MétaCan
Menu
Back to cohort
Record W4411079194 · doi:10.1016/j.segan.2025.101768

Detection and classification of concurrent attacks in substation automation systems using wavelet design and deep learning

2025· article· en· W4411079194 on OpenAlexfundno aff
Matthew Oinonen, Walid G. Morsi

Bibliographic record

VenueSustainable Energy Grids and Networks · 2025
Typearticle
Languageen
FieldEngineering
TopicSmart Grid Security and Resilience
Canadian institutionsnot available
FundersNatural Sciences and Engineering Research Council of Canada
KeywordsAutomationWaveletArtificial intelligenceComputer scienceDeep learningLearning designEngineeringSystems engineeringMachine learningMathematicsMechanical engineering

Abstract

fetched live from OpenAlex

This paper presents a novel approach to detect and classify cyberattacks using wavelet design and deep learning. Existing works fail to investigate concurrent cyberattacks and works that utilize time-frequency features for cyberattack detection only use the existing standard wavelet filters that have not been designed for cybersecurity applications. This work proposes a detection scheme for concurrent attacks using new wavelet filters with the Discrete Wavelet Transform (DWT) to better extract time-frequency features from substation automation system (SAS) data. A set of new wavelet filters are generated from parameterized equations. The wavelet filter that best suits SAS cyberattack detection is used to extract the salient features of cyberattacks using the DWT. Unlike existing detection approaches, the use of wavelet design allows the generation of new wavelet filters that better match the time-frequency features of SAS data. The proposed approach has been tested on a publicly available dataset as well as experimentally using OPAL-RT. The results demonstrate its effectiveness in detecting four popular cyberattack types as well as the challenging concurrent attacks, which involve two or more attacks occurring simultaneously. The use of the wavelets not only enables the detection of the attacks but also their classification by type from power disturbances with an accuracy reaching 99.12% on a synthetic dataset and 95.47% on an experimental dataset. Furthermore, the results have shown that the use of the newly designed wavelets leads to an increase in the detection accuracy by 9.36% and a significant reduction in the computational complexity of the feature extraction process by up to 99.16% over the existing time-frequency transforms.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.001
metaresearch head score (Gemma)0.002
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Simulation or modeling · Consensus signal: none
GenreCandidate signal: Empirical · Consensus signal: none
Teacher disagreement score0.002
Threshold uncertainty score0.004

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0010.002
Meta-epidemiology (narrow)0.0010.000
Meta-epidemiology (broad)0.0010.001
Bibliometrics0.0010.001
Science and technology studies0.0000.000
Scholarly communication0.0010.001
Open science0.0010.001
Research integrity0.0010.002
Insufficient payload (model declined to judge)0.0010.000

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.007
GPT teacher head0.217
Teacher spread0.209 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designSimulation or modeling
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations1
Published2025
Admission routes1
Has abstractyes

Explore more

Same venueSustainable Energy Grids and NetworksSame topicSmart Grid Security and ResilienceFrench-language works237,207