IP Library › Granted Patent US 12,513,182
Granted Patent B2
US 12,513,182 · App. 18/708,700 · Granted Dec 30, 2025

Modeling of adversarial artificial intelligence in blind false data injection against AC state estimation in smart grid security, safety and reliability

Inventors: Emmanuel Thepie Fapi (Cote-Saint-Luc, CA); Moshfeka Rahman (Montreal, CA); Jun Yan (Montreal, CA)
Assignee: Telefonaktiebolaget LM Ericsson (Publ)
H04L63/1433G06N3/09G06N3/094
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,182
App. No.
18/708,700
Granted
Dec 30, 2025
Kind
B2
Abstract

Computer-implemented methods and systems for training an adversarial neural network to simulate a stealthy blind false data injection attack on a cyber physical system are provided. Supervised learning is used to generate an initial attack vector, by an adversarial attack generation model, based on inferred grid topology and historical measurements. A final attack vector is generated, by an adversarial verification model, based on a filtered subset of the initial attack vector utilizing a substitute bad data detection threshold, wherein the final attack vector enables creation of a counter measure.

Claims (38)

1 . A computer-implemented method for training an adversarial neural network to simulate a stealthy blind false data injection attack on a cyber physical system, the method comprising:

using supervised learning to generate an initial attack vector, by an adversarial attack generation model, based on inferred grid topology and historical measurements, the adversarial attack generation model generating a mapping representing the inferred grid topology and the adversarial neural network being trained by the adversarial attack generation model, with a subset of historical measurements as input and all historical measurements as output;

determining, by an adversarial verification model, a substitute bad data detection threshold by obtaining pseudo-estimated measurements from the adversarial neural network utilizing the subset of the historical measurements as input;

generating a final attack vector, by the adversarial verification model, based on a filtered subset of the initial attack vector utilizing the substitute bad data detection threshold, the final attack vector enabling of a counter measure, the final attack vector including malicious data and the counter measure including storing final attack vectors in a security catalog for security purposes;

classifying, by the adversarial verification model, data in the initial attack vector into abnormal data and malicious data; and

generating and sending updated security parameters to the cyber physical system based on the counter measure.

2 . The method of claim 1 , wherein the historical measurements include one or more of voltage angle, magnitudes, active power flows, reactive power flows, and generated power.

3 . The method of claim 1 , further comprising selecting input data, by the adversarial attack generation model, for training the adversarial neural network, the selected input data including a subset of the historical measurements based on a state to be estimated for the cyber physical system.

4 . The method of claim 1 , further comprising selecting input data, by the adversarial attack generation model, for training the adversarial neural network, the selected input data including a subset of the historical measurements, wherein the subset includes voltage angles and magnitudes.

5 . The method of claim 1 , further comprising generating, by the adversarial attack generation model, intended state deviation using a random gaussian distribution.

6 . The method of claim 1 , further comprising using supervised learning, by the adversarial attack generation model, to generate the initial attack vector, wherein input data for training the adversarial neural network includes a subset of the historical data and an intended state deviation.

7 . The method of claim 1 , wherein the adversarial neural network comprises four layers.

8 . The method of claim 1 , wherein the adversarial neural network utilizes a Tan-Sigmoid activation function to infer grid topology.

9 . The method of claim 1 , wherein determining the substitute bad data detection comprises:

determining the filtered subset of the initial attack vector by filtering the initial attack vector utilizing the substitute bad data detection threshold.

10 . The method of claim 1 , wherein determining the substitute bad data detection threshold comprises obtaining pseudo-estimated measurements from the adversarial neural network utilizing a subset of the historical measurements as input.

11 . The method of claim 1 , wherein determining the substitute bad data detection threshold comprises obtaining an error vector determined by a difference between the historical measurements and the pseudo-estimated measurements.

12 . The method of claim 1 , wherein determining the substitute bad data detection threshold comprises setting a scalar factor for adjusting filtering strength.

13 . The method of claim 1 , further comprising filtering, by the adversarial verification model, the initial attack vector utilizing a substitute bad data detection threshold and a normalized residual vector.

14 . The method of claim 1 , wherein the counter measure is based on at least one of a signature detection mechanism, an anomaly detection mechanism, and an intrusion detection mechanism.

15 . A non-transitory computer readable medium or media containing instructions for executing a method for training an adversarial neural network to simulate a stealthy blind false data injection attack on a cyber physical system, the method comprising:

using supervised learning to generate an initial attack vector, by an adversarial attack generation model, based on inferred grid topology and historical measurements, the adversarial attack generation model generating a mapping representing the inferred grid topology and the adversarial neural network being trained by the adversarial attack generation model, with a subset of historical measurements as input and all historical measurements as output;

determining, by an adversarial verification model, a substitute bad data detection threshold by obtaining pseudo-estimated measurements from the adversarial neural network utilizing the subset of the historical measurements as input;

generating a final attack vector, by the adversarial verification model, based on a filtered subset of the initial attack vector utilizing the substitute bad data detection threshold, the final attack vector enabling creation of a counter measure, the final attack vector including malicious data and the counter measure including storing final attack vectors in a security cataloge for security purposes;

classifying, by the adversarial verification model, data in the initial attack vector into abnormal data and malicious data; and

generating and sending updated security parameters to the cyber physical system based on the counter measure.

16 . A system for training an adversarial neural network to simulate a stealthy blind false data injection attack on a cyber physical system, the system comprising:

a database connected to a network, configured for receiving and storing historical measurements and attack vectors; and

one or more processors and memory, the memory containing instructions executable by the one or more processors whereby the system is operative to:

use supervised learning to generate an initial attack vector, by an adversarial attack generation model, based on inferred grid topology and historical measurements, the adversarial attack generation model generating a mapping representing the inferred grid topology and the adversarial neural network being trained by the adversarial attack generation model, with a subset of historical measurements as input and all historical measurements as output;

determine, by the adversarial verification model, a substitute bad data detection threshold by obtaining pseudo-estimated measurements from the adversarial neural network utilizing the subset of the historical measurements as input; and

generate a final attack vector, by the adversarial verification model, based on a filtered subset of the initial attack vector utilizing the substitute bad data detection threshold, the final attack vector enabling creation of a counter measure, the final attack vector including malicious data and wherein the counter measure includes storing final attack vectors in a security catalog for security purposes;

classify, by the adversarial verification model, data in the initial attack vector into abnormal data and malicious data; and

generate and sending updated security parameters to the cyber physical system based on the counter measure.

17 . The system of claim 16 , wherein implementing the counter measure is based on at least one of a signature detection mechanism, an anomaly detection mechanism, and an intrusion detection mechanism.

18 . The system of claim 16 , further comprising generating and sending updates for the adversarial attack generation model.

19 . The system of claim 16 , further comprising generating and sending updates for the adversarial verification model.

20 . The system of claim 16 , further comprising training the adversarial neural network with the classified data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2024
From: THEPIE FAPI, EMMANUEL; RAHMAN, MOSHFEKA; YAN, JUN
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 067368/0942 →
Continuity (1)
Related Publication 20250023902A1 · Jan 16, 2025
References Cited (30)
US 11983271B2 · dos Santos Silva · 2024 [cited by examiner]
US 20210157912A1 · Kruthiveti Subrahmanyeswara Sai · 2021 [cited by examiner]
US 20220156376A1 · dos Santos Silva · 2022 [cited by examiner]
US 20220309229A1 · Walters · 2022 [cited by examiner]
US 20220335335A1 · Basak · 2022 [cited by examiner]
US 20230386044A1 · Kundeti · 2023 [cited by examiner]
US 20250094571A1 · Taghia · 2025 [cited by examiner]
International Search Report and Written Opinion dated Jul. 11, 2022 for International Application No. PCT/IB2021/060429 filed Nov. 11, 2021, consisting of 9 pages. [cited by applicant]
E. Wang et al.; Security Issues and Challenges for Cyber Physical System; 2010 IEEE/ACM International Conference on Green Computing and Communications & 2010 IEEE/ACM International Conference on Cyber, Physical and Soci… [cited by applicant]
A. Rahman et al.; False Data Injection Attacks Against Nonlinear State Estimation in Smart Power Grids; 2013 IEEE Power & Energy Society General Meeting; Jul. 2013, consisting of 5 pages. [cited by applicant]
A. Sargolzaei et al.; Detection and Mitigation of False Data Injection Attacks in Networked Control Systems; IEEE Transactions on Industrial Informatics, vol. 16, No. 6; Jun. 2020, consisting of 12 pages. [cited by applicant]
M. Hossain et al.; Cyber-physical security for on-going smart grid initiatives: a survey; IET Cyber-Physical Systems: Theory & Applications; IET Journals: The Institution of Engineering and Technology; vol. 5, Issue 3; … [cited by applicant]
H. He et al.; Cyber-Physical Attacks and Defenses in the Smart Grid: a survey; IET Cyber-Physical Systems: Theory & Applications; Dec. 1, 2016, consisting of 34 pages. [cited by applicant]
M. Esmalifalak et al.; Stealth False Data Injection using Independent Component Analysis in Smart Grid; Cyber and Physical Security and Privacy ; 2011 IEEE International Conference on Smart Grid Communications (IEEE Sma… [cited by applicant]
A. Anwar et al.; Modelling and Performance Evaluation of Stealthy False Data Injection Attacks on Smart Grid in the Presence of Corrupted Measurements; arXiv; May 20, 2016, consisting of 20 pages. [cited by applicant]
Z.H. Yu et al.; Blind False Data Injection Attack Using PCA Approximation Method in Smart Grid; IEEE Transactions on Smart Grid, vol. 6, No. 3; May 2015, consisting of 8 pages. [cited by applicant]
W.L.Chin et al.; Blind False Data Attacks Against AC State Estimation Based on Geometric Approach in Smart Grid Communications; IEEE Transactions on Smart Grid; vol. 9, No. 6; Nov. 2018, consisting of 9 pages. [cited by applicant]
B. Tang et al.; Detection of False Data Injection Attacks in Smart Grid under Colored Gaussian Noise; 2016 IEEE Conference on Communications and Network Security (CNS); Oct. 2016, consisting of 8 pages. [cited by applicant]
R.D. Zimmerman et al.; MATPOWER: Steady-State Operations, Planning, and Analysis Tools for Power Systems Research and Education; IEEE Transactions on Power Systems; vol. 26, No. 1; Feb. 2011, consisting of 8 pages. [cited by applicant]
M. Ozay et al.; Sparse Attack Construction and State Estimation in the Smart Grid: Centralized and Distributed Models; IEEE Journal on Selected Areas in Communications; vol. 31, No. 7; Jul. 2013, consisting of 13 pages. [cited by applicant]
H. Zhong et al.; A Novel Sparse False Data Injection Attack Method in Smart Grids with Incomplete Power Network Information; Hindawi Complexity; vol. 2018, Article ID 8503825; 2018, consisting of 17 pages. [cited by applicant]
H. Margossian et al.; Partial grid false data injection attacks against state estimation; International Journal of Electrical Power & Energy Systems; vol. 110; Sep. 2019, consisting of 7 pages. [cited by applicant]
A. Sawas et al.; Two-fold Intelligent Approach for Successful FDI Attack on Power Systems State Estimation; 2018 IEEE Electrical Power and Energy Conference (EPEC); Oct. 2018, consisting of 6 pages. [cited by applicant]
J. Liang et al.; Cyber Attacks on AC State Estimation: Unobservability and Physical Consequences; 2014 IEEE PES General Meeting/Conference & Exposition; Jul. 2014, consisting of 5 pages. [cited by applicant]
M.F. Moller; A Scaled Conjugate Gradient Algorithm for Fast Supervised Learning; Neural Networks, vol. 6, Issue 4; 1993, consisting of 9 pages. [cited by applicant]
M. Ashrafuzzaman et al.; Detecting Stealthy False Data Injection Attacks in the Smart Grid using Ensemble-based Machine Learning; ScienceDirect; Elsevier Computers & Security, vol. 97; Oct. 2020, consisting of 21 pages. [cited by applicant]
J. Li et al.; Toward Adversarial-Resilient Deep Neural Networks for False Data Injection Attack Detection in Power Grids; arXiv; Feb. 17, 2021, consisting of 12 pages. [cited by applicant]
M. Rahman et al.; Finding the Worse Case: Undetectable False Data Injection with Minimized Knowledge and Resource; 2019 IEEE Global Communications Conference (GLOBECOM); Dec. 2019, consisting of 7 pages. [cited by applicant]
O. Boyaci et al.; Graph Neural Networks Based Detection of Stealth False Data Injection Attacks in Smart Grids; arXiv; Oct. 10, 2021, consisting of 12 pages. [cited by applicant]
M. Rahman et al.; Multi-Objective Evolutionary Optimization for Worst-Case Analysis of False Data Injection Attacks in the Smart Grid; 2020 IEEE Congress on Evolutionary Computation (CEC); Jul. 2020, consisting of 8 pag… [cited by applicant]