A method, system and device for latent attack identification for active power distribution networks and storage medium

By constructing a synchronous detection signal and time series method, a dynamic identification index of latent attacks is generated, which solves the problem of identifying latent attacks caused by false information injection in active distribution networks and ensures the security and stability of the system.

CN119788371BActive Publication Date: 2025-10-10CHONGQING UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411914095.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-10-10
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

The existing technology cannot effectively identify latent attacks by injecting false information into active distribution networks, making it difficult to ensure the security of cyber-physical systems.

Method used

By constructing synchronous detection signals and their time series, dynamic identification indicators of latent attacks are generated, false information injection into latent attacks is located and attack signals are identified, and signal analysis is performed using data acquisition modules, calculation modules and comparison modules.

Benefits of technology

It achieves effective positioning and identification of latent attacks of false information injection, ensures the safe and stable operation of the cyber-physical system of the active distribution network, and provides a basis for defense measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788371B_ABST
    Figure CN119788371B_ABST
Patent Text Reader

Abstract

The present application belongs to the field of power information physical system, and relates to a kind of latent attack identification method, system, device and storage medium for active distribution network, comprising: real-time acquisition distributed cluster control distribution network information physical system in distributed power cluster Real-time output active power of each distributed power;The output power ratio of each distributed power is calculated;Synchronous detection signal and its time sequence of each slave type distributed power in distributed cluster are generated;False information injection latent attack dynamic identification index is calculated;False information injection latent attack dynamic identification index is used to locate slave type distributed power suffering from false information injection latent attack;According to the time sequence of synchronous detection signal, the size of latent attack signal is calculated.The present application can accurately identify the distributed power cluster suffering from false information injection latent attack in active distribution network information physical system and specific attack signal, so as to facilitate cluster manager to eliminate potential security loopholes in cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power cyber-physical systems, and specifically relates to a method, system, device and storage medium for identifying latent attacks in active power distribution networks. Background Art

[0002] The proportion of distributed power sources, represented by wind power and photovoltaics, continues to rise, and active distribution networks are developing rapidly. Simultaneously, cyber-physical systems (CPSs) are being developed in the power sector. These CPSs, based on the data transmission requirements and collaborative functional objectives of a control center, communication network, control terminal, and physical network, utilize interactive devices such as gateways and switches to implement data protocol conversion and meet data transmission security requirements via communication carriers such as optical fiber and Ethernet. CPSs enable control centers to observe grid status in real time and effectively issue control commands. However, the deep cyber-physical coupling of CPSs provides attackers with avenues to disrupt the normal operation of distribution networks through cyberattacks. Cyberattacks targeting active distribution networks could cause control failures of distributed power sources, thereby compromising the security of the active distribution network.

[0003] Depending on the communication network architecture of the cyber-physical system, control modes for distributed power generation in active distribution networks include centralized and decentralized control. Centralized control, with its one-to-many nature, is susceptible to interference and suffers from low reliability. Decentralized control, employing a one-to-one model, allows for individual control via dedicated controllers, but struggles to achieve coordinated optimization across multiple controlled objects. Therefore, distributed cluster control has emerged. Distributed cluster control, through coordinated control of active distribution network clusters, enables regionalized management of adjacent active distribution networks and reduces the deployment of communication links. However, while existing communication channels connecting distribution network terminals to control centers are equipped with firewalls and visitor authentication mechanisms, and encryption is added to the transmission and interaction protocols for service messages, the wireless private network architecture between the access layer and the terminal layer of the distribution network's cyber-physical system still provides a gateway for cyberattacks. Attackers can tamper with the electrical quantity data from the monitoring system and inject false information into the distributed cluster control, disrupting the normal operation of the active distribution network.

[0004] False information injection attacks can either immediately invade cyber systems and paralyze physical systems, or covertly invade cyber systems to seize control of physical systems. Depending on the intent, false information injection attacks can be divided into a latent attack phase and a destructive attack phase. A latent attack injects attack signals into a cyber-physical system without disrupting its normal operation. After a successful latent attack, a destructive attack modifies the attack signals lurking in the cyber-physical system to disrupt the achievement of control objectives. In distributed cluster-controlled active distribution networks, attackers often first use a latent attack to invade the cyber-physical system and then use a destructive attack to disable control. Therefore, identifying latent false information injection attacks is key to preventing further damage to active distribution networks.

[0005] Current research on false information injection attacks in active power distribution networks primarily focuses on pre-emptive attack and defense, as well as post-incident isolation, with limited research on latent attacks. Some experts have analyzed the characteristics of false information injection attacks against different targets from the attacker's perspective, but have not distinguished between latent and destructive attacks. Some have proposed an attack-defense strategy for power cyber-physical systems under false information injection attacks, but have not analyzed the cross-domain propagation of false information injection attacks. Others have summarized false information injection attack detection and defense methods from both the information and physical sides of power cyber-physical systems, but these methods all rely heavily on communications.

[0006] In summary, the current research on latent attacks of false information injection into active distribution networks is still in its infancy. The information-physical interaction characteristics of the cyber-physical system of active distribution networks under latent attacks are still unclear. There is currently no feasible technical solution for effectively identifying latent attacks of false information injection into distributed cluster-controlled active distribution networks. Summary of the Invention

[0007] In response to the above-mentioned deficiencies in the prior art, the present invention provides a method, device and equipment for identifying latent attacks caused by false information injection in active distribution networks, which can solve the problem in the prior art that latent attacks caused by false information injection in distributed cluster-controlled active distribution networks cannot be effectively identified. By constructing a synchronous detection signal and its time series, a dynamic identification index for latent attacks is generated, which can effectively locate latent attacks caused by false information injection and reliably identify attack signals.

[0008] To achieve the above objectives, the present invention provides a method for identifying latent attacks in an active power distribution network, the method comprising:

[0009] S101, collecting real-time output active power of each distributed power source in the distributed power source cluster, and calculating the output power ratio of each distributed power source; the distributed power sources in the distributed power source cluster include master-controlled distributed power sources and slave-controlled distributed power sources;

[0010] S102, calculating the synchronization detection signal of the slave-controlled distributed power source in the distributed power source cluster according to the output power ratio, and constructing a discrete sequence of the synchronization detection signal at time 1;

[0011] S103, calculating a dynamic identification index of a false information injection latent attack based on a discrete sequence of synchronous detection signals;

[0012] S104, setting a positioning criterion. If the dynamic identification index of the false information injection latent attack meets the positioning criterion, execute step S105; otherwise, set l=l+1 and return to step S103;

[0013] S105. Locate the slave-controlled distributed power source that is potentially attacked;

[0014] S106. Calculate the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply that is under potential attack;

[0015] S107. Set a threshold. If the correlation coefficient of the discrete sequence of the synchronous detection signal is greater than the threshold, identify the false information injection latent attack signal and complete the false information injection latent attack identification; otherwise, set l=l+1, regenerate the discrete time sequence of the synchronous detection signal of the slave-controlled distributed power supply that is subject to the latent attack, and return to step S106.

[0016] A latent attack identification system for an active power distribution network, the system comprising: a data acquisition module, a first calculation module, a second calculation module, a third calculation module, a fourth calculation module, a fifth calculation module, a first comparison module, and a second comparison module;

[0017] The data acquisition module is used to collect the real-time output active power of each distributed power source in the distributed power source cluster of the distributed cluster control distribution network;

[0018] The first calculation module calculates the output power ratio of each distributed power source according to the active power collected by the data collection module;

[0019] The second calculation module is used to calculate the synchronous detection signal of the slave-controlled distributed power supply and the discrete time series at time l;

[0020] The third calculation module calculates the dynamic identification index of false information injection latent attack based on the discrete time series;

[0021] The first comparison module is used to compare the latent attack dynamic identification index with a threshold value, and if the latent attack dynamic identification index is reliably greater than the threshold value, the fourth calculation module is called, otherwise the third calculation module is called;

[0022] The fourth calculation module is used to calculate the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply that is subject to a latent attack;

[0023] The second comparison module is used to compare the correlation coefficient of the discrete sequence of synchronous detection signals with the threshold value, and if the correlation coefficient of the discrete sequence of synchronous detection signals is greater than the threshold value, the fifth calculation module is called, otherwise the fourth calculation module is called;

[0024] The fifth calculation module is used to identify false information injection latent attack signals.

[0025] To achieve the above objectives, the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the above-mentioned latent attack identification methods for an active power distribution network.

[0026] To achieve the above-mentioned objectives, the present invention also provides a latent attack identification device for an active distribution network, comprising a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory and is used to execute the computer program stored in the memory, so that the latent attack identification device for an active distribution network performs any of the above-mentioned latent attack identification methods for an active distribution network.

[0027] Beneficial effects of the present invention:

[0028] The present invention establishes a synchronous detection signal model and a latent attack dynamic identification model, and proposes a false information injection latent attack positioning and attack signal identification method based on the synchronous detection signal dynamic identification, realizing the distributed dynamic identification of false information injection latent attacks, which facilitates cluster managers to carry out subsequent defense measures to eliminate potential security vulnerabilities in the cluster and prevent attackers from taking further measures to destroy the safe and stable operation of the active distribution network information-physical system by relying on latent attack signals. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0030] Figure 1 This is a flow chart of the method for identifying latent attacks caused by false information injection in active power distribution networks of this application;

[0031] Figure 2 This is a schematic diagram of the 10kV distributed cluster control distribution network structure in an embodiment of the present application;

[0032] Figure 3A waveform diagram of output characteristics of a distributed power supply cluster in a normal operation in an embodiment of the present application;

[0033] Figure 4 A waveform diagram of output characteristics of a distributed power supply cluster in a false information injection latent attack in an embodiment of the present application;

[0034] Figure 5 A schematic diagram of a latent attack dynamic identification index calculation result in an embodiment of the present application;

[0035] Figure 6 A block diagram of a false information injection latent attack identification system of an active power distribution network in an embodiment of the present application. DETAILED DESCRIPTION

[0036] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0037] The present application discloses a false information injection latent attack identification method of an active power distribution network. The method is applied to a computer device and equipment, such as a terminal or a server. The method collects real-time output active power of each distributed power supply in a distributed cluster control power distribution network information physical system distributed power supply cluster; calculates output power ratio of each distributed power supply; generates a synchronous detection signal of each slave distributed power supply in the distributed cluster and a time sequence thereof; calculates a false information injection latent attack dynamic identification index; locates a slave distributed power supply suffering from a false information injection latent attack by using the false information injection latent attack dynamic identification index; and calculates a latent attack signal size according to the time sequence of the synchronous detection signal.

[0038] A latent attack identification method for an active power distribution network, as shown in Figure 1 the method comprises:

[0039] S101, collecting real-time output active power of each distributed power supply in a distributed power supply cluster, and calculating output power ratio of each distributed power supply; the distributed power supplies in the distributed power supply cluster include master distributed power supplies and slave distributed power supplies;

[0040] S102, calculating a synchronous detection signal of a slave distributed power supply in the distributed power supply cluster according to the output power ratio, and constructing a discrete sequence of the synchronous detection signal at time l;

[0041] S103, calculating a false information injection latent attack dynamic identification index according to the discrete sequence of the synchronous detection signal;

[0042] S104, setting a positioning criterion. If the dynamic identification index of the false information injection latent attack meets the positioning criterion, execute step S105; otherwise, set l=l+1 and return to step S103;

[0043] S105. Locate the slave-controlled distributed power source that is potentially attacked;

[0044] S106. Calculate the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply that is under potential attack;

[0045] S107. Set a threshold. If the correlation coefficient of the discrete sequence of the synchronous detection signal is greater than the threshold, identify the false information injection latent attack signal and complete the false information injection latent attack identification; otherwise, set l=l+1, regenerate the discrete time sequence of the synchronous detection signal of the slave-controlled distributed power supply that is subject to the latent attack, and return to step S106.

[0046] In this embodiment, the output power ratio of the distributed power source is the ratio of the active power output by the distributed power source to the maximum allowable output power of the distributed power source. Its expression is:

[0047]

[0048] Where i = 1, 2, ..., n, n is the number of distributed generation in the cluster; is the active power output by the i-th distributed power source; is the maximum allowable output power of the i-th distributed power source.

[0049] In this specific implementation, the distributed cluster control distribution network is divided into master-controlled distributed power supplies and slave-controlled distributed power supplies. The master-controlled distributed power supply is the only one in the cluster and directly receives control instructions from the distribution network control center. That is, the master-controlled distributed power supply corresponds to the information node as the central information node of the cyber-physical system and has more defense resources deployed. Therefore, false information injection attacks often target slave-controlled distributed power supplies with weaker defense deployments. The slave-controlled distributed power supplies directly or indirectly interact with the master-controlled distributed power supply. The synchronous detection signal x of the jth slave-controlled distributed power supply at time l is j (l) is generated as follows:

[0050]

[0051] Among them, x j (l) represents the synchronous detection signal generated by the jth slave-controlled distributed power supply at time l; - is the parent distributed power supply number of the jth slave-controlled distributed power supply; represents the communication coupling gain parameter between the jth slave-controlled distributed power source and its upper-level distributed power source; is the output power ratio of the jth slave-controlled distributed power source at time l; is the output power ratio of the jth slave-controlled distributed power source at time l-1; is the output power ratio of the jth slave-controlled upper distributed power source at time l-1.

[0052] In this specific embodiment, the discrete time sequence X of the synchronous detection signal of the jth slave-controlled distributed power supply at time l is j (l) is constructed as follows:

[0053] X j (l)={x j (l-m+1),x j (l-m+2),…,x j (l-m+p),…,x j (l)}

[0054] Among them, x j (l-m+p) is the pth element in the time series, 1≤p≤m; m is the number of elements in the time series. In order to ensure that the calculation period of the discrete sequence of synchronous detection signals is greater than the duration period of the information disturbance, m is set to 10-12.

[0055] In this specific implementation, the jth slave-controlled distributed power supply at time l injects false information into the latent attack dynamic identification index FQ j (l) Calculate as follows:

[0056] FQ j (l) = β j d(X j (l), 0)

[0057] Among them, β j is the adjustment coefficient, β j >0;d(X j (l), 0) is the discrete sequence X of synchronous detection signal j (l) The minimum cumulative difference distance from the zero sequence is calculated as follows:

[0058]

[0059] Among them, min{x j (l-m+p),x j (l-m+p+1)} is X j The minimum value between the pth element and the p+1th element in (l).

[0060] In this specific embodiment, a positioning criterion for a latent attack caused by false information injection is set. The positioning criterion includes a reliability coefficient. The reliability coefficient is set in such a way as to ensure that the dynamic identification index of the latent attack caused by false information injection is reliably greater than a threshold value. The reliability coefficient is set to a value of 1.2 to 1.3. The positioning criterion is:

[0061] FQ j (l)>K rel FQ th

[0062] Among them, K rel is the reliability coefficient; FQ th The threshold value is set according to the dynamic identification index of the maximum potential attack that may be generated by other slave-controlled distributed power sources under information disturbance:

[0063]

[0064] Among them, Ω j FQ is a slave-controlled distributed power supply collection; j,max It represents the maximum potential attack dynamic identification index that may be generated by the j-th slave-controlled distributed power supply under information disturbance, and is calculated according to the maximum output power ratio deviation under 5 consecutive cycles.

[0065] In this specific embodiment, the discrete sequence correlation coefficient r of the synchronous detection signal of the slave-controlled distributed power supply subjected to the latent attack j (l) Calculate as follows:

[0066]

[0067] Among them, r j (l) represents the time series correlation coefficient of the synchronous detection signal at time l and the previous time, r j (l) between 0 and 1; x l-1,j (p), x l,j (p) is the discrete sequence X of synchronous detection signals of the jth slave-controlled distributed power supply at time l-1 and l, which is latently attacked by false information injection. j (l-1), X j (l) in the elements.

[0068] In this specific implementation, the threshold value r th,j For X j (l-1) contains m-1 non-zero elements, X j (1) The correlation coefficient of the discrete sequence of synchronous detection signals calculated when all elements are non-zero is calculated as follows:

[0069]

[0070] In this specific implementation, the false information injection latent attack signal on the jth slave-controlled distributed power supply is calculated as follows:

[0071]

[0072] To verify the effectiveness of the method of the present invention, the schematic diagram of the 10kV distributed cluster control distribution network is shown in the figure below: Figure 2 shown. Figure 2 In the example, distributed generation (DGs) are connected at nodes 822, 828, 832, 838, and 848, respectively. DGs 1-5 employ a distributed cluster control strategy, outputting power to the distribution network as a controllable entity. DG 1 is a master-controlled DG with a maximum allowable output power of 6 MW; DGs 2 and 3 are first-level slave-controlled DGs, each with a maximum allowable output power of 4 MW; DGs 4 and 5 are second-level slave-controlled DGs, each with a maximum allowable output power of 3 MW. All loads adopt a constant power model, with an active power of 0.6 MW. The threshold value for the correlation coefficient of the synchronous detection signal time series is 0.99.

[0073] In this specific implementation, the power command value of the distributed power cluster is set to 3.5MW and is modified to 6.5MW at t=1.5s. The attack target is set to the output power ratio of distributed power 3, and an attack signal of 0.2 is injected at t=0.8s. The attack signal persists. The output power of the distributed power in the cluster and its power under normal operation and false information injection latent attack are as follows: Figure 3 and Figure 4 shown.

[0074] In this specific embodiment, Figure 3 As shown in (a) and (b), at t = 0.51s, the output power of the distributed generation cluster tracks the power command value of 3.5MW, and the output power ratio of each distributed generation converges to 0.325. When the power command value switches from 3.5MW to 6.5MW, the output power of the distributed generation cluster quickly tracks the command value, and the output power ratio of each distributed generation converges to 0.475. The active distribution network under the control of the distributed cluster can deliver a certain amount of power according to the control command.

[0075] In this specific embodiment, Figure 4 As shown in (a), at t = 0.8s, the output power of the distributed power cluster fluctuates. Under different power command values, the output power of the distributed power cluster achieves tracking command values ​​at t = 1.15s and 2.04s respectively. Figure 4In (b), the output power ratio of distributed power supply 3 fluctuates with an amplitude of 0.2 at t = 0.8s, and the output power ratios of the other distributed power supplies also fluctuate accordingly, but the output power ratios of each distributed power supply still converge at t = 1.15s and 2.04s.

[0076] In this specific embodiment, a synchronous detection signal of each slave-controlled distributed power source is constructed at each sampling moment, and a discrete sequence of synchronous detection signals at time 1 is constructed, which is substituted into step S103 to calculate the latent attack dynamic identification index. Among them, the number of elements in the synchronous detection signal time series is 12; the adjustment coefficient is 0.3; the threshold value is adjusted based on the maximum identification index that may be generated by the slave-controlled DG output power ratio under the longest information disturbance period, that is, the latent attack dynamic identification index calculated by the output power ratio disturbance of 5 consecutive periods with a value of 1, and the threshold value is adjusted to 1.5. The latent attack dynamic identification index is as follows Figure 5 shown.

[0077] In this specific embodiment, before t = 0.8s, the distributed power supply cluster did not suffer from the latent attack of false information injection, and the dynamic identification index of the slave-controlled distributed power supply was 0, which was reliably less than the threshold value. After t = 0.8s, the attack signal was continuously injected into distributed power supply 3, and the dynamic identification index of the latent attack of distributed power supply 3 was greater than the threshold value. The dynamic identification index of the latent attack of the remaining slave-controlled distributed power supplies increased slightly but was still within the normal range. At t = 1.5s, the power command value controlled by the distributed cluster switched, and the output power of the distributed power supply cluster fluctuated, causing the dynamic identification index of the latent attack of the slave-controlled distributed power supply to fluctuate, but the dynamic identification index result of distributed power supply 3 still met the positioning criterion, which proves that the switching of the power command value does not affect the effectiveness of the positioning method of the latent attack of false information injection.

[0078] In this specific embodiment, after t = 0.8 s, the correlation coefficient of the discrete sequence of synchronous detection signals from distributed power source 3 is calculated according to step S106, as shown in Table 1 below. Table 1 shows that the correlation coefficient calculated for the time series of the synchronous detection signals from distributed power source 3 at the 11th sampling time after t = 0.8 s and its immediately preceding sampling time is 0.9901, which is greater than the threshold value. The time series of the synchronous detection signals from distributed power source 3 at the 10th and 11th sampling times after t = 0.8 s are used to identify the latent attack signal of false information injection. The constant attack signal value for distributed power source 3 is 0.1977. The error between this result and the actual attack signal is 0.0023, demonstrating the high reliability of the proposed method.

[0079] Table 1 Correlation coefficients of synchronous detection signal time series

[0080]

[0081] A latent attack identification system for an active power distribution network, as shown in the accompanying drawings, comprising a data acquisition module, a first calculation module, a second calculation module, a third calculation module, a fourth calculation module, a fifth calculation module, a first comparison module, and a second comparison module. Figure 6

[0082] The data acquisition module is configured to acquire real-time output active power of each distributed power source in a distributed cluster control power distribution network distributed power source cluster.

[0083] The first calculation module calculates the output power ratio of each distributed power source according to the active power acquired by the data acquisition module.

[0084] The second calculation module is configured to calculate the synchronous detection signal of the controlled distributed power source and the discrete time sequence at time l.

[0085] The third calculation module calculates the false information injection latent attack dynamic identification index according to the discrete time sequence.

[0086] The first comparison module is configured to compare the latent attack dynamic identification index with a threshold value, and if the latent attack dynamic identification index is reliably greater than the threshold value, the fourth calculation module is invoked, otherwise the third calculation module is invoked.

[0087] The fourth calculation module is configured to calculate the correlation coefficient of the synchronous detection signal discrete sequence of the controlled distributed power source subjected to the latent attack.

[0088] The second comparison module is configured to compare the correlation coefficient of the synchronous detection signal discrete sequence with a threshold value, and if the correlation coefficient of the synchronous detection signal discrete sequence is greater than the threshold value, the fifth calculation module is invoked, otherwise the fourth calculation module is invoked.

[0089] The fifth calculation module is configured to identify the false information injection latent attack signal.

[0090] In this embodiment, the specific implementation of the system is the same as that of the method.

[0091] In an embodiment of the present application, the present application further comprises a computer readable storage medium having a computer program stored thereon, which is executed by a processor to implement any of the above-mentioned latent attack identification methods for an active power distribution network.

[0092] ​Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with a computer program. The aforementioned computer program can be stored in a computer-readable storage medium. When executed, the program performs the steps in the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0093] A latent attack identification device for an active power distribution network comprises a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory and is used to execute the computer program stored in the memory, so that the latent attack identification device for an active power distribution network performs any of the above-mentioned latent attack identification methods for an active power distribution network.

[0094] Specifically, the memory includes various media that can store program codes, such as ROM, RAM, magnetic disk, USB flash drive, memory card or optical disk.

[0095] Preferably, the processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0096] The above embodiments further illustrate the purpose, technical solutions and advantages of the present invention in detail. It should be understood that the above embodiments are only preferred implementation plans of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made to the present invention within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for identifying latent attacks in active distribution networks, characterized in that: include: S101, collecting the real-time output active power of each distributed power source in the distributed power source cluster, and calculating the output power ratio of each distributed power source; The distributed power sources in the distributed power cluster include master-controlled distributed power sources and slave-controlled distributed power sources; S102, calculating the synchronization detection signal of the slave-controlled distributed power source in the distributed power source cluster according to the output power ratio, and constructing a discrete sequence of the synchronization detection signal at time 1; S103, calculating a dynamic identification index of a false information injection latent attack based on a discrete sequence of synchronous detection signals; S104, setting a positioning criterion. If the dynamic identification index of the false information injection latent attack meets the positioning criterion, execute step S105; otherwise, set l=l+1 and return to step S103; S105. Locate the slave-controlled distributed power source that is potentially attacked; S106. Calculate the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply that is under potential attack; S107. Set a threshold. If the correlation coefficient of the discrete sequence of the synchronous detection signal is greater than the threshold, identify the false information injection latent attack signal and complete the false information injection latent attack identification; otherwise, set l=l+1, regenerate the discrete time sequence of the synchronous detection signal of the slave-controlled distributed power supply that is subject to the latent attack, and return to step S106.

2. A method for identifying latent attacks in an active power distribution network according to claim 1, characterized in that: The output power ratio of the distributed power supply is the ratio of the active power output by the distributed power supply to the maximum allowable output power of the distributed power supply.

3. The method for identifying latent attacks in an active power distribution network according to claim 1, wherein: There is only one master-controlled distributed power source in the distributed power source cluster, which is used to directly receive control instructions issued by the distribution network control center; the slave-controlled distributed power sources directly or indirectly exchange information with the master-controlled distributed power source.

4. The method for identifying latent attacks in an active power distribution network according to claim 1, wherein: Calculating the dynamic identification index of the false information injection latent attack includes: calculating the minimum difference cumulative distance between the discrete sequence of the synchronous detection signal and the zero sequence; setting the adjustment coefficient; and taking the product of the minimum difference cumulative distance and the adjustment coefficient as the dynamic identification index of the false information injection latent attack.

5. The method for identifying latent attacks in an active power distribution network according to claim 1, wherein: Setting the positioning criterion includes: setting the reliability coefficient, calculating the maximum latent attack dynamic identification index generated by the slave-controlled distributed power supply under information disturbance; if the latent attack dynamic identification index of false information injection at the first moment is greater than the product of the maximum latent attack dynamic identification index and the reliability coefficient, then the positioning criterion is met, otherwise the positioning criterion is not met.

6. A method for identifying latent attacks in an active power distribution network according to claim 1, characterized in that: Calculating the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply subjected to a latent attack includes: Among them, r j (l) represents the time series correlation coefficient of the synchronous detection signal at time l and the previous time, x l-1,j (p) is the discrete sequence X of synchronous detection signals of the jth slave-controlled distributed power supply at time l-1, which is attacked by false information injection. j The elements in (l-1), x l,j (p) is the discrete sequence X of synchronous detection signals of the jth slave-controlled distributed power supply at time l that is latently attacked by false information injection. j (l) in the elements.

7. The method for identifying latent attacks in an active power distribution network according to claim 1, wherein: Identify the potential attack signals of false information injection: Among them, m is the number of elements in the time series, x l-1,j (p) is the discrete sequence X of synchronous detection signals of the jth slave-controlled distributed power supply at time l-1, which is attacked by false information injection. j The elements in (l-1), x l,j (p) is the discrete sequence X of synchronous detection signals of the jth slave-controlled distributed power supply at time l that is latently attacked by false information injection. j (l) in the elements.

8. A system for identifying latent attacks in an active power distribution network, the system being used to execute a method for identifying latent attacks in an active power distribution network according to any one of claims 1 to 7, characterized in that: include: A data acquisition module, a first calculation module, a second calculation module, a third calculation module, a fourth calculation module, a fifth calculation module, a first comparison module, and a second comparison module; The data acquisition module is used to collect the real-time output active power of each distributed power source in the distributed power source cluster of the distributed cluster control distribution network; The first calculation module calculates the output power ratio of each distributed power source according to the active power collected by the data collection module; The second calculation module is used to calculate the synchronous detection signal of the slave-controlled distributed power supply and the discrete time series at time l; The third calculation module calculates the dynamic identification index of false information injection latent attack based on the discrete time series; The first comparison module is used to compare the latent attack dynamic identification index with a threshold value, and if the latent attack dynamic identification index is reliably greater than the threshold value, the fourth calculation module is called, otherwise the third calculation module is called; The fourth calculation module is used to calculate the discrete sequence correlation coefficient of the synchronous detection signal of the slave-controlled distributed power supply that is subject to a latent attack; The second comparison module is used to compare the correlation coefficient of the discrete sequence of synchronous detection signals with the threshold value, and if the correlation coefficient of the discrete sequence of synchronous detection signals is greater than the threshold value, the fifth calculation module is called, otherwise the fourth calculation module is called; The fifth calculation module is used to identify false information injection latent attack signals.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: The computer program is executed by a processor to implement the latent attack identification method for an active power distribution network according to any one of claims 1 to 7.

10. A latent attack identification device for active power distribution network, characterized in that: The invention comprises a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory and is used to execute the computer program stored in the memory, so that the latent attack identification device for an active distribution network executes the latent attack identification method for an active distribution network according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Centralized control unmanned aerial vehicle resisting system based on sound wave attacking

    CN107167037A

  • Micro-grid distributed synchronous detection method for false injection attack

    CN113285495A