Experimental Assessment of a Multi-Class AI/ML Architecture for Real-Time Characterization of Cyber Events in a Live Research Reactor

📅 2025-08-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Addressing the challenge of real-time differentiation between cybersecurity incidents and operational anomalies in nuclear reactors, this study proposes and validates a multi-layer AI/ML architecture integrating heterogeneous IT/OT data streams. The architecture combines multivariate time-series modeling, online streaming data synchronization, and lightweight classification models. It is trained and evaluated on 13.8 million real-world, multi-source time-series records collected from an operational research reactor. For the first time, it achieves simultaneous high-accuracy identification—average F1-score > 0.92—across 14 distinct system states, including normal operation, non-malicious physical anomalies, and 12 distinct cyberattack types, thereby enabling clear discrimination between cyber threats and physical faults. The results demonstrate the feasibility, robustness, and engineering applicability of AI/ML for real-time safety monitoring in nuclear facilities, establishing a transferable technical paradigm for intelligent nuclear security protection.

Technology Category

Machine Learning: Hardware-aware MLHumans and AI: Human-in-the-loop Machine LearningIntelligent Robots: Multimodal Perception & Sensor Fusion

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsSecurity and Privacy: Security and privacy of machine learning and AI applicationsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systems
📝 Abstract
There is increased interest in applying Artificial Intelligence and Machine Learning (AI/ML) within the nuclear industry and nuclear engineering community. Effective implementation of AI/ML could offer benefits to the nuclear domain, including enhanced identification of anomalies, anticipation of system failures, and operational schedule optimization. However, limited work has been done to investigate the feasibility and applicability of AI/ML tools in a functioning nuclear reactor. Here, we go beyond the development of a single model and introduce a multi-layered AI/ML architecture that integrates both information technology and operational technology data streams to identify, characterize, and differentiate (i) among diverse cybersecurity events and (ii) between cyber events and other operational anomalies. Leveraging Purdue Universitys research reactor, PUR-1, we demonstrate this architecture through a representative use case that includes multiple concurrent false data injections and denial-of-service attacks of increasing complexity under realistic reactor conditions. The use case includes 14 system states (1 normal, 13 abnormal) and over 13.8 million multi-variate operational and information technology data points. The study demonstrated the capability of AI/ML to distinguish between normal, abnormal, and cybersecurity-related events, even under challenging conditions such as denial-of-service attacks. Combining operational and information technology data improved classification accuracy but posed challenges related to synchronization and collection during certain cyber events. While results indicate significant promise for AI/ML in nuclear cybersecurity, the findings also highlight the need for further refinement in handling complex event differentiation and multi-class architectures.
Problem

Research questions and friction points this paper is trying to address.

Assessing AI/ML for real-time cyber event characterization in nuclear reactors
Differentiating cybersecurity events from operational anomalies using multi-layered architecture
Evaluating multi-class AI/ML performance under realistic reactor conditions and attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Multi-layered AI/ML architecture for cyber event characterization
Integration of IT and OT data streams for anomaly detection
Real-time classification of cyber events in operational nuclear reactors
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Zachery Dahm
Zachery Dahm
Graduate Research Assistant, Purdue University
Autonomous ControlMicroreactorsMachine LearningAnomaly Detection
Konstantinos Vasili
Konstantinos Vasili
PhD student, Purdue University
Machine LearningNuclear engineeringcybersecurityRemote SensingGIS
V
Vasileios Theos
School of Nuclear Engineering, Purdue University, West Lafayette, IN 47907
K
Konstantinos Gkouliaras
School of Nuclear Engineering, Purdue University, West Lafayette, IN 47907
W
William Richards
School of Nuclear Engineering, Purdue University, West Lafayette, IN 47907
T
True Miller
School of Nuclear Engineering, Purdue University, West Lafayette, IN 47907
B
Brian Jowers
School of Nuclear Engineering, Purdue University, West Lafayette, IN 47907
Stylianos Chatzidakis
Stylianos Chatzidakis
Purdue University
nuclear fuel cyclecosmic ray muonsmuon tomographyimagingaerosol transport