arXiv:2607.06632cs.LG2026-07

研究电价预测被恶意篡改如何影响工业需求响应的收益

Does Demand Response Increase Vulnerability to Cyber Attacks by Adversarial Data Modifications?

  • 设计针对电价预测模型的对抗性攻击,模拟篡改数据
  • 攻击使需求响应利润下降,但小幅度扰动仍保留约90%优势
  • 攻击效果取决于扰动方向,需结合调度模型敏感性评估

对抗性攻击是精心构造的数据篡改,旨在破坏预测或决策算法的输出。在电力系统文献中,这类攻击多聚焦于电网层面,如负荷预测与状态估计,也被称为虚假数据注入攻击。然而,对需求侧潜在影响的研究较少。本文分析了被篡改的电价预测如何影响工业级需求响应的决策。通过设计针对电价预测模型的对抗性攻击,并利用扭曲的电价信号求解高耗能生产流程的调度优化问题,研究其在不同工艺灵活性下的脆弱性。结果表明,对抗性攻击会削弱需求响应带来的利润;但当扰动幅度较小时(人类难以察觉),需求响应仍可保持约90%的财务优势。此外,攻击影响不仅取决于扰动大小,更关键的是扰动方向。因此,建议在攻击设计中显式考虑调度优化模型的敏感性,以实现对决策系统在对抗攻击下的更严谨评估。

原文摘要 · Abstract (English)

Adversarial attacks are crafted data manipulations that aim to deteriorate the outcomes of prediction or decision-making algorithms. In the energy systems literature, adversarial attacks have been studied with a focus on problems regarding the electricity grid. Such problems include forecasting and grid state estimation, where adversarial attacks are also known as false data injection attacks. Only few studies have analyzed the potential impact that adversarial attacks have on the demand side. We analyze how manipulated price forecasts impact the decision-making in industrial demand response. To this end, we design adversarial attacks that aim to deteriorate the output of electricity price forecasting models and solve scheduling optimization problems of energy-intensive production processes using the distorted price forecasts. We make use of a generalized process model to investigate the vulnerability to adversarial attacks for a range of production scheduling problems with different levels of process flexibility. We find that adversarial attacks can erode the profits gained from demand response. However, when perturbations are limited in extent (so that they are hard to detect by the human user), demand response preserves about 90\% of its financial advantage compared to steady-state process operation. Further, we find that the impact of adversarial attacks on demand response does not only depend on the magnitude of the perturbations but rather on the orientation of the adversarial perturbations. Therefore, we argue that attack analyses should explicitly incorporate the sensitivities of scheduling optimization models into the attack design to enable more rigorous assessments of decision-making under adversarial attacks.

需求响应对抗攻击电力系统优化安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。