Content-Aware Spoofed Sensor Data Detection in Microgrids
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Microgrid control systems are vulnerable to cyber-attacks due to the tight message transmission time constraints imposed by standards like IEC 61850, which make encryption and authentication of real-time SMV messages impractical, allowing for manipulation of digital measurement data.
Innovation Solution
A bi-layer content-aware fake sensor data detection mechanism using an artificial intelligence module to forecast and compare measurement data integrity, with a second layer for collaborative decision-making over a secured private mesh network, employing statistical formulations to verify the accuracy of AI module decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and authentication techniques are applied to SMV messages, then security against cyber-attacks is improved, but processing time exceeds the 4 ms limitation making it impractical
Solution Approach 1:
The security detection function is segmented into two independent layers: Layer 1 uses AI/ML algorithms for initial detection, while Layer 2 uses statistical formulations for verification. This segmentation allows each layer to operate independently with appropriate computational resources, avoiding the need for time-consuming encryption while maintaining security through intelligent detection of spoofed measurements.
Solution Approach 2:
An intermediary detection system is introduced between the sensor measurements and the control decisions. This intermediary layer comprising AI/ML models and statistical verification processes acts as a mediator that detects and filters out spoofed measurements without requiring encryption of the underlying measurement data, thus maintaining real-time performance while enhancing security.
2Measurement precision
If AI/ML algorithms are used for detection, then detection accuracy is improved, but computational complexity and processing requirements increase
Solution Approach 1:
The detection system is segmented into two layers with different computational requirements. Layer 1 employs AI/ML algorithms for initial detection with moderate computational complexity, while Layer 2 uses simpler statistical formulations for verification. This segmentation allows the system to achieve high detection accuracy through the combination of both layers while managing computational complexity by applying simpler methods where appropriate.
Solution Approach 2:
The system applies AI/ML algorithms partially - specifically for the initial detection phase - rather than throughout the entire detection process. By using AI/ML only where most beneficial for accuracy and reserving simpler statistical methods for verification, the system achieves high detection accuracy while avoiding excessive computational complexity in all processing stages.
3Speed
If real-time detection is implemented, then response time is improved, but system reliability under attack conditions deteriorates
Solution Approach 1:
The detection system is divided into two sequential layers that work together to maintain both speed and reliability. Layer 1 provides rapid initial detection using AI/ML algorithms, while Layer 2 provides verification using statistical methods. This segmentation enables the system to respond quickly to potential attacks while maintaining high reliability through the verification step, preventing false positives from compromising system reliability.
Solution Approach 2:
The system implements feedback through the two-layer verification process where Layer 2's statistical verification provides feedback on the accuracy of Layer 1's AI/ML detections. This feedback mechanism allows the system to correct false positives and maintain reliability while preserving real-time response capability through the efficient feedback loop between the two layers.
Data Source
AI summary
Systems and methods for detection of spoofed sensor measurements in a microgrid are provided. A system can include a control agent that is configured to determine whether an isolated or continuing intrusion of measurement data received from the primary sensors has occurred, and transmit forecasted measurement data to the controller rather than suspected corrupt measurement data for a suspected isolated intrusion. The control agent and a clone agent can be configured to communicate and work in parallel to confirm a continuing intrusion is occurring, and the control agent can be further configured to transmit measurement data from the redundant sensors to the controller if a continuing intrusion is confirmed.


