Dear Editor,
We are pleased to submit our manuscript, “Modeling Normal Is All You Need: Joint Latent Clustering for Anomaly Detection in Multimodal Industrial-IoT Cyber-Physical Systems,” for consideration as a research article in IoT.
Cyber-physical systems form the sensing-and-actuation layer of the Industrial Internet of Things (IIoT), and detecting their faults and cyberattacks from streaming telemetry, without labeled failures, is a central problem for IIoT reliability and security. Our work addresses a specific, under-recognized failure mode: a CPS state can be individually normal on every sensor and can be reconstructed accurately by a deep model, yet be highly improbable under normal joint operation. We show that reconstruction-based detectors, the current standard, measure whether a state is reachable rather than whether it is probable, and therefore miss exactly these stealthy, in-envelope faults.
Our detector, LatAD, models normal behavior as a union of operating regimes in a jointly learned latent space and scores anomalies by probability rather than reconstruction. Because a plant is an assembly of physically coupled subsystems, LatAD factorizes that probability over subsystems recovered without supervision as communities of the normal-data correlation graph, and combines the per-subsystem evidence by a cohesion-weighted, sparsity-adaptive statistic, so that a local fault a whole-plant score would dilute is instead concentrated. Evaluated under a deliberately fair protocol (raw point-wise metrics, difficulty stratification, and train-normal-only calibration) on three real IIoT / industrial-control testbeds (WADI, HAI, and SWaT), LatAD attains the best overall AUROC on every dataset (0.862, 0.949, 0.993) and leads the stealthy difficult subset of all three, by a statistically significant margin on HAI (95% confidence interval [0.046, 0.160]), while the reconstruction-based deep detectors USAD and TranAD fall to 0.30–0.48 on exactly the faults that matter.
We believe the work fits the scope of IoT in Industrial-IoT security, edge intelligence, condition monitoring, and predictive maintenance, and that its evaluation methodology (raw, difficulty-stratified metrics) is of independent interest to the community. Because LatAD calibrates from normal telemetry alone, it can be commissioned per site without labeled attacks and scored in a gateway or edge monitoring pipeline, matching how IIoT systems are deployed and operated. The manuscript is original, has not been published previously, and is not under consideration by any other journal. All source code and trained model checkpoints supporting the reported results are openly archived on Zenodo. The authors declare no conflicts of interest.
We thank you for considering our submission and look forward to the reviewers’ feedback.
Sincerely,
Alexander Apartsin (Holon Institute of Technology) and Yehudit Aperstein (Afeka Academic College of Engineering)
Corresponding author: Yehudit Aperstein, apersteiny@afeka.ac.il