返回
Cyber-Attack Detection Using Principal Component Analysis and Noisy Clustering Algorithms: A Collaborative Machine Learning-Based Framework
DOI:10.1109/TSG.2022.3176311.png)
摘要
En 中文
This paper proposes a collaborative machine learning-based framework to detect cyber-attacks in a power system, leading to deviation in the state variable behavior. Based on the proposed architecture, three different machine learning-based methods, i.e., visualization, classification, and clustering, are employed and compared to find the best one in the FDIA detection process. To this end, pre-processing is employed in the first stage. In the second stage, the patterns of the state vectors are transferred into features. Hence, 24 statistical features, including measures of central tendency, variability, measures of shape, and position, are extracted to find various properties. Then, in the third stage, a supervised algorithm is employed to rank and find the most crucial features in FDIA. In the fourth stage, an unsupervised dimensionality reduction technique (PCA) is applied to reduce the feature space. In the fifth and last stage, visualization, classification, and clustering-based methods are developed to detect FDIA. To simulate an attack, it is assumed that an intruder decreases or increases the state vectors at different buses with various attack parameters (i.e., 0.90, 0.95, 0.96, 0.97, 0.98, 1, 1.02, 1.03, 1.04, 1.05, and 1.10). The proposed method effectiveness is assessed on the New York Independent System Operator (NYISO) data applied to the IEEE 14-bus system. The results presented in the paper from different scenarios (i.e., phase angle (theta), voltage magnitude (V-m), measurements, and multiple attacks) on a real-world dataset demonstrate that the collaborative optimized PCA-Density-based machine learning technique can detect most of the attack samples with good performance scores (i.e., recall, precision, Fl) and outperforms the other investigated methods. Moreover, it is general and adaptable enough to cover the situation where either the system characteristics or the attack behavior changes.
Keyword:
False data injection attack (FDIA)
principal component analysis
noisy clustering algorithm
hyper-parameter optimization
adaptive semi-supervised learning detection method
期刊
IF:
9.8
论文数:
5.7K
被引数:
4.3W
机构
引用论文
Unsupervised Machine Learning-Based Detection of Covert Data Integrity Assault in Smart Grid Networks Utilizing Isolation Forest基于无监督机器学习的隔离森林智能电网网络隐蔽数据完整性攻击检测
Key Management Systems for Smart Grid Advanced Metering Infrastructure: A Survey智能电网高级计量基础设施的密钥管理系统: 综述
Vulnerability Assessment of AC State Estimation With Respect to False Data Injection Cyber-Attacks虚假数据注入网络攻击下交流状态估计的脆弱性评估

