Detecting Load Redistribution Attacks via Support Vector Models

Detecting Load Redistribution Attacks via Support Vector Models
复制标题

DOI:
10.1049/iet-stg.2020.0030
复制
发表时间:
2020-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Zhigang Chu;O. Kosut;L. Sankar
Zhigang Chu;O. Kosut;L. Sankar
中科院分区:
其他
文献类型:
--
作者:
Zhigang Chu;O. Kosut;L. Sankar

文献摘要

相似文献

提出了一种基于机器学习的检测框架来检测一类通过修改测量值来重新分配负载的网络攻击。该检测框架包括一个多输出支持向量回归(SVR)负载预测器,利用空间和时间的相关性预测负载,以及随后的支持向量机(SVM)攻击检测器,利用SVR预测器预测的负载来确定负载重新分配(LR)攻击的存在。从公开可用的PJM分区负荷中获得用于训练SVR的历史负荷数据,并将其映射到IEEE 30节点系统。SVM使用正常数据和随机创建的LR攻击进行训练,并针对随机和智能设计的LR攻击进行测试。实验结果表明,该检测框架能够有效地检测LR攻击。此外,攻击缓解可以通过使用SVR预测的负载来重新分派代来实现。
A machine learning-based detection framework is proposed to detect a class of cyber-attacks that redistribute loads by modifying measurements. The detection framework consists of a multi-output support vector regression (SVR) load predictor that predicts loads by exploiting both spatial and temporal correlations, and a subsequent support vector machine (SVM) attack detector to determine the existence of load redistribution (LR) attacks utilizing loads predicted by the SVR predictor. Historical load data for training the SVR are obtained from the publicly available PJM zonal loads and are mapped to the IEEE 30-bus system. The SVM is trained using normal data and randomly created LR attacks, and is tested against both random and intelligently designed LR attacks. The results show that the proposed detection framework can effectively detect LR attacks. Moreover, attack mitigation can be achieved by using the SVR predicted loads to re-dispatch generations.