论文标题
将数据和物理与虚假数据注入攻击相结合:事件触发的移动目标防御方法
Blending Data and Physics Against False Data Injection Attack: An Event-Triggered Moving Target Defence Approach
论文作者
论文摘要
快速准确检测网络攻击是网络弹性系统的关键要素。最近,已经提出了基于数据驱动的探测器和基于物理的移动目标防御(MTD)来检测对状态估计的虚假数据注入(FDI)攻击。但是,数据驱动的检测器的不可控制的假正率和频繁使用MTD使用的额外成本限制了其广泛的应用。很少有作品探讨了这两个领域之间的重叠。为了填补这一空白,本文提出了将基于数据驱动和物理基于物理的方法融合以增强检测性能的方法。首先,提出了物理知识的数据驱动攻击检测和识别算法。然后,MTD协议是由数据驱动的检测器的积极警报触发的。 MTD被称为双层优化,以稳健地保证其在确定的攻击载体周围最坏情况下的攻击方面的有效性。同时,MTD的隐藏性也得到了改善,因此攻击者无法检测到防御。为了确保可行性和融合,凸的两阶段重新印象是通过二元性和线性矩阵不平等得出的。模拟结果验证了混合数据和物理学可以达到极高的检测率,同时降低了数据驱动的检测器的假阳性率和MTD的额外成本。所有代码均可在https://github.com/xuwkk/ddet-mtd上找到。
Fast and accurate detection of cyberattacks is a key element for a cyber-resilient power system. Recently, data-driven detectors and physics-based Moving Target Defences (MTD) have been proposed to detect false data injection (FDI) attacks on state estimation. However, the uncontrollable false positive rate of the data-driven detector and the extra cost of frequent MTD usage limit their wide applications. Few works have explored the overlap between these two areas. To fill this gap, this paper proposes blending data-driven and physics-based approaches to enhance the detection performance. To start, a physics-informed data-driven attack detection and identification algorithm is proposed. Then, an MTD protocol is triggered by the positive alarm from the data-driven detector. The MTD is formulated as a bilevel optimisation to robustly guarantee its effectiveness against the worst-case attack around the identified attack vector. Meanwhile, MTD hiddenness is also improved so that the defence cannot be detected by the attacker. To guarantee feasibility and convergence, the convex two-stage reformulation is derived through duality and linear matrix inequality. The simulation results verify that blending data and physics can achieve extremely high detection rate while simultaneously reducing the false positive rate of the data-driven detector and the extra cost of MTD. All codes are available at https://github.com/xuwkk/DDET-MTD.