The widespread adoption and application of Machine Learning (ML) based Intrusion Detection Systems (IDS) has increased the flexibility and efficiency of automated cyber attack detection in smart grid systems. However, the emergence of such IDSes has led to a new attack vector against learning models, known as adversarial attacks. Such attacks could have serious effects in smart grid systems since adversaries can circumvent detection by IDS. This could result in detection of attacks. From the existing literature, a lot of research proposes threat models that are inappropriate for generating realistic adversarial attacks. In this research, we model realistic adversarial attacks with a focus on real attacker capabilities that are feasible to launch adversarial attacks. We discuss how adversarial learning may be used to target ML models using the Jacobian-based Saliency Map Attack (JSMA) and the Fast Gradient Sign Method (FGSM). A power system dataset generated from a smart grid testbed was used for testing the models. The performance of the trained classifiers, Random Forest, XGBoost, and Naive Bayes, dropped when adversarial instances were introduced. The outcomes of this paper are useful for helping researchers model realistic scenarios to avoid dealing with hypothetical problems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Penetrating the Power Grid: Realistic Adversarial Attacks on Smart Grid Intrusion Detection Systems

  • Nelson Makau Mutua,
  • Simin Nadjm-Tehrani,
  • Petr Matoušek

摘要

The widespread adoption and application of Machine Learning (ML) based Intrusion Detection Systems (IDS) has increased the flexibility and efficiency of automated cyber attack detection in smart grid systems. However, the emergence of such IDSes has led to a new attack vector against learning models, known as adversarial attacks. Such attacks could have serious effects in smart grid systems since adversaries can circumvent detection by IDS. This could result in detection of attacks. From the existing literature, a lot of research proposes threat models that are inappropriate for generating realistic adversarial attacks. In this research, we model realistic adversarial attacks with a focus on real attacker capabilities that are feasible to launch adversarial attacks. We discuss how adversarial learning may be used to target ML models using the Jacobian-based Saliency Map Attack (JSMA) and the Fast Gradient Sign Method (FGSM). A power system dataset generated from a smart grid testbed was used for testing the models. The performance of the trained classifiers, Random Forest, XGBoost, and Naive Bayes, dropped when adversarial instances were introduced. The outcomes of this paper are useful for helping researchers model realistic scenarios to avoid dealing with hypothetical problems.