Securing Smart Grid False Data Detectors Against White-Box Evasion Attacks Without Sacrificing Accuracy
In the realm of smart grids, smart meters can be hacked to report false data to lower the consumers' electricity bills. While machine learning (ML) techniques have shown promise in detecting false data, they are also prone to adversarial attacks, such as evasion attacks. This article investigat...
Gespeichert in:
Veröffentlicht in: | IEEE internet of things journal 2024-10, Vol.11 (20), p.33873-33889 |
---|---|
Hauptverfasser: | , , , , , |
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | In the realm of smart grids, smart meters can be hacked to report false data to lower the consumers' electricity bills. While machine learning (ML) techniques have shown promise in detecting false data, they are also prone to adversarial attacks, such as evasion attacks. This article investigates the impact of gradient-ensemble-based evasion attacks on the smart grid ML-based false data detectors, focusing on the white-box threat model where attackers possess detailed knowledge of the defense mechanism. First, we examines the vulnerability of three detectors (consumer-based, cluster-based, and global) to gradient-based evasion attacks. The evaluation results show an inverse relationship between robustness of the detectors and regularization (i.e., generalization), where higher data set variability usually causes higher regularization. Notably, minimal regularization level is observed when electricity consumption patterns are close. Our findings also indicate that the consumer-based detector exhibits higher accuracy and robustness but remains susceptible to zero day attacks and demands substantial computational resources for training an ML model for each consumer. In contrast, the cluster-based detector improves accuracy and exhibits satisfactory robustness compared to the global detector. Subsequently, we proposes two parallel-ensemble approaches (stacking and voting) for the cluster-based false data detectors trained on the adversarial samples. The evaluation results demonstrate that integrating clustering, adversarial training, and ensemble methods, the proposed detector enhances robustness against gradient-ensemble-based evasion attacks while significantly boosting accuracy. This stands in contrast to benchmark defenses, which often face a tradeoff between accuracy and robustness, sacrificing accuracy to bolster resilience against evasion attacks. |
---|---|
ISSN: | 2327-4662 2327-4662 |
DOI: | 10.1109/JIOT.2024.3433600 |