False Data Injection Attack Detection and Location Method Based on Physical Constraints and Adaptive Threshold

By introducing physical constraints and adaptive threshold generation mechanisms in the detection of false data injection attacks, combined with WGAN, LSTM and CNN-Transformer models, the problem of insufficient detection accuracy and positioning capabilities in the prior art is solved, and more efficient and accurate detection and positioning of false data injection attacks is achieved.

CN119892499BActive Publication Date: 2025-06-13QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510360779.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-13
Estimated Expiration
2045-03-26

AI Technical Summary

Technical Problem

The existing False Data Injection Attack (FDIA) detection methods have shortcomings in detection accuracy, robustness and positioning capabilities, especially in the face of dynamic changes in the system and complex spatiotemporal correlations, it is difficult to generate high-quality data that meets physical constraints, and it is difficult to accurately locate the attack source.

Method used

Using detection methods based on physical constraints and adaptive thresholds, synthetic data that conforms to physical laws is generated by generating adversarial networks (WGANs), and the long and short-term characteristics of the time series are captured in combination with LSTM. The CNN-Transformer model is used for global feature extraction and dynamic threshold generation, and combined with the dynamic detection mechanism of quantiles, the distribution of normal data is analyzed and the potential attack sources are accurately located.

Benefits of technology

It significantly improves the detection accuracy and robustness of false data injection attacks, and can efficiently identify and locate FDIA in complex environments, reduce the risk of false alarms and missed alarms, and improves the timeliness and accuracy of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892499B_ABST
    Figure CN119892499B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of data analysis and network security, and specifically relates to a method for detecting and locating false data injection attacks based on physical constraints and adaptive thresholds. The method includes: preprocessing the measurement data of multiple sensors and inputting the data into a WGAN framework based on physical constraints and time condition embedding for training; the WGAN generates high-quality synthetic data that conforms to physical laws, and combines LSTM to capture the long-term and short-term characteristics of time series; subsequently, a CNN-Transformer model is used for global feature extraction and dynamic threshold generation, and a quantile-based dynamic detection mechanism is combined to analyze the distribution of normal data to accurately locate potential attack sources; finally, by cyclically optimizing the model architecture and parameters, the accuracy and efficiency of detection and location are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data analysis and network security, and particularly relates to a method for detecting and locating false data injection attacks (FDIA, False Data Injection Attack) based on physical constraints and adaptive thresholds, which is particularly applicable to various sensor-based network systems. Background Art

[0002] With the wide application of various intelligent monitoring and control systems (ICS, Industrial Control Systems) based on information and communication technology (ICT, Information and Communication Technology) in critical infrastructures, the real-time performance and automation level of these systems have been significantly improved. However, such highly integrated systems also bring new security threats, especially false data injection attacks (FDIA, False Data Injection Attack). FDIA misleads state estimation by tampering with the measurement data in the system, thereby affecting the normal operation and decision-making scheduling of the system.

[0003] Traditional residual-based bad data detection (BDD, Bad Data Detection) methods identify abnormal data by detecting the difference between the measurement data and the predicted value in the system state estimation. However, FDIA can bypass the traditional residual detection mechanism by carefully designing the attack vector, making the injected false data almost indistinguishable from the normal data. These attacks are called "stealth FDIA" because they can adjust the structure of the attack data to keep the residual of the state estimation within the normal range, resulting in the attacks not being detected. Therefore, various sensor-based critical infrastructure systems urgently need more advanced detection and defense mechanisms.

[0004] The existing FDIA detection methods are mainly divided into two categories: model-based methods and data-driven methods. Model-based methods rely on the physical and mathematical models of the system and detect false data injection by comparing the deviation between the actual measurement values and the predicted values. However, the effectiveness of such methods is limited by the accuracy and integrity of the system model. Once the model parameters change or are incomplete, the accuracy of the detection results will drop significantly. In contrast, data-driven methods utilize machine learning and deep learning technologies, especially generative adversarial networks (GANs), autoencoders (AEs), etc., to detect abnormal data by learning historical data. These methods can automatically extract features from the data and do not rely on the precise model of the system. Therefore, they have stronger adaptability and robustness when facing complex and dynamically changing systems.

[0005] For example, Chinese patent document CN113094702A discloses a method and device for detecting false data injection attacks based on an LSTM network, which specifically discloses: obtaining the state values of each node in the distribution network in real time to generate historical state value data; using the trained LSTM state prediction model to process the historical state value data to obtain the state prediction values of each node at the next moment; obtaining the actual measured values of the states of each node at the next moment, comparing the state prediction values and the actual measured values according to the preset mean square error, and obtaining the detection results of false data injection attacks.

[0006] Chinese patent document CN116886351A discloses a method, device, equipment and medium for simulating and detecting false data injection attacks, which specifically discloses: collecting the original time series data monitored by the sensors of an aeroengine; screening the data length of the collected original time series data to obtain the pre-screened time series data that meets the preset requirements, and preprocessing the pre-screened time series data to obtain the target time series data; simulating continuous false data injection attacks and intermittent false data injection attacks for each target time series data to obtain the continuous false data and intermittent false data corresponding to the target time series data; setting type labels for each target time series data, continuous false data and intermittent false data respectively, and then dividing the training set and the test set; constructing an LSTM network, training the LSTM network with the training set to obtain a trained LSTM network; inputting the test set into the trained LSTM network, outputting the predicted class labels, and evaluating the prediction effect.

[0007] However, existing anomaly detection methods still have some deficiencies when dealing with FDIA, especially in terms of detection accuracy, robustness, and localization ability. Traditional methods often rely on fixed thresholds or static models, which show significant limitations when facing system dynamic changes and complex spatio-temporal correlations. First, existing methods are difficult to generate high-quality data that conforms to physical constraints, resulting in the inability to effectively reflect the actual operating state of the system during the model training process. Second, many detection algorithms fail to fully utilize the temporal characteristics of the data and lack the capture of long-term dependencies, leading to insufficient response speed and accuracy for sudden attacks. In addition, when dealing with the complex structure and dynamic changes of the system, existing methods often cannot accurately locate the attack source, resulting in high false alarm and missed alarm rates.

[0008] Based on this, there is an urgent need for a detection method that can generate data conforming to the physical laws of the system and can dynamically adjust the detection threshold to address the above challenges. Summary of the Invention

[0009] The present invention aims to overcome several defects in the prior art and provides a method for detecting and locating FDIA based on physical constraints and adaptive thresholds, which is particularly suitable for the detection and location of FDIA in various critical infrastructure systems based on sensor data; this method combines physical constraints and temporal characteristics, and uses an adaptive threshold generation and dynamic detection mechanism to effectively identify false data and accurately locate the attack source, thereby improving the accuracy and robustness of anomaly detection.

[0010] The detailed technical solution of the present invention is as follows:

[0011] A method for detecting and locating false data injection attacks based on physical constraints and adaptive thresholds. First, by preprocessing the measurement data of multiple sensors, the data is input into a WGAN framework based on physical constraints and time condition embedding for training; the WGAN generates high-quality synthetic data that conforms to physical laws and combines LSTM to capture the long-term and short-term characteristics of the time series. Subsequently, a CNN-Transformer model is used for global feature extraction and dynamic threshold generation, and a dynamic detection mechanism based on quantiles is combined to analyze the distribution of normal data to accurately locate potential attack sources. Finally, by cyclically optimizing the model architecture and parameters, the accuracy and efficiency of detection and location are improved.

[0012] The method specifically includes:

[0013] S1. Obtain historical measurement data from multiple sensors and preprocess the historical measurement data to obtain normal data samples;

[0014] S2, initializing the parameters of the generator and the discriminator of the generative adversarial network WGAN, and performing model training on the generative adversarial network WGAN in combination with the time condition embedding and the physical constraint loss function, so that the generator generates synthetic data samples that conform to the physical laws of the system based on the normal data samples;

[0015] S3, initializing the parameters of the LSTM model, first pre-training the LSTM model using the synthetic data sample, then optimizing the parameters of the pre-trained LSTM model in combination with actual data, and extracting the time series features of the normal data sample using the optimized LSTM model;

[0016] S4, initializing the parameters of the CNN-Transformer model, inputting the time series features extracted by the LSTM model and the normal data sample as a data combination into the CNN-Transformer model, extracting the local time series features of the input data combination through the CNN model, and capturing the global time series evolution characteristics of the input data combination through the Transformer model, so as to generate a dynamic threshold;

[0017] S5. Optimize the interval range of the dynamic threshold based on the quantile loss function, monitor the measurement data of the sensor to be detected based on the optimized dynamic threshold, compare the preprocessed measurement data of the sensor to be detected with the interval range of the dynamic threshold, and if it exceeds the interval range of the dynamic threshold, it is determined that an attack exists.

[0018] Preferably, according to the present invention, in S1, preprocessing the historical measurement data specifically includes:

[0019] Performing data cleaning on the historical measurement data to remove abnormal values ​​therein;

[0020] Performing time alignment on the cleaned historical measurement data to make the time mark of each data point consistent;

[0021] The aligned historical measurement data are processed by Z-score standardization to adjust all data to the same scale range;

[0022] Among them, the formula for Z-score standardization is:

[0023] (1);

[0024] In formula (1): represents the data before normalization; represents the mean of the data; represents the standard deviation of the data, Represents the normalized data.

[0025] Preferably according to the present invention, in S2, a weight initialization method based on prior knowledge is adopted to initialize the generator and discriminator of the generative adversarial network WGAN;

[0026] And during model training, physical constraint conditions are introduced:

[0027] (2);

[0028] In formula (2): represents the total generated power, with the unit of MW; represents the total load power generated, with the unit of MW; represents the generated transmission loss, with the unit of MW;

[0029] Define the physical constraint loss function as:

[0030] (3);

[0031] In formula (3): represents the physical constraint loss, and the L2 norm is used to measure the deviation degree of power conservation, which is used to ensure power conservation;

[0032] The intermediate loss function of the generator considers the combination of physical constraints and WGAN loss, that is:

[0033] (4);

[0034] In formula (4): represents the intermediate loss function of the generator; represents the WGAN loss of the generator, which is used to constrain the data distribution; is a hyperparameter, which is used to adjust the weight of the physical constraint loss in the optimization process of the generator;

[0035] The total loss function of the generator adds the time consistency loss on the basis of its intermediate loss function, that is:

[0036] (5);

[0037] In formula (5): represents the total loss function of the generator; represents the time consistency loss, which is used to ensure time dynamic consistency; is a hyperparameter;

[0038] The time consistency loss is:

[0039] (6);

[0040] In formula (6): represents the generated data; represents the mean value of the real data at this time point to make the GAN closer to the real data in the time dimension, , represents the time condition, which is the discrete time points of 24 hours a day.

[0041] According to the preference of the present invention, in S2, the time condition embedding uses one-hot encoding to convert the time information of 24 hours a day into a 24-dimensional vector; in terms of the model structure, the time condition embedding is respectively used as the input of the generator and the discriminator in the generative adversarial network WGAN, wherein the input of the generator consists of random noise η and time embedding :

[0042] (7);

[0043] The input of the discriminator consists of normal data samples and time embedding :

[0044] (8).

[0045] According to the preference of the present invention, in S3, the weights of the LSTM model are initialized by a uniform distribution, and its bias is initialized to zero; when pre-training the LSTM model, its input is the synthetic data sample, and its output is the time series value of the next time step; the pre-training objective function of the LSTM model is:

[0046] (9);

[0047] In formula (9): represents the real time series value corresponding to the next time step in the synthetic data sample; represents the time series value of the next time step predicted by the LSTM model.

[0048] According to the preference of the present invention, in S4, the parameters of the CNN-Transformer model are initialized using the Kaiming initialization and Xavier initialization methods; the time series features extracted by the LSTM model and the normal data samples are input into the CNN-Transformer model together as a data combination, that is:

[0049] (10);

[0050] In Equation (10): represents the input of the CNN-Transformer model; represents the temporal features extracted by the LSTM model; represents a normal data sample.

[0051] Preferably according to the present invention, in S4, the local temporal features of the input data combination are extracted through the convolutional layer of the CNN model, and the convolutional operation is expressed as:

[0052] (11);

[0053] In Equation (11): represents the convolutional operation; represents the local temporal features extracted by the CNN model; represents the activation function; represents the convolutional kernel of the convolutional layer.

[0054] Preferably according to the present invention, in S4, the Transformer model captures the global temporal evolution characteristics of the input data combination through the self-attention mechanism, and the self-attention mechanism is expressed as:

[0055] (12);

[0056] In Equation (12): represents the query, which is used to query the correlation between time steps; represents the key, which is used to calculate similarity; represents the value matrix, which contains the original feature information; represents the output of the self-attention mechanism, which is a weighted representation of the global temporal features and captures the long-term dependencies between time steps in the time series.

[0057] Preferably according to the present invention, in S5, two independent CNN-Transformer models are used to adjust the upper and lower limits of the dynamic threshold respectively. Among them, the upper limit of the prediction is adjusted by minimizing the quantile loss function, and the lower limit of the prediction is optimized by the quantile loss function; the quantile loss function is:

[0058] (13);

[0059] In Equation (13): represents the quantile loss function; represents the predicted value of the CNN-Transformer model; represents the true value; is the set quantile; denotes the number of training samples, i.e., the total number of feature values of normal data samples.

[0060] Preferably according to the present invention, in the step S5, the formula for determining the existence of an attack is:

[0061] (14);

[0062] In formula (14): denotes the measured data of the sensor to be detected after preprocessing; denotes the upper limit of the dynamic threshold; denotes the lower limit of the dynamic threshold.

[0063] Compared with the prior art, the beneficial effects of the present invention are:

[0064] (1) A method for detecting and locating false data injection attacks based on physical constraints and adaptive thresholds provided by the present invention combines the advantages of the WGAN and CNN-Transformer architectures, utilizes the generated data and temporal characteristics, and effectively enhances the detection and location capabilities of false data injection attacks. The temporal data generated by the WGAN can highly simulate the operating characteristics, and the CNN-Transformer can capture complex spatio-temporal correlations, thereby improving the detection accuracy and robustness. Compared with traditional methods, the present invention can more efficiently identify and locate FDIA in complex environments.

[0065] (2) By introducing physical constraints and an adaptive threshold generation mechanism, the present invention improves the accuracy and reliability of FDIA detection. Physical constraints help ensure that the generated data conforms to the actual operating laws and avoid the generated false data deviating from the real situation; while the adaptive threshold generation mechanism dynamically adjusts the threshold according to real-time data, effectively coping with changes in different attack scenarios and reducing the risks of false alarms and missed alarms.

[0066] (3) The present invention adopts an anomaly detection strategy based on the LSTM pre-training mechanism, enabling the model to quickly adapt and make accurate judgments when facing unknown attack patterns. The pre-training mechanism helps the model effectively capture the long-term dependence relationships in the data when processing temporal data, improving the timeliness and accuracy of detection. Description of the Drawings

[0067] Figure 1 is a flowchart of the method for detecting and locating false data injection attacks based on physical constraints and adaptive thresholds according to the present invention.

[0068] Figure 2 is a comparative analysis chart of power conservation of different data generation methods in the embodiments of the present invention.

[0069] Figure 3It is a moving average comparison diagram of different data generation methods in the embodiments of the present invention. Detailed implementation manners

[0070] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0071] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0072] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0073] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0074] When dealing with complex dynamic changes in the system, the prior art often relies on large-scale historical data for training and lacks physical constraints, resulting in the generated data may violate the physical laws of the system, thereby affecting the reliability of detection. In addition, the prior art relies on static thresholds or models and is difficult to effectively cope with the concealment and timing characteristics of FDIA. For this reason, the present invention significantly improves the detection accuracy and positioning efficiency of FDIA through an innovative generative adversarial network architecture and a dynamic threshold generation mechanism.

[0075] The following further describes the false data injection attack detection and positioning method based on physical constraints and adaptive thresholds of the present invention in conjunction with specific embodiments.

[0076] Embodiment

[0077] Refer Figure 1 , this embodiment provides a false data injection attack detection and positioning method based on physical constraints and adaptive thresholds. First, by preprocessing the measurement data of multiple sensors, the data is input into a WGAN framework based on physical constraints and time condition embedding for training; the WGAN generates high-quality synthetic data that conforms to physical laws and combines LSTM to capture the long-term and short-term characteristics of time series. Subsequently, a CNN-Transformer model is used for global feature extraction and dynamic threshold generation, and the distribution of normal data is analyzed in combination with a quantile-based dynamic detection mechanism to accurately locate potential attack sources. Finally, by cyclically optimizing the model architecture and parameters, the accuracy and efficiency of detection and positioning are improved.

[0078] The method specifically includes:

[0079] S1. Obtain historical measurement data from multiple sensors, and preprocess the historical measurement data to obtain normal data samples.

[0080] In this embodiment, in order to accurately detect FDIA (False Data Injection Attack) in the system, it is necessary to obtain historical measurement data from multiple sensors and preprocess these data. The preprocessing process includes operations such as outlier filtering, time alignment, and standardization, aiming to ensure the quality and consistency of the data, and providing a reliable basis for subsequent model training and anomaly detection.

[0081] Specifically, after obtaining the historical measurement data of multiple sensors, data cleaning and preprocessing are first performed to ensure the quality and consistency of the data.

[0082] The first step of data cleaning is outlier filtering. This process identifies and removes unreasonable or extreme outliers by performing statistical analysis on the input data. Outliers may be caused by sensor failures, data transmission errors, or external environmental interferences. If not excluded, they will have an adverse impact on the accuracy of model training.

[0083] Next, in the case where there are differences in the acquisition frequencies or timestamps of different sensors, it is necessary to align the data of each sensor in time. Through time alignment, ensure that the time stamps of each data point are consistent, so as to ensure that the model can correctly process the temporal characteristics of the data.

[0084] In addition, since the measurement data of different sensors often have different dimensions, this may cause interference during model training. Therefore, during data standardization processing, all input data is adjusted to the same scale range to avoid the negative impact of dimensional differences on model training.

[0085] Common standardization methods include Z-score standardization or Min-Max standardization. In order to ensure the consistency of the scales of each feature and avoid biases during the training process caused by features with different dimensions, this method uses Z-score standardization.

[0086] The formula for the Z-score standardization is:

[0087] (1);

[0088] In formula (1): represents the data before standardization; represents the mean of the data; represents the standard deviation of the data, Represents the standardized data.

[0089] Through this series of data preprocessing steps, the quality and consistency of the data can be effectively improved, laying a solid foundation for the training of subsequent deep learning models.

[0090] S2. Initialize the parameters of the generator and discriminator of the generative adversarial network WGAN, and combine the time condition embedding and the physical constraint loss function to train the generative adversarial network WGAN, so that its generator generates synthetic data samples that conform to the physical laws of the system based on the normal data samples.

[0091] In this embodiment, the normal data samples represent the true operating state of the system without being interfered by FDIA.

[0092] In this embodiment, first, it is necessary to initialize the generator and discriminator of the generative adversarial network WGAN to ensure that the generated synthetic data conforms to the physical laws. During initialization, a weight initialization method based on prior knowledge is adopted to ensure the stable operation of the model in the initial stage of training. In addition, optimizing the generator by combining the physical constraint loss function helps to reduce the error of the generated data, making the generated synthetic data closer to the actual operating state.

[0093] Furthermore, generate high-quality synthetic data that conforms to physical laws and time dynamic characteristics through the generative adversarial network WGAN, and use these generated data for the pre-training of the LSTM model. The goal of the generator is to learn the physical laws from the normal data to ensure that the generated data can effectively reflect the operating state. The key to this process lies in introducing the physical constraint loss function and the time condition embedding to improve the quality and authenticity of the generated data.

[0094] Specifically, the goal of the generator is to generate data that conforms to physical laws, and the principle of power conservation is the key constraint condition. The principle of power conservation requires a strict balance relationship between the power generation, load power, and transmission losses, that is, at any point in time, the power generation must be equal to the sum of the load power and the transmission losses.

[0095] In this method, in order to strengthen this physical constraint during the data generation process, a physical constraint loss function is introduced , which is used to measure the degree to which the generated data deviates from the physical laws and incorporate it into the generator optimization goal.

[0096] The principle of power conservation can be expressed as:

[0097] (2);

[0098] In Equation (2): Represents the total generated power, with the unit of MW; Represents the total generated load power, in MW; Represents the transmission loss generated, in MW.

[0099] However, during the actual data generation process, the generated data may violate this physical constraint. Therefore, the physical constraint loss function is defined as:

[0100] (3);

[0101] In Equation (3): Represents the physical constraint loss, using the L2 norm to measure the deviation from power conservation; by minimizing this loss, the generator can gradually reduce the deviation of the generated data from the physical laws.

[0102] During the GAN training process, the intermediate loss function of the generator considers the combination of physical constraints and the WGAN loss, specifically expressed as:

[0103] (4);

[0104] In Equation (4): is the intermediate loss function of the generator, only considering physical constraints; is the WGAN loss of the generator, used to constrain the data distribution; is a hyperparameter, used to adjust the weight of the physical constraint loss in the generator optimization process.

[0105] Furthermore, the data has obvious time dynamic characteristics, and the load, generation power, and transmission loss vary periodically in different time periods. For example, the daily load curve usually shows morning and evening peaks, with lower loads at night, and seasonal changes also affect electricity demand. Traditional GANs do not consider time information, which may lead to unreasonableness of the generated data in the time dimension, such as extremely high loads at night or extremely low loads during the day. Therefore, in this method, a time condition embedding mechanism is introduced to enable GANs to learn time change patterns and ensure the time consistency of data generation.

[0106] To ensure that the generated data conforms to the time characteristics, the time consistency loss is added to the optimization objective function of GAN, and the total loss function of the generator is modified to:

[0107] (5);

[0108] In Equation (5): Represents the total loss function of the generator Represents the time consistency loss, used to ensure time dynamic consistency; is a hyperparameter.

[0109] The time consistency loss is:

[0110] (6);

[0111] In formula (6): represents the generated data; represents the mean of the real data at this time point to make the GAN closer to the real data in the time dimension, , represents the time condition, which is the discrete time points of 24 hours a day.

[0112] It should be understood that the above time condition embedding adopts one-hot encoding, which converts the time information of 24 hours a day into a 24-dimensional vector. For example:

[0113] 00:00 → [1, 0, 0,..., 0];

[0114] 12:00 → [0, 0, 0,..., 1, 0, 0];

[0115] 18:00 → [0, 0, 0,..., 0, 1, 0].

[0116] This encoding method ensures that the information of different time points can be learned by the model, guiding the generator to generate data that conforms to the characteristics of this time period. For example, during the day's peak period, the generator can generate higher load data, while during the night's low period, it can generate lower load data, ensuring the time consistency of the data.

[0117] In terms of the model structure, the time condition embedding is not only used as an input to the generator but also added to the discriminator input. Among them, the input of the generator consists of random noise and time embedding :

[0118] (7);

[0119] The input of the discriminator consists of data and time embedding :

[0120] (8).

[0121] In this way, the discriminator can not only judge the authenticity of the data but also whether it conforms to the characteristics of this time period. If the GAN generates high load data in the middle of the night, the discriminator will be more likely to identify it as fake data, thus optimizing the learning direction of the GAN.

[0122] S3. Initialize the parameters of the LSTM model. First, pre-train the LSTM model using the synthetic data samples, then optimize the parameters of the pre-trained LSTM model in combination with the actual data, and use the optimized LSTM model to extract the temporal features of the normal data samples.

[0123] In this embodiment, the initialization of the LSTM model is also crucial, especially when capturing long-term and short-term dependencies. The LSTM model initializes its weights with a uniform distribution and initializes the biases to zero to ensure that it can efficiently learn temporal patterns. The initialized LSTM model is trained on non-attacked data to provide accurate temporal predictions in subsequent detection stages.

[0124] Use the high-quality data generated by the WGAN for pre-training the LSTM model, aiming to enable the LSTM model to converge quickly and internalize the physical laws in the early stage of training, ensuring that the parameters of the LSTM model have certain physical information and completing the preliminary training of the model.

[0125] The LSTM model is good at capturing long-term dependencies in time series and can maintain the memory of past moment information for future predictions when dealing with complex data. Therefore, pre-training the LSTM model with the data generated by the WGAN can not only enable the LSTM model to better learn the temporal characteristics in the data but also effectively reduce the model's dependence on real data.

[0126] The input of the LSTM model is the synthetic time series data generated by the WGAN, and the output is the predicted value of the state at the next time step. The generated time series data covers features such as load changes and power consumption at different time periods. By training the LSTM model with these synthetic data, the model can learn the long-term time dependence relationships and dynamic characteristics. During the pre-training process, the LSTM can converge faster in the training of actual data by learning the temporal information in these synthetic data and improve the prediction accuracy.

[0127] The pre-training objective function of the LSTM model is:

[0128] (9);

[0129] In formula (9): represents the true time series value at the next time step, that is, the true state value corresponding to the next time step in the synthetic data sample, such as load or power; represents the time series value predicted by the LSTM model at the next time step.

[0130] By minimizing this loss function, the LSTM model can gradually adjust its internal parameters to make the generated data predictions more accurate.

[0131] Furthermore, after pre-training, the LSTM model will be combined with the pre-processed data. By further optimizing the parameters, it can accurately extract the temporal features in the data, and then provide efficient temporal information for subsequent anomaly detection tasks. By combining real and synthetic data, the LSTM model not only accelerates the convergence process but also improves the detection accuracy of FDIA.

[0132] Specifically, after the LSTM model is pre-trained with the synthetic data generated by WGAN, the next step is to combine the model with the actual normal data to further optimize its parameters so that it can better capture the temporal characteristics and long-term dependencies, providing accurate temporal features for anomaly detection. At this stage, the LSTM model fully learns the temporal characteristics, volatility, and potential long-term dependencies by inputting historical actual normal measurement data. The real data provides more complex and diverse dynamic features for the LSTM model, enabling the model to more accurately capture the actual operation mode and fluctuation trend. By combining with the real data, the LSTM model can effectively adjust its internal state, better fit the temporal features, and improve the prediction ability and adaptability of the model.

[0133] After the LSTM model is combined with the actual normal data, the model will be further trained to optimize its parameters. By analyzing the temporal features of the data during normal operation, the LSTM model can better learn and extract the long-term dependencies and temporal patterns in the data. This process helps the model better distinguish normal operation modes from possible future abnormal behaviors.

[0134] The parameter optimization of the LSTM model can be achieved through algorithms such as backpropagation and gradient descent, enabling the model to more accurately predict the temporal characteristics during normal operation. In this way, the LSTM model can provide efficient temporal information for subsequent anomaly detection tasks, thereby improving the detection accuracy of FDIA.

[0135] S4. Initialize the parameters of the CNN-Transformer model, and input the temporal features extracted by the LSTM model and the normal data samples as a data combination into the CNN-Transformer model. Extract the local temporal features of the input data combination through the CNN model therein, and capture the global temporal evolution characteristics of the input data combination through the Transformer model therein to generate a dynamic threshold.

[0136] In this embodiment, the initialization of the CNN-Transformer model aims to extract global and local features from historical data. To improve the convergence speed, Kaiming initialization (for convolutional layers) and Xavier initialization (for fully connected layers) are used to initialize the model parameters. The CNN part is used to extract local temporal features, while the Transformer captures global temporal information, thereby helping the model learn spatio-temporal correlations and accelerate training.

[0137] Further, to accurately detect FDIA, after the LSTM model is trained, the CNN-Transformer model will then be used to extract global features and generate dynamic thresholds for normal data samples.

[0138] First, the features generated by the LSTM model through temporal modeling and the normal data samples are input into the CNN-Transformer model together. The CNN model extracts local temporal features of the input data, and then the Transformer captures the global temporal evolution characteristics of the input data.

[0139] Specifically, after the LSTM model is trained and generates temporal features, these features and the normal data samples are then input into the CNN-Transformer model together, that is:

[0140] (10);

[0141] In Equation (10): represents the input of the CNN-Transformer model; represents the temporal features extracted by the LSTM model; represents the normal data samples.

[0142] The temporal features generated by the LSTM model contain the dynamic changes and long-term dependencies of, while the preprocessed data provides the actual measurement information of. By combining these two, the CNN-Transformer model can more comprehensively capture the temporal evolution characteristics of the data and learn more complex features.

[0143] The local temporal features of the input data are extracted through the CNN model. Specifically: through the CNN model, the input temporal data will be processed by its convolutional layers to extract local temporal features. The convolutional layers can effectively capture the local fluctuations and short-term changes in the data, such as instantaneous load fluctuations and other rapidly changing patterns. Each convolutional layer filters the data through the convolutional kernel to extract local feature information at different scales.

[0144] The convolution operation is expressed as:

[0145] (11);

[0146] In formula (11): represents the convolution operation; represents the local temporal features extracted by the CNN model; represents the activation function; represents the convolution kernel of the convolutional layer.

[0147] Through this process, the CNN can effectively capture local fluctuations in, such as short-term anomalies like load fluctuations.

[0148] After the CNN extracts local features, the data will be passed to the Transformer model. The Transformer captures long-term temporal dependencies in the data through the self-attention mechanism. It learns the global temporal evolution pattern in by weighted summation of the features of each time step with the features of other time steps, thereby helping the model understand the global trend and complex temporal characteristics of.

[0149] The self-attention mechanism is expressed as:

[0150] (12);

[0151] In formula (12): represents the query, used to query the correlation between time steps; represents the key, used to calculate similarity; represents the value matrix, containing the original feature information; represents the output of the self-attention mechanism, which is a weighted representation of the global temporal features, capturing the long-term dependencies between each time step in the time series.

[0152] Through this mechanism, the Transformer can capture global temporal relationships and generate global features.

[0153] Finally, the model will generate dynamic upper and lower threshold values according to the temporal evolution of the data, and these threshold values can be automatically adjusted according to the distribution of the actual data.

[0154] S5. Optimize the interval range of the dynamic threshold based on the quantile loss function, and monitor the measurement data of the sensor to be detected based on the optimized dynamic threshold. Compare the preprocessed measurement data of the sensor to be detected with the interval range of the dynamic threshold. If it exceeds the interval range of the dynamic threshold, it is determined that there is an attack.

[0155] That is, based on the distribution characteristics of the data, the quantile loss function is used to dynamically adjust the threshold interval to ensure the accurate detection of abnormal data.

[0156] In the process of generating the dynamic threshold, the model optimizes the upper and lower limits by introducing the quantile loss function. To achieve this goal, two independent CNN-Transformer models are used in this method: one model is used to predict the upper limit, and the other model is used to predict the lower limit. Through these models, the generated dynamic threshold can adapt to the distribution characteristics of the data.

[0157] The quantile loss function is as follows:

[0158] (13);

[0159] In formula (13): represents the quantile loss function; represents the predicted value of the CNN-Transformer model; represents the true value; is the set quantile. For example, 0.95 represents the 95% quantile of the predicted upper limit, and 0.05 represents the 5% quantile of the predicted lower limit; represents the number of training samples, that is, the total number of characteristic values of normal data samples.

[0160] By minimizing this loss function, the model will dynamically adjust the predicted upper and lower limits, thereby generating a dynamic threshold that adapts to the data distribution.

[0161] The upper limit CNN-Transformer model adjusts the predicted upper limit by minimizing the quantile loss function, so that normal data can be better adapted within the high quantile interval (such as the 95% quantile), ensuring that normal data does not exceed the upper limit.

[0162] The lower limit CNN-Transformer model optimizes the lower limit prediction through the quantile loss function, so that normal data can be accurately adapted within the low quantile interval (such as the 5% quantile) and will not be predicted as abnormal. Abnormal data (such as FDIA) usually deviates from the normal data distribution, so they are likely to exceed the lower limit and are thus identified as abnormal.

[0163] In this way, the model can automatically generate a more accurate dynamic threshold based on the distribution characteristics of the data and effectively detect abnormal data or potential FDIA.

[0164] After the threshold values are generated, the model monitors the monitoring data of the sensors to be detected based on these dynamic threshold values. First, preprocessing operations such as outlier filtering, time alignment, and normalization are performed on the monitoring data of the sensors to be detected, and then the preprocessed monitoring data of the sensors to be detected is compared with the threshold range. When the monitoring data of a certain sensor to be detected exceeds the dynamically generated threshold range , it will be marked as abnormal data. These abnormal data may be caused by FDIA. The localization of the attack can be completed through the detected abnormal features and their corresponding time ranges.

[0165] During the monitoring process, this method determines whether there is an attack by calculating whether each data sample exceeds the threshold range. The specific judgment formula is:

[0166] (14);

[0167] In formula (14): represents the preprocessed monitoring data of the sensors to be detected; represents the upper limit of the dynamic threshold; represents the lower limit of the dynamic threshold.

[0168] Finally, repeat the above steps S2~S5 to continuously optimize the parameters of the WGAN, LSTM, and CNN-Transformer models to ensure the robustness and efficiency of the detection and localization models in a dynamic environment.

[0169] To ensure the robustness and efficiency of the detection and localization models in a dynamic environment, it is necessary to continuously optimize the parameters of the WGAN, LSTM, and CNN-Transformer models. During the training process, the parameters of the generator and discriminator of the WGAN are the key points of optimization. By continuously adjusting their weights, the generated data can be made closer to the real data. This process can improve the model's detection ability for FDIA. At the same time, adopting appropriate loss functions and regularization techniques helps to avoid training problems such as mode collapse.

[0170] The LSTM model focuses on processing the temporal characteristics in the data. By optimizing the hyperparameters such as the hidden layer, learning rate, and gating mechanism of the LSTM, the model's ability to capture temporal data can be improved, thereby enhancing the accuracy and stability of the detection.

[0171] The CNN-Transformer model combines the advantages of convolutional neural networks and Transformers, enabling it to extract both spatial and temporal features of data simultaneously. Optimizing the convolutional layer, attention mechanism, and the encoder and decoder structures of the Transformer helps enhance the ability of feature extraction and temporal modeling, thereby improving the effectiveness of FDIA detection and localization.

[0172] After multiple rounds of training and parameter adjustment, the model can gradually improve its accuracy and stability in data processing. After each round of iterative training, the model adjusts its parameters based on the performance on the validation set, gradually learning more data features and enhancing its ability to detect FDIA. By optimizing the algorithm to adjust the learning rate and regularization parameters, the training is ensured to be stable and overfitting is avoided.

[0173] Overfitting is a key issue in optimization, which may cause the model to be unable to generalize to new data. To address this, regularization methods (such as L2 regularization, Dropout, etc.) can be used to prevent overfitting. At the same time, the model complexity is adjusted and the number of training rounds is increased to solve the underfitting problem and ensure that the model fully learns the data features.

[0174] To improve stability, techniques such as learning rate decay and gradient clipping can be adopted to avoid gradient explosion or vanishing. Methods such as adjusting the batch size and introducing an early stopping mechanism help maintain stability during the training process.

[0175] As the training progresses, the model gradually improves its accuracy in detecting false data injection attacks and ensures its generalization ability in different scenarios through methods such as cross-validation. Through these optimization strategies, the WGAN, LSTM, and CNN-Transformer models can provide efficient, accurate, and robust detection and localization capabilities in dynamic data.

[0176] This method is applicable to various sensor networks and complex network environments. For the sake of illustration, the following embodiments will be described in detail taking the smart grid scenario as an example.

[0177] The method includes the following steps:

[0178] S1. Data acquisition and preprocessing:

[0179] First, historical measurement data is obtained from multiple sensors in the smart grid. These data include multi-dimensional features of the power grid (such as voltage, current, active power, reactive power, etc.) for detecting FDIA.

[0180] The collected sensor data is preprocessed, including data cleaning, outlier filtering, time alignment, and normalization, to ensure data consistency and high quality. The preprocessed data is used to initialize model training.

[0181] S2. WGAN Model Initialization and Synthetic Data Generation:

[0182] Initialize the parameters of the WGAN generator and discriminator;

[0183] Using the WGAN generator, combined with the physical constraint loss function and the time condition embedding mechanism, generate regular synthetic data only using normal operation data.

[0184] S3. LSTM Model Initialization and Pre-training:

[0185] Initialize the weight matrix of the LSTM model;

[0186] Use the synthetic data generated by the WGAN generator to pre-train the LSTM model to capture the temporal characteristics and long-term dependencies.

[0187] S4. CNN-Transformer Model Initialization, Feature Extraction and Dynamic Threshold Generation:

[0188] Initialize the convolutional kernels and attention weights of the CNN-Transformer model;

[0189] After the LSTM model completes pre-training, further use the CNN-Transformer model to extract global and local features from normal data and generate dynamic detection thresholds. The CNN model is used to extract local temporal features, while the Transformer model captures global features through the self-attention mechanism.

[0190] S5. Dynamic Threshold Optimization and Attack Detection and Location Based on Dynamic Threshold:

[0191] Combine the quantile loss function to generate dynamic upper and lower threshold values to accurately distinguish normal data from abnormal data;

[0192] Use the dynamic threshold to detect the input data. When the data exceeds the set dynamic threshold range, trigger the attack detection mechanism. Based on the difference between the features extracted by the CNN-Transformer and the actual observed data, use the classification network model to accurately locate the sensor positions under attack.

[0193] Based on the above, after completing the attack detection and location, through multiple rounds of iterative training, continuously optimize the parameters of the WGAN, LSTM, and CNN-Transformer models. Update the parameters and conduct performance evaluations to ensure that the detection accuracy and robustness of the models are gradually improved in the dynamic power grid environment.

[0194] Conduct experimental comparisons. The following are some basic settings for the experiments:

[0195] The present invention verifies the performance of the FDIA detection and localization method based on WGAN and CNN-Transformer through multiple experiments. The simulation experiment is based on the IEEE 14-node power grid model and uses the MATPOWER simulation environment. The experimental dataset includes hourly power grid data and an attack vector dataset generated through a formal model. These attack vectors are designed to tamper with sensor data to evade the detection of the BDD system and affect the power grid state estimation. In the experimental setup, 50% of the data is used for training and 50% for testing. The experiment is conducted in a high-performance computing environment equipped with an NVIDIA GeForce RTX 3090 graphics card.

[0196] Figure 2 It shows the comparison of the generated data and the real data in terms of power conservation. The data generated by the method of the present invention is significantly superior to the traditional WGAN method in terms of power conservation deviation and is closer to the real data distribution. The average power deviation of the data generated by the method of the present invention is 11.97 MW, lower than 20.01 MW of the traditional WGAN method, showing the important role of the physical constraint loss function in power conservation during the generation process. This indicates that the data generated by the method of the present invention can better reflect the actual operating characteristics of the power grid and provides high-quality training samples for subsequent anomaly detection.

[0197] Figure 3 It shows the moving average trends of different data generation methods with a moving window size of 5. The experimental results show that the moving average (red solid line) generated by the method of the present invention is highly consistent with the real data (blue solid line), while the traditional generation method based on simple noise (green solid line) shows obvious deviations. This indicates that the method of the present invention has significant advantages in temporal dynamic consistency and can better capture the temporal characteristics of the operating data.

[0198] Table 1 shows the performance comparison between the method of the present invention (Our) and other baseline methods in the false data injection attack detection task. The evaluation metrics include precision, recall / TPR, F1-score, false positive rate (FPR), and area under the curve (AUC). The comparison methods include traditional CNN, EE-PMQ, MMLD, and SSA-CNN.

[0199] Table 1

[0200]

[0201] As can be seen from Table 1, the method of the present invention performs excellently in comprehensive performance. The method of the present invention shows high detection ability in terms of F1 score and Recall, while maintaining a low FPR, significantly improving the detection accuracy compared with traditional CNN. Although the Precision of EE-PMQ and MMLD reaches 1.0000, their Recall is low, indicating a high false negative rate and possibly missing a large number of covert attacks. SSA-CNN performs excellently in terms of AUC and F1 score, but is slightly inferior to the present method in Recall, indicating that its coverage ability for certain attacks is slightly weaker. By introducing physical constraints, time condition embedding and dynamic threshold generation mechanism, the present method effectively improves the detection performance of false data injection attacks, especially outstanding in balancing false positives and false negatives.

[0202] Table 2 further shows the performance comparison between the method of the present invention (Our) and other baseline methods in the task of false data injection attack detection and localization. The evaluation metrics include row accuracy (RACC, Random Adjusted Concordance Coefficient) and detection accuracy. RACC measures the overall prediction accuracy of the model for all measurement point labels in a multi-label classification task, that is, the probability that all uncompromised positions are correctly labeled as uncompromised and all compromised positions are correctly labeled as compromised. Row accuracy detects the ability to detect the existence of attacks. The comparison methods are the same as in Table 1, including traditional CNN, EE-PMQ, MMLD and SSA-CNN.

[0203] Table 2

[0204]

[0205] As can be seen from Table 2, the method of the present invention is significantly superior to other baseline methods in both RACC and Detection Accuracy, demonstrating its excellent performance in detecting and localizing false data injection attacks. The specific analysis is as follows:

[0206] The RACC of the present method is 0.9013, significantly higher than that of CNN (0.5118), EE-PMQ (0.6492), MMLD (0.6563), and slightly higher than that of SSA-CNN (0.8725). RACC measures the classification consistency of the model for the states of all measurement points after excluding random guessing. A high value indicates that the present method can accurately locate the source of the attack. The low RACC of CNN (0.5118) shows that its localization ability is close to random level, while the improvement of EE-PMQ and MMLD is limited and the localization is still insufficient.

[0207] The line detection accuracy of this method is 0.9903, which is close to perfection and far exceeds CNN (0.7033), EE-PMQ (0.6672), MMLD (0.6690), and SSA-CNN (0.9229). Let's take a step back and investigate how effective the proposed mechanism is in detecting the presence of attacks. Specifically, we consider the power system as not being attacked or the attack not existing if for all Otherwise, we consider the power system as being attacked or the attack existing. This metric reflects the model's ability to distinguish between attacks and normal states, and the excellent performance of this method verifies its detection reliability, especially for stealth attacks.

[0208] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the claims of the present invention shall be included within the protection scope of the claims of the present invention.

Claims

1. A false data injection attack detection and location method based on physical constraints and adaptive thresholds, characterized in that: The method comprises: S1. Acquire historical measurement data from multiple sensors, and preprocess the historical measurement data to obtain normal data samples; S2, initializing the parameters of the generator and the discriminator of the generative adversarial network WGAN, and performing model training on the generative adversarial network WGAN in combination with the time condition embedding and the physical constraint loss function, so that the generator generates synthetic data samples that conform to the physical laws of the system based on the normal data samples; The generator and discriminator of the generative adversarial network WGAN are initialized by using a weight initialization method based on prior knowledge; and physical constraints are introduced during model training: (2); In formula (2): Indicates the total generated power in MW; Indicates the total load power generated in MW; represents the generated transmission loss in MW; Define the physical constraint loss function for: (3); In formula (3): It represents the physical constraint loss and uses the L2 norm to measure the deviation from power conservation to ensure power conservation; The intermediate loss function of the generator considers the combination of physical constraints and WGAN loss: (4); In formula (4): Represents the intermediate loss function of the generator; represents the WGAN loss of the generator, which is used to constrain the data distribution; is a hyperparameter used to adjust the weight of the physical constraint loss in the generator optimization process; The total loss function of the generator adds the temporal consistency loss to its intermediate loss function: (5); In formula (5): represents the total loss function of the generator; Represents the time consistency loss, which is used to ensure the time dynamic consistency; is a hyperparameter; The temporal consistency loss for: (6); In formula (6): Indicates the generation of data; Indicates the real data at this time point The mean of makes GAN closer to the real data in the time dimension. , Represents the time condition, which is a discrete time point in a 24-hour day; S3, initializing the parameters of the LSTM model, first pre-training the LSTM model using the synthetic data sample, then optimizing the parameters of the pre-trained LSTM model in combination with actual data, and extracting the time series features of the normal data sample using the optimized LSTM model; S4, initializing the parameters of the CNN-Transformer model, inputting the time series features extracted by the LSTM model and the normal data sample as a data combination into the CNN-Transformer model, extracting the local time series features of the input data combination through the CNN model, and capturing the global time series evolution characteristics of the input data combination through the Transformer model, so as to generate a dynamic threshold; S5. Optimize the interval range of the dynamic threshold based on the quantile loss function, monitor the measurement data of the sensor to be detected based on the optimized dynamic threshold, compare the preprocessed measurement data of the sensor to be detected with the interval range of the dynamic threshold, and if it exceeds the interval range of the dynamic threshold, it is determined that an attack exists.

2. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S1, preprocessing the historical measurement data specifically includes: Performing data cleaning on the historical measurement data to remove abnormal values ​​therein; Performing time alignment on the cleaned historical measurement data to make the time mark of each data point consistent; The aligned historical measurement data are processed by Z-score standardization to adjust all data to the same scale range; Among them, the formula for Z-score standardization is: (1); In formula (1): represents the data before normalization; represents the mean of the data; represents the standard deviation of the data, Represents the normalized data.

3. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S2, the time condition embedding uses one-hot encoding to convert the time information of 24 hours a day into a 24-dimensional vector; in the model structure, the time condition embedding is used as the input of the generator and the discriminator in the generative adversarial network WGAN, where the input of the generator By random noise η and time embedding composition: (7); Input to the discriminator From normal data samples and time embedding composition: (8)。 4. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S3, the weight of the LSTM model is initialized by uniform distribution, and its bias is initialized to zero; when the LSTM model is pre-trained, its input is a synthetic data sample, and its output is a time series value of the next time step; the pre-training objective function of the LSTM model is for: (9); In formula (9): Represents the true time series value corresponding to the next time step in the synthetic data sample; Represents the time series value of the next time step predicted by the LSTM model.

5. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S4, the parameters of the CNN-Transformer model are initialized using Kaiming initialization and Xavier initialization; the time series features extracted by the LSTM model and the normal data samples are input into the CNN-Transformer model as a data combination: (10); In formula (10): Represents the input of the CNN-Transformer model; Represents the time series features extracted by the LSTM model; represents a normal data sample.

6. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 5 is characterized in that: In S4, the local temporal features of the input data combination are extracted through the convolution layer of the CNN model, and the convolution operation is expressed as: (11); In formula (11): Represents the convolution operation; Represents the local temporal features extracted by the CNN model; represents the activation function; Represents the convolution kernel of the convolution layer.

7. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 6 is characterized in that: In S4, the Transformer model captures the global temporal evolution characteristics of the input data combination through the self-attention mechanism, and the self-attention mechanism is expressed as: (12); In formula (12): Represents a query, which is used to query the correlation between time steps; Represents the key, used to calculate similarity; Represents the value matrix, containing the original feature information; Represents the output of the self-attention mechanism, which is a weighted representation of the global temporal features, capturing the long-term dependencies between time steps in the time series.

8. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S5, two independent CNN-Transformer models are used to adjust the upper limit and lower limit of the dynamic threshold respectively, wherein the upper limit of the prediction is adjusted by minimizing the quantile loss function, and the lower limit of the prediction is optimized by the quantile loss function; the quantile loss function is: (13); In formula (13): represents the quantile loss function; Represents the predicted value of the CNN-Transformer model; represents the true value; is the set quantile; Represents the number of training samples, which is the total number of eigenvalues ​​of normal data samples.

9. The false data injection attack detection and location method based on physical constraints and adaptive thresholds according to claim 1 is characterized in that: In S5, the formula for determining whether an attack exists is: (14); In formula (14): Represents the pre-processed measurement data of the sensor to be detected; Indicates the upper limit of the dynamic threshold; Indicates the lower limit of the dynamic threshold.

Citation Information

Patent Citations

  • False data injection attack detection method and device based on LSTM network

    CN113094702A

  • False data injection attack simulation and detection method and device, equipment and medium

    CN116886351A

  • SQL (Structured Query Language) attack false alarm elimination method

    CN119109678A

  • System and method for DNN-based cyber-security using federated learning-based generative adversarial network

    US20230308465A1