Lightweight Data-Driven Anomaly Detection for IoT-Based Smart Grids: Capabilities and Limitations

dc.contributor.authorEskilson, Lisa
dc.contributor.authorLager Carvalho, Alexander
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerDuvignau, Romaric
dc.contributor.supervisorAlmgren, Magnus
dc.date.accessioned2024-11-15T08:38:38Z
dc.date.available2024-11-15T08:38:38Z
dc.date.issued2024
dc.date.submitted
dc.description.abstractThe integration of Internet of Things devices in critical infrastructure, such as the smart grid, has made it possible to monitor and manage energy distribution with increased efficiency. However, as these devices become more complex and interconnected, detecting physical tampering or data manipulation by malicious actors, such as the Sandworm attack in Ukraine, becomes increasingly challenging. One way that has shown promise in addressing this problem is the use of lightweight data-driven anomaly detection techniques. In this thesis, PASAD and USAD, two state-of-the-art lightweight data-driven anomaly detection algorithms were selected and evaluated using a series of experiments simulating common attacks against smart grids as suggested by relevant research. These experiments aimed to investigate the viability of these algorithms in IoT-based smart grids. More specifically, the experiments include two different attack areas, namely OT- and network-level attacks, which were crafted by manipulating real smart grid operational data. These experiments were evaluated using time series-aware metrics to get a fair assessment of the efficacy of the algorithms. The results from the experiments were used to evaluate the viability of lightweight data-driven anomaly detection algorithms and their capabilities and limitations were highlighted. Furthermore, the knowledge acquired from executing the experiments was used to propose guidelines for the development of an event management system that handles alerts produced by different models to provide valuable and actionable information to the OT operator. The selected algorithms were successful in detecting various long-duration attacks with stealth characteristics, while other, shorter and more direct attacks, were significantly harder to detect. Despite this, these lightweight data-driven anomaly detection algorithms proved to be a good fit for the experiments evaluated in this thesis.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/308984
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectLightweight Anomaly Detection
dc.subjectMachine Learning
dc.subjectInternet of Things
dc.subjectSmart Grid
dc.titleLightweight Data-Driven Anomaly Detection for IoT-Based Smart Grids: Capabilities and Limitations
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc
Ladda ner
Original bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 24-167 LE ALC.pdf
Storlek:
3.64 MB
Format:
Adobe Portable Document Format
Beskrivning:
License bundle
Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: