Main Article Content
A Secured Low-Latency Cyber-Physical Attack Detection and Mitigation Scheme
Abstract
The transition to smart grids integrated with information and communication technology (ICTs) for the Special Protection Group (SPG) not only increases operational efficiency but also creates opportunities for advanced Cyber-Physical Attacks (CPAs). These threats are often stealthy, hard to detect with current security measures, and can quickly evade machine learning (ML) approaches. This paper presents a framework designed for real-time detection and mitigation of CPAs in modern grids. The paper uses a hybrid feature-engineering method that combines physical power information from phasor measurement units (PMUs) and Supervisory Control and Data Acquisition (SCADA) with cyber-side network logs. Using statistical and time-series analysis on this fused information, the authors detected subtle evidence of malicious activity. The key to the developed scheme is a stacking-based ensemble learning framework that integrates XGBoost, Support Vector Machine, and Convolutional Neural Network models to ensure high detection accuracy and reliability. The dataset was divided into 80% for training and 20% for testing; experimental evaluation showed a high detection rate of 96% and a low false positive rate of 1.5% for False Data Injection (FDI), Denial of Service (DoS), and Replay attacks. The framework also provides low detection latency and high throughput, supporting real-time operation. Low latency includes Data acquisition, Data cleaning, Normalization, Synchronization, and windowing. The scheme not only detects threats but enable a context-aware response module to provide real-time isolation of components or rerouting of power in response. This keeps the grid stable even during an attack. The paper presents an advanced AI-powered, real-time defense against increasingly sophisticated cyber-physical threats.



