Industrial control systems increasingly use learned anomaly detectors to gate automated controllers: normal-looking telemetry goes to the primary controller, and an alarm hands control to a fallback. This project asks whether that design actually keeps the plant safe. In a closed-loop water-distribution network, the detector catches every ordinary fault, never fires on a clean day, and defers on almost every attacked sample, yet most attacked runs still drive tanks outside their safe operating range.
The gap is structural rather than a matter of detector calibration. Anomaly detection asks whether telemetry looks abnormal; physical safety depends on whether the command about to reach a pump is safe for the current plant state. A correct deferral to "close the pumps" can prevent overflow but cause underflow when the network is already draining, and a compromised controller can skip the detector entirely and issue a harmful command directly.