoba, T. O. (2021). Certifying algorithm model for Horn constraint systems in distributed databases. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 7(1), 537-554. Aifuwa, S. E., Oshoba, T. O., Ogbuefi, E., Ike, P. N., Nnabueze, S. B., & Olatunde-Thorpe, J. (2020). Predictive analytics models enhancing supply chain demand forecasting accuracy and reducing inventory management inefficiencies. International Journal of Multidisciplinary Research and Growth Evaluation, 1(3), 171-181. DOI: 10.54660/.IJMRGE.2020.1.3.171-181. Ajayi, A. E., Moyo, T. M., Tafirenyika, S., Taiwo, A. E., Tuboalabo, A., & Bukhari, T. T. (2022). Predictive Analytics Systems for Enhancing Financial Forecast Accuracy and Real-Time Monitoring in Hospital Networks. Akeju, B., Edivri, J., Ogbole, J. I., Okoruwa, P. O., Fadayomi, O., & Abolaji, T. O. (2018). Conceptual model for insider threat classification and risk modeling in complex digital systems. IRE Journals, 1(9). https://doi.org/10.64388/IREV1I9-1713778 Akhigbe, R., Falemi, A., & Akin-Oluyomi, O. T. (2023). A Conceptual Model for Improving Customer Experience using Workforce Behavior and Real-Time Operational Data. Akhtar, N. and Mian, A. (2018). Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6, 14410 to 14430. Akin-Oluyomi, O. T., & Akhigbe, R. (2022). A supply chain governance model for enhancing compliance and operational quality across retail networks. All Multidisciplinary Journal. Akin-Oluyomi, O. T., & Akhigbe, R. (2023a). A proposed supply chain analytics framework for improving forecasting accuracy and reducing bottlenecks. Akin-Oluyomi, O. T., & Akhigbe, R. (2023b). An advanced framework for improving multi-site operational efficiency using data-driven performance indicators. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2021a). Applied Statistics Models Optimizing Global Supply Chain Networks Under Uncertainty Conditions. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2021b). Cross-Functional Framework using AI-Enhanced Analysis for Supplier Selection Accuracy. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2022). Data Visualization with Predictive Modeling Measuring Workplace Diversity Performance Metrics. Akinlade, O. F., Filani, O. M., & Nwachukwu, P. S. (2023). AI-Integrated Procurement Frameworks Aligning Operational Efficiency with Organizational Strategic Goals. Akinleye, O. K., & Adeyoyin, O. (2021). Process Automation Framework for Enhancing Procurement Efficiency and Transparency. Akinleye, O. K., & Adeyoyin, O. (2022). Supplier Relationship Management Framework for Achieving Strategic Procurement Objectives. Akinleye, O. K., & Adeyoyin, O. (2023). A Category Spend Mapping and Supplier Risk Assessment Framework for Global Supply Chains. Akinlolu, V. S., Omaghomi, T. T., Fapohunda, M., & Atima, M. E. (2022). A systems-level policy framework for integrating mental health screening into primary healthcare in low-resource settings. Akinlolu, V. S., Fapohunda, M., Omaghomi, T. T., Atima, M. E., & Igweonu, C. (2023). A proposed care-coordination framework for reducing readmissions among chronic disease patients. Multidisciplinary Global Environment Journal, 4(5), 1187 to 1195. Akinola, A. S., Adesanya, O. S., Okafor, C. M., & Farounbi, B. O. (2018). Automated Payroll Compliance Assurance: Linking Withholding Algorithms to Financial Statement Reliability. IRE Journals, 1(7). Akinola, A. S., Farounbi, B. O., Onyelucheya, O. P., & Okafor, C. M. (2020a). Translating finance bills into strategy: Sectoral impact mapping and regulatory scenario analysis. Journal of Frontiers in Multidisciplinary Research, 1(1), 102-111. Akinola, A. S., Okafor, C. M., Dako, O. F., & Adesanya, O. S. (2020b). Evidence-informed Advisory for Ultra-High-Net-Worth Clients: Portfolio Governance and Fiduciary Risk Controls. Journal of Frontiers in Multidisciplinary Research, 1(2), 112-120. Akomolafe, O., Agu, M. U., & Bello, A. (2023). A Conceptual Model for Implementing Risk- Based Auditing in Strategic Financial Management. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2274-2286. Aldaraani, N. and Begum, Z. (2018). Understanding the impact of ransomware: A survey on its evolution, mitigation and prevention techniques. NCC 2018, 1 to 5. Alexander, O., Belisle, M. and Steele, J. (2020). MITRE ATT&CK for Industrial Control Systems: Design and Philosophy. MITRE Corporation, McLean, VA. Aliliele, C., Mbonu, I.S. and Iwuanyanwu, U. (2023a). A Conceptual Framework for Continuous Cloud Misconfiguration Monitoring and Enterprise Risk Mitigation Strategies. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 9(10), 373 to 394. Aliliele, C., Mbonu, I.S. and Iwuanyanwu, U. (2023b). A Review of API Governance and Risk Prioritization Frameworks in Modern Financial Institutions. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 9(10), 395 to 433. Aliliele, C., Mbonu, I.S. and Iwuanyanwu, U. (2023c). Advances in Predictive Analytics Models for Student Retention and Institutional Risk Management Systems. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2692 to 2711. Alladi, T., Chamola, V. and Zeadally, S. (2020). Industrial control systems: Cyberattack trends and countermeasures. Computer Communications, 155, 1 to 8. Alliance, C. S. (2022). Cloud Controls Matrix v4. Cloud Security Alliance, Seattle, WA. Alliance, C. S. (2023). Top Threats to Cloud Computing: Pandemic Eleven. Cloud Security Alliance, Seattle, WA. Almorsy, M., Grundy, J. and Muller, I. (2016). An analysis of the cloud computing security problem. arXiv preprint arXiv:1609.01107. Alsentzer, E., Murphy, J.R., Boag, W., Weng, W.H., Jin, D., Naumann, T. and McDermott, M. (2019). Publicly available clinical BERT embeddings. Proceedings of the 2nd Clinical Natural Language Processing Workshop, 72 to 78. Ambali, K.B., Eyetsemitan, R.A., Oyeleye, A.O. & Fadayomi, O. (2021). Lean Six Sigma for Small Enterprises: A Systematic Review and Lite-DMAIC Adaptation Framework for Resource-Constrained Organizations. IRE Journals, 5(5), 562 to 583. DOI: 10.64388/IREV5I5 to 1716957 Amebleh, J., Igba, E. & Ijiga, O. M. (2021). Graph-Based Fraud Detection in Open-Loop Gift Cards: Heterogeneous GNNs, Streaming Feature Stores, and Near-Zero-Lag Anomaly Alerts International Journal of Scientific Research in Science, Engineering and Technology Volume 8, Issue 6 DOI: https://doi.org/10.32628/IJSRSET214418 Aminu-Ibrahim, A. Y., Ogbete, J. C., & Ambali, K. B. (2018). Developing sustainable diagnostic laboratory infrastructure models for emerging and resource constrained health systems. Iconic Research and Engineering Journals, 1(8), 118 to 132.https://doi.org/10.64388/IREV1I8 to 1713586 Aminu-Ibrahim, A.Y., Ogbete, J.C. & Ambali, K.B. (2019). Capital Project Delivery Models for High Risk Healthcare Infrastructure in Developing National Health Systems. Iconic Research and Engineering Journals, 2(10), 626 to 649. DOI: 10.64388/IREV2I10 to 1713588. Aminu-Ibrahim, A.Y., Ogbete, J.C. & Ambali, K.B. (2020). Infrastructure Driven Expansion of Diagnostic Access Across Underserved and Rural Healthcare Regions. International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), 691 to 706. DOI: 10.54660/IJMRGE.2020.1.5.691 to 706. Aminu-Ibrahim, A.Y. & Ogbete, J.C. (2023). Healthcare Infrastructure as a Public Health Intervention Using Evidence from Large Laboratory Networks. Shodhshauryam, International Scientific Refereed Research Journal, 6(1), 256 to 286. DOI: 10.32628/SHISRRJ23678. Ani, U.P.D., He, H. and Tiwari, A. (2017). Review of cybersecurity issues in industrial critical infrastructure: Manufacturing in perspective. Journal of Cyber Security Technology, 1(1), 32 to 74. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2019). Global marketing law and consumer protection challenges: a strategic framework for multinational compliance. IRE Journals, 3(6), 325-333. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2020). Designing ethics and compliance training frameworks to drive measurable cultural and behavioral change. Int J Multidiscip Res Growth Eval, 1(3), 205-20. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2021a). Blockchain-based architectures for tamper-proof regulatory recordkeeping and real-time audit readiness. Int J Multidiscip Res Growth Eval, 2(6), 485-504. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2021b). Digital Marketing Compliance Risk Mitigation: Balancing Growth Objectives with Multi-Jurisdictional Regulations. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2022). LegalTech-Enabled Internal Audit Automation: Advancing Efficiency, Transparency, and Regulatory Preparedness. Anichukwueze, C. C., Osuji, V. C., & Oguntegbe, E. E. (2023). Building a Comprehensive AI Governance Risk Index to Support Global Enterprise Decision-Making. Anioke, S. C., & Atima, M. E. (2018). Regulatory Analytics Approaches for Improving Occupational Health Safety Outcomes Across Public and Private Workplaces. Anioke, S. C., & Atima, M. E. (2019). Digital Employer Risk Rating Frameworks Supporting Public Health Oriented Social Insurance Compliance Systems. Anioke, S. C., & Atima, M. E. (2023a). Public health governance models using process optimization and performance metrics for regulatory oversight. International Journal of Advanced Multidisciplinary Research and Studies, 3(6), 2534 to 2548. https://doi.org/10.62225/2583049X.2023.3.6.5491 Anioke, S. C., & Atima, M. E. (2023b). Public health informatics frameworks for protecting vulnerable populations through data-driven policy enforcement. International Journal of Advanced Multidisciplinary Research Studies, 3(6), 2564 to 2579. Anthony, P., Ezeh, F.E., Oparah, O.S., Gado, P., Adeleke, A.S., Gbaraba, S.V., Okoli, A.O. & Omotayo, O. (2023). Adaptive Multi-Modal AI Systems for Continuous Disease Monitoring Via IoT and Wearable Devices. International Journal of Advanced Multidisciplinary Research and Studies, 3(1), 1557 to 1570. DOI: 10.62225/2583049X.2023.3.1.5158. Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J. et al. (2017). Understanding the Mirai botnet. USENIX Security 2017, 1093 to 1110. Anwar, S. and Soltesz, B. (2016). Securing the smart grid. International Journal of Advanced Research in Computer Science, 7(1). Apruzzese, G., Colajanni, M., Ferretti, L., Guido, A. and Marchetti, M. (2018). On the effectiveness of machine and deep learning for cyber security. CyCon 2018, 371 to 390. Apruzzese, G., Colajanni, M., Ferretti, L. and Marchetti, M. (2019). Addressing adversarial attacks against security systems based on machine learning. International Conference on Cyber

More Articles from INTERNATIONAL JOURNAL OF ENGINEERING AND MODERN TECHNOLOGY