ABSTRACT To address the challenges of real‐time control over the dynamic evolution of malware behavior and abnormal traffic in smart grids, this study proposed a dynamic defense model integrating graph attention network (GAT), long short‐term memory (LSTM), and adversarial reinforcement learning (ARL). By incorporating the ARL mechanism to optimize the decision‐making process of GAT‐LSTM, the model extracted more robust spatio‐temporal feature representations in adversarial environments, enabling precise prediction of malicious activities. Furthermore, a constraint‐optimized active traffic shaping strategy generator was designed to map predicted probabilities in real time to optimal control commands. The study first analyzed the performance of the combination algorithm. The results showed that the algorithm's feature recognition accuracy could reach 96.3%, demonstrating excellent performance. The effectiveness of the malware behavior prediction model was then analyzed. The results showed that the model's prediction accuracy could reach 96.7%. The active traffic shaping model could defend against more than 94% of network attacks. In summary, the dynamic defense method proposed in this study can accurately predict malicious software behavior and defend against most network attacks, thereby ensuring the security of smart grids.
Yang et al. (Fri,) studied this question.