arXiv:2506.19302cs.LG2025-06被引 14

攻击者可骗过电网故障检测模型,让恶意数据伪装成正常故障。

Adversarial Attacks on Deep Learning-Based False Data Injection Detection in Differential Relays

  • 用快速梯度法生成微小干扰,欺骗深度学习检测模型。
  • 部分模型被攻破成功率超99.7%,且触发保护动作。
  • 对抗训练能有效提升模型抗攻击能力,适合电网安全研究者。

深度学习方案(DLS)在智能电网中用于检测虚假数据注入攻击(FDIAs)已受到广泛关注。本文表明,精心设计的对抗攻击可规避用于线路电流差动继电器(LCDRs)FDIA检测的现有DLS。我们提出一种新型对抗攻击框架,利用快速梯度符号法,对LCDR远端测量引入微小扰动,导致FDIA被误判为合法故障,同时触发继电器跳闸。我们在多种深度学习模型上评估了鲁棒性,包括多层感知机、卷积神经网络、长短期记忆网络和残差网络。实验结果表明,尽管这些模型表现良好,但对对抗攻击高度脆弱,部分模型的攻击成功率超过99.7%。为应对该威胁,我们引入对抗训练作为主动防御机制,显著提升了模型抵御对抗性FDIA的能力,且不影响故障检测精度。结果强调了对抗攻击对基于DLS的FDIA检测构成的重大威胁,凸显了智能电网中强化网络安全的必要性,并证明了对抗训练在提升模型鲁棒性方面的有效性。

原文摘要 · Abstract (English)

The application of Deep Learning-based Schemes (DLSs) for detecting False Data Injection Attacks (FDIAs) in smart grids has attracted significant attention. This paper demonstrates that adversarial attacks, carefully crafted FDIAs, can evade existing DLSs used for FDIA detection in Line Current Differential Relays (LCDRs). We propose a novel adversarial attack framework, utilizing the Fast Gradient Sign Method, which exploits DLS vulnerabilities by introducing small perturbations to LCDR remote measurements, leading to misclassification of the FDIA as a legitimate fault while also triggering the LCDR to trip. We evaluate the robustness of multiple deep learning models, including multi-layer perceptrons, convolutional neural networks, long short-term memory networks, and residual networks, under adversarial conditions. Our experimental results demonstrate that while these models perform well, they exhibit high degrees of vulnerability to adversarial attacks. For some models, the adversarial attack success rate exceeds 99.7%. To address this threat, we introduce adversarial training as a proactive defense mechanism, significantly enhancing the models' ability to withstand adversarial FDIAs without compromising fault detection accuracy. Our results highlight the significant threat posed by adversarial attacks to DLS-based FDIA detection, underscore the necessity for robust cybersecurity measures in smart grids, and demonstrate the effectiveness of adversarial training in enhancing model robustness against adversarial FDIAs.

对抗攻击电力系统深度学习安全差动保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。