Power grid false data injection attack identification method based on robust graph auto-encoder
By adopting a robust graph autoencoder-based method in the smart grid, using a generalized graph neural network and autoencoder structure to capture data correlation, the problems of poor FDIA detection performance and susceptibility to data poisoning in the prior art are solved, and higher detection performance and toughness are achieved.
Patent Information
- Application Number
- CN202510217671.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art has problems with poor detection performance, susceptibility to data poisoning, spatial and temporal correlations of power grid data cannot be captured, and lack of topological awareness when detecting false data injection attacks (FDIAs) in smart grids.
Using a grid false data injection attack recognition method based on a robust graph autoencoder, a generalized graph neural network anomaly detector uses Chebischev graph convolutional cyclic layer and attention mechanism to capture the spatial and temporal correlation of data, a CR-GAE model is constructed to ensure the correct labeling of FDIA, and the detection performance is optimized through hyperparameter selection.
It improves the resilience of the power grid to data poisoning and false data injection attacks, maintains high detection performance, and can effectively detect FDIA even when there are malicious samples that are wrongly marked as benign, with good generalization ability and robustness, and adapts to different grid topological reconstructions.
Smart Images

Figure CN120074915A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of smart grid security, and in particular to a method for identifying false data injection attacks in the power grid based on a robust graph autoencoder. Background Art
[0002] The cyber-physical characteristics of the smart grid make it a complex system, in which a large amount of measurement data is continuously exchanged between its components. To achieve correct operation, decision-making, and situation awareness, the smart grid relies on these measurement data. Therefore, when it comes to the reliability of the power system, ensuring the integrity of these data is a key goal. Unfortunately, when the power system is subjected to false data injection attacks (FDIAs), the integrity of the data is compromised because the measurement data is manipulated by malicious entities. Such operations may lead to incorrect operation decisions, thus overloading the system. FDIAs pose a major challenge because they may be executed in a stealthy manner, which can bypass traditional bad data detection (BDD) systems.
[0003] Use data-driven machine learning (ML) methods to detect FDIAs. This defense employs ML models with shallow or deep neural network (DNN) structures, or uses graph signal processing (GSP) filters, or methods based on graph neural networks (GNN). Although this mechanism exhibits good detection performance, they still have the following disadvantages:
[0004] 1) Machine learning-based detection schemes: For shallow machine learning models, the support vector machine (SVM) and decision tree detection schemes reported F1-Scores of 82% and 88% respectively. The detection rate of the random forest-based detection scheme is 93%. However, due to the complex patterns presented by the measurement data in the smart grid, the above shallow models cannot fully capture these patterns, which explains their relatively poor detection performance.
[0005] Different from shallow models, deep neural networks can capture more complex patterns and provide better detection performance. For example, the accuracy rates reported by the feedforward neural network (FNN) detection scheme are 90% and 99% respectively. The recognition rates of the recurrent neural network (RNN) and autoencoder detection schemes reach 96% and 96.2% respectively. The accuracy rates of the convolutional neural network (CNN) detection scheme are 93% and 99% respectively. However, these figures do not fully reflect the practicality of these schemes because their performance is only evaluated based on one network topology and not tested on different topological configurations. In addition, these schemes provide detectors that do not understand the topology and cannot capture the spatial aspects and relationships in the power grid data.
[0006] Due to the limitations of the above ML-based detection schemes, the shallow model and DNN-based detection schemes are highly vulnerable to data poisoning, with their DRs decreasing by 17 - 29% and 10 - 21% respectively.
[0007] 2) Graph-based detection schemes: To utilize the spatial relationship between power measurements and grid topology information, graph-based FDIA detection schemes (GSP and GNN) have been proposed in the literature. The DR value of the GSP model is 90%. One limitation of the GSP models is that they require manual and custom filter design, which limits their scalability. The DR value of the convolutional GNN (C-GNN) detection scheme is 83 - 96%. However, the reported performance is still based on only one topological configuration without considering different topological reconfigurations. Although the spatial relationship is captured, the simulation results in Section IV-D show that the C-GNN detector is still vulnerable to data poisoning, with a DR degradation rate of 9 - 11%, because it cannot generalize in the case of power system topology reconfiguration, which may occur for various reasons. In addition, it cannot fully capture the temporal correlation in the grid time series data. Moreover, this detection scheme is highly vulnerable to zero-day (invisible) attacks because they are only trained on a predefined set of FDIAs.
[0008] It is worth mentioning that the above inventions reveal different metrics for different FDIAs and system scales, and comparing them is challenging due to the lack of common ground. In addition to the limitations of the above existing FDIA detection schemes, most importantly, they are trained on datasets assuming that the samples have correct label information. Ignoring such an aspect makes the detector vulnerable to data poisoning, in which malicious samples are mislabeled as benign samples because they have not been detected before.
[0009] 3) Data Poisoning Detection Scheme: Only a few inventions have considered the impact of data poisoning on the smart grid. For example, linear regression and neural network-based models have been proposed to detect data poisoning in load forecasting. In addition, a detector based on sequential ensemble learning (SEL) provides high robustness against data poisoning in smart meters. In different contexts, other inventions have proposed traditional data poisoning defense schemes using outlier detection, local intrinsic dimensionality, and federated learning. However, these detectors still suffer from the same limitations as the above-mentioned studies because they do not capture the spatial relationships in grid measurement data. In addition, these detectors propose unrealistic solutions because they fail in the case of topological reconfiguration (i.e., lack of generalization ability). Moreover, some inventions are designed specifically for detecting data poisoning and do not consider other network attacks (e.g., other types of FDIA). Therefore, it is not sufficient to use them alone when detecting multiple attack types. In addition to requiring an additional data poisoning filtering step before the actual FDIA detection scheme, the data poisoning detection they provide is only designed for a specific ML model (e.g., SVM), or they are probabilistic, which requires additional calculations on the server side. Therefore, in this work, we attempt to create a robust detector that is immune to data poisoning and, at the same time, provides stable detection performance for various types of FDIA without the need for additional data filtering operations or calculations.
[0010] Due to the limitations of the above existing detection schemes, it is necessary to develop a robust detector that takes into account several aspects, including capturing: 1) complex patterns in measurement data; 2) spatial aspects of the power system topology; 3) temporal correlations in time series measurements. In addition, the detector should be topology-aware; 4) provide generalization ability to capture new topological reconfigurations of the power grid. Due to the lack of correctly labeled data, the detector should be robust against unseen correctly labeled FDIA in unseen topologies, as well as data poisoning without the need for additional data filtering operations. Summary of the Invention
[0011] The object of the present invention is to provide a method for identifying false data injection attacks in the power grid based on a robust graph autoencoder, which provides improved detection performance and enhances the resilience of the power system against data poisoning and false data injection attacks.
[0012] To achieve the above object, the present invention provides a method for identifying false data injection attacks in the power grid based on a robust graph autoencoder, comprising the following steps:
[0013] S1. Provide an anomaly detector based on a generalized graph neural network; the anomaly detector only needs a benign data set for training, and uses an autoencoder with a Chebyshev graph convolutional recurrent layer and an attention mechanism to capture the spatial and temporal correlations in the measurement data;
[0014] S2. Generate adversarial data poisoning samples and correctly labeled FDIA malicious samples using six network attack functions that bypass traditional BDD; the attack functions include random attack, general attack, and four replay attacks;
[0015] S3. Inject the adversarial data poisoning samples into the training set of the anomaly detector using multiple injection levels to simulate data poisoning with incorrect annotation information;
[0016] S4. Inject the correctly labeled FDIA malicious samples into the test sets of supervised and unsupervised anomaly detectors, and the training set of the supervised anomaly detector to simulate correctly labeled FDIA;
[0017] S5. Construct a CR-GAE model through the anomaly detector to ensure correct labeling of FDIA;
[0018] S6. Perform a hyperparameter selection process to adopt the optimal hyperparameter set that provides the best detection performance for XVAL; the best detection performance refers to the highest detection rate, the highest false alarm rate, and the lowest accuracy;
[0019] S7. The anomaly detector distinguishes between benign samples and malicious samples through a detection threshold ψ;
[0020] S8. Evaluate the detection performance of the anomaly detector through evaluation metrics under general and topology-specific settings; the evaluation metrics include detection rate, false alarm rate, and accuracy.
[0021] Preferably, the random attack obtains the adversarial data poisoning sample X s (t,i) as follows:
[0022] X s (t,i) = X b (t,i) + α.X b (t,i);
[0023] where t represents the timestamp, i represents the bus, α represents the perturbation amplitude randomly applied to a given benign sample to maliciously change the measured value, and -0.05 ≤ α ≤ 0.05, and X b (t,i) represents the benign sample.
[0024] Preferably, the adversarial data poisoning sample generated using the general attack is as follows:
[0025] X s (t,i) = X b (t,i) + (-1) β α.γ.Range(X b (t,i));
[0026] where β represents a binary random variable, γ represents a uniform random variable between (0, 1), and Range(X b (t,i)) represents the true measurement range of timestamp t and bus i.
[0027] Preferably, the four replay attacks include one-step replay attack, random replay attack, interval replay attack, and strategic replay attack.
[0028] Preferably, in the one-step replay attack, the data of the previous timestamp (t-1) is repeated to generate X s (t,i) as follows:
[0029] X s (t,i) = X b (t-1,i);
[0030] In the random replay attack, data from a previous timestamp 2 ≤ t ≤ 5 is randomly selected for repetition to generate X s (t,i) as follows:
[0031]
[0032] In the interval replay attack, a series of random benign samples are replaced with the true measurements of a random previous time interval [[t n , …, m], [X b (t*n, i), …, X b (t m ,i)], resulting in:
[0033]
[0034] where represents the starting time point of the historical time interval randomly selected by the attacker, represents the ending time point of the historical time interval randomly selected by the attacker;
[0035] In the strategic replay attack, the benign samples [X b (t n , i), …, X b (t m , i)] are replaced with the true measurements of the previous time interval to obtain: resulting in:
[0036]
[0037] where must be higher / lower than [X b (t n , i), …, Xb (t m , i)].
[0038] Preferably, the adversarial data poisoning samples in S3 provide manipulated measurements mislabeled as benign and are injected at multiple levels, accounting for 10%, 20%, or 30% of the training set respectively.
[0039] Preferably, in S5, the CR-GAE model learns the normal operations of benign samples and labels the abnormal operations of malicious samples based on the deviation from the learned benign patterns.
[0040] Preferably, let E = f Φ (X) and D = gΦ(X) be the graph encoder and decoder respectively, and the cost function of the obtained CR-GAE model is expressed as:
[0041]
[0042] where Φ describes the parameters of the model.
[0043] Preferably, the discrimination method in S7 is: when the score is greater than ψ, the malicious sample is assigned the label y = 1; otherwise the sample is considered benign.
[0044] Preferably, the specific steps for evaluating the anomaly detector in S8 include:
[0045] Determine the degree to which the model identifies malicious samples through the detection rate:
[0046] DR = TP / (TP + FN);
[0047] where DR represents the detection rate, and TP and FN represent true positive and false negative samples respectively;
[0048] Obtain the false alarm rate by calculating the percentage of benign samples misdetected as malicious samples:
[0049] FAR = FP / (FP + TN);
[0050] where FAR represents the false alarm rate, and FP and TN represent false positive and true negative samples respectively;
[0051] Determine the degree to which the model correctly labels benign and malicious samples through the accuracy rate:
[0052] ACC = (TP + TN) / (TP + TN + FP + FN);
[0053] where ACC represents the accuracy rate.
[0054] Therefore, the present invention adopts the above-mentioned method for identifying false data injection attacks in power grids based on a robust graph autoencoder, and has the following beneficial effects:
[0055] (1) This method only requires a benign data set for training. Through the autoencoder structure, it can effectively capture the normal patterns in the data. Therefore, when there are malicious samples mislabeled as benign in the training data, it can still maintain a high detection performance.
[0056] (2) Since this method adopts an unsupervised learning method and does not rely on pre-labeled malicious samples, it can detect new types of FDIAs that have not appeared in the training set, namely so-called zero-day attacks. This is of great significance in practical applications because attackers may constantly change their attack means to avoid detection.
[0057] (3) This method is trained and tested on various power grid topologies of different scales. The results show that it has good generalization ability and can maintain stable detection performance on unseen topologies. This benefits from its ability to capture the spatial relationships and temporal correlations in power system data, thus adapting to different power grid topology reconstruction situations.
[0058] (4) Since this method does not rely on specific attack patterns but conducts anomaly detection by learning the normal patterns of the data, it also has a certain detection ability for new types of FDIA attack types and can adapt to the constantly changing attack means of attackers.
[0059] The technical solution of the present invention will be further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 It is a schematic structural diagram of three topologies of a 14-bus system according to an embodiment of the present invention;
[0061] Figure 2 It is a schematic structural diagram of a CR-GAE model according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0062] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0063] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0064] As Figure 1 - Figure 2 shown, the present invention provides a method for identifying false data injection attacks in a power grid based on a robust graph autoencoder, including the following steps:
[0065] S1. Provide an anomaly detector based on a generalized graph neural network (GNN) to overcome the limitations exhibited by data-driven FDIA benchmark detectors. This anomaly detector is robust to correctly labeled FDIA and data poisoning. The anomaly detector only requires a benign dataset for training and uses an autoencoder with Chebyshev graph convolutional recurrent layers and an attention mechanism to capture the spatial and temporal correlations in the measurement data.
[0066] S2. Use six network attack functions that bypass traditional BDDs to generate adversarial data poisoning samples and correctly labeled FDIA malicious samples.
[0067] The attack functions include random attacks, general attacks, and four replay attacks. To ensure the concealment of this attack and not be detected, the difference between the altered and real measurement data is kept below a threshold, which is considered acceptable but can effectively bypass the traditional BDDs of the power system.
[0068] The attack functions are FDIA functions that create data poisoning and correctly label malicious samples, as follows:
[0069] a) Random attack: Apply a small perturbation value to the benign sample to affect its integrity, that is, change the measurement data in this article. Generate an adversarial data poisoning sample X s (t,i) at time stamp t and bus i, as follows:
[0070] Xs (t, i) = X b (t, i) + α·X b (t, i);
[0071] where -0.05 ≤ α ≤ 0.05, α is a random variable representing the perturbation amplitude (or attack amplitude) randomly applied to a given benign sample to maliciously change the measured value, and X b (t, i) represents a benign sample. Figure 1 (a) shows the random attacks that occurred in the 14-bus system at t = 2 and t = 6 compared to normal operation.
[0072] b) General attack: The adversarial data poisoning samples generated using the general attack are as follows:
[0073] X s (t, i) = X b (t, i) + (-1) β α·γ·Range(X b (t, i));
[0074] where β represents a binary random variable respectively, γ represents a uniform random variable between (0, 1), and Range(X b (t, i)) represents the true measurement range of timestamp t and bus i.
[0075] c) Replay attacks include four types of replay attacks: one-step replay attack, random replay attack, interval replay attack, and strategy replay attack. For the first two attacks, namely the one-step replay attack and the random replay attack, a benign sample needs to be selected and replaced with the true measured value of a previous timestamp.
[0076] In the one-step replay attack, the data of the previous timestamp (t - 1) is repeated to generate X s (t, i) as follows:
[0077] X s (t, i) = X b (t - 1, i);
[0078] Figure 1 (c) gives an illustration of the one-step replay attack that occurred at t = 3 and t = 7 compared to normal operation.
[0079] In the random replay attack, the data of a previous timestamp 2 ≤ t ≤ 5 is randomly selected for repetition to generate X s (t, i) as follows:
[0080]
[0081] Interval replay attack and strategy replay attack require within a time interval [tn , …] select a series of consecutive benign samples [[X b (t n , i), …, X b (t m , i)], t m , and replace them with a series of consecutive true measurements from a previous timestamp.
[0082] In the interval replay attack, a series of random benign samples are replaced with random true measurements from the previous time interval [[t n , …], m] [[X b (t*n, i), …], X b (t m , i)], resulting in:
[0083]
[0084] where, represents the starting time point of the historical time interval randomly selected by the attacker, represents the ending time point of the historical time interval randomly selected by the attacker.
[0085] In the strategic replay attack, the benign samples [X b (t n , i), …, X b (t m , i)] are replaced with the true measurements from the previous time interval to obtain: resulting in:
[0086]
[0087] where, must be higher / lower than [X b (t n , i), …, X b (t m , i)].
[0088] In this way, a series of relatively high measurements are replaced by previously lower values, and vice versa.
[0089] In the interval replay attack and the strategic replay attack, the length of the time interval is randomly selected between 2 and 5. According to the experimental results, replay attacks with longer time intervals are more likely to be detected by the anomaly detector.
[0090] S3. Inject adversarial data poisoning samples into the training set of the anomaly detector using multiple injection levels to simulate data poisoning with incorrect annotation information. The adversarial data poisoning samples provide manipulated measurements that are mislabeled as benign and are injected at multiple levels, accounting for 10%, 20%, or 30% of the training set respectively. Simulation studies were conducted on 14, 39, and 118 bus systems, where the anomaly detector either uses multiple topologies (generalized setting) or one topology (topology-specific setting).
[0091] Adversarial data poisoning samples (X s ): Data poisoning refers to the implicit assumption that training samples have correct information when training on data and labeling true benign samples as benign. However, in reality, this assumption is not always valid because the sample values and labels input into a given ML model are not always correct. Consider the case where a malicious entity changes measurement data (e.g., manipulates sensor data) and performs FDIA when traditional BDD cannot detect it. The measurements generated using these cyberattacks will be mislabeled as benign with incorrect label information, and such generated samples are called adversarial data poisoning samples. When these poisoned data are used to train the detector of FDIA, the training set will wrongly include adversarial samples with benign labels. Consequently, the detector will be trained and process such adversarial patterns as if they present benign measurements. These situations are described as data poisoning, which causes the decision boundary of the detector to shift and reduces the detection ability of FDIA.
[0092] To quantify the impact of data poisoning, the previously mentioned attack functions are used to create adversarial data poisoning samples, which are injected into the training set of the anomaly detector with false benign labels of y = 0 (y represents the label of the sample, used to indicate whether the measurement data is "benign" or "malicious", i.e., whether it is subject to the false data injection attack FDIA, and y = 0 indicates that the sample is mislabeled as benign) instead of the true malicious y = 1 label. The attack functions are used to generate an equal number of adversarial data poisoning samples, where the samples from each attack function are 1 / 6X s .
[0093] Attack injection level: Since data poisoning only exists in the training phase, adversarial data poisoning samples are launched into the training set X TR by using four levels for each training topology to study the impact of adversarial data poisoning samples. Six attack functions are used to generate an equal number of adversarial data poisoning samples, and the adversarial data poisoning samples are injected into X TR , where X b and X sIt is divided as follows: the first layer contains 0% adversarial data poisoning samples (100% real benign samples); the second layer contains 10% adversarial data poisoning samples (90% real benign samples); the third layer contains 20% adversarial data poisoning samples (80% real benign samples); the fourth layer contains 30% adversarial data poisoning samples (70% real benign samples).
[0094] S4. Inject correctly labeled FDIA malicious samples into the test sets of supervised and unsupervised anomaly detectors, as well as the training set of the supervised anomaly detector, to simulate correctly labeled FDIA.
[0095] Correctly labeled FDIA malicious sample (X m ): Similarly, use the attack function to generate the correctly labeled FDIA malicious sample X m , and assign it the true malicious label y = 1. The attack function is used to generate an equal number of correctly labeled FDIA samples, where each sample of the attack function is 1 / 6 of X m . The sample X m existing in the test sets of (supervised and unsupervised) anomaly detectors simulates the detector encountering FDIA. The sample X m also exists in the training set of the supervised anomaly detector, representing the previously detected correctly labeled FDIA.
[0096] Training set and test set: The benign sample X b has the correct labeling information with y = 0; the adversarial data poisoning sample X s has the wrong labeling information with y = 0; the correctly labeled FDIA malicious sample X m has the correct labeling information y = 1. Since the supervised anomaly detector performs binary classification and needs to train on samples with y = 0 and y = 1 labels, therefore, the training set of the supervised anomaly detector includes: the supervised anomaly detector on X with b (label y = 0) label of X b 、X s (label y = 0) with y = 0 label of X s and X with y = 1 label m (label y = 1) for training, while its test set only includes: the supervised anomaly detector on X with y = 0 label b and (label y = 0) and X with y = 1 label for testing m (label y = 1). However, the unsupervised anomaly detector needs to train on samples with one label (y = 0), so the training set of the unsupervised anomaly detector includes: X b (label y = 0) and X s(Label y = 0), and its test set contains: X b (Label y = 0) and X m (Label y = 0). Since the data poisoning sample X s is an undetected mislabeled sample and only exists in the training set. While the malicious sample X m is added to the test set of the anomaly detector (supervised and unsupervised) to simulate the scenario where the system encounters FDIA. X is also included in the training set of the supervised anomaly detector m , indicating the correctly labeled and detected FDIA samples.
[0097] S5. Build a CR-GAE (Convolutional Recurrent Graph Autoencoder) model through the anomaly detector to ensure the correct labeling of FDIA. The CR-GAE model has the following characteristics: providing topology-aware detection to capture the spatial relationships in power system data; providing a generalization ability to detect network attacks in invisible topologies; providing an unsupervised anomaly detection that only requires benign data for training and provides the detection of completely invisible FDIA, thus providing robustness against zero-day attacks; using an autoencoder with Chebyshev graph convolutional recurrent layers and an attention mechanism to capture complex patterns and spatio-temporal correlations in the measurement data.
[0098] The characteristics provided by the CR-GAE model improve the detection performance of the anomaly detector. Specifically, the CR-GAE model provides stable detection performance during the training with a high level of adversarial data poisoning samples and unseen correctly labeled FDIA malicious samples. And in the test set with unseen topologies, its detection performance only drops by 1.6 - 3.7%. This means that compared with the shallow, deep, and C-GNN models, the CR-GAE model improves the detection rate DR index by 16 - 25%, 8 - 17%, and 7 - 8% respectively.
[0099] The CR-GAE model provides unsupervised training. Since it uses an autoencoder, it only requires the benign data of normal operation for training. The CR-GAE model also provides generalized training on multiple graph representations of various topologies and has the ability to detect unseen FDIA types in different unseen topologies. The structure of the CR-GAE model allows it to capture complex patterns and temporal and spatial aspects in the data due to the presence of its graph convolutional recurrent layers equipped with an attention mechanism. Capturing these features enables it to distinguish different sample types, thus making it robust against data poisoning and other invisible malicious FDIA.
[0100] Through the graph encoder and decoder, the CR-GAE model utilizes the reconstruction process of graph-structured data to learn the representations of different graph structures from the benign data of normal operations. The CR-GAE model includes an input layer, followed by a graph encoding hidden layer, then an attention layer and a latent layer. During training, the input to the model is sampled with the y = 0 label (i.e., benign samples with true labels and toxic samples with false labels), and the input samples hold time measurement values [P i ,Q i ∈R n ×2. Then, a graph decoding hidden layer is placed, and then the reconstructed output is obtained.
[0101] This CR-GAE model can learn the normal operations of benign samples and label the abnormal operations of malicious samples based on the deviation from the learned benign patterns. Determining when an anomaly occurs is based on the reconstruction error ζ during the entire reconstruction process.
[0102] Let E = f Φ (X) and D = gΦ(X) be the graph encoder and decoder respectively, and the cost function of the resulting CR-GAE model is expressed as:
[0103]
[0104] where Φ describes the parameters of the model. The objective of this cost function (i.e., the mean squared error mse) is to penalize g Φ (f Φ (X)) because of its difference from X.
[0105] S6. Perform a hyperparameter selection process to adopt the optimal hyperparameter set that provides the best detection performance (i.e., the highest detection rate DR and the lowest false alarm rate ACC and false positive rate FAR) for the validation set X VAL . Specifically, perform a multi-stage sequential grid search, where one hyperparameter is selected from the selection space in each stage.
[0106] Selection space: Define the optimal hyperparameter values selected from the selection space P for each of the following hyperparameters. Number of layers L = {2, 3, 4, 5, 6, 8}, number of units U = {4, 8, 16, 32, 64}, dropout rate D = {0, 0.2, 0.4, 0.5}, neighborhood order K = {2, 3, 4, 5}, optimizer O = {Adam, Adamax, SGD, Rmsprop}, activation function A = {Sigmoid, Tanh, Relu, Elu}.
[0107] Optimal Hyperparameters: After sequential grid search, the hyperparameters listed in Table 1 are the optimal hyperparameters for the deep detector. For the autoencoder-based models (SEL and CR-GAE), the reported U represents the number of units in the first encoding layer. Thus, when L and U are 4 and 32 respectively, the model has (32, 16) and (16, 32) units in the encoder and decoder layers respectively. For the shallow model, ARIMA gives the optimal values of 0 and 1 for the moving average and differencing degrees with P taken as {0, 1, 2, 3} respectively. For the SVM model, P is taken from kernel = {Linear, Sigmoid, rbf}, gamma = {scale, auto}, and regularization = {1, 10, 100}, which are Sigmoid, auto, and 1 respectively.
[0108] S7. The anomaly detector distinguishes between benign and malicious samples by detecting the threshold ψ. When the score (mse for ARIMA, ζ for SEL and CR-GAE) is greater than ψ, the malicious sample is assigned the label y = 1; otherwise the sample is considered benign. Using X VAL , it can be found that the ψ values of ARIMA, SEL, and CR-GAE are ψ = 0.42, ψ = 0.53, and ψ = 0.55 respectively.
[0109] S8. Evaluate the detection performance of the anomaly detector through evaluation metrics under general and topology-specific settings. Evaluation Metrics: To quantify the impact of attacks, three performance metrics (detection rate, false alarm rate, and accuracy) are used to report the performance of the anomaly detector, as follows:
[0110] To determine the degree to which the model identifies malicious samples, use the detection rate:
[0111] DR = TP / (TP + FN);
[0112] where TP and FN represent true positive and false negative samples respectively.
[0113] Secondly, to represent the percentage of benign samples misdetected as malicious samples, use the false alarm rate:
[0114] FAR = FP / (FP + TN);
[0115] where FP and TN represent false positive and true negative samples respectively.
[0116] Thirdly, to determine the degree to which the model correctly labels benign and malicious samples, use the accuracy:
[0117] ACC = (TP + TN) / (TP + TN + FP + FN).
[0118] Simulation studies were carried out on 14, 39 and 118 bus systems, and the effects of data poisoning on benchmarks and anomaly detectors in the generalized setting are shown in Tables 1 - 3 as follows:
[0119] Table 1 Effects of data poisoning on various detection methods in the 14 - bus system
[0120]
[0121]
[0122] In the 14 - bus system, for benchmarks without topology knowledge, at data poisoning injection levels of 10%, 20% and 30%, DR will deteriorate by 3.1 - 6.8%, 7.7 - 15.6% and 13.8 - 26.4% respectively; for topology - aware benchmarks, when the injection levels are 10%, 20% and 30% respectively, DR drops by 2.3%, 5.7% and 10.2% respectively; for the anomaly detector of the present invention, at data poisoning injection levels of 10%, 20% and 30%, DR only deteriorates by 0.6%, 1.6% and 3.2%.
[0123] Table 2 Effects of data poisoning on various detection methods in the 39 - bus system
[0124]
[0125]
[0126] In the 39 - bus system, for benchmarks without topology knowledge, at data poisoning injection levels of 10%, 20% and 30%, DR will deteriorate by 2.5 - 5.8%, 6.4 - 13.3% and 11.8 - 22.5% respectively; for topology - aware benchmarks, when the injection levels are 10%, 20% and 30% respectively, DR drops by 2.2%, 5.4% and 9.6% respectively; for the anomaly detector of the present invention, at data poisoning injection levels of 10%, 20% and 30%, DR only deteriorates by 0.5%, 1.4% and 2.6%.
[0127] Table 3 Effects of data poisoning on various detection methods in the 118 - bus system
[0128]
[0129]
[0130] In the 118-bus system, for benchmark tests that are unaware of the topology, at adversarial injection levels of 10%, 20%, and 30%, the DR decreased by 2 - 4.6%, 5.3 - 10.8%, and 9.9% - 18.2% respectively; for topology-aware benchmarks, when the injection levels were 10%, 20%, and 30% respectively, the DR decreased by 1.8%, 4.8%, and 8.9% respectively; for the anomaly detector of the present invention, when the adversarial injection levels were 10%, 20%, and 30%, the DR decreased slightly by 0.3%, 0.8%, and 1.6% respectively.
[0131] Therefore, the present invention adopts the above-mentioned method for identifying false data injection attacks in power grids based on a robust graph autoencoder. The convolutional recurrent graph autoencoder model was trained and tested on various topologies (from 14-, 39-, and 118-bus systems). This model produces stable generalized detection performance, with only a 1.6 - 3.7% reduction in the DR to cope with high levels of data poisoning and invisible false data injection attacks in unobserved topologies.
[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions of the present invention or make equivalent replacements, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for identifying false data injection attacks in power grids based on robust graph autoencoders, characterized in that: The following steps are involved: S1. Provide an anomaly detector based on a generalized graph neural network; The anomaly detector requires only benign datasets for training and employs an autoencoder with Chebyshev graph convolutional recurrent layers and an attention mechanism to capture spatial and temporal correlations in the measured data; S2, using six network attack functions that bypass traditional BDD to generate adversarial data poisoning samples and correctly labeled FDIA malicious samples; the attack functions include random attack, general attack and four replay attacks; S3, using multiple injection levels to inject adversarial data poisoning samples into the training set of anomaly detectors to simulate data poisoning with incorrectly labeled information; S4, injecting correctly labeled FDIA malicious samples into the test sets of supervised and unsupervised anomaly detectors, as well as the training set of supervised anomaly detectors, to simulate correctly labeled FDIA; S5. Build the CR-GAE model through the anomaly detector to ensure that FDIA is correctly labeled; S6. performing a hyperparameter selection process to adopt an optimal set of hyperparameters that provides the best detection performance for XVAL; the best detection performance refers to the highest detection rate and the highest false alarm rate, and the lowest accuracy rate; S7, the anomaly detector distinguishes benign samples from malicious samples by detecting the threshold ψ; S8. Evaluate the detection performance of anomaly detectors by using evaluation metrics in generalized and topology-specific settings; the evaluation metrics include detection rate, false alarm rate, and accuracy.
2. According to claim 1, a method for identifying false data injection attacks in a power grid based on a robust graph autoencoder is characterized in that: Random attack obtains adversarial data poisoning sample X by applying small perturbation value to benign sample s (t,i) is as follows: X s (t,i)=X b (t,i)+α.X b (t,i); Where t represents the timestamp, i represents the bus, α represents the disturbance amplitude randomly applied to a given benign sample to maliciously change the measurement value, and -0.05≤α≤0.05, X b (t,i) represents a benign sample.
3. According to claim 1, a method for identifying false data injection attacks in a power grid based on a robust graph autoencoder is characterized in that: The adversarial data poisoning samples generated using general attacks are as follows: X s (t,i)=X b (t,i)+(-1) β α.γ.Range(X b (t,i)); Among them, β represents a binary random variable, γ represents a uniform random variable between (0,1), and Range(X b (t,i)) represents the timestamp t and the actual measurement range of bus i.
4. The method for identifying false data injection attacks in a power grid based on a robust graph autoencoder according to claim 1, characterized in that: The four types of replay attacks include one-step replay attack, random replay attack, interval replay attack and strategic replay attack.
5. The method for identifying false data injection attacks in power grids based on robust graph autoencoders according to claim 4 is characterized in that: In a one-step replay attack, the data of the previous timestamp (t-1) is repeated to generate X s (t,i) is as follows: X s (t,i)=X b (t-1,i); In a random replay attack, the data with a previous timestamp of 2≤t≤5 is randomly selected and repeated to generate X s (t,i) is as follows: In an interval replay attack, a series of random benign samples are replaced with a random previous time interval [[t n , …], m], the true measured value [[X b (t*n,i),…],X b (t m ,i)], we get: in, represents the starting time point of the historical time interval randomly selected by the attacker, represents the end time point of the historical time interval randomly selected by the attacker; In a strategic replay attack, the benign sample [X b (t n , i),…,X b (t m , i)] is replaced by the previous time interval The true measurement value get: in, The value must be higher / lower than [X b (t n , i),…,X b (t m , i)].
6. The method for identifying false data injection attacks in power grids based on robust graph autoencoders according to claim 1 is characterized in that: The adversarial data poisoning samples in S3 provide manipulated measurements that are mislabeled as benign and are injected at multiple levels, accounting for 10%, 20%, or 30% of the training set.
7. The method for identifying false data injection attacks in a power grid based on a robust graph autoencoder according to claim 1, characterized in that: The CR-GAE model in S5 learns the normal operations of benign samples and marks the abnormal operations of malicious samples according to the deviations of the learned benign patterns.
8. The method for identifying false data injection attacks in power grids based on robust graph autoencoders according to claim 7 is characterized in that: Let E = f Φ (X) and D = gΦ(X) are the graph encoder and decoder respectively, and the cost function of the obtained CR-GAE model is expressed as: Among them, Φ describes the parameters of the model, X TR Represents the training set.
9. The method for identifying false data injection attacks in power grids based on robust graph autoencoders according to claim 1 is characterized in that: The distinguishing method in S7 is: when the score is greater than ψ, the malicious sample is assigned a label y=1; otherwise, the sample is considered to be benign.
10. The method for identifying false data injection attacks in power grids based on robust graph autoencoders according to claim 1, characterized in that: The specific steps of evaluating the anomaly detector in S8 include: The detection rate determines how well the model identifies malicious samples: DR = TP / (TP + FN); Among them, DR represents the detection rate, TP and FN represent true positive and false negative samples, respectively; The false alarm rate is obtained by calculating the percentage of benign samples that are mistakenly detected as malicious samples: FAR = FP / (FP+TN); Among them, FAR represents the false alarm rate, FP and TN represent false positive and true negative samples respectively; Accuracy determines how well the model correctly labels benign and malicious samples: ACC=(TP+TN) / (TP+TN+FP+FN); Among them, ACC represents the accuracy rate.
Citation Information
Patent Citations
Honey point perception enhanced malicious traffic detection method
CN117614742A
Cited By
Black box adversarial false data injection attack modeling method and device for improving robustness of detection model
CN120524483A