College of Graduate Studies: Theses & Dissertations
Term of Award
Summer 2026
Degree Name
Master of Science, Electrical and Computer Engineering
Document Type and Release Option
Thesis (restricted to Georgia Southern)
Copyright Statement / License for Reuse
Digital Commons@Georgia Southern License
Department
Department of Electrical and Computer Engineering
Committee Chair
Rami Haddad
Committee Member 1
Min Gyu Kim
Committee Member 2
Stetson Rowles
Committee Member 3
Seungmo Kim
Abstract
Water treatment plants are critical infrastructure systems that support public health, economic stability, and national security. However, many facilities continue to rely on legacy industrial control systems and increasingly connected operational technologies, making them vulnerable to cyber-physical attacks. Malicious manipulation of chemical dosing, sensor readings, or process-control logic can degrade water quality, disrupt operations, and compromise public confidence drinking water systems.
This thesis presents a digital twin (DT)-driven framework for detecting cyber-physical attacks in water treatment infrastructure. The proposed framework integrates discrete-event simulation (DES), DT modeling, and Long Short-Term Memory (LSTM) neural networks. A DES-based DT of a simplified water treatment plant was developed in Python to model key treatment processes, including coagulation, flocculation, sedimentation, filtration, disinfection, and treated water storage. The DT generated labeled time-series datasets representing both normal operation and cyber-physical attacks involving alum and chloramine underdosing and overdosing. These datasets were used to train and evaluate LSTM-based classifiers for five-class, nine-class, and binary attack detection tasks.
The proposed framework demonstrated strong detection and classification performance. The five-class model achieved an accuracy of 99.1%, a precision of 96.5%, a recall of 95.2%, and an F1-score of 95.8%. The expanded nine-class model, which included simultaneous alum and chloramine attacks, achieved a mean accuracy of 97.88%, a weighted F1-score of 97.97%, a macro F1-score of 90.62%, and a balanced accuracy of 95.09% across 50 cross-validation runs. The binary classifier provided the strongest overall detection capability, achieving 99.32% accuracy, a macro F1-score of 98.13%, balanced accuracy of 98.1%, and an attack recall of 96.57%.
The results demonstrate that DES-based digital twins can effectively generate process-aware datasets for training machine learning models to detect cyber-physical attacks in water treatment systems. While the framework performed exceptionally well for broad attack detection and alum-related attacks, chloramine-related attacks were more challenging due to their lower concentration levels and greater operational variability. These findings suggest that a two-stage detection architecture, combining binary attack detection with subsequent attack classification, offers a promising direction for enhancing cybersecurity in critical water infrastructure.
Recommended Citation
Chen, Jonas, "A Digital Twin and LSTM-Based Framework for Cyber-Physical Attack Detection in Water Treatment Systems" (2026). College of Graduate Studies: Theses & Dissertations. 3186.
https://digitalcommons.georgiasouthern.edu/etd/3186
Research Data and Supplementary Material
No