Generative Adversarial Networks to Secure Vehicle-to-Microgrid Services
Bibliographic record
Abstract
As the use of Artificial Intelligence (AI) becomes more prevalent in the cyber-physical systems, there has been a rise in the number of adversarial attacks targeting Machine Learning (ML) models. Therefore, it has become imperative to safeguard ML models against such attacks. Our analysis under a vehicle-to-microgrid service setting shows that adversaries aim to deceive the victim's ML classifier at the network edge to misclassify the incoming energy requests from microgrid users. In this paper, we introduce an AI-powered framework to detect new instances of Adversarial attacks against Vehicle-to-Microgrid (V2M) systems. The proposed detection technique uses a Generative Adversarial Network (GAN) model and ML classifiers to accurately detect adversarial attacks. We test the proposed detection technique under three strategies of adversarial sample generation. Adversaries perform a two-stage adversarial attack beginning with an inference attack followed by an evasion attack against the victim's ML model. In addition, we investigate how the adversaries' knowledge of the victim's ML training dataset impacts the Adversarial Detection Rate (ADR). We assess five access cases to the victim's ML training dataset varying from a white-box to various levels of a gray-box attack. Moreover, we implement an unsupervised ML algorithm (i.e., DBSCAN) as a baseline method. Through simulations, we show that DBSCAN results in an ADR up to 69% and 17% for gray-box and white-box attacks, respectively. On the other hand, our proposed generative approach (i.e., GAN-based) outperforms DBSCAN resulting in an ADR up to 94.6% for the gray-box attack and 30.2% for the white-box attack.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.001 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".