Texas A&M University
Trust-Centric Reactive Defenses Against Evasive Cyber Threats in Industrial Networks
Abstract
dc:description.abstractIndustrial Control Systems (ICS) are increasingly vulnerable to evasive cyber threats that exploit weaknesses in Machine Learning-based Intrusion Detection Systems (ML-IDS). Traditional IDS and ML-based defenses struggle to detect stealth attacks, adversarial perturbations, and covert cyber-physical exploits, as attackers manipulate network traffic features to evade detection. This dissertation first demonstrates these vulnerabilities by developing novel attack strategies, including SCADA hijacking, blackout attacks, and model-agnostic adversarial perturbations. By implementing and analyzing these sophisticated evasion techniques, this research systematically exposes the limitations of existing IDS models, proving their inefficacy against adversarially crafted threats. To counter these advanced attacks, this dissertation introduces a multi-layered, trust-centric defense aimed at enhancing the resilience of industrial IDS. A heterogeneous graph-based multimodal intrusion detection system is developed, integrating both Information Technology (IT) and Operational Technology (OT) layers to offer a comprehensive understanding of cyber-physical threats. By combining network-layer, process-layer, and contextual threat intelligence, this approach improves detection accuracy against covert attacks designed to blend into normal operations. Additionally, a reactive defense mechanism is proposed, leveraging an autoencoder-based pre-filtering system capable of identifying adversarial perturbations in network traffic. To further improve IDS transparency and reliability, a novel credibility assessment mechanism is introduced, using Shapley values to assess the trustworthiness of predicted threats. Furthermore, an undeterministic defense pipeline is designed to mitigate surrogate model-based adversarial attacks, ensuring resilience against adversaries attempting to exploit deterministic patterns in ML-IDS. Extensive empirical validation demonstrates that the proposed defenses significantly enhance intrusion detection, reduce evasion rates, and improve adversarial robustness. By exposing critical vulnerabilities in ML-IDS and introducing multi-faceted, adaptive, and explainable security solutions, this dissertation lays the foundation for next-generation ICS defense strategies, ensuring resilience against evolving cyber-physical threats.
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy
- Discipline thesis:degree_discipline
- Computer Engineering
- Grantor
- Texas A&M University
- Year dc:date.issued
- 2025
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Rizvi, Syed Wali Abbas 1996-
- Advisor dc:contributor.advisor
-
- Khan, Irfan
- Committee members dc:contributor.committeemember
-
- Hu, Jiang
- Watson, Karan
- Hamilton, John
Subjects
dc:subject × 1Rights
- Language dc:language.iso
- English
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- https://hdl.handle.net/1969.1/1598196