LATIDIA · Ciberseguridad
Detectar primero, explicar más tarde: Detección de anomalías gemelas digitales de memoria temporal sin entrenamiento con interpretación LLM post-hoc para ICS
arXiv: 2609.29704v1Tipo de anuncio: nuevo Resumen: Los sistemas de control industrial (ICS) están cada vez más expuestos a ataques ciberfísicos que se manifiestan como desviaciones sutiles y en evolución temporal en el comportamiento del proceso. Detectin
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.29704v1 Announce Type: new Abstract: Industrial Control Systems (ICS) are increasingly exposed to cyber-physical attacks that manifest as subtle and temporally evolving deviations in process behavior. Detecting such anomalies requires reasoning over persistence, cross-signal dependencies, and process-level constraints. Digital Twins (DTs) encode system knowledge through physical and logical relationships between signals, but existing DT-based approaches rely on instantaneous rule violations and lack mechanisms to aggregate weak evidence over time. This paper proposes a training-free anomaly detection method that combines deterministic DT constraints with explicit temporal memory. The DT monitors process signals and produces anomaly scores based on constraint violations, while a lightweight memory mechanism captures persistence and contextual relationships across