{"id":{"repo_id":"tamu","oai_identifier":"oai:oaktrust.library.tamu.edu:1969.1/1598196"},"canonical_url":"https://search.dev.ndltd.org/etd/tamu/oai:oaktrust.library.tamu.edu:1969.1/1598196","repository":{"repo_id":"tamu","name":"Texas A&M University","base_url":"https://oaktrust.library.tamu.edu/server/oai/request"},"display":{"title":"Trust-Centric Reactive Defenses Against Evasive Cyber Threats in Industrial Networks","abstract":"Industrial Control Systems (ICS) are increasingly vulnerable to evasive cyber threats that exploit weaknesses in Machine Learning-based Intrusion Detection Systems (ML-IDS). Traditional IDS and ML-based defenses struggle to detect stealth attacks, adversarial perturbations, and covert cyber-physical exploits, as attackers manipulate network traffic features to evade detection. This dissertation first demonstrates these vulnerabilities by developing novel attack strategies, including SCADA hijacking, blackout attacks, and model-agnostic adversarial perturbations. By implementing and analyzing these sophisticated evasion techniques, this research systematically exposes the limitations of existing IDS models, proving their inefficacy against adversarially crafted threats. To counter these advanced attacks, this dissertation introduces a multi-layered, trust-centric defense aimed at enhancing the resilience of industrial IDS. A heterogeneous graph-based multimodal intrusion detection system is developed, integrating both Information Technology (IT) and Operational Technology (OT) layers to offer a comprehensive understanding of cyber-physical threats. By combining network-layer, process-layer, and contextual threat intelligence, this approach improves detection accuracy against covert attacks designed to blend into normal operations. Additionally, a reactive defense mechanism is proposed, leveraging an autoencoder-based pre-filtering system capable of identifying adversarial perturbations in network traffic. To further improve IDS transparency and reliability, a novel credibility assessment mechanism is introduced, using Shapley values to assess the trustworthiness of predicted threats. Furthermore, an undeterministic defense pipeline is designed to mitigate surrogate model-based adversarial attacks, ensuring resilience against adversaries attempting to exploit deterministic patterns in ML-IDS. Extensive empirical validation demonstrates that the proposed defenses significantly enhance intrusion detection, reduce evasion rates, and improve adversarial robustness. By exposing critical vulnerabilities in ML-IDS and introducing multi-faceted, adaptive, and explainable security solutions, this dissertation lays the foundation for next-generation ICS defense strategies, ensuring resilience against evolving cyber-physical threats.","abstract_html":"Industrial Control Systems (ICS) are increasingly vulnerable to evasive cyber threats that exploit weaknesses in Machine Learning-based Intrusion Detection Systems (ML-IDS). Traditional IDS and ML-based defenses struggle to detect stealth attacks, adversarial perturbations, and covert cyber-physical exploits, as attackers manipulate network traffic features to evade detection. This dissertation first demonstrates these vulnerabilities by developing novel attack strategies, including SCADA hijacking, blackout attacks, and model-agnostic adversarial perturbations. By implementing and analyzing these sophisticated evasion techniques, this research systematically exposes the limitations of existing IDS models, proving their inefficacy against adversarially crafted threats. To counter these advanced attacks, this dissertation introduces a multi-layered, trust-centric defense aimed at enhancing the resilience of industrial IDS. A heterogeneous graph-based multimodal intrusion detection system is developed, integrating both Information Technology (IT) and Operational Technology (OT) layers to offer a comprehensive understanding of cyber-physical threats. By combining network-layer, process-layer, and contextual threat intelligence, this approach improves detection accuracy against covert attacks designed to blend into normal operations. Additionally, a reactive defense mechanism is proposed, leveraging an autoencoder-based pre-filtering system capable of identifying adversarial perturbations in network traffic. To further improve IDS transparency and reliability, a novel credibility assessment mechanism is introduced, using Shapley values to assess the trustworthiness of predicted threats. Furthermore, an undeterministic defense pipeline is designed to mitigate surrogate model-based adversarial attacks, ensuring resilience against adversaries attempting to exploit deterministic patterns in ML-IDS. Extensive empirical validation demonstrates that the proposed defenses significantly enhance intrusion detection, reduce evasion rates, and improve adversarial robustness. By exposing critical vulnerabilities in ML-IDS and introducing multi-faceted, adaptive, and explainable security solutions, this dissertation lays the foundation for next-generation ICS defense strategies, ensuring resilience against evolving cyber-physical threats.","abstract_has_math":false,"creators":["Rizvi, Syed Wali Abbas 1996-"],"institution":"Texas A&M University","degree_name":"Doctor of Philosophy","degree_level":null,"degree_discipline":"Computer Engineering","degree_department":null,"school":null,"contributors":[],"advisors":["Khan, Irfan"],"committee_chairs":[],"committee_members":["Hu, Jiang","Watson, Karan","Hamilton, John"],"year":2025,"date_issued":"2025-08","date_published":"2025-08","updated_at":"2026-08-21T16:48:40Z","subjects":["Computer Science"],"languages":["English"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1969.1/1598196","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"source_record":{"url":"https://oaktrust.library.tamu.edu/server/oai/request?verb=GetRecord&metadataPrefix=dim&identifier=oai%3Aoaktrust.library.tamu.edu%3A1969.1%2F1598196","prefix":"dim"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Khan, Irfan"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Hu, Jiang","Watson, Karan","Hamilton, John"]},{"key":"dc:creator","label":"Author","values":["Rizvi, Syed Wali Abbas 1996-"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-02-04T22:01:25Z"]},{"key":"dc:date.issued","label":"Date","values":["2025-08"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Engineering"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Texas A&M University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer Science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["English"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1969.1/1598196"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Industrial Control Systems (ICS) are increasingly vulnerable to evasive cyber threats that exploit weaknesses in Machine Learning-based Intrusion Detection Systems (ML-IDS). Traditional IDS and ML-based defenses struggle to detect stealth attacks, adversarial perturbations, and covert cyber-physical exploits, as attackers manipulate network traffic features to evade detection. This dissertation first demonstrates these vulnerabilities by developing novel attack strategies, including SCADA hijacking, blackout attacks, and model-agnostic adversarial perturbations. By implementing and analyzing these sophisticated evasion techniques, this research systematically exposes the limitations of existing IDS models, proving their inefficacy against adversarially crafted threats. To counter these advanced attacks, this dissertation introduces a multi-layered, trust-centric defense aimed at enhancing the resilience of industrial IDS. A heterogeneous graph-based multimodal intrusion detection system is developed, integrating both Information Technology (IT) and Operational Technology (OT) layers to offer a comprehensive understanding of cyber-physical threats. By combining network-layer, process-layer, and contextual threat intelligence, this approach improves detection accuracy against covert attacks designed to blend into normal operations. Additionally, a reactive defense mechanism is proposed, leveraging an autoencoder-based pre-filtering system capable of identifying adversarial perturbations in network traffic. To further improve IDS transparency and reliability, a novel credibility assessment mechanism is introduced, using Shapley values to assess the trustworthiness of predicted threats. Furthermore, an undeterministic defense pipeline is designed to mitigate surrogate model-based adversarial attacks, ensuring resilience against adversaries attempting to exploit deterministic patterns in ML-IDS. Extensive empirical validation demonstrates that the proposed defenses significantly enhance intrusion detection, reduce evasion rates, and improve adversarial robustness. By exposing critical vulnerabilities in ML-IDS and introducing multi-faceted, adaptive, and explainable security solutions, this dissertation lays the foundation for next-generation ICS defense strategies, ensuring resilience against evolving cyber-physical threats."]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Trust-Centric Reactive Defenses Against Evasive Cyber Threats in Industrial Networks"]}]}],"canonical_facts":{"dc:contributor.advisor":["Khan, Irfan"],"dc:contributor.committeemember":["Hu, Jiang","Watson, Karan","Hamilton, John"],"dc:creator":["Rizvi, Syed Wali Abbas 1996-"],"dc:date.accessioned":["2026-02-04T22:01:25Z"],"dc:date.issued":["2025-08"],"dc:description.abstract":["Industrial Control Systems (ICS) are increasingly vulnerable to evasive cyber threats that exploit weaknesses in Machine Learning-based Intrusion Detection Systems (ML-IDS). Traditional IDS and ML-based defenses struggle to detect stealth attacks, adversarial perturbations, and covert cyber-physical exploits, as attackers manipulate network traffic features to evade detection. This dissertation first demonstrates these vulnerabilities by developing novel attack strategies, including SCADA hijacking, blackout attacks, and model-agnostic adversarial perturbations. By implementing and analyzing these sophisticated evasion techniques, this research systematically exposes the limitations of existing IDS models, proving their inefficacy against adversarially crafted threats. To counter these advanced attacks, this dissertation introduces a multi-layered, trust-centric defense aimed at enhancing the resilience of industrial IDS. A heterogeneous graph-based multimodal intrusion detection system is developed, integrating both Information Technology (IT) and Operational Technology (OT) layers to offer a comprehensive understanding of cyber-physical threats. By combining network-layer, process-layer, and contextual threat intelligence, this approach improves detection accuracy against covert attacks designed to blend into normal operations. Additionally, a reactive defense mechanism is proposed, leveraging an autoencoder-based pre-filtering system capable of identifying adversarial perturbations in network traffic. To further improve IDS transparency and reliability, a novel credibility assessment mechanism is introduced, using Shapley values to assess the trustworthiness of predicted threats. Furthermore, an undeterministic defense pipeline is designed to mitigate surrogate model-based adversarial attacks, ensuring resilience against adversaries attempting to exploit deterministic patterns in ML-IDS. Extensive empirical validation demonstrates that the proposed defenses significantly enhance intrusion detection, reduce evasion rates, and improve adversarial robustness. By exposing critical vulnerabilities in ML-IDS and introducing multi-faceted, adaptive, and explainable security solutions, this dissertation lays the foundation for next-generation ICS defense strategies, ensuring resilience against evolving cyber-physical threats."],"dc:format.mimetype":["application/pdf"],"dc:identifier.uri":["https://hdl.handle.net/1969.1/1598196"],"dc:language.iso":["English"],"dc:subject":["Computer Science"],"dc:title":["Trust-Centric Reactive Defenses Against Evasive Cyber Threats in Industrial Networks"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Engineering"],"thesis:degree_name":["Doctor of Philosophy"],"thesis:institution_name":["Texas A&M University"]},"updated_at":"2026-08-21T16:48:40Z"}