Book a demo

Semi-Supervised Anomaly Detection for ICS — 2026

Semi-Supervised Anomaly Detection for ICS — 2026
Explore in Eureka
ICS Security Landscape

Semi-Supervised Anomaly Detection for ICS 2026

Collecting labeled attack data from live critical infrastructure is near-impossible, making semi-supervised methods essential. This landscape covers architectures, application sectors, and the assignee landscape from patent and literature evidence spanning 2013–2025.

2013–2025
publication and filing date range in this dataset
Explore in Eureka
4
core technical architecture clusters in retrieved records
Explore in Eureka
8+
named patent assignees in this dataset
Explore in Eureka
6
application domains benchmarked in retrieved records
Explore in Eureka
Published byPatSnap Insights Team··12 min readVerified by PatSnap Eureka Data
Technology Overview

Why Semi-Supervised Methods Are Central to ICS Security

Semi-supervised anomaly detection for ICS occupies the methodological space between fully supervised classifiers—which require extensive labeled attack samples—and fully unsupervised methods that suffer from high false-positive rates under dynamic operational conditions. The field in this dataset spans normal-behavior modeling, weakly supervised contrastive learning, and hybrid ensemble pipelines.

Systems operate across two data modalities: network traffic using protocol-level features from Modbus, DNP3, and IEC 104, and physical process measurements from PLCs, RTUs, and SCADA historians. A recurring finding is that fusing both modalities outperforms single-modality approaches, as network-layer camouflage attacks can still be detected through physical process deviations.

Technology Architecture Clusters — Patent and Literature Records
Architecture clusters in retrieved records: Autoencoder/Generative (9), One-Class/SVDD (4), Weakly Supervised/Contrastive (4), Hybrid Ensemble/Multi-Stage (4)Horizontal bar chart showing the count of papers and patents per technical architecture cluster in this dataset. Source: PatSnap Eureka retrieved records 2013–2025.Architecture Clusters in Retrieved RecordsAutoencoder / Generative9One-Class / SVDD4Weakly Supervised / Contrastive4Hybrid Ensemble / Multi-Stage4↗ Click bars to explore

Publication dates in this dataset span from 2013 to late 2023, revealing a field that moved from foundational statistical and rule-based work into deep learning dominance within approximately a decade. The SWaT (Secure Water Treatment) testbed developed at Singapore University of Technology and Design became the dominant benchmark across autoencoder and isolation-forest papers.

Patent assignees in retrieved records include IBM, Kyndryl, General Electric, Singapore University of Technology and Design, IIT Kanpur, ABB Technology, Booz Allen Hamilton, and ASELSAN. Filings span US, DE, IN, SG, GB, IL, and WO jurisdictions, with the US remaining the primary commercial IP battleground in this dataset.

PatSnap Eureka Source: PatSnap Eureka patent and literature records retrieved across targeted searches, 2013–2025. Dataset snapshot only.Explore the data ↗
Filing & Publication Trends

Temporal Evolution and Jurisdiction Distribution

Retrieved records in this dataset span four distinct phases from 2013 to 2023, moving from foundational statistical methods to deep learning consolidation and critical reassessment. Patent filings are distributed across US, DE, IN, SG, GB, WO, and IL jurisdictions.

Publication Phase Distribution — Retrieved Records by Era

In this dataset, the 2020–2023 deep learning consolidation and maturation phases account for the majority of retrieved records, with foundational work from 2013–2016 establishing the statistical baseline.

Publication phase distribution in retrieved records: Foundational 2013-2016 (3), Scaling 2017-2019 (3), Deep Learning 2020-2021 (10), Maturation 2022-2023 (18)Horizontal bar chart showing count of retrieved records per publication phase. Source: PatSnap Eureka, 2013–2023.Records per Innovation Phase (Dataset Snapshot)2013–2016 Foundational32017–2019 Scaling32020–2021 Deep Learning102022–2023 Maturation18↗ Click bars to explore

Patent Jurisdiction Distribution — Retrieved Patent Records

In this dataset, US and DE jurisdictions account for the largest share of enterprise-sector patent filings, with India (IN) showing a notable cluster of recent filings from 2020–2025.

Patent jurisdiction distribution in retrieved records: US (4), DE (3), IN (3), SG (1), WO (1), Others (2)Horizontal bar chart showing patent filing counts by jurisdiction in this dataset. Source: PatSnap Eureka, 2013–2025.Patent Jurisdiction Distribution (Dataset Snapshot)US4DE3IN3SG / WO2GB / Other2↗ Click bars to explore
PatSnap Eureka Source: PatSnap Eureka patent records retrieved across targeted searches. Dataset snapshot only — not a comprehensive industry survey.Explore the data ↗
Application Domains

Key Deployment Domains for ICS Anomaly Detection

Retrieved records in this dataset span six application sectors: water treatment, electric power grids, industrial manufacturing, energy asset monitoring, oil and gas, and pipeline security. Each domain presents distinct data modalities and threat models that shape architecture choices.

SWaT Testbed · LSTM-VAE · Isolation Forest

Water Treatment & Distribution

The SWaT (Secure Water Treatment) and WADI (Water Distribution) testbeds at Singapore University of Technology and Design are the most frequently benchmarked environments in this dataset. Nearly every autoencoder and isolation-forest paper validates against SWaT, including the Lightweight LW-LSTM-VAE designed for edge deployment on water purification datasets and the Dual Isolation Forests framework. A combined digital twin anomaly detection framework specifically for water treatment facilities is also documented in retrieved records.

Critical Infrastructure
DNP3 · PMU · False Data Injection Detection

Electric Power Grids & SCADA

Retrieved records cover detection of false data injection attacks (FDIAs) and protocol-level anomalies in energy infrastructure including DNP3-based substations and smart grid PMU networks. The GRU-OCSVM hybrid was demonstrated on power grid source-network-load systems in 2019. Semi-supervised deep representation learning using PMU data requires only normal instances for training. A 2022 paper addresses SCADA security via unsupervised learning and DNP3 function code analysis.

Energy Infrastructure
Digital Twin · Sensor Telemetry · STL Learning

Industrial Manufacturing & Process Control

Applications in this dataset include chemical reactors, textile production lines, food processing plants, and coal mines using physical process sensor data and digital twin integrations. A 2023 paper on coal mine ICS applies DFA-based interpretable detection, addressing operator trust requirements. The Semantic Hybrid Signal Temporal Logic approach was evaluated on textile process data in 2023, and a 2022 paper integrates digital twins, machine learning, and Industry 4.0 tools in a food plant setting.

Process Industry
DAS Fusion · LSTM-SAE · Wind Turbine Monitoring

Energy Assets & Pipeline Security

Semi-supervised fault detection in power-generating assets is evidenced by a 2020 paper using LSTM-SAE and CNN-SAE for wind turbine protection under the proactive critical energy infrastructure protection framework. A scalable architecture for jet engines and gas turbines uses OpenTSDB-based ingestion for anomaly visualization. For pipeline and perimeter security, ASELSAN’s 2022 WO patent covers fusion of spatio-temporal unsupervised anomaly detection with supervised classification for Distributed Acoustic Sensing (DAS) systems.

Asset Monitoring
PatSnap Eureka Source: PatSnap Eureka retrieved records. Domain classification based on application benchmarks cited in retrieved literature and patents.Explore insights ↗
Key Assignees

Key Patent Assignees in ICS Anomaly Detection — Dataset Snapshot

In retrieved records, IBM holds the earliest ICS-specific anomaly detection patents in the dataset with filings from 2013–2014 in DE and GB jurisdictions, while Kyndryl holds two US patents from 2021 and 2023 covering ensemble deep learning approaches. In this dataset, US and German enterprise assignees account for the largest share of commercial patent filings.

Top Assignees by Filing Count in Retrieved Records (Dataset Snapshot)

Top assignees by filing count in retrieved records: IBM (3), Kyndryl Inc. (2), Singapore Univ. of Technology and Design (2), General Electric Company (1), Booz Allen Hamilton Inc. (1)Horizontal bar chart of patent assignee filing counts in this dataset. Source: PatSnap Eureka, 2013–2025.International Business Machines Corporation3Kyndryl, Inc.2Singapore University ofTechnology and Design2General Electric Company1Booz Allen Hamilton Inc.1↗ Click bars to explore
Distributed ICS Monitoring · Security Policy Wrappers

International Business Machines Corporation

IBM holds three patents in this dataset: two active patents in DE jurisdiction (2013, 2014) and one in GB jurisdiction (2014), covering distributed ICS monitoring networks with integrated security policy wrappers. These represent the earliest ICS-specific anomaly detection patents in the retrieved records. The DE patents focus on anomaly detection system architectures applicable to industrial control network environments.

United States — DE/GB filings
Ensemble Deep Learning · Clustered Time-Series Training

Kyndryl, Inc.

Kyndryl holds two US patents in this dataset (2021, 2023) covering ensemble deep learning anomaly detection with clustered time-series training and majority-vote anomaly identification for IT/OT infrastructure convergence monitoring. The 2023 patent specifically addresses downstream grouping and mitigation actions following anomaly identification, indicating continued enterprise ICS/IT convergence investment. Both patents are in US jurisdiction.

United States — US filings
🔍
Unlock Full Assignee Profiles for 6+ More ICS Security Filers
Retrieved records include additional filings from General Electric Company (dynamic dual decision boundary, US 2020), Singapore University of Technology and Design (SG 2020, IN 2025), IIT Kanpur (IN 2025), ASELSAN (WO 2022), ABB Technology, and Booz Allen Hamilton. Access full filing details and technology focus areas in PatSnap Eureka.
GE dual boundary patent SUTD cross-layer IT/OT + more
Unlock full assignee analysis →
PatSnap Eureka Source: PatSnap Eureka patent records. Assignee filing counts reflect retrieved records only and do not represent total portfolio sizes.Explore players ↗
Emerging Directions

Five Forward-Looking Directions from 2022–2023 Records

Based on the most recent filings and publications (2022–2023) in this dataset, five forward-looking directions are evident, spanning contrastive pretraining, dynamic data abstraction, digital twin ecosystems, formal specification models, and protocol-agnostic generalization.

Contrastive and Self-Supervised Pretraining

The 2023 SimCLR-based approach pretrains a feature extractor using contrastive learning on unlabeled ICS traffic, then adds a supervised linear classification head fine-tuned on minimal labeled data. Evaluated on SWaT and Mississippi State University ICS datasets, it outperformed fully supervised baselines. This signals a pivot from reconstruction-based to representation-learning-based semi-supervision, leveraging the entire unlabeled ICS dataset as a pretraining corpus.

Dynamic Data Abstraction for APT-Style Attacks

The December 2023 Dynamic Data Abstraction-Based Anomaly Detection paper proposes real-time noise reduction and abstraction to optimize both update rate and detection boundary simultaneously. It specifically addresses APT-style attacks exploiting zero-day vulnerabilities in OT/IT converged networks. A Snitch Digital Twin concept from 2023 extends beyond single-asset twins to collaborative DT ecosystems modeling behavioral connections between physical entities for inter-system anomaly detection.

🔒
Unlock All 5 Emerging Direction Deep-Dives
Full analysis includes edge and lightweight deployment gaps (LW-LSTM-VAE, sub-100ms inference targets) and physical process fusion as an IP differentiator — both identified as underserved in retrieved records.
Edge LW-LSTM-VAE deploymentCyber-physical fusion IP+ more
Unlock full analysis →
PatSnap Eureka Source: PatSnap Eureka retrieved records 2022–2023. Forward-looking directions inferred from most recent publications in dataset.Explore emerging trends ↗
Architecture Comparison

Autoencoder-Based vs. One-Class Boundary Methods for ICS

Click any row to explore further.

DimensionAutoencoder / Generative ModelsOne-Class Boundary Methods (OCSVM, IF, SVDD)
Training data requirementNormal data only; zero abnormal samples required (e.g., DAGAN architecture)Normal data only; boundary learned around normal hypersphere or contour
Representative architecturesLSTM-Autoencoder, VAE, GAN, DAGAN encoder-decoder-encoder, LW-LSTM-VAEOCSVM, Isolation Forest, SVDD; often combined with deep feature extractors (1DCAE, GRU)
Anomaly signalReconstruction error or adversarial discrimination exceeding a dynamically set thresholdDistance or score relative to learned boundary or isolation depth
Benchmark evidenceValidated on SWaT, WADI, water purification and distribution datasets in retrieved recordsValidated on SWaT, WADI, PLC memory monitoring, and power grid datasets in retrieved records
Handling high-dimensional dataDeep autoencoders with DBSCAN outlier removal and Bayesian GMM boundary estimation (2023 paper)Requires deep feature extraction pre-stage (e.g., 1DCAE) to compress to manageable dimensions
Edge deployment suitabilityLW-LSTM-VAE designed specifically for resource-constrained ICS edge environmentsIsolation Forest and OCSVM are computationally lighter but less expressive for temporal sequences
Multimodal fusionLSTM-AE + GAN fusion combines cyber and physical features for improved recall (2022 paper)GRU-OCSVM fuses temporal traffic features with one-class boundary for power grid networks
Known limitationRisk of misclassifying unseen marginal normal samples as anomalies; addressed by dynamic margin learning in DAGANPerformance degrades with high-dimensional raw input without prior deep feature extraction
PatSnap Eureka Source: PatSnap Eureka retrieved records. Comparison derived from architecture descriptions in cited papers and patents.Compare in Eureka ↗
Frequently asked questions

Frequently Asked Questions: Semi-Supervised Anomaly Detection for ICS

Still have questions? PatSnap Eureka can answer them instantly from patent and research data.Ask Eureka ↗
PatSnap Eureka

Generate Your ICS Anomaly Detection Patent Landscape Report

Join 18,000+ innovators using PatSnap Eureka to generate reports like this one for any technology area.

Data and insights on this page are based on a limited patent and literature dataset and are for reference only. Figures may not represent the complete technology landscape.

Powered by PatSnap Eureka
Link copied to clipboard

Help us improve this page

Found incorrect or outdated information? Let us know and we'll get it fixed.