FDI attack detection method for wind power plant power prediction

By applying the xLSTM-AE-based FDI attack detection method in the wind farm power prediction system, the problem of difficult to identify FDI attack behavior in the wind farm in the prior art is solved, effective identification and defense of complex attacks is achieved, and the security and reliability of the system are improved.

CN120045892AActive Publication Date: 2025-05-27QINGDAO UNIV OF TECH +1

Patent Information

Application Number
CN202411933124.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-27
Estimated Expiration
2044-12-25

AI Technical Summary

Technical Problem

Existing FDI attack detection methods are difficult to fully capture and identify attack behaviors in wind farm power prediction, especially in complex wind farm environments, and lack the ability to identify unknown new attacks.

Method used

Using the FDI attack detection method based on xLSTM-AE, the wind farm power data is preprocessed, and outliers are identified using sliding window technology and 3-σ principle. The xLSTM-AE model is constructed to capture the spatial and temporal correlation, and the abnormal patterns in the data are identified through the autoencoder structure.

Benefits of technology

Effectively identify and defend against complex FDI attacks, improve the safety and reliability of wind farm power prediction, and enhance the adaptability and generalization capabilities to unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045892A_ABST
    Figure CN120045892A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of FDI attack detection, and particularly relates to an FDI attack detection method for wind power plant power prediction. The method comprises the following steps: firstly, preprocessing acquired wind power plant power data by using a # imgabs0 # principle and a sliding window technology, and cutting the wind power plant power data into a training set, a verification set and a test set which are suitable for xLSTM-AE model processing; thirdly, constructing an xLSTM-AE model, training the model by using the training set data, and meanwhile, finely adjusting model parameters by using a check set so as to avoid an over-fitting phenomenon; and after model training is completed, a specific threshold value is calculated for each wind turbine generator set according to the # imgabs1 # principle. And finally, performing FDI attack detection on the test set data by using an FDI attack detector, and identifying and marking the test set data of which the square residual errors exceed respective threshold values as FDI attack data. The safety and reliability of the wind power plant power prediction system can be enhanced, and the economic benefit of the wind power plant and the stability of the power grid are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of FDI attack detection, and particularly relates to an FDI attack detection method for wind farm power prediction. Background Art

[0002] With the increase in greenhouse gas emissions, gradually building a new power system and promoting the transformation of the energy structure have become important issues in the energy and power industry. Therefore, the installed capacity of renewable energy has continuously achieved new breakthroughs. As of the end of June 2024, the installed capacity of renewable energy power generation in the country reached 1.653 billion kilowatts, accounting for approximately 53.8% of the total installed power generation capacity in China. Among them, the cumulative grid-connected capacity of wind power reached 467 million kilowatts, including 429 million kilowatts of onshore wind power and 38.17 million kilowatts of offshore wind power. This progress provides important experience for the global energy transformation, helps China achieve the goals of "carbon peak and carbon neutrality", and moves towards a green and low-carbon future.

[0003] The accuracy of wind power prediction is crucial for ensuring the stable operation of a new power system and optimizing the scheduling of renewable energy. According to the differences in prediction targets, prediction models can be divided into two major categories: single-machine and whole-field output power prediction. For a single wind turbine, methods such as the Heteroscedastic Spline Regression Model (HSRM), Robust Spline Regression Model (RSRM), Back Propagation Neural Networks (BPNN), Deep Belief Network (DBN), and Long Short-Term Memory networks (LSTM) can predict its future power output by analyzing the output data of the wind turbine. For wind farm-level prediction, the prediction of the whole-field power or the output power of multiple turbines is achieved by analyzing the spatio-temporal dependence relationships among the historical output data of multiple wind turbines. Currently, a variety of deep neural network structures, including the Deep Convolutional Network (DCN), Long Short-Term Memory (LSTM), Sparse Autoencoder (SAE), Mixture Density Network (MDN), and Graph Convolutional Long Short-Term Memory (GC-LSTM), have been used to extract the complex spatio-temporal correlation features within the wind farm and have been successfully applied to the problem of whole-field power prediction.

[0004] These power prediction models are mainly deployed in the central control room or dispatching center of the wind farm for centralized management and optimization of the wind farm operation. Wind turbines within the wind farm collect data through sensors and transmit the data to the central control room or cloud server via the Supervisory Control and Data Acquisition (SCADA) system to achieve real-time data monitoring and communication. This deployment and communication mechanism enables operation and maintenance personnel to accurately predict power output, optimize the dispatching and operation of the power grid. However, it also increases the risk of the system being attacked by cyberattacks, especially False Data Injection (FDI) attacks. According to a report by General Electric (GE), 96% of wind farms have at least one machine with an operating system vulnerable to cyberattacks. FDI attackers reduce the prediction accuracy of the wind power prediction system by injecting false data into the SCADA system. The power grid dispatching center usually requires wind farms to submit in advance the predicted wind power output for future time for power grid dispatching. Therefore, inaccurate power generation prediction will not only affect the stable operation of the power grid but also lead to economic penalties for wind farms. In this context, ensuring the cybersecurity of the wind power generation system and accurately detecting and defending against FDI attacks have become an urgent problem to be solved.

[0005] In the existing literature, FDI attack detection methods are mainly divided into two categories: one is the model-based algorithms, which detect FDI attacks by analyzing the differences between state estimation values and measurement values. However, such methods require accurate system parameters and mathematical models and have poor scalability; the other type of methods is data-based algorithms. They do not rely on system models or parameters but learn the characteristic patterns of FDI attacks or normal behavior patterns existing in the historical data of the system under attack or operating normally by using machine learning algorithms such as Reinforcement Learning (RL), Convolutional Neural Network (CNN), and K-Means Clustering Algorithm (K-Means), and then use the trained detection model to achieve online detection of attacks. Due to the development of artificial intelligence and big data analysis technologies, such algorithms have received increasing attention.

[0006] Although certain research results have been achieved in these methods in other fields, in the specific field of wind farm power prediction, relatively few studies on FDI attack detection have been conducted in the existing literature. Currently, the existing FDI attack detection methods mainly focus on the time series characteristics of the output power of a single wind turbine, while ignoring the spatial correlation of the output power among the wind turbines in the wind farm. This limitation leads to the inability of these methods to comprehensively capture and identify attack behaviors, especially in complex wind farm environments. To improve the accuracy of FDI attack detection, the detection method needs to comprehensively consider the time and spatial correlations among the wind turbines in the wind farm. In addition, most of the existing supervised learning attack detection methods rely on labeled datasets of specific attack types, which limits their ability to identify unknown new attacks.

[0007] To address these issues, the present invention proposes an FDI attack detection method based on xLSTM-AE (Extended Long Short-Term Memory Autoencoders). This method can meet the requirements of the wind farm power prediction system for FDI attack detection, effectively capture the time series characteristics of the output power of wind turbines, deeply analyze the spatial dependence among different wind turbines in the wind farm, and enhance its adaptability and generalization ability when facing unknown attacks. Therefore, the attack detection method proposed in this application is of great significance in improving the security and reliability of wind farm power prediction, providing a powerful security guarantee tool for wind power prediction. First, the 3-σ principle and the sliding window technique are used to preprocess the obtained wind farm power data, and cut it into a training set, a validation set, and a test set suitable for processing by the xLSTM-AE model. Then, an xLSTM-AE model is constructed and trained using the above training set data, and the validation set is used to fine-tune the model parameters to avoid overfitting. After the model training is completed, specific thresholds are calculated for each wind turbine according to the 3-σ principle. Finally, the FDI attack detector is used to detect FDI attacks on the test set data, and the test set data with squared residuals exceeding their respective thresholds are identified and marked as FDI attack data. Summary of the Invention

[0008] The present invention develops an FDI attack detection method for wind farm power prediction, which is a method based on xLSTM-AE and can capture the spatio-temporal correlation among the wind turbines in the wind farm and effectively identify FDI attacks. Specifically targeting the wind farm power prediction scenario, it is of great significance for improving the accuracy of wind power prediction and the stability of the power grid.

[0009] The method includes the following steps:

[0010] (1) Obtain wind farm power data to get the original dataset;

[0011] (2) Preprocess the wind power data;

[0012] ① To test the FDI attack detection model, randomly select the data of two days in the original dataset as the test set X s , and the remaining data is split into the training set X and the validation set X according to the ratio of 8:2 v ;

[0013] ② Simulate the FDI attacks suffered by the wind farm, and process the output power data of a certain wind turbine in the test set X s , and simulate different types of FDI attacks, including basic FDI attacks, stealth FDI attacks, and replay attacks;

[0014] ③ Use the 3-σ principle to identify the outliers in the training set X, the validation set X v and the test set after the attack . For the processing of outliers, choose the linear interpolation method instead of simply discarding them to maintain the integrity of the time series data;

[0015] ④ Using the sliding window technique, for the training set X, the validation set X v and the test set after steps ①②③, divide the data to ensure that the sample size M is determined according to the following formula:

[0016]

[0017] where, n represents the total amount of data in the dataset; ω represents the size of the sliding window; s represents the moving step; represents the floor operation to ensure that the obtained sample size is an integer; in addition, the sliding window technique of the present invention is an existing technology, which creates training samples by sliding a window of a fixed size on the dataset to capture the temporal characteristics and local patterns in the data;

[0018] (3) Training and validation of xLSTM-AE;

[0019] The Extended Long Short-Term Memory (xLSTM) is an enhanced version of the traditional LSTM. It improves performance by introducing exponential gating and new memory structures, including sLSTM with scalar storage, update, and new memory mixing mechanisms, and mLSTM with matrix memory and covariance update rules, supporting fully parallel processing. These improved LSTM variants are integrated into residual blocks to form xLSTM blocks, and a complete xLSTM architecture is constructed through residual stacking. These innovations enable xLSTM to perform well in processing large-scale datasets, especially in capturing the temporal dependencies between samples in time series, significantly enhancing the model's performance.

[0020] Autoencoders (AE) are unsupervised learning neural networks that learn the compressed representation of data through the backpropagation algorithm and attempt to reconstruct the original input data from these low-dimensional representations. The model consists of an input layer, one or more hidden layers, and an output layer. The part from the input to the hidden layer is the encoder, and the part from the hidden layer to the output is the decoder. Autoencoders aim to minimize the difference between the input and the reconstructed data to capture the intrinsic structure and features of the data.

[0021] The xLSTM-AE model is a deep learning architecture that combines xLSTM units and an autoencoder structure. The encoder of this model consists of two layers of xLSTM, which are responsible for encoding the input time series data into a fixed-size latent space vector. This vector is stored in the middle layer of the model, also known as the "data bridge". The first xLSTM layer of the encoder has the same number of units as the number of input features, achieving a direct mapping from features to xLSTM units. The number of units in the second xLSTM layer is half of that of the first layer, which helps to further compress the data and extract higher-level abstract features. The decoder is symmetric to the encoder structure and also contains two layers of xLSTM. Its goal is to reconstruct the original input sequence from the latent space vector. This design enables the model to effectively capture the spatio-temporal coupling characteristics in time series data, making it particularly suitable for analyzing complex data sequences such as the output power of a wind farm.

[0022] In the multivariate time series training set of the wind farm output power given in the present invention where m represents the input feature dimension, that is, the number of wind turbines in the whole field;

[0023] The xLSTM-AE model can be expressed as:

[0024]

[0025] where Encode and decode respectively represent the encoding and decoding processes; H represents the compression space of latent features; respectively represent the non-linear mapping functions in the encoding and decoding processes of the model; respectively represent the sets of matrices of the training weights (W) and biases (b) in the encoding and decoding processes of the model; X represents the training data composed of wind farm output power data; represents the reconstructed wind farm output power data; in normal operations, take

[0026] By minimizing the residuals between the training data composed of wind farm output power data and the reconstructed wind farm output power data, the optimal parameter set of the model can be obtained as follows:

[0027]

[0028] The reconstruction error of the xLSTM-AE model is:

[0029]

[0030] where, represents the wind power data of the i-th wind turbine at time t among m wind turbines; respectively represent the non-linear mapping functions in the encoding and decoding processes of the model; ||·|| 2 represents the L2 norm, that is, the Euclidean distance; and represent the optimal parameter set of the model;

[0031] The xLSTM-AE model learns the spatio-temporal features in the time series data of wind farm output power by optimizing the parameters to minimize the reconstruction error. After training, the model can reconstruct the input wind farm power data with the minimum reconstruction error. To avoid overfitting and adjust the hyperparameters of the model, the present invention evaluates the model performance on the validation set X v to fine-tune the model parameters. If the model performs well on the training set but the performance drops on the validation set, this usually means that the model may be too complex or over-trained, and at this time, the model structure or training strategy needs to be adjusted accordingly. Through this monitoring and adjustment, it is ensured that the model can not only effectively capture the key features of the data during the training process but also maintain good generalization ability. Specifically, the model training includes setting 800 training epochs, a learning rate of 0.01, and the number of units in the second LSTM layer of the encoder is half of that of the first layer. The selection of these parameters is based on the performance feedback on the validation set to optimize the model performance.

[0032] (4) Identify the attacked data;

[0033] The FDI attack detector is constructed as follows:

[0034]

[0035] where represents the detection output of the i-th wind turbine among m wind turbines at time t. 1 indicates that an FDI attack is detected, and 0 indicates that no FDI attack is detected; τ i represents a specific threshold calculated for each wind turbine based on the squared residuals of the training set X without attacks; represents the squared residual of the wind power data of the i-th wind turbine among m wind turbines at time t. The calculation formula for the squared residual is:

[0036]

[0037] where represents the wind power data of the i-th wind turbine among m wind turbines at time t; respectively represent the encoding and decoding non-linear functions of the xLSTM-AE model; and represents the optimal parameter set of the xLSTM-AE model.

[0038] After training the xLSTM-AE model using the training set X without attacks, the xLSTM-AE detection algorithm is used to detect FDI attacks on the test set X s A The test set data of all wind turbines whose squared residuals are greater than their respective set thresholds are identified and marked as FDI attack data. The method for calculating the specific threshold for each wind turbine follows the 3-σ principle, that is, 68% of the data is distributed within one standard deviation of the mean, 95% within two standard deviations, and 99.7% within three standard deviations. Therefore, in this study, the data points where the squared residuals of each wind turbine in the test set exceed the mean of the squared residuals of the corresponding wind turbine in the training set plus 2.5 standard deviations are regarded as data affected by FDI attacks.

[0039] Furthermore, in item ② of step (2), the following operations are performed on the output power data of the 14th wind turbine in the test set X s Add a basic FDI attack with an attack multiplier of 1.25 and an attack adder of 0.35 MW at the 30th to 50th data points;

[0040] Apply a stealth FDI attack at the 100th to 130th data points;

[0041]

[0042] ​Add a base FDI attack with an attack multiplier of 1.25 and an attack adder of -0.45 MW to the 180th to 200th data points;

[0043] Apply a replay attack to the 250th to 270th data points (using the 200th to 220th data points to replace the current values).

[0044] Furthermore, in step (2)②, the base FDI attack is achieved by changing a single measurement value, and this attack is described by the following formula:

[0045]

[0046] Where, refers to the i-th measurement value under attack; X i refers to the actual measurement value, A i is an arbitrary attack adder; a i is an arbitrary attack multiplier, and this multiplier results in over-scaling (a i > 1), under-scaling (0 < a i < 1) or negative scaling (a i < 0).

[0047] Furthermore, in step (2)②, the attack vector of the stealth FDI attack includes an adder and a multiplier that vary with time. This dynamic method enables the attacker to gradually tamper with the data in an imperceptible manner. The stealth FDI attack is described by the following formula:

[0048]

[0049] Where, refers to the i-th measurement value under attack; X i refers to the actual measurement value; A i (t) is the attack adder that varies with time; a i (t) is the attack multiplier that varies with time.

[0050] Furthermore, in step (2)②, in the replay attack, the attacker's use of previously intercepted data to replace the current measurement value is regarded as:

[0051]

[0052] Where, is the data after being attacked, is a record of the system measurement value at an earlier time.

[0053] The test set X after the FDI attack s is represented by .

[0054] Further, in step (3)③, the 3-σ principle is based on the normal distribution in statistics, that is, 68% of the data is within one standard deviation of the mean, 95% is within two standard deviations, and 99.7% is within three standard deviations; the specific formula is as follows:

[0055] P(μ - σ ≤ X ≤ μ + σ) ≈ 0.68

[0056] P(μ - 2σ ≤ X ≤ μ + 2σ) ≈ 0.95

[0057] P(μ - 3σ ≤ X ≤ μ + 3σ) ≈ 0.997

[0058] where X is a random variable, μ represents the mean of the sequence. Suppose there is a sequence {x 1 , x 2 ,..., x n}, and its expression is:

[0059]

[0060] σ represents the standard deviation of the sequence, and its calculation formula is:

[0061]

[0062] Compared with the prior art, the advantages of the present invention are as follows:

[0063] 1. The present invention proposes an FDI attack detection method for wind farm power prediction. This method uses the xLSTM-AE technology to effectively integrate the spatio-temporal correlation of the wind farm output power data, which is crucial for identifying and defending against complex FDI attacks.

[0064] 2. The xLSTM-AE model of the present invention is completely data-driven and adopts an unsupervised learning mechanism, which can intelligently identify abnormal patterns in the data. This feature gives the present invention a significant advantage in detecting unknown or new attacks, eliminating the cumbersome data annotation and model training processes for each potential attack, and greatly saving time and resources.

[0065] 3. The present invention has the ability to be applied in real time and can be deployed in the wind farm power prediction system to detect and prevent FDI attacks, thus ensuring the safe and stable operation of the wind farm. This real-time protection mechanism is of great significance for maintaining the reliability of the new power system and resisting external threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] The present invention will be further described below with reference to the accompanying drawings.

[0067] Figure 1 It is a schematic diagram of the sliding window technology;

[0068] Figure 2 It is the structure diagram of xLSTM;

[0069] Figure 3 It is the structure diagram of AE with one hidden layer;

[0070] Figure 4 It is the FDI attack detection algorithm based on xLSTM-AE;

[0071] Figure 5 It is the detection effect diagram of xLSTM-AE;

[0072] Figure 6 It is the schematic diagram of the square residual between the FDI attack value and the output value of xLSTM-AE;

[0073] Figure 7 It is the flow chart of the FDI attack detection method for wind farm power prediction. Specific implementation manner

[0074] The present invention will be further described below with reference to the accompanying drawings.

[0075] Embodiment 1

[0076] A FDI attack detection method for wind farm power prediction includes the following steps:

[0077] (1) Obtain the wind farm power data to get the original data set;

[0078] (2) Preprocess the wind power data;

[0079] ① For testing the FDI attack detection model, randomly select the data of two days in the original data set as the test set X s , and the remaining data is split into the training set X and the verification set X according to the ratio of 8:2 v ;

[0080] ② Simulate the FDI attack suffered by the wind farm, randomly select the output power data of one wind turbine in the test set X s , and process it to simulate different types of FDI attacks, including basic FDI attack, stealth FDI attack and replay attack. Among them, the basic FDI attack, stealth FDI attack and replay attack in the test set satisfy the intelligence of the FDI attack, and the 3-σ principle cannot identify them;

[0081] The basic FDI attack is achieved by changing a single measurement value, and this attack is described by the following formula:

[0082]

[0083] Wherein, Refers to the i-th measured value under attack; X i Refers to the actual measured value, A i Is an arbitrary attack additive; a i Is an arbitrary attack multiplier that causes over-scaling (a i > 1), under-scaling (0 < a i < 1) or negative scaling (a i < 0).

[0084] The attack vector of the stealthy FDI attack includes time-varying additives and multipliers. This dynamic approach enables the attacker to gradually tamper with the data in an imperceptible manner. The stealthy FDI attack is described by the following equation:

[0085]

[0086] Where, Refers to the i-th measured value under attack; X i Refers to the actual measured value; A i (t) is the time-varying attack additive; a i (t) is the time-varying attack multiplier.

[0087] In a replay attack, the attacker uses previously intercepted data to replace the current measured value, which is regarded as:

[0088]

[0089] Where, Is the data after being attacked, Is a record of the system's measured values at an earlier time.

[0090] The test set X after the FDI attack s Is denoted by X s A For presentation.

[0091] ③Adopt the 3-σ principle to identify the outliers in the training set X, the verification set X v And the test set after the attack For the handling of outliers, the linear interpolation method is selected instead of simply discarding them to maintain the integrity of the time series data;

[0092] The 3-σ principle is based on the normal distribution in statistics, that is, 68% of the data is within one standard deviation of the mean, 95% is within two standard deviations, and 99.7% is within three standard deviations; the specific formula is as follows:

[0093] P(μ - σ ≤ X ≤ μ + σ) ≈ 0.68

[0094] P(μ - 2σ ≤ X ≤ μ + 2σ) ≈ 0.95

[0095] P(μ - 3σ ≤ X ≤ μ + 3σ) ≈ 0.997

[0096] where X is a random variable, μ represents the mean of the sequence. Suppose there is a sequence {x 1 , x 2 ,..., x n} and its expression is:

[0097]

[0098] σ represents the standard deviation of the sequence, and its calculation formula is:

[0099]

[0100] ④ Using the sliding window technique, partition the training set X, validation set X v and the test set data after steps ①②③ to ensure that the sample size M is determined according to the following formula:

[0101]

[0102] where n represents the total amount of data in the dataset; ω represents the size of the sliding window; s represents the moving step size; denotes the floor operation to ensure that the obtained sample size is an integer;

[0103] (3) Training and validation of xLSTM - AE;

[0104] The xLSTM - AE model is a deep learning architecture that combines xLSTM units and an auto - encoder structure. The encoder of this model consists of two layers of xLSTM, which is responsible for encoding the input time - series data into a latent space vector of a fixed size. This vector is stored in the middle layer of the model, also known as the "data bridge". The first xLSTM layer of the encoder has the number of units matching the number of input features, realizing a direct mapping from features to xLSTM units; the number of units in the second xLSTM layer is half of the first layer, which helps to further compress the data and extract higher - level abstract features. The decoder is symmetric to the encoder structure and also contains two layers of xLSTM. Its goal is to reconstruct the original input sequence from the latent space vector. This design enables the model to effectively capture the spatio - temporal coupling characteristics in time - series data, especially suitable for analyzing complex data sequences such as wind farm output power.

[0105] In the multivariate time - series training set of wind farm output power given in the present invention m represents the input feature dimension, that is, the number of wind turbines in the whole field;

[0106] The xLSTM-AE model can be expressed as:

[0107]

[0108] Among them, and ψ respectively represent the encoding and decoding processes; H represents the compressed space of latent features; respectively represent the non-linear mapping functions in the encoding and decoding processes of the model; respectively represent the sets of matrices of the training weights (W) and biases (b) in the encoding and decoding processes of the model; X represents the training data composed of wind farm output power data; represents the reconstructed wind farm output power data; in conventional operations, generally take

[0109] By minimizing the residual between the training data composed of wind farm output power data and the reconstructed wind farm output power data, the optimal parameter set of the model can be obtained as follows:

[0110]

[0111] The reconstruction error of the xLSTM-AE model is:

[0112]

[0113] Among them, x i t represents the wind power data of the i-th wind turbine at time t among m wind turbines; respectively represent the non-linear mapping functions in the encoding and decoding processes of the model; ||·|| 2 represents the L2 norm, that is, the Euclidean distance; and represent the optimal parameter set of the model;

[0114] The xLSTM-AE model learns the spatio-temporal features in the time series data of the wind farm output power by optimizing the parameters to minimize the reconstruction error. After training, the model can reconstruct the input wind farm power data with the minimum reconstruction error. To avoid overfitting and adjust the hyperparameters of the model, the present invention uses the validation set X vThe performance of the model is evaluated to fine-tune the model parameters. If the model performs well on the training set but its performance degrades on the validation set, this usually means that the model may be too complex or over-trained. In this case, corresponding adjustments need to be made to the model structure or training strategy. Through this kind of monitoring and adjustment, it is ensured that the model can not only effectively capture the key features of the data during the training process but also maintain good generalization ability. Specifically, the model training includes setting 800 training epochs, a learning rate of 0.01, and the number of units in the second LSTM layer of the encoder being half that of the first layer. The selection of these parameters is based on the performance feedback on the validation set to optimize the model performance.

[0115] (4) Identify the attacked data;

[0116] The FDI attack detector is constructed as:

[0117]

[0118] Among them, represents the detection output of the i-th wind turbine at time t among m wind turbines. 1 indicates that an FDI attack is detected, and 0 indicates that no FDI attack is detected; τ i represents the specific threshold calculated for each wind turbine based on the squared residuals of the training set X without attacks; represents the squared residual of the wind power data of the i-th wind turbine at time t among m wind turbines. The calculation formula for the squared residual is:

[0119]

[0120] Among them, represents the wind power data of the i-th wind turbine at time t among m wind turbines; respectively represent the encoding and decoding non-linear functions of the xLSTM-AE model; and represent the optimal parameter set of the xLSTM-AE model.

[0121] After training the xLSTM-AE using the training set X without attacks, the xLSTM-AE detection algorithm as shown in Figure 4 is used to detect FDI attacks on the test set X s A for FDI attack detection.

[0122] In this embodiment, the validation set X vThe performance of the model is evaluated to fine-tune the model parameters. The model training includes setting 800 training epochs, a learning rate of 0.01, and the number of units in the second LSTM layer of the encoder is half of that in the first layer. The selection of these parameters is based on the performance feedback on the validation set to optimize the model performance.

[0123] Example 2

[0124] The present invention develops an FDI attack detection method for wind farm power prediction, specifically targeting the wind farm power prediction scenario, which is of great significance for improving the accuracy of wind power prediction and the stability of the power grid.

[0125] This method includes the following steps:

[0126] (1) Obtain wind farm power data to get the original dataset;

[0127] Specifically, obtain the output power data of 14 wind turbines in a certain wind farm in the UK from 00:00:00 on January 1, 2021 to 00:00:00 on July 1, 2021 (a total of 181 days), and record it every 10 minutes to construct the original dataset.

[0128] (2) Preprocess the wind power data;

[0129] ① To test the FDI attack detection model, the present invention selects the data of 2 days in the original dataset as the test set X s . The remaining data is split into the training set X and the validation set X according to the ratio of 8:2 v .

[0130] ② To simulate the FDI attacks suffered by the wind farm, the present invention performs the following operations on the output power data of the 14th wind turbine in the test set X s :

[0131] Add a basic FDI attack with an attack multiplier of 1.25 and an attack adder of 0.35 MW at the 30th to 50th data points;

[0132] Apply a stealth FDI attack at the 100th to 130th data points;

[0133] Add a basic FDI attack with an attack multiplier of 1.25 and an attack adder of -0.45 MW at the 180th to 200th data points;

[0134] Apply a replay attack (using the 200th to 220th data points to replace the current value) at the 250th to 270th data points.

[0135] In this embodiment, a basic FDI attack was introduced at data points 30 to 50, where the attack multiplier was set to 1.25 and the attack adder was set to 0.35 MW. Since wind power data is usually positive and the original data in this interval is relatively small, choosing a positive attack adder helps ensure that the data after the attack remains within a reasonable range. At data points 180 to 200, the basic FDI attack was introduced again, with the attack multiplier remaining unchanged while the attack adder was adjusted to -0.45 MW. Considering that the original data in this interval is large and choosing a negative attack adder can form a contrast with the positive attack adder to further test the FDI attack detection ability of the system. The attack multiplier and attack adder can be arbitrarily selected, but it is necessary to ensure that the data after the attack cannot be identified by the 3-σ principle.

[0136] These attacks simulate different types of FDI attacks, including basic FDI attacks, stealth FDI attacks, and replay attacks. The basic FDI attack is achieved by changing a single measurement value, and this attack can be described by the following formula:

[0137]

[0138] where, refers to the i-th measurement value under attack; X i refers to the actual measurement value, A i is an arbitrary attack adder; a i is an arbitrary attack multiplier, which causes over-scaling (a i > 1), under-scaling (0 < a i < 1), or negative scaling (a i < 0).

[0139] Compared with the basic FDI attack, the stealth FDI attack adopts a more refined strategy, and its attack vector includes an attack adder and a multiplier that vary with time. This dynamic method enables the attacker to gradually tamper with the data in an imperceptible way. The stealth FDI attack can be described by the following formula:

[0140]

[0141] where, refers to the i-th measurement value under attack; X i refers to the actual measurement value; A i (t) is the attack adder that varies with time; a i (t) is the attack multiplier that varies with time.

[0142] In a replay attack, the attacker uses previously intercepted data to replace the current measurement value. This can be regarded as:

[0143]

[0144] Among them, is the data after being attacked, is the record of the system measurement values at an earlier time.

[0145] The test set X after the FDI attack s is represented by .

[0146] ③ During the operation of the wind turbine generator, due to daily maintenance, sensor failures, and environmental factors such as high temperature and extreme cold, there will always be some outliers in the collected data. To improve the data quality and the detection performance of the model, the present invention adopts the 3-σ principle to identify the outliers in the training set X, the verification set X v and the test set after the attack (the FDI attack in is intelligent and cannot be identified by the 3-σ principle). This principle is based on the normal distribution in statistics, that is, about 68% of the data is within one standard deviation of the mean, 95% is within two standard deviations, and 99.7% is within three standard deviations. The specific formulas are as follows:

[0147] P(μ - σ ≤ X ≤ μ + σ) ≈ 0.68

[0148] P(μ - 2σ ≤ X ≤ μ + 2σ) ≈ 0.95

[0149] P(μ - 3σ ≤ X ≤ μ + 3σ) ≈ 0.997

[0150] Among them, X is a random variable, μ represents the mean of the sequence. Assuming there is a sequence {x 1 , x 2 ,..., x n}, its expression is:

[0151]

[0152] σ represents the standard deviation of the sequence, and its calculation formula is:

[0153]

[0154] For the processing of outliers, the present invention selects the linear interpolation method instead of simply discarding them to maintain the integrity of the time series data. The linear interpolation method can effectively correct the outliers, thereby improving the continuity and quality of the data.

[0155] ④ Using the sliding window technique as shown in Figure 1 , the present invention processes the training set X, the verification set X v and the test set The data is partitioned to ensure that the sample size M is determined according to the following formula:

[0156]

[0157] where n represents the total data volume of the dataset; ω represents the sliding window size (set to 144 in this invention); s represents the moving step size (set to 144 in this invention); denotes the floor operation to ensure that the obtained sample size is an integer.

[0158] (3) Training and verification of xLSTM-AE;

[0159] The xLSTM-AE model is a deep learning architecture that combines xLSTM units and an autoencoder structure. The encoder of this model consists of two layers of xLSTM, which are responsible for encoding the input time series data into a latent space vector of a fixed size. This vector is stored in the middle layer of the model, also known as the "data bridge". The first xLSTM layer of the encoder has the same number of units as the number of input features, achieving a direct mapping from features to xLSTM units; the number of units in the second xLSTM layer is half of that of the first layer, which helps to further compress the data and extract higher-level abstract features. The decoder is symmetric to the encoder structure and also contains two layers of xLSTM. Its goal is to reconstruct the original input sequence from the latent space vector. This design enables the model to effectively capture the spatio-temporal coupling characteristics in time series data, and is particularly suitable for analyzing complex data sequences such as wind farm output power.

[0160] In the multivariate time series training set of wind farm output power given in this invention where m represents the input feature dimension, that is, the number of wind turbines in the whole field;

[0161] The xLSTM-AE model can be expressed as:

[0162]

[0163] where and ψ represent the encoding and decoding processes respectively; H represents the compressed space of latent features; represent the non-linear mapping functions in the encoding and decoding processes of the model respectively; represent the sets of matrices of training weights (W) and biases (b) in the encoding and decoding processes of the model respectively; X represents the training data composed of wind farm output power data; represents the reconstructed wind farm output power data; in conventional operations, generally take

[0164] The optimal parameter set of the model can be obtained by minimizing the residual between the training data composed of wind farm output power data and the reconstructed wind farm output power data, as follows:

[0165]

[0166] The reconstruction error of the xLSTM-AE model is:

[0167]

[0168] where represents the wind power data of the i-th wind turbine at time t among m wind turbines; respectively represent the non-linear mapping functions in the encoding and decoding processes of the model; ||·|| 2 represents the L2 norm, that is, the Euclidean distance; and represent the optimal parameter set of the model;

[0169] The xLSTM-AE model learns the spatio-temporal features in the time series data of the wind farm output power by optimizing the parameters to minimize the reconstruction error. After training, the model can reconstruct the input wind farm power data with the minimum reconstruction error. To avoid overfitting and adjust the hyperparameters of the model, the present invention evaluates the model performance on the validation set X v to fine-tune the model parameters. If the model performs well on the training set but its performance drops on the validation set, this usually means that the model may be too complex or overtrained, and at this time, corresponding adjustments need to be made to the model structure or training strategy. Through this kind of monitoring and adjustment, it is ensured that the model can not only effectively capture the key features of the data during the training process but also maintain good generalization ability. Specifically, the model training includes setting 800 training epochs, a learning rate of 0.01, and the number of units in the second LSTM layer of the encoder is half of that of the first layer. The selection of these parameters is based on the performance feedback on the validation set to optimize the model performance.

[0170] (4) Identify the attacked data;

[0171] The squared residual is the square of the difference between the actual observed value and the model predicted value. Outliers or abnormal points may produce very large squared residuals. By monitoring the squared residuals, outliers or abnormal points in the dataset can be identified. Therefore, the FDI attack detector is constructed as:

[0172]

[0173] where represents the detection output of the i-th wind turbine among m wind turbines at time t, 1 means that an FDI attack is detected, and 0 means that no FDI attack is detected; τ i represents the specific threshold calculated for each wind turbine based on the squared residual of the training set X without attack; It represents the square residual of the wind power data of the i-th wind turbine among m wind turbines at time t. The calculation formula of the square residual is:

[0174]

[0175] in, represents the wind power data of the i-th wind turbine among m wind turbines at time t; They represent the encoding and decoding nonlinear functions of the xLSTM-AE model respectively; and Represents the optimal parameter set for the xLSTM-AE model.

[0176] After training the xLSTM-AE model with the non-attacked training set X, the xLSTM-AE detection algorithm is used to detect the test set. FDI attack detection is performed to identify and mark the test set data of all wind turbines whose squared residuals are greater than their respective set thresholds as FDI attack data. The method of calculating a specific threshold for each wind turbine follows the 3-σ principle, that is, 68% of the data are distributed within one standard deviation of the mean, 95% are distributed within two standard deviations, and 99.7% are distributed within three standard deviations. Therefore, in this study, the data points whose squared residuals of each wind turbine in the test set exceed the mean of the squared residuals of the corresponding wind turbine in the training set plus 2.5 standard deviations are considered to be data attacked by FDI.

[0177] The FDI attack detection results show that in the test set In the above figure, except for the 14th wind turbine, no FDI attack was detected for the remaining wind turbines (the output of the FDI attack detector was 0). For the 14th wind turbine, the detection performance of the xLSTM-AE model is as follows: Figure 5 As shown in the figure, the xLSTM-AE output value is represented by a solid line, the true value is represented by a dotted line, and the FDI attack value is depicted by a dotted line. The analysis results show that in four different time periods, the xLSTM-AE output value curve is basically consistent with the true value curve, but there is a significant difference with the FDI attack value curve. This phenomenon clearly shows that the xLSTM-AE model effectively identifies and distinguishes normal wind power data from wind power data that has been attacked by FDI.

[0178] also, Figure 6Furthermore, a visual display of the squared residuals between the FDI attack value and the output value of xLSTM-AE is provided. As can be seen from the figure, when the squared residual exceeds the preset threshold boundary, the attack behavior is accurately captured, thus revealing the existence of the FDI attack and further demonstrating the effectiveness and accuracy of xLSTM-AE in detecting FDI attacks.

[0179] To comprehensively evaluate the statistical performance of the developed xLSTM-AE detection method, four key evaluation metrics are adopted in this invention:

[0180]

[0181] Among them, TP represents the correctly identified attacks, FP represents the misidentified attacks, TN represents the correctly identified non-attack data points, and FN represents the misidentified non-attack data points. The accuracy measures the overall ability of the model to make correct predictions; the recall rate (also known as sensitivity) measures the ability of the model to identify all actual attacks; the false alarm rate (FAR) measures the frequency at which the model incorrectly labels normal data points as attacks; the F1 score is the harmonic mean of the precision and recall rate, and a high F1 score means low FP and low FN. Table 1 shows the evaluation metrics of the studied xLSTM-AE model.

[0182] Table 1. Evaluation Metrics of the xLSTM-AE Detection Method

[0183] Accuracy Recall False Positive Rate F1 Score 0.9722 0.9255 0.0052 0.9560

Claims

1. A FDI attack detection method for wind farm power prediction, characterized in that: The following steps are involved: (1) Obtain wind farm power data and obtain the original data set; (2) Preprocessing wind power data; ① To test the FDI attack detection model, we randomly select two days of data from the original data set as the test set X s The remaining data is divided into training set X and verification set X according to the ratio of 8:

2. v ; ②Simulate the FDI attack on the wind farm and randomly select the test set X s The output power data of a wind turbine in the simulation is processed to simulate different types of FDI attacks, including basic FDI attacks, stealth FDI attacks, and replay attacks. ③Use the 3-σ principle to identify the training set X and the verification set X v And the test set after attack For outliers in the data, linear interpolation is used instead of simple discarding to maintain the integrity of the time series data. ④Use the sliding window technology to train the training set X and the verification set X after steps ①②③. v And the test set The data is divided to ensure that the sample size M is determined according to the following formula: Among them, n represents the total amount of data in the data set; ω represents the sliding window size; s represents the moving step size; Indicates the rounding down operation to ensure that the number of samples obtained is an integer; (3) Training and verification of xLSTM-AE; The xLSTM-AE model combines xLSTM units and autoencoder structures. The encoder of the model consists of two layers of xLSTM, which is responsible for encoding the input time series data into a latent space vector of a fixed size. This vector is stored in the middle layer of the model, also known as the "data bridge". The number of units in the first xLSTM layer of the encoder matches the number of input features, realizing a direct mapping of features to xLSTM units. The number of units in the second xLSTM layer is half of the first layer, which helps to further compress the data and extract higher-level abstract features. The decoder is symmetrical with the encoder structure and contains two xLSTM layers. Its goal is to reconstruct the original input sequence from the latent space vector. Given a multivariate time series training set of wind farm output power In , m represents the input feature dimension, i.e., the number of wind turbines in the whole field; The xLSTM-AE model is represented as: in, and ψ represent the encoding and decoding processes respectively; H represents the compressed space of latent features; They respectively represent the nonlinear mapping functions in the encoding and decoding process of the model; They represent the set of matrices of training weights (W) and biases (b) in the encoding and decoding process of the model respectively; X represents the training data consisting of wind farm output power data; Represents the reconstructed wind farm output power data; in conventional operation, it is generally taken By minimizing the residual between the training data consisting of the wind farm output power data and the reconstructed wind farm output power data, the optimal parameter set of the model can be obtained as follows: The reconstruction error of the xLSTM-AE model is: in, represents the wind power data of the i-th wind turbine among m wind turbines at time t; They represent the nonlinear mapping functions in the encoding and decoding process of the model respectively; ||·||2 represents the L2 norm, which is the Euclidean distance; and represents the optimal parameter set for the model; (4) Identify the attacked data; The FDI attack detector is built to: in, represents the detection output of the i-th wind turbine among m wind turbines at time t, 1 means that an FDI attack is detected, and 0 means that no FDI attack is detected; τ i represents the specific threshold calculated for each wind turbine based on the squared residual of the training set X without attack; It represents the square residual of the wind power data of the i-th wind turbine among m wind turbines at time t. The calculation formula of the square residual is: in, represents the wind power data of the i-th wind turbine among m wind turbines at time t; They represent the encoding and decoding nonlinear functions of the xLSTM-AE model respectively; and Represents the optimal parameter set for the xLSTM-AE model. After training xLSTM-AE with the non-attacked training set X, the xLSTM-AE detection algorithm is used to detect the test set Perform FDI attack detection.

2. The method according to claim 1, characterized in that In step (2)②, the basic FDI attack, invisible FDI attack and replay attack in the test set meet the requirement that FDI attack is intelligent and cannot be identified by the 3-σ principle.

3. The method according to claim 1, characterized in that In step (2) ②, for the test set X s The output power data of the 14th wind turbine is operated as follows: Add a base FDI attack with an attack multiplier of 1.25 and an attack adder of 0.35MW to the 30th to 50th data points; Apply the invisible FDI attack on data points 100 to 130; Add a base FDI attack with an attack multiplier of 1.25 and an attack adder of -0.45MW to data points 180 to 200; A replay attack is applied on data points 250 to 270 (using data points 200 to 220 to replace the current value).

4. The method according to claim 1, characterized in that: In step (2) ②, the basic FDI attack is achieved by changing a single measurement value. This attack is described by the following formula: in, refers to the i-th measurement value under attack; X i Refers to the actual measured value, A i is any attack adder; a i is an arbitrary attack multiplier that causes overscaling (a i >1), underscaling (0 < a i <1) or negative scaling (a i <0).

5. The method according to claim 1, characterized in that In step (2) ②, the attack vector of the stealth FDI attack includes addends and multipliers that change over time. This dynamic approach enables the attacker to gradually tamper with data in an imperceptible manner. The stealth FDI attack is described by the following formula: in, refers to the i-th measurement value under attack; X i Refers to the actual measured value; A i (t) is the attack adder that changes over time; a i (t) is the attack multiplier that varies over time.

6. The method according to claim 1, characterized in that In step (2)②, in the replay attack, the attacker will use the previously intercepted data to replace the current measurement value as: in, It is the data after the attack. It is a record of system measurements at an earlier time. Test set X after FDI attack s use express.

7. The method according to claim 1, characterized in that In step (3) ③, the 3-σ principle is based on the normal distribution in statistics, that is, 68% of the data are within one standard deviation of the mean, 95% are within two standard deviations, and 99.7% are within three standard deviations; the specific formula is as follows: P(μ-σ≤X≤μ+σ)≈0.68 P(μ-2σ≤X≤μ+2σ)≈0.95 P(μ-3σ≤X≤μ+3σ)≈0.997 Where X is a random variable, μ represents the mean of the sequence, assuming that there is a sequence {x1, x2, ..., x n }, its expression is: σ represents the standard deviation of the sequence, and its calculation formula is:

8. The method according to claim 1, characterized in that In step (3), the verification set X v The model performance is evaluated on the validation set to fine-tune the model parameters. Model training includes setting 800 training cycles, a learning rate of 0.01, and the number of units in the second LSTM layer of the encoder is half of the first layer. These parameters are selected based on performance feedback on the validation set to optimize the model performance.

Citation Information

Patent Citations

  • Abnormal behavior identification monitoring method based on incremental space-time learning

    CN117315565A

  • Power false data injection attack detection method and system based on deep learning

    CN118779787A

  • Anomaly detection in a network

    US11294756B1

Cited By

  • Double-target countermeasure attack method for wind power prediction model

    CN121997325A