False data injection attack positioning detection method and system based on improved extreme learning machine

By building a hybrid FDIA model with cost-benefit balance of attacks, combining GRU and ELM algorithms for timing feature extraction and hyperparameter optimization, the instability and low efficiency in detection of false data injection attacks is solved, and efficient and accurate detection and positioning of the power system is achieved.

CN120415787AActive Publication Date: 2025-08-01ZHEJIANG UNIV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510487374.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-08-01
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

The prior art fails to fully utilize the timing characteristics of the power system in the detection of false data injection attacks, and the random initialization of traditional extreme learning machine algorithms leads to unstable detection results, which cannot effectively reflect the diversity characteristics and economic losses of the attack, consumes high computing resources, and is low optimization efficiency.

Method used

A hybrid FDIA model with attack cost-benefit balance is constructed, time-series feature extraction is performed in combination with GRU algorithm, binary classification is performed through ELM algorithm, and hyperparameters are optimized using Bayesian optimization algorithm, and GRU weights are optimized, and GRU weights are optimized to achieve efficient and accurate FDIA positioning detection.

Benefits of technology

It realizes efficient and accurate detection of false data injection attacks, can fully reflect the diversity characteristics of the attack, improve the stability and efficiency of the detection results, and provide important security defense and abnormal repair basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415787A_ABST
    Figure CN120415787A_ABST
Patent Text Reader

Abstract

The invention discloses a false data injection attack positioning detection method and system based on an improved extreme learning machine, and relates to the field of smart power grids, and the method comprises the steps: constructing an attack cost-benefit balanced hybrid FDIA model, and obtaining an attack measurement data set; performing time sequence feature extraction on the attack measurement data set by adopting a GRU algorithm, and performing dichotomy on each node state of the power system through an ELM algorithm to obtain a GRU-ELM attack positioning detection algorithm; performing global optimization on hyper-parameters of the GRU-ELM attack positioning detection algorithm based on a Bayesian optimization algorithm to obtain an optimal hyper-parameter combination; and obtaining a power grid FDIA positioning detection algorithm based on the BO-GRU-ELM according to the optimal hyper-parameter combination, and positioning the hybrid FDIA attack. According to the method, the extreme learning machine algorithm is improved and optimized through the optimization algorithm, and efficient and accurate positioning detection of the false data injection attack of the power system can be effectively realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart grids, and more particularly to a method and system for locating and detecting false data injection attacks based on an improved extreme learning machine. Background Art

[0002] With the continuous development of new power systems, the degree of cyber-physical coupling in power systems continues to deepen, exacerbating the potential threat of cyberattacks to the security, stability, and economic operation of power grids. Among them, false data injection attacks can undermine the integrity and accuracy of power system terminal data by constructing residual-invariant attack vectors, thereby affecting power system state estimation results, misleading dispatcher decisions, and seriously threatening the operational safety of the power system. Therefore, research on the location and detection methods of false data injection attacks can improve the security and stability of power systems and provide support for post-analysis and anomaly repair work.

[0003] Although research on the location and detection of false data injection attacks (FDIA) based on extreme learning machines (ELMs) has made some progress, some shortcomings remain. First, existing research primarily focuses on attack detection targeting the power system's operating status, ignoring the diverse nature of FDIA attack targets. In reality, attackers not only target the system's operating status but can also influence power generation costs by tampering with load demand data, thereby causing significant economic losses. Second, existing research fails to fully utilize the temporal characteristics of power system measurement data, whereas in-depth exploration of its time series features could significantly improve detection accuracy. Finally, the traditional random initialization of input weights in the ELM algorithm often leads to insufficiently stable detection results. Furthermore, while metaheuristic hyperparameter optimization methods can achieve optimal solutions for complex machine learning tasks, their high computational resource consumption and low optimization efficiency remain significant limitations.

[0004] Therefore, how to improve and optimize the extreme learning machine algorithm through optimization algorithm, and then effectively achieve efficient and accurate positioning detection of false data injection attacks on power systems is a technical problem that technical personnel in this field urgently need to solve. Summary of the Invention

[0005] In view of this, the present invention provides a false data injection attack location detection method and system based on an improved extreme learning machine, which solves the problems existing in the background technology.

[0006] In order to achieve the above object, the present invention provides the following technical solutions:

[0007] A false data injection attack location detection method based on an improved extreme learning machine, comprising the following steps:

[0008] S1: Construct a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set;

[0009] S2: Use the GRU algorithm to extract time series features from the attack measurement data set, and perform binary classification on the states of each node in the power system through the ELM algorithm to obtain the GRU-ELM attack location detection algorithm;

[0010] S3: Globally optimize the hyperparameters of the GRU-ELM attack location detection algorithm based on the Bayesian optimization algorithm to obtain the optimal hyperparameter combination;

[0011] S4: Obtain the power grid FDIA location detection algorithm based on BO-GRU-ELM according to the optimal hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA location detection result.

[0012] Optionally, in S1, constructing a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set specifically includes the following steps:

[0013] S11: Considering both the attack cost and the attack benefit comprehensively, transform the attack strategy into an optimization problem, and the objective function is:

[0014] min F = min(f attack -k×f power )

[0015] Where: f attack = ||h(x a ) - h(x)||0 represents the sparsity of the attack vector, represents the generation cost; x a represents the state estimation value after the attack, h(x a ) represents the measured value after the attack, x represents the state estimation value before the attack, and h(x) represents the measured value before the attack, represents the active power output of the generator, a represents the quadratic term coefficient, b represents the linear term coefficient, c represents the constant term, and k represents the balance coefficient;

[0016] S12: For the above objective function, the following constraint conditions are listed simultaneously:

[0017]

[0018] Where: x i and respectively represent the state estimation values before and after the attack, V i and θ iThe state estimation values representing the voltage amplitude and phase angle respectively represent the deviation of the state estimation value after the attack, Ω net represents the set of power system nodes, x imin represents the minimum value of the state value, x imax represents the maximum value of the state value;

[0019] Substitute the state estimation values x before and after the attack i and into the FDIA attack construction principle formula, and the following formula can be obtained:

[0020]

[0021] In the formula: represents the SCADA measurement attack vector data, including node voltage amplitude, node active power, node reactive power, line active power and line reactive power; represents the PMU measurement attack vector data, including node voltage amplitude and phase angle, real and imaginary parts of line current;

[0022]

[0023] In the formula: represents the false load value of node i, P di represents the true load value of node i, represents the load deviation value deliberately injected by the attacker;

[0024] The power balance formula for each node of the system is:

[0025]

[0026] In the formula: represents the generator injection power of node i; represents the node injection power, which is equal to the difference between the power flowing into the line and the power flowing out of the line of node i; the injected active and reactive power of the generator needs to meet the set maximum and minimum value constraints [P gimin , P gimax and [Q gimin , Q gimax .

[0027] Optionally, in S2, obtain the GRU-ELM attack localization detection algorithm, which specifically includes the following steps:

[0028] S21: Use GRU to extract features from the attack measurement data set to obtain the hidden layer output matrix H;

[0029] S22: Use the output matrix H of the hidden layer of the GRU as the input matrix of the hidden layer of the ELM, and use the ELM to perform binary classification label determination on the states of each node in the power system. A label of 0 indicates that the detection result is normal, and a label of 1 indicates that the detection result is abnormal;

[0030] S23: Calculate the loss function L based on binary cross-entropy. The overall loss function L is defined as the sum of the loss functions L in each dimension, and the expression is as follows: j Sum, the expression is as follows:

[0031]

[0032] In the formula: n represents the number of samples, c represents the output dimension, t ij represents the true value, and y ij represents the predicted value;

[0033] S24: Perform gradient optimization on the GRU weight function based on error backpropagation. Use the ELM as the output, and the gradient of the loss function with respect to the output h ij of the GRU cell changes. The updated gradient is shown in the following formula:

[0034]

[0035] In the formula: β + represents the inverse matrix of the output weight β;

[0036] Obtain the gradients of the loss function with respect to the GRU parameters W z , W r , W h , and implement weight optimization based on the following formula:

[0037]

[0038] In the formula: W (k+1) represents the weight at the (k + 1)th moment, W (k) represents the weight at the kth moment, η represents the learning rate, and L represents the loss function.

[0039] Optionally, in S22, the ELM directly calculates the output weight by randomly initializing the weight and the least squares method, without iterative training. The specific content is as follows:

[0040] Based on the hidden layer output matrix H obtained in S21, assume the output weight is β = [β1,..., β c T ∈R c×k , then the calculation formula from the hidden layer H to the output layer Y is expressed as:

[0041] βH = Y

[0042] For the objective function min||βH - Y||​2 , the output weight β is solved based on the least squares method as follows:

[0043] β = YH +

[0044] In the formula: H + represents the Moore - Penrose generalized inverse of matrix H.

[0045] Optionally, in S3, obtaining the optimal hyperparameter combination specifically includes the following steps:

[0046] S31: By using the Synthetic Minority Over - sampling Technique (SMOTE) to equalize the attack - class data samples, a model training data set is obtained;

[0047] S32: Construct a probabilistic surrogate model through Gaussian process to approximate the objective function f(x), that is, the F2 - score;

[0048] S33: Based on the acquisition function EI +, select the next most potential hyperparameter combination situation and re - evaluate the objective function;

[0049] S34: Repeat S32 and S33. Through continuous iterative optimization, until the convergence condition or the number of iterations is met, output the best historical evaluation point to obtain the optimal hyperparameter combination.

[0050] A false data injection attack location detection system based on an improved extreme learning machine, which executes the false data injection attack location detection method based on an improved extreme learning machine described in any one of the above, includes:

[0051] A data acquisition module, used to construct a hybrid FDIA model with balanced attack cost - benefit, and obtain an attack measurement data set;

[0052] An algorithm establishment module, used to extract time - series features from the attack measurement data set by using the GRU algorithm, and perform binary classification on the states of each node in the power system through the ELM algorithm to obtain a GRU - ELM attack location detection algorithm;

[0053] A BO algorithm optimization module, used to globally optimize the hyperparameters of the GRU - ELM attack location detection algorithm through the Bayesian optimization algorithm to obtain the optimal hyperparameter combination;

[0054] A location detection module, used to obtain a power grid FDIA location detection algorithm based on BO - GRU - ELM according to the optimal hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA location detection result.

[0055] It can be seen from the above - mentioned technical solutions that, compared with the prior art, the present invention discloses a false data injection attack location detection method and system based on an improved extreme learning machine, having the following beneficial effects:

[0056] (1) The present invention constructs a hybrid FDIA model with an attack cost-benefit balance, breaking through the limitation of traditional FDIA attacks that only focus on the system operating state, and being able to more comprehensively reflect the diversity characteristics of actual attacks;

[0057] (2) The present invention proposes an FDIA positioning detection architecture based on GRU-ELM, deeply excavates the temporal characteristics of measurement data, and introduces an error backpropagation mechanism to optimize and improve the weight function of GRU, thereby enhancing the accuracy of feature extraction and the stability of detection results;

[0058] (3) The present invention designs a GRU hyperparameter adaptive tuning scheme based on Bayesian optimization. Compared with traditional heuristic algorithms, it can significantly improve the operation efficiency of the FDIA positioning detection algorithm while maintaining the optimization accuracy;

[0059] (4) The present invention can efficiently and accurately detect and locate hybrid FDIA attacks, providing an important basis for aspects such as power system security defense, post-event analysis, and anomaly repair. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.

[0061] Figure 1 It is a flowchart of the false data injection attack positioning detection method based on the improved extreme learning machine provided by the present invention;

[0062] Figure 2 It is a comparison diagram of measurement data before and after the attack provided by the present invention;

[0063] Figure 3 It is a comparison diagram of state estimation results before and after the attack provided by the present invention;

[0064] Figure 4 It is a loss function decline curve graph provided by the present invention;

[0065] Figure 5 It is a Bayesian optimization convergence curve graph provided by the present invention;

[0066] Figure 6 It is a flowchart of the FDIA positioning detection algorithm based on BO-GRU-ELM provided by the present invention;

[0067] Figure 7The FDIA detection accuracy diagram of the power system nodes provided by the present invention. Detailed implementation manners

[0068] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0069] An embodiment of the present invention discloses a false data injection attack location detection method based on an improved extreme learning machine, as Figure 1 shown, including the following steps:

[0070] S1: Construct a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set;

[0071] S2: Use the GRU algorithm to extract the time series features of the attack measurement data set, and perform binary classification on the states of each node of the power system through the ELM algorithm to obtain the GRU-ELM attack location detection algorithm;

[0072] S3: Based on the Bayesian optimization algorithm, globally optimize the hyperparameters of the GRU-ELM attack location detection algorithm to obtain the optimal hyperparameter combination, and further improve the accuracy of the attack detection model;

[0073] S4: Obtain the power grid FDIA location detection algorithm based on BO-GRU-ELM according to the optimal hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA location detection result.

[0074] Further, in S1, constructing a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set specifically includes the following steps:

[0075] S11: Considering both the attack cost and the attack benefit comprehensively, transform the attack strategy into an optimization problem, and the objective function is:

[0076] min F = min(f attack -k×f power )

[0077] In the formula: f attack = ||h(x a ) - h(x)||0 represents the sparsity of the attack vector, represents the generation cost; x a represents the state estimation value after the attack, h(x a) represents the measured value after the attack, x represents the state estimate before the attack, and h(x) represents the measured value before the attack. represents the active power output of the generator, a represents the quadratic coefficient, b represents the linear coefficient, c represents the constant term, and k represents the balance coefficient.

[0078] Specifically, the attack targets of FDIA in the power system include system operation instability, power economic losses, power failure accidents, etc. Currently, most research mainly focuses on analyzing the operation state of the power system. However, at the economic level, by tampering with the load demand data through load redistribution attacks, forcing the dispatching of power generation resources to deviate from the optimal state, the overall power generation cost of the power system can increase. In addition, attackers often strive to cause great harm at low cost. However, the two are contradictory. The better the attack benefit, that is, the more system state values affected by the attack and the greater the deviation, it means that more measurement units need to be tampered with collaboratively, the greater the required attack cost, and the higher the probability of being detected. At the same time, considering the attack vector sparsity f attack and the power generation cost f power have different orders of magnitude. Therefore, in this embodiment, a balance coefficient k is introduced. By adjusting the value of k, the importance ratio of the two in the objective function F is changed, and then an optimal objective optimization function that comprehensively considers sparsity and power generation cost is obtained. Through example simulation verification, k = 1.5 is selected in this embodiment.

[0079] S12: For the above objective function, the following constraint conditions are listed simultaneously:

[0080]

[0081] In the formula: x i and respectively represent the state estimates before and after the attack, V i and θ i respectively represent the state estimates of the voltage amplitude and phase angle. represents the deviation of the state estimate after the attack, Ω net represents the set of power system nodes, x imin represents the minimum value of the state value, x imax represents the maximum value of the state value; this formula indicates the deviation constraint of FDIA on the state estimate, ensuring that the voltage amplitude V i and phase angle θ i estimate x i are still within the non-alarm range [x imin , x imax ;

[0082] The state estimates x i and Substituting the FDIA attack construction principle formula, we can get the following formula:

[0083]

[0084] Where: Represents SCADA measurement attack vector data, including node voltage amplitude, node active power, node reactive power, line active power, and line reactive power; represents the PMU-measured attack vector data, including the node voltage amplitude and phase angle, and the real and imaginary parts of the line current. This formula ensures that the residuals before and after the system attack remain unchanged, which means that the power system can successfully pass the bad data detection.

[0085]

[0086] Where: represents the false load value of node i, P di represents the actual load value of node i, It represents the load deviation value deliberately injected by the attacker to construct false load demand data;

[0087] The power balance formula of each node in the system is:

[0088]

[0089] Where: represents the generator injected power at node i; It represents the node injection power, which is equal to the difference between the incoming line power and the outgoing line power of node i. Simplified, the generator P g The calculation formula of the active and reactive power injected by the generator must meet the set maximum and minimum constraints [P gimin ,P gimax ] and [Q gimin ,Q gimax ].

[0090] Specifically, in the example simulation, the measurement data and state estimation results of the power system before and after the FDIA attack are as follows: Figure 2 、 Figure 3 As shown in the figure, the attack can effectively cause some nodes to deviate, and after the attack, the power system's power generation cost increases from 7.3729e+03 to 1.84e+04, causing economic losses to the power system.

[0091] Furthermore, in S2, a GRU-ELM attack location detection algorithm is obtained, which specifically includes the following steps:

[0092] S21: Use GRU to extract features from the attack measurement dataset and obtain the hidden layer output matrix H;

[0093] Specifically, the power measurement data mainly includes key parameters such as node voltage amplitude, phase angle, line current, active power, and reactive power, and has time-series characteristics related to the periodic fluctuations of the power grid load. By deeply mining time-series characteristics such as voltage volatility and power trend, the accuracy of data feature extraction can be improved, providing reliable support for the FDIA detection of power systems. The Gated Recurrent Unit (GRU), as a variant of the Long Short-Term Memory (LSTM) network, is suitable for processing time-series data and reduces the model complexity by simplifying the control gate structure. Based on this characteristic, the GRU has significant advantages in the FDIA attack detection task with high real-time requirements, and can quickly respond and reduce the impact of attacks on the system.

[0094] The GRU unit can efficiently capture the time-domain features contained in the measurement data by controlling the update gate and the reset gate, while avoiding the problem of gradient disappearance or explosion, as shown below:

[0095] z t = σ(W z ·[h t-1 , x t )

[0096] r t = σ(W r ·[h t-1 , x t )

[0097] h' t = tanh(W h ·[r t ⊙ h t-1 , x t )

[0098] h t = (1 - z t ) ⊙ h t-1 + z t ⊙ h' t

[0099] In the formula: x t represents the input state of the GRU unit at time t; h t-1 , h t represent the output states of the GRU unit at times t - 1 and t respectively; W z , W r , W h represent the update gate z t , the reset gate r t , and the hidden layer h' tThe weight matrix; σ and tanh represent activation functions, where σ represents the Sigmoid function; ⊙ represents the element-wise product of vectors. Among them, the update gate determines the degree of information transmission, and the reset gate controls the degree of information forgetting. By calculating the hidden layer state h' of the measurement feature at time t t , and then combining the update gate with h t-1 and h' t for summation, the output state h t of the GRU cell at time t can be obtained, that is, the time series eigenvalue of the measurement data.

[0100] S22: Use the hidden layer output matrix H of the GRU as the input matrix of the ELM hidden layer, and use ELM to perform binary classification label determination on the states of each node in the power system. A label of 0 indicates that the detection result is normal, and a label of 1 indicates that the detection result is abnormal;

[0101] Specifically, ELM is a fast single-hidden-layer feedforward neural network algorithm that directly calculates the output weights through random initialization of weights and the least squares method, without iterative training. Due to the simplicity, efficiency and suitability for large-scale data of the ELM algorithm, it is widely used in attack detection.

[0102] For an ELM model with k hidden layer neurons, based on the hidden layer output matrix H obtained from S21, let the output weight be β = [β1,…,β c T ∈R c×k , then the calculation formula from the hidden layer H to the output layer Y is expressed as:

[0103] βH = Y

[0104] For the objective function min||βH - Y|| 2 , the output weight β is solved based on the least squares method as:

[0105] [[ID=X]]β = YH +

[0106] In the formula: H + represents the Moore-Penrose generalized inverse of matrix H. [[ID=X]]

[0107] At the same time, the ELM algorithm has the characteristics of multiple inputs and multiple outputs. Through the multi-label binary classification method, the attack location detection of the power system node state estimation value can be realized. In practical applications, the output result y is determined by the following formula for labels:

[0108]

[0109] Among them, a label of 0 indicates that the detection result is normal, and a label of 1 indicates that the detection is abnormal.

[0110] ​S23: Calculate the loss function L based on binary cross - entropy. Since the output result is in multi - dimensional form, the overall loss function L is defined as the sum of the loss functions L for each dimension, and the expression is as follows: j where:

[0111]

[0112] In the formula: n represents the number of samples, c represents the output dimension, t ij represents the true value, and y ij represents the predicted value;

[0113] S24: Optimize the gradient of the GRU weight function based on error backpropagation. Using ELM as the output, when the loss function changes the gradient of the output h ij of the GRU unit, the updated gradient is shown as follows:

[0114]

[0115] In the formula: β + represents the inverse matrix of the output weight β;

[0116] Obtain the gradients of the loss function with respect to the GRU parameters W z , W r , W h [[ID=�4]]and optimize the weights based on the following formula:

[0117]

[0118] In the formula: W (k+1) represents the weight at the (k + 1) - th moment, W (k) represents the weight at the k - th moment, η represents the learning rate, and L represents the loss function.

[0119] Specifically, due to the random weight initialization of traditional ELM, the results are somewhat unstable. However, the BP mechanism can make the output results tend to be stable through error backpropagation and iterative optimization. At the same time, as a differentiable neural network, GRU combined with the BP mechanism can make full use of gradient optimization to improve the accuracy of measuring data feature extraction, thus significantly enhancing the performance and accuracy of the algorithm. The BP algorithm is a classic method in neural network training. It adjusts the network parameters through gradient descent technology, making the loss function gradually converge to the minimum value to achieve model optimization. Among them, the descent curve of the loss function is as Figure 4 shown. Although the loss function fluctuates, the overall trend is significantly decreasing. The loss value has decreased from 0.011 to 0.0029 and finally tends to be stable, thus verifying the effectiveness of the error backpropagation algorithm.

[0120] Furthermore, in S3, obtain the best hyperparameter combination, which specifically includes the following steps:

[0121] S31: Dataset preprocessing. The synthetic minority over-sampling technique (SMOTE) is used to equalize the attack-class data samples, obtaining the model training dataset.

[0122] Specifically, the multi-dimensional measurement data generated by the hybrid FDIA model is used as the input and divided into a training set and a test set. To address the problem of the imbalance in the proportion of attack data and normal data in the dataset, the synthetic minority over-sampling technique is used to equalize the attack-class data samples.

[0123] S32: Construct a probabilistic surrogate model through Gaussian Processes (GPs) to approximate the objective function f(x), i.e., the F2 score.

[0124] S33: Based on the acquisition function EI+, select the next most promising hyperparameter combination and re-evaluate the objective function.

[0125] S34: Repeat S32 and S33. Through continuous iterative optimization until the convergence condition or the number of iterations is met, output the best historical evaluation point to obtain the best hyperparameter combination.

[0126] Specifically, the Bayesian Optimization (BO) algorithm mainly consists of two core parts: a probabilistic surrogate model and an acquisition function. Its core idea is to approximate the objective function by constructing a surrogate model and combine the acquisition function to select the most promising parameter combination, gradually approaching the global optimal solution. In the FDIA positioning detection algorithm of this embodiment, the probabilistic surrogate model approximates the objective function f(x) through Gaussian Processes. The acquisition function is responsible for guiding the hyperparameter optimization process. In this embodiment, EI+ is used to select the next most "promising" hyperparameter combination. To address the possible gradient fluctuations and noise problems in the GRU-ELM training under the hybrid FDIA scenario, EI+ introduces a smoothing factor on the basis of the traditional Expected Improvement (EI), enhancing the robustness of the algorithm in complex attack data and enabling it to efficiently select the optimal parameter combination, thereby improving the convergence efficiency of the FDIA positioning detection model and the accuracy of attack feature recognition.

[0127] In addition, since the performance of the GRU-ELM algorithm is significantly affected by hyperparameters such as the learning rate, batch size, and the number of hidden layer units. To maximize the performance of the attack detection algorithm, in this embodiment, the F2 score is used as the objective function, and the BO algorithm is used to optimize the above hyperparameters. The convergence curve of the Bayesian optimization process is as Figure 5As shown in the figure, through continuous iterative optimization, the best F2 score of 0.9863 is finally obtained. The corresponding best hyperparameter combination is: learning rate of 0.02, batch size of 124, and the number of hidden layer units of 85.

[0128] This embodiment combines the adaptive and efficient parameter optimization ability of Bayesian optimization, the time series feature extraction ability of GRU, and the fast and accurate classification ability of ELM, and proposes an attack location detection method based on Bayesian optimization GRU-ELM to achieve accurate location and detection of FDIA. The specific architecture and process of the algorithm are as Figure 6 shown.

[0129] Compared with Figure 1 the method described above, the embodiment of the present invention also provides a false data injection attack location detection system based on an improved extreme learning machine for Figure 1 the specific implementation of the method in. The false data injection attack location detection system based on an improved extreme learning machine provided by the embodiment of the present invention can be applied to computer terminals or various mobile devices, and specifically includes:

[0130] A data acquisition module, configured to construct a hybrid FDIA model with an attack cost-benefit balance to obtain an attack measurement data set;

[0131] An algorithm establishment module, configured to use the GRU algorithm to extract time series features from the attack measurement data set, and perform binary classification on the states of each node in the power system through the ELM algorithm to obtain a GRU-ELM attack location detection algorithm;

[0132] A BO algorithm optimization module, configured to globally optimize the hyperparameters of the GRU-ELM attack location detection algorithm through the Bayesian optimization algorithm to obtain the best hyperparameter combination;

[0133] A location detection module, configured to obtain a power grid FDIA location detection algorithm based on BO-GRU-ELM according to the best hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA location detection result.

[0134] In order to further analyze and verify the effectiveness of the algorithm proposed in this embodiment, taking the accuracy rate as the evaluation index, instance simulations are carried out on three FDIA location detection algorithms of BO-GRU-ELM, GRU-ELM, and ELM. The experimental results are as Figure 7 shown. As Figure 7As shown, the BO-GRU-ELM algorithm shows good detection performance on almost all nodes. In terms of amplitude detection at nodes 6, 10, and 13, it is significantly better than the other two methods, further verifying the effectiveness of the proposed algorithm. Overall, the performance of each algorithm in phase angle detection is significantly better than that in amplitude detection, indicating that phase angle features may be more discriminative in FDIA detection. In summary, the BO-GRU-ELM algorithm demonstrates more superior performance in FDIA detection and location, and can effectively improve the security of the power system.

[0135] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For related parts, reference can be made to the description in the method section.

[0136] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting the location of false data injection attacks based on an improved extreme learning machine, characterized in that It includes the following steps: S1: Construct a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set; S2: Use the GRU algorithm to extract time series features from the attack measurement data set, and perform binary classification on the states of each node in the power system through the ELM algorithm to obtain the GRU-ELM attack location detection algorithm; S3: Globally optimize the hyperparameters of the GRU-ELM attack location detection algorithm based on the Bayesian optimization algorithm to obtain the optimal hyperparameter combination; S4: Obtain the power grid FDIA location detection algorithm based on BO-GRU-ELM according to the optimal hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA location detection result.

2. The false data injection attack localization and detection method based on an improved extreme learning machine according to claim 1, wherein, In S1, to construct a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set, it specifically includes the following steps: S11: Comprehensively consider the attack cost and attack benefit, and transform the attack strategy into an optimization problem. The objective function is: min F = min(f attack -k×f power ) where: f attack = ||h(x a ) - h(x)||0 represents the sparsity of the attack vector, represents the power generation cost; x a represents the state estimation value after the attack, h(x a ) represents the measured value after the attack, x represents the state estimation value before the attack, h(x) represents the measured value before the attack, represents the active power output of the generator, a represents the quadratic coefficient, b represents the linear coefficient, c represents the constant term, k represents the balance coefficient; S12: For the above objective function, the following constraint conditions are listed at the same time: where: x i and represent the state estimation values before and after the attack, V i and θ i represent the state estimation values of the voltage amplitude and phase angle respectively, represents the deviation of the state estimation value after the attack, Ω net represents the set of power system nodes, x imin represents the minimum value of the state value, x imax represents the maximum value of the state value; Substitute the state estimation values x before and after the attack i and into the FDIA attack construction principle formula, and the following formula can be obtained: In the formula: represents the SCADA measurement attack vector data, including the node voltage amplitude, node active power, node reactive power, line active power, and line reactive power; represents the PMU measurement attack vector data, including the node voltage amplitude and phase angle, and the real and imaginary parts of the line current; In the formula: represents the false load value of node i, P di represents the true load value of node i, represents the load deviation value deliberately injected by the attacker; The power balance formula for each node in the system is: In the formula: represents the generator injection power of node i; represents the node injection power, which is equal to the difference between the power flowing into the lines and the power flowing out of the lines of node i; the active and reactive power injected by the generator needs to satisfy the set maximum and minimum value constraints [P gimin , P gimax and [Q gimin , Q gimax .

3. The false data injection attack localization and detection method based on an improved extreme learning machine according to claim 1, wherein In S2, to obtain the GRU-ELM attack location detection algorithm, it specifically includes the following steps: S21: Use GRU to extract features from the attack measurement data set to obtain the hidden layer output matrix H; S22: Use the hidden layer output matrix H of GRU as the input matrix of the hidden layer of ELM, and perform binary classification label determination on the states of each node in the power system through ELM. The label of 0 indicates that the detection result is normal, and the label of 1 indicates that the detection result is abnormal; S23: Calculate the loss function L based on binary cross-entropy. The overall loss function L is defined as the sum of the loss functions L for each dimension, and the expression is as follows: j The sum is as follows: Where: n represents the number of samples, c represents the output dimension, and t ij represents the true value, and y ij represents the predicted value; S24: Gradient optimization is performed on the GRU weight function based on error backpropagation, using ELM as the output, and the gradient of the loss function with respect to the output h of the GRU cell changes. The updated gradient is shown as follows: ij The gradient of the loss function with respect to the output h of the GRU cell changes. The updated gradient is shown as follows: where: β + represents the inverse matrix of the output weight β; Obtain the gradients of the loss function with respect to the GRU parameters W z , W r , W h , and implement the optimization of the weights based on the following formula: where: W (k+1) represents the weight at time k+1, W (k) represents the weight at time k, η represents the learning rate, and L represents the loss function.

4. A false data injection attack localization and detection method based on an improved extreme learning machine according to claim 3, characterized in that In S22, ELM directly calculates the output weight through random initialization of weights and the least squares method without iterative training. The specific content is: Based on the hidden layer output matrix H obtained from S21, let the output weight be β = [β1, …, β c T ∈ R c×k , then the calculation formula from the hidden layer H to the output layer Y is expressed as:​ βH = Y For the objective function min||βH - Y|| 2 , the output weight β is solved based on the least squares method as follows: β = YH + where: H + denotes the Moore-Penrose generalized inverse of matrix H.

5. A false data injection attack localization and detection method based on an improved extreme learning machine according to claim 1, characterized in that, In S3, to obtain the optimal hyperparameter combination, it specifically includes the following steps: S31: Perform equalization processing on the attack class data samples by using the synthetic minority over-sampling technique to obtain the model training data set; S32: Construct a probabilistic surrogate model through the Gaussian process to approximate the objective function f(x), that is, the F2 score; S33: Select the next most potential hyperparameter combination situation based on the acquisition function EI+ and re-evaluate the objective function; S34: Repeat S32 and S33, and through continuous iterative optimization until the convergence condition or the number of iterations is met, output the best historical evaluation point to obtain the optimal hyperparameter combination.

6. A false data injection attack location detection system based on an improved extreme learning machine, characterized in that, Execute the false data injection attack location detection method based on the improved extreme learning machine as described in any one of claims 1-5, including: A data acquisition module for constructing a hybrid FDIA model with balanced attack cost and benefit to obtain an attack measurement data set; An algorithm establishment module for using the GRU algorithm to extract time series features from the attack measurement data set and performing binary classification on the states of each node in the power system through the ELM algorithm to obtain the GRU-ELM attack location detection algorithm; A BO algorithm optimization module for globally optimizing the hyperparameters of the GRU-ELM attack location detection algorithm through the Bayesian optimization algorithm to obtain the optimal hyperparameter combination; The positioning detection module is used to obtain the power grid FDIA positioning detection algorithm based on BO-GRU-ELM according to the optimal hyperparameter combination, locate the hybrid FDIA attack, and output the FDIA positioning detection result.

Citation Information

Patent Citations

  • Intelligent power grid false data injection attack detection method

    CN110035090A

  • Network abnormal flow detection method, model and system

    CN112784881A

  • False data injection attack defense method based on differential game

    CN114157478A

  • Annular DC micro-grid fault positioning method based on local data driving

    CN119337182A