HydroJEV: A one-second, training-free screen for cyber-attack and fault attribution in water distribution networks
Tianwei Mu, Shengyan Jiang, Mingzhe Yuan, Qing Luo, Min Xiao, Wenhong Wang, Jun Li, Manhong Huang
- Published
- Oct 1, 2026 — 16:57 UTC
Problem
The paper addresses a critical gap in the capability of Supervisory Control and Data Acquisition (SCADA) systems to make rapid decisions in response to alarms without relying on labeled incident data. This is particularly important for timely responses to potential cyber-attacks and faults in water distribution networks. The work is presented as a preprint and has not undergone peer review.
Method
The authors introduce a model named Jev, which operates without prior training and is designed to return class probabilities in approximately one second. The model is evaluated on a four-class cause-attribution benchmark developed using the C-Town network in EPANET. Jev's performance is compared against several baseline models, including a hand-written rule tree, a supervised classifier, and seven cloud-based large language models (LLMs). A label-free prior correction method is employed to enhance the model's predictions. The evaluation is conducted across four sealed, pre-registered rounds to ensure robustness and reliability of the results.
Results
The Jev model achieves a Macro-F1 Score ranging from 0.62 to 0.64, outperforming the rule tree baseline, which scores between 0.56 and 0.61. Furthermore, Jev exceeds the supervised classifier's performance by 0.36 to 0.42 on event subtypes that were not included in the training labels. In terms of speed, Jev operates 20 to 40 times faster than the leading LLMs. Additionally, the efficiency of the model is highlighted by the fact that accepted benign verdicts from Jev, when confirmed by the rule tree, allowed for a 35-38% reduction in the number of windows that required review by LLMs without compromising the Macro-F1 Score. The gated cascade architecture of Jev demonstrated transferability, maintaining performance within a non-inferiority margin when applied to two additional networks.
Limitations
The authors do not report any limitations in their study. However, the absence of labeled data for training may inherently limit the model's applicability in scenarios where labeled incidents are available.
Why it matters
The implications of this work are significant for the field of cybersecurity in critical infrastructure, particularly in water distribution systems. By enabling rapid and accurate fault attribution without the need for extensive training data, HydroJEV could enhance the responsiveness of SCADA systems to potential threats, thereby improving overall system resilience and security. This model's efficiency and transferability also suggest potential applications in other domains requiring real-time decision-making under uncertainty.
By Turing Wire Research Desk · Oct 1, 2026 · How we work →
Summarised from the paper by the Turing Wire Research Desk. The full paper has the complete methods and results.
Source: arXiv cs.AI
