Industrial control systems (ICS) and SCADA networks underpin critical infrastructure yet remain acutely vulnerable to cyber-physical attacks that manipulate sensor readings while evading conventional IT security tools. We present KA-IDS, an unsupervised streaming intrusion detection system grounded in the Karimov–Alekberli (KA) thermodynamic framework, combining four complementary detection channels: C1 (causal entropy deviation, CER), C2 (structural coupling covariance), C3 (fixed-reference residual z-score), and CB (correlation-break replay indicator). Each alert is attributed in real time to the dominant channel (C1/C2/C3/CB ), satisfying IEC 62443 forensic documentation requirements. Validation on a HAI-statistics-matched simulation (21 sensors, 3 HIL-coupled subsystems, 38 attacks spanning FDI, Command injection, and Replay; 10-day horizon; physics-aware replay model based on published HAI 1.0 parameters 1) demonstrates: DR = 100% across all attack types including Replay via CB; AUC = 0.864; FPR = 0.04 alerts/hr (1.0/day). Benchmark comparison against CUSUM, Isolation Forest, and a neural autoencoder reveals that ML baselines generate 5–7×more false alarms per day (5.2–7.0 alerts/day) despite comparable or higher AUC, making them operationally untenable under strict ICS alarm management. A stealthy coordinated attack demonstration confirms that five sensors shifted by 0.8σ each—below the individual detection threshold θ=2.5σ—drive C2 to 4.5σ (detected) while max-z and CUSUM score at 2.1σ (missed). This paper is the second in the KA Framework series and invites empirical validation on the real SWaT 2 and HAI 1 datasets.
Karimov et al. (Mon,) studied this question.