Cyber-Resilient System Identification for Power Grid through Bayesian Integration
Shimiao Li, Guannan Qu, Bryan Hooi, Vyas Sekar, Soummya Kar, Larry Pileggi
TL;DR
This work addresses the fragility of snapshot-based grid state and topology estimation under cyber threats by introducing a Bayesian integration that fuses robust snapshot-based identification with a distance-based time-series prior learned from historical, non-IID data. The method extends ckt-GSE to bus-branch models and augments it with a temporal prior via DynWatch-like weighting, enabling resilient detection of random errors and targeted FDIA while preserving near-linear scalability. Key results show over 70% reduction in estimation error under FDIA, accurate anomaly detection and localization, and runtimes under 1 minute per tick on large networks using a laptop. The approach offers a practical path to cyber-resilient situational awareness for large-scale power grids using hybrid SCADA-PMU data and historically informed priors.
Abstract
Power grids increasingly need real-time situational awareness under the ever-evolving cyberthreat landscape. Advances in snapshot-based system identification approaches have enabled accurately estimating states and topology from a snapshot of measurement data, under random bad data and topology errors. However, modern interactive, targeted false data can stay undetectable to these methods, and significantly compromise estimation accuracy. This work advances system identification that combines snapshot-based method with time-series model via Bayesian Integration, to advance cyber resiliency against both random and targeted false data. Using a distance-based time-series model, this work can leverage historical data of different distributions induced by changes in grid topology and other settings. The normal system behavior captured from historical data is integrated into system identification through a Bayesian treatment, to make solutions robust to targeted false data. We experiment on mixed random anomalies (bad data, topology error) and targeted false data injection attack (FDIA) to demonstrate our method's 1) cyber resilience: achieving over 70% reduction in estimation error under FDIA; 2) anomalous data identification: being able to alarm and locate anomalous data; 3) almost linear scalability: achieving comparable speed with the snapshot-based baseline, both taking <1min per time tick on the large 2,383-bus system using a laptop CPU.
