arXiv:2601.09287cs.CRcs.LG2026-01被引 2

基于可解释自编码器的智能电网通信异常检测,精准识别攻击且误报极低。

Explainable Autoencoder-Based Anomaly Detection in IEC 61850 GOOSE Networks

  • 分离协议语义与时间特性,用非监督多视角自编码器学习正常行为
  • 在真实数据上实现99%以上攻击检出率,误报率低于总流量5%
  • 结果可解释,适合电力系统安全人员用于追踪攻击根源

IEC 61850通用对象面向变电站事件(GOOSE)协议在数字变电站实时保护与自动化中起关键作用,但其缺乏原生安全机制,易受复杂网络攻击。传统规则与有监督检测方法在类别极度不平衡及标注数据稀缺下,难以发现协议合规和零日攻击。本文提出一种可解释的无监督多视图异常检测框架,显式区分语义完整性和时间可用性。该方法仅使用真实运行中的GOOSE流量训练非对称自编码器,学习序列化协议语义与时间传输动态的独立潜在表示。通过混合重构误差与统计阈值实现异常检测,无需预设攻击类型。特征级重构分析提供内在可解释性,直接关联检测结果与IEC 61850协议特性。框架在真实变电站数据上训练,并在含正常流量及消息抑制、数据篡改、拒绝服务攻击的公开数据集上测试。实验结果表明,攻击检测率超过99%,误报率低于总流量的5%,展现出跨环境强泛化能力,在极端类别不平衡下仍表现良好,且支持可解释的异常归因。

原文摘要 · Abstract (English)

The IEC 61850 Generic Object-Oriented Substation Event (GOOSE) protocol plays a critical role in real-time protection and automation of digital substations, yet its lack of native security mechanisms can expose power systems to sophisticated cyberattacks. Traditional rule-based and supervised intrusion detection techniques struggle to detect protocol-compliant and zero-day attacks under significant class imbalance and limited availability of labeled data. This paper proposes an explainable, unsupervised multi-view anomaly detection framework for IEC 61850 GOOSE networks that explicitly separates semantic integrity and temporal availability. The approach employs asymmetric autoencoders trained only on real operational GOOSE traffic to learn distinct latent representations of sequence-based protocol semantics and timing-related transmission dynamics in normal traffic. Anomaly detection is implemented using reconstruction errors mixed with statistically grounded thresholds, enabling robust detection without specified attack types. Feature-level reconstruction analysis provides intrinsic explainability by directly linking detection outcomes to IEC 61850 protocol characteristics. The proposed framework is evaluated using real substation traffic for training and a public dataset containing normal traffic and message suppression, data manipulation, and denial-of-service attacks for testing. Experimental results show attack detection rates above 99% with false positives remaining below 5% of total traffic, demonstrating strong generalization across environments and effective operation under extreme class imbalance and interpretable anomaly attribution.

异常检测电力系统可解释性自编码器

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。