Detecting DDoS Attacks in U.S. Smart Grids Using Explainable Machine Learning
Open Access DepositedThe integration of cyber-physical networks in the U.S. power grid has increased its vulnerability to Distributed Denial-of-Service (DDoS) attacks, posting significant threats to essential grid operations and potentially leading to cascading power failures and blackouts nationwide. This vulnerability is exacerbated by the inherent weaknesses in Internet Protocols, the widespread adoption of Internet of Things (IoT) devices with inadequate security measures, and the increased attack capabilities by U.S. adversaries. This research proposes a novel, explainable machine learning (ML) model designed for the precise and transparent detection of DDoS attacks within the U.S. power grid.Using a subset of the CICDDoS2019 dataset, the study implements data preprocessing, feature selection, data balancing, model training, testing, and optimization. The goal is to achieve a minimum precision and accuracy of 95%, enhancing the security of the U.S. power grid. The research also employs the XAI method, specifically the Local Interpretable Model-Agnostic Explanation (LIME) module, to identify and quantify key features driving the model's decisions, improving transparency and trust. Through a comparative analysis of seven machine learning algorithms, Random Forest emerged as the top-performing model. Hyperparameter tuning using GridSearchCV, along with learning curve analysis, further optimized the model's performance. This research contributes to the development of explainable and trustworthy ML-based cybersecurity solutions to enhance the resilience of the U.S. smart grid against sophisticated cyber threats and adversaries, this novel praxis marks a major advancement in the field of smart grid cybersecurity.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.