A two-dimensional safety risk assessment method of data-driven state estimation
By establishing a two-dimensional security risk assessment method based on artificial neural networks and CGAN to evaluate the attack cost and business vulnerability of data-driven state estimation, the problem of insufficient security risk assessment against attacks in new power systems is solved, providing a guarantee for system stability.
Patent Information
- Application Number
- CN202411537168.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-31
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-10-31
AI Technical Summary
Existing data-driven state estimation methods are easily targeted by adversarial attacks in new power systems and lack effective security risk assessment methods, leading to data security threats and system stability problems.
A data-driven state estimation model based on an artificial neural network architecture is used in combination with a conditional generative network (CGAN) to launch adversarial attacks. Through the attacker's perspective and business vulnerability assessment, a two-dimensional security risk assessment system is established to evaluate attack costs, resources, attack intensity, and concealment.
It reveals the security risks in data-driven state estimation, provides a scientific basis for formulating defense measures, reduces attack costs and improves system stability.
Smart Images

Figure CN119323357B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of safety risk assessment, and particularly relates to a two-dimensional safety risk assessment method for data-driven state estimation. BACKGROUND
[0002] The diversification of operation modes, the randomization of power flow distribution and the complication of stability mechanism of new power systems put forward higher requirements for the real-time and accuracy of wide-area system state perception. The data-driven system under the new architecture provides new possibilities for the observability expansion of state estimation. However, the problems such as ubiquitous access, massive data transmission and frequent real-time interaction of new power systems threaten the data security of state estimation. The sensitivity to small perturbations and the limitation of generalization ability make the data-driven state estimation become the target of adversarial attacks.
[0003] Under this background, it is necessary to continuously optimize the data-driven state estimation method, and timely detect and evaluate potential safety risks to ensure the stable and reliable operation of the power system. It is particularly urgent to systematically evaluate and research the safety problems that may be caused by data-driven algorithms in state estimation. However, the research on these safety risks is still relatively lacking. SUMMARY
[0004] The technical problem to be solved by the present application is to overcome the shortcomings of the prior art and provide a two-dimensional safety risk assessment method for data-driven state estimation. The present application discloses the safety risks existing in the existing data-driven state estimation, and provides a scientific basis for formulating corresponding defense measures.
[0005] The present application adopts the following technical solutions to solve the above technical problems:
[0006] According to the two-dimensional safety risk assessment method for data-driven state estimation provided by the present application, the method comprises the following steps:
[0007] Based on an artificial neural network architecture, a data-driven state estimation model is established;
[0008] Based on the perspective of an attacker, a conditional generative network CGAN is used to launch an adversarial attack on the data-driven state estimation model;
[0009] From the first dimension and the second dimension, the safety risks faced by the state estimation under the adversarial attack are evaluated, wherein
[0010] The first dimension refers to the strategy analysis of the attacker. The first dimension evaluation of the safety risks faced by the state estimation under the adversarial attack refers to evaluating the attack cost and resources required by the attacker when implementing the adversarial attack;
[0011] The second dimension refers to business vulnerability assessment, and the second dimension refers to the security risk faced by the state estimation against attack, that is, the attack strength and concealment of the attack against attack are evaluated.
[0012] The evaluation indexes of the attack cost and resources in the first dimension and the attack strength and concealment in the second dimension are weighted and summed to establish a two-dimensional security risk assessment system to implement the security risk assessment of data-driven state estimation.
[0013] As a further optimization scheme of the two-dimensional security risk assessment method of data-driven state estimation, a data-driven state estimation model is established, and the specific implementation is as follows:
[0014] Firstly, the attacker captures real-time and historical data from multiple data sources through the power system monitoring mechanism, and the data includes measurement data and system running state, and the historical data is integrated into an original data set I={X 1:S ,Z 1:S} used to train the data-driven state estimation model, wherein X 1:S is S original state quantities, and Z 1:S is S original measurement; then, based on the artificial neural network architecture, the data-driven state estimation model f 1:S (*) is constructed according to the obtained original data set I={X 1:S ,Z θ}, and the objective function is defined as minimizing the prediction error; further, the prediction ability of f θ (*) is refined through the gradient descent optimization algorithm, and the nonlinear relationship between the measurement and the state quantity is simulated.
[0015] As a further optimization scheme of the two-dimensional security risk assessment method of data-driven state estimation, the CGAN is used to launch an attack against the data-driven state estimation model, including:
[0016] The process of launching the attack against the attack is as follows: firstly, the attacker obtains the original data set of the attack node under different running states of the power system; then, the generator and the discriminator two deep network architectures in the CGAN are constructed, and the CGAN is updated through the alternating adversarial training method; further, the label information consistent with the attacker's intention is determined, the original measurement of the power system is collected, the attacker generates the disturbance quantity u using the generator, and the disturbance quantity and the original measurement z are superimposed to form the simulated measurement z' which cannot be distinguished by the discriminator, and the simulated measurement is consistent with the label information; finally, the predicted state quantity x' output by the data-driven state estimation model is tested, and the attack against the data-driven state estimation model under the given label information is completed.
[0017] As a further optimization scheme of the two-dimensional safety risk assessment method of data-driven state estimation, the generator and the discriminator in the CGAN include:
[0018] The generator G in the CGAN inputs a set of original measurement z and label information y, and in an iterative process, the generator generates a disturbance quantity u having the same distribution as the original measurement, and forms simulated measurement z' by superimposing the disturbance quantity u and the original measurement z;
[0019] The discriminator D in the CGAN inputs a set of original measurement z and simulated measurement z' to form a data batch, and then inputs the data batch and the label information y respectively, and then inputs them into the discriminator together; the discriminator distinguishes the original measurement and the simulated measurement, and the discriminator classifies the given data batch as real or false; when the simulated measurement approximates the original measurement and meets the pre-set label information, it is classified as real.
[0020] As a further optimization scheme of the two-dimensional safety risk assessment method of data-driven state estimation, a two-dimensional safety risk assessment system is established, and the specific implementation is as follows:
[0021] In a power system with a total of K nodes, it is assumed that an attacker launches A times of adversarial attacks on N attack nodes, 1≤N≤K, and determines the evaluation indexes corresponding to the two dimensions of attacker strategy analysis and business vulnerability assessment respectively;
[0022] The four evaluation indexes of attack cost and resource in the first dimension and attack strength and concealment in the second dimension are weighted and summed to obtain a safety risk assessment score.
[0023] As a further optimization scheme of the two-dimensional safety risk assessment method of data-driven state estimation, the evaluation indexes include:
[0024] The first dimension:
[0025] The average attack cost c and the resource r required for the attack are defined a The attack entry point and sustainability are analyzed according to the obtained attack cost and resource evaluation results;
[0026] The ratio of the disturbance quantity generated by the generator in the adversarial attack to the original measurement, i.e. the relative disturbance error, is taken as the measurement standard of the attack cost; for the i th attack node, 1≤i≤N, c i The attack cost of the i th attack node is calculated, 1≤j≤A, and it is assumed that each attack is independent; the attack costs of all attacks are summed to obtain the average attack cost c of the total A times of adversarial attacks;
[0027] The resource r required for the attacka The ratio of the number of attack nodes selected by the attacker to the total number of nodes of the power system is used for representation;
[0028]
[0029] Wherein, a i Whether the attack cost of the i th attack node meets the pre-set threshold requirement λ, u i The disturbance amount generated by the generator on the i th attack node, z i The original measurement of the i th attack node;
[0030] The average attack cost represents the attack cost required by the attacker when launching the adversarial attack on the data-driven state estimation model, and whether the adversarial attack is sustainable depends on the cost of attack investment and the resources required by the attack; the selected attack node represents the required resources of the attack, and is used to indicate the attack entry point;
[0031] The second dimension:
[0032] The average attack result deviation Δx and the probability B of attack bypassing the bad data detection are defined; the attack strength and concealment of the adversarial attack are evaluated according to the obtained attack result deviation and the probability of attack bypassing the bad data detection mechanism;
[0033] The distance between the predicted state quantity output by the data-driven state estimation model under the adversarial attack and the original state quantity is taken as the measurement standard of the attack result deviation; for the i th attack node, 1≤i≤N, the attack result deviation of the j th adversarial attack is calculated for all attack nodes, 1≤j≤A, assuming that each attack is independent, the sum of the attack result deviations of all attacks is obtained, and the average attack result deviation Δx of the total A times of adversarial attacks is obtained;
[0034]
[0035]
[0036] Wherein, B j To represent whether the j th attack in the total A times of adversarial attacks can bypass the bad data detection, x i ′ is the predicted state quantity output by the data-driven state estimation model after the analog measurement is input into the data-driven state estimation model, x i is the original state quantity of the i th attack node;
[0037] The average attack result deviation represents the attack strength of the adversarial attack, and the concealment of the adversarial attack is measured by the probability of attack bypassing the bad data detection.
[0038] Compared with the prior art, the above technical scheme has the following technical effects:
[0039] The present application considers the sensitivity of current data-driven algorithms to small perturbations, and provides a two-dimensional security risk assessment method for data-driven state estimation under CGAN-based adversarial attacks, which explores the security vulnerabilities from two dimensions of attacker strategy analysis and business vulnerability assessment, evaluates the risk impact of attack cost and attack strength, and reveals the security threats existing in the existing data-driven state estimation, and provides a scientific basis for formulating corresponding defense measures. BRIEF DESCRIPTION OF DRAWINGS
[0040] Figure 1 A flowchart of the method of the present application;
[0041] Figure 2 A schematic diagram of a data-driven state estimation model based on an artificial neural architecture according to the present application;
[0042] Figure 3 A schematic diagram of the CGAN structure according to the present application;
[0043] Figure 4 A schematic diagram of the two-dimensional security risk assessment method according to the present application;
[0044] Figure 5 An IEEE-39 node power grid model according to the present application;
[0045] Figure 6 A data-driven state estimation model test curve according to the present application; wherein (a) is the voltage amplitude V, and (b) is the phase angle θ;
[0046] Figure 7 An adversarial attack result diagram according to the present application; wherein (a) is normal to upper boundary crossing, (b) is upper boundary crossing to lower boundary crossing, (c) is upper boundary crossing to normal, and (d) is lower boundary crossing to upper boundary crossing;
[0047] Figure 8 A comparison diagram of attack cost of the present application and the adversarial attack method based on FGSM; wherein (a) is the adversarial attack based on FGSM, and (b) is the attack method according to the present application. DETAILED DESCRIPTION
[0048] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be described in detail below with reference to the drawings and specific embodiments.
[0049] As shown in Figure 1 A two-dimensional security risk assessment method for data-driven state estimation (SE) under adversarial attacks based on conditional generative adversarial network (CGAN), the method comprising the following steps:
[0050] a data-driven state estimation model is established based on an artificial neural network architecture;
[0051] Based on the perspective of the attacker, a conditional generative network CGAN is used to launch an adversarial attack on the data-driven state estimation model;
[0052] From the first dimension and the second dimension, the security risks faced by the state estimation under the adversarial attack are evaluated, wherein,
[0053] The first dimension refers to the strategy analysis of the attacker, and the first dimension evaluation of the security risks faced by the state estimation under the adversarial attack refers to: evaluating the attack cost and resources required by the attacker when implementing the adversarial attack;
[0054] The second dimension refers to the business vulnerability evaluation, and the second dimension evaluation of the security risks faced by the state estimation under the adversarial attack refers to: evaluating the attack strength and concealment of the adversarial attack;
[0055] According to the logical order of the attack, the evaluation indexes of the attack cost and resources in the first dimension and the attack strength and concealment in the second dimension are weighted and summed to establish a two-dimensional security risk evaluation system to implement the security risk evaluation of the data-driven state estimation.
[0056] The data-driven state estimation model is established as follows:
[0057] As shown in Figure 2 , the present application selects a deep neural network (DNN) in an artificial neural network architecture to establish a data-driven state estimation model, and the specific process is as follows:
[0058] Firstly, the attacker captures real-time and historical data from multiple data sources through the power system monitoring mechanism, and the data includes measurement data and system running state, and the historical data is integrated into an original data set I={X 1:S ,Z 1:S} used for training the data-driven state estimation model, wherein X 1:S is S groups of original state quantities, and Z 1:S is S groups of original measurement quantities; then, based on the DNN, the data-driven state estimation model f 1:S (*) is constructed according to the obtained original data set I={X 1:S ,Z θ}, and the objective function is defined as minimizing the prediction error; further, the prediction ability of f θ (*) is refined through the gradient descent optimization algorithm, and the nonlinear relationship between the measurement and the state quantity is simulated;
[0059]
[0060] wherein, S sets of predicted state quantities estimated for the data-driven state estimation model. The loss function L(0) is used to measure the difference between the predicted state quantities of the data-driven state estimation model and the original state quantities X . 1:S is a pre-set loss function, 0 t+1 is the model parameter updated after the t+1th round of training, 0 t is the model parameter obtained after the current tth round of training. η is the learning rate, is the loss function L(0 (t) ) after the current tth round of training with respect to the model parameter 0
[0061] The model parameter 0 is updated according to the gradient descent algorithm to minimize the loss function.
[0062] The process of launching an adversarial attack on the data-driven state estimation model using the CGAN includes:
[0063] The process of launching an adversarial attack is as follows: first, the attacker obtains the original data set of the attack nodes under different operating states of the power system; then, the two deep network architectures of the generator and the discriminator in the CGAN are constructed, and the CGAN is updated through the alternating adversarial training method; further, the label information consistent with the attacker's intention is determined, the power system measurement is collected, and the attacker uses the generator to generate the disturbance quantity u, which is superimposed with the original measurement z to form the simulated measurement z', which cannot be accurately distinguished by the discriminator. The simulated measurement is consistent with the label information; finally, the predicted state quantity x' output by the data-driven state estimation model is verified, and the adversarial attack on the data-driven state estimation model under the given label information is completed.
[0064] In a power system, assume that there are N attack nodes, and the attack nodes are M-dimensional vectors. The original measurement of each attack node is denoted as z = [z1, z2, … z N ] T , z n’ is then'th original measurement, 1≤n'≤N, the superscript T represents the transpose, and the original state quantity is denoted as x = [x1, x2, … x N ] T , x n’ is then'th original state quantity, the disturbance quantity generated by the generator is u = [u1, u2, … u N ] T , u n’ is then'th disturbance quantity, u is superimposed on the original measurement to form the simulated measurement z', and the predicted state quantity output by the data-driven state estimation model after z' is denoted as x'. G(*) represents the mapping relationship of the generator, and D(*) represents the mapping relationship of the discriminator.
[0065] Combined with the formula, the process of launching an adversarial attack against the i-th attack node is expressed as follows, 1≤i≤N:
[0066] u i =G(z i ,y)
[0067]
[0068] {d i ,d i ′}=D(z i ,z i ′,y)
[0069] x i ′=f θ (z i ′)
[0070] Among them, u i is the perturbation amount generated by the generator on the i-th attack node, z i is the raw quantity measurement of the i-th attack node, z i (M,:) means taking z i All M-dimensional attack vectors, z i ′ is the analog measurement formed by the attacker at the i-th attack node, and F(*) is z i 、u i and z i ′, F(*) represents the superposition relationship, d i The original quantity measurement and label information y are input into the discriminator’s discrimination result, d i ′ is the discrimination result of the discriminator inputted with the analog measurement and the label information y, d i and d i ′ are all probability vectors output by the sigmoid function of the last layer of the discriminator, x i ′ is the analog measurement z i ′ is input into the data-driven state estimation model and outputs the predicted state quantity.
[0071] The generator and discriminator in the CGAN include:
[0072] like Figure 3 As shown in Figure 2, the generator G in CGAN takes as input a set of original measurements z and label information y. During the iteration process, the generator generates perturbations u with the same distribution as the original measurements, and superimposes the perturbations u with the original measurements z to form simulated measurements z′.
[0073] The discriminator D in the CGAN forms a data batch with a set of original measurements z and simulated measurements z', inputs the data batch and the label information y respectively, and then inputs them into the discriminator together; the discriminator distinguishes the original measurements and the simulated measurements, and classifies the given data batch as real or fake; when the simulated measurements approximate the original measurements and meet the pre-set label information, the classification is real;
[0074] The CGAN is trained according to the loss function J(*);
[0075]
[0076] wherein, indicates that the original measurements z are subject to the distribution P z (z).
[0077] The establishment of the two-dimension security risk assessment system comprises:
[0078] In a power system with a total of K nodes, assuming that an attacker launches an adversarial attack A times on N attack nodes, 1≤N≤K, determine the evaluation indexes corresponding to the attacker strategy analysis and the business vulnerability assessment in two dimensions respectively;
[0079] Weighted sum of the four evaluation indexes of the attack cost and resources in the first dimension and the attack strength and concealment in the second dimension, to obtain the security risk assessment score R:
[0080] R=(R1c+R2r a )+(R3Δx+R4B)
[0081] Wherein, R1-R4 are the weighted coefficients of the four evaluation indexes of the attack cost and resources in the first dimension and the attack strength and concealment in the second dimension, and the weighted coefficients are pre-set according to the system size, attack target and evaluation standard.
[0082] The evaluation indexes comprise:
[0083] The first dimension:
[0084] The average attack cost c and the resources r required for the attack are defined a According to the obtained attack cost and resource evaluation results, the attack entry point and sustainability are analyzed;
[0085] The ratio of the disturbance quantity generated by the generator in the adversarial attack to the original measurement, i.e. the relative disturbance error, is taken as the measurement standard of the attack cost; for the i-th attack node, 1≤i≤N, c iThe attack cost of the ith attack node is calculated for all attack nodes, and the attack cost of the jth attack is calculated, 1≤j≤A, assuming that each attack is independent, and the sum of the attack costs of all attacks is calculated to obtain the average attack cost c of the total A times of attack;
[0086] The resources r required for the attack a The ratio of the number of attack nodes selected by the attacker to the total number of nodes in the power system is used to represent.
[0087]
[0088] Wherein, a i To represent whether the attack cost of the ith attack node meets the pre-set threshold requirement λ, u i The disturbance amount generated by the generator on the ith attack node is z i The original measurement of the ith attack node is x
[0089] The average attack cost represents the attack cost required by the attacker when launching an attack against the data-driven state estimation model, and whether the attack can be sustained depends on the cost of the attack input and the resources required for the attack; the selected attack node represents the resources required for the attack, and is used to indicate the attack point;
[0090] Second dimension:
[0091] The average attack result deviation Δx and the probability B of attack bypassing bad data detection are defined; the attack strength and concealment of the attack are evaluated according to the obtained attack result deviation and the probability of attack bypassing the bad data detection mechanism;
[0092] The distance between the predicted state quantity output by the data-driven state estimation model under the attack and the original state quantity is used as a measure of the attack result deviation. For the ith attack node, 1≤i≤N, the attack result deviation of the jth attack is calculated for all attack nodes, 1≤j≤A, assuming that each attack is independent, and the sum of the attack result deviations of all attacks is calculated to obtain the average attack result deviation Δx of the total A times of attack;
[0093]
[0094] Wherein, B j To represent whether the jth attack in the total A times of attack can bypass the bad data detection, x i ′ is the predicted state quantity output by the data-driven state estimation model after the analog measurement is input into the data-driven state estimation model, x i is the original state quantity of the ith attack node;
[0095] The average attack result deviation represents the attack strength of the adversarial attack, and the stealthiness of the adversarial attack is measured by the probability that the attack can bypass the detection of bad data.
[0096] Figure 4 Schematic diagram of the two-dimensional security risk assessment method.
[0097] An optional implementation manner of the present invention is described in detail below.
[0098] In one embodiment of the present invention, the above-mentioned security risk assessment method is applied to Figure 5 The IEEE-39-node grid model shown in the figure consists of 39 buses, 19 loads, and 10 generators. In this scenario, uniform sampling is used to obtain 10,000 steady-state samples, or raw quantity measurements, including node active power P, reactive power Q, and voltage amplitude V. The dimensions of P, Q, and V are all 39 x 10,000. The validation scenario database is generated using the Monte Carlo method, with the following random parameters: load levels follow a uniform distribution in the range [0.8, 1], and load variations follow a normal distribution in the range N(0, 0.03).
[0099] For the state estimation problem in the power system, the main focus is on the stable state of the power grid at a specific time point, including the voltage amplitude and angle, the injected power of the bus, etc., which plays a key role in preventing faults and optimizing power grid operation. The present invention uses the voltage amplitude state as an attack guide to verify the effectiveness of the method in assessing voltage safety risks.
[0100] We further supplemented the data with 2000 sets of abnormal voltage amplitude status samples, including 1000 sets of over-bounded and under-bounded samples. In this example, the normal voltage per unit value range is set to 0.95 to 1.05. Over-bounded refers to samples where the voltage per unit value of some nodes exceeds 1.05, and under-bounded refers to samples where the voltage per unit value is below 0.95.
[0101] After learning and optimizing the training data set, the DNN-based data-driven state estimation model can effectively identify and measure the complex relationship between data and system state, such as Figure 6 The test results shown, Figure 6 (a) is the voltage amplitude V, Figure 6 (b) in the figure is the phase angle θ. When the model predicts the voltage amplitude and phase angle, the mean absolute error (MAE) is 0.0013 and 0.0019 respectively, indicating that the model has high prediction accuracy, thus providing a business-side state estimation model foundation for the CGAN-based adversarial attack.
[0102] The method performs preliminary attack cost and resource assessment on all nodes, determines which nodes have smaller true values and are more sensitive to attacks based on the attacker's perspective. Based on the evaluation results, select those nodes with the best attack effect and lower resource demand for attack. In the examples described in the present application, after screening, the attacker only implements the adversarial attack on 28 nodes of the IEEE-39 node power grid model, and these nodes are used as the breakthrough point of the attack, so as to more efficiently use the limited resources.
[0103] Figure 7 For the adversarial attack result graph of the present application, Figure 7 (a) in (a) is from normal to upper bound, Figure 7 (b) in (b) is from upper bound to lower bound, Figure 7 (c) in (c) is from upper bound to normal, Figure 7 (d) in (d) is from lower bound to upper bound; wherein the dashed line represents the upper bound standard of 1.05, and the dotted line represents the lower bound standard of 0.95. In the security risk assessment method, the output of the data-driven SE model can be modified in a targeted manner based on the adversarial attack of the CGAN from the perspective of the state estimation business, and the samples subjected to the adversarial attack can cause all state variables V to be incorrectly estimated as a preset label category, such as causing the original normal sample to be misjudged as an out-of-bound sample, thereby interfering with the reliable operation of subsequent businesses.
[0104] In the attacker strategy analysis dimension, the CGAN uses node information as the breakthrough point, uses the learning process of the data distribution and features obtained by the attacker to replace the direct modeling of the physical mechanism of the power system, and uses the generated simulation measurement influence model. As long as the observation authority of the system measurement value within a period of time is mastered, a sustained adversarial attack can be launched, which can cause serious consequences to the system decision. At the same time, the reduction and efficient use of attack nodes also reduce the difficulty of obtaining attack resources and attack costs.
[0105] Test the possibility of attack bypassing the bad data detection mechanism in the security risk assessment method. Table 1 shows the average bypass rate of the simulated measurement and the original measurement under different detection thresholds. It can be observed that for a threshold greater than 1.2, the bad data detection bypass rates of the two are very close, which indicates that the simulated measurement and the original measurement generated by the method have a similar distribution. At the same time, through analysis, the degree of freedom of the network is 39, assuming that the weighted residual sum of squares follows the chi-square distribution, and the significance level alpha is 0.01, the test value in the distribution table is 62.42. The weighted sum of squares estimated value corresponding to the generated simulated measurement is 19.95, so the estimation result meets the residual test.
[0106] Table 1 Bypass rate of bad data detection of simulated measurement under different thresholds
[0107] Threshold Raw measurement Analog measurement 1.02 0.98 0.78 1.05 0.98 0.84 1.08 0.99 0.92 1.2 0.99 0.98 2 0.99 0.99
[0108] In the business vulnerability assessment dimension, the attack strength of the proposed attack method is quantified. After the label information conforming to the attack intention is given, the proposed method can guide the system original state quantity to the preset state quantity corresponding to the label information, so that the voltage amplitude produces a larger deviation, and the purpose of manipulating the data-driven SE model is achieved. At the same time, by analyzing the bypass rate of bad data detection, the proposed attack also has a certain guarantee in the aspect of concealment, which injects potential security risks for state estimation business and confirms the vulnerability of the attack against it.
[0109] In order to further verify the effectiveness of the security risk assessment method of data-driven state estimation under the proposed attack against, the following two attack schemes are adopted for comparison:
[0110] Scheme 1: FGSM-based attack against method;
[0111] Scheme 2: The proposed attack against method based on CGAN.
[0112] The perturbation amount ε of the FGSM algorithm is set to 0.1, and the relative error of the superimposed perturbation on the measurement data in scheme 1 compared with the proposed method, i.e. the attack cost, is verified. The comparison results are shown in Figure 8 Figure 8 (a) in the figure is the FGSM-based attack against, Figure 8 (b) in the figure is the proposed attack method. As can be seen from the figure, the relative error of the superimposed perturbation in scheme 1 at each node is up to 30 times, and the average perturbation relative error of more than 70% of the measurements is higher than 10%. In scheme 2, the error of most attack nodes is within 10%, and the error of less than 3% of the measurements exceeds 20%, and the relative error of the perturbation superimposed on the reactive power and voltage amplitude is less than 20%, and the attack cost is generally much smaller than that of the attack against in scheme 1.
[0113] Table 2 selects five buses to present the comparison results of the two methods. Compared with scheme 1, in the case of a certain number of attack buses, the superimposed perturbation of scheme 2 is smaller, and the attack cost is lower. Taking node 38 as an example, the relative errors of active power and reactive power in scheme 1 are 4.3 and 0.48 respectively, while scheme 2 only needs to superimpose relative perturbation values of 0.01 and 0.183, which are much smaller than the former.
[0114] Table 2 Comparison of attack costs of two methods
[0115]
[0116] Similarly in the attacker strategy analysis dimension, the method in scheme 1 can achieve the attack effect that meets the attack intention with less attack cost, and has more significant attack sustainability.
[0117] To sum up, the application proposes a double-dimensional security risk assessment method for data-driven state estimation under adversarial attack. First, based on the artificial neural network architecture, a data-driven state estimation model is established to simulate the nonlinear relationship between measurement and state quantity. Then, based on the perspective of the attacker, CGAN is used to launch adversarial attack on the data-driven state estimation model. Then, from two dimensions, the security risks of state estimation under adversarial attack are evaluated. Dimension one refers to the attacker strategy analysis, which evaluates the attack cost and resources required by the attacker when implementing adversarial attack. Dimension two refers to business vulnerability assessment, which evaluates the attack strength and concealment of adversarial attack. Finally, according to the logical order of attack, a double-dimensional security risk assessment system is established. The actual operation effect of the proposed scheme is verified by examples. From the perspective of security risk assessment, the security risks existing in data-driven state estimation are revealed, which provides a theoretical basis and practical guidance for designing and implementing effective defense measures.
[0118] Under the background of current new power system operation mode diversification and stability mechanism complication, the problems of ubiquitous access and massive data transmission will threaten the data security of state estimation. The sensitivity to small perturbations and the limitation of generalization ability make data-driven state estimation an easy attack target. Attackers can launch hidden adversarial attacks to threaten the stable operation of state estimation business. However, the research on these security risks and attack threats is still relatively lacking.
[0119] The application aims to provide a double-dimensional security risk assessment method for data-driven state estimation to comprehensively reveal the security risks existing in existing data-driven state estimation, thereby providing a scientific basis for formulating corresponding defense measures.
[0120] The innovation of the application lies in:
[0121] 1. The application innovatively launches adversarial attack on the data-driven state estimation model based on CGAN, improves and optimizes the basic model, realizes the reduction of attack cost, and makes the attack result produce a preset deviation according to the intention of the attacker, so as to maximize the security risks of state estimation business under adversarial attack and provide attack basis for the evaluation system.
[0122] 2. The application innovatively proposes a double-dimensional security risk assessment method from the perspectives of the attacker and the system business. According to the logical order of attack, from the acquisition of attack source to the implementation of attack behavior, and then to the malicious results caused by attack and the corresponding attack detection means, the influence of adversarial attack on state estimation business is considered more comprehensively.
[0123] The application of the present application is:
[0124] 1. The attack method is not only limited to the artificial neural network architecture DNN used in the data-driven state estimation model instance of the present application, but also applicable to other various data-driven state estimation models, and has strong adaptability.
[0125] 2. The method described in the present application is mainly applied to the technical field of power system security risk assessment. By using the attack method described in the invention to mine the potential vulnerabilities of the state estimation business, the security risk assessment system analyzes the attacker's strategy and the vulnerability of the business, thereby providing a scientific basis for formulating corresponding defense measures and providing strong support for the security of future power systems.
[0126] 3. The actual application can be carried out by constructing an active defense system, deeply researching network intrusion and attack models, and combining artificial intelligence technology to carry out rapid assessment and early warning of security risks, thereby enhancing the security of the system.
[0127] In the description of the present specification, the description of the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. In the present specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0128] The above shows and describes the basic principles, main features and advantages of the present disclosure. Those skilled in the art should understand that the present disclosure is not limited to the above embodiments, and the above embodiments and descriptions in the specification are only to illustrate the principles of the present disclosure. Without departing from the spirit and scope of the present disclosure, various changes and improvements can be made to the present disclosure, and these changes and improvements all fall within the scope of the claimed present disclosure.
Claims
1. A dual-dimensional security risk assessment method based on data-driven state estimation, characterized in that: include: Establish a data-driven state estimation model based on artificial neural network architecture; From the attacker's perspective, we use the conditional generative network (CGAN) to launch an adversarial attack on the data-driven state estimation model. The security risks faced by state estimation under adversarial attacks are evaluated from the first and second dimensions, where: The first dimension refers to the attacker's strategy analysis. The first dimension evaluates the security risks faced by state estimation under adversarial attacks, which means: evaluating the attack cost and resources required by the attacker to implement the adversarial attack; The second dimension refers to business vulnerability assessment. The second dimension assesses the security risks faced by state estimation under adversarial attacks, which means: assessing the attack intensity and concealment of adversarial attacks; A two-dimensional security risk assessment system is established by weighting and summing the attack cost and resources in the first dimension and the attack intensity and concealment in the second dimension to implement data-driven state estimation security risk assessment. Establish a data-driven state estimation model; the details are as follows: First, the attacker captures real-time and historical data from multiple data sources through the power system monitoring mechanism. The data includes measurement data and system operation status, and integrates the historical data into the original data set I = {X 1:S ,Z 1:S }, where X 1:S is the original state quantity of group S, Z 1:S For the S group of original quantity measurements; then, based on the artificial neural network architecture, according to the obtained original data set I = {X 1:S ,Z 1:s }Build a data-driven state estimation model f θ (*), the objective function is defined as minimizing the prediction error; then, the optimization algorithm of gradient descent is used to refine f θ (*) predictive ability, nonlinear relationship between analog measurement and state quantity; Using CGAN to launch adversarial attacks on data-driven state estimation models includes: The process of launching an adversarial attack is as follows: first, the attacker obtains the original data set of the attack node under different operating states of the power system; then, the two deep network architectures of the generator and discriminator in the CGAN are constructed, and the CGAN is updated through alternating adversarial training; then, the label information that meets the attacker's intention is determined, and the original measurement of the power system is collected. The attacker uses the generator to generate a disturbance u, and superimposes the disturbance with the original measurement z to form an analog measurement z' that the discriminator cannot distinguish. This analog measurement is consistent with the label information; finally, the predicted state x' output by the data-driven state estimation model is tested, completing the adversarial attack on the data-driven state estimation model under the given label information.
2. A data-driven state estimation dual-dimensional safety risk assessment method according to claim 1, characterized in that: The generator and discriminator in CGAN include: The generator G in CGAN takes as input a set of raw measurements z and label information y. During the iteration process, the generator generates perturbations u with the same distribution as the raw measurements, and superimposes the perturbations u with the raw measurements z to form simulated measurements z'. The discriminator D in CGAN combines a set of raw measurements z and simulated measurements z' into a data batch, associates this data batch with label information y, and then inputs them into the discriminator. The discriminator distinguishes between raw and simulated measurements and classifies a given data batch as real or fake. When the simulated measurement approaches the raw measurement and meets the pre-set label information, it is judged as real.
3. The dual-dimensional security risk assessment method based on data-driven state estimation according to claim 1 is characterized in that: Establish a two-dimensional security risk assessment system, as follows: In a power system with a total of K nodes, assume that an attacker launches A counterattacks against N attack nodes, 1≤N≤K. Determine the evaluation indicators corresponding to the two dimensions of attacker strategy analysis and business vulnerability assessment. The security risk assessment score is obtained by weighting and summing the four evaluation indicators of attack cost and resources in the first dimension and attack intensity and concealment in the second dimension.
4. A dual-dimensional security risk assessment method based on data-driven state estimation according to claim 3, characterized in that the evaluation index include: First dimension: Define the average attack cost c and the resources r required for the attack a ,Analyze the attack entry point and sustainability based on the obtained attack cost and resource assessment results; The ratio of the perturbation generated by the generator in the adversarial attack to the original amount, i.e., the relative perturbation error, is used as the metric of the attack cost; for the i-th attack node, 1≤i≤N, c i is the attack cost of the i-th attack node. Calculate the attack cost of the j-th adversarial attack for all attack nodes, 1≤j≤A. Assuming that each attack is independent, sum the attack costs of all attacks to obtain the average attack cost c of the total A adversarial attacks. The resources that the attack needs to obtain a It is represented by the ratio of the number of attack nodes selected by the attacker to the total number of nodes in the power system; Among them, a i It is used to characterize whether the attack cost of the i-th attack node meets the pre-set threshold requirement λ, u i is the perturbation amount generated by the generator on the i-th attack node, z i The raw quantity measurement of the i-th attack node; The average attack cost represents the cost of an attacker launching an adversarial attack against a data-driven state estimation model. The sustainability of an adversarial attack depends on the cost of the attack and the resources required for the attack. The selected attack nodes represent the resources required for the attack and indicate the entry point of the attack. Second Dimension: Define the average attack result deviation Δx and the probability B of the attack bypassing bad data detection. Evaluate the attack strength and stealth of the adversarial attack based on the obtained attack result deviation and the probability of the attack bypassing the bad data detection mechanism. The distance between the predicted state quantity output by the data-driven state estimation model under adversarial attack and the original state quantity is used as the metric for the attack result deviation. For the i-th attack node, 1≤i≤N, the attack result deviation of the j-th adversarial attack is calculated for all attack nodes, 1≤j≤A. Assuming that each attack is independent, the attack result deviations of all attacks are summed to obtain the average attack result deviation Δx of the total A adversarial attacks. Among them, B j It is used to characterize whether the jth attack in the total A adversarial attacks can bypass the bad data detection, x i ' is the predicted state quantity output after the analog measurement is input into the data-driven state estimation model, x i is the original state of the i-th attack node; The average attack result deviation represents the attack strength of the adversarial attack, and the stealthiness of the adversarial attack is measured by the probability that the attack can bypass the detection of bad data.
Citation Information
Patent Citations
Multi-point FDI attack detection method for industrial information physical system of generative adversarial network
CN113281998A
Secret attack risk assessment method applied to power system
CN114926014A