This invention relates to the field of
power grid information security technology, specifically a method,
system, device, and storage medium for detecting malicious
software in the
power grid Internet of Things (IoT) based on active learning. The method involves acquiring application samples from
power grid IoT nodes, extracting static features, dynamic features, and power grid context information to form a multi-dimensional
feature vector, and organizing these into data blocks according to timestamps. Classification uncertainty scores are calculated from an unlabeled
sample pool, a
detector committee is constructed to calculate
consensus entropy, and the sample with the most information content is selected by combining the two scores and submitted for expert
annotation. A
random forest classifier is trained to build a detection model. The F1
score of the current data block is evaluated;
annotation stops when a preset threshold is reached and is applied to the next data block. Model performance changes are monitored, and when performance degradation is detected, batch retraining, rolling back historical configurations, or incremental updates are performed based on the evolution of the
threat environment. The method reduces
annotation costs through
sample selection and addresses the conceptual drift problem of the power grid
threat environment through an adaptive update strategy.