Cyber-physical system hazard assessment method and system superimposed with new energy fluctuation and data injection attack
By constructing an attack model of new energy fluctuations and data injection attacks and combining it with line load security constraints, the cyber-physical fusion hazards under the superposition of new energy fluctuations and data injection attacks are evaluated, solving the problem of the existing technology failing to effectively combine new energy uncertainty and data injection attacks, and achieving accurate hazard assessment of the power system.
Patent Information
- Application Number
- CN202411983291.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Existing technologies fail to effectively combine the impact of new energy uncertainties and data injection attacks on power systems, resulting in the underestimation of network risks.
An attack model that combines new energy fluctuations and data injection attacks is constructed. By introducing data injection attack vectors and new energy output uncertainty change vectors into line flow, combined with line load security constraints, the hazards of cyber-physical fusion are evaluated.
It achieves accurate modeling and hazard assessment of the superposition of new energy fluctuations and data injection attacks, helping to identify key risk nodes in the power system.
Smart Images

Figure CN119835048B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electric power information security, and in particular to an information-physical fusion hazard assessment method and system for superposition of new energy fluctuations and data injection attacks. Background Art
[0002] Considering the risks that renewable energy uncertainty poses to power systems, existing literature has extensively studied wind power uncertainty. However, existing research on FDIA and wind power generation suffers from a major shortcoming: nearly all approaches to studying FDIA and renewable energy are independent of each other. In other words, FDIA research fails to consider the impact of wind power uncertainty on the system, and studies of renewable energy uncertainty also fail to consider the impact of FDIA cyberattacks on the system. This is clearly inconsistent with the actual risks facing the power grid, as renewable energy sources are increasingly integrated into the grid and the grid becomes increasingly intelligent, posing significant challenges to security protection. Summary of the Invention
[0003] The purpose of the present invention is to provide a cyber-physical fusion hazard assessment method and system for superposition of new energy fluctuation and data injection attacks.
[0004] The purpose of the present invention can be achieved by the following technical solutions:
[0005] A cyber-physical fusion hazard assessment method for superposition of new energy fluctuation and data injection attacks, the method comprising the following steps:
[0006] Construct an attack model that combines renewable energy fluctuations with data injection attacks. This attack model introduces a data injection attack vector and a change vector caused by renewable energy output uncertainty into the power flow.
[0007] By calculating the line load security constraints, the cyber-physical fusion hazards under the superposition of new energy fluctuations and data injection attacks are determined based on the attack model.
[0008] In the attack model, the calculation method of the real line power flow is:
[0009]
[0010] Where SF represents the shift factor matrix, KP represents the bus-generator correlation matrix, represents the generator output power (MW) under attack conditions, represents the wind power output power (MW) under attack, KD represents the bus load correlation matrix, Indicates the line load data under attack, ΔP wis the change vector caused by the uncertainty of renewable energy output, ΔD is the load data injection attack vector, ΔP w is the change vector caused by the uncertainty of renewable energy output, and ΔD is the load data injection attack vector.
[0011] The cyber-physical fusion hazard under the superposition of new energy fluctuations and data injection attacks can be expressed as follows:
[0012] max:|F| / F r
[0013] Among them, F is the real current considering the superposition of new energy fluctuations and data injection attacks, F r Represents the line power flow restriction vector.
[0014] The line load safety constraints include power balance constraints, load attack range constraints, and new energy output fluctuation range constraints.
[0015] The power balance constraint is expressed as:
[0016] 1 T ΔD=1 T ΔP w
[0017] Where ΔP w is the change vector caused by the uncertainty of renewable energy output, and ΔD is the load data injection attack vector.
[0018] The attack range constraint of the payload is expressed as:
[0019]
[0020] in, represents the line load data under attack, ΔD is the load data injection attack vector, and ε represents the load attack amplitude.
[0021] The fluctuation range constraint of the new energy output is expressed as:
[0022]
[0023] in, Indicates the wind power output power under attack conditions, ΔP w is the change vector caused by the uncertainty of the new energy output, and δ represents the predicted attack amplitude of the new energy.
[0024] The value of the predicted attack amplitude δ of the new energy is determined according to the accuracy of the new energy prediction. The higher the accuracy, the smaller the δ value.
[0025] Generator output power under the attack scenario Wind power output in attack situation The value is calculated using a conventional SCED model.
[0026] A new energy fluctuation and data injection attack superposition information physical fusion hazard evaluation system for realizing the method as described above, the system comprises:
[0027] An attack model construction module: constructing an attack model of new energy fluctuation and data injection attack superposition, the attack model introduces a data injection attack vector and a change vector caused by new energy output uncertainty in line flow;
[0028] A hazard evaluation module: based on the attack model, the hazard of information physical fusion under the superposition of new energy fluctuation and data injection attack is determined through the calculation of line load safety constraints.
[0029] Compared with the prior art, the present application has the following beneficial effects:
[0030] (1) The present application gives a modeling method of superimposed attack of new energy fluctuation uncertainty and malicious data injection attack in the environment of power grid information physical fusion, which can accurately model new energy fluctuation uncertainty and malicious data injection attack.
[0031] (2) The present application realizes information physical fusion hazard evaluation to determine the hazard level of power grid ontology caused by superimposed attack of new energy output uncertainty and malicious data attack in the worst case, and the evaluation result can help operation and maintenance personnel to find the key risk nodes in the power system. BRIEF DESCRIPTION OF DRAWINGS
[0032] Figure 1 The flow chart of the information physical fusion hazard evaluation method of the present application;
[0033] Figure 2 The schematic diagram of power grid dispatching model;
[0034] Figure 3 The schematic diagram of line overload mechanism under the combined action of FDIA and new energy uncertainty. DETAILED DESCRIPTION
[0035] The present application will be described in detail below in combination with the drawings and specific embodiments. The present embodiment is implemented on the premise of the technical solution of the present application, and gives detailed implementation mode and specific operation process, but the protection scope of the present application is not limited to the following examples.
[0036] The embodiment provides a new energy fluctuation and data injection attack superposition information physical fusion hazard evaluation method, first, the malicious data injection attack means of the power system under the new energy scene is modeled. Secondly, from the perspective of information physical fusion attack, the hazard evaluation method of the power line physical overload caused by the malicious data injection attack. Next, the attack model under the superposition of new energy output fluctuation uncertainty and malicious data injection attack is given. Finally, through the calculation of the line load safety constraint, the hazard evaluation method of the line overload caused by the superposition of the two is given, and the hazard quantitative evaluation under the information physical fusion attack is realized.
[0037] Specifically, as shown in the figure, Figure 1 The method comprises the following steps:
[0038] S1, an attack model of new energy fluctuation and data injection attack superposition is constructed, and the attack model introduces a data injection attack vector and a change vector caused by new energy output uncertainty in line flow.
[0039] In the application, under normal circumstances without network attack, the power dispatching strategy (such as thermal power output power Pg and new energy output power Pw) is usually determined by the safety-constrained economic dispatching SCED model. In Figure 2 , the thermal power generation output Pg and the predicted flow F are predicted based on the new energy output power Pw and the load data D, so as to form the power grid dispatching strategy and the flow F also satisfies the system safety constraint. However, the new energy output power Pw and the load data D are obtained by smart meter measurement and can be maliciously tampered with by network attackers. In this case, the flow F will be affected by the attack, and the safety constraint may be violated. In Figure 2 , the flow F represents the error power flow caused by the error data of ΔPw and ΔD.
[0040] Based on the above premise, the embodiment first constructs an FDIA attack model.
[0041] Considering the case that the FDIA malicious data injection attack alone causes harm, the entire FDIA attack process is constructed as shown in the figure, Figure 3 Firstly, the attacker obtains the smart meter measurement value by illegal means. Secondly, the attacker carefully designs the false data and injects it into the measurement value of the smart meter, and ensures that the false data bypasses the detection of the BDD. Then, the error dispatching strategy is induced by the dispatching center. Finally, the error dispatching strategy will cause serious line overload, so as to achieve the purpose of the attacker.
[0042] In this attack, the attacker usually selects a random attack vector to construct a false injection value, in order to bypass the BDD, the load attack vector is usually limited in a certain range, and is designed as a vector with a zero sum, and the formula is as follows:
[0043] 1 T ·ΔD=0 (1)
[0044] -ε·D≤ΔD≤ε·D (2)
[0045] where D denotes the line load data, ΔD is the load data injection attack vector, and ε represents the attack amplitude of the load.
[0046] When the constraint condition (1) is satisfied, the false measurement value constructed by the FDIA attacker can ensure that the system maintains power balance. Constraint (2) limits the level of load data injection on each line, and a larger ε value indicates that the attacker can induce a more serious attack.
[0047] Under the influence of the constructed attack vector ΔD, the line flow will be modified and rewritten as:
[0048] F=SF·(KP·(P g +P w )-KD·(D+ΔD)) (3)
[0049] -F r ≤F≤F r (4)
[0050] where SF denotes the shift factor matrix, KP denotes the bus-generator association matrix, P g represents the generator output power (MW), P w represents the wind power output power (MW), and KD represents the bus load association matrix. Because the line flow in equation (3) is calculated based on the damaged load vector D+ΔD, constraint (4) will safely constrain the false flow vector F. In other words, the safety of the actual line flow cannot be guaranteed.
[0051] Since the real load vector is D, the real line flow F 0 is:
[0052] F 0 =SF·(KP·(p g +p w )-KD·D) (5)
[0053] By introducing equation (5) to equation (3), we obtain:
[0054] -F r +SF·KD·ΔD≤F 0 ≤F r +SF·KD·ΔD (6)
[0055] In formula (6), it can be seen that due to the influence of the false injection data SF·KD·ΔD, the upper and lower limits of the real power flow may exceed the line power flow limit vector F r , and the degree of harm can be calculated.
[0056] On the other hand, as the proportion of renewable energy generation connected to the power system increases, the uncertainty of large amounts of renewable energy output may also cause some lines to overload. This is mainly due to the strong randomness and variability of renewable energy output. The range of renewable energy generation can vary by 20% within 10 minutes, making renewable energy output data difficult to accurately predict.
[0057] However, existing research has not considered the cyber-physical convergence hazards brought about by the combined effects of FDIA attacks and renewable energy output uncertainty, potentially underestimating cyber risks. This paper investigates the cyber risks of power systems with high renewable energy penetration by considering FDIA target loads and predicted renewable energy generation data. Figure 3 The principle of line overload caused by FDIA-DW is explained. Based on formula (3), it is assumed that there is another change vector ΔP caused by the uncertainty of renewable energy output. w Added to the system to produce an impact, the actual line flow F 0 Expressed as:
[0058]
[0059] Where ΔP w is the change vector caused by the uncertainty of new energy output.
[0060] Therefore, constraint (6) is rewritten as:
[0061]
[0062] Constraint (8) shows that due to the error data SF·KD·ΔD and SF·KP·ΔP w , the real trend vector F 0 The line power flow limit vector F may be exceeded r Given the attacks on renewable energy generation data, FDIA will lead to more severe line overloads in the power grid.
[0063] Based on the above analysis, in order to accurately predict and assess the degree of damage caused by the combined effects of injection attacks and renewable energy output uncertainty, this paper develops a linear programming model to assess the line overload damage caused by FDIA-DW, as follows:
[0064] max:|F| / F r (9)
[0065]
[0066] Among them, F is the real current considering the superposition of new energy fluctuations and data injection attacks, represents the generator output power (MW) under attack conditions, represents the wind power output power (MW) under attack conditions, Indicates line load data under attack conditions. and The value of is calculated using the traditional SCED model. Equation (9) represents the maximum overload level of each line in the system caused by FDIA-DW. Equation (10) represents the actual power flow on each line.
[0067] S2, through the calculation of line load security constraints, determines the cyber-physical fusion hazards under the superposition of new energy fluctuations and data injection attacks based on the attack model.
[0068] Line load security constraints include power balance constraints, load attack range constraints, and renewable energy output fluctuation range constraints, which can be expressed as:
[0069] 1 T ΔD=1 T ΔP w (11)
[0070]
[0071] The parameters ε and δ represent the attack range of the load and predicted renewable energy, respectively. Generally, high-precision renewable energy predictions correspond to smaller δ values, while low-precision renewable energy predictions correspond to larger δ values. Equation (11) ensures power balance in the system, while Equations (12) and (13) limit the attack range of the load and the fluctuation range of renewable energy output.
[0072] This assessment model can determine the maximum overload level under the worst-case scenario for FDIA-DW and analyze the deep relationship between network risk and renewable energy generation penetration.
[0073] The above is an introduction to the method embodiment. The following further illustrates the solution of the present invention through a system embodiment.
[0074] This embodiment further provides a cyber-physical fusion hazard assessment system for superposition of new energy fluctuation and data injection attacks, for implementing the above-mentioned method, the system comprising:
[0075] Attack model construction module: Constructs an attack model that combines new energy fluctuations with data injection attacks. The attack model introduces a data injection attack vector and a change vector caused by uncertainty in new energy output into the line power flow.
[0076] Hazard assessment module: By calculating line load security constraints, the cyber-physical fusion hazards under the superposition of new energy fluctuations and data injection attacks are determined based on the attack model.
[0077] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the described module can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.
[0078] The above describes in detail the preferred embodiments of the present invention. It should be understood that those skilled in the art can make numerous modifications and variations based on the concepts of the present invention without inventive effort. Therefore, any technical solutions that can be derived by those skilled in the art through logical analysis, reasoning, or limited experimentation based on the concepts of the present invention and the prior art should be within the scope of protection defined by the claims.
Claims
1. A cyber-physical fusion hazard assessment method for superposition of new energy fluctuation and data injection attacks, characterized in that: The method comprises the following steps: An attack model combining renewable energy fluctuations and data injection attacks is constructed. The attack model introduces a data injection attack vector and a change vector caused by renewable energy output uncertainty into the line flow. In the attack model, the calculation method for the real line flow is: in, represents the shift factor matrix, represents the bus-generator correlation matrix, represents the generator output power under attack, represents the wind power output power under attack conditions, represents the bus load correlation matrix, Indicates line load data under attack conditions, is the change vector caused by the uncertainty of new energy output, Provides a payload data injection attack vector; By calculating line load security constraints, the cyber-physical fusion hazards under the superposition of renewable energy fluctuations and data injection attacks are determined based on attack models. The line load security constraints include power balance constraints, load attack range constraints, and renewable energy output fluctuation range constraints. The power balance constraint is expressed as: in, is the change vector caused by the uncertainty of new energy output, Provides a payload data injection attack vector; The attack range constraint of the payload is expressed as: in, Indicates line load data under attack conditions, For payload data injection attack vector, Indicates the attack amplitude of the load; The fluctuation range constraint of the new energy output is expressed as: in, represents the wind power output power under attack conditions, is the change vector caused by the uncertainty of new energy output, Indicates the predicted attack amplitude of new energy.
2. The cyber-physical fusion hazard assessment method for superposition of new energy fluctuation and data injection attacks according to claim 1 is characterized in that: The cyber-physical fusion hazard under the superposition of new energy fluctuations and data injection attacks can be expressed as follows: max: in, F In order to consider the real trend of new energy fluctuations and data injection attacks, Represents the line power flow restriction vector.
3. The cyber-physical fusion hazard assessment method for superposition of new energy fluctuation and data injection attacks according to claim 1 is characterized in that: The predicted attack range of new energy The value is determined by the accuracy of new energy prediction. The higher the accuracy, The smaller the value.
4. The cyber-physical fusion hazard assessment method for superposition of new energy fluctuation and data injection attacks according to claim 1 is characterized in that: Generator output power under the attack scenario Wind power output power under attack conditions The value of is calculated using the traditional SCED model.
5. A cyber-physical fusion hazard assessment system for superposition of new energy fluctuation and data injection attacks, characterized in that: For implementing the method according to any one of claims 1 to 4, the system comprises: Attack model construction module: Constructs an attack model that combines new energy fluctuations with data injection attacks. The attack model introduces a data injection attack vector and a change vector caused by uncertainty in new energy output into the line power flow. Hazard assessment module: By calculating line load security constraints, the cyber-physical fusion hazards under the superposition of new energy fluctuations and data injection attacks are determined based on the attack model.
Citation Information
Patent Citations
Power grid information physical security risk detection method based on three-layer model
CN111404915A
Method for detecting, isolating and eliminating false data injection attack of micro-grid system
CN115766062A