<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>18</Volume>
				<Issue>3</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>07</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>A Federated framework for unsupervised intrusion detection on the Modbus protocol in cyber-physical systems</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>167</FirstPage>
			<LastPage>178</LastPage>
			<ELocationID EIdType="pii">242101</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2026.242101</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Hamid Reza</FirstName>
					<LastName>Dashtabadi</LastName>
<Affiliation>Information Systems and Security Lab (ISSL), Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran</Affiliation>

</Author>
<Author>
					<FirstName>Siavash</FirstName>
					<LastName>Ahmadi</LastName>
<Affiliation>Electronics Research Institute, Sharif University of Technology, Tehran, Iran</Affiliation>
<Identifier Source="ORCID">0000-0002-8801-337X</Identifier>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2025</Year>
					<Month>10</Month>
					<Day>01</Day>
				</PubDate>
			</History>
		<Abstract>The increasing integration of modern network infrastructure into industrial control systems elevates the need for robust cyber intrusion detection for industrial protocols. Unsupervised anomaly detection is particularly effective for this task, as it identifies novel attacks by modeling normal behaviour rather than relying on limited attack data. While techniques like autoencoders, which use reconstruction error to flag deviations, can be effective, their application is often hindered by practical challenges, such as regulatory constraints and the large volumes of data that prohibit the centralised collection required for training. Federated learning offers a solution by distributing the training process to local clients and aggregating only the resulting model parameters, thus preserving data privacy and locality. This paper proposes an anomaly-based intrusion detection framework built on federated learning. Using the CIC-Modbus2023 dataset, which comprises raw Modbus traffic from a smart grid, we systematically extract and label network flows based on attack logs. We then train and evaluate several autoencoder variants—including standard, variational, and adversarial autoencoders—within this federated setting. Our results demonstrate strong performance in detecting malicious behaviour, highlighting the framework’s potential as a promising approach for mitigating threats against the Modbus protocol without centralised data access. The code is available at https://github.com/hamid-rd/FLBased-ICS-NIDS.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Industrial network intrusion detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Modbus/TCP attacks</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Federated deep learning</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Autoencoder models</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Raw network traffic preprocessing</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_242101_b950217e5291d89385502147536c5775.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
