[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83057-en":3,"doc-seo-83057-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83057,13056703019404,"Miles","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","FDIFormer Protocol Aware Transformer Learning for False Data Injection Attack Detection in Smart Grid Networks","Smart grids rely on communications networks and IEC 61850-based intelligent electronic devices, yet tight integration increases exposure to cyberattacks such as message tampering and denial of service. A key threat is False Data Injection (FDI), where attackers delete, modify, or add packets to manipulate messages. Detecting FDI in IEC 61850 GOOSE traffic is difficult because malicious packets can closely mimic legitimate protocol behavior. FDIFormer addresses this with a feature-engineering-free framework that encodes GOOSE packet sequences as structured text windows and fine-tunes Transformer models to learn attack patterns directly, evaluated on the QUT-ZSS-2023-GOOSE dataset.","FDIFormer:Protocol-Aware Transformer Learning for False Data Injection Attack Detection in Smart  \nGrid Networks  \nSandara Sathsarani Wijethunga, Muneeb Ul Hassan, Member, IEEE, and Nasrin Sohrabi, Member, IEEE  \narXiv :2607 .062 13v 1 [ cs .CR] 7 Jul 2026  \nAbstract—Smart grids use communication networks and intelligent electronic devices for reliable and automated operation of power systems. As these systems become increasingly interconnected, they are also becoming more exposed to cyberattacks such as message tampering, false command injection, and denialof-service attacks. One particularly concerning threat is False Data Injection (FDI), where attackers manipulate communication messages by deleting, modifying, or adding packets. This is especially crucial in IEC 61850-based substations, where Generic Object-Oriented Substation Event (GOOSE) messages are used for delivering time-critical protection and control information between devices. Detecting FDI attacks in IEC 61850 GOOSE traffic remains challenging because malicious packets can closely resemble legitimate communication, making them difficult to distinguish from normal operational behaviour. Furthermore, many existing detection methods depend heavily on manually engineered protocol features, which require extensive domain knowledge and may not generalise well across different smart grid environments. This paper proposes FDIFormer, a featureengineering-free framework for FDI attack detection using structured textual representations of GOOSE packet sequences and fine-tuned pre-trained Transformer models. The proposed framework converts protocol packets into structured text windows that capture communication behaviour and enables Transformer models to learn attack-related patterns directly from the data. The framework is evaluated using the QUT-ZSS-2023-GOOSE dataset under a scenario-level three-fold cross-validation strategy.  \nExperimental results show that GraphCodeBERT achieves an MCC of 0.595 ± 0.122, achieving performance comparable to the strongest feature-engineered baseline, XGBoost (MCC = 0.604 ± 0.121), while improving MCC by 0.133 compared with the TF-IDF baselines. These findings demonstrate that pre-trained Transformer representations can provide an effective technique for FDI attack detection in IEC 61850 GOOSE communication without relying on manually engineered protocol features.  \nIndex Terms—IEC 61850, GOOSE protocol, False Data Injection, Transformer models, pre-trained language models, smart grid cybersecurity, intrusion detection, feature-engineering-free detection.  \nI. INTRODUCTION  \nSMART Grids have become an important part of modern  \npower systems because they improve efficiency, reliability, and real-time monitoring of electricity networks [19], [20] . With the switch of substations to digital architectures, standardised communication protocols have become essential for coordinating the growing number of interconnected devices  \nS. S. Wijethunga, M. U. Hassan, and N. Sohrabi are with the School of Information Technology, Deakin University, Australia (email: [s224740132@deakin.edu.au](s224740132@deakin.edu.au); [muneeb.ulhassan@deakin.edu.au](muneeb.ulhassan@deakin.edu.au); nas[rin.sohrabi@deakin.edu.au](rin.sohrabi@deakin.edu.au)) .  \n[36] . The IEC 61850 standard has been widely used in modern substations to support communication between Intelligent Electronic Devices (IEDs), providing a common framework for interoperability and automation [21], [22] .  \nThe Generic Object-Oriented Substation Event (GOOSE) protocol is one of the communication services defined by IEC 61850, which is especially important for fast, eventdriven exchange of protection and control information between substation devices [36] . GOOSE messages are developed for speed and reliable communication over shared Ethernet networks and are time-sensitive, not designed for security and thus subject to being hacked [24] .  \nIEC 61850 improves operational performance, but it als","cbCaip6QGIxJXlI6","https://ap.wps.com/l/cbCaip6QGIxJXlI6","pdf",8515218,2,1,15,"English","en",105,"# Introduction\n## Background: Smart grids and IEC 61850\n## GOOSE protocol and False Data Injection threats\n## Motivation and challenges of existing detection methods","[{\"question\":\"What is a False Data Injection (FDI) attack in smart grid communications?\",\"answer\":\"An FDI attack manipulates communication messages by deleting, modifying, or adding packets so that power system devices receive misleading data. In IEC 61850 contexts, this can mislead protection relays or controllers.\"},{\"question\":\"Why is detecting FDI attacks in IEC 61850 GOOSE traffic challenging?\",\"answer\":\"Malicious GOOSE messages can resemble legitimate operational traffic, making them difficult to distinguish. Additionally, many existing methods depend on manually engineered protocol features that may not generalize well.\"},{\"question\":\"How does FDIFormer detect FDI attacks without feature engineering?\",\"answer\":\"FDIFormer converts GOOSE packet sequences into structured textual representations (text windows) and fine-tunes pre-trained Transformer models to learn attack-related patterns directly from the data.\"}]",1784184915,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"fdiformer-protocol-aware-transformer-learning-for-false-data-injection-attack-detection-in-smart-grid-networks","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/fdiformer-protocol-aware-transformer-learning-for-false-data-injection-attack-detection-in-smart-grid-networks/83057/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-21","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is a False Data Injection (FDI) attack in smart grid communications?","Question",{"text":75,"@type":76},"An FDI attack manipulates communication messages by deleting, modifying, or adding packets so that power system devices receive misleading data. In IEC 61850 contexts, this can mislead protection relays or controllers.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why is detecting FDI attacks in IEC 61850 GOOSE traffic challenging?",{"text":80,"@type":76},"Malicious GOOSE messages can resemble legitimate operational traffic, making them difficult to distinguish. Additionally, many existing methods depend on manually engineered protocol features that may not generalize well.",{"name":82,"@type":73,"acceptedAnswer":83},"How does FDIFormer detect FDI attacks without feature engineering?",{"text":84,"@type":76},"FDIFormer converts GOOSE packet sequences into structured textual representations (text windows) and fine-tunes pre-trained Transformer models to learn attack-related patterns directly from the data.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]