Source-linked AI summary

Subspace Methods for Data Attack on State Estimation: A Data Driven Approach

Jinsub Kim, Lang Tong, Robert J. Thomas

arXiv:1406.0866v1cs.CR

TL;DR

State-estimation attacks traditionally require detailed system information, which may be difficult for an adversary to obtain. This paper learns measurement subspaces from full or partial observations to construct unobservable and data-framing attacks, and reports effective performance on benchmark power networks, including under nonlinear equations.

  • Problem

    Existing state-attack schemes often require network topology and physical parameters that are difficult to access, motivating attacks based on observable measurement information instead.

  • Method

    The paper estimates system measurement subspaces from measurements and uses them to construct unobservable attacks and data-framing attacks under full and partial measurement models.

  • Results

    Subspace-based attacks perform as well as attacks using H on the IEEE 14-bus test, and numerical results show efficiency comparable to attacks based on full system information.

  • Takeaways & Limitations

    Even limited observation of certain sensor measurements can provide enough information to construct state attacks when system information is secure.

Abstract

from arXiv · show

Data attacks on state estimation modify part of system measurements such that the tempered measurements cause incorrect system state estimates. Attack techniques proposed in the literature often require detailed knowledge of system parameters. Such information is difficult to acquire in practice. The subspace methods presented in this paper, on the other hand, learn the system operating subspace from measurements and launch attacks accordingly. Conditions for the existence of an unobservable subspace attack are obtained under the full and partial measurement models. Using the estimated system subspace, two attack strategies are presented. The first strategy aims to affect the system state directly by hiding the attack vector in the system subspace. The second strategy misleads the bad data detection mechanism so that data not under attack are removed. Performance of these attacks are evaluated using the IEEE 14-bus network and the IEEE 118-bus network.

I. INTRODUCTION

State attacks alter sensor data to induce incorrect state estimates while avoiding detection, but existing methods often require system parameters that are difficult to obtain. This paper develops subspace-based attacks from measurements, including direct unobservable attacks and data framing attacks, and evaluates them on nonlinear power-grid models.

  • State attacks modify sensor data to mislead control systems with incorrect state estimates while avoiding detection and identification.
  • Existing attack schemes commonly require network topology and physical system parameters that may be difficult to access in practice.
  • A. Summary of contributions: The proposed approach learns measurement subspace structure from monitored data, avoiding detailed system knowledge and potentially using only partial observations.
  • A. Summary of contributions: The first attack constructs an unobservable attack from the estimated measurement subspace, with partial-measurement feasibility characterized by a graph-theoretic condition.
  • A. Summary of contributions: The second attack frames valid measurements, causing the fusion center to remove non-tempered data while retaining some falsified data and potentially producing arbitrarily large state-estimation error.
  • A. Summary of contributions: Simulations on IEEE 14-bus and 118-bus networks show that subspace-based attacks perform well despite nonlinear system equations, although theoretical guarantees are not provided.

II. MATHEMATICAL MODELS

The paper models CPS measurements, adversarial biases, and centralized nonlinear state estimation, then analyzes a recursive estimator with bad-data detection and removal. Linearization supplies the model used to construct attacks, while experiments validate attacks against the original nonlinear system.

  • CPS state estimation uses sensor measurements related to the state through a generally nonlinear measurement function with Gaussian noise.
  • Adversarial or malfunctioning sensors produce biased measurements represented by a deterministic attack vector whose support is constrained to adversary-controlled sensors.
  • The linearized model uses measurement matrix H, Gaussian noise with covariance σ^2I, and assumes H has full column rank for system observability.
  • C. State estimation and bad data processing: The nonlinear estimator is implemented through iterative linearization, while the attack experiments construct attacks from the linearized model and validate them using the original nonlinear model.
  • C. State estimation and bad data processing: The recursive estimator computes a least-squares state estimate and residual, applies a J(ˆx)-test, and removes the sensor with the largest normalized residual when data are declared bad.

D. Adversary model

The adversary can modify measurements from a sensor subset, and an unobservable attack is one that can be absorbed into an alternative state estimate without detection. Its feasibility is tied to whether removing adversary sensors destroys system observability.

  • D. Adversary model: The adversary modifies measurements only on a designated subset of sensors, producing corrupted measurements through an attack vector.
  • D. Adversary model: An attack is unobservable when a nonzero modification makes the corrupted measurements consistent with a different system state under the same measurement model.
  • D. Adversary model: Scaling a nonzero unobservable attack by any nonzero real factor preserves unobservability and can make the state-estimation error arbitrarily large.
  • D. Adversary model: An unobservable attack exists exactly when removing the adversary sensors makes the grid unobservable, meaning the measurement matrix loses full column rank.

III. SUBSPACE METHODS FOR UNOBSERVABLE ATTACK

The paper constructs unobservable attacks from measurement-subspace information rather than the measurement matrix itself. It also identifies conditions under which partial sensor measurements suffice, including a graph condition for power grids.

  • III. SUBSPACE METHODS FOR UNOBSERVABLE ATTACK: The proposed unobservable-attack design uses the system measurement subspace without requiring knowledge of the measurement matrix H.
  • III. SUBSPACE METHODS FOR UNOBSERVABLE ATTACK: The paper gives conditions for constructing such attacks from subspace information and characterizes partial-measurement feasibility through a graph condition on network topology.

A. Feasibility of an unobservable attack

An unobservable attack exists when the attacker can find a nonzero measurement-subspace vector that is zero on uncompromised sensors. Theorems characterize this condition using basis matrices and extend it to partial measurements and graph-based sensor settings.

  • Full measurement model: An unobservable attack is feasible if and only if the basis submatrix excluding adversary sensors lacks full column rank.When feasible, a nonzero vector in its null space produces the attack vector a = Uv.
  • Full measurement model: Only a basis matrix of the measurement subspace R(H) is necessary to construct the unobservable attack vector.The measurement subspace is the set of all possible noiseless measurements.
  • Partial measurement model: With partial measurements, the attack conditions require observability of the relevant state variables and a critical sensor set whose removal destroys observability.Under these conditions, the corresponding null space has dimension one and yields an unobservable attack.
  • Partial measurement model: For partial measurements, any nonzero vector in the relevant null space defines an attack by adding its corresponding entries to the controlled sensors.The resulting attack is unobservable, and the null space is one-dimensional under the theorem’s conditions.
  • Power-grid conditions: Graph conditions based on topology and sensor locations can replace full system information when identifying feasible partial-measurement attacks.In the IEEE 118-bus example, a cut isolating bus 115 satisfies the stated condition.

C. Subspace attack algorithm

The data-driven subspace attack algorithm estimates the measurement subspace from sampled measurements, extracts a null-space direction with SVD, and scales the resulting attack before modifying adversary sensors.

  • Data-driven design: Subspace methods require only R(H) or R(Ho), enabling attacks to be designed from measurement data rather than detailed system parameters.The paper frames subspace estimation as the basis for practical data-driven attack algorithms.
  • Subspace estimation: Under the model zi = Hxi + ei, the leading singular vectors of the measurement covariance provide a basis for the measurement subspace.The result relies on independent state and noise samples, a positive definite state covariance, and uncorrelated states and noise.
  • Full observations: For full observations, the algorithm estimates U, removes adversary-sensor rows, and uses the smallest-singular-value right vector as a null-space estimate.It then adds the corresponding entries of ηUv to the adversary sensors.
  • Partial observations: For partial observations, the algorithm estimates Uo from samples, removes controlled-sensor rows, and applies SVD before adding ηUov to those sensors.The partial measurements are collected from sensors in So at multiple time instances.

IV. SUBSPACE METHODS FOR DATA FRAMING ATTACK

Data framing attacks manipulate bad-data detection so normally operating sensors are removed, allowing the remaining attack to perturb state estimates even when a direct unobservable attack is unavailable.

  • Attack objective: A data framing attack selects sensors SF disjoint from the attack set SA and frames normally operating meters as bad data.The purpose is to remove those meters from the estimator before the attack takes effect.
  • Attack design: Maximizing the first-iteration normalized-residue energy at SF is a practical heuristic for encouraging those sensors’ removal.The heuristic does not guarantee that every sensor in SF will be identified as bad through all iterations.
  • Attack design: Constraining the attack to R(H1) ensures that, after framed data are removed, the attack has the same effect as an unobservable attack.H1 is formed by replacing SF rows of H with zero rows.
  • Subspace formulation: A basis matrix U of R(H) is sufficient to solve the framing-attack optimization without knowing H.Theorem 4.1 establishes equivalence between the original optimization and a subspace-based QCQP.
  • Detection effect: The attack changes the mean of normalized residues at SF, providing the mechanism used to steer bad-data detection toward those sensors.The resulting residue mean is expressed through the attack vector and the selected sensors.

B. Sufficiency of partial measurements

Partial measurements can support both unobservable and data framing attacks when the observability and critical-set conditions hold. The required attack directions can be obtained from subspaces estimated using only selected sensor observations.

  • Partial framing attacks: For a partition of the critical set into C1 and C2, a one-dimensional null space from partial measurements yields an optimal framing attack on C1 while framing C2.The resulting attack is equivalent to a nonzero scalar multiple of the optimal solution.
  • Partial framing attacks: Knowledge of the measurement subspace from So \ C2 is sufficient to launch the framing attack with attack sensors C1 and framed sensors C2.The same observability conditions required for the partial unobservable attack also apply.
  • Data-driven implementation: The paper combines subspace estimation and SVD to construct data-driven framing attacks from partial or full sensor observations.The full-observation procedure additionally estimates a QCQP basis and solves for an attack direction before scaling it.
  • Data-driven implementation: The full-observation construction uses an estimated intersection basis for R(U1) ∩ A, obtained through a null-space basis after removing SA ∪ SF rows.This basis supplies feasible directions for the QCQP attack design.
  • Data-driven implementation: With partial observations, the algorithm estimates UA from So \ C2, removes C1 rows, and uses the smallest singular-value direction before adding ηUAv to C1.The scaling factor η adjusts the degree of perturbation.

V. NUMERICAL RESULTS

Simulations on IEEE 14-bus and 118-bus networks evaluated data-driven unobservable attacks using full and partial sensor observations. The data-driven attacks matched attacks using full system knowledge, while partial observations were sufficient even in the larger network.

  • Simulation setup: The simulations used nonlinear measurement and state-estimation models for IEEE 14-bus and IEEE 118-bus power networks.Performance was measured by the l2 norm of the mean state estimation error.
  • Simulation setup: Three methods were compared: attacks with full knowledge of H, data-driven attacks with full sensor observations, and data-driven attacks with partial sensor observations.Data-driven methods estimated measurement-subspace bases from 1,000 observations.
  • IEEE 14-bus results: Both data-driven attacks performed as well as attacks using knowledge of H on the IEEE 14-bus network.The comparison used normalized state-estimation error versus relative attack magnitude.
  • IEEE 118-bus results: The IEEE 118-bus results showed almost the same state-estimate perturbation for all three methods.The experiment tested relative attack magnitudes of 2, 4, and 6% with 200 Monte Carlo runs per scenario.
  • IEEE 118-bus results: Only about 2 percent of sensors needed to be observed for launching an unobservable attack on the large network.This result concerns the IEEE 118-bus simulation with partial observations.

C. Data-driven framing attack

Data framing attacks extend the data-driven approach to settings where unobservable attacks are infeasible. Simulations show that partial sensor observations can still support substantial state-estimate perturbation in both tested networks.

  • IEEE 14-bus framing attack: In the IEEE 14-bus setting, the adversary could not launch an unobservable attack under the specified control and framing configuration.The adversary instead controlled some sensors and framed others as sources of bad data.
  • IEEE 14-bus framing attack: Even when an unobservable attack was infeasible, data framing could perturb the state estimate by an arbitrary degree.Partial sensor observations were sufficient for designing the attack.
  • IEEE 118-bus framing attack: The IEEE 118-bus configuration satisfied the graph conditions for launching a data framing attack with partial observations.The adversary controlled selected line-flow sensors and framed others as bad-data sources.
  • IEEE 118-bus framing attack: Partial sensor observations were sufficient for designing a data framing attack in the large IEEE 118-bus network.Figure 7 tested relative attack magnitudes of 0.8, 1.6, and 2.4% with 200 Monte Carlo runs per scenario.
  • Overall implication: The paper concludes that data-driven attacks based on partial observations can be as efficient as attacks using full system information.This conclusion covers the proposed subspace attack methods evaluated in the simulations.

APPENDIX A PROOF OF THEOREM 2.1

The proof characterizes unobservable attack vectors through the null space of the measurement matrix after adversary sensors are removed. It then constructs an attack from a null-space vector and extends the argument to critical sensor sets.

  • Null-space characterization: An unobservable attack is feasible if and only if the reduced measurement matrix H̄ lacks full column rank.Equivalently, the null space N(H̄) must have nonzero dimension.
  • Null-space characterization: Using a basis U for the measurement subspace, unobservable attack feasibility is equivalent to Ū being rank deficient.The columns of Ū span the range of H̄, preserving the relevant rank condition.
  • Attack construction: When an attack is feasible, a nonzero vector v in N(Ū) produces an attack a = Uv supported only on adversary sensors.Because Uv can also be written as H(B^-1v), the resulting vector is an unobservable attack vector.
  • Critical-set construction: For a critical sensor set, the relevant null space has dimension one, so the corresponding attack space is generated by a single vector H_sy_o.Every nonzero attack in that space is a nonzero scalar multiple of this basis vector.
  • Critical-set construction: Adding the corresponding entries of the constructed attack to measurements from the critical set is equivalent to applying αHy, which is unobservable.The equivalence follows from H̄y = 0.

APPENDIX E PROOF OF THEOREM 4.2

The proof links critical-set structure to the dimensionality and solution form of the attack-design problem. It relies on power-system measurement and observability properties, including the linearized relation between measurements and state variables.

  • Critical-set structure: Removing a sensor set C leaves a one-dimensional null space when C contains exactly one critical set.More than one critical set would imply a null space of larger dimension.
  • Critical-set structure: Because SA ∪ SF contains exactly one critical set, the intersection R(H1) ∩ A in the optimization problem has dimension one.This follows by relating that intersection to the null space of the matrix obtained after removing SA ∪ SF.
  • Attack-design solution: The optimization problem therefore has only two feasible points with identical objective values, represented by the direction H1Δx.Here Δx is a nonzero vector in the null space of the reduced matrix H2.
  • Attack-design solution: The assumed theorem conditions imply that the null space of Ū_A is one-dimensional, supporting the stated solution for a* = H1Δx.The solution is defined up to a nonzero scalar α.
  • Observability model: Linearization at the nominal operating point separates real measurement components based on voltage phase angles from imaginary components based on voltage magnitudes.The DC model uses phase angles excluding the reference bus as its state.
  • Observability model: Power-system observability is determined by full column rank of H, while topology and sensor locations can provide an alternative spanning-tree test.The measurement matrix depends on network topology and line impedance.
Loading 1406.0866v1…