Multipoint FDI attack detection and defense method facing load frequency control

By using the combined method of DL-LSTM and BiGRU models in the load frequency control system, detecting and defending multi-point FDI attacks, the problem of poor detection and defense of multi-point FDI attacks in complex power systems is solved, and the stability and adaptability of the system are improved.

CN120034366APending Publication Date: 2025-05-23CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510118342.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art is poor in real-time and adaptability when facing multi-point FDI attacks in complex power systems, and it is difficult to effectively detect and defend, especially in high-voltage DC links, renewable energy and system nonlinear environments.

Method used

The attack detector is built using a two-layer long and short-term memory neural network (DL-LSTM), and the attack defense is built using a bidirectional gated memory unit (BiGRU). Combining the dynamic response and load regulation model of the LFC system, the detection and defense of multi-point FDI attacks are realized.

Benefits of technology

It improves the stability and resilience of LFC systems under cyber attacks, and can respond and adjust in real time in complex power environments, minimize the impact of FDI attacks on the system, and ensures the long-term sustainability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034366A_ABST
    Figure CN120034366A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-point FDI attack detection and defense method for load frequency control, and relates to the technical field of smart grid security, and the method mainly comprises the steps: constructing an LFC system dynamic model according to a research object system, the method comprises the following steps: constructing an FDI attack model according to multipoint false data injection attack characteristics, constructing an attack detector by using a double-layer long-short-term memory neural network, and constructing an attack defender by using a bidirectional gating memory unit; and detecting and defending a research object system by using an attack detector and the attack defender. By implementing the multi-point FDI attack detection and defense method for load frequency control provided by the invention, the stability and elasticity of the LFC system under the network attack can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart grid security technology, and more specifically, to a multi-point FDI attack detection and defense method for load frequency control. Background Art

[0002] In modern power systems, with the rapid development of computing, communication and control technologies, power systems have gradually transformed into cyber-physical power systems (CPPS), which are characterized by the deep integration of physical power grids with sensing, information, and communication networks. Load frequency control (LFC), as a typical application of CPPS, is mainly used to adjust the output power of generators in the control area to maintain the real-time balance between power generation and load and power exchange between regions. However, with the high degree of informatization and openness of the new power system, the LFC system faces more network security threats, especially false data injection (FDI) attacks. FDI attacks are a common form of network attacks. Attackers invade the communication network, tamper with the measurement or control signals of the LFC system, bypass the data detection mechanism, and induce the LFC system center to misjudge the power balance state of the region. This attack may not only undermine the stability of the system, but also lead to the loss of control of the grid frequency and serious deviations in economic operation. FDI attacks usually target telemetry data from remote terminal devices, which are key inputs for control decisions of the LFC system. Once tampered, the attack may lead to erroneous power generation instructions, undermine the stability of the grid frequency, and may have catastrophic consequences for the power system. At present, the research on FDI attack defense for LFC systems is mainly divided into two categories: model-based and data-driven methods. In the model-based method, the system's mathematical model and prior knowledge are relied on to detect abnormal behavior, such as Kalman filtering, matrix decomposition and other technologies. Although these methods are effective in theory, they have poor real-time and adaptability in complex network environments, especially when facing multi-point FDI attacks, and their effects are limited. At the same time, the data-driven method avoids the reliance on prior knowledge by directly learning the normal behavior of the system from large-scale measurement data, which provides higher flexibility and adaptability for attack detection. However, the existing data-driven methods mostly focus on the attack scenario of a single measurement point, ignoring the problem of multi-point attacks that may occur in the LFC system, which is particularly critical in the complex power system environment. The time series analysis method has significant advantages in the application of multi-point FDI attack detection and defense in the power system. First, the time series analysis method can effectively capture the laws of dynamic changes in the system, especially the time-varying characteristics of key variables such as frequency and power in the LFC system. Secondly, the time series analysis method can make full use of historical data and enhance the system's ability to identify attack patterns, especially when facing multi-dimensional data and multi-point attacks, and has good adaptability. In addition, the time series analysis method has strong flexibility in a dynamic environment, can adapt to system changes and adjust in real time, and provide higher detection accuracy and attack mitigation capabilities.However, there are obvious deficiencies in the current research on the application of time series analysis to FDI attack detection and defense methods. First, the current time series analysis methods perform poorly in the face of multi-point FDI attacks, especially when the attack sources are distributed in different sensors or control points. They often cannot capture multiple attack modes at the same time, resulting in poor detection results. Second, the existing time series analysis methods have limitations when dealing with complex power system environments. Factors such as the rapid dynamics of high voltage direct current (HVDC) links, renewable energy sources (RESs) fluctuations, and system nonlinearity increase the complexity of the system. Traditional time series models may not be able to effectively distinguish normal fluctuations from attack signals under these complex backgrounds, thus affecting the accuracy of attack detection. Summary of the invention

[0003] The purpose of the present invention is to provide a multi-point FDI attack detection and defense method for load frequency control, which can enhance the stability and resilience of the LFC system under network attacks.

[0004] The present invention provides a multi-point FDI attack detection and defense method for load frequency control, comprising the following steps: S1: constructing an LFC system dynamics model according to a research object system; S2: constructing an FDI attack model according to the characteristics of multi-point false data injection attacks; S3: constructing an attack detector according to the LFC system dynamics model and the FDI attack model using a double-layer long short-term memory neural network; S4: constructing an attack defender according to the LFC system dynamics model and the FDI attack model using a bidirectional gated memory unit; S5: detecting and defending the research object system using the attack detector and the attack defender.

[0005] Furthermore, step S1 specifically includes: constructing a LFC system dynamics model according to the object system, such as formula:

[0006]

[0007] ACE i =β i Δf i +P tie-i ,

[0008] Where Δf i , ΔP tie-i , ΔP tie-ij,ac , ΔP tie-ij,dc , ΔP mi , ΔP vi , ΔP di , ΔP ci and ΔP RESiThey represent the frequency deviation in the power system, the net tie line power deviation of region i, the AC tie line power deviation between regions i and j, the DC tie line power deviation between regions i and j, the mechanical input deviation of the generator, the valve position deviation, the load change, the power regulation command of region i, and the change of the renewable energy output power of region i; D i 、M i , R i , T gi , T ti are the generator damping coefficient, generator inertia moment, speed reduction coefficient, governor time constant and turbine time constant in power system zone i; T ij K is the synchronization coefficient of the tie line between regions ij; dci is the DC link gain, T dci is the DC link time constant; ACE i Represents the automatic control error in region i, which is the frequency deviation Δf i and tie line power deviation ΔP tie-i A linear combination of i =1 / R i +D i is the frequency offset factor, K pi and K ii is the proportional gain and integral gain of the PI controller in region i; N i is the set of regions adjacent to region i, and s is a complex frequency domain variable.

[0009] Furthermore, step S2 specifically includes: constructing an FDI attack model according to the characteristics of multi-point false data injection attack, such as formula:

[0010] a i1 (t) = λ si ,t∈[τ i ,+∞),

[0011] a i2 (t) = λ pi ,t∈τ i ,

[0012] a i3 (t) = λ sin1i ·sin(λ sin2i ·t),t∈τ i ,

[0013] A=[A f,i ,A Pij,ac ,A Pij,dc ],

[0014] Among them, AI 1 (t) is a step attack, λ si and τi are step parameter and attack duration respectively; a i2 (t) is the pulse attack, λ pi is the pulse parameter; a i3 (t) is a sinusoidal attack, λ sin1i is the amplitude, λ sin2i is the frequency; A represents the multi-point attack vector for different measurement channels, A f,i Represents the elements corresponding to the frequency channel, A Pij,ac Represents the element corresponding to the AC tie line power supply, A Pij,dc Represents the element corresponding to the DC tie line power supply.

[0015] Furthermore, the above-mentioned attack detector includes a first classifier, a second classifier and a third classifier, the first classifier includes a sequence input layer, a stacked LSTM layer and an output layer; the second classifier and the third classifier have the same structure as the first classifier; the stacked LSTM layer includes a first LSTM layer, a second LSTM layer and a third LSTM layer stacked in sequence, and there is a dropout layer behind the first LSTM layer, the second LSTM layer and the third LSTM layer, and the first LSTM layer, the second LSTM layer and the third LSTM layer have 256, 128 and 64 hidden units respectively; using the LFC system dynamics model and the FDI attack model, a variety of attack scenarios and normal operation cases are constructed to obtain a training data set; the attack detector is obtained by training the training data set.

[0016] Furthermore, the first classifier is used to obtain the first layer of labels according to the input features; the second classifier and the third classifier are used to perform conditional classification according to the first layer of labels to obtain the second layer of labels, such as the formula:

[0017] Label 1 =classifer 1 (X),

[0018]

[0019] Among them, Label 1 is the first-level label, classifer 1 represents the first classifier, X represents the input feature, Label 2 For the second layer of labels, classifer 2 Represents the second classifier, classifer 3 Indicates the third classifier, normal indicates normal, single indicates single-point attack, and multi indicates multi-point attack.

[0020] Furthermore, the above attack detector also includes a fully connected dense layer, such as the formula:

[0021]

[0022] Among them, z is the output of the fully connected dense layer, ReLU is the activation function, and W d and b d is the weight matrix and bias vector of the fully connected dense layer, h (3) T is the final time feature of the third LSTM layer.

[0023] Further, step S4 specifically includes: according to the LFC system dynamics model and the FDI attack model, using real-time measurement data to train the bidirectional gated memory unit to obtain a trained bidirectional gated memory unit, and obtaining an attack defender according to the trained bidirectional gated memory unit.

[0024] Furthermore, step S5 specifically includes: S51: using the attack detector to detect the LFC data to obtain the operating status and the attack type, S52: when the operating status and the attack type are normal, it means that the system is operating normally and the system detection is continuously performed; when the operating status and the attack type are single-point attacks, using the attack defender, the damaged measurement is replaced with the predicted normal value to ensure the stability of the system; when the operating status and the attack type are multi-point attacks, using the attack defender, activating multiple bidirectional gated memory unit models at the same time, obtaining the predicted normal value, and replacing the damaged measurement with the predicted normal value to ensure the stability of the system.

[0025] Furthermore, the above model of activating multiple bidirectional gated memory units simultaneously is as follows:

[0026]

[0027] in, Represents the predicted normal value of the bidirectional gated memory unit corresponding to the i-th region, BiGRU i represents the bidirectional gated memory unit corresponding to the i-th region, represents the input vector of the bidirectional gated memory unit corresponding to the i-th region, and N represents the number of regions of the object system.

[0028] The present invention also provides a computer program product, including a computer program, which implements the steps of the above-mentioned multi-point FDI attack detection and defense method for load frequency control when executed by a processor.

[0029] The implementation of the multi-point FDI attack detection and defense method for load frequency control provided by the present invention has the following beneficial effects:

[0030] Aiming at the problem of multi-point FDI attack detection and defense, the present invention analyzes the characteristics of multi-point FDI attacks in power systems, combines the dynamic response and load regulation model of LFC systems, and uses a data-driven double-layer long short-term memory (Double-Layer Long Short-Term Memory, DL-LSTM) attack detector to accurately and efficiently detect multi-point FDI attacks. Through the hierarchical LSTM structure, the system can effectively capture time dependencies and identify attack patterns in time series data. At the same time, combined with the bidirectional gated recurrent unit (Bidirectional Gated Recurrent The invention proposes a defense mechanism of a multi-region LFC system, BiGRU, which can mitigate the impact of attacks in real time and ensure the stability of the system through its superior performance in time series data prediction. Through deep learning analysis of power system time series data, the system can respond and adjust in real time in a changeable power environment to minimize the impact of FDI attacks on the LFC system. Considering the complexity of the multi-region LFC system, the invention carries out simulation and testing under the influence of high voltage direct current (HVDC) links, renewable energy sources (RESs) and nonlinear characteristics of the system, and verifies the effectiveness and high adaptability of the invention in a complex power grid environment. By establishing a multi-region LFC system with high complexity and simulating its dynamic response, the invention can maximize the response speed and accuracy of the system to FDI attacks, while ensuring the stability and efficient operation of the LFC system in a changeable power environment, and ensuring the long-term sustainability and security of the system. In short, by designing a multi-layer defense framework, the invention can provide a robust solution for multi-point simultaneous attacks in a complex power environment, ensuring the safe and stable operation of the LFC system. It can adapt to different attack types and effectively dynamically protect the system, enhance the resilience of the LFC system under network attacks, and ensure the stability and resilience of the power system. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The present invention will be further described below with reference to the accompanying drawings and embodiments, in which:

[0032] Figure 1 It is a flow chart of a multi-point FDI attack detection and defense method for load frequency control provided by the present invention;

[0033] Figure 2 It is a simplified diagram of the N-zone power system and a schematic diagram of the LFC model framework of the i-th zone provided by the present invention;

[0034] Figure 3 It is a flow chart of the detection and defense strategy provided by the present invention;

[0035] Figure 4 is a comparison diagram of BiGRU prediction results provided by the present invention; wherein, Figure 4(a) is the frequency deviation of region 1, Figure 4 (b) is the tie line power in area 2;

[0036] Figure 5 It is a schematic diagram comparing the frequency deviation stability of region 1 before and after attack elimination in case A provided by the present invention;

[0037] Figure 6 It is a schematic diagram comparing the stability of frequency deviation in region 2 before and after attack elimination in case B provided by the present invention;

[0038] Figure 7 It is a schematic diagram comparing the power stability of the interconnection line in area 3 before and after the attack is eliminated in the CASE C situation provided by the present invention. DETAILED DESCRIPTION

[0039] In order to have a clearer understanding of the technical features, purposes and effects of the present invention, specific embodiments of the present invention are now described in detail with reference to the accompanying drawings.

[0040] Figure 1 A schematic diagram of a multi-point FDI attack detection and defense method for load frequency control in this embodiment is shown. In this embodiment, the multi-point FDI attack detection and defense method for load frequency control includes the following steps:

[0041] S1: Construct the LFC system dynamics model according to the object system;

[0042] In an exemplary embodiment, step S1 specifically includes: constructing a LFC system dynamics model according to the object system, such as formula:

[0043]

[0044] ACE i =β i Δf i +P tie-i ,

[0045] Where Δf i , ΔP tie-i , ΔP tie-ij,ac , ΔP tie-ij,dc , ΔP mi , ΔP vi , ΔP di , ΔP ci and ΔP RESiThey represent the frequency deviation in the power system, the net tie line power deviation of region i, the AC tie line power deviation between regions i and j, the DC tie line power deviation between regions i and j, the mechanical input deviation of the generator, the valve position deviation, the load change, the power regulation command of region i, and the change of the renewable energy output power of region i; D i 、M i , R i , T gi , T ti are the generator damping coefficient, generator inertia moment, speed reduction coefficient, governor time constant and turbine time constant in power system zone i; T ij K is the synchronization coefficient of the tie line between regions ij; dci is the DC link gain, T dci is the DC link time constant; ACE i Represents the automatic control error in region i, which is the frequency deviation Δf i and tie line power deviation ΔP tie-i A linear combination of i =1 / R i +D i is the frequency offset factor, K pi and K ii is the proportional gain and integral gain of the PI controller in region i; N i is the set of regions adjacent to region i, s is a complex frequency domain variable;

[0046] S2: Construct FDI attack model based on the characteristics of multi-point false data injection attack;

[0047] In an exemplary embodiment, step S2 specifically includes: constructing an FDI attack model according to the characteristics of multi-point false data injection attack, such as formula:

[0048] a i1 (t) = λ si ,t∈[τ i ,+∞),

[0049] a i2 (t) = λ pi ,t∈τ i ,

[0050] a i3 (t) = λ sin1i ·sin(λ sin2i ·t),t∈τ i ,

[0051] A=[A f,i ,A Pij,ac ,A Pij,dc ],

[0052] Among them, AI 1 (t) is a step attack, λ si and τ i are step parameter and attack duration respectively; a i2 (t) is the pulse attack, λ pi is the pulse parameter; a i3 (t) is a sinusoidal attack, λ sin1i is the amplitude, λ sin2i is the frequency; A represents the multi-point attack vector for different measurement channels, A f,i Represents the elements corresponding to the frequency channel, A Pij,ac Represents the element corresponding to the AC tie line power supply, A Pij,dc Represents the element corresponding to the DC tie line power supply;

[0053] S3: Based on the LFC system dynamics model and the FDI attack model, an attack detector is constructed using a two-layer long short-term memory neural network;

[0054] In an exemplary embodiment, the attack detector includes a first classifier, a second classifier and a third classifier, the first classifier includes a sequence input layer, a stacked LSTM layer and an output layer; the second classifier and the third classifier have the same structure as the first classifier; the stacked LSTM layer includes a first LSTM layer, a second LSTM layer and a third LSTM layer stacked in sequence, the first LSTM layer, the second LSTM layer and the third LSTM layer are each followed by a dropout layer, and the first LSTM layer, the second LSTM layer and the third LSTM layer have 256, 128 and 64 hidden units respectively;

[0055] Using the LFC system dynamics model and the FDI attack model, a variety of attack scenarios and normal operation cases are constructed to obtain a training data set; the attack detector is obtained by training the training data set;

[0056] It should be noted that the above-mentioned attack scenarios include attack types such as step, pulse, and sine, as well as normal operation cases, which are used as input data; each case consists of a vector with multiple time steps, which contains the measurement features: Δf 1 (t),Δf 2 (t),Δf 3 (t),ΔP tie-1 (t),ΔP tie-2 (t),ΔP tie-3 (t), during the training process, the impact of RES and load perturbations is considered, and the dataset includes single-point and multi-point FDI attacks;

[0057] In an exemplary embodiment, the first classifier is used to obtain a first layer of labels according to the input features; the second classifier and the third classifier are used to perform conditional classification according to the first layer of labels to obtain a second layer of labels, such as the formula:

[0058] Label 1 =classifer 1 (X),

[0059]

[0060] Among them, Label 1 For the first layer of labels, classifer 1 represents the first classifier, X represents the input feature, Label 2 For the second layer of labels, classifer 2 Represents the second classifier, classifer 3 Indicates the third classifier, normal means normal, single means single-point attack, and multi means multi-point attack;

[0061] It should be noted that the attack detector;ultimately obtains the operation status and attack type according to the first layer label and the second layer label;

[0062] In an exemplary embodiment, the dropout rate of the dropout layer is 0.5;

[0063] In an exemplary embodiment, the attack detector further includes a fully connected dense layer, such as the formula:

[0064]

[0065] Among them, z is the output of the fully connected dense layer, ReLU is the activation function, and W d and b d is the weight matrix and bias vector of the fully connected dense layer, h (3) T is the final time feature of the third LSTM layer;

[0066] It should be noted that the ReLU activation function is defined as ReLU(x)=max(0,x), which introduces nonlinearity to enhance feature representation;

[0067] In an exemplary embodiment, the output layer uses a softmax function for multi-class classification;

[0068] It should be noted that the output layer uses the softmax function for multi-class classification, as shown below:

[0069]

[0070] Among them, K is the total number of categories, y i represents the predicted probability of the i-th class, and the softmax output is used to assign the classification label according to the highest probability;

[0071] S4: Based on the LFC system dynamics model and FDI attack model, an attack defender is constructed using a bidirectional gated memory unit;

[0072] In an exemplary embodiment, step S4 specifically includes: according to the LFC system dynamics model and the FDI attack model, using real-time measurement data to train the bidirectional gated memory unit to obtain a trained bidirectional gated memory unit, and obtaining an attack defender according to the trained bidirectional gated memory unit;

[0073] Specifically, as the formula:

[0074]

[0075] if an FDI attack is detected., where, is the predicted value of the bidirectional gated memory unit corresponding to the ith region in the LFC system dynamics model, represents a bidirectional gated memory unit, represents the τth element of the input time series vector; min means that the training goal is to minimize the prediction error, θ is the parameter of the bidirectional gated memory unit, T is the total number of training samples, represents the real-time measurement data corresponding to the ith region in the LFC system dynamics model, It means that once an FDI attack is detected, the damaged measurements are replaced with predicted normal values ​​to ensure system stability;

[0076] S5: Use attack detectors and attack defenders to detect and defend the research object system;

[0077] In an exemplary embodiment, step S5 specifically includes:

[0078] S51: Use the attack detector to detect the LFC data and obtain the operation status and attack type.

[0079] S52: When the operation status and the attack type are normal, it indicates that the system is operating normally and the system detection is continuously performed; when the operation status and the attack type are single-point attacks, the attack defender is used to replace the damaged measure with the predicted normal value to ensure the stability of the system; when the operation status and the attack type are multi-point attacks, the attack defender is used to simultaneously activate multiple bidirectional gated memory unit models to obtain the predicted normal value, and the damaged measure is replaced with the predicted normal value to ensure the stability of the system;

[0080] In an exemplary embodiment, multiple bidirectional gated memory unit models are activated simultaneously, such as the formula:

[0081]

[0082] in, Represents the predicted normal value of the bidirectional gated memory unit corresponding to the i-th region, BiGRU i represents the bidirectional gated memory unit corresponding to the i-th region, represents the input vector of the bidirectional gated memory unit corresponding to the ith region, and N represents the number of regions of the object system;

[0083] As an exemplary embodiment, in step S5, first, the DL-LSTM attack detection module detects the load frequency deviation Δf of all regions i∈{1,2,…,N} i (t) and tie line power deviation ΔP tie-i (t) Conduct real-time monitoring; input real-time data x t =[Δf i (t),ΔP tie-i (t)] Input DL-LSTM to detect FDI attack; Mathematically, the detection mechanism can be expressed as: Label i =DL-LSTM(x t ), where Label i ∈{Normal,Attack-1,Attack-2,…,Attack-m} represents the identified operation state or specific attack type; for multi-point FDI attacks, where multiple regions are attacked, DL-LSTM captures temporal and spatial dependencies by analyzing the joint dynamics of all regions; when an attack is detected (Label i =Normal), the system activates the BiGRU defense module to mitigate the impact of the attack; the BiGRU model uses real-time measurements and historical data to predict the true state of the system; let x t =[Δf i (t),ΔP tie-i (t)] represents the predicted normal working value; the prediction correction is performed according to formula (19); the corrected value replaces the attacked value; in the case of multiple attacks targeting different regions at the same time, the defense mechanism handles the attack of each region independently; the coordinated response ensures that the LFC system can mitigate the impact of multi-point FDI attacks and prevent cascading failures; this is achieved by activating multiple BiGRU models simultaneously (BiGRU for each region i i ) is implemented as follows:

[0084]

[0085] Correction data collection for all areas helps restore the system to normal operating conditions.

[0086] In some embodiments, the above-mentioned multi-point FDI attack detection and defense method for load frequency control can also be implemented in the following manner. In this embodiment, the multi-point FDI attack detection and defense method for load frequency control includes:

[0087] Step 1: Establish a multi-region interconnected LFC system including HVDC, renewable energy and system nonlinearity:

[0088] Figure 2 The block diagram of the N-area power system is presented. Each area is interconnected by parallel AC / DC tie lines; each area has a similar structural design, such as Figure 2 The framework of the LFC model in the i-th zone is shown; each control zone includes the LFC center, generators and loads, combined with RESs and nonlinear constraints;

[0089] Define Δf i , ΔP tie-i , ΔP tie-ij,ac , ΔP tie-ij,dc , ΔP mi , ΔP vi , ΔP di , ΔP ci and ΔP RESi They represent the frequency deviation in the power system, the net tie line power deviation of region i, the AC tie line power deviation between regions i and j, the DC tie line power deviation between regions i and j, the mechanical input deviation of the generator, the valve position deviation, the load change, the power regulation command of region i, and the change of the output power of renewable energy sources (RESs) in region i; then the LFC system dynamics model of region i can be expressed as:

[0090]

[0091] ACE i =β i Δf i +P tie-i (8) Where D i 、M i , R i , T gi , T ti are the generator damping coefficient, generator inertia moment, speed reduction coefficient, governor time constant and turbine time constant in power system zone i; T ij K is the synchronization coefficient of the tie line between regions ij; dc is the DC link gain, Tdc is the DC link time constant; ACE i Represents the automatic control error in region i, which is the frequency deviation Δf i and tie line power deviation ΔP tie-i A linear combination of i is the frequency offset factor, β i =1 / R i +D i ; K pi and K ii are the proportional gain and integral gain of the PI controller in region i;

[0092] Step 2: Modeling of FDI attacks in load frequency control systems:

[0093] The secondary control loop relies on the communication network to transmit the information sensed by the RTU (Δf i and ΔP tie-i ) is transmitted to the LFC center, and a control command ΔP is sent from the LFC center to the generator ci ; However, malicious attackers can infiltrate the network to carry out FDI attacks, change the transmitted signals, and threaten the stable operation of the LFC scheme; It is worth noting that in a multi-region LFC system, both the frequency and the AC / DC tie line power supply are vulnerable to attacks at the same time, resulting in multiple vulnerability points; Therefore, this embodiment considers the FDI attack on Δf i and ΔP tie-i The impact of the measurement channel, where the attack signal A i (t) may tamper with Δf i , ΔP tie-ijac or ΔP tie-ijdc The actual measured value of ΔP tie-ijac or ΔP tie-ijdc The attack on ΔP can be equivalently expressed as tie-i In a multi-region LFC system, multi-point FDI attacks are very likely because attackers can use the interconnected communication network to attack multiple measurement channels across regions at the same time; therefore, A = [A f,i ,A Pij,ac ,A Pij,dc ] represents the multi-point attack vector for different measurement channels; each element corresponds to a specific channel, such as frequency or AC / DC tie line power; the attack period τ i Defined as the time interval between attacks; design the following FDI attack model:

[0094] Step Attack: a i (t) = λ si ,t∈[τ i ,+∞), where λsi and τ i are the step parameter and attack duration, respectively;

[0095] Pulse attack: a i (t) = λ pi ,t∈τi, where λ pi is the pulse parameter;

[0096] Sine Attack: a i (t) = λ sin1i ·sin(λ sin2i ·t),t∈τ i , where λ sin1i is the amplitude, λ sin2i is the frequency;

[0097] To avoid triggering the bad data detection system in the power system, the attacker must carefully design the parameter λ si ,λr1,λ pi , sin 1i , sin 2i ,The multi-point attack detection and mitigation scheme of this embodiment is applicable to all types of stealth and non-stealth FDI attacks, so the attack model can be any unbounded, non-smooth, time-varying signal that satisfies the above attack model;

[0098] Step 3: Design of a two-layer LSTM neural network attack detector for load frequency control systems:

[0099] This embodiment achieves effective detection and accurate classification of FDI attacks on the power system by hierarchically integrating LSTM networks; the input of the model classifier includes the frequency deviation Δf from each region i i , and the total power deviation ΔP from the AC and DC tie lines tie-i ; The output is the label of the attack method; The output of the classifier corresponds to the attack mode label, marked as Label i , the system state is divided into normal state and attack mode; the DL-LSTM attack detection framework operates through a hierarchical classification mechanism; in the first stage, the classification model is used to classify the input feature X = [Δf i , ΔP tie-i ] to obtain the first layer of labels; in the second stage, based on the first layer of labels Label 1 , using different model classifer 2 , classifer 3 Perform condition classification as shown in (9)-(10);

[0100] Label_1=classifer_1(X) (9)

[0101]

[0102] Among them, LSTM classifier classifer i The model structure design is based on the time series input data X = [x 1, x 2 , …x N ], where N is the sequence length; the model starts with a sequence input layer, followed by three stacked LSTM layers with 256, 128, and 64 hidden units, respectively; the transformation of each LSTM layer is controlled by equations (11)-(16);

[0103] f t =σ(W f [h t-1 , x t ]+b f ) (11)

[0104] i t =σ(W i [h t-1 , x t ]+b i ) (12)

[0105]

[0106] o t =σ(W o [h t-1 , x t ]+b o ) (15)

[0107] h t =o t ⊙tanh(C t ) (16)

[0108] In order to alleviate overfitting and enhance the generalization of the model, each LSTM layer is followed by a dropout layer with a dropout rate of 0.5; the final temporal feature h of the last LSTM layer (3) T Calculated through a fully connected (dense) layer, as shown in formula (17);

[0109]

[0110] Where Wd and bd are the weight matrix and bias vector of the dense layer; the ReLU activation function is defined as ReLU(x)=max(0,x), which introduces nonlinearity to enhance feature representation;

[0111] Finally, the output layer uses the softmax function for multi-class classification, as shown in formula (18);

[0112]

[0113] Among them, K is the total number of categories, y i represents the predicted probability of the i-th class; the softmax output is used to assign the classification label according to the highest probability;

[0114] For both single-region and multi-region FDI attacks, the hierarchical LSTM structure of the DL-LSTM model effectively captures the density and attack patterns in the time series data, enabling the identification of specific affected measurements;

[0115] Step 4: Design of bidirectional gated memory unit attack defender for load frequency control system:

[0116] The core of the proposed defense mechanism is to use the BiGRU model to learn the normal measurement values ​​of the LFC system through the training dataset, and achieve accurate prediction and replacement when the attack occurs;

[0117] First, the defense mechanism operates by utilizing real-time measurement data from the LFC system, including the frequency deviation Δf i and power deviation ΔP tie-i As input; these measurements are represented as a time series vector x i =[Δf i ,ΔP tie,i ]; The defense framework uses the BiGRU model M BiGRU Learning mapping, as shown in formula (19);

[0118]

[0119] BiGRU is an enhanced RNN structure that can process sequence data in both forward and backward directions. In the BiGRU architecture, the hidden state of each time step is processed by forward and backward GRU units. Each GRU unit includes a reset and update gate, and its calculation process is shown in equations (20)-(23).

[0120] r t =σ(W r x t +U r h t-1 ) (20)

[0121] z t =σ(W z x t +U z h t-1 ) (twenty one)

[0122]

[0123] where x t Represents the input of the current time step; R t and z t stands for reset gate and update gate, which control the selective forgetting and retention of information; H~t is the candidate hidden state, which combines the information from the current input and the previous state; this is the final hidden state, which integrates the forward and backward hidden states to form comprehensive contextual information; its bidirectional structure further enhances the model's ability to capture complex dependency patterns in the input sequence and its ability to handle high-variability and high-noise data typical in power systems;

[0124] In the training phase, a large amount of historical data is provided to the BiGRU model to distinguish between normal operation and abnormal state caused by FDI attacks; the training goal is to minimize the prediction error, as shown in formula (24);

[0125]

[0126] Where θ is the parameter of MBiGRU, T is the total number of training samples;

[0127] Once an FDI attack is detected, the system will immediately activate the defense mechanism; Replace with predicted normal value The stability of the system is guaranteed, as shown in formula (25);

[0128] if an FDI attack is detected. (25)

[0129] This real-time replacement can minimize the adverse effects of an attack, keep the power system in normal operating condition, and ensure resilience to potential disruptions;

[0130] Step 5: Design of overall strategy for multi-point FDI attack detection and defense for load frequency control systems:

[0131] The multi-point FDI attack detection and defense strategy is divided into two stages: detection and defense. The DL-LSTM and BiGRU models are used to protect the LFC system from FDI attack threats; Figure 3 The step-by-step process of detection and defense in the LFC system is shown; first, the DL-LSTM attack detection module detects the load frequency deviation Δf of all regions i∈{1,2,…,N} i (t) and tie line power deviation ΔP tie-i (t) Conduct real-time monitoring; input real-time data x t =[Δf i(t),ΔP tie-i (t)] Input DL-LSTM to detect FDI attack; Mathematically, the detection mechanism can be expressed as: Label i =DL-LSTM(x t ), where Label i ∈{Normal,Attack-1,Attack-2,…,Attack-m} represents the identified operation state or specific attack type; for multi-point FDI attacks, where multiple regions are attacked, DL-LSTM captures temporal and spatial dependencies by analyzing the joint dynamics of all regions; when an attack is detected (Label i =Normal), the system activates the BiGRU defense module to mitigate the impact of the attack; the BiGRU model uses real-time measurements and historical data to predict the true state of the system; let x t =[Δf i (t),ΔP tie-i (t)] represents the predicted normal working value; the prediction correction is performed according to formula (19); the corrected value replaces the attacked value; in the case of multiple attacks targeting different regions at the same time, the defense mechanism handles the attack of each region independently; the coordinated response ensures that the LFC system can mitigate the impact of multi-point FDI attacks and prevent cascading failures; this is achieved by activating multiple BiGRU models simultaneously (BiGRU for each region i i ) is realized as formula (26);

[0132]

[0133] Correction data collection for all areas helps restore the system to normal operating conditions.

[0134] In an exemplary embodiment, for a multi-region load frequency control system including high-voltage AC / DC interconnection lines, participation of renewable energy, and consideration of system nonlinearity, this embodiment tests the operating effect of the proposed combined timing analysis neural network model detection and defense strategy when the power grid is subjected to various types of FDI attacks; at the same time, the detection and defense effects of different types of FDI attacks when single-point attacks occur and when multiple-point attacks occur are tested, and the frequency stability of the load frequency control system obtained by applying the strategy and not applying the strategy is compared. The specific test scheme is as follows:

[0135] (1) Model training and verification:

[0136] To train and evaluate the LSTM and BiGRU neural network models, this example constructs multiple attack scenarios (step, pulse, and sine) as well as normal operation cases and uses them as input data; each case consists of a vector with multiple time steps containing the measured features: Δf1 (t),Δf 2 (t),Δf 3 (t),ΔP tie-1 (t),ΔP tie-2 (t),ΔP tie-3 (t); During the training process, the effects of RES and load disturbances are considered; The dataset includes single-point and multi-point FDI attacks; The data is divided into 70% for training and validation, and 30% for testing; In order to evaluate the performance of the trained DL-LSTM attack detector and BiGRU predictor, the test set is used in this embodiment; Table 1 compares the proposed classification model with other machine learning models in terms of accuracy, precision, recall, and F1 score; Among these models, the DL-LSTM classification model scored the highest in all four indicators, with an accuracy of 0.972 and an F1 score of 0.911;

[0137] In addition, the frequency deviation of region 1 and the tie line power of region 2 were used as examples to test the prediction accuracy of BiGRU during LFC operation, e.g. Figure 4 As shown in the figure, the results show that the BiGRU model has high accuracy in estimating the measured values ​​of the LFC system, proving its effectiveness in making high-precision predictions.

[0138] Table 1 Detection performance of DL-LSTM on FDI attacks

[0139]

[0140]

[0141] (2) Detection and defense effect analysis:

[0142] In order to verify the effectiveness of the proposed method, this embodiment designs three different FDI attack scenarios, including three types of attacks, to evaluate the performance of the proposed detection and defense methods:

[0143] Case A: At t = 10s, the frequency deviation Δf is measured for region 1 1 Apply a step attack of 0.8 Hz;

[0144] Case B: Frequency deviation measurement Δf for region 1 at t = 20 seconds 1 A sine attack is applied, while a pulse attack with a maximum amplitude of 0.2 pu is applied to the HVAC link power measurement. The P tie-1 be affected;

[0145] Case C: Frequency deviation measurement Δf for region 1 at t = 30 seconds 1 and Δf in region 33 A step attack is applied, while a pulse attack with a total amplitude of 0.7 pu is applied to the tie-line power measurements of the HVAC and HVDC links. tie-2 be affected;

[0146] Under different attack scenarios, the system frequency deviation or tie line power stability before and after the attack is eliminated is compared, such as Figure 5 The figure shows the comparison of the frequency deviation stability of region 1 before and after the attack is eliminated in case of CASE A; Figure 6 The figure shows the comparison of the frequency deviation stability of region 2 before and after the attack elimination in case of CASE B; Figure 7 Shown is a schematic diagram comparing the power stability of the area 3 tie line before and after the attack is eliminated in case C; compared with the LFC system lacking attack detection and mitigation, the proposed framework significantly reduces the frequency deviation, highlighting its effectiveness in mitigating the adverse effects of FDI attacks and enhancing system stability.

[0147] In summary, the present invention is effective and has better detection and defense performance, and is suitable for complex multi-point FDI attacks.

[0148] This embodiment provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the above-mentioned multi-point FDI attack detection and defense method for load frequency control.

[0149] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the enlightenment of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which all fall within the protection of the present invention.

Claims

1. A multi-point FDI attack detection and defense method for load frequency control, characterized in that: The following steps are involved: S1: Construct the LFC system dynamics model according to the research object system; S2: Construct FDI attack model based on the characteristics of multi-point false data injection attack; S3: Based on the LFC system dynamics model and the FDI attack model, an attack detector is constructed using a double-layer long short-term memory neural network; S4: constructing an attack defender using a bidirectional gated memory unit according to the LFC system dynamics model and the FDI attack model; S5: Utilize the attack detector and the attack defender to detect and defend the research object system.

2. The multi-point FDI attack detection and defense method for load frequency control according to claim 1 is characterized in that: Step S1 specifically includes: constructing a LFC system dynamics model according to the object system, such as formula: ACE i =β i Δf i +P tie-i , Where Δf i , ΔP tie-i , ΔP tie-ij,ac , ΔP tie-ij,dc , ΔP mi , ΔP vi , ΔP di , ΔP ci and ΔP RESi They represent the frequency deviation in the power system, the net tie line power deviation of region i, the AC tie line power deviation between regions i and j, the DC tie line power deviation between regions i and j, the mechanical input deviation of the generator, the valve position deviation, the load change, the power regulation command of region i, and the change of the renewable energy output power of region i; D i 、M i , R i , T gi , T ti are the generator damping coefficient, generator inertia moment, speed reduction coefficient, governor time constant and turbine time constant in power system zone i; T ij K is the synchronization coefficient of the tie line between regions ij; dci is the DC link gain, T dci is the DC link time constant; ACE i Represents the automatic control error in region i, which is the frequency deviation Δf i and tie line power deviation ΔP tie-i A linear combination of i =1 / R i +D i is the frequency offset factor, K pi and K ii is the proportional gain and integral gain of the PI controller in region i; N i is the set of regions adjacent to region i, and s is a complex frequency domain variable.

3. The multi-point FDI attack detection and defense method for load frequency control according to claim 1 is characterized in that: Step S2 specifically includes: constructing an FDI attack model according to the characteristics of multi-point false data injection attacks, such as formula: a i1 (t)=λ si ,t∈[τ i ,+∞), a i2 (t)=λ pi ,t∈τ i , a i3 (t)=λ sin1i ·sin(λ sin2i ·t),t∈τ i , A=[A f,i ,A Pij,ac ,A Pij,dc ], Among them, ai1(t) is a step attack, λ si and τ i are step parameter and attack duration respectively; a i2 (t) is the pulse attack, λ pi is the pulse parameter; a i3 (t) is a sinusoidal attack, λ sin1i is the amplitude, λ sin2i is the frequency; A represents the multi-point attack vector for different measurement channels, A f,i Represents the element corresponding to the frequency channel, A Pij,ac Represents the element corresponding to the AC tie line power supply, A Pij,dc Represents the element corresponding to the DC tie line power supply.

4. The multi-point FDI attack detection and defense method for load frequency control according to claim 1 is characterized in that: The attack detector includes a first classifier, a second classifier and a third classifier, the first classifier includes a sequence input layer, a stacked LSTM layer and an output layer; the second classifier and the third classifier have the same structure as the first classifier; the stacked LSTM layer includes a first LSTM layer, a second LSTM layer and a third LSTM layer stacked in sequence, the first LSTM layer, the second LSTM layer and the third LSTM layer are each followed by a dropout layer, and the first LSTM layer, the second LSTM layer and the third LSTM layer have 256, 128 and 64 hidden units respectively; using the LFC system dynamics model and the FDI attack model, a variety of attack scenarios and normal operation cases are constructed to obtain a training data set; The attack detector is obtained by training the training data set.

5. The multi-point FDI attack detection and defense method for load frequency control according to claim 4 is characterized in that: The first classifier is used to obtain a first layer of labels according to the input features; the second classifier and the third classifier are used to perform conditional classification according to the first layer of labels to obtain second layer of labels, such as formula: Label1 = classifer1(X), Among them, Label1 is the first-layer label, classifer1 represents the first classifier, X represents the input feature, Label2 is the second-layer label, classifer2 represents the second classifier, classifer3 represents the third classifier, normal represents normal, single represents single-point attack, and multi represents multi-point attack.

6. The multi-point FDI attack detection and defense method for load frequency control according to claim 4 is characterized in that: The attack detector also includes a fully connected dense layer, as shown in the formula: Among them, z is the output of the fully connected dense layer, ReLU is the activation function, and W d and b d is the weight matrix and bias vector of the fully connected dense layer, h (3) T is the final time feature of the third LSTM layer.

7. The multi-point FDI attack detection and defense method for load frequency control according to claim 1 is characterized in that: Step S4 specifically includes: according to the LFC system dynamics model and the FDI attack model, using real-time measurement data to train the bidirectional gated memory unit to obtain a trained bidirectional gated memory unit, and obtaining an attack defender according to the trained bidirectional gated memory unit.

8. The multi-point FDI attack detection and defense method for load frequency control according to claim 1 is characterized in that: Step S5 specifically includes: S51: Use the attack detector to detect the LFC data to obtain the operation status and attack type. S52: When the operating status and attack type are normal, it indicates that the system is operating normally and the system detection is continuously performed; when the operating status and attack type are single-point attacks, the attack defender is used to replace the damaged measurement with the predicted normal value to ensure system stability; when the operating status and attack type are multi-point attacks, the attack defender is used to simultaneously activate multiple bidirectional gated memory unit models to obtain predicted normal values, and the damaged measurement is replaced with the predicted normal value to ensure system stability.

9. The multi-point FDI attack detection and defense method for load frequency control according to claim 8 is characterized in that: The model of activating multiple bidirectional gated memory units at the same time is as follows: in, Represents the predicted normal value of the bidirectional gated memory unit corresponding to the i-th region, BiGRU i represents the bidirectional gated memory unit corresponding to the i-th region, represents the input vector of the bidirectional gated memory unit corresponding to the i-th region, and N represents the number of regions of the object system.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the multi-point FDI attack detection and defense method for load frequency control described in any one of claims 1-9 are implemented.