Construction and countermeasure of hidden data injection attack under incomplete system information

By constructing the measurement matrix and minimum spanning tree model of the cyber-physical system, the problem of hidden data injection attacks in the cyber-physical system is solved, and the protection of core parameters and the improvement of system security are achieved.

CN119520110BActive Publication Date: 2025-10-10SHANGHAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411673255.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-10-10
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively deal with hidden data injection attacks under incomplete system information in cyber-physical systems. Attackers can destroy system integrity and evade detection by manipulating data, causing system managers to make wrong decisions.

Method used

By establishing the measurement matrix and system model of the cyber-physical system, a hidden data injection attack relationship is constructed, and a parameter information protection strategy is constructed using the minimum spanning tree to protect core parameters and defend against hidden data injection attacks.

Benefits of technology

Effectively protect system security, assist managers in assessing security risks, identifying key information elements, optimizing parameter protection strategies, and improving network security defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520110B_ABST
    Figure CN119520110B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of under non-complete system information, and a kind of covert data injection attack construction and coping method, including based on the characteristics of physical system in information physical system, establish measurement matrix and system model;Based on system model, establish attack model, in single unknown parameter case, construct the first covert data injection attack relationship formula of avoiding residual detection;Based on the first covert data injection attack relationship formula, construct the second covert data injection attack relationship formula of avoiding residual detection under multiple unknown parameter condition;Based on minimum spanning tree, propose parameter information protection strategy, with the first covert data injection attack relationship formula and the second covert data injection attack relationship formula are ineffective as target, obtain the core parameter and minimum parameter quantity needing protection, cope with covert data injection attack under non-complete system information.Compared with prior art, the present application can assist information physical system manager to assess system security risk, identify system key information element, optimize parameter protection strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a method for constructing and responding to hidden data injection attacks under incomplete system information. Background Art

[0002] A hidden data injection attack is a cyber threat that compromises data integrity by manipulating data. The attacker tampers with measurement data in the perception or communication stages, injecting false or malicious data, causing the system state estimate to deviate from the true value. At the same time, the attacker circumvents bad data detection mechanisms to maintain the attack's stealth. The success of the attack is highly dependent on the attacker's in-depth understanding of the target system's estimation methods and bad data detection techniques, culminating in their knowledge of the measurement matrix.

[0003] In cyber-physical systems, even if attackers have partial knowledge of system parameters, they can still leverage these known parameters and the system's network topology to conduct malicious data manipulation. Attackers can tamper with or fabricate data to make it appear legitimate, thereby circumventing bad data detection and manipulating state estimates, leading system managers to make erroneous decisions.

[0004] Cyber-physical systems typically consist of numerous sensors, control nodes, and data transmission paths, involving complex interactions between multiple devices. By analyzing historical operational data and observing and analyzing the overall system behavior over time, it is possible to identify the system's responses at different points in time or under different operating conditions. For example, attackers can exploit data inconsistencies between devices to launch stealthy data injection attacks, preventing system administrators from promptly detecting anomalies. Furthermore, targeted attacks can be launched against specific devices or subsystems, thereby inducing global system errors and amplifying the attack's impact.

[0005] Covert attacks are diverse and difficult to detect, making them challenging to defend against and potentially damaging to the stability and security of systems. Therefore, defenders must adopt advanced, multi-layered security strategies to counter these complex and insidious threats. By proactively simulating potential attack scenarios, deeply analyzing the topology of cyber-physical systems, and uncovering patterns hidden in measurement data, we can study covert data injection attacks under incomplete system information and develop defense strategies. This will help strengthen the cybersecurity of cyber-physical systems and enhance defense capabilities. Summary of the Invention

[0006] The purpose of the present invention is to overcome the defects of the above-mentioned prior art and provide a method for constructing and responding to hidden data injection attacks under incomplete system information.

[0007] The purpose of the present invention can be achieved by the following technical solutions:

[0008] A method for constructing and countering hidden data injection attacks under incomplete system information includes the following steps:

[0009] S1: Based on the physical system characteristics in the cyber-physical system, establish the measurement matrix and system model;

[0010] S2: Based on the system model, an attack model is established. In the case of a single unknown parameter, the first hidden data injection attack equation that evades residual detection is constructed.

[0011] S3: Based on the first hidden data injection attack relation, a second hidden data injection attack relation that can evade residual detection in the case of multiple unknown parameters is constructed;

[0012] S4: A parameter information protection strategy is proposed based on the minimum spanning tree. The goal is to make the first hidden data injection attack relationship and the second hidden data injection attack relationship invalid. The core parameters that need to be protected and the minimum parameter amount are obtained to deal with hidden data injection attacks under incomplete system information.

[0013] Furthermore, in step S1, the information-physical system is composed of nodes and branches connecting the nodes, each branch has a single parameter, and the parameter of the branch determines the value of the non-zero elements in the measurement matrix H; the topological structure of the system and the arrangement order of the elements of the measurement vector y jointly determine the position of the non-zero elements.

[0014] Furthermore, in step S1, the measurement matrix H is determined by the association matrix A between branches and nodes and the parameter value diagonal matrix D. The expression of the association matrix A between branches and nodes is:

[0015] A∈{-1,0,1} l×(n+1)

[0016] Where n+1 is the number of nodes, l is the number of branches, and the i-th row of the association matrix A is A i,· , i∈{1,…,l}, A i,· Contains only non-zero elements 1 or -1, 1 is located at the index position of the starting node, and -1 is located at the index position of the ending node;

[0017] The expression of the parameter value diagonal matrix D is:

[0018]

[0019] Where, the matrix E ii Only the i-th diagonal element is 1, the rest are 0, and the diagonal elements of D are D i , i∈{1,…,l}, D i The corresponding element value depends on the parameter value b i ;

[0020] Select the first node as the reference node, and the calculation expression of the measurement matrix H is:

[0021]

[0022] The rank of the measurement matrix H is n.

[0023] Furthermore, in step S1, the expression of the cyber-physical system is:

[0024] y=Hx+z

[0025] Where, is the measurement value vector, is the system state variable vector, is the measurement matrix, is the system noise, usually a random variable vector The realized value of Σ is the noise covariance matrix.

[0026] Furthermore, in step S1, the calculation expression for minimizing the estimated residual of the system model by the weighted least squares estimation method is:

[0027]

[0028] Where, is the estimated value of the system state; It is a diagonal matrix, and its diagonal elements are preset weights. The preset weights are the inverse of the noise variance, and the estimated residual r is obtained: The expression for the estimated residual is:

[0029]

[0030] By comparing the estimated residuals with a preset threshold Determine whether the system is running normally.

[0031] Furthermore, in step S2, the attack model is specifically:

[0032] Let the set of unknown parameter branches be ε is the set of all branches; the parameter diagonal matrix of the actual system branch is The parameter matrices D and D′ known to the attacker satisfy the relationship:

[0033]

[0034] Where, For actual e i The branch parameters are known to the attacker i The deviation of the branch line parameters, the actual measurement matrix H′ is obtained as:

[0035]

[0036] The hidden data injection attack model with unknown parameters is:

[0037] y a =H′x+z+a

[0038] K′y a ≠K′y

[0039] r′(y)=r′(y a )

[0040] Where a is the attack injection vector, K′=(H′ T WH′) -1 H′ T W, K′y a and K′y are estimated values ​​calculated based on the actual measurement matrix H′; That is, r′ is the actual residual function of the system.

[0041] Furthermore, in step S2, the process of constructing the first hidden data injection attack equation is as follows:

[0042] Assume that the input of functions f:ε→{1,…,n+1} and t:ε→{1,…,n+1} are branches, and the outputs are the starting node and the ending node of the branch respectively. When the attacker only targets a single branch e k When the parameters of are unknown, let ε U ={e k}, k∈{1,…,l}, f(e k )≠1 and t(e k )≠1, for all non-zero vectors If it satisfies:

[0043]

[0044] That is, the f(e k )-1 element is equal to the t(e k )-1 element, then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′;

[0045] When f(e k )=1 or t(e k )=1, for all non-zero vectors If it satisfies:

[0046]

[0047] Then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′.

[0048] Further, in step S3, in the case of multiple unknown parameters, i.e. the attacker knows the system parameter branch set ε U unknown, and satisfies |ε U |>1, let f(e)≠1 and t(e)≠1, for all nonzero vectors If it satisfies:

[0049] c f(e)-1 =c t(e)-1

[0050] i.e. the f(e)-1th element of the vector c is equal to the t(e)-1th element, then the attack vector a=Hc is a hidden data injection attack under H'; let When f(e)=1 or t(e)=1, for all nonzero vectors If it satisfies:

[0051] c f(e)-1 =0, if t(e)=1

[0052] c f(e)-1 =0, if f(e)=1

[0053] c t(e)-1 =c f(e)-1 , if f(e)≠1 and t(e)≠1

[0054] then the attack vector a=Hc is a hidden data injection attack under H';

[0055] Let the function b:ε→{1,…,l} be a mapping of the branch and the branch index, the input is the branch, and the return is the branch index, and the elements a n+1+b(e) and a n+1+l+b(e) in the attack vector a satisfy:

[0056]

[0057] represent that no interference is caused to the measurement value of any branch e in the set ε U .

[0058] Further, step S4 is specifically: a minimum spanning tree model is constructed by using a graph theory method, and a minimum spanning tree is generated using an equal weight condition or a proportional condition, a starting point of the minimum spanning tree is a reference node, nodes are expanded by a method of gradually increasing an index, let be an undirected graph composed of a node set and a branch set ε, if the subgraph is ​​If the spanning tree of the subgraph is generated, then there is no hidden non-zero attack vector.

[0059] Further, in step S4, when the subgraph If the spanning tree of the subgraph is generated, then there is a path between any two nodes, and the reference node can be connected to the remaining nodes through a path, and any branch e on the path satisfies:

[0060] c f(e)-1 = 0, if t(e) = 1

[0061] c f(e)-1 = 0, if f(e) = 1

[0062] c t(e)-1 = c f(e)-1 = 0, if f(e) = 1 and t(e) = 1

[0063] c f(e)-1 is the f(e k )-1th element of the vector c, and c t(e)-1 is the t(e k )-1th element of the vector c; then c = 0, and there is no non-zero vector Satisfy the S2 or S3 condition, and the hidden data injection attack under incomplete system information should be prevented.

[0064] Compared with the prior art, the present application has the following beneficial effects:

[0065] 1) The present application proposes the feasibility of constructing a hidden attack by an attacker when a single parameter or multiple parameters of a system are unknown. By establishing a system measurement matrix, the information physical system is modeled, an attack vector is established, and it is proved that the attack is still valid when a single parameter or multiple parameters of the system are unknown. In order to resist the hidden data injection attack, the present application uses the minimum spanning tree to construct the core parameters that need to be protected, and effectively protects the security of the system.

[0066] 2) The present application helps the information physical system manager to evaluate the system security risk, identify the key information elements of the system, optimize the parameter protection strategy, effectively cope with network threats, and protect the network security of the information physical system. BRIEF DESCRIPTION OF DRAWINGS

[0067] Figure 1 A flowchart of a hidden data injection attack construction method under incomplete system information in the embodiment of the present application is shown.

[0068] Figure 2 A node and branch diagram in the measurement matrix H in the embodiment of the present application is shown.

[0069] Figure 3 ​The embodiment of the present invention demonstrates the effect of improving the system detection probability in a power system environment when an attacker faces unknown parameters of different single branches.

[0070] Figure 4 The probability of a hidden attack when the attacker faces a branch with unknown random parameters in an embodiment of the present invention is demonstrated.

[0071] Figure 5 The invention describes an example of a minimum spanning tree constructed in a power system environment according to an embodiment of the invention. DETAILED DESCRIPTION

[0072] The present invention is described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented based on the technical solution of the present invention, and provides a detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to the following embodiments.

[0073] Example 1

[0074] The present invention is a method for injecting hidden data and dealing with it under incomplete system information. Figure 1 As shown, the following steps are included:

[0075] S1: Based on the physical system characteristics in the cyber-physical system, establish the measurement matrix and system model;

[0076] Measurement matrix H modeling:

[0077] like Figure 2 As shown in Figure 1, the system consists of nodes and branches connecting the nodes. Each branch has a single parameter, and the branch parameter determines the value of the non-zero elements in the measurement matrix H. The topological structure of the system and the order of the elements of the measurement vector y jointly determine the position of the non-zero elements. Suppose the number of nodes in the system is n+1, the number of branches is l, and the set of all branches is ε={e1,…,e l}; branch e k The specific parameter value is b k , k∈{1,…,l}; the association matrix between branches and nodes is A∈{-1,0,1} l×(n+1) ; The i-th row of matrix A is A i,· , i∈{1,…,l}, A i,· Contains only non-zero elements 1 or -1, 1 is located at the index position of the starting node, -1 is located at the index position of the ending node; the parameter value diagonal matrix is Where matrix E ii Only the i-th diagonal element is 1, and the rest are 0; the diagonal elements of matrix D are D i , i∈{1,…,l}, D i The corresponding element value depends on the parameter value b i; The inputs of functions f:ε→{1,…,n+1} and t:ε→{1,…,n+1} are branches, and the outputs are the starting node and ending node of the branch respectively.

[0078] In order to simplify the mathematical model and calculation process and make the analysis more efficient and reliable, the first node is selected as the reference node, and the first column of the measurement matrix is ​​removed to obtain the measurement matrix H. The calculation expression is:

[0079]

[0080] The rank of the measurement matrix H is n.

[0081] The expression of the cyber-physical system model is:

[0082] y=Hx+z

[0083] Where, is the measurement value vector; is the system state variable vector; is the measurement matrix; is the system noise, usually a random variable vector The realized value of ∑ is the noise covariance matrix.

[0084] In the system, it is usually necessary to estimate the value of the state variable x based on the measured value y, and use the weighted least squares estimation method to minimize the estimated residual, which is expressed as:

[0085]

[0086] Where, is the estimated value of the system state; is a diagonal matrix whose diagonal elements are preset weights, usually the inverse of the noise variance. The estimated residual r is: Its expression is:

[0087]

[0088] System managers usually compare the estimated residual r with a preset threshold The size of the system can be used to determine whether the system is running normally.

[0089] S2: Based on the system model, an attack model is established. In the case of a single unknown parameter, the first hidden data injection attack equation that evades residual detection is constructed.

[0090] Let the set of unknown parameter branches be The parameter diagonal matrix of the actual system branch is The parameter matrices D and D′ known to the attacker satisfy the relationship:

[0091]

[0092] Where, For actual e i The branch parameters are known to the attacker i Deviation of branch line parameters. Therefore, the actual measurement matrix H′ of the system can be obtained as:

[0093]

[0094] The hidden data injection attack model with unknown parameters is:

[0095] y a =H′x+z+a

[0096] K′y a ≠K′y

[0097] r′(y)=r′(y a )

[0098] Where a is the attack injection vector; y = H′x + z is the original measurement, y a is the measured value after the injection attack; function r is the residual of the system estimate; after the injection attack, the estimated value Ky a Not equal to the original estimated value Ky; function r takes values ​​y and y a At this point, the attack is stealth.

[0099] When the hidden data injection attack is only performed on a single system branch parameter, let ε U ={e k}, k∈{1,…,l}, f(e k )≠1 and t(e k )≠1, for all non-zero vectors If it satisfies:

[0100]

[0101] That is, the f(e k )-1 element is equal to the t(e k )-1 element, then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′;

[0102] When f(e k )=1 or t(e k )=1, for all non-zero vectors If it satisfies:

[0103]

[0104] Then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′.

[0105] Therefore, the construction of the first hidden data injection attack relationship is achieved.

[0106] S3: Based on the first hidden data injection attack relation, a second hidden data injection attack relation that can evade residual detection in the case of multiple unknown parameters is constructed;

[0107] The attacker implements a hidden data injection attack on the system parameter branch set ε U Unknown (i.e., multiple unknown parameters), and satisfy |ε U |=k>1. According to the characteristics of H,

[0108]

[0109] Where H i The calculation expression is:

[0110]

[0111] Therefore, the actual measurement matrix

[0112] set up f(e)≠1 and t(e)≠1, for all non-zero vectors If the right satisfy:

[0113] c f(e)-1 =c t(e)-1

[0114] That is, when the f(e)-1th element of vector c is equal to the t(e)-1th element, then:

[0115] [h i ] ·,2,…,n+1 c=0

[0116]

[0117] therefore:

[0118] r′(y a )=r′(y+a)=r′(y+Hc)=r′(y+H′c)=r′(y)

[0119] K′y a =K′(y+Hc)=K′(y+H′c)=K′y+c≠K′y

[0120] Then the attack vector a=Hc is a hidden data injection attack under H′.

[0121] Let f(e) = 1 or t(e) = 1. For all non-zero vectors If its pair satisfies:

[0122] c f(e)-1 = 0, if t(e) = 1

[0123] c t(e)-1 = 0, if f(e) = 1

[0124] c t(e)-1 = c f(e)-1 , if f(e)≠1 and t(e)≠1

[0125] Then:

[0126] [H i ] ·,2,…,n+1 c = 0

[0127]

[0128] Therefore:

[0129] r′(y a ) = r′(y+a) = r′(y+Hc) = r′(y+H′c) = r′(y)

[0130] K′y a = K′(y+Hc) = K′(y+H′c) = K′y+c≠K′y

[0131] Then the attack vector a = Hc is a covert data injection attack under H′.

[0132] The elements a n+1+b(e) and a n+1+l+b(e) in the attack vector a do not interfere with the measurement of any branch e in the set ε U , that is:

[0133]

[0134] The same conclusion is reached as S2, and the attacker can still construct a second covert data injection attack relationship under the condition of unknown multi-parameters.

[0135] S4: Based on the minimum spanning tree, a parameter information protection strategy is proposed to make the first and second covert data injection attack relationship invalid as the goal, obtain the core parameters and the minimum parameter amount that need to be protected, and realize the covert data injection response under incomplete system information.

[0136] Let be the node set and the branch set ε is an undirected graph, and the association matrix between branches and nodes is A. yes If there is a spanning tree of , there is a path between any two nodes, thus ensuring that the reference node can be connected to the rest of the nodes through a path, and any branch e on the path satisfies:

[0137] c f(e)-1 =0, ift(e)=1

[0138] c f(e)-1 =0,iff(e)=1

[0139] c t(e)-1 =c f(e)-1 =0,iff(e)≠1andt(e)≠1

[0140] Therefore, we can know that: if the subgraph yes The spanning tree of , then c=0, so there is no non-zero vector Satisfy S2 or S3 conditions. Therefore, the minimum spanning tree is selected to construct the parameter information protection strategy, and the minimum spanning tree model is constructed using graph theory methods. The minimum spanning tree is generated using equal weight conditions or proportional conditions. The starting point of the minimum spanning tree is the reference node, and the nodes are expanded by gradually increasing the index method.

[0141] This embodiment is based on the IEEE power system environment, and the parameters and topology are derived from MATPOWER. The specific implementation process is as follows:

[0142] Define the relationship between the system state variable vector x and the measured value y as y = Hx + z, where the estimated value of x is The attack is constructed as a=Hc. Given a system with n+1 nodes and l branches, the set of all branches is ε={e1,…,e k}; branch e k The specific parameter value is the impedance value b k , k∈{1,…,l}; the association matrix between branches and nodes is A; the parameter value diagonal matrix is ​​D.

[0143] For the case where a single parameter is unknown, a branch in the system is selected to adjust the parameter value, simulating an attacker to carry out a hidden data injection attack. The difference in detection probability when the parameters of different branches are unknown is noted, and the attack detection probability is compared under the two cases of known and unknown single parameters.

[0144] Based on the IEEE 30-node test system (including 41 branches), the injection error c is generated by multivariate uniform distribution. Assume that the covariance matrix of the noise is ∑ = σ 2 I, σ=3; alarm threshold Ensure that the false positive probability is 0.05; each branch e i , the parameter changes of i∈{1,…,41} are:

[0145] ΔD i =αD i

[0146] Randomly generate 20×41 attacks.

[0147] like Figure 3 Figure 2 shows the improvement in detection probability when an attacker faces different single-branch parameter unknowns. Experimental results show that there is an upper limit to the improvement in detection probability, and single-branch parameter unknowns have limited defense capabilities against hidden data injection attacks. If the node being injected is connected to a node with unknown parameters, the detection probability increases accordingly. However, if the estimated state deviates significantly from the normal value, administrators may easily detect system anomalies.

[0148] We select multiple branches in the system and adjust parameter values ​​to simulate an attacker launching a hidden data injection attack. For the case where multiple parameters are unknown, it is intuitively believed that as the number of unknown branch parameters increases, the probability of successfully constructing a hidden data injection attack decreases.

[0149] In this embodiment, the ratio of the number of unknown parameters to the total number of parameters in the system is used as the x-axis, and the branch index of the unknown parameters is randomly generated. The experiment is repeated 1000 times to estimate the probability of hidden attacks. Figure 4 As shown, when the number of unknown parameters is less than 40% of the total, a hidden attack is almost inevitable. As the number of unknown parameters increases, the probability of a hidden attack gradually decreases, reaching zero when all branch parameters are unknown. Furthermore, the experiment shows that as the system scale increases, the proportion of branches with unknown parameters increases accordingly to maintain the same level of hidden attack protection. This suggests that in large systems, system administrators need to change a higher proportion of branch parameters to achieve effective and secure protection.

[0150] Graph theory methods are used to construct a spanning tree model to design countermeasures against hidden attacks, and sufficient conditions that can effectively mitigate such attacks are explored.

[0151] like Figure 5 As shown in Figure 1, a minimum spanning tree is generated when all branches have the same weight in a power system environment. The branches of the tree are marked in red. This tree starts at the reference node and gradually increases the index and expands the node.

[0152] Table 1 lists the number of branches in a minimum spanning tree, and their percentage of the total number of branches in the system, under equal weight conditions. The data indicates that to significantly improve defenses against hidden data injection attacks, system administrators need to construct a minimum spanning tree with at least 62% to 72% branches.

[0153] Table 1

[0154] Test system Minimum spanning tree branch number Proportion IEEE 14-Bus system 13 0.65 IEEE 30-Bus system 29 0.707 IEEE 57-Bus system 56 0.7 IEEE 118-Bus system 117 0.629 IEEE 300-Bus system 299 0.7275

[0155] According to the branch index in the MATPOWER test case data file, sort the measurement vector y and select the node with index 1 as the reference node. Assume that the weight of the branch satisfies the function w: e k The weight of the branch is related to D k Proportional to:

[0156] w(e k )∝D k

[0157] Table 2 lists the number of branches in the minimum spanning tree under the proportionality condition and their percentage of the total number of branches in the system. It can be seen that the proportion of branches in the equal-weighted case is equal to that in the case where the weights satisfy the above formula. This conclusion also holds true when the branch weights are randomly assigned.

[0158] Table 2

[0159] Test system Minimum spanning tree branch number Proportion IEEE 14-Bus system 13 0.65 IEEE 30-Bus system 29 0.707 IEEE 57-Bus system 56 0.7 IEEE 118-Bus system 117 0.629 IEEE 300-Bus system 299 0.7275

[0160] The above describes in detail the preferred embodiments of the present invention. It should be understood that those skilled in the art can make numerous modifications and variations based on the concepts of the present invention without inventive effort. Therefore, any technical solutions that can be derived by those skilled in the art through logical analysis, reasoning, or limited experimentation based on the concepts of the present invention and the prior art should be within the scope of protection defined by the claims.

Claims

1. A method for constructing and countering hidden data injection attacks under incomplete system information, characterized in that: The following steps are involved: S1: Based on the physical system characteristics in the cyber-physical system, establish the measurement matrix and system model; S2: Based on the system model, an attack model is established. In the case of a single unknown parameter, the first hidden data injection attack equation that evades residual detection is constructed. S3: Based on the first hidden data injection attack relation, a second hidden data injection attack relation that can evade residual detection in the case of multiple unknown parameters is constructed; S4: A parameter information protection strategy is proposed based on the minimum spanning tree. The goal is to make the first hidden data injection attack relationship and the second hidden data injection attack relationship invalid. The core parameters that need to be protected and the minimum parameter amount are obtained to deal with hidden data injection attacks under incomplete system information.

2. The method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 1 is characterized in that: In step S1, the information-physical system is composed of nodes and branches connecting the nodes. Each branch has a single parameter, and the parameter of the branch determines the value of the non-zero elements in the measurement matrix H; the topological structure of the system and the arrangement order of the elements of the measurement vector y jointly determine the position of the non-zero elements.

3. The method for constructing and responding to a hidden data injection attack under incomplete system information according to claim 2 is characterized in that: In step S1, the measurement matrix H is determined by the association matrix A between branches and nodes and the parameter value diagonal matrix D. The expression of the association matrix A between branches and nodes is: A∈{-1,0,1} l×(n+1) Where n+1 is the number of nodes, l is the number of branches, and the i-th row of the association matrix A is A i,· , i∈{1,…,l}, A i,· Contains only non-zero elements 1 or -1, 1 is located at the index position of the starting node, and -1 is located at the index position of the ending node; The expression of the parameter value diagonal matrix D is: Where, the matrix E ii Only the i-th diagonal element is 1, the rest are 0, and the diagonal elements of D are D i , i∈{1,…,l}, D i The corresponding element value depends on the parameter value b i ; Select the first node as the reference node, and the calculation expression of the measurement matrix H is: The rank of the measurement matrix H is n.

4. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 3, characterized in that: In step S1, the expression of the cyber-physical system is: y=Hx+z Where, is the measurement value vector, is the system state variable vector, is the measurement matrix, is the system noise, i.e., the random variable vector The realized value of Σ is the noise covariance matrix.

5. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 4, characterized in that: In step S1, the system model minimizes the estimated residual by weighted least squares estimation method. The calculation expression is: Where, is the estimated value of the system state; is a diagonal matrix whose diagonal elements are preset weights. The preset weights are the inverse of the noise variance, and the estimated residual is obtained The expression for the estimated residual is: By comparing the estimated residuals with a preset threshold Determine whether the system is running normally.

6. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 5, characterized in that: In step S2, the attack model is specifically: Let the set of unknown parameter branches be ε is the set of all branches; The parameter diagonal matrix of the actual system branch is The parameter matrices D and D′ known to the attacker satisfy the relationship: Where, For actual e i The branch parameters are known to the attacker i The deviation of the branch line parameters, the actual measurement matrix H′ is obtained as: The hidden data injection attack model with unknown parameters is: y a =H′x+z+a K'y a ≠K′y r′(y)=r′(y a ) Where a is the attack injection vector, K′=(H′ T WH′) -1 H′ T W, K′y a and K′y are estimated values ​​calculated based on the actual measurement matrix H′; That is, r′ is the actual residual function of the system.

7. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 6, characterized in that: In step S2, the process of constructing the first hidden data injection attack equation is as follows: Assume that the input of functions f:ε→{1,…,n+1} and t:ε→{1,…,n+1} are branches, and the outputs are the starting node and the ending node of the branch respectively. When the attacker only targets a single branch e k When the parameters of are unknown, let ε U ={e k }, k∈{1,…,l}, f(e k )≠1 and t(e k )≠1, for all non-zero vectors If it satisfies: That is, the f(e k )-1 element is equal to the t(e k )-1 element, then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′; When f(e k )=1 or t(e k )=1, for all non-zero vectors If it satisfies: Then the attack vector a=Hc is a hidden data injection attack under the actual measurement matrix H′.

8. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 7, characterized in that: In step S3, in the case of multiple unknown parameters, the attacker sets the system parameter branch set ε U Unknown, and satisfying |ε U When |>1, set f(e)≠1 and t(e)≠1, for all non-zero vectors If the right satisfy: c f(e)-1 =c t(e)-1 That is, the f(e)-1th element of vector c is equal to the t(e)-1th element, then the attack vector a=Hc is a hidden data injection attack under H′; let When f(e) = 1 or t(e) = 1, for all non-zero vectors If the right satisfy: c f(e)-1 =0,if t(e)=1 c f(e)-1 =0,if f(e)=1 c t(e)-1 =c f(e)-1 ,if f(e)≠1andt(e)≠1 Then the attack vector a=Hc is a hidden data injection attack under H′; Let the function b:ε→{1,…,l} be the mapping between branches and branch indices, with the input being the branch and the return being the branch index. The element a in the attack vector a n+1+b(e) and a n+1+l+b(e) satisfy: Represents the set ε U The measurement value of any branch e in the θ2−θ2−θ2−θ2 causes interference.

9. The method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 3 is characterized in that: Step S4 is specifically as follows: constructing a minimum spanning tree model using graph theory, using equal weight conditions or proportional conditions to generate a minimum spanning tree, the starting point of the minimum spanning tree is the reference node, and the nodes are expanded by gradually increasing the index method, and the minimum spanning tree is generated by the graph theory method. For the node set and the branch set ε of the undirected graph, if the subgraph yes If there is a spanning tree of , there is no hidden non-zero attack vector.

10. A method for constructing and responding to hidden data injection attacks under incomplete system information according to claim 9, characterized in that: In step S4, when the subgraph yes When the spanning tree is , there is a path connecting any two nodes, and the reference node can be connected to the other nodes through a path, and any branch e on the path satisfies: c f(e)-1 =0,if t(e)=1 c f(e)-1 =0,if f(e)=1 c t(e)-1 =c f(e)-1 =0,if f(e)≠1 and t(e)≠1 c f(e)-1 is the f(e k )-1 element, c t(e)-1 is the t(e k )-1 element; then c=0, there is no non-zero vector Satisfy S2 or S3 conditions to counter hidden data injection attacks with incomplete system information.

Citation Information

Patent Citations

  • Method of detecting power grid false data injection attack based on nonlinear measurement equation

    CN107016236A

  • False data injection attack detection method for electric power information physical system

    CN114091557A