Security/ scada security · water infrastructure · ai triage · critical infrastructure

A one-second triage tool for water system cyberattacks

Jev, a training-free model, screens water-network SCADA alarms in about a second and scored higher than a hand-built rule tree in tests.

A fast, training-free screening tool just outscored a hand-coded rule tree at spotting cyberattacks in a simulated water utility's control system.

Researchers tested a model called Jev against a hand-written rule tree, a supervised classifier, and seven cloud LLMs on a four-class attack-attribution benchmark built on the C-Town water network in the EPANET simulator. Jev needs no training data and makes a decision in about a second, using only a label-free statistical correction to its priors. Across four sealed, pre-registered test rounds, it posted a macro-F1 of 0.62-0.64, consistently above the rule tree's 0.56-0.61. It also beat the supervised classifier by 0.36-0.42 on attack types that weren't in its training labels, and ran 20-40 times faster than the cloud LLMs.

That speed and label-free design matter because water utilities rarely have enough documented cyberattack incidents to train a reliable classifier, and manual review by a human analyst is slow. Plugging Jev in as a first-pass filter, only escalating flagged cases to the rule tree and then a human, spared a simulated LLM reviewer 35-38% of its workload on fresh test sets without hurting accuracy, and the setup held up when transferred to two other water networks.

Still, this is one simulated benchmark on one open-source network model, not a live utility feed with real sensor noise and real attackers. The gap between a one-second screen and a confirmed intrusion is still a human reviewing an alert, and a third less workload is useful triage, not a replacement for it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →