DeepTempo and Technology Advancement Center Validate AI Threat Detection for Critical Infrastructure


Posted September 21, 2026 by mark12341

DeepTempo, the company behind LogLM and Vigil, has announced the results of a joint operational validation with the Technology Advancement Center (TAC)

 
DeepTempo, the company behind LogLM and Vigil, has announced the results of a joint operational validation with the Technology Advancement Center (TAC), a nonprofit established by the National Security Agency that advances technological capabilities through proof-of-concept innovation and defender training.

The validation was conducted on TAC's WS3 water-plant range, where DeepTempo's Intelligent Defense Platform detected an advanced attack without requiring a signature, device-specific rule, or model fine-tuning for the targeted endpoint.

Operational technology (OT) environments often operate under constraints that conventional cybersecurity tools are not designed to handle. Industrial controllers may run for years on firmware that cannot be patched on demand, while networks can be segmented or completely air-gapped. In addition, telemetry may not be permitted to leave the plant.

The validation demonstrated that DeepTempo's AI-based behavioral detection and investigation capabilities can operate within these conditions using a passive and local approach without requiring a prior learning period on the plant. The system also provided protocol-level evidence to operators during the investigation.

How the Assessment Worked
Packet captures from the WS3 range were processed locally. DeepTempo's LogLM captured Modbus reads and writes as semantic events.

LogLM is an encoder-only transformer foundation model designed for security telemetry. It evaluated event sequences for deviations from typical behavior and similarities to malicious behavioral patterns.

The results were then imported into Vigil, DeepTempo's open-source AI security operations center (SOC), licensed under Apache 2.0. Analysts could inspect each finding alongside the underlying network flows and register operations.

During the validation, DeepTempo identified a specific human-machine interface (HMI) as the source of an attack. TAC independently confirmed that the endpoint was the rogue HMI responsible for causing a simulated flow valve to fluctuate against the benign controller.

Read More: https://theinfotech.info/deeptempo-and-technology-advancement-center-validate-ai-threat-detection-for-critical-infrastructure
 
Contact Email [email protected]
Issued By markpetays78
Country Barbados
Categories Advertising
Last Updated September 21, 2026