Lujia Zhan, Saharnaz Mehrani, Chengzhi Xie, Payman Dehghanian
Malicious and negligent insiders pose significant security risks to mission-critical systems like electric power grids due to their high privileges in increasingly digitized infrastructures. This paper investigates the vulnerability of smart power grids to load redistribution (LR) attacks in the presence of insider threats. We introduce a stochastic optimization model to minimize the expected risk of high operation costs due to LR attacks by protecting critical grid components and deploying detection technologies, such as honeypots, to detect insider threats and prevent information leakage. Our model accounts for uncertainties in insider presence, honeypot effectiveness, and attack targets, and uses the conditional value-at-risk (CVaR) measure, which can be adjusted based on the decision-maker's conservatism. In addition, it accounts for real-time power demand variations and dynamic false-data injection by attackers. To enhance tractability, we transform our model, originally formulated as a trilevel mixed-integer nonlinear programming (Tri-MINLP) problem, into an approximate single-level mixed-integer linear programming (MILP) formulation. We apply our proposed model to the IEEE 14-bus test system, and our results highlight the effectiveness of our approach in lowering the risk of high operation costs due to LR attacks. In addition, we present several insights by assessing the impact of key factors on the expected financial risk of attacks, including the protection budget, insider-threat likelihood, honeypot-detection effectiveness, and the defender's decision-making conservatism.