Source-linked AI summary

Bad Data Injection Attack and Defense in Electricity Market using Game Theory Study

Mohammad Esmalifalak, Ge Shi, Zhu Han, Lingyang Song

arXiv:1210.3252v1cs.CRcs.GTstat.AP

TL;DR

Bad-data attacks on smart-grid measurements can alter state estimates, congestion, and electricity prices, while defending every measurement is infeasible. The paper analyzes selective attacker and defender strategies as a zero-sum game, finding in PJM’s 5-Bus test system that the attacker can change prices in a desired direction.

  • Problem

    Compromised measurements can affect state estimation, congestion, and electricity prices, while attackers and defenders cannot respectively attack or protect all measurements.

  • Method

    The paper evaluates each measurement’s effect and models selective attack and defense choices as a two-person zero-sum game.

  • Results

    In the PJM 5-Bus test system, the computed mixed strategies assign different attack and defense proportions across measurements, and simulations show price manipulation effectiveness.

  • Takeaways & Limitations

    The study indicates that an attacker can change electricity prices in a desired direction under the specified load level.

Abstract

from arXiv · show

Applications of cyber technologies improve the quality of monitoring and decision making in smart grid. These cyber technologies are vulnerable to malicious attacks, and compromising them can have serious technical and economical problems. This paper specifies the effect of compromising each measurement on the price of electricity, so that the attacker is able to change the prices in the desired direction (increasing or decreasing). Attacking and defending all measurements are impossible for the attacker and defender, respectively. This situation is modeled as a zero sum game between the attacker and defender. The game defines the proportion of times that the attacker and defender like to attack and defend different measurements, respectively. From the simulation results based on the PJM 5 Bus test system, we can show the effectiveness and properties of the studied game.

I. INTRODUCTION

Smart-grid cyber technologies support monitoring and decision making but expose electricity systems to bad-data attacks. The paper frames selective measurement attacks and defenses as a zero-sum game affecting electricity prices.

  • Smart grids use bidirectional electricity and information flows to respond efficiently to changing conditions.This contrasts with traditional grids that carry power from a few central generators to many customers.
  • State estimation builds real-time network models and supports observation of operating constraints such as line loadings and bus-voltage magnitudes.Its accuracy can be affected by measurement errors, topology errors, and injected bad data.
  • Cyber-attacks on energy-management technologies can cause technical problems, including blackouts, and can be designed for attackers’ financial benefit.The paper links compromised measurements to changes in electricity costs for consumers.
  • The paper models an attacker’s selective measurement attacks and a defender’s selective protections as a two-person zero-sum strategic game.Neither party can attack or defend all measurements, so strategies focus on influential measurements.
  • Prior research covers undetectable attacks, security technologies, reliable state estimation, defense allocation, and broader smart-grid game-theory applications.The paper distinguishes its focus on mutual attacker–defender interaction from work centered on separate attack or defense scenarios.

IV. ATTACK IN ELECTRICITY MARKET

Power networks require continuous operation and system-wide monitoring, yet faulty or manipulated measurements can alter control-center decisions. This section introduces the electricity-market setting and formulates attacks intended to change prices without being detected.

  • Measurement failures or cyber-attacks can change control-center decisions and cause serious technical or economic problems in power networks.

A. Optimal Power Flow (OPF) and DCOPF

The electricity-market model uses optimal power flow and DC approximations to determine dispatch and locational marginal prices from bids, demand, and network constraints. Loss pricing is ignored in this work.

  • GENCOs and LSEs compete to generate and consume energy, while the control center seeks to maximize social welfare subject to network conditions.
  • Locational marginal price at each bus includes marginal energy, congestion, and loss components.The formulation identifies the associated multipliers and delivery factor.
  • The generic dispatch model uses generation costs, dispatch, demand, generation-shift factors, transmission limits, and generator bounds.
  • The model ignores the loss price to emphasize the paper’s main point.Under the lossless optimization model, the delivery factor is 1 and the loss component is 0.
  • The control center runs a DCOPF program using submitted bids and predicted network conditions to determine generator dispatch and bus-level LMPs.

1) Day-Ahead Market:

The day-ahead market uses predicted network conditions and historical-load-based forecasts to schedule generation and establish market prices. These outputs support the real-time market’s measurement, estimation, and dispatch sequence.

  • The next day’s load level can be predicted from historical load data from previous years.
  • Electricity markets including PJM Interconnection, New York, and New England use the locational marginal pricing method.
  • The control center gathers physical-layer measurements, estimates network states, and runs incremental dispatch using those estimates.The resulting LMPs are treated as real-time electricity prices.
  • Real-time dispatch constrains changes in generator output and dispatchable-load consumption within specified upper and lower bands.
  • Changes in transmitted power on congested lines must be non-positive under the second dispatch constraint.

LMP RT

The paper describes how measurement manipulation can alter state estimation, congestion, and real-time electricity prices, while stealth constraints limit the attack.

  • LMP RT: Real-time market operations use state-estimator outputs based on measurements transmitted through communication channels vulnerable to cyber attack.The state estimator supports online network-state monitoring, while communication channels such as power-line communication increase exposure to attacks.
  • LMP RT: Attackers seek financial benefit by changing measurement values without detection, thereby affecting state-estimation and real-time-market results.The paper links manipulated congestion with changed electricity prices and identifies undetected false-data injection as the attacker’s main goal.
  • LMP RT: Measurements are divided into groups according to whether positive injected data increase or decrease estimated transmitted power flow.Groups M and N contain measurements whose increases respectively raise or lower the estimated flow in the targeted line.
  • LMP RT: An attacker can compromise power-flow measurements through RTUs, communication networks, or SCADA infrastructure, while knowledge of H and attack locations supports measurement grouping.The paper assumes the attacker knows the state-estimation Jacobian matrix H and can distinguish groups M and N.
  • LMP RT: The attack optimization maximizes desired measurement changes subject to stealth, protected-measurement, and attack-location constraints.The bad-data detector constraint is ∥(I − HM)za∥ ≤ ξ; smaller ξ improves likely undetectability but limits state-estimation manipulation.

1) Decreasing The Congestion:

The decreasing-congestion strategy uses transmission-price differences and Financial Transmission Rights to obtain a trading profit.

  • 1) Decreasing The Congestion:: The attacker buys at a lower day-ahead-market price and sells at a higher price.The described trade uses differences between day-ahead and real-time congestion-related prices.
  • 1) Decreasing The Congestion:: Decreasing congestion lowers the congestion payment in the real-time market relative to the day-ahead expectation, creating profit per $/MWh.The paper states that the congestion price paid by the attacker is less in real time because congestion decreases.
  • 1) Decreasing The Congestion:: Increasing power from bus i to bus j can congest line Lij and change prices at the receiving and sending ends.The attacker uses an FTR from sending bus i to receiving bus j to hedge congestion charges.

2) Increasing the congestion:

The paper frames congestion manipulation as a constrained contest: the attacker selects measurements to attack, while the defender selects measurements to protect.

  • 2) Increasing the congestion:: Because the attacker lacks complete market information, changing estimated transmitted power increases the chance of creating or releasing congestion in a targeted line.The paper notes that the attacker may not know submitted prices or generation limits.
  • 2) Increasing the congestion:: Creating congestion can allow an FTR to be sold at a higher price to Load Serving Entities in the real-time market.The FTR is associated with a specific transmission line, time, location, and transmitted power value.
  • 2) Increasing the congestion:: The resulting mathematical model addresses where the attacker should attack and where the defender should defend under limited action capacity.The paper presents this formulation as an answer to the strategic measurement-selection problem.
  • 2) Increasing the congestion:: Defending line L requires protecting both measurement groups M and N, but defending every measurement is impossible.The inserted attack is designed to pass the state estimator’s bad-data detector, motivating additional detection methods and secure measurements.
  • 2) Increasing the congestion:: The attacker and defender compete to increase and decrease the change in estimated transmitted power ΔP̂ij, respectively.The game is defined with the defender and attacker as the two players.
  • 2) Increasing the congestion:: The attacker chooses measurements to attack, with strategy sets determined by the maximum numbers of measurements each player can attack or defend.The strategy sets enumerate combinations of available measurements.
  • 2) Increasing the congestion:: The attacker’s utility is ΔP̂ij, whereas the defender’s utility is −ΔP̂ij.The opposing utilities encode the zero-sum structure of the measurement-selection game.

B. Noncooperative Finite Games: Two–Person Zero–Sum

The paper models attacker–defender interaction as a finite two-person zero-sum matrix game, using mixed strategies when pure-strategy saddle points are unavailable.

  • B. Noncooperative Finite Games: Two–Person Zero–Sum: A strategic game models simultaneous decision-making in which each player chooses a plan of action once and for all.This provides the general decision-making framework for the subsequent matrix-game formulation.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: The paper combines multiple attackers into one party to represent the worst case for the defender.Noncooperative attackers are described as having worse performance, while cooperative attackers create the defender’s worst case.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: A pure-strategy saddle point consists of a row and column strategy satisfying the saddle-point inequalities for all strategies.Its corresponding matrix entry is the saddle-point value.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: When a pure saddle point is unavailable, mixed strategies assign probability distributions to the players’ pure strategies.The frequencies of selecting rows and columns converge to the respective probability distributions.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: The vectors y and w represent the defender’s and attacker’s probability distributions over their strategy sets.The paper writes y = (y1, · · ·, ym)′ and w = (w1, · · ·, wn)′.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: The defender minimizes the game quantity by selecting y, while the attacker maximizes it by selecting w.The two players optimize the same quantity in opposite directions.
  • B. Noncooperative Finite Games: Two–Person Zero–Sum: Mixed strategies guarantee a saddle-point solution for two-person zero-sum matrix games.The paper identifies this solution as the unique game value in mixed strategies.

C. Computation of A Two-Person Zero-Sum Game

The paper converts the two-person zero-sum game into linear programming problems to obtain mixed security strategies for the defender and attacker.

  • Mixed strategies are used when the matrix game lacks a saddle point in pure strategies.The mixed-strategy game value is formulated for a payoff matrix with positive entries.
  • The computation relies on the game’s payoff matrix, whose entries represent outcomes associated with attacker and defender strategies.The supplied material also identifies the line reactance and thermal-limit data for the 5-bus test system.
  • The defender’s mixed security strategy is obtained by normalizing an LP solution based on v1(y).The transformed variable ˜y is defined as y/v1(y), yielding a standard maximization LP.
  • A corresponding standard LP problem is formulated for the attacker using the transformed variable ˜w.The attacker’s transformed variable is defined as w/v2(w).

VI. NUMERICAL RESULTS

Numerical results apply the attack-defense game to the PJM 5-bus system, identifying measurement strategies and illustrating how a successful attack changes line flow and real-time prices.

  • The PJM 5-bus numerical study uses line parameters, generation shift factors, measurement locations, and attacker-defender strategy sets.The attacker selects measurements affecting estimated flow on the congested L54 line, while the defender protects measurements.
  • The attacker and defender’s payoffs form a normal-form zero-sum game because neither player knows the other’s action or the sequence of play.The payoff difference is represented as ΔP̂54 = U1 = −U2.
  • The game has no single saddle point, so the players’ strategy proportions are obtained through linear programming.The reported condition is min(max column) = 0, with no ai*j* satisfying the saddle-point condition.
  • The computed defender strategy is y = [0 0.094 0.26 0.262 0.0347 0.35], while the attacker strategy is w = [0.556 0 0.038 0.036 0.037 0.333].These are normalized mixed-strategy proportions derived from the corresponding transformed LP solutions.
  • The strategy proportions identify how frequently the defender should defend and the attacker should attack different measurements.Figure 4 reports these proportions for the measurement set.
  • 236.59 MW is the attacked estimate for transmitted power on L54, below its thermal limit and indicating released congestion.The example assumes unchanged actual load and attributes estimated-load changes to bad-data injection.

VII. CONCLUSION

The paper analyzes how compromising individual measurements affects state estimation, congestion, and electricity prices, then models attacker–defender choices as a game. PJM 5-Bus simulations show that prices can be changed in a desired direction.

  • Compromising individual measurements can change state-estimator results, congestion, and consequently electricity prices.
  • Because attacking or defending all measurements is impossible, the paper models these choices using game theory.
  • Figure 5 reports changes in estimated transmitted power on lines following attacks on Z1 and Z4.
  • The PJM 5-Bus simulation indicates that an attacker can change prices in a desired direction at the specified load level.
Loading 1210.3252v1…