Source-linked AI summary

Vulnerability Analysis and Consequences of False Data Injection Attack on Power System State Estimation

Jingwen Liang, Lalitha Sankar, Oliver Kosut

arXiv:1506.03774v1eess.SYcs.CR

TL;DR

The physical consequences of cyberattacks on electric power systems, particularly unobservable FDI attacks on AC state estimation, remain less understood. The paper formulates and tests constrained worst-case attacks, finding that transmission-line overloads can occur with mild load shifts, especially in congested systems.

  • Problem

    The physical consequences of cyberattacks on electric power systems, including FDI attacks on state estimation, remain less understood despite their potential seriousness.

  • Method

    The paper combines local AC state estimation with a bi-level optimization that maximizes line flow under attack-resource, load-shift, and power-flow constraints.

  • Results

    Attacks tested on the IEEE-RTS-24-bus system overloaded transmission lines despite mild load shifts, with congested systems more vulnerable than non-congested systems.

  • Takeaways & Limitations

    Unobservable FDI attacks can produce physical line overloads while avoiding significant observed load shifts at the control center.

Abstract

from arXiv · show

An unobservable false data injection (FDI) attack on AC state estimation (SE) is introduced and its consequences on the physical system are studied. With a focus on understanding the physical consequences of FDI attacks, a bi-level optimization problem is introduced whose objective is to maximize the physical line flows subsequent to an FDI attack on DC SE. The maximization is subject to constraints on both attacker resources (size of attack) and attack detection (limiting load shifts) as well as those required by DC optimal power flow (OPF) following SE. The resulting attacks are tested on a more realistic non-linear system model using AC state estimation and ACOPF, and it is shown that, with an appropriately chosen sub-network, the attacker can overload transmission lines with moderate shifts of load.

I. INTRODUCTION … II. PROBLEM FORMULATION: SYSTEM AND ATTACK MODEL

The paper examines the physical consequences of cyber attacks on increasingly integrated electric power systems, focusing on unobservable FDI attacks on AC state estimation. It develops an attack-consequence framework that combines restricted attack resources, detection constraints, and system response.

  • I. INTRODUCTION: Increasing integration of monitoring, sensing, control, and communication improves power-system controllability but increases vulnerability to cyber attacks with potentially serious physical consequences.The paper motivates assessing possible attacks and consequences before attacks occur to support utility preparation.
  • I. INTRODUCTION: The paper focuses on the less-understood consequences of cyber attacks on electric power systems, especially attacks involving system states, topology, generator dynamics, and energy markets.It introduces a class of false data injection attacks on AC state estimation to study these consequences.
  • A. Contributions: The first contribution is a sophisticated unobservable AC state-estimation attack that accounts for sequential data processing in the power system’s cyber layer.The attack assumes access to measurements in a small sub-network and seeks significant physical-network changes if it remains undetected.
  • A. Contributions: Enabling physical consequences requires changing measurements to cause redispatch and subsequent changes in the physical network.The attacker is modeled as having access to measurements in a small sub-network and intending potentially damaging consequences.
  • B. State of the Art: Prior work established that judiciously chosen FDI vectors can alter estimated system states without triggering state-estimation bad-data detection, while balancing estimation error against detection probability.This literature includes unobservable attacks on DC state estimation and attacks restricted to sub-networks or subgraphs.
  • B. State of the Art: The paper extends prior AC subgraph attacks to study consequences by determining an optimal attack through a bi-level optimization problem that includes the attacker’s objective and ensuing optimal-power-flow response.Earlier bi-level formulations primarily sought to increase system operating costs.
  • B. State of the Art: The formulation restricts both load-shift magnitude and attack-subgraph size to model detection limits alongside attacker observability and limited-resource constraints.This extends prior work that constrained load shifts because FDI attacks induce inevitable load shifts within the subgraph.
  • II. PROBLEM FORMULATION: SYSTEM AND ATTACK MODEL: The paper proceeds from system and attack modeling to unobservable-attack strategies, worst-case overflow-attack optimization, numerical analysis, and conclusions with future-work directions.These topics are presented sequentially in Sections II through VI.

A. Temporal nature processing of the grid · B. Measurements · C. State estimation

The grid-processing cycle uses SCADA measurements to support generation-dispatch decisions for the next interval, while AC measurement and state-estimation procedures model noisy system observations and assess observability. Measurements that pass bad-data detection can influence subsequent control decisions.

  • A. Temporal nature processing of the grid: The grid model includes nb buses, nbr branches, and ng generators, with active and reactive loads represented by PL and QL.Measurements and estimated measurement residues are denoted z and r, respectively.
  • A. Temporal nature processing of the grid: At each time interval, SCADA measurements inform generation-dispatch control decisions for the next interval.The same processing occurs for each time t, so temporal dependence is omitted thereafter.
  • A. Temporal nature processing of the grid: An attacker can corrupt measurements that pass the bad-data detector and directly influence subsequent control decisions.The detector uses a residue threshold τ; the system state is x = [V, θ]^T.
  • B. Measurements: The AC measurement model follows a non-linear relationship between measurement, error, and system-state vectors.The vectors z, e, and x have dimensions m × 1, m × 1, and n × 1, respectively.
  • B. Measurements: Measurements include line power flows, bus voltage, and line current magnitude, while measurement errors are assumed independent and Gaussian with 0 mean and σ2.Each measurement zi and error ei corresponds to indexed entries of the measurement and error vectors.
  • C. State estimation: All raw measurements first undergo an observability check; insufficient measurements cause the system to be divided into several observable islands.With enough measurements, the system is observable.
  • C. State estimation: AC state estimation determines the most likely system state from noisy measurements by solving a least square problem.The estimated state is represented as x̂ = [V̂, θ̂]^T.
  • C. State estimation: After state estimation, a bad-data detector filters noisy measurements and guarantees estimation accuracy using χ2.The detector operates subsequent to state estimation.

D. AC and DC optimal power flow

ACOPF is formulated as a generation-cost optimization over voltage, angle, and generator active/reactive powers, with nonlinear thermal-limit and power-balance constraints. DCOPF linearizes these constraints around V = 1 and θ = 0 and uses dependency matrices and operating limits.

  • ACOPF formulation: ACOPF minimizes generation cost over x = [V, θ, PG, QG]T.The optimization variables include voltage, voltage angle, and generator active and reactive powers.
  • ACOPF formulation: ACOPF imposes nonlinear line thermal-limit inequalities F and node power-balance equalities G.Both constraints are nonlinear because they involve active and reactive power.
  • DCOPF approximation: DCOPF approximates G and F around V = 1, θ = 0 using their first-order Taylor expansions.This provides a linearized representation of the ACOPF constraints around the specified operating point.
  • DCOPF parameters: H1 maps power injections to state θ, while H2 maps branch power flows to state θ; P max is the thermal limit and PG limits bound generator capacity.The generator lower and upper limits are denoted P min G and P max G, respectively.

E. Attack model · III. ATTACK STRATEGY · A. Unobservable attack

The attack model assumes an attacker can access and alter all measurements in a bounded area, while unobservability requires the attacked measurements to be consistent with a nonzero state shift. The resulting attack subgraph is constructed around target load buses and bounded by buses whose states remain unchanged.

  • E. Attack model: The attacker is assumed to know all measurements and topology in a small bus-bounded area S, alter or replace its measurements, and possess computational capability.The measurement and state index sets in S are denoted I_S and K_S.
  • E. Attack model: Each attacked measurement z_i is changed from its pre-attack model h_i(x) + e_i to an attacker-chosen value.The passages specify the general replacement model and state that the altered measurement is selected by the attacker.
  • A. Unobservable attack: An attack is unobservable when, without measurement noise, a nonzero state shift c makes every attacked measurement satisfy z_i^(a) = h_i(x + c).The definition requires c ≠ 0 and consistency across all measurements.
  • A. Unobservable attack: If a state x_k is needed to compute any measurement outside S, unobservability requires the corresponding attack-vector entry c_k to equal zero.Thus, external measurements constrain which states inside the attack region can change.
  • A. Unobservable attack: Not all bus states inside an attack region S can change; its boundary must contain buses with unchanged states but changed measurements.The method distinguishes load buses from non-load buses using K_load, the indices of load buses, and permits attacks on either bus type.
  • A. Unobservable attack: The attack-subgraph procedure starts at a target load bus, expands through connected buses and branches, and continues across boundary non-load buses until bounded by load buses or no further expansion is possible.The resulting subgraph includes the target load bus and is bounded by load buses.
  • A. Unobservable attack: The selected attack subgraph produces estimated-load changes at every load bus within S while causing no net load change in the system.This condition is stated as a consequence of the attack-subgraph choice.

B. DC attack

The DC attack simplifies attack construction by using the system Jacobian to create an unobservable vector. However, because it omits reactive power flow, it is detectable by AC state estimation when the attack parameter is too large.

  • Attack construction: Knowing the system Jacobian H, an attacker can construct an unobservable DC attack vector a = Hc.The DC formulation is introduced because the corresponding nonlinear problem is generally hard to solve.
  • Attack construction: The DC formulation distinguishes active-power measurement indices IP, their intersection with IS as ISP, and the ith Jacobian row H(i,:).
  • AC-estimation limitation: A DC attack is not unobservable to an AC state estimator because it ignores reactive power flow.
  • AC-estimation limitation: When c is too large, the DC attack is detected by the AC state estimator.

C. AC attack

The AC attack requires reconstructing false measurements without access to all state values in the measurement functions. The attacker instead builds the attack through load-bus selection, local AC state estimation, nodal-balance equations, and iterative state computation.

  • AC attack: Unlike a DC attack, the attacker cannot precisely construct z(a) because all state values appearing in h_i(.) are unavailable.The missing state information motivates the alternative construction procedure.
  • AC attack: The attacker selects nonzero c entries only at load buses, chooses S using the Sec. III-A protocol, and performs local AC state estimation using measurements available in S.The selected load buses define the attack subgraph’s center buses.
  • AC attack: For load buses k, the attacker sets x^(a)_k = x̂^(a)_k + c_k, with the slack bus chosen arbitrarily among load buses.This assigns attacked states at the load buses after local estimation.
  • AC attack: Because non-load-bus injections cannot change, the attacker computes their states from nodal-balance equations involving connected buses and the complex bus admittance matrix.The equations use G_ki + jB_ki and angle differences θ_ki = θ_k − θ_i.
  • AC attack: The resulting equations can be solved iteratively, such as with Newton-Raphson, enabling computation of false measurements z(a) from the complete state information.This completes the attack-measurement construction after the states are computed.

IV. OPTIMIZATION PROBLEM FOR THE WORST-CASE LINE OVERLOAD ATTACK

The section formulates worst-case unobservable line-overload attacks as a bi-level optimization that maximizes target-line flow while minimizing attack sparsity under attacker and operational constraints. The embedded convex DCOPF is replaced by KKT conditions, enabling a mixed-integer linear formulation.

  • Optimization formulation: The attacker maximizes physical power flow on a chosen branch while changing as few states as possible in a bi-level optimization problem.The formulation captures limited attacker resources and the desire to avoid detection.
  • Optimization formulation: The objective balances target-line flow and attack sparsity as Pl − γ ∥c∥0.The l0-norm counts altered quantities only over load buses, while γ weights the attack-vector norm.
  • Constraints: The constraints enforce attack unobservability, allow alterations to up to N0 states, and limit the resulting load shift to LSPL.The embedded second-level problem is a standard DCOPF with a thermal-limit relaxation penalty to ensure convergence.
  • Constraint relaxation: Because the modified l0-norm constraint is complex and generally non-convex, it is relaxed to a corresponding l1-norm constraint.The relaxation introduces the non-negative parameter N1.
  • KKT reformulation: The convex embedded DCOPF is replaced by its KKT optimality conditions with zero duality gap, including complementary slackness and partial-gradient conditions.Complementary slackness is subsequently represented using binary variables and a sufficiently large constant, yielding a mixed-integer linear program.

V. SIMULATION RESULTS

The simulation applies the Sec. IV optimization to the IEEE RTS-24-bus system, then tests the resulting attack vector in a nonlinear AC state-estimation and ACOPF model.

  • V. SIMULATION RESULTS: The IEEE RTS-24-bus system is used to compute an optimal attack vector c, which is then simulated as the AC attack in (15).AC power flow, AC state estimation, and ACOPF use MATPOWER in MATLAB, while CPLEX solves the optimization problem.

A. Solution for the optimization problem

The optimization is evaluated on non-congested and congested RTS-24-bus systems, with congestion modeled by reducing all branch ratings by 50%. Relaxing the load-shift constraint increases maximum target-branch flow and attack success, while reducing the required attack sparsity.

  • Scenario comparison: The study compares original-rating, non-congested conditions with reduced-rating, congested conditions in the RTS-24-bus system.The reduced-rating scenario represents a congested system, whereas the original-rating scenario has no prior congestion.
  • Attack criteria: Feasible attacks change target-branch flow by more than 1%, while successful attacks overload the target branch after the attack.The threshold γ is chosen as 1% of the target branch’s original power-flow value.
  • Scenario comparison: 50% lower branch ratings define the congested system, and the figures summarize 38 omnipotent-attacker scenarios for each system.The omnipotent attacker controls all measurements and may modify any number of them.
  • Load-shift constraint: As the LS constraint relaxes, maximum power flow increases in both systems, while average l0-norm decreases because fewer bus states must be changed.In the congested system, maximum flow plateaus after LS > 50% because generator location and capacity limit further increases on branch 10.
  • Attack success: The congested system is more vulnerable: successful attacks are absent in the non-congested case but increase with LS constraint in the congested case.The increased vulnerability follows from reduced transmission capacity and the resulting greater susceptibility to overload.

B. Attack consequences for a non-linear model

The AC attack is simulated under a complete-measurement setup with unchanged physical load and reduced branch ratings. Sustained false-data injection overloads the targeted branch and can also overload untargeted congested branches until the system configuration changes.

  • Attack consequences: If false data injection continues, the attack and resulting branch overload persist until the system configuration changes.The persistence describes the attack as sustained rather than momentary.
  • Simulation setup: 186 measurements are used, with zero-mean error of variance 10^-4, unchanged physical load, and branch ratings decreased by 50%.The setup measures active and reactive flows at both branch ends and active and reactive injections at each load bus.
  • Attack consequences: 145 MVA ratings are used for branches whose limits are relaxed, while the AC and DC OPF flows closely track as attack size increases.Without attack, AC and DC OPF produce slightly different target-branch flows; with increasing attacker size, their flows converge closely.
  • Attack consequences: The AC attack successfully overloads target branch 17 and also overloads branches 12, 23, and 28 without directly targeting them.Branches 23 and 28 were already congested before the attack, contributing to their overload.

VI. CONCLUSIONS AND FUTURE WORK

The paper analyzes the physical consequences of false data injection attacks, introducing an AC-aware attack framework and a linear optimization method for worst-case line overloads. Simulations show that mild-load-shift attacks can still cause branch overloads, while future work targets multiple lines, nonlinear optimization, and improved load-pattern detection.

  • Contributions: The framework matches nonlinear AC system characteristics through local AC state estimation using a small number of measurements.It then formulates a linear optimization problem to identify worst-case line overload attacks.
  • Results: On the IEEE-RTS-24-bus system, the observed-load-shift constraint significantly affects the ability to overload a branch, alongside attack-subgraph size.The simulations tested the resulting attacks on this system.
  • Results: Attacks with mild load shift can still cause branch overloads.This result indicates that limiting observed load shifts does not eliminate all physically consequential attacks.
  • Future Work: Future work includes targeting multiple-line overloads, extending the optimization to a more accurate nonlinear formulation, and using accurate load statistics to detect abnormal patterns.More targeted attacks could cause greater damage or cascading outages, while improved detection could restrict undetectable attacks.
Loading 1506.03774v1…