A 5G smart grid intrusion detection method based on federated learning
By adopting the combination of federated learning and Transformer models in the smart grid, the problems of intrusion detection delay and data privacy protection of smart grids are solved, and efficient and secure intrusion detection results are achieved.
Patent Information
- Application Number
- CN202210710073.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-22
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-06-22
AI Technical Summary
The existing smart grid intrusion detection system has shortcomings in detection delay and user data privacy protection, especially intrusions near smart meters may not be detected in time, and user data is easily leaked during transmission.
Using the 5G smart grid intrusion detection method based on federated learning, the smart meter trains a Transformer-based intrusion detection model locally and exchanges model parameters with cloud servers for collaborative training to ensure data privacy protection while performing intrusion detection locally to reduce latency.
It effectively protects the privacy of user data, reduces the latency of intrusion detection, and reduces network traffic through model aggregation, thereby improving the security and efficiency of the system.
Smart Images

Figure CN114980109B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of smart grids, and in particular to a 5G smart grid intrusion detection method based on federated learning. Background Art
[0002] With the continuous development of science and technology, people's daily life demand for electric energy and corresponding services is growing rapidly. However, due to its simple structure, the traditional power network can no longer cope with the growing service demand and power supply problems. Therefore, relevant scholars have proposed smart grids to deal with these problems. In smart grids, energy and information can flow between customers and power companies to provide various services. As a core component of smart grids, the Advanced Metering Infrastructure (AMI) is mainly composed of smart meters, two-way communication links and data centers (cloud servers). Because of the existence of a two-way communication network, AMI can not only record the data of electricity itself such as voltage and current, but also provide more services, such as remote control of household appliances, etc., truly realizing the intelligent use of electricity. However, as services and electricity consumption continue to increase, the amount of data that needs to be transmitted is also increasing. Therefore, the transmission speed and stability of the communication network are crucial to the service quality and function of the AMI system.
[0003] The fifth generation of wireless communication technology (5G) can provide a communication network with large bandwidth, high transmission speed and low communication latency, and its network slicing improves spectrum efficiency and can provide differentiated quality of service (QoS) guarantees under shared physical infrastructure. Therefore, 5G technology can meet the requirements of AMI systems for reliable, fast and highly connected communications, which makes 5G communication technology suitable as the communication basis of AMI systems, and the combination of smart grid and 5G will also become an inevitable development direction in the future.
[0004] In addition, with the increasing popularity of smart grids, attempts to tamper with electricity consumption data by attacking smart meters continue to occur, and intrusions into AMI systems may steal information, manipulate energy prices, or cause power system interruptions. Therefore, it is extremely important to ensure the security of smart grids and AMI systems. However, most existing intrusion detection is performed on cloud servers. When an intrusion occurs near a smart meter, the intrusion may not be detected in time. In addition, the server usually needs to collect a large amount of user information to train an efficient intrusion detection model. However, when collecting user data, it is easy to cause privacy leakage of user data, which has a negative impact on users.
[0005] In order to solve the above privacy issues, McMahan et al. proposed federated learning in 2016. In federated learning, the device and the cloud server only transmit the model parameters of the neural network to each other. Therefore, the cloud server will not directly obtain the local private data of the device, thus ensuring the security of data privacy. In addition, federated learning has no limit on the number of connected devices, so it can easily cover a large number of devices. Summary of the invention
[0006] The purpose of the present invention is to provide a 5G smart grid intrusion detection method based on federated learning, so that the smart meters participating in the federated learning can cooperatively train an efficient intrusion detection model only by exchanging model parameters with the cloud server. In the process of cooperative training, not only can the user's data privacy be effectively protected, but each smart meter can also use the final intrusion detection model to directly perform intrusion detection locally to reduce the delay of intrusion detection. In addition, when uploading the smart meter model, the present invention first aggregates the model once at the base station to achieve the purpose of reducing network traffic in the core network.
[0007] To achieve the above object, the technical solution of the present invention is: a 5G smart grid intrusion detection method based on federated learning, providing a system including several smart meters, 5G base stations, edge servers and cloud servers, including the following steps:
[0008] Step S1, the smart meter collects the electricity consumption data and flow information of household appliances through the home area network HANs;
[0009] Step S2: The smart meter uses the collected data to locally train a Transformer-based intrusion detection model;
[0010] Step S3: The smart meter is connected to the 5G base station and the intrusion detection model trained in step S2 is uploaded;
[0011] Step S4: After the 5G base station receives the intrusion detection model uploaded by the smart meter participating in the federated learning within its coverage area, the received intrusion detection model is aggregated at the edge server deployed near the 5G base station to obtain a cluster model;
[0012] Step S5: The 5G base station transmits the aggregated cluster model to the cloud server through the 5G core network for global aggregation; after the cloud server obtains the global model, it sends the global model to the smart meter to start a new round of training;
[0013] Step S6: Through multiple iterations of steps S2-S5, each smart meter will eventually obtain an efficient intrusion detection model, and use the efficient intrusion detection model to directly perform intrusion detection locally.
[0014] In one embodiment of the present invention, the step S1 is specifically as follows:
[0015] Household appliances transmit electricity usage data and flow information to smart meters through home area networks HANs, where the home area networks use short-range communication technologies including WI-FI or Zigbee.
[0016] In one embodiment of the present invention, step S2 is specifically as follows:
[0017] The smart meter will train a Transformer-based intrusion detection model based on local data, using the gradient update method during the training process, namely:
[0018]
[0019] in represents the Transformer-based intrusion detection model of smart meter i at the tth iteration, D i is the local dataset of smart meter i, μ is the learning rate, represents the local loss function of device i at the tth iteration, so, Represents the gradient of the loss function.
[0020] In one embodiment of the present invention, the Transformer-based intrusion detection model is specifically:
[0021] The Transformer-based intrusion detection model includes two Transformer layers and two feature extraction layers. The Transformer layer consists of a multi-head attention layer and a feedforward network, and the feature extraction layer includes a convolution layer and a pooling layer. Assume that (x, y) is a sample in the original dataset, where y is the label of the current sample and x is the input feature of the current sample. The input feature x is composed of the category feature x. cate and numerical features x num The x composed of num ,x cate}; During training or prediction, the category feature x cate First, each category feature is converted into an embedding vector of the same length through the embedding layer, and then input into the Transformer layer to extract the correlation between category features; the numerical feature x numFirst, all neuron nodes are normalized by layer normalization, and then input into the feature extraction layer to extract features; after that, the output of the Transformer layer and the feature extraction layer passes through the fusion layer (Concatenation layer) and the multi-layer perceptron output result.
[0022] In one embodiment of the present invention, step S4 is specifically as follows:
[0023] When base station B j After receiving the intrusion detection models of all smart meters participating in federated learning within its coverage area, the received intrusion detection models are aggregated on the edge servers near it. The specific aggregation method is:
[0024]
[0025] in represents the Transformer-based intrusion detection model uploaded by smart meter i, D i is the local dataset of smart meter i, Base station B j The obtained cluster model, C j Indicates all access base stations B j A collection of smart meter devices, Indicates access to base station B j The sum of the local data volume of all smart meters; From the above formula, it can be seen that the cluster model is obtained by weighting the local models of all connected smart meters, and the weight depends on the local data volume of the smart meter.
[0026] In one embodiment of the present invention, step S5 is specifically as follows:
[0027] The base station transmits the obtained cluster model to the cloud server through the 5G core network for global aggregation. The specific aggregation method is as follows:
[0028]
[0029] Among them, w( t+1) is the global model obtained, U is the total number of base stations participating in federated learning, Base station B j The obtained cluster model, |D| represents the total amount of local data of all smart meters participating in federated learning, C j Indicates all access base stations B j A collection of smart meter devices, Indicates all access base stations B jThe sum of the local data volume of the smart meters; From the above formula, it can be seen that the global model is obtained by weighting the cluster models of different base stations, and the weighted weight depends on the sum of the local data volume of all smart meters connected to a base station.
[0030] Compared with the prior art, the present invention has the following beneficial effects:
[0031] First, the present invention proposes a Transformer-based intrusion detection model, which has a good effect when performing intrusion detection; secondly, the present invention applies federated learning in the field of smart grids to protect the privacy and security of user data and reduce the latency of intrusion detection. Specifically, the smart meter only needs to transmit the model parameters to the cloud server, so as to protect the user's data privacy. Moreover, by participating in federated learning, each smart meter will eventually obtain an efficient intrusion detection model, which can be used by the smart meter to directly perform intrusion detection locally. Compared with the traditional intrusion detection performed in the cloud, this can reduce the latency of intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is a schematic diagram of a smart grid AMI system in a 5G network according to an embodiment of the present invention.
[0033] Figure 2 It is a schematic diagram of an implementation of Transformer-based intrusion detection in the present invention.
[0034] Figure 3 It is a schematic diagram comparing the verification accuracy of each round of global iteration when performing federated learning between the method provided by an embodiment of the present invention and a method using other intrusion detection models.
[0035] Figure 4 It is a schematic diagram comparing the amount of data uploaded by smart meters and the verification accuracy rate when executing federated learning between the method provided by an embodiment of the present invention and the method using other intrusion detection models.
[0036] Figure 5 It is a schematic diagram comparing the evaluation indicators of the model obtained by performing 200 global iterations under federated learning between the method provided by an embodiment of the present invention and the method using other intrusion detection models.
[0037] Figure 6 A comparison chart showing the amount of data transmitted between the base station and the cloud server during the execution of federated learning between traditional federated learning and this solution is shown. DETAILED DESCRIPTION
[0038] The technical solution of the present invention is described in detail below in conjunction with the accompanying drawings.
[0039] Please refer to Figure 1and Figure 2 The present invention provides a 5G smart grid intrusion detection method based on federated learning, comprising the following steps:
[0040] Step S1, the smart meter collects the electricity consumption information and flow data of household appliances through the home area network (HANs);
[0041] Step S2: The smart meter uses the received data to locally train a Transformer-based intrusion detection model;
[0042] Step S3: After the training is completed, the 5G base station collects the local models of the smart meters participating in the federated learning within its coverage area;
[0043] Step S4, the 5G base station aggregates the collected models at the edge server nearby to obtain a cluster model;
[0044] In step S5, the 5G base station transmits the obtained cluster model to the cloud server for global aggregation; the aggregated global model will be sent to the smart meter for the next round of training.
[0045] Preferably, in this embodiment, Figure 1 As shown in Figure 1, there is a smart grid AMI system consisting of ten smart meters deployed at different locations. Smart meters can directly access 5G base stations to upload and download data, and an edge server is deployed near each base station to pre-process the data uploaded by the smart meters, thereby reducing the network traffic in the process of transmitting from the base station to the cloud server.
[0046] Preferably, in this embodiment, the smart meter collects the electricity consumption data and flow information of household appliances through the home area network (HANs) for training a Transformer-based intrusion detection model locally. The gradient update method is usually used in the training process, specifically:
[0047]
[0048] in represents the Transformer-based intrusion detection model of smart meter i at the tth iteration, D i is the local dataset of smart meter i, μ is the learning rate, represents the local loss function of device i at the tth iteration, so, Represents the gradient of the loss function.
[0049] Preferably, in this embodiment, Figure 2As shown in the figure, the Transformer-based intrusion detection model mentioned mainly includes two Transformer layers and two feature extraction layers, where the Transformer layer consists of a multi-head attention layer and a feed forward network, and the feature extraction layer includes a convolutional layer and a pooling layer. Assume that (x, y) is a sample in the original data set, where y is the label of the current sample and x is the input feature of the current sample; the input feature x is composed of the category feature x cate and Numerical Features x num The x composed of num ,x cate}; During training or prediction, the category feature x cate First, each category feature is converted into an embedding vector of the same length through the embedding layer, and then input into the Transformer layer to extract the correlation between category features; the numerical feature x num First, all neuron nodes are normalized through layer normalization, and then input into the feature extraction layer to extract features; after that, the output of the Transformer layer and the feature extraction layer passes through the fusion layer (Concatenation layer) and the multi-layer perceptron output result.
[0050] Preferably, in this embodiment, after the model training is completed, the smart meter uploads the trained model to the base station to realize the interaction of the model. However, as the number of smart meters participating in federated learning continues to increase, the network traffic between the base station and the cloud server will continue to increase, which may cause network congestion and hinder the training process of federated learning. In order to avoid this situation, this solution proposes that after the base station receives the model uploaded by the smart meter, the received model is first aggregated at the edge server deployed near it to obtain a cluster model. The specific aggregation method is:
[0051]
[0052] in represents the Transformer-based intrusion detection model uploaded by smart meter i, D i is the local dataset of smart meter i, Base station B j The obtained cluster model, C jIndicates all access base station B j A collection of smart meter devices, Indicates that at base station B j The sum of the local data volumes of all smart meters participating in federated learning within the coverage area; From the above formula, it can be seen that the cluster model is obtained by weighting the local models of all connected smart meters, and the weight depends on the local data volume of the smart meter.
[0053] exist Figure 1 In the example shown, there are ten smart meters and three base stations. In traditional federated learning, the number of models that the base station needs to upload to the cloud server is 10. In this solution, since the base station first performs a model aggregation, the number of models uploaded by the base station to the cloud server is reduced to 3. Therefore, this solution can effectively reduce the network traffic between the base station and the cloud server and reduce the probability of network congestion. Figure 3 It is a schematic diagram comparing the verification accuracy of each round of global iteration when performing federated learning between the method provided by an embodiment of the present invention and a method using other intrusion detection models. Figure 4 It is a schematic diagram comparing the amount of data uploaded by smart meters and the verification accuracy rate when executing federated learning between the method provided by an embodiment of the present invention and the method using other intrusion detection models. Figure 5 It is a schematic diagram comparing the evaluation indicators of the model obtained by performing 200 global iterations under federated learning between the method provided by an embodiment of the present invention and the method using other intrusion detection models. Figure 6 A comparison chart showing the amount of data transmitted between the base station and the cloud server during the execution of federated learning between traditional federated learning and this solution is shown.
[0054] Preferably, in this embodiment, after receiving the cluster model uploaded by the base station, the cloud server performs global aggregation to obtain a global model. The specific aggregation method is:
[0055]
[0056] Among them, w( t+1) is the global model obtained, U is the total number of base stations participating in federated learning, Base station B j The obtained cluster model, |D| represents the total amount of local data of all smart meters participating in federated learning, C j Indicates all access base station B j A collection of smart meter devices, Indicates all access base station B j The sum of the local data volume of the smart meters; From the above formula, it can be seen that the global model is obtained by weighting the cluster models of different base stations, and the weighted weight depends on the sum of the local data volume of all smart meters connected to a base station.
[0057] Preferably, in this embodiment, after the cloud server obtains the global model, it will send it to all smart meters participating in federated learning for the next round of training. Through continuous iteration, the smart meter will eventually obtain an efficient intrusion detection model. At the same time, the smart meter will use the obtained intrusion detection model to directly perform intrusion detection locally to achieve the purpose of real-time monitoring.
[0058] The present invention first designs a Transformer-based intrusion detection model that can be deployed at smart meters to improve the performance of intrusion detection. Secondly, federated learning is introduced into the smart grid AMI system, so that the smart meter can cooperate to train an efficient intrusion detection model only by exchanging model parameters with the cloud server. In this process, the user's data is not directly transmitted, thereby effectively protecting the privacy of the data. In addition, the smart meter can use the efficient intrusion detection model obtained through federated learning to perform intrusion detection locally, reducing the latency of intrusion detection. At the same time, this solution also proposes to perform model aggregation at the base station first after the smart meter uploads the model to the base station to reduce the network traffic between the base station and the cloud server.
[0059] The above are preferred embodiments of the present invention. Any changes made according to the technical solution of the present invention, as long as the resulting functions do not exceed the scope of the technical solution of the present invention, belong to the protection scope of the present invention.
Claims
1. A 5G smart grid intrusion detection method based on federated learning, providing a system including several smart meters, 5G base stations, edge servers and cloud servers, It is characterized in that The steps include: Step S1, the smart meter collects the electricity consumption data and flow information of household appliances through the home area network HANs; Step S2: The smart meter uses the collected data to locally train a Transformer-based intrusion detection model; Step S3: The smart meter is connected to the 5G base station and the intrusion detection model trained in step S2 is uploaded; Step S4: After the 5G base station receives the intrusion detection model uploaded by the smart meter participating in the federated learning within its coverage area, the received intrusion detection model is aggregated at the edge server deployed near the 5G base station to obtain a cluster model; Step S5: The 5G base station transmits the aggregated cluster model to the cloud server through the 5G core network for global aggregation; After the cloud server obtains the global model, it sends it to the smart meter to start a new round of training; Step S6: Through multiple iterations of steps S2-S5, each smart meter will eventually obtain an efficient intrusion detection model, and use the efficient intrusion detection model to directly perform intrusion detection locally; The step S2 is specifically as follows: The smart meter will train a Transformer-based intrusion detection model based on local data, and use the gradient update method to update the model during the training process, namely: in represents the Transformer-based intrusion detection model of smart meter i at the tth iteration, D i is the local dataset of smart meter i, μ is the learning rate, represents the local loss function of device i at the tth iteration, so, Represents the gradient of the loss function; The Transformer-based intrusion detection model is specifically: The Transformer-based intrusion detection model includes two Transformer layers and two feature extraction layers. The Transformer layer consists of a multi-head attention layer and a feedforward network, and the feature extraction layer includes a convolution layer and a pooling layer. Assume that (x, y) is a sample in the original data set, where y is the label of the current sample and x is the input feature of the current sample. The input feature x is composed of the category feature x cate and numerical features x num The x composed of num ,x cate }; During training or prediction, the category feature x cate First, each category feature is converted into an embedding vector of the same length through the embedding layer, and then input into the Transformer layer to extract the correlation between category features; the numerical feature x num All neuron nodes are first normalized through layer standardization, and then input into the feature extraction layer to extract features; after that, the outputs of the Transformer layer and the feature extraction layer are passed through the fusion layer and the multi-layer perceptron to output the results.
2. According to the 5G smart grid intrusion detection method based on federated learning according to claim 1, It is characterized in that The step S1 is specifically as follows: Household appliances transmit electricity usage data and flow information to smart meters through home area networks HANs, where the home area networks use short-range communication technologies including WI-FI or Zigbee.
3. According to the 5G smart grid intrusion detection method based on federated learning according to claim 1, It is characterized in that The step S4 is specifically as follows: When base station B j After receiving the intrusion detection models of all smart meters participating in federated learning within its coverage area, the received intrusion detection models are aggregated on the edge servers near it. The specific aggregation method is: in represents the Transformer-based intrusion detection model uploaded by smart meter i, D i is the local dataset of smart meter i, Base station B j The obtained cluster model, C j Indicates all access base stations B j A collection of smart meter devices, Indicates access to base station B j The sum of local data volume of all smart meters; The cluster model is obtained by weighting the local models of all connected smart meters, and the weight depends on the amount of local data of the smart meter.
4. According to a 5G smart grid intrusion detection method based on federated learning according to claim 1, It is characterized in that The step S5 is specifically as follows: The base station transmits the obtained cluster model to the cloud server through the 5G core network for global aggregation. The specific aggregation method is as follows: Among them, w (t+1) is the global model obtained, U is the total number of base stations participating in federated learning, Base station B j The obtained cluster model, |D| represents the total amount of local data of all smart meters participating in federated learning, C j Indicates all access base stations B j A collection of smart meter devices, Indicates all access base stations B j The global model is obtained by weighting the cluster models of different base stations, and the weighted weight depends on the sum of the local data volume of all smart meters connected to a base station.
Citation Information
Patent Citations
Intelligent ammeter abnormity detection method based on nerve network
CN106817363A
Method and system for intrusion detection of distribution terminal unit (DTU) based on machine learning
CN112187820A