Fault and Attack Detection and Diagnosis by Analysis of Electrical Waveforms of Power Networks

Fault and Attack Detection and Diagnosis by Analysis of Electrical Waveforms of Power Networks
复制标题

DOI:
10.1109/aero53065.2022.9843462
复制
发表时间:
2022-03
期刊:
2022 IEEE Aerospace Conference (AERO)
影响因子:
--
通讯作者:
S. Coshatt;Bowen Yang;Jin Ye;Wenzhan Song;F. Zahiri;James Hill
S. Coshatt;Bowen Yang;Jin Ye;Wenzhan Song;F. Zahiri;James Hill
中科院分区:
其他
文献类型:
--
作者:
S. Coshatt;Bowen Yang;Jin Ye;Wenzhan Song;F. Zahiri;James Hill

文献摘要

相似文献

近年来,越来越多的电子控制单元(ECU)、可编程逻辑控制器(PLC)和其他类型的可编程电子器件已被部署到网络物理系统中。虽然这种进步提高了生产力和产品质量,但也给硬件和软件带来了脆弱性。本研究提出了一种数据驱动的方法来监测网络物理系统的电力网络的电波形,以进行攻击和故障检测与诊断。在方法论方面,大多数研究都集中在分类上,只允许对已知的攻击或故障进行分类。虽然可以检测到新的攻击,但它们不能被正确诊断,因为新的攻击将被迫进入现有的分类器之一,从而导致不正确的诊断。本研究提出使用聚类来检测和诊断异常。具体来说,它建议使用二维无监督shapestra(2D u-shapestra)进行聚类。U形曲线是具有判别能力的短时间序列,可以从数据集中自动提取。这项研究是第一个两阶段的研究,将动态聚类与u形。这种长期方法的优点是允许系统向系统用户通知新类型的攻击或故障,这些攻击或故障稍后可以被标记。因此,系统可以学习识别新的异常。进行了广泛的评估,以研究算法的性能,如性能指标与集群和异常类型的数量,以及对此类系统的新型对抗性攻击的有效性。
In recent years, increasing numbers of electronic control units (ECUs), programmable logic controllers (PLCs), and other types of programmable electronics have been deployed into cyber-physical systems. While such progress increased productivity and product quality, it also introduces vulnerabilities to both hardware and software. This study proposes a data-driven approach to monitoring the electric waveforms of the power network of cyber-physical systems for attack and fault detection and diagnosis. In terms of methodology, most studies focus on classification, which only allows for classification of known attacks or faults. While new attacks could be detected, they cannot be properly diagnosed as a new attack would be forced into one of the existing classifiers, thus leading to an incorrect diagnosis. This study proposes using clustering to detect and diagnosis anomalies. Specifically, it proposes using two dimensional unsupervised shapelets (2D u-shapelets) for clustering. U-shapelets are short time series with discriminatory capabilities that can be automatically extracted from a data set. This study is the first of a two phase study to incorporate dynamic clustering with u-shapelets. The advantage of this long term approach allows a system to notify systems users of a new type of attack or fault, which can later be labelled. Thus, the system can learn to identify new anomalies. Extensive evaluations are conducted to study the algorithm performance, such as the performance metrics vs the number of clusters and anomaly types, and the effectiveness for novel adversarial attacks on such systems.