Detection, differentiation and localization of replay attack and false data injection attack based on random matrix

Abstract Replay attack and false data injection attack (FDIA) are two common types of cyber-attacks against supervisory control and data acquisition systems, aiming to disrupt the normal operation of the power system by falsifying meter measurements. In this paper, we proposed a systematic methodolo...

Full description

Bibliographic Details
Main Authors: Yuehao Shen, Zhijun Qin
Format: Article
Language:English
Published: Nature Portfolio 2024-02-01
Series:Scientific Reports
Online Access:https://doi.org/10.1038/s41598-024-52954-z
_version_ 1797274736760193024
author Yuehao Shen
Zhijun Qin
author_facet Yuehao Shen
Zhijun Qin
author_sort Yuehao Shen
collection DOAJ
description Abstract Replay attack and false data injection attack (FDIA) are two common types of cyber-attacks against supervisory control and data acquisition systems, aiming to disrupt the normal operation of the power system by falsifying meter measurements. In this paper, we proposed a systematic methodology to defend hybrid attack with both replay attack and FDIA. Specifically, we propose a detection method applying random matrix theory to: (1) detect the hybrid attack on static state estimation, and (2) distinguish FDIA from replay attack as well as localize falsified measurements. Firstly, short-term forecast on load and renewable power generation is conducted to obtain the predicted measurements. Secondly, random variables are calculated by differentiating the forecasting measurements and real-time measurements. A random matrix is consequently constructed with the above random variables. Thirdly, hybrid attacks are detected by the changes of the linear eigenvalue statistics of the random matrix obtained by the sliding time window. More importantly, a novel multi-label classifier to distinguish replay attack from FDIA is designed to localize FDIA by combining SVD decomposition and eigenvalue analysis with convolutional neural network (SVD-CNN). Finally, comprehensive simulations on the IEEE 14-bus system and IEEE 57-bus system are provided to validate the performance of the proposed method. It is shown that the proposed detection method has strong detection ability by filtering measurement noise. Moreover, the proposed SVD-CNN improves the accuracy in FDIA localization.
first_indexed 2024-03-07T15:02:32Z
format Article
id doaj.art-a18b90a3e7924f9295148c94b4f0f2fb
institution Directory Open Access Journal
issn 2045-2322
language English
last_indexed 2024-03-07T15:02:32Z
publishDate 2024-02-01
publisher Nature Portfolio
record_format Article
series Scientific Reports
spelling doaj.art-a18b90a3e7924f9295148c94b4f0f2fb2024-03-05T19:03:28ZengNature PortfolioScientific Reports2045-23222024-02-0114111810.1038/s41598-024-52954-zDetection, differentiation and localization of replay attack and false data injection attack based on random matrixYuehao Shen0Zhijun Qin1Guangxi Key Laboratory of Power System Optimization and Energy Technology, Guangxi UniversityGuangxi Key Laboratory of Power System Optimization and Energy Technology, Guangxi UniversityAbstract Replay attack and false data injection attack (FDIA) are two common types of cyber-attacks against supervisory control and data acquisition systems, aiming to disrupt the normal operation of the power system by falsifying meter measurements. In this paper, we proposed a systematic methodology to defend hybrid attack with both replay attack and FDIA. Specifically, we propose a detection method applying random matrix theory to: (1) detect the hybrid attack on static state estimation, and (2) distinguish FDIA from replay attack as well as localize falsified measurements. Firstly, short-term forecast on load and renewable power generation is conducted to obtain the predicted measurements. Secondly, random variables are calculated by differentiating the forecasting measurements and real-time measurements. A random matrix is consequently constructed with the above random variables. Thirdly, hybrid attacks are detected by the changes of the linear eigenvalue statistics of the random matrix obtained by the sliding time window. More importantly, a novel multi-label classifier to distinguish replay attack from FDIA is designed to localize FDIA by combining SVD decomposition and eigenvalue analysis with convolutional neural network (SVD-CNN). Finally, comprehensive simulations on the IEEE 14-bus system and IEEE 57-bus system are provided to validate the performance of the proposed method. It is shown that the proposed detection method has strong detection ability by filtering measurement noise. Moreover, the proposed SVD-CNN improves the accuracy in FDIA localization.https://doi.org/10.1038/s41598-024-52954-z
spellingShingle Yuehao Shen
Zhijun Qin
Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
Scientific Reports
title Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
title_full Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
title_fullStr Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
title_full_unstemmed Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
title_short Detection, differentiation and localization of replay attack and false data injection attack based on random matrix
title_sort detection differentiation and localization of replay attack and false data injection attack based on random matrix
url https://doi.org/10.1038/s41598-024-52954-z
work_keys_str_mv AT yuehaoshen detectiondifferentiationandlocalizationofreplayattackandfalsedatainjectionattackbasedonrandommatrix
AT zhijunqin detectiondifferentiationandlocalizationofreplayattackandfalsedatainjectionattackbasedonrandommatrix