Protocol-Independent Intrusion Detection in Industrial Iot: A Review of Foundations, Benchmarks, and Evaluation Practice
DOI:
https://doi.org/10.51483/IJAIML.6.8s.2026.1201-1214Keywords:
Industrial Internet of Things; Intrusion detection; Protocol-independent detection; Anomaly detection; Self-supervised learning; Industrial control systems.Abstract
The convergence of operational technology with the Industrial Internet of Things (IIoT) has expanded the attack surface of critical infrastructure while fragmenting it across a heterogeneous mixture of industrial communication protocols. Network intrusion detection systems for these environments have historically been built around the semantics of individual protocols—Modbus, DNP3, EtherNet/IP, S7comm, PROFINET, OPC UA, MQTT and others—yielding accurate but brittle detectors that fail to transfer when the protocol, device vendor, or process changes. This review synthesises the literature at the intersection of industrial cyber-physical security, network anomaly detection, and representation learning to characterise the protocol-independence problem: the difficulty of building detection that generalises across the protocol heterogeneity intrinsic to IIoT. We trace the evolution from signature- and specification-based monitoring, through flow-statistical and process-aware anomaly detection, to recent self-supervised and transfer-learning approaches, and examine the datasets and evaluation practices underpinning the field. We consolidate a comparative view of widely used ICS/IIoT benchmark datasets, highlighting their divergence in modality, protocol coverage, and attack prevalence, and discuss recurrent pitfalls that inflate reported performance and obscure poor generalisation. We argue that a protocol-independent, self-supervised detection paradigm is both necessary and, given recent advances, increasingly viable, and articulate the open research questions motivating dedicated investigation.





