arXiv:2601.03495eess.SYcs.AI2026-01被引 1

用轻量模型在微电网中快速识别多种网络攻击

Cyberattack Detection in Virtualized Microgrids Using LightGBM and Knowledge-Distilled Classifiers

  • 用LightGBM和知识蒸馏构建轻量检测模型
  • 多类攻击识别准确率达99.72%,二分类达94.8%
  • 适合边缘设备实时部署,延迟仅54–67毫秒

现代微电网依赖分布式传感与通信接口,易受网络物理攻击威胁运行连续性与设备安全。本文在MATLAB/Simulink中构建完整虚拟微电网,集成异构可再生能源与二次控制层。基于MGLib设计结构化攻击框架,直接向二次控制路径注入扰动信号,模拟突变、正弦、加性、协同隐蔽及拒绝服务等多类攻击。利用虚拟环境生成正常与攻击状态下的标注数据集,训练Light Gradient Boosting Machine(LightGBM)模型实现入侵检测(二分类)与攻击类型区分(多分类)。多分类模型达到99.72%准确率与99.62% F1分数,二分类模型达94.8%准确率与94.3% F1分数。通过知识蒸馏压缩模型,实现更快预测且性能损失小。实时测试显示每1000样本处理延迟约54至67毫秒,证实其适用于基于CPU的微电网控制器边缘部署。结果表明,轻量级机器学习方法可在不依赖复杂深度学习模型的前提下,实现快速、精准、高效的网络攻击检测。主要贡献包括:(1) 基于MATLAB的虚拟微电网系统,(2) 控制层结构化攻击注入,(3) 多类标注数据集构建,(4) 面向实际应用的低成本AI检测模型。

原文摘要 · Abstract (English)

Modern microgrids depend on distributed sensing and communication interfaces, making them increasingly vulnerable to cyber physical disturbances that threaten operational continuity and equipment safety. In this work, a complete virtual microgrid was designed and implemented in MATLAB/Simulink, integrating heterogeneous renewable sources and secondary controller layers. A structured cyberattack framework was developed using MGLib to inject adversarial signals directly into the secondary control pathways. Multiple attack classes were emulated, including ramp, sinusoidal, additive, coordinated stealth, and denial of service behaviors. The virtual environment was used to generate labeled datasets under both normal and attack conditions. The datasets trained Light Gradient Boosting Machine (LightGBM) models to perform two functions: detecting the presence of an intrusion (binary) and distinguishing among attack types (multiclass). The multiclass model attained 99.72% accuracy and a 99.62% F1 score, while the binary model attained 94.8% accuracy and a 94.3% F1 score. A knowledge-distillation step reduced the size of the multiclass model, allowing faster predictions with only a small drop in performance. Real-time tests showed a processing delay of about 54 to 67 ms per 1000 samples, demonstrating suitability for CPU-based edge deployment in microgrid controllers. The results confirm that lightweight machine learning based intrusion detection methods can provide fast, accurate, and efficient cyberattack detection without relying on complex deep learning models. Key contributions include: (1) development of a complete MATLAB-based virtual microgrid, (2) structured attack injection at the control layer, (3) creation of multiclass labeled datasets, and (4) design of low-cost AI models suitable for practical microgrid cybersecurity.

微电网安全轻量模型入侵检测边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。