{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T03:54:45Z","timestamp":1782964485445,"version":"3.54.5"},"reference-count":53,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2023,5,5]],"date-time":"2023-05-05T00:00:00Z","timestamp":1683244800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Sichuan Provincial Science and Technology Achievement Transformation Project","award":["2022ZHCG0004"],"award-info":[{"award-number":["2022ZHCG0004"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Data poisoning attack is a well-known attack against machine learning models, where malicious attackers contaminate the training data to manipulate critical models and predictive outcomes by masquerading as terminal devices. As this type of attack can be fatal to the operation of a smart grid, addressing data poisoning is of utmost importance. However, this attack requires solving an expensive two-level optimization problem, which can be challenging to implement in resource-constrained edge environments of the smart grid. To mitigate this issue, it is crucial to enhance efficiency and reduce the costs of the attack. This paper proposes an online data poisoning attack framework based on the online regression task model. The framework achieves the goal of manipulating the model by polluting the sample data stream that arrives at the cache incrementally. Furthermore, a point selection strategy based on sample loss is proposed in this framework. Compared to the traditional random point selection strategy, this strategy makes the attack more targeted, thereby enhancing the attack\u2019s efficiency. Additionally, a batch-polluting strategy is proposed in this paper, which synchronously updates the poisoning points based on the direction of gradient ascent. This strategy reduces the number of iterations required for inner optimization and thus reduces the time overhead. Finally, multiple experiments are conducted to compare the proposed method with the baseline method, and the evaluation index of loss over time is proposed to demonstrate the effectiveness of the method. The results show that the proposed method outperforms the existing baseline method in both attack effectiveness and overhead.<\/jats:p>","DOI":"10.3390\/s23094509","type":"journal-article","created":{"date-parts":[[2023,5,5]],"date-time":"2023-05-05T09:18:09Z","timestamp":1683278289000},"page":"4509","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Research on Data Poisoning Attack against Smart Grid Cyber\u2013Physical System Based on Edge Computing"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2370-060X","authenticated-orcid":false,"given":"Yanxu","family":"Zhu","sequence":"first","affiliation":[{"name":"School of Aeronautics and Astronautics, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Aircraft Swarm Intelligent Sensing and Cooperative Control Key Laboratory of Sichuan Province, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8645-2264","authenticated-orcid":false,"given":"Hong","family":"Wen","sequence":"additional","affiliation":[{"name":"School of Aeronautics and Astronautics, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Aircraft Swarm Intelligent Sensing and Cooperative Control Key Laboratory of Sichuan Province, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Runhui","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Aeronautics and Astronautics, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Aircraft Swarm Intelligent Sensing and Cooperative Control Key Laboratory of Sichuan Province, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yixin","family":"Jiang","sequence":"additional","affiliation":[{"name":"Electric Power Research Institute, China Southern Power Grid Co., Ltd., Guangzhou 510663, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qiang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Aeronautics and Astronautics, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Aircraft Swarm Intelligent Sensing and Cooperative Control Key Laboratory of Sichuan Province, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peng","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Aeronautics and Astronautics, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Aircraft Swarm Intelligent Sensing and Cooperative Control Key Laboratory of Sichuan Province, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,5,5]]},"reference":[{"key":"ref_1","unstructured":"Paul, S., Gupta, S.D., Islam, K.A., Saha, K., and Majumder, S. (2012, January 28). Challenges of Securing the Smart Grid and Their Probable Security Solutions. Proceedings of the 2012 2nd International Conference on Environment and BioScience, Phnom Penh, Cambodia."},{"key":"ref_2","first-page":"64","article-title":"Edge computing enabled smart grid","volume":"5","author":"Zhang","year":"2019","journal-title":"Big Data Res."},{"key":"ref_3","first-page":"100006","article-title":"Smart Grid Encounters Edge Computing: Opportunities and Applications","volume":"2","author":"Feng","year":"2020","journal-title":"Adv. Appl. Energy"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1738","DOI":"10.1109\/JPROC.2019.2918951","article-title":"Edge intelligence: Paving the last mile of artificial intelligence with edge computing","volume":"107","author":"Zhou","year":"2019","journal-title":"Proc. IEEE"},{"key":"ref_5","first-page":"637","article-title":"Edge Computing: Vision and Challenges","volume":"3","author":"Shi","year":"2016","journal-title":"IEEE IoT J."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Lynn, T., Aalsalem, M.Y., and Li, X. (2020). The Cloud-To-Thing Continuum: Opportunities and Challenges in Cloud, Fog and Edge Computing, Springer Nature Switzerland AG. [1st ed.].","DOI":"10.1007\/978-3-030-41110-7"},{"key":"ref_7","first-page":"53","article-title":"Edge intelligence: A new nexus of edge computing and artificial intelligence","volume":"5","author":"Zhou","year":"2019","journal-title":"Big Data Res."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"869","DOI":"10.1109\/COMST.2020.2970550","article-title":"Convergence of Edge Computing and Deep Learning: A Comprehensive Survey","volume":"22","author":"Wang","year":"2020","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"7457","DOI":"10.1109\/JIOT.2020.2984887","article-title":"Edge Intelligence: The Confluence of Edge Computing and Artificial Intelligence","volume":"7","author":"Deng","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Mahmoud, M.M. (2022). Improved current control loops in wind side converter with the support of wild horse optimizer for enhancing the dynamic performance of PMSG-based wind generation system. Int. J. Model. Simul., 1\u201315.","DOI":"10.1080\/02286203.2022.2139128"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Boudjemai, H., Ardjoun, S.A.E.M., Chafouk, H., Denai, M., Elbarbary, Z.M., Omar, A.I., and Mahmoud, M.M. (2023). Application of a Novel Synergetic Control for Optimal Power Extraction of a Small-Scale Wind Generation System with Variable Loads and Wind Speeds. Symmetry, 15.","DOI":"10.3390\/sym15020369"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"26289","DOI":"10.1109\/ACCESS.2023.3257266","article-title":"Secure Industrial IoT Systems via RF Fingerprinting Under Impaired Channels With Interference and Noise","volume":"11","author":"Gul","year":"2023","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Comert, C., Kulhandjian, M., Gul, O.M., Touazi, A., Ellement, C., Kantarci, B., and D\u2019Amours, C. (2022, January 19). Analysis of Augmentation Methods for RF Fingerprinting under Impaired Channels. Proceedings of the 2022 ACM Workshop on Wireless Security and Machine Learning (WiseML \u201822), San Antonio, TX, USA.","DOI":"10.1145\/3522783.3529518"},{"key":"ref_14","unstructured":"Cin\u00e0, A.E., Grosse, K., Demontis, A., Biggio, B., Roli, F., and Pelillo, M. (2022). Machine Learning Security against Data Poisoning: Are We There Yet?. arXiv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Hossain, J., and Mahmud, A. (2014). Renewable Energy Integration. Green Energy and Technology, Springer.","DOI":"10.1007\/978-981-4585-27-9"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Sanjab, A., and Saad, W. (2015, January 2\u20135). Smart Grid Data Injection Attacks: To Defend or Not?. Proceedings of the 2015 IEEE International Conference on Smart Grid Communications (SmartGridComm), Miami, FL, USA.","DOI":"10.1109\/SmartGridComm.2015.7436330"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Nawaz, R., Shahid, M.A., Qureshi, I.M., and Mehmood, M.H. (2018, January 14\u201316). Machine Learning Based False Data Injection in Smart Grid. Proceedings of the 2018 1st International Conference on Power, Energy and Smart Grid (ICPESG), Mirpur Azad Kashmir, Pakistan.","DOI":"10.1109\/ICPESG.2018.8384510"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Musleh, A.S., Chen, G., Dong, Z.Y., Wang, C., and Chen, S. (2020, January 21\u201323). Vulnerabilities, Threats, and Impacts of False Data Injection Attacks in Smart Grids: An Overview. Proceedings of the 2020 International Conference on Smart Grids and Energy Systems (SGES), Perth, Australia.","DOI":"10.1109\/SGES51519.2020.00021"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., Nita-Rotaru, C., Li, B., Procopiuc, C., Ghasemian, A., Srivastava, M., and Singh, S. (2018, January 21\u201325). Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning. Proceedings of the IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00057"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Liu, C., Li, B., Vorobeychik, Y., Kantarcioglu, M., and Song, D. (2017, January 3\u20137). Robust Linear Regression Against Training Data Poisoning. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140447"},{"key":"ref_21","unstructured":"Xiao, H., Biggio, B., Brown, G., Fumera, G., Eckert, C., and Roli, F. (2015, January 6\u201311). Is Feature Selection Secure Against Training Data Poisoning?. Proceedings of the International Conference on Machine Learning, Lille, France."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","article-title":"The Security of Machine Learning","volume":"81","author":"Barreno","year":"2010","journal-title":"Mach. Learn."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"102","DOI":"10.1016\/j.compeleceng.2017.07.006","article-title":"Smart Grid Load Forecasting Using Online Support Vector Regression","volume":"65","author":"Ezzeddine","year":"2018","journal-title":"Comput. Electr. Eng."},{"key":"ref_24","first-page":"1","article-title":"Poisoning Attacks and Defenses on Artificial Intelligence: A Survey","volume":"4","author":"Ramirez","year":"2016","journal-title":"Comput. Sci."},{"key":"ref_25","first-page":"1","article-title":"Threats to Training: A Survey of Poisoning Attacks and Defenses on Machine Learning Systems","volume":"55","author":"Wang","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Zhou, M., Wu, J., Liu, Y., Liu, S., and Zhu, C. (2020, January 13\u201319). DaST: Data-free Substitute Training for Adversarial Attacks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"ref_27","unstructured":"Qiu, W. (2022). A Survey on Poisoning Attacks Against Supervised Machine Learning. arXiv."},{"key":"ref_28","unstructured":"Biggio, B., Nelson, B., and Laskov, P. (2011, January 13\u201315). Support vector machines under adversarial label noise. Proceedings of the Asian Conference on Machine Learning, PMLR, Taoyuan, Taiwan."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/j.neucom.2014.08.081","article-title":"Support vector machines under adversarial label contamination","volume":"160","author":"Xiao","year":"2015","journal-title":"Neurocomputing."},{"key":"ref_30","unstructured":"Paudice, A., Mu\u00f1oz-Gonz\u00e1lez, L., and Lupu, E.C. (2018). Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Springer."},{"key":"ref_31","first-page":"146","article-title":"Poisoning attacks against support vector machines","volume":"6854","author":"Biggio","year":"2013","journal-title":"Comput. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Burkard, C., and Lagesse, B. (2017, January 24). Analysis of causative attacks against svms learning from data streams. Proceedings of the 3rd ACM on International Workshop on Security And Privacy Analytics, Scottsdale, AZ, USA.","DOI":"10.1145\/3041008.3041012"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Mei, S., and Zhu, X. (2015, January 25\u201330). Using machine teaching to identify optimal training-set attacks on machine learners. Proceedings of the Twenty Ninth AAAI Conference on Artificial Intelligence, Austin, TX, USA.","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Alfeld, S., Zhu, X., and Barford, P. (2016, January 12\u201317). Data poisoning attacks against autoregressive models. Proceedings of the AAAI Conference on Artificial Intelligence, Phoenix, AZ, USA.","DOI":"10.1609\/aaai.v30i1.10237"},{"key":"ref_35","unstructured":"Koh, P.W., and Liang, P. (2017, January 6\u201311). Understanding black-box predictions via influence functions. Proceedings of the International Conference on Machine Learning, Sydney, Australia."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Biggio, B., Demontis, A., and Paudice, A. (2017, January 3). Towards poisoning of deep learning algorithms with back-gradient optimization. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140451"},{"key":"ref_37","unstructured":"Cisse, M.M., Adi, Y., Neverova, N., and Keshet, J. (2017, January 4\u20139). Houdini: Fooling deep structured visual and speech recognition models with adversarial examples. Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_38","unstructured":"Chen, Y., and Zhu, X. (2019). Optimal Adversarial Attack on Autoregressive Models. arXiv."},{"key":"ref_39","unstructured":"Li, B., Wang, Y., and Singh, A. (2016). Data poisoning attacks on factorization-based collaborative filtering. arXiv."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"M\u00fcller, N., Kowatsch, D., and B\u00f6ttinger, K. (2020, January 1\u20134). Data Poisoning Attacks on Regression Learning and Corresponding Defenses. Proceedings of the 2020 IEEE 25th Pacific Rim International Symposium on Dependable Computing (PRDC), Perth, WA, Australia.","DOI":"10.1109\/PRDC50213.2020.00019"},{"key":"ref_41","unstructured":"Zhang, X.Z., Zhu, X.J., and Lessard, L. (2020, January 11\u201312). Online Data Poisoning Attacks. Proceedings of the 2nd Annual Conference on Learning for Dynamics and Control (L4DC 2020), Berkeley, CA, USA."},{"key":"ref_42","unstructured":"Wang, Y.Z., and Chaudhuri, K. (2018). Data Poisoning Attacks against Online Learning. arXiv."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10994-021-06119-y","article-title":"Stronger Data Poisoning Attacks Break Data Sanitization Defenses","volume":"111","author":"Koh","year":"2021","journal-title":"Mach. Learn."},{"key":"ref_44","unstructured":"Koh, P.W., Ang, K.S., Teo, H.K., and Liang, P. (2019, January 8\u201314). On the Accuracy of Influence Functions for Measuring Group Effects. Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Wojnowicz, M., Cruz, B., Zhao, X., Wallace, B., Wolf, M., Luan, J., and Crable, C. (2016, January 5\u20138). \u201cInfluence Sketching\u201d: Finding Influential Samples in Large-Scale Regressions. Proceedings of the 2016 IEEE International Conference on Big Data (Big Data), Washington, DC, USA.","DOI":"10.1109\/BigData.2016.7841024"},{"key":"ref_46","first-page":"1","article-title":"Sample Size for Survey Re-search: Review and Recommendations","volume":"4","author":"Memon","year":"2020","journal-title":"J. Appl. Struct. Equ. Model."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"499","DOI":"10.1207\/s15327906mbr2603_7","article-title":"How Many Subjects Does It Take To Do A Regression Analysis","volume":"26","author":"Green","year":"1991","journal-title":"Multivar. Behav. Res."},{"key":"ref_48","unstructured":"Feng, J., Cai, Q., and Zhou, Z. (2019, January 8\u201314). Learning to confuse: Generating training time adversarial data with autoencoder. Proceedings of the Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019 (NeurIPS 2019), Vancouver, BC, Canada."},{"key":"ref_49","unstructured":"Shafahi, A., Huang, W.R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T. (2018, January 3\u20138). Poison frogs! targeted clean-label poisoning attacks on neural networks. Proceedings of the Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018 (NeurIPS 2018), Montreal, QC, Canada."},{"key":"ref_50","unstructured":"Gu, T.Y., Dolan-Gavitt, B., and Garg, S. (2017). Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv."},{"key":"ref_51","unstructured":"Ahmad, M. (2019). Mitigating Catastrophic Forgetting in Incremental Learning. [Master\u2019s Thesis, National University of Computer and Emerging Sciences]."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Barreno, M., Nelson, B., Sears, R., Joseph, A.D., and Tygar, J.D. (2006, January 21\u201324). Can machine learning be secure?. Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security, Taipei, Taiwan.","DOI":"10.1145\/1128817.1128824"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"984","DOI":"10.1109\/TKDE.2013.57","article-title":"Security evaluation of pattern classifiers under attack","volume":"26","author":"Biggio","year":"2014","journal-title":"IEEE Trans. Knowl. Data Eng."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/9\/4509\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:29:54Z","timestamp":1760124594000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/9\/4509"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,5]]},"references-count":53,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2023,5]]}},"alternative-id":["s23094509"],"URL":"https:\/\/doi.org\/10.3390\/s23094509","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,5]]}}}