False Data Injection Attack Detection and Location Method Based on TGRU Model
By using the TGRU model combined with Transformer and GRU technical means in false data injection attack detection, the problem of insufficient accuracy and low computing efficiency of false data injection attack detection and positioning in complex network environments is solved, and efficient and accurate attack detection and positioning is achieved.
Patent Information
- Application Number
- CN202411783759.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-06
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-12-06
AI Technical Summary
The prior art has problems of insufficient accuracy and low computing efficiency in handling false data injection attack detection and positioning in complex network environments, especially when processing high-dimensional timing data.
Using a false data injection attack detection and positioning method based on the TGRU model, the predicted value is generated and the detection threshold is set using the dual Euclidean distance computer system by preprocessing sensor data and combining the global feature extraction capability of Transformer and the time series processing capability of GRU. After an attack is detected, the predicted data generated by the TGRU model is integrated with the attack data, and the meta-model is trained to achieve precise positioning of the attack location.
It significantly improves the detection accuracy of false data injection attacks and the accuracy of attack positioning, reduces the computational complexity, and realizes real-time attack detection and positioning, which is better than existing methods.
Smart Images

Figure CN119272205B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security and data protection, and more specifically, relates to a method for detecting and locating false data injection attacks based on the TGRU model. Background Art
[0002] With the wide application of information technology in various infrastructures, the deep integration of traditional systems and modern information technology has significantly improved management efficiency and resource utilization. However, this high degree of automation also exposes various automated systems to network security threats such as false data injection attacks (FDIA). FDIA affects system state estimation by manipulating sensor data, which may lead to misjudgments of the system, thus causing huge economic losses and security risks. Although traditional bad data detection (BDD) algorithms can effectively identify certain data anomalies, they often fail when dealing with more complex and concealed attacks such as FDIA. Therefore, various automated systems urgently need more advanced detection and defense mechanisms.
[0003] Existing FDIA detection methods are mainly divided into two categories: model-based methods and data-driven methods. Model-based methods judge anomalies by analyzing the input and output data of the system, but their performance often depends on the accuracy and integrity of the system model. When the model is inaccurate, the detection effect will be greatly reduced. In contrast, data-driven methods use machine learning and deep learning technologies to achieve efficient fault detection through a large amount of historical data. For example, frameworks such as R2N2 and LSTM have achieved certain results in improving detection accuracy. In addition, ensemble learning methods have also been gradually applied to the field of network security to improve the robustness and accuracy of detection by combining the advantages of multiple models.
[0004] Chinese patent document CN118779787A discloses a method for detecting false data injection attacks in power systems based on deep learning, including: collecting the power data set of a power station as the original data set and preprocessing the original data set; simulating the power flow calculation process through a virtual power grid to obtain power flow data, constructing false data injection attacks, and obtaining a bad data set after the attack; using a long short-term memory neural network with a multi-head self-attention mechanism to establish a detection model, and using the detection model to detect attacks on the bad data set.
[0005] Chinese Patent Document CN116881714A discloses a method for detecting false data injection in power grids based on a dual-branch CNN-LSTM. The method preprocesses a data set containing normal data samples and false data samples of the smart grid, and divides the preprocessed data set into a training set and a test set; constructs a dual-branch CNN-LSTM false data injection detection model for the power grid, and uses the divided training set to train the detection model; inputs the test set into the trained dual-branch CNN-LSTM false data injection detection model for the power grid to determine whether a false data injection attack has occurred in the smart grid.
[0006] However, existing FDIA detection methods still have deficiencies in terms of detection accuracy and localization ability. Especially when dealing with complex structures and spatio-temporal correlations, it is more challenging to accurately locate the attack source.
[0007] In view of this, the present invention designs a method for detecting and locating false data injection attacks based on TGRU, aiming to solve the limitations of the prior art in dealing with complex network environments, and can be applied to smart grids and other Internet of Things systems to improve the security and data integrity of the system. Summary of the Invention
[0008] The present invention aims to overcome at least one defect in the prior art, and provides a method for detecting and locating false data injection attacks based on TGRU, aiming to solve the limitations of the prior art in dealing with complex network environments, especially the problems of insufficient accuracy and low computational efficiency when dealing with high-dimensional time series data. Overview of the Invention
[0010] The present invention first preprocesses the measurement data of multiple sensors and inputs it into the TGRU model for training, and analyzes the data by combining the global feature extraction ability of Transformer and the time series processing ability of GRU. A dual calculation mechanism based on Euclidean distance is used to analyze the distribution of normal data and attack data, and a detection threshold is set. Once an attack is detected, the system integrates the prediction data generated by the TGRU model at the current moment with the detected attack data, and trains a meta-model to achieve precise positioning of the attack location. Finally, the computational steps are reduced by optimizing the model architecture to ensure efficient operation.
[0011] The detailed technical solution of the present invention is as follows:
[0012] A method for detecting and locating false data injection attacks based on TGRU, the method comprising:
[0013] S1. Obtain normal measurement data from the historical data of multiple sensors, preprocess the data, and initialize the parameters of the TGRU model;
[0014] S2. Train the TGRU model using the preprocessed normal measurement data: Extract global features using the Transformer encoder, and process the time series data through GRU to generate prediction values. The Adam optimizer is used during the training process.
[0015] S3. After the TGRU model is trained, generate simulated attack data, and adopt a dual Euclidean distance calculation mechanism. On the one hand, calculate the Euclidean distance between the TGRU prediction value and the normal measurement data, and on the other hand, calculate the Euclidean distance between the TGRU prediction value and the generated attack data to form a distribution map based on the dual Euclidean distance. Use the distribution difference between the normal measurement data and the generated attack data to set a threshold to distinguish normal data and attack data.
[0016] S4. After detecting an attack, train a meta-model using the prediction data of the TGRU and the detected attack data to accurately locate the attack position.
[0017] S5. Repeat steps S2 - S4 to optimize the TGRU model and the meta-model through multiple rounds of iterative training, continuously optimize the parameters of the TGRU model and the meta-model, and set the maximum number of training rounds.
[0018] Preferably according to the present invention, the specific steps in step S1 are as follows:
[0019] S11. Data acquisition
[0020] Extract a section of measurement data within a specific time range from the historical data of the sensor as historical measurement data. The historical measurement data is the operation data of the automated system in the normal state, that is, normal measurement data.
[0021] S12. Data preprocessing
[0022] First, perform data cleaning to remove outliers and noise caused by sensor failures, external interferences, and acquisition errors. Secondly, fill in missing values. When the sensor loses data due to a failure or communication problem, the missing values need to be filled to ensure data integrity. Finally, perform normalization processing. Use Min - Max scaling to scale the data to the same range.
[0023] S13. Model initialization
[0024] After the data preprocessing is completed, next, it is necessary to initialize the TGRU model for false data injection attack (FDIA) detection:
[0025] First is the initialization of the Transformer encoder, which is used to extract the global features of the input data. The parameters of the Transformer encoder include the attention weight matrix, the multi-head attention layer, and the fully connected layer. Next is the initialization of the GRU, which is responsible for handling the dependencies of time series data. The parameters of the GRU include the input weight matrix, the hidden state weight matrix, and the bias term. Finally is the initialization of the meta-model, which is used to locate attacks. The meta-model is a fully connected neural network used to process the combination of the prediction data generated by the TGRU and the attack data.
[0026] According to a preferred embodiment of the present invention, the specific steps in step S2 are as follows:
[0027] S21. The first part of the TGRU model, the Transformer encoder extracts global features from the input data: In time series data, the Transformer calculates the correlation between each time step and other time steps through the multi-head self-attention mechanism, focusing on the most relevant information, which enables the model to consider both the current and context information simultaneously and capture complex dependencies. During the training process, the Transformer layer encodes the normal measurement data, extracts the dependencies between sensors and between different time steps, and provides a higher-level feature representation for subsequent time series processing.
[0028] S22. After extracting the global features, the second part of the TGRU model, the GRU processes the dependencies in the time series: The GRU controls the information flow through the update gate and the reset gate, determines which historical information to retain or discard, avoids the vanishing gradient, and ensures that important time series information is captured. During training, the GRU gradually processes the features generated by the Transformer and generates the predicted values for the sensor data at the current moment.
[0029] According to a preferred embodiment of the present invention, the specific steps of step S3 are as follows:
[0030] S31. Generation of simulated attack data
[0031] After the TGRU model is trained, in order to compare the feature distributions of normal data and attack data and set effective detection thresholds, simulated FDIA data needs to be generated. The simulated attack data is obtained by performing specific false data injection operations on the normal data.
[0032] S32. Calculation of the Euclidean distance
[0033] A dual Euclidean distance mechanism is adopted for analysis to form a distribution map based on the dual Euclidean distance. First, calculate the Euclidean distance between the predicted value of the TGRU model for each time step and the normal data. The formula is as follows:
[0034] (1);
[0035] In formula (1), represents the predicted value of the TGRU model on the th feature, indicating the estimation of the TGRU model for this time step and this feature; represents the value of the th feature actually measured by the sensor, indicating the true state of the power grid at this time step, i.e., normal data; represents the number of features of the sensor data;
[0036] Secondly, calculate the Euclidean distance between the predicted value of the TGRU model for each time step and the simulated attack data. The formula is as follows:
[0037] (2);
[0038] In formula (2), represents the value of the
[0039] th feature in the simulated attack state, which is simulated attack data generated by performing specific false data injection operations on normal data and is used to help the model distinguish between normal data and attack data;
[0040] Set the threshold based on the distribution map of the double Euclidean distance. In the said distribution map, the distance distribution of normal data is usually relatively concentrated, indicating that when the system is in the normal state, the difference between the model predicted data and the actual measured data is small; the distance distribution of attack data is relatively discrete, indicating that the attack will cause a large deviation between the model predicted value and the actual value;
[0041] Analyze the distance distributions of normal data and attack data, determine the boundary between the two, and set a threshold;
[0042] S34, Detection mechanism
[0043] When new sensor data enters the system, the TGRU model will predict the data at the current moment and calculate the Euclidean distance between the predicted value at the current moment and the actual sensor reading. If the Euclidean distance between the predicted value at the current moment and the actual sensor reading is less than the set threshold, the data is normal data; if the Euclidean distance between the predicted value at the current moment and the actual sensor reading exceeds the set threshold, the system will issue an alarm to indicate the existence of a false data injection attack.
[0044] By combining simulated attack data and the double Euclidean distance mechanism, the TGRU model can not only accurately predict normal data but also effectively detect false data attacks.
[0045] Preferably according to the present invention, the specific steps of step S4 are as follows:
[0046] S41. Data processing and meta-model training
[0047] Once a false data injection attack FDIA is detected at the current moment, the prediction data generated by the TGRU model at the current moment will be integrated with the detected attack data to form combined data;
[0048] Then, the system inputs these combined data into a simplified positioning model, that is, a meta-model; this meta-model uses a fully connected neural network FCL to process the combined data, analyzes the difference between the TGRU prediction value and the actual attack data, identifies the abnormal behavior of each sensor, and combines the multi-label classification method to enable the meta-model to detect the states of multiple sensors simultaneously, so as to accurately locate the position of the attacked sensor.
[0049] S42. Multi-label classification method
[0050] Each sensor is regarded as an independent label, and the meta-model uses the multi-label classification method to identify and locate multiple sensors that are simultaneously attacked. Through the multi-label classification method, the meta-model can detect each sensor one by one to determine whether they are attacked.
[0051] Preferably according to the present invention, in the process of optimizing the TGRU model and the meta-model through multiple rounds of iterative training, the error between the predicted value and the normal measurement data is calculated by the loss function MSE, and then the weight parameters of the model are updated through the gradient descent algorithm. The formula is as follows:
[0052] (3);
[0053] In formula (3), is the parameter of the TGRU model after the -th round of iterative training; is the parameter of the TGRU model in the -th round of iterative training; is the learning rate, which controls the step size of model parameter update; is the gradient of the loss function in the -th round of training;
[0054] The loss function of the meta-model adopts the binary cross-entropy loss function in the multi-label classification task to calculate the difference between the actual label and the predicted label of each sensor:
[0055] (4);
[0056] In formula (4), is the The actual label of a sensor, where 0 indicates normal and 1 indicates being attacked. is the predicted label of the attack status of this sensor by the meta-model;
[0057] The meta-model updates the weight parameters according to the gradient of the loss function through the gradient descent algorithm. The formula is as follows:
[0058] (5);
[0059] In formula (5), is the weight parameter of the meta-model after the th round of iterative training; is the learning rate of the meta-model; is the gradient of the multi-label classification loss function of the meta-model.
[0060] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0061] (1) The TGRU model of the present invention combines the global feature extraction ability of Transformer and the advantages of GRU in processing time-series data, and can effectively capture the spatio-temporal dependence relationship of data, thus significantly improving the detection accuracy of false data injection attacks. Compared with the existing traditional detection methods, this model is more adaptable to complex data structures and can detect FDIA attacks with higher accuracy.
[0062] (2) The present invention can accurately locate the position where the attack occurs while detecting the FDIA attack. By combining the real-time prediction data generated by the TGRU model with the actual attack data, a simplified location model, that is, the meta-model, is trained, which not only improves the accuracy of attack location, but also reduces the computational complexity of the model, realizing real-time attack detection and location, and is superior to the mode of separating detection and location in the existing methods.
[0063] (3) The present invention introduces a method for determining a threshold based on the Euclidean distance. Through double Euclidean distance analysis, both the distance between normal data and predicted data and the distance between simulated attack data and predicted data are compared, and finally an optimal attack detection threshold is found. This method improves the accuracy and reliability in the detection process.
[0064] (4) The present invention reduces the dependence on expert experience through a data-driven approach. Existing methods often require experts to conduct in-depth analysis of the system, while the TGRU model automatically identifies anomalies and attacks through data training, simplifies the operation process, and improves the automation degree of detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1It is the flowchart of the method for detecting and locating false data injection attacks based on the TGRU model according to the present invention.
[0066] Figure 2 It is the Euclidean distance distribution diagram of normal and attack data based on the TGRU model of the present invention.
[0067] Figure 3 It is the curve of the change of precision, recall rate and F1 value under different thresholds of the present invention. Specific implementation manner
[0068] The following further describes the present disclosure in conjunction with the accompanying drawings and embodiments. This method is applicable to various sensor networks and complex network environments. For the convenience of description, the following embodiments are described in detail taking the smart grid scenario as an example.
[0069] Embodiment 1
[0070] Refer Figure 1 This embodiment provides a method for detecting and locating false data injection attacks in a smart grid based on the TGRU model. The method includes:
[0071] S1. Obtain historical measurement data from multiple sensors in the smart grid, preprocess the data, and initialize the TGRU model parameters at the same time;
[0072] The following is a detailed introduction to this process:
[0073] S11. Data acquisition
[0074] The sensors in the smart grid are responsible for collecting the electrical parameters of each node. These parameters are stored in the grid database in the form of time series for the state estimation and security detection of the system. In order to detect false data attacks FDIA, a section of sensor measurement data within a specific time range is extracted from the historical data. These historical measurement data are the operation data of the automation system in the normal state, that is, normal measurement data.
[0075] These sensor data usually have multi-dimensional features, such as voltage (V), current (I), active power (P), reactive power (Q), etc. These multi-dimensional time series data provide sufficient information for detecting false data. However, due to the complexity of the smart grid and the possible measurement errors of the sensors, the acquired raw data often needs to be further processed before it can be used for model training.
[0076] S12. Data preprocessing
[0077] Before model training, sensor data needs to go through a series of preprocessing steps to improve data quality and the learning effect of the model. First, data cleaning is performed. This step reduces the bias of the model by removing outliers and noise caused by sensor failures, external interferences, or acquisition errors. Second, missing value imputation is carried out. When data is lost due to sensor failures or communication problems, missing values need to be filled to ensure data integrity. Finally, normalization is performed. To balance the magnitude differences of different features, Min-Max scaling is used to scale the data to the same range.
[0078] S13. Model initialization
[0079] After the data preprocessing is completed, the TGRU model for false data injection attack (FDIA) detection needs to be initialized next. The TGRU model combines the advantages of Transformer and GRU, and can capture global features and handle time series dependencies simultaneously.
[0080] First is the initialization of the Transformer encoder, which is used to extract global features of the input data. The parameters of the Transformer encoder include the attention weight matrix, multi-head attention layer, and fully connected layer. Then is the initialization of GRU, which is responsible for handling the dependencies of time series data. The parameters of GRU include the input weight matrix, hidden state weight matrix, and bias term. Finally is the initialization of the meta-model, which is used to locate attacks. The meta-model is a fully connected neural network for processing the combination of prediction data and attack data generated by TGRU.
[0081] S2. Train the preprocessed historical sensor data through the TGRU model, use the Transformer encoder to extract global features, and process the time series data through GRU to generate prediction results.
[0082] In the TGRU model, model training mainly relies on historical sensor data for fitting. The training dataset only contains data during normal operation to ensure that the model can accurately identify and predict the normal state of the power grid. By combining the advantages of Transformer and GRU, the TGRU model can efficiently process multi-dimensional time series data in the power grid. The following is a detailed introduction to this process:
[0083] S21. Selection of model training data
[0084] During the training process of the TGRU model, only historical normal measurement data is used to ensure that the model can accurately learn the characteristic patterns of the system in the normal state. The selection of these normal data is particularly important because they directly affect the model's ability to identify normal behaviors.
[0085] To this end, select the sensor measurement data over a relatively long period of time to ensure that the data covers various normal operating states of the system, such as data under different loads, different time periods, and different operating conditions. This helps the model capture the global characteristics and temporal dependencies of the system in the normal state.
[0086] S22. Temporal Feature Learning and Prediction Based on the TGRU Model
[0087] The first part of the TGRU model is the Transformer encoder, which is responsible for extracting global features from the input data. In time series data, the Transformer calculates the correlation between each time step and other time steps through the multi-head self-attention mechanism, focusing on the most relevant information. This enables the model to consider both the current and context information simultaneously and capture complex dependencies. During the training process, the Transformer layer encodes the historical sensor data, extracts the dependencies between sensors and between different time steps, and provides a higher-level feature representation for subsequent temporal processing.
[0088] After extracting the global features, the second part of the TGRU model, the GRU, processes the dependencies in the time series. The GRU controls the flow of information through the update gate and the reset gate, determining which historical information to retain or discard, avoiding the vanishing gradient, and ensuring that important temporal information is captured. During training, the GRU gradually processes the features generated by the Transformer to generate the predicted values for the sensor data at the current moment.
[0089] After the training is completed, combined with the simulated attack data, a dual Euclidean distance calculation mechanism is adopted. On the one hand, calculate the Euclidean distance between the TGRU predicted data and the normal data, and on the other hand, calculate the Euclidean distance between the TGRU predicted data and the attack data. Utilize the distribution differences between the normal data and the attack data to set a threshold to distinguish between the normal data and the attack data.
[0090] After the TGRU model is trained and generates predictions for the normal state, it is then necessary to use a small amount of historical attack data to further optimize the model to improve the detection ability for FDIA. To this end, this paper adopts a dual Euclidean distance calculation mechanism, calculates the distances between the TGRU predicted data and the normal data as well as the attack data respectively, and sets an appropriate threshold by analyzing the distribution differences between these two distances to distinguish between the normal data and the attack data. The following is a detailed introduction to this process:
[0091] S31. Generation of Simulated Attack Data
[0092] In the smart grid, historical attack data is usually scarce, but it is of great significance for optimizing the detection model. By selecting some known false data injection attack samples, the TGRU model can better learn the feature differences between normal measurement data and attack data: After the TGRU model is trained, in order to compare the feature distributions of normal data and attack data and set effective detection thresholds, simulated FDIA data needs to be generated. The simulated attack data is obtained by performing specific false data injection operations on normal data, such as injecting biases into key sensor readings, tampering with specific feature values or system states, to affect the model's judgment of the system state.
[0093] Assume that the data of the sensor is under normal conditions, where represents the reading of the i-th sensor in the normal state, and n is the number of sensors.
[0094] To generate attack data, the data of key sensors is tampered with to generate attack data where represents the observed value of the i-th sensor in the attack state. The generation of attack data can be expressed as where, is the bias term added to the normal data , and the magnitude and direction of
[0095] S32, Calculation of Euclidean distance
[0096] The TGRU model has formed a prediction of the power grid state based on normal measurement data. After the model is trained, simulated attack data is introduced and a dual Euclidean distance mechanism is used for analysis. Specifically, the Euclidean distance is used to measure the similarity between two vectors. The larger the distance, the greater the difference between the data points.
[0097] The dual Euclidean distance calculation mechanism includes two parts:
[0098] Calculation of the distance of normal measurement data: First, calculate the Euclidean distance between the predicted value of the TGRU model for each time step and the normal measurement data. This distance can reflect the deviation between the prediction of the TGRU model and the normal measurement data under normal conditions. Usually, this distance should be small, indicating that the model's prediction of normal data is accurate.
[0099] The Euclidean distance formula is as follows:
[0100] (1);
[0101] In Equation (1), represents the value predicted by the TGRU model for the th feature, which is the estimation of the model for this time step and this feature. represents the value of the th feature actually measured by the sensor, which represents the true state of the power grid at this time step. represents the dimension of the data, or the number of features of the sensor data.
[0102] Calculation of the distance between the simulated attack data: Secondly, calculate the Euclidean distance between the TGRU predicted value and the simulated attack data. Since the simulated attack data deviates from the normal power grid state, the distance between the prediction result and these attack data is usually large. This can help the model distinguish between attack data and normal measurement data.
[0103] The Euclidean distance formula for the simulated attack data is:
[0104] (2);
[0105] In Equation (2), represents the observed value of the i-th feature in the simulated attack state, which is the simulated attack data generated by performing a specific false data injection operation on the normal data and is used to help the model distinguish between normal data and attack data.
[0106] S33. Threshold setting
[0107] The threshold is set based on the distribution diagram of the double Euclidean distance. In this distribution diagram, the distance distribution of the normal measurement data is usually relatively concentrated, indicating that when the system is in the normal state, the difference between the model predicted data and the normal measurement data is small. While the distance distribution of the attack data is relatively discrete, indicating that the attack will cause a large deviation between the model predicted data and the attack data. By analyzing the distance distributions of these two types of data, the distinction boundary between the two can be determined, and thus a reasonable threshold can be found. If the Euclidean distance between the predicted data of the TGRU model and the measured data exceeds this set threshold, the system considers that the measured data at the current moment is under attack, and then triggers the corresponding protection mechanism.
[0108] Through this threshold setting based on the distance distribution, the system can accurately identify the false data injection attack and effectively improve the security and reliability of the smart grid. During the detection process, the system can monitor the data at each time step in real time and make timely responses according to the difference between it and the model predicted value.
[0109] S34. Detection mechanism
[0110] Once the threshold of the Euclidean distance is set, the TGRU model can be used for online detection. When new sensor data enters the system, the TGRU model predicts the measurement data at the current moment and calculates the Euclidean distance between the predicted data and the sensor measurement data. If the distance is less than the set threshold, the measurement data is judged to be normal; if the distance exceeds the threshold, the system will issue an alarm, indicating that there is a false data injection attack.
[0111] By combining simulated attack data and the dual Euclidean distance mechanism, the TGRU model can not only accurately predict normal data but also effectively detect attack data.
[0112] S4. After detecting an attack, use the predicted data of TGRU and the detected attack data to train the meta-model for precise positioning of the attack location;
[0113] When the TGRU model successfully detects an FDIA, the system enters the attack location positioning stage. To accurately determine the location of the attack, this paper proposes a meta-model. This meta-model is trained by combining the predicted data of the TGRU model and the attack data, so as to achieve precise positioning of the attack location. The following is a detailed introduction to this process:
[0114] S41. Data processing and meta-model training
[0115] Once an FDIA is detected, the predicted data generated by the TGRU model will be integrated with the detected attack data. The purpose of this process is to combine the prediction results of the model with the attack data to form a more comprehensive data set. These combined data sets contain the differences between the predicted data and the attack data, reflecting the impact of potential attacks. This difference can help the model better understand which sensors have been attacked. After completing the data combination, the system will input these combined data into a simplified positioning model, that is, the meta-model. This meta-model uses a fully connected neural network FCL to process the combined data and learn how to locate the position where the attack occurs by observing the difference between the predicted value and the true value.
[0116] The design of the meta-model not only simplifies the attack location process but also significantly reduces the computational complexity. Compared with other complex deep learning models, the meta-model of TGRU can reduce the consumption of computing resources while ensuring high positioning accuracy by simplifying the architecture and optimizing the data processing flow. This optimization enables the meta-model to operate efficiently in the actual smart grid environment with limited resources.
[0117] The core objective of this meta-model is to find the abnormal behavior of specific sensors by analyzing the differences between the predicted data and attack data generated by the TGRU, so as to accurately locate the position of the attack. Since there are a large number of sensors in the smart grid, the data of each sensor will be regarded as an independent label. Through the multi-label classification method, the meta-model can simultaneously identify whether the data of multiple sensors has been attacked.
[0118] S42. Multi-label classification method
[0119] The multi-label classification method used by the meta-model is a classification method that can handle multiple labels simultaneously. In the scenario of the smart grid, each sensor can be regarded as an independent label. If multiple sensors are attacked simultaneously, multi-label classification can effectively identify and locate them.
[0120] Through multi-label classification, the meta-model can detect each sensor one by one to determine whether it has been attacked. This method greatly improves the accuracy of attack location and can handle complex multi-point attack scenarios. Especially in a large smart grid, it becomes particularly important to locate multiple attack points.
[0121] S5. Repeat steps S2 - S4 to continuously optimize the parameters of the TGRU model and the meta-model;
[0122] After the initial training of the TGRU model and attack detection and location, this step further improves the accuracy and robustness of the model through multiple rounds of repeated training and parameter optimization to ensure high performance can be maintained in different power grid operating environments and various attack situations. The process is introduced in detail as follows:
[0123] S51. Iterative training
[0124] In this step, the TGRU model and the meta-model will be optimized through multiple rounds of iterative training. In each round of iterative training, the system will use historical normal measurement data and simulated attack data to train and update the model parameters.
[0125] The TGRU model is trained using historical normal measurement data to generate predicted values of the current system state. The system optimizes the model parameters by comparing the differences between the predicted data of the TGRU model and the normal measurement data.
[0126] The optimization process calculates the error between the predicted value and the normal measurement data through the loss function MSE, and then updates the weight parameters of the model through the gradient descent algorithm:
[0127] (3);
[0128] In formula (3), is the The parameters of the TGRU model after round training; is the parameters of the model during the round training; is the gradient of the loss function during the
[0129] As each round of training progresses, the TGRU model gradually learns the normal operation mode of the smart grid.
[0130] In addition to the training of the TGRU model, during each round of training, the meta-model, as a multi-label classification model, is trained using the prediction data of the TGRU model and the simulated attack data. The goal of the meta-model is to accurately locate multiple sensors that may be attacked by analyzing the differences between the normal prediction data and the simulated attack data.
[0131] The input data of the meta-model includes the predicted values (normal data) of the TGRU model and the simulated attack data, and the attack status of the sensors is identified through a multi-label classification method. The loss function of the meta-model adopts the binary cross-entropy loss function in the multi-label classification task to calculate the difference between the actual label and the predicted label of each sensor:
[0132] (4);
[0133] In formula (4), is the actual label of the th sensor (0 indicates normal, 1 indicates attacked),
[0134] The meta-model updates the weight parameters according to the gradient of the loss function through the gradient descent algorithm:
[0135] (5);
[0136] In formula (5), is the weight parameter of the meta-model after round training; is the learning rate of the meta-model; is the gradient of the multi-label classification loss function of the meta-model.
[0137] During the training process, when the loss function of the model tends to be stable after multiple rounds of training, that is, the change amplitude is extremely small, it indicates that the optimization process of the model has been basically completed, and further training has limited effect on improving the model performance. At the same time, in order to avoid the model falling into overfitting, the system usually also sets a maximum number of training rounds. Even if the loss function and performance indicators are not completely stable, the system will automatically stop training after reaching the set number of rounds.
[0138] S52. Obtain the detection threshold
[0139] After each round of training, the system dynamically adjusts the detection threshold of the Euclidean distance according to the new round of training results. By calculating the Euclidean distance distribution between the predicted data of the TGRU model and the normal measurement data and attack data, the system can reset the optimal threshold to ensure effective discrimination between normal measurement data and attack data.
[0140] The core of this process lies in the system's self-adaptive adjustment of the threshold to adapt to different attack patterns and grid operating states, reducing false alarms and missed detections. After each round of training, the system calculates a new detection threshold based on the new distance distribution, and determines the final detection threshold after training. In this way, the model can more flexibly cope with the dynamically changing grid environment.
[0141] Experimental example
[0142] The present application was experimentally compared. The following are some basic settings for the experiment:
[0143] Based on multiple experimental results, the performance of the proposed TGRU model was evaluated. The simulation results were executed on the IEEE 14-bus power grid model. The simulation environment was set using MATPOWER. It was also compared with the Transformer, CNN-Transformer, and CNN models. Meanwhile, an hourly statistical power grid dataset was used, and the attack vector dataset used was generated by a formal model, aiming to avoid the detection of the BDD system by modifying sensor data, thereby causing significant deviations in the grid state. In this study, 90% of the dataset was used for training, and the remaining 10% was used for testing. The experiment was conducted on a system equipped with an NVIDIA GeForce GTX 1650 graphics card.
[0144] In the experimental section, the performance of the TGRU model in the FDIA detection and localization tasks in the smart grid was comprehensively evaluated, and a comparative analysis was carried out with other models, including CNN, CNN-Transformer, and Transformer. The experiment was mainly divided into four parts: prediction accuracy evaluation, attack detection effect analysis, and attack localization experiment, covering the performance and advantages of the model at different stages.
[0145] In the prediction accuracy evaluation section, normal data was used for training, and the measurement data for future time was predicted. To evaluate the prediction performance, MSE, RMSE, and MAE were used as measurement metrics. Table 1 shows the comparison results of the prediction performance of the TGRU model with other models, including Transformer, CNN-Transformer, and CNN:
[0146] Table 1 Performance Comparison Table of Different Models in Detecting False Data Injection Attacks
[0147]
[0148] The experimental results show that TGRU performs excellently in all three evaluation metrics. Specifically, the RMSE of TGRU is 1.4662, significantly lower than 11.5126 of CNN and 12.0760 of Transformer, indicating that it is more accurate in capturing complex data patterns. In addition, the MSE of TGRU is 3.3931, significantly better than 246.7321 of CNN and 273.0599 of Transformer. These data show that TGRU has obvious advantages in processing large-scale normal power grid measurement data. Although CNN-Transformer has improved in some metrics, its prediction accuracy is still not as good as TGRU. By combining the global dependency extraction ability of Transformer with the temporal processing advantage of GRU, the TGRU model not only improves the prediction accuracy but also significantly reduces the computational complexity. This optimization of the architecture enables the TGRU model to more effectively address the detection and localization problems of false data injection attacks in smart grids.
[0149] As Figure 2 shown, to evaluate the detection effect of the TGRU model, 120 simulated false data samples were generated, and 90% of them were injected into the normal measurement data. By analyzing the data distribution after the injection attack, it was found that when the threshold was set to 0.4, the TGRU model could effectively distinguish normal data from attack data, thus achieving accurate detection. In the part of analyzing the attack detection effect, the present invention verified the effectiveness of the found threshold in dealing with unknown attacks. The present invention used all the generated attack vectors for testing, and by adjusting the threshold from 0 to 1 at intervals of 0.1, its performance under unknown attacks was evaluated. The experimental results are as Figure 3 shown. When the threshold of the TGRU model is between 0.4 and 0.6, the precision, recall rate, and F1 score are all close to 1.0. Especially when the threshold is 0.4, all three metrics reach 0.9964, showing strong robustness and adaptability.
[0150] In the part of the attack localization task, the performance of each model in the task of locating the attack position was compared as shown in Table 2. These experiments were carried out after confirming that the data contained attack behaviors:
[0151] Table 2 Model Performance and Training Time Comparison Table of Different Models in Attack Localization Tasks
[0152] Model Precision Time(s) CNN 0.9971 202.78 CNN-Transformer 0.9967 249.14 Transformer 0.9990 305.15 TGRU meta-model 0.9982 116.82
[0153] The experimental results show that the Transformer model performs best with an accuracy of 0.9990, but its complex architecture leads to high computational resource requirements and a long training time of 305.15 seconds. In contrast, the TGRU model also performs excellently with an accuracy of 0.9982, and its training time is significantly shorter, 116.82 seconds, making it suitable for applications in resource-constrained environments.
[0154] The accuracy of the CNN model in the localization task is 0.9971, but the training time is long, 202.78 seconds, and its performance is inferior to that of the TGRU and Transformer. The CNN-Transformer model performs the worst.
[0155] The TGRU model shows a more balanced advantage in terms of accuracy, training time, and resource consumption, making it suitable for resource-constrained environments. The Transformer model has a slight advantage in accuracy but requires higher computational resource support.
[0156] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the claims of the present invention shall be included within the protection scope of the claims of the present invention.
Claims
1. A false data injection attack detection and location method based on TGRU, characterized in that: The method comprises: S1, obtain normal measurement data from the historical data of multiple sensors, preprocess the data, and initialize the TGRU model and meta-model; S2. Use the preprocessed normal measurement data to train the TGRU model: use the Transformer encoder to extract global features, and process the time series data through GRU to generate prediction values; use the Adam optimizer during training; S3. After the TGRU model training is completed, simulated attack data is generated, and a dual Euclidean distance calculation mechanism is used to calculate the Euclidean distance between the TGRU prediction value and the normal measurement data on the one hand, and the Euclidean distance between the TGRU prediction value and the generated attack data on the other hand, to form a distribution map based on the dual Euclidean distance. The distribution difference between the normal measurement data and the generated attack data on the distribution map is used to set a threshold to distinguish between normal data and attack data; the details are as follows: S31. Simulated attack data generation Perform specific false data injection operations on normal data to obtain simulated attack data; S32. Calculation of Euclidean distance The double Euclidean distance mechanism is used for analysis to form a distribution graph based on the double Euclidean distance. First, the Euclidean distance between the predicted value of the TGRU model for each time step and the normal data is calculated. The formula is as follows: (1); In formula (1), Indicates that the TGRU model is The predicted value on a feature represents the TGRU model's estimate of the time step and the feature; Indicates the actual value measured by the sensor. The value of a feature represents the real state of the power grid at this time step, that is, normal data; The number of features representing the sensor data; Secondly, the Euclidean distance between the predicted value of the TGRU model for each time step and the simulated attack data is calculated as follows: (2); In formula (2), It represents the value of the i-th feature in the simulated attack state, which is the simulated attack data generated by injecting specific false data into normal data; S33, threshold setting The threshold is set based on a distribution diagram of double Euclidean distance, in which the distance distribution of normal data is relatively concentrated, while the distance distribution of attack data is relatively discrete; Analyze the distance distribution of normal data and attack data, determine the distinction between the two, and set a threshold; S34. Detection Mechanism When new sensor data enters the system, the TGRU model predicts the data at the current moment and calculates the Euclidean distance between the predicted value at the current moment and the actual sensor reading. If the Euclidean distance between the predicted value at the current moment and the actual sensor reading is less than the set threshold, the data is normal data; if the Euclidean distance between the predicted value at the current moment and the actual sensor reading exceeds the set threshold, the system will issue an alarm to indicate the existence of a false data injection attack; S4. After the attack is detected, the meta-model is trained using the TGRU prediction data and the detected attack data to accurately locate the attack location, as follows: S41. Data processing and metamodel training Once the false data injection attack FDIA is detected at the current moment, the prediction data generated by the TGRU model at the current moment will be integrated with the detected attack data to form combined data; The system then inputs these combined data into a simplified positioning model, namely the meta-model; the meta-model uses a fully connected neural network FCL to process the combined data, identifies the abnormal behavior of each sensor by analyzing the difference between the TGRU prediction value and the actual attack data, and combines the multi-label classification method to enable the meta-model to simultaneously detect the status of multiple sensors, thereby accurately locating the attacked sensor. S42. Multi-label classification method Each sensor is considered as an independent label, and the meta-model uses a multi-label classification method to identify and locate multiple sensors that are attacked at the same time; S5. Repeat steps S2 to S4 to optimize the TGRU model and meta-model through multiple rounds of iterative training, continuously optimize the parameters of the TGRU model and meta-model, and set the maximum number of training rounds.
2. The false data injection attack detection and location method based on TGRU according to claim 1 is characterized in that: The specific steps in step S1 are as follows: S11. Data Acquisition Extract measurement data within a specific time range from the historical data of the sensor as historical measurement data, and the historical measurement data is the operation data of the automation system in a normal state, that is, normal measurement data; S12. Data preprocessing First, data cleaning is performed to remove outliers and noise caused by sensor failure, external interference, and acquisition errors. Second, missing values are filled. Finally, normalization is performed and Min-Max scaling is used to scale the data to the same range; S13. Model initialization After data preprocessing is completed, the TGRU model for false data injection attack FDIA detection needs to be initialized: First, the Transformer encoder is initialized. The Transformer encoder is used to extract the global features of the input data. The parameters of the Transformer encoder include the attention weight matrix, multi-head attention layer and fully connected layer. Next is the initialization of GRU. GRU is responsible for processing the dependencies of time series data. The parameters of GRU include the input weight matrix, hidden state weight matrix and bias term. Finally, the meta-model is initialized. The meta-model is used to locate attacks. The meta-model is a fully connected neural network used to process the combination of prediction data and attack data generated by TGRU.
3. The false data injection attack detection and location method based on TGRU according to claim 1 is characterized in that: The specific steps in step S2 are as follows: S21, the first part of the TGRU model, the Transformer encoder extracts global features from the input data: in time series data, the Transformer calculates the correlation between each time step and other time steps through a multi-head self-attention mechanism, focusing on the most relevant information; During the training process, the Transformer layer encodes the normal measurement data, extracts the dependencies between sensors and different time steps, and provides a higher-level feature representation for subsequent time series processing; S22. After extracting global features, the second part of the TGRU model, GRU, processes dependencies in the time series: GRU controls the flow of information through update gates and reset gates to decide which historical information to retain or discard; during training, GRU gradually processes the features generated by Transformer to generate predicted values for the sensor data at the current moment.
4. The false data injection attack detection and location method based on TGRU according to claim 1 is characterized in that: In the process of optimizing the TGRU model and the meta-model through multiple rounds of iterative training, the error between the predicted value and the normal measurement data is calculated by the loss function MSE, and then the weight parameters of the model are updated by the gradient descent algorithm. The formula is as follows: (3); In formula (3), For the TGRU model parameters after rounds of iterative training; For the TGRU model parameters in round iterative training; is the learning rate, which controls the step size of model parameter update; It is The gradient of the loss function in the training round; The loss function of the meta-model adopts the binary cross entropy loss function in the multi-label classification task to calculate the difference between the actual label and the predicted label of each sensor: (4); In formula (4), It is The actual label of the sensor, 0 means normal, 1 means attacked, is the metamodel’s predicted label for the sensor’s attack status; The meta-model updates the weight parameters according to the gradient of the loss function through the gradient descent algorithm. The formula is as follows: (5); In formula (5), For the metamodel in Weight parameters after rounds of iterative training; is the learning rate of the meta-model; is the gradient of the meta-model multi-label classification loss function.
Citation Information
Patent Citations
Power grid false data injection detection method and device based on double-branch CNN-LSTM
CN116881714A
Power false data injection attack detection method and system based on deep learning
CN118779787A
Power grid false data injection attack detection method of artificial intelligence four-layer architecture
CN115834161A
Intrusion detection method and system based on feature selection and transformer-BiGRU
CN118199933A