Downloads · 30 days
0
stetteh/otics-anomaly
otics-anomaly is a machine learning model from stetteh. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
A deep autoencoder that detects cyber-physical attacks on industrial control systems from sensor/actuator telemetry. Trained on the HAI (HIL-based Augmented ICS) turbine/boiler testbed using only normal operation — so…
Downloads · 30 days
0
Access
Public
Updated Jul 17, 2026
Repo size
151 KB
Likes
0
Public
Click a slice to open those files.
.pth149 KB · 82%
From the Hugging Face model README
A deep autoencoder that detects cyber-physical attacks on industrial control systems from sensor/actuator telemetry. Trained on the HAI (HIL-based Augmented ICS) turbine/boiler testbed using only normal operation — so it needs no labeled attacks — and flags a reading as an intrusion when its reconstruction error exceeds a learned threshold.
Takes a reading of the 59 real HAI sensor/actuator tags, reconstructs it, and compares the
reconstruction error to the trained threshold (0.009223). Missing tags are filled from a real
recorded normal reading, so partial live feeds still score sensibly.
pip install -r requirements.txt
python example.py
from otics_score import score_reading, BASELINE_READING
score_reading(BASELINE_READING) # normal -> is_anomaly False
score_reading({**BASELINE_READING, "P1_FT01": 900.0}) # tampered -> anomaly
docker run -p 8082:8080 ghcr.io/samuelgtetteh/otics-anomaly:0.1
curl -s localhost:8082/example | curl -s localhost:8082/score -H 'Content-Type: application/json' -d @- # (or POST {"readings": {...}})
GET /example returns a real normal reading; POST /score {"readings": {...}} scores one.
autoencoder_hai.pth — trained weights · scaler_hai.pkl — fitted StandardScalerautoencoder_hai_meta.txt — input_dim / encoding_dim / threshold / 59 feature orderotics_score.py — model + scoring · serve.py — FastAPI wrapperAssistive monitoring for OT/ICS: a high reconstruction error flags a reading worth investigating, not a confirmed attack. The threshold is tuned to this HAI testbed; deploying on a different plant requires re-fitting the scaler/threshold on that plant's normal data. Trained on 59 specific HAI tags — inputs must use those tag names.
Trained on the HAI dataset (iTrust/HIL testbed; subject to its terms). Code and released weights:
Apache-2.0 (LICENSE).
Tetteh, S. G. OT/ICS Intrusion Detection with a Physics-Aware Autoencoder. Jarvis College of Computing and Digital Media, DePaul University.