top of page

Advancing Railway Cyber-Physical Systems Security through Simulation-Driven Threat Modelling, Large-Scale Dataset Generation, and AI-Enabled Anomaly Detection

Principal Investigator: Mays Abukeshek

Advancing Railway Cyber-Physical Systems Security through Simulation-Driven Threat Modelling, Large-Scale Dataset Generation, and AI-Enabled Anomaly Detection

01 Oct 2025 - 30 Apr 2026
Principal Investigator: Mays Abukeshek
Supporting Partner(s): Templar International Group (Industry host) and the University of Huddersfield (Academic institution)

Project overview

The rapid digitalisation of railway networks has transformed them into interconnected cyber-physical systems (CPS), where trains, control centres, and trackside infrastructure continuously exchange real-time data. While this enhances operational efficiency, it also exposes railways to sophisticated cyber threats, including denial-of-service (DoS) attacks, RF jamming, spoofing, and ransomware. High-profile incidents, including the WannaCry attack (2017), demonstrate how digital compromise can severely disrupt critical operations and endanger public safety.

Despite growing research interest, key challenges remain: existing simulation environments lack the fidelity needed to reproduce realistic cyber-attack scenarios; publicly available datasets do not capture the domain-specific semantics of railway control systems; and organisations increasingly require intelligent, AI-supported tools to assess and improve their cybersecurity maturity in a scalable and consistent manner. This internship addressed these challenges by translating advanced doctoral research into practical industry-relevant tools and outputs within an international cybersecurity consultancy and research organisation.


Activities

  • Actively contributed as an embedded researcher within the organisation’s cybersecurity advisory and research environment over a structured internship. Responsibilities extended well beyond observation and included substantive contribution to strategic planning, applied research, and international academic engagement.

  • Contributed to the ongoing doctoral research on cyber-physical systems (CPS) security for railway infrastructure. This included the design of hybrid simulation environments capable of injecting and analysing DoS and RF-jamming attacks across both TCP/IP and radio frequency communication layers. A central research output of the internship was the generation of the Smart Train Security Research Set (STSRS), a large-scale, time-synchronised dataset. The dataset captures both train telemetry (speed, location, signal state, overlap counts) and control-centre network logs (packet timestamps, RSSI, command latency, packet loss), and is publicly available on GitHub.

  • Cyber Maturity Assessment Modernisation: Contributed to the conceptual design of an AI-enabled enhancement framework for an internal cyber maturity assessment process. This included governance-aware AI workflows, structured digital evidence collection, automated reporting and visualisation concepts, and standards mapping aligned with ISO 27001, NIST CSF, and CIS Controls.

  • Participated in strategic meetings (approximately three per week), in-person office engagements in London, and international academic research dissemination, including:

  • A remote invited presentation at Mohammed V University (ENSIAS) in Morocco on railway cyber-physical systems security. The presentation covered the technical contributions of the doctoral research, including simulation-based threat modelling, the STSRS dataset, and the AI–Fuzzy multi-layer detection system, alongside key findings from published work. The session also opened discussions on potential future collaboration and joint research opportunities between the University of Huddersfield and ENSIAS in the domain of critical infrastructure cybersecurity.


Impact

The internship delivered significant and multi-dimensional impact across research, industry, and societal domains:

  1. STSRS Dataset (Research / Knowledge Impact): The STSRS dataset is the large-scale, time-synchronised dataset specifically designed for cybersecurity research in railway cyber-physical systems. Publicly released on GitHub, it enables reproducible machine learning experiments, cross-validation benchmarking, and comparative research across the global cybersecurity community. It addresses a critical data gap identified in the systematic literature review and provides a domain-grounded foundation for training AI-based intrusion detection models.

  2. Cyber Maturity Assessment Modernisation (Organisational / Economic Impact): The AI-enabled cyber maturity assessment enhancement framework provides a pathway to reduce the manual effort and inconsistency associated with traditional assessment processes. By integrating intelligent automation, structured evidence collection, and governance-aware AI deployment, the framework supports more scalable, efficient, and trustworthy cybersecurity advisory services.

Across multiple dimensions, the impact of this internship is as follows:

  • Organisational / Economic: The internship strengthened the host organisation’s research-informed cybersecurity capabilities and contributed to the modernisation of internal advisory tools. The research outputs provide commercially relevant frameworks for cyber-physical system security advisory.

  • Sector / Policy: Advances the resilience of railway cyber-physical infrastructure, a safety-critical national asset, against sophisticated cyber threats. The research contributes to evidence-based policy and best practice development in transport cybersecurity, supporting alignment with emerging regulatory frameworks such as NIS2 and national rail security standards.

  • Research / Knowledge: Advances the state of the art by introducing simulation-driven, data-centric methodologies for railway CPS security. The research bridges the gap between abstract security frameworks and operationally grounded implementations, supporting the development of explainable and trustworthy AI systems for safety-critical environments.

  • Social: Contributes to the long-term safety and reliability of public transport infrastructure, directly benefiting the passengers, operators, and communities who depend on secure railway systems. By reducing the operational impact of cyber-physical threats, the research supports the sustainability and trustworthiness of smart transportation networks.

The research streams were mutually reinforcing: threat modelling and simulation informed the design of the STSRS dataset; the dataset enabled rigorous ML benchmarking; and together, these outputs deliver an end-to-end, reproducible framework for railway cybersecurity research and practice.


Future work

  • Expand the STSRS dataset with additional adversary modalities, signalling standards, and cross-platform transfer scenarios, and prepare the associated dataset manuscript for journal submission.

  • Engage with railway sector stakeholders, including the Institute of Railway Research, to demonstrate the prototype and gather feedback to refine both system design and real-world deployment strategies.

  • Extended collaboration with Templar International Group on cyber-physical security services, supporting the continued development of AI-enabled cybersecurity assessment tools, contributing to additional academic-industry research initiatives in critical infrastructure protection, and actively participating in the development of an AI-powered chatbot for the organisation's website.

  • Invite the wider research community to use and build upon the publicly released STSRS dataset for IDS benchmarking, anomaly detection research, and railway CPS security experimentation. Researchers and industry partners interested in collaborative extensions are encouraged to engage through the GitHub repository.


Outcomes/outputs

Publications (prepared / under review):

  • "Cybersecurity in Intelligent Railway Systems: Taxonomy, Research Trends, Challenges, and Future Directions," published in a Q1 international journal.

  • "Cyber-Attack Resilience in Railway Cyber-Physical Systems: Impact Analysis and Mitigation Strategies," published.

  • "Simulation of DoS and Jamming Attacks on Railway Control Systems over TCP/IP and Radio Frequency," published.

  • "STSRS: A New Dataset for Simulating Security Threats in Smart Railway Systems," published. Achievement: Winner of the Best Poster and Best Presentation Awards.

Dataset: 

STSRS (Smart Train Security Research Set) – publicly released on GitHub, comprising labelled records of railway telemetry and control-centre network logs. Available at: https://github.com/maysalreemh/Security-Threats-in-Smart-Railway-Systems-STSRS- (ongoing updates and documentation).

Strategic Deliverables:

Executive-level strategic documentation and internal presentations on AI-enabled cyber maturity assessment modernisation, developed and delivered to senior stakeholders within the host organisation during the internship.

International Research Dissemination:

Invited research presentation delivered remotely at Mohammed V University, École Nationale Supérieure d’Informatique et d’Analyse des Systèmes (ENSIAS), Rabat, Morocco, as part of an international academic workshop on cybersecurity and digital resilience. The presentation, entitled “Securing the Rails: A Cybersecurity Framework for Railway Cyber-Physical Systems,”.

Collaboration:

Strengthened academic-industry partnership between the University of Huddersfield, the host organisation, and international partner ENSIAS, reinforcing shared interests in railway cybersecurity research, AI-driven defence systems, and cross-border academic collaboration.

bottom of page