Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (9): 831-841.DOI: 10.12379/j.issn.2096-1057.2026.09.06

Previous Articles     Next Articles

An Intrusion Detection Method for Industrial Control Systems Integrating Memory Autoencoder and CNN-Transformer

Shen Xueli Li, Qianqian   

  • Online:2026-09-02 Published:2026-09-02

融合记忆自编码器与CNN-Transformer的工控系统入侵检测方法

沈学利,李千千   

  • 作者简介:沈学利,李千千

Abstract: To address the problems of high false alarm rate in unsupervised detection and insufficient generalization capability of supervised detection in existing industrial control system intrusion detection methods, this paper proposes an intrusion detection method integrating memory autoencoder and CNN-Transformer. First, the sliding window technique is employed to construct temporal contexts, so as to mitigate detection blind spots caused by static features. Second, multi-dimensional feature enhancement is implemented to expand the original data representation, which improves the model's robustness against complex attack patterns and reduces misclassification caused by insufficient dimensionality. Furthermore, a Memory AutoEncoder (MemAE) and a Transformer-equipped Convolutional Neural Network (CNN-Transformer) are constructed as supervised models, and a parallel intrusion detection model termed MemAE-CT is established by combining the two modules. The proposed model incorporates an adaptive weight distribution mechanism to dynamically adjust the decision contribution of each component, thereby balancing the accurate identification of known attacks and the generalized detection of unknown threats. The proposed method achieves an accuracy of 97.26% and an F1-score of 96.23% on the natural gas pipeline dataset released by Mississippi State University, which verifies its excellent performance. Its generalization capability is further validated on the CICIDS2017 dataset, and the method provides a reliable solution for industrial control system security.

Key words: intrusion detection, industrial control network, sliding window, memory autoencoder, convolutional neural networks

摘要: 针对工控系统入侵检测中无监督方法误报率高与有监督泛化能力弱的问题,本文提出一种融合记忆自编码器与有监督模型(Convolutional Neural Networks and Transformer,CNN-Transformer)的工控系统入侵检测方法。首先,采用滑动窗口构建时序上下文,克服静态特征导致的检测盲区;其次,通过多维度特征增强扩展原始数据表示,提升模型对复杂攻击模式的鲁棒性,减少维度不足引发的误判;最后,构建记忆自编码器(Memory Autoencoder,MemAE)与CNN-Transformer并行的入侵检测模型(MemAE and CNN-Transformer intrusion detection model,MemAE-CT),引入自适应权重分配机制动态调节决策贡献,从而平衡已知攻击的精确识别与未知威胁的泛化检测。该方法在密西西比州立大学发布的天然气管道数据集上准确率达97.26%,F1分数达96.23%,验证了其优秀的检测性能,后续在CICIDS2017数据集上的测试进一步验证了其泛化能力,可为工控安全领域提供可靠的技术方案。

关键词: 入侵检测, 工业控制网络, 滑动窗口, 记忆自编码器, 卷积神经网络

CLC Number: