A3D: Attention-based auto-encoder anomaly detector for false data injection attacks

A3D: Attention-based auto-encoder anomaly detector for false data injection attacks
复制标题

DOI:
10.1016/j.epsr.2020.106795
复制
发表时间:
2020-12
影响因子:
3.9
通讯作者:
Arnav Kundu;A. Sahu;E. Serpedin;K. Davis
Arnav Kundu;A. Sahu;E. Serpedin;K. Davis
中科院分区:
工程技术3区
文献类型:
--
作者:
Arnav Kundu;A. Sahu;E. Serpedin;K. Davis

文献摘要

相似文献

随着更先进、更互联的计算和控制设备的涌入,电网不断演变为依赖通信网络进行高效的运行和控制。这些新技术面临的一个挑战是,它们可能会引入新的、不可预见的接入途径,使电网更容易受到网络攻击。虚假数据注入攻击(FDIA)是一种特殊类型的攻击,旨在通过影响控制电网的反馈机制来导致电网运行中断。这是通过修改使状态估计器能够近似系统状态的测量来实现的。这些攻击的设计方式是,它们保留状态估计器对其进行操作的系统方程;因此,它们不能被简单的基于残差的检测机制检测到。在本文中,我们提出了基于单调注意力的自动编码器,这是一种检测FDIA的无监督学习技术。自动编码器是在正常操作条件下训练的,我们假设即使测量结果被对手修改,它也会产生接近正常操作时真实系统值的输出。基于这一假设,假设被攻击条件下存在较高的重构误差,利用精度-召回曲线的门限机制进行入侵检测。我们通过在IEEE 14节点系统上执行FDIA,验证了我们提出的基于注意力的自动编码器异常检测器(A3D)相对于其他自动编码器的变体,例如基于ANN和RNN的自动编码器,以及一些有监督的学习技术的有效性。
With the influx of more advanced and more connected computing and control devices, the electric power grid has continuously evolved to rely on communication networks for efficient operation and control. A challenge with these new technologies is that they may introduce new and unforeseen avenues of access, making the grid more susceptible to cyber attacks. False Data Injection Attacks (FDIA) are a particular type of attack that aims to cause disruptions in the operation of the power grid by affecting the feedback mechanism to control the grid. This is carried out by modifying the measurements which enable a state estimator to approximate the state of the system. These attacks are designed in such a way that they preserve the system equations on which the state estimator operates; therefore, they cannot be detected by a simple residual-based detection mechanism. In this paper, we propose monotonic attention based auto-encoders, an unsupervised learning technique to detect FDIAs. The auto-encoder is trained under normal operating conditions, and we hypothesize that it will produce outputs which are close to the true system values at normal operation even if the measurements are modified by an adversary. Based on this hypothesis, that high reconstruction error occurs for the attacked conditions, the intrusion detection is performed by a threshold mechanism using Precision-Recall curve. We validate the efficacy of our proposed attention-based auto-encoder anomaly detector (A3D) over other variants of auto-encoders such as ANN and RNN based auto-encoders, and a few supervised learning techniques, by performing FDIAs on a IEEE 14 bus system.