Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?
Aug 2026· Science and Technology of Engineering, Chemistry and Environmental Protection· 0 citations
TL;DR
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
Abstract
This Extended Project Qualification investigates whether machine-learning-based anomaly detection systems introduce greater operational risk in automated smart grid protection controllers, that is, in latency and false-positive circuit-trip rates, than traditional regex-based and signature-based filtering. This project compares three detection methods, including Snort-based rule filtering, an Isolation Forest classifier, and an LSTM Autoencoder using a primary data based on an analysis of the bachirbarika Power System data, a testbed PMU and SCADA dataset consisting of 78,369 rows and 15 different attack scenarios with assistance provided by a review of peer-reviewed literature. Findings indicate that ML-based algorithms identify a significantly higher number of attacks compared to Snort in a setup where the attack is shown as a physical-state anomaly, not as an event on the network layer, but at the tradeoff of introducing a quantifiably higher false positive rate and, in the case of the Isolation Forest, a very great curiousness of inference. LSTM Autoencoder has a more refined portrait with similar accuracy on detection at a lower latency to the baseline of the rule-based. The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers. All the differences in the latencies were statistically significant, as tested with Mann-Whitney U at p < 0.001.
The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.
A hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring is presented, providing initial evidence of generalization to one held-out attack family but should not be interpreted as proof of...
Muath A. Obaidat, Meryem Abouali, Aneeza Shakeel· Italian National Conference...· 0 citations
SA-IDS is proposed, a self-supervised and adaptive intrusion detection framework designed for resource-constrained IIoT edge devices that leverages contrastive self-supervised learning to learn robust representations of benign telemetry data without requiring labeled attacks.
The revised framework extends this four-layer pipeline by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements.
A. Havy, Muhammad Faishol Amrulloh· Jurnal Riset Informatika· 0 citations
The proposed suggested system proves that ensemble learning based on the Random Forest along with optimized feature selection can increase the reliability of cyber attack detection and computational efficiency to a considerable extent.
Nirmal Kumar Jingar, Cheema Priyanka, A. Thaseen· 0 citations
A proprietary methodology for identifying LOLBin abuse in Windows environments, based on telemetry collected by Sysmon and machine learning models is presented, which indicates that incorporating the context of natural user behavior significantly reduces the number of false alarms and increases the effectiveness of det...
Piotr Kaliszuk· Communications of Internatio...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.