arXiv:2507.22239cs.CRcs.AI2025-07中稿 · Paper被引 3

用大模型生成可解释的电网攻击检测报告,兼顾速度与可信度。

Large Language Model-Based Framework for Explainable Cyberattack Detection in Automatic Generation Control Systems

  • 结合轻量级机器学习与大模型,实现快速攻击检测与自然语言解释。
  • 检测准确率达95.13%,攻击目标识别准确率93%,定位误差仅0.075 pu。
  • 适合电力系统安全人员、决策者使用,提升对AI判断的信任与响应效率。

智能电网的数字化提升了运行效率,但也带来了针对自动发电控制(AGC)系统的虚假数据注入攻击(FDIA)等新型网络安全威胁。尽管机器学习(ML)和深度学习(DL)模型在检测此类攻击方面表现出潜力,但其决策过程不透明,限制了运维人员的信任与实际应用。本文提出一种混合框架,将轻量级机器学习攻击检测与大型语言模型(LLM)生成的自然语言解释相结合。LightGBM等分类器在仅0.004秒推理延迟下实现最高95.13%的攻击检测准确率。检测到攻击后,系统调用GPT-3.5 Turbo、GPT-4 Turbo及GPT-4o mini等大模型生成人类可读解释。在100个测试样本上评估显示,采用20次提示的GPT-4o mini在攻击目标识别中达93%准确率,攻击幅度估计均方绝对误差为0.075 pu,攻击起始时间估计平均绝对误差为2.19秒。结果表明,该框架有效平衡了实时检测与高保真可解释性,满足智能电网安全领域对可操作AI的核心需求。

原文摘要 · Abstract (English)

The increasing digitization of smart grids has improved operational efficiency but also introduced new cybersecurity vulnerabilities, such as False Data Injection Attacks (FDIAs) targeting Automatic Generation Control (AGC) systems. While machine learning (ML) and deep learning (DL) models have shown promise in detecting such attacks, their opaque decision-making limits operator trust and real-world applicability. This paper proposes a hybrid framework that integrates lightweight ML-based attack detection with natural language explanations generated by Large Language Models (LLMs). Classifiers such as LightGBM achieve up to 95.13% attack detection accuracy with only 0.004 s inference latency. Upon detecting a cyberattack, the system invokes LLMs, including GPT-3.5 Turbo, GPT-4 Turbo, and GPT-4o mini, to generate human-readable explanation of the event. Evaluated on 100 test samples, GPT-4o mini with 20-shot prompting achieved 93% accuracy in identifying the attack target, a mean absolute error of 0.075 pu in estimating attack magnitude, and 2.19 seconds mean absolute error (MAE) in estimating attack onset. These results demonstrate that the proposed framework effectively balances real-time detection with interpretable, high-fidelity explanations, addressing a critical need for actionable AI in smart grid cybersecurity.

可解释AI电网安全大模型应用攻击检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。