Industrial Cyber Defense
Layered neural models for network, process and system anomaly detection with interpretable security signals.
2026Academic industry collaboration · Ram Antivirus.
Layered industrial anomaly analysis
Industrial Cyber Defense examines network traffic, physical-process sequences, hardware signals and device relationships through separate neural modeling paths. Python/TensorFlow experiments and Flask ingestion design connect layer-specific inputs to interpretable security output. The project was developed through academic industry collaboration with Ram Antivirus.
Tabular events, multivariate windows and topology graphs require distinct preprocessing and model assumptions before their outputs can be combined.
Four analytical layers
Scroll horizontally to compare.
| Layer | Approach | Signal of interest |
|---|---|---|
| Network | Feedforward classification and feature attribution | Traffic and access behavior |
| Process | LSTM autoencoder reconstruction | Changes in multivariate process sequences |
| Hardware | CNN/BiLSTM signal analysis | Electrical and physical-device patterns |
| Topology | Graph-based analysis | Device relationships and communication structure |
From payload to explanation
- Layer-specific input
- Schema & transform
- Model output
- Score normalization
- Explanation & triage
The integration design preserves layer context before combining risk information.
Engineering decisions
The process LSTM autoencoder reconstructs sensor sequences; mean squared reconstruction error describes departures from learned behavior and can be examined by variable/time position. Network classification uses traffic and access features, with SHAP attribution tying results to contributing variables.
Validation contracts and transformation steps define the input boundary before inference. Score normalization and configurable weighting support a common severity view while retaining affected asset and source-layer context. The integration design organizes feature contributions and process error profiles into structured investigation output and JSON forwarding contracts. Each analytical layer remains explicit rather than disappearing into an unexplained fused alarm.