用上下文学习识别电力系统未知攻击,无需重训即可应对新威胁。
Detecting Zero-Day Attacks in Digital Substations via In-Context Learning
- 利用Transformer的上下文学习能力,从少量样本中快速适应新攻击。
- 在IEC-61850数据集上对零日攻击检测准确率超85%,远超现有方法。
- 适合电力网络安全研究者及智能电网防护系统开发者参考。
近年来电力网络遭受网络攻击的频率逐年上升,新型攻击手法不断出现。本文针对采用IEC-61850通信协议的数字变电站中的新型/零日攻击检测难题提出解决方案。尽管已有大量启发式与机器学习方法用于IEC-61850变电站的攻击检测,但对新型或零日攻击的泛化能力仍面临挑战。本文提出一种基于Transformer架构的上下文学习(ICL)方法,使模型能在不进行显式重训练的情况下,仅通过少量该类攻击样本即可实现有效检测。在IEC-61850数据集上的实验表明,该方法对零日攻击的检测准确率超过85%,而现有最先进基线方法则无法实现有效检测。本工作为构建未来更安全、更具韧性的数字变电站提供了新路径。
原文摘要 · Abstract (English)
The occurrences of cyber attacks on the power grids have been increasing every year, with novel attack techniques emerging every year. In this paper, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and machine learning (ML)-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than $85\%$ detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。