Power system anomaly detection method, device and equipment and storage medium
By extracting and fusing the physical layer and information layer features of the power system, calculating the abnormal probability and using neural network models for detection, the problem of difficulty in dealing with complex power information physical attacks is solved in the existing technology, and high-accurate abnormal detection is achieved.
Patent Information
- Application Number
- CN202510117168.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art is difficult to deal with complex physical attacks on power information, resulting in the inability to accurately and timely detect power system abnormalities.
By extracting the features of physical layer information and information layer data, feature fusion is performed, the abnormal probability of physical layer and information layer is calculated, and anomaly detection is performed using a preset neural network model, and finally fusion abnormality detection and analysis is performed.
It realizes the identification of cross-layer attack behavior from different dimensions and levels, ensures the accuracy and reliability of anomaly detection, and can effectively deal with complex power information physical attacks.
Smart Images

Figure CN119988942A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power systems, and in particular to a method, device, equipment and storage medium for detecting anomalies in a power system. Background Art
[0002] The power system is increasingly dependent on information and communication networks, and has gradually evolved into a complex power cyber-physical system (CPS). CPS combines physical power networks and information and communication technologies to achieve intelligent operation through data collection, transmission of control instructions, remote monitoring and management. However, this makes the power system not only face traditional physical attack threats, but also vulnerable to complex network attacks. Attackers may cause system voltage fluctuations, frequency instability, or even system collapse by invading information networks and manipulating power generation or load control equipment. This coordinated attack, called power cyber-physical attacks (CPA), seriously threatens the safety and stability of the power system.
[0003] The existing power system security protection means are mainly single-level monitoring and defense, targeting physical-level equipment failures or information-level network intrusions, but are difficult to deal with cross-level complex attacks. For example, physical attacks may manifest as tampering with the setting values of power generation equipment, resulting in abnormal system fluctuations; while information attacks may affect the normal operation of information and communication networks through packet injection, delay manipulation, etc. If faced with complex power information physical attacks, traditional attack detection methods cannot effectively respond, which will have a direct impact. Summary of the invention
[0004] The present application provides a method, device, equipment and storage medium for detecting anomalies in a power system, which are used to solve the technical problem that the existing technology is too single-minded in consideration and cannot cope with complex physical attacks on power information, resulting in the inability to accurately and timely detect anomalies in the power system.
[0005] In view of this, the first aspect of the present application provides a method for detecting abnormality in a power system, comprising:
[0006] Extracting features of physical layer information and information layer data respectively to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate;
[0007] Performing feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector;
[0008] According to the power deviation of the physical layer and the delay deviation of the information layer, the abnormal probability of the physical layer and the abnormal probability of the information layer are calculated respectively;
[0009] Inputting the fused feature vector into a preset neural network model to perform anomaly detection to obtain an anomaly probability prediction value;
[0010] A fusion anomaly detection analysis is performed based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
[0011] Preferably, the extracting the features of the physical layer information and the information layer data respectively to obtain the physical layer features and the information layer features comprises:
[0012] Obtain physical layer variables in the power system and obtain physical layer information;
[0013] Performing standardization processing on each feature in the physical layer information to obtain a physical layer feature;
[0014] Extract information layer data from power system communication and control networks;
[0015] Each feature in the information layer data is standardized to obtain an information layer feature.
[0016] Preferably, the calculating the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer includes:
[0017] Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer;
[0018] Calculating a power deviation of a physical layer according to the transmission active power;
[0019] Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer;
[0020] Based on the confidence interval probability, the physical layer abnormality probability and the information layer abnormality probability are calculated respectively according to the power deviation and the delay deviation.
[0021] Preferably, the calculating the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer includes:
[0022] Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer;
[0023] Calculating a power deviation of a physical layer according to the transmission active power;
[0024] Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer;
[0025] Based on the confidence interval probability, the physical layer abnormality probability and the information layer abnormality probability are calculated respectively according to the power deviation and the delay deviation.
[0026] Preferably, performing fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result includes:
[0027] Combining the physical layer abnormality probability, the information layer abnormality probability and the abnormality probability prediction value, a weighted result fusion calculation is performed to obtain an abnormality detection fusion value;
[0028] Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain an anomaly detection result.
[0029] A second aspect of the present application provides a power system anomaly detection device, comprising:
[0030] A feature extraction unit, used to extract features of physical layer information and information layer data respectively, to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate;
[0031] A feature fusion unit, used for performing feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector;
[0032] A knowledge calculation unit, used to calculate the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer;
[0033] A model prediction unit, used for inputting the fused feature vector into a preset neural network model to perform anomaly detection and obtain an anomaly probability prediction value;
[0034] The anomaly detection unit is used to perform fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
[0035] Preferably, the feature extraction unit is specifically used for:
[0036] Obtain physical layer variables in the power system and obtain physical layer information;
[0037] Performing standardization processing on each feature in the physical layer information to obtain a physical layer feature;
[0038] Extract information layer data from power system communication and control networks;
[0039] Each feature in the information layer data is standardized to obtain an information layer feature.
[0040] Preferably, the knowledge computing unit is specifically used for:
[0041] Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer;
[0042] Calculating a power deviation of a physical layer according to the transmission active power;
[0043] Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer;
[0044] Based on the confidence interval probability, the physical layer abnormality probability and the information layer abnormality probability are calculated respectively according to the power deviation and the delay deviation.
[0045] Preferably, the anomaly detection unit is specifically used to:
[0046] Combining the physical layer abnormality probability, the information layer abnormality probability and the abnormality probability prediction value, a weighted result fusion calculation is performed to obtain an abnormality detection fusion value;
[0047] Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain an anomaly detection result.
[0048] A third aspect of the present application provides a power system anomaly detection device, the device comprising a processor and a memory;
[0049] The memory is used to store program code and transmit the program code to the processor;
[0050] The processor is used to execute the power system anomaly detection method described in the first aspect according to the instructions in the program code.
[0051] A fourth aspect of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to execute the power system anomaly detection method described in the first aspect.
[0052] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0053] In the present application, a method for detecting anomalies in a power system is provided, including: extracting features of physical layer information and information layer data respectively to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate; performing feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector; calculating the physical layer anomaly probability and the information layer anomaly probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer; inputting the fused feature vector into a preset neural network model for anomaly detection to obtain an anomaly probability prediction value; performing fused anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
[0054] The power system anomaly detection method provided by this application takes into account the data analysis of the physical layer and the information layer at the same time, so that cross-layer attack behaviors can be identified from different dimensions and levels, thereby ensuring that the anomaly detection scheme can cope with complex physical attacks on power information; and in this process, anomaly detection analysis is performed based on knowledge calculation and anomaly prediction, and the fusion analysis results are taken as the final detection results, which can ensure the accuracy and reliability of anomaly detection and meet the current needs of power system anomaly detection. Therefore, this application can solve the technical problem that the existing technology is too single-minded in considering the level and cannot cope with complex physical attacks on power information, resulting in the inability to accurately and timely detect power system anomalies. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 A flowchart of a method for detecting abnormality in a power system provided in an embodiment of the present application;
[0056] Figure 2 A schematic diagram of the structure of a power system anomaly detection device provided in an embodiment of the present application;
[0057] Figure 3 Schematic diagram of the IEEE 14-node system topology provided for the application example of this application;
[0058] Figure 4 Data change curve diagram of the physical layer and information layer provided for the application example of this application;
[0059] Figure 5 A graph showing the abnormality detection probability changing over time provided for the application example of this application. DETAILED DESCRIPTION
[0060] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0061] For easier understanding, see Figure 1 , an embodiment of a power system anomaly detection method provided by the present application includes:
[0062] Step 101, respectively extract the features of physical layer information and information layer data to obtain physical layer features and information layer features, the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate.
[0063] Furthermore, step 101 includes:
[0064] Obtain physical layer variables in the power system and obtain physical layer information;
[0065] Performing standardization on each feature in the physical layer information to obtain a physical layer feature;
[0066] Extract information layer data from power system communication and control networks;
[0067] Each feature in the information layer data is standardized to obtain the information layer feature.
[0068] It should be noted that this embodiment considers the abnormality detection of the power system from different levels, mainly including the physical level and the information level. The physical layer information mainly includes the physical variables of the power system, such as voltage, current, power and frequency, etc., which are not limited here and are only used as examples. This embodiment extracts the physical variables of the nodes. In order to ensure that these features are comparable, they also need to be standardized; standardization can eliminate the dimensional differences between different feature values, concentrate them on the same scale, and improve data processing efficiency.
[0069] If it is assumed that the physical layer information of the i-th node is extracted in this embodiment, then the node voltage can be expressed as , Node current , active power between nodes , System frequency , reactive power between nodes The standardization process is expressed as:
[0070]
[0071] in, It is a kind of physical layer information at time t. It represents the result after standardization. It is a feature The mean of It is a feature This process adjusts the eigenvalues to have a mean of 0 and a variance of 1.
[0072] By standardizing all the features extracted at each time point t, we can obtain the standardized feature vector of the physical layer, that is, the physical layer feature :
[0073]
[0074] The physical layer characteristics include all characteristic information of the physical layer, and are all the results of standardization processing.
[0075] The information layer data refers to the communication and control network related information of the power system, including but not limited to network traffic, communication delay, packet loss rate, network topology changes and log information. The information layer data extracted in this embodiment includes communication delay, , Network traffic , Packet Loss Rate Statistics of abnormal behaviors in log information ; The standardization formula is the same as above and will not be repeated here. After standardizing all the features extracted at each time point, the standardized feature vector of the information layer can be obtained, that is, the information layer feature :
[0076]
[0077] The information layer features include all characteristic information of the information layer, and are all the results of standardized processing.
[0078] Step 102: Perform feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector.
[0079] By performing a vector splicing fusion operation on the physical layer features and the information layer features, the fused feature vector can be obtained. :
[0080]
[0081] The fused feature vector combines the features of the physical layer and the information layer, which can improve the accuracy of subsequent anomaly prediction results and thus ensure the detection effect of physical attacks on power information.
[0082] Step 103: Calculate the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer.
[0083] Further, step 103 includes:
[0084] Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer;
[0085] Calculate the power deviation of the physical layer based on the transmitted active power;
[0086] Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer;
[0087] Based on the confidence interval probability, the physical layer anomaly probability and information layer anomaly probability are calculated according to the power deviation and delay deviation respectively.
[0088] In order to accurately and reliably detect and analyze the abnormality of the power system from different aspects, this embodiment provides two methods to analyze the abnormality probability, one of which is a knowledge-based abnormality probability calculation method. The corresponding deviation values can be calculated based on the physical layer information and the information layer data respectively; and the corresponding abnormality probability value can be calculated based on the respective deviation values.
[0089] Specifically, the power balance and power flow of the power system are analyzed based on the following formula:
[0090]
[0091] in, , Node and nodes The voltage, , Node and nodes The phase angle, For Node , The impedance between Is a node and nodes The active power transmitted between.
[0092] Calculate the power deviation of the physical layer based on the transmitted active power :
[0093]
[0094] in, , Respectively represent the original value and calculated value of the transmitted active power, and the calculated value is the value obtained by the above calculation. The larger the value, the more likely the physical layer is abnormal.
[0095] The information layer mainly monitors and analyzes network traffic:
[0096]
[0097] in, , represents the actual transmission delay and predicted transmission delay of the ith communication session, Indicates the delay deviation in network communication. If the deviation is significant, there may be an information layer attack.
[0098] Based on the confidence interval probability, the physical layer anomaly probability and information layer anomaly probability are calculated according to the power deviation and delay deviation respectively:
[0099]
[0100] in, is the cumulative distribution function of the standard normal distribution, , are respectively the expected value of the delay deviation detection of the power deviation, , They represent the standard deviation of the delay deviation detection value of the power deviation respectively; , They represent the abnormal probability of physical layer and the abnormal probability of information layer respectively.
[0101] Step 104: Input the fused feature vector into a preset neural network model to perform anomaly detection to obtain an anomaly probability prediction value.
[0102] It is understandable that the preset neural network model is a prediction model obtained by training and optimizing based on historical data information, and can be directly used to predict abnormal probability values in actual scenarios; in fact, it is to continuously optimize the parameters of the model by analyzing historical data. Model optimization is based on historical attack patterns and detection performance to improve the recognition ability and detection accuracy of new attacks; the specific process is not described in detail.
[0103] The anomaly detection process based on the preset neural network model is expressed as:
[0104]
[0105] in, , , are all model weight matrices, is the sigmoid activation function, is the activation function. The fused feature vector After entering the model, the abnormal probability value can be predicted, that is, the abnormal probability prediction value .
[0106] Step 105: Perform fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
[0107] Further, step 105 includes:
[0108] Combine the physical layer anomaly probability, information layer anomaly probability and anomaly probability prediction value to perform weighted result fusion calculation to obtain anomaly detection fusion value;
[0109] Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain the anomaly detection result.
[0110] The final abnormal probability value of this embodiment is the result of integrating the probability values obtained by driving in different ways. The fusion calculation process is expressed as:
[0111]
[0112] in, is the number of abnormal probability analysis schemes, or the number of abnormal probability values. In this embodiment, the value is 3. is the weight of each abnormal probability value, and satisfies:
[0113]
[0114] The anomaly detection fusion value is .
[0115] Anomaly detection is to get a clear anomaly result based on the anomaly detection fusion value analysis. The anomaly threshold is expressed as , can be set according to actual conditions; if it is anomaly detection fusion value Exceeded the abnormal threshold , it proves that the power system is abnormal, which can directly trigger the early warning operation. Based on the above different methods, we can analyze in detail whether it is the abnormality of the physical layer or the abnormality of the information layer. The specific process will not be repeated.
[0116] For ease of understanding, this application provides an application example of a power system anomaly detection method, mainly analyzing an IEEE 14-node system, with topological relationships such as Figure 3As shown in the figure, it is used to simulate the power flow and system behavior in the process of power generation, transmission and load scheduling in the actual power network. The main physical equipment of the system includes: Nodes 1 to 14: Each node represents a bus or load center, responsible for receiving or distributing electricity. Generator: Set at nodes 1, 2, 3, 6 and 8, responsible for the generation of electricity. Transmission lines: Connect each node and transmit active power and reactive power. System frequency: Maintained at the rated frequency of 50Hz, but may fluctuate under attack. The information layer is responsible for communication and control, including: Communication network: Connect each node, transmit control commands, monitoring data and alarm information. Control center: Centrally monitor and manage the operation of each node, detect attacks and take countermeasures.
[0117] In order to accurately monitor the attack behavior in the power system, the system collects data from the physical layer and information layer in real time. The physical layer data includes node voltage, current, power transmission and system frequency, and the information layer data includes communication delay, packet loss rate, network traffic and abnormal log information. For the change of information layer data over time, please refer to Figure 4 .
[0118] The system collected physical layer information of each node at different time points, especially before and after the attack, where significant changes in power transmission, voltage, and frequency can be seen. The sampling results are shown in Table 1.
[0119] Table 1 Physical layer information data before and after the attack
[0120]
[0121] During the attack, the information layer data also showed obvious anomalies, especially the significant increase in communication delay, packet loss rate and network traffic. The sampling results are shown in Table 2.
[0122] Table 2 Information layer data before and after the attack
[0123]
[0124] Through the data physics fusion method, the data of the physical layer and the information layer are standardized and input into the model. The standardized feature vectors of the physical layer and the information layer are shown in Table 3.
[0125] Table 3 Standardized feature vectors of cyber-physical fusion
[0126]
[0127] Through the data physics fusion model, the system can calculate the anomaly detection probability at each moment in real time. When an attack occurs, the detection probability will increase significantly, as shown in Table 4.
[0128] Table 4 Anomaly detection probability at each time
[0129]
[0130] The specific anomaly detection probability changes over time as follows Figure 5 As shown, it can be found that at time seconds, when an attack occurs, the anomaly detection probability of the detection model exceeds the anomaly threshold , the system triggers the early warning mechanism and takes load adjustment and network isolation measures at subsequent time points.
[0131] This application example demonstrates how to apply the data-physical fusion-driven power information-physical attack collaborative detection method in the IEEE14-node system. By combining the data of the physical layer and the information layer, the system can effectively detect physical attacks and information attacks, and protect the stability and security of the power system through a real-time response mechanism.
[0132] The power system anomaly detection method provided by the embodiment of the present application takes into account the data analysis of the physical layer and the information layer at the same time, so that cross-layer attack behaviors can be identified from different dimensions and levels, thereby ensuring that the anomaly detection scheme can cope with complex physical attacks on power information; and in this process, anomaly detection analysis is performed based on knowledge calculation and anomaly prediction, and the fusion analysis results are taken as the final detection results, which can ensure the accuracy and reliability of anomaly detection and meet the current needs of power system anomaly detection. Therefore, the embodiment of the present application can solve the technical problem that the existing technology is too single-level and cannot cope with complex physical attacks on power information, resulting in the inability to accurately and timely detect power system anomalies.
[0133] For easier understanding, see Figure 2 The present application provides an embodiment of a power system abnormality detection device, comprising:
[0134] The feature extraction unit 201 is used to extract features of physical layer information and information layer data respectively to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate;
[0135] The feature fusion unit 202 is used to perform feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector;
[0136] A knowledge calculation unit 203, used to calculate the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer;
[0137] The model prediction unit 204 is used to input the fused feature vector into a preset neural network model to perform anomaly detection and obtain an anomaly probability prediction value;
[0138] The anomaly detection unit 205 is used to perform fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
[0139] Furthermore, the feature extraction unit 201 is specifically used for:
[0140] Obtain physical layer variables in the power system and obtain physical layer information;
[0141] Performing standardization on each feature in the physical layer information to obtain a physical layer feature;
[0142] Extract information layer data from power system communication and control networks;
[0143] Each feature in the information layer data is standardized to obtain the information layer feature.
[0144] Furthermore, the knowledge computing unit 203 is specifically used for:
[0145] Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer;
[0146] Calculate the power deviation of the physical layer based on the transmitted active power;
[0147] Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer;
[0148] Based on the confidence interval probability, the physical layer anomaly probability and information layer anomaly probability are calculated according to the power deviation and delay deviation respectively.
[0149] Furthermore, the abnormality detection unit 205 is specifically configured to:
[0150] Combine the physical layer anomaly probability, information layer anomaly probability and anomaly probability prediction value to perform weighted result fusion calculation to obtain anomaly detection fusion value;
[0151] Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain the anomaly detection result.
[0152] The present application also provides a power system anomaly detection device, the device comprising a processor and a memory;
[0153] The memory is used to store the program code and transmit the program code to the processor;
[0154] The processor is used to execute the power system anomaly detection method in the above method embodiment according to the instructions in the program code.
[0155] The present application also provides a computer-readable storage medium, which is used to store program codes, and the program codes are used to execute the power system anomaly detection method in the above method embodiment.
[0156] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0157] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0158] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0159] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for executing all or part of the steps of the method described in each embodiment of the present application through a computer device (which can be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (full name in English: Read-Only Memory, English abbreviation: ROM), random access memory (full name in English: Random Access Memory, English abbreviation: RAM), disk or optical disk and other media that can store program codes.
[0160] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for detecting abnormality in a power system, characterized in that: include: Extracting features of physical layer information and information layer data respectively to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate; Performing feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector; According to the power deviation of the physical layer and the delay deviation of the information layer, the abnormal probability of the physical layer and the abnormal probability of the information layer are calculated respectively; Inputting the fused feature vector into a preset neural network model to perform anomaly detection to obtain an anomaly probability prediction value; A fusion anomaly detection analysis is performed based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
2. The power system anomaly detection method according to claim 1, characterized in that: The extracting the features of the physical layer information and the information layer data respectively to obtain the physical layer features and the information layer features comprises: Obtain physical layer variables in the power system and obtain physical layer information; Performing standardization processing on each feature in the physical layer information to obtain a physical layer feature; Extract information layer data from power system communication and control networks; Each feature in the information layer data is standardized to obtain an information layer feature.
3. The power system anomaly detection method according to claim 1, characterized in that: The calculating the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer comprises: Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer; Calculating a power deviation of a physical layer according to the transmission active power; Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer; Based on the confidence interval probability, the physical layer abnormality probability and the information layer abnormality probability are calculated respectively according to the power deviation and the delay deviation.
4. The power system anomaly detection method according to claim 1, characterized in that: The performing of fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result includes: Combining the physical layer abnormality probability, the information layer abnormality probability and the abnormality probability prediction value, a weighted result fusion calculation is performed to obtain an abnormality detection fusion value; Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain an anomaly detection result.
5. A power system anomaly detection device, characterized in that: include: A feature extraction unit, used to extract features of physical layer information and information layer data respectively, to obtain physical layer features and information layer features, wherein the physical layer information includes node current, node voltage and transmission power, and the information layer data includes network traffic, communication delay and data packet loss rate; A feature fusion unit, used for performing feature fusion and splicing operations on the physical layer features and the information layer features to obtain a fused feature vector; A knowledge calculation unit, used to calculate the physical layer abnormality probability and the information layer abnormality probability respectively according to the power deviation of the physical layer and the delay deviation of the information layer; A model prediction unit, used for inputting the fused feature vector into a preset neural network model to perform anomaly detection and obtain an anomaly probability prediction value; The anomaly detection unit is used to perform fusion anomaly detection analysis based on the physical layer anomaly probability, the information layer anomaly probability and the anomaly probability prediction value to obtain an anomaly detection result.
6. The power system anomaly detection device according to claim 5, characterized in that: The feature extraction unit is specifically used for: Obtain physical layer variables in the power system and obtain physical layer information; Performing standardization processing on each feature in the physical layer information to obtain a physical layer feature; Extract information layer data from power system communication and control networks; Each feature in the information layer data is standardized to obtain an information layer feature.
7. The power system anomaly detection device according to claim 5, characterized in that: The knowledge computing unit is specifically used for: Calculate the active power transmitted between nodes based on the node voltage and the impedance between nodes in the physical layer; Calculating a power deviation of a physical layer according to the transmission active power; Calculating a delay deviation of the information based on the actual transmission delay and the predicted transmission delay of the communication session in the information layer; Based on the confidence interval probability, the physical layer abnormality probability and the information layer abnormality probability are calculated respectively according to the power deviation and the delay deviation.
8. The power system anomaly detection device according to claim 5, characterized in that: The anomaly detection unit is specifically used for: Combining the physical layer abnormality probability, the information layer abnormality probability and the abnormality probability prediction value, a weighted result fusion calculation is performed to obtain an abnormality detection fusion value; Anomaly detection analysis is performed based on the anomaly detection fusion value and the anomaly threshold to obtain an anomaly detection result.
9. A power system anomaly detection device, characterized in that: The device comprises a processor and a memory; The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the power system anomaly detection method according to any one of claims 1-4 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program codes, and the program codes are used to execute the power system anomaly detection method according to any one of claims 1 to 4.