遇见数据集

GRFICSv3 MITRE-Annotated ICS Security Dataset (GRAD-RL)

收藏
Zenodo2026-06-11 更新2026-05-29 收录
官方服务:

资源简介:

Overview This repository contains the official dataset, deployment telemetry, and explainable AI (XAI) incident logs for the GRAD-RL (Graph-Informed Autonomous Cyber-Physical Defense) framework. The dataset is generated and evaluated within the GRFICSv3 industrial control system (ICS) environment and is explicitly annotated with MITRE ATT&CK for ICS techniques. This dataset is designed to evaluate multi-stage autonomous defense mechanisms, anomaly detection algorithms, and safety-constrained reinforcement learning agents in critical infrastructure settings. File Structure & Data Dictionary 1. grad_rl_final_dataset.csv (Main Dataset) Contains 90,728 samples of multivariate time-series data captured from the ICS environment during normal operations and active cyberattacks. Network & Physical Features: Continuous sensor readings (e.g., flow rates, pressure levels), actuator states (valves, pumps), and network telemetry (Modbus/TCP traffic metadata). Label: Binary classification target (0 = Normal, 1 = Attack). MITRE_Technique: Granular MITRE ATT&CK for ICS annotations (e.g., T0836 - Modification of Parameter, T0856 - Spoofing Standard Network Operating Data). 2. telemetry_audit.csv (Live Deployment Log) The operational telemetry recorded during the live deployment of the GRAD-RL framework. It logs the continuous interactions between the PPO RL agent and the deterministic safety gate. Timestamp: Execution timestamp (ms resolution). Risk_Score: The continuous risk tensor output (0.0 to 10.0) calculated via graph centrality and CVSS v4.0 impact vectors. RL_Action: The autonomous mitigation action proposed by the PPO agent (e.g., ISOLATE_ZONE, BLOCK_IP). Gate_Decision: The final safety-constrained action enforced by the IEC 61511 safety gate (e.g., REQUIRE_HUMAN_APPROVAL). 3. xai_incidents.json (Explainable AI Records) Structured JSON records generated by the Detective Node's XGBoost classifier, providing interpretable incident reports for human operators. Incident_ID: Unique identifier for the detected anomaly window. Attack_Class: The predicted attack family. Culprit_Features: The top features (sensors/actuators) that contributed to the anomaly, based on SHAP (SHapley Additive exPlanations) values. 4. experiment_journal.txt (Ground Truth & Timeline) A chronological journal detailing the experimental setup, attack execution windows, and ground truth timestamps. Essential for aligning the telemetry logs with the physical attack scenarios. Usage & License This dataset is released under the CC BY 4.0 License. You are free to share and adapt the material for any purpose, even commercially, provided you give appropriate credit to the original authors. For the associated source code, reinforcement learning models, and training pipelines, please refer to the official GitHub repository linked in the metadata.

提供机构:
Zenodo
创建时间:
2026-05-28
二维码
社区交流群
二维码
科研交流群
商业服务