With the increasing number of users and multi-type loads accessing the cyber–physical distribution system (CPDS), the bidirectional interaction between the system becomes more and more frequent. The Load aggregator (LA) also plays an increasingly important role in the interaction process. However, the LA’s high dependence on information and lack of security measures make it vulnerable to attacks, so this paper analyzes the interactive security of the LAs from two points. Considering the game process between the LAs and users from the attacker’s point of view, this paper puts forward an attack strategy aiming cost function of the LAs, establishes a bi-level multi-objective programming attack model of false data injection attacks(FDIAs), and proposes an attack detection method based on the multi-state matching method and improved similar daily data preprocessing generative adversarial network (P-GAN) from the defender’s point of view to defend against the above attack strategy. Furthermore, a hybrid detection mechanism combining event triggering and periodic detection is proposed to ensure response speed and adaptability of detection. The effectiveness of the proposed attack model and the detection method is verified by simulation analysis.