Joint Detection and Localization of Stealth False Data Injection Attacks in Smart Grids Using Graph Neural Networks

Joint Detection and Localization of Stealth False Data Injection Attacks in Smart Grids Using Graph Neural Networks
复制标题

DOI:
10.1109/tsg.2021.3117977
复制
发表时间:
2021-04
影响因子:
9.6
通讯作者:
Osman Boyaci;M. Narimani;K. Davis;Muhammad Ismail;T. Overbye;E. Serpedin
Osman Boyaci;M. Narimani;K. Davis;Muhammad Ismail;T. Overbye;E. Serpedin
中科院分区:
工程技术1区
文献类型:
--
作者:
Osman Boyaci;M. Narimani;K. Davis;Muhammad Ismail;T. Overbye;E. Serpedin

文献摘要

被引文献

相似文献

虚假数据注入攻击(FDIA)是威胁电力系统安全的网络攻击的主要类别。与发现这些攻击相反,人们对确定电网中被攻击的单位的关注较少。为此,本文联合研究了电网中隐身FDIA的检测与定位。利用电力系统固有的图形拓扑结构和测量数据的空间相关性,提出了一种基于图神经网络(GNN)的故障诊断方法。该方法利用了自回归滑动平均(ARMA)型图滤波(GFS),与切比雪夫等多项式型GFS相比,GFS由于其有理类型的滤波器组成而能够更好地适应谱域中的急剧变化。据我们所知,这是第一个基于GNN的工作,自动检测和定位电力系统中的FDIA。大量的仿真和可视化结果表明,对于不同的IEEE测试系统,该方法在检测和定位FDIA方面都优于现有的方法。因此,可以识别目标区域,并在攻击影响电网之前采取预防措施。
False data injection attacks (FDIA) are a main category of cyber-attacks threatening the security of power systems. Contrary to the detection of these attacks, less attention has been paid to identifying the attacked units of the grid. To this end, this work jointly studies detecting and localizing the stealth FDIA in power grids. Exploiting the inherent graph topology of power systems as well as the spatial correlations of measurement data, this paper proposes an approach based on the graph neural network (GNN) to identify the presence and location of the FDIA. The proposed approach leverages the auto-regressive moving average (ARMA) type graph filters (GFs) which can better adapt to sharp changes in the spectral domain due to their rational type filter composition compared to the polynomial type GFs such as Chebyshev. To the best of our knowledge, this is the first work based on GNN that automatically detects and localizes FDIA in power systems. Extensive simulations and visualizations show that the proposed approach outperforms the available methods in both detection and localization of FDIA for different IEEE test systems. Thus, the targeted areas can be identified and preventive actions can be taken before the attack impacts the grid.