DOI: https://doi.org/10.1016/j.jpdc.2024.104951
تاريخ النشر: 2024-07-04
المؤلف: Rakesh Shrestha وآخرون
الموضوع الرئيسي: التقنيات التي تحافظ على الخصوصية في البيانات
نظرة عامة
تقدم ورقة البحث إطارًا لاكتشاف الشذوذ في أنظمة الشبكة الكهربائية الذكية، باستخدام شبكات الذاكرة طويلة وقصيرة المدى (LSTM) والمشفّرات الذاتية. يتناول الإطار مخاوف الخصوصية والأمن السيبراني المرتبطة بجمع البيانات الكهربائية من المحطات الفرعية، والتي غالبًا ما تكون عرضة للإساءة وانتهاكات الخصوصية عند نقلها إلى التخزين المركزي. للتخفيف من هذه المخاطر، يقترح المؤلفون نظام اكتشاف الشذوذ الذي يستخدم طرق الانحراف المعياري المتوسط (MSD) والانحراف المطلق الوسيط (MAD)، جنبًا إلى جنب مع التعلم الفيدرالي (FL) لضمان خصوصية البيانات من خلال تمكين تدريب النماذج التعاوني دون تعرض البيانات. بالإضافة إلى ذلك، يتم تنفيذ التشفير المتجانس بناءً على خوارزمية بايلييه لتأمين البيانات بشكل أكبر، محققًا درجة F1 تبلغ 97% ودقة 98% باستخدام نهج MSD باستخدام مفتاح بطول 128 بت.
تشير النتائج إلى أن إطار ADLA-FL المقترح يكتشف الشذوذ بشكل فعال في البيانات الصناعية، حيث يتفوق نهج MSD على MAD، محققًا درجات F1 تبلغ 80% و98% لـ $K=3$ و$K=5$، على التوالي. بينما يحافظ الإطار على مستويات أداء مقارنة بالطرق الأساسية دون تشفير، فإن استخدام التشفير المتجانس يقدم عبئًا حسابيًا كبيرًا، مما يبرز التوازن بين الخصوصية والأداء ووقت التنفيذ. تشمل اتجاهات البحث المستقبلية التحقيق في التشفير المتجانس متعدد المفاتيح في FL للتطبيقات الحساسة مثل الشبكات الكهربائية الذكية وتنفيذ تدابير الأمان لمنع تسرب الخصوصية وتواطؤ الأجهزة مع الخوادم، مما يعزز الأمان والموثوقية العامة للنظام.
مقدمة
تؤكد مقدمة ورقة البحث هذه على الانتقال الحاسم من أنظمة توزيع الكهرباء التقليدية إلى الشبكات الكهربائية الذكية، مع تسليط الضوء على الفوائد البيئية والتشغيلية لمثل هذا التحول. تعزز الشبكة الذكية من الموثوقية والأمان والكفاءة من خلال البنية التحتية الرقمية، لكنها تقدم أيضًا مخاطر كبيرة تتعلق بالأمن السيبراني وخصوصية البيانات. لمعالجة هذه التحديات، تقترح الورقة إطارًا يدمج تقنيات إنترنت الأشياء (IoT) والذكاء الاصطناعي (AI) داخل المحطات الكهربائية، مع التركيز على اكتشاف الشذوذ باستخدام شبكات الذاكرة طويلة وقصيرة المدى (LSTM) والمشفّرات الذاتية. يهدف هذا النهج إلى تحسين القرارات التشغيلية مع حماية الشبكة الكهربائية من التقلبات.
يدعو المؤلفون إلى استراتيجية التعلم الفيدرالي (FL) للحفاظ على خصوصية البيانات، مما يسمح بتدريب نماذج التعلم الآلي على أجهزة لامركزية دون نقل البيانات الحساسة إلى خادم مركزي. لا يخفف هذا الأسلوب من مخاوف الخصوصية فحسب، بل يتوافق أيضًا مع اللوائح مثل GDPR. يعزز دمج التشفير المتجانس (HE) الأمان من خلال تشفير معلمات النموذج أثناء الاتصال. تظهر النتائج التجريبية أن النموذج المقترح يحقق درجة F1 تبلغ 97% ودقة 98% باستخدام مفتاح HE بطول 128 بت، متفوقًا على النماذج بدون تشفير. توضح الورقة مساهماتها، بما في ذلك تصميم تقنيات اكتشاف الشذوذ ضمن سياق التعلم الفيدرالي، وتضع الأساس للأقسام التالية التي تتناول الأعمال ذات الصلة، ونماذج النظام، وتقييمات الأداء.
طرق
في هذا القسم، يوضح المؤلفون الإعداد التجريبي لإطار اكتشاف الشذوذ القائم على التعلم الفيدرالي (FL). تم إجراء التجارب باستخدام بايثون، مستفيدين من مكتبات مثل Pandas وNumpy وPytorch وScikit Learn لمعالجة البيانات. كانت البيئة الحسابية تتكون من معالج Intel Core i7-11800H مقترنًا ببطاقة رسومات Nvidia GeForce RTX 3050 و16 جيجابايت من ذاكرة الوصول العشوائي، باستخدام بايثون 3.8 وTensorFlow 2.8.0 لتطوير النموذج. كانت وحدة التحكم عن بعد PowerLogic T300 من Schneider Electric تعمل كجهاز RTU، مما يسهل إدارة الشبكات العامة للتوزيع.
شملت المعلمات التجريبية ثلاثة عملاء FL، كل منها يحتوي على 376 عينة لتدريب النموذج المحلي، وخادم عالمي في السحابة. استخدم التدريب مُحسّن ADAM بمعدل تعلم قدره 0.001، وحقبة محلية قدرها 4، وحقبة عالمية قدرها 50، مع حجم دفعة قدره 8. كانت طريقة التجميع المستخدمة هي FedAvg. لضمان الخصوصية، تم تنفيذ التشفير المتجانس بمفاتيح بطول 128 بت و256 بت. كانت مجموعة البيانات المستخدمة للتدريب اصطناعية، وتم تقييم أداء النموذج العالمي باستخدام مجموعة اختبار، جنبًا إلى جنب مع مقياسين للتقييم: درجة الانحراف المربّع المتوسط (MSD) ودرجة الانحراف المطلق المتوسط (MAD).
نتائج
تظهر نتائج الدراسة فعالية إطار التعلم الفيدرالي (FL) لاكتشاف الشذوذ باستخدام بنية مشفّر الذاكرة طويلة وقصيرة المدى (LSTM-AE)، التي تم تقييمها من خلال مقاييس خسارة الانحراف المربّع المتوسط (MSE). شمل الإعداد التجريبي ثلاثة عملاء FL وخادم واحد، مع إجراء محاكاة سواء مع أو بدون تشفير متجانس (HE) باستخدام مفاتيح بطول 128 بت و256 بت. كشفت التحليلات أن النموذج المقترح حقق معدل تعريف يبلغ 100% للعينات الطبيعية ومعدل اكتشاف يبلغ 98.4% للشذوذ، كما هو موضح في مصفوفة الارتباك. أكدت تحليل منطقة تحت المنحنى (AUC-ROC) أيضًا أن أداء النموذج كان متسقًا عبر استراتيجيات التشفير المختلفة، حيث حققت السيناريوهات غير HE وHE-128 وHE-256 نتائج قابلة للمقارنة.
تم تقديم مقاييس الأداء المقارنة للتقنيتين المعتمدتين على العتبة، الانحراف المطلق المتوسط (MAD) والانحراف المربّع المتوسط (MSD)، في الجداول 4 و5. تفوق نهج MSD على MAD، خاصة عند قيمة عتبة قدرها \( K=5 \)، محققًا درجة استرجاع تبلغ 98% ودرجة F1 تبلغ 97%. في المقابل، كان أداء MAD أقل بكثير، خاصة عندما كانت عينات الشذوذ أقرب إلى العينات الطبيعية، مما يبرز أهمية اختيار استراتيجيات الكشف المناسبة. بينما لم يؤثر تنفيذ HE سلبًا على أداء النموذج، إلا أنه قدم عبئًا حسابيًا، حيث زادت أوقات التنفيذ من 29.61 ثانية بدون HE إلى 1387 ثانية و4662 ثانية لـ HE-128 وHE-256، على التوالي. يبرز هذا التوازن بين الأمان والكفاءة الحسابية ضرورة تحقيق توازن بين طول المفتاح ومتطلبات الأداء في التطبيقات العملية.
مناقشة
تسلط المناقشة حول اكتشاف الشذوذ الضوء على دوره الحاسم في تحديد السلوكيات غير العادية والنقاط الشاذة في مجموعات البيانات الكبيرة، خاصة في بيانات السلاسل الزمنية من أنظمة الشبكة الذكية. تعقد تحديات تعريف السلوك الطبيعي اكتشاف الشذوذ، خاصة عند حدود توزيعات البيانات. تم استخدام تقنيات التعلم الآلي، وخاصة شبكات الذاكرة طويلة وقصيرة المدى (LSTM) والمشفّرات الذاتية، لمعالجة هذه التحديات. تتعلم مشفّرات LSTM (LSTM-AE) الأنماط في البيانات التسلسلية بشكل فعال، مما يسمح باكتشاف الشذوذ من خلال أخطاء إعادة البناء. ومع ذلك، غالبًا ما تفتقر النماذج الحالية إلى المتانة ضد إساءة استخدام البيانات ومخاوف الخصوصية، والتي تعتبر ذات أهمية قصوى في التطبيقات الحساسة مثل الشبكات الذكية.
يظهر التعلم الفيدرالي (FL) كنهج واعد لتعزيز اكتشاف الشذوذ مع الحفاظ على خصوصية البيانات. من خلال تمكين تدريب النماذج بشكل لامركزي عبر عدة عملاء دون مشاركة البيانات الخام، يقلل FL من مخاطر الخصوصية المرتبطة بتخزين البيانات المركزي. يدمج الإطار المقترح LSTM-AE مع FL، مستفيدًا من خوارزمية التشفير المتجانس بايلييه لتأمين معلمات النموذج أثناء التجميع. يهدف هذا الجمع إلى تحسين قدرات اكتشاف الشذوذ مع ضمان بقاء المعلومات الحساسة سرية. يبرز تصميم الإطار الحاجة إلى تخصيص الموارد بشكل فعال والتواصل في البيئات الموزعة، مما يعالج قيود أساليب التعلم الآلي المركزية التقليدية.
DOI: https://doi.org/10.1016/j.jpdc.2024.104951
Publication Date: 2024-07-04
Author(s): Rakesh Shrestha et al.
Primary Topic: Privacy-Preserving Technologies in Data
Overview
The research paper presents a framework for anomaly detection in smart electric grid systems, utilizing Long Short-Term Memory (LSTM) networks and autoencoders. The framework addresses data privacy and cybersecurity concerns associated with the collection of electrical data from substations, which is often vulnerable to misuse and privacy breaches when transferred to central storage. To mitigate these risks, the authors propose an anomaly detection system that employs Mean Standard Deviation (MSD) and Median Absolute Deviation (MAD) methods, alongside Federated Learning (FL) to ensure data privacy by enabling collaborative model training without data exposure. Additionally, homomorphic encryption based on the Paillier algorithm is implemented to further secure the data, achieving a 97% F1-score and 98% accuracy with the MSD approach using a 128-bit key.
The findings indicate that the proposed ADLA-FL framework effectively detects anomalies in industrial data, with the MSD approach outperforming MAD, yielding F1-scores of 80% and 98% for $K=3$ and $K=5$, respectively. While the framework maintains performance levels comparable to baseline methods without encryption, the use of homomorphic encryption introduces significant computational overhead, highlighting a trade-off between privacy, performance, and execution time. Future research directions include investigating multi-key homomorphic encryption in FL for sensitive applications like smart electric grids and implementing security measures to prevent privacy leakage and device-server collusion, thereby enhancing overall system security and reliability.
Introduction
The introduction of this research paper emphasizes the critical transition from traditional electric distribution systems to smart electrical grids, highlighting the environmental and operational benefits of such a shift. The smart grid enhances reliability, security, and efficiency through digital infrastructure, yet it also introduces significant risks related to cybersecurity and data privacy. To address these challenges, the paper proposes a framework that integrates Internet of Things (IoT) and Artificial Intelligence (AI) technologies within electrical substations, focusing on anomaly detection using Long Short-Term Memory (LSTM) networks and autoencoders. This approach aims to optimize operational decisions while safeguarding the electrical network from fluctuations.
The authors advocate for a Federated Learning (FL) strategy to maintain data privacy, allowing machine learning models to be trained on decentralized devices without transferring sensitive data to a central server. This method not only mitigates privacy concerns but also complies with regulations like GDPR. The integration of Homomorphic Encryption (HE) further enhances security by encrypting model parameters during communication. Experimental results demonstrate that the proposed model achieves a 97% F1-score and 98% accuracy with a 128-bit HE key, outperforming models without encryption. The paper outlines its contributions, including the design of anomaly detection techniques within a federated learning context, and sets the stage for subsequent sections detailing related works, system models, and performance evaluations.
Methods
In this section, the authors outline the experimental setup for their federated learning (FL) based anomaly detection framework. The experiments were conducted using Python, leveraging libraries such as Pandas, Numpy, Pytorch, and Scikit Learn for data processing. The computational environment consisted of an Intel Core i7-11800H processor paired with an Nvidia GeForce RTX 3050 graphics card and 16 GB of RAM, utilizing Python 3.8 and TensorFlow 2.8.0 for model development. The PowerLogic T300 RTU from Schneider Electric served as the remote terminal unit (RTU), facilitating the management of public distribution networks.
The experimental parameters included three FL clients, each with 376 samples for local model training, and a global server in the cloud. The training utilized the ADAM optimizer with a learning rate of 0.001, a local epoch of 4, and a global epoch of 50, with a batch size of 8. The aggregation method employed was FedAvg. To ensure privacy, homomorphic encryption was implemented with both 128-bit and 256-bit keys. The dataset used for training was synthetic, and the performance of the global model was evaluated using a testing set, alongside two evaluation metrics: the Mean Squared Deviation (MSD) and the Mean Absolute Deviation (MAD) score.
Results
The results of the study demonstrate the effectiveness of a federated learning (FL) framework for anomaly detection using a Long Short-Term Memory Autoencoder (LSTM-AE) architecture, evaluated through Mean Squared Error (MSE) loss metrics. The experimental setup involved three FL clients and a single server, with simulations conducted both with and without homomorphic encryption (HE) using 128-bit and 256-bit keys. The analysis revealed that the proposed model achieved a 100% identification rate for normal samples and a 98.4% detection rate for anomalies, as indicated by the confusion matrix. The Area Under the Curve (AUC-ROC) analysis further confirmed that the model’s performance was consistent across different encryption strategies, with the non-HE, HE-128, and HE-256 scenarios yielding comparable results.
Comparative performance metrics for the two threshold-based techniques, Mean Absolute Deviation (MAD) and Mean Squared Deviation (MSD), were presented in Tables 4 and 5. The MSD approach outperformed MAD, particularly at a threshold value of \( K=5 \), achieving a recall score of 98% and an F1-score of 97%. In contrast, MAD’s performance was significantly lower, especially when anomaly samples were closer to normal samples, highlighting the importance of selecting appropriate detection strategies. While the implementation of HE did not adversely affect model performance, it introduced computational overhead, with execution times increasing from 29.61 seconds without HE to 1387 seconds and 4662 seconds for HE-128 and HE-256, respectively. This trade-off between security and computational efficiency underscores the necessity of balancing key length with performance requirements in practical applications.
Discussion
The discussion on anomaly detection highlights its critical role in identifying unusual behaviors and outliers in large datasets, particularly in time series data from smart grid systems. The challenges of defining normal behavior complicate the detection of anomalies, especially at the boundaries of data distributions. Machine learning techniques, particularly Long Short-Term Memory (LSTM) networks and autoencoders, have been employed to address these challenges. LSTM autoencoders (LSTM-AE) effectively learn patterns in sequential data, allowing for the detection of anomalies through reconstruction errors. However, existing models often lack robustness against data misuse and privacy concerns, which are paramount in sensitive applications like smart grids.
Federated learning (FL) emerges as a promising approach to enhance anomaly detection while preserving data privacy. By enabling decentralized training of models across multiple clients without sharing raw data, FL mitigates privacy risks associated with centralized data storage. The proposed framework integrates LSTM-AE with FL, utilizing the Paillier homomorphic encryption algorithm to secure model parameters during aggregation. This combination aims to improve anomaly detection capabilities while ensuring that sensitive information remains confidential. The framework’s design emphasizes the need for efficient resource allocation and communication in distributed environments, addressing the limitations of traditional centralized machine learning approaches.
