paper-with-me

홈 › Papers

Large Language Model-Based Framework for Explainable Cyberattack Detection in Automatic Generation Control Systems

2025-07-29 · Muhammad Sharshar, Ahmad Mohammad Saber, Davor Svetinovic, Amr M. Youssef, Deepa Kundur, Ehab F. El-Saadany arxiv

The increasing digitization of smart grids has improved operational efficiency but also introduced new cybersecurity vulnerabilities, such as False Data Injection Attacks (FDIAs) targeting Automatic Generation Control (AGC) systems. While machine learning (ML) and deep learning (DL) models have shown promise in detecting such attacks, their opaque decision-making limits operator trust and real-world applicability. This paper proposes a hybrid framework that integrates lightweight ML-based attack detection with natural language explanations generated by Large Language Models (LLMs). Classifiers such as LightGBM achieve up to 95.13% attack detection accuracy with only 0.004 s inference latency. Upon detecting a cyberattack, the system invokes LLMs, including GPT-3.5 Turbo, GPT-4 Turbo, and GPT-4o mini, to generate human-readable explanation of the event. Evaluated on 100 test samples, GPT-4o mini with 20-shot prompting achieved 93% accuracy in identifying the attack target, a mean absolute error of 0.075 pu in estimating attack magnitude, and 2.19 seconds mean absolute error (MAE) in estimating attack onset. These results demonstrate that the proposed framework effectively balances real-time detection with interpretable, high-fidelity explanations, addressing a critical need for actionable AI in smart grid cybersecurity.

📄 PDF Abstract BibTeX arXiv:2507.22239

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

A Kolmogorov-Arnold Network for Explainable Detection of Cyberattacks on EV Chargers

2025-03-04 · Ahmad Mohammad Saber, Max Mauro Dias Santos, Mohammad Al Janaideh, Amr Youssef 외

The increasing adoption of Electric Vehicles (EVs) and the expansion of charging infrastructure and their reliance on communication expose Electric Vehicle Supply Equipment (EVSE) to cyberattacks. This paper presents a n…

Explainable Machine Learning for Cyberattack Identification from Traffic Flows

2025-05-02 · Yujing Zhou, Marc L. Jacquet, Robel Dawit, Skyler Fabre 외

The increasing automation of traffic management systems has made them prime targets for cyberattacks, disrupting urban mobility and public safety. Traditional network-layer defenses are often inaccessible to transportati…

Anomaly DetectionManagement

Large Language Models for Detecting Cyberattacks on Smart Grid Protective Relays

2026-01-07 · Ahmad Mohammad Saber, Saeed Jafari, Zhengmao Ouyang, Paul Budnarain 외 arxiv

This paper presents a large language model (LLM)-based framework that adapts and fine-tunes compact LLMs for detecting cyberattacks on transformer current differential relays (TCDRs), which can otherwise cause false trip…

The Role and Applications of Airport Digital Twin in Cyberattack Protection during the Generative AI Era

2024-08-08 · Abraham Itzhak Weinberg

In recent years, the threat facing airports from growing and increasingly sophisticated cyberattacks has become evident. Airports are considered a strategic national asset, so protecting them from attacks, specifically c…

Anomaly Detection

A Hybrid Approach for an Interpretable and Explainable Intrusion Detection System

2021-11-19 · Tiago Dias, Nuno Oliveira, Norberto Sousa, Isabel Praça 외

Cybersecurity has been a concern for quite a while now. In the latest years, cyberattacks have been increasing in size and complexity, fueled by significant advances in technology. Nowadays, there is an unavoidable neces…

Intrusion Detection