Stacking Ensemble Learning Model for Intrusion Detection in Electrical Substation

Open

Mohammad Mahruf Alam, Feddy Setio Pribadi, Rizky Ajie Aprilianto, Arvina Rizqi Nurul’aini

2025 Jurnal RESTI Vol. 9 Issue 5 Article Cited by 0 Quartile

Abstract

Electrical substations are crucial infrastructure in power transmission and distribution but are increasingly vulnerable to cyber threats. However, existing intrusion detection systems (IDS) face several limitations, such as high false positive rates, weak in anticipating new attack patterns, and imbalances in detecting different types of intrusions. This study proposes a Stacking Ensemble Learning model to enhance intrusion detection accuracy in electrical substations. The proposed model integrates Logistic Regression (LR), K-Nearest Neighbors (KNN), Support Vector Machine (SVM), and XGBoost (XGB) as base models with XGB acting as the meta-model. A real-world electrical substation IEC 60870-5-104 network traffic dataset comprising 319,949 instances with multiple attacks, such as DoS, Port Scan, NTP DdoS, IEC 104 Starvation, Fuzzy Attack, Flood Attack, and MITM, was used in this study. The results demonstrate that the stacking model achieves the best performance, with accuracy (0.99990), precision (0.99990), recall (0.99990), and F1 score (0.99990), surpassing the base model, Bagging, and Boosting. T-test results further confirmed statistical significance, with p-values of 0.00428 (LR), 0.04237 (SVM), 0.00000 (XGB), 0.00057 (KNN), 0.00549 (Boosting), and 0.00000 (Bagging) reinforcing the superiority of the proposed method approach. These findings highlight the effectiveness of Stacking Ensemble Learning in enhancing the detection performance of IDS for electrical substations and outperforming traditional models and other ensemble learning methods. © 2025, Ikatan Ahli Informatika Indonesia. All rights reserved.

Affiliations

Department of Electrical Engineering, Faculty of Engineering, Universitas Negeri Semarang, Semarang, Indonesia