[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119859-en":3,"doc-seo-119859-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119859,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Anomaly detection in SCADA systems using machine learning - A Master of Science Thesis","This graduate thesis applies multiple machine learning algorithms to detect anomalies using a dataset generated from a Gas pipeline SCADA system by Mississippi State University’s SCADA laboratory. The study is organized into two tracks: binary classification covering command injection and response injection attacks, and categorized classification analyzing seven attack types. LightGBM and decision trees show stronger performance in binary detection, while LGBM outperforms other models across attack categories. An autoencoder is used to improve classifier performance, and SHAP plots provide explanations for the features driving each attack type.","Mississippi State University  \nScholars Junction  \n\n| Theses and Dissertations | Theses and Dissertations |\n| --- | --- |\n| 5-12-2023\u003Cbr>Anomaly detection in SCADA systems using machine learning\u003Cbr>Eric Kudjoe Fiah\u003Cbr>Mississippi State University, [ef588@msstate.edu](ef588@msstate.edu)\u003Cbr>Follow this and additional works at: [https://scholarsjunction.msstate.edu/td](https://scholarsjunction.msstate.edu/td) |  |\n\nRecommended Citation  \nFiah, Eric Kudjoe, \"Anomaly detection in SCADA systems using machine learning\" (2023) . Theses and Dissertations. 5824.  \n[https://scholarsjunction.msstate.edu/td/5824](https://scholarsjunction.msstate.edu/td/5824)  \nThis Graduate Thesis-Open Access is brought to you for free and open access by the Theses and Dissertations at Scholars Junction. It has been accepted for inclusion in Theses and Dissertations by an authorized administrator of Scholars Junction. For more information, please contact scholcomm@msstate. libanswers.com.  \nAnomaly detection in SCADA systems using machine learning  \nBy  \nEric Kudjoe Fiah  \nApproved by:  \nSudip Mittal (Major Professor)  \nJ. Edward Swan, II Stephen Torri  \nT.J. Jankun-Kelly (Graduate Coordinator) Jason M. Keith (Dean, The Bagley College of Engineering)  \nA Thesis Submitted to the Faculty of Mississippi State University in Partial Fulfillment of the Requirements for the Degree of Master of Science in Computer Science  \nin the Department of Computer Science and Engineering  \nMississippi State, Mississippi  \nMay 2023  \nCopyright by  \nEric Kudjoe Fiah  \n2023  \nName: Eric Kudjoe Fiah  \nDate of Degree: May 12, 2023  \nInstitution: Mississippi State University  \nMajor Field: Computer Science  \nMajor Professor: Sudip Mittal  \nTitle of Study: Anomaly detection in SCADA systems using machine learning  \nPages of Study: 62  \nCandidate for Degree of Master of Science  \nIn this thesis, different Machine learning (ML) algorithms were used in the detection of anomalies using a dataset from a Gas pipeline SCADA system which was generated by Mississippi State University’s SCADA laboratory. This work was divided into two folds: Binary Classification and Categorized classification.  \nIn the binary classification, two attack types namely: Command injection and Response injection attacks were considered. Eight Machine Learning Classifiers were used and the results were compared. The Light GBM and Decision tree classifiers performed better than the other algorithms used.  \nIn the categorical classification task, Seven (7) attack types in the dataset were analyzed using six different ML classifiers. The light gradient-boosting machine (LGBM) outperformed all the other classifiers in the detection of all the attack types. One other aspect of the categorized classification was the use of an autoencoder in improving the performance of all the classifiers  \nused. The last part of this thesis was the use of SHAP plots to explain the features that accounted for each attack type in the dataset.  \nKeywords: Anomaly, Autoencoders, Machine learning, Supervisory Control And Data Acquisition  \nDEDICATION  \nThanks be to God for giving me the strength and wisdom to complete this thesis. I dedicate this work to my wife Adjoa and daughter Soteria for their love and support.  \nACKNOWLEDGEMENTS  \nI would like to thank Dr. Sudip Mittal for the time and expertise he gave me throughout this work. I would like to thank him for his guidance, patience, and valuable corrections in the course of this work and beyond.  \nI would also like to thank my committee members Dr. Ed Swan II and Dr. Stephen Torri for agreeing to serve on my committee. I would like to thank them, especially for all the time, advice, and knowledge they provided for the success of this work.  \nTABLE OF CONTENTS  \nDEDICATION . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ii  \nACKNOWLEDGEMENTS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii  \n[LIST OF TABLES ..........................","cbCaiakPYAJunwGA","https://ap.wps.com/l/cbCaiakPYAJunwGA","pdf",1527715,1,74,"English","en",105,"# Dedication\n# Acknowledgements\n# List of Tables\n# List of Figures\n# List of Symbols, Abbreviations, and Nomenclature\n# Chapter I. Introduction\n## Objectives, Research Questions, and Approach\n## Motivation\n## The architecture of SCADA systems\n## Modbus Protocol\n## Organization of the Work\n# Chapter II. Related Work\n## Background\n## SCADA Security Challenges\n## Some recent attacks on SCADA systems\n## Anomaly Detection\n# Chapter III. Methodology\n## Backgroud\n## Why limited SCADA Systems Dataset\n## Dataset Description\n## Various Attack types in the Dataset\n## Features in Dataset","[{\"question\":\"What is the main goal of the thesis on SCADA systems?\",\"answer\":\"The thesis aims to detect anomalies in a Gas pipeline SCADA dataset using multiple machine learning algorithms and compare their effectiveness for different attack settings.\"},{\"question\":\"How are attacks handled in the thesis’s two classification tasks?\",\"answer\":\"It uses binary classification for command injection and response injection attacks, and categorized classification to analyze seven attack types present in the dataset.\"},{\"question\":\"Which techniques improve performance and interpretability?\",\"answer\":\"An autoencoder is used to improve classifier performance across attack categories, and SHAP plots explain which dataset features account for each attack type.\"}]","Anomaly detection in SCADA systems using machine learning - A Master of Science Thesis | PDF",1785726683,186,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"anomaly-detection-in-scada-systems-using-machine-learning-a-master-of-science-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/anomaly-detection-in-scada-systems-using-machine-learning-a-master-of-science-thesis/119859/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the main goal of the thesis on SCADA systems?","Question",{"text":75,"@type":76},"The thesis aims to detect anomalies in a Gas pipeline SCADA dataset using multiple machine learning algorithms and compare their effectiveness for different attack settings.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How are attacks handled in the thesis’s two classification tasks?",{"text":80,"@type":76},"It uses binary classification for command injection and response injection attacks, and categorized classification to analyze seven attack types present in the dataset.",{"name":82,"@type":73,"acceptedAnswer":83},"Which techniques improve performance and interpretability?",{"text":84,"@type":76},"An autoencoder is used to improve classifier performance across attack categories, and SHAP plots explain which dataset features account for each attack type.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]