cs.AIOct 1, 2026

HydroJEV: A one-second, training-free screen for cyber-attack and fault attribution in water distribution networks

Authors: Tianwei Mu, Shengyan Jiang, Mingzhe Yuan, Qing Luo, Min Xiao, Wenhong Wang, Jun Li, Manhong Huang

Organizations: School of Municipal Engineering and Environment, Shenyang Jianzhu University, Shenyang 110168, China · Guangzhou Institute of Industrial Intelligence, Guangzhou 510000, China · Shenyang Institute of Automation, Chinese Academy of Sciences, Shenyang 110169, China · Key Laboratory of Ecological Restoration of Regional Contaminated Environment, Ministry of Education, College of Environment, Shenyang University, Shenyang 110044, China · College of Environmental Science and Engineering, State Environmental Protection Engineering Center for Pollution Treatment and Control in Textile Industry, Donghua University, Shanghai 201620, China

Abstract

When a SCADA alarm is raised in a water distribution network, operators must decide quickly whether it reflects a cyberattack, a physical fault, a normal transient or a faulty sensor. Supervised classifiers need labelled incidents that utilities rarely have, and frontier large language models (LLMs) take tens of seconds per decision. We tested whether Jev, a training-free model that returns class probabilities in about one second, can serve as the first tier of this triage. On a four-class cause-attribution benchmark built on the C-Town network in EPANET, Jev was compared with a hand-written rule tree, a supervised classifier and seven cloud LLMs on identical evidence in four sealed, pre-registered rounds. With only a label-free prior correction, Jev matched the rule tree (macro-F1 0.62-0.64 against 0.56-0.61 in distribution) and exceeded the supervised classifier by 0.36-0.42 on event subtypes absent from its labels, in all four rounds, and it outperformed the classifier whenever fewer than about four labelled events per class were available. Jev also decided 20-40 times faster than frontier LLMs. Accepting only benign Jev verdicts confirmed by the rule tree spared an LLM reviewer 35-38% of windows on fresh sealed sets without loss of macro-F1. Transferred unchanged to two further networks, this gated cascade stayed within the non-inferiority margin of its reviewer on all four sets. A fast, training-free screen can therefore take over about a third of the review load in SCADA anomaly triage while preserving the accuracy of deliberate review.

Figures & tables

Explore similar work

CardsList
  1. A First Glance at Jev for Network Traffic Classification: Accuracy, Processing Time, and Cost

    Sep 30, 2026Shenghe Xu, Lifan MeiModel EvaluationCloud

  2. Jev-IDS: System One Models for Network Intrusion Detection

    Oct 1, 2026Paulo Severo, Silvio E. Quincozes, Amanda DiasIntrusion DetectionRandom Forest

  3. NetCause: Counterfactual Learning for Root Cause Analysis in Large-Scale Networks

    Jun 11, 2026Fabien Chraim, Jian Zhang, Dominik Janzing +3Root Cause AnalysisCausal Graph