Robust Feature Extraction and Ensemble Classification Against Cyber-Physical Attacks in the Smart Grid
Bibliographic record
Abstract
Intrusion detection systems (IDS) are crucial in threats monitoring for the cyber-physical security of electrical power and energy systems in the smart grid with increasing machine-to-machine communication. However, the multi-sourced, voluminous, correlated, and often noise-contained data, which record various concurring cyber and physical events, are posing significant challenges to the accurate distinction by IDS among events of inadvertent and malignant natures. To tackle such challenges, this paper proposes a robust end-to-end framework based on Stacked Denoising Autoencoder (SDAE) and Ensemble Machine Learning to extract new noise and attack-informed feature sets from cyber-physical system data and incorporate different sources of information for reliable event classification. The proposed framework first leverages SDAE to create lower-dimensional features that allow reconstruction of a noise-free input from noise-corrupted perturbations. By combining attack and noisy inputs, we extracted new, automatically-engineered features that can preserve and present information on normal, fault, and attack events against different synthetic but realistic noises for better classification. Considering the heterogeneous nature of the inputs, which are composed of PMU measurements, system logs, and IDS alerts, we further introduced ensemble learning-based multi-classifier classification with the Extreme Gradient Boosting (XGBoost) technique to classify the samples based on the SDAE-extracted features. Normalization and oversampling were also both performed to improve the uniformity and balance of the data. On a realistic dataset of 37 sub-types of normal, fault, and attack collected from co-simulations on a hardware-in-the-loop (HIL) testbed security testbed, the results have shown that the proposed SDAE+XGBoost solution achieves over 90% classification accuracy with the SDAE features and ensemble classifiers, an effective 8% increase over the state-of-the-art.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".