Power grid information tampering attack positioning method and system

By applying a recurrent neural network model with a fusion self-attention mechanism in the power grid, the problem of grid information attack positioning is solved, the attack recognition efficiency and accuracy are improved, and the safe and stable operation of the power grid is ensured.

CN119945702APending Publication Date: 2025-05-06GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411642288.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The vulnerability of the power grid in the face of information attacks is prominent, and the existing technology is difficult to effectively locate and identify information tampering attacks, resulting in serious consequences such as instability in the power grid operation, misjudgment of decisions and market chaos.

Method used

A recurrent neural network (SA-RNN) model with a fusion self-attention mechanism is used to establish a mathematical model of information tampering attacks, analyze the impact of the attack on the power grid state quantity, and determine the attacked nodes through feature extraction.

Benefits of technology

It significantly improves the efficiency and accuracy of the abnormal behavior of the power grid, can timely identify the attacked nodes, provide power grid operators with tools to quickly respond and handle information tampering attacks, and ensure the safe and stable operation of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945702A_ABST
    Figure CN119945702A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent power distribution networks, in particular to a power grid information tampering attack positioning method and system, and the method comprises the steps: building an information tampering attack mathematical model, and analyzing the influence of the information tampering attack on the state quantity of a power grid; establishing a recurrent neural network (SA-RNN) model fused with a self-attention mechanism; and feature extraction is performed on the power grid load information after information tampering based on an SA-RNN model, and attacked nodes are determined. The method has the beneficial effects that the long-distance dependency relationship in the power grid data is effectively captured by utilizing a self-attention mechanism, and the recognition efficiency and accuracy of the abnormal behavior of the power grid are remarkably improved in combination with the capability of processing the time sequence data of the recurrent neural network. By analyzing the load of the power grid node and the output data of the generator in real time, the attacked node can be recognized in time, a powerful tool is provided for a power grid operator, information tampering attacks can be quickly responded and processed, and therefore safe and stable operation of the power grid is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart distribution network, and in particular to a method and system for locating power grid information tampering attacks. Background Art

[0002] As information and communication technologies (ICTs) are increasingly involved in the measurement, operation, control and protection of power systems, power systems are evolving into cyber physical power systems (CPPS) that deeply integrate information flows and energy flows in physical space. The high degree of cyber-physical coupling also means that more smart terminals are connected to the power grid, and their cyber-physical characteristics are becoming more complex and difficult to identify, which makes the power grid more vulnerable to information attacks.

[0003] There are more and more ways of information attack nowadays, such as false data injection attack (FDIA), man-in-the-middle attack (MiTMA), data replay attack (DRA), denial of service attack (DoS), etc. Once the massive sensitive data such as the topology structure, power load data, equipment status information, and operation indicators in the power grid are successfully attacked, it will cause serious consequences such as instability of the new power system, misjudgment of decision-making, and market chaos. These accidents show that the threat and potential harm of information attacks faced by the new power system cannot be ignored. It is particularly important to effectively locate potential information attacks as a leading measure for subsequent defense and dispatch. Summary of the invention

[0004] The purpose of this section is to summarize some aspects of embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of this application to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.

[0005] In view of the above existing problems, the present invention is proposed.

[0006] Therefore, the present invention provides a method and system for locating a power grid information tampering attack, which can solve the problems mentioned in the background technology.

[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0008] In a first aspect, the present invention provides a method for locating a power grid information tampering attack, including establishing a mathematical model of the information tampering attack and analyzing the impact of the information tampering attack on the power grid state quantity;

[0009] Establish a recurrent neural network (SA-RNN) model integrating self-attention mechanism;

[0010] Based on the SA-RNN model, the features of the grid load information after information tampering are extracted to determine the attacked nodes.

[0011] As a preferred solution of the power grid information tampering attack positioning method of the present invention, the SA-RNN model includes a two-layer RNN model, a self-attention layer, a fully connected layer and an output layer.

[0012] As a preferred solution of the power grid information tampering attack positioning method of the present invention, each layer of the RNN model includes an input layer, a hidden layer and an output layer, and the sample features are the load and generator output of each physical node after the power grid is attacked.

[0013] As a preferred solution of the power grid information tampering attack positioning method of the present invention, the following is used: based on the SA-RNN model, the power grid load information after information tampering is extracted to determine the attacked nodes including

[0014] The relevant data of each node in the power grid are input into the SA-RNN model as the training set and the test set to obtain the trained target SA-RNN model;

[0015] Obtain relevant data of the current power grid node and input it into the target SA-RNN model to obtain the current target node under attack.

[0016] As a preferred solution of the method for locating power grid information tampering attacks of the present invention, the relevant data includes load data.

[0017] As a preferred solution of the method for locating power grid information tampering attacks of the present invention, the relevant data also includes generator output data.

[0018] As a preferred solution of the power grid information tampering attack positioning method of the present invention, wherein: the attacked node is an information-physical coupling node with a load bus.

[0019] In a second aspect, the present invention provides a power grid information tampering attack positioning system, including: establishing an analysis module for establishing an information tampering attack mathematical model and analyzing the impact of the information tampering attack on the power grid state quantity;

[0020] Build a module for building a recurrent neural network (SA-RNN) model with self-attention mechanism;

[0021] The determination module is used to extract features of the grid load information after information tampering based on the SA-RNN model and determine the attacked nodes.

[0022] In a third aspect, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.

[0023] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when the computer program is executed by a processor.

[0024] Compared with the prior art, the present invention has the following beneficial effects: by utilizing the self-attention mechanism to effectively capture long-distance dependencies in power grid data, combined with the ability of recurrent neural networks to process time series data, the efficiency and accuracy of identifying abnormal behaviors in the power grid are significantly improved. By analyzing the load and generator output data of power grid nodes in real time, nodes under attack can be identified in a timely manner, providing power grid operators with a powerful tool to quickly respond to and handle information tampering attacks, thereby ensuring the safe and stable operation of the power grid. In addition, by combining offline training with online real-time monitoring, the solution reduces the reliance on complex coupling analysis and improves the practicality and efficiency of the power grid monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:

[0026] Figure 1 This is a flowchart of a method for locating power grid information tampering attacks.

[0027] Figure 2 This is the SA-RNN model structure diagram.

[0028] Figure 3 A schematic diagram of the internal structure of a computer device. DETAILED DESCRIPTION

[0029] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0030] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0031] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0032] Example 1

[0033] Reference Figure 1-2 , which is the first embodiment of the present invention, and provides a method for locating a power grid information tampering attack, which includes:

[0034] S1. Establish a mathematical model of information tampering attack and analyze the impact of information tampering attack on the state quantity of the power grid.

[0035] It should be noted that this step is specifically aimed at the high coupling of information and physics in the power information-physical system. It collects sensor measurements based on the wide-area wireless measurement (SCADA) system, such as power flow, power injection, circuit breaker status, voltage and other measurements, and analyzes how information tampering attacks can target the impact of data tampering on the power grid state quantity, so as to purposefully set tampering attack vectors, thereby avoiding bad data monitoring (BDD) and achieving the purpose of concealing attacks.

[0036] It is further necessary to explain the structure of the power information physical system (CPPS): the constructed power information physical system mainly consists of three parts: physical network, measurement equipment, communication network and various channels connecting the various parts. Specifically, the physical network system model: the power grid can be abstracted as a graph consisting of a set of point sets and a set of edge sets. In order to facilitate the calculation of power flow, the physical equipment of the power grid, such as power plants, substations, buses, etc., can be abstracted as PQ nodes, PV nodes, balancing nodes and isolation nodes. The power transmission lines are abstracted as the edges of the graph. For the convenience of representation, it can be described by an n×n matrix M:

[0037]

[0038] The diagonal element X in the above formula ii represents physical node i, non-diagonal element X ijIndicates that the reference direction is the transmission line from node i to node j. Information network system model: The power communication network is a dedicated communication network serving the operation of the power system. It is mainly laid according to the power grid structure and has a high degree of similarity with the power grid. Since the structure of the power grid varies from place to place, the structure of the power network system is also different. The power network system is roughly divided into three layers: core layer, backbone layer, and access layer. This paper believes that all information devices of each physical node in the power grid are assembled into a network node, and this network node forms a network-physical coupling with its corresponding physical node.

[0039] It is further necessary to explain the information tampering attack model: SCADA system is widely used in smart grid to monitor the operation of the system. It collects sensor measurements such as power flow, power injection, circuit breaker status, voltage, etc. These sensor measurements are transmitted to the control center through the SCADA network, where they are analyzed and processed to make control decisions. The mathematical expression of the relationship between sensor measurements and state variables is:

[0040]

[0041] in represents the measured value of the sensor, H is the measurement matrix, The state vector of the system contains control variables, power flow information, load information, etc. δ is an independent measurement noise, which is usually assumed to be sampled from a Gaussian distribution [i.e. ].

[0042] In the power system, the transmission network plays a vital role in the transmission and balance of electric energy. Information tampering attacks will change the control variable v of the line relay protection device (circuit breaker, switch, etc.), causing the transmission line to trip, which is mathematically expressed as:

[0043]

[0044] After a trip occurs, the topology of the power grid changes, the load of the attacked node may be lost, and the load of the rest of the power grid and the output of the generator will also change. Usually we use power flow calculation to reflect these changes:

[0045]

[0046] in is the branch power flow information, S j is the load information of other load nodes, G i is the generator output, Ψ(·) is the power flow calculation function, M is the topology information, is the measured value of the system status.

[0047] When an attacker launches an information tampering attack, he will input an attack vector based on a selected node to tamper with and overwrite the existing data. The mathematical expression of the attack vector is:

[0048]

[0049] in is the attack vector, v a is the tampered circuit breaker control variable, is the local load after tampering, It is the tampered power flow information of the attacked tripped line.

[0050] Usually there will be bad data detection (BDD) after the system state estimation. Circuit breaker relay protection devices are generally installed far away from the city to prevent some accidents. Therefore, if someone deliberately causes the circuit breaker to trip due to non-protection factors, the staff can often only judge whether there is a fault by the change of system measurement values. In order to hide the physical changes caused by the tripping attack, the attacker can avoid BDD detection by setting specific attack vector parameters, making it impossible for the staff to obtain any alarm information of the tripped transmission line. Under the attack, the system's measurement values ​​are as follows:

[0051]

[0052] in is the actual measured value after the system is attacked, x a is the state quantity of the system after being attacked, H a is the measurement matrix after the system is attacked, H is the measurement matrix when the system is normal, δ is the measurement noise, ΔH=HH a , because the system believes that the current topology information has not changed, it still uses H for calculation. is the measured value obtained by the system.

[0053] From the above analysis, we can see that the parameters in the attack vector only need to satisfy The Euclidean norm condition can bypass the BDD detection:

[0054]

[0055] Where τ is the BDD predetermined threshold, and v in the attack vector a , All three parameters can be obtained from the system data just before the attack, with certain noise fluctuations added.

[0056] S2. Establish a recurrent neural network (SA-RNN) model integrating self-attention mechanism.

[0057] It should be noted that the self-attention mechanism is implemented through a fully connected layer, which maps the hidden state of the last time step of the RNN to a new space. For each element in it, a query vector Q, a key vector K and a value vector V are calculated. Q and K are used to calculate the attention score, and then scaled by the softmax function to obtain the attention weight. The attention weight determines which features in the sequence the model should focus on. The attention output is obtained by multiplying the value vector V corresponding to the hidden state of the last time step by the attention weight element by element. This enables the model to redistribute the attention to different hidden states according to the attention weights, thereby highlighting more important features. The weighted attention output is passed to the hidden layer, and then after the ReLU activation function, the final prediction of the attacked node is generated through the output layer.

[0058] Preferably, the RNN has internal state (memory) that can be used to handle temporal or serial dependencies in the input sequence. The self-attention mechanism can consider all elements in the sequence at the same time, which enables it to capture long-distance dependencies more effectively and can be processed in parallel, thereby improving computational efficiency. The RNN model and the self-attention mechanism (SA) are introduced into power grid data analysis to quickly find nodes that are under information attack and maintain the stable operation of the power grid.

[0059] Furthermore, the SA-RNN model contains a two-layer RNN model, a self-attention layer, a fully connected layer, and an output layer.

[0060] Furthermore, each layer of the RNN model contains an input layer, a hidden layer, and an output layer, and the sample features are the load and generator output of each physical node after the power grid is attacked.

[0061] S3. Based on the SA-RNN model, feature extraction is performed on the grid load information after information tampering to determine the attacked nodes.

[0062] Furthermore, the attacked node is an information-physical coupling node with a load bus.

[0063] It should be noted that this application believes that when attackers choose attack nodes, they will only choose information-physical coupling nodes with load buses. This is because nodes with load buses often have regional control centers, and attackers can more easily hide the attack effect by tampering with the information of the control center. At the same time, these nodes carry a large amount of load. When the attacker successfully launches an attack, the load loss on the system will have a greater impact, and the possibility of system instability is also higher. If the usual flow calculation and state analysis methods are used to analyze real-time flow information, the required amount of calculation and calculation time are relatively long. The neural network method based on big data can get rid of the dependence on complex coupling analysis of multiple variables on the basis of offline training, and achieve rapid data analysis and judgment.

[0064] Furthermore, based on the SA-RNN model, the features of the grid load information after information tampering are extracted to determine the attacked nodes including

[0065] The relevant data of each node in the power grid are input into the SA-RNN model as the training set and the test set to obtain the trained target SA-RNN model;

[0066] Obtain relevant data of the current power grid node and input it into the target SA-RNN model to obtain the current target node under attack.

[0067] Furthermore, the relevant data includes load data.

[0068] Furthermore, the relevant data also includes generator output data.

[0069] It should be noted that the input of the model in this application is the load and generator output of each node in the power grid at different times and different attacked nodes. The SA-RNN model can effectively capture the correlation of different loads of the same attack node over a long distance and the changing characteristics of the load of each node at different times.

[0070] It should be further explained that, in view of the fact that the current power grid may be subject to hidden data tampering attacks, the load and generator processing data of each node in the current power grid are input into the SA-RNN model, and the attack status of the current power grid node is output to locate the attacked node.

[0071] In summary, the beneficial effect of the method for locating power grid information tampering attacks of the present invention is that it effectively captures long-distance dependencies in power grid data by utilizing the self-attention mechanism, and combines the ability of recurrent neural networks to process time series data, thereby significantly improving the efficiency and accuracy of identifying abnormal behaviors of the power grid. By analyzing the load and generator output data of power grid nodes in real time, nodes under attack can be identified in a timely manner, providing power grid operators with a powerful tool to quickly respond to and handle information tampering attacks, thereby ensuring the safe and stable operation of the power grid. In addition, the scheme reduces the reliance on complex coupling analysis and improves the practicality and efficiency of the power grid monitoring system by combining offline training with online real-time monitoring.

[0072] Example 2

[0073] This embodiment provides a power grid information tampering attack location system, which includes an establishment analysis module for establishing an information tampering attack mathematical model and analyzing the impact of the information tampering attack on the power grid state quantity;

[0074] Build a module for building a recurrent neural network (SA-RNN) model with self-attention mechanism;

[0075] The determination module is used to extract features of the grid load information after information tampering based on the SA-RNN model and determine the attacked nodes.

[0076] The above-mentioned unit modules may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to the above-mentioned modules.

[0077] Example 3

[0078] This embodiment provides a computer device, which may be a terminal, and its internal structure diagram may be as follows: Figure 3As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for locating a power grid information tampering attack is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.

[0079] This embodiment also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the following is achieved: establishing a mathematical model of information tampering attack, analyzing the impact of information tampering attack on power grid state quantities; establishing a recurrent neural network (SA-RNN) model integrating a self-attention mechanism; and extracting features of power grid load information after information tampering based on the SA-RNN model to determine the attacked nodes.

[0080] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for locating power grid information tampering attacks, characterized in that: include, Establish a mathematical model of information tampering attack and analyze the impact of information tampering attack on power grid status; Establish a recurrent neural network (SA-RNN) model integrating self-attention mechanism; Based on the SA-RNN model, feature extraction is performed on the tampered power grid load information to determine the attacked node.

2. The method for locating a power grid information tampering attack according to claim 1, characterized in that: The SA-RNN model includes a two-layer RNN model, a self-attention layer, a fully connected layer and an output layer.

3. The method for locating a power grid information tampering attack according to claim 2, characterized in that: Each layer of the RNN model includes an input layer, a hidden layer and an output layer, and the sample features are the load and generator output of each physical node after the power grid is attacked.

4. The method for locating a power grid information tampering attack according to claim 3, characterized in that: The SA-RNN model is used to extract features of the grid load information after information tampering, and determines that the attacked nodes include Inputting relevant data of each node of the power grid into the SA-RNN model as a training set and a test set to obtain a trained target SA-RNN model; The relevant data of the current power grid node is obtained and input into the target SA-RNN model to obtain the target node currently under attack.

5. The method for locating a power grid information tampering attack according to claim 4, characterized in that: The relevant data includes load data.

6. The method for locating a power grid information tampering attack according to claim 5, characterized in that: The relevant data also includes generator output data.

7. The method for locating a power grid information tampering attack according to any one of claims 1 to 6, characterized in that: The attacked node is an information-physical coupling node with a load bus.

8. A power grid information tampering attack location system, characterized by: Establish an analysis module to establish a mathematical model of information tampering attacks and analyze the impact of information tampering attacks on power grid status quantities; Build a module for building a recurrent neural network (SA-RNN) model with self-attention mechanism; The determination module is used to extract features of the grid load information after information tampering based on the SA-RNN model to determine the attacked node.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.