1. China Electric Power Research Institute Co. Ltd Nanjing 210003 China; 2. State Grid Laboratory of Power Cyber-Security Protection and Monitoring Technology Nanjing 210003 China; 3. Wuhan Power Supply Company State Grid Hubei Electric Power Co. Ltd Wuhan 430000 China
Abstract:With the continuous advancement of digital transformation in power grids, data interactions in power business systems have shown long-chain circulation characteristics across systems, regions, and entities. To address the difficulty of accurately identifying unconventional data leakage behaviors in power business systems, such as unauthorized circulation of sensitive data, over-privileged user access, and long-term cumulative data export, this paper proposes an endogenous-exogenous semantic collaborative method for power data leakage risk identification. Firstly, power business traffic is aggregated by time slices and organized into long time-series windows, from which endogenous semantics are generated to describe behavioral features such as access frequency, data volume, receiver changes, and cumulative export volume. security labels and associated logs are used to construct exogenous semantics containing information such as data classification, permitted circulation domains, data providers, data receivers, and signature status. Sparse cross-attention associates circulation behavior with security-label semantics. The sparse relation mask is determined by predefined field mappings, temporal neighborhood relations, and top-k semantic similarity. These relations retain associations between traffic statistics and security-label fields while reducing interactions among weakly related time slices and semantic fields. Secondly, risk semantic compression is applied to the fused representations. A learnable retention probability matrix and Bernoulli sampling preserve information related to subject authorization, circulation-path compliance, and long-term cumulative outflow. The compressed risk semantics are used to reconstruct masked numerical time-series windows. Reconstruction errors are converted into leakage risk scores, and the decision threshold is selected according to the Affiliated F1 score on validation set. Thirdly, the PowerLeakage dataset is constructed from the ELECTRON-MITM-Attack Dataset and SANDI-2024. Based on publicly available power communication traffic data and in accordance with power data classification, grading, and security identification management requirements, the PowerLeakage dataset is constructed. While retaining the original traffic statistical characteristics, business scenario mappings, field-level security identifiers, subject authorization relationships, and time-slice-level risk labels are further generated to verify the proposed method's ability to identify unconventional power data leakage risks. The method is compared with recurrent neural network, long short-term memory, bidirectional long short-term memory, BiLC, TranAD, and MindTS under the same data split, window length, and evaluation metrics. The method obtains 92.65% for Aff-F, 82.13% for V-PR, and 83.70% for V-ROC. Ablation results show that removing exogenous semantic text reduces the average of the three metrics from 86.16 to 82.80, while removing sparse endogenous-exogenous semantic fusion reduces it to 82.79. Finally, the results indicate that long time-series circulation behavior and security-label semantics provide complementary information for unconventional data leakage identification. Sparse semantic fusion, risk semantic compression, and cross-modal reconstruction associate circulation behavior with corresponding security constraints and quantify deviations related to subject authorization, circulation paths, and cumulative outflow.
[1] 国家能源局. 新型电力系统发展蓝皮书[R]. 北京: 国家能源局, 2023. [2] 国家发展改革委, 国家能源局, 国家数据局. 加快构建新型电力系统行动方案(2024—2027年): 发改能源〔2024〕1128号[R]. 北京: 国家发展改革委, 国家能源局, 国家数据局, 2024. [3] 丁正凯, 颜剑峰, 王蓓蓓. 电力数据资产价值化评估: 研究框架与展望[J]. 电工技术学报, 2026, 41(5): 1425-1449. Ding Zhengkai, Yan Jianfeng, Wang Beibei.The valuation of electricity power data assets: research framework and future prospects[J]. Transactions of China Electrotechnical Society, 2026, 41(5): 1425-1449. [4] 郭庆来, 王博弘, 田年丰, 等. 能源互联网数据交易: 架构与关键技术[J]. 电工技术学报, 2020, 35(11): 2285-2295. Guo Qinglai, Wang Bohong, Tian Nianfeng, et al.Data transactions in energy Internet: architecture and key technologies[J]. Transactions of China Electro-technical Society, 2020, 35(11): 2285-2295. [5] 黄彦钦, 余浩, 尹钧毅, 等. 电力物联网数据传输方案: 现状与基于5G技术的展望[J]. 电工技术学报, 2021, 36(17): 3581-3593. Huang Yanqin, Yu Hao, Yin Junyi, et al.Data transmission schemes of power Internet of Things: present and outlook based on 5G technology[J]. Transactions of China Electrotechnical Society, 2021, 36(17): 3581-3593. [6] 国家市场监督管理总局, 国家标准化管理委员会.数据安全技术数据分类分级规则: GB/T 43697—2024[S]. 北京: 中国标准出版社, 2024. [7] 全国网络安全标准化技术委员会秘书处. 网络安全标准实践指南—网络数据标签标识技术要求[R]. 北京: 全国网络安全标准化技术委员会, 2026. [8] 张涛, 费稼轩, 王琦, 等. 电力信息物理系统跨域攻击协同防御架构及机制研究[J]. 电子学报, 2024, 52(4): 1205-1218. Zhang Tao, Fei Jiaxuan, Wang Qi, et al.Research of architecture and mechanism of coordinative defense methods for cross-domain attacks of cyber physical system[J]. Acta Electronica Sinica, 2024, 52(4): 1205-1218. [9] Miao Weiwei, Zhao Xinjian, Zhang Yinzhao, et al.A deep learning-based method for preventing data leakage in electric power industrial Internet of Things business data interactions[J]. Sensors, 2024, 24(13): 4069. [10] Jiang Chengzhi, Deng Song.Data leakage prevention system for smart grid[C]//1st International Conference on Big Data and Security (ICBDS 2019), Nanjing, China, 2019: 541-549. [11] Deng Song, Yue Dong, Zhou Aihua, et al.Distributed content filtering algorithm based on data label and policy expression in active distribution networks[J]. Neurocomputing, 2017, 270: 159-169. [12] Deng Song, Yuan Changan, Yang Jiquan, et al.Distributed mining for content filtering function based on simulated annealing and gene expression programming in active distribution network[J]. IEEE Access, 2017, 5: 2319-2328. [13] Deng Song, Xie Xiangpeng, Yuan Changan, et al.Numerical sensitive data recognition based on hybrid gene expression programming for active distribution networks[J]. Applied Soft Computing, 2020, 91: 106213. [14] Deng Song, Cai Qingyuan, Zhang Zi, et al.Data filter function incremental mining based on feature selection in an active distribution network[J]. IET Cyber-Physical Systems: Theory & Applications, 2020, 5(3): 301-309. [15] 肖勇, 钱斌, 蔡梓文, 等. 电力物联网终端非法无线通信链路检测方法[J]. 电工技术学报, 2020, 35(11): 2319-2327. Xiao Yong, Qian Bin, Cai Ziwen, et al.Malicious wireless communication link detection of power Internet of thing devices[J]. Transactions of China Electrotechnical Society, 2020, 35(11): 2319-2327. [16] 潘玺安, 艾欣, 胡俊杰, 等. 考虑网络安全约束的分布式智能电网边云协同优化调度方法[J]. 电工技术学报, 2024, 39(19): 6104-6118. Pan Xi’an, Ai Xin, Hu Junjie, et al.Network security constrained distributed smart grid edge-cloud collaborative optimization scheduling[J]. Transactions of China Electrotechnical Society, 2024, 39(19): 6104-6118. [17] 崔沛然, 崔明建, 汪清, 等. 基于张量分解个性化联邦学习的网络-光伏爬坡协同攻击辨识[J]. 电工技术学报, 2025, 40(23): 7677-7693. Cui Peiran, Cui Mingjian, Wang Qing, et al.Cyber-ramping coordinated attack identification method for PV using a tensor decomposition based personalized federated learning[J]. Transactions of China Electro-technical Society, 2025, 40(23): 7677-7693. [18] 李扬, 李智, 陈亮, 等. 发电机动态状态估计中的一种虚假数据注入攻击方法[J]. 电工技术学报, 2020, 35(7): 1476-1488. Li Yang, Li Zhi, Chen Liang, et al.A false data injection attack method for generator dynamic state estimation[J]. Transactions of China Electrotechnical Society, 2020, 35(7): 1476-1488. [19] Berghout T, Benbouzid M, Muyeen S M.Machine learning for cybersecurity in smart grids: a comprehensive review-based study on methods, solutions, and prospects[J]. International Journal of Critical Infrastructure Protection, 2022, 38: 100547. [20] Radoglou Grammatikis P, Sarigiannidis P, Efstatho-poulos G, et al. ARIES: a novel multivariate intrusion detection system for smart grid[J]. Sensors, 2020, 20(18): 5305. [21] 王方雨, 刘文颖, 陈鑫鑫, 等. 基于“秩和”近似相等特性的同期线损异常数据辨识方法[J]. 电工技术学报, 2020, 35(22): 4771-4783. Wang Fangyu, Liu Wenying, Chen Xinxin, et al.Abnormal data identification of synchronous line loss based on the approximate equality of rank sum[J]. Transactions of China Electrotechnical Society, 2020, 35(22): 4771-4783. [22] 申江卫, 岩川, 刘永刚, 等. 基于数据挖掘与大数据分析的电池故障诊断与异常检测[J]. 电工技术学报, 2024, 39(24): 7979-7994. Shen Jiangwei, Yan Chuan, Liu Yonggang, et al.Battery fault diagnosis and anomaly detection based on data mining and big data analysis[J]. Transactions of China Electrotechnical Society, 2024, 39(24): 7979-7994. [23] 陈俊生, 李剑, 陈伟根, 等. 采用滑动窗口及多重加噪比堆栈降噪自编码的风电机组状态异常检测方法[J]. 电工技术学报, 2020, 35(2): 346-358. Chen Junsheng, Li Jian, Chen Weigen, et al.A method for detecting anomaly conditions of wind turbines using stacked denoising autoencoders with sliding window and multiple noise ratios[J]. Transactions of China Electrotechnical Society, 2020, 35(2): 346-358. [24] 马然, 栗文义, 齐咏生. 风电机组健康状态预测中异常数据在线清洗[J]. 电工技术学报, 2021, 36(10): 2127-2139. Ma Ran, Li Wenyi, Qi Yongsheng.Online cleaning of abnormal data for the prediction of wind turbine health condition[J]. Transactions of China Electrotechnical Society, 2021, 36(10): 2127-2139. [25] 马良玉, 程善珍. 基于支持向量数据描述和XGBoost的风电机组异常工况预警研究[J]. 电工技术学报, 2022, 37(13): 3241-3249. Ma Liangyu, Cheng Shanzhen.Abnormal state early warning of wind turbine generator based on support vector data description and XGBoost[J]. Transactions of China Electrotechnical Society, 2022, 37(13): 3241-3249. [26] 李阳, 沈小军, 张扬帆, 等. 基于速度-关联约束的风电机组风速感知异常数据识别方法[J]. 电工技术学报, 2023, 38(7): 1793-1807. Li Yang, Shen Xiaojun, Zhang Yangfan, et al.Cleaning method of wind speed outliers for wind turbines based on velocity and correlation constraints[J]. Transactions of China Electrotechnical Society, 2023, 38(7): 1793-1807. [27] 李阳, 沈小军, 杨伟新, 等. 基于运行数据的风电场风速传感器运行品质评价方法及应用[J]. 电工技术学报, 2024, 39(13): 4188-4203. Li Yang, Shen Xiaojun, Yang Weixin, et al.An operation quality evaluation method and its applications for wind speed sensors of wind farms based on operation data[J]. Transactions of China Electrotechnical Society, 2024, 39(13): 4188-4203. [28] Elrawy M F, Hadjidemetriou L, Laoudias C, et al.Detecting and classifying man-in-the-middle attacks in the private area network of smart grids[J]. Sustainable Energy, Grids and Networks, 2023, 36: 101167. [29] Gutiérrez Mlot E D, Saldana J, Rodríguez R J, et al. A dataset to train intrusion detection systems based on machine learning models for electrical substations[J]. Data in Brief, 2024, 57: 111153. [30] Tuli S, Casale G, Jennings N R.TranAD: deep transformer networks for anomaly detection in multivariate time series data[J]. Proceedings of the VLDB Endowment, 2022, 15(6): 1201-1214. [31] Hu Shiyan, Jin Jianxin, Shu Yang, et al. Towards multimodal time series anomaly detection with semantic alignment and condensed interaction[J/OL]. ArXiv, 2026: 2604 23972v1. (2026-03-23)[2026-07-08]. https://doi.org/10.48550/arXiv.2603.21612. [32] Huet A, Navarro J M, Rossi D.Local evaluation of time series anomaly detection algorithms[C]// Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Washington D.C., USA, 2022: 635-645. [33] Paparrizos J, Boniol P, Palpanas T, et al.Volume under the surface: a new accuracy evaluation measure for time-series anomaly detection[J]. Proceedings of the VLDB Endowment, 2022, 15(11): 2774-2787.