Traditional Intrusion Detection Systems (IDSs) struggle with unseen attacks, a critical gap in industrial settings, while single-view approaches lack cross-context detection for attacks that manifest across host and network layers. We propose DIversity-driven Multi-view Ensemble IDS (DIME-IDS), a diversity-driven multi-view ensemble for Supervisory Control and Data Acquistion (SCADA) systems, which manage critical industrial infrastructures. Our work introduces: (i) A public hybrid SCADA dataset with 16 attack behaviors synchronized across four Linux/Windows views (network, host, user-activity, system-activity); (ii) A novel Nondominated Sorting Genetic Algorithm II (NSGA-II) optimization constructing ensembles that maximize both accuracy and inter-view diversity; (iii) Dynamic classifier selection at inference using Pareto-optimal operation points. Evaluated against strong baselines (XGB/RF/MLP), DIME-IDS achieves 0.86 accuracy, 0.95 AUC, and 6.51% False Negative (FN) rate, outperforming single-view (10.03%) and concatenated (14.38%) approaches, with lowest FN rates in 3 of 4 unseen attacks. These results demonstrate that explicit multi-view diversity and dynamic selection significantly enhance generalization against novel threats in industrial environments.
Espindola et al. (2026) studied this question.