{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T21:13:51Z","timestamp":1784582031423,"version":"3.55.0"},"reference-count":47,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2021,8,15]],"date-time":"2021-08-15T00:00:00Z","timestamp":1628985600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science Foundation","award":["CNS-1757945"],"award-info":[{"award-number":["CNS-1757945"]}]},{"name":"National Science Foundation","award":["OIA-1757207"],"award-info":[{"award-number":["OIA-1757207"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Smart grids integrate advanced information and communication technologies (ICTs) into traditional power grids for more efficient and resilient power delivery and management, but also introduce new security vulnerabilities that can be exploited by adversaries to launch cyber attacks, causing severe consequences such as massive blackout and infrastructure damages. Existing machine learning-based methods for detecting cyber attacks in smart grids are mostly based on supervised learning, which need the instances of both normal and attack events for training. In addition, supervised learning requires that the training dataset includes representative instances of various types of attack events to train a good model, which is sometimes hard if not impossible. This paper presents a new method for detecting cyber attacks in smart grids using PMU data, which is based on semi-supervised anomaly detection and deep representation learning. Semi-supervised anomaly detection only employs the instances of normal events to train detection models, making it suitable for finding unknown attack events. A number of popular semi-supervised anomaly detection algorithms were investigated in our study using publicly available power system cyber attack datasets to identify the best-performing ones. The performance comparison with popular supervised algorithms demonstrates that semi-supervised algorithms are more capable of finding attack events than supervised algorithms. Our results also show that the performance of semi-supervised anomaly detection algorithms can be further improved by augmenting with deep representation learning.<\/jats:p>","DOI":"10.3390\/info12080328","type":"journal-article","created":{"date-parts":[[2021,8,15]],"date-time":"2021-08-15T21:43:55Z","timestamp":1629063835000},"page":"328","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":55,"title":["Detecting Cyber Attacks in Smart Grids Using Semi-Supervised Anomaly Detection and Deep Representation Learning"],"prefix":"10.3390","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9072-9484","authenticated-orcid":false,"given":"Ruobin","family":"Qi","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, New Mexico Institute of Mining and Technology, Socorro, NM 87801, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Craig","family":"Rasband","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, New Mexico Institute of Mining and Technology, Socorro, NM 87801, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6727-5867","authenticated-orcid":false,"given":"Jun","family":"Zheng","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, New Mexico Institute of Mining and Technology, Socorro, NM 87801, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raul","family":"Longoria","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Prairie A&M University, Prairie, TX 77446, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,8,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"529","DOI":"10.1109\/TII.2011.2166794","article-title":"Smart grid technologies: Communication technologies and standards","volume":"7","author":"Gungor","year":"2011","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"944","DOI":"10.1109\/SURV.2011.101911.00087","article-title":"Smart grid\u2014The new and improved power grid: A survey","volume":"14","author":"Fang","year":"2011","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"2589","DOI":"10.1016\/j.renene.2019.08.092","article-title":"A survey on smart grid technologies and applications","volume":"146","author":"Dileep","year":"2020","journal-title":"Renew. Energy"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1109\/MNET.2011.6033030","article-title":"Cognitive radio based hierarchical communications infrastructure for smart grid","volume":"25","author":"Yu","year":"2011","journal-title":"IEEE Netw."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Flick, T., and Morehouse, J. (2010). Securing the Smart Grid: Next Generation Power Grid Security, Elsevier.","DOI":"10.1016\/B978-1-59749-570-7.00001-7"},{"key":"ref_6","unstructured":"Hink, R.C.B., Beaver, J.M., Buckner, M.A., Morris, T., Adhikari, U., and Pan, S. (2014, January 19\u201321). Machine learning for power system disturbance and cyber-attack discrimination. Proceedings of the 2014 7th International Symposium on Resilient Control Systems (ISRCS), Denver, CO, USA."},{"key":"ref_7","unstructured":"Salmon, D., Zeller, M., Guzm\u00e1n, A., Mynam, V., and Donolo, M. (2009, January 20\u201322). Mitigating the aurora vulnerability with existing technology. Proceedings of the 36th Annual Western Protection Relay Conference, Spokane, WA, USA."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Karnouskos, S. (2011, January 7\u201310). Stuxnet worm impact on industrial cyber-physical system security. Proceedings of the IECON 2011-37th Annual Conference of the IEEE Industrial Electronics Society, Melbourne, VIC, Australia.","DOI":"10.1109\/IECON.2011.6120048"},{"key":"ref_9","unstructured":"Alert, I.C. (2016). Cyber-Attack against Ukrainian Critical Infrastructure, Tech. Rep. ICS Alert (IR-ALERT-H-16-056-01)."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1389","DOI":"10.1109\/JPROC.2017.2686394","article-title":"Cyber-physical attack-resilient wide-area monitoring, protection, and control for the power grid","volume":"105","author":"Ashok","year":"2017","journal-title":"Proc. IEEE"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Blair, S., Burt, G., Gordon, N., and Orr, P. (2018, January 12\u201315). Wide area protection and fault location: Review and evaluation of PMU-based methods. Proceedings of the 14th International Conference on Developments in Power System Protection, Belfast, UK.","DOI":"10.1049\/joe.2018.0245"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1109\/TSG.2011.2119336","article-title":"Strategic protection against data injection attacks on power grids","volume":"2","author":"Kim","year":"2011","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1306","DOI":"10.1109\/JSAC.2013.130713","article-title":"Sparse attack construction and state estimation in the smart grid: Centralized and distributed models","volume":"31","author":"Ozay","year":"2013","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"206","DOI":"10.1109\/MCOM.2015.7045410","article-title":"Detection of false data injection attacks in smart-grid systems","volume":"53","author":"Chen","year":"2015","journal-title":"IEEE Commun. Mag."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1652","DOI":"10.1109\/LSP.2015.2421935","article-title":"Detection of false data injection attacks in smart grid communication systems","volume":"22","author":"Rawat","year":"2015","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"532","DOI":"10.1109\/JSYST.2014.2323266","article-title":"Real-time detection of false data injection in smart grid networks: An adaptive CUSUM method and analysis","volume":"10","author":"Huang","year":"2016","journal-title":"IEEE Syst. J."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1773","DOI":"10.1109\/TNNLS.2015.2404803","article-title":"Machine learning methods for attack detection in the smart grid","volume":"27","author":"Ozay","year":"2015","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Yan, J., Tang, B., and He, H. (2016, January 24\u201329). Detection of false data attacks in smart grid with supervised learning. Proceedings of the 2016 International Joint Conference on Neural Networks (IJCNN), Vancouver, BC, Canada.","DOI":"10.1109\/IJCNN.2016.7727361"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Singh, V.K., and Govindarasu, M. (2018, January 5\u201310). Decision tree based anomaly detection for remedial action scheme in smart grid using pmu data. Proceedings of the 2018 IEEE Power & Energy Society General Meeting (PESGM), Portland, OR, USA.","DOI":"10.1109\/PESGM.2018.8586159"},{"key":"ref_20","first-page":"42","article-title":"Detection of power grid disturbances and cyber-attacks based on machine learning","volume":"46","author":"Wang","year":"2019","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sakhnini, J., Karimipour, H., and Dehghantanha, A. (2019, January 12\u201314). Smart grid cyber attacks detection using supervised learning and heuristic feature selection. Proceedings of the 2019 IEEE 7th International Conference on Smart Energy Grid Engineering (SEGE), Oshawa, ON, Canada.","DOI":"10.1109\/SEGE.2019.8859946"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1644","DOI":"10.1109\/JSYST.2014.2341597","article-title":"Detecting stealthy false data injection using machine learning in smart grid","volume":"11","author":"Esmalifalak","year":"2014","journal-title":"IEEE Syst. J."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"2765","DOI":"10.1109\/TIFS.2019.2902822","article-title":"Unsupervised machine learning-based detection of covert data integrity assault in smart grid networks utilizing isolation forest","volume":"14","author":"Ahmed","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Maglaras, L.A., and Jiang, J. (2014, January 27\u201329). Intrusion detection in SCADA systems using machine learning techniques. Proceedings of the 2014 Science and Information Conference, London, UK.","DOI":"10.1109\/SAI.2014.6918252"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Maglaras, L.A., and Jiang, J. (2014, January 18\u201320). Ocsvm model combined with k-means recursive clustering for intrusion detection in scada systems. Proceedings of the 10th International Conference on Heterogeneous Networking for Quality, Reliability, Security and Robustness, Rhodes, Greece.","DOI":"10.1109\/QSHINE.2014.6928673"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Song, F., Guo, Z., and Mei, D. (2010, January 12\u201314). Feature selection using principal component analysis. Proceedings of the 2010 International Conference on System Science, Engineering Design and Manufacturing Informatization, Yichang, China.","DOI":"10.1109\/ICSEM.2010.14"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"6026","DOI":"10.1038\/s41598-020-63159-5","article-title":"DeepMicro: Deep representation learning for disease prediction based on microbiome data","volume":"10","author":"Oh","year":"2020","journal-title":"Sci. Rep."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C. (2017). An introduction to outlier analysis. Outlier Analysis, Springer.","DOI":"10.1007\/978-3-319-47578-3"},{"key":"ref_29","first-page":"582","article-title":"Support vector method for novelty detection","volume":"12","author":"Williamson","year":"1999","journal-title":"NIPS"},{"key":"ref_30","unstructured":"Goldstein, M., and Dengel, A. (2012, January 24\u201327). Histogram-based outlier score (hbos): A fast unsupervised anomaly detection algorithm. Proceedings of the 35th Annual German Conference on Artificial Intelligence, Saarbr\u00fccken, Germany."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Paulauskas, N., and Baskys, A. (2019). Application of Histogram-Based Outlier Scores to Detect Computer Network Anomalies. Electronics, 8.","DOI":"10.3390\/electronics8111251"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Breunig, M.M., Kriegel, H.P., Ng, R.T., and Sander, J. (2000, January 15\u201318). LOF: Identifying density-based local outliers. Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, Dallas, TX, USA.","DOI":"10.1145\/342009.335388"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1641","DOI":"10.1016\/S0167-8655(03)00003-5","article-title":"Discovering cluster-based local outliers","volume":"24","author":"He","year":"2003","journal-title":"Pattern Recognit. Lett."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"611","DOI":"10.1007\/BF02948829","article-title":"Squeezer: An efficient algorithm for clustering categorical data","volume":"17","author":"He","year":"2002","journal-title":"J. Comput. Sci. Technol."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kriegel, H.P., Schubert, M., and Zimek, A. (2008, January 24\u201327). Angle-based outlier detection in high-dimensional data. Proceedings of the 14th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Las Vegas, NV, USA.","DOI":"10.1145\/1401890.1401946"},{"key":"ref_36","unstructured":"Hinneburg, A., Aggarwal, C.C., and Keim, D.A. (2000, January 10\u201314). What is the nearest neighbor in high dimensional spaces?. Proceedings of the 26th International Conference on Very Large Databases, Cairo, Egypt."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C., Hinneburg, A., and Keim, D.A. (2001, January 4\u20136). On the surprising behavior of distance metrics in high dimensional space. Proceedings of the International Conference on Database Theory (ICDT), London, UK.","DOI":"10.1007\/3-540-44503-X_27"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Ramaswamy, S., Rastogi, R., and Shim, K. (2000, January 15\u201318). Efficient algorithms for mining outliers from large data sets. Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, Dallas, TX, USA.","DOI":"10.1145\/342009.335437"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Angiulli, F., and Pizzuti, C. (2002, January 19\u201323). Fast outlier detection in high dimensional spaces. Proceedings of the European Conference on Principles of Data Mining and Knowledge Discovery (PKDD), Helsinki, Finland.","DOI":"10.1007\/3-540-45681-3_2"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Lazarevic, A., and Kumar, V. (2005, January 22\u201324). Feature bagging for outlier detection. Proceedings of the Eleventh ACM SIGKDD International Conference on Knowledge Discovery in Data Mining, Chicago, IL, USA.","DOI":"10.1145\/1081870.1081891"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Liu, F.T., Ting, K.M., and Zhou, Z.H. (2008, January 15\u201319). Isolation forest. Proceedings of the 2008 Eighth IEEE International Conference on Data Mining, Pisa, Italy.","DOI":"10.1109\/ICDM.2008.17"},{"key":"ref_42","unstructured":"Zhao, Y., Nasrullah, Z., and Li, Z. (2019). Pyod: A python toolbox for scalable outlier detection. arXiv."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"823","DOI":"10.2307\/2533545","article-title":"Receiver operating characteristic studies and measurement errors","volume":"53","author":"Coffin","year":"1997","journal-title":"Biometrics"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"670","DOI":"10.1093\/aje\/kwj063","article-title":"The inconsistency of \u201coptimal\u201d cutpoints obtained using two criteria based on the receiver operating characteristic curve","volume":"163","author":"Perkins","year":"2006","journal-title":"Am. J. Epidemiol."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1016\/j.inffus.2020.05.001","article-title":"A dynamic ensemble outlier detection model based on an adaptive k-nearest neighbor rule","volume":"63","author":"Wang","year":"2020","journal-title":"Inf. Fusion"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Akcay, S., Atapour-Abarghouei, A., and Breckon, T.P. (2018, January 2\u20136). Ganomaly: Semi-supervised anomaly detection via adversarial training. Proceedings of the Asian Conference on Computer Vision (ACCV), Perth, Australia.","DOI":"10.1007\/978-3-030-20893-6_39"},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3439950","article-title":"Deep learning for anomaly detection: A review","volume":"54","author":"Pang","year":"2021","journal-title":"ACM Comput. Surv. (CSUR)"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/8\/328\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:46:29Z","timestamp":1760165189000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/12\/8\/328"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,15]]},"references-count":47,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2021,8]]}},"alternative-id":["info12080328"],"URL":"https:\/\/doi.org\/10.3390\/info12080328","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,8,15]]}}}