Authors
JuHyeon Lee, Ilhwan Ji, Seungho Jeon, Jung Taek Seo
Published in
Sensors (Basel, Switzerland). Volume 26. Issue 18. Sep 20, 2026. Epub Sep 20, 2026.
Abstract
Anomaly detection systems for detecting cyber threats in industrial control systems (ICSs) can suffer performance degradation because rare normal samples may not be sufficiently learned. To address this problem, various data augmentation methods have been studied. However, existing methods may generate data in unknown regions based on model decision boundaries or unnecessarily augment regions that already contain sufficient samples. Many existing methods also require anomalous data. To address these limitations, we propose Tail-Guided Low-Density Normal Data Augmentation (TGLDA), which operates using only normal data. TGLDA consists of a low-density region estimator and a data generator. It identifies low-density regions with relatively few samples in the observed data distribution and selectively augments these regions. TGLDA uses feature-tail seeds as heuristic starting points for generating samples in low-density regions. Experiments on a water treatment cybersecurity dataset show that TGLDA successfully generates data focused on low-density regions compared with other data augmentation methods. When each augmentation method was applied to baseline anomaly detection models, TGLDA achieved the highest Accuracy and F1-score across all models. These results show that TGLDA can mitigate problems caused by a lack of rare normal samples in real-world ICS environments where only normal data are available.
PMID:
42817497
Bibliographic data and abstract were imported from PubMed on 01 Oct 2026.
Read full publication at:
Please sign in
to see all details.
Advertisement
Stats
- Recommendations n/a n/a positive of 0 vote(s)
- Views 13
- Comments 0