Cyber Threat Detection in Electric Power Grids Using Feature Vectors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electric power grids connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing protection methods like FDIA systems are limited in detecting malicious threats and do not address multiple faults simultaneously.
Innovation Solution
A system that uses heterogeneous data source nodes to generate feature vectors, which are compared to decision boundaries created offline using normal and abnormal data sets, to automatically detect and alert on cyber threats in real-time, enabling accurate and automatic protection against malicious intent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous malicious faults cannot be detected and the system remains vulnerable to cyber-attacks
Solution Approach 1:
The system segments the power grid into multiple zones and creates separate decision boundaries for each zone. Each zone's data source nodes are independently analyzed against their specific decision boundaries, allowing the system to detect multiple simultaneous faults across different zones without mutual interference
Solution Approach 2:
The system transforms raw sensor data into feature vectors that represent the state of data source nodes in a multi-dimensional space. Decision boundaries are established in this feature space rather than in the original sensor space, enabling more effective separation and detection of multiple simultaneous abnormal states that would be difficult to distinguish in the original dimension
2Reliability
If more data source nodes are monitored to improve detection coverage, then system security improves, but system complexity and computational burden increase
Solution Approach 1:
The system extracts only the most relevant features from raw sensor data to create compact feature vectors. By selecting and extracting key characteristics rather than processing all raw data, the system maintains high detection accuracy while reducing computational complexity and making the system more manageable
Solution Approach 2:
The system changes the parameter representation from raw sensor values to normalized feature vectors that highlight abnormal conditions. This parameter transformation simplifies the detection process by converting complex multi-parameter sensor readings into standardized features that can be efficiently compared against decision boundaries
Data Source
AI summary
According to some embodiments, a plurality of heterogeneous data source nodes may each generate a series of current data source node values over time that represent a current operation of an electric power grid. A real-time threat detection computer, coupled to the plurality of heterogeneous data source nodes, may receive the series of current data source node values and generate a set of current feature vectors. The threat detection computer may then access an abnormal state detection model having at least one decision boundary created offline using at least one of normal and abnormal feature vectors. The abnormal state detection model may be executed, and a threat alert signal may be transmitted if appropriate based on the set of current feature vectors and the at least one decision boundary.


