ConceptioArchivearXiv CS
arXiv CSopen access

ProvICS: A Provenance-based Intrusion Detection for Industrial Control Systems

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

arXiv:2607.05989v1 [cs.CR] 7 Jul 2026

ProvICS: A Provenance-based Intrusion Detection for Industrial Control Systems Md Neyamul Islam Shibbir

Deepak K Tosh

Department of Computer Science The University of Texas at El Paso [email protected]

Department of Computer Science The University of Texas at El Paso [email protected]

Abstract—The convergence of Information Technology and Operational Technology has exposed Industrial Control Systems (ICS) to multi-stage cyberattacks that traverse software, network, and physical process layers simultaneously. Although Provenance-based Intrusion Detection Systems (PIDS) are effective in Information Technology (IT) environments, their applicability to Industrial Cyber-Physical Systems (CPS) remains largely unexplored because of the absence of datasets that jointly capture host-level causal behavior, industrial network semantics, and physical process state. To address this gap, we design an open-source, Hardware-in-the-Loop (HIL) CPS testbed that replicates an industrial chemical reactor control architecture across the Purdue model layers. Using this testbed, we propose ProvICS, a multimodal provenance dataset purpose-built for CPS intrusion detection, which synchronously captures four streams: whole-system provenance graphs from the supervisory host and the resource-constrained PLC, decoded Modbus deeppacket inspection records, and physical process telemetry. The collection comprises a 48-hour benign phase and a 22-hour attack phase across four campaigns covering 20 ICS ATT&CK techniques over 32 attack events, ranging from reconnaissance to physical process manipulation. Comparative analysis shows that ProvICS is among the few existing ICS/CPS benchmarks with multi-host kernel-level provenance, real PLC hardware-inthe-loop execution, decoded Modbus traffic, physical processstate measurements, and auxiliary raw PCAP traces in a timesynchronized collection. Baseline detection further confirms that cross-modal fusion can detect all 32 labeled attack events (F1 = 0.913, false-positive rate (FPR) = 1.40%), demonstrating the dataset’s ability to expose complementary attack signals across modalities and addressing a gap not covered by prior benchmarks. Index Terms—Operational Technology, Provenance-based Intrusion Detection, Multimodal Dataset, Hardware-in-the-Loop Testbed, ICS Security

I. I NTRODUCTION Critical infrastructures including power grids, industrial manufacturing, water systems, healthcare, and transportation networks have increasingly adopted computational and digital technologies. While these advancements have substantially improved operational efficiency, they simultaneously expand the attack surface of systems whose compromise can carry catastrophic consequences. A successful cyberattack against such infrastructure can trigger significant physical incidents, threaten national security, endanger public safety, and cause This work is supported by the National Science Foundation, Award # 2239609.

severe disruptions to essential services [1]. Modern Industrial Control System (ICS) attacks span host, network, and physical layers, making them impossible to reconstruct from a single viewpoint. Data provenance solves this by tracking kernellevel causal relationships, linking seemingly benign events across the entire control stack to reveal full, cross-layer attack paths that isolated monitoring misses [2]. Intrusion Detection Systems (IDSs) have been extensively studied in IT environments, yet they exhibit fundamental limitations against modern, multi-stage threats [2]. These limitations are further compounded in OT contexts, where conventional IDS solutions are designed predominantly for IT-layer monitoring which can lack the visibility necessary to account for process-based behaviors and physical state dynamics central to Industrial Control System (ICS) security [3], [4]. A fundamental barrier to IDS research in the OT domain is the lack of open-source resources. Industrial deployments are prohibitively expensive, and most factory components are proprietary systems governed by vendors that rely on “security through obscurity” [5] [6]. Vendors rarely disclose architectural details, communication protocols, or internal configurations, a posture that, despite its prevalence, is no longer considered a viable defense strategy [7]. This inaccessibility severely constrains reproducible security research on live ICS infrastructure. Furthermore, effective IDS development requires telemetry that captures every observable dimension of the CPS environment, including host-level system provenance across all nodes, industrial network traffic, and physical process states. Partial observability risks missed attack signals and an incomplete ground truth for evaluation [8]. In computer security, data provenance graphs have emerged as a powerful paradigm for intrusion detection and forensic investigation [9]. These graphs capture causal relationships among system entities such as processes, files, and network connections by using information derived from audit logs. By linking events and their dependencies, data provenance enables full reconstruction of an attack sequence, revealing insights that isolated log analysis or network flow inspection alone cannot provide [10], [11]. While Provenance-based Intrusion Detection Systems (PIDS) have demonstrated strong efficacy in traditional IT environments, their applicability to OT/ICS settings where attacks manifest concurrently across software, industrial communication protocols, and physical processes

remains largely unexplored. These gaps motivate the following research questions: • Given the resource-constrained nature of CPS, how can we collect system telemetry, and network packets for enabling real-time provenance-based intrusion detection? • How can provenance-based multimodal data serve as an effective foundation for intrusion detection in OT environments? To address these questions, this paper makes the following contributions: • We develop an open-source and lightweight CPS testbed that architecturally replicates the behavioral characteristics of a standard industrial control systems environment. • We outline a systematic, multimodal data collection process that captures host-level system provenance, industrial network traffic, and physical process telemetry from ICS environments. • To the best of our knowledge, this work is among the first to provide an open-source multimodal provenance dataset designed specifically for CPS intrusion detection, which is publicly available on Hugging Face.1 II. R ELATED W ORK As previously mentioned, there is a significant lack of research on provenance-based intrusion detection within CyberPhysical Systems (CPS) environments. Consequently, there is a significant shortage of provenance-based intrusion detection datasets available for study. Ghiasvand et al. [12] proposed the CICAPT-IIoT dataset, a provenance-based Advanced Persistent Threat (APT) dataset specifically designed for Industrial IoT (IIoT) settings. However, they only collected system provenance data from a single node despite the testbed containing multiple virtual machines, Raspberry Pis, and physical sensors. This restricts the dataset’s applicability for analyzing distributed, network-wide APT activities, particularly lateral movement across diverse hosts within a CPS architecture. Furthermore, a critical examination of their published dataset reveals a significant gap in data-flow coverage. The provenance graphs record process activity and file/socket events such as opening files or creating connections, but they largely miss actual data-transfer operations like read, write, sendto, and recvfrom. Because of this, the graphs show who connected to what, but not how data actually moved. This makes it harder to detect behavior such as real data transfer, lateral movement, or data exfiltration accurately. To our knowledge, no other existing CPS intrusion detection dataset includes system provenance data. While several existing datasets capture network traffic and physical state information, they frequently lack the depth necessary to facilitate the detection of Advanced Persistent Threats (APTs). For example, Mathur et al. [13] proposed the SWaT dataset, which represents a scaled-down, high-fidelity replica of a modern six-stage water treatment facility. The data collected include network traffic (PCAPs) and values from 51 sensors and actuators. Another testbed 1 https://huggingface.co/datasets/trucyberlab/multimodal-ICS-provenance

[14] combined model control systems from multiple critical infrastructure industries, such as power and water, to provide a realistic environment for security research and training. However, while it effectively demonstrates common industrial protocols and vulnerabilities, it primarily focuses on networklevel data and lacks the internal system provenance needed for detecting advanced, multi-stage APT threats. Another dataset named ICS-Flow [15] provides integrated network traffic and process state logs from simulated industrial components to support both supervised and unsupervised machine learning. While it covers common network attacks, it lacks the deep system provenance data required to track the internal logic of APTs. In our work, we propose a complete dataset that collects system information from all the components of the environment; in addition, it includes network information and the physical state of the system at any given time. III. P ROVENANCE - AWARE OT ARCHITECTURE In this work, we present an architecture that has the capability to capture provenance information from heterogeneous ICS components by instantiating the sensing-actuation feedback loop across the physical, control, and supervisory layers. This architecture includes a dedicated PLC that sits at Purdue Level 1 and executes a deterministic scan-cycle loop that repeatedly reads sensor feedback values from a physical plant (Purdue Level 0), which is a digital twin [16] of a continuous stirredtank chemical reactor, runs control logic to compute actuator setpoints, and writes those outputs back to the plant, thereby closing the sensing and actuation feedback loop that maintains the chemical reactor at its target operating state. A SCADA HMI (Purdue Level 2) serves as the supervisory boundary between the human operator and the automated control loop by continuously polling all mapped process variables from the PLC, rendering the live plant state as operator-interpretable visualizations, and translating operator decisions into setpoint write commands that propagate downward through the architecture to effect physical change in the plant. Furthermore, a Historian (Purdue Level 3) functions as the passive, readonly time-series archive of the OT architecture, continuously storing all process-variable tags polled by the SCADA layer and compressing and persisting each timestamped observation into a long-term site-wide database without issuing any write commands to the control plane. IV. M ODELING M ULTIMODAL DATA R ELATIONSHIP We formalize ProvICS as a multimodal observation space D = {M1 , M2 , M3 , M4 }, where each modality Mi captures a complementary projection of system behavior. Modalities are distinguished by their generating process and representational structure rather than by sensory format. Modality M1 : Host Provenance Graph. A directed acyclic graph Gh = (Vh , Eh ) capturing kernel-level causal dependencies on the supervisory host, where Vh = Vp ∪ Vf ∪ Vn represents process(Vp ), file(Vf ), and network socket(Vn ) entities, and each edge e ∈ Eh is annotated with a syscall operation and timestamp: e = (vi , vj , op, t).

PLC host (M2)

Supervisory and Physical Simulation Host (M1)

fuxa

send

Node Red

main.js

Open PLC

connect

load

modbus recv write

access

connect

client pc

:502

factory.js bind connect

write

Historian (influxdb) 10.0.1.22

fork

load execute

influxdb

Level 3: Operational Control

connect

connect

Level 2: Supervisory Control HMI (Fuxa)

reactor.st sshd

Python

:22 bash

webserver.py

Router

A. Testbed Configuration The proposed testbed comprises two physical computation nodes. There is a Raspberry Pi 4 Model B [17] (1 GB RAM) running Debian 11 (64-bit), hosting the OpenPLC Runtime v3 [18] as the PLC. The second is an x86-64 workstation (16 GB RAM) running Ubuntu 22.04 LTS [19], hosting the SCADA stack, the physical plant simulator, and the data collection infrastructure. 1) Network Emulation Environment (CORE Emulator): The CORE network emulator [20] provides an isolated virtual network with dedicated per-node IP addressing with 10.0.1.0/24 subnet of the testbed. All virtual nodes interconnect through a central CORE router node. Connectivity between the CORE virtual network and the physical Raspberry Pi is established via a veth-bridge interface, which bridges the emulated network to the physical host network adapter. Modbus/TCP traffic destined for the virtual controller address 10.0.1.50:502 is transparently forwarded to the physical OpenPLC instance at Physical_IP:502 via DNAT rule.

Benign Workstation 10.0.1.25 Attacker Workstation 10.0.1.28

Level 1: Basic Control PLC (OpenPLC) Virtual 10.0.1.50

Fig. 1. Provenance Graph Representation

V. DATA C OLLECTION I NFRASTRUCTURE

Switch

10.0.1.20

open

Modality M2 : PLC Provenance Graph. A graph Gplc = (Vplc , Eplc ) analogous to host graph Gh but captured on the PLC host, augmented with scan-cycle instrumentation edges that expose internal control logic decisions, bridging the otherwise opaque boundary between network inputs and physical outputs. We can see provenance graph samples for modalities M1 and M2 in Figure 1. Modality M3 : Protocol Semantic Capture. A sequence of application-layer records S = {s1 , s2 , . . . , sn }, where each si = (ti , f ci , addri , vali ) encodes the timestamp, function code, register address, and payload of an ICS protocol transaction (e.g., Modbus/TCP). Modality M4 : Physical Process State. A multivariate timeseries X(t) = [x1 (t), x2 (t), . . . , xk (t)]T of k process variables sampled at frequency fs , representing the plant’s dynamic response to both legitimate control actions and adversarial manipulations. From here, researchers have a variety of options for using this multimodal data, including cross-modality correlation, score-level fusion, and causal reconstruction. Synchronized timestamps and socket identities enable events from provenance, protocol, and physical-process streams to be fused into unified causal chains, while modality-specific anomaly scores can be combined to improve detection coverage across heterogeneous attack phases.

Dashboard (Grafana) 10.0.1.23

Level 0: Physical Process Virtual Physical Plant (NODE-RED) 10.0.1.24

Fig. 2. Our proposed CPS testbed with the Purdue reference model

Table I summarizes the network configuration. In addition, Figure 2 shows the network topology of the environment. TABLE I T ESTBED N ETWORK C ONFIGURATION Node

UID

IP Address

Role

Raspberry Pi 4 (OpenPLC) Node-RED

0

10.0.1.50

PLC

1101

10.0.1.24

FUXA InfluxDB Grafana Kali Linux Ubuntu 22.04

1100 1102 1103 1105 1104

10.0.1.20 10.0.1.22 10.0.1.23 10.0.1.28 10.0.1.25

Plant Simulator HMI Historian Visualization Attack Node Benign Node

Key Ports 502,20, 8080 1880 1881 8086 3000 – –

2) Programmable Logic Controller (PLC): The OpenPLC Runtime v3 [18] executes an IEC 61131-3 Structured Text (.st) control program that implements the chemical reactor’s process logic. It is deployed on the Raspberry Pi (10.0.1.50); this embedded device serves as the physical Hardware-in-the-Loop (HIL) Programmable Logic Controller (PLC) within our testbed. 3) Physical Plant Simulator: The simulated physical plant is modelled after a continuous stirred-tank reactor (CSTR) with gas–liquid separation, inspired by the Tennessee Eastman (TE) challenge process [21], a widely adopted benchmark in process control and fault-detection research [22]. The plant is implemented in Node-RED [23] as a software-based digital twin, hosted at 10.0.1.24:1880, where it executes the process dynamics in simulation and exchanges sensor readings and actuator commands with the PLC exclusively via the Modbus/TCP protocol. 4) Supervisory SCADA Stack: The supervisory stack comprises two Dockerized services managed within the CORE emulation environment: 1. HMI (FUXA [24]) (10.0.1.20, port 1881) FUXA performs cyclic register polling via FC3 at one-second intervals across all mapped registers and issues FC16 commands for operator setpoint changes. 2. Historian (InfluxDB [25]) (10.0.1.22, port 8086) Time-series historian. FUXA writes all polled process variables at one-second resolution, producing a continuous multivariate telemetry record across all the variables summarized in Table II

B. Collection Attributes for ProvICS Provenance Data Collection (M1 ): A daemon service (Auditd [26]) is used on the supervisory host to capture the whole-system provenance, which is inspired by the SPADE framework [27]. PLC Provenance Data Collection (M2 ): On the Raspberry Pi, we configured targeted auditd rules on the controller to record PLC-specific system calls. These audit logs are subsequently parsed and translated into a provenance graph. Protocol Semantic Capture (M3 ): At the analytical level, a concurrent tshark dissection stream performs real-time deep-packet inspection of Modbus/TCP traffic, extracting structured protocol fields such as function code, register address, word count, and payload exported into machine-readable JSONL records which provides the ground-truth evidence of what was written, where, and when records that can be directly correlated with provenance graph edges to reconstruct the causal chain from attacker action to physical consequence. Physical Process States Data Collection (M4 ): Physical process state data is collected through FUXA’s built-in historian integration, which polls all mapped Modbus holding registers from OpenPLC at one-second intervals via FC3 Read Holding Registers requests and writes the resulting values directly to InfluxDB. Data collection is organized into two runs: a benign run capturing 48 hours of normal operational behavior with no adversarial activity, and an attack run executing four adversarial campaigns (C1–C4) comprising 32 attack events across 27 labeled phases over 22 hours, with all collection services active throughout. All components shared a common UTC time reference via NTP. VI. A DVERSARY S IMULATION A. Threat Model We consider an adversary whose objective is to disrupt or destroy the physical process governed by the ICS, consistent with NIST SP 800-82 [28] and MITRE ATT&CK for ICS [29]. The adversary possesses network-level access, knowledge of standard industrial protocols, and multi-stage campaign capabilities spanning reconnaissance, lateral movement, and physical impact, consistent with documented threat actors such as those behind Stuxnet [30] and CRASHOVERRIDE [31]. The attack surface spans three layers. At the network layer, the adversary may scan, enumerate protocol register spaces, intercept traffic, and flood control channels. At the host layer, the adversary may exploit remote services to gain execution, escalate privileges, establish persistence, and move laterally. At the physical layer, the adversary may inject false register values, manipulate setpoints, upload modified control logic, or spoof sensor feedback to induce unsafe states while evading process-level alarms. B. Attack Campaigns To generate labelled attack data, four campaigns were executed against the live CPS testbed from a dedicated Kali

Linux [32] node, targeting the OpenPLC controller, NodeRED physical simulator, FUXA HMI, and InfluxDB historian. Each campaign ran as an autonomous Python script producing a ground-truth CSV with UTC-timestamped phase boundaries, ICS ATT&CK mappings, and action descriptions. The campaigns span contrasting detection profiles, from aggressive, network-noisy intrusions to persistent threats generating minimal attacker-originated traffic. Campaign 1 (C1): Smash and Grab. A noise-indifferent adversary performs high-rate scanning, Modbus enumeration, setpoint manipulation, unauthorised actuation, sensor spoofing, and multi-layer denial-of-service flooding before restoring all values. Serves as the high-visibility reference case. Campaign 2 (C2): Low and Slow APT. A stealth-oriented adversary uses passive observation and low-rate enumeration mimicking legitimate polling, then gradually drifts process parameters, establishes an adversary-in-the-middle position, and tampers with historian records. Campaign 3 (C3): Targeted Sabotage. An insider adversary replaces the PLC Structured Text program with a malicious version that removes safety protections and destabilises control loops, while spoofing sensor feedback. Following impact, the attacker restores the original ST program and wipes historian records covering the anomaly window to eliminate forensic evidence. Decisive actions manifest exclusively as host-side program events rather than anomalous network traffic, making this campaign particularly relevant for provenancebased detection. Campaign 4 (C4): Full Spectrum Persistent Threat. The most comprehensive scenario, combining persistence implantation, lateral movement, traffic interception, process manipulation, and historian tampering. After silent withdrawal, implanted PLC logic continues driving unsafe conditions without attacker-originated traffic, a phase uniquely valuable for evaluating detectors reliant on physical state or provenance traces rather than packet-level activity. Table III summarises the ICS ATT&CK technique coverage across campaigns. It comprises four adversarial campaigns with 32 attack events covering 20 unique ICS ATT&CK techniques across 37 labeled technique-campaign pairs which exceeds total number of events (32) because a single event may exercise multiple techniques simultaneously. Taken together, the four campaigns exercise all four data collection modalities and include at least one attack stage that would be weakly observable or completely missed without each of them. This makes ProvICS suitable for evaluating provenance-based intrusion detection while also supporting broader multi-modal CPS security analysis. VII. DATASET A SSESSMENT The ProvICS dataset spans four modalities, whose variables and attributes are fully enumerated in Table II. The physical process state (M4 ) modality records 7 operator setpoints, 6 process variables, 3 valve position feedbacks, and 6 other control variables collectively capturing the full sensing actuation

TABLE II DATASET P ROPERTIES : VARIABLES AND ATTRIBUTES ACROSS A LL M ODALITIES Modality

Variables

Description

Physical Process State (M4 ) Operator Setpoints

flow_set, a_setpoint, pressure_sp, level_sp, override_sp PLC Setpoints f1_valve_sp, f2_valve_sp, purge_valve_sp, Product Valve SP Process Variables Pressure, LevelPV, F1 Flow, f2_flow, purge_flow, ProductFlowPV, A in purge PV, b_in_purge, c_in_purge, Product Actuator Feedback F1 Valve Position Feedback, F2 valve Postion Feedback, Purge Valve Feedback Protocol Semantic Network (M3 )

HMI-issued reference values governing the reactor operating point.

Flow Identity Modbus Application

ip_src, ip_dst, tcp_srcport, tcp_dstport modbus_func_code, modbus_reference_num, modbus_data frame_time_epoch

IP/port tuples defining IT–OT communication channels. Function code, register address, and raw payload of each Modbus transaction.

type, name, exe, command line, cwd, pid, ppid, tgid, uid, euid, gid, egid, seen time, start time, source subtype a , path, permissions, version, epoch, fd, read fd, write fd type, operation b , time, event id, pid, size, flags, mode, source

Execution context of supervisory services such as Node-RED, FUXA HMI, InfluxDB, and Grafana.

type, name, exe, command line, pid, ppid, tgid, uid, euid, gid, egid, machine, note, seen time, start time, source subtype c , path, permissions, version, epoch, remote address, remote port, fd type, operation d , time, event id, size, flags, source

Execution context of the PLC runtime and its supporting services on the edge device.

Timing Host Provenance (M1 ) Process Vertices Artifact Vertices Causal Edges

Valve positions computed by the PLC control logic from operator setpoints. Sensor telemetry from the continuous reactor, including pressure, level, flow, and composition measurements. Physical valve position feedback confirming actuator state.

Packet timestamp for inter-arrival analysis and polling-frequency baselines.

File, pipe, and device descriptors accessed by host processes. Syscall-level causal links with payload size and permission flags.

PLC Provenance (M2 ) Process Vertices Artifact Vertices Causal Edges

Files, network sockets, and descriptors. Syscall-level links; unlike the host provenance, these edges omit mode and pid.

a Host subtypes: file, directory, character device, eventfd, unnamed pipe, unknown. b Host operations: read, write, open, clone, fork, execve, exit, load, create, chmod, setuid, setgid, update. c RPi subtypes: file, directory, network socket, unknown. d RPi operations: read, write, open, connect, accept, bind, send, recv, fork, execve, exit, load.

TABLE III ICS ATT&CK [29] T ECHNIQUE C OVERAGE ACROSS C AMPAIGNS ID

Technique Name

T0842 T0846 T0861 T0859 T0836 T0855 T0856 T0814 T0807 T0801 T0830 T0893 T0832 T0809 T0886 T0845 T0889 T0843 T0872 T0831

Network Sniffing Remote System Discovery Point & Tag Identification Valid Accounts Modify Parameter Unauthorized Command Message Spoof Reporting Message Denial of Service Command-Line Interface Monitor Process State Adversary-in-the-Middle Data from Local System Manipulation of View Data Destruction Remote Services Program Upload Modify Program Program Download Indicator Removal on Host Manipulation of Control

C1

C2

C3

C4

✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓

✓ ✓ ✓ ✓

✓ ✓ ✓ ✓ ✓ ✓

✓ ✓

✓ ✓ ✓ ✓ ✓

✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓

loop of the reactor. The network (M3 ) modality encodes perpacket Modbus/TCP semantics with function code, register address, and raw payload alongside flow-identity tuples and epoch timestamps, enabling both command-level and timingbased analysis. In addition, The raw network capture modality retains the complete .pcap binary record of all traffic traversing the OT network interface, preserving full packet payloads, link-layer headers, and per-packet timestamps at libpcap resolution. The host and PLC provenance modalities

(M1 and M2 ) represent system activity as directed W3CPROV-compatible [33] graphs of process and artifact vertices connected by syscall-level causal edges. Table VI details the scale of the collection. The 48-hour benign phase yields over 4 million host provenance nodes, 28 million host edges, and 11 million Modbus packets, providing a substantial baseline for anomaly detectors to learn normal behavior. The 22-hour attack phase spans four campaigns that exercise 13 distinct ATT&CK tactics, producing an additional ∼ 2 million host nodes and ∼ 15 million host edges. Although the total collection duration (70 hours) is shorter than some benchmarks (e.g., HAI [8] at 30 days), the per-hour data density is substantially higher due to the four-modality design. A single hour of our collection produces host provenance graphs, PLC provenance graphs, decoded Modbus logs, raw packets, and physical state rows simultaneously which no prior dataset achieves, making each hour of data far more informative for multi-modal and cross-layer detection research. Table V compares our dataset with existing relevant datasets. Existing CPS datasets typically capture one or two observation planes. SWaT [13], WADI [34], and HAI [8] record physical sensor/actuator state but omit host-level and network telemetry entirely, limiting detectors to the physical process view. ICSSIM [35] adds raw PCAP and decoded ICS logs but provides no host provenance. CICAPT-IIoT [12] contributes provenance graphs yet lacks file and network data-flow

TABLE IV BASELINE EVENT- LEVEL DETECTION RESULTS FOR 32 LABELED ATTACK PHASES ACROSS FOUR CAMPAIGNS . Detector Provenance only Physical only Modbus only Max-z fusion Sum-z fusion Max3-z fusion OR-calibrated fusion

Events

TP

FN

Recall

F1

FPR

32 32 32 32 32 32 32

24 17 22 31 32 32 29

8 15 10 1 0 0 3

0.7500 0.5312 0.6875 0.9688 1.0000 1.0000 0.9062

0.6818 0.6358 0.7556 0.8915 0.9133 0.9153 0.8892

0.0140 0.0140 0.0140 0.0140 0.0140 0.0140 0.0131

edges (i.e., read/write/sendto/recvfrom operations are essentially absent) and multi-host capture. DARPA TC [36] offers the richest provenance among prior works but targets an enterprise-only IT environment. Our dataset contains four time-synchronized modalities, M1 , M2 , M3 , and M4 . The combination of these properties positions ProvICS to support detection approaches that are infeasible with existing datasets. Multi-host provenance (M1 , M2 ) captures cross-boundary anomalies as attackers pivot between the supervisory host and PLC. Synchronized protocolsemantic network (M3 ) and physical-process data (M4 ) support multimodal fusion by linking Modbus behavior, processstate deviations, and provenance context. ATT&CK ICS labels further enable tactic-level evaluation across kill-chain stages rather than only aggregate scoring. VIII. BASELINE I NTRUSION D ETECTION E VALUATION We validate the ProvICS dataset’s detection tractability using three benign trained autoencoders: a GraphSAGE autoencoder [37] over the host and PLC provenance modalities (M1 and M2 ), a three-layer MLP autoencoder [38] over 94dimensional windowed physical process features (M4 ), and another GraphSAGE [37] graph autoencoder over per-window Modbus semantic graphs (M3 ). Each modality produces a perwindow reconstruction error, which is z normalized against the benign distribution and evaluated using late fusion. We use event-level evaluation: each labeled attack phase is treated as one event and is counted as detected if at least one anomalous 60 s window overlaps its time interval; alerts outside labeled attack phases are counted as false positives and remain penalized. As shown in Table IV, no single modality detects all 32 attack phases: provenance detects 24, physical process detects 17, and Modbus detects 22. In contrast, three-modality sum-z fusion detects all 32 phases, achieving 100% event-level recall and 0.9133 event-level F1 at a benign window false-positive rate (FPR) of 1.40%. We also evaluate an FPR constrained OR fusion rule, where each modality has an independently calibrated anomaly threshold and an alert is raised if any modality exceeds its threshold. This stricter OR calibrated fusion setting reduces the FPR to 1.31% while still detecting 29 of 32 phases. Figure 3 shows the temporal complementarity of the modalities, where different attack phases activate different provenance, physical process, and Modbus anomaly signals. IX. C ONCLUSION AND F UTURE D IRECTIONS This paper presented a multimodal, provenance-aware CPS intrusion detection dataset (ProvICS) collected from a

Fig. 3. Per-modality and fused anomaly-score timeline across the four attack campaigns. TABLE V C OMPARISON WITH E XISTING ICS/CPS I NTRUSION D ETECTION DATASETS Capability

DARPA [36] CICAPT [12] SWaT [13] WADI [34] HAI [8] ICSSIM [35] ProvICS

Host Provenance Process lifecycle File data flow Network data flow Event-loop coverage Multi-host provenance

✓ ✓ ✓ Partial ✓

✓ × × × ×

× × × × ×

× × × × ×

× × × × ×

× × × × ×

✓ ✓ ✓ ✓ ✓

Network Raw PCAP Decoded ICS logs

Partial ×

✓† ×

× ✓

× ×

× ×

✓ ✓

✓ ✓

Physical Process Sensor/actuator state Real PLC hardware

× ×

× Partial

✓ ✓

✓ ✓

✓ ✓

✓ ×

✓ ✓

Ground Truth & Labeling Attack labels ATT&CK ICS mapping Cross-modal bridges

✓ × ×

✓ × ×

✓ × ×

✓ × ×

✓ × ×

✓ × ×

✓ ✓ ✓

Enterprise 8-14 d

IIoT sim. 168 h

Water 11 d

Water 16 d

HIL 30 d

Generic Var.

CSTR 70 h

Physical Process Duration †

Simulated via NS-3. ✓ = present; × = absent or not applicable. Dataset duration: 48-hour benign phase + 22-hour attack phase across four campaigns.

hardware-in-the-loop ICS testbed following the Purdue architecture. The dataset includes host provenance, PLC-edge provenance, decoded Modbus records with raw PCAP, and physical-process telemetry, all aligned on a common UTC timeline to support cross-modal causal analysis. ProvICS contains a 48-hour benign phase and a 22-hour attack phase spanning four heterogeneous adversarial campaigns, with 32 attack events covering 20 unique ICS ATT&CK techniques across 37 labeled technique-campaign pairs. Baseline evaluation with benign-trained autoencoders confirms the dataset’s effectiveness. No single modality detected all 32 labeled attack events, while three-modality sum-z fusion detected all phases with 100% event-level recall and 0.9133 F1 at a benignwindow false-positive rate of 1.40%. This demonstrates that the dataset contains complementary, temporally aligned signals for evaluating multimodal OT/PIDS methods. To the best of our knowledge, ProvICS is among the first CPS intrusion detection datasets to jointly provide multi-host kernel-level provenance (M1 and M2 ), protocol semantic capture (M3 ), physical process state telemetry (M4 ), ATT&CK ICS-mapped ground truth with cross-modal bridges, and real PLC hardware in the loop. The dataset is open source and publicly released on Hugging Face. The current single-PLC, digital-twin testbed is representative rather than large-scale. Future work will focus on real-time PIDS for CPS, multi-PLC and multi-host scaling, real physical plant integration beyond the Node-RED simulator, and support for wireless ICS protocols such as WirelessHART [39] and

TABLE VI DATA DISTRIBUTION ACROSS PHASES AND ATTACK TACTICS Phase

Type

Phase 1 Benign

H-N

H-E

4,113,492 16,006,282

Phase 2 Benign 1,448,932 Discovery 6,643 Lateral Move. 596 Impair Proc. Ctrl. 44,388 Inhibit Resp. Func. 8,191 Restore 1,822 Collection 4,386 Impact 21,508 Def. Evasion 14,039 Init. Access 2,027 Persistence 858 Execution 404 Cred. Access 318 Withdraw 31 Dwell 41,614

P-N

P-E

MB

Phys

7,174 12,952,594 11,798,001 125,375

6,337,905 27,130 26,269 1,688 1,405 344 189,108 456 36,798 456 8,489 12 18,069 58 92,558 74 62,353 145 7,246 33 3,454 34 1,273 72 674 272 105 5 175,939 488

9,113,900 20,804 1,721 149,145 33,384 6,828 7,244 47,870 16,829 5,502 2,285 1,043 986 3 5,711

4,806,622 18,448 682 142,403 28,239 6,736 14,043 69,499 47,075 5,328 2,372 838 749 51 133,056

44,823 171 6 1,333 244 65 136 595 393 49 20 5 6 1 1,232

H-N: Host nodes; H-E: Host edges; P-N: PLC host nodes; P-E: PLC host edges; MB: Modbus packets; Phys: Physical-state.

encrypted industrial traffic. R EFERENCES [1] Y. Roumani and M. Alraee, “Examining the factors that impact the severity of cyberattacks on critical infrastructures,” Computers & Security, vol. 148, p. 104074, 2025. [2] S. Li, F. Dong, X. Xiao, H. Wang, F. Shao, J. Chen, Y. Guo, X. Chen, and D. Li, “Nodlink: An online system for fine-grained apt attack detection and investigation,” arXiv preprint arXiv:2311.02331, 2023. [3] E. Anthi, L. Williams, P. Burnap, and K. Jones, “A three-tiered intrusion detection system for industrial control systems,” Journal of Cybersecurity, vol. 7, no. 1, p. tyab006, 2021. [4] N. J. Wani, D. Pesch, and U. Roedig, “Kids: Intrusion detection for industrial control systems,” in International Conference on Availability, Reliability and Security. Springer, 2025, pp. 191–208. [5] D. Formby, M. Rad, and R. Beyah, “Lowering the barriers to industrial control system security with {GRFICS},” in 2018 USENIX Workshop on Advances in Security Education (ASE 18), 2018. [6] D. Silverman, Y.-H. Hu, and M. Hoppa, “A study on vulnerabilities and threats to scada devices,” in Journal of The Colloquium for Information Systems Security Education, vol. 7, no. 1, 2020, pp. 8–8. [7] K. Stouffer, J. Falco, K. Scarfone et al., “Guide to industrial control systems (ics) security,” NIST special publication, vol. 800, no. 82, pp. 16–16, 2011. [8] H.-K. Shin, W. Lee, J.-H. Yun, and H. Kim, “{HAI} 1.0:{HIL-based} augmented {ICS} security dataset,” in 13Th USENIX workshop on cyber security experimentation and test (CSET 20), 2020. [9] B. Jiang, T. Bilot, N. El Madhoun, K. Al Agha, A. Zouaoui, S. Iqbal, X. Han, and T. Pasquier, “Orthrus: Achieving high quality of attribution in provenance-based intrusion detection systems,” in Security Symposium (USENIX Sec’25). USENIX, 2025. [10] T. Bilot, B. Jiang, Z. Li, N. El Madhoun, K. Al Agha, A. Zouaoui, and T. Pasquier, “Sometimes simpler is better: A comprehensive analysis of {State-of-the-Art}{Provenance-Based} intrusion detection systems,” in 34th USENIX Security Symposium (USENIX Security 25), 2025, pp. 7193–7212. [11] L. Wang, X. Shen, W. Li, Z. Li, R. Sekar, H. Liu, and Y. Chen, “Incorporating gradients to rules: Towards lightweight, adaptive provenancebased intrusion detection,” arXiv preprint arXiv:2404.14720, 2024. [12] E. Ghiasvand, S. Ray, S. Iqbal, S. Dadkhah, and A. A. Ghorbani, “Resilience against apts: A provenance-based iiot dataset for cybersecurity research,” in International Conference on Mobile and Ubiquitous Systems: Computing, Networking, and Services. Springer, 2024, pp. 121–144. [13] A. P. Mathur and N. O. Tippenhauer, “Swat: A water treatment testbed for research and training on ics security,” in 2016 international workshop on cyber-physical systems for smart water networks (CySWater). IEEE, 2016, pp. 31–36. [14] T. Morris, A. Srivastava, B. Reaves, W. Gao, K. Pavurapu, and R. Reddi, “A control system testbed to validate critical infrastructure protection concepts,” International Journal of Critical Infrastructure Protection, vol. 4, no. 2, pp. 88–103, 2011.

[15] A. Dehlaghi-Ghadim, M. H. Moghadam, A. Balador, and H. Hansson, “Anomaly detection dataset for industrial control systems,” IEEE Access, vol. 11, pp. 107 982–107 996, 2023. [16] A. Fuller, Z. Fan, C. Day, and C. Barlow, “Digital twin: Enabling technologies, challenges and open research,” IEEE access, vol. 8, pp. 108 952–108 971, 2020. [17] Raspberry Pi Foundation. Raspberry pi homepage. [Online]. Available: https://www.raspberrypi.org/ [18] T. Alves, L. Buratto, F. M. de Souza, and T. V. Rodrigues, “Openplc: An open source alternative to automation,” in 2018 Global Internet of Things Summit (GIoTS). IEEE, 2018, pp. 1–6. [19] Canonical Ltd., “Ubuntu,” linux Operating System. [Online]. Available: https://www.ubuntu.com/ [20] J. Ahrenholz, C. Danilov, T. R. Henderson, and J. H. Kim, “Core: A real-time network emulator,” in MILCOM 2008-2008 IEEE Military Communications Conference. IEEE, 2008, pp. 1–7. [21] J. J. Downs and E. F. Vogel, “A plant-wide industrial process control problem,” Computers & chemical engineering, vol. 17, no. 3, pp. 245– 255, 1993. [22] C. Ekisa, D. Ó. Briain, and Y. Kavanagh, “Vicsort-a virtualised ics opensource research testbed,” in 2022 Cyber Research Conference-Ireland (Cyber-RCI). IEEE, 2022, pp. 1–8. [23] K. Ferencz and J. Domokos, “Using node-red platform in an industrial environment,” XXXV. Jubileumi Kandó Konferencia, Budapest, pp. 52– 63, 2019. [24] frangoteam. [Online]. Available: https://frangoteam.github.io/FUXA/ [25] InfluxData, “Influxdb.” [Online]. Available: https://www.influxdata.com/ [26] S. Grubb, R. E. Faith, R. G. Briggs, and J. Kanemaru, “audituserspace,” Linux Audit Project, the user-space components to the Linux Auditing System (auditd). [Online]. Available: https: //github.com/linux-audit/audit-userspace [27] A. Gehani and D. Tariq, “Spade: Support for provenance auditing in distributed environments,” in ACM/IFIP/USENIX International Conference on Distributed Systems Platforms and Open Distributed Processing. Springer, 2012, pp. 101–120. [28] K. Stouffer, K. Stouffer, M. Pease, C. Tang, T. Zimmerman, V. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule et al., “Guide to operational technology (ot) security,” 2023. [29] O. Alexander, M. Belisle, and J. Steele, “Mitre att&ck for industrial control systems: Design and philosophy,” The MITRE Corporation: Bedford, MA, USA, vol. 29, pp. 21–85, 2020. [30] J. P. Farwell and R. Rohozinski, “Stuxnet and the future of cyber war,” Survival, vol. 53, no. 1, pp. 23–40, 2011. [31] J. Slowik, “Anatomy of an attack: Detecting and defeating crashoverride,” VB2018, October, 2018. [32] OffSec Services Limited. (2026) Kali Linux Documentation. Kali Linux. [Online]. Available: https://www.kali.org/docs/ [33] P. Missier, K. Belhajjame, and J. Cheney, “The w3c prov family of specifications for modelling provenance metadata,” in Proceedings of the 16th international conference on extending database technology, 2013, pp. 773–776. [34] C. M. Ahmed, V. R. Palleti, and A. P. Mathur, “Wadi: a water distribution testbed for research in the design of secure cyber physical systems,” in Proceedings of the 3rd international workshop on cyber-physical systems for smart water networks, 2017, pp. 25–28. [35] A. Dehlaghi-Ghadim, A. Balador, M. H. Moghadam, H. Hansson, and M. Conti, “Icssim—a framework for building industrial control systems security testbeds,” Computers in Industry, vol. 148, p. 103906, 2023. [36] J. Griffith, D. Kong, A. Caro, B. Benyo, J. Khoury, T. Upthegrove, T. Christovich, S. Ponomorov, A. Sydney, A. Saini et al., “Scalable transparency architecture for research collaboration (starc)-darpa transparent computing (tc) program,” Tech. Rep., 2020. [37] W. Hamilton, Z. Ying, and J. Leskovec, “Inductive representation learning on large graphs,” Advances in neural information processing systems, vol. 30, 2017. [38] J. Feng and Z.-H. Zhou, “Autoencoder by forest,” in Proceedings of the AAAI conference on artificial intelligence, vol. 32, no. 1, 2018. [39] J. Song, S. Han, A. Mok, D. Chen, M. Lucas, M. Nixon, and W. Pratt, “Wirelesshart: Applying wireless technology in real-time industrial process control,” in 2008 IEEE Real-Time and Embedded Technology and Applications Symposium. IEEE, 2008, pp. 377–386.

Record · ID 346448 · SHA-256 935ddbdac112b18c
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.