Attentional LSTM-ensemble architecture for intrusion detection in smart grids
摘要
Smart grids integrate real-time communication, computational intelligence, and physical energy infrastructure to improve operational efficiency and adaptability. However, this interconnectivity increases vulnerability to cyber intrusions capable of disrupting control signals, compromising data integrity, and causing large-scale outages. This study presents an architectural synthesis that combines a long short-term memory network with an attention mechanism for temporal–saliency feature extraction, followed by an ensemble of gradient-boosting classifiers (XGBoost, LightGBM, and CatBoost) for robust decision-making. Experiments on the benchmark smart grid intrusion detection dataset demonstrate that the integrated framework achieves 79.8% average cross-validation accuracy and 75.67% overall test accuracy, with a normal-class recall of 98.26% in the baseline configuration. To address severe class imbalance, a combination of synthetic minority oversampling technique and focal loss was applied, which improved minority attack-class recall from 1.43 to 64.3% and increased its PR-AUC from 0.2884 to 0.791. The balanced configuration yielded an receiver operating characteristic curve (ROC-AUC) of 0.928 for both classes, demonstrating substantial gains in minority-class detection while maintaining high precision for majority classes. These results highlight the potential of strategically combining temporal modelling, attention-driven interpretability, and ensemble diversity, augmented with targeted imbalance mitigation, to develop effective, scalable, and interpretable intrusion detection systems for critical energy infrastructure.