False data injection attacks (FDIAs) pose a significant security threat to power system state estimation. To detect such attacks, recent studies have proposed machine learning (ML) techniques, particularly deep neural networks (DNNs). However, most of these methods fail to account for the risk posed by adversarial measurements, which can compromise the reliability of DNNs in various ML applications. In this paper, we present a DNN-based FDIA detection approach that is resilient to adversarial attacks. We first analyze several adversarial defense mechanisms used in computer vision and show their inherent limitations in FDIA detection. We then propose an adversarial-resilient DNN detection framework for FDIA that incorporates random input padding in both the training and inference phases. Our simulations, based on an IEEE standard power system, demonstrate that this framework significantly reduces the effectiveness of adversarial attacks while having a negligible impact on the DNNs' detection performance.
翻译:虚假数据注入攻击对电力系统状态估计构成重大安全威胁。为检测此类攻击,近期研究提出了机器学习技术,特别是深度神经网络。然而,多数方法未能考虑对抗性测量带来的风险,这类测量可能在各类机器学习应用中损害深度神经网络的可靠性。本文提出一种基于深度神经网络的虚假数据注入攻击检测方法,该方法对对抗攻击具有鲁棒性。我们首先分析了计算机视觉领域常用的几种对抗防御机制,并揭示了其在虚假数据注入攻击检测中的固有局限性。随后,我们提出一种融合训练与推理阶段随机输入填充的对抗鲁棒深度神经网络检测框架。基于IEEE标准电力系统的仿真表明,该框架能显著降低对抗攻击的有效性,同时对深度神经网络的检测性能影响微乎其微。