Tool Demo: Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks
arXiv SecurityArchived Aug 08, 2026✓ Full text saved
arXiv:2608.05902v1 Announce Type: new Abstract: Water distribution networks depends on industrial control systems to integrate the physical process with communication network, making them vulnerable to cyberattacks that alter the traffic pattern and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often oversee structural changes that are induced by such attacks. In this work, we presents a topology-driven approach for detection of cyberattacks
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 6 Aug 2026]
Tool Demo: Topology analysis with GPML for detection of cyberattacks in Water Distribution Networks
Majed Jaber (ICube-Réseaux), Abdul Qadir Khan, Ankush Meshram, Julien Michel (LRE, ICube), Côme Frappé - - Vialatoux (ICube, LRE), Pierre Parrend (ICube, LRE)
Water distribution networks depends on industrial control systems to integrate the physical process with communication network, making them vulnerable to cyberattacks that alter the traffic pattern and network behavior. Traditional detection approaches that rely on raw traffic or protocol information often oversee structural changes that are induced by such attacks. In this work, we presents a topology-driven approach for detection of cyberattacks in water distribution networks based on Graph Processing for Machine Learning (GPML) framework. The raw traffic is transformed into dynamic graphs, from which community and spectral metrics are extracted and analyzed for any structural and communication modifications with time. The proposed methodology is evaluated on three industrial water distribution datasets such as HITL, SWaT, and CrossTest. Spectral and community graph metrics improve the model performance in detection of cyber and pyhiscal attacks across the three datasets.
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2608.05902 [cs.CR]
(or arXiv:2608.05902v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.05902
Focus to learn more
Journal reference: IEEE/IFIP Network Operations and Management Symposium 2026 / MCT Management of Complex Threats, May 2026, Rome, France
Submission history
From: Pierre Parrend [view email] [via CCSD proxy]
[v1] Thu, 6 Aug 2026 11:31:38 UTC (694 KB)
Access Paper:
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)