{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/anomaly-detection-with-generative-adversarial","title":"Anomaly Detection with Generative Adversarial Networks for Multivariate Time Series","arxiv_id":"1809.04758","date":"2018-09-13","proceeding":null,"authors":["Dan Li","Dacheng Chen","Jonathan Goh","See-Kiong Ng"],"abstract":"Today's Cyber-Physical Systems (CPSs) are large, complex, and affixed with\nnetworked sensors and actuators that are targets for cyber-attacks.\nConventional detection techniques are unable to deal with the increasingly\ndynamic and complex nature of the CPSs. On the other hand, the networked\nsensors and actuators generate large amounts of data streams that can be\ncontinuously monitored for intrusion events. Unsupervised machine learning\ntechniques can be used to model the system behaviour and classify deviant\nbehaviours as possible attacks. In this work, we proposed a novel Generative\nAdversarial Networks-based Anomaly Detection (GAN-AD) method for such complex\nnetworked CPSs. We used LSTM-RNN in our GAN to capture the distribution of the\nmultivariate time series of the sensors and actuators under normal working\nconditions of a CPS. Instead of treating each sensor's and actuator's time\nseries independently, we model the time series of multiple sensors and\nactuators in the CPS concurrently to take into account of potential latent\ninteractions between them. To exploit both the generator and the discriminator\nof our GAN, we deployed the GAN-trained discriminator together with the\nresiduals between generator-reconstructed data and the actual samples to detect\npossible anomalies in the complex CPS. We used our GAN-AD to distinguish\nabnormal attacked situations from normal working conditions for a complex\nsix-stage Secure Water Treatment (SWaT) system. Experimental results showed\nthat the proposed strategy is effective in identifying anomalies caused by\nvarious attacks with high detection rate and low false positive rate as\ncompared to existing methods.","url_abs":"http://arxiv.org/abs/1809.04758v3","url_pdf":"http://arxiv.org/pdf/1809.04758v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"anomaly-detection-with-generative-adversarial","repo_url":"https://github.com/LiDan456/GAN-AD","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}},{"paper_slug":"anomaly-detection-with-generative-adversarial","repo_url":"https://github.com/LiDan456/MAD-GANs","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}}],"tasks":[{"task_slug":"anomaly-detection","task_name":"Anomaly Detection"},{"task_slug":"time-series-1","task_name":"Time Series"},{"task_slug":"time-series","task_name":"Time Series Analysis"}],"methods":[{"method_slug":"convolution","method_name":"Convolution"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1809.04758","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}