Protection method and device for power grid cyber physical system
By constructing an interaction model and vulnerability assessment model for the power grid cyber-physical system, allocating defense resources, establishing an attack-defense game model, and optimizing defense strategies, the system's security and stability were improved by resolving the cascading failure problem caused by information attacks.
Patent Information
- Application Number
- CN202410838885.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-26
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-06-26
AI Technical Summary
In existing technologies, information attacks on cyber-physical systems (CPPS) can easily lead to a chain reaction of faults propagating to the physical side, threatening the safe and stable operation of the system. Furthermore, existing game theory models fail to combine specific attack scenarios and targets for analysis.
Based on the power grid cyber-physical system interaction model, attack scenarios and targets are identified, a vulnerability assessment model is constructed, and defense resources are allocated using Newton-Raphson power flow calculation and power constraints. An attack-defense game model is established to optimize defense strategies.
It improved the accuracy of defense resource allocation, enhanced the protection capability of the power grid's cyber-physical system during attacks, and reduced load loss.
Smart Images

Figure CN119544244B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information and communication technology, and in particular to a protection method and apparatus for a power grid cyber-physical system. Background Technology
[0002] In recent years, driven by the rapid development of information and communication technologies, modern power grids are transforming into smarter, more extensive, and safer systems, gradually evolving into Cyber-Physical Power Systems (CPPS). The information control system and the physical power system are closely coupled and interact with each other; therefore, power grid security requires comprehensive consideration of both information and physical security. Information attacks exploit the CPPS's dependence on information networks to damage weak links in the information system and even cascade faults to the physical side, endangering the security of the entire system. Information attacks targeting CPPS seriously threaten the safe and stable operation of the system.
[0003] In related technologies, game theory methods are widely used in power grid security research because they can reflect the interaction mechanism of offensive and defensive behaviors and capture multiple decision-making processes. Many scholars have established CPPS attack-defense game models based on game theory, such as CPPS attack-defense game models under remote attacks injecting false authentication information and dynamic CPPS attack-defense game models under cooperative cyber-physical attacks. However, these models lack specific analysis considering the attack scenarios and targets. Summary of the Invention
[0004] Therefore, it is necessary to provide a protection method and device for a power grid cyber-physical system to address the aforementioned technical problems.
[0005] Firstly, this application provides a protection method for a power grid cyber-physical system. The method includes:
[0006] Attack scenarios are determined based on the structure of the power grid cyber-physical system interaction model, and the attack targets and defense targets are different in different attack scenarios;
[0007] Based on the attack targets and defense targets under different attack scenarios, a vulnerability assessment model for the power grid cyber-physical system is obtained;
[0008] Based on the Newton-Raphson power flow calculation equations and the preset power constraints, an active power load loss model for the power grid cyber-physical system is obtained.
[0009] Based on the aforementioned cyber-physical system vulnerability assessment framework and the aforementioned cyber-physical system active power load loss model, the defense resources allocated to the attack target are obtained.
[0010] Based on the power grid cyber-physical system interaction model and the defense resources allocated to the attack target, an attack-defense game model for the power grid cyber-physical system is established and an attack-defense game scenario is designed to obtain a protection scheme for the power grid cyber-physical system.
[0011] In one embodiment, the structure of the power grid cyber-physical system interaction model includes:
[0012] The upper-layer information network includes multiple information nodes and information channels;
[0013] The lower-level physical network includes multiple physical nodes and physical channels;
[0014] An intermediate interaction channel is used to connect the information node and the physical node.
[0015] In one embodiment, the vulnerability assessment model for the power grid cyber-physical system is constructed in the following manner:
[0016] R T =TVC;
[0017] In the above formula, R T Let V represent the expected loss of the target, T represent the probability that the target is attacked, V represent the probability of successfully attacking the target, and C represent the active power loss of the target.
[0018] In one embodiment, the allocation process of the defense resources includes:
[0019] In the absence of defense resources, the active load loss under different attack scenarios is obtained based on the active load loss model of the power grid cyber-physical system.
[0020] Obtain the total amount of defense resources, and based on the preset defense resource allocation precision and the total amount of defense resources, obtain the amount of each defense resource;
[0021] The active load loss is sorted in descending order, and each portion of defense resources is sequentially allocated to the first N active load loss portions after sorting, until the total amount of defense resources is allocated. N is a positive integer greater than or equal to 1.
[0022] In one embodiment, the CPPS attack-defense game optimization model includes a planning model, the structure of which includes:
[0023] The upper-level planning model, wherein the decision variables of the upper-level planning model include the defensive resources allocated to the attack target;
[0024] The mid-level planning model, wherein the decision variables of the mid-level planning model include physical attack resources for physical channels and information attack resources for information nodes;
[0025] The lower-level planning model, whose decision variables include the load reallocated to CPPS.
[0026] In one embodiment, the CPPS attack-defense game optimization model includes a three-layer programming model;
[0027] The decision variables of the next-level planning model depend on the decision variables of the previous-level planning model; changes in the decision variables of the next-level planning model along with changes in the decision variables of the previous-level planning model will be fed back to the previous-level planning model.
[0028] In one embodiment, the process of performing an attack-defense game based on the power grid cyber-physical system attack-defense game optimization model includes:
[0029] The initial power flow of the power grid cyber-physical system is obtained based on the Newton-Raphson power flow calculation equation.
[0030] By traversing all attack scenarios, the active load loss is obtained based on the active load loss model of the power grid cyber-physical system.
[0031] Obtain information nodes under a preset active power load loss and determine the attack target;
[0032] Based on the initial power flow and the allocation process of the defense resources, the defense resources allocated to the attack target are obtained.
[0033] In one embodiment, the attack-defense game scenario includes a defender and an attacker;
[0034] In the upper-level planning model, the defense resources pre-allocated by the defender are determined, and these defense resources are used to reduce the probability of a node being successfully attacked.
[0035] In the mid-level planning model, the attacker's planned attack strategy is determined, which is used to increase the losses of the power grid cyber-physical system;
[0036] In the lower-level planning model, the resources after the defenders are redistributed are determined.
[0037] In one embodiment, the resource reallocation process includes:
[0038] Based on preset rules, the balance nodes of isolated networks that were disconnected after the power grid cyber-physical system was attacked are reselected, and the nodes and lines of the isolated networks are renumbered.
[0039] Secondly, this application also provides a protection device for a power grid cyber-physical system, the device comprising:
[0040] The confirmation module is used to determine the attack scenario based on the structure of the power grid cyber-physical system interaction model. Different attack scenarios correspond to different attack targets and defense targets.
[0041] The assessment module is used to obtain a vulnerability assessment model for the power grid cyber-physical system based on the defense targets under different attack scenarios.
[0042] The load calculation module is used to obtain the active load loss model of the power grid cyber-physical system based on the Newton-Raphson power flow calculation equation and preset power constraints.
[0043] The resource allocation module is used to obtain the defense resources allocated to the attack target based on the vulnerability assessment model of the power grid cyber-physical system and the active power loss model of the power grid cyber-physical system.
[0044] The game theory calculation module is used to establish an attack and defense game model of the power grid cyber-physical system based on the structure of the interaction model of the power grid cyber-physical system and the defense resources allocated to the attack target, and to design an attack and defense game scenario to obtain a protection scheme for the power grid cyber-physical system.
[0045] Thirdly, this disclosure also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of a protection method for a power grid cyber-physical system.
[0046] Fourthly, this disclosure also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of a protection method for a power grid cyber-physical system.
[0047] Fifthly, this disclosure also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of a protection method for a power grid cyber-physical system.
[0048] The aforementioned protection methods for the cyber-physical system of the power grid include at least the following beneficial effects:
[0049] The embodiments provided in this disclosure predetermine possible attack scenarios, attack targets, and defense targets based on the structure of the power grid cyber-physical system interaction model. Based on the power grid cyber-physical system vulnerability assessment model and the power grid cyber-physical system active power load loss model, defense resources allocated to attack targets are generated. On the basis of pre-allocated defense resources, a power grid cyber-physical system attack-defense game model is established to obtain different attack-defense game scenarios. During the actual operation of the power grid cyber-physical system interaction model, when attacked, the protection scheme of the power grid cyber-physical system is readjusted according to the attack scenario, attack target, and defense resources, thereby improving the accuracy of defense resource allocation.
[0050] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0051] To more clearly illustrate the technical solutions in the embodiments or conventional technologies of this disclosure, the accompanying drawings used in the description of the embodiments or conventional technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0052] Figure 1 This is an application environment diagram of a protection method for a power grid cyber-physical system in one embodiment;
[0053] Figure 2 This is a schematic diagram of the node-channel relationship in a power grid cyber-physical system in one embodiment;
[0054] Figure 3 This is a flowchart illustrating a protection method for a power grid cyber-physical system in one embodiment;
[0055] Figure 4 This is a defense resource allocation process in one embodiment;
[0056] Figure 5 This is a 14-node power distribution system in one embodiment;
[0057] Figure 6 This is a channel relationship diagram of a 14-node power distribution system in one embodiment;
[0058] Figure 7 This is a flowchart of the algorithm for simulating the attack and defense game of a cyber-physical system in a power grid in one embodiment;
[0059] Figure 8 This is a diagram showing the particle swarm iteration results under three attack scenarios in one embodiment.
[0060] Figure 9This is a structural block diagram of a protection device for a power grid cyber-physical system in one embodiment. Detailed Implementation
[0061] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0062] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims. The terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitation, the presence of other identical or equivalent elements in a process, method, product, or apparatus that includes said elements is not excluded. For example, the use of terms such as "first," "second," etc., is to denote names and does not indicate any specific order.
[0063] This disclosure provides a protection method for a power grid cyber-physical system, which can be applied to, for example... Figure 1 In the application environment shown, considering the interaction between physical and information components in CPPS, CPPS is abstracted into a node-channel model. The information network includes C nodes (information nodes) and CC (Control Center, CC) channels, while the physical network includes P nodes (physical nodes) and PP channels (physical-to-physical channels). The information network and physical network are connected through CP channels (interaction channels). The physical components, information components, information nodes, physical nodes, and interaction channels can be the attack targets mentioned below.
[0064] In some embodiments of this disclosure, the structure of the CPPS interaction model includes:
[0065] The upper-layer information network includes multiple information nodes and information channels;
[0066] The lower-level physical network includes multiple physical nodes and physical channels;
[0067] An intermediate interaction channel is used to connect the information node and the physical node.
[0068] The CPPS interaction model has a three-layer structure, such as Figure 2 The diagram illustrates the node-channel relationship in a power grid cyber-physical system in one embodiment. The upper-layer information network includes communication and information systems. C-nodes (information nodes) represent the Control Center (CC) and information terminals. Generally, information components are paired with physical components, enabling data acquisition and control signal transmission to these components, such as Remote Terminal Units (RTUs). CC channels represent the communication connections of C-nodes; each C-node should maintain a connection with the control center through its channel.
[0069] The underlying physical network refers to the electrical equipment on the physical side. P-nodes (physical nodes) represent generators and loads, while PP channels (physical-to-physical channels) represent transmission and distribution lines. Transformers and substations, used for voltage and current transformation during transmission and distribution, and for distributing power to loads at distribution terminals, are intermediate processes in the transmission of power from generator nodes to load nodes. To simplify the model and calculations, this invention treats transformers and substations as PP channels. Failure of a P-node will cause the corresponding generator node to be unable to adjust its generator output power, or the load node to be unable to perform load shedding. Failure of a PP channel will cause the corresponding line to disconnect.
[0070] The interaction channel of the middle layer, namely the CP channel, is realized through the terminal (data collection) and the wire (power supply). It represents the connection between the P node and the corresponding C node. When the information component collects data through the CP channel, the physical component also supplies power to the local information component through the CP channel, thus forming bidirectional communication.
[0071] However, in actual power grids, the interaction relationships between P nodes and C nodes are diverse, including one-to-many, many-to-one, one-to-many, or no correspondence. Based on the specific circumstances of actual power grids, this embodiment simplifies the correspondence between P nodes and C nodes as follows:
[0072] (1) When there is a one-to-many relationship between P node and C node, the different C nodes connected to P node generally have different functions. By simplifying all C nodes corresponding to the same P node into a single C node that integrates all functions, the one-to-many relationship between P node and C node can be processed into a one-to-one mapping.
[0073] (2) When there is a many-to-one relationship between P nodes and C nodes, the C node will be disconnected only when all the paths connecting all P nodes to a certain C node are broken. At the same time, P nodes connected to the same C node generally have the same control requirements or similar characteristics. Therefore, all P nodes connected to the same C node can be regarded as a generalized P node, and the many-to-one relationship between P nodes and C nodes can be processed as a one-to-one mapping.
[0074] (3) When there is no correspondence between P and C nodes, firstly, there is no corresponding C node for P node. These P nodes can be equivalent to backup power supply or protected generator nodes; secondly, there is no corresponding P node for C node. These nodes are generally used for information transmission within the control system and do not directly correspond to a specific P node. They can be equivalent to protected information nodes. Therefore, when there is no correspondence between P node and C node, P node and C node can be regarded as protected nodes in the physical system and information system, respectively. They are not the objects of attack and defense in the CPPS attack and defense game model established in this embodiment.
[0075] In summary, to simplify the model representation, this embodiment has made reasonable simplifications based on the actual situation. The cases where P nodes and C nodes have one-to-many, many-to-one, or no correspondence are properly handled as the assumption of a one-to-one mapping between P nodes and C nodes, thereby forming a one-to-one, bidirectional communication CP channel.
[0076] In some embodiments of this disclosure, such as Figure 3 As shown, a protection method for a power grid cyber-physical system is provided. In one specific embodiment, the method may include the following steps:
[0077] S302: The attack scenario is determined based on the structure of the power grid cyber-physical system interaction model. Different attack scenarios correspond to different attack targets and defense targets.
[0078] Some embodiments provided in this disclosure can identify potential attack targets and scenarios through the structure of the power grid cyber-physical system interaction model. Furthermore, by conducting cyber-physical system vulnerability assessments on different attack targets and scenarios, the security of the power grid cyber-physical system operation can be improved. The CP channel is typically an internal connection providing power to information devices and is not an easy target for attackers. In the information subsystem, the CC channel is often cable or wireless, relatively reliable, and not easily attacked, but the C node is easily targeted. In the physical subsystem, the PP channel is usually the most vulnerable. Therefore, the targets of information attacks are determined to be the PP channel and the C node. Thus, the coordinated cyber-physical attack behavior discussed in this embodiment involves simultaneously launching a physical attack on the PP channel and an information attack on the C node. In some embodiments, the attack target can be the target selected in this embodiment, but it is not limited to other implementation methods and attack targets.
[0079] When an attacker simultaneously attacks both the PP channel and the C node, the PP channel becomes physically ineffective, affecting the power flow distribution of the system. This may cause some lines to exceed their power flow limits. Power flow refers to the process by which current or power flows from the power source through various system components and is distributed throughout the power grid during operation, under the excitation of the power source's potential. At this point, grid defenders need to use the first line of defense—relay protection—to disconnect severely overloaded lines, and may even need to use the second line of defense—overload shedding and load stabilization devices—to adjust generator output and load shedding to bring the system back to a stable operating state. However, these operations result in load losses. The control center can also send control commands to adjust the state of some P nodes, but because the C node, which is under information attack, fails at this time, blocking communication with some P nodes, P nodes connected to the damaged C node will be unable to adjust generator output or refuse to shed loads, further increasing load losses. Therefore, attacking components on either the physical or information side of the CPPS will affect the other side and increase load losses. Since the defense strategy studied in this embodiment is to trip the line and cut the load, without considering out-of-synchronization disconnection, frequency or voltage emergency control, etc., the third line of defense of the power system is not involved.
[0080] In summary, this embodiment proposes at least three attack scenarios and clarifies the corresponding defense targets for power grid defenders:
[0081] 1) Scenario 1: Physical attack on one PP channel, the power grid defender defends against the PP channel attack through relay protection;
[0082] 2) Scenario 2: Collaborative cyber-physical attack on 1 PP channel and 1 C node. The defender defends against the attack on the PP channel and C node simultaneously through relay protection, overload tripping and load stabilization devices.
[0083] 3) Scenario 3: Collaborative cyber-physical attack on 1 PP channel and 2 C nodes. The defender defends against the attack on the PP channel and C nodes simultaneously through relay protection, overload tripping and load stabilization devices.
[0084] S304: Based on the attack target and the defense target under different attack scenarios, a CPPS vulnerability assessment model is obtained.
[0085] This embodiment studies the security impact of collaborative cyber-physical attacks on CPPS by assessing the vulnerabilities of system components. Specifically, one implementation involves constructing a CPPS vulnerability assessment model: R T =TVC(1)
[0086] Where: Risk R T(Risk) represents the expected loss of the attacked component; Threat (T) represents the probability that the component is attacked; Vulnerability (V) represents the probability that the component is successfully compromised; Consequence (C) represents the amount of loss incurred by the attacked component.
[0087] The CPPS vulnerability assessment results are more realistic by introducing two probability values, T and V. In this embodiment, under the background of collaborative cyber-physical attacks, the three factors of “consequence” C, “vulnerability” V and “threat” T in formula (1) are quantified respectively, thereby constructing a CPPS vulnerability assessment framework and providing a basis for building an attack-defense game model.
[0088] The system loss is measured by the amount of active power loss generated by CPPS under a cooperative cyber-physical attack. The amount of active power loss caused by the successful attack on component i (PP channel or C node) is defined as Ci. CPPS can include n components, and component i is one of the n components.
[0089] Clearly, the vulnerability V of a component in CPPS is related to the allocated offensive and defensive resources. The more defensive resources allocated, the lower the probability of successful attack; conversely, the more attack resources a component receives, the easier it is to destroy. To simplify calculations, this embodiment primarily quantifies V from the perspective of the grid defender. Let di be the defensive resources allocated to component i by the grid defender. The probability Vi of successful attack on component i is defined as depending on the amount of allocated defensive resources di, calculated as follows:
[0090] In quantifying the threat level T, this invention assumes that the probability Ti of component i being attacked varies with the amount of defense resources allocated, di. The probability Vi of component i being successfully attacked is obtained from equation (2), and the expected value ViCi of the system active power load loss after allocating defense resources is calculated. If there are n components in the CPPS, the maximum value among the expected values of the system active power load loss after allocating defense resources to these components is denoted as VCmax:
[0091] VC max =max(V i C i (3) i = 1, 2, ..., n
[0092] If m out of n components represent the expected maximum value of the system's active power load loss VC max The components are:
[0093]
[0094] The formula for calculating the probability Ti of component i being attacked is as follows:
[0095]
[0096] S306: Based on the Newton-Raphson power flow calculation equation and the preset power constraints, the active power load loss model of CPPS is obtained.
[0097] This invention employs optimal load shedding and generator output power regulation to minimize the cost to the system in restoring stable operation. The load shedding method involves proportionally cutting off active and reactive power at load nodes. The principle of load shedding is to minimize active power load loss. The optimal load shedding model is solved using a particle swarm optimization algorithm. Based on the Newton-Raphson power flow model, the minimum active power load loss model is determined as follows:
[0098]
[0099] satisfy:
[0100] 0≤η i ≤1 (7)
[0101]
[0102] In the formula: L={L a ,L off}, L a / L off These represent the sets of controllable or uncontrollable load nodes in the system, respectively. Let i represent the active and reactive power losses at load node i, respectively. η represents the initial active load of load node i. i This represents the load shedding ratio of load node i, with a value ranging from 0 to 1; Let represent the upper and lower limits of the active power at load node i, respectively. P represents the upper and lower limits of reactive power at load node i, respectively; i ΔP i Q represents the actual active power and actual active power loss of node i. i ΔQ i U represents the actual reactive power and actual reactive power loss of node i. i δ represents the voltage magnitude at node i; ij G represents the voltage phase angle difference in branch ij; ij B ij Let N represent the conductance and susceptance of branch i; N represents the set of all nodes. PV N PQ These represent the sets of PQ nodes and PV nodes, respectively. In this embodiment, the load node is a concept of a component in the power grid cyber-physical system.
[0103] Equation (6) gives the optimal load shedding target, Equation (7) is the constraint condition for the load shedding ratio, Equation (8) is the constraint condition for the proportional shedding of active and reactive power of the load node, Equations (9)-(11) are the constraints condition for the active and reactive power of the load node, and Equations (12)-(13) are the Newton-Raphson power flow calculation equations. The optimal generator output regulation scheme is the same as above.
[0104] S308: Based on the CPPS vulnerability assessment framework and the CPPS active power loss model, obtain the defense resources allocated to the attack target.
[0105] Because the CPPS (Concurrent Processing Power Grid) offensive-defense game is a boundedly rational behavior—that is, both sides seek to maximize their own interests given limited resources—the grid defender minimizes the system's active power load loss by allocating limited defense resources, while the attacker maximizes the system's active power load loss by coordinating cyber-physical attacks to allocate limited attack resources to vulnerable components. The sum of the payoffs for both sides is zero, constituting a zero-sum game. The Nash equilibrium of the CPPS offensive-defense game refers to the optimal strategy achieved by both the attacker and defender through confrontation, where both parties' payoffs are maximized. Therefore, under the condition of bounded rationality for both sides, the CPPS offensive-defense game can ultimately reach a unique Nash equilibrium solution, at which point the defense resource strategy is optimal.
[0106] S310: Based on the structure of the CPPS interaction model and the defense resources allocated to the attack target, establish a CPPS attack and defense game model and design an attack and defense game scenario to obtain a CPPS protection scheme.
[0107] The upper-level planning model of the constructed three-layer CPPS attack-defense game optimization model is the first step in the attack-defense game scenario. Based on the three-layer attack-defense game optimization model, the defender predicts the attacker's attack strategy and attack result by calculating the minimum system active power load loss caused by three attack scenarios when the initial total amount of defense resources is zero, so as to obtain the optimal defense resource allocation strategy.
[0108] In the aforementioned protection method for the power grid cyber-physical system, the possible attack scenarios, attack targets, and defense targets are pre-determined based on the structure of the power grid cyber-physical system interaction model. Based on the power grid cyber-physical system vulnerability assessment model and the power grid cyber-physical system active power load loss model, defense resources allocated to the attack targets are generated. On the basis of pre-allocated defense resources, a power grid cyber-physical system attack-defense game model is established to obtain different attack-defense game scenarios. During the actual operation of the power grid cyber-physical system interaction model, when attacked, the protection scheme of the power grid cyber-physical system is readjusted according to the attack scenario, attack target, and defense resources, thereby improving the accuracy of defense resource allocation.
[0109] In some embodiments of this disclosure, the vulnerability assessment model for the power grid cyber-physical system is constructed in the following manner:
[0110] R T =TVC;
[0111] In the above formula, R T Let V represent the expected loss of the target, T represent the probability that the target is attacked, V represent the probability of successfully attacking the target, and C represent the active power loss of the target.
[0112] CPPS vulnerability assessment model: R T =TVC,
[0113] Where: Risk R T (Risk) represents the expected loss of the attacked component; Threat (T) represents the probability that the component is attacked; Vulnerability (V) represents the probability that the component is successfully compromised; Consequence (C) represents the amount of loss incurred by the attacked component.
[0114] In some embodiments of this disclosure, the allocation process of the defense resources includes:
[0115] In the absence of defense resources, the active load loss under different attack scenarios is obtained based on the active load loss model of the power grid cyber-physical system.
[0116] Obtain the total amount of defense resources, and based on the preset defense resource allocation precision and the total amount of defense resources, obtain the amount of each defense resource;
[0117] The active load loss is sorted in descending order, and each portion of defense resources is sequentially allocated to the first N active load loss portions after sorting, until the total amount of defense resources is allocated. N is a positive integer greater than or equal to 1.
[0118] Figure 4 This is a defense resource allocation process in one embodiment.
[0119] 1) Calculate the minimum expected value of system active power load loss VC0 when there is no defense, that is, when the initial total defense resources D0 = 0, we have:
[0120] VC0=C (14)
[0121] 2) Assume the defense resource allocation precision K = 10000, and take the total defense resource D as 50% of the total vulnerable components (PP channel and C node), then each defense resource is D / K.
[0122] 3) For the three attack scenarios, allocate one set of defense resources D / K to VC.max The value is combined with the PP channel and C node as follows:
[0123]
[0124] 4) If the defense resources have been allocated, output the results of the defense resources allocated to the vulnerable components under the three attack scenarios; otherwise, return to step 3 and continue to allocate defense resources.
[0125] In one embodiment of this disclosure, the CPPS attack-defense game optimization model includes a planning model, the structure of which includes:
[0126] The upper-level planning model, wherein the decision variables of the upper-level planning model include the defensive resources allocated to the attack target;
[0127] The mid-level planning model, wherein the decision variables of the mid-level planning model include physical attack resources for physical channels and information attack resources for information nodes;
[0128] The lower-level planning model, whose decision variables include the load reallocated to CPPS.
[0129] Based on the CPPS vulnerability assessment framework and attack / defense scenario design, a three-layer mathematical programming model is constructed to quantitatively analyze the attack / defense game problem of CPPS, and to discuss the security impact of CPPS subjected to cooperative cyber-physical attacks. This invention proposes a simplified three-layer CPPS attack / defense game optimization model based on non-cooperative dynamic incomplete zero-sum game:
[0130] Upper-level planning model:
[0131]
[0132] satisfy
[0133] h u (d,ω,f)≥0(17)
[0134] Mid-level programming model:
[0135]
[0136] satisfy
[0137] h m (d,ω,f)≥0(19)
[0138] Lower-level planning model:
[0139]
[0140] satisfy
[0141] hl (d,ω,f)≥0(21)
[0142] In the formula: the goal of the grid defender is to minimize system loss, d is the defender's defense resource allocation strategy, which is the decision variable of the upper-level planning model, including the defense resources allocated to the PP channel and C node, and the defense resources are limited; the goal of the attacker is to maximize system loss, ω is the attacker's attack strategy, which is the decision variable of the middle-level planning model, including physical attacks on the PP channel and information attacks on the C node, and the attack resources are also limited; f is the remedial measures activated by the grid defender in response to system damage, which is the decision variable of the lower-level planning model, including reallocating power flow to the system, tripping the line with the most severe over-limit, adjusting generator output power, and shedding loads, etc. The g function in formula (16) is a function of parameters d, ω, and f, and is the expected value of the final system loss.
[0143] In one embodiment of this disclosure, the CPPS attack-defense game optimization model includes a three-layer programming model;
[0144] The decision variables of the next-level planning model depend on the decision variables of the previous-level planning model; changes in the decision variables of the next-level planning model along with changes in the decision variables of the previous-level planning model will be fed back to the previous-level planning model.
[0145] In one embodiment of this disclosure, the process of performing attack-defense game based on the CPPS attack-defense game optimization model includes:
[0146] The initial power flow of the power grid cyber-physical system is obtained based on the Newton-Raphson power flow calculation equation.
[0147] By traversing all attack scenarios, the active load loss is obtained based on the active load loss model of the power grid cyber-physical system.
[0148] Obtain information nodes under a preset active power load loss and determine the attack target;
[0149] Based on the initial power flow and the allocation process of the defense resources, the defense resources allocated to the attack target are obtained.
[0150] The model solving algorithm proposed in this invention takes the IEEE 14-bus system (14-bus power distribution system) as an example. Figure 5 In one embodiment, a 14-node power distribution system is provided. Figure 6 This is a channel relationship diagram of a 14-node power distribution system in one embodiment. Figure 7 This is a flowchart illustrating the algorithm for a simulated cyber-physical system attack and defense game in a power grid, as shown in one embodiment. The algorithm flow is described in detail below:
[0151] 1) Construct the CPPS interaction model.
[0152] 2) Calculate the power flow of the system. The power flow distribution when the system is operating normally is calculated based on the Newton-Raphson power flow model, which serves as the initial power flow state of the system.
[0153] 3) Traverse all attack scenarios. Select an attacker's attack scenario (PP\(PP+C)\(PP+C+C)), and use the particle swarm optimization algorithm to calculate the minimum common load loss and optimal generator output regulation scheme under cooperative cyber-physical attack.
[0154] 4) Searching for the worst-case attack C-node combination. The impact of information attacks on different C-nodes on system security varies. In reality, during simulation, the failure of certain C-nodes can cause communication interruptions, making it impossible to monitor or control some physical components. This leads to the worst-case attack C-node combination that maximizes the system's active power load loss. To simplify calculations, when the attack scenario is scenario 2 or scenario 3, this invention considers the worst-case attack C-node combination and uses a particle swarm optimization algorithm to solve for the attack C-node combination that maximizes the system's active power load loss.
[0155] 5) Identify the attack target. Attack scenarios 2 and 3 refer to conducting an information attack on the worst-case combination of attack C nodes found in step 4 and a physical attack on one PP channel.
[0156] 6) If all attack scenarios are listed, proceed to step 7; otherwise, return to step 3.
[0157] 7) Calculate the optimal defense resources for the components. Based on the optimal defense resource allocation strategy in Section 2.2, firstly, solve for the minimum active power load loss of the vulnerable components (C node and PP channel) under the three attack scenarios when there is no defense; secondly, allocate defense resources to the PP channel and C node.
[0158] 8) Assess CPPS vulnerabilities. The CPPS vulnerability assessment model based on step 3) can be used to perform vulnerability analysis on the components.
[0159] In one embodiment of this disclosure, the attack-defense game scenario includes a defender and an attacker;
[0160] In the upper-level planning model, the defender pre-allocates defense resources to reduce the probability of a node being successfully attacked;
[0161] In the mid-level planning model, attackers plan their attack strategies to increase CPSS losses.
[0162] In the lower-level planning model, the defender reallocates resources to reduce CPSS losses.
[0163] This embodiment is based on game theory, establishing a dynamic attack-defense game model under the condition of bounded rationality for both the attacker and defender, and considering the certain order in which they choose their strategies. The external attacker aims to maximize system losses, while the power grid defender does the opposite; the sum of their gains is zero, constituting a zero-sum game. The attacker typically steals the defense strategy by hacking into the system and then formulates their own attack strategy, while the defender does not necessarily know the attacker's strategy in advance; this is called an incomplete information game. Furthermore, the attacker and defender are adversaries without any agreed-upon protocol, thus it is a non-cooperative game.
[0164] In summary, the CPPS attack-defense game behavior discussed in this invention is a non-cooperative, dynamic, non-complete zero-sum game. The design of the attack-defense game scenario involves the following three steps:
[0165] 1) By predicting attack strategies and results, and given a limited total amount of defense resources, the power grid defender pre-allocates defense resources to PP channels and C nodes that may be subject to coordinated cyber-physical attacks, thereby reducing the probability V of successful component attacks before the system is attacked. This step corresponds to the upper-level planning model shown in equation (16) of the three-layer CPPS attack-defense game model, with the goal of minimizing system losses;
[0166] 2) After illegally intruding into the system and stealing the defense strategy, the attacker plans an attack strategy to maximize the system loss. The attacker coordinates cyber-physical attacks on the C node and PP channel to increase the probability V of the component being successfully attacked. The physically attacked PP channel trips due to failure, affecting the power flow distribution of the system. At the same time, the P node connected to the C node attacked by information fails, unable to adjust the generator output or refuse to cut load. The above faults may cause the power flow to exceed the limit, requiring the remedial measures in step 3 to restore the system to stable operation. This step corresponds to the intermediate planning model shown in equation (18) in the three-layer CPPS attack-defense game optimization model, with the goal of maximizing the system loss;
[0167] 3) The power grid defender takes further remedial measures to reduce the final system loss based on the damage to the system. When the line physically attacked in step 2 is disconnected, the defender needs to recalculate the power flow. If any line power flow exceeds the limit, the line with the most severe power flow exceedance will be tripped. The system power flow is recalculated. If there are still lines with power flow exceeding the limit, the power flow of other lines will not exceed the limit by adjusting the generator output or cutting off the load. The optimal generator output adjustment scheme and load cutting scheme are shown in step 4). At the same time, due to the failure of the P node connected to the C node of the information attack, the P node cannot adjust the generator output and refuses to cut off the load. The power flow needs to be recalculated. If there are still lines with power flow exceeding the limit, the above actions of adjusting the generator output and cutting off the load are repeated. This step corresponds to the lower-level planning model shown in equation (20) in the three-layer CPPS attack and defense game optimization model. The goal is to minimize the final system loss.
[0168] In one embodiment of this disclosure, the resource reallocation process includes:
[0169] Based on preset rules, the balanced nodes of the isolated network that was disconnected after the CPSS was attacked are reselected, and the nodes and lines of the isolated network are renumbered to form a new topology.
[0170] If the power grid topology is split into multiple isolated networks due to line disconnection, it is necessary to reselect balancing nodes for the networks without balancing nodes. The new balancing nodes are selected according to the principle of maximizing generator capacity (active power), and the nodes and lines of these isolated networks are renumbered to form new topologies and redistribute the power flow of each isolated network.
[0171] Furthermore, the simulation analysis method for the CPPS three-layer attack-defense game optimization model specifically includes the following:
[0172] Assuming the power flow limit of a line is 1.3 times the initial power flow, if the power flow value of a line exceeds 1.2 times the power flow limit after an attack, then the power flow of that line is considered to be out of limit. The first step in allocating optimal defense resources is to calculate the minimum active power load loss of the system without defense, at which point all components will fail if attacked.
[0173] To visually demonstrate the difference in the impact of coordinated cyber-physical attacks and single physical attacks on CPPS security, this invention defines the percentage of additional active power loss generated by attack scenario 2 compared to scenario 1:
[0174]
[0175] Similarly, compared to attack scenario 1, the percentage of additional active power load loss caused to the system by attack scenario 3 is:
[0176]
[0177] In the formula: C1, C2, and C3 correspond to the minimum active power load loss of the system under the three attack scenarios, respectively. If the minimum active power load loss of the system caused by attack scenario 2 or attack scenario 3 is greater than the loss caused by attack scenario 1, σ is a positive number; otherwise, σ is a negative number.
[0178] This invention, based on Matlab R2016a, uses the IEEE 14-node system as an example to simulate and analyze the above model. The IEEE 14-node system comprises 14 nodes and 20 lines, serving as the CPPS physical system in the simulation example of this invention. Based on the one-to-one mapping principle, an information system is generated from the network topology of this physical system, with node 5 serving as the control center. The IEEE 14-node system is as follows: Figure 5 As shown, its node-channel relationship is as follows: Figure 6 The simulation results are as follows:
[0179] Table 1 shows the minimum active power load loss of the IEEE 14-node system under three types of attacks when defense resources are zero. Column 1 represents the PP channels that failed due to physical attacks; column 2 represents the PP channels with the most severe power flow exceedances; columns 3 and 4 represent the 1-node and 2-node nodes with the greatest active power load loss due to information attacks, respectively; columns 5, 6, and 8 represent the minimum active power load loss under the three attack scenarios without defense, all in per-unit values; columns 7 and 9 represent the percentage of additional active power load loss caused by scenarios 2 and 3 compared to attack scenario 1.
[0180] Taking the failure of lines 2-4 due to physical attacks as an example, Figure 8 The image shows the particle swarm optimization (PSO) iteration results for three attack scenarios in one embodiment. The PSO algorithm is used to calculate the iterative results of the minimum system active power load loss under these three attack scenarios. Figure 8 As shown, the proposed solution algorithm converges within a finite number of iterations under all three attack scenarios, verifying the effectiveness of the algorithm in solving the model.
[0181] The minimum active power load loss of the system without defense can be shown in the table below:
[0182] Table 1 Minimum Active Load Loss of the System Without Defense
[0183]
[0184] Analysis of Table 1 shows that when lines 1-2 and 1-5 fail, the minimum active power load loss in attack scenarios 2 and 3 is smaller than that in scenario 1. When line 5-6 fails, the minimum active power load loss in attack scenario 3 is smaller than that in scenario 1. However, when line 4-9 fails, the minimum active power load loss in attack scenario 3 is larger than that in scenario 1. When line 5-6 fails, the minimum active power load loss in attack scenario 2 is larger than that in scenario 1. When lines 2-4, 2-5, 4-5, 4-7, 6-12, and 6-13 fail, the minimum active power load loss in attack scenarios 2 and 3 is larger than that in scenario 1. In particular, when lines 6-12 and 6-13 fail, the minimum active power load loss in attack scenario 2 increases by 61.5% compared to scenario 1. Therefore, physical attacks on different PP channels will cause different minimum active power load losses. Both physical and information attacks will affect the physical side of CPPS, and coordinated information-physical attacks will add additional load losses on top of a single physical attack.
[0185] Based on the defensive behaviors of power grid defenders in the three attack scenarios proposed above, the optimal allocation strategy for defensive resources can be obtained by solving a three-layer attack-defense game optimization model. For the IEEE 14-node system, the 14 C-nodes and 20 PP channels are vulnerable to malicious attacks, thus requiring defense of these vulnerable components. Let the total defensive resources be 50% of the vulnerable components, i.e., the total defensive resources, representing the sum of defensive resources allocated to the PP channels and C-nodes.
[0186] Under the three attack scenarios, what is the optimal amount of defense resources, d, to allocate to vulnerable components? PP or d PP,C The expected minimum active power load loss VC of the system after allocating defense resources is shown in Table 2:
[0187] Table 2 Optimal Defense Resource Allocation Strategy
[0188]
[0189] In Table 2, all lines except lines 2-3, 3-4, 6-11, 7-8, 9-10, 9-14, 10-11, 12-13, and 13-14 are allocated a certain amount of defense resources. Among them, lines 2-4 and 4-5 receive the most defense resources. In particular, due to the limited total amount of defense resources, some lines, such as line 2-5, may not be allocated any defense resources in attack scenarios 2 and 3. As shown in Equation (14), the minimum system without defense...
[0190] The expected active power load loss is the minimum system active power load loss. Comparing with Table 1, it can be seen that the expected minimum system active power load loss is significantly reduced after allocating defense resources. Therefore, grid defenders can allocate defense resources according to the degree of component damage, and by allocating optimal defense resources, they can minimize the extent of system damage.
[0191] The minimum expected active power load loss of the system in Table 2 is obtained as the maximum value VC. max The components, i.e., those allocated to defense resources, are highly likely to be attacked. Therefore, as shown in equation (4), the probability T of the component being attacked is calculated, as shown in equation (5). Finally, the risk value R of the component is obtained by solving equation (1). T See Table 3. The columns are arranged in descending order of the allocated defense resources from top to bottom. In the table, columns 1-5 represent, respectively, the PP channel under security threat in attack scenario 1, the amount of defense resources allocated to that PP channel (same as Table 2), the probability T of that PP channel being attacked, the expected minimum active power load loss VC of the system after allocating defense resources, and the risk value R. TTables 4 and 5 follow the same logic. If components in the system are allocated defensive resources, it indicates that these components have a high probability of facing security threats and are key targets for power grid defenders. The more defensive resources allocated to these components, the higher their vulnerability. Table 3 shows the vulnerable components under attack scenario 1:
[0192] Table 3. Vulnerable components under attack scenario 1 (D=17)
[0193]
[0194] Table 4 shows the vulnerable components under attack scenario 2:
[0195] Table 4. Vulnerable components under attack scenario 2 (D=17)
[0196]
[0197] Table 5 shows the vulnerable components under attack scenario 3:
[0198] Table 5. Vulnerable components under attack scenario 3 (D=17)
[0199]
[0200] Comparing the data in Tables 3-5, we can see that the parameter values VC, T, and R under a cooperative cyber-physical attack... T The values are all higher than those under a single physical attack, which verifies the above (the simulation analysis of the minimum active load loss of the system without defense) and the simulation analysis conclusion that coordinated cyber-physical attacks will cause additional load loss to the system.
[0201] Furthermore, when the total defense resources D = 17, under the same attack scenario, the parameter values VC, T, and R of different components... T The approximate similarity is a result of the allocation of defense resources. This is because the allocation of defense resources causes the minimum expected maximum value (VC) of the active power load loss generated by different vulnerable components. max The values are approximately the same, as shown in Table 2. Therefore, m is obtained from this, and the attack probabilities T for all components are also the same. Finally, the system risk value R is obtained from T, V, and C. T The same applies, see formula (1-5). Changing the total amount of defense resources will change the data in the above three tables. When the total amount of defense resources is 7, the vulnerable components under attack scenario 1 are shown in Table 6:
[0202] Table 6. Vulnerable components under attack scenario 1 (D=7)
[0203]
[0204] Table 7 shows the vulnerable components under attack scenario 2:
[0205] Table 7. Vulnerable components under attack scenario 2 (D=7)
[0206]
[0207] Table 8 shows the vulnerable components under attack scenario 3:
[0208] Table 8. Vulnerable components under attack scenario 3 (D=7)
[0209]
[0210] Changing the total amount of defense resources further confirms the above conclusions. Comparing Tables 3-5 with Tables 6-8, it can be seen that under the same attack scenario, the vulnerable components threatened by security threats and their vulnerability ranking are related to the degree of damage to these components, determined by the attacker's attack behavior, and are unrelated to the total amount of defense resources; while the vulnerability assessment results of system components are affected by the total amount of defense resources.
[0211] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0212] Based on the same inventive concept, this disclosure also provides a power grid cyber-physical system protection device for implementing the aforementioned protection method for power grid cyber-physical systems. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in the power grid cyber-physical system protection device embodiments provided below can be found in the limitations of the power grid cyber-physical system protection method described above, and will not be repeated here.
[0213] The apparatus may include a system (including a distributed system), software (application), module, component, server, client, etc., that uses the methods described in the embodiments of this specification, combined with necessary hardware implementation. Based on the same innovative concept, the apparatuses in one or more embodiments provided in this disclosure are as described in the following embodiments. Since the implementation schemes and methods for solving the problem by the apparatus are similar, the implementation of the specific apparatus in the embodiments of this specification can refer to the implementation of the foregoing methods, and repeated details will not be repeated. As used below, the terms "unit" or "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the apparatuses described in the following embodiments are preferably implemented in software, hardware implementations, or a combination of software and hardware, are also possible and contemplated.
[0214] In one embodiment, such as Figure 9 As shown, a protection device 900 for a power grid cyber-physical system is provided. The device can be the aforementioned server, or a module, component, device, or unit integrated into the server. The device 900 may include:
[0215] The confirmation module 902 is used to determine the attack scenario based on the structure of the power grid cyber-physical system interaction model. Different attack scenarios correspond to different attack targets and defense targets.
[0216] Evaluation module 904 is used to obtain a vulnerability assessment model for the power grid cyber-physical system based on the defense targets under different attack scenarios.
[0217] The load calculation module 906 is used to obtain the active load loss model of the power grid cyber-physical system based on the Newton-Raphson power flow calculation equation and preset power constraints.
[0218] The resource allocation module 908 is used to obtain the defense resources allocated to the attack target based on the vulnerability assessment framework of the power grid cyber-physical system and the active power loss model of the power grid cyber-physical system.
[0219] The game calculation module 910 is used to establish an attack and defense game model of the power grid cyber-physical system based on the structure of the interaction model of the power grid cyber-physical system and the defense resources allocated to the attack target, and to design an attack and defense game scenario to obtain a protection scheme for the power grid cyber-physical system.
[0220] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0221] Based on the foregoing description of the method embodiments, this disclosure also provides other apparatus implementations corresponding to the method embodiments. For example, it may include a first module that implements the method steps corresponding to the structure-related method embodiments of the CPPS interaction model. Alternatively, it may include a second module that implements the processing method steps for allocating the defense resources. Similarly, it may include a third module, a fourth module, etc., that implement the method processing steps of the corresponding methods.
[0222] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the methods described in any embodiment of this disclosure.
[0223] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the methods described in any embodiment of this disclosure.
[0224] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0225] The embodiments described above are merely illustrative of several implementations of this disclosure, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent disclosure. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this disclosure, and these all fall within the protection scope of this disclosure. Therefore, the protection scope of this disclosure should be determined by the appended claims.
Claims
1. A protection method for a power grid cyber-physical system, characterized in that, The method includes: Attack scenarios are determined based on the structure of the power grid cyber-physical system interaction model, and the attack targets and defense targets are different in different attack scenarios; Based on the attack targets and defense targets under different attack scenarios, a vulnerability assessment model for the power grid cyber-physical system is obtained; Based on the Newton-Raphson power flow calculation equations and the preset power constraints, an active power load loss model for the power grid cyber-physical system is obtained. The Newton-Raphson power flow calculation equations include: The preset power constraints include: The constraint condition for the load shedding ratio is: 0 ≤ η i ≤1, Active and reactive power constraints for proportional load shedding at nodes Active power constraints of load nodes Reactive power constraints of load nodes Active power load loss model for power grid cyber-physical systems: In the formula: L={L a ,L off }, L a / L off These represent the sets of controllable or uncontrollable load nodes in the system, respectively. Let i represent the active and reactive power losses at load node i, respectively. η represents the initial active load of load node i. i This represents the load shedding ratio of load node i, with a value ranging from 0 to 1; Let represent the upper and lower limits of the active power at load node i, respectively. P represents the upper and lower limits of reactive power at load node i, respectively; i ΔP i Q represents the actual active power and actual active power loss of node i. i ΔQ i U represents the actual reactive power and actual reactive power loss of node i. i δ represents the voltage magnitude at node i; ij G represents the voltage phase angle difference in branch ij; ij B ij Let N represent the conductance and susceptance of branch i; N represents the set of all nodes. PV N PQ These represent the sets of PQ nodes and PV nodes, respectively. Based on the vulnerability assessment model of the power grid cyber-physical system and the active power load loss model of the power grid cyber-physical system, the defense resources allocated to the attack target are obtained; The vulnerability assessment model for the power grid cyber-physical system includes: R T =TVC; In the above formula, R T Let V represent the expected loss of the target, T represent the probability that the target is attacked, V represent the probability of successfully attacking the target, and C represent the active power loss of the target. Based on the power grid cyber-physical system interaction model and the defense resources allocated to the attack target, an attack-defense game model for the power grid cyber-physical system is established and an attack-defense game scenario is designed to obtain a protection scheme for the power grid cyber-physical system. The allocation process for the defense resources includes: In the absence of defense resources, the active load loss under different attack scenarios is obtained based on the active load loss model of the power grid cyber-physical system. Obtain the total amount of defense resources, and based on the preset defense resource allocation precision and the total amount of defense resources, obtain the amount of each defense resource; The active load loss is sorted in descending order, and each portion of defense resources is sequentially allocated to the first N active load loss portions after sorting, until the total amount of defense resources is allocated. N is a positive integer greater than or equal to 1.
2. The method according to claim 1, characterized in that, The structure of the power grid cyber-physical system interaction model includes: The upper-layer information network includes multiple information nodes and information channels; The lower-level physical network includes multiple physical nodes and physical channels; An intermediate interaction channel is used to connect the information node and the physical node.
3. The method according to claim 1, characterized in that, The power grid cyber-physical system attack-defense game optimization model includes a planning model, the structure of which includes: The upper-level planning model, wherein the decision variables of the upper-level planning model include the defensive resources allocated to the attack target; The mid-level planning model, wherein the decision variables of the mid-level planning model include physical attack resources for physical channels and information attack resources for information nodes; The lower-level planning model, whose decision variables include the load redistributed to the power grid cyber-physical system.
4. The method according to claim 3, characterized in that, The power grid cyber-physical system attack and defense game optimization model includes a three-layer programming model; The decision variables of the next-level planning model depend on the decision variables of the previous-level planning model; Changes in the decision variables of the next-level planning model, along with changes in the decision variables of the previous-level planning model, will be fed back to the previous-level planning model.
5. The method according to claim 1, characterized in that, The process of conducting an attack-defense game based on the power grid cyber-physical system attack-defense game optimization model includes: The initial power flow of the power grid cyber-physical system is obtained based on the Newton-Raphson power flow calculation equation. By traversing all attack scenarios, the active load loss is obtained based on the active load loss model of the power grid cyber-physical system. Obtain information nodes under a preset active power load loss and determine the attack target; Based on the initial power flow and the allocation process of the defense resources, the defense resources allocated to the attack target are obtained.
6. The method according to claim 4, characterized in that, The offensive and defensive game scenario includes defenders and attackers; In the upper-level planning model, the defense resources pre-allocated by the defender are determined, and these defense resources are used to reduce the probability of a node being successfully attacked. In the mid-level planning model, the attacker's planned attack strategy is determined, which is used to increase the losses of the power grid cyber-physical system; In the lower-level planning model, the resources after the defenders are redistributed are determined.
7. The method according to claim 6, characterized in that, The resource reallocation process includes: Based on preset rules, the balance nodes of isolated networks that were disconnected after the power grid cyber-physical system was attacked are reselected, and the nodes and lines of the isolated networks are renumbered.
8. A protection device for a power grid cyber-physical system, characterized in that, The device includes: The confirmation module is used to determine the attack scenario based on the structure of the power grid cyber-physical system interaction model. Different attack scenarios correspond to different attack targets and defense targets. The assessment module is used to obtain a vulnerability assessment model for the power grid cyber-physical system based on the defense targets under different attack scenarios. The load calculation module is used to obtain the active load loss model of the power grid cyber-physical system based on the Newton-Raphson power flow calculation equation and preset power constraints. The Newton-Raphson power flow calculation equations include: The preset power constraints include: The constraint condition for the load shedding ratio is: 0 ≤ η i ≤1, Constraints on proportionally cutting off active and reactive power at load nodes Active power constraints of load nodes Reactive power constraints of load nodes Active power load loss model for power grid cyber-physical systems: In the formula: L={L a ,L off }, L a / L off These represent the sets of controllable or uncontrollable load nodes in the system, respectively. Let i represent the active and reactive power losses at load node i, respectively. η represents the initial active load of load node i. i This represents the load shedding ratio of load node i, with a value ranging from 0 to 1; Let represent the upper and lower limits of the active power at load node i, respectively. P represents the upper and lower limits of reactive power at load node i, respectively; i ΔP i Q represents the actual active power and actual active power loss of node i. i ΔQ i U represents the actual reactive power and actual reactive power loss of node i. i δ represents the voltage magnitude at node i; ij G represents the voltage phase angle difference in branch ij; ij B ij Let N represent the conductance and susceptance of branch i; N represents the set of all nodes. PV N PQ These represent the sets of PQ nodes and PV nodes, respectively. The resource allocation module is used to obtain the defense resources allocated to the attack target based on the vulnerability assessment model of the power grid cyber-physical system and the active power load loss model of the power grid cyber-physical system. The vulnerability assessment model for the power grid cyber-physical system includes: R T =TVC; In the above formula, R T Let V represent the expected loss of the target, T represent the probability that the target is attacked, V represent the probability of successfully attacking the target, and C represent the active power loss of the target. The game calculation module is used to establish an attack and defense game model of the power grid cyber-physical system based on the structure of the interaction model of the power grid cyber-physical system and the defense resources allocated to the attack target, and to design an attack and defense game scenario to obtain a protection scheme for the power grid cyber-physical system. The allocation process for the defense resources includes: In the absence of defense resources, the active load loss under different attack scenarios is obtained based on the active load loss model of the power grid cyber-physical system. Obtain the total amount of defense resources, and based on the preset defense resource allocation precision and the total amount of defense resources, obtain the amount of each defense resource; The active load loss is sorted in descending order, and each portion of defense resources is sequentially allocated to the first N active load loss portions after sorting, until the total amount of defense resources is allocated. N is a positive integer greater than or equal to 1.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Information physics power system defense method, device and equipment based on security game
CN117134987A
Modeling of adversarial artificial intelligence in blind false data injection against ac state estimation in smart grid security, safety and reliability
WO2023084279A1