A Convolutional Neural Network Based Approach for Cyber Intrusion Detection in Smart Grids
DOI:
https://doi.org/10.4108/ew.13843Keywords:
Deep Learning (DL), Convolutional Neural Network (CNN), Intrusion Detection, Smart GridAbstract
Smart grids, increasingly reliant on information and communication technologies (ICT), are vulnerable to complex cyberattacks, thereby mandating the deployment of intelligent and adaptable intrusion detection systems (IDS). However, the efficacy of existing IDS techniques is frequently constrained by their limited capacity to extract distinguishing features from the high-dimensional, heterogeneous data characteristic of grid operations. In order to overcome this, we suggest a novel intrusion detection model that uses a convolutional neural network (CNN) to automatically extract hierarchical features from network traffic. The suggested CNN model outperforms conventional signature-based and SVM-based techniques with an accuracy of 98.8%, precision of 98.6%, and recall of 99.3% using the KDD-CUP99 dataset. Validation on a semi-realistic dataset from the IEEE 14-bus system, which uses IEC 61850 communication protocols, shows that it is 97.3% accurate. This means that it works well when physical and cyber layers are combined. Feature importance analysis shows that cyber-layer features, such as the continuity of GOOSE sequence numbers, are very important for detection. This research introduces a feature-learning-based intrusion detection system (IDS) framework. It works well and shows potential for practical use in improving the cybersecurity of smart grids.
Downloads
References
[1] D. M. Manias, A. M. Saber, M. I. Radaideh, et al. Trends in smart grid cyber-physical security: Components, threats, and solutions. IEEE Access, vol. 12, pp. 161329–161356, 2024.
[2] M. Liu, F. Teng, Z. Zhang, et al. Enhancing cyber-resiliency of DER-based smart grid: A survey. IEEE Transactions on Smart Grid, vol. 15, no. 5, pp. 4998–5030, 2024.
[3] A. M. Saber, A. Maheshwari, A. Youssef, and D. Kundur. Adversarial attacks on deep learning-based false data injection detection in differential relays. IEEE Transactions on Smart Grid, vol. 16, no. 5, pp. 4155–4166, 2025.
[4] Reuters. (2023, November 9). Russian spies behind cyber attack on Ukrainian power grid in 2022—researchers. [Online]. Available: https://www.reuters.com/technology/cybersecurity/russian-spies-behind-cyberattack-ukrainian-power-grid-2022-researchers-2023-11-09/
[5] A. Thakkar and R. Lohiya. A survey on intrusion detection system: Feature selection, model, performance measures, application perspective, challenges, and future research directions. Artificial Intelligence Review, vol. 55, no. 1, pp. 453–563, 2022.
[6] G. Singh and N. Khare. A survey of intrusion detection from the perspective of intrusion datasets and machine learning techniques. International Journal of Computer Applications, vol. 44, no. 7, pp. 659–669, 2022.
[7] M. Ghiasi, T. Niknam, Z. Wang, M. Mehrandezh, M. Dehghani, and N. Ghadimi. A comprehensive review of cyber-attacks and defense mechanisms for improving security in smart grid energy systems: Past, present and future. Electric Power Systems Research, vol. 215, Art. no. 108975, 2023.
[8] A. Khan, M. Keshk, D. Pi, N. Khan, Y. Hussain, and H. Soliman. Enhancing IIoT networks protection: A robust security model for attack detection in Internet Industrial Control Systemst. Ad Hoc Networks, vol. 134, p. 102930, 2022.
[9] N. K. Singh, M. A. Majeed, and V. Mahajan. Statistical machine learning defensive mechanism against cyber intrusion in smart grid cyber-physical network. Computers & Security, vol. 123, p. 102941, 2022.
[10] H. Ding, L. Chen, L. Dong, Z. Fu, and X. Cui. Imbalanced data classification: A KNN and generative adversarial networks-based hybrid approach for intrusion detection. Future Generation Computer Systems, vol. 131, pp. 240–254, 2022.
[11] D. J. Kalita, V. P. Singh, and V. Kumar. A novel adaptive optimization framework for SVM hyper-parameters tuning in non-stationary environment: A case study on intrusion detection system. Expert Systems with Applications, vol. 213, Part C, p. 119189, 2023.
[12] K. Pramilarani and P. V. Kumari. Cost based random forest classifier for intrusion detection system in internet of things. Applied Soft Computing, vol. 151, p. 111125, 2024.
[13] M. Priyadarsini and N. Sonekar. A CNN-based approach for anomaly detection in smart grid systems. Electric Power Systems Research, vol. 238, Art. no. 111077, 2025.
[14] H. N. Noura, J. P. A. Yaacoub, O. Salman, and A. Chehab. Advanced machine learning in smart grids: An overview. Internet of Things and Cyber-Physical Systems, vol. 5, pp. 95–142, 2025.
[15] M. A. Husnoo, A. Anwar, N. Hosseinzadeh, S. N. Islam, A. N. Mahmood, and R. Doss. False data injection threats in active distribution systems: A comprehensive survey. Future Generation Computer Systems, vol. 140, pp. 344–364, Mar. 2023.
[16] H. Yang and Z. Wang. A false data injection attack approach without knowledge of system parameters considering measurement noise. IEEE Internet of Things Journal, vol. 11, no. 1, pp. 1452–1464, 2024.
[17] I. Ortega-Fernandez and F. Liberati. A review of denial of service attack and mitigation in the smart grid using reinforcement learning. Energies, vol. 16, no. 2, p. 635, 2023.
[18] J. Tian, B. Wang, J. Li, and Z. Wang, “Adversarial attacks and defense for CNN based power quality recognition in smart grid,” IEEE Transactions on Network Science and Engineering, vol. 9, no. 2, pp. 807–819, Mar./Apr. 2022.
[19] R. Huang and Y. Li. Adversarial attack mitigation strategy for machine learning-based network attack detection model in power system. IEEE Transactions on Smart Grid, vol. 14, no. 3, pp. 2367–2376, 2023.
[20] L. Zhang, C. Jiang, Z. Chai, and Y. He. Adversarial attack and training for deep neural network based power quality disturbance classification. Engineering Applications of Artificial Intelligence, vol. 127, Art. no. 107245, 2024.
[21] Y. Cui, T. Wu, and Y. Zhang. Load frequency control of smart grid based on data-driven FDI attacks detection and data repair. IEEE Transactions on Smart Grid, vol. 16, no. 6, pp. 5404–5415, Nov. 2025.
[22] X. C. Shangguan, M. H. Yu, C. K. Zhang, and Y. He. Detection and defense against multi-point false data injection attacks of load frequency control in smart grid. IEEE Transactions on Smart Grid, vol. 16, no. 5, pp. 4143–4154, Sep. 2025.
[23] Z. Zhang, J. Hu, J. Lu, J. Yu, J. Cao, and A. Kashkynbayev. Detection and defense method against false data injection attacks for distributed load frequency control system in microgrid. Journal of Modern Power Systems and Clean Energy, vol. 12, no. 3, pp. 913–924, May 2024.
[24] A. S. Musleh, G. Chen, Z. Y. Dong, C. Wang, and S. Chen. Attack detection in automatic generation control systems using LSTM-based stacked autoencoders. IEEE Transactions on Industrial Informatics, vol. 19, no. 1, pp. 153–165, 2023.
[25] K. Lu, L. Zhou, and Z. Wu. Representation-learning-based CNN for intelligent attack localization and recovery of cyber-physical power systems. IEEE Transactions on Neural Networks and Learning Systems, vol. 35, no. 5, pp. 6145–6155, 2024.
[26] J. Zhu, W. Meng, M. Sun, J. Yang, and Z. Song. FLLF: A fast-lightweight location detection framework for false data injection attacks in smart grids. IEEE Transactions on Smart Grid, vol. 15, no. 1, pp. 911–920, 2024.
[27] K. Yang, J. Wang, G. Zhao, X. Wang, W. Cong, M. Yuan, J. Luo, X. Dong, J. Wang, and J. Tao. NIDS-CNNRF integrating CNN and random forest for efficient network intrusion detection model. Internet of Things, vol. 32, Art. no. 101607, 2025.
[28] E. Vincent, M. Korki, M. Seyedmahmoudian, A. Stojcevski, and S. Mekhilef. Detection of false data injection attacks in cyber-physical systems using graph convolutional network. Electric Power Systems Research, vol. 217, Art. no. 109118, 2023.
[29] Y. Han, H. Feng, K. Li, and Q. Zhao. False data injection attacks detection with modified temporal multi-graph convolutional network in smart grids. Computers & Security, vol. 124, Art. no. 103016, 2023.
[30] G. Morgenstern, J. Kim, J. Anderson, G. Zussman, and T. Routtenberg. Protection against graph-based false data injection attacks on power systems. IEEE Transactions on Control of Network Systems, vol. 11, no. 4, pp. 1924–1936, 2024.
[31] S. Peng, Z. Zhang, R. Deng, and P. Cheng. Localizing false data injection attacks in smart grid: A spectrum-based neural network approach. IEEE Transactions on Smart Grid, vol. 14, no. 6, pp. 4827–4838, 2023.
[32] X. Li, Y. Wang, and Z. Lu. Graph-based detection for false data injection attacks in power grid. Energy, vol. 263, Art. no. 125865, 2023.
[33] A. Presekal, A. Stefanov, V. S. Rajkumar, and P. Palensky. Attack graph model for cyber-physical power systems using hybrid deep learning. IEEE Transactions on Smart Grid, vol. 14, no. 5, pp. 1–13, 2023.
[34] A. Takiddin, R. Atat, M. Ismail, O. Boyaci, K. R. Davis, and E. Serpedin. Generalized graph neural network-based detection of false data injection attacks in smart grids. IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 7, no. 3, pp. 1–13, 2023.
[35] T. Zhu, J. Wang, Y. Zhu, H. Chen, H. Zhang, and S. Yin. Power grid network security: A lightweight detection model for composite false data injection attacks using spatiotemporal features. International Journal of Critical Infrastructure Protection, vol. 46, Art. no. 100697, 2024.
[36] F. Kausar, S. Deo, S. Hussain, and Z. Ul Haque. Federated deep learning model for false data injection attack detection in cyber physical power systems. Energies, vol. 17, no. 21, p. 5337, 2024.
[37] M. Kesici, B. Pal, and G. Yang. Detection of false data injection attacks in distribution networks: A vertical federated learning approach. IEEE Transactions on Smart Grid, vol. 15, no. 6, pp. 5952–5964, 2024.
[38] M. Kesici, M. Alduhaymi, A. Ishchenko, G. Yang, and B. C. Pal. Locational detection of false data injection attacks in smart grids: A cloud–edge framework based on split learning. IEEE Transactions on Smart Grid, vol. 16, no. 6, pp. 5378–5391, 2025.
[39] KDD-CUP99 Dataset. [Online]. Available: http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ying Lan, Chenye Zhu, Fan Wu, Qibin Hu

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This is an open-access article distributed under the terms of the Creative Commons Attribution CC BY 4.0 license, which permits unlimited use, distribution, and reproduction in any medium so long as the original work is properly cited.