Hardware in loop simulation of replay attacks on synchrophasor data and detection using machine learning approach
Soumya Ranjan Nath, Bhavesh R. Bhalja, Tarlochan Sidhu · IET conference proceedings. · 2025
In the 21stcentury, the power system has integrated large-scale communication technology with existing infrastructure, enabling wide-area monitoring, protection, and control (WAMPAC) applications. Though this has enhanced the grid’s reliability, stability, security, and operations, it has also increased its dependency on communication networks, resulting in new cybersecurity issues. Among various cyber-attacks, Replay attacks have received less attention due to their similarity to healthy scenarios, making them difficult to detect. This article presents a machine learning (ML) approach using Random Forest (RF) to detect Replay attacks in Synchrophasor data. The method classifies data as either "Healthy" or "Replay-attack" by extracting statistical features such as mean, standard deviation, variance, skewness, kurtosis and auto-correlation. The algorithm’s effectiveness is evaluated by comparing different metrics with models like Support Vector Machines (SVM) andk-Nearest Neighbour(k-NN). To validate the proposed method, a Hardware-in-the-Loop (HIL) cyber-physical testbed was developed, and various datasets for training and validation were generated. Synchrophasor data, from a Phasor Measurement Unit (PMU) to a Phasor Data Concentrator (PDC), are generated using network emulation software containing both healthy cases and attack scenarios. The comparative analysis of the results demonstrates that the proposed model outperforms SVM andk-NN, thereby accurately detecting Replay attacks.