arXiv · 2609.29704
Detect First, Explain Later: Training-Free Temporal-Memory Digital Twin Anomaly Detection with Post-Hoc LLM Interpretation for ICS
Abstract
Industrial Control Systems (ICS) are increasingly exposed to cyber-physical attacks that manifest as subtle and temporally evolving deviations in process behavior. Detecting such anomalies requires reasoning over persistence, cross-signal dependencies, and process-level constraints. Digital Twins (DTs) encode system knowledge through physical and logical relationships between signals, but existing DT-based approaches rely on instantaneous rule violations and lack mechanisms to aggregate weak evidence over time. This paper proposes a training-free anomaly detection method that combines deterministic DT constraints with explicit temporal memory. The DT monitors process signals and produces anomaly scores based on constraint violations, while a lightweight memory mechanism captures persistence and contextual relationships across time. The approach is evaluated on the HAI and BATADAL datasets. Ablation results show that the memory-less detector fails completely, demonstrating that temporal aggregation is essential for DT-based detection. On HAI, the memory-aware DT achieves stable detection with only 4 false alarm events, and on BATADAL, it remains effective without retraining, with 21 false alarms under domain shift. In comparison, Isolation Forest (IF) produces substantially more false alarms (328 on HAI and 127 on BATADAL), while Autoencoder (AE) exhibits dataset-dependent behavior, achieving high precision on BATADAL but low recall and inconsistent performance overall. A gated LLM is used for post-hoc interpretation, providing structured explanations without affecting detection performance. Our findings highlight the importance of temporal memory in constraint-based detection and support the use of decoupled reasoning for interpretability in ICS monitoring.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Konstantinos E. Kampourakis, Vasileios Gkioulos, Sokratis Katsikas. 2026-08-31. Detect First, Explain Later: Training-Free Temporal-Memory Digital Twin Anomaly Detection with Post-Hoc LLM Interpretation for ICS. https://arxiv.org/abs/2609.29704
Cite the original work for its findings. Save a collection to share your selection of sources.