Learning fuzzy normal-operation regimes for interpretable power system anomaly detection
This paper presents an interpretable one-class anomaly detection framework for power systems based on adaptive neuro-fuzzy inference systems (ANFIS). The proposed method is trained exclusively on benign operational data and learns a compact set of fuzzy regimes describing normal cyber-physical behavior. The learned regimes are used to define rule-local invariant bounds and regularized Gaussian compatibility models. A fuzzy rule-weighted Mahalanobis score then measures the compatibility of each new observation with the activated benign regimes. Unlike supervised detectors, the proposed method requires no fault or attack samples during training and evaluates anomalous observations through deviations from learned normal operation. The framework is evaluated on the Mississippi State University and Oak Ridge National Laboratory Power System Attack Dataset, which contains benign operation, natural faults, and cyberattacks. The proposed detector achieves a ROC-AUC of 0.9773, a PR-AUC of 0.9998, precision of 0.9994, recall of 0.9265, specificity of 0.9138, and an F1-score of 0.9616. In addition to anomaly detection, the framework provides rule and feature-level explanations by identifying the activated fuzzy regime, the measurements contributing most strongly to the anomaly score, and any violated invariant conditions. The learned rules also capture distinct physical measurement profiles, supporting interpretable analysis of detected faults and attacks.
Authors
- Mirco Rampazzo (ORCID: https://orcid.org/0000-0003-0881-0131)
- Emad Efatinasab (ORCID: https://orcid.org/0000-0003-3812-436X)
- Nahal Azadi
Institutions
- University of Padua (IT)
Publication Details
- Journal
- Electric Power Systems Research
- Published
- 2026-09-19
- DOI
- https://doi.org/10.1016/j.epsr.2026.114221
- Primary Topic
- Smart Grid Security and Resilience
- Type
- article
- Field-Weighted Citation Impact
- 0.00