Discover the SciOpen Platform and Achieve Your Research Goals with Ease.
Search articles, authors, keywords, DOl and etc.
With the rapid integration of information and communication technology into power systems, traditional power grids have evolved into highly interconnected cyber-physical power systems (CPPSs), considerably enhancing observability and controllability. However, this integration exposes CPPSs to severe cybersecurity threats, notably false data injection attacks (FDIAs), which maliciously alter measurement data to mislead operational decisions. Among various forms of FDIAs, load redistribution (LR) attacks are particularly stealthy and dangerous, involving the manipulation of load and line measurements without altering the total load, causing severe operational risks and economic damage. Due to their inherent stealthiness and complexity, LR attacks are often ineffectively detected and inaccurately localized by traditional model-based detection methods. Thus, developing efficient and precise data-driven detection and localization methods is necessary to ensure the reliable operation of CPPSs.
This paper proposes an innovative LR attack detection and localization approach based on a convolutional neural network integrated with a convolutional block attention module (CBAM-CNN). A dual-level optimization model is first constructed to simulate realistic attack scenarios considering different attack intensities and resources. The upper-level model represents attacker strategies aimed at maximizing load shedding using limited resources, while the lower-level model simulates dispatcher responses aiming to minimize load loss. Three distinct LR attack types are defined: manipulation of bus and transmission line measurements and interference with substation data uploads. Comprehensive attack scenarios are simulated on a 38-bus CPPS, generating diverse datasets for model training and validation. The CBAM-CNN approach transforms the attack localization problem into a multi-label classification problem. CNN layers initially extract local features from sparse measurement data, exploiting the inherent network topology and neighborhood relationships within power grids. Subsequently, the CBAM considerably enhances the network’s capability by simultaneously performing channel- and spatial-wise attention to focus on crucial features and suppress irrelevant data, effectively reducing false negatives and improving detection accuracy. Extensive simulations conducted with the 38-bus CPPS model demonstrated the superior performance of the proposed CBAM-CNN method.
Compared with existing methods, including multi-class support vector machine, K-nearest neighbors, extreme gradient boosting, and standard CNN classifiers, the CBAM-CNN consistently achieved higher precision, recall, and F1 scores. Specifically, the proposed method achieved an average precision of 91.63%, a recall of 91.02%, and an F1 score of 91.32%, considerably outperforming other classifiers. Furthermore, detailed scenario analyses indicated that the CBAM-CNN maintained robust performance even with varying attack strengths and resource availability, notably excelling in scenarios with moderate attack intensities and resources, effectively balancing sensitivity and specificity. Radar charts demonstrated that the CBAM-CNN notably improved localization precision across challenging nodes and lines frequently targeted in attacks, highlighting its efficacy in managing sparse and complex attack patterns.
This study successfully developed a highly effective LR attack detection and localization framework combining physical system modeling and advanced data-driven neural network techniques. The dual-level planning model provides realistic, purposeful attack datasets, enhancing training quality and generalizability. The innovative use of CBAM integrated into CNN considerably improved the network's ability to identify and localize stealthy LR attacks accurately. This research underscores the necessity of integrating attention mechanisms in neural networks for cybersecurity applications within CPPSs, offering practical insights and a promising methodology for future security enhancement efforts.
Comments on this article