<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Smart Electrical grids Under the Lens of Adversarial Attacks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Fatemeh Nazary</string-name>
          <email>fatemeh.nazary@poliba.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yashar Deldjoo</string-name>
          <email>yashar.deldjoo@poliba.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tommaso Di Noia</string-name>
          <email>tommaso.dinoia@poliba.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Carmelo Ardito</string-name>
          <email>carmelo.ardito@poliba.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eugenio Di Sciascio</string-name>
          <email>eugenio.disciascio@poliba.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Politecnico di Bari</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Italy</string-name>
        </contrib>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <fpage>29</fpage>
      <lpage>31</lpage>
      <abstract>
        <p>The detection of faults in smart electrical grids is a crucial task as it can have significant economic and societal impacts. In recent years, data-driven approaches have been adopted for various smart grid applications, including fault detection and load forecasting. This study aims to explore the challenges associated with ensuring the security of machine learning (ML) applications in the smart grid context. Despite the widespread use of data-driven algorithms, their robustness and security have not been thoroughly examined in all power grid applications. Our research demonstrates that deep neural network methods used in smart grids are vulnerable to adversarial perturbations. Additionally, we highlight the weaknesses of current ML algorithms in smart grids to various adversarial attacks by examining fault localization and type classification problems.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The World Health Organization reports that
inadequate infrastructure security causes at least one in
every ten patients sufering. Power grid networks
are a critical energy infrastructure [1], and their
security is essential to societal well-being.
Electrical faults in power grids can be caused by natural
disasters such as lightning, tree or bird contact, or
aging of equipment, which may result in large-scale
cascading efects that could harm the country’s
economy and security [2]. Therefore, detecting and
classifying faults with high accuracy is crucial to
the power supply industry and the overall security
of critical energy infrastructure.</p>
      <p>The paper focuses on fault classification and their
occurring area in power grids. Fault zone
classification (FZC) aims to find the zone where the fault
has occurred, while fault type classification (FCT)
vious literature has utilized a combination of tools
and techniques from electrical engineering, signal
processing, and artificial intelligence (AI) [ 3, 4, 5]
to solve the above fault classification tasks. Among
them, machine-learned (ML) models, notably those
based on deep learning, have witnessed an increase
in their acceptance in the current infrastructure of
power systems, owing to the huge amounts of data
cause the ML model employed in the SCADA’s fault
classification system to misclassify an input sample
into a known but erroneous class. To accomplish
aims to determine the class of the fault type. Pre- integrity, or availability of smart grids (SGs).
Advercan cause greater damage and sufering, so as to the adversarial prediction  ( x0 + ) and the
misprolong the expedition and recovery efort. These classification label   .
examples highlight the potential catastrophic harm
that adversarial attacks can cause if left unchecked
due to their often impenetrable nature [6]. Definition 2 (Untargeted attack). The goal of the</p>
      <p>The key contributions of this study include in- attacker in an untargeted attack is to cause any
vestigating the impact of adversarial attacks on mis-classification to maximize the loss between the
several fault classification problems, namely FTC adversarial prediction and the legitimate label  0
and FZC, and their combination, analyzing
adversseatrtiainlgasttaancdkspebryfoerxmaimngineimngpidriicfearelnetxpexerpiemreimntesnotanl a ∶m‖a‖≤x ℒ ( ( x0 + ; ),  0) (2)
widely adopted dataset based on the IEEE-13 test as such, it is clear that the attacker’s objective
node feeder. In summary, the importance of this in this scenario is to cause any mis-classification,
research lies in its potential to improve the overall regardless of the specific type.
security of power grids and their impact on society.</p>
      <p>We highlight the critical role that power grids play
in people’s lives and societal well-being, emphasiz- 3. Approach
ing that their instability or inadequate distribution
of electrical energy can directly afect people’s lives. We have conducted adversarial attacks against two
By improving the fault classification process and machine-learned fault classification tasks in smart
mitigating the impact of adversarial attacks, the electrical grids, which serve as the core attack
tarresearch can enhance smart grids’ robustness, and get. The attacks are conducted as non-targeted
eficiency, thus contributing to a more sustainable and targeted. This section discusses our strategy in
application of AI in power grid systems. depth.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Problem definition</title>
      <p>Adversarial task. Given a training dataset  of 
pairs (,  ) ∈  ×  , where  is the input sample,
and  is its corresponding class label, the
classification problem is formulated as finding a target
function   ∶  →  that can predict the class
label  surroundings the input sample  , where  is
the model parameter. The goal of the adversarial
attacks is to find a non-random perturbation  to
produce an adversarial example   =  +  such
that it can induce an inaccurate detection (e.g.,
mis-classification). The methods by which  is
learned are referred to as adversarial attacks, and
they can be either targeted or untargeted.
Definition 1 (Targeted adversarial attack). Given
a trained classifier  ( x; ) and a test instance from
the dataset x0 ∈  where  ( x0; ) =  0, the goal of a
targeted attack is to perturb x0 with a small budget
‖ ‖ ≤  such that the perturbed sample would be
mis-classified to the target label   ≠  0, referred
to as the mis-classification label. The problem can
be represented using an unconstrained optimization
problem formulation
min
∶ ‖ ‖≤
ℒ ( ( x0 + ; ),   )
(1)</p>
      <sec id="sec-2-1">
        <title>One can note that in this case, here the attacker aims to minimize the distance (loss) between</title>
        <sec id="sec-2-1-1">
          <title>3.1. Fault Classification in Smart Grids.</title>
        </sec>
      </sec>
      <sec id="sec-2-2">
        <title>We consider diferent multi-class classification prob</title>
        <p>lems pertinent to fault prediction in smart grids
with  ≥ 2 classes in this paper, in which  is the
input space and  = {1, 2, ...,  } the output space.
Our problem showcases two diferent target labels
for the problems at hand (i) fault location and (ii)
fault type. Therefore, the main task is split into
three sub-tasks:
1. Fault location classification (FLC): with  =
4 the task aims to classify a given signal into
its originating zone as shown in Table 1.
2. Fault type classification (FTC): with  = 11
the task aims to classify a given signal into
one of the predefined fault types as shown in
Table 1.
3. Joint location and type classification
(FLC+FTC)  = 44 integrating the both
fault class labels in the preceding cases;
where, (1) and (2) are explicitly contained in the
dataset, while (3) is derived by combing each
different possible combination of task 1 and task 2.
Thus, we can state that the joint task is expected
to be a more complex task compared to the former.</p>
        <sec id="sec-2-2-1">
          <title>3.2. Adversary threat model.</title>
        </sec>
        <sec id="sec-2-2-2">
          <title>4.1. Datasets</title>
          <p>Before examining the efects of adversarial attacks, For data collection and creating the training dataset
we explain the adversary threat model. The adver- for the fault classification in smart grids, similar
sary’s assumption entails: to [7, 8, 3] we used short-circuit faults that were
injected to IEEE-13 node test feeder using the
MAT• Adversary goal. The adversary is interested LAB Simulink environment. The node feeder
conin mis-classifying smart-grid fault classifica- tained renewable energies such as wind turbine and
tion tasks in each of the three FZC, FTC, photovoltaic system. We divided the network into
and joint sub-tasks through the use of two four zones, adjacent to four load flow buses
(numtypes of attacks: untargeted vs. targeted. In bered via 671,633, 675, and 680, see [9]), and
meathe latter situation, the purpose may be to sured the three-phase voltage signals.
produce more dificult-to-reach or dificult- We applied 11 short circuit faults to four specified
to-resolve (mis-classification) labels in order zone in the IEEE-13 network. These faults cover
to obstruct or delay the recovery of the task. every conceivable short-circuit faults and are
sum• Adversary knowledge. Our assumption is marized in Table 1. To ensure having a suficient
white-box setting where the attacker knows number of samples in the training dataset, each
all of the parameters of the feature extrac- fault was generated with 22 diferent fault
resistion model used to estimate the perturbation tance values [7, 10]. Our final training dataset
conhe/she wants to estimate. In addition, the tained 4 (zones)×11 (faults)×22 (resistance values)×
attacker has full access to the input features 4 (measured locations) = 3872 samples. Note that
that would be changed as a result of the at- we collected (measured) signals from 4 locations
tack. The attacker can also obtain the class regardless of locations, and after feature extraction
labels in targeted attack scenarios. (see below) stacked them together to create a
superSimilar to other works in classification, we evaluate vector which was fed into the neural network ML
the efects of targeted and untargeted attacks as model.
the reduction in classification accuracy. To inject faults, the entire simulation duration
was carried out in the time interval  = [0.0 − 0.022] ,
with the network frequency 60  , sampling time
4. Experimental Evaluation 0.00001. Each fault with every resistance was
applied at a certain start time  = 0.01 and revoked at
We analyzed adversarial attacks against smart grids a specified end time  = 0.02 , hence   = [0.01 − 0.02]
on a dataset acquired from IEEE-13 test node feeder. represents the faulty duration and  ℎ = [0 − 0.01]
repIn the following, we begin by presenting the experi- resents the healthy duration. For the signal type,
mental setup; afterward, we discuss the experimen- in this work we only relied on (three-phase)
volttal results. age signals and kept investigation of other possible
signals such as current for future investigation.</p>
          <p>The time series signals were represented as
   = 0.4569
, and    +    = 0.4543
. Best results for C&amp;W
were obtained under ℓ
∞ for untargeted attacks and
ℓ2 for targeted attacks. Note that the starting point of noise power for all attacks and random noise is 0.001.
discrete features retrieved from the time,
fre</p>
        </sec>
      </sec>
      <sec id="sec-2-3">
        <title>The second category of adversarial attacks is Car</title>
        <p>quency,
and
wavelet domains using temporal,
lini and Wagner. It is a powerful attack model for
Discrete Fourier transform (DFT), and Discrete
ifnding adversarial perturbation under three various
wavelet transform (DWT) analysis, as previously
explored [11, 12]. Afterwards, we extract from each
distance metrics (ℓ0, ℓ2, ℓ∞). Its key insight is similar
to L-BFGS [? ] as it transforms the constrained
domain, six features related to energy, maximum, as
optimization problem into an empirically chosen
well as the 4-th moment of their probability distribu- loss function to form an unconstrained optimization
tion functions (PDFs) (e.g., mean, norm, skewness,
problem as
tions and BIM is the iterative version of the FGSM. ral network, a Multi-layer Perceptron (MLP), for
kurtosis). The overall length of the feature vectors
utilized in the learning model is 48, divided into</p>
      </sec>
      <sec id="sec-2-4">
        <title>6 (time) + 6 (DFT) + 36 (DWT), where we employed</title>
      </sec>
      <sec id="sec-2-5">
        <title>6 (coeficients)</title>
        <p>× 6 (aggregation operations) for the</p>
      </sec>
      <sec id="sec-2-6">
        <title>DWT features, resulting in a 36-dimensional feature vector.</title>
        <sec id="sec-2-6-1">
          <title>4.2. Adversarial Attacks</title>
        </sec>
      </sec>
      <sec id="sec-2-7">
        <title>The performed attacks consist of the fast gradient</title>
        <p>sign method (FGSM), basic iterative method (BIM)
[13], and Carlini and Wagner (C&amp;W) [14]. FGSM is
a white-box attack that employs the sign of the loss
function’s gradient to learn adversarial
perturbaFormally, in the untargeted scenario, FGSM aims to
generate a perturbation that maximizes the training
loss formulated as</p>
        <p>=  ⋅ sign(▽ ℓ( (; ),  ))
where  (perturbation level) represents the attack
strength and ▽ is the gradient of the loss function
w.r.t. input sample x,  is the legitimate label and
sign(.)is the sign operator. A targeted FGSM attack
is, instead, formulated as</p>
        <p>= − ⋅ sign(▽ ℓ( (; ),   ))
in which the goal of the attacker is maximize the
conditional probability (  |) for a given input  .
(3)
(4)</p>
        <p>min (‖ ‖ +  ⋅ ℎ( x + ,   ))
(5)
where ℎ(⋅) is the candidate loss function.</p>
      </sec>
      <sec id="sec-2-8">
        <title>The C&amp;W attack has been used with several</title>
        <p>been reported to be most efective [ 14].
norm-type constraints on perturbation ℓ0, ℓ2, ℓ∞
among which the ℓ2 and ℓ∞-bound constraint has</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>5. Experiments and Results</title>
      <sec id="sec-3-1">
        <title>5.1. Explored Machine-Learnings Tasks</title>
        <sec id="sec-3-1-1">
          <title>Model and training details. We trained a deep neu</title>
          <p>the three classification tasks specified in Section
3.1
The model is made of an input layer, two dense
layers, and an output layer. The latter is the only
layer that varies throughout the three tasks, as its
number of neurons must correspond to the number
of output classes in each task. The tasks require
separate training phases, which all take place with the
same settings, using 500 Epochs, Adam Optimizer,
and a fixed learning rate of 10e-3 with a batch size
of 20. The hyper-parameters were obtained after
ifne-tuning.</p>
        </sec>
        <sec id="sec-3-1-2">
          <title>Implementation of the attacks. We employed the IBM</title>
        </sec>
        <sec id="sec-3-1-3">
          <title>Adversarial Robustness Toolbox to perform</title>
          <p>the adversarial attacks due to its full compatibility
with Keras and its wide ofer of suitable attacks for a attacks varies across smart grid fault prediction
deep learning model. The performed attacks consist tasks, and whether the complexity of these tasks
of FGSM, multi-step (BIM), and C&amp;W attacks. impacts the performances obtained.
These attacks were performed in both untargeted We start this by assessing the absolute power of
and targeted scenarios. attacks across three tasks. At  = 0.04 the power
of attacks FGSM-untrg, BIM-untargeted,
C&amp;W5.2. Results untargeted, FGSM-targeted, BIM-targeted,
C&amp;Wtargeted is equal to 0.166, 0.160, 0.281, 0.271, 0.265,
Evaluation Questions. To obtain a better under- and 0.631 respectively. Thus, w.r.t the base ML
standing of the efectiveness of the examined adver- model (0.713), we may remark a relative
degradasarial attacks against fault classification systems in tion of 329% , 345% , 153% , 163%, 168%, and 13%.
SGs, through the course of experiments, we intend The equivalent relative degrading power of attacks
to answer the following evaluation questions. for FTC task are 396%, 756%, 175%, 374%, 108%,
17% and for the joint FZC+FTC task include 339%,
RQ 1: Against the three faults classification tasks 1408%, 226%, 779%, 206%, 4.9%. Thus, the
averin SGs presented in Section 3.1, how efective age degradation power for (untargeted, targeted)
are adversarial perturbations generated by goals are, FZC=(275.6%, 114.6%), FTC=(442.3%,
diferent adversarial attack methods (FGSM, 166.3%), FTC=(657.6%, 329.9%). We might notice
BIM, and C&amp;W) compared to random noise? that both untargeted and targeted attack models
RQ 2: How does the performance of attacks change work better (are stronger) as the task gets more
when we alternate between the attack goals? complicated and this is true for both types of tasks.</p>
          <p>In summary, the result of empirical evaluation
Discussion. We begin our experimental study by shows that the complexity of the fault prediction
addressing the above evaluation questions. tasks (in SGs) impacts the efectiveness of the
ex</p>
          <p>Answer to RQ 1. This research question veri- plored adversarial attacks, meaning the attacks are
ifes whether the application of adversarial attacks better able to manipulate the decision outcomes
against fault classification systems (FZC, FTC, and according to FZC+FTC&gt;FTC&gt;FZC.
joint) has a sensible impact on the behavior of the
ML models. As shown in Figure 2, all investigated 6. Conclusion
adversarial attacks FGSM, BIM, and C&amp;W have
a much greater impact than random perturbation This work examines the security of fault
classificaacross three tasks and under diferent noise levels tion systems in smart electrical grids powered by
( ), with the efect growing as the perturbation bud- deep neural networks. Minor adversarial
perturbaget increases. Comparing the strength of the three tions can reduce the quality of fault classification
adversarial attack models, BIM is the strongest in systems, highlighting the need for further studies
all tasks. For instance, in the case of (untargeted, to defend against adversarial training and detection
FTC) with an attack budget (noise level) equal to methods (see [15]). Visual explanation of such
ad = 0.04 , BIM untargeted adversarial attack accu- versarial threats [16] would constitute another
interracy reaches 0.05, whilst FGSM and C&amp;W reach esting direction, which future work will investigate.
0.09 and 0.16, respectively, under the same condition. Additionally, multi-party computation techniques,
The efect of attack target (targeted vs. untargeted) such as federated learning, could be used to develop
is stronger on BIM and C&amp;W than on FSGM. For privacy-preserving fault-prediction systems [17, 18],
example, for the FTC ( = 0.04 ), the classification allowing separate zones to train models without
accuracy is 0.21 vs. 0.05 (BIM-untargeted vs. BIM- exchanging data with a central server.
targeted), while for FGSM the corresponding
difference is only 0.1 vs. 0.09 (FGSM-untargeted vs. References
FGSM-targeted).</p>
          <p>In summary, the attacks’ powers might be con- [1] I. Onyeji, M. Bazilian, C. Bronk, Cyber
setrasted according to BIM&gt;C&amp;W&gt;FGSM (the first curity and critical energy infrastructure, The
being the strongest). The lone exception is C&amp;W- Electricity Journal 27 (2014) 52–60.
targeted, which deviates from the trend and per- [2] E. D. Santis, A. Rizzi, A. Sadeghian, A
forms poorly, while C&amp;W-untargeted performs well cluster-based dissimilarity learning approach
in all the explored scenarios. for localized fault classification in smart grids,</p>
          <p>Answer to RQ 2. This research question verifies Swarm Evol. Comput. 39 (2018) 267–278.
how much the performance of diferent adversarial doi:10.1016/j.swevo.2017.10.007.
[3] S. Shi, B. Zhu, S. Mirsaeidi, X. Dong, Fault [13] A. Kurakin, I. J. Goodfellow, S. Bengio,
Adverclassification for transmission lines based on sarial examples in the physical world, in: 5th
group sparse representation, IEEE Trans. International Conference on Learning
RepreSmart Grid 10 (2019) 4673–4682. doi:10.1109/ sentations, ICLR 2017, Toulon, France, April
TSG.2018.2866487. 24-26, 2017, Workshop Track Proceedings,
[4] S. Das, S. N. Ananthan, S. Santoso, Estimating 2017.</p>
          <p>zero-sequence line impedance and fault resis- [14] N. Carlini, D. A. Wagner, Defensive distillation
tance using relay data, IEEE Trans. Smart is not robust to adversarial examples, CoRR
Grid 10 (2019) 1637–1645. doi:10.1109/TSG. abs/1607.04311 (2016). arXiv:1607.04311.
2017.2774179. [15] Y. Deldjoo, T. D. Noia, F. A. Merra, A
sur[5] N. Sapountzoglou, J. Lago, B. De Schut- vey on adversarial recommender systems: from
ter, B. Raison, A generalizable and sensor- attack/defense strategies to generative
adverindependent deep learning method for fault sarial networks, ACM Computing Surveys
detection and location in low-voltage distribu- (CSUR) 54 (2021) 1–38.</p>
          <p>tion grids, Applied Energy 276 (2020) 115299. [16] C. Ardito, Y. Deldjoo, T. Di Noia, E. Di
Scias[6] L. Cui, Y. Qu, L. Gao, G. Xie, S. Yu, Detect- cio, F. Nazary, Visual inspection of fault type
ing false data attacks using machine learning and zone prediction in electrical grids using
techniques in smart grid: A survey, J. Netw. interpretable spectrogram-based cnn modeling,
Comput. Appl. 170 (2020) 102808. doi:10.1016/ Expert Systems with Applications 210 (2022)
j.jnca.2020.102808. 118368.
[7] M. Shafiullah, M. A. Abido, S-transform based [17] V. W. Anelli, Y. Deldjoo, T. D. Noia, A.
FerFFNN approach for distribution grids fault rara, Towards efective device-aware federated
detection and classification, IEEE Access 6 learning, in: International Conference of the
(2018) 8080–8088. doi:10.1109/ACCESS.2018. Italian Association for Artificial Intelligence,
2809045. Springer, 2019, pp. 477–491.
[8] T. S. Abdelgayed, W. G. Morsi, T. S. Sidhu, [18] V. W. Anelli, Y. Deldjoo, T. D. Noia, A.
FerA new harmony search approach for optimal rara, Prioritized multi-criteria federated
learnwavelets applied to fault classification, IEEE ing, Intelligenza Artificiale 14 (2020) 183–200.
Trans. Smart Grid 9 (2018) 521–529. doi:10. doi:10.3233/IA-200054.</p>
          <p>1109/TSG.2016.2555141.
[9] A. K. Onaolapo, K. T. Akindeji, E. Adetiba,</p>
          <p>Simulation experiments for faults location in
smart distribution networks using ieee 13 node
test feeder and artificial neural network, in:
Journal of Physics: Conference Series, volume
1378, IOP Publishing, 2019, p. 032021.
[10] M. S. Hossan, B. H. Chowdhury, Data-driven
fault location scheme for advanced distribution
management systems, IEEE Trans. Smart Grid
10 (2019) 5386–5396. doi:10.1109/TSG.2018.</p>
          <p>2881195.
[11] C. Ardito, Y. Deldjoo, E. D. Sciascio,</p>
          <p>F. Nazary, Revisiting security threat on smart
grids: Accurate and interpretable fault
location prediction and type classification, in:
A. Armando, M. Colajanni (Eds.),
Proceedings of the Italian Conference on
Cybersecurity, ITASEC 2021, All Digital Event, April 7-9,
2021, volume 2940 of CEUR Workshop
Proceedings, CEUR-WS.org, 2021, pp. 523–533.
[12] K. A. Saleh, A. Hooshyar, E. F. El-Saadany,</p>
          <p>Hybrid passive-overcurrent relay for detection
of faults in low-voltage DC grids, IEEE Trans.</p>
          <p>Smart Grid 8 (2017) 1129–1138. doi:10.1109/
TSG.2015.2477482.</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>