Distributed cyber-physical intrusion detection using stacking learning for wide-area protection system

被引:6
作者
Lu, Qiuyu [1 ]
Gao, Qize [1 ]
Li, June [1 ]
Xie, Xuanxuan [1 ]
Guo, Wenrui [2 ]
Wang, Jin [3 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
[2] State Grid Econ & Technol Res Inst Co Ltd, Beijing 102209, Peoples R China
[3] Hubei Elect Power Res Inst, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Power wide -area protection; Cyber-physical system security; Intrusion detection; Stealthy and coordinated cyberattacks; Stacking learning; ANOMALY DETECTION; ATTACK DETECTION; SECURITY;
D O I
10.1016/j.comcom.2023.12.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Wide-area protection systems (WAPSs) heavy depends on communication technologies to operate, which leaves space for cyberattacks. A well-designed stealthy and coordinated cyberattacks can disrupt the seamless operation of WAPS by compromising measurement signals, control signals, or both. In this paper, we present a distributed cyber-physical intrusion detection system (DCPIDS) that utilizes the bilateral data from both the cyber side and the physical side to accurately detect cyberattacks on both measurement and control signals in WAPSs. DCPIDS consists of multiple slave agents (SAs) scattered in every area of the power system for regional-area intrusion detection and a master agent (MA) embedded in the system protection center for system status awareness. For the SAs, a hybrid-based intrusion detection method is utilized to conduct regional-area intrusion detection. The proposed method receives the bilateral data to simultaneously detect data integrity attacks on measurement and control signals using three classification models and performs the identification of single and coordinated attacks using a rule-based approach. Further, to train the classification models in the proposed method, a NewStacking-based model training algorithm is adopted. The proposed algorithm combines different selected classifiers that operate on two different feature subsets, which improves the detection accuracy of the models and extends the generalization ability with better robustness. Experimental results reveal that the proposed algorithm has better performance than existing machine learning algorithms and state-of-art works, the proposed method can identify single and coordinated attacks with high accuracy, and our DCPIDS satisfies the real-time requirements for practical online application.
引用
收藏
页码:91 / 102
页数:12
相关论文
共 42 条
[1]   Wide area protection - Technology and infrastructures [J].
Adamiak, MG ;
Apostolov, AP ;
Begovic, MM ;
Heriville, CF ;
Martin, KE ;
Michel, GL ;
Phadke, AG ;
Thorp, JS .
IEEE TRANSACTIONS ON POWER DELIVERY, 2006, 21 (02) :601-609
[2]   Feature Selection-Based Detection of Covert Cyber Deception Assaults in Smart Grid Communications Networks Using Machine Learning [J].
Ahmed, Saeed ;
Lee, Youngdo ;
Hyun, Seung-Ho ;
Koo, Insoo .
IEEE ACCESS, 2018, 6 :27518-27529
[3]   Deep Machine Learning Model-Based Cyber-Attacks Detection in Smart Power Systems [J].
Almalaq, Abdulaziz ;
Albadran, Saleh ;
Mohamed, Mohamed A. .
MATHEMATICS, 2022, 10 (15)
[4]  
Caire Giovanni., 2009, Jade Programming for beginners
[5]   Reliability Evaluation of the Communication Network in Wide-Area Protection [J].
Dai, Zhi-Hui ;
Wang, Zeng-Ping ;
Jiao, Yan-Jun .
IEEE TRANSACTIONS ON POWER DELIVERY, 2011, 26 (04) :2523-2530
[6]   A Hybrid Method for False Data Injection Attack Detection in Smart Grid Based on Variational Mode Decomposition and OS-ELM [J].
Dou, Chunxia ;
Wu, Di ;
Yue, Dong ;
Jin, Bao ;
Xu, Shiyun .
CSEE JOURNAL OF POWER AND ENERGY SYSTEMS, 2022, 8 (06) :1697-1707
[7]   A Novel Back Up Wide Area Protection Technique for Power Transmission Grids Using Phasor Measurement Unit [J].
Eissa, M. M. ;
Masoud, M. Elshahat ;
Elanwar, M. Magdy Mohamed .
IEEE TRANSACTIONS ON POWER DELIVERY, 2010, 25 (01) :270-278
[8]  
F.I.P.A. Fipa, Specifications
[9]  
google, Power systems datasets
[10]   Data Integrity Attack Detection Using Ensemble-Based Learning for Cyber-Physical Power Systems [J].
Goyel, Himanshu ;
Swarup, K. Shanti .
IEEE TRANSACTIONS ON SMART GRID, 2023, 14 (02) :1198-1209