Digital power grid security situation awareness method and system based on selective convolutional network

By combining selective convolutional networks and temporal convolutional networks, the problems of insufficient feature extraction and low accuracy of dynamic situation prediction in digital power grid security situation awareness are solved, and efficient processing of multi-source heterogeneous data and accurate prediction of fault risks are achieved.

CN119624110BActive Publication Date: 2026-01-06GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411695711.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2026-01-06
Estimated Expiration
2044-11-25

AI Technical Summary

Technical Problem

Existing technologies in digital power grid security situation awareness suffer from insufficient feature extraction capabilities, poor data imbalance processing performance, and low accuracy in dynamic situation prediction, making it difficult to effectively perceive fault risks in complex, multi-source, heterogeneous data environments.

Method used

Selective convolutional networks are used to preprocess multivariate heterogeneous data. Fault risk is judged by multi-scale feature extraction and a secondary classification model. Temporal convolutional networks are combined for situation prediction. State probability factors and attack impact factors are used to quantify the power grid security situation.

Benefits of technology

It improves feature extraction accuracy, enhances minority class sample recognition capabilities, optimizes complex temporal feature modeling, and significantly improves the efficiency and reliability of digital power grid security situation awareness and prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119624110B_ABST
    Figure CN119624110B_ABST
Patent Text Reader

Abstract

The application discloses a digital power grid security situation awareness method and system based on a selective convolution network, relates to the technical field of asset security management and control, and comprises the following steps: collecting multi-element heterogeneous data of digital power grid operation by using a sensor and performing preprocessing; adopting a selective convolution network to perform multi-scale feature extraction on the preprocessed data; inputting the extracted multi-scale features into a secondary classification model to perform fault risk judgment and classification; and combining a time domain convolution network to perform time sequence modeling on the classification results and the multi-scale features, and predicting future operation situation and potential risks of the digital power grid. The application improves the selective convolution network and the selective time domain convolution network, solves the problems of insufficient multi-source heterogeneous data feature extraction capability, low classification precision caused by data imbalance and limited time sequence modeling capability, and achieves the effects of enhancing feature extraction precision, improving minority class sample recognition capability, optimizing complex time sequence feature modeling and situation prediction precision.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of asset security management technology, specifically to a digital power grid security situation awareness method and system based on selective convolutional networks. Background Technology

[0002] Digital grids, as a core technology of modern power systems, are rapidly developing globally. They are a new type of network that improves the efficiency and security of power system operations by combining digitalization, informatization, and power management. The main characteristic of digital grids lies in their use of internet technology to integrate traditional power facilities with modern information processing methods, constructing a power operation system with real-time sensing, intelligent analysis, and efficient control. In this new grid, every node, device, and even user becomes a data generation or management point within the power network. Through the collaborative application of sensor networks, edge computing, cloud computing, and big data analytics, digital grids achieve dynamic monitoring and optimized management of the entire lifecycle of electricity, from production to consumption. However, with the rapid development of digital grid technology, its security issues are becoming increasingly prominent. Traditional power system operation and management models are unable to adapt to this highly interconnected and dynamically changing complex system, necessitating the introduction of more intelligent and dynamic security situation awareness technologies to ensure the stable and efficient operation of digital grids.

[0003] The core function of a digital grid is to achieve dynamic management and optimization of the entire power system by comprehensively sensing the grid's operational status. Real-time monitoring and status detection are fundamental to a digital grid, relying on sensors and data acquisition systems to accurately monitor the status of each link in the power generation, transmission, and distribution systems. The digital grid also provides early warnings of potential equipment failures through fault prediction and diagnosis, preventing sudden power outages. Furthermore, the load management and optimized scheduling functions of a digital grid can adjust power allocation according to real-time demand, improving resource utilization efficiency and reducing energy waste. Intelligent decision support is a higher-level manifestation of a digital grid, providing scientific decision-making basis for grid scheduling, operation, and maintenance through the integration of multi-dimensional data analysis. The effective implementation of these functions makes the digital grid a crucial foundation for ensuring energy supply in modern society, but it also places higher demands on the security and intelligent management of grid operation.

[0004] While digital grids offer significant advantages in improving the efficiency and intelligence of power systems, they also inevitably bring many security challenges. First, because digital grids heavily rely on internet technology, their various devices and systems are exposed to the network environment, making them highly vulnerable to external hacker attacks. Intrusion into core power facilities could lead to large-scale power outages and even threaten national security. Second, digital grids generate massive amounts of data from complex and heterogeneous sources, including equipment operation data, user demand data, and network communication data. This complex data environment makes real-time processing and security management difficult. Third, real-time prediction of grid status becomes more challenging. The operating status of the grid is not only affected by the performance of the equipment itself but is also closely related to external factors such as climate change and user demand. This high dynamism and uncertainty pose a significant challenge to traditional situational awareness methods. Finally, the reliability issues of numerous sensors and devices in digital grids also pose a threat to the overall system security. Failure or false alarms at any node could lead to inaccurate situational awareness across the entire system. Therefore, improving the security situational awareness capabilities of digital grids has become a top priority.

[0005] The development of digital power grid security situation awareness technology has evolved from traditional statistical analysis to machine learning. Traditional statistical analysis methods mainly predict potential faults by analyzing historical data and building mathematical models. While these methods were effective in the early stages, their overly idealistic assumptions made them difficult to adapt to complex and dynamic data environments. For example, regression analysis and time series analysis often exhibit prediction bias when dealing with heterogeneous data from multiple sources. Furthermore, knowledge-based reasoning methods, such as Markov chain models and Bayesian networks, infer future states by modeling the historical state of the power grid. Although these methods perform well in processing structured data, their computational complexity and generalization ability are limited when dealing with real-time data and unstructured information. In recent years, machine learning methods such as BP neural networks and RBF neural networks have brought new breakthroughs to digital power grid situation awareness. These methods can extract fault patterns by training on historical data, thereby improving fault identification capabilities. However, these technologies still have certain limitations in practical applications, such as sensitivity to data imbalance and a lack of comprehensive extraction capabilities for multi-dimensional features.

[0006] While existing technologies have played a role in digital power grid security situation awareness, many problems remain when facing more complex application scenarios. First, insufficient feature extraction capability is one of the main bottlenecks. Traditional models struggle to extract high-dimensional features with spatiotemporal correlations from complex multi-source data, leading to insufficient accuracy in situation awareness. Second, most existing methods use fixed receptive fields, which cannot adapt to the dynamic changes in power grid operating conditions. This single receptive field design cannot comprehensively capture multi-scale information from the data. Furthermore, the imbalance between normal and fault data in power grid data further exacerbates the difficulty of model training, resulting in poor fault prediction and classification performance. Finally, existing situation prediction methods are prone to gradient explosion or vanishing gradient problems when processing time-series data, leading to insufficient timeliness of prediction results. These shortcomings limit the performance and reliability of digital power grid security situation awareness systems. Summary of the Invention

[0007] In view of the above-mentioned problems, the present invention is proposed.

[0008] Therefore, the technical problem solved by this invention is: how to effectively perceive the security status of the digital power grid in a complex, multi-source, heterogeneous data environment, and achieve accurate classification and prediction of fault risks, while overcoming the problems of insufficient feature extraction capability, poor data imbalance processing effect, and low accuracy of dynamic situation prediction in the existing technology.

[0009] To address the aforementioned technical problems, this invention provides the following technical solution: a digital power grid security situation awareness method based on selective convolutional networks, comprising the following steps:

[0010] Use sensors to collect diverse and heterogeneous data on the operation of the digital power grid for preprocessing;

[0011] Selective convolutional networks are used to extract multi-scale features from the preprocessed data;

[0012] The extracted multi-scale features are input into a secondary classification model to determine and classify fault risks.

[0013] By combining time-domain convolutional networks to perform time-series modeling of classification results and multi-scale features, the future operating status and potential risks of digital power grids can be predicted.

[0014] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the step of collecting diverse and heterogeneous data on digital power grid operation using sensors includes:

[0015] Log collectors are deployed on key equipment and nodes of the digital power grid to collect log information generated during equipment operation. The collectors communicate with the equipment through system logs and obtain detailed information on equipment operating status, fault alarms, and performance indicators in real time.

[0016] The collected log data is sent to the central processing unit for processing through a secure transmission path, and encryption technology is used during the transmission process.

[0017] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the preprocessing is performed in the central processing unit. The data first enters the parsing and filtering module to clean and classify the log data, remove redundant information, and extract the core features related to the security situation of power grid equipment. The extracted features are then organized and stored.

[0018] The collected multivariate heterogeneous data exists in the form of network traffic, including discrete and continuous features. The discrete features are quantified and transformed into a numerical form that can be processed by machines. The expression is as follows:

[0019] X m =f(X) cat ), f = X cat ->{0,1,2,...,n-1}

[0020] Where n is the number of network protocol types, X cat For discrete features, f(x) is a mapping function, X m It is a set of certificate values;

[0021] To address the discretized characteristics in network traffic data, one-hot encoding is used to convert different IP addresses or protocol types into binary vectors.

[0022] In one-hot encoding, suppose a categorical variable X1 has k distinct categories, and each category i corresponds to a category value X. i Where i∈{1,2,…,k}, for each value of the categorical variable X1, it is transformed into a k1-dimensional one-hot vector v. For a categorical variable X1=x i The expression for the one-hot encoded vector v is:

[0023]

[0024] Among them, v j This represents the value of the j-th element in vector v;

[0025] For continuous features in network traffic data, standardization or normalization methods can be used to scale the range of feature values ​​to a suitable range, thereby reducing scale differences between features.

[0026] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the step of using selective convolutional networks to extract multi-scale features from the preprocessed data includes:

[0027] In the improved selective convolutional unit, multi-scale features of the input data are extracted in parallel using convolutional kernels of different scales. Let the input feature map be X2 with a size of H×W×C, and the input feature map U of each convolutional kernel be... k The calculation formula is:

[0028]

[0029] Among them, W k These are the weights of the k-th convolutional kernel, where M×N is the kernel size, and b k is the bias parameter of the k-th convolution kernel, i and j are the row and column indices of the feature map, k is the kernel index, m is the kernel row index, and n1 is the kernel column index;

[0030] Introducing a global average pooling operation, for each branch U k Global average pooling result S k The expression is:

[0031]

[0032] Weights W are generated using a two-layer fully connected network and an activation function. k The expression is:

[0033] W k =σ(W2·δ(W1·S) k ))

[0034] Where σ is the Sigmoid activation function, δ is the ReLU activation function, and W1 and W2 are the weight matrices of the fully connected layer;

[0035] Weight W k Branch feature map U corresponding to the action k And perform weighted fusion, the expression is:

[0036]

[0037] Here, V1 is a weighted integration of multi-scale features, and K is the total number of convolution kernels.

[0038] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the step of inputting the extracted multi-scale features into a secondary classification model for fault risk judgment and classification includes,

[0039] Let the input dataset be D = {(x i ,y i )}, where x i Represents the input features, y i Indicates the label, y i ∈{0, 1, ..., C1};

[0040] Construct an attack identification model, expressed as:

[0041] F1(x) = Sigmoid(W attack ·x+b)

[0042] Among them, W attack is the classification weight, x is the multi-scale feature extracted by the selective convolutional network, and b is the bias parameter of the quadratic classification model;

[0043] The output F1(x) represents the probability that sample x belongs to the attack class. A new dataset D is constructed for attack samples whose predicted probability F1(x) > 0.5. attack ={(x i ,y i )|y i ≠0};

[0044] Construct an attack classification model, with the following expression:

[0045] F2(x)=Softmax(W class ·x+b)

[0046] Where F2(x) is the probability distribution of the attack sample belonging to each attack type, and W class This is the attack classification weight matrix.

[0047] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the step of inputting the extracted multi-scale features into a secondary classification model for fault risk judgment and classification further includes,

[0048] A situational value calculation model is constructed using a state probability factor and an attack impact factor. The state probability factor P... i The probability of type i attack occurring within the current time period is expressed by the formula:

[0049]

[0050] Where, n i N1 represents the number of attack samples of type i, and N1 represents the total number of samples in the situational value calculation model.

[0051] Attack Impact Factor E i The expression for evaluating the impact of type i attacks on confidentiality, integrity, and availability is:

[0052] E i =C i +I i +A i

[0053]

[0054] Among them, C i I i A i These represent the degree of threat to confidentiality, integrity, and availability, respectively. i T represents the amount of sensitive data leaked due to the i-th type of attack. i T represents the number of data tampering events caused by the i-th type of attack. t U represents the total number of data transmission events within the current time period. i U represents the percentage of effective service time or traffic caused by the i-th type of attack. t This indicates the percentage of total service time or traffic that should be processed. t This represents the total amount of sensitive data related to the power grid within the current time period.

[0055] The final situation value expression is:

[0056]

[0057] Where C2 represents the number of network attack states, and P i E represents the probability of the i-th type of attack occurring within the current time period. i This is an attack influencing factor.

[0058] As a preferred embodiment of the digital power grid security situation awareness method based on selective convolutional networks described in this invention, the step of combining a time-domain convolutional network to perform time-series modeling of classification results and multi-scale features to predict the future operating status and potential risks of the digital power grid includes:

[0059] For each input sample Where T is the time step and C3 is the number of feature channels, the selective convolution branch extracts temporal features in parallel through dilated convolution kernels of different sizes. The formula for calculating the dilated convolution is:

[0060]

[0061] Where t is the time step, M×N is the kernel size, r is the dilation rate, w(i) is the kernel weight, and x(tr·i) is the input feature;

[0062] Selective convolution dynamically assigns weights to each branch through a global weighting mechanism, expressed as:

[0063] Wk =σ(W2·δ(W1·GAP(X)))

[0064] Where GAP(X) is global average pooling, W1 and W2 are weight matrices, σ is the Sigmoid activation function, and δ is the ReLU activation function;

[0065] Feature extraction is performed on the input historical situation value sequence using a selective temporal convolutional network, and future situation values ​​are predicted using causal relationships. The expression is as follows:

[0066]

[0067] Where N2 is the total number of samples in the selective temporal convolutional network;

[0068] The situation values ​​are divided into training and test sets according to time sequence and converted into T×C input format. The selective temporal convolutional network is trained using the training set, and the parameters are adjusted using the Adam optimization algorithm to minimize the error. The mean squared error is used as the training objective function, and its expression is:

[0069]

[0070] Among them, y i y^i and y^i represent the true value and the predicted value, respectively, and n2 is the total number of time series samples.

[0071] Another objective of this invention is to provide a digital power grid security situation awareness system based on selective convolutional networks. This system can collect multi-source heterogeneous data from the digital power grid in real time by deploying multiple sensors, extract multi-scale features using selective convolutional networks, and then use classification models and time series modeling techniques to judge the risk of power grid faults and predict the situation. This solves the technical defects of existing technologies, such as insufficient processing of multi-source heterogeneous data and limited dynamic perception and forward-looking early warning capabilities.

[0072] To address the aforementioned technical problems, this invention provides the following technical solution: a digital power grid security situation awareness system based on selective convolutional networks, comprising: a multi-dimensional heterogeneous data acquisition and preprocessing module, a multi-scale feature extraction module, a classification and risk assessment module, and a time series modeling and situation prediction module;

[0073] The multi-heterogeneous data acquisition and preprocessing module collects key data on the operation of the digital power grid by deploying sensors, transmits the data to the central processing unit, and performs cleaning, classification and format standardization processing to eliminate redundant information and extract core features related to the power grid security status.

[0074] The multi-scale feature extraction module uses a selective convolutional network to extract multi-dimensional features from preprocessed data through parallel processing of multi-scale convolutional kernels.

[0075] The classification and risk assessment module inputs multi-scale features into a secondary classification model to determine whether there is a fault risk, classifies specific fault types, and quantifies the risk value of the current power grid security status through state probability factors and attack impact factors.

[0076] The time series modeling and situation prediction module combines classification results and multi-scale features, and uses a time-domain convolutional network to construct a time series model to predict the future operating status and potential risks of the digital power grid.

[0077] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the digital power grid security situation awareness method based on selective convolutional networks as described above.

[0078] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the digital power grid security situation awareness method based on selective convolutional networks as described above.

[0079] The beneficial effects of this invention are as follows: By improving selective convolutional networks and selective temporal convolutional networks, this invention technically solves the problems of insufficient feature extraction capability of multi-source heterogeneous data, low classification accuracy caused by data imbalance, and limited temporal modeling capability. It achieves the effects of enhancing feature extraction accuracy, improving minority class sample recognition capability, optimizing complex temporal feature modeling and situation prediction accuracy, and significantly improving the efficiency and reliability of digital power grid security situation awareness and prediction. Attached Figure Description

[0080] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0081] Figure 1 A flowchart of the digital power grid security situation awareness method based on selective convolutional networks provided in the first embodiment of the present invention;

[0082] Figure 2 A selective convolutional network model diagram is shown in the digital power grid security situation awareness method based on selective convolutional networks provided in the first embodiment of the present invention.

[0083] Figure 3A diagram of a secondary classification combination model for a digital power grid security situation awareness method based on selective convolutional networks provided in the first embodiment of the present invention;

[0084] Figure 4 This is a schematic diagram of the SKTCN structure in the digital power grid security situation awareness method based on selective convolutional networks provided in the first embodiment of the present invention. Detailed Implementation

[0085] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0086] Example 1, referring to Figures 1-4 As one embodiment of the present invention, a digital power grid security situation awareness method based on selective convolutional networks is provided, comprising:

[0087] The data acquisition module in the digital power grid situational awareness model acquires real-time operational status information of power grid equipment through log data integration without modifying the physical structure or logical configuration of existing equipment, thus ensuring no impact on the normal operation of the power grid. The module aims to efficiently and reliably integrate operational log data while maintaining normal equipment operation, providing data support for subsequent deep learning model analysis. By deploying log collectors, configuring log transmission paths, and parsing and storing log information, the module achieves comprehensive awareness of the operational status of power grid equipment.

[0088] First, log collectors are deployed on key equipment and nodes of the digital power grid to collect log information generated during equipment operation. The collectors can communicate directly with the equipment through system log services (such as Syslog or event logs) to obtain detailed information in real time, including equipment operating status, fault alarms, and performance indicators. This collection process is transparent to the equipment operating environment, neither interfering with normal equipment operation nor increasing equipment load.

[0089] The collected log data is transmitted securely to the central processing unit for further processing. Encryption technology is used during transmission to ensure data integrity and security. In the central processing unit, the data first enters the parsing and filtering module, which is responsible for cleaning and classifying the log data, removing redundant information, and extracting core features related to the safety status of power grid equipment, such as records of abnormal equipment behavior and load information of power grid nodes. This extracted high-quality data is organized and stored, providing a solid data foundation for subsequent feature extraction and pattern analysis in deep learning models.

[0090] The log data integration module can effectively collect and process the operating status information of power grid equipment in a non-intrusive manner, providing accurate and real-time data support for the digital power grid situation awareness system, and ensuring the efficient operation and accurate analysis of the security situation awareness model.

[0091] In the model, the captured network traffic data needs to undergo a meticulous data preprocessing process to ensure that the data input into the Selective Kernel Network (SKNet) meets the model's format and quality requirements. The following are the detailed preprocessing steps, including numericalization, one-hot encoding, normalization, and dimensionality expansion.

[0092] Data quantification

[0093] Raw network traffic data typically includes discrete features (such as protocol type and flags) and continuous features (such as packet size and traffic rate). First, the discrete features are quantified, transforming them into a machine-processable numerical form.

[0094] For discrete feature X cat Construct a mapping function f(x) to map it to the set of certificate values:

[0095] X m =f(X) cat ), f = X cat ->{0,1,2,...,n-1}

[0096] Where n is the number of network protocol categories. For continuous features such as packet size, proceed directly to the next normalization operation without additional processing.

[0097] One-hot encoding

[0098] For discretized features in network traffic data (such as IP addresses, MAC addresses, network protocol types, etc.), one-hot encoding is used to convert different IP addresses or protocol types into binary vectors. As a commonly used encoding method in machine learning and data processing, it is mainly used to convert discrete data into numerical form so that it can be input into a model for training. In one-hot encoding, assuming a categorical variable X1 has k different categories, each category i corresponds to a category value X. i Where i∈{1,2,…,k}, for each value of the categorical variable X1, it is transformed into a k1-dimensional one-hot vector v. For a categorical variable X1=x i The expression for the one-hot encoded vector v is:

[0099]

[0100] Among them, v j This represents the value of the j-th element in vector v.

[0101] For continuous features in network traffic data (such as packet size, traffic length, time interval, etc.), appropriate preservation and normalization are performed. Furthermore, by using standardization or normalization methods, the value range of these features is scaled to a suitable range, reducing scale differences between features and enabling deep learning models to better learn the relationships between these features. The formula is as follows.

[0102]

[0103] Feature Dimension Expansion

[0104] The encoded discontinuous features are combined with the retained continuous features to form a complete feature vector, which serves as the input to the model. After formatting the preprocessed data, all features are integrated into a single feature vector of length 196. To meet the input requirements of the selective convolutional network, this one-dimensional vector is transformed into a 14×14 two-dimensional matrix using a reshape operation. The transformation formula is as follows:

[0105] X reshaped =reshape(X) processed ,(14,14))

[0106] Specifically, the process involves filling a 14×14 matrix with a feature vector of length 196 according to row priority, then calculating the normalized feature value corresponding to the value of each matrix element after preprocessing. The resulting matrix is ​​the grayscale image, with each value mapped to the grayscale range [0, 1].

[0107] Treat a 14×14 two-dimensional matrix as a grayscale image, where each element x in the matrix... i,jMapped to grayscale value G i,j The grayscale value range is [0, 255], and the final generated grayscale image will be used as the input to a selective convolutional network.

[0108] G i,j =x i,j ×255

[0109] By preprocessing network traffic data, the network traffic characteristics of the digital power grid are effectively encoded and preserved.

[0110] The main contents of building a cybersecurity situational awareness model based on Selective Convolutional Networks (SKNet) include the background and optimization details of the model design, the proposal of a secondary classification model and its theoretical support, and methods for quantifying and evaluating cybersecurity situational awareness. Through theoretical derivation, this system proposes an efficient cybersecurity situational awareness method for digital power grids based on traditional selective convolutional networks, significantly improving classification accuracy and robustness, especially demonstrating superior performance in handling imbalanced data.

[0111] Reference Figure 2 The design of the improved Selective Convolutional Network (SKNet) stems from the limitations of traditional Convolutional Neural Networks (CNNs) in cybersecurity situational awareness. The inherent fixed receptive field of CNN models prevents them from dynamically adjusting the feature extraction range based on the complexity and feature distribution of the input data, leading to the omission of some key patterns. Furthermore, the heterogeneity and high dimensionality of cybersecurity data place higher demands on traditional models. SKNet addresses these issues to some extent through dynamic receptive field and adaptive weight allocation, but it carries the risk of information loss during multi-branch feature fusion, and the original structure has relatively low training efficiency when processing cybersecurity data. Therefore, this system improves the selective convolutional units of SKNet, designs a more efficient feature branch fusion mechanism, and introduces a lightweight structure to adapt to the needs of cybersecurity situational awareness.

[0112] In the improved selective convolutional unit, multi-scale features of the input data are extracted in parallel using convolutional kernels of different scales. Let the input feature map be X2 with a size of H×W×C, and the input feature map U of each convolutional kernel be... k The calculation formula is:

[0113]

[0114] Among them, W k These are the weights of the k-th convolutional kernel, where M×N is the kernel size, and b kHere, is the bias parameter of the k-th convolutional kernel, i and j are the row and column indices of the feature map, k is the kernel index, m is the kernel row index, and n1 is the kernel column index. To reduce computational complexity, the convolutional kernel is further decomposed into multiple one-dimensional convolution operations, specifically:

[0115] U k =Conv(X,W k1 )*Conv(X,W k2 )

[0116] This operation significantly reduces the number of parameters and computational cost while preserving the feature extraction capability of the convolution kernel. To fuse the extracted multi-scale features, this system introduces a global average pooling operation, where each branch U... k Its global average pooling result S k The calculation is as follows:

[0117]

[0118] Weights W are generated using a two-layer fully connected network and an activation function. k The expression is:

[0119] W k =σ(W2·δ(W1·S) k ))

[0120] Where σ is the Sigmoid activation function, δ is the ReLU activation function, and W1 and W2 are the weight matrices of the fully connected layer;

[0121] Weight W k Branch feature map U corresponding to the action k And perform weighted fusion, the expression is:

[0122]

[0123] Here, V1 is a weighted integration of multi-scale features, and K is the total number of convolution kernels.

[0124] The output feature V1 is a weighted integration of multi-scale features, which can more comprehensively capture the feature correlations of the input data.

[0125] To address the issue of extremely imbalanced distribution of attack types in network security datasets, refer to Figure 3This system proposes a quadratic classification model. Traditional single-stage classification methods struggle to effectively handle the problem of a high proportion of normal samples, often resulting in low recall rates for minority attack samples and impacting overall performance. The quadratic classification model decomposes the classification task into two steps: attack identification and attack classification. The attack identification model determines whether an input sample is an attack sample, reducing interference from normal samples in attack classification; the attack classification model further refines the selected attack samples to determine the specific attack type.

[0126] Let the input dataset be D = {(x i ,y i )}, where x i Represents the input features, y i Indicates the label, y i ∈{0, 1, ..., C1};

[0127] Construct an attack identification model, expressed as:

[0128] F1(x) = Sigmoid(W attack ·x+b)

[0129] Among them, W attack is the classification weight, x is the multi-scale feature extracted by the selective convolutional network, and b is the bias parameter of the quadratic classification model;

[0130] The output F1(x) represents the probability that sample x belongs to the attack class. A new dataset D is constructed for attack samples whose predicted probability F1(x) > 0.5. attack ={(x i ,y i )|y i ≠0};

[0131] Construct an attack classification model, with the following expression:

[0132] F2(x)=Softmax(W class ·x+b)

[0133] Where F2(x) is the probability distribution of the attack sample belonging to each attack type, and W class This is the attack classification weight matrix.

[0134] The input F2(x) represents the probability distribution of the attack sample belonging to each attack type. Ultimately, a two-stage processing method improves the recognition accuracy of minority class samples.

[0135] In terms of quantifying and assessing network security posture, this system constructs a posture value calculation model using state probability factors and attack impact factors. State probability factor P iThe probability of type i attack occurring within the current time period is expressed by the formula:

[0136]

[0137] Where, n i The number of attack samples of type i is obtained by classifying digital power grid traffic using the classification model F2(x), and N1 is the total number of samples in the situation value calculation model.

[0138] Attack Impact Factor E i Assess the impact of type i attacks on confidentiality, integrity, and availability:

[0139] E i =C i +I i +A i

[0140] Among them, C i I i A i These represent the degree of threat to confidentiality, integrity, and availability, respectively. Confidentiality (C) i It can be represented as:

[0141]

[0142] Among them, l i l represents the amount of sensitive data leaked due to the i-th type of attack, such as the number of bytes and the number of words. t This represents the total amount of sensitive data related to the power grid within the current time period. Integrity I i It can be represented as:

[0143]

[0144] Among them, T i T represents the number of data tampering events caused by the i-th type of attack, such as packet checksum errors or file modification counts. t This indicates the total number of data transmission events within the current time period, such as the total number of data packets. Availability A i It can be represented as:

[0145]

[0146] Among them, U i U represents the percentage of effective service time or traffic caused by the i-th type of attack, such as the number of normal requests processed. t This indicates the percentage of total service time or traffic to be processed, such as the planned total number of requests. The final status value is calculated as follows:

[0147]

[0148] Where C2 represents the number of network attack states, and P i E represents the probability of the i-th type of attack occurring within the current time period. i This is an attack influencing factor.

[0149] Model testing shows that our system's model outperforms traditional models in traffic classification, especially in handling imbalanced data. The improved SKNet model and secondary classification strategy demonstrate higher accuracy, robustness, and efficiency when processing complex cybersecurity data.

[0150] Compared to Long Short-Term Memory (LSTM) neural networks, temporal convolutional neural networks (TCNNs) offer advantages such as parallelism, flexible receptive fields, and stable gradients, resulting in shorter training times and higher accuracy when dealing with time-series problems. However, due to the complex and rapidly changing nature of cybersecurity situations, the residual connections in TCNNs, which fuse original time-series data with feature data, may lead to significant time delays or low prediction accuracy. To address this prediction delay issue in cybersecurity situational awareness using TCNNs, this system integrates the concept of selective convolutional networks (SCNNs) and designs a selective temporal convolutional residual block (SKResidual Block), enabling it to perform better in the field of cybersecurity situational awareness for digital power grids.

[0151] Reference Figure 4 In the design of Selective Temporal Convolutional Network (SKTCN), the advantages of Selective Convolutional Network (SKNet) and Temporal Convolutional Network (TCN) are combined to propose Selective Temporal Convolutional Residual Blocks. This network structure can effectively extract temporal features from cybersecurity data through dynamic receptive fields, while maintaining high parallelism and model stability. In SKTCN, the residual block is the basic unit, and its core is to model multi-scale temporal features through selective convolutional branches and causal dilated convolutional branches.

[0152] For each input sample X∈R T×C Where T is the time step and C is the number of feature channels, the selective convolution branch extracts temporal features in parallel using dilated convolution kernels of different sizes. The formula for calculating the dilated convolution is:

[0153]

[0154] Where t is the time step, M×N is the kernel size, r is the dilation rate, w(i) is the kernel weight, and x(tr·i) is the input feature.

[0155] Dilated convolutions can reduce computation while maintaining a large receptive field, extracting multi-scale temporal patterns through combinations of different dilation rates. Selective convolutions dynamically assign weights to each branch through a global weighting mechanism to enhance the expressive power of key features. The formula for calculating the weights is:

[0156] W k =σ(W2·δ(W1·GAP(X)))

[0157] Where GAP(X) is global average pooling, W1 and W2 are weight matrices, σ is the Sigmoid activation function, and δ is the ReLU activation function. Through the above calculations, the weight matrix W... k The feature maps from each branch are used for weighted convolution output and then fused together to generate a unified temporal feature representation.

[0158] In the process of cybersecurity situation prediction, the first step is to extract features from the input historical situation value sequence using a selective temporal convolutional network, and then use causal relationships to predict future situation values. The specific prediction steps are as follows:

[0159] First, the situation value is calculated and the dataset is constructed. Based on the situation quantification index defined above, the current digital power grid situation value V3 is calculated using the following formula:

[0160]

[0161] Where N2 is the total number of samples in the selective temporal convolutional network.

[0162] SKTCN is trained using the training set, and the model's parameters are adjusted using the Adam optimization algorithm to minimize the error. The training objective function uses mean squared error (MSE).

[0163]

[0164] Among them, y i y^i and y^i represent the true value and predicted value, respectively, and n2 is the total number of time-series samples. Finally, the test set is input into the trained model to generate a sequence of predicted values, which is then compared with the true values.

[0165] It should be further explained that:

[0166] V2 is the classification model, C is the total number of attack types, and pi and ei are the data statistics based on different attack types.

[0167] V3 is a regression prediction model, where N is the total number of time series samples, and pi and ei are the data trends based on the time window.

[0168] The two models take different inputs: one is attack traffic data, and the other is the attack traffic time series situation value. They correspond to classifiers for attack sample identification and classification, and the SKTCN time series prediction model, respectively.

[0169] Use V1 as input to V2, and then use several V2 values ​​as input to V3 for calculation.

[0170] It should be further explained that:

[0171] The situational awareness system created by this invention differs significantly from the structure of similar products mentioned above, mainly in the breadth and depth of information collection, the dynamism and efficiency of data fusion, and the intelligence and predictive capabilities of situational awareness.

[0172] First, at the information acquisition layer, the system of this invention not only relies on traditional log sensors but also integrates multiple data sources, including environmental monitoring data, equipment behavior logs, user load data, and external network threat intelligence. This integration of multi-source data makes the acquisition scope more comprehensive and can more accurately reflect the overall operation of the digital power grid. Furthermore, this system introduces a real-time data verification and repair mechanism during the acquisition process. By verifying data while acquiring it, the impact of data noise and missing data is effectively reduced, improving data quality from the source. In contrast, similar products rely more on a single data source, resulting in narrower data coverage and greater quality fluctuations, failing to provide comprehensive and reliable basic data for situational awareness.

[0173] Secondly, in the multi-source data fusion layer, the system of this invention achieves dynamic feature extraction from multi-source heterogeneous data by introducing a Selective Kernel Network (SKNet). SKNet can dynamically adjust its receptive field according to the characteristics of the input data, extracting multi-scale features. Especially in high-dimensional, unstructured data processing, it can better capture key patterns and spatiotemporal correlations. This dynamic feature extraction capability is significantly superior to feature extraction methods based on fixed rules or static models in similar products. This system also improves the efficiency of data fusion through distributed computing technology, overcoming the performance bottleneck of traditional systems in large-scale data processing.

[0174] The most significant difference lies in the situational awareness layer. This invention's system, based on traditional deep neural networks, integrates Selective Convolutional Networks (SKNet) and Selective Temporal Convolutional Networks (SKTCN), achieving refined feature extraction and trend prediction of power grid data through dynamic receptive fields. In particular, by modeling temporal features using SKTCN, this system can not only accurately assess the current situation but also predict future trends, realizing a shift from passive defense to proactive early warning. In contrast, the situational awareness function of similar products is typically limited to assessing the current state, lacking the ability to proactively predict future risks. Furthermore, this system designs a secondary classification model, first identifying faults and then further classifying specific fault types, significantly mitigating the impact of power grid data imbalance on model training. In contrast, many similar products employ single-stage classification models, which can easily lead to low recognition rates for a few fault types.

[0175] Finally, regarding system robustness, this invention significantly improves the system's stability when facing abnormal or noisy data by introducing residual structures and noise filtering mechanisms. Combined with an attention-based data weighting strategy, this system can still maintain high evaluation and prediction accuracy even with incomplete or low-quality data. In contrast, similar products are prone to significant performance degradation when dealing with abnormal data.

[0176] In summary, the situational awareness system created by this invention has significant advantages over similar products in terms of the comprehensiveness of information collection, the dynamism and efficiency of data fusion, as well as the intelligence, robustness and predictive ability of situational awareness, and can more comprehensively meet the needs of digital power grid security management.

[0177] Example 2, an embodiment of the present invention, provides a system for a digital power grid security situation awareness method based on selective convolutional networks, including: a multi-heterogeneous data acquisition and preprocessing module, a multi-scale feature extraction module, a classification and risk assessment module, and a time series modeling and situation prediction module;

[0178] The multi-heterogeneous data acquisition and preprocessing module collects key data on the operation of the digital power grid by deploying sensors, transmits the data to the central processing unit, and performs cleaning, classification and format standardization processing to eliminate redundant information and extract core features related to the power grid security status.

[0179] The multi-scale feature extraction module uses a selective convolutional network to extract multi-dimensional features from preprocessed data through parallel processing of multi-scale convolutional kernels.

[0180] The classification and risk assessment module inputs multi-scale features into a secondary classification model to determine whether there is a fault risk, classifies specific fault types, and quantifies the risk value of the current power grid security status through state probability factors and attack impact factors.

[0181] The time series modeling and situation prediction module combines classification results and multi-scale features, and uses a time-domain convolutional network to construct a time series model to predict the future operating status and potential risks of the digital power grid.

[0182] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0183] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0184] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0185] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0186] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A digital power grid security situation awareness method based on a selective convolutional network, characterized in that, The method comprises the following steps: Collecting multi-element heterogeneous data of digital power grid operation using sensors for preprocessing; Using a selective convolutional network to extract multi-scale features from the preprocessed data; Inputting the extracted multi-scale features into a secondary classification model for fault risk judgment and classification; Combining a time domain convolutional network to model the classification results and multi-scale features in time series, and predicting the future operation trend and potential risks of the digital power grid; The step of inputting the extracted multi-scale features into a secondary classification model for fault risk judgment and classification comprises the following steps: Let the input dataset be D = {(x i ,y i )} where x i represents input features, y i represents labels, y i ∈ {0, 1,..., C1}; Constructing an attack recognition model, and the expression is as follows: F1(x) = Sigmoid(W attack ·x + b) wherein W attack is a classification weight, x is a multi-scale feature extracted by a selective convolution network, and b is a bias parameter of the quadratic classification model. The output F1(x) represents the probability that the sample x belongs to the attack class, and the samples whose predicted probability F1(x) > 0.5 for the attack samples are used to construct a new data set D attack = {(x i ,y i )|y i ≠ 0} ; Building an attack classification model, and the expression is as follows: F2(x) = Softmax(W class • x + b) where F2(x) is the probability distribution of the attack sample belonging to each attack type, W class is the attack classification weight matrix; The step of inputting the extracted multi-scale features into a secondary classification model for fault risk judgment and classification further comprises the following steps: A situation value calculation model is constructed by state probability factor and attack influence factor, and the state probability factor P i represents the occurrence probability of the i-th type of attack in the current time period, and its formula is: wherein n i is the number of the ith attack sample, and N1 is the total number of samples of the situation value calculation model. Attack impact factor E i The expression for assessing the impact of an attack of class i on confidentiality, integrity and availability is: E i = C i + I i + A i wherein, C i , I i , A i respectively represent the threat degree to confidentiality, integrity and availability, l i represents the amount of sensitive data leaked by the i-th attack, T i represents the number of data tampering events caused by the i-th attack, T t represents the total number of data transmission events in the current time period, U i represents the proportion of effective service time or traffic caused by the i-th attack, U t represents the total proportion of service time or traffic to be handled, l t is the total amount of sensitive data of the power grid in the current time period; The final trend value expression is as follows: wherein C2 is the number of network attack state categories, P i represents the occurrence probability of the ith attack in the current time period, E i is the attack impact factor.

2. The selective convolution network based digital power grid security situation awareness method of claim 1, wherein: The step of collecting multi-element heterogeneous data of digital power grid operation using sensors comprises the following steps: Deploying log collectors on key devices and nodes of the digital power grid to collect log information generated during device operation, and the collectors communicate with the devices through a system log service to obtain device operation status, fault alarms, and performance index details in real time; The collected log data is sent to a central processing unit for processing through a secure transmission path, and encryption technology is used during the transmission process.

3. The selective convolution network based digital power grid security situation awareness method of claim 2, wherein: The preprocessing is performed in the central processing unit, and the data first enters an analysis and filtering module to clean and classify the log data, remove redundant information, and extract core features related to the safety trend of the power grid equipment, and the extracted features are arranged and stored; The collected multi-element heterogeneous data exists in the form of network traffic, including discrete features and continuous features, the discrete features are numerically valued, and the expression is as follows: X m = f(X cat ), f = X cat ->{0, 1, 2,..., n-1} where n is the number of network protocol categories, X cat is a set of discrete features, f(x) is a mapping function, X m is a set of certificate values; For the discrete features in the network traffic data, different IP addresses or protocol types are converted into binary vectors using one-hot encoding; In one-hot encoding, suppose a categorical variable X1 has k different categories, each category i corresponds to a category value X i , where i ∈ {1, 2, …, k}, for each value of the categorical variable X1, it is converted to a k1-dimensional one-hot vector v, for a categorical variable X1 = x i , the one-hot encoding vector v is expressed as: where v j denotes the value of the jth element in the vector v; For the continuous features in the network traffic data, standardization or normalization methods are used to scale the feature value range to a suitable range, reducing the scale difference between features.

4. The selective convolution network based digital power grid security situation awareness method of claim 3, wherein: The step of using a selective convolutional network to extract multi-scale features from the preprocessed data comprises the following steps: In the improved selective convolution unit, multi-scale features of input data are extracted in parallel through convolution kernels of different scales. Assuming that an input feature map is X2, the size of which is HxWxC, the input feature map U of each convolution kernel is k The calculation formula is as follows: wherein W k is the weight of the kth convolution kernel, MxN is the size of the convolution kernel, b k is the bias parameter of the kth convolution kernel, i, j are the row and column indexes of the feature map respectively, k is the convolution kernel index, m is the convolution kernel row index, and n1 is the convolution kernel column index. A global average pooling operation is introduced, for each branch U k The global average pooling result S k The expression is: The weights W are generated by a two-layer fully connected network and an activation function k with the expression: W k = σ(W2·δ(W1·S k )) Wherein, σ is the Sigmoid activation function, δ is the ReLU activation function, and W1 and W2 are the weight matrices of the full connection layer; The weight W k The corresponding branch feature map U k And weighted fusion, expression is: Wherein, V1 is the weighted integration of multi-scale features, and K is the total number of convolution kernels.

5. The selective convolutional network-based digital electric grid security situation awareness method of claim 4, wherein: The step of combining a time domain convolutional network to model the classification results and multi-scale features in time series, and predicting the future operation trend and potential risks of the digital power grid comprises the following steps: For each input sample where T is the time step, C3 is the number of feature channels, and the selective convolution branch extracts the timing features in parallel through different sizes of dilated convolution kernels. The calculation formula of dilated convolution is: Wherein, t is the time step, M×N is the convolution kernel size, r is the dilation rate, w(i) is the convolution kernel weight, and x(t-r·i) is the input feature; The selective convolution dynamically allocates weights to each branch through a global weighting mechanism, and the expression is as follows: W k = σ(W2·δ(W1·GAP(X))) Wherein, GAP(X) is the global average pooling, W1 and W2 are the weight matrices, σ is the Sigmoid activation function, and δ is the ReLU activation function; The selective time domain convolutional network extracts features from the input historical trend value sequence, and predicts future trend values using causal relationships, and the expression is as follows: Wherein, N2 is the total number of selective time domain convolutional network samples; The trend values are divided into training set and test set in time sequence, and are converted into input format of TxC. The selective time domain convolution network is trained by training set, and the parameters are adjusted by Adam optimization algorithm to minimize the error. The training objective function adopts mean square error, and the expression is: where y i and y^i represent the true and predicted values, respectively, and n2 is the total number of time series samples.

6. A system employing the digital power grid security situation awareness method based on the selective convolutional network according to any one of claims 1 to 5, characterized in that: The method comprises a multi-element heterogeneous data acquisition and preprocessing module, a multi-scale feature extraction module, a classification and risk assessment module, a time series modeling and trend prediction module. The multi-element heterogeneous data acquisition and preprocessing module collects key data of digital power grid operation through deployment of sensors, transmits the data to a central processing unit, performs cleaning, classification and format standardization processing, eliminates redundant information, and extracts core features related to power grid security situation; The multi-scale feature extraction module extracts multi-dimensional features from preprocessed data by using a selective convolution network through a multi-scale convolution kernel parallel processing mode; The classification and risk assessment module inputs the multi-scale features into a secondary classification model, judges whether there is a fault risk, classifies specific fault types, and quantifies the risk value of the current power grid security situation through state probability factors and attack influence factors; The time series modeling and trend prediction module combines the classification results and multi-scale features, uses a time domain convolution network to construct a time series model, and predicts the future operation trend and potential risk of the digital power grid. 7.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-6 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the selective convolution network-based digital power grid security situation awareness method in any one of claims 1 to 5.

8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the selective convolution network-based digital power grid security situation awareness method in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Real-time flow detection method based on network situation awareness

    CN115811440A

  • Smart power grid security situation assessment method and system

    CN118536875A