Generative adversarial network-based attack detection method and system for power monitoring system

By applying generative adversarial networks to conduct attack detection in the power monitoring system, the problem of simple detection strategies in the prior art and inability to identify deep-level attacks is solved, achieving higher detection accuracy and operational safety of the power system.

CN119966672APending Publication Date: 2025-05-09STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510009484.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

When the existing power monitoring system detects attacks during the operation of the power system, the detection strategy is simple and cannot identify deep-level attacks, such as false data injection, resulting in poor detection accuracy and reducing the operational safety of the power system.

Method used

The attack detection method based on the generative adversarial network is adopted, and the power system data is monitored in real time by controlling the monitoring equipment, and data mutation detection and abnormal data detection are carried out. The pre-trained abnormal data detection model is used to train based on the historical operation data of the power system, and the real data probability value is generated, and an abnormal alarm is triggered when the threshold is reached.

Benefits of technology

It improves the accuracy of attack detection, can identify potential problems and malicious attacks in the operation of the equipment, and promptly alarms, which enhances the operational security of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966672A_ABST
    Figure CN119966672A_ABST
Patent Text Reader

Abstract

The invention provides an attack detection method and system for a power monitoring system based on a generative adversarial network, and the method comprises the steps: controlling a monitoring device to monitor the operation conditions of different devices in a power system in real time, collecting the real-time operation data of different devices in the power system, and carrying out the data mutation detection, determining a data abrupt change condition of the real-time operation data; when it is detected that the real-time operation data does not have data mutation, abnormal data detection is carried out on the real-time operation data by adopting a pre-trained abnormal data detection model, and a real data probability value of the real-time operation data is determined; and when the real data probability value of the real-time operation data is determined to be smaller than or equal to the calibration threshold value, the alarm device is controlled to carry out abnormal alarm on the source device of the real-time operation data, so that attack of malicious users on a power system or other systems can be accurately detected, and the alarm can be timely given. And the operation safety of a power system or other systems is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of equipment control technology, and in particular to an attack detection method and system for an electric power monitoring system based on a generative adversarial network. Background Art

[0002] With the integration of information and communication technologies, the power system is gradually transformed into a smart grid. With the development of smart grids, the importance of power monitoring systems in ensuring power supply and management is becoming increasingly prominent. During the operation of the power system, it may be attacked by malicious users, such as attacking measurement facilities, destroying communication facilities, or injecting false data. The power monitoring system needs to detect malicious attacks during operation to ensure the safe and normal operation of the power system.

[0003] The applicant found that the power monitoring system in the related technology often relies on specific rules and data feature matching to detect attacks during the operation of the power system. The detection strategy of this type of attack detection is simple, and it is unable to identify and detect deep-level attacks such as false data injection, resulting in poor accuracy of the power monitoring system in detecting related attacks, thereby reducing the operational safety of the power system. Summary of the invention

[0004] The present application provides an attack detection method, system, device, storage medium and program product for an electric power monitoring system based on a generative adversarial network, so as to solve the problem that the detection strategy of attack detection in the related technology is simple, resulting in poor accuracy of the electric power monitoring system in detecting related attacks.

[0005] In a first aspect, an embodiment of the present application provides an attack detection method for a power monitoring system based on a generative adversarial network, comprising:

[0006] The control and monitoring equipment monitors the operation status of different equipment in the power system in real time and collects real-time operation data of different equipment in the power system;

[0007] Perform data mutation detection on the real-time operation data of different equipment in the power system to determine the data mutation situation of the real-time operation data;

[0008] When it is detected that there is no data mutation in the real-time operation data, a pre-trained abnormal data detection model is used to perform abnormal data detection on the real-time operation data to determine the true data probability value of the real-time operation data. The abnormal data detection model is a prediction model obtained by training the generative adversarial network based on the historical operation data of different equipment in the power system;

[0009] When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the control alarm device issues an abnormal alarm to the source device of the real-time operation data.

[0010] Optionally, when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, controlling the alarm device to issue an abnormal alarm to the source device of the real-time operation data includes:

[0011] When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, determining the abnormal level of the real-time operation data according to the true data probability value of the real-time operation data;

[0012] When it is determined that the abnormal level of the real-time operation data is a first-level abnormality, the control alarm device issues a first-level abnormality alarm to the source device of the real-time operation data;

[0013] When it is determined that the abnormal level of the real-time operation data is a level 2 abnormality, the control alarm device issues a level 2 abnormality alarm to the source device of the real-time operation data, and the alarm level of the level 1 abnormality is greater than the alarm level of the level 2 abnormality.

[0014] Optionally, determining the abnormality level of the real-time operation data according to the true data probability value of the real-time operation data includes:

[0015] When it is determined that the true data probability value of the real-time operation data is in the first interval, determining that the abnormality level of the real-time operation data is a first-level abnormality;

[0016] When it is determined that the true data probability value of the real-time operation data is in the second interval, the abnormal level of the real-time operation data is determined to be a secondary abnormality, the value of the first interval is greater than the value of the second interval, and the maximum value of the first interval is the calibration threshold.

[0017] Optionally, data mutation detection is performed on the real-time operation data of different devices in the power system to determine the data mutation situation of the real-time operation data, including:

[0018] Acquire multiple historical operation data collected within a preset time period before the real-time operation data, where the source devices and data types of the multiple historical operation data are the same as the source devices and data types of the real-time operation data;

[0019] According to the standard deviation of the real-time operation data and multiple historical operation data, the data mutation evaluation is performed on the real-time operation data to determine the data mutation situation of the real-time operation data.

[0020] Optionally, performing a data mutation assessment on the real-time operation data according to a standard deviation between the real-time operation data and a plurality of historical operation data to determine the data mutation situation of the real-time operation data includes:

[0021] Determine the mutation risk value of the real-time operation data based on the mean and standard deviation of the real-time operation data and multiple historical operation data;

[0022] When it is determined that the mutation risk value of the real-time operation data is greater than a preset value, determining that there is a data mutation in the real-time operation data;

[0023] When it is determined that the mutation risk value of the real-time operation data is less than or equal to the preset value, it is determined that there is no data mutation in the real-time operation data.

[0024] Optionally, using a pre-trained abnormal data detection model to perform abnormal data detection on the real-time operation data to determine a true data probability value of the real-time operation data includes:

[0025] Inputting a plurality of historical operation data and real-time operation data collected within a preset time period before the real-time operation data into an abnormal data detection model for abnormal data detection;

[0026] The normal data probability value of the real-time running data output by the abnormal data detection model is used as the true data probability value of the real-time running data.

[0027] Optionally, the generative adversarial network includes a generator and a discriminator, the generator is used to generate simulated samples according to random noise data of the power system, and the discriminator is used to predict the probability that the input data is real normal data;

[0028] The abnormal data detection model is trained in the following way:

[0029] Sampling a plurality of historical operation data of the same data type at a preset time step to obtain a plurality of sample data groups, wherein the sample data groups include a plurality of the historical operation data of the same data type from different devices within the preset time step;

[0030] Perform data mutation detection on multiple historical running data in the sample data group, remove data with data mutation in the sample data group and output it as a real sample, thereby obtaining multiple real samples;

[0031] According to multiple real samples and simulated samples generated by the generator, the parameters of the discriminator and the generator are iteratively updated based on back propagation;

[0032] When it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, the discriminator with converged parameters is output as an abnormal data detection model.

[0033] Optionally, detecting that the parameters of the discriminator meet preset convergence conditions and the model training effect achieves the expected effect includes:

[0034] Performing Fréchet starting distance calculation based on multiple real samples and multiple simulated samples generated by the generator to determine the difference value of feature distribution between the real samples and the simulated samples;

[0035] When it is determined that the probability output by the discriminator after predicting the simulated sample is within a preset range and the feature distribution difference value is less than the preset difference value, it is determined that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect.

[0036] In a second aspect, an embodiment of the present application provides a power monitoring system, including a monitoring device, an alarm device, and a control device, wherein the control device is used to:

[0037] The control and monitoring equipment monitors the operation status of different equipment in the power system in real time and collects real-time operation data of different equipment in the power system;

[0038] Perform data mutation detection on the real-time operation data of different equipment in the power system to determine the data mutation situation of the real-time operation data;

[0039] When it is detected that there is no data mutation in the real-time operation data, a pre-trained abnormal data detection model is used to perform abnormal data detection on the real-time operation data to determine the true data probability value of the real-time operation data. The abnormal data detection model is a neural network model obtained by training based on the historical operation data of the power system;

[0040] When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the alarm device is controlled to issue an abnormal alarm.

[0041] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the electronic device implements the above-mentioned attack detection method for the power monitoring system based on the generative adversarial network.

[0042] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned attack detection method for the power monitoring system based on the generative adversarial network is executed.

[0043] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program. When the computer program is run, the above-mentioned attack detection method for the power monitoring system based on the generative adversarial network is executed.

[0044] In a solution provided by the attack detection method, system, device, storage medium and program product of the power monitoring system based on the above-mentioned generative adversarial network, the control monitoring device monitors the operation status of different equipment in the power system in real time, and collects the real-time operation data of different equipment in the power system; performs data mutation detection on the real-time operation data of different equipment in the power system to determine the data mutation status of the real-time operation data; when it is detected that there is no data mutation in the real-time operation data, a pre-trained abnormal data detection model is used to perform abnormal data detection on the real-time operation data to determine the true data probability value of the real-time operation data, and the abnormal data detection model is a prediction model obtained by training the generative adversarial network based on the historical operation data of different equipment in the power system; when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the control alarm device performs an abnormal alarm on the source device of the real-time operation data. In this embodiment, by detecting mutations in real-time operating data, obviously abnormal data can be quickly screened out to ensure that subsequent predictions focus on potential risk data and improve analysis efficiency. Then, an abnormal data detection model trained based on historical operating data is used to detect abnormal data, which can enhance the model's processing capabilities and prediction accuracy for complex nonlinear problems, identify potential problems in equipment operation, and improve the accuracy of anomaly detection. This solution can accurately detect attacks by malicious users on power systems or other systems and issue alarms in a timely manner, thereby improving the operational safety of power systems or other systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0046] Figure 1 is a structural schematic diagram of a power monitoring system in one embodiment of the present application;

[0047] Figure 2 It is a flow chart of an attack detection method for a power monitoring system based on a generative adversarial network in one embodiment of the present application;

[0048] Figure 3 Schematic diagram of the training process of an abnormal data detection model in one embodiment of the present application;

[0049] Figure 4 yes Figure 3 A schematic diagram of an implementation process of step S04;

[0050] Figure 5 yes Figure 2A schematic diagram of an implementation process of step S20;

[0051] Figure 6 yes Figure 2 A schematic diagram of an implementation process of step S30;

[0052] Figure 7 yes Figure 2 A schematic diagram of an implementation process of step S40;

[0053] Figure 8 yes Figure 1 A structural schematic diagram of the control device;

[0054] Fig. 9 It is a structural schematic diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0055] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0056] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or their collections. It should also be understood that the term "and / or" used in the present specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes these combinations.

[0057] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0058] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0059] It should be understood that the size of the serial numbers of the steps in the following embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0060] In order to illustrate the technical solution of the present application, a specific embodiment is provided below for illustration.

[0061] The attack detection method for a power monitoring system based on a generative adversarial network provided in the embodiment of the present application can be applied in the following aspects: Figure 1 In the power monitoring system shown, the power monitoring system includes a monitoring device, an alarm device and a control device, and the power monitoring system is used to monitor and analyze the operation of the power system to determine the abnormal operation of different devices in the power system. Among them, the monitoring device includes multiple sensors of different types, and the multiple sensors are arranged at different devices in the power system to monitor and collect the operation data of different devices in the power system. The monitoring device and the alarm device communicate with the control device through a bus or a network.

[0062] During the operation of the power system, the control device controls the monitoring devices installed in different devices in the power system, monitors the operation of different devices in the power system in real time, and controls the monitoring devices to collect different types of real-time operation data of different devices in the power system. The control device performs data mutation detection on the real-time operation data of different devices in the power system to determine the data mutation of the real-time operation data; when it is detected that there is no data mutation in the real-time operation data, a pre-trained abnormal data detection model is used to perform abnormal data detection (such as false data injection attack detection) on the real-time operation data to determine the true data probability value of the real-time operation data. The abnormal data detection model is a prediction model obtained by training the generative adversarial network based on different types of historical operation data of different devices in the power system; when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the control alarm device performs an abnormal alarm on the source device of the real-time operation data.

[0063] In this embodiment, by detecting mutations in real-time operation data, obviously abnormal data can be quickly screened out, ensuring that subsequent predictions focus on potential risk data and improving analysis efficiency; then, an abnormal data detection model trained based on historical operation data is used for abnormal data detection, which makes full use of the characteristics of historical data and can improve the model's processing capabilities and prediction accuracy for complex nonlinear problems, so as to identify potential problems in equipment operation and issue alarms in a timely manner, effectively reducing false alarms and missed alarms. By using data mutation detection and intelligent analysis of abnormal data detection models, the accuracy and real-time performance of abnormal detection are improved, and the responsiveness of the power monitoring system to abnormal attacks is also improved. This solution can accurately detect malicious users' attacks on power systems or other systems and issue alarms in a timely manner, thereby improving the operational safety of power systems or other systems.

[0064] In this embodiment, the control device can be various electronic devices, including but not limited to various personal computers, laptops, smart phones, tablet computers and other electronic devices, and can also be a server device implemented by an independent server or a server cluster composed of multiple servers.

[0065] In one embodiment, if Figure 2 As shown, a method for attack detection of a power monitoring system based on a generative adversarial network is provided. Figure 1 The power monitoring system in the example is used as an example to illustrate, including the following steps:

[0066] S10: Control the monitoring equipment to monitor the operation status of different equipment in the power system in real time, and collect real-time operation data of different equipment in the power system.

[0067] In this embodiment, the power monitoring system includes a monitoring device, an alarm device and a control device. The monitoring device includes multiple sensors of different types, which are arranged at different devices in the power system to monitor and collect operation data of different devices in the power system.

[0068] During the operation of the power system, the control device controls the monitoring device to monitor the operation status of different equipment in the power system in real time, and obtains different types of real-time operation data of different equipment in the power system through multiple sensors in the monitoring device.

[0069] Among them, taking the power system as an example, different equipment in the power system includes power grids, substations, transmission lines and other power equipment. Real-time operation data may include any of the data such as real-time voltage, current intensity, active power, reactive power, voltage phase angle and voltage amplitude of different equipment in the power system.

[0070] S20: Perform data mutation detection on the real-time operation data of different equipment in the power system to determine the data mutation status of the real-time operation data.

[0071] After collecting different types of real-time operating data of different devices in the power system, the control device performs data mutation detection on the real-time operating data of different devices in the power system to determine the data mutation situation of the real-time operating data. The data mutation situation of the real-time operating data indicates whether the real-time operating data has changed significantly compared with the operating data collected before the current time point.

[0072] For example, the real-time operating data is that the current voltage of device A is b, and the voltage of the device collected before the current time point is c. If the difference between b and c is greater than or equal to the predetermined voltage difference, it indicates that the current voltage of device A has changed significantly, that is, there is a data mutation in the current voltage of device A; if the difference between b and c is less than the predetermined voltage difference, it indicates that the current voltage change of device A is normal, that is, there is no data mutation in the current voltage of device A.

[0073] S30: When it is detected that there is no data mutation in the real-time operation data, a pre-trained abnormal data detection model is used to perform abnormal data detection on the real-time operation data to determine a true data probability value of the real-time operation data.

[0074] During the operation of the power system, the control device obtains a pre-trained abnormal data detection model, which is a prediction model obtained by training a generative adversarial network based on different types of historical operation data of different devices in the power system.

[0075] When the control device detects that there is no data mutation in the real-time operation data, the control device uses a pre-trained abnormal data detection model to perform abnormal data detection (such as false data injection attack detection) on the real-time operation data to determine the true data probability value of the real-time operation data. For example, the real-time operation data can be input into the abnormal data detection model, and the real-time operation data can be detected by the abnormal data detection model to obtain the true data probability value of the real-time operation data.

[0076] The generative adversarial network includes a generator and a discriminator. The generator is used to generate simulated samples based on the random noise data of the power system, and the discriminator is used to predict the probability that the input data is real normal data. The abnormal data detection model is a discriminator after parameter convergence obtained by training the generative adversarial network based on different types of historical operating data of different equipment in the power system and simulated samples generated by the generator. The output of the discriminator is the probability of predicting that the input data is real normal data, that is, the real data probability value of the real-time operating data, which can be the probability of predicting that the real-time operating data is real normal data in the power system.

[0077] S40: When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the alarm device is controlled to issue an abnormal alarm to the source device of the real-time operation data.

[0078] When the real data probability value of the real-time operation data is obtained, the control device determines whether the real data probability value of the real-time operation data is greater than a calibration threshold value, which is a probability value determined by analyzing the real normal data of the system based on different types of historical operation data of different devices in the power system. The calibration threshold value may be 0.7.

[0079] When it is determined that the true data probability value of the real-time operation data is greater than the calibration threshold, that is, when it is predicted that the probability of the real-time operation data being the true normal data in the power system is greater than the calibration threshold, it indicates that the real-time operation data is the true normal data in the power system, and there is no abnormality in the real-time operation data, and data mutation detection and abnormal data detection continue to be performed on other data at that time point.

[0080] When the control device determines that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, that is, when the probability of predicting that the real-time operation data is the real normal data in the power system is less than or equal to the calibration threshold, it means that the real-time operation data may not be the real normal data in the power system, and there is an abnormality in the real-time operation data. The power system may have equipment failure or risk of being attacked (such as false data injection attack). The control device controls the alarm device to send an abnormal alarm to the source device of the real-time operation data, so as to facilitate relevant personnel to technically discover data abnormalities, and accurately conduct risk investigation and implement risk control strategies for equipment with data abnormalities.

[0081] Among them, the abnormal alarm can include sound alarm and light alarm. For example, when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the control device determines that the source device of the abnormal real-time operation data is an abnormal device, and generates an alarm message based on the abnormal device and its abnormal real-time operation data (such as voltage or current intensity), and plays the alarm message in voice to prompt the information of the abnormal device (such as name, number and location), as well as the abnormal real-time operation data, and synchronously controls the flashing of the alarm light and controls the buzzer to send an alarm sound.

[0082] In this embodiment, by detecting mutations in real-time operation data, obviously abnormal data can be quickly screened out, ensuring that subsequent predictions focus on potential risk data and improving analysis efficiency; then, an abnormal data detection model trained based on historical operation data is used for abnormal data detection, which makes full use of the characteristics of historical data and can improve the model's processing capabilities and prediction accuracy for complex nonlinear problems, so as to identify potential problems in equipment operation and issue alarms in a timely manner, effectively reducing false alarms and missed alarms. By using data mutation detection and intelligent analysis of abnormal data detection models, the accuracy and real-time performance of abnormal detection are improved, and the responsiveness of the power monitoring system to abnormal attacks is also improved. This solution can accurately detect malicious users' attacks on power systems or other systems and issue alarms in a timely manner, thereby improving the operational safety of power systems or other systems.

[0083] In one embodiment, before using a pre-trained abnormal data detection model to perform abnormal data detection on real-time operating data, the control device may train a generative adversarial network based on different types of historical operating data of different devices in the power system to obtain an abnormal data detection model. The generative adversarial network includes a generator and a discriminator, the generator is used to generate simulated samples based on random noise data of the power system, and the discriminator is used to predict the probability that the input data is real normal data. Figure 3 As shown in the figure, the abnormal data detection model is trained in the following way:

[0084] S01: Sampling multiple historical operating data of the same data type at a preset time step to obtain multiple sample data groups.

[0085] The control device obtains multiple historical operation data of different types from different devices in the power system, and samples multiple historical operation data of the same data type from different devices in the power system at a preset time step to obtain multiple sample data groups. The sample data group includes multiple historical operation data of the same data type from different devices collected within a preset time step. The multiple sample data groups are arranged according to the time period of collection, and the step size of two adjacent sample data groups is the preset time step. The sample data groups are sampled from different types of historical operation data from different devices, so that the subsequent model can learn the operating characteristics of multiple devices and multiple scenarios, and enhance the generalization ability of the abnormal data detection model in complex environments.

[0086] For example, the preset time step is n time points, that is, the historical operation data collected within n time points are taken as a group, and multiple historical operation data of the same data type of different equipment in the power system are sampled to obtain multiple sample data groups, that is, each sample data group includes historical operation data collected within n consecutive time points from different equipment and the same data type, and each time point corresponds to historical operation data of different equipment. For example, a sample data group includes multiple voltages from different equipment collected at n time points between time point 1 and time point n.

[0087] Specifically, for different types of historical operation data of different equipment in the power system, different data types are classified according to the time point of data collection to obtain multiple historical data groups of different data types, each of which includes multiple historical operation data from different equipment but with the same data type arranged in the order of collected data points. Then, sampling is performed for each historical data group at a preset time step to obtain multiple sample data groups under each historical data group; multiple sample data groups are arranged according to the time period of collection, and the step size of two adjacent sample data groups is the preset time step.

[0088] Taking the power system as the power system, the historical operation data of different types of different equipment in the power system are classified according to the time point of data collection to obtain multiple historical data groups of different data types.

[0089] Among them, multiple historical operation data from different devices but with the same data type in each historical data group can be shown in Table 1. As shown in Table 1, starting from the second column in the table, each column represents a historical data group, and each historical data group includes i*j historical operation data, i represents the time point of data collection, and j represents the number of the device. For example, historical data group U ij Including U 11 ,U 22 ...U ij There are i*j historical operation data in total.ij For example, for the historical data set U ij Sampling is performed with a preset time step of 2 to obtain i / 2 sample data groups, each of which includes the voltages of multiple devices collected at 2 time points. For example, the first sample array includes U 11 ...U 1j , and U 21 ...U 2j , j=1, 2, ...j. In other embodiments, the preset time step may be other, and the historical operation data composition included in the sample data group may be other, which will not be described in detail here.

[0090] Table 1

[0091]

[0092] S02: Perform data mutation detection on multiple historical operating data in the sample data group, remove the data with data mutation in the sample data group and output it as a real sample, thereby obtaining multiple real samples.

[0093] For each sample data group, the control device performs data mutation detection on multiple historical operation data in the sample data group, removes data with data mutation in the sample data group and outputs it as a real sample to obtain multiple real samples. That is, the real sample includes multiple normal historical operation data with the same data type under the same device.

[0094] Among them, for each sample data group, multiple historical running data in the sample data group are tested for data mutations to determine whether there are historical running data with data mutations in the sample data group; if there are historical running data with data mutations, the historical running data with data mutations are eliminated, and the sample data group after eliminating the data with data mutations is output as a real sample; all sample data groups are traversed to obtain multiple real samples. By performing data mutation detection on historical running data and eliminating abnormal data, the authenticity and reliability of real samples for subsequent training are ensured, providing a high-quality data foundation for the model and improving the model training effect.

[0095] Among them, a mutation risk assessment can be performed on each historical operation data according to the mean and standard deviation of multiple historical operation data in the sample data group, and the mutation risk value of each historical operation data in the sample data group can be determined, and whether the historical operation data has a data mutation can be determined according to the mutation risk value of the historical operation data. If the mutation risk value of the historical operation data is greater than a preset value, it is determined that the historical operation data has a data mutation; if the mutation risk value of the historical operation data is less than or equal to the preset value, it is determined that the historical operation data does not have a data mutation.

[0096] Among them, the mutation risk value of historical operation data is determined by the following formula:

[0097] Z ij =(|X ij -μ|-σ) 2 ;

[0098] Among them, Z i represents the mutation risk value of the historical operation data of device i collected at time point i in the sample data group; X ij represents the historical operation data of device i collected at time point i in the sample data group; i = 1, 2, 3...n, n represents the number of sampling time points in the sample data group; j = 1, 2, 3...m, m represents the number of devices included in the sample data group; μ represents the mean of multiple historical operation data in the sample data group; σ represents the standard deviation of multiple historical operation data in the sample data group; |·| represents the absolute value symbol.

[0099] S03: According to multiple real samples and simulated samples generated by the generator, the parameters of the discriminator and the parameters of the generator are iteratively updated based on back propagation.

[0100] The control device iteratively updates the parameters of the discriminator and the parameters of the generator based on back propagation according to multiple real samples and simulated samples generated by the generator.

[0101] During the model training process, the control device inputs the real sample into the discriminator to predict the probability of the real sample being the real normal data, and obtains the predicted probability of the real sample; the simulated sample generated by the generator is input into the discriminator to predict the probability of the simulated sample being the real normal data, and obtains the predicted probability of the simulated sample. Among them, the generator generates a simulated sample including multiple simulated running data based on random noise, and the number and data type of the simulated running data in the simulated sample are the same as the number and data type of the historical running data in the real sample input in the same round. The back propagation algorithm is used to update the parameters of the discriminator according to the predicted probability of the real sample and the predicted probability of the simulated sample; the back propagation algorithm is used to update the parameters of the generator according to the predicted probability of the simulated sample. Generative adversarial networks are used to automatically generate simulated samples, reduce dependence on large-scale real data, accelerate model development and iteration cycles, and reduce time and cost investment; through adversarial training between the generator and the discriminator, the generator continuously optimizes the quality of simulated samples and improves the discriminator's ability to distinguish abnormal data; through iterative updates of back propagation, the parameters of the generator and discriminator are continuously optimized, the model's ability to characterize complex nonlinear relationships is improved, and the prediction accuracy is improved, so that a more robust and accurate abnormal data detection model can be constructed.

[0102] Among them, the discriminator includes a convolution layer, a fully connected layer, and an activation function layer connected in sequence. The convolution layer is used to extract the data features of multiple historical operation data from the input real sample (or simulated sample), and map the extracted data features of multiple historical operation data to the high-dimensional space respectively, to obtain the feature vectors of multiple historical operation data, which is convenient for subsequent processing. The fully connected layer is used to fuse the feature vectors of multiple historical operation data output by the convolution layer to obtain a fused feature vector. The activation function layer is used to use an activation function (such as a sigmoid function) to normalize and activate the fused feature vector output by the fully connected layer, limit the output between 0 and 1, and obtain the predicted probability. Among them, 0 indicates that the input data is false (that is, the input data is a simulated sample generated by the generator), and 1 indicates that the input data is true (that is, the input data is a real sample).

[0103] The back propagation algorithm is used to update the parameters of the discriminator according to the predicted probability of the real sample and the predicted probability of the simulated sample, including: determining the loss value of the discriminator according to the predicted probability of the real sample and the predicted probability of the simulated sample; and using the back propagation algorithm to update the discriminator parameters according to the loss value of the discriminator. The loss function of the discriminator is a binary cross entropy loss function, and the loss value of the discriminator is calculated by the following formula:

[0104]

[0105] Among them, L D represents the loss value of the discriminator D; x represents the real sample; D(x) represents the discriminator's judgment result on the real sample x, that is, the predicted probability of the real sample; P data (x) represents the data distribution (i.e., probability distribution) of the real sample x; represents the expected value of the data distribution of the real sample x; z represents random noise; G(z) represents the simulated sample generated by the generator based on the random noise z; D(G(z)) is the discriminant result of the simulated sample, that is, the predicted probability of the simulated sample; P z (z) represents the data distribution of the simulated samples; Represents the expected value of the data distribution of the simulated sample. Random noise is a random vector, usually drawn from a standard normal distribution. Random noise is used as the input of the generator G in order to enable the generator to generate diverse simulated samples. The simulated samples do not carry any information about the specific data samples.

[0106] Among them, the back propagation algorithm is used to update the parameters of the generator according to the predicted probability of the simulated sample, including: determining the loss value of the generator according to the predicted probability of the simulated sample; using the back propagation algorithm to update the parameters of the generator according to the loss value of the generator. Among them, the loss function of the generator is the binary cross entropy loss function, and the loss value of the generator is calculated by the following formula:

[0107]

[0108] Among them, L G represents the loss value of the discriminator G; z represents random noise; G(z) represents the simulated sample generated by the generator based on the random noise z; D(G(z)) is the discriminator's judgment result on the simulated sample, that is, the predicted probability of the simulated sample; P z (z) represents the data distribution of the simulated samples; Represents the expected value of the data distribution for simulated samples.

[0109] S04: When it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, the discriminator with converged parameters is output as an abnormal data detection model.

[0110] During the training process, the control device can detect whether the parameters of the discriminator meet the preset convergence conditions and detect whether the model training effect reaches the expected effect; when it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, the discriminator with converged parameters is output as an abnormal data detection model.

[0111] In this embodiment, multiple historical operation data of the same data type are sampled at a preset time step to obtain multiple sample data groups, and the sample data group includes multiple historical operation data of the same data type from different devices within the preset time step; multiple historical operation data in the sample data group are subjected to data mutation detection, and data with data mutation in the sample data group are removed and output as a real sample to obtain multiple real samples; according to multiple real samples and simulated samples generated by the generator, the parameters of the discriminator and the parameters of the generator are iteratively updated based on back propagation; when it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, the discriminator with converged parameters is output as an abnormal data detection model. Using the adversarial training mechanism and mutation data elimination strategy of the generative adversarial network, a high-quality abnormal data detection model is constructed, which improves the accuracy, robustness and generalization ability of the prediction, and accelerates the model development and deployment.

[0112] In one embodiment, in the process of iteratively updating the parameters of the discriminator and the parameters of the generator based on back propagation according to multiple real samples and simulated samples generated by the generator, that is, in the model training process, the generator generates simulated samples in the following manner:

[0113] S031: According to the number and data type of historical operating data in the input real sample, multiple random noises with the same data type and data volume are determined to obtain a random noise group.

[0114] The control device constructs different types of noise data sets in advance according to different types of historical operation data, such as voltage, current intensity, active power, reactive power and other types of noise data sets. The multiple noise vectors in each noise data set satisfy the Gaussian distribution, thereby improving the data diversity and randomness of the noise data set.

[0115] During the training process, the control device determines the data type of the real sample input in the current round, randomly samples the noise data set with the same data type as the real sample, obtains multiple random noises with the same number of historical running data as the real sample input in the current round, and groups the multiple random noises into a random noise group.

[0116] S032: Inputting multiple random noises in the random noise group into a generator for data simulation to obtain simulation samples including multiple simulation running data.

[0117] The control device inputs multiple random noises in the random noise group into the generator for data simulation to obtain simulation samples including multiple simulation operation data. The generator includes a neural network structure, an activation function layer and a normalization layer connected in sequence, and the neural network structure includes multiple network layers connected in sequence.

[0118] After multiple random noises in the random noise group are input into the generator, the following process is performed:

[0119] S0321: Linearly transform multiple random noises in the random noise group through multiple network layers of the neural network structure to obtain linear transformation values ​​of each random noise.

[0120] Among them, the linear transformation process of the neural network structure is expressed by the following formula:

[0121] h=wz+b;

[0122] Among them, h represents the linear transformation value of random noise; z represents random noise; w represents the weight of the mapping from the nth network layer to the n+1th network layer in the neural network structure; b represents the bias of the mapping from the nth network layer to the n+1th network layer in the neural network structure.

[0123] S0322: Activate the linear transformation value of each random noise through the activation function layer to obtain the activation vector of each random noise.

[0124] Among them, the activation function layer can use an activation function (such as a sigmoid function) to activate the linear transformation value of the random noise, limit the output range of the linear transformation value of the random noise, and obtain the activation vector of the random noise. The activation process of the activation function layer is expressed by the following formula:

[0125]

[0126] Among them, f(h) represents the output of the activation function, that is, the activation vector of random noise; h represents the linear transformation value of random noise.

[0127] S0323: Normalize the activation vector of each random noise through the normalization layer, simulate and obtain the simulation operation data of each random noise, and output it as a simulation sample.

[0128] Among them, the normalization layer normalizes the activation vector of random noise, which is expressed by the following formula:

[0129]

[0130] Where x represents the activation vector of random noise; μ B Represents the mean of the activation vectors of multiple random noises in the random noise group; σ B represents the variance of the activation vector of multiple random noises in the random noise group; γ and β represent the network parameters of the normalization layer, that is, the parameters that can be updated and iterated in the generator; ∈ represents a constant value to avoid division by zero errors during training.

[0131] In this embodiment, the generator includes a neural network structure, an activation function layer and a normalization layer connected in sequence, and linear transformation is performed on multiple random noises in the random noise group through multiple network layers of the neural network structure to obtain linear transformation values ​​of each random noise, and the linear transformation values ​​of each random noise are activated through the activation function layer to obtain the activation vector of each random noise, and the activation vector of each random noise is normalized through the normalization layer to simulate and obtain the simulated operation data of each random noise, and output as a simulated sample. The random noise is subjected to linear transformation and activation function processing of a multi-layer neural network, and then standardized through a normalization layer, so that diversified simulated operation data that conforms to the actual data distribution can be generated, and the authenticity and diversity of the generated simulated samples are improved, and rich and reliable training samples are provided for the abnormal data detection model.

[0132] In this embodiment, according to the number and data type of historical operation data in the input real sample, multiple random noises of the same data type and data volume are determined to obtain a random noise group, and the multiple random noises in the random noise group are input into the generator for data simulation to obtain a simulated sample including multiple simulated operation data. The generation of the random noise group is based on the data type and quantity characteristics of the real sample, so that the generated simulated sample matches the structure and distribution characteristics of the real sample, reducing the complexity of the generator's adaptation to the input noise, improving the efficiency and quality of the generator's generation of simulated samples, and improving the training effect and applicability of the model, and significantly reducing the dependence on real data, providing an efficient and flexible solution for abnormal data detection in complex systems.

[0133] In one embodiment, if Figure 4 As shown, in step S04, it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, which specifically includes the following steps:

[0134] S041: Perform Fréchet starting distance calculation based on multiple real samples and multiple simulated samples generated by the generator to determine the difference value of feature distribution between the real samples and the simulated samples.

[0135] During the model training process, the control device uses the Frechet Inception Distance (FID) algorithm to calculate the Frechet inception distance between multiple real samples and multiple simulated samples generated by the generator, and determines the Frechet inception distance (FID) between multiple real samples and multiple simulated samples as the feature distribution difference value between the real samples and the simulated samples. FID is an indicator for evaluating model performance, which evaluates the quality and diversity of fake samples by comparing the feature distribution of fake samples (simulated samples) and real samples (real samples).

[0136] Specifically, when it is determined that the parameters of the discriminator meet the preset convergence conditions, such as when it is determined that the probability output by the discriminator after predicting the simulated samples is within a preset range (i.e., a probability range close to 0.5, such as [0.45, 0.55]), obtain the real samples used in the training process and combine them to obtain a real sample set including multiple real samples; use the generator of the converged generative adversarial network to generate multiple simulated samples to obtain a simulated sample set; the number of multiple simulated samples in the simulated sample set is the same as the number of multiple real samples in the real sample set. Use a deep convolutional neural network model (such as the Inception V3 model) to extract the feature vectors of multiple real samples in the real sample set respectively, and store the feature vectors of the multiple real samples as a feature vector matrix of the real samples; use a deep convolutional neural network model to extract the feature vectors of multiple simulated samples in the simulated sample set respectively, and store the feature vectors of the multiple simulated samples as a feature vector matrix of the simulated samples. According to the eigenvector mean and covariance matrix of the eigenvector matrix of the real sample and the eigenvector mean and covariance matrix of the eigenvector matrix of the simulated sample, the Fréchet starting distance of the eigenvector matrix of the real sample and the simulated sample is calculated to obtain the difference value of the characteristic distribution between the real sample and the simulated sample.

[0137] The difference in characteristic distribution between the real sample and the simulated sample (i.e., the Fréchet starting distance) is expressed by the following formula:

[0138] FID=||μ r -μ g || 2 +Tr(∑r+∑g-2(∑r∑g) 1 / 2 );

[0139] Among them, FID represents the Fréchet starting distance, that is, the difference between the characteristic distribution of the real sample and the simulated sample; μ r represents the mean of the eigenvectors of the eigenvector matrix of the real sample; μ g represents the eigenvector mean of the eigenvector matrix of the simulated sample; ∑r represents the covariance matrix of the eigenvector matrix of the real sample; ∑g represents the covariance matrix of the eigenvector matrix of the simulated sample; Tr represents the trace of the eigenvector matrix of the real sample; (∑r∑g) 1 / 2 Represents the square root of the product of two covariance matrices.

[0140] Among them, if the feature distribution difference value FID is close to 0, it means that the feature distributions of the simulated samples and the real samples are very similar, the generator and the discriminator are well trained, and the model training effect reaches the expected effect; if the feature distribution difference value FID is close to 1, it means that the feature distributions of the simulated samples and the real samples are quite different, the model training effect is not very ideal, and the expected effect is not achieved.

[0141] S042: When it is determined that the probability output by the discriminator after predicting the simulated sample is within a preset range and the feature distribution difference value is less than the preset difference value, it is determined that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect.

[0142] When it is determined that the probability output by the discriminator after predicting the simulated sample is within a preset range (i.e., a probability range close to 0.5, such as [0.45, 0.55]), and the feature distribution difference value is less than a preset difference value (such as 0.1), it is determined that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect.

[0143] In this embodiment, the Fréchet starting distance is calculated based on multiple real samples and multiple simulated samples generated by the generator to determine the difference value of the feature distribution between the real samples and the simulated samples; when it is determined that the probability output by the discriminator after predicting the simulated samples is within the preset range, and the feature distribution difference value is less than the preset difference value, it is determined that the parameters of the discriminator meet the preset convergence conditions, and the model training effect reaches the expected effect. The dual indicators of feature distribution difference value (FID) and discriminator output probability are used to scientifically evaluate the training effect of the generative adversarial network, effectively avoiding insufficient or excessive training; by dynamically judging the model convergence conditions, the quality of the simulated samples and the prediction ability of the model are improved, providing stable, efficient and reliable support for subsequent abnormal data detection.

[0144] In one embodiment, if Figure 5 As shown, in step S20, data mutation detection is performed on the real-time operation data of different devices in the power system to determine the data mutation situation of the real-time operation data, which specifically includes the following steps:

[0145] S21: Acquire a plurality of historical operation data collected within a preset time period before the real-time operation data.

[0146] The source devices and data types of the plurality of historical operation data are the same as the source devices and data types of the real-time operation data.

[0147] After the control device collects the real-time operation data of different devices, for each real-time operation data of each device, multiple historical operation data with the same data type collected within a preset time period before the real-time operation data are obtained.

[0148] S22: Perform data mutation evaluation on the real-time operation data according to the standard deviation of the real-time operation data and the plurality of historical operation data to determine the data mutation status of the real-time operation data.

[0149] The control device performs a data mutation assessment on the real-time operation data based on the standard deviation of the real-time operation data and multiple historical operation data to determine the data mutation situation of the real-time operation data. That is, the control device uses multiple historical operation data from the preset time period to the current time point to perform a data mutation assessment on the real-time operation data at the current time point to determine the data mutation situation of the real-time operation data.

[0150] Specifically, the mutation risk value of the real-time operation data is determined based on the mean and standard deviation of the real-time operation data and multiple historical operation data; when it is determined that the mutation risk value of the real-time operation data is greater than a preset value, it is determined that there is a data mutation in the real-time operation data; when it is determined that the mutation risk value of the real-time operation data is less than or equal to the preset value, it is determined that there is no data mutation in the real-time operation data.

[0151] The mutation risk value of real-time operation data is determined by the following formula:

[0152] Z i =(|X i -μ|-σ) 2 ;

[0153] Among them, Z i represents the mutation risk value of the real-time operation data collected at time point i; X i represents the real-time operation data collected at time point i; μ represents the mean of the real-time operation data and multiple historical operation data; σ represents the standard deviation of the real-time operation data and multiple historical operation data; |·| represents the absolute value symbol.

[0154] In this embodiment, multiple historical operation data collected within a preset time period before the real-time operation data are obtained, and the source devices and data types of the multiple historical operation data are the same as the source devices and data types of the real-time operation data; according to the standard deviation of the real-time operation data and the multiple historical operation data, the real-time operation data is evaluated for data mutation, and the data mutation of the real-time operation data is determined. Using the standard deviation to measure the degree of deviation between the real-time operation data and the historical operation data can quickly discover abnormal values ​​or mutation phenomena, improve the response speed of data monitoring, and effectively reduce misjudgments caused by single data fluctuations, thereby improving the accuracy of anomaly detection.

[0155] In one embodiment, if Figure 6 As shown, in step S30, the pre-trained abnormal data detection model is used to perform abnormal data detection on the real-time operation data to determine the true data probability value of the real-time operation data, which specifically includes the following steps:

[0156] S31: Inputting a plurality of historical operation data and real-time operation data collected within a preset time period before the real-time operation data into an abnormal data detection model to perform abnormal data detection.

[0157] The source devices and data types of the plurality of historical operation data are the same as the source devices and data types of the real-time operation data.

[0158] After the control device collects the real-time operation data of different devices, for each real-time operation data of each device, multiple historical operation data of the same data type collected within a preset time period before the real-time operation data are obtained, and the multiple historical operation data and real-time operation data are input into the abnormal data detection model for abnormal data detection.

[0159] S32: Using the normal data probability value of the real-time operation data output by the abnormal data detection model as the true data probability value of the real-time operation data.

[0160] The control device uses the normal data probability value of the real-time operation data output by the abnormal data detection model as the true data probability value of the real-time operation data, and when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the control alarm device issues an abnormal alarm to the source device of the real-time operation data.

[0161] In this embodiment, multiple historical operation data and real-time operation data collected within a preset time period before the real-time operation data are input into the abnormal data detection model for abnormal data detection, and the normal data probability value of the real-time operation data output by the abnormal data detection model is used as the real data probability value of the real-time operation data. The abnormal data detection model is used to analyze the historical and real-time data in real time to output the real data probability value. The abnormal data detection model is used to capture the complex relationship between the historical and real-time data, improve the ability to identify abnormal trends and potential risks, and improve the accuracy of abnormal detection.

[0162] In one embodiment, if Figure 7 As shown, in step S40, that is, when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the alarm device is controlled to issue an abnormal alarm to the source device of the real-time operation data, which specifically includes the following steps:

[0163] S41: When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, determine the abnormality level of the real-time operation data according to the true data probability value of the real-time operation data.

[0164] When the control device determines that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, it can be determined that there is data anomaly in the real-time operation data, and there may be a risk of equipment failure or attack (such as false data injection attack). The control device determines the abnormality level of the real-time operation data based on the true data probability value of the real-time operation data.

[0165] Wherein, when it is determined that the true data probability value of the real-time operation data is in the first interval, the abnormality level of the real-time operation data is determined to be a first-level abnormality; when it is determined that the true data probability value of the real-time operation data is in the second interval, the abnormality level of the real-time operation data is determined to be a second-level abnormality. Wherein, the value of the first interval is greater than the value of the second interval, and the maximum value of the first interval is the calibration threshold. Dividing the true data probability value into multiple intervals (such as the first interval and the second interval) can clearly define the abnormality level (first level and second level), realize more refined risk management, and facilitate the subsequent rapid triggering of corresponding response measures according to the level of the abnormality, thereby improving the efficiency of emergency handling.

[0166] S42: When it is determined that the abnormal level of the real-time operation data is a first-level abnormality, the alarm device is controlled to issue a first-level abnormality alarm to the source device of the real-time operation data.

[0167] When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, and the true data probability value of the real-time operation data is in the first interval, it means that there may be data anomalies in the real-time operation data, but the anomaly detection cannot clearly identify it, and timely investigation and confirmation are required to determine that the anomaly level of the real-time operation data is a level one anomaly. The control device controls the alarm device to issue a level one anomaly alarm to the source device of the real-time operation data, that is, a high-risk alarm, to remind relevant personnel to make timely judgments and investigations.

[0168] S43: When it is determined that the abnormality level of the real-time operation data is a level 2 abnormality, the alarm device is controlled to issue a level 2 abnormality alarm to the source device of the real-time operation data.

[0169] Among them, the alarm level of the first-level abnormality is greater than the alarm level of the second-level abnormality. When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, and the true data probability value of the real-time operation data is in the second interval, it means that there is a data abnormality in the real-time operation data, and the abnormal level of the real-time operation data is determined to be a second-level abnormality. The control device controls the alarm device to issue a second-level abnormality alarm to the source device of the real-time operation data, that is, a medium-risk alarm, so that relevant personnel can be informed of the abnormal device and the abnormal data in a timely manner.

[0170] For example, when the true data probability value of the real-time operation data is in the third interval, it can be determined that there is no data anomaly in the real-time operation data, and there is no need to issue a risk alarm. Wherein, the value of the third interval is greater than the value of the first interval, such as the third interval can be (0.7, 1]. When it is determined that the true data probability value of the real-time operation data is in the first interval, that is, in the interval (0.3-0.7], it means that there may be data anomalies in the real-time operation data, but the anomaly detection cannot clearly identify it, and it is necessary to conduct timely investigation and confirmation, and determine that the abnormal level of the real-time operation data is a first-level abnormality. The control device controls the alarm device to issue a high-risk alarm to remind relevant personnel to make timely judgments and investigations. When it is determined that the true data probability value of the real-time operation data is in the second interval, that is, in the interval [0-0.3], it means that there is a data anomaly in the real-time operation data, and the abnormal level of the real-time operation data is determined to be a second-level abnormality. The control device controls the alarm device to issue a medium-risk alarm so that relevant personnel can be informed of abnormal equipment and abnormal data in a timely manner.

[0171] In this embodiment, when it is determined that the real data probability value of the real-time operation data is less than or equal to the calibration threshold, the abnormal level of the real-time operation data is determined according to the real data probability value of the real-time operation data; when it is determined that the abnormal level of the real-time operation data is a first-level abnormality, the alarm device is controlled to make an abnormal alarm of a first-level abnormality for the source device of the real-time operation data; when it is determined that the abnormal level of the real-time operation data is a second-level abnormality, the alarm device is controlled to make an abnormal alarm of a second-level abnormality for the source device of the real-time operation data, and the alarm level of the first-level abnormality is greater than the alarm level of the second-level abnormality. According to the real data probability value, it is clearly divided into a first-level abnormality and a second-level abnormality, ensuring that the level of the alarm matches the severity of the abnormal situation, thereby avoiding excessive alarms or ignoring important alarms. When it is determined that the real data probability value of the real-time operation data is less than or equal to the calibration threshold, and the real data probability value is large and it is difficult to clearly identify the data abnormality, a higher level of abnormal alarm is performed compared to the case where the real data probability value is low and the data abnormality can be accurately identified, and the human identification of relevant personnel can be used in the case where it is difficult to accurately identify the data abnormality, thereby improving the accuracy of data abnormality risk judgment.

[0172] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0173] In one embodiment, a control device is provided, which corresponds one-to-one to the attack detection method of the power monitoring system based on the generative adversarial network in the above embodiment. Figure 8As shown, the control device includes a first control module 801, a first detection module 802, a second detection module 803 and a second control module 804. Each functional module is described in detail as follows:

[0174] The first control module 801 is used to control the monitoring device to monitor the operation of different devices in the power system in real time and collect real-time operation data of different devices in the power system;

[0175] The first detection module 802 is used to perform data mutation detection on the real-time operation data of different devices in the power system to determine the data mutation situation of the real-time operation data;

[0176] The second detection module 803 is used to detect abnormal data of the real-time operation data using a pre-trained abnormal data detection model when it is detected that there is no data mutation in the real-time operation data, and determine the true data probability value of the real-time operation data. The abnormal data detection model is a prediction model obtained by training a generative adversarial network based on historical operation data of different equipment in the power system;

[0177] The second control module 804 is used to control the alarm device to issue an abnormal alarm to the source device of the real-time operation data when it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold.

[0178] Optionally, the second control module 804 is specifically configured to:

[0179] When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, determining the abnormal level of the real-time operation data according to the true data probability value of the real-time operation data;

[0180] When it is determined that the abnormal level of the real-time operation data is a first-level abnormality, the control alarm device issues a first-level abnormality alarm to the source device of the real-time operation data;

[0181] When it is determined that the abnormal level of the real-time operation data is a level 2 abnormality, the control alarm device issues a level 2 abnormality alarm to the source device of the real-time operation data, and the alarm level of the level 1 abnormality is greater than the alarm level of the level 2 abnormality.

[0182] Optionally, the second control module 804 is further configured to:

[0183] When it is determined that the true data probability value of the real-time operation data is in the first interval, determining that the abnormality level of the real-time operation data is a first-level abnormality;

[0184] When it is determined that the true data probability value of the real-time operation data is in the second interval, the abnormal level of the real-time operation data is determined to be a secondary abnormality, the value of the first interval is greater than the value of the second interval, and the maximum value of the first interval is the calibration threshold.

[0185] Optionally, the first detection module 802 is specifically configured to:

[0186] Acquire multiple historical operation data collected within a preset time period before the real-time operation data, where the source devices and data types of the multiple historical operation data are the same as the source devices and data types of the real-time operation data;

[0187] According to the standard deviation of the real-time operation data and multiple historical operation data, the data mutation evaluation is performed on the real-time operation data to determine the data mutation situation of the real-time operation data.

[0188] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0189] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned function allocation can be completed by different functional units and modules based on needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0190] The embodiment of the present application also provides an electronic device, which may be an electronic control unit, a terminal device or a server. Fig. 9 As shown, the electronic device includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps in any of the above-mentioned method embodiments when executing the computer program, or implements the functions of the modules / units in the above-mentioned device embodiments when executing the computer program.

[0191] Those skilled in the art will understand that Fig. 9These are merely examples of electronic devices and do not constitute a limitation of the electronic device. The electronic device may include more or fewer components than those shown in the figure, or a combination of certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.

[0192] The processor may be a central processing unit, or other general-purpose processors, digital signal processors, application-specific integrated circuits, field programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0193] The memory may be an internal storage unit of an electronic device, such as a hard disk or memory of the electronic device. The memory may also be an external storage device of the electronic device, such as a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, etc. equipped on the electronic device. Furthermore, the memory may also include both an internal storage unit of the electronic device and an external storage device.

[0194] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned attack detection method for the power monitoring system based on the generative adversarial network is executed.

[0195] An embodiment of the present application provides a computer program product. When the computer program product is run on an electronic device, the above-mentioned attack detection method for the power monitoring system based on the generative adversarial network is executed.

[0196] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium, which can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera device / terminal device, recording medium, computer memory, read-only memory, random access memory, electric carrier signal, telecommunication signal and software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.

[0197] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0198] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0199] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic, for example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0200] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected based on actual needs to achieve the purpose of the solution of this embodiment.

[0201] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. An attack detection method for a power monitoring system based on a generative adversarial network, characterized in that: include: The control monitoring equipment monitors the operation status of different equipment in the power system in real time, and collects the real-time operation data of different equipment in the power system; Performing data mutation detection on the real-time operating data of different devices in the power system to determine the data mutation status of the real-time operating data; In the case where it is detected that there is no data mutation in the real-time operation data, abnormal data detection is performed on the real-time operation data using a pre-trained abnormal data detection model to determine a true data probability value of the real-time operation data, wherein the abnormal data detection model is a prediction model obtained by training a generative adversarial network based on historical operation data of different devices in the power system; When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the alarm device is controlled to issue an abnormal alarm to the source device of the real-time operation data.

2. The attack detection method according to claim 1, characterized in that: When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, controlling the alarm device to issue an abnormal alarm to the source device of the real-time operation data includes: When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, determining the abnormality level of the real-time operation data according to the true data probability value of the real-time operation data; When it is determined that the abnormal level of the real-time operation data is a first-level abnormality, controlling the alarm device to issue an abnormal alarm of the first-level abnormality to the source device of the real-time operation data; When it is determined that the abnormality level of the real-time operation data is a level 2 abnormality, the alarm device is controlled to issue an abnormality alarm of the level 2 abnormality to the source device of the real-time operation data, and the alarm level of the level 1 abnormality is greater than the alarm level of the level 2 abnormality.

3. The attack detection method according to claim 2, characterized in that: The determining the abnormality level of the real-time operation data according to the true data probability value of the real-time operation data comprises: When it is determined that the true data probability value of the real-time operation data is in the first interval, determining that the abnormality level of the real-time operation data is a first-level abnormality; When it is determined that the true data probability value of the real-time operation data is in the second interval, the abnormality level of the real-time operation data is determined to be a secondary abnormality, the value of the first interval is greater than the value of the second interval, and the maximum value of the first interval is the calibration threshold.

4. The attack detection method according to claim 1, characterized in that: The performing data mutation detection on the real-time operation data of different devices in the power system to determine the data mutation situation of the real-time operation data includes: Acquire a plurality of historical operation data collected within a preset time period before the real-time operation data, wherein the source devices and data types of the plurality of historical operation data are the same as the source devices and data types of the real-time operation data; According to the standard deviation between the real-time operation data and a plurality of the historical operation data, a data mutation assessment is performed on the real-time operation data to determine the data mutation situation of the real-time operation data.

5. The attack detection method according to any one of claims 1 to 4, characterized in that: The generative adversarial network includes a generator and a discriminator, wherein the generator is used to generate simulation samples according to the random noise data of the power system, and the discriminator is used to predict the probability that the input data is real normal data; The abnormal data detection model is trained in the following way: Sampling the plurality of historical operation data of the same data type at a preset time step to obtain a plurality of sample data groups, wherein the sample data groups include the plurality of historical operation data of the same data type from different devices within the preset time step; Performing data mutation detection on the plurality of historical operation data in the sample data group, removing the data with data mutation in the sample data group and outputting them as a real sample, thereby obtaining a plurality of real samples; According to the plurality of real samples and the simulated samples generated by the generator, iteratively updating the parameters of the discriminator and the parameters of the generator based on back propagation; When it is detected that the parameters of the discriminator meet the preset convergence conditions and the model training effect reaches the expected effect, the discriminator with converged parameters is output as the abnormal data detection model.

6. The attack detection method according to claim 5, characterized in that: The detecting that the parameters of the discriminator meet the preset convergence conditions and the model training effect achieves the expected effect includes: Performing Fréchet starting distance calculation based on the multiple real samples and the multiple simulated samples generated by the generator to determine the difference value of the characteristic distribution between the real samples and the simulated samples; When it is determined that the probability output by the discriminator after predicting the simulated sample is within a preset range and the feature distribution difference value is less than a preset difference value, it is determined that the parameters of the discriminator meet the preset convergence conditions and the model training effect achieves the expected effect.

7. A power monitoring system, characterized in that: It includes monitoring equipment, alarm equipment and control equipment, and the control equipment is used to: Control the monitoring device to monitor the operation status of different devices in the power system in real time, and collect real-time operation data of different devices in the power system; Performing data mutation detection on the real-time operating data of different devices in the power system to determine the data mutation status of the real-time operating data; In the case where it is detected that there is no data mutation in the real-time operation data, abnormal data detection is performed on the real-time operation data using a pre-trained abnormal data detection model to determine a true data probability value of the real-time operation data, wherein the abnormal data detection model is a neural network model obtained by training according to historical operation data of the power system; When it is determined that the true data probability value of the real-time operation data is less than or equal to the calibration threshold, the alarm device is controlled to issue an abnormal alarm.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the electronic device implements the attack detection method for the power monitoring system based on the generative adversarial network as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the attack detection method for a power monitoring system based on a generative adversarial network as described in any one of claims 1 to 6 is executed.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed, the attack detection method for a power monitoring system based on a generative adversarial network as described in any one of claims 1 to 6 is executed.