Deep learning-based power distribution network attack detection method, device and medium
By extracting time-domain and frequency-domain features using a dual-layer deep learning model, and combining feature fusion and recognition, the problem of low accuracy in attack detection in power distribution networks is solved, achieving a highly efficient attack recognition effect.
Patent Information
- Application Number
- CN202411602768.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-11
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2044-11-11
AI Technical Summary
Existing deep learning methods have low accuracy in detecting attacks on power distribution networks and are difficult to effectively identify fake data injection attacks.
A two-layer deep learning model is adopted, including an upper feature extraction layer and a frequency feature extraction layer based on depthwise separable convolution, and a lower composite scaling layer based on efficient neural networks. By extracting features in the time domain and frequency domain, and combining feature fusion and recognition, attack identification is achieved.
It improves the accuracy and efficiency of attack detection in power distribution networks, enabling accurate attack identification even with limited computing resources.
Smart Images

Figure CN119544277B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of power system security, and particularly relates to a power distribution network attack detection method, device and medium based on deep learning. BACKGROUND
[0002] The power distribution network is facing various network attack threats, one of which is the false data injection attack (FDIA). In this attack, the attacker tampers with sensor measurement data, control signals or communication data packets to inject false information into the power distribution network control system, misleading the system's decision and operation. For example, the attacker can tamper with the readings of the smart meter, causing the system to incorrectly estimate the power demand and supply situation. Or the attacker can modify the voltage, current and other measurement values in the power grid, causing the system to make incorrect control decisions, such as incorrectly adjusting the transformer tap, switch state, etc., thereby affecting the stability and reliability of the power grid.
[0003] Currently, the methods for false data injection detection are mainly divided into model-driven and data-driven. Deep learning methods have good feature extraction capability and are widely used in attack detection. However, how to efficiently utilize the performance of deep learning to achieve more accurate network attack detection still needs to be studied. SUMMARY
[0004] Therefore, the present application provides a power distribution network attack detection method, device and medium based on deep learning, aiming to solve the problem of low accuracy of deep learning in network attack detection in the prior art.
[0005] The first aspect of the embodiment of the present application provides a power distribution network attack detection method based on deep learning, comprising:
[0006] Obtaining telemetry signals of the power distribution network;
[0007] Inputting the telemetry signals into a double-layer deep learning model to obtain an attack recognition result;
[0008] The double-layer deep learning model includes an upper-layer deep learning model and a lower-layer deep learning model; the upper-layer deep learning model includes a feature extraction layer based on deep separable convolution, a frequency feature extraction layer and a feature fusion layer; and the lower-layer deep learning model is based on a composite scaling layer of an efficient neural network.
[0009] In one possible implementation, inputting the telemetry signals into the double-layer deep learning model to obtain the attack recognition result comprises:
[0010] The telemetry signal is input into the upper deep learning model to obtain a fusion feature and a target feature vector; wherein the target feature vector is used to describe the extracted fusion feature;
[0011] The fusion feature and the target feature vector are input into the lower deep learning model to obtain an attack recognition result.
[0012] In a possible implementation, the telemetry signal is input into the upper deep learning model to obtain the fusion feature, comprising:
[0013] The telemetry signal is input into a feature extraction layer based on deep separable convolution to obtain a time domain feature;
[0014] According to the frequency feature extraction layer, the telemetry signal is transformed into a frequency domain signal;
[0015] The frequency domain signal is input into a feature extraction layer based on deep separable convolution to obtain a frequency domain feature;
[0016] The time domain feature and the frequency domain feature are input into a feature fusion layer to obtain the fusion feature and the target feature vector.
[0017] In a possible implementation, according to the frequency feature extraction layer, the telemetry signal is transformed into a frequency domain signal, comprising:
[0018] The telemetry signal is subjected to fast Fourier transform to obtain the frequency domain signal.
[0019] In a possible implementation, the fusion feature and the target feature vector are input into the lower deep learning model to obtain the attack recognition result, comprising:
[0020] According to the target feature vector, feature parameters of a composite scaling layer based on an efficient neural network are determined;
[0021] The fusion feature is input into the lower deep learning model to obtain the attack recognition result.
[0022] In a possible implementation, according to the target feature vector, feature parameters of a composite scaling layer based on an efficient neural network are determined, comprising:
[0023] According to feature dimension information, feature complexity information and feature correlation information in the target feature vector, a depth adjustment interval, a width adjustment interval and a resolution adjustment interval of the composite scaling layer based on the efficient neural network are determined.
[0024] In a possible implementation, a loss function of the double-layer deep learning model is a joint loss function; the joint loss function is a weighted sum of an upper loss function and a lower loss function; the upper loss function is a mean square error loss function; and the lower loss function is a cross-entropy loss function.
[0025] In a possible implementation, the method further includes:
[0026] obtaining normal sample data of the power distribution network;
[0027] randomly tampering with part of the normal sample data to generate attack samples with different attack intensities;
[0028] randomly mixing the normal sample data and the attack sample data, dividing training set, validation set and test set, and training the double-layer deep learning model.
[0029] The second aspect of the embodiment of the application provides a power distribution network attack detection device based on deep learning, including:
[0030] an acquisition module configured to acquire telemetry signals of the power distribution network;
[0031] an identification module configured to input the telemetry signals into a double-layer deep learning model to obtain an attack identification result;
[0032] The double-layer deep learning model includes an upper-layer deep learning model and a lower-layer deep learning model; the upper-layer deep learning model includes a feature extraction layer based on a deep separable convolution, a frequency feature extraction layer and a feature fusion layer; and the lower-layer deep learning model is based on a composite scaling layer of an efficient neural network.
[0033] The third aspect of the embodiment of the application provides an electronic device including a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the power distribution network attack detection method based on deep learning of the first aspect when executing the computer program.
[0034] The fourth aspect of the embodiment of the application provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the power distribution network attack detection method based on deep learning of the first aspect.
[0035] The embodiment of the application provides a power distribution network attack detection method, device and medium based on deep learning. First, telemetry signals of a power distribution network are acquired. Then, the telemetry signals are input into a double-layer deep learning model to obtain an attack identification result. The double-layer deep learning model comprises an upper-layer deep learning model and a lower-layer deep learning model. The upper-layer deep learning model comprises a feature extraction layer based on a deep separable convolution, a frequency feature extraction layer and a feature fusion layer. The lower-layer deep learning model is based on a composite scaling layer of an efficient neural network. The embodiment of the application designs a double-layer network. The feature extraction layer based on the deep separable convolution of the upper-layer network can simultaneously extract time domain and frequency domain features, can capture more details and patterns in the power distribution network data, the lower-layer network has efficient model performance, and accurate classification can be realized under limited computing resources, so that accurate power distribution network attack detection is realized. BRIEF DESCRIPTION OF DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor under the premise of the drawings.
[0037] Figure 1 is an implementation flowchart of the power distribution network attack detection method based on deep learning provided by the embodiment of the application.
[0038] Figure 2 is a structural schematic diagram of the power distribution network attack detection device based on deep learning provided by the embodiment of the application.
[0039] Figure 3 is a structural schematic diagram of the electronic device provided by the embodiment of the application. DETAILED DESCRIPTION
[0040] In the following description, specific details are set forth such as particular system configurations, techniques, etc., in order to provide a thorough understanding of the embodiments of the application. However, it should be apparent to those skilled in the art that the application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the application with unnecessary detail.
[0041] Figure 1 is an implementation flowchart of the power distribution network attack detection method based on deep learning provided by the embodiment of the application. As shown in Figure 1 , in some embodiments, the power distribution network attack detection method based on deep learning comprises:
[0042] S110, acquire telemetry signals of the power distribution network;
[0043] S120, input the telemetry signals into a double-layer deep learning model to obtain an attack identification result;
[0044] The double-layer deep learning model comprises an upper-layer deep learning model and a lower-layer deep learning model; the upper-layer deep learning model comprises a feature extraction layer based on a deep separable convolution, a frequency feature extraction layer, and a feature fusion layer; and the lower-layer deep learning model is based on a composite scaling layer of an efficient neural network.
[0045] The power grid telemetry signal is a technical means for remotely measuring and monitoring the operation state of the power grid in the power system. The telemetry signal is very important in the power grid, which can help the power grid operator to monitor the operation state of the power grid in real time, and ensure the stable, safe and efficient operation of the power grid.
[0046] In the embodiment of the present application, the telemetry signal data is composed of real-time monitoring of the operation parameters of the power grid, such as voltage, current, power and other power parameters collected from various sensors, devices or systems.
[0047] In addition, the telemetry signal needs to be denoised, and a filtering algorithm (such as median filtering, mean filtering, etc.) can be used to remove noise interference. Then, normalization processing is performed to scale the data to the same numerical range, such as [0, 1] or [-1, 1], to improve the training effect and stability of the model. The data can be segmented for processing, and long time series data can be segmented into shorter segments for better model processing.
[0048] In the embodiment of the present application, the deep separable convolution is an efficient convolution operation that decomposes the traditional convolution into two lighter operations: depthwise convolution and pointwise convolution.
[0049] Depthwise convolution: In depthwise convolution, each input channel is convolved individually, rather than all channels simultaneously. This means that if the input has C channels, C different filters will be used, each acting on the corresponding input channel. The size of each filter is usually small, such as 3x3. This operation significantly reduces the number of parameters and computational complexity.
[0050] Pointwise convolution: After depthwise convolution, pointwise convolution is used to combine the outputs of depthwise convolution. Pointwise convolution uses a 1x1 convolution kernel, and its purpose is to combine the outputs of depthwise convolution to generate new feature maps. This operation is crucial if you need to change the number of output channels.
[0051] Depthwise separable convolutions have a much lower total computational cost than standard convolutions, making them very popular for use on mobile and edge devices. For example, MobileNets are built on this type of convolution, significantly reducing model complexity and size while maintaining performance.
[0052] Efficient neural networks are a series of convolutional neural network architectures that use a method called compound scaling to balance the width, depth, and resolution of the network, thereby improving accuracy while maintaining efficiency.
[0053] Composite scaling: Efficient neural networks do not scale the width, depth, or resolution of the network independently, but rather scale all three dimensions simultaneously using a uniform scaling factor. This factor is determined based on extensive experimentation to optimize accuracy and efficiency.
[0054] Network Architecture: The efficient neural network is built on MobileNetV2 and inverted residual blocks, which contain depthwise separable convolutions. These blocks first expand the number of channels using depthwise convolutions, and then reduce the number of channels using pointwise convolutions.
[0055] Swish activation function: The Swish activation function has been shown to be more efficient than ReLU in some cases.
[0056] Auto-sizing pooling layers: Auto-sizing pooling layers are used at the end of the network to handle images of different input sizes.
[0057] Model variants: There are multiple versions of EfficientNet, such as EfficientNet-B0, B1, B2, etc., each with different scaling factors and network size.
[0058] Highly efficient neural networks have demonstrated outstanding performance across a wide range of image recognition tasks, achieving state-of-the-art results on various datasets while maintaining high efficiency. The success of these networks proves that scaling networks systematically can lead to more efficient model design without sacrificing performance.
[0059] In some embodiments, inputting telemetry signals into a two-layer deep learning model to obtain attack identification results includes: inputting telemetry signals into an upper-layer deep learning model to obtain fused features and target feature vectors; wherein the target feature vectors are used to describe the extracted fused features; and inputting the fused features and target feature vectors into a lower-layer deep learning model to obtain attack identification results.
[0060] In this embodiment of the invention, the depthwise separable convolutional network structure can be based on lightweight depthwise separable convolutional networks such as MobileNetV2 and Xception. These networks maintain high performance while having relatively low computational cost, making them suitable for processing large-scale telemetry data. Efficient neural network architectures such as EfficientNet and MobileNetV3 can be selected as the basis for the lower-layer models. These networks have adjustable depth, width, and resolution, and can adaptively adjust according to the characteristics of the input features.
[0061] In some embodiments, inputting telemetry signals into an upper-layer deep learning model to obtain fused features includes: inputting telemetry signals into a feature extraction layer based on depthwise separable convolution to obtain temporal features; transforming the telemetry signals into frequency domain signals according to a frequency feature extraction layer; inputting the frequency domain signals into a feature extraction layer based on depthwise separable convolution to obtain frequency domain features; and inputting the temporal and frequency domain features into a feature fusion layer to obtain fused features and a target feature vector.
[0062] In this embodiment of the invention, a network structure is constructed comprising multiple depthwise separable convolutional layers, batch normalization layers, and activation function layers. For example, the following structure can be used:
[0063] Input layer: Receives telemetry signal data.
[0064] Depthwise separable convolutional layer 1: Use a small convolutional kernel (e.g., 3x3), set an appropriate number of filters (e.g., 32) and stride (e.g., 1) to extract temporal features.
[0065] Batch Normalization Layer 1: Performs batch normalization on the output of the convolutional layer to accelerate model training and improve stability.
[0066] Activation function layer 1: Use activation functions such as ReLU to increase the non-linear expressive power of the model.
[0067] Parameter tuning: Based on the characteristics of telemetry data and computational resource limitations, adjust the network's hyperparameters, such as kernel size, number of filters, and stride. The optimal parameter combination can be determined through performance evaluation on experimental and validation sets.
[0068] Frequency Domain Signal Transformation: Fast Fourier Transform (FFT) Implementation: Implement the Fast Fourier Transform algorithm using existing signal processing libraries (such as NumPy, SciPy, etc.). Convert telemetry signals from the time domain to the frequency domain to obtain a frequency domain representation.
[0069] Frequency domain signal processing: Appropriate processing of frequency domain signals, such as removing DC components and performing amplitude normalization, can improve the effectiveness of subsequent frequency domain feature extraction. The amplitude spectrum or power spectrum of the frequency domain signal can be calculated as the basis for frequency domain feature extraction.
[0070] Frequency domain feature extraction:
[0071] Constructing a frequency domain feature extraction network: Similar to the time domain feature extraction network, construct a frequency domain feature extraction network based on depthwise separable convolutions. The network structure and parameters can be adjusted according to the characteristics of the frequency domain signal.
[0072] Frequency domain convolutional layer design: Use a convolutional kernel size and number of filters suitable for the frequency domain signal. For example, a larger convolutional kernel (such as 5x5) can be used to capture local patterns in the frequency domain.
[0073] Batch normalization and activation function: Similar to the temporal feature extraction network, batch normalization layers and activation function layers are added to improve the performance and stability of the model.
[0074] Feature Fusion: Fusion Strategy Selection: Various fusion strategies can be employed, such as concatenation and weighted summation. Concatenation fusion combines time-domain and frequency-domain features along the channel dimension to form a higher-dimensional feature vector. Weighted summation fusion assigns different weights to the time-domain and frequency-domain features and then performs a summation operation.
[0075] Fully connected layer processing: A fully connected layer is added to the fused features to further compress the feature vector, resulting in the target feature vector. The fully connected layer can learn a higher-level representation of the fused features while reducing feature dimensionality and improving model efficiency. The role of the target feature vector: The target feature vector describes important information about the fused features, such as feature dimensionality, complexity, and relevance. It can serve as input to lower-level deep learning models, helping them better understand and process the fused features.
[0076] In some embodiments, transforming telemetry signals into frequency domain signals according to the frequency feature extraction layer includes: performing a fast Fourier transform on the telemetry signals to obtain frequency domain signals.
[0077] In some embodiments, inputting the fused features and the target feature vector into the lower-level deep learning model to obtain the attack identification result includes: determining the feature parameters of the composite scaling layer based on the target feature vector; and inputting the fused features into the lower-level deep learning model to obtain the attack identification result.
[0078] In this embodiment of the invention, an output layer is added to the last layer of the lower-level deep learning model to predict the attack type. A softmax classifier can be used to map the fused features to different attack categories.
[0079] In some embodiments, determining the feature parameters of the composite scaling layer based on the efficient neural network according to the target feature vector includes: determining the depth adjustment range, width adjustment range, and resolution adjustment range of the composite scaling layer based on the efficient neural network according to the feature dimension information, feature complexity information, and feature correlation information in the target feature vector.
[0080] In this embodiment of the invention, the feature parameter adjustment range is determined by: determining the depth adjustment range, width adjustment range, and resolution adjustment range of the composite scaling layer based on the feature dimension information, feature complexity information, and feature correlation information in the target feature vector.
[0081] Feature dimensionality information: If the target feature vector has a high dimensionality, the network depth can be appropriately increased to better capture complex feature relationships. Depth can be adjusted by increasing the number of network layers or the number of filters in each layer.
[0082] Feature complexity information: Based on the entropy, variance, or other complexity metrics of the feature vectors, determine the range for adjusting the network width. If the feature complexity is high, the network width can be increased, i.e., the number of filters in each layer can be increased, to improve the model's expressive power.
[0083] Feature correlation information: Analyze the correlation between different features in the target feature vector to determine the resolution adjustment range. If the correlation between features is high, the network resolution can be reduced to decrease computation while maintaining model performance. Resolution adjustment can be achieved by adjusting the size of the input image or by using downsampling layers in the network.
[0084] Dynamic tuning strategies: During training, dynamic tuning strategies can be used to adjust the parameters of the composite scaling layer based on different samples. For example, random search, evolutionary algorithms, or gradient-based optimization methods can be used to find the optimal parameter combination. Parameters can be adjusted based on the performance metrics of the validation set after each training batch or after a certain number of training epochs.
[0085] In some embodiments, the loss function of the two-layer deep learning model is a joint loss function; the joint loss function is a weighted sum of the upper-layer loss function and the lower-layer loss function; the upper-layer loss function is the mean squared error loss function; and the lower-layer loss function is the cross-entropy loss function.
[0086] In this embodiment of the invention, mean squared error is used to evaluate the loss during feature extraction, ensuring the accuracy of feature extraction. Cross-entropy loss is used to evaluate the loss during classification, ensuring the accuracy of classification results. The reconstruction loss of the upper-layer network and the classification loss of the lower-layer network are combined to form a joint loss function, specifically implemented through weighting, thereby ensuring the collaborative optimization of the two networks. The upper-layer and lower-layer networks alternately update their weights to ensure the collaborative optimization of feature extraction and classification tasks. An optimization algorithm, such as Adam or SGD, is selected to minimize the loss function and update the model parameters. A suitable optimization algorithm can be selected based on the characteristics of the model and the scale of the training data, and its hyperparameters, such as learning rate and momentum, can be adjusted.
[0087] In some embodiments, the method further includes: acquiring normal sample data of the power distribution network; randomly tampering with some normal samples to generate attack samples with different attack intensities; randomly mixing normal samples and attack samples, dividing them into training sets, validation sets and test sets, and training a two-layer deep learning model.
[0088] In this embodiment of the invention, the time span of the data is ensured to be sufficiently long, and the sample distribution of each dataset is representative to cover different operating states and possible attack scenarios. The data also needs to be labeled to identify which samples are normal and which samples have been subjected to different types of attacks. The training set, validation set, and test set can typically be divided in a ratio of 70%, 15%, and 15%, respectively.
[0089] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0090] Figure 2 This is a schematic diagram of the structure of a deep learning-based power distribution network attack detection device provided in an embodiment of the present invention. Figure 2 As shown, in some embodiments, the deep learning-based power distribution network attack detection device 2 includes:
[0091] Acquisition module 210 is used to acquire telemetry signals from the power distribution network;
[0092] The identification module 220 is used to input telemetry signals into a two-layer deep learning model to obtain attack identification results;
[0093] The two-layer deep learning model includes an upper-layer deep learning model and a lower-layer deep learning model. The upper-layer deep learning model includes a feature extraction layer, a frequency feature extraction layer, and a feature fusion layer based on depthwise separable convolution. The lower-layer deep learning model is based on a composite scaling layer of an efficient neural network.
[0094] Optionally, the identification module 220 is used to input telemetry signals into the upper-layer deep learning model to obtain fused features and target feature vectors; wherein, the target feature vector is used to describe the extracted fused features; and the fused features and target feature vectors are input into the lower-layer deep learning model to obtain the attack identification result.
[0095] Optionally, the recognition module 220 is used to input the telemetry signal into a feature extraction layer based on depthwise separable convolution to obtain time-domain features; transform the telemetry signal into a frequency-domain signal according to the frequency feature extraction layer; input the frequency-domain signal into a feature extraction layer based on depthwise separable convolution to obtain frequency-domain features; and input the time-domain features and frequency-domain features into a feature fusion layer to obtain fused features and target feature vectors.
[0096] Optionally, the identification module 220 is used to perform a fast Fourier transform on the telemetry signal to obtain a frequency domain signal.
[0097] Optionally, the recognition module 220 is used to determine the feature parameters of the composite scaling layer based on the target feature vector; and input the fused features into the lower-level deep learning model to obtain the attack recognition result.
[0098] Optionally, the recognition module 220 is used to determine the depth adjustment range, width adjustment range, and resolution adjustment range of the composite scaling layer based on the efficient neural network according to the feature dimension information, feature complexity information, and feature correlation information in the target feature vector.
[0099] Optionally, the loss function of the two-layer deep learning model is a joint loss function; the joint loss function is a weighted sum of the upper-layer loss function and the lower-layer loss function; the upper-layer loss function is the mean squared error loss function; and the lower-layer loss function is the cross-entropy loss function.
[0100] Optionally, the deep learning-based distribution network attack detection device 2 also includes a training module for acquiring normal sample data of the distribution network; randomly tampering with some normal samples to generate attack samples with different attack intensities; randomly mixing normal samples and attack samples to divide them into training set, validation set and test set, and training the two-layer deep learning model.
[0101] The deep learning-based power distribution network attack detection device provided in this embodiment can be used to execute the above method embodiment. Its implementation principle and technical effect are similar, and will not be described again here.
[0102] Figure 3 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. For example... Figure 3As shown, an embodiment of the present invention provides an electronic device 3, which includes a processor 30, a memory 31, and a computer program 32 stored in the memory 31 and executable on the processor 30. When the processor 30 executes the computer program 32, it implements the steps in the various LLC-based output voltage calibration method embodiments described above, for example... Figure 2 The steps shown. Alternatively, when processor 30 executes computer program 32, it implements the functions of each module / unit in the above system embodiments, for example... Figure 3 The functions of each module are shown.
[0103] For example, computer program 32 may be divided into one or more modules / units, one or more of which are stored in memory 31 and executed by processor 30 to complete the present invention. One or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of computer program 32 in electronic device 3.
[0104] Electronic device 3 can be a mobile phone, MCU, ECU, industrial control computer, etc., and is not limited thereto. Electronic device 3 may include, but is not limited to, processor 30 and memory 31. Those skilled in the art will understand that... Figure 3 Figure 3 This is merely an example of electronic device 3 and does not constitute a limitation on electronic device 3. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device may also include input / output devices, network access devices, buses, etc.
[0105] The processor 30 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0106] The memory 31 can be an internal storage unit of the electronic device 3, such as a hard disk or RAM. The memory 31 can also be an external storage device of the electronic device 3, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the memory 31 can include both internal and external storage units of the electronic device 3. The memory 31 is used to store computer programs and other programs and data required by the electronic device. The memory 31 can also be used to temporarily store data that has been output or will be output.
[0107] This invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the LLC-based output voltage calibration method embodiment.
[0108] A computer-readable storage medium stores a computer program 32. The computer program 32 includes program instructions. When executed by the processor 30, the program instructions implement all or part of the processes in the methods described in the above embodiments. The computer program 32 can also instruct related hardware to complete the process. The computer program 32 can be stored in a computer-readable storage medium. When executed by the processor 30, the computer program 32 can implement the steps of the various method embodiments described above. The computer program 32 includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0109] The computer-readable storage medium can be an internal storage unit of the electronic device in any of the foregoing embodiments, such as a hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk, smart media card (SMC), secure digital card (SD), flash card, etc., equipped on the electronic device. Furthermore, the computer-readable storage medium can include both internal and external storage units of the electronic device. The computer-readable storage medium is used to store computer programs and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0110] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0111] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0112] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0113] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0114] In the embodiments provided by this invention, it should be understood that the disclosed devices / electronic devices and methods can be implemented in other ways. For example, the device / electronic device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0115] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0116] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0117] If an integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0118] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A deep learning-based method for detecting attacks on power distribution networks, characterized in that, include: Acquire telemetry signals from the power distribution network; The telemetry signal is input into a two-layer deep learning model to obtain the attack identification result; The dual-layer deep learning model includes an upper-layer deep learning model and a lower-layer deep learning model; the upper-layer deep learning model includes a feature extraction layer, a frequency feature extraction layer, and a feature fusion layer based on depthwise separable convolution; the lower-layer deep learning model is based on a composite scaling layer of an efficient neural network. The telemetry signal is input into a two-layer deep learning model to obtain attack identification results, including: The telemetry signal is input into the upper-layer deep learning model to obtain fused features and target feature vectors; wherein, the target feature vector is used to describe the extracted fused features; The fused features and target feature vectors are input into the lower-level deep learning model to obtain the attack identification result; The fused features and target feature vectors are input into the lower-level deep learning model to obtain the attack identification result, including: The feature parameters of the composite scaling layer based on the efficient neural network are determined according to the target feature vector; The fused features are input into the lower-level deep learning model to obtain the attack identification result.
2. The deep learning-based power distribution network attack detection method according to claim 1, characterized in that, The telemetry signal is input into the upper-layer deep learning model to obtain fused features, including: The telemetry signal is input into a feature extraction layer based on depthwise separable convolution to obtain temporal features; Based on the frequency feature extraction layer, the telemetry signal is transformed into a frequency domain signal; The frequency domain signal is input into a feature extraction layer based on depthwise separable convolution to obtain frequency domain features; The time-domain features and the frequency-domain features are input into the feature fusion layer to obtain the fused features and the target feature vector.
3. The deep learning-based power distribution network attack detection method according to claim 2, characterized in that, Based on the frequency feature extraction layer, the telemetry signal is transformed into a frequency domain signal, including: The telemetry signal is subjected to a fast Fourier transform to obtain a frequency domain signal.
4. The deep learning-based power distribution network attack detection method according to claim 1, characterized in that, Determining the feature parameters of the composite scaling layer based on the efficient neural network according to the target feature vector includes: Based on the feature dimension information, feature complexity information, and feature correlation information in the target feature vector, the depth adjustment range, width adjustment range, and resolution adjustment range of the composite scaling layer based on the efficient neural network are determined.
5. The deep learning-based power distribution network attack detection method according to claim 1, characterized in that, The loss function of the two-layer deep learning model is a joint loss function; the joint loss function is a weighted sum of the upper-layer loss function and the lower-layer loss function; the upper-layer loss function is the mean squared error loss function; and the lower-layer loss function is the cross-entropy loss function.
6. The deep learning-based power distribution network attack detection method according to any one of claims 1-5, characterized in that, The method further includes: Obtain normal sample data of the power distribution network; Randomly modify the data of some normal samples to generate attack samples with different attack strengths; Normal samples and attack samples are randomly mixed and divided into training set, validation set and test set, and the two-layer deep learning model is trained.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the deep learning-based power distribution network attack detection method as described in any one of claims 1 to 6.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the deep learning-based power distribution network attack detection method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
False data attack detection method and system based on state estimation
CN116232742A
Distributed photovoltaic power distribution network different-frequency injection attack identification method and system
CN118250092A