Song Liu, Yun Wang
2026.1.1IEEE Canadian Journal of Electrical and Computer Engineering
Abstract
The cyberthreats faced by power cyber–physical systems (CPSs) have become increasingly serious. However, existing cyberattack detectors still cannot resist them effectively due to the data imbalance, the high false alarm rate (FAR), and highly covert cyberattacks. To address the issues, this article proposes a novel data-driven cyberattack detector based on deep learning for power CPSs. The proposed detector is equipped with two Wasserstein generative adversarial networks (WGANs), which overcome the data imbalance issue in existing detectors by synthesizing adequate abnormal samples involving cyberattacks. Moreover, a novel substation-level detector with a modified light gradient boosting machine (LightGBM) and a maximal information coefficient (MIC) unit is introduced into the proposed detector. It captures differences between abnormal sampled values caused by cyberattacks and natural faults, thus reducing the FAR. Furthermore, a novel overalllevel detector based on an improved graph convolutional neural network (IGCNN) is built for the proposed detector. It performs spatial–temporal topology mining on complete power CPS graphs to fully extract more comprehensive attack-related features than existing detectors, thus realizing exhaustive detection sensitive enough to highly covert cyberattacks. Finally, the effectiveness and superiority of the proposed detector are verified by experimental research on actual power data from China.
Citation format
LIU, Song; WANG, Yun. Data-driven cyberattack detection based on deep learning for power cyber–physical systems. IEEE Canadian Journal of Electrical and Computer Engineering, 2026, 49(1): 69–82.