An Optimized Method for Integrated Energy Cyber-Physical System Defense Against Deliberate Attacks

By establishing a linear comprehensive energy information physics system model and applying dual theory solutions, the optimal defense resource deployment strategy is obtained, which solves the problem that existing technology is difficult to deal with deliberate attacks in the integrated energy information physics system, and achieves effective defense and economic losses in harsh attack scenarios.

CN119788416BActive Publication Date: 2025-05-16SICHUAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510256453.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-16
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

Due to its complex coupling relationship and diverse energy subsystem models, existing defense methods are difficult to effectively deal with deliberate attacks, especially in the coordinated attack scenarios between information systems and physical systems.

Method used

By establishing a linear comprehensive energy information physics system model based on energy path theory and single commodity flow principle, and solving it with dual theory, we obtain the optimal defense resource deployment strategy to deal with load losses in different attack scenarios.

Benefits of technology

It realizes the most effective defensive resource allocation in the harshest attack scenarios, reduces the economic losses of the integrated energy information physics system, and improves the security protection level of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788416B_ABST
    Figure CN119788416B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of security defense technology for integrated energy information-physical systems, and discloses an integrated energy information-physical system defense optimization method for responding to intentional attacks; first, given an attack uncertainty set, solve the first-stage defense resource deployment model according to the attack strategy therein, and update the lower bound; then solve the second-stage attack strategy according to the defense resource deployment strategy solved in the first stage, and update the upper bound; finally, judge the difference between the upper and lower bounds, if the difference between the upper and lower bounds is less than a threshold, output the optimal defense resource deployment strategy, and the solution ends; otherwise, add the lower-level attack strategy to the attack uncertainty set, and repeat the first two steps until the threshold requirement is met. The present invention solves the optimal defense resource deployment plan by giving a new attack uncertainty set, and the obtained defense resource plan can ensure the best protection in the worst attack scenario, thereby reducing the economic losses of the integrated energy information-physical system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security defense technology for integrated energy information-physical systems, and specifically to an integrated energy information-physical system defense optimization method for responding to intentional attacks. Background Art

[0002] In order to cope with the increasingly severe energy problems, the development of an integrated energy system that can achieve coordinated planning and collaborative management of multiple heterogeneous energy sources has been highly supported and vigorously developed by the country. In order to achieve mutual complementation and interactive response between multiple energies, in addition to physical interconnection, each subsystem cannot do without accurate interaction at the information level. As the scale of the integrated energy system continues to expand, the amount of data in information interaction is also growing, forming a typical integrated energy cyber-physical system (IECPS Integrated Energy Cyber ​​Physical Systems). Although the integrated energy cyber-physical system is conducive to energy integration, the high coupling of information systems and multiple physical systems greatly increases the security risks of the system, especially the risk of intentional human attacks. On the one hand, the coupling mechanism of the new system coupled by the system is not completely clear, and some vulnerabilities have yet to be discovered. The probability of attackers launching intentional attacks on the energy system through these vulnerabilities is relatively high; on the other hand, the damage of a single system can be transmitted through the "coupling channel" between systems, and finally cause large-scale failures of multiple subsystems, and the loss of effective attacks is greatly increased. Under the dual pressure of security risks and losses of the integrated energy cyber-physical system, it is urgent to study the defense methods of the integrated energy information system against intentional attacks to reduce the risk of the system being attacked or the loss when attacked.

[0003] Considering the investment cost of the system, the configuration of defense resources is often not fully covered. In addition to economic considerations, system vulnerabilities are difficult to completely avoid, and the occurrence of attacks cannot be eliminated even with full coverage of existing defense resources. Therefore, how to optimize defense means has become the research focus of the defense of integrated energy information-physical systems. Due to the complex coupling relationship of the integrated energy information-physical system and the huge differences in the models of various energy subsystems, the existing single energy system defense methods are difficult to apply directly. In addition, when the integrated energy information-physical system model established according to the coupling relationship of the existing energy system model is applied to the defense optimization research, it is difficult to solve it directly due to the nonlinear problem of the model, resulting in the current lack of an effective defense optimization model, and it is impossible to obtain a scientific and excellent defense means configuration strategy. Therefore, there is an urgent need for an integrated energy information-physical system model that can take into account both linearization accuracy and solution complexity for the optimization of intentional attack defense of the integrated energy information-physical system. In summary, the current integrated energy information-physical system needs to study effective security means configuration strategies and defense optimization models to ensure the safe operation of the system.

[0004] Research on the security of cyber-physical systems mainly focuses on the detection and defense of intentional attacks. Although existing technical means have a good application effect on some intentional attacks, they ignore the interaction between cyber systems and physical systems in the modeling process and cannot solve the problem of cross-domain propagation of faults. Moreover, as the degree of coupling of energy systems deepens, the system control mechanism becomes more complex, and a single system failure may propagate to other systems along the coupled equipment, and the risk of intentional attacks continues to rise. Therefore, focusing only on the security of a single system, such as the power system, cannot guarantee the safe and stable operation of the integrated energy system. At present, some scholars have been conducting security research on integrated energy cyber-physical systems.

[0005] As the interactions between energy subsystems become more frequent, high informatization is an inevitable choice and an important feature of future integrated energy systems. While information systems bring convenience to physical system scheduling, they significantly increase the risk of the system being attacked by cyber attacks. In addition to reducing the risk of system failure and reducing the loss of the system when it is attacked from the system scheduling level, attention should also be paid to the impact of information systems on system scheduling. However, although existing research has provided some available protection measures for integrated energy systems against intentional attacks, due to the simplification of attack models and the high complexity of integrated energy information-physical system models, existing methods have certain limitations in resisting intentional attacks on integrated energy information-physical systems. Therefore, establishing a more specific attack model and an integrated energy information-physical system model that takes into account both accuracy and solution performance is the key to studying the protection of integrated energy information-physical systems.

[0006] In terms of attack models, although existing research has established some attack methods with significant threats, it lacks consideration of coordinated attacks on information systems and physical systems. In terms of integrated energy information-physical system models, most existing integrated energy system models directly connect various subsystems through coupling devices. Secondly, since traditional thermal systems and natural gas systems mostly use differential equations to describe the flow process of heat carriers and natural gas, there are a large number of discrete variables after linearization. Although this coupling model accurately describes the dynamic process of the system, it is not conducive to studying the game process between attackers and defenders.

[0007] In summary, although a lot of progress has been made in the research on energy system security protection, with the development of integrated energy information-physical systems, these studies cannot cope with the increasingly severe risk of intentional attacks. First, most of the current attack methods against integrated energy information-physical systems consider the separate effects of information attacks or physical attacks, or only launch information-physical coordinated attacks on a single energy system, and the cross-domain propagation of information-physical coordinated attacks in integrated energy systems is not accurate enough. Secondly, limited by the complex coupling relationship of the integrated energy system and the differences in the scheduling time scales between the various subsystems, the existing integrated energy information-physical system model is extremely complex, and there are a large number of discrete variables in the linearized model, making it difficult to apply the existing integrated energy information-physical system operation scheduling model to defense optimization research. If based on the existing model, only heuristic algorithms can be used for iteration when solving, and heuristic algorithms cannot solve the disconnection type attack model. In addition, since the existing defense or mitigation strategy research lacks consideration of attack uncertainty, the effectiveness of the obtained strategy will be greatly reduced in practical applications. Therefore, it is necessary to study more advanced collaborative attack models of integrated energy information-physical systems and operation scheduling models that are more suitable for defense optimization research, so as to establish a defense optimization model that takes into account multiple intentional attack methods, thereby improving the security protection level of the integrated energy information-physical system and reducing system losses. Summary of the invention

[0008] In view of the above problems, the purpose of the present invention is to provide a defense optimization method for an integrated energy information-physical system to deal with intentional attacks. By solving the optimal defense resource deployment plan given a new attack uncertainty set, the obtained defense resource plan can ensure the best protection in the worst attack scenario, thereby reducing the economic losses of the integrated energy information-physical system. The technical solution is as follows:

[0009] The integrated energy cyber-physical system defense optimization method against intentional attacks includes the following steps:

[0010] Step 1: Initialize the parameters of the integrated energy cyber-physical system;

[0011] Step 2: Establish the first-stage defense resource deployment model, randomly give an attack uncertainty set that satisfies the attack resource constraints, and according to the attack strategy in the attack uncertainty set, the defender obtains the specific optimal defense strategy by solving the first-stage defense resource deployment model, and obtains the load loss value of the integrated energy information-physical system at this time, and compares the load loss value at this time with the lower bound of the currently stored load loss value. L Compare and update. If the load loss value at this time is greater than its lower limit value L , the new lower limit is the load loss value at this time; if the load loss value at this time is less than its lower limit L , the new lower bound value is still the current lower bound valueL ;

[0012] Step 3: Establish the second-stage attack optimization model, take the optimal defense resource deployment strategy obtained by solving the first-stage defense resource deployment model as input, pass it to the second-stage attack optimization model, and solve to obtain the optimal attack strategy and the maximum load loss value; compare the load loss value at this time with the upper limit of the currently stored load loss value U For comparison, if the load loss value at this time is less than its upper limit U , the new upper limit value is the load loss value at this time; otherwise, keep the current upper limit value U constant;

[0013] The second-stage attack optimization model is a two-layer model. The upper-layer attacker maximizes the load loss caused by the system attack by finding the optimal attack vector, and the lower-layer operator solves the operation strategy with the minimum load loss under the attack strategy given by the upper-layer attacker.

[0014] Step 4: Calculate the difference between the upper and lower bounds. If the difference between the upper and lower bounds is less than the set threshold, output the optimal defense resource deployment strategy and the solution ends. Otherwise, add the attack strategy solved in the second stage to the attack uncertainty set and repeat steps 2 and 3 until the set threshold requirement is met.

[0015] The beneficial effects of the present invention are:

[0016] 1) When studying the defense optimization problem of integrated energy information-physical systems, since the linearization of traditional models brings a large number of discrete variables, the two-layer model describing the behavior of attackers and operators is difficult to solve directly through the duality theory, and it is also impossible to solve the defense optimization strategy; however, the present invention establishes a linearized integrated energy information-physical system model based on the energy path theory and the single commodity flow principle. When the model is applied to solve the defense optimization strategy, the attack-operation two-layer model can be directly converted into a single-layer model through the duality theory, thereby realizing the solution of the defense optimization strategy.

[0017] 2) The present invention can effectively deal with information attacks, physical attacks and information-physical coordinated attacks. By taking into account the failure conditions of each system under various attack modes, the present invention can accurately reflect the behavior and response of the integrated energy information-physical system under uncertain attacks. Based on this, the corresponding defense resource configuration scheme can be adopted to effectively reduce the loss of the system when facing uncertain attacks.

[0018] 3) The present invention establishes an optimal defense resource model for an integrated energy information-physical system, and uses a column and constraint generation algorithm to couple the defense resource model and the optimal attack model, thereby establishing an iterative solution framework for the optimal defense resource allocation strategy. Through this solution framework, the optimal defense resource allocation strategy under limited defense resources can be solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 Solve the flow chart for integrated energy cyber-physical system defense optimization.

[0020] Figure 2 This is the physical topology diagram of the integrated energy system.

[0021] Figure 3 It is the information topology diagram of the integrated energy system.

[0022] Figure 4 The diagram shows the system load shedding under different attack defense parameters.

[0023] Figure 5 Figure 2 is the system loss diagram under different attack scenarios. DETAILED DESCRIPTION

[0024] The present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0025] This paper proposes a defense optimization method for an integrated energy cyber-physical system to deal with deliberate attacks. By solving the optimal defense resource deployment plan given a new attack uncertainty set, the obtained defense resource plan can ensure the best protection in the worst attack scenario, thereby reducing the economic losses of the integrated energy cyber-physical system. Figure 1 The specific steps are described as follows:

[0026] Step 1: Initialize the parameters of the integrated energy information-physical system, including the topological parameters of the integrated energy information-physical system, the upper and lower limits of generator output, the upper and lower limits of gas source output, the upper and lower limits of gas pressure, the upper and lower limits of flow, the upper and lower limits of gas turbine output, and the upper and lower limits of power-to-gas equipment output.

[0027] Step 2: Given an attack uncertainty set, solve the first-stage defense resource deployment model according to the attack strategies in the set and update the lower bound value L .

[0028] Initially, an attack strategy that satisfies the attack resource constraint is randomly given. The defender obtains the specific optimal defense strategy by solving the first-stage defense resource deployment model, and obtains the load loss of the integrated energy information-physical system at this time, and compares and updates the load loss value with the lower bound value of the currently stored load loss value. If the current load loss value is greater than the current lower bound value, the new lower bound value is L is the current load loss value; if the current load loss value is less than the current lower limit value, the new lower limit value L It is still the current lower bound value. In this step, the specific first-order defense resource deployment model is as follows.

[0029] 1) Objective function:

[0030] Statistical analysis of the load loss of the integrated energy cyber-physical system is the most direct way to judge whether the integrated energy cyber-physical system is under attack. Therefore, the objective function of the first-stage defense resource deployment model is:

[0031] (1);

[0032] Where: and are the number of electrical nodes and gas nodes, respectively; and They are the node power shedding load and gas shedding load respectively; H It is the calorific value of natural gas, which represents the energy value of natural gas flow converted into electrical energy.

[0033] 2) Constraints:

[0034] a. Power system constraints:

[0035] As an important part of the integrated energy cyber-physical system, the power system not only undertakes the important task of power transmission, but also can use the surplus power for gas production through power-to-gas equipment. Its main constraints are as follows:

[0036] (2);

[0037] (3);

[0038] (4);

[0039] (5);

[0040] Where: P is the active power flow vector of the power line; is the branch admittance matrix; is the node admittance matrix; is the node voltage phase angle vector, is the equilibrium node voltage phase angle; is the power line attack vector, which is 1 if there is an attack on the power line, and 0 if there is no attack; is the power line protection vector, which is 1 if the power line has protection, and 0 if it does not; and They represent the minimum and maximum values ​​of the active power flow of the power line respectively; , and They represent the generator node matrix, gas turbine matrix and power-to-gas equipment matrix in the power system respectively; , , , and They are respectively the generator active power vector, the gas turbine active power vector, the power-to-gas equipment active power vector, the node load vector and the node power shedding load vector; T is the transposition symbol.

[0041] b. Natural gas system constraints:

[0042] As an important part of the integrated energy information-physical system, the natural gas system not only undertakes the task of natural gas supply, but also can generate electricity through gas turbines to support the stable power supply of the power system. The traditional natural gas system model is often based on the Weymouth equation. Based on the energy path theory, the present invention equates the natural gas system to the power system, with the following specific constraints:

[0043] (6);

[0044] (7);

[0045] (8);

[0046] (9);

[0047] (10);

[0048] (11);

[0049] Where: , , and They are the gas source node matrix, power-to-gas equipment node matrix, node branch matrix and gas turbine node matrix in the natural gas system; is the gas production vector of the gas source; , , , , and They are respectively the gas production of the power-to-gas equipment, gas load, gas consumption of the gas turbine, pipeline gas flow, node gas cut-off load and gas flow provided by the compressor equivalent gas pressure source; k is the equivalent controlled air pressure source parameter; is the gas path admittance matrix; , and They are the gas circuit node outflow matrix, gas circuit node inflow matrix and compressor node matrix respectively; is the node pressure vector; , and They are the minimum pressure vector, maximum pressure vector and the pressure value of the pressure stabilizing source respectively; is the natural gas pipeline attack vector, 1 indicates that the natural gas pipeline is attacked, and 0 indicates that there is no attack; is the natural gas pipeline protection vector, which is 1 if the natural gas pipeline is protected and 0 if it is not; is the voltage stabilizing source matrix; and are the minimum and maximum values ​​of pipeline gas flow respectively.

[0050] c. Coupling device constraints:

[0051] The natural gas system and the power system are coupled with the gas turbine through the power-to-gas device. The power-to-gas device converts the surplus electricity of the power system into hydrogen in the form of water electrolysis, and then reacts carbon dioxide and hydrogen to generate methane under high temperature and high pressure, while the gas turbine generates electricity by burning natural gas raw materials. In this process, there is an energy conversion efficiency problem, so the coupling device constraint can be expressed as:

[0052] (12);

[0053] (13);

[0054] Where: and Represent the conversion efficiency of power-to-gas equipment and gas turbine respectively.

[0055] d. Information system constraints:

[0056] As the hub for controlling physical systems, information systems are one of the important targets of malicious attackers. Assuming that there is no delay or blockage in the transmission of information, this means that information can flow from the communication node to the control center through any available link. That is, as long as the communication node has a link to reach the control center, it can maintain normal working conditions. The present invention uses a single commodity flow model to simulate the working state of the information system. When all communication links connecting the control center and the communication node are disconnected, the demand for the node disappears completely because the commodity cannot flow from the control center to the node. On the contrary, if the communication of the node is connected, the demand can be met. The specific constraints are:

[0057] (14);

[0058] (15);

[0059] Where: and They represent the control center node matrix and node branch matrix in the power information system respectively; , and They represent the virtual information flow sent by the control center in the power information system, the virtual information flow circulated in the communication link, and the information node status respectively; and They represent the attack vector and link protection vector of the power information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow flowing through the communication link in the power information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow sent by the control center in the power information system respectively; and They represent the control center node matrix and node branch matrix of the natural gas information system respectively; , and They represent the virtual information flow sent by the control center in the natural gas information system, the virtual information flow circulated in the communication link, and the information node status respectively; and They represent the attack vector and link protection vector of the natural gas information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow circulating in the communication link in the natural gas information system respectively; and They respectively represent the minimum and maximum values ​​of the virtual information flow sent by the control center in the natural gas information system.

[0060] e. Cyber-physical coupling constraints:

[0061] When the communication link is attacked and the node cannot connect to the control center, the communication node fails, and the physical entity it controls will also undergo a series of changes. Specifically, when the power information node fails, in order to ensure the safe operation of the power system, the system will make the following adjustments: when the information node that controls the load fails, the system will cut off the corresponding load; when the information node that controls the generator fails, the system will cut off the corresponding generator; when the information node that controls the power-to-gas equipment and gas turbine fails, the system will cut off the output of both. Therefore, the corresponding constraints can be represented as:

[0062] (16);

[0063] (17);

[0064] (18);

[0065] (19);

[0066] Where: , , and They represent the corresponding relationship matrices between power information nodes and loads, generators, power-to-gas equipment, and gas turbines respectively.

[0067] When the information node of the natural gas system fails, due to the large time scale of the natural gas system, the change results in a short period of time are not completely similar to those of the power system. Specifically, when the information node controlling the load fails, the natural gas load will not be completely cut off; when the information node controlling the gas source fails, the gas source gas production remains unchanged; when the information node controlling the compressor fails, the compressor stops working; when the information node controlling the gas turbine and the power-to-gas equipment fails, the current state is maintained. Therefore, the corresponding constraints can be expressed as:

[0068] (20);

[0069] (twenty one);

[0070] (twenty two);

[0071] (twenty three);

[0072] Where: , , and They are the corresponding relationship matrices between natural gas information nodes and compressors, gas sources, power-to-gas equipment, and gas turbines; , and They are the flow rates of gas source, power-to-gas equipment and gas turbine at the previous moment respectively.

[0073] Considering the importance of information nodes, all information nodes are equipped with uninterruptible power supplies, and the present invention focuses on the load loss of the integrated energy information-physical system in a short time scale. Therefore, the energy supply demand of the information node can still be met after the attack event occurs. That is, the information system crash caused by the power failure of the physical system can be ignored.

[0074] f. Available resource constraints:

[0075] As a defender, considering the defense cost and defense capability, it is impossible to defend every component. Therefore, defense resources are limited, and the specific constraints are:

[0076] (twenty four);

[0077] Where: is the maximum value of defense resources; Defend physical systems against variables; Defend variables for information systems; For physical lines, including gas pipelines and electric power lines; m For information lines, including natural gas information lines and electricity information lines; is a collection of physical lines; A collection of information lines.

[0078] As an attacker, considering the attacker's attack capabilities, only limited attacks can be launched on the system. Therefore, the attack resources are limited, and the specific constraints are:

[0079] (25);

[0080] Where: is the maximum value of attack resources; Attack variables for physical systems; is the information system attack variable.

[0081] The current defense resource deployment strategy can be obtained by solving the defense resource deployment model shown in equations (1) to (25). The obtained objective function value is compared with the lower bound value to obtain the latest lower bound value.

[0082] Step 3: Based on the defense resource deployment strategy solved in the first stage, solve the second stage attack strategy and update the upper bound U .

[0083] The defense resource deployment strategy obtained by solving the first-stage defense resource deployment model is used as input and passed to the second-stage attack optimization model to solve the optimal attack strategy and maximize the load loss value; the load loss value at this time is compared with the upper limit of the currently stored load loss value. If the load loss value is less than the current upper limit, the new upper limit is the load loss value; otherwise, the upper limit remains unchanged. The second-stage attack optimization model is a typical two-layer model. The upper-layer attacker maximizes the load loss caused by the system attack by finding the optimal attack vector, and the lower-layer operator solves the operation strategy with the minimum load loss under the attack strategy given by the upper layer. The specific model is as follows:

[0084] 1) Two-stage two-layer model:

[0085] The attacker's goal is to maximize the attack benefits, that is, maximize the load loss, by optimizing the attack implementation strategy under limited attack resources. In order to ensure the safety and economy of system operation, the operator's scheduling goal is to ensure the minimum system load loss. Therefore, the objective function is:

[0086] (26);

[0087] Where: Attack strategies include power line attacks, power information attacks, natural gas pipeline attacks, and natural gas information attacks; is the scheduling strategy, including generator output, gas turbine output, power consumption of power-to-gas equipment, gas production of gas source, etc. The remaining constraints are shown in equations (2) to (23) and (25).

[0088] 2) Model Duality:

[0089] The attack strategy in the second stage is a typical two-layer model. The upper model is the attacker model, and the lower model is the operator model. Solving this model requires the use of duality theory. For the attacker, the main consideration is the limitation of attack resources. The objective function and constraints are:

[0090] (27);

[0091] When scheduling system resources, in order to reduce system losses, the lower-level operator needs to minimize the expected load loss and also ensure that the number of failed nodes in the information system is minimized when an attack occurs. Therefore, the operator's objective function and constraints are:

[0092] (28);

[0093] (29);

[0094] (30);

[0095] (31);

[0096] Where: is the Lagrange multiplier of the equality constraint; is the Lagrange multiplier of the inequality constraint, and its value is greater than 0.

[0097] All constraints in equations (28) to (29) are transformed into matrices express, Using the matrix Indicates that ; All constraints in formula (30) are represented by matrices express, Using the matrix Indicates that ; All constraints in formula (31) are represented by the set express, Using the matrix Indicates that ; Construct Lagrangian function , and , which are in the following forms:

[0098] (32);

[0099] (33);

[0100] (34);

[0101] Where: and They are respectively a valid electricity information node and a valid natural gas information node; is a collection of power information nodes; A collection of natural gas information nodes.

[0102] In order to satisfy the dual theory conditions, the partial derivative of the Lagrangian function should be 0, then all variables can be expressed as , the Lagrangian function , , Using the matrix If , then the constraint is expressed as:

[0103] (35);

[0104] After the dual transformation, the two-layer model of the second stage shown in equation (26) is converted into a single-layer model shown in equations (27) to (35), which can be solved directly. The solution model obtains the optimal attack strategy and the most serious load loss result of the integrated energy information-physical system under a given defense strategy. The result is compared with the upper limit value to obtain a new upper limit value.

[0105] Step 4: Determine the difference between the upper and lower bounds. If the difference between the upper and lower bounds is less than the threshold , output the optimal defense resource deployment strategy, and the solution ends; otherwise, add the lower-level attack strategy to the attack uncertainty set, and repeat steps 2 and 3 until the threshold is met. Require.

[0106] The defense optimization problem of the integrated energy information-physical system that the present invention focuses on is to find a defense strategy so that the system can still have the most effective defense capability when subjected to the worst attack strategy. This is a typical robust optimization problem. The problem cannot obtain the optimal strategy through a single solution, so it needs to be continuously iterated until the solution converges, that is, the difference between the upper and lower bounds is within a very small range, and it can be considered that the optimal defense strategy has been obtained. Therefore, after completing step 2 and step 3 each time, it is necessary to judge the values ​​of the upper and lower bounds. If it exceeds the set threshold range, it means that the model solution result is not the optimal defense strategy at this time, and it needs to continue to iterate; if the threshold requirements are met, the defense strategy at this time can be output, which is the optimal defense strategy.

[0107] Case analysis:

[0108] 1. Case introduction:

[0109] The physical system of the example is composed of a 14-node transmission network and an 8-node gas network, equipped with two power-to-gas devices and two gas turbines. The information system consists of a 23-node power information system and a 16-node natural gas information system. The physical system nodes, devices and information system nodes correspond one to one. The specific topological structure of the integrated energy information-physical system is as follows: Figure 2 , Figure 3 As shown in the figure, G1-G4 represent generators, B1-B14 represent power system nodes, N1-N8 represent natural gas nodes, W1-W2 represent natural gas sources, GT1-GT2 represent gas turbines, P2G1-P2G2 represent power-to-gas equipment, and CP represents compressors. CCG and CCP represent the natural gas information system control center and the power system control center, respectively.

[0110] The specific parameter settings of each device in the example are shown in Table 1-3:

[0111] Table 1 Coal-fired unit parameters

[0112] .

[0113] Table 2 Gas source parameters

[0114] .

[0115] Table 3 Conversion equipment parameters

[0116] .

[0117] The pipeline numbers in the example are shown in Table 4:

[0118] Table 4 Pipeline No.

[0119] .

[0120] In order to verify the effectiveness of the proposed method, the present invention designs a number of verification examples, and the specific example settings are as follows:

[0121] 1) Considering that IECPS is only subjected to physical attacks, the ability of physical defense measures to resist intentional attacks is studied. The number of physical attack resources is set to 6, and the maximum number of physical defense resource configurations is set to 3~8. The simulation results are shown in Table 5.

[0122] Table 5: Defense results considering only physical attacks

[0123] .

[0124] It can be seen from Table 5 that the system load shedding will gradually decrease as the number of defense resources configured increases, and defense resources will be preferentially configured on the lines connecting important loads and generators. The reason is that configuring defense resources there can avoid transmission congestion or even islanding caused by attacks, thereby causing large-scale load reduction.

[0125] 2) The impact of physical attack uncertainty on defense effect. When the number of physical defense configurations is set between 3 and 8 and the maximum number of physical attacks is set between 1 and 4, the system load shedding under different parameter settings is as follows: Figure 4 shown.

[0126] Depend on Figure 4 It can be seen that the system load abandonment increases with the increase of the maximum number of attacks and decreases with the increase of the number of defense resource configurations. When the number of line attacks increases from 3 to 4, the system load abandonment does not increase significantly, so the increase in the number of attacks at this time causes a waste of attack resources. On the other hand, when the number of defense resources increases from 3 to 7, the system load abandonment does not decrease significantly, but when it further increases from 7 to 8, the system load abandonment decreases significantly. The reason is that when the number of defense resources in the system is small, the defense effect against physical attacks is low, and a certain number of defense resources must be deployed to have a certain defense capability.

[0127] 3) In order to verify the effectiveness of the cyber-physical collaborative attack model of the present invention, the following attack scenario is set:

[0128] Scenario 1: Only consider the information attack scenario.

[0129] Scenario 2: Only physical attack scenarios are considered.

[0130] Scenario 3: Directly combine the attack plans of scenarios 1 and 2.

[0131] Scenario 4: Consider a cyber-physical coordinated attack scenario.

[0132] The defense resource configuration strategy in Table 5 is used as the ex ante defense strategy. The number of physical attack resources is set to 3 and the number of information attack resources is set to 2. The attack schemes for scenarios 1, 2, and 4 are determined by solving the attack optimization model. The system load shedding in different scenarios is as follows: Figure 5 shown.

[0133] Depend on Figure 5 It is known that in scenario 2, as the number of defense resource configurations increases, the system load abandonment maintains a downward trend, but the reduction in scenario 4 is smaller than that in scenario 2, indicating that the cyber-physical coordinated attack will restrict the improvement of system resilience by the defense resource configuration. The load abandonment in scenario 1 remains unchanged, because the physical side defense resources cannot resist the impact of information attacks. In scenarios 3 and 4, as the number of defense resources increases, the system load abandonment does not show a monotonic change trend. The reason is that under the combined attack and coordinated attack schemes, the load abandonment caused by the information attack is different under different physical resource configuration strategies. In addition, compared with scenarios 1 and 2, the load abandonment in scenarios 3 and 4 is significantly increased, that is, the combined attack and coordinated attack schemes will cause more serious load losses than the single attack scheme. Furthermore, the load abandonment in scenario 4 is always larger than that in scenario 3, indicating that cyber-physical coordinated attacks can cause greater harm to the system.

[0134] Based on the above experiments, it can be seen that the IECPS model established by the present invention can realize the joint dispatch of natural gas and power systems, and the established IECPS attack model can launch effective attacks on the system and cause serious damage. In addition, the IECPS defense resource optimization model established on the basis of the IECPS model and the intentional attack model can quickly realize the optimal deployment of defense resources, effectively reduce system losses, and improve the system's ability to cope with uncertain intentional attacks.

Claims

1. A method for optimizing the defense of an integrated energy cyber-physical system against deliberate attacks, characterized in that: The following steps are involved: Step 1: Initialize the parameters of the integrated energy cyber-physical system; Step 2: Establish the first-stage defense resource deployment model, randomly give an attack uncertainty set that satisfies the attack resource constraints, and according to the attack strategy in the attack uncertainty set, the defender obtains the specific optimal defense resource deployment strategy by solving the first-stage defense resource deployment model, and obtains the load loss value of the integrated energy information-physical system at this time, and compares the load loss value at this time with the lower bound of the currently stored load loss value. L Compare and update. If the load loss value at this time is greater than its lower limit value L , the new lower limit is the load loss value at this time; if the load loss value at this time is less than its lower limit L , then the new lower bound value is still the current lower bound value L ; Step 3: Establish the second-stage attack optimization model, take the optimal defense resource deployment strategy obtained by solving the first-stage defense resource deployment model as input, pass it to the second-stage attack optimization model, and solve to obtain the optimal attack strategy and the maximum load loss value; compare the load loss value at this time with the upper limit of the currently stored load loss value U For comparison, if the load loss value at this time is less than its upper limit U , the new upper limit value is the load loss value at this time; otherwise, keep the current upper limit value U constant; The second-stage attack optimization model is a two-layer model. The upper-layer attacker maximizes the load loss caused by the attack on the integrated energy information-physical system by finding the optimal attack vector, and the lower-layer operator solves the operation strategy with the minimum load loss under the attack strategy given by the upper-layer attacker. Step 4: Calculate the difference between the upper and lower bounds. If the difference between the upper and lower bounds is less than the set threshold, output the optimal defense resource deployment strategy and the solution is completed; otherwise, add the attack strategy solved in the second stage to the attack uncertainty set, and repeat steps 2 and 3 until the set threshold requirement is met; The first phase defense resource deployment model includes: Objective function: The attack on the integrated energy information-physical system is judged by counting the load loss of the integrated energy information-physical system. Therefore, the objective function of the first-stage defense resource deployment model is: (1); Where: and are the number of electrical nodes and gas nodes, respectively; and Node i Shedding loads and nodes u Cut-off load; H is the calorific value of natural gas, which represents the energy value of natural gas flow when all the energy is converted into electrical energy; Constraints: a. Power system constraints: (2); (3); (4); (5); Where: P is the active power flow vector of the power line; is the branch admittance matrix; is the node admittance matrix; is the node voltage phase angle vector, is the equilibrium node voltage phase angle; is the power line attack vector, which is 1 if there is an attack on the power line, and 0 if there is no attack; is the power line protection vector, which is 1 if the power line has protection, and 0 if it does not; and They represent the minimum and maximum values ​​of the active power flow of the power line respectively; , and They represent the generator node matrix, gas turbine matrix and power-to-gas equipment matrix in the power system respectively; , , , and They are respectively the generator active power vector, the gas turbine active power vector, the power-to-gas equipment active power vector, the node load vector and the node power shedding load vector; T is the transposition symbol; b. Natural gas system constraints: Based on the energy path theory, the natural gas system is equivalent to the power system, and the specific constraints are as follows: (6); (7); (8); (9); (10); (11); Where: , , and They are the gas source node matrix, power-to-gas equipment node matrix, node branch matrix and gas turbine node matrix in the natural gas system; is the gas production vector of the gas source; , , , , and They are respectively the gas production of the power-to-gas equipment, gas load, gas consumption of the gas turbine, pipeline gas flow, node gas cut-off load and gas flow provided by the compressor equivalent gas pressure source; k is the equivalent controlled air pressure source parameter; is the gas path admittance matrix; , and They are the gas circuit node outflow matrix, gas circuit node inflow matrix and compressor node matrix respectively; is the node pressure vector; , and They are the minimum pressure vector, maximum pressure vector and the pressure value of the pressure stabilizing source respectively; is the natural gas pipeline attack vector, 1 indicates that the natural gas pipeline is attacked, and 0 indicates that there is no attack; is the natural gas pipeline protection vector, which is 1 if the natural gas pipeline is protected and 0 if it is not; is the voltage stabilizing source matrix; and are the minimum and maximum values ​​of pipeline gas flow respectively; c. Coupling device constraints: (12); (13); Where: and Represent the conversion efficiency of power-to-gas equipment and gas turbine respectively; d. Information system constraints: The single commodity flow model is used to simulate the working state of the information system. When all communication links connecting the control center and the communication node are disconnected, the demand for the communication node disappears completely; on the contrary, if the communication of the communication node is connected, the demand can be met; the specific constraints are: (14); (15); Where: and They represent the control center node matrix and node branch matrix in the power information system respectively; , and They represent the virtual information flow sent by the control center in the power information system, the virtual information flow circulated in the communication link, and the information node status respectively; and They represent the attack vector and link protection vector of the power information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow flowing through the communication link in the power information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow sent by the control center in the power information system respectively; and They represent the control center node matrix and node branch matrix of the natural gas information system respectively; , and They represent the virtual information flow sent by the control center in the natural gas information system, the virtual information flow circulated in the communication link, and the information node status respectively; and They represent the attack vector and link protection vector of the natural gas information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow circulating in the communication link in the natural gas information system respectively; and They represent the minimum and maximum values ​​of the virtual information flow sent by the control center in the natural gas information system respectively; e. Cyber-physical coupling constraints: When the information node controlling the load fails, the corresponding load is cut off; when the information node controlling the generator fails, the corresponding generator is cut off; when the information node controlling the power-to-gas device and the gas turbine fails, the output of both is cut off at the same time; therefore, the corresponding constraints are represented as: (16); (17); (18); (19); Where: , , and Respectively represent the corresponding relationship matrix between the power information node and the load, generator, power-to-gas equipment and gas turbine; and are the minimum and maximum values ​​of the generator active power vector respectively; and are the minimum and maximum values ​​of the active vector of the power-to-gas equipment respectively; and are the minimum and maximum values ​​of the active power vector of the gas turbine, respectively; When the information node controlling the load fails, the natural gas load will not be completely cut off; when the information node controlling the gas source fails, the gas source gas production remains unchanged; when the information node controlling the compressor fails, the compressor stops working; when the information node controlling the gas turbine and the power-to-gas equipment fails, the current state is maintained; therefore, the corresponding constraints are expressed as: (20); (21); (22); (23); Where: , , and They are the corresponding relationship matrices between natural gas information nodes and compressors, gas sources, power-to-gas equipment, and gas turbines; , and They are the flow rates of gas source, power-to-gas equipment and gas turbine at the last moment respectively; and are the minimum and maximum values ​​of the gas flow provided by the compressor equivalent gas pressure source; and are the minimum and maximum values ​​of the gas production vector of the gas source, respectively; and are the minimum and maximum gas production of the power-to-gas equipment, respectively; and are the minimum and maximum values ​​of gas turbine gas consumption respectively; f. Available resource constraints: Defense resources are limited, and the specific constraints are: (24); Where: is the maximum value of defense resources; Defend physical systems against variables; Defend variables for information systems; For physical lines, including gas pipelines and electric power lines; m For information lines, including natural gas information lines and electricity information lines; is a collection of physical lines; A collection of information lines; Attack resources are limited, and the specific constraints are: (25); Where: is the maximum value of attack resources; Attack variables for physical systems; is the information system attack variable.

2. The method for optimizing the defense of an integrated energy cyber-physical system against deliberate attacks according to claim 1, characterized in that: Step 3 specifically includes: Step 3.1: Determine the objective function of the second-stage attack optimization model: (26); Where: Attack strategies include power line attacks, power information attacks, natural gas pipeline attacks, and natural gas information attacks; For the scheduling strategy, including generator output, gas turbine output, power consumption of power-to-gas equipment and gas production of gas source; The constraints for determining the second-stage attack optimization model are shown in equations (2)-(23) and (25); Step 3.2: Solve the second-stage attack optimization model using duality theory; For the upper attacker in the second-stage attack optimization model, considering the limitation of attack resources, its objective function and constraints are: (27); The lower layer operator constraints are: (28); (29); (30); (31); Where: is the Lagrange multiplier of the equality constraint; is the Lagrange multiplier of the inequality constraint, and its value is greater than 0; All constraints in equations (28) to (29) are transformed into matrices express, Using the matrix Indicates that ; All constraints in formula (30) are represented by matrices express, Using the matrix Indicates that ; All constraints in formula (31) are represented by the set express, Using the matrix Indicates that ; Construct Lagrangian function , and , which are in the following forms: (32); (33); (34); In the formula, and They are respectively a valid electricity information node and a valid natural gas information node; is a collection of power information nodes; It is a collection of natural gas information nodes; In order to satisfy the dual theory conditions, the partial derivative of the Lagrangian function should be 0, then all variables can be expressed as , the Lagrangian function , , Using the matrix If , then the constraint is expressed as: (35); Step 3.3: Convert the second-stage attack optimization model shown in equation (26) into a single-layer model shown in equations (27) to (35), and solve it directly; obtain the optimal attack strategy and the most serious load loss result of the integrated energy information-physical system under a given defense strategy, and compare the load loss result with the currently stored upper limit value to obtain a new upper limit value.

Citation Information

Patent Citations

  • Energy value-based multi-energy collaborative park energy utilization efficiency control method

    CN110298556A

  • Improved method for optimized scheduling of electricity-gas interconnected integrated energy system

    CN115392035A