Unsupervised cyberattack detection in smart grids: A novel approach integrating horizontal federated learning for the control center and substations
Haofeng Zheng,
Xingmei Li and
Fengyun Li
Reliability Engineering and System Safety, 2025, vol. 264, issue PB
Abstract:
To mitigate the cyber ​​threats in smart grids caused by vulnerabilities in the IEC 60870-5-104 (IEC 104) protocol and to address the gaps in existing detection methods, this paper proposes an unsupervised cyber-attack detection (UCAD) method and a distributed, privacy-preserving detection framework (DUCADF) for the control center and substations. First, UCAD operates without reliance on ground-truth labels. It employs a dynamic pseudo-label generation strategy that utilizes the reconstruction error of a deep autoencoder (DAE) to differentiate between normal and attack data, thereby providing the pseudo-classifier based on Transformer encoder with the necessary pseudo-labels for training. This approach enables UCAD to train directly on mixed datasets, circumventing the common limitation of DAE-based unsupervised methods that require training exclusively on normal samples. Second, UCAD features an end-to-end joint training architecture. By alternately updating the DAE and the pseudo-classifier, the framework empowers the pseudo-classifier to detect attacks autonomously, eliminating the need for manually preset detection thresholds, which are typical in DAE-based variants. Building on this foundation, DUCADF is developed by leveraging the consistency of data feature dimensions across substations and integrating horizontal federated learning with UCAD. This framework enables multiple substations to collaboratively train their local UCAD models while keeping their original data private, thereby enhancing detection performance and safeguarding data privacy. Experiments on the IEC 104 dataset demonstrate that UCAD achieves an F1 score of 0.9612, surpassing the most recent methods—DLSC, DAGMM, SLSDAE, and ATUAD—by 8.56 %, 14.61 %, 28.88 %, and 6.42 %, respectively, thus underscoring its substantial advantages in cyberattack detection.
Keywords: Smart grids; IEC 60870-5-104; Cyberattack detection; Unsupervised method; Horizontal federated learning (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S0951832025006441
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:reensy:v:264:y:2025:i:pb:s0951832025006441
DOI: 10.1016/j.ress.2025.111444
Access Statistics for this article
Reliability Engineering and System Safety is currently edited by Carlos Guedes Soares
More articles in Reliability Engineering and System Safety from Elsevier
Bibliographic data for series maintained by Catherine Liu ().