Vitale, Francesco (2024) Anomaly Detection by Process Mining and Machine Learning for Industrial Cyber-Physical Systems. [Tesi di dottorato]
|
Documento PDF
Vitale_Francesco_37.pdf Visibile a [TBR] Amministratori dell'archivio Download (11MB) | Richiedi una copia |
| Tipologia del documento: | Tesi di dottorato |
|---|---|
| Lingua: | English |
| Titolo: | Anomaly Detection by Process Mining and Machine Learning for Industrial Cyber-Physical Systems |
| Autori: | Autore Email Vitale, Francesco francesco.vitale@unina.it |
| Data: | 11 Dicembre 2024 |
| Numero di pagine: | 156 |
| Istituzione: | Università degli Studi di Napoli Federico II |
| Dipartimento: | Ingegneria Elettrica e delle Tecnologie dell'Informazione |
| Dottorato: | Information technology and electrical engineering |
| Ciclo di dottorato: | 37 |
| Coordinatore del Corso di dottorato: | nome email Russo, Stefano stefano.russo@unina.it |
| Tutor: | nome email Mazzocca, Nicola [non definito] |
| Data: | 11 Dicembre 2024 |
| Numero di pagine: | 156 |
| Parole chiave: | Industrial cyber-physical systems, anomaly detection, process mining, machine learning, process discovery, conformance checking |
| Settori scientifico-disciplinari del MIUR: | Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni |
| Informazioni aggiuntive: | Appartengo al ciclo 37 |
| Depositato il: | 29 Dic 2024 09:44 |
| Ultima modifica: | 12 Ago 2026 05:37 |
| URI: | https://www.fedoa.unina.it/id/eprint/16440 |
Abstract
The ever-increasing spread and complexity of Industrial Cyber-Physical Systems (ICPSs) allow the seamless connection of the physical and cyber worlds through advanced physical plants, sensor networks and software, improving the quality of service of several industrial applications. Unfortunately, such complexity makes ICPSs vulnerable to faults and troubles the development of accurate models capturing their real behavior. Owing to the dependability issues of ICPSs, the scientific literature proposed many data-driven solutions based on Machine Learning (ML) for characterizing ICPSs and detecting disruptive anomalies. However, ML algorithms are typically process-agnostic and may be affected by explainability issues, especially those employing deep learning. Besides, the specific ML algorithm should be tailored to the data at hand, the types of anomalies to discover, and the learning paradigm to use. To provide process-based characterizations of ICPSs while maintaining a high level of explainability, this dissertation investigates PM for anomaly detection due to its ability to discover reference process models from ICPS data and check for deviations from such models. To develop PM-based anomaly detection in ICPSs while accounting for the shortcomings of existing approaches, this thesis puts forward a methodology that guides ICPS development toward implementing PM-based anomaly detection. The methodological steps provide insight into the ICPS application type, requirements, and data. These insights are used to drive the development of a specific PM-based anomaly detection technique through a flexible and explainable framework that integrates ML to enhance data pre-processing and improve the classification accuracy of anomalous behaviors. During the evaluation, several framework techniques were developed and applied to different industrial case studies, including railways, manufacturing, and healthcare. The results demonstrate that these techniques achieve high levels of explainability and detection effectiveness. These findings underscore the potential for integrating PM techniques in modern industries to enable interpretable, data-driven modeling of ICPS behavior and effectively detect deviations from nominal behavior.
Downloads
Downloads per month over past year
Actions (login required)
![]() |
Modifica documento |


