Machine Learning for Anomaly Detection

A special issue of Mathematics (ISSN 2227-7390). This special issue belongs to the section "E1: Mathematics and Computer Science".

Deadline for manuscript submissions: 20 December 2026 | Viewed by 995

Editor

Data Science and Intelligent Computing Laboratory, Hangzhou International Innovation Institute, Beihang University, Hangzhou 311115, Zhejiang, China
Interests: artificial intelligence; computer vision; blockchain; smart city

Special Issue Information

Dear Colleagues,

As digital systems grow increasingly complex and interconnected, generating vast volumes of high-dimensional data streams, the ability to identify unusual or malicious activities becomes paramount for security, reliability, and operational integrity. Traditional anomaly detection methods, often reliant on predefined rules or static thresholds, struggle to keep pace with the dynamic nature of modern threats and the sheer scale and complexity of contemporary data environments. These limitations expose critical infrastructure, financial systems, healthcare networks, and industrial processes to significant, evolving risks. In this context, Machine Learning (ML) emerges as a transformative paradigm for anomaly detection, offering the potential to learn intricate patterns from data, adapt to new behaviors, and uncover subtle, previously unknown threats with unprecedented accuracy and efficiency.

This Special Issue invites high-quality, original research papers that explore how machine learning (ML) techniques—such as deep learning, graph neural networks, ensemble methods, and self-supervised learning—can be leveraged to advance anomaly detection in complex, high-dimensional systems.

In this Special Issue, original research articles and reviews are welcome. Research areas may include (but not limited to) the following: industrial systems anomaly detection, critical infrastructure anomaly detection, image & video anomaly detection, high-dimensional complex data processing and analysis, multimodal complex data processing and analysis, etc.

I look forward to receiving your contributions.

Dr. Da Yang
Guest Editor

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Mathematics is an international peer-reviewed open access semimonthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 2600 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • anomaly detection
  • industrial systems
  • critical infrastructure
  • image & video
  • high-dimensional
  • multimodal

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (1 paper)

Order results
Result details
Select all
Export citation of selected articles as:

Research

28 pages, 613 KB  
Article
Attack-Level Failure Analysis of Invariant-Rule-Based Anomaly Detection in Industrial Control Systems
by Geumhwan Cho
Mathematics 2026, 14(11), 2016; https://doi.org/10.3390/math14112016 - 5 Jun 2026
Viewed by 444
Abstract
Invariant-rule-based anomaly detection is attractive for industrial control systems (ICSs) because its rules are interpretable, auditable, and learnable from normal-operation data alone. However, mined invariants can miss attacks that induce weak, localized, transient, or rule-consistent deviations, because such attacks may not sufficiently violate [...] Read more.
Invariant-rule-based anomaly detection is attractive for industrial control systems (ICSs) because its rules are interpretable, auditable, and learnable from normal-operation data alone. However, mined invariants can miss attacks that induce weak, localized, transient, or rule-consistent deviations, because such attacks may not sufficiently violate the specific variable relationships captured by the rules. Aggregate time-step metrics can also obscure these failures, since they do not reveal which documented attack windows remain uncovered. Therefore, we analyze rule-only detection failures at the attack-window level and evaluate a rule-preserving hybrid detector that keeps the original invariant-rule alarm unchanged while adding learned anomaly evidence from per-sensor XGBoost residual models and an Anomaly Transformer. The final alarm uses OR fusion and matched-FPR results are reported as an evaluation-time operating-point analysis under a common system-level false-positive budget. On the SWaT benchmark, the reproduced rule-only detector detects 16/36 attacks at an attack-window recall threshold of 0.05 and 13/36 at 0.4. At the Zhu-matched evaluation-time false-positive budget (α0.00447), the pre-specified equal-weight hybrid reaches 19/36 and 16/36, respectively. For localization, SHAP attribution on the XGBoost residual models places the attacked sensor in the top-5 for 70.6% of direct sensor attacks and a variable from the correct process stage in the top-5 for 94.4% of all attacks. These results indicate that rule-preserving residual learning modestly improves attack-level coverage while providing operator-oriented localization evidence rather than definitive root-cause identification. Full article
(This article belongs to the Special Issue Machine Learning for Anomaly Detection)
Show Figures

Figure 1

Back to TopTop