A black-box adversarial attack on demand side management

Eike Cramer,Ji Gao
DOI: https://doi.org/10.1016/j.compchemeng.2024.108681
IF: 4.13
2024-04-14
Computers & Chemical Engineering
Abstract:Demand side management (DSM) contributes to the industry's transition to renewables by shifting electricity consumption in time while maintaining feasible operations. Machine learning is promising for DSM with reasonable computation times and electricity price forecasting (EPF), which is paramount to obtaining the necessary data. Increased usage of machine learning makes production processes susceptible to so-called adversarial attacks. This work proposes a black-box attack on DSM and EPF based on an adversarial surrogate model that intercepts and modifies the data flow of load forecasts and forces the DSM to result in financial losses. Notably, adversaries can design the data modifications without knowledge of the EPF model or the DSM optimization model. The results show how barely noticeable modifications of the input data lead to significant deterioration of the decisions by the optimizer. The results implicate a significant threat, as attackers can design and implement powerful attacks without infiltrating secure company networks.
engineering, chemical,computer science, interdisciplinary applications
What problem does this paper attempt to address?