Skip to main content

Léa Kenmogne

Thursday, October 15, 2026

Process-aware attack detection in industrial control systems using explianable artificial intelligence

Abstract: 

Cybersecurity of Industrial Control Systems (ICS) is a field of research that gained prominence around the 2010s, following the emblematic Stuxnet attack. This incident highlighted a new category of cyber-threats, capable of targeting physical processes controlled by industrial systems whilst evading traditional detection methods. The increasing number of such attacks over time (Industroyer, BlackEnergy) highlights the need to focus on detecting these intrusions.

The aim of this thesis is to develop an Intrusion Detection System (IDS) specifically designed for industrial systems to detect process-aware attacks. These so-called "stealth'' attacks do not necessarily violate communication protocols and do not generate suspicious traffic, making them difficult to identify using systems based on signatures or conventional behavioural models. In this context, conventional approaches to cybersecurity are reaching their limits, particularly when faced with process-oriented attacks that manipulate the system’s internal states without visibly altering communications. We propose an approach based on artificial intelligence, and more specifically on eXplainable Artificial Intelligence (XAI), with a twofold objective: to detect anomalous behaviour, whilst providing human operators understandable explanations of the model’s predictions.

Our methodology comprises three main stages: firstly, we conduct a study and analysis of the process under investigation in order to understand how it functions. Next, we benchmark models to select the most suitable one for detecting intrusions in the process studied, and we train this model. Finally, we apply three explainability methods (SHAP, LIME and LEMNA) to understand the model’s predictions.

We have applied this methodology to a simulated industrial process and to an industrial dataset (SWaT). The results show that explainability enables us to understand the model’s decisions by identifying the variables that influence an alert, and also reveals other compromised security properties that were invisible to specification-based approaches. The integration of these techniques into on-time IDSs could therefore significantly improve the ability of industrial systems to deal with increasingly sophisticated cyber threats.

 

Keywords: Intrusion Detection, Industrial Control Systems, Process-aware Attacks, Physical process, eXplainable Artificial Intelligence 

 

Date and place

Thursday, October 15 at 10:00
Presqu'île Grenoble Bâtiment GREn-Er, ENSE3 (amphitéâtre Coulomb)

and Lien Zoom

Jury members

Stéphane MOCANU
Associate Professor, HDR, University of Grenoble Alpes (Thesis Supervisor)
Abdelkader LAHMADI
Full Professor, University of Lorraine (Reviewer)
Gil UTARD
Full Professor, University of Picardie Jules Verne (Reviewer)
Grégor GÖSSLER
Research Director, Inria Grenoble Alpes (Examiner)
Pierre-François GIMENEZ
Research Scientist, Iniria Rennes (Examiner)

Submitted on October 8, 2026

Updated on October 8, 2026