Anomaly detection method, device and computer equipment of power grid cyber physical system
By establishing a probabilistic dependency network and converting it into a probabilistic analysis network, the problem of low efficiency in anomaly detection in the power grid cyber-physical system is solved, and higher-precision system anomaly detection is achieved.
Patent Information
- Application Number
- CN202311035516.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-16
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2043-08-16
AI Technical Summary
In the existing technology, the anomaly detection efficiency of the power grid cyber-physical system is low and cannot effectively describe the cyber-physical processes of complex logic and transition states.
By obtaining the dependency and actual probability relationship between the node structures of the power grid cyber-physical system, a probabilistic dependency network is established and converted into a probabilistic analysis network carrying logical impact results for node anomaly detection.
The quantitative and qualitative calculation accuracy of the power grid cyber-physical system is improved, and the efficiency of detecting abnormal conditions of the system is enhanced.
Smart Images

Figure CN117171527B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of power grid cyber-physical system modeling, and in particular to a method, apparatus, and computer equipment for detecting anomalies in power grid cyber-physical systems. Background Art
[0002] As internet and IoT technologies mature, collaboration and interdependence between systems are becoming increasingly stronger. Interconnectivity between systems enables broader functional collaboration and expands the use of diverse information. While there's no consensus on the definition of cyber-physical systems, institutions and experts around the world have a relatively mature understanding. New power systems are typical system-level cyber-physical systems, with the application of new-generation intelligent technologies permeating every aspect of grid operation. Cyber-physical convergence will play an increasingly important role in renewable energy coordination, intelligent power distribution and utilization, drone inspections, and smart grid self-healing control.
[0003] Existing technologies often describe the structural characteristics of coupled CPS (Cyber-Physical Systems) networks through dependency networks. These networks reflect the connections between abstract nodes, but are unable to describe cyber-physical processes that involve complex logic and transition states, such as redundancy and functional degradation. Furthermore, current modeling based on dependency network theory primarily focuses on the site level, using substations as the smallest unit. This simplified approach is suitable for analyzing network dynamics, but falls short in analyzing the system's electrical and functional logic characteristics.
[0004] Currently, no effective solution has been proposed to the problem of low anomaly detection efficiency in power grid cyber-physical systems. Summary of the Invention
[0005] Based on this, it is necessary to provide an anomaly detection method, device and computer equipment for the power grid cyber-physical system to address the above technical problems.
[0006] In a first aspect, the present application provides a method for detecting anomalies in a power grid cyber-physical system. The method comprises:
[0007] Obtaining a dependency relationship and an actual probability relationship between at least two node structures of a power grid cyber-physical system, and collecting node structure states;
[0008] A dependency network is established based on dependency relationships, and actual probability relationships are introduced into the dependency network to obtain a probabilistic dependency network for the power grid cyber-physical system.
[0009] The probabilistic dependency network is converted into a probabilistic analysis network carrying logical impact results, and the node structure state is input into the probabilistic analysis network to obtain the node anomaly detection results of the power grid cyber-physical system; among them, the logical impact results are obtained based on the dependency relationship and the actual probability relationship.
[0010] In one embodiment, obtaining the actual probability relationship includes:
[0011] Obtain statistical data and logical dependencies of the power grid cyber-physical system, and obtain actual probability relationships based on the statistical data and logical dependencies.
[0012] In one embodiment, the node structure includes child nodes and target nodes, and the target node refers to a node whose corresponding state is determined based on the node structure state of the child node; the logical impact result includes a logical dependency relationship and an impact result, and converting the probabilistic dependency network into a probabilistic analysis network carrying the logical impact result includes:
[0013] If it is detected that the child node and the target node are in a direct dependency relationship, the logical dependency relationship between the child node and the target node is obtained according to the actual probability relationship, and the probabilistic dependency network is converted into a causal probability analysis network according to the logical dependency relationship;
[0014] If it is detected that the child node and the target node have an indirect dependency relationship, the arrow pointing expression of the probability dependency network is reversed according to the dependency relationship to obtain the impact result of the child node on the target node, and reverse reasoning is performed based on the actual probability relationship to obtain the evidence probability relationship; according to the impact result and the evidence probability relationship, the probability dependency network is converted into an evidence probability analysis network; among them, the probability analysis network includes a causal probability analysis network and an evidence probability analysis network.
[0015] In one embodiment, actual probability relationships are introduced into a dependency network to obtain a probabilistic dependency network for a power grid cyber-physical system, including:
[0016] Obtaining a preset virtual relationship node; wherein the virtual relationship node includes a virtual probabilistic relationship between at least three node structures;
[0017] According to the virtual probability relationship and the actual probability relationship, a dependency network is introduced to obtain a probabilistic dependency network.
[0018] In one embodiment, the node structure state is input into a probabilistic analysis network to obtain quantitative analysis results for the cyber-physical system, including:
[0019] The node anomaly detection results of the cyber-physical system are obtained based on the actual probability relationship, dependency relationship and node structure status.
[0020] In one of the embodiments, the node structure comprises a target node and a sub-node, and a node anomaly detection result of the cyber-physical system is obtained according to the actual probability relationship, the dependency relationship and the node structure state, comprising:
[0021] In the case that the probability analysis network is a causal analysis network, the node structure state is multiplied according to the actual probability relationship and the dependency relationship to obtain a causal dependency strength, and the number of causal states of the sub-node is obtained according to the node structure state, the causal dependency strength is averaged according to the number of causal states to obtain the node anomaly detection result of the power grid cyber-physical system;
[0022] In the case that the probability analysis network is an evidence analysis network, the actual probability relationship between the target node and the sub-node is multiplied according to the dependency relationship to obtain a support factor function value, and the number of evidence states of the sub-node is obtained according to the node structure state, the support factor function value is averaged according to the number of states to obtain the node anomaly detection result of the power grid cyber-physical system.
[0023] In one of the embodiments, the node structure comprises a target node and a sub-node, and a node anomaly detection result of the cyber-physical system is obtained according to the actual probability relationship, the dependency relationship and the node structure state, comprising:
[0024] In the case that the probability analysis network is an evidence probability analysis network, the node structure state is input into the probability analysis network, and the node structure state is detected by the probability analysis network;
[0025] If the probability of detecting the failure of the sub-node based on the node structure state is less than a preset threshold, the node structure state is determined as a small probability feature type, and in response to the determined small probability feature type, the algebraic result of the sub-node is generated according to the actual probability relationship;
[0026] According to the algebraic result of the sub-node, a node anomaly detection result of the power grid cyber-physical system is obtained.
[0027] In one of the embodiments, the node anomaly detection result comprises a target node state result; according to the algebraic result of the sub-node, a node anomaly detection result of the power grid cyber-physical system is obtained, comprising:
[0028] According to the algebraic result of the sub-node, a support factor is obtained; wherein all the sub-nodes and the support factor are in one-to-one correspondence;
[0029] All the support factors are multiplied to obtain a support factor function value, and the target node state result is obtained according to the support factor function value.
[0030] In a second aspect, the application further provides an anomaly detection device for a power grid cyber-physical system. The device comprises:
[0031] The acquisition module is configured to acquire a dependency relationship and an actual probability relationship between at least two node structures of the power grid information physical system, and collect a node structure state;
[0032] The calculation module is configured to establish a dependency network according to the dependency relationship, and introduce the actual probability relationship into the dependency network to obtain a probability dependency network for the power grid information physical system.
[0033] The generation module is configured to convert the probability dependency network into a probability analysis network carrying a logical influence result, and input the node structure state into the probability analysis network to obtain a node anomaly detection result for the power grid information physical system, wherein the logical influence result is obtained according to the dependency relationship and the actual probability relationship.
[0034] In a third aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0035] The acquisition module is configured to acquire a dependency relationship and an actual probability relationship between at least two node structures of the power grid information physical system, and collect a node structure state;
[0036] The calculation module is configured to establish a dependency network according to the dependency relationship, and introduce the actual probability relationship into the dependency network to obtain a probability dependency network for the power grid information physical system.
[0037] The generation module is configured to convert the probability dependency network into a probability analysis network carrying a logical influence result, and input the node structure state into the probability analysis network to obtain a node anomaly detection result for the power grid information physical system, wherein the logical influence result is obtained according to the dependency relationship and the actual probability relationship.
[0038] The above-mentioned anomaly detection method, device and computer equipment for the power grid cyber-physical system first obtains the dependency relationships, actual probability relationships and node structural states between multiple nodes of the power grid cyber-physical system; secondly, a dependency network is established based on the dependency relationships, and the actual probability relationships are introduced into the dependency network to obtain a probabilistic dependency network; finally, the probabilistic dependency network is converted into a probabilistic analysis network, and the node anomaly detection results for the power grid cyber-physical system are obtained based on the node structural states. Through the above-mentioned method, the actual probability relationships are introduced into the dependency network, which can express more dependency relationships between nodes, solves the shortcoming that the existing dependency network cannot describe cyber-physical processes containing complex logic and transition states, and improves the accuracy of quantitative and qualitative calculations of the power grid cyber-physical system; further, the probabilistic dependency network is converted into a probabilistic analysis network carrying logical influence results, which facilitates the subsequent detection and calculation of the node states of the power grid cyber-physical system and the calculation and analysis of the influence relationships between nodes, thereby improving the efficiency of detecting system abnormal states. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 1 is a flow chart of a method for detecting abnormalities in a cyber-physical system of a power grid according to an embodiment;
[0040] Figure 2 1 is a schematic diagram of a one-way probability dependency relationship of a power grid system anomaly detection method in one embodiment;
[0041] Figure 3 Schematic diagram of bidirectional probability dependency of a power grid system anomaly detection method in one embodiment;
[0042] Figure 4 Schematic diagram of a one-to-many probability dependency relationship of a power grid system anomaly detection method in one embodiment;
[0043] Figure 5 Schematic diagram of a probabilistic dependency hierarchical model of a power grid system anomaly detection method in one embodiment;
[0044] Figure 6 Schematic diagram of virtual relationship nodes of a method for detecting abnormalities in a power grid system in one embodiment;
[0045] Figure 7 Schematic diagram of equivalent transformation between a series-parallel structure and a structure including virtual relationship nodes in one embodiment;
[0046] Figure 8 A schematic diagram of a probability analysis network in one embodiment;
[0047] Figure 9 A schematic diagram of the relationship between the target node state and the child node state in one embodiment;
[0048] Figure 10 A probabilistic analysis network for a circuit protection function of a power grid cyber-physical system in one embodiment;
[0049] Figure 11 is a structural block diagram of an abnormality detection device for a power grid cyber-physical system in one embodiment;
[0050] Figure 12 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0051] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0052] The embodiment of the present application provides an abnormality detection method for a power grid cyber-physical system. This embodiment uses the method applied to a terminal as an example for illustration. It is understandable that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through the interaction between the terminal and the server. In this embodiment, Figure 1 As shown, a method for detecting anomalies in a power grid cyber-physical system is provided, the method comprising the following steps:
[0053] Step S101 : obtaining the dependency relationship and actual probability relationship between at least two node structures of a power grid cyber-physical system, and collecting the node structure status.
[0054] Among them, there can be multiple node structures mentioned above. In actual applications, the node structure often contains multiple node structures, such as target nodes, child nodes, etc., wherein the target node is a node whose corresponding state is determined based on the state of the child node. The above-mentioned dependency relationship can include one-way dependency and mutual dependency. The dependency relationships involved in this application are all one-way dependencies, that is, only the state of one party is affected by the other party. In actual applications, relevant technical personnel can introduce mutual dependency relationships according to actual conditions, and the two parties in the mutual dependency relationship affect each other. For the above-mentioned dependency relationships, they can be divided into direct dependency and indirect dependency. Generally speaking, when the dependency relationship is single and close, the dependency relationship can be considered as direct dependency, otherwise it is indirect dependency. The above-mentioned actual probability relationship in this application usually refers to the conditional probability relationship between two node structures. The above-mentioned node structure status can be set according to the actual application situation, and can be set to "valid", "invalid" or other more complex states.
[0055] Step S102 : establishing a dependency network based on the dependency relationship, and introducing the actual probability relationship into the dependency network to obtain a probabilistic dependency network for the power grid cyber-physical system.
[0056] Among them, the dependency relationship mainly includes the dependency relationship between different nodes, excluding the specific conditional probability relationship. The only information it can carry is the influence relationship between nodes. Multiple dependency relationships can form a dependency network. At this time, the dependency network is the same as the existing dependency network, which only includes the influence relationship between different nodes, and by default has only two states: "failed" and "valid". Then, the actual probability relationship is introduced into the dependency network to obtain a probabilistic dependency network. The probabilistic dependency network in this application can include the probabilistic expression of multiple dependency relationships. The probabilistic dependency state of a node includes the description of the dependency relationship between nodes and the node state, such as Figure 2 As shown, Figure 2 A schematic diagram of a one-way probabilistic dependency relationship is provided. Node A is one-way dependent on node B, which can be expressed as A←B. The dependency state of node A can be expressed by probability ζ(A). ζ(A) is a probability value between [0, 1]. ζ(A) = 1 means that the failure of node B will inevitably lead to the failure of node A. Conversely, ζ(A) = 0 means that the state of node B is independent of the state of node A. In a one-way dependency relationship, node B does not depend on other nodes. For the sake of the same expression, the state of node B in this application is also represented by ζ(B), which actually represents the probability of independent failure of node B. The above ζ(A) can be expressed as a conditional probability P(A|B) related to node B, which represents the probability of node A failure when node B fails. Similarly, Figure 3 A schematic diagram of a bidirectional probabilistic dependency is provided. In this case, the dependency state of node B can be further converted into a conditional probability related to the state of node A. In summary, the probabilistic dependency relationships in this application can include unidirectional probabilistic dependencies, bidirectional probabilistic dependencies, one-to-many probabilistic dependencies, logical dependencies, etc., which will not be repeated here. In other words, through the above method, the actual probabilistic relationship can be introduced into the dependency network to obtain the above-mentioned probabilistic dependency network.
[0057] Step S103, converting the probabilistic dependency network into a probabilistic analysis network carrying logical impact results, and inputting the node structure state into the probabilistic analysis network to obtain node anomaly detection results for the power grid information-physical system; wherein the logical impact results are obtained based on the dependency relationship and the actual probability relationship.
[0058] The above-mentioned logical influence results include, but are not limited to, dependency relationships between different node structures, logical relationships such as logical AND and logical OR, etc. Specifically, the above-mentioned probabilistic dependency network is converted into a network containing information such as a Bayesian network, a Markov model, a probabilistic tree model, etc., which contains information such as logical relationships and influence relationships between nodes. At the same time, the logical influence results calculated based on the logical dependency relationships between node structures and the influence results between node structures are introduced into the network, thereby obtaining the above-mentioned probabilistic analysis network. Furthermore, after the above-mentioned node structure state is input into the probabilistic analysis network, the calculation results of the node state can be obtained quickly and accurately, thereby obtaining the above-mentioned node anomaly detection results.
[0059] Through steps S101 to S103, actual probabilistic relationships are introduced into the dependency network, expanding the existing dependency network, which only uses 0s and 1s to express connection relationships, into a probabilistic dependency network that uses conditional probabilities to express various logical connection relationships. This allows the dependencies between different modules of the power grid system to be quantified through the probabilistic dependencies between nodes in the probabilistic dependency network, thereby expressing more complex relationships within the power grid cyber-physical system. Furthermore, converting the probabilistic dependency network into a probabilistic analysis network facilitates the subsequent detection and calculation of node states in the power grid cyber-physical system, as well as the calculation and analysis of influence relationships between nodes, making it more suitable for practical calculations in existing power grid cyber-physical systems.
[0060] In one embodiment, obtaining the actual probability relationship includes:
[0061] Obtain statistical data and logical dependencies of the power grid cyber-physical system, and obtain actual probability relationships based on the statistical data and logical dependencies.
[0062] Specifically, the actual probability relationship can be derived from two aspects: one is to collect existing statistical data, and the other is to analyze and reason based on logical dependencies to obtain the actual probability relationship. For example, in the "one-to-many" probability dependency relationship, such as Figure 4 As shown, Figure 4 A one-to-many probabilistic dependency diagram is provided. In the diagram, n is the total number of B-family nodes. In a one-to-many dependency, the state of node A is related to multiple B-family nodes, indicating that the state of node A depends on the combination of the states of multiple B-family nodes. The probabilistic dependency relationship for node A failure can be expressed as:
[0063] ζ(A)=P(A|B1,B2,...,B n )
[0064] Specifically, how the state of node A is affected by the nodes in group B depends on the dependency relationship between them.
[0065] Similarly, for Figure 5 In the probabilistic dependency hierarchical equivalent model shown, the dependency relationship can be decomposed into one-to-one and one-to-many forms. Figure 5 Node A not only depends on the nodes of family B, but also node B3 depends on the nodes of family C. Therefore, we can first calculate the probability ζ(B3) when node B3 is in the current state, and then further calculate the dependency state of node A based on this. The logical dependency relationship can be expressed as:
[0066] ζ(B3)=P(B3|C1, C2,...,C m )
[0067] ζ(A)=P(A|B1,B2,...,B n )ζ(B3)
[0068] Similarly, when a node's state depends on a logical combination of multiple node states, the node satisfies a logical relationship with the other nodes. This logical relationship includes logical AND, logical OR, logical XOR, etc., which expresses the dependency relationship under the uncertainty of the power-on state. Specifically, the probabilistic relationship between nodes is mainly constructed through the conditional probability of the node state. For example, when the state of node A depends on the state of the node in the group B, the logical NOT relationship between node A and the node in the group B can be expressed as:
[0069]
[0070] When node A and node B are in a logical AND relationship, it can be expressed as:
[0071]
[0072] When node A and node B are in a logical OR relationship, it can be expressed as:
[0073]
[0074] When node A and group B nodes are in a logical exclusive OR relationship, it can be expressed as:
[0075]
[0076] In summary, based on the aforementioned "one-to-one," "one-to-many," and logical combination relationships, calculations can be performed to obtain the aforementioned logical dependency relationships. Furthermore, existing large quantities of statistical data can be collected, such as the statistical data on relay protection operations of the State Grid Corporation of China over the past few years, and reasoning and analysis can be performed based on the aforementioned logical dependency relationships to obtain the actual probability relationships between the aforementioned nodes. By determining the actual probability relationships through the aforementioned method of collecting statistical data, the actual probability relationship results of the statistical data can be obtained quickly and easily. Furthermore, in actual applications, relevant personnel can choose to perform reasoning and calculations based on the existing logical dependency relationships, thereby supplementing the actual probability relationship results of the statistical data, and more flexibly and accurately obtaining the actual probability relationships suitable for the current power grid system.
[0077] In one embodiment, the node structure includes child nodes and target nodes, and the target node refers to a node whose corresponding state is determined based on the node structure state of the child node; the logical impact result includes a logical dependency relationship and an impact result, and converting the probabilistic dependency network into a probabilistic analysis network carrying the logical impact result includes:
[0078] If it is detected that the child node and the target node are in a direct dependency relationship, the logical dependency relationship between the child node and the target node is obtained according to the actual probability relationship, and the probabilistic dependency network is converted into a causal probability analysis network according to the logical dependency relationship;
[0079] If it is detected that the child node and the target node have an indirect dependency relationship, the arrow pointing expression of the probability dependency network is reversed according to the dependency relationship to obtain the impact result of the child node on the target node, and reverse reasoning is performed based on the actual probability relationship to obtain the evidence probability relationship; according to the impact result and the evidence probability relationship, the probability dependency network is converted into an evidence probability analysis network; among them, the probability analysis network includes a causal probability analysis network and an evidence probability analysis network.
[0080] Specifically, in most practical applications, the above-mentioned probability dependency network may include a target node and multiple child nodes. The above-mentioned probability analysis network may include a causal probability analysis network and an evidence probability analysis network. The choice of the causal probability analysis network or the evidence probability analysis network may depend on the form of the existing conditional probability parameters and the dependency relationship between the nodes. If the node conditional probability parameter is in the form of P(O|x1, x2, ..., x n) and the logical connection relationship between the child nodes and the target node is simple and clear, then the causal probability analysis model can be selected. Furthermore, the logical dependency relationship contained in the causal model can be derived more directly, so that the logical dependency relationship can be added when converting the probabilistic dependency network into a causal probability analysis network to more clearly and accurately determine the causal probability analysis network, which is convenient for the subsequent calculation and detection of the power grid information-physical system. If the form of the node conditional probability is the posterior probability form of P(y|O), or there is no direct dependency relationship between the child node and the target node, and only the state probability P(y|O) of the child node is known when the target node is in a specific state, then the probability dependency network can be converted into an evidence probability analysis network. When converting the probability dependency network into an evidence probability analysis network, it is necessary to reverse the direction of the arrows representing the dependency relationship between nodes. Reversing the direction of the arrows also further represents that the meanings of different network expressions are different. The more arrows point to a node, the more conditional probabilities it contains, and the above-mentioned new influence results between the arrows can be obtained. Furthermore, after completing the arrow direction reversal to obtain the new arrow pointing expression form, the above-mentioned evidence probability relationship can be obtained through Bayesian reverse reasoning, that is, P(O|y1, y2, ..., y m Furthermore, if both forms of conditional probability parameters between child nodes and target nodes are present in practical applications, the model that facilitates data statistics should be prioritized for analysis. The two forms of probability analysis networks have no absolute application boundaries and can be mixed when needed. By converting the probabilistic dependency network into the more appropriate of the two forms, the above method can better reflect the actual probabilistic dependency network of the power grid system, improve the accuracy of the network representation, and facilitate subsequent detection and calculation.
[0081] In one embodiment, actual probability relationships are introduced into the dependency network to obtain a probabilistic dependency network for the power grid cyber-physical system, including:
[0082] Acquire a preset virtual relationship node; wherein the virtual relationship node includes a virtual probability relationship between at least three of the node structures; introduce a dependency network according to the virtual probability relationship and the actual probability relationship to obtain a probabilistic dependency network.
[0083] Specifically, although the probabilistic dependency network contains probabilistic relationships between multiple nodes, if the data is incomplete or the statistical method is one-sided, in actual applications, the calculation results may not meet expectations. Therefore, this application proposes the concept of virtual relationship nodes. Virtual relationship nodes have no physical entities and only express the relationship between nodes. They are the result of the combination of the states of multiple nodes, and their main function is to express the impact of node behavior on the target node. The state of the virtual relationship node is established only when the state of the target node meets the specific logical state of nodes x1 and x2 (i.e., x3=1). Figure 6 As shown, Figure 6 is a schematic diagram of virtual relationship nodes, Figure 6 It can be seen that the virtual node x3 is connected to the target node and the nodes with internal related relationships at the same time. After adding the virtual relationship nodes, the probabilistic dependency network expresses two meanings: the independent dependency relationship between the child nodes x1 and x2 and the target node, and the dependency relationship between different state combinations between the child nodes and the target node. Figure 6 The node x3 and other nodes in the structure form a logical structure. Assuming that each node has only two states, 0 and 1, and there are n nodes connected to it, then the node x3 has 2 n+1 states, and for child nodes x1 and x2, they have 4 state combinations. By assigning probabilities, any logical relationship can be expressed. Furthermore, by replacing the true and false values (0 / 1) of the above logical operations with probabilities, the probability of child nodes x1 and x2 presenting the logical relationship in the table can be expressed. The following table is a table of logical relationship probability expressions, which gives the probability expressions of logical AND, logical OR, and logical XOR respectively. The rest of the logical relationships are similar, as shown in the following table:
[0084]
[0085] Among them, P+ represents that its probability value is much greater than 0.5 and close to 1, and P- represents that its probability value is much less than 0.5 and close to 0. Any hybrid structure can be equivalently transformed by adding virtual relationship nodes, such as Figure 7 As shown, Figure 7This is an equivalent transformation between the hybrid structure and the structure with the newly added virtual relationship nodes. After adding the virtual relationship nodes, the connection line between nodes x1 and x2 is transferred to node x3. Nodes x1 and x2 are not directly connected. At this time, the conditional probability P(x2|x1, O) of node x2 is converted to P(x2|O). If node x2 has no independent association with node O, P(x2|O) only needs to be set to 0.5. The two networks are still equivalent transformations. The state combination between nodes x1 and x2 and the connection with the target node are transferred to node x3 with the conditional probability P(x3|x1, x2, O). The probability relationship contained in the virtual node is the aforementioned virtual probability relationship. Through the above method, the introduction of virtual relationship nodes is equivalent to supplementing the existing actual probability relationship. In practical applications, when there is a clear logical relationship between two modules in the power grid cyber-physical system but lacks probabilistic data support, a virtual probability relationship can be artificially added to describe the relationship between them, thereby more comprehensively expressing the logical relationship between the power grid system.
[0086] In one embodiment, the node structure state is input into a probabilistic analysis network to obtain quantitative analysis results for the cyber-physical system, including:
[0087] The node anomaly detection results of the cyber-physical system are obtained based on the actual probability relationship, dependency relationship and node structure status.
[0088] Specifically, if Figure 8 As shown, Figure 8 Taking the probability analysis network as an example, after converting the probability dependency network into a Bayesian network, the anomaly detection results of the power grid cyber-physical system are calculated based on the Bayesian network. Figure 8 The upper part is to convert the probability dependency network into a causal probability analysis network, and the lower part is to convert the probability dependency network into an evidence probability analysis network. The Bayesian network is represented by a directed solid arrow network, and the probability dependency network is represented by a directed dotted arrow network. n ) represents the dependency relationship of the target node in the causal probability analysis model, P(O|y1,y2,...,y m ) represents the dependency relationship of the target node in the evidence probability analysis model. In the case where the probability analysis network is a causal probability analysis network, it represents that there is a direct logical dependency relationship between multiple node structures. Figure 8 The nodes directly connected to the target node and the target node are directly dependent, such as node x j , the rest are indirect dependencies (node x1 to node x n ), in the causal probability analysis network, nodes x1, x2, .., x n With node xj They are independent of each other and have no additional logical connections. The anomaly detection results can be expressed as the actual probability relationship, dependency relationship and collected node structure state:
[0089]
[0090] Where N x For nodes x1, x2, .., x n The number of state combinations, R x is the state space of all child nodes, P(O|x j ) represents a node, x j Dependencies with the target node.
[0091] In the case where the probability analysis network is an evidence probability analysis network, it represents that there is no direct dependency relationship between multiple node structures, that is, when the target node fails, the child node has a probability of being in a certain state. Such nodes belong to evidence nodes and can be expressed as Y = (y1, y2, ..., y m ), in the evidence probability analysis network, the target node and each child node are indirectly dependent. The anomaly detection result between the target node and the child nodes can be expressed as the actual probability relationship, dependency relationship and the collected node structure state:
[0092]
[0093] Where Ny is the node y1, y2, .., y n The number of state combinations, Ry is the state space of all child nodes. In summary, when the child node state X or Y is determined, the dependent state of the target node Through Bayesian inference, we can get:
[0094]
[0095] Where, Indicates the state of target node failure, such as Figure 9 As shown, Figure 9 The following diagram shows the relationship between the target node's state and the states of its child nodes. It clearly shows that the value of the target node's failure dependency increases as the child node transitions from a normal state to a failed state. This method accurately quantifies the target node's failure probability, specifically as the anomaly detection result I between multiple child nodes and the target node. A higher value indicates greater importance to the target node and a greater impact on it. This allows for a more accurate and intuitive assessment of the probability that the target node will maintain stable operation under the current state of its child nodes.
[0096] In one embodiment, the node structure comprises a target node and a child node, and a node anomaly detection result of the information physical system is obtained according to the actual probability relationship, the dependency relationship and the node structure state, comprising:
[0097] In the case that the probability analysis network is a causal analysis network, the node structure state is multiplied according to the actual probability relationship and the dependency relationship to obtain a causal dependency strength, and the number of causal states of the child node is obtained according to the node structure state, the causal dependency strength is averaged according to the number of causal states to obtain the node anomaly detection result of the power grid information physical system;
[0098] In the case that the probability analysis network is an evidence analysis network, the actual probability relationship between the target node and the child node is multiplied according to the dependency relationship to obtain a support factor function value, and the number of evidence states of the child node is obtained according to the node structure state, the support factor function value is averaged according to the number of states to obtain the node anomaly detection result of the power grid information physical system.
[0099] Specifically, in the case that the probability analysis network is a causal probability analysis network, the above node anomaly detection result can be expressed as follows:
[0100]
[0101] Further, in the case that the probability analysis network is an evidence probability analysis network, the actual probability relationship is multiplied to obtain a support factor function value, wherein specifically, the support factor function value can be expressed as:
[0102]
[0103] wherein is a natural factor, represents the ratio of the conditional probability that the target node is in a normal state to the conditional probability that the target node is in an abnormal state, i.e. =P(O=0) / P(O=1), and P+ represents a child node probability value that is much greater than 0.5 and close to 1, and P- represents a child node probability value that is much less than 0.5 and close to 0, further, the support factor function value can also be expressed as:
[0104]
[0105] In summary, the anomaly detection result of the evidence probability analysis network can be further expressed as:
[0106]
[0107] Each support factor is greater than 0. The support factor value is inversely proportional to the anomaly detection result. The smaller the support factor value, the greater its impact on the anomaly detection result of the target node. Furthermore, the anomaly detection result can also be understood as the dependency strength between the child node and the target node, that is, the maximum failure probability of the target node under the current state of the child node. A higher probability corresponds to a stronger dependency strength, meaning it is more important to the target node. By introducing the support factor function value based on anomaly detection for the target node, the above method makes the calculation of anomaly detection results more intuitive and easier to understand.
[0108] In one embodiment, a node structure includes a target node and child nodes. The node structure state is input into a probability analysis network to obtain node anomaly detection results for the power grid cyber-physical system, including:
[0109] In the case where the probability analysis network is an evidence probability analysis network, the node structure state is input into the probability analysis network, and the node structure state is detected using the probability analysis network;
[0110] If the probability of a subnode failure detected based on the node structure state is less than a preset threshold, the node structure state is determined to be a low-probability feature type, and in response to the determined low-probability feature type, a subnode algebraic result is generated according to the actual probability relationship;
[0111] According to the sub-node algebra results, the node anomaly detection results of the power grid cyber-physical system are obtained.
[0112] Specifically, the above-mentioned low-probability feature type is the probability of subnode failure being far less than a preset threshold. In practical applications, if the probability of subnode failure is far less than 0.5 and close to 0, the subnode structural state is determined to be a low-probability feature type, which can be expressed as P-. Correspondingly, if the probability of subnode failure is far greater than 0.5 and close to 1, the subnode structural state is also determined to be a low-probability feature type, which can be expressed as P+, where P- and P+ are the above-mentioned subnode algebraic results. Through the above method, low-probability features and subnode algebraic results are introduced into the calculation of anomaly detection results, and a large number of complex decimal calculations are converted into algebraic calculations, which can greatly speed up the calculation efficiency, make the calculation results more intuitive, and facilitate rapid analysis and prediction of the results.
[0113] In one embodiment, the node anomaly detection result includes a target node status result; and according to the child node algebra result, a node anomaly detection result for the power grid cyber-physical system is obtained, including:
[0114] The support factor is obtained based on the algebraic result of the child nodes; wherein all child nodes and support factors have a one-to-one correspondence;
[0115] All support factors are multiplied to obtain the support factor function value, and the target node state result is obtained according to the support factor function value.
[0116] Specifically, taking the probability analysis network as a Bayesian network as an example, assuming that the variable set in the Bayesian network is X=(X1,X2,...,X i ), i∈[1,n], the state set of each variable is θ=(θ1,θ2,...,θ j ),j∈[1,k], the target state of node O is θ t The posterior probability of the node being in the target state is the conditional probability P(O=θ t |X1,X2,...X i ), the probability value of the target node can be obtained by reverse reasoning through the evidence set X, that is:
[0117]
[0118] Where θ is the actual state value of X of each evidence sub-node, and the joint probability on the right side of the equation can be obtained by the Bayesian network chain rule:
[0119]
[0120] Among them, Parent(X i ) is the parent node of the child node, and the parent node at the top level is the root node of the network. Further, assuming that the variable states of the target node O are 0 and 1, and the child evidence node is X = (x1, x2, x3), then the posterior probability that the target node state is 1 can be expressed as:
[0121]
[0122] Dividing both sides of the above equation by the same factor can be simplified to the formula for the support factor function value α:
[0123]
[0124] The specific expression of α is as follows. According to the value of α, the influence of the Bayesian network node on the probability value of the target node can be analyzed.
[0125]
[0126] Furthermore, the above expression α can be understood as the product of a series of child node conditional probability ratios, where the conditional probability ratio of each child node can be expressed as:
[0127]
[0128] Where ζ(x) is the support factor acting on the target node when its state is 1, i.e., the ratio of the conditional probabilities of each node x, and ζ(x)>0, α is the product of the conditional probability ratios of each node, and ζ0=P(O=0) / P(O=1), then the support factor function value α can be further written as:
[0129]
[0130] Substituting the algebraic conditional probability of each node, α can be expressed as follows:
[0131]
[0132] If the conditional probability of node x satisfies P(x|O=1)=P+ and P(x|O=0)=P-, then the node has positive support factor ζ(x)=p- / p+=ζ + On the contrary, the node has a negative support factor ζ(x) = p+ / p- = ζ - , the above support factor includes the positive support factor and the negative support factor, so the above α formula can be simplified to:
[0133]
[0134] Where ζ0 is a natural factor, which is the ratio of the conditional probabilities of the target node being in a normal state to the abnormal state. Further expanding to a Bayesian network with 1 target node and n child nodes, the conditional probability of the target node can be further expressed in terms of the support factor:
[0135]
[0136] Where, P m is the number of positive factors, P n is the number of negative factors, n is the total number of nodes. If the influence of natural factors is ignored, when the number of positive factors exceeds the negative factors, the posterior probability P(O=1|x1,x2,...,x n )>0.5, when the number of positive factors and negative factors is equal, P(O=1|x1,x2,...,x n ) = 0.5, so in a Bayesian network that satisfies the small probability characteristic, the conditional probability of the target node can be roughly determined by the number of positive and negative factors in the evidence model. Through the above method, in actual operation, the conditional probability of the target node can be quickly calculated based on the previous formula containing positive and negative support factors. Moreover, based on the influence of the number of positive and negative support factors on the conditional probability introduced above, the approximate algebraic value of the conditional probability of the target node can be quickly inferred, thereby obtaining the target node status result.
[0137] This embodiment also provides a specific embodiment of a method for detecting anomalies in a power grid cyber-physical system, taking the circuit protection function network in the power grid system as an example, Figure 10 This is a probabilistic analysis network for circuit protection functions in power grid cyber-physical systems. First, the dependencies between multiple nodes of the circuit protection function, as well as the actual probability relationships, are obtained. A dependency network is then established based on these dependencies. After the actual probability relationships are introduced into the dependency network, a probabilistic dependency network is obtained. The actual probability relationships are primarily derived from statistical data and artificially added logical dependencies. For example, the priori failure probability of the protection network is based on the relay protection operation statistics of the State Grid Corporation of China from 2005 to 2009. The priori probabilities of the remaining secondary devices are represented by the component availability A:
[0138]
[0139] The mean time to failure (MTTF) of a device is called the mean time to failure, and the mean time to repair (MTTR) is called the mean time to repair. The artificially added logical dependencies are probabilistic relationships that can be determined manually. Furthermore, virtual relationship nodes are added as a supplement.
[0140] The following table shows the parameters of each protection sub-node:
[0141]
[0142] The following table is a table of virtual relationship node parameters, where the near backup relationship is a virtual relationship node set artificially, and the status of the near backup relationship node depends on the status of the main protection and the near backup protection.
[0143]
[0144] After obtaining the actual probability relationship through the above method, the actual probability relationship is introduced into the dependency network.
[0145] Secondly, to facilitate subsequent detection and analysis, the probabilistic dependency network is converted into a probabilistic analysis network. When choosing the type of probabilistic analysis network, priority can be given to the more versatile evidence probabilistic analysis network. Furthermore, in practical applications, the evidence probabilistic analysis network and the causal probabilistic analysis network can be used in combination. The figure shows the probabilistic analysis network of the circuit protection function in the power grid cyber-physical system.
[0146] Each line has at least one primary protection system and a backup protection system. The protection function shown in the figure is a common dual protection configuration. The sampled information from the protection devices is measured by the line voltage and current transformers and connected to a merging unit. Each protection device corresponds to a merging unit, and they exchange information directly via optical fiber. Each protection device includes corresponding primary and backup protection schemes. Backup protection is categorized as local backup and remote backup. Local backup protection replaces the primary protection in the event of a circuit breaker failure. In addition, failure protection is also a type of local backup protection. It isolates the fault by disconnecting the remaining bus breakers in the event of a circuit breaker failure. The failure protection operates after the combined time between the line protection tripping and the circuit breaker disconnection. Its criterion is that if a protection system has issued a trip command for the circuit breaker, but current is still flowing to the circuit breaker, the bus tie switch and all other circuit breakers on the bus are disconnected after a time delay. Remote backup protection relies on the protection of adjacent power equipment or lines when both primary and local backup protection fail. Most existing microcomputer-based protection configurations combine primary and backup protection. Primary protection utilizes high-speed criteria such as longitudinal protection and first-stage distance protection, while second-stage distance protection and overcurrent protection serve as local backup protection. Typically, redundant protection configurations and the addition of failure protection prevent most line faults from escalating. The activation of remote backup protection at other substations often indicates a widespread power outage. This example does not consider fault scenarios involving remote backup protection activation; instead, it models the in-station protection function using the substation as the unit.
[0147] The probabilistic dependency network of line protection functions includes both Bayesian causal models and evidence models. Figure 10 There are two virtual relationship nodes, representing the two backup protection behaviors of the near backup protection. The status of the virtual relationship node is related to the connected nodes. The status of the near backup relationship node 1.1 and node 2.1 depends on the status of the main protection and the near backup protection. When the main protection refuses to operate and the near backup protection operates, the backup protection behavior expressed by the virtual relationship node is established, and its status value is 1, otherwise it is 0; the status of the near backup relationship nodes 1.2 and 2.2 is related to the status of the failure protection node and the circuit breaker node. Similarly, when the circuit breaker refuses to operate and the failure protection operates, the failure protection behavior is established. At this time, the status of the virtual relationship node is 1, otherwise it is 0.
[0148] Based on the probabilistic dependency network, the dependency characteristics of the protection function nodes are tested by randomly injecting abnormal events through Monte Carlo simulation. In each simulation cycle, a uniformly distributed random number is generated. If it is less than the probability of the abnormal event, the abnormal event is considered to have occurred. Abnormal events will change the state of the probabilistic dependency network nodes. Abnormal events in the simulation include single failure events of information or physical nodes and combinations of multiple sub-events. The higher the probability of failure of the protection function, the greater its dependence on the information or physical nodes in the event. Abnormal events mainly include refusal to operate events of main protection, backup protection and failure protection; refusal to operate events of circuit breaker that lead to failure protection action; merging unit failure, mutual inductor failure and communication link disconnection events that lead to failure of the protection device. The specific contents of the abnormal events are shown in the following table:
[0149]
[0150] Depend on Figure 10 It can be seen that the line protection function involves 6 protection nodes and 4 virtual relationship nodes in the evidence model, where the status of the virtual relationship node depends on the status of the protection node. Therefore, the maximum number of random abnormal times can be set to 6, corresponding to 1024 system abnormal states. If the line does not have a double protection configuration, it corresponds to 3 protection nodes and 2 virtual relationship nodes. 10,000 scenarios are randomly generated through Monte Carlo simulation, and each 10,000 scenarios corresponds to a number of abnormal events. The dependency probability of the line protection function is calculated according to the status corresponding to each node in the scenario. The Monte Carlo simulation results are shown in the following table. The maximum failure probability refers to the maximum probability of failure of the protection function in scenarios with the same number of random events. The dependency strength is the average failure probability of the protection function, which represents the dependency strength of the protection function and each node in the dependency network. The average effective probability is the average probability that the protection function is in an effective state:
[0151]
[0152] The results show that the probability of normal protection function conforms to the following form: (1+(ζ + ) 6-Pn (ζ - ) Pn ) -1Pn is the number of negative support factors. When Pn is equal to 3, the probability of the protection function being normal at least drops to close to 0.5. Theoretically, it is also proved that the inflection point of the protection function degradation occurs when there are 3 abnormal events. If the number of abnormal events exceeds 4, the protection function has difficulty maintaining normal operation, and the average effective probability is less than 30%. This is the detection result obtained by the reasoning analysis above. In summary, the probabilistic dependency network model can effectively express the dependency relationship between component failure caused by random abnormal events and the protection function. The more positive support factors, the closer the probability of the protection function being normal is to 1, and the more negative support factors, the closer it is to 0. Compared with the existing dependency network model based on the adjacency matrix, the probabilistic dependency model proposed in this application can more accurately express the probabilistic dependency relationship between nodes, and the introduction of virtual relationship nodes can make the calculation results more accurate and can be applied to a wider range of working environments; furthermore, its solution and detection process for abnormal states can be simplified and accelerated by the support factor analysis method of "small probability characteristics", which can perform large-scale qualitative and quantitative analysis, and the results of the support factor analysis method can also effectively predict the results of some simple power grid information-physical systems quickly. The probabilistic dependency model can be applied to the complex primary and secondary fusion technology in new power systems and can provide better ideas for physical information model analysis and modeling.
[0153] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0154] Based on the same inventive concept, embodiments of the present application also provide a power grid cyber-physical system anomaly detection device for implementing the aforementioned power grid cyber-physical system anomaly detection method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more power grid cyber-physical system anomaly detection device embodiments provided below can be found in the aforementioned limitations of the power grid cyber-physical system anomaly detection method, and will not be further elaborated here.
[0155] In one embodiment, Figure 11As shown, a device for detecting anomalies in a power grid cyber-physical system is provided, comprising:
[0156] An acquisition module, configured to acquire a dependency relationship and an actual probability relationship between at least two node structures of a power grid cyber-physical system, and collect a node structure state;
[0157] A calculation module is used to establish a dependency network based on the dependency relationship and introduce the actual probability relationship into the dependency network to obtain a probabilistic dependency network for the power grid cyber-physical system;
[0158] A generation module is used to convert the probabilistic dependency network into a probabilistic analysis network carrying logical impact results, and input the node structure state into the probabilistic analysis network to obtain node anomaly detection results for the power grid information-physical system; among which the logical impact results are obtained based on the dependency relationship and the actual probability relationship.
[0159] Specifically, the acquisition module first obtains the dependency relationships and actual probability relationships between multiple node structures in the power grid cyber-physical system. In practical applications, multiple node structures often include a target node and multiple child nodes. The actual probability relationships can be obtained in a variety of ways, such as from existing large-scale statistical data or by artificially adding relatively clear but lacking data-supported probability relationships. The calculation module establishes a dependency network based on the above dependency relationships. In this case, the dependency network does not include probability relationships. By introducing the actual probability relationships, a probabilistic dependency network for the power grid cyber-physical system can be established. Unlike existing dependency networks, which can only express simple 0 or 1 relationships, the probabilistic dependency network in this application can accurately express probabilistic relationships between 0 and 1, making it more suitable for use in practical working environments. The generation module then converts the probabilistic dependency network into a probabilistic analysis network with logical influence results. In practical applications, this probabilistic analysis network is often a mature Bayesian network. The node structure state is input into the probabilistic analysis network for computational analysis to obtain node anomaly detection results for the power grid cyber-physical system. Through the above method, by introducing probabilistic relationships in the dependency network, the dependency status between different nodes can be more accurately represented, and more complex systems can also more accurately describe complex working environments. Furthermore, by converting the probabilistic dependency network into a probabilistic analysis network for calculation, we can further summarize the analysis and detection methods suitable for the power grid information-physical system based on the mature calculation formula, so as to obtain more accurate and rapid abnormal detection results for the power grid system nodes.
[0160] Each module in the aforementioned power grid cyber-physical system-based anomaly detection device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, allowing the processor to call and execute the corresponding operations of each module.
[0161] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 12 As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an interface information synchronization method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.
[0162] Those skilled in the art will understand that Figure 12 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the anomaly detection device of the power grid information-physical system to which the solution of the present application is applied. The specific anomaly detection device of the power grid information-physical system may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0163] Those skilled in the art should understand that the various technical features of the above-described embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the various technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0164] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A method for detecting anomalies in a cyber-physical system of a power grid, characterized in that: The method comprises: Obtaining a dependency relationship and an actual probability relationship between at least two node structures of a power grid cyber-physical system, and collecting a node structure state; the node structure includes a child node and a target node, and the target node is a node whose corresponding state is determined based on the node structure state of the child node; Establishing a dependency network according to the dependency relationship and obtaining a preset virtual relationship node; wherein the virtual relationship node includes a virtual probabilistic relationship between at least three of the node structures; Introducing the dependency network according to the virtual probability relationship and the actual probability relationship to obtain a probabilistic dependency network for the power grid cyber-physical system; The probability dependency network is converted into a probability analysis network carrying a logical influence result, wherein the logical influence result is obtained based on the dependency relationship and the actual probability relationship; the logical influence result includes the logical dependency relationship and the influence result; the probability analysis network includes a causal probability analysis network and an evidence probability analysis network; the causal probability analysis network is obtained by, when it is detected that the child node and the target node are in a direct dependency relationship, obtaining the logical dependency relationship between the child node and the target node based on the actual probability relationship, and converting the probability dependency network based on the logical dependency relationship; the evidence probability analysis network is obtained by, when it is detected that the child node and the target node are in an indirect dependency relationship, reversely swapping the arrow pointing expression form of the probability dependency network based on the dependency relationship to obtain the influence result of the child node on the target node, and performing reverse reasoning based on the actual probability relationship to obtain the evidence probability relationship, and converting the probability dependency network based on the influence result and the evidence probability relationship; The node structure state is input into the probability analysis network to obtain a node anomaly detection result for the power grid information-physical system; the node anomaly detection result includes a node anomaly detection result obtained when the probability analysis network is the causal probability analysis network, and a node anomaly detection result obtained when the probability analysis network is the evidence probability analysis network, wherein the node anomaly detection result obtained when the probability analysis network is the causal probability analysis network is obtained by multiplying the node structure state according to the actual probability relationship and the dependency relationship to obtain the causal dependency strength, obtaining the number of causal states of the child node according to the node structure state, and averaging the causal dependency strength according to the number of causal states; the node anomaly detection result obtained when the probability analysis network is the evidence probability analysis network is obtained by multiplying the actual probability relationship between the target node and the child node according to the dependency relationship to obtain a support factor function value, obtaining the number of evidence states of the child node according to the node structure state, and averaging the support factor function value according to the number of states.
2. The method according to claim 1, characterized in that Obtaining the actual probability relationship includes: Statistical data and logical dependencies of the power grid cyber-physical system are obtained, and the actual probability relationship is obtained based on the statistical data and the logical dependencies.
3. The method according to claim 1, characterized in that The node structure includes a target node and child nodes, and inputting the node structure state into the probability analysis network to obtain a node anomaly detection result for the power grid cyber-physical system includes: In the case where the probability analysis network is an evidence probability analysis network, the node structure state is input into the probability analysis network, and the node structure state is detected using the probability analysis network; If the probability of the sub-node failure detected based on the node structure state is less than a preset threshold, the node structure state is determined to be a low-probability feature type, and in response to the determined low-probability feature type, a sub-node algebraic result is generated according to the actual probability relationship; According to the sub-node algebra result, a node anomaly detection result for the power grid cyber-physical system is obtained.
4. The method according to claim 3, characterized in that The node anomaly detection result includes a target node status result; and the node anomaly detection result for the power grid cyber-physical system is obtained based on the sub-node algebra result, including: Obtaining a support factor according to the algebraic result of the child nodes; wherein all the child nodes and the support factors are in a one-to-one correspondence; All the support factors are multiplied to obtain a support factor function value, and the target node state result is obtained according to the support factor function value.
5. The method according to claim 4, characterized in that The support factors include positive support factors and negative support factors.
6. The method according to any one of claims 1 to 4, characterized in that The dependency relationship is a unidirectional dependency relationship.
7. The method according to any one of claims 1 to 4, characterized in that The logical impact result includes the dependency relationship and logical relationship between different node structures.
8. The method according to any one of claims 1 to 4, characterized in that The probabilistic dependency network includes multiple probabilistic dependency relationships, and the probabilistic dependency relationships include unidirectional probabilistic dependency relationships, one-to-many probabilistic dependency relationships, and logical dependency relationships.
9. An abnormality detection device for a power grid cyber-physical system, characterized in that: The device comprises: An acquisition module is configured to acquire a dependency relationship and an actual probability relationship between at least two node structures of a power grid cyber-physical system, and collect a node structure state; the node structure includes a child node and a target node, and the target node is a node whose corresponding state is determined based on the node structure state of the child node; a calculation module, configured to establish a dependency network based on the dependency relationship and obtain preset virtual relationship nodes; wherein the virtual relationship nodes include virtual probability relationships between at least three of the node structures; introduce the dependency network based on the virtual probability relationships and the actual probability relationships to obtain a probabilistic dependency network for the power grid cyber-physical system; A generation module, for converting the probability dependency network into a probability analysis network carrying a logical influence result, wherein the logical influence result is obtained based on the dependency relationship and the actual probability relationship; the logical influence result includes a logical dependency relationship and an influence result; the probability analysis network includes a causal probability analysis network and an evidence probability analysis network; the causal probability analysis network is obtained by, when it is detected that the child node and the target node are in a direct dependency relationship, obtaining the logical dependency relationship between the child node and the target node based on the actual probability relationship, and converting the probability dependency network based on the logical dependency relationship; the evidence probability analysis network is obtained by, when it is detected that the child node and the target node are in an indirect dependency relationship, reversely swapping the arrow pointing expression form of the probability dependency network based on the dependency relationship to obtain the influence result of the child node on the target node, and performing reverse reasoning based on the actual probability relationship to obtain the evidence probability relationship, and converting the probability dependency network based on the influence result and the evidence probability relationship; The generation module is further configured to input the node structure state into the probability analysis network to obtain a node anomaly detection result for the power grid information-physical system; the node anomaly detection result includes a node anomaly detection result obtained when the probability analysis network is the causal probability analysis network and a node anomaly detection result obtained when the probability analysis network is the evidence probability analysis network, wherein the node anomaly detection result obtained when the probability analysis network is the causal probability analysis network is obtained by multiplying the node structure state according to the actual probability relationship and the dependency relationship to obtain the causal dependency strength, obtaining the number of causal states of the child node according to the node structure state, and averaging the causal dependency strength according to the number of causal states; the node anomaly detection result obtained when the probability analysis network is the evidence probability analysis network is obtained by multiplying the actual probability relationship between the target node and the child node according to the dependency relationship to obtain a support factor function value, obtaining the number of evidence states of the child node according to the node structure state, and averaging the support factor function value according to the number of states.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Failure diagnostic system and failure diagnostic program
JP2008293128A
Methods and Systems for Constructing Bayesian Belief Networks
US20090006305A1