Source-linked AI summary
Comprehensive Survey and Taxonomies of False Injection Attacks in Smart Grid: Attack Models, Targets, and Impacts
Haftu Tasew Reda, Adnan Anwar, Abdun Mahmood
TL;DR
Smart Grid connectivity has expanded vulnerabilities, making stealthy FDI a critical threat to data and power-system operation. This survey synthesizes FDI research across adversarial models, targets, and impacts, evaluates the literature, and identifies gaps and future directions. It finds that surveyed work concentrates on full-knowledge adversarial models and EMS/SCADA/PMU targets, while emerging areas remain insufficiently studied.
Problem
FDI can stealthily violate Smart Grid data availability, integrity, and confidentiality, while existing research leaves gaps across models, targets, impacts, and emerging infrastructures.
Method
The paper systematically searches, selects, analyzes, and compares approximately 101 publications using taxonomies and evaluation criteria for FDI models, targets, and impacts.
Results
Approximately 42% of surveyed publications assume full adversarial knowledge, while EMS and SCADA/PMU account for almost 95% of targeted critical elements.
Takeaways & Limitations
The survey organizes the FDI literature into three classes and proposes future research directions to advance Smart Grid cybersecurity.
Abstract
from arXiv · showhide
Smart Grid has rapidly transformed the centrally controlled power system into a massively interconnected cyber-physical system that benefits from the revolutions happening in the communications (e.g. 5G) and the growing proliferation of the Internet of Things devices (such as smart metres and intelligent electronic devices). While the convergence of a significant number of cyber-physical elements has enabled the Smart Grid to be far more efficient and competitive in addressing the growing global energy challenges, it has also introduced a large number of vulnerabilities culminating in violations of data availability, integrity, and confidentiality. Recently, false data injection (FDI) has become one of the most critical cyberattacks, and appears to be a focal point of interest for both research and industry. To this end, this paper presents a comprehensive review in the recent advances of the FDI attacks, with particular emphasis on 1) adversarial models, 2) attack targets, and 3) impacts in the Smart Grid infrastructure. This review paper aims to provide a thorough understanding of the incumbent threats affecting the entire spectrum of the Smart Grid. Related literature are analysed and compared in terms of their theoretical and practical implications to the Smart Grid cybersecurity. In conclusion, a range of technical limitations of existing false data attack research is identified, and a number of future research directions is recommended.
I. INTRODUCTION
The paper frames FDI as a critical Smart Grid cybersecurity threat and reviews its construction methods, targets, impacts, and research gaps. It positions the survey as a systematic synthesis extending prior work across the Smart Grid infrastructure.
- Threat and motivation: Energy-sector infrastructure reported 178, 110, and 283 incidents out of 322, 415, and 509 ICS incidents in fiscal years 2017, 2018, and 2019, respectively.The cited reports identify the energy sector as having the greatest number of vulnerabilities among network infrastructures.
- Threat and motivation: FDI attacks can evade established bad-data detection and threaten Smart Grid data integrity, availability, and confidentiality.The paper identifies FDI as capable of making the power system unobservable and causing outages, cost increases, and broader operational failures.
- Survey scope and approach: The survey systematically searches, analyzes, evaluates, and compares literature on FDI attack construction, targets, and impacts.Its review spans older and recent publications and places findings within the broader context of cyber-physical data-integrity attacks.
- Survey scope and approach: It develops taxonomies for FDI attack models, attack targets, and attack impacts, alongside cybersecurity requirements and stealthy-attack examples.The paper also compares existing surveys and identifies gaps addressed by its broader taxonomy.
- Findings and directions: The paper analyzes adversarial modeling methods, reports evaluation statistics, identifies research gaps, and recommends directions for IoT-based AMI, edge computing, distributed trading, and blockchain.The recommendations also cover cognitive radio and lightweight machine learning for resource-constrained IoT devices.
III. BACKGROUND
Smart Grid infrastructure integrates cyber and physical layers, control applications, communications, distributed resources, and customer-facing systems. Its cybersecurity goals emphasize reliable operation while protecting availability, integrity, confidentiality, and accountability.
- Smart Grid architecture: Smart Grid is a cyber-physical ecosystem formed by interdependent cyber and physical layers.Understanding relations between these layers is necessary for investigating cyber-physical attacks.
- Control and monitoring systems: SCADA acquires power-system measurements, supervises remote IEDs, and connects these functions through communications subsystems.SCADA gathers data from IEDs and presents it through monitoring and visualization tools.
- Control and monitoring systems: EMS monitors, controls, coordinates, and optimizes energy-data performance, relying on SCADA and incorporating state estimation, OPF, contingency analysis, alarms, AGC, and economic dispatch.The control center uses EMS across much of the Smart Grid infrastructure in real time.
- Control and monitoring systems: A state estimator processes measurements to provide system information and identify malicious data, typically using bad-data detection.Its output supplies a real-time database for other EMS applications.
- Communications and distributed resources: Smart Grid communications include IEC 61850, PMUs, AMIs, and networked control systems across substations, wide-area monitoring, customer-side systems, and sensor-control links.These technologies connect sensors, actuators, controllers, and operational domains.
- Communications and distributed resources: Distributed energy resources use decentralized renewable generation, while microgrids coordinate DERs and can isolate from or access conventional grid electricity.DERs enable production and delivery from many homes and businesses.
- Cybersecurity goals: Smart Grid cybersecurity addresses physical, cyber, and cyber-physical security, with data integrity, availability, confidentiality, and accountability as core objectives.These objectives protect equipment and information while supporting reliable service and customer privacy.
B. Smart Grid Security Requirements
Smart Grid security requires resilient, holistic protection because cyber-physical dependencies and Internet connectivity expose power-system operations to diverse threats. FDI attacks exploit state-estimation and bad-data-detection weaknesses, using topology-informed or data-driven constructions that can remain stealthy.
- Security requirements: Smart Grid security must address cyber-physical dependencies, Internet connectivity, continuous operation, data availability, integrity, and consumer privacy.The stated requirements include maintaining power-system operation during cyber incidents, preserving data availability and integrity, and ensuring consumer privacy.
- Threat landscape: Attacks vary by attacker motive, capability, skill, system familiarity, implementation ease, and complexity, and simultaneous compromises can cause widespread outages.The paper frames Smart Grid components as vulnerable to multiple concurrent cyber threats.
- FDI attack model: FDI attacks target measurements by injecting an attack vector a without operator detection, potentially compromising state variables across the power system.The attack objective is stealthy manipulation of measurements and estimated system states.
- FDI attack model: Topology-informed attacks set y_false = y + a and x_hat_false = x_hat + b, while data-driven blind attacks provide an alternative construction strategy.The reviewed demonstration uses the topology-informed approach; b denotes the adversarially injected estimated-error vector.
- Stealthiness: When a = Hb, residuals can remain below detection threshold τ, allowing malicious measurements to pass traditional bad-data detection.The stealth condition preserves ||r_false||_2^2 < τ when the original residual satisfies ||r||_2^2 < τ.
- Attack constraints: Sparse FDI attacks use only a few non-zero attack components when secure devices or limited physical access restrict the adversary’s control.Sparse attacks arise from access constraints and target a small number of measurement devices.
3) Demonstration with an Example:
The IEEE 5-bus demonstration compares state-estimation measurements before and after a stealthy FDI attack and examines observability and detection. It shows large compromised-measurement deviations, poor χ2-detector detection, and attack-induced risks to state estimation and network observability.
- Demonstration with an Example: The IEEE 5-bus test case uses a WLS state estimator to compare original measurements, FDI-affected estimates, and corresponding residual vectors.The demonstration includes attack-free and FDI-estimated measurements together with residual comparisons.
- Power system measurement: The attack-free residuals are approximately zero, whereas compromised measurements show a very large deviation.Figure 4 presents the original measurement, WLS estimate under attack, and two residual-vector results.
- Attack detection: The χ2-detector exhibits a very poor probability of detecting the false data attack.Figure 5 reports the detection result for the bad-data detector in the demonstration.
- Observability: System observability determines whether available measurements permit a unique estimate of power-system states.Insufficient measurements, compromised measurement removal, or limited PMU placement can produce partial or unobservable systems.
- Observability: Intelligently constructed FDI vectors can falsify critical state estimates and make the power system unobservable.The attack combines injected and original measurements to produce falsified control-center estimates.
- Attack impact: False data can remain undetected while causing incorrect state-estimator decisions, and detected attacks may still leave part of the network unobservable.The paper distinguishes stealthy incorrect decisions from residual unobservability after detection.
6) Requirement Based on Security Violations:
FDI attacks can violate data availability, integrity, and confidentiality, while adversaries balance operational impact against detection risk. The survey classifies attacks by models, targets, and impacts across Smart Grid infrastructure.
- Security violations: FDI attacks can compromise data integrity, availability, or confidentiality across Smart Grid systems.Examples include modifying meter readings, disrupting critical information, and violating customer privacy in advanced metering infrastructure.
- Security violations: Attack impacts range from operational malfunctions and communication failures to cascading power-system failures.The survey identifies low, moderate, and high impact levels according to adversarial effects and associated risks.
- Security violations: Adversaries trade off maximizing impact on cyber-physical components against minimizing the probability of detection.This trade-off shapes the construction of stealthy attacks.
- Security violations: The survey organizes FDI attacks into attack models, attack targets, and attack impacts, with subcategories within each class.The taxonomy covers construction methodologies, vulnerable Smart Grid elements, and consequences for stability, reliability, economy, privacy, and social welfare.
- Security violations: Most existing FDI research uses simplified DC state estimators, although industry-standard estimators commonly use nonlinear AC power-flow models.The survey notes that DC-based techniques may not remain valid for AC-based state estimation and that AC estimators can be more robust to unobservable attacks.
2) Network Architecture:
FDI attacks are studied across centralized and distributed architectures and under varying attacker knowledge. Construction methods include complete-, partial-, and data-driven approaches, alongside topology, load-redistribution, and coordinated attacks.
- Network architecture: Centralized FDI attacks manipulate measurements sent to a central state estimator, affecting optimal power flow, economic dispatch, and contingency analysis.Such attacks can be difficult to implement in distribution systems that require local-state knowledge.
- Network architecture: Distributed architectures broaden attack opportunities to supply-side systems, control commands, communication links, and distributed energy routing.The survey distinguishes centralized and distributed perspectives because Smart Grid information is hierarchically distributed.
- Attacker knowledge: Complete-topology attacks assume knowledge of network topology, transmission parameters, state-estimation algorithms, or bad-data detection methods.The paper notes that this assumption is common but may be impractical for adversaries.
- Attacker knowledge: Partial-topology attacks obtain required information through manual or online collection, market databases, or power-flow measurements.These mechanisms support attack construction when real-time topology knowledge is incomplete.
- Specialized attacks: Topology attacks can create false grid configurations, while load-redistribution attacks bias nodal-injection and power-flow estimates under restricted meter access.Topology attacks may target transmission-line outages; load-redistribution frameworks distinguish immediate and delayed objectives.
- Construction methods: Data-driven or blind attacks construct stealthy FDI vectors without prior grid knowledge using statistical inference, heuristic methods, or machine learning.Examples include independent component analysis, singular-value methods, principal component analysis, sparse optimization, and matrix recovery.
VII. CLASSIFICATION BASED ON ATTACK TARGETS
FDI attacks target cyber-physical elements throughout generation, transmission, distribution, consumption, markets, and operations. The state estimator is especially central because downstream control and security modules depend on its outputs.
- Target domains: FDI attacks span Smart Grid domains including generation, transmission, distribution, consumption, markets, and operations.The survey frames these components as vulnerable because they support monitoring and control while exposing data-integrity, confidentiality, and availability risks.
- Energy management systems: The state estimator is the most important attack target because sequential EMS modules depend on its outputs.Compromised measurements can produce unbounded estimation errors and deceive operators stealthily.
- Control and communication: Attack targets also include transmission lines, grid topology, system observability, and communication systems linking control functions.SCADA and PMU communications transmit data between automatic generation control, generators, and network control systems.
- Security analysis: False data can mislead contingency analysis and security-constrained dispatch, potentially leaving transmission lines overloaded.Attackers may introduce a false transmission-line contingency into the normal contingency list through the state estimator.
- Distribution and markets: Distribution energy management and market management systems are additional targets because they support real-time decisions, pricing, dispatch, and operational constraints.The survey identifies these systems as important components of distributed networks and electricity markets.
- Communication pathways: SCADA compromise can propagate from power-system measurements to state estimation or advanced metering infrastructure, including customer billing.Communication protocols such as IEC 61850 are also described as vulnerable.
7) Intelligent Electronic Devices:
FDI attacks against intelligent electronic devices and related infrastructure can alter measurements or settings, causing relay trips, voltage drops, load shedding, and outages. Across the broader grid, impacts include reliability, cascading failures, economic losses, and market manipulation.
- Intelligent electronic devices: FDI attacks can breach IED information, alter voltage readings, and modify settings that cause protective relays to trip.The resulting voltage drop may trigger load shedding and power outages.
- Distributed energy resources: Forged data targeting distributed energy resources can imbalance demand and response, increase transmission and distribution costs, and raise outage-customer counts.The survey identifies DER routing processes as a vulnerability area.
- Reliability impacts: Cyber-capable attacks through SCADA and RTUs can contribute to circuit-breaker trips and threaten power-system reliability.The paper connects cyber-to-physical attack paths with reliability consequences.
- Cascading impacts: False data can induce overloaded branch trips or force generation redispatch that creates physical transmission-line overflow and cascading failure.These attacks can harm secure operation and grid stability even when hidden from operators.
- Economic and market impacts: FDI attacks can cause prolonged outages, substantial economic losses, and financial misconduct through electricity-market or economic-dispatch manipulation.Market attacks can shift prices while remaining undetected by the state estimator.
- Economic and market impacts: Multi-step electricity-price models have also been used to analyze FDI effects on energy efficiency, load balancing, and fairness in consumption.The survey identifies this as a distinct line of electricity-market impact research.
4) Energy Theft:
The section examines FDI-enabled energy theft and extends the discussion to privacy risks at smart-meter interfaces. It also describes the review process used to select and compare relevant literature.
- Energy Theft: FDI-based energy theft can manipulate sensor measurements sent to regional transmission organizations to generate adversary profit.The attack exploits false measurement data in market operations.
- Energy Theft: $272,871 in falsely reduced consumer charges resulted when an attack minimized active power measurements and shifted load between buses for one day.The reported case concerns consumers connected to the 5th bus after load movement from the 5th to the 4th bus.
- Energy Theft: Malicious customers can falsify renewable-generation readings to demand higher grid supply and overcharge the utility provider.The attack compromises smart-meter monitoring of renewable generation systems.
- Energy Data Privacy and Confidentiality: Smart meters expose customer usage and monitoring data to coordinated attacks that can manipulate readings, falsify utility-center data, or disrupt communications.The described attacks include bypassing cryptographic functions and exhausting smart-meter communication bandwidth.
- Literature Review Methodology: The review uses systematic search, selection, analysis, and critical evaluation across multiple academic databases and FDI taxonomies.Keywords cover adversarial models, attack targets, and attack impacts, while titles and abstracts support categorization and re-categorization.
C. Evaluation Criteria
The evaluation framework compares FDI attack construction methods, targets, and impacts using criteria tied to power-system requirements and Smart Grid cybersecurity. It spans adversarial knowledge, sensing infrastructure, algorithms, models, and reported outcomes.
- Evaluation Framework: The evaluation criteria are designed to quantify the efficacy and challenges of different cyberattack strategies in Smart Grid settings.The criteria support comparison of attack construction methods, targets, and impacts.
- Attack Models: Attack-model comparisons distinguish complete, partial, and data-driven knowledge settings alongside centralized or decentralized architectures.The surveyed approaches also distinguish AC and DC power-flow models.
- Measured Outcomes: Reported comparisons pair outcomes such as generation dispatch, economic loss, load curtailment, line outages, power flows, detection metrics, and attack resources with attack magnitude, location, budget, or observations.The table entries include SCADA, PMU, router, and IEC 61850 sensing or communication contexts.
- Measured Outcomes: The framework includes measurement-residue, detection, risk, stability, pricing, loss, and operational-cost outcomes across diverse attack targets and system settings.Examples include MSE, probability of missed detection, attack-detection rate, real-time pricing, and transmission loss.
- Algorithms and Models: The reviewed attack-design approaches include heuristic, graph-theoretic, game-theoretic, MILP, statistical-transformation, Markov, and machine-learning methods.The listed statistical approaches include PCA, ICA, and PARAFAC; optimization approaches include bi-level and tri-level MILP.
X. COMPARISON AND STATISTICS AMONG DEFENCE STRATEGIES
The paper compares 101 publications covering three FDI attack classes and presents statistical facts based on the selected evaluation criteria.
- Comparison Scope: 101 publications are considered across adversarial models, attack targets, and attack impacts.The review compares strategies and reports statistics using its evaluation criteria.
- Comparison Scope: The reviewed strategies are compared using evaluation criteria developed for the three FDI attack classes.The comparison is presented alongside statistical facts about the surveyed literature.
- Comparison Scope: The comparison covers false injection attacks across the three classes rather than a single attack-construction or impact category.The passage identifies the classes as adversarial models, attack targets, and attack impacts.
A. Adversarial Model
The surveyed literature is dominated by full-knowledge adversarial models, while limited-knowledge and data-driven models form substantial alternatives. Data-driven strategies are described as increasingly appealing for complex Smart Grid infrastructure.
- Adversarial Model: 42% of surveyed works use adversarial models assuming full knowledge of power-system operations.These models assume knowledge of network data and topological settings.
- Adversarial Model: Approximately 18% of surveyed publications use adversarial models with limited knowledge of topological and network data.The paper describes this threat model as more reasonable than complete knowledge.
- Adversarial Model: About one-fifth of the surveyed literature uses data-driven adversarial models for FDI attack construction.The paper identifies these strategies as the second most popular research area for attack construction.
- Adversarial Model: Data-driven strategies are presented as appealing for handling complex Smart Grid infrastructure as cyber-physical datasets emerge.The passage links their appeal to the emergence of such datasets.
B. Attack Target
EMS and SCADA/PMU are the main FDI targets, while renewable DERs and microgrids receive comparatively little attention. The surveyed literature also concentrates on simulated, mostly DC-based studies, leaving important validation and modeling gaps.
- Primary targets: EMS and SCADA/PMU are the most vulnerable control and monitoring systems and constitute almost 95% of targeted critical elements.Attackers commonly compromise SCADA measurements or manipulate EMS/DEM outcomes.
- Primary targets: FDI attacks also target sensors, IEDs/RTUs, and communication systems including AMI, IEC 61850, DNP3, and Modbus.
- Impacts: Around 30% of surveyed papers analyze effects on secure operation and power system reliability, while just under 10% examine energy theft and customer data privacy.
- Evaluation practices: Most studies report numerical results from IEEE or modified grid simulations, commonly using the IEEE 14-bus system and MATPOWER.
- Research gaps: Existing research largely focuses on centralized EMS, leaving distribution-system state estimation, DERs, and several communication systems insufficiently studied.
- Research gaps: Most FDI experiments assume linear DC power-flow models, although industry-standard state estimators commonly use nonlinear AC models.
- Research gaps: Numerical results are rarely validated through cyber-physical testbeds, despite testbeds being essential for evaluating Smart Grid algorithms and protocols.
XII. EMERGING ADVANCED APPLICATIONS: FUTURE RESEARCH DIRECTIONS
The paper identifies emerging Smart Grid applications and communication environments that require further FDI research. It emphasizes security studies for new architectures, resource-constrained devices, edge computing, distributed trading, and blockchain-based infrastructures.
- Emerging communication systems: FDI threat modeling and impacts require further study in emerging communication systems, especially IEC 61850, IEEE C37.118, and AMI.
- Emerging communication systems: Software-defined networking, cognitive radio, wireless sensor networks, and IoT are identified as promising settings for future FDI cybersecurity research.
- Resource-constrained IoT: Lightweight machine learning frameworks are proposed for defending resource-constrained IoT devices against FDI attacks.
- Edge computing: Edge computing reduces communication overhead and bandwidth use by moving processing and storage closer to data sources, while introducing additional security concerns.
- Distributed electricity trading: FDI risks against LMP market pricing warrant investigation in distributed energy-market applications enabled by DERs.
- Blockchain technology: Blockchain-based Smart Grid interactions introduce a new FDI research area involving privacy preservation and anomaly detection.
- Threat significance: Coordinated FDI attacks can cause sequential transmission-line outages, increase operating costs, and produce large-scale or regional consequences.
- Survey scope: The survey organizes FDI research into attack models, attack targets, and attack impacts, then proposes evaluation criteria and future research directions.