New energy power system false load data detection and recovery method and system

By constructing an attack model based on the limited resources of the attacker and using the GoDec algorithm to decompose false load data, combined with compact mixed integer programming, the efficiency and accuracy problems of false data injection attack detection and recovery are solved, and the security and stability of the new energy power system are improved.

CN120785580APending Publication Date: 2025-10-14XI AN JIAOTONG UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510851265.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

The existing false data injection attack (FDIA) detection method has low computational efficiency and insufficient recovery accuracy, making it difficult to meet the requirements of load data security and unit combination optimization in an environment with a high proportion of renewable energy grid connection.

Method used

Based on the realistic constraints of the attacker's limited resources, an attack model is constructed and decomposed into two sub-problems: low-rank matrix estimation and sparse matrix update using the GoDec algorithm. A compact mixed integer linear programming model is then used to perform unit commitment optimization decision-making.

Benefits of technology

Significantly reduce numerical errors and position errors, improve computing efficiency, meet real-time needs, reduce operating costs, and enhance system stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785580A_ABST
    Figure CN120785580A_ABST
Patent Text Reader

Abstract

The invention discloses a new energy power system false load data detection and recovery method and system, and the method comprises the steps: carrying out the attack behavior modeling of load data, and obtaining an attack model; when it is monitored that the data of the power system is abnormal, the constraint of the obtained attack model is converted into a mathematical decoupling condition through a matrix decomposition algorithm so that the abnormal data can be processed subsequently, an attack amplitude and a position matrix are identified, and a GoDec algorithm is adopted to decompose a problem into two sub-problems of low-rank matrix estimation and sparse matrix updating; iterative solution is carried out, so that an attack amplitude and a position matrix are identified, and a recovered load matrix is obtained; obtaining recovered load data, and evaluating errors; and adopting a compact mixed integer linear programming model to carry out unit commitment optimization decision on the recovered load data, and adding compact constraints. According to the method, attack modeling, the GoDec algorithm and optimization decision are fused, high-efficiency detection and recovery of false load data are realized, and the security, stability and economy of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of electrical engineering technology, and in particular relates to a method and system for detecting and recovering false load data of a new energy power system. Background Art

[0002] With the increasing integration of cyber and physical infrastructure, modern power systems are increasingly susceptible to information security threats, which can compromise operational reliability and increase system costs. As core data in power systems, load measurement and forecasting accuracy are directly related to the reliability of key energy management system (EMS) functions, such as unit commitment (UC), state estimation (SE), and load frequency control (LFC). These risks are particularly prominent in renewable energy systems, where volatility and uncertainty complicate safe operation. Therefore, designing effective methods to recover distorted load data is crucial to ensuring the safe operation of power systems.

[0003] From an analysis of attack mechanisms, power system cyberattacks primarily operate at two levels: Information layer attacks involve penetrating measurement and communication networks to launch false data injection attacks (FDIAs). Load redistribution attacks (LRAs) that target node power and branch flows are particularly damaging. Physical layer attacks directly damage primary equipment or secondary systems, potentially leading to serious consequences such as voltage instability. In particular, attackers can inject malicious temperature data into weather forecast application programming interfaces (APIs) to distort load forecasts, thereby impacting power system unifying (UC) decisions.

[0004] In the environment of high proportion of renewable energy grid-connected, the distortion of load data will have more significant impact. The superposition of strong randomness of wind power and photovoltaic output and load measurement error will exacerbate the net load prediction deviation and affect the rationality of rotating reserve capacity configuration. Notably, due to the coupling effect between weather conditions and loads, there is a certain degree of similarity between certain load nodes, and the attack matrix presents a sparse feature. Based on this, the FDIA detection can be modeled as a low-rank and sparse matrix decomposition problem. The existing research uses methods such as augmented Lagrange multiplier (ALM) and low-rank matrix fitting (LMaFit) to solve this problem. Among them, the ALM method of double-noise-dual-problem (DNDP) further improves the robustness of matrix separation by introducing double regularization terms, providing a solution for detecting and restoring load data. SUMMARY

[0005] The technical problem to be solved by the present application is to provide a new energy power system false load data detection and recovery method and system to solve the technical problems of low calculation efficiency, insufficient recovery accuracy and difficulty in meeting the load data security and unit commitment optimization requirements in the high proportion of new energy grid-connected environment.

[0006] The application adopts the following technical scheme: A new energy power system false load data detection and recovery method, comprising the following steps: S1, based on the realistic constraints of the limited resources of the attacker, modeling the attack behavior of the load data to obtain an attack model; S2, when the abnormality of the power system data is monitored, the constraints of the attack model obtained in step S1 are converted into mathematical decoupling conditions by a matrix decomposition algorithm, and a mathematical model is obtained by conversion; S3, using the GoDec algorithm to decompose the mathematical model obtained in step S2 into two sub-problems of low-rank matrix estimation and sparse matrix update, and after iterative solving, the attack amplitude and position matrix are identified, and the restored load matrix is obtained; S4, after multiple update iterations, the restored load data and the identified attack matrix are obtained, and the error is evaluated; S5, using a compact mixed integer linear programming model to make unit commitment optimization decision on the restored load data in step S4, and adding compact constraints to obtain the unit commitment decision result under the injection of false load information.

[0007] Preferably, in step S1, the attack behavior modeling comprises: Local damage constraint: the attacker can only target a limited set of nodes Implement data tampering, and its attack matrix satisfies the sparsity condition , Represents the actual value of the total elements of the sparse attack matrix; Randomness constraint: The attacker's attack penetration rate follows a Poisson distribution ; Rational attack constraints: attackers prioritize important load nodes and critical time periods as attack targets.

[0008] Preferably, in step S2, the matrix decomposition algorithm adopts robust matrix decomposition technology.

[0009] Preferably, the power grid includes Nodes in The original load matrix of the period , and has low-rank characteristics, when subjected to false data injection attacks, given the observation load matrix , decoupled by robust matrix decomposition technology:

[0010] The low-rank matrix decomposition problem is transformed into a non-convex optimization problem:

[0011] in, is the restored low-rank load matrix, represents the rank of the low-rank loading matrix, To satisfy The sparse attack matrix, Represents the estimated value of the total elements of the sparse attack matrix.

[0012] Preferably, in step S3, the GoDec algorithm adopts an alternating direction optimization strategy and dynamically adjusts the matrix rank and sparsity.

[0013] Preferably, the GoDec algorithm transforms the problem into:

[0014] The corresponding optimization problem is:

[0015] in, represents noise, represents the number of nonzero entries in the matrix, represents the observation load matrix, is the restored low-rank load matrix, To satisfy The sparse attack matrix, represents the rank of the matrix, represents the estimated value of the rank of the low-rank matrix, Represents the estimated value of the total elements of the sparse attack matrix.

[0016] Preferably, the recovery error in step S4 includes a numerical error and a position error, which is specifically calculated as follows:

[0017]

[0018] in, and They are the attack position of the identified attack matrix and the actual attack matrix position, is the restored low-rank load matrix, is the original load matrix, is the number of selected grid nodes, The selected time period.

[0019] Preferably, in step S5, the objective function of the compact mixed integer linear programming model is to minimize the sum of power generation cost and energy abandonment penalty, and the remaining constraints include upper and lower limit constraints of unit output, thermal power unit ramping constraints, thermal power unit start and stop constraints, and grid power balance constraints.

[0020] Preferably, the objective function is expressed as:

[0021] in, Indicates thermal power unit In the period The cost of electricity generation is higher than the minimum output; is the corresponding segment cost coefficient; For the crew In the period The start / stop state binary variable; A collection representing the startup types of the unit; Indicates the unit In startup mode Start-up costs; is the corresponding startup state binary variable; is the penalty coefficient for renewable energy curtailment; and Represents renewable energy units In the period Maximum output and actual output; The compact constraints added are:

[0022]

[0023] in, represents the shutdown state of the thermal generator at a point in time, Indicates the starting status of the thermal generator at a point in time, Shut down the unit The time after which the device starts offline.

[0024] In a second aspect, an embodiment of the present invention provides a new energy power system false load data detection and recovery system, comprising: The construction module models the attack behavior of the load data based on the realistic constraints of the attacker's limited resources to obtain the attack model; The conversion module, when detecting abnormal power system data, converts the constraints of the attack model into mathematical decoupling conditions through a matrix decomposition algorithm to obtain a mathematical model; The iterative module uses the GoDec algorithm to decompose the obtained mathematical model into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the recovered load matrix is ​​obtained; The calculation module obtains the restored load data and the identified attack matrix after multiple update iterations and evaluates the error; The recovery module uses a compact mixed integer linear programming model to make unit commitment optimization decisions based on the restored load data, and adds compact constraints to obtain the unit commitment decision results under the injection of false load information.

[0025] In a third aspect, a computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned new energy power system false load data detection and recovery method when executing the computer program.

[0026] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, comprising a computer program, which, when executed by a processor, implements the steps of the above-mentioned new energy power system false load data detection and recovery method.

[0027] In a fifth aspect, a chip includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned method for detecting and recovering false load data of a new energy power system are implemented.

[0028] In a sixth aspect, an embodiment of the present invention provides an electronic device, comprising a computer program, which, when executed by the electronic device, implements the steps of the above-mentioned new energy power system false load data detection and recovery method.

[0029] Compared with the prior art, the present invention has at least the following beneficial effects: A method for detecting and recovering false load data in renewable energy power systems constrains attack behavior through attack modeling, providing a theoretical basis for detection. The GoDec algorithm, combined with dynamic rank adjustment, significantly reduces numerical and position errors. Alternating direction optimization shortens calculation time to 0.35-0.49 seconds, meeting real-time requirements. Compact mixed integer programming reduces unit costs and load losses, improving the stability of renewable energy grid connection.

[0030] Furthermore, we can accurately simulate actual attack scenarios, improve the practicality of the model, and provide sparsity condition support for decoupling.

[0031] Furthermore, the robust matrix factorization technique decouples the contamination matrix and effectively separates the attack data, reducing the recovery error by 54.7%, which is better than the traditional ALM / DNDP method.

[0032] Furthermore, through adaptive parameter optimization, computing efficiency is improved by 28 times, making it suitable for large-scale power systems.

[0033] Furthermore, the recovery effect can be quantitatively evaluated to provide a reliable data basis for unit optimization.

[0034] Furthermore, it can reduce operating costs, minimize load losses, and enhance system stability under a high proportion of new energy.

[0035] Furthermore, through modular design and full-process automation, the response speed and anti-interference ability are improved.

[0036] It can be understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here.

[0037] In summary, the present invention integrates attack modeling, the Godec algorithm, and optimized decision-making to achieve efficient detection and recovery of false load data, thereby improving system security, stability, and economy.

[0038] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 Flow chart of the method of the present invention; Figure 2 It is the box diagram of the restored load error at each moment; Figure 3 shows the load recovery effect under different attack levels, where (a) shows the cost increase under Attack 1 and (b) shows the load loss under Attack 2. Figure 4 A schematic diagram of a computer device provided in accordance with an embodiment of the present invention; Figure 5 The block diagram of a chip provided according to one embodiment of the present invention is shown.

[0040] Among them, 60. Computer device; 61. Processor; 62. Memory; 63. Computer program; 600. Electronic device; 610. Processing unit; 620. Storage unit; 6201. Random access memory unit; 6202. Cache memory unit; 6203. Read-only memory unit; 6204. Program / Utility; 6205. Program module; 630. Bus; 640. Display unit; 650. Input / output interface; 660. Network adapter; 700. External device. DETAILED DESCRIPTION

[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0042] In the description of the present invention, it is to be understood that the terms “include” and “comprise” indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.

[0043] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0044] It should be further understood that the term "and / or" as used in the present specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects are in an "or" relationship.

[0045] It should be understood that, although the terms first, second, third, etc. can be employed in describing the preset ranges, etc. in the embodiments of the present application, the preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from each other. For example, the first preset range can also be referred to as the second preset range, and similarly, the second preset range can also be referred to as the first preset range, without departing from the scope of the embodiments of the present application.

[0046] Depending on the context, the word "if" as used herein can be interpreted to mean "when" or "while" or "in response to determining" or "in response to detecting." Similarly, the phrase "if it is determined" or "if [a stated condition or event] is detected" can be interpreted to mean "when it is determined" or "in response to determining" or "when [a stated condition or event] is detected" or "in response to detecting [a stated condition or event]."

[0047] Various structural diagrams according to the disclosed embodiments of the present application are shown in the accompanying drawings. These diagrams are not drawn to scale, in which certain details are exaggerated for the purpose of clarity, and certain details can be omitted. The shapes of various regions, layers, and the relative size and positional relationship therebetween shown in the diagrams are only exemplary, and in actuality, they can be deviated due to manufacturing tolerances or technical limitations, and regions / layers with different shapes, sizes, and relative positions can be additionally designed according to actual needs by those skilled in the art.

[0048] In view of the load data distortion caused by false data injection attack (FDIA) under high proportion of renewable energy grid connection, the present application provides a new energy power system false load data detection and recovery method. An attack model is constructed based on the limited resources of the attacker, the attack constraints are converted into mathematical decoupling conditions, the problem is made more in line with the actual attack characteristics, and it is distinguished from the traditional generalization modeling of pure data driving. The GoDec algorithm is used to replace the traditional ALM / LMaFit method, and the mathematical model is decomposed into two sub-problems of low-rank matrix estimation and sparse matrix update for iterative solution. Compared with existing methods, GoDec realizes high-precision attack identification and data recovery with lower computational complexity, significantly improving real-time performance. The recovered load data is directly input into a compact mixed integer linear programming model for unit commitment optimization, and a compact constraint is introduced to process the uncertainty of the recovered data. This solves the problem of the separation of detection and decision in the prior art, ensuring the robustness of UC decision in the attack scenario. Through the three-stage innovation of attack constraint decoupling + GoDec efficient decomposition + compact decision optimization, the limitations of low computational efficiency and insufficient recovery accuracy of traditional FDIA detection methods are broken through, and integrated protection from attack detection to safe decision is realized, which is especially suitable for the load data security demand under high proportion of renewable energy grid connection.

[0049] Please refer to Figure 1The present invention provides a method for detecting and recovering false load data of a new energy power system, comprising the following steps: S1, load data attack modeling; S101. First, explain the causes of load data distortion: The integrity of power system load data may be subject to multiple security threats: 1) False data injection attack: A malicious entity in a cyber-physical system injects fake load values ​​through the communication channel; 2) Meteorological parameter tampering attacks: For example, abnormal temperature data can be implanted through the weather forecast interface to interfere with the spatiotemporal correlation characteristics of the load forecast model and achieve multi-directional manipulation of the load curve.

[0050] S102. Analysis of potential hazards of load data distortion; For unit combinations, the following risks exist: Exaggerating peak load forecasts can lead to over-commitment of high-cost peaking units and inefficient reserve allocation, which in turn increases operating costs and reduces system efficiency due to frequent starts and shutdowns.

[0051] Underestimating load can violate the minimum output constraints of thermal power units, forcing unnecessary outages or deep cycling, increasing maintenance costs, and shortening unit life.

[0052] Furthermore, this would lead to curtailment of renewable energy, undermining carbon reduction targets and destabilizing the system during high-demand conditions.

[0053] When the system experiences heavy loads, failures in several key lines can trigger a chain reaction. Distorting the relationship between peak and valley loads disrupts the coupling of operational decisions across time periods. This leads to inefficient unit scheduling and imbalanced reserve margins, compromising system stability.

[0054] S103, aggressive behavior modeling; Based on the attacker's limited resources (attack cost , penetration ability and data tampering rate ) realistic constraints, the following basic assumptions are proposed: 1) Local damage assumption: the attacker can only target a limited set of nodes Implement data tampering, and its attack matrix satisfies the sparsity condition , Represents the actual value of the total elements of the sparse attack matrix; 2) Randomness constraint: Due to the defense mechanism of the cyber-physical power systems (CPS) of the power grid, the attacker’s attack penetration rate follows a Poisson distribution. ; 3) Rational attack assumption: To maximize the system operating cost, attackers prioritize high-importance load nodes and important time periods as attack vectors.

[0055] S2, construct the load low-rank matrix; Considering the meteorological-load coupling effect of geographically adjacent nodes, the power grid contains Nodes in The original load matrix of the period Has low-rank properties.

[0056] S201, when subjected to false data injection attack, the contaminated load matrix Expressed as:

[0057] in, is the attack matrix; given the observation load matrix , through the robust matrix decomposition technology, decoupling is:

[0058] in, is the restored low-rank load matrix, Represents the rank of the matrix, satisfying , To satisfy The sparse attack matrix, Represents the estimated value of the total elements of the sparse attack matrix.

[0059] S202. The low-rank matrix decomposition problem is transformed into a non-convex optimization problem:

[0060] When abnormal power system data is detected, the matrix decomposition algorithm is used to process the abnormal data. Through matrix decomposition, the attack amplitude and position matrix can be identified, and the restored low-rank load matrix can be obtained. , providing a reliable load data foundation for subsequent unit commitment optimization. Since this type of optimization problem is NP-hard and it is difficult to guarantee a global optimal solution, this paper proposes an improved decomposition and coordination algorithm (GoDec algorithm) to achieve efficient recovery of the load matrix.

[0061] S3. Using the GoDec algorithm, the problem is transformed into:

[0062] in, represents noise, Represents the number of non-zero entries in the matrix, that is, the sparse attack matrix Contains up to non-zero elements. The corresponding optimization problem is:

[0063] An alternating direction optimization strategy is adopted to decompose the original problem into two sub-problems and solve them iteratively.

[0064] S301, low rank matrix estimation; fixed Solution

[0065] Accelerate the calculation by BRP. , have:

[0066] in, is the number of iterations used to improve the accuracy of the low-rank approximation. Generate a Gaussian random matrix ;but The BRP is:

[0067] in, for The left random projection of is a right random projection, is the rank of the low-rank matrix; is an independent Gaussian random matrix, is a The updated matrix is ​​updated as follows:

[0068] Using BRP, The rank estimate of is:

[0069] To obtain the rank of Approximate value, calculated and The QR decomposition of

[0070] Thus we get The estimated value of is:

[0071] S302, sparse matrix update: fixed Solution:

[0072] Its closed-form solution is a hard threshold operation:

[0073] in, To retain the residual matrix The largest absolute value elements and set the rest to zero.

[0074] Finally, the relative error is used to test the convergence of the algorithm.

[0075]

[0076] in, is a positive scalar.

[0077] S303. Rank and sparsity of the dynamic matrix.

[0078] The initial rank estimate and sparsity estimate may deviate from the actual state, so the rank and sparsity of the matrix are dynamically adjusted in the loop as follows:

[0079]

[0080] in, To dynamically adjust the ratio, 、 is the sparsity The upper and lower bounds of .

[0081] S4. Calculation of load matrix recovery error: The attacker's attack matrix contains two types of information: the value of the false injection information and the location where the false information is injected. The numerical error and position error are set to test the effectiveness of the Gode method proposed in this invention. The numerical error and position error are calculated as follows:

[0082]

[0083] in, and They are the attack position of the identified attack matrix and the actual attack matrix position, , the attack point is 1, and the rest are 0.

[0084] The ALM algorithm of low-rank matrix decomposition, the ALM algorithm of random low-rank matrix decomposition, and the DNDP dual solution algorithm were selected as the control groups for comparison.

[0085] S5. Solve the unit combination.

[0086] S501, the compact mixed integer linear programming (Tight and Compact MILP) model performs unit commitment optimization decision-making on the restored load data. Its objective function is expressed as:

[0087] in, Indicates thermal power unit In the period The cost of electricity generation is higher than the minimum output; is the corresponding segment cost coefficient; For the crew In the period The start / stop state binary variable; A collection representing the startup types of the unit; Indicates the unit In startup mode Start-up costs; is the corresponding startup state binary variable; is the penalty coefficient for renewable energy curtailment; and Represents renewable energy units In the period The maximum output and actual output.

[0088] S502. The added compact constraints are:

[0089]

[0090] in, represents the shutdown state of the thermal generator at a point in time, Indicates the startup status of the thermal generator at a point in time. Shut down the unit The time after which the device starts offline.

[0091] The remaining constraints include: upper and lower limit constraints on unit output, thermal power unit ramp constraints, thermal power unit start and stop constraints, and grid power balance constraints.

[0092] In another embodiment of the present invention, a new energy power system false load data detection and recovery system is provided, which can be used to implement the above-mentioned new energy power system false load data detection and recovery method. Specifically, the new energy power system false load data detection and recovery system includes a construction module, a conversion module, an iteration module, a recovery module and a recovery module.

[0093] Among them, the construction module models the attack behavior of the load data based on the realistic constraints of the attacker's limited resources to obtain the attack model; The conversion module, when detecting abnormal power system data, converts the constraints of the attack model into mathematical decoupling conditions through a matrix decomposition algorithm to obtain a mathematical model; The iterative module uses the GoDec algorithm to decompose the obtained mathematical model into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the recovered load matrix is ​​obtained; The calculation module obtains the restored load data and the identified attack matrix after multiple update iterations and evaluates the error; The recovery module uses a compact mixed integer linear programming model to make unit commitment optimization decisions based on the restored load data, and adds compact constraints to obtain the unit commitment decision results under the injection of false load information.

[0094] The present invention provides a terminal device, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, graphics processing units (GPUs), tensor processing units (TPUs), digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the false load data detection and recovery method of the new energy power system, including: Based on the realistic constraints of the attacker's limited resources, the attack behavior of the load data is modeled to obtain the attack model; when the power system data is monitored to be abnormal, the constraints of the attack model are converted into mathematical decoupling conditions through the matrix decomposition algorithm to obtain the mathematical model; the GoDec algorithm is used to decompose the obtained mathematical model into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the restored load matrix is ​​obtained; after multiple update iterations, the restored load data and the identified attack matrix are obtained, and the error is evaluated; a compact mixed integer linear programming model is used to perform unit combination optimization decision on the restored load data, and compact constraints are added to obtain the unit combination decision result under the injection of false load information.

[0095] See also Figure 4 The terminal device is a computer device. Computer device 60 in this embodiment includes: a processor 61, a memory 62, and a computer program 63 stored in memory 62 and executable by processor 61. When executed by processor 61, computer program 63 implements the method for estimating the concentration of radioactive iodine species in a post-accident containment vessel described in this embodiment. To avoid repetition, this description is omitted here. Alternatively, when executed by processor 61, computer program 63 implements the functions of various models / units in the false load data detection and recovery system for a new energy power system described in this embodiment. To avoid repetition, this description is omitted here.

[0096] The computer device 60 may be a desktop computer, a notebook computer, a PDA, a cloud server, or other computing devices. The computer device 60 may include, but is not limited to, a processor 61 and a memory 62. It will be understood by those skilled in the art that Figure 4 This is merely an example of the computer device 60 and does not constitute a limitation of the computer device 60 . The computer device 60 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device may also include input and output devices, network access devices, buses, etc.

[0097] The processor 61 may be a central processing unit (CPU), or other general-purpose processors, a graphics processing unit (GPU), a tensor processing unit (TPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0098] The memory 62 may be an internal storage unit of the computer device 60, such as a hard disk or memory of the computer device 60. The memory 62 may also be an external storage device of the computer device 60, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 60.

[0099] Furthermore, the memory 62 may include both an internal storage unit of the computer device 60 and an external storage device. The memory 62 is used to store computer programs and other programs and data required by the computer device. The memory 62 may also be used to temporarily store data that has been output or is about to be output.

[0100] See also Figure 5 The terminal device is an electronic device 600, which is implemented as a general-purpose computing device. The components of the electronic device may include, but are not limited to, at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different platform components (including the storage unit 620 and the processing unit 610), and a display unit 640.

[0101] The storage unit stores program codes, which can be executed by the processing unit 610, so that the processing unit 610 performs the steps according to various exemplary embodiments of the present invention described in the above method section of this specification. For example, the processing unit 610 can perform the following steps: Figure 1 Follow the steps shown in .

[0102] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 6201 and / or a cache memory unit 6202 , and may further include a read-only memory unit (ROM) 6203 .

[0103] The storage unit 620 may also include a program / utility 6204 having a set (at least one) of program modules 6205, such program modules 6205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0104] Bus 630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0105] The electronic device 600 may also communicate with one or more external devices 700 (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 600, and / or any device that enables the electronic device 600 to communicate with one or more other computing devices (e.g., a router, a modem). Such communication may occur via an input / output interface 650. Furthermore, the electronic device 600 may also communicate with one or more networks (e.g., a local area network, a wide area network, and / or a public network, such as the Internet) via a network adapter 660. The network adapter 660 may communicate with other modules of the electronic device 600 via a bus 630. It should be understood that, although not shown in the figures, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms.

[0106] Example 4 The present invention also provides a storage medium, specifically a computer-readable storage medium. The computer-readable storage medium is a memory device in a terminal device, used to store programs and data. It is understood that the computer-readable storage medium herein may include both the built-in storage medium in the terminal device and, of course, the extended storage medium supported by the terminal device. It may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for being loaded and executed by a processor. These instructions may be one or more computer programs (including program code). It should be noted that more specific examples of the computer-readable storage medium herein include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0107] Computer-readable storage media also include data signals propagated in baseband or as part of a carrier wave, which carry readable program code. Such propagated data signals can take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium can also be any readable medium other than a readable storage medium, which can send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the readable storage medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, radio frequency, etc., or any suitable combination of the above.

[0108] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and the like, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device via any type of network, including a local area network or a wide area network, or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0109] The processor may load and execute one or more instructions stored in a computer-readable storage medium to implement the corresponding steps of the method for detecting and recovering false load data of a new energy power system in the above embodiment. The processor may load and execute the following steps: Based on the realistic constraints of the attacker's limited resources, the attack behavior of the load data is modeled to obtain the attack model; when the power system data is monitored to be abnormal, the constraints of the attack model are converted into mathematical decoupling conditions through the matrix decomposition algorithm to obtain the mathematical model; the GoDec algorithm is used to decompose the obtained mathematical model into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the restored load matrix is ​​obtained; after multiple update iterations, the restored load data and the identified attack matrix are obtained, and the error is evaluated; a compact mixed integer linear programming model is used to perform unit combination optimization decision on the restored load data, and compact constraints are added to obtain the unit combination decision result under the injection of false load information.

[0110] The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may include, but are not limited to, general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic units, data processing logic units based on quantum computing, and the like.

[0111] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0112] In this part, the proposed GoDec algorithm is verified through numerical simulation.

[0113] The three areas of assessment are as follows: 1. Load matrix recovery error; 2. Iteration duration; 3. Impact on unit combination decision-making.

[0114] All tests are conducted on the IEEE118 system, and the load forecast data contains minimal Gaussian noise. Four attack methods are designed to be carried out in the range of Attack: (1) Attack 1 Increase load: Prioritize attacking load peaks, implementing attacks ranging from 0% to +50% of the original data; (2) Attack2 Reduce load: Prioritize attacking load valleys, implementing an attack from -50% to 0% of the original data; (3) Attack3 Increase peak-valley difference: prioritize attacking peak values ​​(valley values), and implement attacks from 0% to +50% (-50% to 0%) of the original data; (4) Attack4 Reduce the difference between peaks and valleys: prioritize attacking peaks (valleys) and implement an attack of -50%~0%-(0%~+50%) of the original data.

[0115] The initial value is set to: , , , , , , , ; Total number of attack elements , For attack strength.

[0116] 1) Load matrix recovery error and iteration time.

[0117] Table 1 Recovery matrix error table (%)

[0118] As can be seen from Table 1, the GoDec algorithm has a high numerical error ( ) and positioning error ( ) outperformed other methods in both detection accuracy and accuracy. This is primarily because the ALM and RALM algorithms do not explicitly account for noise in the data, resulting in some noise being misclassified as attacks or minor attacks going undetected. For example, under Attack3, the proposed method reduced the numerical error by 54.7% compared to the post-attack load matrix. The DNDP method improves on the original ALM method by incorporating noise constraints, significantly improving detection accuracy. However, as shown in Table 2, this improvement comes at the expense of a significant increase in computational time, highlighting the effectiveness of the BRP-based implementation in reducing computational time.

[0119] Table 2 Iteration duration (s)

[0120] 2) Analysis of the impact on unit commitment decision-making In large-scale power systems, unit commitment decisions rely heavily on accurate total load forecasts at each time step.

[0121] In order to quantify the effect of load distortion, we define Relative distortion error ,in is the load after distortion or restoration, It is a real load. Figure 2 Boxplots of the load distortion and recovery error over time are presented.

[0122] The center line of each box represents the median, and the boxes themselves encompass the interquartile range, indicating that 50% of the data fall within that interval.

[0123] exist Figure 2 The box plot directly presents the distribution characteristics of load distortion and recovery errors in each time period, while the normal distribution curve provides additional information on the overall distribution of the data. In the box plot, the center line of the box represents the median, and the box range covers the interquartile range, which means that 50% of the data falls within this interval. Points outside the interval are potential outliers and are usually regarded as extreme data. The comparison of the results shows that the error range of the distorted load data under the original attack is wide, and the median deviates significantly from 0, indicating that the attack caused significant and unstable distortion. In contrast, the load data recovered by the GoDec algorithm has a significantly narrowed box, the median approaches 0, and the extreme value (maximum error) is greatly reduced. Compared with other recovery methods, the GoDec algorithm shows higher accuracy in load data recovery. After using the GoDec algorithm to restore the distorted load data, the specific values ​​of the maximum error are as follows: Table 3 Comparison of maximum errors at each moment (%)

[0124] These results strongly demonstrate that the GoDec algorithm significantly improves recovery accuracy and effectively reduces error in all attack scenarios. This significant reduction in maximum error demonstrates the algorithm's exceptional effectiveness in mitigating the impact of load distortion and ensuring the reliability of unit commitment decisions.

[0125] The robustness of the algorithm was evaluated under varying attack intensities. As shown in Figure 3, data recovery accuracy decreases with increasing attack severity. However, the GoDec algorithm maintains stable and excellent performance, fully demonstrating its anti-interference capabilities and stability under harsh conditions.

[0126] Specifically, in Figure 3(a), as the attack intensity (Attack 1) increases, the cost of unit scheduling increases accordingly. This phenomenon is attributed to the increased operating costs of thermal power units due to the additional load caused by the attack. This cost increase essentially reflects the higher operating costs required to compensate for the impact of distorted load data. Despite the increasing attack intensity, the GoDec algorithm effectively suppressed the excessive cost increase through its resilience, demonstrating its ability to optimize system operating efficiency and reduce additional losses under attack.

[0127] Similarly, in Figure 3(b), as the attack intensity (Attack 2) increases, the total load reduction caused by it increases significantly, visually demonstrating the negative impact of load loss on power system stability. However, the GoDec algorithm significantly reduces the scale of load reduction through its efficient data recovery mechanism, maintaining a high level of power system reliability even under high-intensity attack scenarios. These analysis results further verify the GoDec algorithm's excellent robustness in resisting data distortion interference, reducing economic losses, and ensuring stable system operation.

[0128] In summary, the present invention provides a method and system for detecting and recovering false load data in a new energy power system. This method solves the problem of false load data detection and recovery through attack behavior modeling, matrix decomposition, and the GoDec algorithm, significantly improving the safety and economy of the new energy power system. The GoDec algorithm outperforms traditional methods in both numerical error and position error, reducing the recovery error by 54.7% and keeping the maximum error within 2.07%. The matrix rank and sparsity are dynamically adjusted, shortening the calculation time to 0.35-0.49 seconds, which is 28 times more efficient than the DNDP algorithm. The compact mixed integer linear programming model reduces the cost of unit combination and load loss, and improves stability under high-proportion new energy grid connection. It maintains stable performance in scenarios such as peak tampering and valley attacks, and enhances the system's anti-interference capability. It provides reliable data security for the new energy power system, reduces operating costs, and promotes the sustainable development of smart grids.

[0129] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0130] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0131] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the present invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0132] In the embodiments provided by the present invention, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical functional division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, and can be electrical, mechanical, or other forms.

[0133] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0134] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0135] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned various method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0136] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices, and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0137] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0139] The above content is only for explaining the technical idea of ​​the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.

Claims

1. A method for detecting and recovering false load data in a new energy power system, characterized in that: The following steps are involved: S1. Based on the realistic constraints of the attacker’s limited resources, the attack behavior is modeled on the load data to obtain the attack model. S2. When abnormal power system data is detected, the constraints of the attack model obtained in step S1 are converted into mathematical decoupling conditions through a matrix decomposition algorithm to obtain a mathematical model; S3. Use the GoDec algorithm to decompose the mathematical model obtained in step S2 into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the recovered load matrix is ​​obtained. S4. After multiple update iterations, the recovered load data and the identified attack matrix are obtained, and the error is evaluated; S5. Use a compact mixed integer linear programming model to perform unit commitment optimization decision on the load data recovered in step S4, and add compact constraints to obtain the unit commitment decision result under the injection of false load information.

2. The method for detecting and recovering false load data in a new energy power system according to claim 1, characterized in that: In step S1, attack behavior modeling includes: Local damage constraint: the attacker can only target a limited set of nodes Implement data tampering, and its attack matrix satisfies the sparsity condition , Represents the actual value of the total elements of the sparse attack matrix; Randomness constraint: The attacker's attack penetration rate follows a Poisson distribution ; Rational attack constraints: attackers prioritize important load nodes and critical time periods as attack targets.

3. The method for detecting and recovering false load data in a new energy power system according to claim 1, characterized in that: In step S2, the matrix decomposition algorithm adopts robust matrix decomposition technology.

4. The method for detecting and recovering false load data in a new energy power system according to claim 3, characterized in that: Assume that the power grid includes Nodes in The original load matrix of the period , and has low-rank characteristics, when subjected to false data injection attacks, given the observation load matrix , decoupled by robust matrix decomposition technology: The low-rank matrix decomposition problem is transformed into a non-convex optimization problem: in, is the restored low-rank load matrix, represents the rank of the low-rank loading matrix, To satisfy The sparse attack matrix, Represents the estimated value of the total elements of the sparse attack matrix.

5. The method for detecting and recovering false load data in a new energy power system according to claim 1, characterized in that: In step S3, the GoDec algorithm adopts an alternating direction optimization strategy and dynamically adjusts the matrix rank and sparsity.

6. The method for detecting and recovering false load data in a new energy power system according to claim 5, characterized in that: The GoDec algorithm transforms the problem into: The corresponding optimization problem is: in, represents noise, represents the number of nonzero entries in the matrix, represents the observation load matrix, is the restored low-rank load matrix, To satisfy The sparse attack matrix, represents the rank of the matrix, represents the estimated value of the rank of the low-rank matrix, Represents the estimated value of the total elements of the sparse attack matrix.

7. The method for detecting and recovering false load data in a new energy power system according to claim 1, characterized in that: The recovery error in step S4 includes numerical error and position error, which can be calculated as follows: in, and They are the attack position of the identified attack matrix and the actual attack matrix position, is the restored low-rank load matrix, is the original load matrix, is the number of selected grid nodes, The selected time period.

8. The method for detecting and recovering false load data in a new energy power system according to claim 1, characterized in that: In step S5, the objective function of the compact mixed integer linear programming model is to minimize the sum of the power generation cost and the energy curtailment penalty. The remaining constraints include the upper and lower limits of the unit output, the thermal power unit ramping constraints, the thermal power unit start and stop constraints, and the power grid balance constraints.

9. The method for detecting and recovering false load data in a new energy power system according to claim 8, characterized in that: The objective function is expressed as: in, Indicates thermal power unit In the period The cost of electricity generation is higher than the minimum output; is the corresponding segment cost coefficient; For the crew In the period The start-stop state binary variable; A collection representing the startup types of the unit; Indicates the unit In startup mode Start-up costs; is the corresponding startup state binary variable; is the penalty coefficient for renewable energy curtailment; and Represents renewable energy units In the period Maximum output and actual output; The compact constraints added are: in, represents the shutdown state of the thermal generator at a point in time, Indicates the starting status of the thermal generator at a point in time, Shut down the unit The time after which the device starts offline.

10. A new energy power system false load data detection and recovery system, characterized in that: include: The construction module models the attack behavior of the load data based on the realistic constraints of the attacker's limited resources to obtain the attack model; The conversion module, when detecting abnormal power system data, converts the constraints of the attack model into mathematical decoupling conditions through a matrix decomposition algorithm to obtain a mathematical model; The iterative module uses the GoDec algorithm to decompose the obtained mathematical model into two sub-problems: low-rank matrix estimation and sparse matrix update. After iterative solution, the attack amplitude and position matrix are identified, and the recovered load matrix is ​​obtained; The calculation module obtains the restored load data and the identified attack matrix after multiple update iterations and evaluates the error; The recovery module uses a compact mixed integer linear programming model to make unit commitment optimization decisions based on the restored load data, and adds compact constraints to obtain the unit commitment decision results under the injection of false load information.