Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

Authors

  • Wenxuan Cao

DOI:

https://doi.org/10.61173/gsd77t17

Keywords:

smart grid security, anomaly detection, machine learning, regex-based filtering, Snort IDS, Isolation Forest, LSTM Autoencoder, false positive rate, system latency, SCADA, Phasor Measurement Units, Intelligent Electronic Devices, false data injection, intrusion detection systems, hybrid architecture, cyber-physical systems

Abstract

This Extended Project Qualification investigates whether machine-learning-based anomaly detection systems introduce greater operational risk in automated smart grid protection controllers, that is, in latency and false-positive circuit-trip rates, than traditional regex-based and signature-based filtering. This project compares three detection methods, including Snort-based rule filtering, an Isolation Forest classifier, and an LSTM Autoencoder using a primary data based on an analysis of the bachirbarika Power System data, a testbed PMU and SCADA dataset consisting of 78,369 rows and 15 different attack scenarios with assistance provided by a review of peer-reviewed literature. Findings indicate that ML-based algorithms identify a significantly higher number of attacks compared to Snort in a setup where the attack is shown as a physical-state anomaly, not as an event on the network layer, but at the tradeoff of introducing a quantifiably higher false positive rate and, in the case of the Isolation Forest, a very great curiousness of inference. LSTM Autoencoder has a more refined portrait with similar accuracy on detection at a lower latency to the baseline of the rule-based. The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers. All the differences in the latencies were statistically significant, as tested with Mann-Whitney U at p < 0.001.

References

[1] S. Amin and B. F. Wollenberg, "Toward a smart grid: Power delivery for the 21st century," IEEE Power and Energy Magazine, vol. 3, no. 5, pp. 34–41, Sep./Oct. 2005. doi: 10.1109/ MPAE.2005.1507024

[2] Mississippi State University and Oak Ridge National Laboratory, "Power System Attack Datasets," Apr. 2014. Distributed via Kaggle [bachirbarika/power-system]. [Online]. Available: https://www.kaggle.com/datasets/bachirbarika/powersystem

[3] G. Bernieri, G. Dini, F. Ferraris, M. Lisanti, L. Marchetti, and F. Pascucci, "On the design of anomaly detection strategies for industrial control systems," Sensors, vol. 19, no. 3, p. 709, 2019. doi: 10.3390/s19030709

[4] A. Carcano, A. Coletta, M. Guglielmi, M. Masera, I. N. Fovino, and A. Trombetta, "A multidimensional critical state analysis for detecting intrusions in SCADA systems," IEEE Transactions on Industrial Informatics, vol. 7, no. 2, pp. 179– 186, May 2011. doi: 10.1109/TII.2010.2099234

[5] H. Farhangi, "The path of the smart grid," IEEE Power and Energy Magazine, vol. 8, no. 1, pp. 18–28, Jan./Feb. 2010. doi: 10.1109/MPE.2009.934876 Dean&Francis Wenxuan Cao

[6] Hadeli, B. Schierholz, B. Klauer, and C. Patel, "Leveraging diagnostics and condition monitoring in industrial control systems security," in Proc. IEEE 10th International Conf. on Industrial Informatics (INDIN), Porto Alegre, Brazil, 2014, pp. 750–755. doi: 10.1109/INDIN.2014.6945600

[7] A. M. Igure, S. A. Laughter, and R. D. Williams, "Security issues in SCADA networks," Computers and Security, vol. 25, no. 7, pp. 498–506, Oct. 2006. doi: 10.1016/j.cose.2006.03.001

[8] F. T. Liu, K. M. Ting, and Z.-H. Zhou, "Isolation forest," in Proc. 8th IEEE International Conf. on Data Mining (ICDM), Pisa, Italy, 2008, pp. 413–422. doi: 10.1109/ICDM.2008.17

[9] Y. Liu, P. Ning, and M. K. Reiter, "False data injection attacks against state estimation in electric power grids," ACM Transactions on Information and System Security, vol. 14, no. 1, article 13, May 2011. doi: 10.1145/1952982.1952995

[10] Y. Mo, T. H.-J. Kim, K. Brancik, D. Dickinson, H. Lee, A. Perrig, and B. Sinopoli, "Cyber-physical security of a smart grid infrastructure," Proceedings of the IEEE, vol. 100, no. 1, pp. 195–209, Jan. 2012. doi: 10.1109/JPROC.2011.2161428

[11] National Institute of Standards and Technology, "Guidelines for smart grid cybersecurity," NIST Interagency Report 7628, U.S. Department of Commerce, Washington, DC, Sep. 2010. [Online]. Available: https://csrc.nist.gov/publications/detail/ nistir/7628/final

[12] S. Pan, T. Morris, and U. Adhikari, "Developing a hybrid intrusion detection system using data mining for power systems," IEEE Transactions on Smart Grid, vol. 6, no. 6, pp. 3104–3113, Nov. 2015. doi: 10.1109/TSG.2015.2409775

[13] M. Sakurada and T. Yairi, "Anomaly detection using autoencoders with nonlinear dimensionality reduction," in Proc. MLSDA 2nd Workshop on Machine Learning for Sensory Data Analysis, Gold Coast, Australia, 2014, pp. 4–11. doi: 10.1145/2689746.2689747

[14] J. Yan, B. Tang, and H. He, "Detection of false data attacks in smart grid with supervised learning," in Proc. IEEE International Joint Conf. on Neural Networks (IJCNN), Vancouver, Canada, 2016, pp. 1395–1402. doi: 10.1109/ IJCNN.2016.7727361

[15] Z. Yan, Y. Xu, X. Wang, and A. Bui, "LSTM-based anomaly detection for smart grid state estimation," in Proc. IEEE PES Innovative Smart Grid Technologies (ISGT Europe), Bucharest, Romania, 2019. doi: 10.1109/ISGTEurope.2019.8905538 Appendix A Dean&Francis ISSN 2959-6157 Appendix B Dean&Francis Wenxuan Cao Dean&Francis ISSN 2959-6157 Dean&Francis Wenxuan Cao Dean&Francis ISSN 2959-6157 Dean&Francis Wenxuan Cao Dean&Francis ISSN 2959-6157 Dean&Francis Wenxuan Cao Dean&Francis ISSN 2959-6157 Dean&Francis Wenxuan Cao Dean&Francis ISSN 2959-6157

Downloads

Published

2026-08-13