Distributed smart grid false data injection attack method and device, medium

By acquiring local sensor values ​​and neighbor state estimates through distributed estimator nodes, and using a chi-square detector to detect and construct a covert attack vector to inject false data, this technology solves the problem of false data injection attacks in multi-regional distributed smart grids that cannot be dealt with in existing technologies, and achieves global covert attack and state estimation deviation.

CN116668090BActive Publication Date: 2025-11-07NORTHEASTERN UNIV CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310533191.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-11
Publication Date
2025-11-07
Estimated Expiration
2043-05-11

AI Technical Summary

Technical Problem

Existing methods for injecting fake data mainly target centralized estimation systems and cannot effectively address distributed smart grid systems in multiple regions. Furthermore, existing detection methods struggle to detect distributed fake data injection attacks.

Method used

The system obtains local sensor values ​​and neighbor state estimates through distributed estimator nodes, calculates state estimates, and uses a chi-square detector to detect attacks. It then constructs a covert attack vector and injects fake data to achieve a global covert attack.

Benefits of technology

It achieves a global covert attack on each estimator node in the distributed smart grid, avoiding detection by the chi-square detector, which would cause the state estimate to deviate from the true value and disrupt the state estimation of the distributed smart grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668090B_ABST
    Figure CN116668090B_ABST
Patent Text Reader

Abstract

The application discloses a false data injection attack method for a distributed smart grid, relates to the field of smart grid security state estimation, and mainly aims to inject false data into a data channel of part of nodes of a distributed state estimator of the smart grid, so that a state estimation value of an attacked node deviates from a real state value of the smart grid system, and the estimation system is damaged without causing any node detector to trigger an alarm. The method comprises the following steps: each distributed estimator node in the smart grid acquires a value of a local sensor and a neighbor state estimation value; each distributed estimator node calculates a state estimation value at a next moment according to the value of the local sensor and the neighbor state estimation value; a neighbor state estimation value received is detected by a chi-square detector, and a distributed estimator node with attack detection capability is constructed; and an attack signal is injected into a data exchange channel. The application is suitable for attack and defense of distributed state estimator nodes in the smart grid.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of state estimation and information security in smart grid, and particularly relates to a distributed smart grid false data injection attack method and device and medium. BACKGROUND

[0002] With the development of science and technology, the traditional power system is combined with the Internet network information to form a smart grid with physical layer and network layer connected to each other. With the continuous increase of power equipment, the smart grid gradually tends to a multi-area power supply mode. In order to let each area get the power grid information of other areas, each area needs to perform a state estimation process on the entire power grid system. State estimation is a process of estimating the real-time state of the entire system by using the measurement information of the system. State estimation is divided into centralized and distributed forms according to the information topology structure. Centralized state estimation means that all sensor measurement information is output to the information center, and the information center performs information fusion and data calculation to finally obtain all system state information. At present, most of the state grids in China adopt this topology structure. With the implementation of the "14th Five-Year Plan" of China, the distributed power grid integrating new energy and other distributed power sources and loads develops rapidly to form a distributed smart grid, and the estimation method also changes from centralized to distributed form. Compared with the centralized estimation method, the distributed state estimation is more suitable for the distributed smart grid system with large amount of calculation and wide distribution range.

[0003] Due to the access of the Internet, the physical equipment in the smart grid is more vulnerable to attacks from the network. Among them, the false data injection attack is the current research hotspot and is more harmful to the smart grid. At present, most of the literature mainly studies the false data injection attack of the centralized estimation system with a single detector, which is obviously not applicable to the multi-area smart grid system. SUMMARY

[0004] Therefore, the present application provides a distributed smart grid false data injection attack method, which mainly aims to analyze the conditions of the smart grid system and the distributed estimator nodes, find out the attack vectors that can avoid detection by the chi-square detector, and inject them into the communication channel of the distributed estimator nodes, so that the estimated value of the distributed estimator deviates from the true value of the system and cannot be found by the chi-square detector of all distributed estimator nodes, thereby realizing the global covert attack on each distributed estimator node in the smart grid.

[0005] According to one aspect of the present application, a distributed smart grid false data injection attack method is provided, which comprises:

[0006] Step one, each distributed estimator node in the smart grid obtains the value of the local sensor and the neighbor state estimation value;

[0007] Step two, according to the obtained values of the local sensor and the neighbor state estimation value, each distributed estimator node calculates the state estimation value at the next time;

[0008] Step three, the received neighbor state estimation value is detected by a chi-square detector, and a distributed estimator node with attack detection capability is constructed;

[0009] Step four, according to the observation matrix corresponding to each distributed estimator node, a stealthy attack vector is calculated;

[0010] Step five, by injecting false data through the data exchange channel between each distributed estimator node, a global stealthy attack on each distributed estimator node is realized.

[0011] Optionally, the step one comprises: respectively configuring a sensor meeting the joint observability condition corresponding to each distributed estimator node, and jointly measuring through all the sensors corresponding to the distributed estimator nodes to obtain the measurement information corresponding to the smart grid system, represented by the following equation:

[0012] y i (k) = C i x(k) + v i (k), i = 1, …, N

[0013] Wherein, there are N distributed estimator nodes, representing the m i dimensional measurement information of node i at time k, is the observation matrix of the sensor of distributed estimator node i, v i (k) represents the measurement noise of distributed estimator node i at time k, and the statistical characteristics thereof satisfy the Gaussian distribution v i ~ N(0, R), R is the measurement noise covariance matrix.

[0014] Optionally, the step two and the step three comprise:

[0015] The data residual transmitted from the neighbor distributed estimator node j to the local distributed estimator node i is calculated The calculation formula is:

[0016]

[0017] Wherein, y i (k) is the measurement value of the sensor corresponding to the local distributed estimator node i at the current time k, C i is the observation matrix of the local distributed estimator node i, The estimated state of the attacked state from neighboring distributed estimator node j to local distributed estimator node i at time k.

[0018] Calculate the detection value D of the neighbor state estimates from the neighbor distributed estimator node j to the local distributed estimator node i. ij (k), its calculation formula is:

[0019]

[0020] in, This represents the change in expression from time k-r+1 to time k. Perform a summation operation, where r represents the length of the detection time window. Σ represents the residual signal of the attacked data from neighboring distributed estimator node j to local distributed estimator node i at time l. ij This is the covariance of the neighbor residuals when not under attack, mainly used for normalizing the received data. (·) T This indicates that the data is transposed, (·)- 1 This indicates that the data is inverted, and δ is the detection threshold used to determine whether the current data has been attacked. The appropriate value can be selected by referring to the chi-square distribution table. If the detection value is less than the detection threshold, it is H0 and the data has not been attacked; otherwise, it is H1 and the data has been attacked.

[0021] Each distributed estimator node with the added defense mechanism discards the received attacked data and uses the received unattacked data to perform state estimation. The iterative formula for estimating the state of its local distributed estimator node i is as follows:

[0022]

[0023] in, and These are the state estimates of whether the local distributed estimator node i has been attacked at time k+1 and time k, respectively. Let A be the state estimation information (whether it has been attacked or not) transmitted from neighboring distributed estimator node j to local distributed estimator node i. Let K be the matrix of the smart grid system. i (k) Local residual gain coefficient, where ε is the consensus term gain coefficient. This represents all neighboring local distributed estimator nodes of local distributed estimator node i. Perform a summation operation, γ ij (k) represents the detection result of the chi-square detector from neighboring distributed estimator node j to local distributed estimator node i.

[0024] Optionally, the step four comprises: calculating a stealthy attack vector a from the neighbor distributed estimator node j to the local distributed estimator node i ij The method of (k) comprises:

[0025] Finding homogeneous linear equations C i a ij The solution space of (k) = 0 is span{u ij ,1,...,u ij,p},

[0026] Wherein, the solution space is composed of p bases, and the expression of the attack vector is set as:

[0027] a ij (k) = a1(k)u ij,1 +... + a p (k)u ij,p ,

[0028] Wherein, a1(k),...,a p (k) are real numbers set by the attacker, not all of which are zero;

[0029] The attack vector obtained is injected into the data communication channel from the neighbor distributed estimator node j to the local distributed estimator node i, and the attacked data is obtained:

[0030]

[0031] Wherein, represents the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i at k time, whether the data is attacked or not.

[0032] Optionally, the step five comprises: replacing the data transmitted from the local distributed estimator node i to the neighbor distributed estimator node j with the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i.

[0033] According to another aspect of the present application, a distributed smart grid false data injection attack device is provided, and the device comprises:

[0034] An acquisition module is configured to acquire a local sensor value and a neighbor state estimation value of each distributed estimator node in a smart grid;

[0035] A first calculation module is configured to calculate a state estimation value at a next time according to the acquired local sensor value and the neighbor state estimation value by each distributed estimator node;

[0036] The detection module is configured to detect the received neighbor state estimation value by using a chi-square detector, and construct a distributed estimator node with attack detection capability.

[0037] The second calculation module is configured to calculate a stealthy attack vector according to an observation matrix corresponding to each distributed estimator node.

[0038] The injection module is configured to inject false data through a data exchange channel between each distributed estimator node, so as to implement a global stealthy attack on each distributed estimator node.

[0039] Optionally, the acquisition module is further configured to:

[0040] A sensor meeting a joint observability condition is configured at each distributed estimator node, and measurement information corresponding to the smart grid system is obtained by joint measurement of sensors corresponding to all distributed estimator nodes, and the measurement information is represented by the following equation:

[0041] y i (k) = C i x(k) + v i (k), i = 1,..., N

[0042] wherein there are N distributed estimator nodes, represents m i dimensional measurement information of node i at time k, is an observation matrix of the sensor of the distributed estimator node i. v i (k) represents measurement noise of the distributed estimator node i at time k, and the statistical characteristics of the measurement noise satisfy v i ~ N(0, R), R is a measurement noise covariance matrix.

[0043] Optionally, the first calculation module and the detection module are further configured to:

[0044] The data residual transmitted from the neighbor distributed estimator node j to the local distributed estimator node i is calculated as The calculation formula is as follows:

[0045]

[0046] wherein y i (k) is a measurement value of the sensor corresponding to the local distributed estimator node i at the current time k, C i is an observation matrix of the local distributed estimator node i, is an attacked state estimation value from the neighbor distributed estimator node j to the local distributed estimator node i at the current time k; and

[0047] calculating a detection value D of a neighbor state estimation value from the neighbor distributed estimator node j to the local distributed estimator node i ij (k), the calculation formula of which is:

[0048]

[0049] wherein, denotes a summation operation on the formula from k-r+1 time to k time, r represents a detection time window length, denotes a residual signal of the attacked data from the neighbor distributed estimator node j to the local distributed estimator node i at l time, Σ ij is a covariance of the neighbor residual when not attacked, mainly used for unitizing the accepted data, (·) T denotes a transposition operation on the data, (·) 1 denotes an inversion operation on the data, δ is a detection threshold value, which is used to judge whether the current data is attacked, and the method for obtaining the detection threshold value can refer to the chi-square distribution table to select a suitable value, if the detection value is less than the detection threshold value, it is H0 data not attacked; otherwise, it is H1, data attacked;

[0050] Each distributed estimator node with a defense mechanism discards the received attacked data, and uses the received unattacked data to perform state estimation, and the iteration formula of the state estimation of the local distributed estimator node i is

[0051]

[0052] wherein, and are state estimation information of the local distributed estimator node i at k+1 time and k time, respectively, whether the state estimation information is attacked or not is unknown, is state estimation information of the local distributed estimator node i transmitted from the neighbor distributed estimator node j, whether the state estimation information is attacked or not is unknown, A is a smart grid system matrix, K i (k) is a local residual gain coefficient, and ε is a consensus term gain coefficient, denotes a summation operation on all neighbor local distributed estimator nodes of the local distributed estimator node i , γ ij (k) is a detection result of the chi-square detector on the neighbor distributed estimator node j to the local distributed estimator node i.

[0053] Optionally, the second calculation module is further configured to:

[0054] calculating a stealth attack vector a from the neighbor distributed estimator node j to the local distributed estimator node i ij The method of (k) comprises:

[0055] finding homogeneous linear equations C i a ij (k) = 0 ij ,1,...,u ij,p},

[0056] wherein the solution space is composed of p bases, and an expression of the attack vector is set as:

[0057] a ij (k) = a1(k)u ij,1 +...+a p (k)u ij,p ,

[0058] wherein a1(k),...,a p (k) are real numbers set by the attacker and not all are zero;

[0059] injecting the attack vector obtained into a data communication channel from the neighbor distributed estimator node j to the local distributed estimator node i, to obtain attacked data:

[0060]

[0061] wherein, represents data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i at k moment, whether the data is attacked or not.

[0062] Optionally, the injection module is further configured to:

[0063] replace data transmitted from the local distributed estimator node i to the neighbor distributed estimator node j with data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i.

[0064] According to yet another aspect of the present application, there is provided a storage medium having a computer program stored thereon, the program being executed by a processor to implement the distributed smart grid false data injection attack method.

[0065] According to still another aspect of the present application, there is provided a computer device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, the processor executing the program to implement the distributed smart grid false data injection attack method.

[0066] By the technical scheme, the application provides a distributed smart grid false data injection attack method and device, medium, first, each distributed estimator node in the smart grid obtains the value of the local sensor and the neighbor state estimation value, according to the obtained value of the local sensor and the neighbor state estimation value, each distributed estimator node calculates the state estimation value of the next time, second, the received neighbor state estimation value is detected by the chi-square detector, the distributed estimator node with attack detection capability is constructed, finally, according to the observation matrix corresponding to each distributed estimator node, the stealthy attack vector is calculated, the false data is injected through the data exchange channel between each distributed estimator node, and the global stealthy attack on each distributed estimator node is realized.

[0067] The above description is only a summary of the technical scheme of the application, in order to more clearly understand the technical means of the application, the content of the specification can be implemented, and in order to make the above and other purposes, characteristics and advantages of the application more obvious and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS

[0068] The drawings described herein are used to provide further understanding of the application, and form a part of the application. The schematic embodiments of the application and their description are used to explain the application, and do not constitute undue limitation on the application. In the drawings:

[0069] Figure 1 A flowchart of a distributed smart grid false data injection attack method provided by the embodiment of the application is shown;

[0070] Figure 2 A schematic diagram of the architecture of a distributed smart grid false data injection attack method provided by the embodiment of the application is shown;

[0071] Figure 3 A state estimation flowchart of a distributed estimator node in the method S20 of the embodiment of the application is shown;

[0072] Figure 4 A state estimation flowchart of a smart grid system after being attacked in the method S30 of the embodiment of the application is shown;

[0073] Figure 5 A flowchart of the stealthy attack vector obtained in the method S40 of the embodiment of the application is shown;

[0074] Figure 6 A communication topology diagram of a distributed estimator in the embodiment of the application is shown;

[0075] Figure 7A smart grid system running state and a distributed estimator node state estimation effect diagram in the embodiment of the present application is shown.

[0076] Figure 8 A smart grid system state and a state estimation effect diagram before and after being attacked in the embodiment of the present application are shown.

[0077] Figure 9 A chi-square detector detection value and a detection threshold effect diagram after being attacked in the embodiment of the present application are shown.

[0078] Figure 10 A structure schematic diagram of a distributed smart grid false data injection attack device provided in the embodiment of the present application is shown.

[0079] Figure 11 A device structure schematic diagram of a computer device provided in the embodiment of the present application is shown.

[0080] Mathematical symbol explanation

[0081] is a positive integer set; is an n-dimensional real number vector; is an n*n real number matrix;[·] T represents a transpose operation of a matrix;[·] -1 represents an inverse operation of a matrix;∑ represents a summation operation; for a matrix X, rank(X) represents a rank operation of the matrix, ker(X) represents a kernel space of the matrix, and min(a,b) represents taking a minimum value of a and b. DETAILED DESCRIPTION

[0082] The present application will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0083] In the present embodiment, a distributed smart grid false data injection attack method is provided, as shown in Figure 1 The method comprises the following steps.

[0084] In step S10, each distributed estimator node in the smart grid acquires a value of a local sensor and a neighbor state estimation value.

[0085] In step S20, according to the acquired value of the local sensor and the neighbor state estimation value, each distributed estimator node calculates a state estimation value at a next time.

[0086] In the embodiment of the present application, each distributed estimator node in the smart grid calculates local residual information based on the measurement information obtained by its own sensor at the current time and the state estimation information at the current time, corrects the state estimation value at the current time by using the local residual information and the neighbor state estimation value, and obtains the state estimation value at the next time and the estimation error covariance matrix.

[0087] In step S30, the received neighbor state estimation value is detected by a chi-square detector, and a distributed estimator node with attack detection capability is constructed.

[0088] In order to prevent the information between different distributed estimator nodes from being attacked, each distributed estimator node detects the received neighbor state estimation value by using a chi-square detector. Through analysis of the smart grid system, a detection threshold of the communication channel is set by referring to the chi-square distribution table. When the detection value is greater than the detection threshold, it is indicated that the smart grid system is attacked, and the data information from the channel is discarded; otherwise, the information of the channel is received and used for estimating the state of the system.

[0089] In step S40, a stealthy attack vector is calculated according to the observation matrix corresponding to each distributed estimator node.

[0090] In order to make the injected false data not be found by the chi-square detector, a suitable attack vector needs to be found, which satisfies the stealthiness to the chi-square detector and also satisfies the destructiveness to the distributed estimator node. The attack vector exists in the null space of the sensor observation matrix of the smart grid system, and therefore, the sensor observation matrix information of the distributed estimator node needs to be known.

[0091] In step S50, false data is injected through the data exchange channel between each distributed estimator node, so as to realize the global stealthy attack on each distributed estimator node.

[0092] The attack on one information receiving channel of the distributed estimator node can make the state estimation value deviate from the real state value of the system. However, in order to maintain the global stealthiness of the attack, the chi-square detector of all the distributed estimator nodes cannot detect the attack, and therefore, all the state estimation values sent by the attacked distributed estimator node to the neighbor nodes need to be replaced by the state estimation values from the neighbor nodes.

[0093] By applying the technical solutions of the embodiment, the condition of the smart grid system and the distributed estimator node is analyzed, an attack vector capable of avoiding detection by the chi-square detector is found out and injected into the communication channel of the distributed estimator node, so that the state estimation value of the distributed estimator node deviates from the true value of the smart grid system and will not be discovered by the chi-square detector of all distributed estimator nodes, thereby realizing destruction to the state estimation of the distributed smart grid.

[0094] Further, as Figure 2 shown, in a specific embodiment, each distributed estimator node in the smart grid estimates the same grid system. The system is modeled as a discrete-time linear time-invariant system, wherein the state equation of the smart grid system is represented as follows:

[0095] x(k+1)=Ax(k)+w(k) (1)

[0096] wherein, is a positive integer time sequence, represents an n-dimensional real state vector of the system at time k, is a system matrix. w(k) is a system process noise, the statistical characteristics of which satisfy a Gaussian distribution w(k)~N(0, Q), and Q is a process noise covariance matrix. It is assumed that the initial state of the smart grid system is x(0)=x0

[0097] Each distributed estimation node is configured with a measurement sensor, which can observe a part of the state of the system. The sensors of different nodes can observe different system states, and they jointly realize the observability of the entire system, which can be represented by the following equation:

[0098] y i (k)=C i x(k)+v i (k),i=1,…,N (2)

[0099] wherein, there are N distributed estimator nodes, represents the m i dimensional measurement information of node i at time k, is an observation matrix of the sensor of the distributed estimator node i. v i (k) represents the measurement noise of the distributed estimator node i at time k, the statistical characteristics of which satisfy a Gaussian distribution v i ~N(0, R), and R is a measurement noise covariance matrix.

[0100] wherein, step S10 includes the process of the distributed estimator node to the normal state estimation of the smart grid system. The specific implementation steps are as follows:

[0101] The processor of each distributed estimator node receives measurement information y from the local sensor at the current k moment i (k) and the local residual information is obtained by subtracting the current moment estimation value as follows:

[0102]

[0103] wherein, is the residual information at the current k moment, and is an m i dimensional vector. is the state estimation of the smart grid system at the current moment by the distributed estimator node i.

[0104] It is generally believed that the local sensor in the distributed estimator cannot observe the state of the entire system, but the sensors of all distributed estimator nodes can jointly observe the state of the system, which is called distributed estimator joint observability, i.e., the ordered pair is detectable. Under this condition, the estimation value of the distributed estimator node can converge to the true state value of the system, and the state estimation of the entire system is realized.

[0105] Step S20 includes correcting the estimation value at the current moment by the distributed estimator node using the residual information and the neighbor communication information to obtain the state estimation value and the estimation error covariance matrix at the next moment and the corresponding parameters. As shown in Figure 3 , the specific implementation steps are as follows:

[0106] S201, calculate the estimation update equation:

[0107]

[0108] wherein, represents the prior estimation of the system state by the estimator i at the k+1 moment, represents the posterior estimation of the system state by the estimator i at the k moment, and the initial state estimation value at the initial moment is assumed to be

[0109] S202, calculate the estimation error covariance update equation:

[0110]

[0111] wherein, is the prior estimation error covariance, and E{} represents the function expectation; is the posterior estimation error covariance.

[0112] S203, calculate the local residual gain coefficient K i (k):

[0113]

[0114] where R is the node observation noise covariance matrix.

[0115] S204, calculate the state estimation of the next time k+1 of the system of the distributed estimation node i:

[0116]

[0117] where, is the state estimation value of the neighbor node j, K i (k) is the local residual gain coefficient, is the neighbor set of the distributed node i, and ε is the residual consensus gain parameter of the neighbor node, which is in the range of is the connectivity of the distributed node i, that is, the number of connected neighbors of the node.

[0118] S205, calculate the estimation error covariance correction equation:

[0119]

[0120] where I is the unit matrix of the corresponding dimension. With the passage of time, the estimator tends to be stable, and it is assumed that the estimation error covariance of node i is P i

[0121] Step S30 is a defense measure taken by the distributed estimator node to deal with malicious attackers. It is generally believed that the sensors of local nodes are close to the processor and will not be attacked, while different distributed estimators are far away and are more likely to be attacked by malicious attacks. We assume that the attack form injected by the malicious attacker is:

[0122]

[0123] where a ij (k) represents the attack vector, represents the state estimation value transmitted from the neighbor node j to the local estimation node i, represents the state estimation value obtained after being attacked. Since the distributed estimator i does not know whether the current data is tampered by the attacker after receiving the data, the communication data between the distributed estimators is detected, as shown in Figure 4 The specific steps are:

[0124] S301, use the measurement information y i (k) of the local sensor at the current time k and the state estimation value of the neighbor node j to the local node i at the current time k to calculate the neighbor residual information after being attacked

[0125] S302、To avoid contingency, the residual data in a period of time need to be calculated and detected, and the detection value D ij (k) is specifically:

[0126]

[0127] represents the summation operation of the formula from the k-r+1 time to the k time, r represents the detection time window length, represents the residual signal of the attacked data from the node j to the node i at the l time, Σ ij is the covariance of the neighbor residual when not attacked, mainly used for unitizing the accepted data, and the value is obtained from , wherein is the posterior estimation error covariance of the node j. δ is a detection threshold value, which is used to judge whether the current data is attacked, and the method for obtaining the threshold value can refer to the chi-square distribution table to select a suitable value. If the detection value is less than the threshold value, it is H0 data not attacked; otherwise, it is H1, data attacked.

[0128] S303, obtain a distributed estimation system with anti-attack, which is expressed as follows:

[0129]

[0130] wherein, and are the state estimation information of the local node i at the k+1 time and the k time, respectively, whether attacked or not, is the attacked state estimation information transmitted from the neighbor node j to the local node i, and ε is the consensus term gain coefficient, represents the summation operation of the of all neighbor nodes of i, and γ ij (k) is the detection result of the current detector, and the expression is:

[0131]

[0132] Step S40 is the process of determining the attack vector by the attacker through the parameter analysis of the distributed estimator node, and achieving the attack target.

[0133] When the attacker implements the attack, the following assumptions need to be made on the information mastered by the attacker

[0134] (1) It is assumed that the attacker can know the topological connection structure of the distributed estimator and its related parameters, including the system matrix A, the local residual gain coefficient K i (k), the sensor observation matrix C i , and the neighbor residual consensus gain ε.​

[0135] (2) Assume that the attacker can intercept the transmitted signal and inject malicious attack signal to the communication channel between the distributed estimation nodes.

[0136] Under the above assumption, the attacker can implement a global concealment attack on the distributed estimator nodes, whose goal is to:

[0137] (1) The malicious attack signal injected by the attacker does not trigger any distributed estimator i to alarm its neighbor 's detector, i.e., the residual statistical characteristics before and after the attack remain unchanged

[0138] (2) Calculate the state estimation bias of node i such that the following conditions are met:

[0139]

[0140] Each distributed estimator is not fully observable to the state of the system, i.e., rank(C i ) < n. Therefore, there must be an attack vector belonging to the null space of the sensor observation matrix, i.e., a ij (k) ∈ ker(C i ). As shown in the following, the specific implementation steps of the global concealment attack of the distributed estimator are as follows: Figure 5

[0141] S401, calculate the update equation of the estimation bias:

[0142]

[0143] wherein, e j (k) is the state estimation bias of node j.

[0144] From the triangle inequality, we have:

[0145] |e i (k+1)| ≥ |εAa ij (k)| - |F i (k)| (15)

[0146] S402, find the solution space of the homogeneous linear equation C i a ij (k) = 0 is span{u ij,1 ,..., u ij,p}, where p = n - Rank(C i ) ≥ 1.

[0147] S403, the expression of the attack vector is:​

[0148] a ij (k)=a1(k)u ij,1 +...+a p (k)u ij,p (16)

[0149] where a1(k),...,a p (k) are real numbers set by the attacker, not all of which are zero.

[0150] Therefore, the attacker can set appropriate parameter values so that the attack vector a ij is large enough to make the estimation bias of the distributed node i diverge, that is,

[0151] S404, inject the obtained attack vector into the data channel from the neighbor node j to the local node i, and obtain the communication data after the attack:

[0152]

[0153] Step S50 is an attack measure implemented to prevent the attack vector from being detected by the remaining distributed estimation nodes. Since the distributed estimator has a consensus item, the estimation values of all distributed estimators eventually converge to the average value of all estimator states, also known as leaderless state consistency. Because the sensors of all distributed nodes are jointly observable to the entire state of the system, the injected attack vector will inevitably be detected. Therefore, the attack vector is injected into all channels through which the attacked distributed estimator node transmits data to neighbors. To facilitate implementation, the method is to replace the data transmitted from the local node i to the neighbor node j with the data transmitted from the neighbor node j to the local node i, that is: is replaced with

[0154] Through the above steps, a global stealth attack on a single distributed estimation node is realized. The state estimation of the attacked distributed estimation node deviates from its true state value without being alarmed by all detectors.

[0155] The following is a specific implementation case to prove the effectiveness of the method of the present application. In a specific embodiment, there are 5 distributed estimator nodes, and the communication topology between the 5 nodes is as shown in Figure 6 . The distributed estimators measure the same system, and the system model is:

[0156] x(k+1)=Ax(k)+w(k)

[0157] where w(k) is a Gaussian white noise with a mean of zero, and the covariance matrix is:

[0158] The observation matrix corresponding to the distributed estimator is: The observation noise v i (k),i=1,…,5 are Gaussian white noises with zero mean, and the corresponding covariance matrix is:

[0159] The neighbor residual consensus gain parameter of each distributed estimator node is set as: ε1=ε5=0.5, ε2=ε3=ε4=0.25.

[0160] Under the above parameter setting, the state estimation value of the distributed estimator to the system is as shown in Figure 7 The solid line represents the true state value of the system running, and the dashed line represents the state estimation value of the system by the five distributed estimator nodes. It can be seen that, in the absence of attacks, the distributed estimator can stably and accurately track the true state of the system within the error range, achieving the goal of real-time estimation of the system state.

[0161] When no attack occurs, the distributed state estimation method proposed in the present application can stably and accurately estimate the true state of the system, as shown in Figure 8 When a general injection attack occurs, the distributed state estimator has joint observability and consistency of state estimation tending to average value, and can finally be detected by the chi-square detector. However, by using the method in the present application, the attacker can implement a global concealment attack, which can cause a deviation in the state estimation of the attacked distributed estimation node while ensuring that all chi-square detectors cannot detect the attack signal, as shown in Figure 9 .

[0162] Further, as a specific implementation of the Figure 1 method, the embodiment of the present application provides a distributed smart grid false data injection attack device, as shown in Figure 10 The device comprises:

[0163] An acquisition module, configured to acquire, by each distributed estimator node in a smart grid, a value of a local sensor and a neighbor state estimation value;

[0164] A first calculation module, configured to calculate, by each distributed estimator node, a state estimation value at a next time according to the acquired value of the local sensor and the neighbor state estimation value;

[0165] A detection module, configured to detect, by a chi-square detector, the received neighbor state estimation value, and construct a distributed estimator node with attack detection capability;

[0166] a second calculation module, configured to calculate a concealment attack vector according to an observation matrix corresponding to each distributed estimator node;

[0167] an injection module, configured to inject false data through a data exchange channel between each distributed estimator node, so as to implement a global concealment attack on each distributed estimator node.

[0168] Optionally, the acquisition module is further configured to:

[0169] a sensor meeting a joint observability condition is configured at each distributed estimator node respectively, and measurement information corresponding to the smart grid system is obtained through joint measurement of sensors corresponding to all distributed estimator nodes, and the measurement information is represented by the following equation:

[0170] y i (k) = C i x(k) + v i (k), i = 1,..., N

[0171] wherein there are N distributed estimator nodes, representing m i dimensional measurement information of node i at k moment, is an observation matrix of the sensor of the distributed estimator node i. v i (k) represents measurement noise of the distributed estimator node i at k moment, and a statistical characteristic of the measurement noise obeys a Gaussian distribution of v i ~ N(0, R), R is a measurement noise covariance matrix.

[0172] Optionally, the first calculation module and the detection module are further configured to:

[0173] calculate a data residual error transmitted from a neighbor distributed estimator node j to a local distributed estimator node i and a calculation formula of the data residual error is as follows:

[0174]

[0175] wherein y i (k) is a measurement value of a sensor corresponding to the local distributed estimator node i at a current k moment, C i is an observation matrix of the local distributed estimator node i, is an attacked state estimation value from the neighbor distributed estimator node j to the local distributed estimator node i at the current k moment;

[0176] calculate a detection value D ij(k), its calculation formula is:

[0177]

[0178] in, This represents the change in expression from time k-r+1 to time k. Perform a summation operation, where r represents the length of the detection time window. Σ represents the residual signal of the attacked data from neighboring distributed estimator node j to local distributed estimator node i at time l. ij This is the covariance of the neighbor residuals when not under attack, mainly used for normalizing the received data. (·) T This indicates that the data is transposed, (·)-1 indicates that the data is inverted, and δ is the detection threshold, which is used to determine whether the current data has been attacked. The method of obtaining the threshold can refer to the chi-square distribution table to select an appropriate value. If the detection value is less than the detection threshold, it is H0 and the data has not been attacked; otherwise, it is H1 and the data has been attacked.

[0179] Each distributed estimator node with the added defense mechanism discards the received attacked data and uses the received unattacked data to perform state estimation. The iterative formula for estimating the state of its local distributed estimator node i is as follows:

[0180]

[0181] in, and These are the state estimates of whether the local distributed estimator node i has been attacked at time k+1 and time k, respectively. Let A be the state estimation information (whether it has been attacked or not) transmitted from neighboring distributed estimator node j to local distributed estimator node i. Let K be the matrix of the smart grid system. i (k) Local residual gain coefficient, where ε is the consensus term gain coefficient. This represents all neighboring local distributed estimator nodes of local distributed estimator node i. Perform a summation operation, γ ij (k) represents the detection result of the chi-square detector from neighboring distributed estimator node j to local distributed estimator node i.

[0182] Optionally, the second computing module is further configured to:

[0183] Calculate the covert attack vector a from the neighboring distributed estimator node j to the local distributed estimator node i. ij The methods of (k) include:

[0184] Finding homogeneous linear equation C i a ij The solution space of (k) = 0 is span{u ij,1 ,...,u ij,p},

[0185] Wherein, the solution space is composed of p bases, and the expression of the attack vector is set as:

[0186] a ij (k) = a1(k)u ij,1 +...+a p (k)u ij,p ,

[0187] Wherein, a1(k),...,a p (k) are real numbers set by the attacker, and not all of them are zero;

[0188] The attack vector obtained is injected into the data communication channel from the neighbor distributed estimator node j to the local distributed estimator node i, and the attacked data is obtained:

[0189]

[0190] Wherein, represents the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i at time k. Whether the data is attacked or not is unknown.

[0191] Optionally, the injection module is further used to:

[0192] Replace the data transmitted from the local distributed estimator node i to the neighbor distributed estimator node j with the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i.

[0193] It should be noted that other corresponding descriptions of the various functional units involved in the distributed smart grid false data injection attack device provided by the embodiments of the present application can be referred to the corresponding descriptions in the Figure 1 Method, which will not be described here.

[0194] The embodiments of the present application also provide a computer device, which can be a personal computer, a server, a network device, etc., such as Figure 11As shown, the computer device includes a bus, a processor, a memory and a communication interface, and can further include an input / output interface and a display device. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store location information. The network interface of the computer device is configured to communicate with an external terminal through a network connection. The computer program is executed by the processor to implement the steps in the method embodiments.

[0195] Those skilled in the art can understand that, Figure 11 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0196] In one embodiment, a computer readable storage medium is provided, which can be non-volatile or volatile, and has stored thereon a computer program. The computer program is executed by a processor to implement the steps in the method embodiments described above.

[0197] In one embodiment, a computer program product is provided, which includes a computer program. The computer program is executed by a processor to implement the steps in the method embodiments described above.

[0198] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties.

[0199] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0200] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0201] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A false data injection attack method for a distributed smart grid, characterized in that, The method comprises the following steps: Step 1: each distributed estimator node in the smart grid acquires the value of a local sensor and a neighbor state estimation value; Step 2: each distributed estimator node calculates a state estimation value at the next time according to the acquired value of the local sensor and the neighbor state estimation value; Step 3: a chi-square detector is used to detect the received neighbor state estimation value, and a distributed estimator node with attack detection capability is constructed; Step four, according to the observation matrix corresponding to each distributed estimator node, the stealthy attack vector is calculated, including: calculating the stealthy attack vector a from the neighbor distributed estimator node j to the local distributed estimator node i ij The method of (k) comprises: finding the solution space of homogeneous linear equations C i a ij (k) = 0, which is span{u ij,1 ,...,u ij,p}, wherein the solution space is composed of p bases, and the expression of the attack vector is set as: a ij (k) = a1(k)u ij,1 +...+a p (k)u ij,p , wherein a1(k),...,a p (k) are real numbers set by the attacker, not all of which are zero, is the observation matrix of the distributed estimator node i sensor; the attack vector obtained is injected into the data exchange channel from the neighbor distributed estimator node j to the local distributed estimator node i, and the attacked data is obtained: Wherein, represents the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i at k time, whether the unknown is attacked or not. Step 5: false data is injected through a data exchange channel between each distributed estimator node to realize a global stealth attack on each distributed estimator node.

2. The method of claim 1, wherein, The step 1 comprises the following steps: a sensor meeting a joint observability condition is respectively configured on each distributed estimator node, and measurement information of the smart grid system is obtained through joint measurement of the sensors corresponding to all distributed estimator nodes, and the equation is as follows: y i (k) = C i x(k) + v i (k), i = 1,..., N where N is the total number of distributed estimator nodes, m represents the n-dimensional real state vector of the system at time k. i dimensional measurement information, is the observation matrix of the sensor of the distributed estimator node i, v i (k) represents the measurement noise of the distributed estimator node i at time k, whose statistical characteristics obey the Gaussian distribution v i ~ N(0, R), R is the measurement noise covariance matrix, m represents the n-dimensional real state vector of the system at time k.

3. The method of claim 1, wherein, The step 2 and the step 3 comprise the following steps: calculating a data residual transmitted from a neighbor distributed estimator node j to a local distributed estimator node i The formula is: where y i (k) is the measurement value of the sensor corresponding to the local distributed estimator node i at the current k time, C i is the observation matrix of the local distributed estimator node i, is the attacked state estimation value from the neighbor distributed estimator node j to the local distributed estimator node i at the current k time; computing a detection value D of a neighbor state estimate value from the neighbor distributed estimator node j to the local distributed estimator node i ij (k) whose formula is: wherein, represents the summation operation of the formula from k-r+1 time to k time, r represents the detection time window length, represents the residual signal of the attacked data of the neighbor distributed estimator node j to the local distributed estimator node i at l time, Σ ij is the covariance of the neighbor residual when not attacked, mainly used for unitizing the accepted data, (·) T represents the transposition operation of the data, (·) -1 represents the inversion operation of the data, δ is a detection threshold value, used to judge whether the current data is attacked, and the method for obtaining the detection threshold value can refer to the chi-square distribution table to select a suitable value, if the detection value is less than the detection threshold value, it is H0 data not attacked; otherwise, it is H1, data attacked; Each of the distributed estimator nodes with defense mechanism discards the received attacked data and estimates the state using the received unattacked data. The iteration formula of the local distributed estimator node i for estimating the state is wherein, and respectively are the state estimation information of the local distributed estimator node i at the k+1 time and the k time whether the unknown is attacked or not, is the state estimation information of the unknown whether the unknown is attacked or not transmitted from the neighbor distributed estimator node j to the local distributed estimator node i, A is the smart grid system matrix, K i (k) is the local residual gain coefficient, ε is the consensus term gain coefficient, denotes the summation operation on all the neighbor distributed estimator nodes of the local distributed estimator node i, γ ij (k) is the detection result of the chi-square detector on the neighbor distributed estimator node j to the local distributed estimator node i.

4. The method of claim 1, wherein, The step 5 comprises the following steps: in order to avoid attack diffusion throughout the power grid, the attack needs to replace the data transmitted from the local distributed estimator node i to the neighbor distributed estimator node j with the data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i, and stealthiness of all node detectors is realized.

5. A distributed smart grid false data injection attack device, comprising: The device comprises: an acquisition module configured to acquire, by each distributed estimator node in the smart grid, a value of a local sensor and a neighbor state estimation value; a first calculation module configured to calculate, by each distributed estimator node, a state estimation value at the next time according to the acquired value of the local sensor and the neighbor state estimation value; a detection module configured to detect, by a chi-square detector, the received neighbor state estimation value, and construct a distributed estimator node with attack detection capability; The second calculation module is configured to calculate a stealthy attack vector according to an observation matrix corresponding to each distributed estimator node, and the calculation includes: calculating a stealthy attack vector a from the neighbor distributed estimator node j to the local distributed estimator node i ij The method of (k) includes: finding a solution space of homogeneous linear equations C i a ij (k) = 0, wherein the solution space is span{u ij,1 ,...,u ij,p}, and the solution space is composed of p bases, and an expression of the attack vector is set as: a ij (k) = a1(k)u ij,1 +...+a p (k)u ij,p , wherein a1(k),...,a p (k) are real numbers set by an attacker and not all of them are zero. is an observation matrix of a sensor of the distributed estimator node i; and the attack vector obtained is injected into a data exchange channel from the neighbor distributed estimator node j to the local distributed estimator node i, so as to obtain attacked data: wherein, represents unknown data transmitted from the neighbor distributed estimator node j to the local distributed estimator node i at the k moment, and whether the data is attacked or not. an injection module configured to inject, through a data exchange channel between each distributed estimator node, false data to realize a global stealth attack on each distributed estimator node.

6. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to realize the distributed smart grid false data injection attack method in any one of claims 1 to 4.

7. A computer device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, The processor executes the computer program to realize the distributed smart grid false data injection attack method in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Safety consistency control method for solving influence of FDI attack on multi-agent system

    CN115022031A

  • Port microgrid control method for resisting false data injection attack

    CN116094769A