Water distribution networks depend on industrial control systems to integrate the physical process with the communication network, making them vulnerable to cyberattacks that alter traffic patterns and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often overlook structural changes induced by such attacks.

This work presents a topology-driven approach for detecting cyberattacks in water distribution networks based on the Graph Processing for Machine Learning (GPML) framework. Raw traffic is transformed into dynamic graphs, from which community and spectral metrics are extracted and analyzed for structural and communication modifications over time. The methodology is evaluated on three industrial water distribution datasets — HITL, SWaT, and CrossTest — and shows that spectral and community graph metrics improve detection performance for both cyber and physical attacks across the three datasets.

Fig. 3 from the paper (above): the three-layered architecture (Supervisory Control, Process Control, Physical) widely used for water distribution ICS.

  • Venue: IEEE/IFIP Network Operations and Management Symposium 2026 / MCT — Management of Complex Threats, Rome, Italy
  • HAL record: hal-05678814
  • PDF: download
  • arXiv: 2608.05902
  • Co-authors: Majed Jaber, Abdul Qadir Khan, Ankush Meshram, Julien Michel, Côme Frappé - - Vialatoux