Cyber-physical system resilience evaluation method for ac-dc hybrid power system under coordinated attack
By establishing a multidimensional heterogeneous model and correlation matrix modeling, a cascaded fault model of an AC/DC hybrid power cyber-physical system is constructed, and the CFRI index is proposed, which solves the problem of insufficient system resilience assessment in existing technologies and achieves more accurate assessment and recovery capability analysis.
Patent Information
- Application Number
- CN202411935274.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-12-26
AI Technical Summary
Existing technologies lack consideration for nonlinear response, comprehensiveness, and dynamism when assessing the resilience of AC/DC hybrid power cyber-physical systems, resulting in an inability to accurately assess the system's vulnerability and resilience in the face of malicious cyberattacks or cyber-physical coordinated attacks.
A multidimensional heterogeneous model of an AC/DC hybrid power cyber-physical system is established. Cyber-physical collaborative attacks are carried out through the correlation matrix modeling method to construct a cascading fault model. The Chain Fault Recovery Index (CFRI) is proposed as a comprehensive evaluation index to reflect the system's recovery capability in cascading faults.
It improves the accuracy of resilience assessment and recovery capability assessment of AC/DC hybrid power cyber-physical systems in the face of coordinated attacks, and can more comprehensively and dynamically reflect the overall resilience level of the system, reducing the impact of attacks.
Smart Images

Figure CN119891412B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system resilience assessment, and in particular to a method for assessing the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks. Background Art
[0002] As traditional power grids continue to transform into smart grids, building intelligent, efficient, secure, and stable new power systems has become an inevitable trend. The widespread introduction of intelligent electronic devices has deeply integrated communication network systems with power-physical systems, forming power cyber-physical systems (CPSs). This not only improves power system efficiency but also facilitates coordinated control, allocation, dispatch, and unified management of regional power grids. The fast start-stop, rapid power control, power reversal, and short-circuit current limiting capabilities of DC transmission systems significantly enhance the voltage stability and power control capabilities of AC systems, reducing transmission losses while increasing transmission distances. These advantages have led to a growing number of high-capacity, long-distance, cross-regional DC interconnection lines in recent power grid construction, and AC / DC power systems have been widely adopted and promoted in modern power networks. Multi-hybrid transmission methods and heterogeneous networks not only bring development opportunities and opportunities to new smart grids, but also pose multiple challenges to the reliability and stability of AC / DC hybrid CPSs.
[0003] With the commissioning of large-scale DC transmission lines, operational faults on the AC side could cause the DC line to lock out and shut down, exacerbating the spread of faults. Furthermore, the propagation of inter-network faults caused by deep cyber-physical coupling could also increase the risk of major blackouts. Therefore, it is necessary to conduct resilience assessments on AC / DC hybrid power cyber-physical systems to clarify the system's resilience threshold to potential cascading failures. This will provide a reliable basis for addressing potential issues in the new power grid, formulating security resource allocation strategies, and establishing a new grid protection system. Summary of the Invention
[0004] The purpose of the present invention is to overcome the shortcomings and deficiencies of the existing technology and provide a method for assessing the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks. A multidimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established based on the actual information network architecture, and matrix modeling of the AC / DC hybrid power cyber-physical system is completed using the correlation matrix method. A cyber-physical coordinated attack is then constructed based on the matrix modeling method, enabling diversified coordinated attacks to be carried out on the established multidimensional heterogeneous model of the AC / DC hybrid power cyber-physical system, causing cascading faults to spread. Finally, a new resilience indicator, the cascading failure recovery index (CFRI), is proposed. This indicator takes into account factors such as the number of nodes, number of branches, and load in the system during cascading fault propagation to evaluate the decoupling and recovery capabilities of the AC / DC hybrid power cyber-physical system in the face of cascading faults. This completes the resilience assessment of the power cyber-physical system under coordinated attacks, minimizing the impact of attackers on the power grid.
[0005] To achieve the above objectives, the present invention provides a technical solution: a method for assessing the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks, comprising the following steps:
[0006] S1. Based on the characteristics of the AC / DC hybrid power cyber-physical system, which has a high degree of coupling between the information side and the physical side and frequent bidirectional information interaction, a multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established. This model reflects the coupling characteristics between the information side and the physical side of the AC / DC hybrid power cyber-physical system. Based on the modeling method of the correlation matrix, the intra-layer information transmission and inter-layer information interaction between the information side and the physical side are modeled in detail to improve the accuracy of the model.
[0007] S2. Based on the multi-dimensional heterogeneous model established in step S1, a cyber-physical collaborative attack is developed using a correlation matrix modeling method. This attack can be launched during the measurement information collection phase and control command issuance phase of the AC / DC hybrid power cyber-physical system, resulting in local unobservability and uncontrollability effects in the AC / DC hybrid power cyber-physical system. Launching a collaborative attack on the constructed multi-dimensional heterogeneous model can lead to the occurrence, propagation, and aggravation of cascading failures.
[0008] S3. Based on the multi-dimensional heterogeneous model established in step S1 and the cyber-physical coordinated attack established in step S2, a cascading failure model of the AC / DC hybrid power cyber-physical system is established. This model can accurately reflect the evolution of the cascading failure by using relevant parameters of the AC / DC hybrid power cyber-physical system under cascading failures, including the number of lost nodes, the number of lost branches, the amount of lost load, and the size and status of the subsystem.
[0009] S4. A "cascading failure recovery index" is proposed as a comprehensive evaluation indicator. This index takes into account the system scale and load level of the AC / DC hybrid power cyber-physical system during the cascading failure recovery process to evaluate the resilience and recovery capability of the AC / DC hybrid power cyber-physical system in the face of cascading failures.
[0010] Furthermore, the specific operation steps of step S1 are as follows:
[0011] S11. Considering the information interaction tasks between the information side and the physical side of the AC / DC hybrid power cyber-physical system, including data uploading and command issuance, a multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established based on the information network architecture of hierarchical power grid control. The model includes a control layer, an interval layer, and a processing layer. The control layer is composed of a monitor host, a remote control interface, and a remote monitoring interface, and is responsible for real-time monitoring of the operating status of the AC / DC hybrid power cyber-physical system. The interval layer is composed of intelligent electronic devices, including relay devices and control switches, and is responsible for processing data uploaded by the processing layer and commands issued by the control layer. The processing layer uses intelligent monitoring terminals and intelligent dispatching terminals to monitor, manage, and coordinate power plants, converter stations, and transmission lines of the AC / DC hybrid power cyber-physical system.
[0012] S12. Use the correlation matrix modeling method to build a coupling model of the information side and the physical side. The model includes the system topology, state transition process, control strategy transmission and information exchange process. The system modeling process for n physical nodes, k intelligent electronic device nodes and m information monitoring nodes is as follows:
[0013] S121. Model the nodes within the layer to obtain the interval layer node model: Use the tuple model to describe the functional characteristics of each layer node. For the interval layer node, the i-th node is modeled as:
[0014] S ii =[F sii ,P sii (F sii ),T sii (F sii ),…]
[0015] Where S ii is the i-th node model in the interval layer, F sii Information processing algorithms for intelligent electronic devices, including data packet parsing F 1s , Data Processing 2s and data packet encryption F 3s , denoted as F sii =F 1s *F 2s *F 3s ...;P sii With T siiare the error probability and delay in the information processing process, and the information processing algorithm F sii related;
[0016] S122, modeling the intra-layer branch to obtain the interval layer branch model: Each layer network model reflects the information exchange of nodes within the layer. The intra-layer branch performance tuple between nodes i and j is expressed as: S ij =[B ij ,P ij ,T ij ,…], where S ij is the branch model between node i and node j, B ij Indicates communication interruption state, P ij With T ij are the error probability and delay in information transmission, respectively;
[0017] S123, intra-layer network modeling, to obtain an intra-layer network model: Based on the bay layer node model established in step S121 and the bay layer branch model established in step S122, the intra-layer network model is represented by a correlation characteristic matrix S:
[0018]
[0019] Where S ij is the branch model between node i and node j. If i = j, it corresponds to the bay layer node. If i ≠ j, it corresponds to the bay layer branch. k is the total number of intelligent electronic device nodes in the bay layer.
[0020] S124, inter-layer coupling modeling: The intra-layer network model of the spacer layer is interconnected with the intra-layer network model of the control layer. In order to describe the relationship between the intelligent electronic device uploading information to the monitoring node and issuing instructions, the correlation characteristic matrix S from the spacer layer to the control layer is established. C :
[0021]
[0022] Where, Describes the coupling relationship between the interval layer nodes and the control layer nodes, The communication from the bay layer to the control layer is interrupted; is the error probability of communication from the bay layer to the control layer; The communication delay from the bay layer to the control layer;
[0023] Based on the above modeling, a multi-dimensional heterogeneous model including the control layer, the interval layer and the processing layer can be constructed. The model not only includes the node and network models of each layer, but also includes the correlation characteristic matrix between each layer. Specifically, the correlation characteristic matrix P from the processing layer to the interval layer S , the correlation characteristic matrix S from the interval layer to the processing layer P, the correlation characteristic matrix S from the interval layer to the control layer C And the correlation characteristic matrix C from the control layer to the interval layer S , which can clearly show the information flow and interactive coupling between the information side and the physical side; the information transmission between different layers is calculated through the correlation matrix, and the control layer sends control instructions to the interval layer through C*C S *S, where C is the control layer network correlation characteristic matrix, C S is the inter-layer correlation characteristic matrix from the control layer to the spacer layer, and S is the network correlation characteristic matrix of the spacer layer.
[0024] Furthermore, in step S2, the cyber-physical coordinated attack consists of two parts: information attack and physical attack. The information attack includes attack A on the AC / DC branch status information upload channel. u and attacks on the generator and load adjustment command issuing channel A d , where A u Uplink channel attack, A d Downstream channel attack; the physical attack is an attack on the AC / DC branch circuit breaker equipment. l The coordinated attack is launched through a physical attack, which controls the opening and closing of the branch by tampering with the state of the branch circuit breaker. In the AC / DC hybrid power cyber-physical system, the AC / DC branches belong to the physical layer, and the circuit breaker equipment is the processing layer node. The two have a one-to-one correspondence. Therefore, the physical attack can be expressed as:
[0025] P a =P×A l =[B Pij ×A lij ,P Pij ,T Pij ,…]
[0026] Where A l is the attack matrix for the circuit breaker device at the processing layer, where the vector A lij =[A Pij ,1,1,…],A Pij is the attack vector against the communication interruption state; P and P a are the branch correlation matrices of the processing layer or physical layer before and after the attack, respectively. Pij 、P Pij 、T Pij They are the communication interruption status of the processing layer, the error probability and delay in the information transmission process; if B Pij =1, B Pij ×A lij = 0, it means that the branch between node i and node j is attacked and disconnected; if B Pij ×A lij =1, it means the branch is not attacked;
[0027] The uplink channel attack and downlink channel attack on the information side are launched by injecting attack vectors into the inter-layer correlation characteristic matrix; the attack A on the uplink channel of AC and DC branch status information u It is the correlation matrix P from the processing layer to the interval layer S The specific forms of the launch are:
[0028] S a =P×P a S × S = P × (P S ×A u )×S
[0029] Where A u is the attack matrix for the uplink channel from the processing layer to the spacer layer, P a S =P S ×A u is the correlation characteristic matrix from the processing layer to the interval layer after the attack; S and S a They are the network correlation characteristic matrices of the spacer layer before and after the attack. The branch status information received by the spacer layer is collected by the processing layer and then transmitted to the spacer layer through the correlation characteristic matrix of the processing layer to the spacer layer. The upstream channel information attack injected during this period will change the original matrix P S The communication error probability in the attack layer matrix S a Receiving wrong information affects the judgment of the control layer;
[0030] Attack A on the generator and load adjustment command channel d The attack principle is similar to A u Similarly, by calculating the inter-layer correlation characteristic matrix S from the interval layer to the processing layer P Attack and tamper with the generator's adjustment instructions to achieve the attack effect.
[0031] Furthermore, the specific operation steps of step S3 are as follows:
[0032] S31. Based on the constructed multi-dimensional heterogeneous model and cyber-physical coordinated attack, a cascading failure model of the AC / DC hybrid power cyber-physical system is established. The specific situation is as follows:
[0033] First, a basic fault is set based on the probability model of disturbance events. The grid power distribution under the fault is calculated based on the AC / DC grid power flow. When a branch exceeds the limit, whether the branch is disconnected is related to the degree of its limit violation. When the degree to which the branch power exceeds the threshold is within the allowable range, it can be maintained for a short time. When the threshold is exceeded but not within the allowable range, an emergency control action is triggered, and the branch is immediately disconnected. Therefore, the spread of cascading faults may cause the decoupling of the AC / DC hybrid power cyber-physical system.
[0034] In the cascading failure model, there are also channels for information uploading and command issuance. Information-side attacks may attack the information transmitted in this channel to achieve a synergistic effect, exacerbating the spread of cascading failures. Each evolution of the AC / DC hybrid power cyber-physical system has three situations: maintaining a single system, splitting into multiple subsystems, and completely splitting. When the first two situations occur, it is necessary to record the resilience assessment indicators of the AC / DC hybrid power cyber-physical system and continue to evolve until the AC / DC hybrid power cyber-physical system can be fully stabilized or completely split.
[0035] Whenever a power device is taken offline, the AC / DC power flow calculation is first used to determine the power flow distribution of the entire AC / DC hybrid power cyber-physical system. If there are still devices in the system that may fail, the AC / DC power grid emergency control model is used to calculate the generator power adjustment and load reduction for each power node. During the process of uploading measurement data and issuing control instructions, the risk of cross-domain fault propagation caused by secondary attacks on the information side is considered, which can fully reflect the occurrence of disturbance events and state transition processes under network attacks.
[0036] S32. It is proposed to use the AC linearization method to construct an AC / DC power grid emergency control model. When a disturbance event caused by a cyber attack occurs, the AC / DC hybrid power cyber-physical system is maintained in a safe and stable operation through adjustment processing, load shedding, and generator disconnection measures. The optimization control objective function of the AC / DC power grid emergency control model is:
[0037]
[0038] Where ΔP di , ΔP gj are the power regulation of load node i and generator node j respectively, N b' 、N g are the load and the number of generators respectively; the constraints of the AC / DC grid emergency control model include active power transmission constraints, node voltage amplitude constraints, generator power regulation constraints and maximum load reduction constraints.
[0039] Furthermore, the specific operation steps of step S4 are as follows:
[0040] S41. The fault evolution process of an AC / DC hybrid power cyber-physical system after an attack can be represented by the resilience system recovery process. Based on the resilience system evaluation theory, a cascading failure recovery index (CFRI) is proposed to reflect the system response of an AC / DC hybrid power cyber-physical system after an attack. The expression is:
[0041]
[0042] Where α is the scale stability factor; β is the performance stability factor; N b 、N acl 、N dcl are the total number of nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system, respectively. The total number of nodes of the AC / DC hybrid power cyber-physical system includes load nodes and generator nodes; N b,x 、N acl,x 、N dcl,x are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x; N b,x-1 、N acl,x-1 、N dcl,x-1 are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x-1; L x , L all are the load and total load of the AC / DC hybrid power cyber-physical system at the evolution time x; ω1, ω2, and ω3 are the node influence factor, AC branch influence factor, and DC branch influence factor, respectively; is a function for calculating the scale of the AC / DC power grid. Since the scale of the AC / DC hybrid power cyber-physical system, including nodes, branches, and load, is taken into account, the changes in the system scale and load of the AC / DC hybrid power cyber-physical system from fault propagation to disconnection after a cascading fault occurs are quantified, reflecting the evolution of the fault in the AC / DC hybrid power cyber-physical system. This indicator can be used as an indicator for comprehensively evaluating the disconnection process of cascading faults and assessing the recovery capability of the AC / DC hybrid power cyber-physical system in the face of cascading faults.
[0043] S42. To more quickly evaluate the CFRI changes and robustness of AC / DC hybrid power cyber-physical systems after being attacked, we improved on the basis of CFRI and used the CFRI area model to score the CFRI level of AC / DC hybrid power cyber-physical systems. The CFRI area model formula is as follows:
[0044]
[0045] Where R is the robustness index of the CFRI curve; T is the evolution time; t0 is the simulation start time, t r is the moment when the AC / DC hybrid power cyber-physical system recovers stability, that is, the AC / DC hybrid power cyber-physical system no longer experiences disconnection or load loss; CFRI(t) is the cascade disconnection resilience index curve of the AC / DC hybrid power cyber-physical system, which depicts the change of the cascade disconnection index of the AC / DC hybrid power cyber-physical system from being attacked to recovering stability.
[0046] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0047] Existing resilience indicators include load resilience and energy storage resilience. These resilience indicators generally help assess the robustness, adaptability, and reliability of power systems. However, when faced with malicious cyber attacks or cyber-physical coordinated attacks, these indicators have several problems:
[0048] 1. Lack of consideration for nonlinear responses: Current resilience metrics are often based on the assumption of linear response, meaning that the system's response changes proportionally. However, in the presence of large-scale attacks or extreme situations, the system may exhibit nonlinear responses, such as system crashes or cascading failures. Current resilience metrics fail to accurately capture these nonlinear reactions and may underestimate the system's vulnerability.
[0049] 2. Lack of comprehensiveness: Current resilience indicators are typically single or partial, failing to comprehensively assess the resilience of the entire system. Power system resilience encompasses multiple aspects, including supply and demand balance, system stability, and resilience. Considering these aspects allows for a more accurate assessment of the overall resilience of the system.
[0050] 3. Lack of Dynamics: Current power system resilience indicators are typically derived from static system models and historical data. However, the power system is a dynamic model, and its state and conditions may change over time. Existing resilience indicators fail to fully account for this dynamic nature and cannot accurately reflect the system's resilience under different operating conditions.
[0051] To address the above issues, this paper studies the resilience assessment of AC / DC hybrid power cyber-physical systems, which will effectively fill this gap in the field and provide a reference for research and development in this direction. The contributions of this paper are summarized as follows:
[0052] 1. A multidimensional heterogeneous model of an AC / DC hybrid power cyber-physical system was established, reflecting the coupling characteristics between the cyber and physical sides. Based on the correlation matrix approach, hierarchical matrix modeling and inter-layer interaction matrix modeling were applied to the cyber network to improve the model's accuracy.
[0053] 2. The cyber-physical collaborative attack developed based on the matrix modeling method can launch attacks during the measurement information collection and control command issuance stages, resulting in local unobservable and uncontrollable effects in the system.
[0054] 3. A cascading failure model for AC / DC hybrid power cyber-physical systems was established, which can accurately reflect the evolution of cascading failures through parameters such as the number of lost nodes, the number of lost branches, the amount of lost load, and the size and status of subsystems, paving the way for resilience assessment.
[0055] 4. A comprehensive resilience evaluation metric called cascading failure recovery index (CFRI) is proposed, which broadly considers the system scale and load level during the cascading failure recovery process. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 Schematic diagram of the multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system.
[0057] Figure 2 Schematic diagram of the cascading failure model of the AC / DC hybrid power cyber-physical system.
[0058] Figure 3 Schematic diagram of resilience assessment of AC / DC hybrid power cyber-physical system under cascading failures. DETAILED DESCRIPTION
[0059] The present invention will be described in further detail below with reference to the embodiments and drawings, but the embodiments of the present invention are not limited thereto.
[0060] This embodiment discloses a method for assessing the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks, the details of which are as follows:
[0061] According to the characteristics of the AC / DC hybrid power cyber-physical system with high coupling between the information side and the physical side and frequent two-way information interaction, a multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established. Figure 1 shown.
[0062] Depend on Figure 1As can be seen, the multi-dimensional heterogeneous model consists of a four-layer architecture. The bottom layer is the physical layer, which includes power equipment such as power plants, substations, converters, AC transmission lines, DC transmission lines, and loads. The information network is a three-layer architecture. The top layer is the control layer, which is the key component responsible for system monitoring and control. The control layer consists of a monitor host, a remote control interface, and a remote monitoring interface. The monitor host is the core component of the control layer and is responsible for real-time monitoring of the power system's operating status, parameters, and performance. The remote control interface is used to remotely control various devices and components in the power system and provides the ability to communicate with remotely controlled devices in the power system (such as switches, circuit breakers, and transformers). The remote monitoring interface is used to communicate and exchange data with the remote monitoring system and provides the ability to transmit system monitoring data to a remote monitoring center or other relevant entities. The second layer is the bay layer, which consists of multiple intelligent electronic devices, including intelligent relays, intelligent protection devices, and intelligent switches. It is responsible for processing data uploaded by the process layer and control commands issued by the control layer. The third layer is the process layer, which is connected to the physical layer and primarily functions to monitor, manage, and coordinate various subsystems and equipment in the power system. Intelligent electronic terminals are key components of the process layer, including intelligent monitoring terminals, intelligent dispatching terminals, etc., which are used for real-time monitoring, data collection, operation dispatch, optimization management and regulation of various subsystems and equipment in the power system.
[0063] The coupling model between the information and physical sides is constructed using an association matrix modeling approach. This model includes the system topology, state transitions, control strategy transfer, and information exchange. The system modeling process for n physical nodes, k intelligent electronic device nodes, and m information monitoring nodes is as follows (because the modeling principles for nodes and branches within different layers, as well as for coupling between layers, are similar, the bay layer modeling and the bay layer to control layer coupling modeling are used as examples):
[0064] 1) Modeling of nodes within the layer to obtain the interval layer node model: A tuple model is used to describe the functional characteristics of each layer node. For the interval layer node, the i-th node is modeled as:
[0065] S ii =[F sii ,P sii (F sii ),T sii (F sii ),…]
[0066] Where S ii is the i-th node model in the interval layer, F sii Information processing algorithms for intelligent electronic devices, including data packet parsing F 1s , Data Processing 2s and data packet encryption F 3s , denoted as F sii=F 1s *F 2s *F 3s ...;P sii With T sii are the error probability and delay in the information processing process, and the information processing algorithm F sii related;
[0067] 2) Intra-layer branch modeling, obtaining the interval layer branch model: Each layer network model reflects the information exchange of nodes within the layer, and the intra-layer branch performance tuple between nodes i and j is expressed as: S ij =[B ij ,P ij ,T ij ,…], where S ij is the branch model between node i and node j, B ij Indicates communication interruption state, P ij With T ij are the error probability and delay in information transmission, respectively;
[0068] 3) Intra-layer network modeling to obtain an intra-layer network model: Based on the bay layer node model established in step S121 and the bay layer branch model established in step S122, the intra-layer network model is represented by a correlation characteristic matrix S:
[0069]
[0070] Where S ij is the branch model between node i and node j. If i = j, it corresponds to the bay layer node. If i ≠ j, it corresponds to the bay layer branch. k is the total number of intelligent electronic device nodes in the bay layer.
[0071] 4) Interlayer coupling modeling: The intra-layer network model of the spacer layer is interconnected with the intra-layer network model of the control layer. In order to describe the relationship between the intelligent electronic device uploading information to the monitoring node and issuing instructions, the correlation characteristic matrix S from the spacer layer to the control layer is established. C :
[0072]
[0073] Where, Describes the coupling relationship between the interval layer nodes and the control layer nodes, The communication from the bay layer to the control layer is interrupted; is the error probability of communication from the bay layer to the control layer; It is the communication delay from the bay layer to the control layer.
[0074] Based on the above modeling, a multi-dimensional heterogeneous model including the control layer, the interval layer and the processing layer can be constructed. The model not only includes the node and network models of each layer, but also includes the correlation characteristic matrix between each layer. Specifically, the correlation characteristic matrix P from the processing layer to the interval layer S , the correlation characteristic matrix S from the interval layer to the processing layer P , the correlation characteristic matrix S from the interval layer to the control layer C And the correlation characteristic matrix C from the control layer to the interval layer S , which can clearly show the information flow and interactive coupling between the information side and the physical side; the information transmission between different layers is calculated through the correlation matrix, and the control layer sends control instructions to the interval layer through C*C S *S, where C is the control layer network correlation characteristic matrix, C S is the inter-layer correlation characteristic matrix from the control layer to the spacer layer, and S is the network correlation characteristic matrix of the spacer layer.
[0075] The cyber-physical coordinated attack consists of two parts: information attack and physical attack. The information attack includes the attack on the AC / DC branch status information upload channel. u and attacks on the generator and load adjustment command issuing channel A d , where A u Uplink channel attack, A d Downstream channel attack; physical attack is an attack on AC / DC branch circuit breaker equipment. l The coordinated attack is launched through a physical attack, which controls the opening and closing of the branch by tampering with the state of the branch circuit breaker. In the AC / DC hybrid power cyber-physical system, the AC / DC branches belong to the physical layer, and the circuit breaker equipment is the processing layer node. The two have a one-to-one correspondence. Therefore, the physical attack can be expressed as:
[0076] P a =P×A l =[B Pij ×A lij ,P Pij ,T Pij ,…]
[0077] Where A l is the attack matrix for the circuit breaker device at the processing layer, where the vector A lij =[A Pij ,1,1,…],A Pij is the attack vector against the communication interruption state; P and P a are the branch correlation matrices of the processing layer or physical layer before and after the attack, respectively. Pij 、P Pij 、T Pij They are the communication interruption status of the processing layer, the error probability and delay in the information transmission process; if BPij =1, B Pij ×A lij = 0, it means that the branch between node i and node j is attacked and disconnected; if B Pij ×A lij =1, it means the branch is not attacked;
[0078] The uplink channel attack and downlink channel attack on the information side are launched by injecting attack vectors into the inter-layer correlation characteristic matrix; the attack A on the uplink channel of AC and DC branch status information u It is the correlation matrix P from the processing layer to the interval layer S The specific forms of the launch are:
[0079] S a =P×P a S × S = P × (P S ×A u )×S
[0080] Where A u is the attack matrix for the uplink channel from the processing layer to the spacer layer, P a S =P S ×A u is the correlation characteristic matrix from the processing layer to the interval layer after the attack; S and S a They are the network correlation characteristic matrices of the spacer layer before and after the attack. The branch status information received by the spacer layer is collected by the processing layer and then transmitted to the spacer layer through the correlation characteristic matrix of the processing layer to the spacer layer. The upstream channel information attack injected during this period will change the original matrix P S The communication error probability in the attack layer matrix S a Receiving wrong information affects the further judgment of the control layer;
[0081] Based on the multi-dimensional heterogeneous model and cyber-physical collaborative attack constructed in the above steps, a cascading failure model of the AC / DC hybrid power cyber-physical system is established, such as Figure 2 As shown in the figure. First, a basic fault is set based on the disturbance event probability model, and the grid power flow distribution under the fault is calculated based on the AC / DC grid power flow. When a branch exceeds the limit, whether the branch is disconnected depends on the degree of the limit. If the branch power exceeds the threshold by a small degree, it can be maintained for a short time. When it exceeds the threshold by a certain degree, an emergency control action is triggered to immediately disconnect. Therefore, the spread of cascading faults may cause the decoupling of the AC / DC hybrid power cyber-physical system.
[0082] In the cascading failure model, there are also channels for uploading information and issuing commands. Information-side attacks could potentially attack the information transmitted in these channels, achieving a synergistic effect and exacerbating the spread of cascading failures. Each evolution of an AC / DC hybrid power cyber-physical system involves three scenarios: maintaining a single system, decomposing it into multiple subsystems, and completely decomposing it. In the first two cases, the resilience assessment indicators of the AC / DC hybrid power cyber-physical system must be recorded and evolution continued until the system is fully stabilized or completely decompressed.
[0083] Whenever a power device is decommissioned, the AC / DC power flow calculation is first used to determine the power flow distribution of the entire AC / DC hybrid power cyber-physical system. If any equipment in the system is still susceptible to failure, the AC / DC power grid emergency control model of the system is used to calculate the generator power adjustment and load reduction for each power node. During the process of uploading measurement data and issuing control commands, the risk of cross-domain fault propagation caused by secondary attacks on the information side is considered, fully reflecting the occurrence of disturbance events and state transitions under cyber attacks.
[0084] The AC linearization method is used to construct an AC / DC power grid emergency control model. When a network attack causes a disturbance event, the safe and stable operation of the power grid is maintained through adjustment processing, load shedding, and generator disconnection. The objective function of the optimal control of the AC / DC power grid emergency control model is:
[0085]
[0086] Where ΔP di , ΔP gj are the power regulation of load node i and generator node j respectively, N b' and N g are the load and the number of generators respectively; the constraints of the AC / DC power grid emergency control model include active power transmission constraints, node voltage amplitude constraints, generator power regulation constraints and maximum load reduction constraints.
[0087] The fault evolution process of an AC / DC hybrid power cyber-physical system after an attack can be represented by the resilience system recovery process. Based on the resilience system evaluation theory, a cascading failure recovery index (CFRI) is proposed to reflect the system response of an AC / DC hybrid power cyber-physical system after an attack. The expression is:
[0088]
[0089] Where α is the scale stability factor; β is the performance stability factor; N b 、N acl、N dcl are the total number of nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system, respectively. The total number of nodes of the AC / DC hybrid power cyber-physical system includes load nodes and generator nodes; N b,x 、N acl,x 、N dcl,x are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x; N b,x-1 、N acl,x-1 、N dcl,x-1 are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x-1; L x , L all are the load and total load of the AC / DC hybrid power cyber-physical system at the evolution time x; ω1, ω2, and ω3 are the node influence factor, AC branch influence factor, and DC branch influence factor, respectively; is a function for calculating the scale of the AC / DC power grid. Since the scale of the AC / DC hybrid power cyber-physical system, including nodes, branches, and load, is taken into account, the changes in the system scale and load of the AC / DC hybrid power cyber-physical system from fault propagation to disconnection after a cascading fault occurs are quantified, reflecting the evolution of the fault in the AC / DC hybrid power cyber-physical system. This indicator can be used as an indicator for comprehensively evaluating the disconnection process of cascading faults and assessing the recovery capability of the AC / DC hybrid power cyber-physical system in the face of cascading faults.
[0090] In order to more quickly evaluate the CFRI changes and robustness performance of the AC / DC hybrid power cyber-physical system after being attacked, an improvement was made based on CFRI, and the CFRI area model was used to score the CFRI level of the AC / DC hybrid power cyber-physical system. The CFRI area model is as follows: Figure 3 As shown, the formula is as follows:
[0091]
[0092] Where R is the robustness index of the CFRI curve; T is the evolution time; t0 is the simulation start time, t r is the moment when the AC / DC hybrid power cyber-physical system recovers stability, that is, the AC / DC hybrid power cyber-physical system no longer experiences disconnection or load loss; CFRI(t) is the cascade disconnection resilience index curve of the AC / DC hybrid power cyber-physical system, which depicts the change of the cascade disconnection index of the AC / DC hybrid power cyber-physical system from the time of being attacked to the time of recovering stability. Figure 3 In the middle, t0-t e This is the prevention period, during which the AC / DC hybrid power cyber-physical system operates stably, and the CFRI value at this time is shown as point A; at t eAt time t, the AC / DC hybrid power cyber-physical system is attacked by cyber-physical coordinated attacks, and the CFRI value drops rapidly to point B. e -t d After a period of fault evolution, the performance of the AC / DC hybrid power cyber-physical system reaches the minimum value C; t d -t r This is the recovery period, during which the AC / DC hybrid power cyber-physical system gradually recovers its performance due to emergency control measures that suppress the continued spread of the fault. Figure 3 Point D is an ideal situation. In actual situations, AC / DC hybrid power cyber-physical systems often cannot recover to their initial performance.
[0093] The above embodiments are preferred implementation modes of the present invention, but the implementation modes of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications that do not deviate from the spirit and principles of the present invention should be considered as equivalent replacement methods and are included in the scope of protection of the present invention.
Claims
1. A method for assessing the resilience of AC / DC hybrid power cyber-physical systems under coordinated attacks, characterized by: The following steps are involved: S1. Based on the characteristics of the AC / DC hybrid power cyber-physical system, which has a high degree of coupling between the information side and the physical side and frequent bidirectional information interaction, a multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established. This model reflects the coupling characteristics between the information side and the physical side of the AC / DC hybrid power cyber-physical system. Based on the modeling method of the correlation matrix, the intra-layer information transmission and inter-layer information interaction between the information side and the physical side are modeled in detail to improve the accuracy of the model. S2. Based on the multi-dimensional heterogeneous model established in step S1, a cyber-physical collaborative attack is developed using a correlation matrix modeling method. This attack can be launched during the measurement information collection phase and control command issuance phase of the AC / DC hybrid power cyber-physical system, resulting in local unobservability and uncontrollability effects in the AC / DC hybrid power cyber-physical system. Launching a collaborative attack on the constructed multi-dimensional heterogeneous model can lead to the occurrence, propagation, and aggravation of cascading failures. S3. Based on the multi-dimensional heterogeneous model established in step S1 and the cyber-physical coordinated attack established in step S2, a cascading failure model of the AC / DC hybrid power cyber-physical system is established. This model can accurately reflect the evolution of the cascading failure by using relevant parameters of the AC / DC hybrid power cyber-physical system under cascading failures, including the number of lost nodes, the number of lost branches, the amount of lost load, and the size and status of the subsystem. S4. The Cascading Failure Recovery Index (CFRI) is proposed as a comprehensive evaluation metric. This metric takes into account the system scale and load level of the AC / DC hybrid power cyber-physical system during the cascading failure recovery process to assess the resilience and recovery capabilities of the AC / DC hybrid power cyber-physical system in the face of cascading failures. The specific indicators are as follows: The fault evolution process of an AC / DC hybrid power cyber-physical system after an attack can be represented by the resilience system recovery process. Based on the resilience system evaluation theory, a cascading failure recovery index (CFRI) is proposed to reflect the system response of an AC / DC hybrid power cyber-physical system after an attack. The expression is: ; ; Where, is the scale stabilization factor; is the performance stabilization factor; 、 、 are the total number of nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system, respectively. The total number of nodes of the AC / DC hybrid power cyber-physical system includes load nodes and generator nodes. 、 、 are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x; 、 、 are the number of system nodes, number of AC branches, and number of DC branches of the AC / DC hybrid power cyber-physical system at time x-1 respectively; 、 are the load and total load of the AC / DC hybrid power cyber-physical system at the evolution time x, respectively; 、 、 They are node impact factor, AC branch impact factor and DC branch impact factor respectively; is the AC and DC grid size calculation function.
2. The method for evaluating the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks according to claim 1 is characterized in that: The specific operation steps of step S1 are as follows: S11. Considering the information interaction tasks between the information side and the physical side of the AC / DC hybrid power cyber-physical system, including data uploading and command issuance, a multi-dimensional heterogeneous model of the AC / DC hybrid power cyber-physical system is established based on the information network architecture of hierarchical power grid control. The model includes a control layer, an interval layer, and a processing layer. The control layer is composed of a monitor host, a remote control interface, and a remote monitoring interface, and is responsible for real-time monitoring of the operating status of the AC / DC hybrid power cyber-physical system. The interval layer is composed of intelligent electronic devices, including relay devices and control switches, and is responsible for processing data uploaded by the processing layer and commands issued by the control layer. The processing layer uses intelligent monitoring terminals and intelligent dispatching terminals to monitor, manage, and coordinate power plants, converter stations, and transmission lines of the AC / DC hybrid power cyber-physical system. S12. Use the correlation matrix modeling method to build a coupling model of the information side and the physical side. The model includes the system topology, state transition process, control strategy transmission and information exchange process. The system modeling process for n physical nodes, k intelligent electronic device nodes and m information monitoring nodes is as follows: S121. Model the nodes within the layer to obtain the interval layer node model: Use the tuple model to describe the functional characteristics of each layer node. For the interval layer node, the i-th node is modeled as: ; Where, is the i-th node model in the interval layer, Information processing algorithms for intelligent electronic devices, including data packet parsing , data processing and data packet encryption , expressed as ; and are the error probability and delay in the information processing process, and the information processing algorithm related; S122. Modeling of intra-layer branches to obtain an interval layer branch model: Each layer network model reflects the information exchange of nodes within the layer. The intra-layer branch performance tuple between nodes i and j is expressed as: ,in, is the branch model between node i and node j, Indicates communication interruption status. and are the error probability and delay in information transmission, respectively; S123, intra-layer network modeling, obtain the intra-layer network model: Based on the bay layer node model established in step S121 and the bay layer branch model established in step S122, the intra-layer network model is represented as the correlation characteristic matrix : ; Where, is the branch model between node i and node j. If i = j, it corresponds to the bay layer node. If i ≠ j, it corresponds to the bay layer branch. k is the total number of intelligent electronic device nodes in the bay layer. S124, inter-layer coupling modeling: The intra-layer network model of the spacer layer is interconnected with the intra-layer network model of the control layer. In order to describe the relationship between the intelligent electronic device uploading information to the monitoring node and issuing instructions, a correlation characteristic matrix from the spacer layer to the control layer is established. : ; Where, Describes the coupling relationship between the interval layer nodes and the control layer nodes, The communication from the bay layer to the control layer is interrupted; is the error probability of communication from the bay layer to the control layer; The communication delay from the bay layer to the control layer; Based on the above modeling, a multi-dimensional heterogeneous model including the control layer, the interval layer and the processing layer can be constructed. The model not only includes the node and network models of each layer, but also includes the correlation characteristic matrix between each layer, specifically: the correlation characteristic matrix from the processing layer to the interval layer , the correlation characteristic matrix from the interval layer to the processing layer , the correlation characteristic matrix from the bay layer to the control layer and the correlation characteristic matrix from the control layer to the bay layer , which can clearly show the information flow and interactive coupling between the information side and the physical side; the information transmission between different layers is calculated through the correlation matrix, and the control layer sends control instructions to the interval layer through In the form of is the control layer network correlation characteristic matrix, is the inter-layer correlation characteristic matrix from the control layer to the spacer layer, is the interval layer network correlation characteristic matrix.
3. The method for evaluating the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks according to claim 2 is characterized in that: In step S2, the cyber-physical coordinated attack consists of two parts: information attack and physical attack. The information attack includes an attack on the AC / DC branch status information upload channel. and attacks on the generator and load adjustment command issuance channels ,in Referred to as uplink channel attack, Downlink channel attack; the physical attack is an attack on AC / DC branch circuit breaker equipment. The coordinated attack is launched through a physical attack, which controls the opening and closing of the branch by tampering with the state of the branch circuit breaker. In the AC / DC hybrid power cyber-physical system, the AC / DC branches belong to the physical layer, and the circuit breaker equipment is the processing layer node. The two have a one-to-one correspondence. Therefore, the physical attack can be expressed as: ; Where, is the attack matrix for the circuit breaker device at the processing layer, where the vector , It is an attack vector targeting the communication interruption state; and are the branch correlation matrices of the processing layer or physical layer before and after the attack, 、 、 They are the communication interruption status of the processing layer, the error probability and delay in the information transmission process; if =1, = 0, it means that the branch between node i and node j is attacked and disconnected; if , it means the branch is not attacked; The uplink channel attack and downlink channel attack on the information side are launched by injecting attack vectors into the inter-layer correlation characteristic matrix; the attack on the AC / DC branch status information upload channel is the correlation feature matrix from the processing layer to the interval layer The specific forms of the launch are: ; Where, This is the attack matrix for the uplink channel from the processing layer to the spacer layer. is the correlation characteristic matrix from the processing layer to the interval layer after the attack; and They are the network correlation characteristic matrices of the spacer layer before and after the attack. The branch status information received by the spacer layer is collected by the processing layer, and then transmitted to the spacer layer through the correlation characteristic matrix of the processing layer to the spacer layer. The upstream channel information attack injected during this period will change the original matrix The communication error probability in the attack layer matrix is Receiving wrong information affects the judgment of the control layer; Attacks on the generator and load adjustment command issuance channel The attack principle and Similarly, by comparing the inter-layer correlation characteristic matrix from the spacer layer to the processing layer Attack and tamper with the generator's adjustment instructions to achieve the attack effect.
4. The method for evaluating the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks according to claim 1 is characterized in that: The specific operation steps of step S3 are as follows: S31. Based on the constructed multi-dimensional heterogeneous model and cyber-physical coordinated attack, a cascading failure model of the AC / DC hybrid power cyber-physical system is established. The specific situation is as follows: First, a basic fault is set based on the probability model of disturbance events. The grid power flow distribution under the fault is calculated based on the AC and DC grid power flows. When a branch exceeds the limit, whether the branch is disconnected depends on the degree of the limit. When the degree to which the branch power exceeds the threshold is within the allowable range, it can be maintained for a short time. When the threshold is exceeded and out of the permissible range, an emergency control action is triggered to disconnect immediately, so the AC / DC hybrid power cyber-physical system is disconnected during the spread of the cascade fault; In the cascading failure model, there are also channels for information uploading and command issuance. Information-side attacks attack the information transmitted in this channel to achieve a synergistic effect, exacerbating the spread of cascading failures. Each evolution of the AC / DC hybrid power cyber-physical system has three situations: maintaining a single system, splitting into multiple subsystems, and completely splitting. In the first two situations, it is necessary to record the resilience assessment indicators of the AC / DC hybrid power cyber-physical system and continue to evolve until the AC / DC hybrid power cyber-physical system can be fully stabilized or completely split. Whenever a power device is taken offline, the AC / DC power flow calculation is first used to determine the power flow distribution of the entire AC / DC hybrid power cyber-physical system. If there are still faulty devices in the AC / DC hybrid power cyber-physical system, the AC / DC power grid emergency control model is used to calculate the generator power adjustment and load reduction for each power node. During the process of uploading measurement data and issuing control instructions, the risk of cross-domain fault propagation caused by secondary attacks on the information side is considered, which can fully reflect the occurrence of disturbance events and state transition processes under network attacks. S32. It is proposed to use the AC linearization method to construct an AC / DC power grid emergency control model. When a disturbance event caused by a cyber attack occurs, the AC / DC hybrid power cyber-physical system is maintained in a safe and stable operation through adjustment processing, load shedding, and generator disconnection measures. The optimization control objective function of the AC / DC power grid emergency control model is: ; Where, 、 are the power regulation values of load node i and generator node j respectively, 、 are the load and the number of generators respectively; the constraints of the AC / DC grid emergency control model include active power transmission constraints, node voltage amplitude constraints, generator power regulation constraints and maximum load reduction constraints.
5. The method for evaluating the resilience of an AC / DC hybrid power cyber-physical system under coordinated attacks according to claim 1 is characterized in that: The specific operation steps of step S4 are as follows: S41. Considering the scale of the AC / DC hybrid power cyber-physical system, including its nodes, branches, and load, the changes in the system scale and load during the process from fault propagation to disconnection after a cascading fault occurs are quantified, reflecting the evolution of the fault in the AC / DC hybrid power cyber-physical system. The Cascading Failure Recovery Index (CFRI) can be used as an indicator to comprehensively evaluate the disconnection process of cascading faults and assess the recovery capability of the AC / DC hybrid power cyber-physical system in the face of cascading faults. S42. To more quickly evaluate the CFRI changes and robustness of AC / DC hybrid power cyber-physical systems after being attacked, we improved on the basis of CFRI and used the CFRI area model to score the CFRI level of AC / DC hybrid power cyber-physical systems. The CFRI area model formula is as follows: ; Where, is the robustness index of the CFRI curve; is the evolution time; is the simulation start time, The moment when the AC / DC hybrid power cyber-physical system returns to stability, that is, the AC / DC hybrid power cyber-physical system no longer experiences disconnection or load loss; It is the cascade decoupling resilience index curve of the AC / DC hybrid power cyber-physical system, which depicts the change of the cascade decoupling index of the AC / DC hybrid power cyber-physical system from being attacked to recovering to stability.
Citation Information
Patent Citations
Power system resilience evaluation method considering network attack
CN114662328A
Elastic evaluation method for information physical fusion power transmission network under ice disaster
CN115081807A