Next Article in Journal
Enhanced Detection of Intrusion Detection System in Cloud Networks Using Time-Aware and Deep Learning Techniques
Next Article in Special Issue
Parameterised Quantum SVM with Data-Driven Entanglement for Zero-Day Exploit Detection
Previous Article in Journal
Carbon-Aware, Energy-Efficient, and SLA-Compliant Virtual Machine Placement in Cloud Data Centers Using Deep Q-Networks and Agglomerative Clustering
Previous Article in Special Issue
Overview on Intrusion Detection Systems for Computers Networking Security
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

One-Class Anomaly Detection for Industrial Applications: A Comparative Survey and Experimental Study

1
Department of Information Engineering, University of Pisa, Via G. Caruso n.16, 56122 Pisa, Italy
2
MOBI-EPOWERS Research Group, ETEC Department, Vrije Universiteit Brussel (VUB), 1050 Brussel, Belgium
*
Author to whom correspondence should be addressed.
Computers 2025, 14(7), 281; https://doi.org/10.3390/computers14070281
Submission received: 21 May 2025 / Revised: 10 July 2025 / Accepted: 11 July 2025 / Published: 16 July 2025

Abstract

This article aims to evaluate the runtime effectiveness of various one-class classification (OCC) techniques for anomaly detection in an industrial scenario reproduced in a laboratory setting. To address the limitations posed by restricted access to proprietary data, the study explores OCC methods that learn solely from legitimate network traffic, without requiring labeled malicious samples. After analyzing major publicly available datasets, such as KDD Cup 1999 and TON-IoT, as well as the most widely used OCC techniques, a lightweight and modular intrusion detection system (IDS) was developed in Python. The system was tested in real time on an experimental platform based on Raspberry Pi, within a simulated client–server environment using the NFSv4 protocol over TCP/UDP. Several OCC models were compared, including One-Class SVM, Autoencoder, VAE, and Isolation Forest. The results showed strong performance in terms of detection accuracy and low latency, with the best outcomes achieved using the UNSW-NB15 dataset. The article concludes with a discussion of additional strategies to enhance the runtime analysis of these algorithms, offering insights into potential future applications and improvement directions.
Keywords: one-class classification; machine learning; cybersecurity; IDS RUNTIME; TCP/UDP protocol; features reduction; PCA one-class classification; machine learning; cybersecurity; IDS RUNTIME; TCP/UDP protocol; features reduction; PCA

Share and Cite

MDPI and ACS Style

Paolini, D.; Dini, P.; Soldaini, E.; Saponara, S. One-Class Anomaly Detection for Industrial Applications: A Comparative Survey and Experimental Study. Computers 2025, 14, 281. https://doi.org/10.3390/computers14070281

AMA Style

Paolini D, Dini P, Soldaini E, Saponara S. One-Class Anomaly Detection for Industrial Applications: A Comparative Survey and Experimental Study. Computers. 2025; 14(7):281. https://doi.org/10.3390/computers14070281

Chicago/Turabian Style

Paolini, Davide, Pierpaolo Dini, Ettore Soldaini, and Sergio Saponara. 2025. "One-Class Anomaly Detection for Industrial Applications: A Comparative Survey and Experimental Study" Computers 14, no. 7: 281. https://doi.org/10.3390/computers14070281

APA Style

Paolini, D., Dini, P., Soldaini, E., & Saponara, S. (2025). One-Class Anomaly Detection for Industrial Applications: A Comparative Survey and Experimental Study. Computers, 14(7), 281. https://doi.org/10.3390/computers14070281

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop