PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 27, 2026Telecom0 citationsOpen Access

Unsupervised Deep Learning-Based Network Traffic Anomaly Detection for DDoS Mitigation in Smart Microgrid Communication Infrastructure

View Full Paper
BHBehar HaxhismajliGMGalia MarinovaEHEdmond Hajrizi

Key Points

  • The study aims to develop a model for detecting DDoS attacks in smart microgrids using unsupervised learning.
  • Utilized a CNN-LSTM model trained on normal traffic data to predict future traffic windows.
  • Implemented a dual-branch architecture to process both time-series metrics and flow aggregates.
  • Evaluated against three protocol-specific DDoS attack scenarios without prior exposure during training.
  • The CNN-LSTM model achieved higher precision and recall compared to isolation forest and autoencoder baselines.
  • It effectively detected Modbus SCADA flooding, MQTT publish storms, and DNP3 response flooding.
  • Real-time detection and anomaly logging were implemented within a web-based monitoring platform.

Abstract

Smart microgrids depend on continuous communication between controllers, sensors, and actuators over industrial protocols like Modbus TCP, message queuing telemetry transport (MQTT), and distributed network protocol 3 (DNP3), which were designed without built-in security mechanisms. The gateway that aggregates this traffic represents a single point of failure and is vulnerable to distributed denial-of-service (DDoS) attacks. Most existing detection methods require labeled attack data for training, a condition rarely met in operational technology (OT) environments. This paper presents an unsupervised convolutional neural network–long short-term memory (CNN-LSTM) model trained exclusively on normal microgrid gateway traffic to predict the next traffic window; anomalies are flagged when the prediction error exceeds a threshold derived from the training distribution. A dual-branch architecture processes metric time-series through LSTM layers and flow aggregate features through CNN layers, fusing both representations for prediction. The model is evaluated against three protocol-specific DDoS attack scenarios—Modbus supervisory control and data acquisition (SCADA) flooding, MQTT publish storm, and DNP3 response flooding—none of which are seen during training. Compared against an isolation forest baseline and an autoencoder baseline under identical unsupervised conditions, the CNN-LSTM achieves higher precision and recall on all attack types. The framework is deployed within a web-based monitoring platform that supports real-time detection and anomaly logging.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Haxhismajli et al. (2026) studied this question.

synapsesocial.com/papers/6a1689eb0c924ddd1bd589aahttps://doi.org/10.3390/telecom7030058
Ask AI
Helpful
Bookmark
Share
View Full Paper