通过融合时空图特征,实现对智能电网窃听攻击的高精度低误报检测。
Federated Spatiotemporal Graph Learning for Passive Attack Detection in Smart Grids
- 基于星型子图和短时窗,融合物理层与行为指标构建多模态检测器。
- 测试准确率达98.32%(每时间步),序列级准确率93.35%,误报率仅0.15%。
- 适用于非独立同分布的联邦学习场景,保护数据隐私且无需上传原始数据。
智能电网面临被动窃听威胁,攻击者静默监听通信链路,虽不篡改数据,但可获取电网拓扑、用电模式与运行行为,为后续针对性攻击铺路。由于此类信号微弱、短暂,单节点或单一时间轴难以察觉。本文提出一种以图为中心的多模态检测方法,在星型子图与短时窗内融合物理层与行为指标,实现主动识别。采用双阶段编码器:图卷积聚合空间上下文,双向GRU建模短期时序依赖,将异构特征统一为时空表示用于分类。训练在联邦学习框架下使用FedProx进行,增强对异构本地数据的鲁棒性,原始测量数据保留在客户端。构建了符合标准的合成数据集,模拟HAN/NAN/WAN通信中无线被动扰动、事件共现及安全划分。模型在简单决策规则(运行长度m=2,阈值τ=0.55)下,达到每时间步98.32%准确率(攻击类F1=0.972),序列级93.35%准确率,误报率0.15%。结果表明,结合时空上下文可有效检测隐蔽侦察,维持低误报率,适用于非独立同分布的联邦智能电网部署。
原文摘要 · Abstract (English)
Smart grids are exposed to passive eavesdropping, where attackers listen silently to communication links. Although no data is actively altered, such reconnaissance can reveal grid topology, consumption patterns, and operational behavior, creating a gateway to more severe targeted attacks. Detecting this threat is difficult because the signals it produces are faint, short-lived, and often disappear when traffic is examined by a single node or along a single timeline. This paper introduces a graph-centric, multimodal detector that fuses physical-layer and behavioral indicators over ego-centric star subgraphs and short temporal windows to detect passive attacks. To capture stealthy perturbations, a two-stage encoder is introduced: graph convolution aggregates spatial context across ego-centric star subgraphs, while a bidirectional GRU models short-term temporal dependencies. The encoder transforms heterogeneous features into a unified spatio-temporal representation suitable for classification. Training occurs in a federated learning setup under FedProx, improving robustness to heterogeneous local raw data and contributing to the trustworthiness of decentralized training; raw measurements remain on client devices. A synthetic, standards-informed dataset is generated to emulate heterogeneous HAN/NAN/WAN communications with wireless-only passive perturbations, event co-occurrence, and leak-safe splits. The model achieves a testing accuracy of 98.32% per-timestep (F1_{attack}=0.972) and 93.35% per-sequence at 0.15% FPR using a simple decision rule with run-length m=2 and threshold $τ=0.55$. The results demonstrate that combining spatial and temporal context enables reliable detection of stealthy reconnaissance while maintaining low false-positive rates, making the approach suitable for non-IID federated smart-grid deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。