Learning from Time-Synchronized Power System Measurements with Rare Anomalous Event Records to Detect PMU Data Manipulation Attacks

Jingyu Wang,Dongyuan Shi
DOI: https://doi.org/10.1109/ei2.2017.8245273
2017-01-01
Abstract:PMU data manipulation attacks (DMA) which maliciously modify the synchrophasor measurements in power systems, is an emerging type of cyber-attack aiming to mislead the control center into taking erroneous control actions. Widespread application of PMU produces a vast amount of time-synchronized historical operating data, making it possible to turn to machine learning approaches to detect the attacks. However, anomalous events occur rarely in practice. To construct a balanced training dataset, where normal and anomalous instances need to be evenly extracted and labeled from historical operating records, is sure to cost plenty of human efforts and may introduce uncontrollable experience errors. In this paper, we design a novel detection model with Synthetic Minority Over-sampling TEchnique (SMOTE)-based data augmentation and Edited Nearest Neighbors (ENN)-based data cleaning technique to reconstruct the imbalanced training dataset into a balanced one to train the subsequent XGBoost classifier. Experiments show that although rare anomalous historical event records are needed, our model is still able to effectively detect out DMAs in power systems.
What problem does this paper attempt to address?