Journal of Modern Power Systems and Clean Energy

ISSN 2196-5625 CN 32-1884/TK

Non-intrusive Hybrid Two-stage Detection of Dynamic Attacks in Wide-area Damping Controller Using Autoencoder and Unscented Kalman Filter with Unknown Input Estimation
CSTR:
Author:
Affiliation:

1.Department of Electrical, Electronics, and Communication Engineering, Indian Institute of Technology Dharwad (IIT DH), Dharwad 580011, India;2.Department of Computer Science and Electrical Engineering, West Virginia University, Morgantown 26506, USA

Clc Number:

Fund Project:

This work was supported in part by ANRF (No. CRG/2021/003827/EEC) and SERB (No. SIRE/SIR/2022/000984).

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Wide-area damping controllers (WADCs) help in damping poorly damped inter-area oscillations (IAOs) using wide-area measurements. However, the vulnerability of the communication network makes the WADC susceptible to malicious dynamic attacks. Existing cyber-resilient WADC solutions rely on accurate power system models or extensive simulation data for training the machine learning (ML) model, which are difficult to obtain for large-scale power system. This paper proposes a novel non-intrusive hybrid two-stage detection framework that mitigates these limitations by eliminating the need for real-time access to large system data or attack samples for training the ML model. In the first stage, an autoencoder is deployed at the actuator location to detect dynamic attacks with sharp gradient variations, e.g., triangular, saw-tooth, pulse, ramp, and random attack signals. In the second stage, an unscented Kalman filter with unknown input estimation at the control center identifies smoothly varying dynamic attacks by estimating the control signal received by the actuator using synchrophasor measurements. A modified cosine similarity (MCS) metric is proposed to compare and quantify the similarity between the estimated control signal and the control signal sent by the WADC placed at the control center to detect any dynamic attacks. The MCS is designed to differentiate between events and dynamic attacks. The performance of the proposed framework has been validated on a hardware-in-the-loop (HIL) cyber-physical testbed built by using the OPAL-RT simulator and industry-grade hardware.

    Reference
    Related
    Cited by
Get Citation
Related Videos

Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:August 26,2024
  • Revised:December 13,2024
  • Adopted:
  • Online: September 17,2025
  • Published:
Article QR Code