Multi-class false data injection attack detection method and system for power Internet of Things based on hierarchical clustering
Through a hierarchical clustering-based method, Kalman filtering and Euclidean distance are used to detect multi-class false data injection attacks in the power Internet of Things, which solves the shortcomings of traditional methods in multi-class attack detection, achieves more efficient attack detection and evaluation, and improves the security of the power system.
Patent Information
- Application Number
- CN202211710347.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2042-12-29
AI Technical Summary
Existing technologies have difficulty in effectively detecting various types of false data injection attacks in the power Internet of Things. Traditional methods are ineffective in the face of various attack strategies, affecting the security and reliability of the power system.
A hierarchical clustering method is adopted to obtain local estimation values through the Kalman filter algorithm, hierarchical clustering is performed using Euclidean distance, and data fusion is performed in combination with the minimum estimation error covariance criterion. The mean absolute error under different cluster numbers is compared to obtain the best clustering result, and multiple types of false data injection attacks in the power Internet of Things are detected.
It improves the detection effect of false data injection attacks in the power Internet of Things, can detect multiple types of attacks at the same time, shortens the judgment time, and improves the safety and reliability of the power system.
Smart Images

Figure CN116155561B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of power Internet of Things security technology, and in particular relates to a power Internet of Things multi-category false data injection attack detection method and system based on hierarchical clustering. Background Art
[0002] In recent years, with the deep interconnection and integration of power systems and information technology, the Power Internet of Things (PoT) has enabled intelligent and reliable management of power generation, transmission, distribution, and consumption. However, as the scale of the PoT has grown, the number of sensors, users, and control modules has increased significantly. While this improves the flexibility and efficiency of the power system, it also increases its complexity. However, the complexity, intelligence, and openness of the PoT have brought new security threats. The number and types of attacks within the power grid environment have increased significantly. Power attacks have compromised the security of power terminals, networks, data, and systems at all levels, causing significant losses and negative impacts to the power grid. In the PoT, attackers can design malicious cyber-physical attacks that target the convergence of the information layer of the information network and the physical layer of the power grid. Therefore, to improve the reliability of smart grids, research on attack detection methods for the PoT is of great significance both theoretically and practically.
[0003] The increasing scale of the Power Internet of Things (PoI) brings flexibility and efficiency, but also numerous vulnerabilities and hidden dangers. Traditional power grid attacks can mostly be identified and detected using the chi-square test, which uses probability distribution as a criterion. However, cyber-physical attacks, such as false data injection attacks, have been discovered in recent years and are able to evade the chi-square test. These attacks often occur in a coordinated manner, posing a significant challenge to the secure and efficient operation of the Power Internet of Things (PoI). Existing technologies primarily target single attack methods for detection. Using different attack strategies for different nodes in the power system, or employing multiple attack strategies simultaneously, can, to a certain extent, affect the effectiveness of existing PoI attack detection methods. Summary of the Invention
[0004] To this end, the present invention provides a method and system for detecting multiple types of false data injection attacks in the power Internet of Things based on hierarchical clustering. The hierarchical clustering in cluster analysis is introduced into the attack detection of the power Internet of Things, and the average absolute error obtained by comparing the estimated value of the security node with the estimated value obtained after clustering is used to evaluate the quality of the clustering, thereby improving the effect of false data injection attack detection in the power Internet of Things.
[0005] According to the design scheme provided by the present invention, a method for detecting multiple types of false data injection attacks in the power Internet of Things based on hierarchical clustering is provided, which includes the following contents:
[0006] The observation data of N observer nodes in the power Internet of Things are filtered using the Kalman filter algorithm to obtain local estimates, where the observer nodes include known safe sensor nodes and other N-1 normal and / or vulnerable sensor nodes;
[0007] Using Euclidean distance as the correlation, the local estimation values of N observer nodes are hierarchically clustered with different cluster numbers, and clustered into 2 to N-1 clusters respectively;
[0008] The data in the cluster where the safety sensor node is located are fused under the minimum estimation error covariance criterion to obtain the state estimation value. The best clustering result is obtained by comparing the mean absolute error between the measurement estimation value and the measurement true value under different cluster numbers after fusion. The state estimation value of the best clustering result is used as the credible fusion estimation value.
[0009] As a multi-class false data injection attack detection method for the power Internet of Things based on hierarchical clustering in the present invention, further, the observation data includes: measuring instrument / sensor measurement value state variables of current phase and amplitude, and the state variables include voltage and phase angle.
[0010] As the multi-class false data injection attack detection method of the power Internet of Things based on hierarchical clustering in the present invention, further, the observer measurement equation is expressed as: i (k)=H i (k)x(k)+v i (k),i=1,2,…,N,z i (k) represents the measurement value of sensor i, H i (k) represents the corresponding measurement matrix, v i (k) is the measurement noise, x(k)=F(k,k-1)x(k-1)+w(k,k-1), k represents the discrete time instant, x(k) represents the measurement system state, F(k,k-1) represents the state transfer matrix, and w(k,k-1) represents the zero-mean Gaussian white noise and covariance.
[0011] As the multi-class false data injection attack detection method of the power Internet of Things based on hierarchical clustering in the present invention, further, filtering and data update are performed through the Kalman filter algorithm to obtain local estimation values, wherein the filtering process is expressed as: in, It is expressed as the estimated state value of the i-th node at the k-th moment, P i (k|k) is the corresponding estimation error variance, P i (k|k-1) is the corresponding prediction estimation error variance, It is expressed as the state prediction value of the i-th node at the k-th moment, K i(k) is the Kalman gain corresponding to the kth moment of the i-th node, and I is a unit vector.
[0012] As a multi-class false data injection attack detection method for the power Internet of Things based on hierarchical clustering of the present invention, the local estimation values of N observer nodes are further subjected to hierarchical clustering with different numbers of clusters, which includes the following contents: first, the initial cluster center (initial average vector) corresponding to the number of clusters is set, and then the distance between each local estimation and the average vector of each cluster in the cluster cluster is calculated, and then the minimum distance between each local estimation and the average vector of each cluster is found, and the local estimation corresponding to the minimum distance is clustered into the same cluster, and the average vector of each cluster is updated at the same time; finally, the clustering is repeated by returning and updating the average vector between the local estimations until the average value of the average vector of each cluster no longer changes.
[0013] As a multi-class false data injection attack detection method for the power Internet of Things based on hierarchical clustering of the present invention, further, the data in the cluster where the security sensor node is located is fused under the minimum estimation error covariance criterion, which includes the following contents: the cluster containing the local estimation of the known security sensor node is used as the security cluster, and the cluster of the local estimation of other sensor nodes is used as the cluster of false data; through the estimation error covariance of the security local estimation, the fusion is performed under the minimum mean square error criterion, wherein the fused state estimation and the corresponding estimation error covariance are expressed as:
[0014] represents the secure local estimate, P i * (k|k) represents the estimation error covariance corresponding to the secure local estimate, Cn is the nth cluster, and 2≤n≤N-2.
[0015] As the multi-class false data injection attack detection method of the power Internet of Things based on hierarchical clustering of the present invention, further, the mean absolute error calculation process is expressed as:
[0016] e n is the average absolute error of measurement in the cluster corresponding to the k moments before cluster 2 to N-1, z1(k) is the measurement value of the known security sensor node, is the fusion estimate corresponding to n clusters.
[0017] Furthermore, the present invention also provides a multi-type false data injection attack detection system for the power Internet of Things based on hierarchical clustering, comprising: a filtering update module, a hierarchical clustering module and a fusion evaluation module, wherein:
[0018] A filtering and updating module is used to filter the observation data of N observer nodes in the power Internet of Things using a Kalman filter algorithm and obtain a local estimated value, wherein the observer nodes include known safe sensor nodes and other N-1 normal and / or vulnerable sensor nodes;
[0019] The hierarchical clustering module is used to perform hierarchical clustering of the local estimated observation values of N observer nodes with different cluster numbers using Euclidean distance as the correlation, and cluster them into 2 to N-1 clusters respectively;
[0020] The fusion evaluation module is used to fuse the data in the cluster where the security sensor node is located under the minimum estimation error covariance criterion to obtain the state estimation value, and obtain the best clustering result by comparing the mean absolute error between the measurement estimation value and the measurement true value under different cluster numbers after fusion. The state estimation value of the best clustering result is used as the credible fusion estimation value.
[0021] Beneficial effects of the present invention:
[0022] The present invention obtains local estimated observation values from the observation data of the observer node in the power Internet of Things through the Kalman filtering algorithm, hierarchically clusters the local estimated observation values of different nodes with different cluster numbers based on the Euclidean distance as the correlation, and fuses the data in the cluster where the security node is located under the minimum estimation error covariance criterion to obtain a state estimation value, thereby solving the problem that the previous method can only detect a single false data injection attack but cannot detect multiple types of attacks at the same time. Finally, by comparing the mean absolute error of the measurement estimation value and the measurement true value under different cluster numbers, the best clustering result is obtained, and its state estimation value is used as a credible fusion estimation value; hierarchical clustering in cluster analysis is used to detect attacks in the power Internet of Things, and the mean absolute error of the measurement estimation value and the measurement true value under different cluster numbers after fusion is used to evaluate the quality of the clustering, thereby shortening the judgment time and being suitable for application in the power Internet of Things security detection scenario. Description of the drawings:
[0023] Figure 1 This is a schematic diagram of the multi-class false data injection attack detection process of the power Internet of Things based on hierarchical clustering in an embodiment;
[0024] Figure 2 This is a schematic diagram of the hierarchical clustering process in the embodiment;
[0025] Figure 3 Schematic diagram of the absolute errors between the observed values and the estimated observed values under different clustering numbers under two types of false data injection in the embodiment;
[0026] Figure 4 Schematic diagram of the mean absolute error between the observed values and the estimated observed values under different cluster numbers under two types of false data injection in the embodiment;
[0027] Figure 5 Schematic diagram of the absolute errors between observed values and estimated observed values under different clustering numbers under four types of false data injection in the embodiment;
[0028] Figure 6 It is the average absolute error between the observed values and the observed estimated values under the four types of false data injection attack with different cluster numbers in the embodiment. DETAILED DESCRIPTION
[0029] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below with reference to the accompanying drawings and technical solutions.
[0030] This embodiment provides a method for detecting multiple types of false data injection attacks in the power Internet of Things based on hierarchical clustering, including:
[0031] S101. Filter observation data of N observer nodes in the power Internet of Things using a Kalman filter algorithm and obtain local estimates, where the observer nodes include known secure sensor nodes and other N-1 normal and / or vulnerable sensor nodes.
[0032] S102, using Euclidean distance as the correlation, hierarchical clustering of different cluster numbers is performed on the local estimation values of the N observer nodes, and clustering them into 2 to N-1 clusters respectively;
[0033] S103. The data in the cluster where the security sensor node is located are fused under the minimum estimation error covariance criterion to obtain a state estimation value, and the best clustering result is obtained by comparing the mean absolute error between the measurement estimation value and the measurement true value under different cluster numbers after fusion. The state estimation value of the best clustering result is used as a credible fusion estimation value.
[0034] In the embodiment of this case, the estimated values of each node are hierarchically clustered with Euclidean distance as the correlation degree, and are fused under the minimum estimation error covariance criterion to obtain the state estimation value, which solves the problem that previous methods can only detect single false data injection attacks but cannot detect multiple types of attacks at the same time; based on the observations obtained by the observer where the security node is located, the average absolute error between the measured estimated value and the measured true value under different numbers of clusters obtained under the framework of the Kalman filter algorithm is used as the standard for evaluating the quality of clustering, which shortens the evaluation time and provides the possibility for application in real power Internet of Things scenarios.
[0035] As a preferred embodiment, further, the observation data includes: measurement values of measuring instruments / sensors related to current phase and amplitude, and the state variables include voltage and phase angle.
[0036] See also Figure 1As shown, in specific applications, the initial state estimate is represented as x0, which is different from the noise {w(k,k-1)} and {v i (k)} are independent of each other, and the corresponding estimation error variance is p0. A distributed networked multi-sensor system includes normal, safe, and vulnerable nodes, and only the safe sensors are known. An attacker can inject false data to replace the measured values or local estimates propagated by the vulnerable nodes. The observed values or local estimates propagated by the vulnerable nodes are replaced by false data.
[0037] Instruments or sensors that measure current phase and amplitude are used in power systems to monitor system status at various locations and ensure proper operation. The measurements obtained from these instruments / sensors are used to report state variables, such as bus voltage and phase angle, to a central controller via wired or wireless communication infrastructure. Furthermore, attacks or faults in the power system are often reflected in voltage, current, or phase variations.
[0038] Taking the voltage signal as an example, it can be expressed as a function of three parameters: discrete time assignment, angular frequency, and phase φ. It can be expressed as equation (1):
[0039] V(t)=Asin(ωt+φ) (1)
[0040] It can also be expanded to
[0041] V(t)=A*sinωt*cosφ+A*cosωt*sinφ (2)
[0042] Assuming that the angular frequency remains relatively constant over time, and using amplitude and phase as state variables, the equation can be transformed into:
[0043] V(t)=x1*sinωt+x2*cosωt (3)
[0044] Here, x1 = A*cosφ and x2 = A*sinφ are defined as state variables. Assuming there is no additional delay in the system and considering the random noise and small errors introduced by the system, the state equation of the system over a period of time can be expressed as Equation (4).
[0045]
[0046] Equivalent to
[0047]
[0048] in, And w(t) is the process noise. It should be noted that A and φ are both time-invariant components of sine waves and state variables.
[0049] The actual voltage of the current state is obtained using the non-stationary deterministic vector [sinωtcosωt] as the observation matrix, and can be written as Equation (6), where v(t) represents the measurement noise.
[0050]
[0051] Then the state space equation of the voltage signal can be expressed as follows:
[0052]
[0053] in, H=[sinωtcosωt].
[0054] Without loss of generality, consider the following linear dynamical system:
[0055] x(k)=F(k,k-1)x(k-1)+w(k,k-1) (8)
[0056] where k = 1, 2, ... represents a discrete time instant, x(k) is the system state, F(k, k-1) is the corresponding state transition matrix, and w(k, k-1) is a zero-mean Gaussian white noise with covariance satisfying equation (9)
[0057] Q(k,k-1)=E{w(k,k-1)w T (k,k-1)} (9)
[0058] The system state is measured by N sensors, and the measurement equation can be described as
[0059] z i (k)=H i (k)x(k)+v i (k),i=1,2,…,N (10)
[0060] Among them, z i (k) is the measurement value of sensor i, H i (k) is the corresponding measurement matrix, and the measurement noise v i (k)∈R mi The following conditions must be met:
[0061] E{v i (k)}=0 (11)
[0062]
[0063] For the measured value z l (k), l=1,2,…,N, and the measurement update process can be expressed by the following equation:
[0064]
[0065] in,
[0066]
[0067] In the above equation, It is expressed as the estimated state value of the lth node at the kth moment, P l (k|k) is the corresponding estimation error variance, P l (k|k-1) is the corresponding prediction estimation error variance, K is the predicted value of the state of the lth node at the kth moment. l (k) is the Kalman gain corresponding to the kth moment of the lth node.
[0068] When the power system is attacked by false data injection, the measured value will change to
[0069] z a =z+a (15)
[0070] The state estimate will change to
[0071]
[0072] Where a = Hc and c = [c1, c2, ..., c n ] T is an arbitrary non-zero vector.
[0073] The residual test based method will make the residual The L2 norm of is compared with a specific threshold τ. If ||r||2≤τ, the control center believes that the system is in a safe state. The false data injection attack is designed based on this vulnerability. Its proof is as follows:
[0074]
[0075] As long as a-Hc=0 is satisfied, a successful false data injection attack can be launched.
[0076] In the clustering process, the purpose of the fusion center is to combine the state estimates of N nodes at time k Cluster into 2 to N-1 clusters respectively. If N nodes are divided into n (2≤n≤N-2) clusters, then the corresponding C1, C2...Cn are the names of the 1st, 2nd...nth clusters respectively. Figure 2As shown in the figure, first set the initial cluster center corresponding to the number of clusters, then calculate the distance between each local estimate and the average vector of each cluster in the cluster, then find the minimum distance between each local estimate, cluster the local estimates corresponding to the minimum distance into the same cluster, and update the average vector of each cluster at the same time; finally, return and repeat the clustering by updating the average vector between the local estimates until the average value of the average vector of each cluster no longer changes.
[0077] Taking cluster number 3 as an example, the detailed clustering process can be designed as follows:
[0078] Step 1: Establish the initial cluster center corresponding to the number of clusters in advance, and let Wherein, N3 is the largest positive integer not exceeding N3.
[0079] Step 2: Calculate the distance between each local estimate and the average vector of each cluster
[0080]
[0081] Among them, 2 is the norm.
[0082] Step 3: Find the minimum distance between each local estimate calculated in Step 2 and the average vector of each cluster, cluster the corresponding local estimate into the corresponding cluster, and calculate the average vector of each cluster. but l=1,2,…,N。
[0083] Step 4: Recalculate the average vector of each cluster, that is, recalculate the average value of C1, C2, and C3.
[0084]
[0085] in,
[0086] Step 5: Repeat Step 2 to Step 4 until the average value of each cluster no longer changes, and the clustering is completed.
[0087] Then, the clusters containing safe local estimates are fused as local estimates. Here, the local estimate of the cluster where node 1 is located is taken as the safe local estimate, and the other clusters are taken as clusters containing false data.
[0088] Define the local estimate in the security cluster as The corresponding estimation error covariance is P i * (k|k), then the state estimation after fusion and the corresponding estimation error covariance under the minimum mean square error criterion can be expressed as:
[0089]
[0090] After information fusion, the mean absolute errors of the fusion estimated measurements of 2 to N-1 clusters and the true measurements will be compared. The cluster with the smallest mean absolute error is the optimal clustering number, and the corresponding fusion state estimate is the optimal state estimate.
[0091]
[0092] Among them, e n is the average absolute error of measurement at k moments before being divided into 2 to N-1 clusters, z1(k) is the measurement value of safe node 1, is the fusion estimate corresponding to the division into n clusters.
[0093] Furthermore, based on the above method, an embodiment of the present invention also provides a multi-type false data injection attack detection system for the power Internet of Things based on hierarchical clustering, comprising: a filtering update module, a hierarchical clustering module and a fusion evaluation module, wherein:
[0094] A filtering and updating module is used to filter the observation data of N observer nodes in the power Internet of Things using a Kalman filter algorithm and obtain a local estimated value, wherein the observer nodes include known safe sensor nodes and other N-1 normal and / or vulnerable sensor nodes;
[0095] The hierarchical clustering module is used to perform hierarchical clustering of the local estimation values of N observer nodes with different cluster numbers using Euclidean distance as the correlation, and cluster them into 2 to N-1 clusters respectively;
[0096] The fusion evaluation module is used to fuse the data in the cluster where the security sensor node is located under the minimum estimation error covariance criterion to obtain the state estimation value, and obtain the best clustering result by comparing the mean absolute error between the measurement estimation value and the measurement true value under different cluster numbers after fusion. The state estimation value of the best clustering result is used as the credible fusion estimation value.
[0097] To verify the effectiveness of this solution, the following is a further explanation based on experimental data:
[0098] The number of nodes is 9, the step size is 100, node 1 is a safe node, and the initial state of the state variable is The frequency is set to 314 and the process noise is set to The measurement noise is set to 0.001, and the initial error covariance is Take the injection of false data into nodes 2 and 3, and the injection of false data into nodes 8 and 9 as an example to obtain the following results: Figure 3 、 Figure 4The results are shown. 2 nodes and 3 nodes are classified into one category, 4 nodes and 5 nodes are classified into one category, 6 nodes and 7 nodes are classified into one category, and 8 nodes and 9 nodes are classified into one category for false data injection attack. The results are as follows Figure 5 and 6 shown.
[0099] The above experimental data further verified that the solution in this case is based on the observations obtained by the observer where the security node is located. The observation estimation value obtained under the framework of the Kalman filter algorithm is compared with the observation estimation value obtained after cluster fusion, and the mean absolute error is used as the standard for evaluating the quality of clustering. It can shorten the evaluation time and is suitable for application in power Internet of Things security scenarios.
[0100] Unless otherwise specifically stated, the relative steps, numerical expressions and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0101] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0102] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.
[0103] Those skilled in the art will appreciate that all or part of the steps in the above method can be performed by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk, or an optical disk. Alternatively, all or part of the steps in the above embodiment can be implemented using one or more integrated circuits. Accordingly, each module / unit in the above embodiment can be implemented in the form of hardware or software functional modules. The present invention is not limited to any specific combination of hardware and software.
[0104] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed by the present invention, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A multi-class false data injection attack detection method for power Internet of Things based on hierarchical clustering, characterized by: Contains the following content: Step 1: Filter the observation data of N observer nodes in the power Internet of Things using the Kalman filter algorithm and obtain local estimates. The observer nodes include known safe sensor nodes and other N-1 normal and / or vulnerable sensor nodes. The filtering process is expressed as: in, It is expressed as the estimated state value of the i-th node at the k-th moment, P i (k|k) is the corresponding estimation error variance, P i (k|k-1) is the corresponding prediction estimation error variance, It is expressed as the state prediction value of the i-th node at the k-th moment, K i (k) is the Kalman gain corresponding to the kth moment of the i-th node, and I is a unit vector; Step 2: Using Euclidean distance as the correlation, perform hierarchical clustering of the local estimation values of the N observer nodes with different cluster numbers, and cluster them into 2 to N-1 clusters respectively; specifically, the following steps are performed: First, the initial cluster center corresponding to the number of clusters is set, that is, the initial mean vector. Then, the distance between each local estimate and the mean vector of each cluster is calculated. Then, the minimum distance between each local estimate and the mean vector of each cluster is found. The local estimates corresponding to the minimum distance are clustered into the same cluster, and the mean vector of each cluster is updated at the same time. Finally, the clustering is repeated by returning to and updating the mean vector between the local estimates until the average value of the mean vector of each cluster no longer changes. Step 3: The local estimated values within the cluster where the safety sensor node is located are fused under the minimum estimation error covariance criterion to obtain the state fusion estimated value. The best clustering result is obtained by comparing the mean absolute error between the measurement estimated value and the true measurement value under different cluster numbers after fusion. The state estimated value of the best clustering result is used as the credible fusion estimated value. The calculation process of the state fusion estimated value is as follows: The cluster containing the local estimates of known safety sensor nodes is regarded as a safety cluster, and the other clusters are regarded as clusters of false data. The state estimation value in the safety cluster is called a safety local estimation. The estimation error covariance of the safety local estimation is used to fuse the safety local estimation under the minimum mean square error criterion. The state fusion estimation value and the corresponding estimation error covariance are expressed as: represents the secure local estimate, P i * (k|k) represents the estimation error covariance corresponding to the secure local estimate, represents the state fusion estimate of the security cluster under the number of clusters n, represents the estimated error covariance corresponding to the safe cluster under the cluster number n, Cn is the safe cluster under the number of clusters n, and 2≤n≤N-2; The mean absolute error calculation process is expressed as: e n is the mean absolute error in the corresponding cluster at the first k moments of the security cluster under the number of clusters 2 to N-1, z1(m) is the true value of the measurement of the known security sensor node, is the estimated value of the state fusion of the security cluster under the number of clusters n.
2. The multi-class false data injection attack detection method for the power Internet of Things based on hierarchical clustering according to claim 1 is characterized in that: The observation data includes voltage state variables and phase angle state variables of the current phase and amplitude measurement instruments / sensors.
3. The method for detecting multi-class false data injection attacks in the power Internet of Things based on hierarchical clustering according to claim 1 is characterized in that: The observer measurement equation is expressed as: i (k)=H i (k)x(k)+v i (k),i=1,2,…,N,z i (k) represents the measurement value of sensor i, H i (k) represents the corresponding measurement matrix, v i (k) is the measurement noise, x(k)=F(k,k-1)x(k-1)+w(k,k-1), k represents the discrete time instant, x(k) represents the measurement system state, F(k,k-1) represents the state transfer matrix, and w(k,k-1) represents the zero-mean Gaussian white noise and covariance.
4. A multi-class false data injection attack detection system for power Internet of Things based on hierarchical clustering, characterized by: The system is used to implement the multi-class false data injection attack detection method based on hierarchical clustering of the power Internet of Things as described in any one of claims 1 to 3, and comprises: a filtering update module, a hierarchical clustering module and a fusion evaluation module, wherein: A filtering and updating module is used to filter the observation data of N observer nodes in the power Internet of Things using a Kalman filter algorithm and obtain local estimated observation values, wherein the observer nodes include known safe sensor nodes and other N-1 normal and / or vulnerable sensor nodes; The hierarchical clustering module is used to perform hierarchical clustering of the local estimated observation values of N observer nodes with different cluster numbers using Euclidean distance as the correlation, and cluster them into 2 to N-1 clusters respectively; The fusion evaluation module is used to fuse the data in the cluster where the security sensor node is located under the minimum estimation error covariance criterion to obtain the state estimation value, and obtain the best clustering result by comparing the mean absolute error between the measurement estimation value and the measurement true value under different cluster numbers after fusion. The state estimation value of the best clustering result is used as the credible fusion estimation value.
5. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to execute a program stored in a memory and implement the method steps described in any one of claims 1 to 3 when the program is executed.
6. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
Distributed state estimation method based on volume Kalman filtering algorithm
CN110289989A
False data injection attack detection method and system for smart power grid
CN115145790A