Information physical system cascading failure safety assessment detection method based on optimization filter
By using an improved method of optimization filters and Kalman filters in cyber-physical systems, malicious data can be identified and eliminated, overcoming the shortcomings of traditional methods in detecting cascading faults and improving the accuracy and reliability of power system security assessment and detection.
Patent Information
- Application Number
- CN202511372776.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-24
- Publication Date
- 2025-11-11
AI Technical Summary
Traditional security assessment methods are insufficient to meet the real-time and accuracy requirements of cyber-physical systems (CPS) in the face of complex network attacks, especially in detecting cascading failures, which could lead to the risk of power system collapse.
An optimization filter-based approach is adopted to analyze the cascading failures of the CPS system through dynamic complex network analysis. An improved Kalman filter is constructed for data optimization processing, the interaction points between the physical layer and the information layer are identified, a heterogeneous dependency matrix is established, malicious data is eliminated, and the detection specificity is improved.
It improves the accuracy and reliability of security assessment and detection in CPS systems, reduces false alarm rates, enhances the comprehensiveness and adaptability of network security protection, and lowers the technical threshold for users.
Smart Images

Figure CN120934896A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically relating to a security assessment and detection method for cascading failures in cyber-physical systems based on optimized filters. Background Technology
[0002] With the increasing digitalization and intelligence of power systems, cybersecurity has become a key factor affecting the stable operation of power systems. Traditional security assessment methods often fail to meet the requirements of real-time performance and accuracy when facing complex cyberattacks.
[0003] Cyber-physical systems (CPS), as complex systems that deeply integrate computing, communication, and control technologies, are widely used in key areas such as smart grids, industrial automation, and intelligent transportation. However, with the continuous expansion of system scale and the deepening interaction and coupling of heterogeneous components within the system, CPS faces increasingly severe security challenges, especially the risk of a chain reaction triggered by a local failure, ultimately leading to system-wide collapse.
[0004] Traditional safety assessment methods primarily rely on physical model analysis or data-driven fault detection techniques, but these often have limitations. For example, methods based on physical equations require precise modeling, but the strong nonlinearity, time-varying nature, and complexity of cyber-physical interactions in CPS make modeling difficult and unable to cover all fault scenarios. In data-driven approaches, while machine learning algorithms can uncover fault characteristics, they are sensitive to noise and adversarial attacks. Regarding detection, most existing methods target network attacks or equipment failures, neglecting the dynamic impact of data packet loss on the physical system, resulting in insufficient ability to detect early cascading failures. This can lead to power system collapse and pose a significant threat to the power system. Summary of the Invention
[0005] To address the aforementioned technical problems, this invention provides a cyber-physical system (CPS) cascading failure security assessment and detection method based on optimized filters. By performing cascading failure analysis on the CPS system through dynamic complex networks, the accuracy of the analysis is enhanced, thereby improving the reliability of the CPS system.
[0006] The present invention discloses a cyber-physical system cascading failure security assessment and detection method based on optimized filters, comprising the following steps:
[0007] Step 1: Analyze the CPS architecture, including the physical layer and the information layer. Model the communication nodes, communication methods, and communication networks between the physical layer and the information layer. Collect power grid data through sensors and construct data flow models for data uploading and downloading respectively.
[0008] Step 2: Monitor the data stream information in real time through the observer, establish a security assessment model, and construct an optimized processing of the transmitted data based on the improved Kalman filter;
[0009] Step 3: Analyze the data transmission volume of the optimized data to determine whether it has been attacked during data transmission. Based on the optimized Kalman filter, achieve specific detection.
[0010] Furthermore, step 1 specifically includes:
[0011] Step 101: Analyze the characteristics of the CPS system and the characteristics of layered modeling of the CPS architecture;
[0012] Step 102: Model the physical layer based on the architecture of CPS, taking into account the power equipment, sensors, communication nodes, communication methods and data flow characteristics.
[0013] Step 103: Model the communication nodes and network, use cross-domain coupling analysis to identify the interaction points between the physical layer and the information layer, establish a heterogeneous dependency matrix, and quantify the coupling strength.
[0014] Step 104: For data flow modeling, a data upload and download model is adopted. First, data is acquired by the sensor at a sampling rate f. s Data is collected, then compressed through local aggregation, and finally transmitted from the sensors to the cloud.
[0015] Step 105: After the data is uploaded, it reaches the cloud. The cloud issues control commands, and priority scheduling ensures low latency for critical commands, transmitting the data from the cloud to the actuator.
[0016] Furthermore, step 2 specifically involves:
[0017] Step 201: Based on the real-time system status data, form a multi-source heterogeneous data stream; perform time synchronization and normalization processing on the sensor data to eliminate dimensional differences; perform preliminary anomaly screening on the collected data and mark observations that may be interfered with or maliciously tampered with.
[0018] Step 202: Construct an optimized filter framework based on the improved Kalman filter, introduce a dynamic weight adjustment mechanism, and use a filter and data fusion algorithm to optimize the filter;
[0019] Step 203: By calculating the sensor observations, reduce the weight of abnormal data, or even completely eliminate malicious measurements, while retaining other sensor measurements, thereby reducing the influx of false data.
[0020] Furthermore, step 3 specifically involves:
[0021] Step 301: Through real-time data acquisition in step S1 and the removal of bad data, the data transmission volume can be continuously monitored, and a dynamic threshold range can be established by training the traffic with historical normal data.
[0022] Step 302: Calculate the deviation between the current flow rate and the dynamic threshold range. If the deviation exceeds the threshold, trigger an anomaly flag.
[0023] Step 303: Use the mean distribution to detect whether an attack has occurred. By optimizing the Kalman filter, identify a subset of sensors and perform protocol analysis on suspected attack traffic to enhance detection specificity.
[0024] The beneficial effects of this invention are as follows: The method described in this invention extracts relevant information from data streams in real time by using a data upload and download model. It does not rely on professional training of the model by specialists, such as data annotation, or extensive environmental configuration. It directly integrates the collected data, completes offline modeling and behavioral analysis, and inputs this data into the evaluation model for judgment. Based on the judgment results, instructions are sent. If there are significant fluctuations or anomalies in the data stream, the model removes these data. The removed data is then processed and output to the offline simulation to determine whether an attack has occurred and to identify potential threat events to the power network, thus helping to provide early warning of network security threats. Simultaneously, the judgment results after data analysis are returned to the model, continuously updating the data information and characteristics to provide data for future judgments. This invention increases the accuracy of evaluation and detection by removing malicious data, not only improving the comprehensiveness and adaptability of network security protection but also lowering the technical threshold for users. Attached Figure Description
[0025] Figure 1 This is a flowchart illustrating the method described in this invention;
[0026] Figure 2 This is a schematic diagram of the data evaluation model structure;
[0027] Figure 3 A flowchart for data evaluation;
[0028] Figure 4 A bar chart showing the advantages of this invention compared to existing technologies;
[0029] Figure 5 This invention is compared with Kalman filtering and particle filtering;
[0030] Figure 6 A comparison chart of the residuals from the three filtering methods;
[0031] Figure 7 This is a comparison chart of the residuals from the three types of filtering. Detailed Implementation
[0032] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings.
[0033] like Figure 1 As shown, the cyber-physical system cascading failure security assessment and detection method based on optimized filters according to the present invention includes the following steps:
[0034] Step 1: Analyze the CPS architecture (including the physical layer and the information layer), model the communication nodes, communication methods and communication networks between the physical layer and the information layer, collect power grid data through sensors, and construct data flow models for data uploading and downloading respectively.
[0035] Step 2: Monitor the data stream information in real time through the observer, establish a security assessment model, and construct an optimized processing of the transmitted data based on the improved Kalman filter;
[0036] Step 3: Analyze the data transmission volume of the optimized data to determine whether it has been attacked during data transmission. Based on the optimized Kalman filter, achieve specific detection.
[0037] Step 1 specifically includes:
[0038] Step 101: Analyze the characteristics of the CPS system and the characteristics of layered modeling of the CPS architecture;
[0039] Step 102: Model the physical layer based on the architecture of CPS, taking into account the power equipment, sensors, communication nodes, communication methods and data flow characteristics.
[0040] Step 103: Model the communication nodes and network, use cross-domain coupling analysis to identify the interaction points between the physical layer and the information layer, establish a heterogeneous dependency matrix, and quantify the coupling strength.
[0041] Step 104: For data flow modeling, a data upload and download model is adopted. First, data is acquired by the sensor at a sampling rate f. s Data is collected, then compressed through local aggregation, and finally transmitted from the sensors to the cloud.
[0042] Step 105: After the data is uploaded, it reaches the cloud. The cloud issues control commands, and priority scheduling ensures low latency for critical commands, transmitting the data from the cloud to the actuator.
[0043] like Figure 2The diagram illustrates the data evaluation model process. The evaluation sensors collect data from firewalls, routers, host logs, etc., and analyze and aggregate the collected data to segment the data stream. Normal data refers to data stream fluctuations within a reasonable range; abnormal data refers to data stream fluctuations exceeding a set range. Abnormal data streams are filtered out. The filtered data streams, along with the normal data streams, are input into the detection model to determine if an attack has occurred, thereby optimizing the CPS system.
[0044] The CPS architecture comprises a physical layer and an information layer. The physical layer is the foundation of CPS, responsible for sensing and controlling physical entities. Its main components include sensors, actuators, physical entities, and communication interfaces. Its functions are to collect physical environment data, execute physical operations according to instructions from the information layer, monitor or control the actual objects, and realize data transmission between sensors, actuators, and the information layer. The information layer is responsible for data processing, analysis, and decision-making. Its main components include data processing units, control algorithms, communication networks, and user interfaces. Its functions are to process and analyze sensor data, generate control instructions based on data analysis, realize data transmission between the physical layer and the information layer, and provide a human-machine interface for easy monitoring and operation.
[0045] Communication node modeling includes:
[0046] Assume the power distribution network contains M communication nodes, and the information flow generated in the communication network at a certain moment is as follows:
[0047] F ab (t)=(In ab (t),L ab (t))
[0048] In the formula, F ab (t) represents the information flow generated by the ab link at time t. ab (t) represents whether a sends a message to b at time t, L ab (t) represents the information flow F at time t. ab (t) is located in link ab.
[0049] Among them, In ab (t) is a random number between 0 and 1, as shown in the formula below:
[0050] In ab (t)=1,X<ω
[0051] In ab (t)=0,X≥ω
[0052] In the formula, X is a randomly generated number in the interval [0, 1], and ω represents the probability of sending; when X is less than ω, the conditions for information flow generation are met, then Inab (t) = 1; conversely, when X is greater than or equal to ω, the conditions for information flow generation are not met, then In ab (t) = 0.
[0053] The amount of information in the buffer of a communication node at a certain moment can be calculated based on the information flow, as shown below:
[0054]
[0055] In the formula, M a (t) represents the amount of information in the communication node's buffer at this time; M a (t-1) represents the number of information streams in the buffer of this communication node at the previous time step; N a (t) represents the number of communication node routing information at this moment; ∑H ka (t) represents the sum of information from node k to node a at this moment, and its value is determined by L. ka The value of (t) is determined, and the specific calculation is shown in the following formula:
[0056] H ka (t)=1,L ka (t)=a
[0057] H ka (t)=0,L ka (t)≠a
[0058] L ka (t) indicates whether the information flow has reached node a, that is, when the information flow on link ka reaches node a, H ka (t) = 1, otherwise H ka (t) = 0.
[0059] In addition, to simulate actual packet loss in communication nodes, the buffer capacity of communication node a is defined as E. a When M a (t)<E a When M, no packet loss will occur; when M a (t)=E a When M..., packet loss will occur; when M... a (t)>E a When this occurs, it is considered that a packet loss has occurred.
[0060] A communication node model is established, and a unified formal modeling method using tuples is adopted, as shown below:
[0061] Y a =[M a (r),E a (r)]
[0062] In the formula, r represents the current time, and Ma (r) represents the current queue length of the communication node, reflecting the instantaneous load and determining whether packets are lost; E a (r) represents the maximum queue length of the communication node, which determines the buffering capacity and affects congestion control.
[0063] A unified formal model is used for the communication method (fiber optic communication):
[0064] C d =[T d ,P d ,P D ,L ab (t)]
[0065] In the formula, C d For the communication performance of the communication method, T d P is the delay of the communication channel. d P is the probability of channel interruption. D M is the probability of channel transmission error. d (t) represents the position of the information flow in the channel;
[0066] P D =1, X>δ
[0067] P D =0, X≤δ
[0068] In the formula, X is a random number between [0, 1] that changes over time, and δ is the threshold for channel transmission interruption; P D =1 indicates that the channel transmission is completely unreliable, and all transmitted data is corrupted; P D =0 indicates that the channel transmission is completely reliable and there are no transmission errors.
[0069] The latency of fiber optic communication is approximately 5 μs / km; therefore, Td = 5 s (μs), where s is the fiber optic channel length in km. Fiber optic communication has high reliability; excluding human error, the probability of channel interruption can be approximated as 0, i.e., Pd = 0. The bit error rate of fiber optic communication should be less than 10e-9; therefore, δ = 10e-9.
[0070] Communication network modeling:
[0071] The communication node model and communication method model established above can be used to model a communication network consisting of M communication nodes and their branches using a unified formal matrix, as shown below. This matrix describes the communication network composed of communication nodes and communication methods:
[0072]
[0073] In the formula, Y on the diagonal represents a communication node, and C off-diagonal represents the communication channel; when communication node a is connected to 1 through a certain communication method, C a1 This represents the performance of the communication method; conversely, when there is no communication method connected, C a1 =0.
[0074] Modeling is performed on the uploaded and distributed data, as detailed below.
[0075] Building an upload data model:
[0076] Considering whether remote terminal units (RTUs) are installed on power grid components, establish a CPS correlation matrix J:
[0077]
[0078] In the formula: J aa =[j aa ,j ab ,...j am And J aa ∈{0,1},j aa j ab These indicate whether remote terminal equipment is installed at node a and on the line with node a as the high-voltage side; and The values represent whether remote terminal equipment is installed on the high-voltage side of the line, respectively. When the value is 1, it means that remote terminal equipment is installed; when the value is 0, it means that remote terminal equipment is not installed. The selection range of nodes a, b, n1, m, etc. is between [1, M] and they are all different.
[0079] Constructing the power grid information matrix L:
[0080]
[0081] In the formula: L aa =[O aa O ab ,...O am ], O aa =[P aa Q aa ,I aa ,θ aa ,T aa ] represents node information, O aa This represents the active power P, reactive power Q, effective current I, phase angle θ, and switching state T of node a; O ab =[P ab Q ab ,I ab ,θab ,T ab This section contains node information from node a (high-voltage side) to node b, including active power P, reactive power Q, RMS current I, phase angle θ, and switching state T, with the voltage at node b higher than that at node m. am =[P am Q am ,I am ,θ am ,T am [This contains node information from node a (high voltage side) to node m, including active power P, reactive power Q, effective current I, phase angle θ, and switching state T.] The node information is represented by P, Q, I, phase angle θ, and T, respectively, which represent the active power P, reactive power Q, effective current I, phase angle θ, and switching state T of node n1. The node information from node n1 (high voltage side) to node b includes active power P, reactive power Q, effective current I, phase angle θ, and switching state T, with the voltage at node b being higher than that at node m. The node information from node n1 (high voltage side) to node m includes active power P, reactive power Q, effective current I, phase angle θ, and switching state T.
[0082] Sensors collect data from power grid components and construct a sensor data acquisition matrix A. g =LLJ, which means multiplying the corresponding elements of the power grid information matrix L and the correlation matrix J; the data collected by the sensor is uploaded through the A / D converter and the router. Considering the working status of the A / D converter and the router, an A / D converter upload status matrix W is established. u ∈R n×n , 1 indicates a normal state, where The operating status of the A / D converter from node a to node b; the router uploads the state matrix M. u ∈R n ×n , 1 indicates a normal state, where The working state of the router from node a to node b; the front-end receiver matrix Y∈R n×n R n×n Represents an n×n matrix space consisting of real numbers; u represents the status of uploaded data;
[0083]
[0084] In the formula: Y 11 Y aa Y nn These are all measurement data received by the front-end processor.
[0085] During the process of preprocessing and uploading data, the front-end machine establishes an additional matrix E. e ∈R n×n The data preprocessing results are stored and sent to the decision analysis unit, serving as the behavioral criteria for the decision analysis unit, characterizing the automatic control capability of the power information system, and establishing a data preprocessing matrix B. b ;
[0086]
[0087] In the formula: the diagonal and off-diagonal elements are the preprocessed data of power grid nodes and line information, respectively; the decision control unit of the intelligent decision-making platform (used to coordinate the workflow of various parts of the system or control decision execution) is based on E e The system reacts accordingly to the data; if everything is normal, it operates normally and improves efficiency; if minor fluctuations occur, it makes fine adjustments or issues warnings; if a serious fault occurs, it coordinates with protection devices as quickly as possible to isolate the fault, executes emergency controls, and does everything possible to prevent the system from crashing.
[0088] B b =[B1..B n ] T =[YE e ]
[0089] Establish the decision reception matrix F∈R n×n l represents the number of front-end processors;
[0090]
[0091] In the formula: F gg =1,F ll =B l ;F eg =0,F ge This indicates that the preprocessing information of the front-end machine g is uploaded by the front-end machine e, F ge =B g =[Y gg E gi ], where E gi This represents the preprocessing information for node g and the lines with g as the high-voltage side.
[0092] Build and distribute the data model:
[0093] The decision analysis unit of the intelligent decision-making platform is used for data analysis operations such as modeling, prediction, and risk assessment. Upon receiving uploaded data, it analyzes the data, issues control commands, and generates a decision unit (used to execute decision-making functions) that distributes matrix H. s ∈R n×n ;
[0094]
[0095] In the formula: H 11 =[P 11 Q 11 H represents the active and reactive power adjustment of node 1 in the power grid. 11 >0 indicates an increase in node injection power, H 11 <0 indicates a decrease, H 11 =0 indicates no adjustment, H 1n =0 indicates that the circuit breaker is open, H 1n =0 indicates that the circuit breaker is closed.
[0096] Control information flows into the front-end network, defining the front-end data distribution matrix X. s ∈R n×n .
[0097]
[0098] In the formula: X gg =1,X ll =[X ii X ie... X oi ], X ie The information pertains to the line where node i is the high-voltage side and the voltage at node e is higher than that at node o; X ge =0,X eg =[H gg H gi This indicates that the front-end machine e will send the control information received from node g and the line to the front-end machine g.
[0099] Control commands reach the actuators via routers and A / D converters, and the actuators execute the control commands; the router establishes the state matrix C. d The A / D converter sends out the state matrix W d and execute the receive matrix G∈R n×n ;
[0100] C d =W d
[0101]
[0102] Data evaluation process such as Figure 3As shown, the process begins with data selection, where suitable data is chosen for acquisition. This data is then input into an evaluation sensor for assessment, based on the input data stream. If the data stream is stable and without anomalies, it is considered normal data and is directly output to the detection model. If fluctuations or anomalies are detected, the data is considered abnormal and is filtered out before being output to the detection model. Next, attack detection is performed. Based on the evaluated data, it is determined whether an attack has occurred. If no attack has occurred, the system continues to operate normally. If an attack has occurred, an early warning is issued based on the real-time detection results.
[0103] In step 2, by using sensor observations to learn the optimal filter over time, malicious sensor observations are filtered out during data stream transmission, while other sensor measurements are retained. This reduces the influx of false data and facilitates a more accurate assessment of the stability of data transmission.
[0104] Step 201: Based on the real-time system status data, form a multi-source heterogeneous data stream; perform time synchronization and normalization processing on the sensor data to eliminate dimensional differences; perform preliminary anomaly screening on the collected data and mark observations that may be interfered with or maliciously tampered with.
[0105] Step 202: Construct an optimized filter framework based on the improved Kalman filter, introduce a dynamic weight adjustment mechanism, and use a filter and data fusion algorithm to optimize the filter;
[0106] Step 203: By calculating the sensor observations, reduce the weight of abnormal data, or even completely eliminate malicious measurements, while retaining other sensor measurements, thereby reducing the influx of false data.
[0107] The specific implementation steps are as follows:
[0108] In order to assess the security status of the system, a security evaluator is modeled:
[0109]
[0110] In the formula: k t Represents the Kalman gain matrix at time t; The upper limit is the value taken as T approaches infinity, where T represents the upper limit of time used to calculate long-term averages, and t represents time; N represents the total number of sensors, 2. N The power set of the sensor set, i.e., the set of all possible subsets, is 2. N There are n elements; B represents a subset of size n0 (0 < n0 < N), |B| represents the size of subset B; Bc is the complement of B, which contains all sensors not in B; The state estimate is calculated using sensor measurements from subset B; The state estimate is calculated using sensor measurements from subset Bc; P t Let be the error covariance matrix, representing the gain matrix k at time t without attack. t Estimation error covariance for sequence; T r () represents the trace of the matrix, which is the sum of the diagonal elements; This represents the maximum allowable long-term average error variance; E is the objective function used to obtain estimates of set B and its complement Bc. and The unusual differences between them.
[0111] estimated value The calculation is as follows:
[0112]
[0113] In the formula: τ=0,1,2,...t-1; Let the result obtained in the last step of the recursive calculation be equal to... A is the state transition matrix, used to describe how the state evolves over time; C is the observation matrix, mapping the state to the sensor measurement space; y(τ+1) represents the sensor measurement vector at time τ+1; K t,B With k t The structures are the same, but the column corresponding to Bc is set to zero; K t,B The Kalman gain is used to balance the predicted and observed data in state estimation.
[0114] Set a parameter And a finitely large number l0 > 0,
[0115]
[0116] In the formula: B=n0,λ max (A-KTCA) is the largest eigenvalue of λ(A-KTCA); K is the set of gain matrices, q and m are the matrix dimensions, and λ max () represents the largest eigenvalue of the matrix; K B With K Bc Let be the gain matrix under the constraints of subsets B and Bc.
[0117] Consider a sequence {K} n The convergence of n≥1 to K * Since the spectral radius is a continuous function of the independent variable matrix, and [δ0, 1-δ0] is a closed set, it can be considered that...
[0118]
[0119] That is, K *Since ∈κ, κ is also a closed set. Furthermore, κ is clearly a bounded set; therefore, κ is a metric space R. q ×m A compact subset of K with Frobenius norm distance; * It is a limit point. We define κ and prove that κ is a closed set containing all gain matrices K that satisfy a specific stability condition. This provides a guarantee for the safety assessment model. By controlling κ, we can ensure that the eigenvalue magnitude is always limited to a certain range no matter which node fails, thus improving the robustness of the safety assessment model. At the same time, the closed set κ guarantees the convergence of the computation and the existence of the solution.
[0120] set up and This indicates that a Kalman filter is used to apply a constant gain matrix to the observed sequence {y(τ): 1≤τ≤t} over the time interval τ=0,1,2,...t. and The estimated value obtained; The formula for calculating τ = 0, 1, 2, ..., t-1 is shown below, using the following recursive method:
[0121]
[0122] Reduced computation and The complexity is reduced, and the computational complexity per time slot is also reduced relative to the number of sensors N.
[0123] Using an iterative algorithm, The estimated value, unconstrained by any complex constraints, is calculated based on the above iterations. To ensure the iterations continue and the algorithm's effectiveness is guaranteed, the value is mapped back to the constraint set, continuously moving closer to the optimization objective. The mathematical expression for projection onto set K is as follows:
[0124]
[0125] st||λ max (A-KTCA)||∈[δ0,1-δ0]
[0126] ||λ max (AK B TCA)||∈[δ0,1-δ0]
[0127] ||λ max (AK Bc TCA)||∈[δ0,1-δ0]
[0128] |B|=n0
[0129] In the formula: ||.|| F It is the F-norm, ensuring that only ||λ max (AK t+1 TCA)||∈[δ0,1-δ0]; if it occurs let (Projected to [-l,l) q×m Multiply by a constant, such that
[0130] The results produced by this method are relatively stable. By evaluating the data stream flow, it can remove some malicious data detected by malicious sensors, thereby improving the stability and accuracy of the evaluation. Removing bad data helps improve the accuracy of subsequent detection steps.
[0131] In step 3, by analyzing whether there is a sudden abnormal increase or decrease in data transmission volume, it is determined whether the data stream transmission process has been attacked. When the data transmission volume changes abnormally, the detector reacts immediately and optimizes the detector to reduce the false alarm rate. Specifically:
[0132] Step 301: Through real-time data acquisition in step S1 and the removal of bad data, the data transmission volume can be continuously monitored, and a dynamic threshold range can be established by training the traffic with historical normal data.
[0133] Step 302: Calculate the deviation between the current flow rate and the dynamic threshold range. If the deviation exceeds the threshold, trigger an anomaly flag.
[0134] Step 303: Use the mean distribution to detect whether an attack has occurred. By optimizing the Kalman filter, identify a subset of sensors and perform protocol analysis on suspected attack traffic to enhance detection specificity.
[0135] The detection problem can be mathematically represented as a hypothesis testing problem for the following two assumptions.
[0136] Assumption 1: No attack:
[0137] Assumption 2: Under attack: e i ≠0, i∈N, t∈{1,2,3...}
[0138] In the formula, For sensor i x The attack signal at time t; N is the set of all sensors; i x t represents the sensor number; t represents a continuous time point.
[0139] use This indicates that the covariance matrix of the optimal Kalman filter using sensor observations, given only a subset B, is in steady state when there is no attack. Clearly, without attacks, in a steady state, e B,Bc (t)≈N(0,P B,Bc In the formula, e B,Bc (t) is the anomaly detection signal, used to describe the deviation between the two sets of estimated values; P B,Bc When there is no attack, e B,Bc The steady-state covariance matrix of (t).
[0140] Due to error and It is a Gaussian distribution with zero mean, therefore it can be determined by checking e. B,Bc (t) Whether it comes from distribution N(0, P B,Bc To detect attacks, we have B, where B is an arbitrary subset of size n0. The covariance matrix P... B,Bc It can be calculated in advance through a simulation process.
[0141] Set a positive integer J. y The observation window and the threshold η>0 are used for attack detection.
[0142] Offline simulation {X(τ)} τ≥0 During the simulation, through appropriate adjustments, for each sensor subset B of size n0, the optimal Kalman filter is calculated. and Therefore, the calculation is as follows:
[0143]
[0144] When t = 1, 2, 3, ..., calculate using the optimal solution and Perform Kalman filtering on each sensor subset B of size n0; for each sensor subset B of size n0, calculate... {X(τ)} τ≥0 The real state sequence generated for offline simulation is the state estimation sequence generated by filtering using only a subset B of sensor data; An estimated sequence generated using sensor data from the complement Bc of B; P -1 B,Bc It is a standardized deviation metric used to determine whether a threshold has been exceeded and whether an attack has occurred.
[0145] An attack has occurred if the following conditions are met:
[0146]
[0147] If an attack occurs, the following maximized subset will be identified as the attacked subset of sensors:
[0148]
[0149] Sensors are used to detect attacks and prevent cascading failures caused by malfunctions.
[0150] In this embodiment, Python 3.x is used for programming, primarily relying on libraries such as NumPy, Matplotlib, Seaborn, FilterPy, and Scikit-learn for numerical computation, matrix computation, data visualization, Kalman filtering implementation, and performance evaluation metric calculation. A two-dimensional state space is constructed, with the system configured to observe the states from five sensors. A linear dynamic system model is used, along with a state transition matrix and a random matrix for the observation matrix. An attack is injected between time steps 200 and 400, randomly selecting one sensor to inject Gaussian noise with a mean of 5.0. The attack signal is superimposed with random noise of a standard deviation of 0.5 to simulate the uncertainty in a real attack. 500 time steps are simulated, with process noise set to 0.01 and observation noise set to 0.1. Then, different methods are compared.
[0151] Assuming the sensor set {1,2,...,n0} is attacked, tests are conducted on three scenarios: unoptimized, optimized evaluation algorithm, optimized evaluation algorithm, and detection algorithm. When an attack occurs, the proportion of time slots in which the detectors are triggered is defined as the detection probability; when no attack occurs, the proportion of time slots in which the detectors are triggered is defined as the false alarm probability. In this numerical example, the observation window for all detectors is fixed at J. y =10. The results show that with the optimization of the evaluation and detection algorithms, the actual attack detection rate increased from 40% to 90%, and the false positive rate decreased from 30% to 5%, which greatly increased the probability of attack detection and reduced the false positive rate.
[0152] like Figure 4 As shown in the comparison data, the security evaluator model can not only significantly improve the threat detection rate, but also effectively reduce the false alarm rate. Especially when facing unknown attacks, complex attack chains and dynamic environments, the evaluation and detection model has shown strong advantages. In traditional security operations centers and environments without security operations centers, although the detection capability has been improved, the false alarm rate is high and it is easily constrained by the evolution of attack types.
[0153] like Figure 5As shown, the system is attacked when the number of steps ranges from 0 to 500. The system is attacked between 200 and 400 steps. The figure shows that in state component 1, the evaluation values of Kalman filtering and particle filtering are significantly higher than the actual state, while the optimized filtering of this invention remains close to the actual state. Under attack, it maintains a stable state, eliminates malicious data, and ensures the reliability of the evaluation. In state component 2, under attack, all state estimates are not significantly different from the actual state, demonstrating the credibility of this filtering method.
[0154] like Figure 6 The figure shows the residual norm plots for three different filters when facing attacks. Figure 6 As can be seen, when attacked, the residuals of Kalman filter and particle filter increase significantly, exceeding the abnormal threshold. At step 200, the system is suddenly attacked, the residual value suddenly increases, and exceeds the abnormal threshold by a large margin, which leads to inaccurate evaluation. At step 400, the attack stops, the residual norm returns to below the threshold, and the system returns to a stable state. The optimized filtering method of this invention exceeds the threshold when attacked, but it quickly decreases. In steps 200-400, there are very few cases where the abnormal threshold is exceeded.
[0155] like Figure 7 As shown in the figure, the specific comparison chart of the three filter residuals is presented. It can be seen from the figure that when attacked, the Kalman filter and particle filter have a larger response, while the optimized filter has a weaker response than the traditional filter, which can better cope with the attack and reduce the change of residual value.
[0156] The above description is merely a preferred embodiment of the present invention and is not intended to further limit the present invention. All equivalent changes made based on the description and drawings of the present invention are within the protection scope of the present invention.
Claims
1. A method for security assessment and detection of cascading failures in a cyber-physical system based on optimized filters, comprising the following steps: Step 1: Analyze the CPS architecture, including the physical layer and the information layer. Model the communication nodes, communication methods, and communication networks between the physical layer and the information layer. Collect power grid data through sensors and construct data flow models for data uploading and downloading respectively. Step 2: Monitor the data stream information in real time through the observer, establish a security assessment model, and construct an optimized processing of the transmitted data based on the improved Kalman filter; Step 3: Analyze the data transmission volume of the optimized data to determine whether it has been attacked during data transmission. Based on the optimized Kalman filter, achieve specific detection.
2. The cyber-physical system cascading failure safety assessment and detection method based on optimized filters according to claim 1, characterized in that, Step 1 involves modeling the communication nodes, including: Assuming the power distribution network contains M communication nodes, the information flow generated in the communication network at a certain moment is as follows: F ab (t)=(In ab (t),L ab (t)) In the formula, F ab (t) represents the information flow generated by the ab link at time t. ab (t) represents whether a sends a message to b at time t, L ab (t) represents the information flow F at time t. ab (t) is located in link ab; Among them, In ab (t) is a random number between 0 and 1, as shown in the formula below: In ab (t)=1,X<ω In ab (t)=0,X≥ω In the formula, X is a randomly generated number in the interval [0, 1], and ω represents the probability of sending; when X is less than ω, the conditions for information flow generation are met, then In ab (t) = 1; conversely, when X is greater than or equal to ω, the conditions for information flow generation are not met, then In ab (t) = 0; The amount of information in the buffer of a communication node at a certain moment is calculated based on the information flow, as shown below: In the formula, M a (t) represents the amount of information in the communication node's buffer at this time; M a (t-1) represents the number of information streams in the buffer of this communication node at the previous time step; N a (t) represents the number of communication node routing information at this moment; ∑H ka (t) represents the sum of information from node k to node a at this moment, and its value is determined by L. ka The value of (t) is determined, and the specific calculation is shown in the following formula: H ka (t)=1,L ka (t)=a H ka (t)=0,L ka (t)≠a L ka (t) indicates whether the information flow has reached node a, that is, when the information flow on link ka reaches node a, H ka (t) = 1, otherwise H ka (t) = 0; Define the buffer capacity of communication node a as E. a When M a (t)<E a When M, no packet loss will occur; when M a (t)=E a When M..., packet loss will occur; when M... a (t)>E a When this occurs, it is considered that a packet loss has occurred; Establish a communication node model and use a unified formal modeling approach based on tuples: Y a =[M a (r),E a (r)] In the formula, r represents the current time, and M a (r) represents the current queue length of the communication node, reflecting the instantaneous load and determining whether packets are lost; E a (r) represents the maximum queue length of the communication node, which determines the buffering capacity and affects congestion control.
3. The cyber-physical system cascading failure safety assessment and detection method based on optimized filters according to claim 2, characterized in that, A unified formal model is used to model the communication methods: C d =[T d ,P d ,P D ,L ab (t)] In the formula, C d For the communication performance of the communication method, T d P is the delay of the communication channel. d P is the probability of channel interruption. D L is the probability of channel transmission error. ab (t) represents the position of the information flow in the channel; P D =1,X>δ P D =0,X≤δ In the formula, X is a random number between [0, 1] that changes over time, and δ is the threshold for channel transmission interruption; P D =1 indicates that the channel transmission is completely unreliable, and all transmitted data is corrupted; P D =0 indicates that the channel transmission is completely reliable and there are no transmission errors.
4. The cyber-physical system cascading failure security assessment and detection method based on optimized filters according to claim 1, characterized in that, In step 1, a unified formal matrix is used to model the communication network consisting of M communication nodes and their branches, as shown below: In the formula, Y on the diagonal represents a communication node, and C off-diagonal represents the communication channel; when communication node a is connected to 1 through a certain communication method, C a1 This represents the performance of the communication method; conversely, when there is no communication method connected, C a1 =0.
5. The cyber-physical system cascading failure safety assessment and detection method based on optimized filters according to claim 1, characterized in that, Modeling is performed on the uploaded and distributed data, specifically as follows: (1) Upload the data model; Considering whether remote terminal equipment is installed on power grid components, establish a CPS association matrix J: In the formula: J aa =[j aa ,j ab ,...j am And J aa ∈{0,1},j aa j ab These indicate whether remote terminal equipment is installed at node a and on the line with node a as the high-voltage side; and This indicates whether remote terminal equipment is installed on node n1 and the line with node b as the high-voltage side, respectively; when the value is 1, it indicates that remote terminal equipment is installed. When the value is 0, it indicates that no remote terminal device is installed; the nodes a, b, n1, and m are selected in the range [1, M] and are all different; Constructing the power grid information matrix L: In the formula: L aa =[O aa O ab ,...O am ], O aa =[P aa Q aa ,I aa ,θ aa ,T aa ] represents node information, O aa This represents the active power P, reactive power Q, effective current I, phase angle θ, and switching state T of node a; O ab =[P ab Q ab ,I ab ,θ ab ,T ab This section contains node information from node a (high-voltage side) to node b, including active power P, reactive power Q, RMS current I, phase angle θ, and switching state T, with the voltage at node b higher than that at node m. am =[P am Q am ,I am ,θ am ,T am [This contains node information from node a (high voltage side) to node m, including active power P, reactive power Q, effective current I, phase angle θ, and switching state T.] The node information is represented by P, Q, I, phase angle θ, and T, respectively, which represent the active power P, reactive power Q, effective current I, phase angle θ, and switching state T of node n1. The node information from node n1 (high voltage side) to node b includes active power P, reactive power Q, effective current I, phase angle θ, and switching state T, with the voltage at node b being higher than that at node m. The node information from node n1 to node m on the high-voltage side includes active power P, reactive power Q, effective current I, phase angle θ, and switching state T. Sensors collect data from power grid components and construct a sensor data acquisition matrix A. g =LLJ, which means multiplying the corresponding elements of the power grid information matrix L and the correlation matrix J; the data collected by the sensor is uploaded through the A / D converter and the router. Considering the working status of the A / D converter and the router, an A / D converter upload status matrix W is established. u ∈R n×n , 1 indicates a normal state, where The operating status of the A / D converter from node a to node b; Router Upload State Matrix M u ∈R n×n , 1 indicates a normal state, where The working state of the router from node a to node b; the front-end receiver matrix Y∈R n×n R n×n Represents an n×n matrix space consisting of real numbers; u represents the status of uploaded data; In the formula: Y 11 Y aa Y nn Measurement data received by the front-end processor; During the process of preprocessing and uploading data, the front-end machine establishes an additional matrix E. e ∈R n×n The data preprocessing results are stored and sent to the decision analysis unit, serving as the behavioral criteria for the decision analysis unit, characterizing the automatic control capability of the power information system, and establishing a data preprocessing matrix B. b ; In the formula: the diagonal and off-diagonal elements are the preprocessed data of power grid nodes and line information, respectively; B b =[B1..B n ] T =[YE e ] Establish the decision reception matrix F∈R n×n l represents the number of front-end processors; In the formula: F gg =1,F ll =B l ;F eg =0,F ge This indicates that the preprocessing information of the front-end machine g is uploaded by the front-end machine e, F ge =B g =[Y gg E gi ], where E gi This represents the preprocessing information for node g and the lines with g as the high-voltage side; (2) Distribute the data model; The decision analysis unit receives the uploaded data, analyzes it, issues control commands, and generates the decision unit's distribution matrix H. s ∈R n ×n ; In the formula: H 11 =[P 11 Q 11 H represents the active and reactive power adjustment of node 1 in the power grid. 11 >0 indicates an increase in node injection power, H 11 <0 indicates a decrease, H 11 =0 indicates no adjustment, H 1n =0 indicates that the circuit breaker is open, H 1n =0 indicates that the circuit breaker is closed; Control information flows into the front-end network, defining the front-end data distribution matrix X. s ∈R n×n ; In the formula: X gg =1,X ll =[X ii X ie... X oi ], X ie The information pertains to the line where node i is the high-voltage side and the voltage at node e is higher than that at node o; X ge =0,X eg =[H gg H gi This indicates that the front-end server e will send the control information received from node g and the line to the front-end server g. Control commands are transmitted to the actuator via the router and A / D converter, and the actuator executes the control commands. Establish router to send state matrix C d The A / D converter sends out the state matrix W d and execute the receive matrix G∈R n×n ; 6. The cyber-physical system cascading failure security assessment and detection method based on optimized filters according to claim 1, characterized in that, Step 2 is as follows: Step 201: Perform time synchronization and normalization processing on the real-time collected data, and conduct preliminary anomaly screening on the collected data to mark the observed values that have been interfered with or maliciously tampered with. Step 202: Establish a security assessment model, construct an optimized filter framework based on the improved Kalman filter, and optimize it. Step 203: By calculating the sensor observations, reduce the weight of abnormal data, eliminate malicious measurements, and retain other sensor measurements to reduce the influx of false data.
7. The cyber-physical system cascading failure safety assessment and detection method based on optimized filters according to claim 6, characterized in that, Step 2-2 specifically involves: In the formula: k t Represents the Kalman gain matrix at time t; Indicates the upper limit; t represents time; N represents the total number of sensors, 2 N The power set of the sensor set, i.e., the set of all possible subsets, is 2. N There are n elements; B represents a subset of size n0, |B| represents the size of subset B; Bc is the complement of B, containing all sensors not in B; The state estimate is calculated using sensor measurements from subset B; The state estimate is calculated using sensor measurements from subset Bc; P t Let be the error covariance matrix, representing the gain matrix k at time t without attack. t Estimation error covariance for sequence; T r () represents the trace of the matrix, which is the sum of the diagonal elements; E represents the maximum allowable long-term average error variance; E represents the objective function. The observer is updated through a ground-based calculation process of state estimation, and the estimated value is obtained. The calculation is as follows: In the formula: τ=0,1,2,...t-1; Let the result obtained in the last step of the recursive calculation be equal to... A is the state transition matrix; C is the observation matrix; y(τ+1) represents the sensor measurement vector at time τ+1; K t,B Kalman gain; Set a parameter And a finitely large number l0 > 0, κ={K∈[-l0,l0] q×m :||l max (A-KTCA)||∈[δ0,1-δ0]} ||l max (AK B TCA)||∈[δ0,1-δ0] In the formula: B=n0,λ max (A-KTCA) is the largest eigenvalue of λ(A-KTCA); K is the set of gain matrices, q and m are the matrix dimensions, and λ max () represents the largest eigenvalue of the matrix; K B With K Bc Let B be the gain matrix under the constraints of subsets B and Bc. Consider a sequence {K} n The convergence of n≥1 to K * Since the spectral radius is a continuous function of the independent variable matrix, and [δ0, 1-δ0] is a closed set, we assume that: ||l max (AK * TCA)||∈[δ0,1-δ0] set up and This indicates that a constant gain matrix is applied to the observed sequence {y(τ): 1≤τ≤t} using a Kalman filter over the time interval τ = 0, 1, 2, ..., t. and The estimated value obtained; Calculated recursively as follows: Will The mathematical expression for projection onto set K is as follows: st||λ max (A-KTCA)||∈[δ0,1-δ0] ||l max (AK B TCA)||[δ0,1-δ0] ||l max (AK Bc TCA)||∈[δ0,1-δ0] |B|=n0 In the formula: ||.|| F It is the F-norm, ensuring that only ||λ max (AK t+1 TCA)||∈[δ0,1-δ0]; if it occurs let (Projected to [-l,l) q×m Multiply by a constant, such that 8. The cyber-physical system cascading failure security assessment and detection method based on optimized filters according to claim 1, characterized in that, Step 3 specifically involves: Step 301: Based on the continuous monitoring of data transmission volume, establish a dynamic threshold range by training the traffic using historical normal data; Step 302: Calculate the deviation between the current data flow and the dynamic threshold range. If it exceeds the threshold, trigger an anomaly flag. Step 303: Use the mean distribution to detect whether an attack has occurred. By optimizing the Kalman filter, identify a subset of sensors and perform protocol analysis on suspected attack traffic to enhance detection specificity.