Abstract
We propose an unsupervised machine learning approach for classifying cyberattacks on smart power grids, with a focus on multi-area AGC systems. Unlike prior work on attack design or detection, our method is the first to classify advanced attacks without labeled data. By analyzing internal gradients from a VAE combined with a TCN, we distinguish among time delay (TDA) and two types of false data injection (FDI) attacks. Simulations using PowerWorld show that K-means clustering on these gradients achieves over 95 % accuracy-comparable to supervised methods but without costly labeling. Our approach also detects zero-day attacks as distinct clusters using equilibrium K-Means.