{"title":"电网拓扑攻击的分布式检测与隔离","authors":"James Weimer, S. Kar, K. Johansson","doi":"10.1145/2185505.2185516","DOIUrl":null,"url":null,"abstract":"This paper addresses the issue of detecting and isolating topology attacks in power networks. A topology attack, unlike a data attack and power injection attack, alters the physical dynamics of the power network by removing bus interconnections. These attacks can manifest as both cyber and physical attacks. A physical topology attack occurs when a bus interconnection is physically broken, while a cyber topology attack occurs when incorrect information about the network topology is transmitted to the system estimator and incorporated as the truth. To detect topology attacks, a stochastic hypothesis testing problem is considered assuming noisy measurements are obtained by periodically sampling a dynamic process described by the networked swing equation dynamics, modified to assume stochastic power injections. A centralized approach to network topology detection and isolation is introduced as a two-part scheme consisting of topology detection followed by topology isolation, assuming a topology attack exists. To address the complexity issues arising with performing centralized detection in large-scale power networks, a decentralized approach is presented that uses only local measurements to detect the presence of a topology attack. Simulation results illustrate that both the centralized and decentralized approaches accurately detect and isolate topology attacks.","PeriodicalId":203753,"journal":{"name":"International Conference on High Confidence Networked Systems","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-04-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"44","resultStr":"{\"title\":\"Distributed detection and isolation of topology attacks in power networks\",\"authors\":\"James Weimer, S. Kar, K. Johansson\",\"doi\":\"10.1145/2185505.2185516\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper addresses the issue of detecting and isolating topology attacks in power networks. A topology attack, unlike a data attack and power injection attack, alters the physical dynamics of the power network by removing bus interconnections. These attacks can manifest as both cyber and physical attacks. A physical topology attack occurs when a bus interconnection is physically broken, while a cyber topology attack occurs when incorrect information about the network topology is transmitted to the system estimator and incorporated as the truth. To detect topology attacks, a stochastic hypothesis testing problem is considered assuming noisy measurements are obtained by periodically sampling a dynamic process described by the networked swing equation dynamics, modified to assume stochastic power injections. A centralized approach to network topology detection and isolation is introduced as a two-part scheme consisting of topology detection followed by topology isolation, assuming a topology attack exists. To address the complexity issues arising with performing centralized detection in large-scale power networks, a decentralized approach is presented that uses only local measurements to detect the presence of a topology attack. Simulation results illustrate that both the centralized and decentralized approaches accurately detect and isolate topology attacks.\",\"PeriodicalId\":203753,\"journal\":{\"name\":\"International Conference on High Confidence Networked Systems\",\"volume\":\"12 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-04-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"44\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Conference on High Confidence Networked Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/2185505.2185516\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on High Confidence Networked Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2185505.2185516","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Distributed detection and isolation of topology attacks in power networks
This paper addresses the issue of detecting and isolating topology attacks in power networks. A topology attack, unlike a data attack and power injection attack, alters the physical dynamics of the power network by removing bus interconnections. These attacks can manifest as both cyber and physical attacks. A physical topology attack occurs when a bus interconnection is physically broken, while a cyber topology attack occurs when incorrect information about the network topology is transmitted to the system estimator and incorporated as the truth. To detect topology attacks, a stochastic hypothesis testing problem is considered assuming noisy measurements are obtained by periodically sampling a dynamic process described by the networked swing equation dynamics, modified to assume stochastic power injections. A centralized approach to network topology detection and isolation is introduced as a two-part scheme consisting of topology detection followed by topology isolation, assuming a topology attack exists. To address the complexity issues arising with performing centralized detection in large-scale power networks, a decentralized approach is presented that uses only local measurements to detect the presence of a topology attack. Simulation results illustrate that both the centralized and decentralized approaches accurately detect and isolate topology attacks.