Detecting Cyber Attacks in Smart Grids Using Semi-Supervised Anomaly Detection and Deep Representation Learning

Detecting Cyber Attacks in Smart Grids Using Semi-Supervised Anomaly Detection and Deep Representation Learning
复制标题

DOI:
10.3390/info12080328
复制
发表时间:
2021-08
期刊:
Inf.
影响因子:
--
通讯作者:
Ruobin Qi;Craig Rasband;Jun Zheng;Raul Longoria
Ruobin Qi;Craig Rasband;Jun Zheng;Raul Longoria
中科院分区:
其他
文献类型:
--
作者:
Ruobin Qi;Craig Rasband;Jun Zheng;Raul Longoria

文献摘要

相似文献

智能电网将先进的信息和通信技术(ICT)整合到传统电网中,以实现更高效、更具弹性的电力输送和管理,但也引入了新的安全漏洞,可被对手利用来发动网络攻击,造成大规模停电和基础设施破坏等严重后果。现有的基于机器学习的智能电网网络攻击检测方法大多是基于监督学习的,需要利用正常事件和攻击事件的实例进行训练。此外,监督学习要求训练数据集包括各种攻击事件的代表性实例,以训练一个好的模型,这有时是困难的,如果不是不可能的话。提出了一种基于半监督异常检测和深度表示学习的基于PMU数据的智能电网网络攻击检测方法。半监督异常检测只利用正常事件的实例来训练检测模型,适合发现未知攻击事件。本研究使用公开可用的电力系统网络攻击数据集对一些流行的半监督异常检测算法进行了研究,以确定性能最好的算法。与常用的监督算法的性能比较表明,半监督算法比监督算法更能发现攻击事件。我们的结果还表明,通过使用深度表示学习来增强半监督异常检测算法,可以进一步提高算法的性能。
Smart grids integrate advanced information and communication technologies (ICTs) into traditional power grids for more efficient and resilient power delivery and management, but also introduce new security vulnerabilities that can be exploited by adversaries to launch cyber attacks, causing severe consequences such as massive blackout and infrastructure damages. Existing machine learning-based methods for detecting cyber attacks in smart grids are mostly based on supervised learning, which need the instances of both normal and attack events for training. In addition, supervised learning requires that the training dataset includes representative instances of various types of attack events to train a good model, which is sometimes hard if not impossible. This paper presents a new method for detecting cyber attacks in smart grids using PMU data, which is based on semi-supervised anomaly detection and deep representation learning. Semi-supervised anomaly detection only employs the instances of normal events to train detection models, making it suitable for finding unknown attack events. A number of popular semi-supervised anomaly detection algorithms were investigated in our study using publicly available power system cyber attack datasets to identify the best-performing ones. The performance comparison with popular supervised algorithms demonstrates that semi-supervised algorithms are more capable of finding attack events than supervised algorithms. Our results also show that the performance of semi-supervised anomaly detection algorithms can be further improved by augmenting with deep representation learning.