arXiv:2411.10367cs.LGcs.AI2024-11被引 1

用持续对抗强化学习提升智能逆变器虚假数据攻击检测能力

Continual Adversarial Reinforcement Learning (CARL) of False Data Injection detection: forgetting and explainability

  • 通过持续对抗强化学习生成攻击样本并融入训练
  • 发现持续学习会引发灾难性遗忘,联合训练可缓解该问题
  • 提升检测系统可解释性,适合安全防御研究者参考

智能逆变器上的虚假数据注入攻击(FDIAs)随着可再生能源产量增加而日益严重。尽管基于数据的检测方法不断发展,但仍易受强化学习生成的隐蔽且影响大的对抗样本攻击。本文提出持续对抗强化学习(CARL)方法,将此类对抗样本纳入检测模型的训练过程,从而识别检测系统的薄弱环节,实现增量改进中的可解释性。实验表明,持续学习存在灾难性遗忘现象,通过联合训练所有生成的FDIA场景可有效缓解该问题。

原文摘要 · Abstract (English)

False data injection attacks (FDIAs) on smart inverters are a growing concern linked to increased renewable energy production. While data-based FDIA detection methods are also actively developed, we show that they remain vulnerable to impactful and stealthy adversarial examples that can be crafted using Reinforcement Learning (RL). We propose to include such adversarial examples in data-based detection training procedure via a continual adversarial RL (CARL) approach. This way, one can pinpoint the deficiencies of data-based detection, thereby offering explainability during their incremental improvement. We show that a continual learning implementation is subject to catastrophic forgetting, and additionally show that forgetting can be addressed by employing a joint training strategy on all generated FDIA scenarios.

对抗攻击持续学习可解释性智能电网

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。