False data injection attack detection method, detection terminal and storage medium
By establishing a state estimation model in the power system, selecting some equipment for false data injection attack detection, and constructing attack detection parameters, the problem that the power CPS cannot effectively detect false data injection attacks is solved, and the security and stability of the system are improved.
Patent Information
- Application Number
- CN202211599533.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-12
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-12-12
AI Technical Summary
In existing technologies, power CPS cannot effectively detect false data injection attacks, lacks the ability to resist malicious network attacks, and poses a threat of large-scale power outages.
A power system state estimation model is established, some devices are selected as devices to be detected based on their contribution, attack detection parameters are constructed, and whether the power system is attacked is determined by detecting the parameters.
The ability of power CPS to resist false data injection attacks is improved, the accuracy and efficiency of detection are enhanced, and the possibility of detection failure is reduced.
Smart Images

Figure CN116032553B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a false data injection attack detection method, a detection terminal and a storage medium. Background Art
[0002] With the advancement of smart grid construction, a large number of sensor devices, communication devices, computing devices and electrical equipment are interconnected through two physical networks, the communication network and the power grid, forming a multi-dimensional heterogeneous complex system with real-time perception, dynamic control and information service integration capabilities, namely the power cyber-physical fusion system (CPS).
[0003] Power CPS can be divided into an information layer, a power layer, and communication networks within and outside these layers. The coordinated operation of sensing, computing, communication, and physical devices enables optimized operation of the entire system. Reliance on networks and communication systems to transmit measurement data and control commands increases the vulnerability of power CPS to attacks, leading to a series of network security issues such as Trojans, DoS attacks, and phishing emails. Cyberattacks have become a significant challenge and threat to the safe and stable operation of power CPS.
[0004] False data injection attacks (FDIAs) can exploit vulnerabilities in corrupted data detection within energy management systems to maliciously tamper with state estimation results, seriously endangering the safe and reliable operation of power systems. Furthermore, distribution networks, due to their complex network topology and low measurement redundancy, present a greater potential threat of cyberattacks. Therefore, preventing and identifying FDIAs has become a new challenge in ensuring the information security, resilience, and economic operation of power systems.
[0005] In the existing technology, power CPS cannot effectively detect FDIS and lacks the ability to resist malicious network attacks, posing a threat of large-scale power outages to the power system. Summary of the Invention
[0006] The embodiments of the present invention provide a false data injection attack detection method, a detection terminal, and a storage medium to solve the problem in the prior art that the power CPS cannot effectively detect FDIS attacks and lacks the ability to resist malicious network attacks.
[0007] In a first aspect, an embodiment of the present invention provides a method for detecting a false data injection attack, comprising:
[0008] Establish a power system state estimation model and determine the contribution of each device in the power system based on the power system state estimation model;
[0009] According to the contribution degrees of the devices, part of the devices in the power system are selected as to-be-detected devices, attack detection parameters of the power system are determined, and whether the power system is attacked is determined according to the attack detection parameters.
[0010] In a second aspect, an embodiment of the present application provides a detection terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps of the false data injection attack detection method provided in the first aspect or any possible implementation manner of the first aspect are implemented.
[0011] In a third aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the steps of the false data injection attack detection method provided in the first aspect or any possible implementation manner of the first aspect are implemented.
[0012] The embodiment of the present application provides a false data injection attack detection method, a detection terminal and a storage medium, the method comprising: establishing a power system state estimation model, determining the contribution degrees of the devices in the power system based on the power system state estimation model; selecting part of the devices in the power system as to-be-detected devices according to the contribution degrees of the devices, determining attack detection parameters of the power system, and determining whether the power system is attacked according to the attack detection parameters. Based on the principle of FDIA, when all the devices are detected, the FDIA may not be effectively detected. Therefore, in the embodiment of the present application, part of the devices in the power system are selected to construct the attack detection parameters for attack detection, the FDIA attack can be effectively detected, and the ability of the power CPS to resist malicious network attacks is improved. BRIEF DESCRIPTION OF DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0014] Figure 1 is an implementation flowchart of the false data injection attack detection method provided by the embodiment of the present application;
[0015] Figure 2 is an implementation flowchart of another false data injection attack detection method provided by the embodiment of the present application;
[0016] Figure 3 is a structural schematic diagram of the false data injection attack detection device provided by the embodiment of the present application;
[0017] Figure 4 is a schematic diagram of a detection terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] In the following description, specific details such as particular system structures and techniques are provided for purposes of illustration, not limitation, to facilitate a thorough understanding of the embodiments of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present invention with unnecessary detail.
[0019] In order to make the purpose, technical solutions and advantages of the present invention more clear, specific embodiments will be described below with reference to the accompanying drawings.
[0020] See also Figure 1 , which shows a flow chart of the implementation of the false data injection attack detection method provided by an embodiment of the present invention, which is described in detail as follows:
[0021] S101: Establishing a power system state estimation model, and determining the contribution of each device in the power system based on the power system state estimation model;
[0022] S102: Select some devices in the power system as devices to be detected based on the contribution of each device, determine attack detection parameters of the power system, and determine whether the power system is attacked based on the attack detection parameters.
[0023] FDIA attacks power systems by maliciously tampering with state estimation results. Testing all devices in the power system can result in detection failure. Therefore, the present invention selects a subset of devices for testing, disrupting the original FDIA logic. This improves detection accuracy, effectively detecting FDIA attacks and enhancing the power CPS's ability to resist malicious network attacks. Taking into account the uncertainty of random selection, the present invention selects devices for testing based on their contribution. This effectively reflects the relationship between state estimation and measurement data, is more realistic, and achieves higher detection accuracy.
[0024] In a possible implementation, the power system state estimation model may be:
[0025]
[0026] in, for Dimensional system state variables, is the system measurement value vector, is the measurement error, and Conforms to Gaussian distribution.
[0027] The embodiment of the present invention adopts a nonlinear relationship Improve state estimation and power flow calculation to make the calculation and estimation results more accurate and more consistent with the actual power system.
[0028] Specifically, it involves active / reactive power flow, The calculation formula is as follows:
[0029]
[0030]
[0031]
[0032]
[0033] in, For nodes and The line conductance between For nodes and Line susceptance between For nodes and The phase angle difference between them.
[0034] In a possible implementation, S101 may include:
[0035] S1011: Solve the power system state estimation model using the least squares method to obtain the measurement Jacobian matrix;
[0036] S1012: Determine the hat matrix based on the measured Jacobian matrix;
[0037] S1013: Determine the contribution of each device in the power system according to the hat matrix.
[0038] In a possible implementation, S1013 may include:
[0039] 1. Normalize the hat matrix to obtain the normalized hat matrix;
[0040] 2. The diagonal elements of the normalized hat matrix are used as the contribution of each device in the power system; wherein the diagonal elements of the normalized hat matrix correspond to each device in the power system.
[0041] The hat matrix is a symmetric projection matrix that plays a special role in residual analysis. The diagonal elements of the hat matrix can reflect the importance of each device. Therefore, the hat matrix is introduced to determine the contribution of each device.
[0042] Specifically, the hat matrix can be normalized. The closer the diagonal elements of the normalized hat matrix are to 1, the more important the corresponding device is. The measurement value of the device is more sensitive to attacks and should be paid special attention to.
[0043] In one possible implementation, the hat matrix The calculation formula can be:
[0044]
[0045] in, is the standard measurement error, is the Jacobian matrix.
[0046] Furthermore, the least squares method is used to solve the power system state estimation model, which can be converted into an optimization problem of the objective function:
[0047]
[0048] in, is a diagonal matrix, , For the The covariance of the measurement errors.
[0049] To obtain The minimum value of , the derivative of the above objective function is 0, then:
[0050]
[0051] is the Jacobian matrix, and its order is , is the standard measurement error.
[0052]
[0053] In one possible implementation, reference Figure 2 , S102 may include:
[0054] S1021: Selecting some devices in the system according to the contribution of each device to form a plurality of device combinations to be detected; wherein, for each device combination to be detected, the device combination to be detected includes some devices in the power system;
[0055] S1022: The initial value of is set to 1;
[0056] S1023: According to The combination of devices to be tested determines the Attack detection parameters corresponding to the combination of devices to be detected;
[0057] S1024: If The attack detection parameter corresponding to the combination of devices to be detected is less than the preset residual, then At this time, if If it is not greater than the preset value, jump to The combination of devices to be tested determines the Continue to execute the steps for attack detection parameters corresponding to the combination to be detected; if If it is greater than the preset value, it is determined that the power system has not been attacked;
[0058] S1025: If If the attack detection parameter corresponding to the combination of devices to be detected is not less than the preset residual, it is determined that the power system is attacked;
[0059] The preset value is the total number of device combinations to be detected.
[0060] Since this application selects some devices for detection, some attack points may be missed. In this embodiment, multiple combinations of devices to be detected are set, that is, multiple device call schemes are set to avoid the problem that a single scheme cannot cover all attack points. By setting multiple device call schemes to include all attack points, a cyclic detection scheme is adopted, and each device call scheme is used for detection in turn.
[0061] For example, if the attack detection parameter for the first device combination to be tested is less than the preset residual, it indicates that there is no attack. The second device combination to be tested is then tested, and so on. If the attack detection parameter corresponding to a device combination to be tested is not less than the preset residual, it indicates an attack, and the loop is exited and testing stops. If all device combinations to be tested have been tested and the corresponding attack detection parameters are all less than the preset residual, then the power system is determined to be safe.
[0062] In a possible implementation, the total number of device combinations to be detected may be 5; S1021 may include:
[0063] 1. Select the top contributors The named devices form the first device combination to be tested;
[0064] 2. Remove the first device combination to be tested with a contribution ranking of Name the device and add it to the ranking to The named devices form the second device combination to be tested;
[0065] 3. Remove the second device combination to be tested, whose contribution ranking is Name the device and add it to the ranking arrive The named devices form the third device combination to be tested;
[0066] 4. Remove the third device combination to be tested, and the contribution ranking is Name the device and add it to the ranking arrive The named devices form the fourth device combination to be tested;
[0067] 5. Remove the fourth device combination to be tested, and the contribution ranking is Name the device and add it to the ranking arrive The named devices form the fifth device combination to be tested;
[0068] in, is the preset quantity, .
[0069] The preset number may be the minimum number of devices required to ensure stable operation of the power system. Different power systems may have different corresponding preset numbers.
[0070] Since the greater the contribution, the more important the device. Therefore, the first device combination to be detected in the embodiment of the present invention selects the device with the highest contribution. The second device combination to be tested is based on the first device combination, with some devices added or removed, while ensuring that the device call solution contributes to the measurement data. This aims to cover as many devices as possible, including all possible FDIA attack points, and improve detection accuracy and efficiency. Methods for determining the device combination to be tested include, but are not limited to, this.
[0071] The preset residual is the threshold for residual detection. Different systems and different residual calculations correspond to different preset residuals, which can be set by the user according to actual application requirements.
[0072] It should be noted that when the number of devices in the power system is small, the total number of device combinations to be detected may also be less than 5, which can be set specifically according to actual application requirements.
[0073] In a possible implementation, before S102, the method may further include:
[0074] S103: Based on the Jacobian matrix, the Gauss-Newton method is used to solve and obtain the state estimation value of the power system.
[0075] In a possible implementation, S102 may include:
[0076] S1026: Forming a device selection matrix based on each device to be detected; wherein, if the device is selected, the value in the device selection matrix corresponding to the device is 1;
[0077] S1027: Determine attack detection parameters of the power system based on the equipment selection matrix, the state estimation value of the power system, and the Jacobian matrix.
[0078] In one possible implementation, the attack detection parameter The calculation formula can be:
[0079]
[0080] in, For the The equipment selection matrix corresponding to the equipment combination to be tested, For the The measurement value vector corresponding to the device combination to be detected is: is the Jacobian matrix, is the estimated state of the power system, is the identity matrix, For the The estimated change in the state of the device to be detected before and after the combined attack.
[0081] Since state estimation has the ability to detect bad data, random measurement errors and small signals in the system are eliminated, and residuals can be used to detect bad data. The model is as follows:
[0082]
[0083] After knowing the network topology of part or the entire system, construct FDIA based on the topology information and tamper with the measurement value , tampered data can still avoid residual detection, the specific principle is as follows:
[0084]
[0085] in, is the attack vector, It is the estimated change value of the state before and after the attack.
[0086] The estimated state after being attacked is:
[0087]
[0088] Based on the above, the residual is:
[0089]
[0090] As can be seen from the above formula, FDIA is cleverly constructed, and the residual value remains unchanged before and after the attack, which can perfectly evade residual detection and cause detection failure. If the attacker injects bad data into the measurement, the bad data detection will not be able to detect FDIA.
[0091] Based on the above, the embodiment of the present invention optimizes the residual detection and constructs the attack detection parameters Used for bad data detection. hour, is the residual produced by the selected device, and This is a value other than the residual, representing information obtained from the device. Under normal circumstances, when the system is not under attack, this term is zero. However, when the grid is under attack, significant changes occur. It can amplify the characteristics of tampered data, improve detection efficiency, and effectively detect FDIA attacks through attack detection parameters with stable detection efficiency.
[0092] Depend on The calculation formula of can be seen that in the embodiment of the present invention, the attack detection parameters of the power system are determined by combining the equipment selection matrix, the state estimation value of the power system and the Jacobian matrix. Therefore, the embodiment of the present invention also needs to solve the state estimation value of the power system. Based on the solution formula of the Jacobian matrix, , and then use the Gauss-Newton method to solve it.
[0093] The specific calculation process is as follows:
[0094] exist Taylor series expansion at:
[0095]
[0096]
[0097] The iterative algorithm is used to solve the problem, and the update process is as follows:
[0098]
[0099]
[0100]
[0101] The state estimation value is calculated by the above formula.
[0102] Furthermore, if the detection accuracy requirement is not high, in order to improve the detection rate and avoid repeated iterations taking up detection time, the state estimation value can also be directly calculated from the Jacobian matrix according to the following formula.
[0103]
[0104] It should be understood that the size of the serial number of each step in the above embodiment does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the application.
[0105] The following is the device embodiment of the application. For details not described in detail, please refer to the corresponding method embodiments described above.
[0106] Figure 3 The structure diagram of the false data injection attack detection device provided by the embodiment of the application is shown. For the convenience of description, only the part related to the embodiment of the application is shown, and the details are as follows:
[0107] As shown in Figure 3 The false data injection attack detection device includes:
[0108] The model establishing module 21 is configured to establish a power system state estimation model, and determine the contribution degree of each device in the power system based on the power system state estimation model.
[0109] The detection output module 22 is configured to select part of the devices in the power system as the to-be-detected devices according to the contribution degree of each device, determine the attack detection parameter of the power system, and determine whether the power system is attacked according to the attack detection parameter.
[0110] In a possible implementation, the model establishing module 21 can include:
[0111] The first matrix calculation unit is configured to solve the power system state estimation model by using the least square method to obtain a measurement Jacobian matrix.
[0112] The second matrix calculation unit is configured to determine a hat matrix according to the measurement Jacobian matrix.
[0113] The contribution degree calculation unit is configured to determine the contribution degree of each device in the power system according to the hat matrix.
[0114] In a possible implementation, the contribution degree calculation unit can include:
[0115] The normalization subunit is configured to normalize the hat matrix to obtain a normalized hat matrix.
[0116] The contribution degree output subunit is configured to take the elements of the diagonal line of the normalized hat matrix as the contribution degree of each device in the power system, wherein the elements of the diagonal line of the normalized hat matrix correspond to each device in the power system respectively.
[0117] In a possible implementation, the detection output module 22 can include:
[0118] A multi-scheme output unit is used to select some devices in the system to form multiple combinations of devices to be tested based on the contribution of each device; wherein, for each combination of devices to be tested, the combination of devices to be tested includes some devices in the power system;
[0119] Initialization unit, used to The initial value of is set to 1;
[0120] The first parameter determination unit is used to determine the The combination of devices to be tested determines the Attack detection parameters corresponding to the combination of devices to be detected;
[0121] The first judgment unit is used to determine if The attack detection parameter corresponding to the combination of devices to be detected is less than the preset residual, then ; At this time, if If it is not greater than the preset value, jump to The combination of devices to be tested determines the Continue to execute the steps for attack detection parameters corresponding to the combination to be detected; if If it is greater than the preset value, it is determined that the power system has not been attacked;
[0122] The second judgment unit is used to If the attack detection parameter corresponding to the combination of devices to be detected is not less than the preset residual, it is determined that the power system is attacked;
[0123] The preset value is the total number of device combinations to be detected.
[0124] In one possible implementation, the total number of device combinations to be detected is 5; the multi-scheme output unit may include:
[0125] The first solution determines the subunits to select the top contribution ranking The named devices form the first device combination to be tested;
[0126] The second solution determines the subunits for removing the first device combination to be detected whose contribution ranking is Name the device and add it to the ranking to The named devices form the second device combination to be tested;
[0127] The third solution determines a subunit for removing the second device combination to be detected whose contribution ranking is Name the device and add it to the ranking arrive The named devices form the third device combination to be tested;
[0128] The fourth solution determines a subunit for removing the third device combination to be detected whose contribution ranking is Name the device and add it to the ranking arrive The named devices form the fourth device combination to be tested;
[0129] The fifth solution determines a subunit for removing the fourth device combination to be tested whose contribution ranking is Name the device and add it to the ranking arrive The named devices form the fifth device combination to be tested;
[0130] in, is the preset quantity, .
[0131] In a possible implementation, the above device may further include:
[0132] The state estimation value solving module is used to obtain the state estimation value of the power system based on the Jacobian matrix and the Gauss-Newton method.
[0133] In a possible implementation, the detection output module 22 may include:
[0134] A third matrix calculation unit is configured to form a device selection matrix based on each device to be detected; wherein, if the device is selected, the value in the device selection matrix corresponding to the device is 1;
[0135] The second parameter determination unit is used to determine the attack detection parameters of the power system according to the equipment selection matrix, the state estimation value of the power system and the Jacobian matrix.
[0136] In one possible implementation, the attack detection parameter The calculation formula can be:
[0137]
[0138] in, For the The equipment selection matrix corresponding to the equipment combination to be tested, For the The measurement value vector corresponding to the device combination to be detected is: is the Jacobian matrix, is the estimated value of the power system state, is the identity matrix, For the The estimated change in the state of the device to be detected before and after the combined attack.
[0139] Figure 4 Schematic diagram of the detection terminal provided by the embodiment of the present invention. Figure 4 As shown, the detection terminal 3 of this embodiment includes: a processor 30 and a memory 31. The memory 31 is used to store a computer program 32, and the processor 30 is used to call and run the computer program 32 stored in the memory 31 to perform the steps of the above-mentioned various false data injection attack detection method embodiments, such as Figure 1 Alternatively, the processor 30 is used to call and run the computer program 32 stored in the memory 31 to implement the functions of each module / unit in the above-mentioned device embodiments, such as Figure 3 The functions of modules 21 to 22 are shown.
[0140] Exemplarily, the computer program 32 may be divided into one or more modules / units, one or more modules / units being stored in the memory 31 and executed by the processor 30 to implement the present invention. One or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, and the instruction segments are used to describe the execution process of the computer program 32 in the detection terminal 3. For example, the computer program 32 may be divided into Figure 3 Modules / units 21 to 22 are shown.
[0141] The detection terminal 3 can be a computing device such as a desktop computer, a notebook, a palmtop computer, a cloud server, etc. The detection terminal 3 can include, but is not limited to, a processor 30 and a memory 31. It will be understood by those skilled in the art that Figure 4 It is only an example of the detection terminal 3 and does not constitute a limitation on the detection terminal 3. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the terminal may also include input and output devices, network access devices, buses, etc.
[0142] The processor 30 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0143] The storage 31 can be an internal storage unit of the detection terminal 3, such as a hard disk or a memory of the detection terminal 3. The storage 31 can also be an external storage device of the detection terminal 3, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, and the like equipped on the detection terminal 3. Further, the storage 31 can also include both the internal storage unit and the external storage device of the detection terminal 3. The storage 31 is used to store computer programs and other programs and data required by the terminal. The storage 31 can also be used to temporarily store data that has been output or will be output.
[0144] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for easy distinction, and do not limit the protection scope of the present application. The specific working process of the unit and module in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0145] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can refer to the relevant description of other embodiments.
[0146] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0147] In the embodiments provided herein, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For example, the division of modules or units is merely a logical functional division. In actual implementation, other division methods may be used, such as multiple units or components being combined or integrated into another system, or some features being ignored or not implemented. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interface, or the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.
[0148] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0149] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0150] If the integrated module / unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process steps in the above-mentioned method embodiments by using a computer program to instruct the relevant hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. Computer-readable media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, mobile hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunications signals, and software distribution media.
[0151] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.
Claims
1. A false data injection attack detection method, characterized in that: include: Establishing a power system state estimation model, and determining the contribution of each device in the power system based on the power system state estimation model; Selecting some devices in the power system as devices to be detected based on the contribution of each device, determining attack detection parameters of the power system, and determining whether the power system is attacked based on the attack detection parameters; Determining the contribution of each device in the power system based on the power system state estimation model includes: Solving the power system state estimation model using the least squares method to obtain a measurement Jacobian matrix; determining a hat matrix based on the measured Jacobian matrix; Determining the contribution of each device in the power system according to the hat matrix; The selecting, based on the contribution of each device, some devices in the power system as devices to be detected, determining attack detection parameters of the power system, and determining whether the power system is attacked based on the attack detection parameters, includes: According to the contribution of each device, some devices in the system are selected to form multiple device combinations to be detected; wherein, for each device combination to be detected, the device combination to be detected includes some devices in the power system; Will The initial value of is set to 1; According to A combination of devices to be detected, determine the Attack detection parameters corresponding to the combination of devices to be detected; If the The attack detection parameter corresponding to the combination of devices to be detected is less than the preset residual, then ; At this time, if If it is not greater than the preset value, then jump to the A combination of devices to be detected, determine the Continue to execute the steps for attack detection parameters corresponding to the combination to be detected; if If the value is greater than the preset value, it is determined that the power system has not been attacked; If the If the attack detection parameter corresponding to the combination of devices to be detected is not less than the preset residual, it is determined that the power system is attacked; The preset value is the total number of the device combinations to be detected.
2. The false data injection attack detection method according to claim 1, characterized in that: Determining the contribution of each device in the power system according to the hat matrix includes: Normalizing the hat matrix to obtain a normalized hat matrix; The elements of the diagonal of the normalized hat matrix are used as the contribution of each device in the power system; wherein the elements of the diagonal of the normalized hat matrix correspond to each device in the power system respectively.
3. The false data injection attack detection method according to claim 1, characterized in that: The total number of the device combinations to be detected is 5; According to the contribution of each device, some devices in the system are selected to form multiple device combinations to be detected, including: Select the top contribution ranking The named devices form the first device combination to be tested; Remove the first device combination to be detected whose contribution ranking is Name the device and add it to the ranking to The named devices form the second device combination to be tested; Remove the second device combination to be detected, whose contribution ranking is Name the device and add it to the ranking arrive The named devices form the third device combination to be tested; Remove the third device combination to be tested and the contribution ranking is Name the device and add it to the ranking arrive The named devices form the fourth device combination to be tested; Remove the fourth device combination to be tested and the contribution ranking is Name the device and add it to the ranking arrive The named devices form the fifth device combination to be tested; in, is the preset quantity, .
4. The false data injection attack detection method according to claim 1, characterized in that: Before selecting some devices in the power system as devices to be detected based on the contribution of each device, determining attack detection parameters of the power system, and determining whether the power system is attacked based on the attack detection parameters, the method further includes: Based on the Jacobian matrix, the Gauss-Newton method is adopted to solve and obtain the state estimation value of the power system.
5. The false data injection attack detection method according to claim 4, characterized in that: The selecting of some devices in the power system as devices to be detected based on the contribution of each device and determining attack detection parameters of the power system includes: Forming a device selection matrix based on each device to be detected; wherein, if the device is selected, the value in the device selection matrix corresponding to the device is 1; Attack detection parameters of the power system are determined according to the equipment selection matrix, the state estimation value of the power system and the Jacobian matrix.
6. The false data injection attack detection method according to claim 5, characterized in that: The attack detection parameters The calculation formula is: in, For the The equipment selection matrix corresponding to the equipment combination to be tested, For the The measurement value vector corresponding to the device combination to be detected is: is the Jacobian matrix, is the estimated value of the power system state, is the identity matrix, For the The estimated change in the state of the device to be detected before and after the combined attack.
7. A control terminal, characterized in that: The system comprises a processor and a memory, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the steps of the false data injection attack detection method according to any one of claims 1 to 6.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the false data injection attack detection method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
AC-DC hybrid system-oriented false data injection attack strategy evaluation method
CN112800420A