自验证异常检测:基于可解释人工智能的分布式能源网络安全
Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks
- Iowa State University(爱荷华州立大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对分布式能源网络,提出基于XAI的自验证异常检测框架ExCYDER,结合LightGBM与SHAP验证警报,实现高准确率与可解释性。
AI中文摘要:
分布式能源(DER)的快速增长显著扩大了现代电网的网络攻击面。此外,攻击技术的日益复杂化要求异常检测系统(ADS)具备准确性、可解释性和可靠性,以支持DER的网络安全。虽然基于机器学习的ADS提供了强大的检测能力,但其黑箱特性降低了操作员的信任,并限制了安全运营中心(SOC)有效解释警报和响应的能力,凸显了可解释人工智能(XAI)在确保透明度和操作信心方面的必要性。本文提出了一个针对DER网络量身定制的基于XAI的异常检测框架(ExCYDER)。该框架采用自验证机制,对ADS警报进行验证,以确保可信的决策制定。ExCYDER结合了LightGBM与SHAP,以检查每个模型决策是否与其特征归因证据一致,从而使系统能够确认其内部推理的一致性和可靠性。在真实的DNP3数据集上的实验实现了超过98%的检测准确率,平均规则-SHAP一致性为44.6%,每个警报的SHAP延迟为14.5毫秒,置信度偏差在5%以内,展示了稳定的验证行为和最小的计算开销。该框架能够区分一致和不一致的警报,而不损害检测准确性,证明了在基于XAI的ADS中集成验证增强了面向DER的SOC的可解释性、可审计性和操作鲁棒性。
英文摘要:
The rapid growth of Distributed Energy Resources (DERs) has significantly expanded the cyber attack surface of modern power grids. Furthermore, increasing sophistication in attack techniques demands anomaly detection systems (ADS) that are accurate, interpretable, and reliable to support DER cybersecurity. While ML-based ADS provide strong detection capabilities, their black-box nature reduces operator trust and limits Security Operation Center's (SOC) ability to effectively interpret alerts and respond, highlighting the need for explainable Artificial Intelligence (XAI) to ensure transparency and operational confidence. This paper presents an XAI-based anomaly detection framework tailored for DER networks (ExCYDER). The proposed framework uses a self-verifying mechanism that validates ADS alerts to ensure trustworthy decision-making. ExCYDER combines LightGBM with SHAP to check whether each model decision aligns with its feature-attribution evidence, allowing the system to confirm that its internal reasoning is consistent and reliable. Experiments on a realistic DNP3 dataset achieved over 98% detection accuracy, an average rule--SHAP consistency of 44.6%, a SHAP latency of 14.5 ms per alert, and a confidence deviation within 5%, demonstrating stable verification behavior with minimal computational overhead. The framework distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-focused SOCs.