Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review
Moriano, Pablo, Hespeler, Steven C., Li, Mingyan, Mahbub, Maria
–arXiv.org Artificial Intelligence
Modern cyberattacks in cyber-physical systems (CPS) rapidly evolve and cannot be deterred effectively with most current methods which focused on characterizing past threats. Adaptive anomaly detection (AAD) is among the most promising techniques to detect evolving cyberattacks focused on fast data processing and model adaptation. AAD has been researched in the literature extensively; however, to the best of our knowledge, our work is the first systematic literature review (SLR) on the current research within this field. We present a comprehensive SLR, gathering 397 relevant papers and systematically analyzing 65 of them (47 research and 18 survey papers) on AAD in CPS studies from 2013 to 2023 (November). We introduce a novel taxonomy considering attack types, CPS application, learning paradigm, data management, and algorithms. Our analysis indicates, among other findings, that reviewed works focused on a single aspect of adaptation (either data processing or model adaptation) but rarely in both at the same time. We aim to help researchers to advance the state of the art and help practitioners to become familiar with recent progress in this field. We identify the limitations of the state of the art and provide recommendations for future research directions.
arXiv.org Artificial Intelligence
Jun-27-2025
- Country:
- Asia
- Bangladesh > Dhaka Division
- Dhaka District > Dhaka (0.04)
- China
- Guangdong Province > Guangzhou (0.04)
- Shaanxi Province > Xi'an (0.04)
- India > Uttarakhand
- Roorkee (0.04)
- Japan > Honshū
- Kantō > Gunma Prefecture > Maebashi (0.04)
- Malaysia > Penang (0.04)
- Middle East > Iran
- Alborz Province > Karaj (0.04)
- Bangladesh > Dhaka Division
- Europe
- Italy > Sardinia
- Cagliari (0.04)
- Poland > Pomerania Province
- Gdańsk (0.04)
- Spain
- Catalonia > Barcelona Province
- Barcelona (0.04)
- Galicia > Madrid (0.04)
- Catalonia > Barcelona Province
- Switzerland > Zürich
- Zürich (0.04)
- United Kingdom > England
- Greater London > London (0.04)
- Kent > Canterbury (0.04)
- Italy > Sardinia
- North America
- Canada
- Alberta > Census Division No. 11
- Edmonton Metropolitan Region > Edmonton (0.04)
- Ontario > Toronto (0.04)
- Alberta > Census Division No. 11
- United States
- California
- Alameda County > Oakland (0.04)
- San Francisco County > San Francisco (0.14)
- Santa Barbara County > Santa Barbara (0.04)
- Santa Clara County > San Jose (0.04)
- Florida > Palm Beach County
- Boca Raton (0.04)
- Georgia > Fulton County
- Atlanta (0.14)
- New Mexico > Bernalillo County
- Albuquerque (0.04)
- Tennessee
- Anderson County > Oak Ridge (0.04)
- Davidson County > Nashville (0.04)
- Knox County > Knoxville (0.04)
- Indiana > Monroe County
- Bloomington (0.04)
- Utah > Salt Lake County
- Salt Lake City (0.04)
- Hawaii > Honolulu County
- Honolulu (0.04)
- Massachusetts > Suffolk County
- Boston (0.04)
- California
- Canada
- Oceania > Australia
- Australian Capital Territory > Canberra (0.04)
- South America > Colombia (0.04)
- Asia
- Genre:
- Overview (1.00)
- Research Report
- New Finding (1.00)
- Promising Solution (0.65)
- Industry:
- Education
- Energy > Power Industry (0.94)
- Government
- Information Technology > Security & Privacy (1.00)
- Technology:
- Information Technology
- Internet of Things (1.00)
- Sensing and Signal Processing (1.00)
- Security & Privacy (1.00)
- Data Science > Data Mining
- Anomaly Detection (1.00)
- Artificial Intelligence
- Cognitive Science (1.00)
- Machine Learning
- Evolutionary Systems (1.00)
- Learning Graphical Models > Directed Networks
- Bayesian Learning (0.92)
- Neural Networks > Deep Learning (1.00)
- Performance Analysis > Accuracy (1.00)
- Statistical Learning (1.00)
- Natural Language (1.00)
- Representation & Reasoning
- Agents (1.00)
- Expert Systems (0.92)
- Uncertainty
- Bayesian Inference (0.67)
- Fuzzy Logic (0.92)
- Robots > Autonomous Vehicles (1.00)
- Modeling & Simulation (0.93)
- Communications > Networks (1.00)
- Architecture > Real Time Systems (1.00)
- Information Management (1.00)
- Information Technology