<p>Distributed photovoltaic (PV) systems receive subsidies based on electricity output, leading some attackers to inflate meter readings for increased subsidies through PV electricity theft. Existing research has not considered the impact of more complex adversarial samples on theft detection. Adversarial samples not only inflate meter readings but also easily circumvent the detection mechanisms of deep learning models. To tackle this issue, we analyze evasion attack scenarios under both white-box and black-box settings and design three distinct types of evasion attacks to generate adversarial samples. Our research shows that the model has a low detection rate for adversarial examples, with stronger attacks in white-box than in black-box settings. To effectively identify these adversarial samples, we propose a supervised deep learning model that incorporates adversarial training for detection. The model comprises multi-scale convolutional block, self-attention block, and fully connected block, which sequentially extract local features and positional dependencies from multi-source data. Adversarial training enables the model to learn the complex patterns of adversarial samples in advance. Even in the white-box setting with high attack intensity, the three evasive attacks achieve only 0.62%, 0.01%, and 1.08% attack success rates against our model, which maintains a 94.52% detection rate against traditional attacks, outperforming other models and defense methods.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detection of distributed photovoltaic electricity theft against adversarial evasion attacks

  • Zhuoqun Xia,
  • Xi Lin,
  • Jingjing Tan,
  • Haidong Tang,
  • Han Qiu

摘要

Distributed photovoltaic (PV) systems receive subsidies based on electricity output, leading some attackers to inflate meter readings for increased subsidies through PV electricity theft. Existing research has not considered the impact of more complex adversarial samples on theft detection. Adversarial samples not only inflate meter readings but also easily circumvent the detection mechanisms of deep learning models. To tackle this issue, we analyze evasion attack scenarios under both white-box and black-box settings and design three distinct types of evasion attacks to generate adversarial samples. Our research shows that the model has a low detection rate for adversarial examples, with stronger attacks in white-box than in black-box settings. To effectively identify these adversarial samples, we propose a supervised deep learning model that incorporates adversarial training for detection. The model comprises multi-scale convolutional block, self-attention block, and fully connected block, which sequentially extract local features and positional dependencies from multi-source data. Adversarial training enables the model to learn the complex patterns of adversarial samples in advance. Even in the white-box setting with high attack intensity, the three evasive attacks achieve only 0.62%, 0.01%, and 1.08% attack success rates against our model, which maintains a 94.52% detection rate against traditional attacks, outperforming other models and defense methods.