Skip to main content
QUICK REVIEW

[论文解读] An Online Approach to Cyberattack Detection and Localization in Smart Grid

Dan Li, Nagi Gebraeel|arXiv (Cornell University)|Feb 22, 2021
Smart Grid Security and Resilience参考文献 25被引用 6
一句话总结

本文提出一种在线、稀疏感知的方法,利用稀疏组套索(SGL)回归来检测和定位智能电网中的隐蔽数据完整性攻击,通过分析状态估计残差。该方法在较高攻击严重程度下,相比传统的卡方检验,实现了更快的检测速度和更高的定位精度,已在线性与非线性IEEE 14节点系统上得到验证。

ABSTRACT

Complex interconnections between information technology and digital control systems have significantly increased cybersecurity vulnerabilities in smart grids. Cyberattacks involving data integrity can be very disruptive because of their potential to compromise physical control by manipulating measurement data. This is especially true in large and complex electric networks that often rely on traditional intrusion detection systems focused on monitoring network traffic. In this paper, we develop an online detection algorithm to detect and localize covert attacks on smart grids. Using a network system model, we develop a theoretical framework by characterizing a covert attack on a generator bus in the network as sparse features in the state-estimation residuals. We leverage such sparsity via a regularized linear regression method to detect and localize covert attacks based on the regression coefficients. We conduct a comprehensive numerical study on both linear and nonlinear system models to validate our proposed method. The results show that our method outperforms conventional methods in both detection delay and localization accuracy.

研究动机与目标

  • 为应对大规模智能电网中隐蔽数据完整性攻击的检测与定位挑战,此类攻击可绕过传统入侵检测系统。
  • 克服假设检验与基于图的方法在大型传感器网络中面临的计算与统计局限性。
  • 开发一种统一、计算高效且统计可解释的框架,用于发电机母线攻击的在线检测与定位。
  • 在线性与非线性电力系统模型上验证该方法的性能,尤其在真实攻击场景下。
  • 展示相比传统卡方检验,该方法在检测速度与定位精度方面均有提升。

提出的方法

  • 该方法将隐蔽攻击建模为状态估计残差中的稀疏特征,利用攻击引起的异常的稀疏性。
  • 采用稀疏组套索(SGL)回归,联合检测异常性(通过残差幅值)与定位攻击(通过回归系数中的稀疏模式)。
  • 检测阈值通过估计系数最大l1-范数的0.995分位数设定,以保持控制状态下的平均运行长度(约200)。
  • 该方法首先在理论上基于线性系统建立,随后通过松弛法与IEEE 14节点模型的仿真,扩展至非线性系统。
  • 该方法使用Pecan Street数据集中的真实负荷数据,并通过求解混合整数机组组合问题生成现实的发电计划。
  • 攻击定位通过识别SGL解中系数幅值最大的发电机母线来确定,该母线即为异常源。

实验结果

研究问题

  • RQ1正则化回归方法能否通过利用状态估计残差中的稀疏性,有效检测智能电网中的隐蔽网络攻击?
  • RQ2与传统卡方检验相比,所提出的SGL方法在检测延迟与定位精度方面表现如何?
  • RQ3该方法在非线性电力系统模型中检测与定位攻击的能力达到何种程度?
  • RQ4攻击严重程度(信噪比)如何影响检测性能与定位精度?
  • RQ5在大规模系统中,该方法能否在保持低误报率的同时实现快速检测?

主要发现

  • 所提出的SGL方法在高严重程度攻击下显著降低了检测延迟,平均运行长度从卡方检验的203.46降至SGL的12.13。
  • 定位精度随攻击严重程度提高而提升,在第6级(发电量100%减少)时,SGL的定位准确率达到86.91%,卡方检验为99.40%。
  • 在第5级(80%减少)时,SGL实现81.28%的定位准确率与15.54的平均运行长度,两项指标均优于卡方检验。
  • 在攻击发生前,该方法保持了低误报率,所有发电机母线的系数幅值均保持在控制限内。
  • 在非线性系统中,SGL方法随着攻击严重程度增加,检测速度与精度同步提升,表现出对系统非线性的强鲁棒性。
  • 在所有攻击等级下,该方法在检测能力与定位精度方面均优于卡方检验,尤其在中等至高严重程度下表现更优。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。