Towards Adversarial-Resilient Deep Neural Networks for False Data Injection Attack Detection in Power Grids

Towards Adversarial-Resilient Deep Neural Networks for False Data Injection Attack Detection in Power Grids
复制标题

DOI:
10.1109/icccn58024.2023.10230180
复制
发表时间:
2021-02
期刊:
2023 32nd International Conference on Computer Communications and Networks (ICCCN)
影响因子:
--
通讯作者:
Jiangnan Li;Yingyuan Yang;Jinyuan Sun;K. Tomsovic;H. Qi
Jiangnan Li;Yingyuan Yang;Jinyuan Sun;K. Tomsovic;H. Qi
中科院分区:
其他
文献类型:
--
作者:
Jiangnan Li;Yingyuan Yang;Jinyuan Sun;K. Tomsovic;H. Qi

文献摘要

相似文献

虚假数据注入攻击(FDIA)对电力系统状态估计构成重大安全威胁。为了检测此类攻击,最近的研究提出了机器学习(ML)技术,特别是深度神经网络(DNN)。然而,这些方法大多数都未能考虑对抗性测量带来的风险,这可能会损害各种机器学习应用中 DNN 的可靠性。在本文中,我们提出了一种基于 DNN 的 FDIA 检测方法,该方法能够抵御对抗性攻击。我们首先分析了计算机视觉中使用的几种对抗性防御机制,并展示了它们在 FDIA 检测中的固有局限性。然后,我们为 FDIA 提出了一种对抗性弹性 DNN 检测框架,该框架在训练和推理阶段都结合了随机输入填充。我们基于 IEEE 标准电力系统的模拟表明,该框架显着降低了对抗性攻击的有效性,同时对 DNN 检测性能的影响可以忽略不计。索引术语-虚假数据注入攻击、智能电网通信、深度学习、对抗性攻击
False data injection attacks (FDIAs) pose a significant security threat to power system state estimation. To detect such attacks, recent studies have proposed machine learning (ML) techniques, particularly deep neural networks (DNNs). However, most of these methods fail to account for the risk posed by adversarial measurements, which can compromise the reliability of DNNs in various ML applications. In this paper, we present a DNN-based FDIA detection approach that is resilient to adversarial attacks. We first analyze several adversarial defense mechanisms used in computer vision and show their inherent limitations in FDIA detection. We then propose an adversarial-resilient DNN detection framework for FDIA that incorporates random input padding in both the training and inference phases. Our simulations, based on an IEEE standard power system, demonstrate that this framework significantly reduces the effectiveness of adversarial attacks while having a negligible impact on the DNNs' detection performance. Index Terms-False Data Injection Attack, Smart Grid Communication, Deep Learning, Adversarial Attacks