Electric power system intelligent security convergence processing method, system, device and medium
The spatiotemporal characteristics of power system data are extracted through the neural network model, and unique mark values are generated based on the equipment security level and timestamp. An elastic trust evaluation model is built, and dynamic trust weight weighting and mark grouping aggregation is carried out, which solves the real-time and security problems of power system data processing and improves the stability and efficiency of the system.
Patent Information
- Application Number
- CN202510511181.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-25
AI Technical Summary
The existing power system data processing methods have problems such as insufficient real-time, extensive feature extraction and weak safety protection, resulting in delayed fault isolation, misjudgment and fault spread, affecting system stability.
The spatiotemporal eigenvectors of data are extracted through the neural network model, and unique mark values are generated based on the device security level and timestamp. An elastic trust evaluation model is built, dynamic trust weight weighting is performed, and marking packet aggregation is used to use anti-collision hash function, and abnormal device isolation is performed through iterative analysis of node importance through the correlation graph.
It improves the real-time and security of data processing, reduces network bandwidth pressure, enhances data transmission stability and reliability, and improves the overall performance of the power system.
Smart Images

Figure CN120372699A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power safety, and in particular to an intelligent security aggregation processing method and system for a power system. Background Art
[0002] Under the background of high proportion access of new energy, wide deployment of distributed energy, and surging interactive demands on the user side, the sources of power data are becoming increasingly diverse. To cope with this trend, technologies such as the Internet of Things (IoT) and Wide Area Measurement System (WMS) are widely used in data collection and transmission. Currently, data aggregation is mainly achieved through time series databases and streaming computing engines, and operation characteristics are extracted relying on algorithms such as clustering analysis and association rule mining to support power grid state assessment and fault warning.
[0003] However, the current data processing methods have the following problems: ① Insufficient real-time performance: Existing aggregation algorithms are difficult to meet the millisecond-level response requirements, resulting in delayed fault isolation; ② Coarse feature extraction: There is a lack of refined modeling of the spatio-temporal correlation characteristics of power data; ③ Weak security protection: The data aggregation process is vulnerable to false data injection attacks (FDIA), and there is a lack of a dynamic trust assessment mechanism; resulting in ignoring spatio-temporal correlation characteristics and other issues in the case of a huge amount of data processing, leading to subsequent decision-making misjudgments and low energy efficiency, fault diffusion, and thus causing the system to become paralyzed. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides an intelligent security aggregation processing method and system for a power system to solve the problems of low energy efficiency and fault diffusion caused by insufficient real-time processing, simple feature extraction, and lack of a dynamic trust assessment mechanism in the current situation of a huge amount of data and multiple data sources.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides an intelligent security aggregation processing method for a power system, including:
[0008] Obtain data samples generated by the power system;
[0009] Extract spatio-temporal feature vectors of the data samples through a neural network model;
[0010] Concatenate the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp;
[0011] Input all the concatenated strings into a collision-resistant hash function, and perform operations based on a preset tag space dimension to obtain a unique tag value for each data sample;
[0012] Perform credibility-weighted aggregation on the device data in the data samples to construct an elastic trust evaluation model, and obtain a dynamic trust weight factor;
[0013] Combine the dynamic trust weight factor, and perform secure aggregation calculation on all data samples through a distributed aggregation method with labeled grouping to obtain the aggregation results of different feature label groups;
[0014] Construct an association graph based on the unique tag value and device nodes, and through iterative calculation of graph algorithms, judge the importance and suspiciousness of each device node to achieve dynamic isolation of abnormal devices.
[0015] As a preferred solution of the intelligent secure aggregation processing method for the power system described in the present invention, wherein:
[0016] Input all the spliced strings into a collision-resistant hash function, and perform operations based on the preset tag space dimension to obtain the unique tag value of each data sample, including:
[0017] Input all the spliced strings into a collision-resistant hash function to obtain their respective hash values;
[0018] Perform a modulo operation on each hash value with respect to the tag space dimension K to obtain the unique tag value of each first type of data.
[0019] The beneficial effect of this preferred technical solution is: generating dynamic tags based on the hash chain technology makes the tags closely associated with the data and verifiable.
[0020] As a preferred solution of the intelligent secure aggregation processing method for the power system described in the present invention, wherein:
[0021] Perform credibility-weighted aggregation on the device data in the data samples to construct an elastic trust evaluation model, and obtain a dynamic trust weight factor; including:
[0022] Calculate the device historical credibility through the device historical data;
[0023] Calculate the data freshness through the timeliness of the data provided by the device;
[0024] Introduce adjustable hyperparameters and attenuation coefficients of the device historical credibility and data freshness to construct an elastic trust evaluation model, and calculate to obtain a dynamic trust weight factor.
[0025] The beneficial effect of this preferred technical solution is: comprehensively considering the device historical behavior and data freshness, through the fusion of time-varying weight functions, the weights can be adjusted according to different power system operation requirements and security policies.
[0026] As a preferred solution of the intelligent secure aggregation processing method for the power system described in the present invention, wherein:
[0027] Combined with the dynamic trust weight factor, perform secure aggregation calculation on all data samples through a distributed aggregation method with marked grouping, including:
[0028] Group all data samples according to the unique marking value to obtain different feature marking groups;
[0029] Use the indicator function to judge whether each device belongs to a specific feature marking group, and filter out the device data belonging to the specific feature marking group;
[0030] For each feature marking group, traverse all devices within the group, multiply the corresponding dynamic trust weight factor, spatio-temporal feature vector and indicator function of each device, sum the product results of all devices within the group, and obtain the aggregation result of the feature marking group.
[0031] The beneficial effect of this preferred technical solution is: dividing the feature marking groups according to the data markings, realizing local aggregation processing, and reducing the data transmission volume.
[0032] As a preferred solution of the intelligent security aggregation processing method for the power system described in the present invention, wherein: constructing an association graph based on the unique marking value and device nodes, including:
[0033] When the data generated by a device is given a unique marking value, a directed edge is established between the device node and the corresponding marking node to generate a marking-device association graph including a node set and an edge set.
[0034] As a preferred solution of the intelligent security aggregation processing method for the power system described in the present invention, wherein: judging the importance and suspiciousness of each device node through iterative calculation of the graph algorithm, including:
[0035] Perform iterative calculation based on the generated marking-device association graph through the PageRank algorithm;
[0036] When the change in the PageRank score of all device nodes is less than a set first threshold, the iteration ends, and the score of each device node is obtained for judging the importance and suspiciousness of each device node.
[0037] As a preferred solution of the intelligent security aggregation processing method for the power system described in the present invention, wherein: judging the importance and suspiciousness of each device node, including:
[0038] Set a second threshold, compare the device node score with the second threshold, and judge whether isolation is required;
[0039] If there are abnormal devices, locate based on the device nodes and perform dynamic isolation.
[0040] In a second aspect, the present invention provides an intelligent security aggregation processing system for a power system, including:
[0041] An acquisition module for acquiring data samples generated by the power system;
[0042] A feature extraction module for extracting spatio-temporal feature vectors of the data samples through a neural network model;
[0043] A splicing module for splicing the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp;
[0044] A marking module for inputting all the spliced strings into a collision-resistant hash function, performing operations based on a preset marking space dimension, and obtaining a unique marking value for each data sample;
[0045] A credibility calculation module for performing credibility weighted aggregation on the device data in the data samples to obtain a dynamic trust weight factor;
[0046] A security aggregation module for combining the dynamic trust weight factor and performing security aggregation calculation on all data samples through a distributed aggregation method grouped by marking to obtain aggregation results of different feature marking groups;
[0047] An anomaly isolation module for constructing an association graph based on the unique marking value and device nodes, and judging the importance and suspiciousness of each device node through iterative calculation of graph algorithms to achieve dynamic isolation of abnormal devices.
[0048] In a third aspect, the present invention provides an electronic device, including:
[0049] A memory and a processor;
[0050] The memory is used for storing computer-executable instructions, and the processor is used for executing the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the intelligent security aggregation processing method for the power system are implemented.
[0051] In a fourth aspect, the present invention provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the intelligent security aggregation processing method for the power system are implemented.
[0052] Compared with the prior art, the beneficial effects of the present invention are as follows: In view of the complex problems in smart grid data processing, the present invention comprehensively extracts spatio-temporal features through an optimized model, which can significantly improve the data processing efficiency; combined with a verifiable hash chain, it can achieve efficient data traceability; specifically calculates dynamic factors for device data, and through a tag-driven grouping aggregation mechanism designed by a hierarchical security aggregation architecture, it can support local processing at the edge computing layer; not only reduces the network bandwidth pressure, but also improves the stability and reliability of data transmission, reduces data problems caused by network congestion, and comprehensively improves the overall performance of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0054] Figure 1 It is a schematic diagram of the overall process of the intelligent security aggregation processing method for a power system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will describe the specific embodiments of the present invention in detail with reference to the drawings of the specification. Obviously, the described embodiments are some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0056] Embodiment 1, referring to Figure 1 , which is an embodiment of the present invention, provides an intelligent security aggregation processing method for a power system, including:
[0057] S100: Obtain data samples generated by the power system;
[0058] S200: Extract spatio-temporal feature vectors of the data samples through a neural network model;
[0059] S300: Concatenate the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp;
[0060] S400: Input all the concatenated strings into a collision-resistant hash function, perform operations based on a preset tag space dimension, and obtain a unique tag value for each data sample;
[0061] S500: Aggregate the device data in the data samples with credibility weighting to construct an elastic trust evaluation model, and obtain dynamic trust weight factors;
[0062] S600: Combine the dynamic trust weight factors, and perform secure aggregation calculations on all data samples through a distributed aggregation method with labeled grouping to obtain the aggregation results of different feature label groups;
[0063] S700: Construct an association graph based on the unique label values and device nodes, and through iterative calculations of graph algorithms, judge the importance and suspiciousness of each device node to achieve dynamic isolation of abnormal devices.
[0064] It should be noted that traditional data aggregation algorithms are mostly based on periodic polling or batch transmission mechanisms, and it is difficult to meet the requirements of millisecond-level response in smart grids. Especially in fault scenarios, data transmission and processing delays may lead to lag in fault isolation, expand the power outage range and threaten the transient stability of the system. In this case, if the extraction of data features is still relatively broad or single, the coupling relationship between device state changes and geographical distribution, load fluctuations and time periods will be ignored, resulting in deviations in power grid power flow calculations and triggering incorrect dispatching instructions, such as: insufficient reactive power compensation; at the same time, existing security mechanisms mostly rely on static keys or fixed trust thresholds, and attackers can forge measurement data to interfere with state estimation, thereby triggering incorrect operations and causing paralysis.
[0065] Therefore, in view of the above existing data calculation and monitoring problems, through the steps of S100 - S700, extract the spatio-temporal features of data based on neural networks, generate unique label values in combination with device security levels and timestamps to ensure data traceability and anti-tampering; then perform credibility weighting on device data through dynamic trust weight factors to enhance the anti-attack ability; then achieve efficient distributed computing through labeled grouping aggregation, taking into account real-time performance and data integrity; finally, construct an association graph and iteratively analyze the importance of nodes to dynamically identify suspicious devices and isolate them. Overall, three-layer association is achieved, which can solve the problems of poor real-time performance and rough features, and establish an active defense mechanism.
[0066] Example 2, refer to Figure 1 , which is an embodiment of the present invention. Based on the above embodiment, a method for intelligent and secure aggregation processing of a power system is provided.
[0067] In the implementation manner of the present application, in step S100, obtain the data samples generated by the power system;
[0068] Specifically, the data samples include: device data, user electricity consumption behavior data, fault alarm data, etc.; among them, the device data can be device status monitoring data.
[0069] In an alternative embodiment, the data obtained in step S100 may collect real-time dynamic data from a Wide Area Measurement System (WAMS) or a Phasor Measurement Unit (PMU), and may also include data such as demand response signals.
[0070] In another alternative embodiment, the data obtained in step S100 may also be collected from Internet of Things (IoT) edge nodes, including external environmental parameter data such as temperature, humidity, and wind speed.
[0071] In the embodiment of the present application, in step S200, a spatio-temporal feature vector of the data sample is extracted through a neural network model, including: extracting the spatio-temporal features of power data by using an improved Deep Convolutional Network (DCNN).
[0072] Preferably, the improved DCNN structure includes 5 convolutional layers. The convolutional kernel size of the first 3 convolutional layers is 3×3, and the convolutional kernel size of the last 2 layers is 5×5. The smaller 3×3 convolutional kernel is beneficial for capturing local detailed features, while the larger 5×5 convolutional kernel can obtain more extensive context information. For the pooling strategy, average pooling is adopted after the 1st and 3rd convolutional layers, which can retain the overall features and statistical information of the data, reduce the data dimension, and have a certain smoothing effect on the noise in the data; max pooling is adopted after the 2nd and 4th convolutional layers, and max pooling can highlight the key features in the data and is more targeted in feature extraction.
[0073] Specifically, in addition to the above structural adjustments, the number of convolutional kernels is also increased, gradually increasing from the traditional 32 to 128 to improve the ability to capture complex features in power data; the parameters of the pooling layer are optimized, and the appropriate pooling window size is selected according to different pooling strategies. For example, the average pooling and max pooling window sizes are both set to 2×2, which can reduce the data dimension while retaining the key features and reduce the computational complexity.
[0074] Exemplarily, for the input data, let X t be the multi-source input data at time t, which is a tensor containing various types of power data. Before the data enters the DCNN, it needs to be normalized to map the data values to the interval [0,1] or [-1,1] to accelerate the convergence speed of the model and improve the training effect.
[0075] The normalization formula can be: where, and are the minimum and maximum values of X t over the entire training set, respectively.
[0076] Preferably, after the improved DCNN processes X t a set of features F can be obtained.t1 To capture the time series characteristics of power data, a Long Short-Term Memory network (LSTM) is introduced; LSTM can effectively process long sequence data and avoid the problems of gradient vanishing and gradient explosion.
[0077] Exemplarily, the input of LSTM is X t-τ:t , representing a multi-source input data sequence from time t - τ to time t. Here, τ is the size of the time window set according to the time characteristics of power data and actual application requirements. For example, when monitoring the status of power equipment, τ can be set from a few minutes to several hours according to the operation cycle of the equipment and the data change frequency. After processing the input sequence, LSTM outputs a set of features F that can reflect the time series dependence relationship t2 .
[0078] Concatenate the features F extracted by DCNN t1 and the features F extracted by LSTM t2 to obtain the final spatio-temporal features F of power data t ; the concatenation operation is achieved through the formula . Among them, represents feature concatenation, that is: combining two feature vectors by dimension to form a new feature vector, which contains both the spatial features and time series features of power data.
[0079] In an alternative embodiment, the spatio-temporal feature vector of the data sample extracted by the neural network model in step S200 can also be captured by a spatio-temporal graph neural network. For example, a graph convolutional network (GCN) captures the spatial associations between devices (such as line connections, electrical distances), and combines a gated recurrent unit (GRU) or a temporal attention mechanism to extract dynamic time features.
[0080] In another alternative embodiment, the spatio-temporal feature vector of the data sample extracted by the neural network model in step S200 can also parallelly learn the time dependence and spatial correlation of power data through a multi-head self-attention mechanism. For example, capture the periodic changes of load or the temporal patterns of fault signals through a time attention mechanism, and then quantify the interaction effects between devices at different geographical locations through a spatial attention mechanism.
[0081] It should be noted that the feature extraction of the present invention preferably improves the collaborative extraction of spatio-temporal features of power data by DCNN and LSTM, and incorporates the device security level and time stamp, ensuring data timeliness and traceability compared to only providing a single dimension or simple fixed labels.
[0082] In the embodiment of the present application, in step S300, the spatio-temporal feature vector of each data sample is concatenated with the device security level and the data generation time stamp;
[0083] Specifically, splice the spatio-temporal features F of each extracted data sample i with the corresponding device security level S i and the time stamp t generated by the corresponding data;
[0084] It should be noted that the device security level S i is determined by comprehensively evaluating factors such as the importance of the device, the security of the network location where it is located, and its historical security records.
[0085] Exemplarily, for the above three aspects:
[0086] Weight ratio of device importance: It can be determined according to the function of the device in the power system and its impact on the stability of system operation. For devices that directly affect the stability of power grid operation and play a key role in the continuity of power supply, such as the core transformers of substations, high-voltage transmission lines, etc., the weight ratio of device importance is set to 60%. For devices that assist in the operation of the power system but are not critical, such as some monitoring auxiliary devices, etc., the weight ratio of device importance is set to 20%. For other general devices, the weight ratio is 40%.
[0087] Security of the network location where it is located: Devices located at the network boundary and vulnerable to external attacks have a lower security score; devices located in the internal core network with perfect protection measures have a higher security score. Based on the network security area division and protection intensity assessment, the network location security is divided into 5 levels, and 1-5 points are assigned respectively. 1 point represents the area with the highest security risk, and 5 points represents the area with the lowest security risk.
[0088] Historical security record scoring formula: Suppose that in the past N data collection and transmission processes of the device, the number of data errors is m, and the number of attacks is n, then the historical security record score According to the score range, it is classified. 90-100 points is excellent (corresponding to security level 1), 75-89 points is good (corresponding to security level 2), 60-74 points is medium (corresponding to security level 3), 45-59 points is poor (corresponding to security level 4), and below 45 points is very poor (corresponding to security level 5).
[0089] Based on the evaluation results of the above three aspects, the device security level is obtained through weighted calculation. The calculation formula can be: Device security level = weight ratio of device importance × device importance score + security score of network location where it is located × 0.2 + historical security record score × 0.2. The final device security level is represented in the form of a digital code, where 1 represents the highest security level and 5 represents the lowest security level.
[0090] Exemplarily, for key equipment directly affecting the operation stability of the power grid, its safety level can be set to a relatively high value; while for some auxiliary equipment, the safety level is relatively low. The safety level can be represented in the form of digital coding. For example, 1 represents the highest safety level and 5 represents the lowest safety level.
[0091] It should be noted that the timestamp t is the timestamp when the data is generated, which can adopt the ISO 8601 standard format, accurate to the millisecond level, to ensure the time uniqueness of the data.
[0092] Exemplarily, the splicing operation splices F j , S j and t to obtain a new string F j ||S j ||t, where || represents the string splicing operation. The splicing order can be that the feature vector is in the front, the equipment safety level, and finally the timestamp.
[0093] In the implementation manner of the present application, in step S400, all the spliced strings are input into the collision-resistant hash function, and operations are performed based on the preset tag space dimension to obtain the unique tag value of each data sample, including:
[0094] Input all the spliced strings into the collision-resistant hash function to obtain their respective hash values;
[0095] By performing a modulo operation on each hash value with respect to the tag space dimension K, the unique tag value of each first-class data is obtained.
[0096] Exemplarily, the spliced string is input into the collision-resistant hash function H(·) to obtain a hash value H(F j ||S j ||t);
[0097] Perform a modulo operation on this hash value, that is, Tag j = H(F j ||S j ||t) mod K, where K is the tag space dimension.
[0098] Specifically, the value of the tag space dimension K can be determined through multiple experiments. The experimental process can be: on power data sets of different scales, set K to different values respectively, such as 100, 500, 1000, etc., calculate the tag conflict rate (that is, the proportion of different data samples obtaining the same tag) and the calculation time.
[0099] Preferably, after multiple rounds of experiments in the present application, it is obtained that when K takes the value of 500, while ensuring that the tag conflict rate is lower than 5%, the calculation time is within an acceptable range, and K = 500 is preferably used in the application.
[0100] It should be noted that in this step, the anti-collision hash function SHA-256 algorithm is preferably used. It can generate a 256-bit hash value, which has high security and reliability. It is a function that maps data of any length to a fixed-length hash value and has collision resistance, that is, it is very difficult to find two different data inputs such that their hash values are the same. At the same time, through this dynamic marking algorithm based on the hash chain, each data sample is assigned a unique mark Tag j , which not only contains the characteristic information of the data, but is also closely related to the security level of the device and the data generation time, and can realize the strong binding of data characteristics and security attributes, providing a basis for subsequent operations such as secure aggregation and attack detection.
[0101] In an alternative embodiment, in step S400, all the concatenated strings are input into the anti-collision hash function, and operations are performed based on the preset marking space dimension to obtain the unique marking value of each data sample. It is also possible to segment the output of the anti-collision hash function (such as SHA-256) bit by bit to generate multi-level hash values. According to the preset marking space dimension K, different hierarchical segments of the hash value are respectively mapped to different sub-spaces. For example, the high-order segment is mapped to the space dimension K1, and the low-order segment is mapped to K2; by combining the mapping results of the multi-level sub-spaces, a unique marking value with a multi-dimensional structure is generated.
[0102] In an alternative embodiment, in step S400, all the concatenated strings are input into the anti-collision hash function, and operations are performed based on the preset marking space dimension to obtain the unique marking value of each data sample. It is also possible to convert the string into a fixed-length binary vector by using the anti-collision hash function, and then compress the high-dimensional binary vector to the preset marking space dimension K through random projection to generate a sparse code. Through an encoding conflict detection mechanism, such as a Bloom filter, the uniqueness of the sparse code is ensured.
[0103] It should be noted that steps S300 and S400, compared with the general marking generation method which is preset and fixed and difficult to adapt to data changes and security requirements, generate dynamic marks through the hash chain technology, making the marks closely associated with the data and verifiable, with dynamics, security and traceability.
[0104] In the embodiment of the present application, in step S500, a credibility weighted aggregation is performed on the device data in the data sample to construct an elastic trust evaluation model, and a dynamic trust weight factor is obtained, including the following steps A1 - A3:
[0105] A1: Calculate the device historical credibility through the device historical data;
[0106] Specifically, the device historical credibility C jIt is evaluated based on the historical performance of the device, such as the failure rate of the device, the data error rate, etc.
[0107] Exemplarily, during the past M data collection processes, the number of times device j has failed is m j , and the number of times the data error exceeds a certain threshold is n j , then the historical credibility C of the device j can be defined as The closer the value is to 1, the stronger the ability of the device to provide reliable data historically.
[0108] It should be noted that the historical credibility C of the device j reflects the ability of the device to provide accurate and reliable data over a period of time in the past; this value can be calculated by recording the performance of the device during multiple data collection and transmission processes.
[0109] A2: Calculate the data freshness through the timeliness of the data provided by the device;
[0110] Specifically, the data freshness Δt j is defined as the difference between the current time t and the last data collection time t of device j j , that is, Δt j =t - t j . The fresher the data, the smaller the value of Δt j , indicating that the data can better reflect the actual state of the current power system.
[0111] It should be noted that the data freshness Δt j measures the timeliness of the data provided by device j; in the power system, the state of the power system may change at any time, so the timeliness of the data is also very important.
[0112] A3: Introduce adjustable hyperparameters of device historical credibility and data freshness, as well as a decay coefficient to construct an elastic trust evaluation model, and calculate the dynamic trust weight factor.
[0113] Specifically, the adjustable hyperparameters and the decay coefficient can be defined as α, β, γ respectively;
[0114] α controls the weight of the device historical credibility C j . When α is larger, it means that more importance is attached to the historical performance of the device, that is, devices that have provided reliable data historically will have a higher weight in the aggregation process.
[0115] β controls the weight of the data freshness-related term. When β is larger, it means that more attention is paid to the timeliness of the data, and fresh data will get a higher weight in the aggregation.
[0116] γ is the attenuation coefficient, which is used to adjust the attenuation speed of data freshness. The larger γ is, the faster the data freshness decays over time, that is, the weight of old data will rapidly decrease.
[0117] It should be noted that the above-introduced parameters are all used to adjust the relative importance of device historical credibility and data freshness in the dynamic trust weight factor.
[0118] In the embodiment of the present application, step A3 constructs an elastic trust evaluation model and calculates the dynamic trust weight factor, which can be specifically expressed as:
[0119]
[0120] where, w j is the dynamic trust weight factor; N is the total number of devices participating in data aggregation.
[0121] It should be noted that in this evaluation model, the denominator part sums up for all devices The purpose is to normalize the weight of each device to the interval [0, 1], so that the sum of the weights of all devices is 1, and the weight w j of each device reflects the relative importance of the device in the data aggregation process.
[0122] Specifically, the optimization of the above hyperparameters α, β, and γ can adopt the grid search method, and the process can be: determine the value range of the hyperparameters, the value range of α is [0.1, 0.9], the value range of β is [0.1, 0.9], and the value range of γ is [0.01, 0.1]; perform grid search within this range and combine different values of each hyperparameter. This application conducts experiments on a large amount of historical data of the power system and calculates the error (such as the mean square error) between the aggregation results and the true values under different combinations; after multiple experimental comparisons, when α = 0.5, β = 0.4, and γ = 0.05, it can balance the device historical credibility and data freshness while making the aggregation result closer to the true value, and the preferred values can be used in practical applications.
[0123] It should also be noted that the elastic trust evaluation model has the ability to dynamically adjust the weight over time and device behavior. Traditional trust evaluation methods usually use fixed weights to measure the credibility of devices, which are difficult to adapt to the dynamic changes of device states and data characteristics in the power system. However, the elastic trust evaluation model of the present invention, by introducing a time-varying weight function, comprehensively considers the device historical behavior (such as the device historical credibility C j ) and data freshness (such as Δt j) and by using adjustable hyperparameters α, β, and γ, it can adjust the relative importance of device historical credibility and data freshness in trust evaluation according to different power system operation requirements and security policies in real time, so as to realize the dynamic and accurate evaluation of device trust; this ability to dynamically adjust weights reflects the "elasticity" of the model, enabling it to better adapt to the complex and changeable operation environment of the power system.
[0124] In the embodiment of the present application, in step S600, in combination with the dynamic trust weight factor, the secure aggregation calculation is performed on all data samples by the distributed aggregation method of labeled grouping to obtain the aggregation results of different feature label groups, including the following steps B1 - B3:
[0125] B1: Group all data samples according to the unique label value to obtain different feature label groups;
[0126] B2: Determine whether each device belongs to a specific feature label group through the indicator function, and filter out the device data belonging to the specific feature label group;
[0127] B3: For each feature label group, traverse all devices in the group, multiply the corresponding dynamic trust weight factor, spatio-temporal feature vector, and indicator function of each device, and sum the product results of all devices in the group to obtain the aggregation result of the feature label group.
[0128] Exemplarily, for the above steps B1 - B3, there can be:
[0129] Group the data provided by all devices according to the label Tag of the data j to obtain the feature label group G g ;
[0130] The indicator function Sign is used to determine whether the label Tag of device j j belongs to the g-th feature label group;
[0131] When Tag j = g, Sign(Tag j = g) = 1;
[0132] When Tag j ≠ g, Sign(Tag j = g) = 0.
[0133] For each feature label group G g , traverse all devices j in the group; for each device j, multiply its dynamic trust weight factor w j , feature vector F j (obtained from the feature space construction step in the multi-dimensional feature labeling engine) and the indicator function Sign(Tag jMultiply by (g), and then add up the product results of all devices to obtain the aggregated result Y of this feature marker group g ; Among them, the formula for secure aggregation calculation can be:
[0134]
[0135] It should be noted that since the calculations between different feature marker groups are independent of each other in the above steps, parallel computing can be achieved. In practical applications, a multi-core processor or a distributed computing platform can be used to perform aggregation calculations on multiple feature marker groups simultaneously, thereby improving the computing efficiency; through the distributed aggregation method based on marker grouping such as S600, not only can the secure aggregation of data be achieved, but also the computing resources can be fully utilized to improve the system performance.
[0136] In an alternative embodiment, in step S600, in combination with a dynamic trust weight factor, secure aggregation calculation is performed on all data samples through the distributed aggregation method based on marker grouping to obtain the aggregated results of different feature marker groups. The feature marker groups can also be further divided into dynamic shards, each shard contains some feature marker group devices, and each shard independently performs local aggregation, that is: the devices within the shard perform weighted aggregation based on the dynamic trust weight factor, and then the aggregated results are obtained through a cross-shard negotiation mechanism.
[0137] In another alternative embodiment, in step S600, in combination with a dynamic trust weight factor, secure aggregation calculation is performed on all data samples through the distributed aggregation method based on marker grouping to obtain the aggregated results of different feature marker groups. Laplace noise inversely proportional to the dynamic trust weight can also be generated for each device, and the device uploads the "spatiotemporal feature vector + noise" to the aggregation node, and sums the noise data according to the feature marker group. This method can be directly embedded in the B1 - B3 process, and only a noise layer needs to be added before data upload.
[0138] In the embodiment of the present application, in step S700, an association graph is constructed based on the unique marker value and the device node, including:
[0139] When a unique marker value is assigned to the data generated by a device, a directed edge is established between the device node and the corresponding marker node to generate a marker - device association graph including a node set and an edge set.
[0140] Specifically, the marker - device association graph can be represented as a directed graph G=(V, E);
[0141] Among them, the node set V contains two types of nodes: marker nodes and device nodes; the marker nodes represent each marker Tag generated by the multi - dimensional feature marker engine; the device nodes represent each device in the power system. The edge set E represents the association relationship between the marker and the device.
[0142] Exemplarily, when the data generated by a certain device is given a specific tag, a directed edge is established between the device node and the corresponding tag node. For example, if the data generated by device j is tagged as Tag k , then there is a directed edge from device node j to tag node Tag k .
[0143] It should be noted that for the convenience of subsequent graph analysis, a certain weight can also be assigned to each edge, and the weight can be determined according to factors such as the frequency of data generation and the importance of the data; for example, if a device frequently generates data with a certain tag, the corresponding edge weight can be set higher. The tag-device association graph constructed in this way can clearly show the association relationship between tags and devices, providing a basis for subsequent abnormal node positioning.
[0144] In the embodiment of the present application, in step S700, the importance and suspiciousness of each device node are judged through iterative calculation of graph algorithms, including:
[0145] C1: Perform iterative calculation through the PageRank algorithm based on the generated tag-device association graph;
[0146] C2: When the change in the PageRank scores of all device nodes is less than a set first threshold, the iteration ends, and the scores of each device node are obtained, which are used to judge the importance and suspiciousness of each device node.
[0147] Specifically, in C1, for each device node i in the graph, its PageRank score R i is calculated through the following iterative formula:
[0148]
[0149] Damping factor d: The damping factor d is a constant between 0 and 1, usually taking a value of 0.85. It represents the probability that a user jumps from one node to another through a link; 1 - d represents the probability that a user randomly accesses a node; the introduction of the damping factor is to avoid problems in the calculation of PageRank scores when there are no out-edges for some nodes or there are some isolated subgraphs in the graph.
[0150] Neighbor set B i : B i is the neighbor set pointing to node i. In the tag-device association graph, if there is a directed edge from node j to node i, then node j belongs to the neighbor set B i of node i. For example, if a certain tag node Tagk If there are multiple device nodes pointing to it, then these device nodes form the neighbor set of the Tag k .
[0151] The number of out-edges L j : L j is the number of out-edges of node j. In the graph spectrum, the number of out-edges of node j represents the number of links from this node to other nodes. For example, if a device node may generate data with multiple different tags, then the number of out-edges of this device node is equal to the number of tag nodes it is associated with.
[0152] Exemplarily, regarding the iterative calculation in C2, PageRank can continuously update the score of each node until the score converges. The specific iterative process can be as follows:
[0153] a. Initialize the PageRank score R of all nodes i to the same value, for example where N is the total number of nodes in the graph spectrum.
[0154] b. Calculate the new PageRank score of each node according to the above iterative formula.
[0155] c. Repeat step b until the change in the PageRank score of all nodes is less than a preset threshold, such as: 10 -6 , at this time, it is considered that the score converges and the iteration ends.
[0156] In the embodiment of the present application, in step S700, judging the importance and suspiciousness of each device node includes:
[0157] Set a second threshold, compare the score of the device node with the second threshold, and judge whether isolation is required;
[0158] If there are abnormal devices, locate based on the device node and perform dynamic isolation.
[0159] Exemplarily, the above steps can be: collect the tag-device association graph spectrum data when the power system is operating normally for a certain period of time, such as: one month, calculate the PageRank score of each device node, count the distribution of these scores, and select a suitable value as the threshold θ so that under normal circumstances, the PageRank scores of the vast majority of device nodes are higher than this threshold. Preferably, the threshold θ can be set to 0.01.
[0160] Once an abnormal device is detected, the system will immediately perform dynamic isolation on it; the method of dynamic isolation can be selected according to the actual situation. For example, the connection between the device and the network can be cut off to prevent it from continuing to interact with other devices for data, thus avoiding the spread of abnormal data and the diffusion of attacks. At the same time, the system will record the relevant information of the abnormal device, such as device identification, time of abnormal occurrence, PageRank score, etc., for subsequent analysis and processing.
[0161] In an alternative embodiment, the iterative calculation of the graph algorithm in step S700 can also calculate the frequency of a node appearing in all the shortest paths through betweenness centrality. High betweenness nodes are usually key hubs in the power grid. If the actual traffic of a certain node significantly deviates from its betweenness prediction value, it may be tampered with or faulty.
[0162] In another alternative embodiment, the iterative calculation of the graph algorithm in step S700 can also divide the power grid devices into multiple functional communities through the label propagation algorithm. If the label of a certain device is inconsistent with that of most of its neighbors (such as a distribution cabinet being divided into a power plant community), or the label oscillates frequently, it is marked as suspicious.
[0163] It should be noted that this step constructs a label-device association graph and optimizes the PageRank algorithm. Compared with other graph algorithms, the PageRank algorithm has global influence. The reliability of a substation depends on the states of upstream power plants and downstream power distribution equipment. It can automatically capture this multi-layer dependence, express the indirect dependence that other algorithms cannot display, and can also effectively locate abnormal devices and take dynamic isolation measures in a timely manner, realizing the key link of attack detection and self-healing mechanism, and improving the security and reliability of the power system.
[0164] Embodiment 3, referring to Figure 1 As well as Tables 1 - 3, in order to verify the feasibility and beneficial effects of the present application, based on the above solutions, comprehensive deployments were carried out in a provincial power grid dispatching system, a urban power distribution network, and an industrial microgrid respectively, and detailed comparative analyses were conducted on key performance indicators.
[0165] (1) Implementation of the provincial power grid dispatching system
[0166] ① Deployment process
[0167] When deploying a provincial power grid dispatching system, the system architecture was adjusted and adapted specifically according to the power system safety specifications and operation procedures. In the data acquisition link, the software of the power data acquisition device was upgraded so that it could accurately extract the spatio-temporal features of power data according to the algorithm combining the improved deep convolutional neural network (DCNN) and long short-term memory network (LSTM), and generate corresponding labels according to the dynamic labeling algorithm based on the hash chain.
[0168] In the data processing and aggregation stage, computing programs of the adaptive security aggregation model are respectively deployed on the edge computing nodes and the central server to achieve credibility-weighted aggregation and distributed aggregation computing based on tag grouping. For the attack detection and self-healing mechanism, a tag-device association graph database is constructed, and an anomaly detection program based on the PageRank algorithm is run on the server.
[0169] ② Test environment
[0170] Hardware configuration: The edge computing nodes adopt servers equipped with Intel Xeon E5-2620v4 processors and 32GB of memory, and the central server adopts high-performance servers with Intel Xeon Platinum 8260 processors and 128GB of memory.
[0171] Network topology: The internal network of the provincial power grid dispatching system adopts a star topology. The data acquisition devices are connected to the edge computing nodes through optical fibers, and the edge computing nodes interact with the central server through high-speed network links for data.
[0172] Attack simulation tools: The Metasploit framework is used to simulate various network attacks, such as false data injection attacks (FDIA), denial of service attacks (DoS), replay attacks, etc.
[0173] ③ Test results and analysis
[0174] Traditional methods generally extract data through statistical features, such as mean, variance, or PCA dimensionality reduction. All data is directly uploaded to the central server, and batch processing or fixed-time window aggregation is adopted, and fixed weights are assigned.
[0175] After a period of running tests, the comparison results of key performance indicators are shown in Table 1:
[0176] Table 1: Comparison results of key performance indicators (1)
[0177] Index Traditional method This method Data processing delay 120ms 18ms Attack detection rate (FDIA) 85.4% 98.7% Attack detection rate (DoS) 80% 95% Attack detection rate (replay attack) 75% 90% Communication overhead 1.2Gbps 0.4Gbps
[0178] Due to the low efficiency of data feature extraction and aggregation computing in traditional methods, the data processing delay is as high as 120ms. However, with the improved network architecture and aggregation computing method of the present invention, the data processing efficiency is significantly improved, and the delay is reduced to 18ms, which enables the power system to respond more quickly when facing tasks with high real-time requirements.
[0179] In terms of attack detection, traditional methods lack effective dynamic trust evaluation mechanisms and accurate anomaly detection means, resulting in low detection rates for different types of attacks. The label-device association graph constructed in the present invention, combined with the PageRank algorithm and the elastic trust evaluation model, can accurately locate suspicious nodes, effectively identify various attacks, and significantly improve the attack detection rate. For example, when simulating the FDIA attack, the detection rate of the present invention reaches 98.7%, showing a significant improvement compared with traditional methods.
[0180] In terms of communication overhead, the communication overhead of traditional methods reaches 1.2 Gbps during data transmission. The hierarchical security aggregation architecture of the present invention adopts a label-driven packet aggregation mechanism, supports local processing in the edge computing layer, and a large amount of data is aggregated in the edge computing layer before transmission, reducing the communication overhead to 0.4 Gbps, a reduction of 67%, effectively reducing the network bandwidth pressure.
[0181] ④ Long-term operation stability
[0182] During the continuous 30-day operation, the false alarm rate of the system was monitored. The results show that the false alarm rate of the present invention always remains at a low level, with an average false alarm rate of 1.2% and a small fluctuation range (between 0.8% and 1.5%), indicating that the system has high stability during long-term operation.
[0183] (2) Implementation in urban distribution network
[0184] ① Deployment process
[0185] In the deployment of the urban distribution network, an area with a high density of users was selected as a pilot. This area contains a large number of residential and commercial users, with a high data collection frequency and complex data types. In view of this characteristic, the components of the present invention were optimized and configured. In the multi-dimensional feature labeling engine, the data feature extraction algorithm was further optimized to adapt to the diverse data in the urban distribution network. In the adaptive security aggregation model, the calculation parameters of the dynamic trust weight factor were adjusted to better handle the aggregation of high-density user data. The attack detection and self-healing mechanism optimized the construction of the label-device association graph and the parameter settings of the PageRank algorithm according to the network structure characteristics of the urban distribution network.
[0186] ② Test environment
[0187] Hardware configuration: The edge computing device uses a small server with an Intel Core i7-8700 processor and 16 GB of memory, and the centralized processing device uses a server with an Intel Xeon E5-2650v4 processor and 64 GB of memory.
[0188] Network Topology: The urban distribution network adopts a tree - shaped network topology. The data acquisition devices are connected to the edge computing devices through low - voltage power line carrier communication or wireless communication technologies, and the edge computing devices transmit data to the centralized processing devices through a wired network.
[0189] Attack Simulation Tools: Use the Scapy tool to simulate common attacks on the urban distribution network, such as tampering with user electricity consumption data and interfering with communication signals.
[0190] ③ Test Results and Analysis
[0191] After testing, the key performance indicators are shown in Table 2:
[0192] Table 2: Comparison Results of Key Performance Indicators (2)
[0193] Index Traditional method This method Data processing delay 150ms 25ms Data processing accuracy 92% 98% Concurrent user processing capacity 5000 users 10000 users Attack detection rate (tampered data attack) 82% 96% Attack detection rate (communication interference attack) 78% 93%
[0194] In the scenario of processing high - density user data in the urban distribution network, the traditional method has a long data - processing delay, reaching 150 ms, a low data - processing accuracy rate, only 92%, and limited concurrent user processing capacity, making it difficult to meet the data - processing requirements during peak hours. Through optimizing the algorithm and architecture, the present invention shortens the data - processing delay to 25 ms, improves the data - processing accuracy rate to 98%, and increases the concurrent user processing capacity to 10,000 households, effectively coping with the complex data - processing scenario of the urban distribution network.
[0195] In terms of attack detection, for the common data - tampering attacks and communication - interference attacks in the urban distribution network, the present invention also shows a high detection rate, having obvious advantages compared with the traditional method.
[0196] ④ Long - term Operational Stability
[0197] During the continuous 30 - day operation monitoring, the average false - alarm rate of the system is 1.3%, and the fluctuation range is between 0.9% - 1.6%, indicating that the system can also operate stably in the urban distribution network environment.
[0198] (3) Implementation of Industrial Micro - grid
[0199] ① Deployment Process
[0200] Industrial microgrids have extremely high requirements for data real-time performance, especially the real-time aggregation of high-frequency data. When deploying in a certain industrial microgrid, the real-time processing capabilities of the multi-dimensional feature marking engine and the adaptive security aggregation model were optimized. In the multi-dimensional feature marking engine, the speed and accuracy of data feature extraction were improved to ensure the ability to process high-frequency data quickly and accurately. The adaptive security aggregation model adopted a more efficient distributed computing framework to meet the needs of real-time aggregation of high-frequency data. The attack detection and self-healing mechanism adjusted the thresholds and algorithm parameters of anomaly detection according to the characteristics of industrial microgrid equipment.
[0201] ② Test environment
[0202] Hardware configuration: The edge computing device uses an FPGA chip with real-time processing capabilities, combined with a high-speed data acquisition card. The central processing unit uses a high-performance NVIDIA GPU server to accelerate data processing.
[0203] Network topology: The industrial microgrid adopts a ring network topology. The data acquisition device is connected to the edge computing device through a high-speed serial bus, and the edge computing device transmits data to the central processing unit through a fiber optic network.
[0204] Attack simulation tool: Custom attack scripts are used to simulate possible attacks in the industrial microgrid, such as maliciously modifying device operation parameters and blocking data transmission.
[0205] ③ Test results and analysis
[0206] The key performance indicators obtained from the test are shown in Table 3:
[0207] Table 3: Comparison results of key performance indicators (3)
[0208] Index Traditional method This method High-frequency data real-time aggregation delay 80ms 15ms Data integrity 90% 99% Abnormal data detection rate 80% 95% Attack detection rate (malicious parameter modification attack) 75% 92% Attack detection rate (blocking data transmission attack) 70% 90%
[0209] When the traditional method processes high-frequency data in an industrial microgrid, the real-time aggregation delay is relatively high, reaching 80 ms, the data integrity is only 90%, and the anomaly data detection rate and attack detection rate are also relatively low. Through the optimized technical solution of the present invention, the real-time aggregation delay of high-frequency data is reduced to 15 ms, the data integrity is increased to 99%, and the anomaly data detection rate and attack detection rate are also greatly improved, meeting the strict requirements of industrial microgrids for data real-time performance and accuracy.
[0210] ④ Long-term operation stability
[0211] During the continuous 30-day operation process, the average false alarm rate of the system is 1.1%, and the fluctuation range is between 0.7% and 1.4%, proving that the system has good stability in the industrial microgrid environment.
[0212] Through implementation in different scenarios of provincial power grid dispatching systems, urban distribution networks, and industrial microgrids, as well as detailed analysis of the test environment, test results, and long-term operation stability, it can be seen that the intelligent security aggregation framework proposed by the present invention exhibits significant advantages in different scales and scenarios, effectively improving data processing efficiency, security, and the overall performance of the system. It has broad practicality and adaptability and can provide reliable technical support for various power systems.
[0213] Embodiment 4. The above is a schematic solution of an intelligent security aggregation processing method for a power system. It should be noted that the technical solution of the system for intelligent security aggregation processing of the power system belongs to the same concept as the technical solution of the above intelligent security aggregation processing method for the power system. For the details not described in detail in the technical solution of the system for intelligent security aggregation processing of the power system in this embodiment, reference can be made to the description of the technical solution of the above intelligent security aggregation processing method for the power system.
[0214] This embodiment also provides a system for intelligent security aggregation processing of a power system, including:
[0215] An acquisition module, configured to acquire data samples generated by the power system;
[0216] A feature extraction module, configured to extract spatio-temporal feature vectors of the data samples through a neural network model;
[0217] A splicing module, configured to splice the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp;
[0218] A marking module, configured to input all the spliced strings into a collision-resistant hash function and perform operations based on a preset marking space dimension to obtain a unique marking value for each data sample;
[0219] A credibility calculation module, configured to perform credibility weighted aggregation on the device data in the data samples to obtain a dynamic trust weight factor;
[0220] A security aggregation module, configured to combine the dynamic trust weight factor and perform security aggregation calculation on all data samples through a distributed aggregation method grouped by marking to obtain aggregation results of different feature marking groups;
[0221] An anomaly isolation module, configured to construct an association graph based on the unique marking value and device nodes, and judge the importance and suspiciousness of each device node through iterative calculation of graph algorithms to achieve dynamic isolation of abnormal devices.
[0222] This embodiment also provides an electronic device, which is applicable to the intelligent and secure aggregation processing of a power system, and includes: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for realizing the intelligent and secure aggregation processing of the power system as proposed in the above embodiment.
[0223] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for realizing the intelligent and secure aggregation processing of the power system as proposed in the above embodiment.
[0224] The storage medium proposed in this embodiment and the method for realizing the intelligent and secure aggregation processing of the power system proposed in the above embodiment belong to the same inventive concept. For the technical details not described in detail in this embodiment, reference can be made to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.
[0225] Through the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software and necessary general-purpose hardware, and of course, it can also be implemented by hardware. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk, or optical disc of a computer, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of various embodiments of the present invention.
[0226] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. An intelligent safety aggregation processing method for a power system, characterized in that, Including: Obtain data samples generated by the power system; Extract spatio-temporal feature vectors of the data samples through a neural network model; Concatenate the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp; Input all the concatenated strings into a collision-resistant hash function, and perform operations based on the preset tag space dimension to obtain the unique tag value of each data sample; Perform credibility weighted aggregation on the device data in the data samples to construct an elastic trust evaluation model, and obtain a dynamic trust weight factor; Combined with the dynamic trust weight factor, perform secure aggregation calculation on all data samples through a distributed aggregation method of tag grouping to obtain the aggregation results of different feature tag groups; Construct an association graph based on the unique tag value and device nodes, and through iterative calculation of graph algorithms, judge the importance and suspiciousness of each device node to achieve dynamic isolation of abnormal devices.
2. The intelligent security aggregation processing method for a power system according to claim 1, wherein Input all the concatenated strings into a collision-resistant hash function, and perform operations based on the preset tag space dimension to obtain the unique tag value of each data sample, including: Input all the concatenated strings into a collision-resistant hash function to obtain their respective hash values; Perform a modulo operation on each hash value with respect to the tag space dimension K to obtain the unique tag value of each first type of data.
3. The intelligent safety aggregation processing method for a power system according to claim 2, wherein, Perform credibility weighted aggregation on the device data in the data samples to construct an elastic trust evaluation model, and obtain a dynamic trust weight factor; including: Calculate the device historical credibility through device historical data; Calculate the data freshness through the timeliness of the data provided by the device; Introduce adjustable hyperparameters and attenuation coefficients of device historical credibility and data freshness to construct an elastic trust evaluation model, and calculate to obtain a dynamic trust weight factor.
4. The intelligent safety aggregation processing method for a power system according to claim 3, characterized in that, Combined with the dynamic trust weight factor, perform secure aggregation calculation on all data samples through a distributed aggregation method of tag grouping, including: Group all data samples according to the unique tag value to obtain different feature tag groups; Use an indicator function to judge whether each device belongs to a specific feature tag group, and filter out the device data belonging to the specific feature tag group; For each feature tag group, traverse all devices in the group, multiply each device by the corresponding dynamic trust weight factor, spatio-temporal feature vector and indicator function, and sum the product results of all devices in the group to obtain the aggregation result of the feature tag group.
5. The intelligent safety aggregation processing method for a power system according to claim 4, wherein, Construct an association graph based on the unique tag value and device nodes, including: When a unique tag value is assigned to the data generated by a device, a directed edge is established between the device node and the corresponding tag node to generate a tag-device association graph including a node set and an edge set.
6. The intelligent safety aggregation processing method for a power system according to claim 5, characterized in that, The iterative calculation through graph algorithms to judge the importance and suspiciousness of each device node, including: Perform iterative calculation based on the generated tag-device association graph through the PageRank algorithm; When the change in the PageRank scores of all device nodes is less than a set first threshold, the iteration ends, and the scores of each device node are obtained for judging the importance and suspiciousness of each device node.
7. The intelligent security aggregation processing method for a power system according to claim 6, wherein, The judgment of the importance and suspiciousness of each device node, including: Set a second threshold, compare the device node score with the second threshold, and determine whether isolation is required; If there are abnormal devices, locate them based on the device nodes and perform dynamic isolation.
8. An intelligent security aggregation and processing system for a power system, which applies the method according to any one of claims 1-7, characterized in that Including: An acquisition module for acquiring data samples generated by the power system; A feature extraction module for extracting spatio-temporal feature vectors of the data samples through a neural network model; A splicing module for splicing the spatio-temporal feature vectors of each data sample with the device security level and the data generation timestamp; A marking module for inputting all spliced strings into a collision-resistant hash function and performing operations based on a preset marking space dimension to obtain a unique marking value for each data sample; A credibility calculation module for performing credibility weighted aggregation on the device data in the data samples to obtain a dynamic trust weight factor; A secure aggregation module for combining the dynamic trust weight factor and performing secure aggregation calculations on all data samples through a distributed aggregation method grouped by marks to obtain the aggregation results of different feature mark groups; An abnormal isolation module for constructing an association graph based on the unique marking value and the device node, and judging the importance and suspiciousness of each device node through iterative calculations of graph algorithms to achieve dynamic isolation of abnormal devices.
9. An electronic device, including: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the power system intelligent secure aggregation processing method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing computer-executable instructions, which when executed by a processor implement the steps of the power system intelligent secure aggregation processing method according to any one of claims 1 to 7.