TY - JOUR
T1 - Deep transfer learning for intrusion detection in industrial control networks
T2 - A comprehensive review
AU - Kheddar, Hamza
AU - Himeur, Yassine
AU - Awad, Ali Ismail
N1 - Funding Information:
We would like to express our sincere gratitude to the anonymous reviewers for their valuable feedback and suggestions, which have improved the quality of this work. The first author acknowledges that the study was partially funded by the Algerian Ministry of Higher Education and Scientific Research (Grant No. PRFU-A25N01UN260120 230001 ). The third author acknowledges that the study was partially funded by a joint research grant between United Arab Emirates University and Zayed University (UAEU-ZU) (Grant No. 12R141 ).
Publisher Copyright:
© 2023 Elsevier Ltd
PY - 2023/11
Y1 - 2023/11
N2 - Globally, the external internet is increasingly being connected to industrial control systems. As a result, there is an immediate need to protect these networks from a variety of threats. The key infrastructure of industrial activity can be protected from harm using an intrusion detection system (IDS), a preventive mechanism that seeks to recognize new kinds of dangerous threats and hostile activities. This review examines the most recent artificial-intelligence techniques that are used to create IDSs in many kinds of industrial control networks, with a particular emphasis on IDS-based deep transfer learning (DTL). DTL can be seen as a type of information-fusion approach that merges and/or adapts knowledge from multiple domains to enhance the performance of a target task, particularly when labeled data in the target domain is scarce. Publications issued after 2015 were considered. These selected publications were divided into three categories: DTL-only and IDS-only works are examined in the introduction and background section, and DTL-based IDS papers are considered in the core section of this review. By reading this review paper, researchers will be able to gain a better grasp of the current state of DTL approaches used in IDSs in many different types of network. Other useful information, such as the datasets used, the type of DTL employed, the pre-trained network, IDS techniques, the evaluation metrics including accuracy/F-score and false-alarm rate, and the improvements gained, are also covered. The algorithms and methods used in several studies are presented, and the principles of DTL-based IDS subcategories are presented to the reader and illustrated deeply and clearly.
AB - Globally, the external internet is increasingly being connected to industrial control systems. As a result, there is an immediate need to protect these networks from a variety of threats. The key infrastructure of industrial activity can be protected from harm using an intrusion detection system (IDS), a preventive mechanism that seeks to recognize new kinds of dangerous threats and hostile activities. This review examines the most recent artificial-intelligence techniques that are used to create IDSs in many kinds of industrial control networks, with a particular emphasis on IDS-based deep transfer learning (DTL). DTL can be seen as a type of information-fusion approach that merges and/or adapts knowledge from multiple domains to enhance the performance of a target task, particularly when labeled data in the target domain is scarce. Publications issued after 2015 were considered. These selected publications were divided into three categories: DTL-only and IDS-only works are examined in the introduction and background section, and DTL-based IDS papers are considered in the core section of this review. By reading this review paper, researchers will be able to gain a better grasp of the current state of DTL approaches used in IDSs in many different types of network. Other useful information, such as the datasets used, the type of DTL employed, the pre-trained network, IDS techniques, the evaluation metrics including accuracy/F-score and false-alarm rate, and the improvements gained, are also covered. The algorithms and methods used in several studies are presented, and the principles of DTL-based IDS subcategories are presented to the reader and illustrated deeply and clearly.
KW - Cybersecurity
KW - Deep transfer learning
KW - Domain adaptation
KW - Fine-tuning
KW - Industrial control network
KW - Intrusion detection system
UR - http://www.scopus.com/inward/record.url?scp=85173442344&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85173442344&partnerID=8YFLogxK
U2 - 10.1016/j.jnca.2023.103760
DO - 10.1016/j.jnca.2023.103760
M3 - Review article
AN - SCOPUS:85173442344
SN - 1084-8045
VL - 220
JO - Journal of Network and Computer Applications
JF - Journal of Network and Computer Applications
M1 - 103760
ER -