研究数据投毒攻击对电网优化模型的影响,揭示其脆弱性并提出防御思路。
Impact of Data Poisoning Attacks on Feasibility and Optimality of Neural Power System Optimizers
- 对比三种神经优化方法在数据投毒下的表现,评估其鲁棒性。
- 发现攻击可导致决策不可行或次优,最优解偏差超15%。
- 适合关注电力系统安全与机器学习鲁棒性的研究人员。
随着清洁但波动的能源大规模接入以及极端天气事件频发,电网调度者的决策窗口日益缩短。为应对这一挑战,基于机器学习(ML)的优化代理成为研究热点。然而,学习方法固有的脆弱性阻碍了其实际应用,其中数据投毒攻击是关键威胁——通过扰动训练数据导致错误决策。目前,此类攻击对基于神经网络的电力系统优化器影响尚缺乏系统研究,存在严重安全隐患。本文聚焦于解决直流最优潮流(DC OPF)问题的三种典型方法:基于惩罚项的方法、后修复策略及直接映射方法,评估它们在数据投毒攻击下的可行性和最优性表现。实验表明,攻击可使优化结果偏离最优解超过15%,且导致不可行解比例显著上升。本研究为提升神经电网优化器的抗攻击能力提供了基础依据。
原文摘要 · Abstract (English)
The increased integration of clean yet stochastic energy resources and the growing number of extreme weather events are narrowing the decision-making window of power grid operators. This time constraint is fueling a plethora of research on Machine Learning-, or ML-, based optimization proxies. While finding a fast solution is appealing, the inherent vulnerabilities of the learning-based methods are hindering their adoption. One of these vulnerabilities is data poisoning attacks, which adds perturbations to ML training data, leading to incorrect decisions. The impact of poisoning attacks on learning-based power system optimizers have not been thoroughly studied, which creates a critical vulnerability. In this paper, we examine the impact of data poisoning attacks on ML-based optimization proxies that are used to solve the DC Optimal Power Flow problem. Specifically, we compare the resilience of three different methods-a penalty-based method, a post-repair approach, and a direct mapping approach-against the adverse effects of poisoning attacks. We will use the optimality and feasibility of these proxies as performance metrics. The insights of this work will establish a foundation for enhancing the resilience of neural power system optimizers.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。