English

An Approach to Abstract Multi-stage Cyberattack Data Generation for ML-Based IDS in Smart Grids

Cryptography and Security 2023-12-22 v1 Systems and Control Systems and Control

Abstract

Power grids are becoming more digitized, resulting in new opportunities for the grid operation but also new challenges, such as new threats from the cyber-domain. To address these challenges, cybersecurity solutions are being considered in the form of preventive, detective, and reactive measures. Machine learning-based intrusion detection systems are used as part of detection efforts to detect and defend against cyberattacks. However, training and testing data for these systems are often not available or suitable for use in machine learning models for detecting multi-stage cyberattacks in smart grids. In this paper, we propose a method to generate synthetic data using a graph-based approach for training machine learning models in smart grids. We use an abstract form of multi-stage cyberattacks defined via graph formulations and simulate the propagation behavior of attacks in the network. Within the selected scenarios, we observed promising results, but a larger number of scenarios need to be studied to draw a more informed conclusion about the suitability of synthesized data.

Keywords

Cite

@article{arxiv.2312.13737,
  title  = {An Approach to Abstract Multi-stage Cyberattack Data Generation for ML-Based IDS in Smart Grids},
  author = {Ömer Sen and Philipp Malskorn and Simon Glomb and Immanuel Hacker and Martin Henze and Andreas Ulbig},
  journal= {arXiv preprint arXiv:2312.13737},
  year   = {2023}
}
R2 v1 2026-06-28T13:58:32.938Z