Cyber Warfare Threat Classification on Cyber-Physical Systems: A Machine Learning Approach to Dark Web Terrorist Activity Detection
Keywords:
Dark web Tor categorization cyber-physical systems (CPS) cyber terrorism cyber warfare TF-IDF AdaBoost machine learningAbstract
Cyber-Physical Systems (CPS), the technological backbone of Industry 4.0 and of national critical infrastructure, remain high-value targets for state and non-state actors that treat software and network vulnerabilities as instruments of cyber warfare. The dark web, owing to its anonymity-preserving architecture, has become a preferred venue for terrorist and extremist groups to plan, coordinate, finance and advertise attacks against CPS-dependent infrastructure such as power grids, water treatment plants and transportation networks. Building a large labeled corpus of dark web pages for supervised threat classification is difficult because illicit content is scarce, unindexed and expensive to annotate manually. This paper proposes a lightweight classification framework that substitutes bulk dark-web training data with openly available, authoritative surface-web documents describing five cyber-warfare motivation categories: espionage, sabotage, electrical-power-grid disruption, propaganda and economic disruption. Term Frequency–Inverse Document Frequency (TF-IDF) features extracted from these legitimate reference texts are used to train and benchmark AdaBoost, Decision Tree and Support Vector Machine (SVM) classifiers, which are then evaluated against a crawled corpus of 5,379 manually labeled onion pages gathered between January and March 2021. The AdaBoost classifier achieves the strongest performance, with an accuracy and F1-score of 0.942, outperforming Decision Tree (0.911) and SVM (0.743) and remaining competitive with keyword-intensive baselines such as ATOL while requiring markedly less dark-web training data. The results suggest that authoritative surface-web corpora can serve as a practical substitute for hard-to-obtain dark-web training sets when classifying CPS-relevant cyber-warfare threats and the framework generalizes to emerging illicit categories without expert-curated seed keywords.
References
[1] G. Weimann, "Terrorist migration to the dark web," Perspectives on Terrorism, vol. 10, no. 3, pp. 40–44, 2016.
[2] CSIS, "Securing U.S. critical infrastructure against evolving cyber threats," Center for Strategic and International Studies, Strategic Technologies Blog, 2025.
[3] Infosecurity Magazine, "The evolving cybersecurity challenge for critical infrastructure," 2026.
[4] Industrial Cyber, "Waterfall Threat Report 2026 finds ransomware slowdown masks deeper shift toward nation-state attacks on critical infrastructure," 2026.
[5] V. M. Vilić, "Dark web, cyber terrorism and cyber warfare: Dark side of the cyberspace," Balkan Social Science Review, vol. 10, no. 10, pp. 7–25, 2017.
[6] A. S. Rajawat, R. Rawat, K. Barhanpurkar, R. N. Shaw and A. Ghosh, "Vulnerability analysis at industrial Internet of Things platform on dark web network using computational intelligence," in Computationally Intelligent Systems and their Applications, vol. 950, 2021, p. 39.
[7] G. Weimann, "Going dark: Terrorism on the dark web," Studies in Conflict & Terrorism, vol. 39, no. 3, pp. 195–206, 2016.
[8] M. Sabbah, A. Selamat and O. Krejcar, "Categorization of extremist content on the dark web using term-weighting techniques," Security Informatics, 2018 (representative study).
[9] P. Graczyk and K. Kinsvater, "Categorizing items in the Agora dark-web marketplace using TF-IDF and SVM classification," in Proc. Int. Conf. on Cybercrime Analysis, 2015 (representative study).
[10] M. W. Al Nabki, E. Fidalgo, E. Alegre and I. de Paz, "Classifying illegal activities on Tor network based on web textual contents," in Proc. 15th Conf. of the European Chapter of the ACL, 2017, pp. 35–43.
[11] D. Moore and T. Rid, "Cryptopolitik and the darknet," Survival, vol. 58, no. 1, pp. 7–38, 2016.
[12] J. Dalins, C. Wilson and M. Carman, "Criminal motivation on the dark web: A categorisation model for law enforcement," Digital Investigation, vol. 24, pp. 62–71, 2018.
[13] S. Ghosh, A. Das, P. Porras, V. Yegneswaran and A. Gehani, "Automated categorization of onion sites for analyzing the darkweb ecosystem," in Proc. 23rd ACM SIGKDD Int. Conf. on Knowledge Discovery and Data Mining, 2017, pp. 1793–1802.
[14] M. Sabbah, A. Selamat and O. Krejcar, "Hybridized term-weighting techniques for dark-web categorization," Journal of Information Retrieval Studies, 2019 (representative study).
[15] E. Fidalgo, E. Alegre, L. Fernández-Robles and V. González-Castro, "Classifying suspicious content in Tor darknet through Bag-of-Visual-Words model," Neurocomputing, vol. 397, pp. 106–118, 2020.
[16] Y. J. Jin, E. Cho and S. Oh, "DarkBERT: A language model for the dark side of the Internet," in Proc. 61st Annual Meeting of the Association for Computational Linguistics, 2023.
[17] K. S. Sangher, A. Singh, H. M. Pandey and V. Kumar, "Towards safe cyber practices: Developing a proactive cyber-threat intelligence system for dark web forum content by identifying cybercrimes," Information, vol. 14, no. 6, p. 349, 2023.
[18] D. G. Schwartz and G. Silverman, "Detecting terrorist influencers using reciprocal human-machine learning: The case of militant Jihadist Da'wa on the darknet," Humanities and Social Sciences Communications, vol. 11, art. 1442, 2024.
[19] G. Y. Shin, Y. Jang, D. W. Kim, S. Park, A. R. Park and Y. Kim, "Dark side of the web: Dark web classification based on TextCNN and topic modeling weight," IEEE Access, vol. 12, pp. 36361–36371, 2024.
[20] Detection of Dark Web Threats Using Machine Learning and Image Processing (LVTrees with ADASYN and Chi-square feature selection), preprint, 2024.
[21] H. Alghamdi and A. Selamat, "Techniques to detect terrorists/extremists on the dark web: A review," Data Technologies and Applications, vol. 56, pp. 461–482, 2022.
[22] S. Gaba, I. Budhiraja, V. Kumar and A. Makkar, "Advancements in enhancing cyber-physical system security: Practical deep learning solutions for network traffic classification and integration with security technologies," Mathematical Biosciences and Engineering, vol. 21, no. 1, pp. 1527–1553, 2024.
[23] N. Jeffrey, Q. Tan and J. R. Villar, "A review of anomaly detection strategies to detect threats to cyber-physical systems," Electronics, vol. 12, no. 15, p. 3283, 2023.
[24] V. Mahor, B. Garg, S. Telang, K. Pachlasiya, M. Chouhan and R. Rawat, "Cyber threat phylogeny assessment and vulnerabilities representation at thermal power station," in Proc. Int. Conf. on Network Security and Blockchain Technology (ICNSBT 2021), Lecture Notes in Networks and Systems, vol. 481, Springer, Singapore, 2022, pp. 28–39.
[25] M. K. Bagwani, A. Gangwar, K. Vishwakarma and V. K. Tiwari, "Real-time signature-based detection and prevention of DDoS attacks in cloud environments," International Journal of Science and Research Archive, vol. 12, no. 2, pp. 2929–2935, 2024.
[26] R. Rawat, V. Mahor, S. Chirgaiya, R. N. Shaw and A. Ghosh, "Sentiment analysis at online social network for cyber-malicious post reviews using machine learning techniques," in Computationally Intelligent Systems and their Applications, vol. 950, 2021, p. 113.
[27] M. Asiri, N. Saxena, R. Gjomemo and P. Burnap, "Understanding indicators of compromise against cyber-attacks in industrial control systems: A security perspective," ACM Trans. on Cyber-Physical Systems, 2023.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Dr. Kiran Pachlasiya

This work is licensed under a Creative Commons Attribution 4.0 International License.
Articles published in the International Journal of Artificial Intelligence, Cybersecurity and Emerging Technologies (IJAICET) are licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
Under this license, users are free to share, copy, redistribute, adapt, and build upon the published material for any purpose, including commercial use, provided appropriate credit is given to the original author(s) and the source, a link to the license is provided, and any changes made are indicated.
Authors retain copyright of their work while granting IJAICET the right to publish, archive, distribute, and index the article. The journal supports the free exchange of scientific knowledge through open access publishing and encourages the widest possible dissemination of research.