A method for predicting network attacks on a heating system in an integrated energy system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SOUTHEAST UNIV
- Filing Date
- 2023-03-20
- Publication Date
- 2026-07-21
Smart Images

Figure CN116436645B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of integrated energy system security, specifically relating to a method for predicting network attacks on heating systems within an integrated energy system. Background Technology
[0002] Humanity's ever-increasing energy consumption and severe environmental problems urgently require the development of a low-carbon, sustainable energy system. Integrated energy systems, as a safe, efficient, clean, and flexible energy system, improve overall energy efficiency and reduce renewable energy consumption through multi-energy complementarity and energy cascade utilization. In engineering applications, integrated energy systems, represented by power-heat coupling systems, improve the flexibility of power system operation, promote wind power absorption, and reduce energy costs, thus receiving increasing attention. Combined heat and power (CHP) energy systems based on CHP units are an important form of CHP energy systems. Natural gas combined cycle CHP units, due to their advantages of small scale, high overall efficiency, and low environmental impact, have long been the main heat source in many urban CHP units in my country.
[0003] Integrated energy systems improve energy efficiency and reduce environmental pollution through the complementary and tiered utilization of multiple energy sources such as electricity, heat, and gas. Advanced information and communication technologies (ICT) play a crucial role in enabling the safe, efficient, clean, and flexible operation of integrated energy systems, promoting deep coupling between information and physical systems. However, the coupling between various energy systems and their supporting information systems increases system complexity and introduces more network-level vulnerabilities, posing greater cybersecurity challenges to the safe and efficient operation of integrated energy systems.
[0004] While there is considerable research on power system cybersecurity, few studies address attacks on integrated energy systems, particularly attacks on heating systems within integrated energy systems. Integrated energy systems are characterized by multi-energy coupling, multiple time scales, and multiple management entities, requiring the coordinated operation of multiple energy systems to form an organic whole. In this context, a failure in one subsystem caused by a cyberattack can spread to other energy systems. According to the "bucket principle," the cybersecurity of an integrated energy system depends on its weakest link. In integrated heat and power systems, compared to the power system, the information technology of the centralized heating system lags behind, making it a weak link in the integrated energy system. How to correctly and reliably analyze and predict cyberattacks on centralized heating systems, thereby facilitating subsequent system detection and recovery, has increasingly become one of the important methods for improving the stability and security of integrated energy systems. Summary of the Invention
[0005] This invention addresses the problems existing in the prior art by providing a method for predicting network attacks on heating systems within an integrated energy system. First, it identifies network attack targets for the centralized heating system and establishes a network attack model. These targets include indoor temperature and secondary-side water supply temperature at the heat exchange station, as well as indoor temperature setpoint attacks, indoor temperature delay scaling attacks, and secondary heating network water supply temperature ramp attacks. Next, it establishes a predictive model for network attacks on the heating system. This prediction method includes rolling optimization scheduling and simulation analysis prediction of the integrated energy system. First, rolling economic scheduling of the integrated energy system is performed to obtain the results of economic scheduling under safety constraints under normal conditions. Then, parameters from two time periods of the rolling economic scheduling are selected for simulation analysis and prediction of network attacks. Finally, based on the model results, predictive analysis is conducted to predict the impact of network attacks on the centralized heating system on the security, user comfort, and economy of the integrated electric-thermal energy system, guiding the identification, detection, and defense of attack types.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is: a method for predicting network attacks on heating systems in an integrated energy system, comprising the following steps:
[0007] S1, Identify the network attack targets of the centralized heating system and establish a network attack model for the centralized heating system: The network attack targets include the indoor temperature of the centralized heating system and the secondary side water supply temperature of the heat exchange station; the indoor temperature setpoint attack, the indoor temperature delay scaling attack, and the secondary heating network water supply temperature ramp attack.
[0008] S2, Establish a prediction model for network attacks on the heating system: The prediction method includes rolling optimization scheduling and simulation analysis prediction of the integrated energy system; first, rolling economic scheduling of the integrated energy system is performed to obtain the results of economic scheduling of the integrated energy system under safety constraints under normal conditions, and then parameters of two time periods of rolling economic scheduling are selected for simulation analysis prediction of network attacks.
[0009] S3, Predictive Analysis: By comparing the differences between the simulation analysis parameters obtained in step S2 and the parameters of normal system operation, predict the network attack status and impact of the integrated energy system. The parameters include at least the aggregated indoor temperature, CHP unit status, heat exchange station water supply temperature, and power system line load.
[0010] As an improvement of the present invention, in step S1, the indoor temperature setpoint attack is achieved by tampering with the mismatch between the indoor temperature and the indoor setpoint temperature, causing the heating system to continuously provide mismatched heat power to the heat load. The indoor temperature setpoint attack model is as follows:
[0011]
[0012] In the formula, Let t be the normal indoor temperature at time t. λ represents the indoor temperature of the heating system after the attack. a1 For attack parameters, Γ a Let t0 be the set of attack times, where t0 is the start time of the attack. This is a delay term for the attack.
[0013] As an improvement to the present invention, in step S1, the indoor temperature delay scaling attack targets the indoor temperature of the centralized heating system, tracks the measured value of the indoor temperature during the attack period, and performs a scaling attack. The indoor temperature delay scaling attack model is as follows:
[0014]
[0015] In the formula, Let t be the normal indoor temperature at time t. λ represents the indoor temperature of the heating system after the attack. a2 For attack parameters, Γ a For the time set of the attack, This is a delay term for the attack.
[0016] As another improvement of the present invention, in step S1, the secondary heating network water supply temperature ramp attack targets the set value of the secondary side water supply temperature of the heat exchange station. This attack involves tampering with the set value of the water supply temperature issued by the dispatch center to the heat exchange station, causing a mismatch between the heat power supplied to the heat load and the heat demand. The secondary heating network water supply temperature ramp attack model is as follows:
[0017]
[0018] In the formula, The setpoint for the secondary water supply temperature of the heat exchange station when it is not under attack. λ is the setpoint for the secondary water supply temperature of the heat exchange station after an attack. a3 For attack parameters, Γ a This refers to the time set of the attack.
[0019] As another improvement of the present invention, in step S2, the simulation analysis and prediction of network attacks includes a physical model and a scheduling model. The physical model includes at least a heat exchange station model, a building model, and an indoor heat exchanger model.
[0020] The specific model of the heat exchange station is as follows:
[0021]
[0022]
[0023] In the formula, m p,1 and m p,2 The mass flow rates of the primary and secondary heating networks are denoted as m. ex The mass flow rate of the heating network entering the primary side of the corresponding heat exchange station; m ot The mass flow rate of the heating network that does not enter the primary side of the heat exchange station; The supply and return water temperatures of the primary heating network; The primary return water temperature of the heat exchange station; h ex A heat exchange station for a heat exchange station; e / k e This refers to the overall heat exchange area and overall heat transfer coefficient of the heat exchange station; For the supply and return water temperatures of the secondary heating network; τ ave This represents the average temperature of the heat exchangers in the heat exchange station.
[0024] The building and indoor heat exchanger models are as follows:
[0025]
[0026]
[0027]
[0028]
[0029] In the formula, Let t be the heat load of the building at time t; Let t be the indoor temperature of the building at the load point; R represents the ambient temperature outside the building at time t; eq / C eq The equivalent heat capacity and equivalent thermal resistance of the building's heat load; Δt is the calculation time interval; A r / k r This refers to the combined heat transfer area and combined heat transfer coefficient of the indoor heat exchanger.
[0030] As another improvement of the present invention, in step S2, the scheduling model for simulation analysis and prediction of network attacks includes at least a hot network model, which adopts a node-based model, specifically:
[0031]
[0032]
[0033] In the formula, These are the inlet and outlet water temperatures p of the water supply pipeline, respectively. The inlet / outlet water temperatures p of the return water pipe are respectively; The water temperature at node j in the supply / return water pipeline; Π PA collection of heating pipes; The set of pipes flowing into node k; The sum of the pipes flowing out of node k; Φ in Φ is the set of intersecting nodes of the pipelines; ln The set of hot-load nodes; Φ sn The set of heat source nodes; ρ w ,c w For the density and specific heat capacity of water; γ p ,R p ,δ p ,ξ p For the pipeline's time delay and heat loss parameters; λ j , l p For heat transfer coefficient, pipe cross-sectional area, and pipe length; This refers to the mass flow rate of the pipeline.
[0034] As a further improvement of the present invention, the objective function in the rolling optimization scheduling and simulation analysis prediction of the integrated energy system in step S2 is:
[0035]
[0036]
[0037] In the formula, For the operating costs of combined heat and power units; c ot Cost of generating electricity per unit of power; This refers to the electrical power of units other than combined heat and power (CHP) units. and This refers to the electrical and thermal power of a combined heat and power (CHP) unit.
[0038] Compared with the prior art, the present invention has the following advantages:
[0039] Advantage (1) Among the existing research and publicly available technologies, there are no technologies or methods for predicting and analyzing the propagation of attacks on thermal systems in integrated energy systems throughout the entire integrated system. We are the first to propose a technical solution and framework for this type of problem.
[0040] Advantage (2) This invention achieves system prediction and impact analysis of attacks on the thermal system in a comprehensive energy system through a complete framework of optimization scheduling and simulation analysis. First, a rolling optimization scheduling process considering the quasi-dynamic process of the thermal system is carried out. This process fully simulates the behavior of the system under normal operating conditions in terms of the rolling scheduling cycle, model, and operation method. At the same time, because the quasi-dynamic process is considered, it can reflect parameters such as the unit status and the temperature distribution of the heating network under normal conditions over a period of time.
[0041] Advantage (3): In the simulation analysis method described in this invention, we use parameters such as the unit status of the system under normal conditions over a period of time and the pipeline temperature distribution of the heating network over a period of time as the initial values for the simulation. Unlike the arbitrary setting of initial values in traditional simulation analysis, this method of obtaining initial values enhances the accuracy of the simulation analysis. In addition, we further reduce the simulation step size and increase the simulation precision in the simulation analysis. In the simulation, we simulate the propagation mechanism and fluctuation of the thermal system from heat load, heat exchange station, heating network, heat source, and power grid under attack conditions, predict the load changes of the system and the overload of power system lines, source-side output, etc., and thus guide the system's response operation under network attack.
[0042] Advantage (4): In our method for network attacks on thermal systems, we simulated three typical types of network attacks on thermal systems, including attacks targeting the room temperature of the polymer and the secondary side supply water temperature of the heat exchange station. By simulating multiple attack problems, we increase the predictive ability of our proposed method for the impact of network attacks. Attached Figure Description
[0043] Figure 1 This is a diagram of the integrated energy system structure, which represents the implementation environment of the method of this invention.
[0044] Figure 2 This is a control flowchart for determining the network attack target in step S1 of the method of the present invention;
[0045] Figure 3 This is a time planning diagram of the joint rolling optimization scheduling and simulation in step S2 of the method of the present invention;
[0046] Figure 4 This is a diagram illustrating the impact of an indoor temperature setpoint attack on indoor temperature, heat load, combined heat and power unit, and power line load in Embodiment 1 of the present invention.
[0047] Figure 5 This is a diagram illustrating the impact of the indoor temperature setpoint attack method in Embodiment 1 of the present invention on indoor temperature, heat load, combined heat and power unit and power line load.
[0048] Figure 6 This is a diagram illustrating the impact of the indoor temperature delay scaling attack method in Embodiment 1 of the present invention on indoor temperature, heat load, combined heat and power unit and power line load.
[0049] Figure 7 This is a flowchart of the steps of the method of the present invention. Detailed Implementation
[0050] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are for illustrative purposes only and are not intended to limit the scope of the invention.
[0051] Example 1
[0052] A method for predicting network attacks on heating systems in integrated energy systems. The application environment of this method is as follows: Figure 1 As shown, Figure 1 This is a structural diagram of the integrated energy system used in this embodiment. The heating system includes 2 source nodes and 3 load nodes, and the power system includes 2 PQ nodes and 2 generator sets. Node 5 in the heating system is connected to bus 3 in the power system to a condensing cogeneration unit (CHP1), which also serves as the balancing node of the heating network. Node 4 in the heating system corresponds to bus 4 in the power system and is a back-pressure cogeneration unit (CHP2), serving as the balancing node of the power system.
[0053] This embodiment presents a method for predicting network attacks on heating systems within an integrated energy system, such as... Figure 7 As shown, it includes the following steps:
[0054] S1. Identify the network attack targets of the centralized heating system and establish a network attack model for the centralized heating system:
[0055] Methods for predicting and controlling heat load in centralized heating systems include methods based on historical data, methods based on comprehensive outdoor temperature, and methods based on indoor temperature. The method of this invention uses indoor temperature feedback control as the heat load control method in the centralized heating system, and its process is as follows: Figure 2 As shown, the specific description is as follows:
[0056] First, SCADA obtains the initial set value of the secondary side water supply temperature of the heat exchange station based on the comprehensive outdoor temperature and historical heating parameters. Then, it compares the actual value of the indoor temperature of the building with the set value of the indoor temperature. The temperature difference is used to correct and calculate the set value of the secondary side water supply temperature of the heat exchange station for the next moment. The set value of the secondary side water supply temperature of the heat exchange station is transmitted to the heat exchange station through the network to guide the local controller of the heat exchange station.
[0057] Based on the control methods and processes of centralized heating systems, two weak links and feasible attack locations in the network security of centralized heating systems can be identified: the actual indoor temperature uploaded by users to the SCADA control center, and the set value of the secondary side water supply temperature issued by the SCADA control center to the heat exchange station.
[0058] Therefore, a network attack model for centralized heating systems is established. This model includes three attack methods and models: indoor temperature setpoint attack, indoor temperature delay scaling attack, and secondary heating network water supply temperature ramp attack, as detailed below.
[0059] Indoor temperature setpoint attack: An indoor temperature setpoint attack manipulates the mismatch between the indoor temperature and the indoor setpoint temperature, causing the heating system to continuously supply mismatched heat power to the heat load. The model is as follows:
[0060]
[0061] In the formula, Let t be the normal indoor temperature at time t. λ represents the indoor temperature of the heating system after the attack. a1 For attack parameters, Γ a Let t0 be the set of attack times, where t0 is the start time of the attack. The delay term is introduced to prevent abrupt temperature changes after an attack. Because thermal systems have thermal inertia and thermal delay characteristics, cyberattacks on thermal systems cannot cause abrupt changes in the system's parameters; otherwise, they would be easily detected by experienced operators.
[0062] Indoor Temperature Delay Scaling Attack: This attack targets the indoor temperature of a centralized heating system, tracking the measured indoor temperature during the attack period and scaling the measured value. The model is as follows:
[0063]
[0064] In the formula, Let t be the normal indoor temperature at time t. λ represents the indoor temperature of the heating system after the attack. a2 For attack parameters, Γ a For the time set of the attack, This is a delay term for the attack.
[0065] Secondary heating network water supply temperature ramp attack: The secondary heating network water supply temperature ramp attack targets the set value of the secondary side water supply temperature of the heat exchange station. By tampering with the set value of the water supply temperature issued by the dispatch center to the heat exchange station, the heat power supplied to the heat load is mismatched with the heat demand.
[0066]
[0067] In the formula, The setpoint for the secondary water supply temperature of the heat exchange station when it is not under attack. λ is the setpoint for the secondary water supply temperature of the heat exchange station after an attack. a3 For attack parameters, Γ a This refers to the time set of the attack.
[0068] Step S2 establishes a predictive model for network attacks on the heating system: the prediction method includes integrated rolling optimization scheduling of the energy system and simulation analysis prediction. Figure 3 As shown, rolling economic scheduling of the integrated energy system is first performed to obtain the results of the economic scheduling of the integrated energy system under the safety constraints under normal conditions. Then, parameters of two time periods of rolling economic scheduling are selected for simulation analysis and prediction of network attacks.
[0069] The simulation analysis method mentioned in step S2 first uses the unit state and other parameters of one or several steps of rolling optimization scheduling as the initial values for simulation analysis. Then, it injects a predetermined network attack into the thermal system in the early stage to predict the propagation mechanism and impact of the network attack on the integrated energy system. The simulation analysis method adopted uses a small step size and quasi-dynamic analysis method, specifically considering the thermal inertia of the thermal system and the delay of thermal attacks.
[0070] Specifically, firstly, rolling economic scheduling of the integrated energy system is performed. In this embodiment, the total duration of rolling economic scheduling is 24 hours, with each rolling cycle lasting 4 hours and a scheduling step size of 15 minutes. Through rolling economic scheduling, the results of economic scheduling of the integrated energy system under safety constraints under normal conditions are obtained, including parameters such as the output and heat-to-power ratio of the cogeneration unit, indoor temperature, heat load, and operating costs. Then, parameters from two time periods of rolling economic scheduling are selected for simulation analysis of network attacks. In this embodiment, the total duration of the simulation analysis is 15 minutes or 30 minutes, with a simulation step size of 1 minute. The impact of the proposed network attack method on the integrated energy system is analyzed through simulation.
[0071] Simulation analysis and prediction of network attacks include physical models and scheduling models.
[0072] The heating network model adopts a nodal method model, as detailed below:
[0073]
[0074]
[0075] In the formula, These are the inlet and outlet water temperatures p of the water supply pipeline, respectively. The inlet / outlet water temperatures p of the return water pipe are respectively; The water temperature at node j in the supply / return water pipeline; ∏ P A collection of heating pipes; The set of pipes flowing into node k; The sum of the pipes flowing out of node k; Φ in Φ is the set of intersecting nodes of the pipelines; ln The set of hot-load nodes; Φ snThe set of heat source nodes; ρ w ,c w For the density and specific heat capacity of water; γ p ,R p ,δ p ,ξ p For the pipeline's time delay and heat loss parameters; λ j , l p For heat transfer coefficient, pipe cross-sectional area, and pipe length; This refers to the mass flow rate of the pipeline.
[0076] The specific model of the heat exchange station is as follows:
[0077]
[0078]
[0079] In the formula, m p,1 and m p,2 The mass flow rates of the primary and secondary heating networks are denoted as m. ex The mass flow rate of the heating network entering the primary side of the corresponding heat exchange station; m ot The mass flow rate of the heating network that does not enter the primary side of the heat exchange station; The supply and return water temperatures of the primary heating network; The primary return water temperature of the heat exchange station; h ex A heat exchange station for a heat exchange station; e / k e This refers to the overall heat exchange area and overall heat transfer coefficient of the heat exchange station; For the supply and return water temperatures of the secondary heating network; τ ave This represents the average temperature of the heat exchangers in the heat exchange station.
[0080] The building and indoor heat exchanger models are as follows:
[0081]
[0082]
[0083]
[0084]
[0085] In the formula, Let t be the heat load of the building at time t; Let t be the indoor temperature of the building at the load point; R represents the ambient temperature outside the building at time t; eq / C eqThe equivalent heat capacity and equivalent thermal resistance of the building's heat load; Δt is the calculation time interval; A r / k r This refers to the combined heat transfer area and combined heat transfer coefficient of the indoor heat exchanger.
[0086] The objective function for the rolling optimization scheduling involved in the joint simulation analysis and prediction is:
[0087]
[0088]
[0089] In the formula, For the operating costs of combined heat and power units; c ot Cost of generating electricity per unit of power; This refers to the electrical power of units other than combined heat and power (CHP) units. and For the electrical and thermal power of a combined heat and power unit;
[0090] The constraints involved in the joint simulation analysis and prediction of rolling optimization scheduling include power system constraints, such as power balance constraints, operating domain constraints, ramping constraints, and line capacity limitations, as well as the node temperature mixing equations, heat and power balance equations, and network topology equations for the heating system.
[0091]
[0092]
[0093]
[0094]
[0095]
[0096]
[0097]
[0098]
[0099]
[0100] In the formula, These are the electrical power of a combined heat and power (CHP) unit and the electrical power of a conventional generator unit, respectively. Let t be the electrical power demand of load i during time period t; For 0-1 variables, if the generator set is operating normally, It is 1 if it is true, otherwise it is 0; Maximum / minimum generating capacity of conventional generator sets; Ru i / Rd i The uphill / downhill climbing ability of generator set i; ∏ OT A collection of conventional generator sets; Π chp A collection of combined heat and power (CHP) units; These are the inlet and outlet water temperatures p of the water supply pipeline, respectively. The inlet / outlet water temperatures p of the return water pipe are respectively; The temperature of the primary heating network's supply / return water pipes; The set of pipes flowing into the node; The sum of the pipes flowing out of the node; Φ in Φ is the set of intersecting nodes of the pipelines; ln The set of hot-load nodes; Φ sn A set of heat source nodes; The mass flow rate of the pipeline; The water supply temperature for the secondary heating network nodes; This sets the upper and lower limits for the water supply temperature of the secondary heating network. This is to limit the ramp-up of water supply temperature in the secondary heating network.
[0101]
[0102]
[0103] The two constraints mentioned above are limitations on the water supply temperature of the secondary heating network.
[0104] Step S3, Predictive Analysis: Based on the model results from Step S2, perform predictive analysis.
[0105] Based on the network attack method and simulation analysis steps for the centralized heating system in the integrated energy system of this embodiment, the changes in indoor temperature, heat load, cogeneration unit output, and power system line load of the integrated energy system under an indoor temperature setpoint attack are as follows: Figure 4 As shown; the changes in indoor temperature, heat load, cogeneration unit output, and power system line load of the integrated energy system under an indoor temperature delay scaling attack are as follows: Figure 5 As shown; the changes in indoor temperature, heat load, cogeneration unit output, and power system line load of the integrated energy system under the influence of a secondary heating network water supply temperature ramp attack are as follows: Figure 6 As shown.
[0106] Figure 4 (a)(b)- Figure 6(a) and (b) describe the fluctuations in indoor temperature and heat load of the centralized heating system under the three attacks described in this embodiment. The dashed line represents the indoor temperature without attack, which remains at 21°C. It can be observed that both indoor temperature and heat load increase, and the fluctuations in room temperature lead to a mismatch with the comfort temperature of heat users, affecting their thermal comfort.
[0107] Figure 4 (c)- Figure 6 (c) describes the fluctuations in thermal and electrical power output of the cogeneration units after the attack. It can be seen that the thermal and electrical outputs of both cogeneration units fluctuated significantly within two time intervals (10-15 minutes and 23-27 minutes). However, the abnormal fluctuations in CHP output did not occur immediately after the attack. This phenomenon can be explained by two characteristics of the integrated energy system and the cogeneration units: the delayed characteristics of the heating network and the electro-thermal coupling characteristics of the integrated energy system. The attack occurred under heat load, and due to the delayed characteristics of the heating network, it took some time for the load to transfer to the corresponding cogeneration units. When the heat load fluctuation caused by the attack was transmitted to the first cogeneration unit, the thermal power output of the cogeneration unit increased accordingly, while its electrical power output decreased accordingly because the cogeneration unit is an extraction condensing unit. To ensure the normal operation of the power system, the second cogeneration unit, as a power balancing node, had to increase its power output to meet real-time power balance. In general, when the heating system is attacked, the system power will also fluctuate within a wide range. By leveraging the coupling characteristics of integrated energy systems, cyberattacks on centralized heating systems can impact the operation of the power system.
[0108] Figure 4 (d)- Figure 6 (d) describes the changes in power system line loads under three types of attacks, where P 12 P 13 P 24 The figures represent the loads of lines 12, 13, and 24, respectively. It is clear that the three types of attacks can cause power system lines to be overloaded, affecting the safety of the power system.
[0109] Table 1. Impact of Three Types of Cyberattacks on the Economy of Integrated Energy Systems
[0110]
[0111]
[0112] Table 1 shows the economic impact of three types of cyberattacks on the operation of the integrated energy system. It can be seen that the cyberattack prediction method for centralized heating systems proposed in this invention has a significant impact on the economics of the integrated energy system, ranging from 10.11% to 18.44%.
[0113] In summary, the method for predicting network attacks on heating systems in integrated energy systems proposed in this invention can effectively reflect the user comfort, system operation economy, and security of integrated energy systems, thereby guiding the identification, detection, and defense of attack types.
[0114] It should be noted that the above content merely illustrates the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. For those skilled in the art, various improvements and modifications can be made without departing from the principle of the present invention, and all such improvements and modifications fall within the scope of protection of the claims of the present invention.
Claims
1. A method for predicting network attacks on heating systems in an integrated energy system, characterized in that, Includes the following steps: S1, Identify the network attack targets of the centralized heating system and establish a network attack model for the centralized heating system: The network attack targets include the indoor temperature of the centralized heating system and the secondary side water supply temperature of the heat exchange station; the indoor temperature setpoint attack, the indoor temperature delay scaling attack, and the secondary heating network water supply temperature ramp attack. S2, Establish a prediction method for network attacks on heating systems: The prediction method includes rolling optimization scheduling and simulation analysis prediction of the integrated energy system; firstly, rolling economic scheduling of the integrated energy system is performed to obtain the results of economic scheduling of the integrated energy system under safety constraints under normal conditions; then, parameters from two time periods of rolling economic scheduling are selected for simulation analysis prediction of network attacks; the objective function in the rolling optimization scheduling and simulation analysis prediction of the integrated energy system is: In the formula, For the operating costs of combined heat and power units; Cost of generating electricity per unit of power; This refers to the electrical power of units other than combined heat and power (CHP) units. and For the electrical and thermal power of a combined heat and power unit; The constraints involved in the joint simulation analysis and prediction of rolling optimization scheduling include power system constraints, including power balance constraints, operating domain constraints, ramping constraints, and line capacity limitations, as well as the node temperature mixing equation, heat power balance equation, and network topology equation for the heating system. S3, Predictive Analysis: By comparing the differences between the simulation analysis parameters obtained in step S2 and the parameters of normal system operation, predict the network attack status and impact of the integrated energy system. The parameters include at least the aggregated indoor temperature, CHP unit status, heat exchange station water supply temperature, and power system line load.
2. The method for predicting network attacks on heating systems in an integrated energy system according to claim 1, characterized in that, In step S1, the indoor temperature setpoint attack is achieved by tampering with the mismatch between the indoor temperature and the indoor setpoint temperature, causing the heating system to continuously supply mismatched heat power to the heat load. The indoor temperature setpoint attack model is as follows: In the formula, Let t be the normal indoor temperature at time t. The indoor temperature of the heating system after the attack. For attack parameters, For the time set of the attack, The moment to begin the attack. This is a delay term for the attack.
3. The method for predicting network attacks on heating systems in an integrated energy system as described in claim 2, characterized in that: In step S1, the indoor temperature delay scaling attack targets the indoor temperature of the centralized heating system. It tracks the measured indoor temperature during the attack period and performs a scaling attack. The indoor temperature delay scaling attack model is as follows: In the formula, Let t be the normal indoor temperature at time t. The indoor temperature of the heating system after the attack. For attack parameters, For the time set of the attack, This is a delay term for the attack.
4. A method for predicting network attacks on heating systems in an integrated energy system as described in claim 1, 2, or 3, characterized in that: In step S1, the secondary heating network water supply temperature ramp attack targets the setpoint of the secondary side water supply temperature of the heat exchange station. It modifies the setpoint of the water supply temperature issued by the dispatch center to the heat exchange station, causing a mismatch between the heat power supplied to the heat load and the heat demand. The secondary heating network water supply temperature ramp attack model is as follows: In the formula, The setpoint for the secondary water supply temperature of the heat exchange station when it is not under attack. This is the setpoint for the secondary water supply temperature of the heat exchange station after an attack. For attack parameters, This refers to the time set of the attack.
5. The method for predicting network attacks on heating systems in an integrated energy system as described in claim 4, characterized in that: In step S2, the simulation analysis and prediction of network attacks includes a physical model and a scheduling model. The physical model includes at least a heat exchange station model, a building model, and an indoor heat exchanger model. The specific model of the heat exchange station is as follows: In the formula, and The mass flow rates of the primary and secondary heating networks are denoted as . The mass flow rate of the heating network entering the primary side of the corresponding heat exchange station; The mass flow rate of the heating network that does not enter the primary side of the heat exchange station; The supply and return water temperatures of the primary heating network; This refers to the primary return water temperature of the heat exchange station. For heat exchange stations; This refers to the overall heat exchange area and overall heat transfer coefficient of the heat exchange station; For the supply and return water temperatures of the secondary heating network; This represents the average temperature of the heat exchangers in the heat exchange station. The building and indoor heat exchanger models are as follows: In the formula, Let t be the heat load of the building at time t; Let t be the indoor temperature of the building at the load location; Let t be the ambient temperature outside the building. The equivalent thermal resistance and equivalent thermal flux of the building's heat load; To calculate the time interval; This refers to the combined heat transfer area and combined heat transfer coefficient of the indoor heat exchanger.
6. The method for predicting network attacks on heating systems in an integrated energy system as described in claim 5, characterized in that, The scheduling model for the simulation analysis and prediction of the network attack includes at least a hot network model, which adopts a node-based model, specifically: In the formula, These are the inlet and outlet water temperatures p of the water supply pipeline, respectively. The inlet / outlet water temperatures p of the return water pipe are respectively; The water temperature at node j in the supply / return water pipeline; A collection of heating pipes; , These are the density and specific heat capacity of water; These are the delay parameters and heat loss parameters for the pipeline; For heat transfer coefficient, pipe cross-sectional area, and pipe length; This refers to the mass flow rate of the pipeline.