IITGN Students Build AI Shield Against Water Plant Cyberattacks
GANDHINAGAR : Gandhinagar: A cyberattack on a water treatment plant may not always look like a cyberattack. A legitimate command can quietly alter physical equipment and put an entire community at...
GANDHINAGAR : Gandhinagar: A cyberattack on a water treatment plant may not always look like a cyberattack. A legitimate command can quietly alter physical equipment and put an entire community at risk. Two IIT Gandhinagar students have developed an AI-powered system aimed at detecting exactly such threats—and won second prize at Intel’s global electronic design contest in Shanghai.
Third-year students Miloni Thakkar from Computer Science and Engineering and Mitwa Goswami from Electrical Engineering developed TrustGate, an AI-based cybersecurity system for industrial control systems used in water treatment plants, power grids and manufacturing facilities.
The team won the second prize at the Intel Electronic System Design Contest 2026, held at Shanghai Jiao Tong University.
TrustGate was inspired partly by the 2021 cyberattack on a water treatment plant in Oldsmar, Florida. In that incident, an attacker remotely attempted to increase sodium hydroxide levels to potentially dangerous levels. The attack was noticed only after an operator saw the computer cursor moving and reversed the command.
The IITGN students wanted to develop a system that could detect such threats without relying entirely on human vigilance.
“TrustGate closes that gap by understanding both the cyber and physical sides of an attack together,” Miloni said. She added that protecting systems responsible for basic services such as clean water has implications for both public health and infrastructure security.
Unlike conventional security tools that mainly monitor network traffic, TrustGate analyses network activity and physical sensor data together. Its dual-stream BiLSTM model uses what the students call “cross-modal attention” to determine whether a suspicious digital command is producing a dangerous physical effect.
The system can identify the likely attack and affected equipment and display the information on a live plant map.
“In a real plant, ‘something is wrong’ isn’t actionable on its own,” Miloni said. “What is important is for the operator to know where to look and what to shut down, in seconds and not minutes.”
TrustGate is designed to operate on embedded hardware rather than depend on cloud connectivity. It also uses TPM 2.0 security and a self-healing watchdog to protect the system and restart critical processes if they fail.
Mentor Prof Sameer Kulkarni said he encouraged the students to question their initial assumptions and take ownership of the project’s development.
However, TrustGate remains a research prototype. It has been tested on a laboratory testbed and still requires live plant testing, support for additional industrial protocols and formal security certification before possible real-world deployment.
The students now plan to further develop the system and explore its potential for other critical infrastructure, including power grids and oil and gas facilities.





