Source-linked AI summary

Detection of false data injection attacks in smart grids based on graph signal processing

Elisabeth Drayer, Tirza Routtenberg

arXiv:1810.04894v4eess.SP

TL;DR

FDI attacks threaten smart-grid state estimation, while classical residual methods and much prior work are limited against designed attacks and AC-model settings. The paper combines graph signal processing with the AC power-flow model, filtering high-frequency graph components of estimated states and thresholding their maximum norm. IEEE 14-bus case studies detect a wide range of previously undetectable attacks on voltage angles and magnitudes.

  • Problem

    Classical residual-based methods cannot reliably detect well-designed FDI attacks, and much prior work relies on the linearized DC model rather than the AC model.

  • Method

    The method applies a graph Fourier transform and graph high-pass filter to an estimated grid state, then compares the filtered signal’s maximum norm with a threshold.

  • Results

    IEEE 14-bus case studies detect a wide range of previously undetectable FDI attacks affecting both voltage angles and magnitudes.

  • Takeaways & Limitations

    The proposed graph-based AC-model approach detects FDI attacks that conventional and DC-model-based approaches may leave undetected.

Abstract

from arXiv · show

The smart grid combines the classical power system with information technology, leading to a cyber-physical system. In such an environment the malicious injection of data has the potential to cause severe consequences. Classical residual-based methods for bad data detection are unable to detect well designed false data injection (FDI) attacks. Moreover, most work on FDI attack detection is based on the linearized DC model of the power system and fails to detect attacks based on the AC model. The aim of this paper is to address these problems by using the graph structure of the grid and the AC power flow model. We derive an attack detection method that is able to detect previously undetectable FDI attacks. This method is based on concepts originating from graph signal processing (GSP). The proposed detection scheme calculates the graph Fourier transform of an estimated grid state and filters the graph's high-frequency components. By comparing the maximum norm of this outcome with a threshold we can detect the presence of FDI attacks. Case studies on the IEEE 14-bus system demonstrate that the proposed method is able to detect a wide range of previously undetectable attacks, both on angles and on magnitudes of the voltages.

ABBREVIATIONS

The paper targets FDI attack detection in smart-grid cyber-physical systems, addressing limitations of traditional methods and DC-model-based research through GSP and AC modeling.

  • The paper addresses FDI attacks that compromise grid measurements and affect power-system state estimation used for monitoring and control.
  • Existing research often relies on the linearized DC model, leaving AC-model-based FDI attack detection insufficiently studied.
  • The proposed method uses graph Fourier transforms and high-pass filtering of estimated grid states to detect previously undetectable attacks.
  • The method uses an AC power-system model and targets attacks on both voltage angles and magnitudes.
  • IEEE 14-bus simulations demonstrate detection of previously undetectable FDI attacks.

A. Graph Representation of Power System

The paper models the power grid as an undirected graph whose electrical properties define a Laplacian representation, then uses the AC power-flow model for complex bus voltages and admittances.

  • A. Graph Representation of Power System: The power system is represented as an undirected graph whose nodes are buses and whose edges are transmission lines.The associated weighted Laplacian uses line admittances as edge weights.
  • A. Graph Representation of Power System: The IEEE 14-bus one-line diagram supplies the test grid used in the paper’s case studies.
  • B. AC Model: The AC power-flow model computes complex steady-state voltages at each bus, which define the system state.
  • B. AC Model: The AC model is nonlinear and non-convex, so it is generally solved numerically.
  • B. AC Model: Under the AC model, the admittance matrix is a complex, non-Hermitian Laplacian whose eigenvalues lack a natural partial order.The paper addresses this by decomposing the matrix into real and imaginary parts.

C. Hypothesis Testing

The paper formulates FDI detection as testing whether the attack vector is zero, using graph structure to address attacks that conventional likelihood-ratio tests cannot distinguish from legitimate states.

  • FDI attacks compromise measurements entering PSSE, potentially including SCADA, PMU, and smart-meter measurements.
  • The detection task is to decide whether the attack vector c equals zero, corresponding to no attack versus an FDI attack.
  • Because the true voltage vector is unknown, likelihood-ratio tests cannot distinguish v from v + c for these attacks.
  • The proposed method uses the electrical graph structure and applies GFT-based processing to detect otherwise unobservable attacks.

A. Smooth Graphs

The method models voltage states on the electrical graph, where smooth undisturbed signals concentrate in low graph frequencies and attacks can introduce high-frequency components.

  • A. Smooth Graphs: The graph total variation measures neighboring voltage differences normalized by line admittances, with smaller values indicating smoother signals.
  • A. Smooth Graphs: Graph spectral decomposition orders Laplacian eigenvalues from low to high graph frequencies and supplies the eigenvectors used for the GFT.
  • A. Smooth Graphs: For smooth signals, GFT coefficients decay with increasing graph frequency, concentrating signal energy in low-frequency components.
  • A. Smooth Graphs: The graph filter takes a graph signal as input and produces another graph signal through a polynomial transfer function.
  • A. Smooth Graphs: The GHPF is designed to extract high-frequency components of the GFT signal that contain information about FDI attacks.

D. Detection Method

Detection applies a graph high-pass filter to extract high-frequency components and declares an attack when the largest absolute filtered coefficient exceeds a threshold.

  • D. Detection Method: An FDI attack is detected when one or more filtered Fourier coefficients exceed the threshold value.
  • D. Detection Method: The decision statistic is the maximum absolute element of the filtered GFT output, compared against τ.
  • D. Detection Method: The procedure first extracts high-frequency graph components with the GHPF and then applies thresholding.

1) Maximum Threshold:

The threshold can be based on historical maxima or an averaged historical statistic with a deviation term, while cutoff selection controls the trade-off between false alarms and missed attacks.

  • 1) Maximum Threshold:: The maximum threshold is defined from the largest detection statistic among historical grid states.
  • 1) Maximum Threshold:: The alternative averaged threshold combines historical values with a deviation term controlled by a confidence-interval parameter.
  • 1) Maximum Threshold:: The averaged historical threshold was more robust to outliers and produced better simulation results than the maximum historical threshold.
  • 1) Maximum Threshold:: Cutoff selection is critical because retaining too much low-frequency content can amplify normal states, whereas retaining too little can leave attacks undetected.
  • 1) Maximum Threshold:: The cutoff is chosen by iteratively decreasing the retained frequency index until the smoothness constraint would be exceeded.

IV. CASE STUDY

The case study applies the proposed GSP-based detector to the IEEE 14-bus grid through graph Fourier analysis, high-pass filtering, and thresholding using historical states.

  • IV. CASE STUDY: The IEEE 14-bus case study evaluates the proposed detector across undisturbed states, angle and magnitude attacks, noise robustness, combined attacks, and comparisons with prior work.The grid states are generated with an AC power-flow solver, with bus 1 as the slack bus.
  • IV. CASE STUDY: The general design computes graph Fourier representations, selects a cutoff frequency from approximation error, fits a polynomial high-pass filter, and derives a detection threshold from historical filtered-state norms.The procedure returns the filtered maximum norm Ψ and threshold τ for attack detection.

A. Test Case 1: Total Variation of Undisturbed Grid States

The first test case characterizes graph smoothness and frequency behavior of valid and attacked IEEE grid states, then evaluates detection across angle and magnitude attacks.

  • A. Test Case 1: Total Variation of Undisturbed Grid States: The real part of the grid signal is smoother than the imaginary part, and valid-state Fourier components decay with increasing graph frequency.Only components above the cutoff frequency are passed to the high-pass detector.
  • A. Test Case 1: Total Variation of Undisturbed Grid States: An angle attack of 10 degrees on bus 9 disrupts the decaying frequency behavior of the imaginary voltage component, producing high-frequency structure used for detection.The graph frequencies are normalized by the maximum eigenvalue.
  • A. Test Case 1: Total Variation of Undisturbed Grid States: The detector evaluates attack probabilities separately for voltage-angle and voltage-magnitude changes across attacked buses using repeated randomized simulations.The tested angle offsets range from -12 to 12 degrees, while magnitude offsets range from -0.2 to 0.2 p.u.
  • A. Test Case 1: Total Variation of Undisturbed Grid States: False-alarm probabilities in the angle test are roughly 0.5, 0.3, and 0.05 for ασ values of 0.5, 1, and 2, respectively.The parameter ασ scales the confidence interval around the historical mean and therefore directly controls the false-alarm rate.
  • A. Test Case 1: Total Variation of Undisturbed Grid States: Angle attacks are mostly detected through the imaginary voltage component, whereas magnitude attacks are largely detected through the real component.Both real- and imaginary-part analyses contribute to detection overall.

C. Test Case 3: Robustness against State Estimation Errors

The third test case examines whether state-estimation noise degrades the proposed detector by adding noise with varying standard deviations before simulating attacks.

  • C. Test Case 3: Robustness against State Estimation Errors: The proposed detection method remains robust against state-estimation noise, including standard deviations larger than those generally assumed.The simulations are summarized in Figs. 8 and 9 for angle and magnitude attacks.

D. Test Case 4: Wide Scale Undetectable FDI Attack

The fourth test case applies the detector to a wide-scale undetectable AC-model FDI attack that tampers with both voltage angles and magnitudes on multiple buses.

  • D. Test Case 4: Wide Scale Undetectable FDI Attack: The proposed detector detects the constructed undetectable FDI attack on buses 6 and 9–14 after both angle and magnitude values are tampered with.For the attacked case, the detection threshold for the imaginary component is exceeded.

E. Comparison with other Approaches

The proposed GSP detector is compared with state-norm and consecutive-state residual methods, while the case studies clarify detection mechanisms and boundaries. The proposed method detects attacks that the state-norm method misses, whereas the residual method detects only strong attacks.

  • E. Comparison with other Approaches: The state-norm method is unable to detect the attacks, while the consecutive-state residual method succeeds only for very strong attacks.Both comparison methods use thresholds selected to match the proposed method’s false alarm rate.
  • A. Detection Characteristics: Attacks on buses with smaller diagonal Laplacian values are more difficult to detect because their voltage differences contribute less to total variation.These buses are described as more loosely coupled to the grid.
  • A. Detection Characteristics: A smoothness-based detector cannot detect an attack when the attack does not increase the graph signal’s total variation.This condition is identified as the boundary of detectability for smoothness-based detection.
  • B. Contribution of Real and Imaginary Parts: Voltage-magnitude attacks are mainly detected through the real part of the voltage vector, whereas angle attacks are mainly detected through the imaginary part.The paper explains this behavior using the Cartesian and polar representations of complex voltage and a small-angle approximation.

C. FDI Attack Detection for the DC Model

The proposed FDI detection approach can also be applied to the DC power flow model under its standard simplifying assumptions. In this setting, the admittance matrix has a weighted-Laplacian structure, enabling the same graph-based approach.

  • C. FDI Attack Detection for the DC Model: The DC model fixes voltage magnitude at 1 p.u., neglects line resistance, and assumes small angle differences between connected buses.Under these assumptions, bus voltage angles are linked to real power injections or consumptions through the DC admittance matrix.
  • C. FDI Attack Detection for the DC Model: The DC admittance matrix is real, symmetric, positive semidefinite, and has the form of a weighted Laplacian matrix.This graph structure is the basis for applying the proposed detection approach to the DC model.
  • C. FDI Attack Detection for the DC Model: The proposed FDI attack detection method can be applied to the DC model, with full DC-case details provided in the authors’ preliminary work.
Loading 1810.04894v4…