Jul 2026· International Conference on Control, Decision and Information Technologies· pp. 925-930· 0 citations· 19 references
Abstract
With the advent of the digitization of power grid systems, fault and cyber-attack detection have been a challenging problem in the field. Due to stealthy cyber-attacks and their similar effects on the grid’s voltage and frequency, it is increasingly difficult for statistical methods to distinguish between faults and cyber-attacks. While deep learning (DL)–based approaches have shown promise, their high computational requirements and scalability limitations pose significant challenges for large-scale grid systems. To this end, we propose a novel federated learning (FL) approach that decentralizes the detection procedure by enabling clients (or grid zones) to perform fault and cyber-attack detection. We consider the IEEE 9-bus system modeled in SIMULINK. Fault and false data injection (FDI) attacks are injected into the vulnerable bus for the system based on PQ-sensitivity. The results show that the proposed FL algorithm successfully distinguishes faults and cyber-attacks, achieving competitive performance compared to baseline centralized DL approaches while reducing data centralization requirements and improving scalability.
False data injection attacks represent a serious cyber-physical security challenge for modern smart grids because falsified measurements can affect state estimation, energy management, and operational decision-making. While various machine learning-based FDIA detection methods have been investigated in literature, many studies report biased results from leakage-prone experiments without rigorous statistical analysis. In this paper, a framework of leakage-safe and physics-informed machine learning for FDIA detection and operational cyber-resilience of renewable smart grids is proposed. The leakage-safe paired normal/attack dataset was constructed using CAISO-derived IEEE 118-bus simulation scenarios integrated with renewable and EMS-related variables. Metadata fields, including scenario ID, sample type, target label, attack severity, and number of attacked buses, were excluded from the model input feature matrix. The framework combines bus-level measurements, grid statistics, physics residual features, and indicators of renewable and EMS and tests Logistic Regression, Random Forest, Extra Trees, HistGradientBoosting, and XGBoost models. The proposed XGBoost model achieved 93.47% accuracy, 93.35% F1-score, 0.9813 ROC-AUC, and 0.9847 PR-AUC on the leakage-safe grouped test set. The repeated grouped split validation indicated good stability with a mean accuracy of 93.81% ± 0.10%. Holm-corrected McNemar tests indicated statistically significant paired-prediction differences between XGBoost and HistGBM, RF, and ET, while the difference between XGBoost and Logistic Regression was not statistically significant. Ablation study, bootstrap confidence intervals, attack severity analysis, and cyber-resilience index provide additional support for evaluation transparency. The results support the feasibility of leakage-safe machine-learning evaluation for FDIA detection under the simulated renewable smart-grid setting.
Abdulrahman Almazroui, F. Albeladi, R. Almazmomi· Scientific Reports· 0 citations
This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path.
Akila Herath, Chen-Ching Liu, Junho Hong et al.· arXiv.org· 0 citations
Cyber attacks on the power grid combine physical disruptions with compromised data to destabilize cyber-physical systems. We demonstrate that data denial attacks, where adversaries block measurements in a targeted region while triggering a line outage, reduce detection performance by more than 86\%, rendering standard data-driven methods ineffective. We propose AdaptoNet, a modular neural network that adapts to measurement availability through conditional controls. AdaptoNet pairs a frozen foundational module trained on complete data with a trainable adaptive module, conditioned on a binary measurement-availability vector, enabling the model to distinguish between denied and anomalous data without retraining the foundational module. Evaluated across four IEEE test systems (30-, 39-, 57-, and 118-bus) under in-region attacks blocking up to 20% of measurements, AdaptoNet recovers F1 from below 12\% to above 81\%, an approximate sevenfold improvement approaching the 89%-99% baseline with complete measurements.
Anissa Elias, Jennifer Rogers, Hui Lin et al.· 0 citations
Simulations on a steam temperature cascade control system validate the effectiveness of the proposed method, demonstrating 20% faster convergence and a 67% reduction in oscillations compared with a conventional method while maintaining stability and security under hybrid attacks.
Hangli Ren, Yuanyuan Cheng, Hui Shang· ISA transactions· 0 citations
This paper evaluated the proposed framework for AI integrated cyber security (AICSF) for real-time threat detection and mitigation in smart industry environments in an AI-Mode, leveraging a recurrently refined DL architecture for real-time anomaly detection and adversarial learning.
S. Kiran, G. Shankarlingam, N. S. Kumar· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.