Vehicle-network interaction cyber-physical system risk assessment method
By using Kalman filtering and Euclidean distance similarity to detect spoofing attacks, and combining this with an attack gain function to assess risk, this approach addresses the shortcomings of existing technologies in combining spoofing attack detection with risk assessment. It enables real-time risk assessment and state prediction for vehicle-to-grid (V2G) interactive power systems, thereby improving system stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ECONOMIC TECH RES INST OF STATE GRID HENAN ELECTRIC POWER
- Filing Date
- 2025-01-13
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies fail to effectively combine the detection of fake data injection attacks with the risk assessment of power cyber-physical systems, making it impossible to identify attack locations and assess system risks in real time, thus threatening the stability and reliability of power systems.
A fake data injection attack detection method based on Kalman filtering is adopted. Fake data injection is detected by Euclidean distance similarity, and the system risk is evaluated by combining the attack gain function, predicting the system state and performing risk assessment.
It enables real-time detection and risk assessment of spoofed data injection attacks on vehicle-to-grid (V2G) power cyber-physical systems, predicts system status and assesses potential risks, prevents line overload caused by erroneous commands, and improves system stability and reliability.
Smart Images

Figure CN119921996B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a technology in the field of information security, specifically a risk assessment method for a vehicle-to-grid (V2G) power cyber-physical system susceptible to false data injection attacks. Background Technology
[0002] As a critical infrastructure ensuring the normal operation of society, the stability and reliability of the power system are of paramount importance. However, with the widespread integration of smart devices, a massive amount of data floods into the power system from various device interfaces. Among this data, the presence of false data is like a hidden tumor, posing a serious threat to the safe operation of the power system. False data exerts its destructive power by interfering with system status data. The power system control center relies on accurate system status data to make decisions directly related to power dispatch and distribution. When false data is mixed in, the authenticity and accuracy of the system status data are compromised, and the control center may issue erroneous commands based on this contaminated data. The consequences of these erroneous commands are unimaginable; for example, they may lead to line overload. Line overload causes the current in the line to exceed its design carrying capacity, leading to problems such as line overheating, accelerated insulation aging, and in severe cases, even line fires, resulting in large-scale power outages. Furthermore, erroneous commands may also cause load wear. This chain reaction triggered by false data presents a significant challenge to the stable operation of the power system. However, the limitations of the existing research include: firstly, current research on the detection of false data injection attacks does not integrate it with the risk assessment of power physical information systems; secondly, current research only detects the existence of false data injection attacks in power physical information systems, not their location.
[0003] In the vehicle-to-grid (V2G) cyber-physical systems, threats arise from spoofed data injection attacks. Attackers can inject false data into vulnerable parts of the control center, communication system, and actuators, causing decision-making failures and achieving their attack objectives. With the increasing number of connected devices in the power grid, the amount of data received by the data acquisition and monitoring control system surges, making it susceptible to spoofed information injection. This can lead to incorrect dispatching commands from the command and control system, causing problems such as overload of distribution network lines and damage to V2G equipment like charging stations in the V2G system. Summary of the Invention
[0004] This invention addresses the shortcomings of existing technologies that fail to combine false data injection attack detection with risk assessment, and are unable to perform risk assessments on the system upon detection of false data attacks. It proposes a risk assessment method for vehicle-to-grid (V2G) power information and physical systems. By detecting false data injection attacks on V2G power information and physical systems and designing a risk assessment method based on attack gains, this method can estimate the current system state and predict the state at the next moment, which is beneficial for system regulation and promotes the management of V2G power information and physical systems.
[0005] This invention is achieved through the following technical solution:
[0006] This invention relates to a risk assessment method for a vehicle-to-grid (V2G) interactive cyber-physical system, comprising:
[0007] Step 1: Collect the state parameters of the vehicle-to-everything (V2X) interaction system and input them into the constructed system space state model. Specifically: , The data collected by the control center at time t are the vehicle-to-grid interactive power information physical system data (system active power, reactive power, etc.). System status data (system voltage amplitude, phase angle); for At time t, the state transition function represents the change in the system state at the previous time. for At time t, the measurement function represents the coupling relationship between the measured value and the state variable; and These represent the state variables and measurement data errors at time t, respectively; system state variables. and system state covariance , Let be the Kalman filter gain at time t; The change in measurement state data after a false data injection attack, representing the predicted covariance at time t. State data change residual Attack constraints .
[0008] Step 2: Based on the fake data injection attack detection model, when the system is not attacked, the Euclidean distance similarity is close to 1. When attacked by fake data injection, the ratio will deviate sharply from 1. This leads to the objective of detecting fake data injection attacks: specifically, the Euclidean distance similarity of the measurement states of the vehicle-to-grid (V2G) power information physical system. Where: Euclidean similarity at the initial moment , Let be the estimated value obtained at time t based on the Kalman filter algorithm. When attacked, its measurement value changes as follows: The Euclidean distance similarity at time t , Set detection thresholds using historical data , To set a threshold; and These are the lower and upper bounds of the ratio under normal circumstances; when If it is not, it is vulnerable to data injection attacks. Conversely, it is normal. .
[0009] Step 3: Based on the status of the vehicle-to-grid interactive power physical information system, detect the attacked nodes using the fake data injection attack model.
[0010] Step 4: Calculate the attack gain function of the fake data injection attack. The decision is made regarding the cost of a system node being subjected to a fake data injection attack, including: For attack buff, The probability of a successful attack on point k, which is subject to a false injection attack. The impact of fake data injection attacks on the vehicle-to-grid (V2G) cyber-physical systems. The system recovery factor is the one that determines the system recovery cost and the impact of the attack.
[0011] Step 5: Calculate the single-step profit and success probability of the fake data injection attack, including: overall attack profit. Among them: single-step attack bonus, bonus per step , To generate profit when attacking node k, The degree of vulnerability that an attacker can exploit in node k; The single-step attack profit from node k to node k+1; the probability of a successful attack when a single node is subjected to a fake data injection attack. The level of node defense when node k is attacked. , Inject an attack vector into the data of node k; The attack complexity when node k is subjected to a data injection attack; the degree of vulnerability patching for node k. and the degree of vulnerability exposure ; , , , These are the weighting coefficients for each parameter, which can be determined based on the situation of the fake data injection attack nodes. For Pareto distribution parameters; the extent to which an attacker exploits a vulnerability in a vulnerable node. , This represents the number of system nodes involved in the attack by the attacker. This represents the number of nodes successfully attacked by the attacker. Let k be the number of times node k was attacked.
[0012] Step 6: Calculate the risk losses of the vehicle-to-grid (V2G) power physical information system, including: the instantaneous losses to charging station users connected to the power distribution network and the physical consequences and communication delays of the long-term recovery process.
[0013] Step 7: Calculate the attack gain function and evaluate the risk of a successful attack on a node in the vehicle-to-grid (V2G) power physical information system.
[0014] Technical effect
[0015] This invention detects spoofing attacks by estimating the state of the vehicle-to-grid (V2G) power information physical system and using Euclidean distance based on Kerman filtering; and conducts a risk assessment of the V2G power physical information system based on attack gain, physical losses of spoofing attacks, and communication delay consequences. Attached Figure Description
[0016] Figure 1 A schematic diagram of a vehicle-to-grid (V2G) power information physical system;
[0017] Figure 2 This is a flowchart of the present invention;
[0018] Figure 3 This is a schematic diagram of the risk assessment module for the vehicle-to-grid (V2G) power information physical system. Detailed Implementation
[0019] like Figure 1 As shown, this embodiment relates to a risk assessment method for a vehicle-to-grid (V2G) interactive power cyber-physical system, including:
[0020] Step 1) Detection of fake information injection attacks, specifically including:
[0021] 1.1 Establishing a system space state model ,in: The data collected by the control center at time t are the vehicle-to-grid interactive power information physical system data (system active power, reactive power, etc.). System status data (system voltage amplitude, phase angle); for At time t, the state transition function represents the change in the system state at the previous time. for At time t, the measurement function represents the coupling relationship between the measured value and the state variable; and These represent the state variable and the measurement data error at time t, respectively.
[0022] 1.2 The unscented Kalman filter method is used to estimate the state of the system, and its state variables and covariance are obtained, specifically: , ,in: Let be the Kalman filter gain at time t; Predict the covariance at time t;
[0023] 1.3 In a complete vehicle-to-grid (V2G) interactive power cyber-physical system, the residual is calculated based on the changes in its measurement status data after being subjected to a false data injection attack. Specifically: ,in: When a vehicle-to-grid (V2G) interconnected power information physical system is attacked, the actual measured values it acquires will rapidly deviate. However, due to the inherent characteristics of the Kalman filter algorithm, the state estimate obtained when estimating the system state will not change abruptly due to the introduction of an attack. Therefore, to identify spoofed data injection attacks, this invention uses Euclidean distance similarity to describe the similarity between the actual measured value and the predicted value. Simultaneously, it uses the ratio at different times to describe whether an attack has occurred, and sets an appropriate threshold based on historical system data.
[0024] 1.4 The purpose of the fake data injection attack is to overload the lines of the vehicle-to-grid (V2G) power information physical system. Therefore, its attack constraints are: ,in: and The active and reactive power of the target line l; and The active and reactive power increments when the target line l is attacked; The maximum apparent power of the target line l.
[0025] Step 2) Detection of False Data Intrusion: The Euclidean distance method is used to detect the similarity between adjacent time points. When false data injects into the system, its actual measurement value will change abruptly, but due to the influence of the Kalman filter algorithm, it will converge to the normal value in the next time point. Therefore, based on the historical data of the vehicle-to-grid interactive power information physical system under normal operation, an appropriate threshold is set, specifically including:
[0026] 2.1 Attack Detection Algorithm: When the system is operating normally and has not suffered a spoofed data injection attack, its Euclidean similarity ratio with other reference data will remain at a stable level. However, once the system is attacked by a spoofed data injection attack, this ratio will change significantly or abruptly. It is based on this characteristic that it is possible to effectively determine whether the system has suffered a spoofed data injection attack.
[0027] The Euclidean distance similarity ,in: The value at time t is the estimated value obtained based on the Kalman filter algorithm; its Euclidean similarity at the initial time is... When attacked, its measurement value will change significantly: Then the Euclidean distance similarity at this time can be inferred. Euclidean distance similarity at time t .
[0028] When the system is not under attack, the Euclidean distance similarity is close to 1. When it is under attack by fake data injection, its ratio will deviate sharply from 1, thus achieving the purpose of detecting fake data injection attacks.
[0029] 2.2 Set detection thresholds using historical data, specifically as follows: ,in: To set a threshold; and These are the lower and upper bounds of the ratio under normal circumstances; when If it is not, it is vulnerable to data injection attacks. Otherwise, it is normal. .
[0030] Step 3) Risk Assessment of the Vehicle-to-Grid Interactive Power Information and Physical System: Based on the detection results of the fake data injection attack introduced in Section 1, the system risk assessment incorporates the results into a general information vulnerability scoring system to obtain the probability of a successful fake data injection attack. The system attack risk is assessed by calculating the attack gains, specifically including:
[0031] 3.1 Attack Gain Calculation: ,in: For attack buff, The probability of a successful attack on point k, which is subject to a false injection attack. The impact of fake data injection attacks on the vehicle-to-grid (V2G) cyber-physical systems. The system recovery factor is the one that determines the system recovery cost and the impact of the attack.
[0032] 3.2 Single-Step Attack Gain and Success Probability: In the process of a fake data injection attack, the success of the attack depends on both the attacker's attack capability and the defense of the vehicle-to-grid (V2G) power information physical system. Therefore, the probability of a single node being successfully attacked by a fake data injection attack is as follows: ,in: The extent to which the attacker exploits the vulnerability when the node k is under attack. The level of defense of node k when it is attacked; ,in: Inject an attack vector into the data of node k; Let be the attack complexity when node k is subjected to a data injection attack; and These represent the degree of remediation and the degree of vulnerability exposure for node k, respectively. , , , These are the weighting coefficients for each parameter, which can be determined based on the situation of the fake data injection attack nodes; ,in: The time taken to discover the vulnerability in node k. These are the parameters of the Weibull distribution; ,in: These are Pareto distribution parameters. The extent to which attackers exploit vulnerabilities in vulnerable nodes. ,in: This represents the number of system nodes involved in the attack by the attacker. This represents the number of nodes successfully attacked by the attacker. Let k be the number of times node k is attacked. Single-step attack gain, gain per step. ,in: To generate profit when attacking node k, The degree of vulnerability that an attacker can exploit in node k; Let the single-step attack gain from node k to node k+1 be the overall attack gain. .
[0033] 3.3 System Risk Analysis under Fake Data Injection Attacks: In the vehicle-to-grid (V2G) power information-physical system, attacks affect the communication system, power lines, and charging stations. Fake data injection introduces erroneous data into the system, potentially causing the control system to issue incorrect commands based on this data, resulting in system damage. The impact includes the instantaneous losses to charging station users connected to the power distribution network and the long recovery time, as well as communication delays.
[0034] The physical consequences include:
[0035] 1. Instantaneous Loss: Establish a fault load loss model and a fault loss number model that consider the power consumption level of users. Specifically, this includes: fault load loss. ,in: The number of load losses obtained after node k is attacked. For the user cluster that contains charging station users on the attacked node k; Let m be the rank factor. The number of loads carried by user m. Number of users lost due to faults. ,in: The total number of users in the affected user cluster m.
[0036] 2. Long-term loss, specifically: number of hours of failure-to-load operation. ,in: The duration of the fault is in hours, of which Location of the fault. Number of hours of user downtime due to the fault. Since the impact of various physical consequences on the power grid varies, dimensionless processing is performed on the baseline values of each indicator, and weights are assigned based on the actual fault conditions, specifically as follows: ,in: , , , These are the baseline values for each indicator. ,in: , , , These are the weighting coefficients for each indicator.
[0037] The aforementioned communication delay consequence refers to the fact that after being subjected to a fake data injection attack, the communication lines will also be affected, causing communication delays. Specifically: ,in: For the consequences of communication, Let be the average communication delay of the i-th data packet. Minimum acceptable communication latency; overall impact of fake data injection attacks .
[0038] Compared with existing technologies, this invention uses Kerman filtering to estimate the state of the vehicle-to-grid interactive power information physical system and Euclidean distance to detect spoofing data injection attacks; then, it evaluates the system attack location through attack gain; compared with single risk assessment, this invention can achieve both global fault early warning and prediction of fault location.
[0039] The above-described specific implementations can be partially adjusted by those skilled in the art in different ways without departing from the principles and purpose of the present invention. The scope of protection of the present invention is defined by the claims and is not limited to the above-described specific implementations. All implementation schemes within the scope of the claims are bound by the present invention.
Claims
1. A risk assessment method for a vehicle-to-grid (V2G) interactive power cyber-physical system, characterized in that, include: Step 1: Collect the state parameters of the vehicle-to-everything (V2X) interaction system and input them into the constructed system space state model. Specifically: , The data collected by the control center at time t represents the vehicle-to-grid (V2G) power information physical system data. System status data, for At time t, the state transition function represents the change in the system state at the previous time step. for At time t, the measurement function represents the coupling relationship between the measured value and the state variable. and These represent the state variables and measurement data errors at time t, respectively, and the system state variables. and system state covariance , Let be the Kalman filter gain at time t. The change in measurement state data after a false data injection attack, representing the predicted covariance at time t. State data change residual Attack constraints ,in: and The active and reactive power of the target line l, and The active and reactive power increments when target line l is attacked. The maximum apparent power of the target line l; Step 2: Based on the fake data injection attack detection model, when the system is not attacked, the Euclidean distance similarity is close to 1. When attacked by fake data injection, the ratio will deviate sharply from 1. This leads to the objective of detecting fake data injection attacks: specifically, the Euclidean distance similarity of the measurement states of the vehicle-to-grid (V2G) power information physical system. Where: the initial Euclidean similarity , Let be the estimated value obtained at time t based on the Kalman filter algorithm. When attacked, its measurement value changes as follows: The Euclidean distance similarity at time t , Set detection thresholds using historical data , To set a threshold, and These are the lower and upper bounds of the ratio under normal circumstances, when If it is not in a certain state, it will be vulnerable to data injection attacks; otherwise, it will function normally. ; Step 3: Based on the status of the vehicle-to-grid interactive power physical information system, detect the attacked nodes using the fake data injection attack model; Step 4: Calculate the attack gain function of the fake data injection attack. The decision is made regarding the cost of a system node being subjected to a fake data injection attack, including: For attack buff, The probability of a successful attack on point k, which is subject to a false injection attack. Impact of fake data injection attacks on the vehicle-to-grid (V2G) cyber-physical system. System recovery factor; Step 5: Calculate the single-step profit and success probability of the fake data injection attack, including: overall attack profit. Among them: single-step attack bonus, bonus per step , To generate profit when attacking node k, To determine the extent to which an attacker can exploit vulnerabilities in node k. The single-step attack profit from node k to node k+1 is the probability of a successful attack when a single node is subjected to a fake data injection attack. The level of node defense when node k is attacked. , Inject an attack vector into the data of node k. Let represent the attack complexity when node k is subjected to a data injection attack, and the degree of patching of the vulnerability in node k. and the degree of vulnerability exposure , , , , These are the weighting coefficients for each parameter, which can be determined based on the situation of the fake data injection attack nodes. The Pareto distribution parameters represent the extent to which an attacker can exploit vulnerabilities on vulnerable nodes. , This represents the number of system nodes involved in the attack by the attacker. This represents the number of nodes successfully attacked by the attacker. This represents the number of times node k was attacked. Step 6: Calculate the risk losses of the vehicle-to-grid interactive power physical information system, including: the instantaneous losses to charging station users connected to the distribution network and the physical consequences and communication delays of the long-term recovery process. Step 7: Calculate the attack gain function and evaluate the risk of a successful attack on a node in the vehicle-to-grid (V2G) power physical information system.
2. The risk assessment method for the vehicle-to-grid interactive power information physical system according to claim 1, characterized in that, Step 1 is implemented in the following way: 1.1 Establishing a system space state model ,in: The data collected by the control center at time t represents the vehicle-to-grid (V2G) power information physical system data. System status data, for At time t, the state transition function represents the change in the system state at the previous time step. for At time t, the measurement function represents the coupling relationship between the measured value and the state variable. and These represent the state variables and measurement data errors at time t, respectively. 1.2 The unscented Kalman filter method is used to estimate the state of the system, and its state variables and covariance are obtained, specifically: , ,in: Let be the Kalman filter gain at time t. Predict the covariance at time t; 1.3 In a complete vehicle-to-grid (V2G) interactive power cyber-physical system, the residual is calculated based on the changes in its measurement status data after being subjected to a false data injection attack. Specifically: ,in: The system uses Euclidean distance similarity to describe the similarity between the actual measurement and the predicted value. At the same time, it uses the ratio at different times to describe whether an attack has occurred, and sets an appropriate threshold based on the system's historical data. 1.4 The purpose of the fake data injection attack is to overload the lines of the vehicle-to-grid (V2G) power information physical system. Therefore, its attack constraints are: .
3. The risk assessment method for the vehicle-to-grid interactive power information physical system according to claim 1, characterized in that, The threshold in step 2 is obtained in the following way: 2.1 Attack Detection Algorithm: When the system is in normal operation and has not been attacked by false data injection, its Euclidean similarity ratio with other reference data will remain at a stable level. However, once the system is attacked by false data injection, this ratio will change significantly or abruptly. It is based on this characteristic that we can effectively determine whether the system has been attacked by false data injection. 2.2 Set detection thresholds using historical data, specifically as follows: ,in: To set a threshold, and These are the lower and upper bounds of the ratio under normal circumstances, when If it is not active, it is vulnerable to data injection attacks; otherwise, it is normal. .
4. The risk assessment method for the vehicle-to-grid interactive power information physical system according to claim 1, characterized in that, The probability of a successful attack is obtained in the following way: 3.1 Attack Gain Calculation: ,in: For attack buff, The probability of a successful attack on point k, which is subject to a false injection attack. Impact of fake data injection attacks on the vehicle-to-grid (V2G) cyber-physical system. System recovery factor; 3.2 Single-Step Attack Gain and Success Probability: In the process of a fake data injection attack, the success of the attack depends on both the attacker's attack capability and the defense of the vehicle-to-grid (V2G) power information physical system. Therefore, the probability of a single node being successfully attacked by a fake data injection attack is as follows: ,in: The degree to which the attacker exploits the vulnerability when the node k is under attack. The degree of node defense when node k is attacked. ,in: Inject an attack vector into the data of node k. Let be the attack complexity when node k is subjected to a data injection attack. and These represent the degree of remediation and the degree of vulnerability exposure for node k, respectively. , , , These are the weighting coefficients for each parameter, which can be determined based on the situation of the fake data injection attack nodes. ,in: The time taken to discover the vulnerability in node k. For the Weibull distribution parameters, ,in: The Pareto distribution parameters represent the extent to which attackers exploit vulnerabilities in vulnerable nodes. ,in: This represents the number of system nodes involved in the attack by the attacker. This represents the number of nodes successfully attacked by the attacker. For the number of times node k is attacked, the single-step attack gain is the gain per step. ,in: To generate profit when attacking node k, To determine the extent to which an attacker can exploit vulnerabilities in node k. Let the single-step attack gain from node k to node k+1 be the overall attack gain. ; 3.3 System Risk Analysis under False Data Injection Attack: In the power information physical system of vehicle-to-grid interaction, when attacked, the impact is on the communication system, lines and charging piles. False data injection causes the system to receive erroneous data. During operation, the control system may make incorrect instructions based on the erroneous data, causing losses to the system. The impact includes the instantaneous loss to users of charging stations connected to the power distribution network and the physical consequences of long-term recovery, as well as the consequences of communication delay.
5. The risk assessment method for a vehicle-to-grid interactive power information physical system according to claim 1 or 4, characterized in that, The physical consequences include: 4.1 Instantaneous Loss: Establish a fault load loss model and a fault loss number model considering the power consumption level of users. Specifically: Fault Load Loss ,in: The number of load losses obtained after node k is attacked. This refers to a user cluster on the attacked node k that contains users of charging stations. Let m be the level factor. The number of loads carried by user m, and the number of users lost due to failure. ,in: The total number of users in the affected user cluster m; 4.2 Long-term losses, specifically: number of hours of failure-to-load operation. ,in: The duration of the fault is in hours, where: Location of the fault point, number of hours of user downtime due to the fault. Since the impact of various physical consequences on the power grid varies, dimensionless processing is performed on the baseline values of each indicator, and weights are assigned based on the actual fault conditions, specifically as follows: ,in: , , , These are the baseline values for each indicator. ,in: , , , These are the weighting coefficients for each indicator.
6. The risk assessment method for a vehicle-to-grid interactive power information physical system according to claim 1 or 4, characterized in that, The aforementioned communication delay consequence refers to the fact that after being subjected to a fake data injection attack, the communication lines will also be affected, causing communication delays. Specifically: ,in: For the consequences of communication, Let be the average communication delay of the i-th data packet. The overall impact of a fake data injection attack with the minimum acceptable communication latency. .
Citation Information
Patent Citations
Power system load frequency safety control method and system under network attack
CN117459283A
Artificial neural network based false data detection and data aggregation in wireless sensor networks
IN201611000900A