Hybrid deep transfer learning framework for cross-domain explainable ICS intrusion detection

Industrial Control Systems (ICS) require intrusion detectors that generalize across sectors, yet labeled attack traces remain scarce outside the domain where a model is trained. Feature-space mismatch, differing class taxonomies, and distribution shift limit direct deployment of single-domain deep models. This paper presents a unified pipeline combining convolutional neural network (CNN) spatial encoding, long short-term memory (LSTM) temporal encoding, attention-based branch fusion, Power-to-Gas transfer learning with selective layer freezing, and post-hoc SHapley Additive exPlanations (SHAP)/Local Interpretable Model-agnostic Explanations (LIME) analysis. It’s not any individual algorithmic portion; it’s generally the methodological integration/assessment when challenged with matched pre-processing. The hybrid model achieves 99.3% held-out test accuracy for the Power source domain (37 classes and 128 features) and 97.0% test accuracy for the Gas target domain (8 classes and 36 features). (97.5% accuracy, +0.5 percentage points, 42% fewer epochs until reaching validation accuracy plateau) shows that the main improvement of transfer learning from Power to Gas is from increased efficiency in training; however, this comes at the expenses of reasonable small accuracy gains. Joint spatial–temporal modeling with adaptive fusion is found to be essential when the accuracy seems still high near 63% on Gas, exhibiting similar improvement than both multilayer perceptron (MLP) and LSTM baselines with exactly the same protocol.

Authors

Institutions

Publication Details

Journal
Intelligent Data Analysis
Published
2026-10-09
DOI
https://doi.org/10.1177/1088467x261492519
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Hybrid deep transfer learning framework for cross-domain explainable ICS intrusion detection

Izhar Ahmed Khan, Danish Javeed, Asif Ali, Fatima et al.
Intelligent Data Analysis
Network Security and Intrusion Detection
article

Hybrid deep transfer learning framework for cross-domain explainable ICS intrusion detection

Izhar Ahmed Khan, Danish Javeed, Asif Ali, Fatima, Muhammad Adil, Dechang Pi
article en

Abstract

Industrial Control Systems (ICS) require intrusion detectors that generalize across sectors, yet labeled attack traces remain scarce outside the domain where a model is trained. Feature-space mismatch, differing class taxonomies, and distribution shift limit direct deployment of single-domain deep models. This paper presents a unified pipeline combining convolutional neural network (CNN) spatial encoding, long short-term memory (LSTM) temporal encoding, attention-based branch fusion, Power-to-Gas transfer learning with selective layer freezing, and post-hoc SHapley Additive exPlanations (SHAP)/Local Interpretable Model-agnostic Explanations (LIME) analysis. It’s not any individual algorithmic portion; it’s generally the methodological integration/assessment when challenged with matched pre-processing. The hybrid model achieves 99.3% held-out test accuracy for the Power source domain (37 classes and 128 features) and 97.0% test accuracy for the Gas target domain (8 classes and 36 features). (97.5% accuracy, +0.5 percentage points, 42% fewer epochs until reaching validation accuracy plateau) shows that the main improvement of transfer learning from Power to Gas is from increased efficiency in training; however, this comes at the expenses of reasonable small accuracy gains. Joint spatial–temporal modeling with adaptive fusion is found to be essential when the accuracy seems still high near 63% on Gas, exhibiting similar improvement than both multilayer perceptron (MLP) and LSTM baselines with exactly the same protocol.

Intelligent Data Analysis
Beijing Institute of Technology (CN), Tianjin University (CN), Dalian Maritime University (CN), Nanjing University of Aeronautics and Astronautics (CN)
Openalex Percentile: Top 11%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Hybrid deep transfer learning framework for cross-domain explainable ICS intrusion detection — Izhar Ahmed Khan, Danish Javeed, et al. · Intelligent Data Analysis (2026) | TGRS Research Map | TGRS