Power generation side network anomaly identification method and system based on deep learning

Through real-time monitoring and feature extraction, hidden variables are quantified and simplified version models are created, which solves the computing resource and time consumption problems of deep learning network exception recognition in scenarios with high real-time requirements, and realizes efficient and automated network exception recognition.

CN120074870APending Publication Date: 2025-05-30CHINA POWER INVESTMENT XINJIANG ENERGY & CHEM IND GRP WUCAIWAN POWER GENERATION CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510077871.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing power generation network anomaly recognition method based on deep learning consumes a lot of computing resources and time in scenarios with high real-time requirements, making it difficult to meet the needs of real-time applications.

Method used

By monitoring network traffic logs on the power generation side and access requests for key nodes in real time, extracting network features, quantifying hidden variables, creating a simplified version of the exception recognition model, and performing streaming deployment, real-time network exception recognition is achieved.

Benefits of technology

On the premise of ensuring the accuracy of deep learning models, the algorithm is simplified, the computing resources and time consumption is reduced, and the application scenarios with high real-time requirements is adapted to the efficiency and automation of abnormal detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074870A_ABST
    Figure CN120074870A_ABST
Patent Text Reader

Abstract

The invention discloses a power generation side network anomaly identification method and system based on deep learning, and relates to the technical field of power generation side network security, and the method comprises the steps: monitoring a traffic log generated in a power generation side network and an access request of each key network node in real time; performing feature extraction on the monitored data by using a power generation side network feature extraction project; quantifying hidden variables between the monitoring features and the network anomaly in advance based on the change trend of each monitoring feature before and after the historical network anomaly of the power generation side occurs; creating a simplified power generation side network anomaly recognition model based on the quantized hidden variables; and performing streaming deployment on the created power generation side network anomaly identification model, and outputting an identification result of the current network anomaly in real time. The method can be used for real-time network anomaly detection and early warning, potential security threats can be found and processed in time, and safe and stable operation of a power generation side network is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power generation side network security, and particularly to a method and system for identifying abnormal power generation side networks based on deep learning. Background Art

[0002] The research status of power side network anomaly recognition methods shows a trend of diversification and intelligence. Existing technologies include: statistical-based anomaly detection methods, distance-based anomaly detection methods, deep learning-based anomaly detection methods, PMU measurement data-based anomaly detection methods, etc. Among them, the most effective one is still the deep learning-based detection method. Through the deep learning model, the correlation features in the electrical quantities and communication traffic before and after the anomaly can be extracted to achieve more accurate anomaly recognition. However, deep learning algorithms usually require a large amount of computing resources and time for inference, which may be restricted in practical applications, especially in scenarios with high real-time requirements. To solve the above problems, the present invention provides a new network anomaly recognition method, aiming to simplify its algorithm on the premise of ensuring the accuracy of the deep learning model, so as to fully adapt to the application scenarios with high real-time requirements. Summary of the Invention

[0003] The present invention provides a method for identifying abnormal power generation side networks based on deep learning, including:

[0004] Step1. Real-time monitor the traffic logs generated in the power generation side network and the access requests of each key network node;

[0005] Step2. Use the power generation side network feature extraction project to extract features from the monitored data;

[0006] Step3. Based on the change trends of various monitoring features before and after the occurrence of historical power generation side network anomalies, quantify the latent variables between the monitoring features and network anomalies in advance;

[0007] Step4. Create a simplified power generation side network anomaly recognition model based on the quantified latent variables;

[0008] Step5. Perform streaming deployment on the created power generation side network anomaly recognition model and output the recognition results of current network anomalies in real time.

[0009] For a method for identifying abnormal power generation side networks based on deep learning as described above, where real-time monitoring the traffic logs generated in the power generation side network and the access requests of each key network node is specifically divided into the following sub-steps:

[0010] Divide the entire power generation side network into multiple network partitions;

[0011] Configure monitoring parameters and obtain traffic data within each partition based on the configured parameters;

[0012] Deploy monitoring points at each key network node to obtain access data on the nodes.

[0013] A method for identifying abnormal power generation-side networks based on deep learning as described above, in which a power generation-side network feature extraction project is used to extract features from the monitored data, specifically divided into the following sub-steps:

[0014] Calculate the stability features and distortion features of the partition based on the monitored data obtained within the same network partition;

[0015] Calculate the liquidity features of the partition based on the relative changes in the monitored data within adjacent network partitions;

[0016] Organize the extracted features into multiple data sets according to the network partitions to which they belong.

[0017] A method for identifying abnormal power generation-side networks based on deep learning as described above, in which latent variables between the monitoring features and network anomalies are quantified in advance based on the change trends of various monitoring features before and after historical network anomalies occur on the power generation side, specifically divided into the following sub-steps:

[0018] Collect the monitored data generated within the network partition before and after each network anomaly occurs;

[0019] Extract various features of the monitored data through the power generation-side network feature extraction project;

[0020] Substitute the extracted features into the latent variable quantification formula to obtain the quantification result.

[0021] A method for identifying abnormal power generation-side networks based on deep learning as described above, in which a simplified power generation-side network anomaly identification model is created based on the quantified latent variables, specifically divided into the following sub-steps:

[0022] Establish a simplified power generation-side network anomaly identification model;

[0023] Create a training data set for the model based on the historical network features and historical network anomalies generated within each network partition;

[0024] Use the created training data set to train and optimize the simplified power generation-side network anomaly identification model.

[0025] The present invention also provides a power generation-side network anomaly identification system based on deep learning, including: a network monitoring module, a network feature extraction module, a latent variable acquisition module, an identification model creation module, and a network anomaly identification module;

[0026] A network monitoring module for real-time monitoring of traffic logs generated in the power generation side network and access requests of each key network node;

[0027] A network feature extraction module for extracting features from the monitored data using the power generation side network feature extraction project;

[0028] A latent variable acquisition module for quantifying in advance the latent variable between the monitoring features and network anomalies based on the change trends of various monitoring features before and after the occurrence of historical network anomalies on the power generation side;

[0029] An identification model creation module for creating a simplified version of the power generation side network anomaly identification model based on the quantified latent variables;

[0030] A network anomaly identification module for streaming deployment of the created power generation side network anomaly identification model and real-time output of the identification results of current network anomalies.

[0031] The beneficial effects achieved by the present invention are as follows: It can be used for real-time network anomaly detection and early warning, which helps to timely discover and handle potential security threats and ensure the safe and stable operation of the power generation side network; it improves the efficiency of anomaly detection, reduces the dependence on professional personnel, and realizes the automation of the detection process. Description of the Drawings

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0033] Figure 1 It is a flowchart of a method for identifying power generation side network anomalies based on deep learning provided in Embodiment 1 of the present application;

[0034] Figure 2 It is a schematic diagram of a system for identifying power generation side network anomalies based on deep learning provided in Embodiment 2 of the present application. Detailed Embodiments

[0035] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0036] Embodiment 1

[0037] As Figure 1As shown in the figure, Embodiment 1 of the present application provides a method for identifying abnormal power generation side networks based on deep learning, including:

[0038] Step S10: Monitor the traffic logs generated in the power generation side network in real time, as well as the access requests of each key network node;

[0039] Traffic logs are the main data in the process of network anomaly identification, and the access requests of each key network node are used to identify illegal intrusion behaviors in the network. The specific monitoring process is divided into the following sub-steps:

[0040] Step S11: Divide the entire power generation side network into multiple network partitions;

[0041] The network partitions can be divided according to various conditions such as usage, logical scope, and physical scope. Just operate according to needs. The main purpose is to limit the access permissions between different partitions and reduce the movement range of attackers in the network.

[0042] Step S12: Configure monitoring parameters and obtain the traffic data within each partition based on the configured parameters;

[0043] Different monitoring parameters can be configured according to the characteristics and requirements of different network partitions. The configured parameters include but are not limited to bandwidth utilization, throughput, number of sessions, network latency, jitter, and packet loss rate.

[0044] Step S13: Deploy monitoring points at each key network node to obtain the access data on the node;

[0045] The access data mainly includes three parts: the access party, the access node, and the access frequency.

[0046] Step S20: Use the power generation side network feature extraction project to extract features from the monitored data;

[0047] The power generation side network feature extraction project needs to extract the stability feature, mobility feature, and distortion feature of the current network partition from the original monitored data. These three features are the key to identifying network anomalies. The extraction process is specifically divided into the following sub-steps:

[0048] Step S21: Calculate the stability feature and distortion feature of the partition according to the monitored data obtained within the same network partition;

[0049] The data participating in the calculation must be numerical. For character data, this embodiment will convert it into numerical data in advance using one-hot encoding and then participate in the calculation. First, use the formula:

[0050] to calculate the distortion feature C of the partition dis where a dkis the value of the d-th monitoring data obtained at the k-th time point, a dk+1 is the value of the d-th monitoring data obtained at the (k + 1)-th time point, represents the mean value of all monitoring data obtained at the k-th time point, d ranges from 1 to D, D is the total number of monitoring data items, k ranges from 1 to W - 1, W is the calculation period; then substitute the distortion feature C dis into the formula: to obtain the stability feature C of this partition stab , where a dk is the value of the d-th monitoring data obtained at the k-th time point, represents the mean value of the d-th monitoring data within the current calculation period, at this time k ranges from 1 to W, W is the calculation period, d ranges from 1 to D, D is the total number of monitoring data items.

[0051] Step S22: Calculate the mobility feature of this partition according to the relative change of the monitoring data in adjacent network partitions;

[0052] The calculation formula of the mobility feature C mob is expressed as: where a dj represents the value of the d-th monitoring data in the current network partition, a dj-1 , a dj+1 respectively represent the values of the d-th monitoring data in two adjacent network partitions, d ranges from 1 to D, D is the total number of monitoring data items.

[0053] Step S23: Organize the extracted features into multiple data sets according to their respective network partitions;

[0054] Prepare a data set for each network partition to store the feature values, and store the extracted features into it in sequence to provide data support for subsequent network anomaly recognition.

[0055] Step S30: Based on the change trend of each monitoring feature before and after the occurrence of historical network anomalies on the power generation side, quantify the latent variables between the monitoring features and network anomalies in advance;

[0056] It should be noted that the latent variables quantified in this step are obtained as an approximate value through calculation, which is used to save the inference time of the model and cannot be directly used as the final parameters of the model. The specific quantification process is divided into the following sub-steps:

[0057] Step S31: Collect the monitoring data generated in this network partition before and after each network anomaly occurs;

[0058] Step S32: Extract each feature of the monitoring data through the power generation side network feature extraction project;

[0059] The extracted features are identified and distinguished using their corresponding network anomaly types.

[0060] Step S33: Substitute the extracted features into the latent variable quantization formula to obtain the quantization result;

[0061] The latent variable quantization formula is denoted as:

[0062] where A i is the numerical data converted from the i-th network anomaly (also using the one-hot encoding conversion method), respectively represent the distortion feature, stability feature, and fluidity feature of the network partition before the i-th network anomaly occurs, respectively represent the distortion feature, stability feature, and fluidity feature of the network partition after the i-th network anomaly occurs, are respectively the latent variables between the distortion feature, stability feature, and fluidity feature and the network anomaly, The value range of is between 0.01 and 0.99. After the calculation starts, these three latent variables start to iterate respectively, and the argmin() function returns the and when the calculation result of the expression in the parentheses is the smallest. i takes values from 1 to n, where n is the total number of network anomalies that occur.

[0063] Step S40: Create a simplified power generation side network anomaly recognition model based on the quantized latent variables;

[0064] The simplified power generation side network anomaly recognition model can save a large amount of inference time and computing resources consumed in the latent variable alignment process, and can directly perform minor modifications on the quantized latent variables, thereby achieving more accurate and complete network anomaly recognition. The specific creation process is divided into the following sub-steps:

[0065] Step S41: Establish a simplified power generation side network anomaly recognition model;

[0066] The established simplified power generation side network anomaly recognition model Y(C) is expressed as:

[0067] where C is the input set, C dis 、C stab 、C mob are respectively the distortion feature, stability feature, and fluidity feature in the input set, are respectively the latent variables between the distortion feature, stability feature, and fluidity feature and the network anomaly, are respectively the modification matrices of the latent variables.

[0068] Step S42: Create a training dataset for the model based on the historical network features and historical network anomalies generated within each network partition;

[0069] Extract features from the historical monitoring data generated within each network partition to obtain historical network features. Then, convert the historical network anomalies into numerical data. Subsequently, use the converted historical network anomalies as the output and the historical network features generated by the corresponding network partition during their occurrence time as the input to form input-output pairs. Finally, organize these input-output pairs into a training dataset.

[0070] Step S43: Use the created training dataset to train and optimize the simplified power generation side network anomaly recognition model;

[0071] During the training process, observe the curve change of the MES loss function in real time and iterate the parameters in the model according to the principle of minimum loss until the function curve no longer decreases.

[0072] Step S50: Perform streaming deployment on the created power generation side network anomaly recognition model to output the recognition results of current network anomalies in real time;

[0073] Streaming deployment can improve the output rate of the power generation side network anomaly recognition model and further enhance the real-time performance of anomaly recognition. For the real-time monitored data obtained, feature extraction is performed in the form of a data stream and input into the model. Then, combined with the output results of the model, anomaly warnings are issued for each network partition, enabling operation and maintenance personnel to take emergency measures in a timely manner and reducing the negative impacts caused by untimely responses.

[0074] Embodiment 2

[0075] As Figure 2 shown, Embodiment 2 of the present application provides a power generation side network anomaly recognition system based on deep learning, including: a network monitoring module 21, a network feature extraction module 22, a latent variable acquisition module 23, a recognition model creation module 24, and a network anomaly recognition module 25;

[0076] The network monitoring module 21 is used to monitor the traffic logs generated within the power generation side network in real time, as well as the access requests of each key network node; specifically including: a network partitioning sub-module, a monitoring configuration sub-module, and a monitoring data acquisition sub-module;

[0077] 1. The network partitioning sub-module is used to divide the entire power generation side network into multiple network partitions;

[0078] The network partitions can be divided according to multiple conditions such as usage, logical scope, physical scope, etc., and can be operated as needed. The main purpose is to limit the access permissions between different partitions and reduce the movement range of attackers in the network.

[0079] 2. The monitoring configuration sub-module is used to configure monitoring parameters according to the characteristics and requirements of different network partitions;

[0080] The configured parameters include but are not limited to bandwidth utilization, throughput, number of sessions, network latency, jitter, and packet loss rate.

[0081] 3. The monitoring data acquisition sub-module is used to obtain traffic data within each partition and access data on each key network node based on the configured parameters.

[0082] The network feature extraction module 22 is used to extract features from the monitored data using the power generation side network feature extraction project; specifically including: a feature calculation sub-module and a feature arrangement sub-module;

[0083] 1. The feature calculation sub-module is used to calculate the stability feature and distortion feature of the partition according to the monitored data obtained within the same network partition, and calculate the mobility feature of the partition according to the relative change of the monitored data in the adjacent network partition;

[0084] The data participating in the calculation must be numerical. For character data, this embodiment will convert it into numerical data in advance using the one-hot encoding method and then participate in the calculation. First, use the formula:

[0085] to calculate the distortion feature C dis , where a dk is the value of the d-th monitored data obtained at the k-th time point, and a dk+1 is the value of the d-th monitored data obtained at the (k + 1)-th time point, represents the mean value of all monitored data obtained at the k-th time point, d takes values from 1 to D, D is the total number of monitored data items, k takes values from 1 to W - 1, and W is the calculation period; then substitute the distortion feature C dis into the formula: to obtain the stability feature C stab , where a dk is the value of the d-th monitored data obtained at the k-th time point, represents the mean value of the d-th monitored data within the current calculation period. At this time, k takes values from 1 to W, W is the calculation period, and d takes values from 1 to D, D is the total number of monitored data items.

[0086] The calculation formula for the mobility feature C mob is expressed as: where a dj represents the value of the d-th monitored data within the current network partition, and a dj-1 , a dj+1respectively represent the values of the d-th monitoring data of two adjacent network partitions, where d ranges from 1 to D, and D is the total number of monitoring data items.

[0087] 2. Feature sorting sub-module, which is used to sort the extracted features into multiple data sets according to the network partitions they belong to;

[0088] Prepare a data set for each network partition to store the feature values, and sequentially store the extracted features into it to provide data support for subsequent network anomaly recognition.

[0089] Latent variable acquisition module 23, which is used to quantify the latent variable between the monitoring features and network anomalies in advance based on the change trends of various monitoring features before and after historical network anomalies occur on the power generation side; specifically including: historical monitoring data collection sub-module, latent variable calculation sub-module;

[0090] 1. Historical monitoring data collection sub-module, which is used to collect the monitoring data generated within the network partition before and after each network anomaly occurs, and extract various features of the monitoring data through the power generation side network feature extraction project;

[0091] The extracted features are identified and distinguished using their corresponding network anomaly types.

[0092] 2. Latent variable calculation sub-module, which is used to substitute the extracted features into the latent variable quantization formula to obtain the quantization result;

[0093] The latent variable quantization formula is marked as:

[0094] where A i is the numerical data converted from the i-th network anomaly (also using the one-hot encoding conversion method), respectively represent the distortion feature, stability feature, and liquidity feature of this network partition before the i-th network anomaly occurs, respectively represent the distortion feature, stability feature, and liquidity feature of this network partition after the i-th network anomaly occurs, are respectively the latent variables between the distortion feature, stability feature, and liquidity feature and the network anomaly, The value range of is between 0.01 and 0.99. After the calculation starts, these three latent variables start to iterate respectively, and the argmin() function returns the value of when the calculation result of the expression in the parentheses is the smallest and where i ranges from 1 to n, and n is the total number of network anomalies that occur.

[0095] Recognition model creation module 24, which is used to create a simplified version of the power generation side network anomaly recognition model based on the quantified latent variables; specifically including: model establishment sub-module, training data set creation sub-module, model training sub-module;

[0096] 1. A model building sub-module for building a simplified power generation side network anomaly recognition model;

[0097] The established simplified power generation side network anomaly recognition model Y(C) is expressed as:

[0098] where C is the input set, and C dis 、C stab 、C mob are the distortion feature, stability feature, and liquidity feature in the input set respectively, are the latent variables between the distortion feature, stability feature, and liquidity feature and network anomalies respectively, are the latent variables 's modification matrices.

[0099] 2. A training dataset creation sub-module for creating a training dataset for the model based on the historical network features and historical network anomalies generated within each network partition;

[0100] Feature extraction is performed on the historical monitoring data generated within each network partition to obtain historical network features, and then the historical network anomalies are converted into numerical data. Subsequently, the converted historical network anomalies are used as outputs, and the historical network features generated by the corresponding network partition during their occurrence times are used as inputs to form input-output pairs. Finally, these input-output pairs are organized into a training dataset.

[0101] 3. A model training sub-module for training and optimizing the simplified power generation side network anomaly recognition model using the created training dataset;

[0102] During the training process, the curve change of the MES loss function is observed in real time, and the parameters in the model are iterated based on the minimum loss principle until the function curve no longer decreases.

[0103] The network anomaly recognition module 25 is used to perform streaming deployment on the created power generation side network anomaly recognition model and output the recognition results of current network anomalies in real time;

[0104] Streaming deployment can improve the output rate of the power generation side network anomaly recognition model and further enhance the real-time performance of anomaly recognition. For the real-time acquired monitoring data, feature extraction is performed in the form of a data stream and input into the model, and then anomaly warnings are issued for each network partition in combination with the output results of the model, enabling the operation and maintenance personnel to take emergency measures immediately and reducing the negative impacts caused by untimely responses.

[0105] Corresponding to the above embodiments, an embodiment of the present invention provides a computer storage medium, including: at least one memory and at least one processor;

[0106] The memory is used to store one or more program instructions;

[0107] The processor is used to run one or more program instructions to execute a method for identifying abnormal power generation side networks based on deep learning.

[0108] Corresponding to the above embodiments, an embodiment of the present invention provides a computer-readable storage medium. The computer storage medium contains one or more program instructions, and the one or more program instructions are used to be executed by a processor to execute a method for identifying abnormal power generation side networks based on deep learning.

[0109] An embodiment disclosed by the present invention provides a computer-readable storage medium. Computer program instructions are stored in the computer-readable storage medium. When the computer program instructions run on a computer, the computer is caused to execute the above-mentioned method for identifying abnormal power generation side networks based on deep learning.

[0110] In an embodiment of the present invention, the processor may be an integrated circuit chip with signal processing capabilities. The processor may be a general-purpose processor, a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0111] It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention may be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. The processor reads the information in the storage medium and combines its hardware to complete the steps of the above method.

[0112] The storage medium may be a memory, for example, it may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories.

[0113] Among them, the non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory.

[0114] The volatile memory can be a Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM).

[0115] The storage media described in the embodiments of the present invention are intended to include but not be limited to these and any other suitable types of memories.

[0116] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by a combination of hardware and software. When applying software, the corresponding functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes a computer storage medium and a communication medium, where the communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0117] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for identifying abnormalities in power generation network based on deep learning, characterized in that: include: Step 1: Real-time monitoring of traffic logs generated in the power generation network and access requests to each key network node; Step 2: Use the power generation side network feature extraction project to extract features from the monitored data; Step 3: Based on the changing trends of various monitoring characteristics before and after the historical network anomalies on the power generation side, the hidden variables between the monitoring characteristics and the network anomalies are quantified in advance; Step 4: Create a simplified generation side network anomaly recognition model based on the quantified latent variables; Step 5: Perform streaming deployment on the created power generation side network anomaly recognition model to output the recognition results of the current network anomaly in real time.

2. According to a method for identifying abnormalities in power generation network based on deep learning in claim 1, it is characterized in that: Real-time monitoring of traffic logs generated in the power generation network and access requests to each key network node is divided into the following sub-steps: Divide the entire power generation side network into multiple network partitions; Configure monitoring parameters and obtain traffic data in each partition based on the configured parameters; Deploy monitoring points at each key network node to obtain access data on the node.

3. According to a method for identifying abnormalities in power generation network based on deep learning in claim 1, it is characterized in that: The power generation side network feature extraction project is used to extract features from the monitored data, which is specifically divided into the following sub-steps: Calculate the stability characteristics and distortion characteristics of the partition based on the monitoring data obtained in the same network partition; Calculate the mobility characteristics of the partition based on the relative changes in the monitoring data in the adjacent network partition; The extracted features are organized into multiple data sets according to the network partitions to which they belong.

4. According to a method for identifying abnormalities in power generation network based on deep learning in claim 1, it is characterized in that: Based on the changing trends of various monitoring characteristics before and after the historical network anomalies on the power generation side, the hidden variables between the monitoring characteristics and the network anomalies are quantified in advance, which is specifically divided into the following sub-steps: Collect monitoring data generated in the network partition before and after each network anomaly occurs; Extract various features of monitoring data through the power generation side network feature extraction project; The extracted features are introduced into the latent variable quantization formula to obtain the quantization results.

5. The method for identifying abnormality in power generation network based on deep learning according to claim 1 is characterized in that: A simplified generation side network anomaly identification model is created based on the quantified latent variables, which is divided into the following sub-steps: Establish a simplified model for identifying network anomalies on the power generation side; A training dataset for creating models based on historical network features and anomalies generated within each network partition; Use the created training data set to train and tune the simplified generation side network anomaly recognition model.

6. A power generation side network anomaly identification system based on deep learning, characterized in that: include: Network monitoring module, network feature extraction module, latent variable acquisition module, recognition model creation module, network anomaly recognition module; The network monitoring module is used to monitor the traffic logs generated in the power generation side network and the access requests of each key network node in real time; A network feature extraction module is used to extract features from the monitored data using a power generation side network feature extraction project; Hidden variable acquisition module, used to quantify the hidden variables between monitoring features and network anomalies in advance based on the changing trends of various monitoring features before and after the historical network anomalies on the power generation side; Identification model creation module, used to create a simplified generation side network anomaly identification model based on quantified latent variables; The network anomaly identification module is used to perform streaming deployment of the created power generation side network anomaly identification model and output the identification results of the current network anomaly in real time.

7. A power generation side network anomaly identification system based on deep learning according to claim 6, characterized in that: The network monitoring module specifically includes: a network division submodule, a monitoring configuration submodule, and a monitoring data acquisition submodule; A network partitioning submodule is used to divide the entire power generation side network into multiple network partitions; The monitoring configuration submodule is used to configure monitoring parameters according to the characteristics and requirements of different network partitions; The monitoring data acquisition submodule is used to obtain the traffic data in each partition and the access data on each key network node based on the configured parameters.

8. A power generation side network anomaly identification system based on deep learning according to claim 6, characterized in that: The recognition model creation module specifically includes: a model building submodule, a training data set creation submodule, and a model training submodule; The model building submodule is used to build a simplified version of the generation side network anomaly identification model; A training data set creation submodule is used to create a training data set for the model based on historical network features and historical network anomalies generated in each network partition; The model training submodule is used to train and tune the simplified generation side network anomaly recognition model using the created training data set.

9. A computer storage medium, characterized in that include: at least one memory and at least one processor; A memory for storing one or more program instructions; A processor, used to run one or more program instructions to execute a method for identifying network anomalies on the power generation side based on deep learning as described in any one of claims 1 to 5.