Abstract

As Information Technology (IT) and Operational Technology (OT) environments converge, Industrial Control Systems (ICS) become highly susceptible to advanced cyber threats. Traditional Network Intrusion Detection Systems (NIDS) relying on L3/L4 signature analysis, fail against semantic attacks concealed within legitimate traffic and suffer from high False Positive Rates (FPR) due to natural process noise. To address these limitations, this paper proposes a data-driven fuzzy feature hybridization (DD-FFH) framework integrated with eXtreme Gradient Boosting (XGBoost) to decouple malicious anomalies from natural operational fluctuations in Modbus TCP networks. By injecting expert domain knowledge directly into the feature space via fuzzy logic, the model effectively mitigates the semantic overlap of volumetric and temporal attacks. Experimental validation on a custom IEC 62443-compliant testbed demonstrates that the proposed architecture achieves a 1.0 overall accuracy and a macro-average F1-score of 0.98, successfully classifying attacks. Furthermore, cross-dataset validation on a public ICS dataset provides a broader scope and demonstrates a promising direction for future research in autonomous defense systems.

Recommended Citation

Krzysztoń, E., Mikołajewski, D. & Prokopowicz, P.(2026). Understand the context, ignore the noise: Detecting semantic and temporal attacks in OT using Fuzzy Features with XGBoost. In M. Valenta, B. Mannová, R. Pergl, A. Przybylek, M. Lang, H. Linger, C. Schneider, N. Iivari, & E. Insfran (Eds.), Making ISD Sustainable: Reloaded with AI and Automation (ISD2026 Proceedings). Prague, Czech Republic: Czech Technical University in Prague. ISBN: 978-80-01-07585-2. https://doi.org/10.62036/ISD.2026.8

Paper Type

Short Paper

DOI

10.62036/ISD.2026.8

Share

COinS
 

Understand the context, ignore the noise: Detecting semantic and temporal attacks in OT using Fuzzy Features with XGBoost

As Information Technology (IT) and Operational Technology (OT) environments converge, Industrial Control Systems (ICS) become highly susceptible to advanced cyber threats. Traditional Network Intrusion Detection Systems (NIDS) relying on L3/L4 signature analysis, fail against semantic attacks concealed within legitimate traffic and suffer from high False Positive Rates (FPR) due to natural process noise. To address these limitations, this paper proposes a data-driven fuzzy feature hybridization (DD-FFH) framework integrated with eXtreme Gradient Boosting (XGBoost) to decouple malicious anomalies from natural operational fluctuations in Modbus TCP networks. By injecting expert domain knowledge directly into the feature space via fuzzy logic, the model effectively mitigates the semantic overlap of volumetric and temporal attacks. Experimental validation on a custom IEC 62443-compliant testbed demonstrates that the proposed architecture achieves a 1.0 overall accuracy and a macro-average F1-score of 0.98, successfully classifying attacks. Furthermore, cross-dataset validation on a public ICS dataset provides a broader scope and demonstrates a promising direction for future research in autonomous defense systems.