Feature Attention Distillation Defense for Backdoor Attack in Artificial Neural Network-Based Electricity Theft Detection

Shizhong Li,Wenchao Meng,Chen Liu,Shibo He
DOI: https://doi.org/10.1109/jiot.2024.3451449
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:Artificial neural networks (ANNs) have been widely used for tasks like electricity theft detection (ETD) in smart meters. However, due to the subtle mechanisms and inherent opaque characteristics, ANNs are vulnerable to attacks. Although this attack surface poses significant risks, it has been largely overlooked in industrial scenarios. To alert the widespread adoption of industrial intelligence, this paper studies the impact of backdoor attacks in ETD for the first time and proposes a feature attention distillation defense. First, the attack surface in current model training pipeline is analyzed, and the adversaries can embed malicious backdoors for specific triggers to escape ETD. Then, six prevalent ANN-based models are tested and the adversaries can bypass the backdoored ETD models with success rates over 90.53%, which would inevitably bring huge losses to electricity companies. We further argue that the electricity companies can mitigate such attacks when noticing the abnormal non-technical loss. A novel feature attention distillation defense that aligns the intermediate feature maps between fine-tuned models and backdoored models is proposed, which can eliminate backdoors more efficiently with few resources compared with two classic defenses. The average attack success rate can drop by 90.71% with slight impacts on ETD performance. This work sheds light on a novel but perilous attack surface, and raises a warning for the wide adoption of artificial intelligence in smart measurement scenarios.
What problem does this paper attempt to address?