Network threat defense optimization method and device, computer equipment and storage medium

By generating confrontation scenarios and dynamically adjusting system parameters, the problem of low operation stability of information physics systems in the prior art is solved, and the system's recovery ability and stability are significantly improved.

CN120074945APending Publication Date: 2025-05-30ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510319620.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing collaborative defense strategies and systems for counterattacks have the problem of low system operation stability.

Method used

By obtaining the system topological structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters and control parameters of the information physics system, multiple confrontation scenarios are generated, and passive and active elastic indicators are generated based on these data. These indicators are used to evaluate the system's recovery ability and stability in different scenarios, and dynamically adjust the system parameters and control parameters through optimization models to improve the system's recovery ability and stability.

Benefits of technology

It significantly improves the operation stability and recovery ability of the information physics system in various confrontational situations, and solves the problems of insufficient system recovery ability and slow response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074945A_ABST
    Figure CN120074945A_ABST
Patent Text Reader

Abstract

The invention relates to a network threat defense optimization method and device, computer equipment and a storage medium. The method comprises the steps of obtaining structure data, operation data, environment meteorological data, historical events, fault data, system parameters and control parameters of an information physical system, generating a plurality of confrontation scenes based on the system operation data, the environment meteorological data, the historical events and the fault data, generating a passive elasticity index according to the structure data, and determining the passive elasticity index according to the passive elasticity index. Generating an active elasticity index based on the operation data, inputting the system parameter, the control parameter, the passive elasticity index and the active elasticity index corresponding to the current confrontation scene into an optimization model, and obtaining a target system parameter and a control parameter under the condition of meeting preset constraint conditions, and updating corresponding parameters in the information physical system in the current confrontation scene by using the target system parameters and the control parameters. By adopting the method, the operation stability of the system in different confrontation scenes is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a method, device, computer device, computer-readable storage medium, and computer program product for optimizing network threat defense. Background Art

[0002] With the wide application of cyber-physical systems, the research on network security has become particularly important. Network attacks not only threaten the normal operation of information systems but may also have a serious impact on the security and resilience of physical systems.

[0003] Currently, a collaborative defense strategy and system against adversarial attacks have been proposed, which can effectively defend against various types of adversarial samples by training an adversarial sample detector to protect the normal operation of the system.

[0004] However, the current collaborative defense strategy and system against adversarial attacks have the problem of low system operation stability. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a method, device, computer device, computer-readable storage medium, and computer program product for optimizing network threat defense that can improve the system operation stability.

[0006] In a first aspect, the present application provides a method for optimizing network threat defense, including:

[0007] Obtain the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0008] Generate a plurality of adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data;

[0009] Generate a passive resilience index according to the system topology structure data, and generate an active resilience index corresponding to each adversarial scenario based on the system operation data; the active resilience index is used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience index is used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled;

[0010] For any current adversarial scenario among the plurality of adversarial scenarios, input the system parameters, control parameters, passive resilience index, and the active resilience index corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain the target system parameters and target control parameters when the predicted recovery ability information meets the pre-set constraint conditions through the optimization model;

[0011] Update the system parameters in the cyber-physical system in the current adversarial scenario to the target system parameters, and update the control parameters to the target control parameters.

[0012] In one embodiment, when the predictive recovery ability information obtained through the optimization model meets the pre-set constraint conditions, the target system parameters and target control parameters include:

[0013] Through the optimization model, obtain the predictive recovery ability information of the cyber-physical system in the current adversarial scenario;

[0014] Obtain the absolute value of the difference between the predictive recovery ability information and the lowest threshold of the recovery ability information pre-set in the optimization model;

[0015] When the absolute value of the difference does not exceed the pre-set absolute value threshold of the difference and the predictive recovery ability information is greater than the preset value, determine the system parameters as the target system parameters, and determine the control parameters as the control parameters;

[0016] When the absolute value of the difference exceeds the absolute value threshold of the difference and the predictive recovery ability information is less than the lowest threshold of the recovery ability information, correspondingly increase the system parameters and control parameters through the optimization model until the absolute value of the difference does not exceed the pre-set absolute value threshold of the difference and the predictive recovery ability information is greater than the preset value, and determine the increased system parameters as the target system parameters, and determine the increased control parameters as the target control parameters;

[0017] If the absolute value of the difference exceeds the absolute value threshold of the difference and the predictive recovery ability information is greater than the lowest threshold of the recovery ability information, correspondingly decrease the system parameters and control parameters through the optimization model until the absolute value of the difference does not exceed the pre-set absolute value threshold of the difference and the predictive recovery ability information is greater than the preset value, and determine the decreased system parameters as the target system parameters, and determine the decreased control parameters as the target control parameters.

[0018] In one embodiment, the optimization model is trained through the following steps:

[0019] Obtain the sample system topology structure data, sample system operation data, sample environmental meteorological data, sample historical events, sample fault data, sample system parameters and sample control parameters of the cyber-physical system;

[0020] Based on the sample system operation data, sample environmental meteorological data, sample historical events and sample fault data, generate multiple sample adversarial scenarios;

[0021] Generate sample passive elasticity indicators according to the sample system topology structure data, and generate sample active elasticity indicators corresponding to each adversarial scenario based on the sample system operation data;

[0022] Using a pre-set performance mapping function, map the sample system parameters, sample control parameters, sample passive elasticity indicators, and each sample active elasticity indicator to obtain multiple resilience information of the cyber-physical system;

[0023] Construct multiple sample input variables based on the sample system parameters, sample control parameters, sample passive elasticity indicators, and each sample active elasticity indicator, and input the multiple sample input variables into the optimization model to be trained to obtain the corresponding predicted resilience information;

[0024] Through the covariance function in the optimization model to be trained, obtain the covariance between the sample system parameters, sample control parameters, and their corresponding sample input variables;

[0025] Based on the covariance, predicted resilience information, and resilience information, update the covariance function until the similarity between the predicted resilience information and the resilience information meets the preset conditions, and obtain the trained optimization model.

[0026] In one embodiment, the system topology structure data includes nodes and edges; generating passive elasticity indicators according to the system topology structure data includes:

[0027] According to the number of edges connected to any current node and the total number of nodes, obtain the topological centrality indicator associated with the cyber-physical system;

[0028] Based on the total number of edges and the total number of nodes, obtain the topological connectivity indicator associated with the cyber-physical system;

[0029] Obtain the first weight corresponding to the topological centrality indicator and the second weight corresponding to the topological connectivity indicator;

[0030] Use the first weight and the second weight to perform a weighted sum of the topological centrality indicator and the topological connectivity indicator to obtain the passive elasticity indicator.

[0031] In an exemplary embodiment, the system operation data includes the recovery time required for the cyber-physical system, the total operation time, and the constraint violation indication function under each adversarial scenario; when any current constraint is violated, the constraint violation indication function corresponding to the current constraint is 1, and when any current constraint is not violated, the constraint violation indication function corresponding to the current constraint is 0;

[0032] Generating the active elasticity indicators corresponding to each adversarial scenario based on the system operation data includes:

[0033] Use the recovery time divided by the total operation time to obtain the recovery ability indicator corresponding to each adversarial scenario;

[0034] Sum up the constraint violation index functions corresponding to each constraint in the cyber-physical system to obtain the operation constraint violation index corresponding to each adversarial scenario;

[0035] Obtain the third weight corresponding to the recovery ability index and the fourth weight corresponding to the operation constraint violation index;

[0036] According to the third weight and the fourth weight, perform weighted summation on the recovery ability index and the operation constraint violation index to obtain the active resilience index corresponding to each adversarial scenario.

[0037] In one embodiment, the system operation data includes power generation data, load data, and energy storage device data; the power generation data includes the actual solar power generation data, and the load data includes the expected load data, historical load data, and demand fluctuation data;

[0038] Generate multiple adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data, including:

[0039] Input the environmental meteorological data into the pre-constructed solar power generation prediction model to obtain the corresponding solar power generation prediction data, and generate a solar prediction error according to the actual solar power generation data and the solar power generation prediction data;

[0040] Obtain the power generation loss according to the energy storage device data, historical events, and fault data;

[0041] Generate a demand prediction error based on the expected load data, historical load data, and demand fluctuation data;

[0042] Perturb the solar prediction error, power generation loss, and demand prediction error to generate multiple solar prediction attack scenarios, power generation loss attack scenarios, and demand prediction attack scenarios;

[0043] Generate multiple adversarial scenarios based on each solar prediction attack scenario, power generation loss attack scenario, and demand prediction attack scenario; each adversarial scenario includes any one solar prediction attack scenario, any one power generation loss attack scenario, and any one demand prediction attack scenario.

[0044] In an exemplary embodiment, after updating the system parameters in the cyber-physical system to the target system parameters and the control parameters to the target control parameters under the current adversarial scenario, the method further includes:

[0045] Obtain the system feedback data of the cyber-physical system under each adversarial scenario;

[0046] Use the system feedback data and the pre-constructed evaluation indicators to perform index calculation to obtain the evaluation indicator data under each adversarial scenario;

[0047] Generate an evaluation report for the cyber-physical system based on the data of each evaluation index, and send the evaluation report to the user terminal.

[0048] In one embodiment, before obtaining the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized, it includes:

[0049] Obtain the original system topology structure data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters of the cyber-physical system; the data types of the original system topology structure data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters are any one of numerical data, categorical data, and time series data;

[0050] Remove duplicate data, error data, and missing data from the numerical data, categorical data, and time series data to obtain the cleaned numerical data, categorical data, and time series data;

[0051] Perform min-max normalization on the cleaned numerical data column by column to obtain the normalized numerical data, perform data conversion on the cleaned categorical data through one-hot encoding or label encoding to obtain the converted categorical data, and use a smoothing technique to remove the high-frequency fluctuations in the cleaned time series data to obtain the removed time series data;

[0052] Perform normalization processing on the normalized numerical data, converted categorical data, and removed time series data to obtain the processed numerical data, categorical data, and time series data.

[0053] In a second aspect, the present application also provides a network threat defense optimization device, including:

[0054] A data acquisition module, configured to acquire the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0055] A scenario generation module, configured to generate multiple adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data;

[0056] An index construction module, configured to generate passive resilience indices based on system topology structure data and generate active resilience indices corresponding to respective adversarial scenarios based on system operation data; the active resilience indices are used to evaluate the recovery ability and constraint violation conditions of the cyber-physical system after enabling control strategies under respective adversarial scenarios, and the passive resilience indices are used to evaluate the robustness and stability of the cyber-physical system when control strategies are not enabled;

[0057] A target parameter acquisition module, configured to, for any current adversarial scenario among multiple adversarial scenarios, input system parameters, control parameters, passive resilience indices, and the active resilience index corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain target system parameters and target control parameters under the condition that the predicted recovery ability information meets a pre-set constraint condition through the optimization model;

[0058] A parameter update module, configured to update the system parameters in the cyber-physical system under the current adversarial scenario to the target system parameters and update the control parameters to the target control parameters.

[0059] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0060] Obtain system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0061] Generate multiple adversarial scenarios based on system operation data, environmental meteorological data, historical events, and fault data;

[0062] Generate passive resilience indices based on system topology structure data and generate active resilience indices corresponding to respective adversarial scenarios based on system operation data; the active resilience indices are used to evaluate the recovery ability and constraint violation conditions of the cyber-physical system after enabling control strategies under respective adversarial scenarios, and the passive resilience indices are used to evaluate the robustness and stability of the cyber-physical system when control strategies are not enabled;

[0063] For any current adversarial scenario among multiple adversarial scenarios, input system parameters, control parameters, passive resilience indices, and the active resilience index corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain target system parameters and target control parameters under the condition that the predicted recovery ability information meets a pre-set constraint condition through the optimization model;

[0064] Update the system parameters in the cyber-physical system under the current adversarial scenario to the target system parameters and update the control parameters to the target control parameters.

[0065] Fourthly, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0066] Obtain the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0067] Generate a plurality of adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data;

[0068] Generate a passive resilience index according to the system topology structure data, and generate an active resilience index corresponding to each adversarial scenario based on the system operation data; the active resilience index is used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience index is used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled;

[0069] For any current adversarial scenario among the plurality of adversarial scenarios, input the system parameters, control parameters, passive resilience index, and the active resilience index corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain the target system parameters and target control parameters when the predicted recovery ability information meets the pre-set constraint conditions through the optimization model;

[0070] Update the system parameters in the cyber-physical system under the current adversarial scenario to the target system parameters, and update the control parameters to the target control parameters.

[0071] Fifthly, the present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0072] Obtain the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0073] Generate a plurality of adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data;

[0074] Generate a passive resilience index according to the system topology structure data, and generate an active resilience index corresponding to each adversarial scenario based on the system operation data; the active resilience index is used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience index is used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled;

[0075] For any current adversarial scenario among multiple adversarial scenarios, input the system parameters, control parameters, passive resilience metrics, and active resilience metrics corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain the target system parameters and target control parameters when the predicted recovery ability information meets the pre-set constraint conditions through the optimization model;

[0076] Update the system parameters in the cyber-physical system under the current adversarial scenario to the target system parameters, and update the control parameters to the target control parameters.

[0077] The above-mentioned network threat defense optimization method, device, computer device, computer-readable storage medium, and computer program product obtain the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized, generate multiple adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data, generate passive resilience metrics according to the system topology structure data, and generate active resilience metrics corresponding to each adversarial scenario based on the system operation data, where the active resilience metrics are used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience metrics are used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled. For any current adversarial scenario among multiple adversarial scenarios, input the system parameters, control parameters, passive resilience metrics, and active resilience metrics corresponding to the current adversarial scenario into a pre-constructed optimization model, obtain the target system parameters and target control parameters when the predicted recovery ability information meets the pre-set constraint conditions through the optimization model, and update the system parameters in the cyber-physical system under the current adversarial scenario to the target system parameters, and update the control parameters to the target control parameters. Simulate and generate multiple adversarial scenarios, use the optimization model to obtain the target system parameters and target control parameters under the current adversarial scenario, and make corresponding adjustments to the parameters under the current adversarial scenario, thereby enhancing the anti-attack ability and recovery ability of the cyber-physical system and improving the operation stability of the system under different adversarial scenarios. Description of the Drawings

[0078] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description in the embodiments of the present application or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0079] Figure 1 It is an application environment diagram of the network threat defense optimization method in an embodiment;

[0080] Figure 2 Schematic flowchart of the network threat defense optimization method in an embodiment;

[0081] Figure 3 Schematic diagram of the IEEE-123 node test system in an embodiment;

[0082] Figure 4 Diagram of power dispatching and power allocation of the system under different adversarial scenarios in another embodiment;

[0083] Figure 5 Diagram of power dispatching and power allocation of the system under multiple adversarial scenarios in an ideal communication environment in an embodiment;

[0084] Figure 6 Diagram of power dispatching and power allocation of the system under demand prediction disturbance and solar prediction disturbance in another embodiment;

[0085] Figure 7 Structural block diagram of the network threat defense optimization device in an embodiment;

[0086] Figure 8 Internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0087] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0088] The network threat defense optimization method provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 . Among them, the cyber-physical system includes a distribution network and a network for controlling power distribution, which are jointly composed of residential areas, power generation plants, transmission lines, etc. The cyber-physical system communicates with the server 102 through the network. The data storage system can store the data that the server 102 needs to process. The data storage system can be integrated on the server 102, or placed in the cloud or other network servers.

[0089] The server 102 obtains the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized. Based on the system operation data, environmental meteorological data, historical events, and fault data, multiple adversarial scenarios are generated. The passive resilience index is generated according to the system topology structure data, and the active resilience index corresponding to each adversarial scenario is generated based on the system operation data. The active resilience index is used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience index is used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled. For any current adversarial scenario among the multiple adversarial scenarios, the system parameters, control parameters, passive resilience index, and the active resilience index corresponding to the current adversarial scenario are input into the pre-constructed optimization model. Through the optimization model, the target system parameters and control parameters are obtained when the predicted recovery ability information meets the pre-set constraint conditions. The system parameters in the cyber-physical system under the current adversarial scenario are updated to the target system parameters, and the control parameters are updated to the target control parameters.

[0090] Among them, the server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0091] In an exemplary embodiment, as Figure 2 shown, a network threat defense optimization method is provided. Taking the method applied to Figure 1 the server 102 therein as an example for illustration, it includes the following steps S201 to S205. Among them:

[0092] Step S201: Obtain the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized.

[0093] Among them, the system topology structure data may include node data and edge data. The node data includes, but is not limited to, generator nodes (such as thermal power generators, wind turbines, solar photovoltaic panels, etc.), energy storage device nodes (such as battery energy storage systems, supercapacitors, etc.), load nodes (such as industrial loads, residential loads, commercial loads, etc.), inverter nodes (if there is power conversion involving solar energy or energy storage systems), and the edge data includes, but is not limited to, transmission lines (power transmission lines between power generation equipment and load nodes), energy storage connections (connection relationships between energy storage devices and other nodes), and grid connection relationships (power flow paths between different nodes).

[0094] The system operation data may include power generation data, load data, energy storage device data, and inverter output data. The power generation data includes, but is not limited to, the generator output power (the power generation capacity data of each generator, including real-time power generation and predicted power generation), solar power generation prediction data (solar power generation amount obtained based on a meteorological prediction model), and wind power generation data (real-time and predicted data of wind power generation); the load data includes, but is not limited to, load prediction data (predicted data of the future load demand of the system), historical load data (real-time monitoring data of the load), and demand fluctuation data (time series data of load mutation and fluctuation); the energy storage device data includes, but is not limited to, the charge and discharge state of the energy storage device (the capacity and charge and discharge rate of the energy storage device), and battery usage data (charge / discharge cycle and health status of the battery); the inverter output data includes, but is not limited to, the power output of the inverter (the power transferred from the photovoltaic panel or the energy storage device), and the inverter efficiency and performance indicators (the working state, conversion efficiency, and output power of the inverter).

[0095] The environmental meteorological data includes, but is not limited to, meteorological data (radiation intensity, temperature, wind speed, etc.) and weather prediction data; the historical event and fault data includes, but is not limited to, historical fault data (fault records of various devices) and system event logs (abnormal events occurring during the operation of the system); the system parameters can be understood as the characteristics used to describe the variable or fixed quantity in a system; the control parameters can be understood as the variables used to describe and define the characteristics and behaviors of the system, such as gain, delay, impedance, pressure, etc.

[0096] Optionally, the server 102 obtains the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized, and obtains the system-related data of the cyber-physical system, laying a solid data foundation for subsequent indicator construction and adversarial scenario simulation. At the same time, using a large amount of data as the construction basis enhances the generality and accuracy of the elastic indicators and simulation data.

[0097] Step S202, generate multiple adversarial scenarios based on the system operation data, environmental meteorological data, historical events, and fault data.

[0098] Exemplarily, based on system operation data, environmental meteorology, historical events, and fault data, the server 102 obtains solar energy prediction errors, power generation losses, and demand prediction errors. Then, using the Latin Hypercube Sampling method, it perturbs the solar energy prediction errors, power generation losses, and demand prediction errors respectively to obtain multiple different solar energy prediction attack scenarios, power generation loss attack scenarios, and demand prediction attack scenarios. By combining any one solar energy prediction attack scenario, any one power generation loss attack scenario, and any one demand prediction attack scenario, multiple adversarial scenarios are constructed. Using the Latin Hypercube Sampling method to generate multiple adversarial scenarios solves the problem of single and insufficient coverage of adversarial scenario generation, thereby improving the operational stability of the system optimized using these adversarial scenarios.

[0099] Among them, Latin Hypercube Sampling (LHS) is a random sampling method used in multi-dimensional spaces, mainly for application scenarios that require effective sampling among multiple variables. Its basic idea is to divide the value range of each variable into several equally spaced intervals, and then randomly select a point from each interval.

[0100] Step S203, generate passive resilience indicators based on system topology structure data, and generate active resilience indicators corresponding to each adversarial scenario based on system operation data; the active resilience indicators are used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling control strategies under each adversarial scenario, and the passive resilience indicators are used to evaluate the robustness and stability of the cyber-physical system when control strategies are not enabled.

[0101] Among them, the passive resilience indicator can be understood as the system stability of the system's inherent properties when the system is attacked, and the active resilience indicator can be understood as an evaluation indicator for the cyber-physical system to recover from an attack to a normal operating state after enabling control strategies.

[0102] Optionally, the server 102 calculates the topological centrality indicator and topological connectivity indicator based on the system topology structure data, obtains the first weight corresponding to the topological centrality indicator and the second weight corresponding to the topological connectivity indicator, and uses the first weight and the second weight to perform weighted summation on the topological centrality indicator and the topological connectivity indicator to obtain the passive resilience indicator corresponding to the cyber-physical system. Then, based on the system operation data, it calculates the recovery ability indicator and operation constraint violation indicator, obtains the third weight corresponding to the recovery ability indicator and the fourth weight corresponding to the operation constraint violation indicator, and uses the third weight and the fourth weight to perform weighted summation on the recovery ability indicator and the operation constraint violation indicator to obtain the active resilience indicators corresponding to each adversarial scenario. Measuring the operational stability of the system by constructing the passive resilience indicator and active resilience indicator of the system facilitates the determination of the system's recovery ability and lays a foundation for subsequent parameter optimization of the system.

[0103] Step S204: For any current adversarial scenario among multiple adversarial scenarios, input the system parameters, control parameters, passive resilience metrics, and the active resilience metrics corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain the target system parameters and target control parameters when the predicted recovery ability information satisfies the pre-set constraint conditions through the optimization model.

[0104] Step S205: Update the system parameters in the cyber-physical system to the target system parameters and the control parameters to the target control parameters under the current adversarial scenario.

[0105] Among them, the predicted recovery ability information can be understood as the quantitative expression information of the predicted recovery ability of a system with corresponding system parameters, control parameters, passive resilience metrics, and the active resilience metrics corresponding to the current adversarial scenario after being attacked under the current adversarial scenario.

[0106] Exemplarily, for any current adversarial scenario among multiple adversarial scenarios, input the system parameters, control parameters, passive resilience metrics, and the active resilience metrics corresponding to the current adversarial scenario into a pre-constructed optimization model, and obtain the target system parameters and target control parameters when the predicted recovery ability information satisfies the pre-set constraint conditions through the optimization model. Server 102 updates the system parameters in the cyber-physical system to the target system parameters and target control parameters under the current adversarial scenario. By setting constraint conditions, it is ensured that the recovery ability information of the cyber-physical system under the current adversarial scenario meets the requirements, guaranteeing the timeliness and stability of the user demand response in the system. By constructing a co-designed detection and optimization method, combining system performance and resilience metrics, dynamically adjusting system parameters and control strategies, real-time optimization under different attack modes is achieved. This method significantly improves the recovery ability of the system in multiple adversarial situations, can cope with complex and changeable cyber-attacks, and solves the problems of insufficient system recovery ability and slow response in the prior art.

[0107] In the above network threat defense optimization method, system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized are obtained. Based on the system operation data, environmental meteorological data, historical events, and fault data, multiple adversarial scenarios are generated. A passive resilience index is generated according to the system topology structure data, and an active resilience index corresponding to each adversarial scenario is generated based on the system operation data. The active resilience index is used to evaluate the recovery ability and constraint violation situation of the cyber-physical system after enabling the control strategy under each adversarial scenario, and the passive resilience index is used to evaluate the robustness and stability of the cyber-physical system when the control strategy is not enabled. For any current adversarial scenario among the multiple adversarial scenarios, the system parameters, control parameters, passive resilience index, and the active resilience index corresponding to the current adversarial scenario are input into the pre-constructed optimization model. When the predicted recovery ability information obtained through the optimization model meets the pre-set constraint conditions, the target system parameters and target control parameters are obtained. The system parameters in the cyber-physical system under the current adversarial scenario are updated to the target system parameters, and the control parameters are updated to the target control parameters. Multiple adversarial scenarios are simulated and generated. The optimization model is used to obtain the target system parameters and target control parameters under the current adversarial scenario, and the parameters under the current adversarial scenario are adjusted correspondingly, thereby enhancing the anti-attack ability and recovery ability of the cyber-physical system and improving the operation stability of the system under different adversarial scenarios.

[0108] In one embodiment, obtaining the target system parameters and target control parameters when the predicted recovery ability information obtained through the optimization model meets the pre-set constraint conditions includes:

[0109] Through the optimization model, obtain the predicted recovery ability information of the cyber-physical system under the current adversarial scenario; obtain the absolute value of the difference between the predicted recovery ability information and the lowest threshold of the recovery ability information pre-set in the optimization model;

[0110] When the absolute value of the difference does not exceed the pre-set absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value, determine the system parameters as the target system parameters and the control parameters as the control parameters;

[0111] When the absolute value of the difference exceeds the absolute value threshold of the difference and the predicted recovery ability information is less than the lowest threshold of the recovery ability information, the system parameters and control parameters are correspondingly increased through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value. The increased system parameters are determined as the target system parameters, and the increased control parameters are determined as the target control parameters; if the absolute value of the difference exceeds the absolute value threshold of the difference and the predicted recovery ability information is greater than the lowest threshold of the recovery ability information, the system parameters and control parameters are correspondingly decreased through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value. The decreased system parameters are determined as the target system parameters, and the decreased control parameters are determined as the target control parameters.

[0112] Exemplarily, the process of dynamically adjusting parameters is as follows: According to the prediction result of the Gaussian process model, the system parameter s and the control parameter c are optimized in real time according to the recovery ability; the recovery ability R(s, c, a) is a key index for the system to recover after encountering the attack mode a. To maintain the adaptability and stability of the system, the expected lowest threshold R of the recovery ability is first defined min , and this value can be set according to the fault tolerance requirements and actual needs of the system design. For example, it is usually set as the target value of the system recovery time or adjusted according to the actual scenario:

[0113] When |R(s, c, a) - R min | ≤ 0.01, the recovery ability is close to the expected threshold, and the system already meets the performance requirements, so no adjustment is needed;

[0114] When |R(s, c, a) - R min | > 0.01, if the recovery ability is lower than the expectation (R(s, c, a) < Rmin), the parameters s and c are increased to increase the system redundancy and recovery ability. The formula is δ recovery = R min - R(s, c, a) s new = s old + γ 1 · δ recovery c new = c old + γ 2 · δ recovery where γ 1 and γ 2 control the adjustment step size and are set according to the system requirements; if the recovery ability is too high (R(s, c, a) > Rmin), the parameters s and c are decreased. The formula is δ recovery = R min - R(s, c, a), s new = s old + γ 1·δ recovery ,c new =c old +γ 2 ·δ recovery 。

[0115] The optimization objective is:

[0116]

[0117] where s and c represent the system and control parameters respectively, a is the attack mode, is a set of adversarial scenarios, and φ passive,i (s, c) represents the i-th passive resilience metric, and φ active,j (s, c, a) represents the j-th active resilience metric. α i , β j are the weight coefficients of the passive and active resilience metrics respectively;

[0118] The predicted recovery ability information corresponding to the adjusted system parameters and control parameters obtained above needs to satisfy the constraint conditions:

[0119]

[0120] where R(s, c, a) represents the recovery ability of the system under the given parameters s and control c in the attack mode a, and it must meet the recoverability requirements of the system in any adversarial situation. Through the above method of dynamically adjusting parameters, the system can:

[0121] 1. Improve the recovery ability: quickly recover to the normal operating state after being attacked.

[0122] 2. Enhance adaptability: flexibly adjust the system and control parameters according to the real-time monitored recovery ability to adapt to different attack modes.

[0123] 3. Optimize the performance: avoid excessive redundancy and improve the overall performance of the system while meeting the recovery ability requirements.

[0124] In one of the embodiments, the optimization model is trained through the following steps: obtaining sample system topology structure data, sample system operation data, sample environmental meteorological data, sample historical events, sample fault data, sample system parameters, and sample control parameters of the cyber-physical system; generating a plurality of sample adversarial scenarios based on the sample system operation data, sample environmental meteorological data, sample historical events, and sample fault data; generating sample passive resilience indicators according to the sample system topology structure data, and generating sample active resilience indicators corresponding to each adversarial scenario based on the sample system operation data; using a preset performance mapping function to map the sample system parameters, sample control parameters, sample passive resilience indicators, and each sample active resilience indicator to obtain a plurality of recovery ability information of the cyber-physical system; constructing a plurality of sample input variables according to the sample system parameters, sample control parameters, sample passive resilience indicators, and each sample active resilience indicator, and inputting the plurality of sample input variables into the optimization model to be trained to obtain corresponding predicted recovery ability information; obtaining the covariance between the sample system parameters, sample control parameters, and their corresponding sample input variables through the covariance function in the optimization model to be trained; updating the covariance function based on the covariance, predicted recovery ability information, and recovery ability information until the similarity between the predicted recovery ability information and the recovery ability information meets the preset condition, and obtaining the trained optimization model.

[0125] Optionally, use Gaussian Process (GP) to model the system performance and resilience indicators, and perform dynamic parameter adjustment on this basis to evaluate the recovery ability of the system in real time; the specific operations include establishing a performance mapping, using Gaussian Process for non-parametric modeling, updating the model of Gaussian Process, and dynamically adjusting parameters;

[0126] The establishment of the performance mapping is to set a performance mapping function f, and map the system parameters s, control parameters c, and resilience indicators φ passive (s, c), φ active (s, c, a) to the recovery ability R(s, c, a) of the system: f: {s, c, φ passive (s, c), φ active (s, c, a)} → R(s, c, a). The function of this mapping function is to convert different input parameter combinations (system configuration, control strategy, and resilience indicators) into corresponding system recovery abilities;

[0127] The use of Gaussian Process for non-parametric modeling is to assume that the objective function R(s, c, a) follows a Gaussian process Among them, μ(x) is the predicted mean function, which represents the predicted mean of the system recovery ability when the input x (a combination of system parameters s and control parameters c) is given; ∑(x, x′) is the covariance function, which represents the correlation between inputs x and x′ and captures the possible change patterns of the system under different configurations; the input data x is defined as (s, c, φ passive (s, c), φ active (s, c, a)), which is the state vector of the system; the output data y = R(s, c, a), which is the target value corresponding to the input data x; the training data set of the Gaussian process is a set of known observed data Among them, X n is the input data, and Y n is the corresponding target value:

[0128] X n =(s n , c n , φ passive (s n , c n ), φ active (s n , c n , a n ))

[0129] Y n =R(s n , c n , a n )

[0130] The model of the Gaussian process is updated as follows: after obtaining the initial observed data, the update formula of the Gaussian process is used to adjust and optimize the model:

[0131]

[0132] Among them, μ(x) is the previous mean prediction, ∑(x, X n ) is the covariance between the input point x and the known data X n , and Y n is the actual target value corresponding to X n ; the role of this update formula is to correct the mean prediction of the model according to the observed data so that it can more accurately reflect the system recovery ability;

[0133]

[0134] This formula is used to update the covariance function to ensure that it can better describe the correlation between input data, thereby improving the prediction ability of the model. By continuously updating the mean and covariance functions, the Gaussian process can gradually adjust and optimize the model according to new observed data to provide more accurate predictions.

[0135] In an exemplary embodiment, the system topology structure data includes nodes and edges; generating a passive resilience metric based on the system topology structure data, including: obtaining a topological centrality metric associated with the cyber-physical system according to the number of edges connected to any current node and the total number of nodes; obtaining a topological connectivity metric associated with the cyber-physical system based on the total number of edges and the total number of nodes; obtaining a first weight corresponding to the topological centrality metric and a second weight corresponding to the topological connectivity metric; using the first weight and the second weight to perform a weighted sum of the topological centrality metric and the topological connectivity metric to obtain the passive resilience metric.

[0136] Exemplarily, the passive resilience metric is used to evaluate the robustness and stability of the system when the activation control strategy does not occur. The specific operations include calculating topological centrality, topological connectivity, and synthesizing the passive resilience metric; calculating topological centrality:

[0137]

[0138] Among them, C degree (s, i) is the degree centrality of node i under system parameter d, deg(s, i) is the degree of node i under system parameter s (i.e., the number of edges connected to node i), and N(s) is the total number of nodes under system parameter s; calculating topological connectivity:

[0139]

[0140] Among them, C connecyivty (s) is the connectivity metric under system parameter s, E(s) is the number of edges under system parameter s, and N(s) is the total number of nodes under system parameter s; synthesizing the passive resilience metric φ passive (s,c) = α 1 ·C degree (s) + α 2 ·C conneciviy (S), where φ passive (s, c) is the passive resilience metric, α 1 and α 2 are weight coefficients that control the contribution of each metric to the overall passive resilience metric. Constructing the passive resilience metric by combining the topological centrality metric and the topological connectivity metric, the constructed passive resilience metric can effectively evaluate the system robustness in the face of node or edge failures.

[0141] In one embodiment, the system operation data includes the recovery time required for the cyber-physical system, the total operation time, and the constraint violation indication function in each adversarial scenario; when any current constraint is violated, the constraint violation indication function corresponding to the current constraint is 1, and when any current constraint is not violated, the constraint violation indication function corresponding to the current constraint is 0;

[0142] Generate active resilience metrics corresponding to each adversarial scenario based on system operation data, including: obtaining the recovery ability metric corresponding to each adversarial scenario by dividing the time required for recovery by the total operation time; summing the constraint violation metric functions corresponding to each constraint in the cyber-physical system to obtain the operation constraint violation metric corresponding to each adversarial scenario; obtaining the third weight corresponding to the recovery ability metric and the fourth weight corresponding to the operation constraint violation metric; and performing a weighted sum of the recovery ability metric and the operation constraint violation metric according to the third weight and the fourth weight to obtain the active resilience metric corresponding to each adversarial scenario.

[0143] Optionally, the active resilience metric is used to evaluate the recovery ability and constraint violation situation of the system after enabling the control strategy. The specific operations include calculating the recovery ability, operation constraint violation, and synthesizing the active resilience metric; calculating the recovery ability:

[0144]

[0145] where R recovery (s, c, a) is the recovery ability score, T recovery (s, c, a) is the time required for the system to recover under the given parameters s and attack mode a, and Ttotal is the total operation time of the system; calculating the operation constraint violation where V violation (s, c, a) is the operation constraint violation score, is the constraint violation indication function, and when the i-th constraint is violated, otherwise it is 0; synthesizing the active resilience metric φ active (s,c,a) = β 11 ·R recovery (s,c,a) + β 2 ·V violation (s,c,a), where φ active (s, c, a) is the active resilience score, β 1 and β 2 are weight coefficients that control the contribution of each metric to the overall active resilience metric. Constructing the active resilience metric by combining the recovery ability metric and the operation constraint violation metric can effectively evaluate the system recovery ability and system stability of the system when facing cyber attacks after enabling the control strategy.

[0146] In an exemplary embodiment, the system operation data includes power generation data, load data, and energy storage device data; the power generation data includes actual solar power generation data, and the load data includes expected load data, historical load data, and demand fluctuation data;

[0147] Based on system operation data, environmental meteorological data, historical events, and fault data, multiple adversarial scenarios are generated, including: inputting environmental meteorological data into a pre-constructed solar power generation prediction model to obtain corresponding solar power generation prediction data, and generating a solar power prediction error based on the actual solar power generation data and the solar power generation prediction data; obtaining power generation losses based on energy storage device data, historical events, and fault data; generating a demand prediction error based on expected load data, historical load data, and demand fluctuation data; perturbing the solar power prediction error, power generation losses, and demand prediction error to generate multiple solar power prediction attack scenarios, power generation loss attack scenarios, and demand prediction attack scenarios; generating multiple adversarial scenarios based on each solar power prediction attack scenario, power generation loss attack scenario, and demand prediction attack scenario; each adversarial scenario includes any one solar power prediction attack scenario, any one power generation loss attack scenario, and any one demand prediction attack scenario.

[0148] Exemplarily, LHS is used to perturb the solar power prediction error. Since the prediction error of solar power generation is usually affected by factors such as weather and season, and its error range is usually between -30% and +30%, therefore, a perturbation factor δ is generated within the normalized interval [0, 1] through LHS. solar , and it is mapped to the range of [-0.3, 0.3]. The formula is δ solar = (LHS sampled · 0.6) - 0.3 where LHS sampled is the perturbation factor obtained by Latin Hypercube Sampling, with a range of [0, 1]. After mapping, the actual value range of the perturbation factor δ solar is [-0.3, 0.3]; calculate the new solar power prediction attack perturbation scenario, and the formula is S attack= S forccast · (1 + δ solar where S attack is the perturbed solar power generation, S forecast is the original predicted value, and δ solar is the perturbation factor, simulating different solar power prediction errors; generate multiple solar power prediction attack scenarios, simulating different solar power prediction errors to ensure that the impact on the system performance is fully covered;

[0149] Use LHS to perturb the power generation losses. Since power generation loss attacks usually manifest as equipment failures or insufficient output, and usually the loss amplitude is between -20% and -50%, therefore, a perturbation factor δ is generated within the normalized interval [0, 1] through LHS. gen , and it is mapped to the range of [-0.5, 0]. The formula is δ gen = (LHS sampled · 0.5) - 0.5, where LHS sampledThe perturbation factor obtained by Latin Hypercube Sampling ranges from [0, 1], and after mapping, the perturbation factor δ is obtained. gen The actual value range of is [-0.5, 0]; calculate the new power generation loss attack perturbation scenario, and the formula is P attack = P base ·(1 + δ gen ), where P attack is the perturbed power generation, P base is the original power generation, and δ gen is the perturbation factor, simulating different power generation losses; generate multiple power generation loss attack scenarios, simulating different power generation loss attacks to ensure that the system can handle multiple power generation loss situations;

[0150] Use LHS to perturb the demand prediction error. Since the load prediction error is usually between -20% and +20%, and its fluctuation range is relatively limited. Therefore, the perturbation factor δ load is generated within the normalized interval [0, 1] through LHS, load and mapped to the range of [-0.2, 0.2]. The formula is δ sampled = (LHS sampled ·0.4) - 0.2, where LHS load is the perturbation factor obtained by Latin Hypercube Sampling, with a range of [0, 1], and after mapping, the perturbation factor δ attack is obtained. The actual value range of δ base is [-0.2, 0.2]; calculate the new demand prediction attack perturbation scenario, and the formula is L load = L attack ·(1 + δ base ), where L load is the perturbed load, L

[0151] Let Δ solar be the set of perturbation factors for solar prediction error, Δ gen be the set of perturbation factors for power generation loss, and Δ load be the set of perturbation factors for demand prediction error. Each adversarial scenario can be represented as a triple (Δ solar , Δ gen , Δ load ), and the adversarial scenario is:

[0152]

[0153] These combinations represent all possible perturbation combinations, that is, the set of all possible adversarial scenarios Each scenario includes the perturbation conditions of different perturbation factors and can simulate different adversarial situations.

[0154] Based on the Latin Hypercube Sampling (LHS) technique, multiple adversarial scenarios can be generated. By simulating different attack modes (such as power generation loss, solar power prediction error, load perturbation, etc.), the adaptability and stability of the system under various network threats can be effectively tested, solving the problems of single generation of adversarial scenarios and insufficient coverage in traditional methods.

[0155] In one embodiment, after updating the system parameters in the cyber-physical system to the target system parameters and the control parameters to the target control parameters under the current adversarial scenario, the method further includes:

[0156] Obtain the system feedback data of the cyber-physical system under each adversarial scenario; use the system feedback data and the pre-constructed evaluation metrics to calculate the metrics, and obtain the evaluation metric data under each adversarial scenario; generate an evaluation report of the cyber-physical system according to the evaluation metric data and send the evaluation report to the user terminal.

[0157] Optionally, construct an evaluation metric system and calculate the system operation cost where c i is the unit operation cost of device i, and p i (t) is the output power of device i at time t; calculate the supply-demand balance degree where p gen (t) is the power generation, and p load (t) is the load demand; calculate the system stability where is the voltage violation event indicator function; calculate the device reliability where λ i is the failure rate of device i;

[0158] For each adversarial scenario Use the optimized system parameters s and control parameters c in step S3 for simulation, and record the system response data, including the power generation curve p gen (t), the load demand curve p load (t), the energy storage state SOC(t), and the device operation state data;

[0159] Define the evaluation function E(s, c, a) = w 1 ·C operation + w 2 ·B blance + w 3 ·S stability + ·w 4 ·R reliability and calculate the expected score Among them, w 1 , w 2 , w 3 , w 4 is the weight coefficient of the evaluation index, and is the size of the set of adversarial scenarios;

[0160] Generate an evaluation report, including system performance evaluation (statistics of performance indicators under different adversarial scenarios, analysis of system response time, cost-benefit analysis), optimization effect evaluation (performance comparison before and after optimization, parameter sensitivity analysis, analysis of system resilience improvement), and security evaluation (system stability analysis, fault recovery ability analysis, risk assessment report).

[0161] By constructing a detailed evaluation index system, comprehensively evaluate the operating cost, supply-demand balance, stability, and equipment reliability of the system to ensure that the system can maintain high efficiency and security under various adversarial scenarios, thereby significantly improving the comprehensive performance of the system and solving the problems of incomplete evaluation criteria and overly simple evaluation methods in the prior art.

[0162] In one embodiment, before obtaining the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized, it includes: obtaining the original system topology structure data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters of the cyber-physical system; the data types of the original system topology structure data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters are any one of numerical data, categorical data, and time series data; removing duplicate data, error data, and missing data from the numerical data, categorical data, and time series data to obtain the cleaned numerical data, categorical data, and time series data; performing min-max normalization on the cleaned numerical data column by column to obtain the normalized numerical data, performing data conversion on the cleaned categorical data through one-hot encoding or label encoding to obtain the converted categorical data, and using a smoothing technique to remove the high-frequency fluctuations in the cleaned time series data to obtain the removed time series data; performing normalization processing on the normalized numerical data, converted categorical data, and removed time series data to obtain the processed numerical data, categorical data, and time series data.

[0163] Exemplarily, based on system topology data, system operation data, environmental and meteorological data, historical event and fault data, as well as control strategy and scheduling data, with the goal of the accuracy of data preprocessing, data cleaning, removing duplicates and error data are performed, and operations such as filling missing values, deleting outliers, and smoothing time series data are adopted to construct normalized and smoothed preprocessed data.

[0164] Furthermore, specifically:

[0165] 1. Collect the topology data of the system, the operation data of the system, environmental and meteorological data, historical event and fault data, as well as control strategy and scheduling data;

[0166] 2. Perform data cleaning, remove duplicates, error data and missing values to ensure the accuracy of the data. Common methods include filling missing values (such as using the mean to fill, interpolation, etc.), deleting records containing outliers, or using data imputation methods for processing;

[0167] 3. Perform min-max normalization (Min-Max Scaling) on numerical data (such as system load, power generation, etc.) column by column to map the data values to between 0 and 1; for categorical data (such as equipment status, event type, etc.), convert it through one-hot encoding or label encoding; for time series data with noise, adopt smoothing techniques (such as moving average, exponential smoothing, etc.) to remove high-frequency fluctuations and retain valid information; finally, output the preprocessed data mapped to the interval [0,1].

[0168] Through the above data preprocessing method, the following technical effects are achieved:

[0169] 1. Through cleaning and processing, the accuracy and consistency of the data are ensured, the effectiveness and usability of the data are improved, and further the accuracy of the target system parameters and target control parameters is improved.

[0170] 2. The normalized and encoded data is more conducive to statistical analysis and machine learning modeling, making the comparison and calculation between different features more intuitive.

[0171] In an exemplary embodiment, such as Figure 3As shown in the figure, the IEEE-123 node test system is a standard model for microgrid simulation and has the ability to operate independently. This system consists of power nodes, distributed generation equipment, energy storage devices, and distribution lines, and can continue to supply power through local distributed energy after disconnecting from the main grid. This system is hosted on the GridLAB-D simulation platform, which supports the accurate modeling and control of generators, energy storage devices, and photovoltaic inverters. By adjusting the set points of the devices, various operating scenarios can be simulated (the following data are all specific examples in a certain embodiment and do not limit that the present application can only be realized in this case).

[0172] Relying on Figure 3 the basis, the network threat defense optimization method is realized through the following steps:

[0173] Step 1: Based on the system topology structure data, system operation data, environment and meteorological data, historical events and fault data, and control strategy and scheduling data, aiming at the accuracy of data preprocessing, perform data cleaning, remove duplicate items and error data, and adopt operations such as filling missing values, deleting outliers, and smoothing time series data to construct normalized and smoothed preprocessed data.

[0174] Furthermore, Step 1 is specifically as follows:

[0175] Step 101: Collect the system topology structure data, system operation data, environment and meteorological data, historical events and fault data, and control strategy and scheduling data;

[0176] Step 102: Perform data cleaning, remove duplicate items, error data, and missing values to ensure the accuracy of the data. Common methods include filling missing values (such as using the mean to fill, interpolation, etc.), deleting records containing outliers, or using data imputation methods for processing;

[0177] Step 103: Perform min-max normalization (Min-Max caling) on numerical data (such as system load, power generation, etc.) by column, and map the data values to between 0 and 1; for categorical data (such as device status, event type, etc.), perform conversion through one-hot encoding or label encoding; for time series data with noise, use smoothing techniques (such as moving average, exponential smoothing, etc.) to remove high-frequency fluctuations and retain valid information; finally, output the preprocessed data mapped to the [0,1] interval.

[0178] Furthermore, the data collected in Step 101 includes the following content:

[0179] (1) System topology structure data, including node data and edge data;

[0180] The node data includes, but is not limited to, generator nodes (such as thermal power generators, wind turbines, solar photovoltaic panels, etc.), energy storage device nodes (such as battery energy storage systems, supercapacitors, etc.), load nodes (such as industrial loads, residential loads, commercial loads, etc.), and inverter nodes (if power conversion involving solar energy or energy storage systems);

[0181] The edge data includes, but is not limited to, transmission lines (power transmission lines between power generation equipment and load nodes), energy storage connections (connection relationships between energy storage devices and other nodes), and power grid connection relationships (power flow paths between different nodes);

[0182] (2) System operation data, including power generation data, load data, energy storage device data, and inverter output data;

[0183] The power generation data includes, but is not limited to, the generator output power P base (the power generation capacity data of each generator, including real-time power generation and predicted power generation), solar power generation prediction data S forecast (solar power generation obtained based on a meteorological prediction model), wind power generation data (real-time and predicted data of wind power generation);

[0184] The load data includes, but is not limited to, load prediction data L forecast (the system's predicted data for future load demand), historical load data L base (real-time monitoring data of the load), demand fluctuation data (time series data of load mutations and fluctuations);

[0185] The energy storage device data includes, but is not limited to, the charge and discharge status of the energy storage device (the capacity and charge / discharge rate of the energy storage device), and battery usage data (the charge / discharge cycle and health status of the battery);

[0186] The inverter output data includes, but is not limited to, the power output of the inverter (the power transferred from the photovoltaic panel or energy storage device), and the efficiency and performance indicators of the inverter (the working status, conversion efficiency, and output power of the inverter);

[0187] (3) Environmental and meteorological data, including, but is not limited to, meteorological data (radiation intensity, temperature, wind speed, etc.), and weather prediction data;

[0188] (4) Historical event and fault data, including, but is not limited to, historical fault data (fault records of various equipment), and system event logs (abnormal events occurring during system operation);

[0189] Step 2: Based on the data preprocessed in Step 1, construct a set of perturbation factors for solar power prediction error, power generation loss, and demand prediction error. Aiming to generate multiple adversarial scenarios, use the Latin hypercube sampling method to perturb various errors, construct different solar power prediction attack scenarios, power generation loss attack scenarios, and demand prediction attack scenarios, and finally generate an adversarial scenario set to simulate various possible adversarial situations.

[0190] Further, Step 2 is specifically as follows:

[0191] Step 201: Perturb the solar power prediction error using LH. Since the prediction error of solar power generation is usually affected by factors such as weather and season, and its error range is usually between -30% and +30%, therefore, generate a perturbation factor δ within the normalized interval [0, 1] through LH solar , and map it to the range of [-0.3, 0.3]. The formula is δ solar = (LHS sampled · 0.6) - 0.3, where LHS sampled is the perturbation factor obtained by Latin hypercube sampling, with a range of [0, 1]. After mapping, the actual value range of the perturbation factor δ solar is [-0.3, 0.3]; calculate the new solar power prediction attack perturbation scenario, and the formula is S attack = S forecast · (1 + δ solar ), where S attack is the perturbed solar power generation, S forecast is the original predicted value, and δ solar is the perturbation factor, simulating different solar power prediction errors; generate multiple solar power prediction attack scenarios, simulating different solar power prediction errors, to ensure that the impact on the system performance is fully covered;

[0192] Step 202: Perturb the power generation loss using LH. Since the power generation loss attack usually manifests as equipment failure or insufficient output, and usually its loss amplitude is between -20% and -50%, therefore, generate a perturbation factor δ within the normalized interval [0, 1] through LH gen , and map it to the range of [-0.5, 0]. The formula is δ gen = (LHS sampled · 0.5) - 0.5, where LHS sampled is the perturbation factor obtained by Latin hypercube sampling, with a range of [0, 1]. After mapping, the actual value range of the perturbation factor δ gen is [-0.5, 0]; calculate the new power generation loss attack perturbation scenario, and the formula is P attack = P base · (1 + δ gen), where P attack is the generated power after perturbation, and P base is the original generated power. δ gen is the perturbation factor, simulating different power generation losses; generating multiple power generation loss attack scenarios, simulating different power generation loss attacks, to ensure that the system can handle multiple power generation loss situations;

[0193] Step 203: Use LH to perturb the demand prediction error. Since the load prediction error is usually between -20% and +20%, and its fluctuation range is relatively limited. Therefore, a perturbation factor δ load is generated within the normalized interval [0, 1] by LH, load and mapped to the range of [-0.2, 0.2]. The formula is δ sampled = (LHS sampled ·0.4) - 0.2, where LHS load is the perturbation factor obtained by Latin hypercube sampling, with a range of [0, 1]. After mapping, the actual value range of the perturbation factor δ attack is [-0.2, 0.2]; calculate the new demand prediction attack perturbation scenario, and the formula is L base = L load ·(1 + δ attack ), where L base is the perturbed load, L load is the original load value, and δ solar is the perturbation factor, simulating different load prediction errors; generating multiple demand prediction attack scenarios, simulating different load prediction errors, to ensure that the system can handle multiple load fluctuations;

[0194] Step 204: Let Δ gen be the set of perturbation factors for solar prediction errors, Δ load be the set of perturbation factors for power generation losses, and Δ solar be the set of perturbation factors for demand prediction errors. Each adversarial scenario can be represented as a triple (Δ gen , Δ load ), and the adversarial scenario is:

[0195]

[0196] These combinations represent all possible perturbation combinations, that is, the set of all possible adversarial scenarios Each scenario includes the perturbation conditions of different perturbation factors and can simulate different adversarial situations.

[0197] Step 3: Based on system performance, elasticity metrics, and recovery capabilities, with the goal of optimizing the system's recovery capabilities under different attack scenarios, design a co - designed detection method, define the system optimization objectives, and use Gaussian processes for modeling. Real - time evaluate the system's recovery capabilities by dynamically adjusting parameters, and finally achieve the optimization and adjustment of system parameters and control parameters to ensure that the system can maintain adaptability and stability in the face of various adversarial situations.

[0198] Step 301: First, define the system optimization objectives and construct a co - designed detection method. The optimization objectives are:

[0199]

[0200] where s and c represent system and control parameters respectively, a is the attack mode, is a set of adversarial scenarios, φ passive,i (s, c) represents the i - th passive elasticity metric, φ active,j( (s, c, a) represents the j - th active elasticity metric, α i , β j are the weight coefficients of passive and active elasticity metrics respectively;

[0201] The constraint conditions are:

[0202]

[0203] where R(s, c, a) represents the recovery capability of the system under the given parameters s and control c in the attack mode a, and must meet the recoverability requirements of the system in any adversarial situation;

[0204] Step 302: Use Gaussian Process (GP) to model system performance and elasticity metrics, and on this basis, perform dynamic parameter adjustment to real - time evaluate the system's recovery capabilities; the specific operations include establishing a performance mapping, using Gaussian processes for non - parametric modeling, updating the Gaussian process model, and dynamically adjusting parameters;

[0205] The establishment of the performance mapping is as follows: Set the performance mapping function f, and map the system parameters s, control parameters c, and elasticity metrics φ passive (s, c), φ active (s, c, a) to the recovery capability R(s, c, a) of the system: f: {s, c, φ passive (s, c), φ active (s, c, a)} → R(s, c, a). The role of this mapping function is to convert different combinations of input parameters (system configuration, control strategy, and elasticity metrics) into the corresponding system recovery capabilities;

[0206] The non-parametric modeling using the Gaussian process is as follows: assume that the objective function R(s, c, a) follows a Gaussian process where μ(x) is the predicted mean function, representing the predicted mean of the system recovery ability when the given input x (a combination of system parameters s and control parameters c); Σ(x, x′) is the covariance function, representing the correlation between inputs x and x′, capturing the possible change patterns of the system under different configurations; define the input data x = (s, c, φ passive (s, c), φ active (s, c, a)), as the state vector of the system; the output data y = R(s, c, a), as the target value corresponding to the input data x; the training data set of the Gaussian process is a set of known observation data where X n is the input data and Y n is the corresponding target value:

[0207] X n =(s n , c n , φ passive (s n , c n ), φ activ e(s n , c n , a n ))

[0208] Y n =R(s n , c n , a n )

[0209] The model update of the Gaussian process is as follows: after obtaining the initial observation data, use the update formula of the Gaussian process to adjust and optimize the model:

[0210]

[0211] where μ(x) is the previous mean prediction, ∑(x, X n ) is the covariance between the input point x and the known data X n , Y n is the actual target value corresponding to X n ; the role of this update formula is to correct the mean prediction of the model according to the observation data to make it more accurately reflect the system recovery ability;

[0212]

[0213] This formula is used to update the covariance function to ensure that it can better describe the correlation between input data, thereby improving the prediction ability of the model; by continuously updating the mean and covariance function, the Gaussian process can gradually adjust and optimize the model according to new observed data to provide more accurate predictions;

[0214] The dynamic adjustment parameters are as follows: according to the prediction results of the Gaussian process model, the system parameters s and control parameters c are optimized in real time according to the recovery ability; the recovery ability R(s, c, a) is a key indicator for the system to recover after encountering the attack mode a. To maintain the adaptability and stability of the system, first define the expected minimum threshold R of the recovery ability min , and this value can be set according to the fault tolerance requirements and actual needs of the system design. For example, it is usually set to the target value of the system recovery time or adjusted according to the actual scenario.

[0215] Furthermore, the calculation method of the passive resilience index in 301 is as follows:

[0216] The passive resilience index is used to evaluate the robustness and stability of the system when the activation control strategy does not occur. The specific operations include calculating the topological centrality, topological connectivity, and synthesizing the passive resilience index; calculating the topological centrality where C degree (s, i) is the degree centrality of node i under the system parameter d, deg(s, i) is the degree of node i under the system parameter (i.e., the number of edges connected to node i), and N(s) is the total number of nodes under the system parameter; calculating the topological connectivity where C connecyiviy (s) is the connectivity index under the system parameter, E(s) is the number of edges under the system parameter, and N(s) is the total number of nodes under the system parameter; synthesizing the passive resilience index φ passive (s, c) = α 1 ·C agree (s) + α 2 ·C connectivty (s), where φ passive (s, c) is the passive resilience index, α 1 and α 2 are weight coefficients that control the contribution of each index to the overall passive resilience index;

[0217] Furthermore, the calculation method of the active resilience index in 301 is as follows:

[0218] The active resilience index is used to evaluate the recovery ability and constraint violation situation of the system after enabling the control strategy. The specific operations include calculating the recovery ability, operation constraint violation, and synthesizing the active resilience index; calculating the recovery ability where R recovery (s, c, a) is the recovery ability score, T recovery(s, c, a) is the time required for system recovery under given parameters and attack mode a, T total is the total running time of the system; calculate operation constraint violations where V violation (s, c, a) is the operation constraint violation score, is the constraint violation indication function. When the i-th constraint is violated, otherwise it is 0; synthesize the active resilience index φ active (s,c,a) = β 1 ·R recovery (s,c,a) + β 2 ·V violation (s,c,a), where φ active (s, c, a) is the active resilience score, β 1 and β 2 are weight coefficients that control the contribution of each index to the overall active resilience index;

[0219] Furthermore, the method for dynamically adjusting parameters in 302 is as follows:

[0220] When |R(s, c, a) - R min | ≤ 0.01, the recovery ability is close to the expected threshold, and the system already meets the performance requirements, so no adjustment is needed;

[0221] When |R(s, c, a) - R min | > 0.01, if the recovery ability is lower than expected (R(s,c,a) < R min ), increase the parameters s and c to increase system redundancy and recovery ability. The formula is δ recovery = R min - R(s,c,a), s new = s old + γ 1 ·δ recovery , c new = c old + γ 2 ·δ recovery , where γ 1 and γ 2 control the adjustment step size and are set according to system requirements; if the recovery ability is too high (R(s,c,a) > R min ), then decrease the parameters s and c. The formula is δ recovery = R min - R(s,c,a), s new = s old + γ 1 ·δ recovery , c new = c old γ 2 ·δrecovery 。

[0222] Step 4: Based on the operation data, evaluation metrics, and optimization results of the system, with the goal of evaluating the comprehensive performance of the system under different adversarial scenarios, construct an evaluation metric system and conduct simulation evaluations. Calculate the operation cost, supply-demand balance degree, stability, and equipment reliability of the system, and finally generate a comprehensive evaluation report to provide multi-dimensional analysis and optimization feedback on performance, optimization effect, and security, etc.

[0223] Further, Step 4 is specifically as follows:

[0224] Step 401: Construct an evaluation metric system and calculate the operation cost of the system where c i is the unit operation cost of device i, and p i (t) is the output power of device i at time t; calculate the supply-demand balance degree where p gen (t) is the power generation, and p load (t) is the load demand; calculate the system stability where is the voltage violation event indicator function; calculate the equipment reliability where λ i is the failure rate of device i;

[0225] Step 402: For each adversarial scenario Use the optimized system parameters and control parameters c from Step 3 to conduct simulations, and record the system response data, including the power generation curve p gen (t), the load demand curve P load (t), the energy storage state SOC(t), and the equipment operation state data;

[0226] Step 403: Define the evaluation function E(s, c, a) = w 1 ·C operation + w 2 ·B blance + w 3 ·S stability + w 4 ·R reliability , and calculate the expected score where, w 1 , w 2 , w 3 , w 4 are the weight coefficients of the evaluation metrics, is the size of the set of adversarial scenarios;

[0227] Step 404: Generate an evaluation report, including system performance evaluation (statistics of performance metrics under different adversarial scenarios, analysis of system response time, cost-benefit analysis), optimization effect evaluation (performance comparison before and after optimization, parameter sensitivity analysis, analysis of system resilience improvement), and security evaluation (system stability analysis, fault recovery ability analysis, risk assessment report).

[0228] Figure 4 It is a diagram of power dispatching and power allocation of the system under different attack scenarios, showing the power changes and dispatching strategies of each component of the system (including load, diesel generator, battery, and photovoltaic) under different attack scenarios such as solar prediction attack, generation loss attack, and demand prediction attack. Figure 4 Example 1 is shown. There are problems of delay and data loss in the communication layer of the system, resulting in the failure to transmit sensor data in a timely manner, and partial information is lost during the transmission process, affecting the overall performance. Therefore, the system increases the communication frequency and selects an optimal sampling interval of 15 minutes to minimize data loss to ensure the stability of power supply. During the generation loss attack (06:00–15:00), the battery is set as the main power replenishment source, with a weight of 100, and the battery is preferentially dispatched to make up for the insufficient power generation. The power output of the battery gradually rises from 0.5 MW to 1.0 MW, ensuring that the load is stable at the 2.5 MW level. Subsequently, as the power generation returns to normal, the output of the battery gradually decreases, reflecting the effective support of the battery for system balance. During the solar prediction attack (11:00–18:00), the photovoltaic output is disturbed, and the system maintains the load power supply through the coordinated regulation of the battery and the diesel generator. Under the interference of the demand prediction attack (06:00–24:00), the system needs to adjust the battery output more frequently to ensure the smooth supply of the actual load demand. The figure shows that the load (green) is the real-time demand of the system, the diesel generator (blue) maintains a stable output of 3.5 MW most of the time, the battery (orange) is flexibly dispatched to make up for the power difference, and the photovoltaic (red) adjusts its output according to the solar prediction. Due to the problems of delay and data loss in the communication layer, the system ensures the timely transmission of control signals by increasing the communication frequency to maintain the balance between supply and demand. Although this increases the frequent use of the battery and the high power output of the diesel generator, resulting in an increase in the overall operating cost. However, this strategy enables the system to maintain resilience and stability in the face of poor communication and various attack scenarios, achieving continuous load supply.

[0229] Figure 5 It is a diagram of power dispatching and power allocation of the system under multiple attack scenarios in an ideal communication environment, showing the power output and dispatching strategies of devices such as diesel generators, batteries, and photovoltaics under different attack scenarios such as generation loss attack, demand prediction attack, and solar prediction attack. Figure 5Example 2 is shown. The communication environment of the system is ideal, without data loss or delay, ensuring stable transmission of data and control instructions. Therefore, the system no longer needs to communicate frequently to resist data loss, and the sampling interval is optimized from 15 minutes in the previous scenario to 30 minutes, thus reducing the communication burden and computational pressure and making the system run more efficiently. In this communication environment, the overall power generation capacity of the system is expanded, and the ability to cope with adversarial attacks is enhanced. During the generation loss attack (06:00–18:00), the diesel generator maintains a stable output of nearly 3.5 MW, effectively meeting the load demand; during the demand forecasting attack (06:00–24:00), although the load forecasting is disturbed, the system reasonably schedules the power generation equipment to ensure that the load remains at a stable level of about 1.5 MW; during the solar forecasting attack (10:30–19:00), the power fluctuation of solar photovoltaics affects the power generation capacity, and the system ensures the stable supply of the load through the reasonable scheduling of the diesel generator and the battery. The figure shows that the diesel generator undertakes most of the power generation tasks with stable power, avoiding excessive dependence on the battery, while the power output of the battery is stable at about 2.0 MW, only slightly decreasing during the solar forecasting attack and then recovering to a more stable level, avoiding frequent charging and discharging and reducing the operating cost. During the entire scheduling process, the system demonstrates high resilience and stability. By precisely controlling the scheduling of the power generation equipment, the system maintains the balance between supply and demand in the face of various attack scenarios, reduces the operating cost, and achieves efficient operation.

[0230] Figure 6 It is a diagram of the power scheduling and power distribution of the system under demand forecasting disturbance and solar forecasting disturbance, showing how the system maintains the stability of load supply by reasonably scheduling power generation resources such as diesel generators, batteries, and photovoltaics in different disturbance scenarios. Figure 6Example 3 is shown. The system mainly focuses on research regarding demand forecasting disturbances and solar energy forecasting disturbances. Since these disturbances can lead to imbalance between supply and demand, to reduce the communication burden and ensure the system's timely response to external disturbances, the sampling interval is increased to 60 minutes, ensuring stable transmission of control signals and avoiding overly frequent communication. During the demand forecasting disturbance (05:00–24:00), the system successfully maintains the load at a stable level of around 2.5 MW by reasonably dispatching the battery and diesel generator, ensuring power supply balance. The output power of the battery is relatively stable, approximately 2.5 MW, reducing frequent charging and discharging, and lowering wear and operating costs; when the solar energy forecasting disturbance (10:00–20:00) ends, the output of the battery slightly increases to further guarantee load supply. The diesel generator maintains an output of 1.0 MW during the demand disturbance, providing a basic guarantee for load supply, reducing dependence on the battery, and making fine-tuning according to photovoltaic fluctuations during the solar energy forecasting disturbance. Despite significant fluctuations in solar photovoltaics during the forecasting disturbance (10:00–20:00), the system balances supply and demand through the coordinated dispatching of the battery and diesel generator, ensuring that photovoltaic fluctuations do not affect the overall load supply. The ideal sampling interval setting and timely control strategy enable the system to exhibit high resilience and stability in the face of the two disturbances, maintaining continuous power supply, while reducing over-reliance on diesel generators, achieving higher operating efficiency and lower costs.

[0231] Compared with the prior art, the present application has the following advantages:

[0232] First, based on the Latin Hypercube Sampling (LH) technique, the present application can generate multiple adversarial scenarios. By simulating different attack modes (such as power generation loss, solar energy forecasting error, load disturbance, etc.), it effectively tests the adaptability and stability of the system under various cyber threats, solving the problems of single adversarial scenario generation and insufficient coverage in traditional methods.

[0233] Second, by constructing a co-designed detection and optimization method, combining system performance and resilience metrics, the present application dynamically adjusts system parameters and control strategies to achieve real-time optimization under different attack modes. This method significantly improves the system's recovery ability in various adversarial situations, enabling it to cope with complex and changing cyber attacks, and solving the problems of insufficient system recovery ability and slow response in the prior art.

[0234] Third, through Gaussian process modeling, the present application can non-parametrically evaluate and optimize system performance, automatically adjusting system parameters to maintain optimal recovery ability. This technology can real-time optimize system design and control strategies according to the requirements of different adversarial scenarios, effectively enhancing the system's resilience and adaptive ability, and solving the problems of manual parameter adjustment and long design cycle in traditional methods.

[0235] Fourth, by constructing a detailed evaluation index system, the present application comprehensively evaluates the operating cost, supply-demand balance, stability, and equipment reliability of the system, ensuring that the system can maintain high efficiency and security in various confrontation scenarios, thereby significantly improving the comprehensive performance of the system and solving the problems of incomplete evaluation criteria and overly simple evaluation methods in the prior art.

[0236] Fifth, the present application can provide an efficient optimization solution in diverse attack scenarios, automatically adjust system parameters and control strategies, significantly enhancing the system's defense and recovery capabilities when facing complex network threats, and providing a more comprehensive and efficient solution for ensuring network security.

[0237] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least some of the steps or stages in other steps or other steps.

[0238] Based on the same inventive concept, the embodiments of the present application also provide a network threat defense optimization device for implementing the above-mentioned network threat defense optimization method. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the network threat defense optimization device provided below can refer to the limitations on the network threat defense optimization method in the above text and will not be elaborated here.

[0239] In an exemplary embodiment, as Figure 7 shown, a network threat defense optimization device is provided, including: a data acquisition module 701, a scenario generation module 702, an index construction module 703, a target parameter acquisition module 704, and a parameter update module 705, where:

[0240] The data acquisition module 701 is configured to acquire the system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, and control parameters of the cyber-physical system to be optimized;

[0241] The scenario generation module 702 is configured to generate multiple confrontation scenarios based on the system operation data, environmental meteorological data, historical events, and fault data;

[0242] The index construction module 703 is used to generate passive resilience indexes based on system topology structure data and generate active resilience indexes corresponding to respective confrontation scenarios based on system operation data; the active resilience indexes are used to evaluate the recovery ability and constraint violation conditions of the cyber-physical system after enabling control strategies under respective confrontation scenarios, and the passive resilience indexes are used to evaluate the robustness and stability of the cyber-physical system when control strategies are not enabled;

[0243] The target parameter acquisition module 704 is used to input system parameters, control parameters, passive resilience indexes, and active resilience indexes corresponding to a current confrontation scenario among multiple confrontation scenarios into a pre-constructed optimization model, and obtain target system parameters and target control parameters when the predicted recovery ability information meets preset constraint conditions through the optimization model;

[0244] The parameter update module 705 is used to update the system parameters in the cyber-physical system under the current confrontation scenario to the target system parameters and update the control parameters to the target control parameters.

[0245] In one embodiment, the target parameter acquisition module 704 is further used to obtain the predicted recovery ability information of the cyber-physical system under the current confrontation scenario through the optimization model; obtain the absolute value of the difference between the predicted recovery ability information and the lowest threshold of the recovery ability information preset in the optimization model; when the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value, determine the system parameters as the target system parameters and determine the control parameters as the control parameters; when the absolute value of the difference exceeds the absolute value threshold of the difference and the predicted recovery ability information is less than the lowest threshold of the recovery ability information, correspondingly increase the system parameters and control parameters through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value, and determine the increased system parameters as the target system parameters and determine the increased control parameters as the target control parameters; if the absolute value of the difference exceeds the absolute value threshold of the difference and the predicted recovery ability information is greater than the lowest threshold of the recovery ability information, correspondingly decrease the system parameters and control parameters through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery ability information is greater than the preset value, and determine the decreased system parameters as the target system parameters and determine the decreased control parameters as the target control parameters.

[0246] In one embodiment, the network threat defense optimization device further includes a model training module, configured to obtain sample system topology structure data, sample system operation data, sample environmental meteorological data, sample historical events, sample fault data, sample system parameters, and sample control parameters of the cyber-physical system; generate a plurality of sample adversarial scenarios based on the sample system operation data, sample environmental meteorological data, sample historical events, and sample fault data; generate a sample passive resilience index according to the sample system topology structure data, and generate a sample active resilience index corresponding to each adversarial scenario based on the sample system operation data; use a preset performance mapping function to map the sample system parameters, sample control parameters, sample passive resilience index, and each sample active resilience index to obtain a plurality of recovery ability information of the cyber-physical system; construct a plurality of sample input variables according to the sample system parameters, sample control parameters, sample passive resilience index, and each sample active resilience index, and input the plurality of sample input variables into an optimization model to be trained to obtain corresponding predicted recovery ability information; obtain the covariance between the sample system parameters, sample control parameters, and their corresponding sample input variables through the covariance function in the optimization model to be trained; update the covariance function based on the covariance, predicted recovery ability information, and recovery ability information until the similarity between the predicted recovery ability information and the recovery ability information meets a preset condition, and obtain a trained optimization model.

[0247] In an exemplary embodiment, the system topology structure data includes nodes and edges. The index construction module 703 includes a passive resilience index construction sub-module, configured to obtain the topology centrality index associated with the cyber-physical system according to the number of edges connected to any current node and the total number of nodes; obtain the topology connectivity index associated with the cyber-physical system based on the total number of edges and the total number of nodes; obtain the first weight corresponding to the topology centrality index and the second weight corresponding to the topology connectivity index; use the first weight and the second weight to perform a weighted sum of the topology centrality index and the topology connectivity index to obtain the passive resilience index.

[0248] In one embodiment, the system operation data includes the time required for the recovery of the cyber-physical system, the total operation time, and the constraint violation indication function in each adversarial scenario; when any current constraint is violated, the constraint violation indication function corresponding to the current constraint is 1, and when any current constraint is not violated, the constraint violation indication function corresponding to the current constraint is 0. The metric construction module 703 further includes an active resilience metric construction sub-module, which is used to obtain the recovery ability metric corresponding to each adversarial scenario by dividing the time required for recovery by the total operation time; sum up the constraint violation metric functions corresponding to each constraint in the cyber-physical system to obtain the operation constraint violation metric corresponding to each adversarial scenario; obtain the third weight corresponding to the recovery ability metric and the fourth weight corresponding to the operation constraint violation metric; and perform weighted summation on the recovery ability metric and the operation constraint violation metric according to the third weight and the fourth weight to obtain the active resilience metric corresponding to each adversarial scenario.

[0249] In one of the embodiments, the system operation data includes power generation data, load data, and energy storage device data. The power generation data includes the actual solar power generation data. The load data includes the expected load data, historical load data, and demand fluctuation data. The scenario generation module 702 is further configured to input the environmental meteorological data into a pre-constructed solar power generation prediction model to obtain the corresponding solar power generation prediction data, and generate a solar power prediction error according to the actual solar power generation data and the solar power generation prediction data; obtain the power generation loss according to the energy storage device data, historical events, and fault data; generate a demand prediction error based on the expected load data, historical load data, and demand fluctuation data; perturb the solar power prediction error, the power generation loss, and the demand prediction error to generate multiple solar power prediction attack scenarios, power generation loss attack scenarios, and demand prediction attack scenarios; and generate multiple adversarial scenarios based on each solar power prediction attack scenario, power generation loss attack scenario, and demand prediction attack scenario. Each adversarial scenario includes any one solar power prediction attack scenario, any one power generation loss attack scenario, and any one demand prediction attack scenario.

[0250] In an exemplary embodiment, the network threat defense optimization device further includes an evaluation report generation module, which is configured to obtain the system feedback data of the cyber-physical system in each adversarial scenario; perform metric calculation using the system feedback data and the pre-constructed evaluation metrics to obtain the evaluation metric data in each adversarial scenario; generate an evaluation report of the cyber-physical system according to each evaluation metric data, and send the evaluation report to the user terminal.

[0251] In one embodiment, the network threat defense optimization device further includes a data preprocessing module, which is configured to obtain the original system topology data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters of the cyber-physical system; the data types of the original system topology data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters, and original control parameters are any one of numerical data, categorical data, and time series data; duplicate data, error data, and missing data in the numerical data, categorical data, and time series data are removed to obtain the cleaned numerical data, categorical data, and time series data; the cleaned numerical data is normalized column by column to obtain the normalized numerical data, the cleaned categorical data is data-converted by one-hot encoding or label encoding to obtain the converted categorical data, and smoothing technology is used to remove the high-frequency fluctuations in the cleaned time series data to obtain the removed time series data; the normalized numerical data, the converted categorical data, and the removed time series data are normalized to obtain the processed numerical data, categorical data, and time series data.

[0252] Each module in the above network threat defense optimization device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above respective modules.

[0253] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the computer device is used to store system topology structure data, system operation data, environmental meteorological data, historical events, fault data, system parameters, control parameters, confrontation scenarios, passive resilience indicators, active resilience indicators, predicted recovery ability information, target system parameters, and target control parameters. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a network threat defense optimization method.

[0254] Those skilled in the art can understand that Figure 8 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0255] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, it implements the network threat defense optimization method in the above embodiment.

[0256] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, it implements the network threat defense optimization method in the above embodiment.

[0257] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, it implements the network threat defense optimization method in the above embodiment.

[0258] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0259] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0260] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in the present application.

[0261] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A network threat defense optimization method, characterized in that: The method comprises: Obtain system topology data, system operation data, environmental meteorological data, historical events, fault data, system parameters and control parameters of the cyber-physical system to be optimized; Generate multiple confrontation scenarios based on the system operation data, environmental meteorological data, historical events and fault data; Generate a passive elasticity index according to the system topology data, and generate an active elasticity index corresponding to each of the confrontation scenarios based on the system operation data; the active elasticity index is used to evaluate the recovery capability and constraint violation of the information-physical system after the control strategy is enabled in each of the confrontation scenarios, and the passive elasticity index is used to evaluate the robustness and stability of the information-physical system when the control strategy is not enabled; For any current confrontation scenario among the multiple confrontation scenarios, the system parameters, control parameters, passive elasticity indicators and active elasticity indicators corresponding to the current confrontation scenario are input into a pre-built optimization model, and the target system parameters and target control parameters are obtained through the optimization model when the predicted recovery capability information satisfies the pre-set constraint conditions; The system parameters in the information-physical system under the current confrontation scenario are updated to target system parameters, and the control parameters are updated to target control parameters.

2. The method according to claim 1, characterized in that The target system parameters and target control parameters obtained by the optimization model when the predicted recovery capability information satisfies the preset constraint conditions include: Obtaining predicted recovery capability information of the cyber-physical system in the current confrontation scenario through the optimization model; Obtaining an absolute value of a difference between the predicted recovery capability information and a minimum threshold of the recovery capability information preset in the optimization model; In a case where the absolute value of the difference does not exceed a preset absolute value threshold of the difference and the predicted restoration capability information is greater than a preset value, determining the system parameter as the target system parameter, and determining the control parameter as the control parameter; In the case where the absolute value of the difference exceeds the absolute value threshold of the difference, and the predicted recovery capability information is less than the minimum threshold of the recovery capability information, the system parameter and the control parameter are correspondingly increased through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery capability information is greater than the preset value, the increased system parameter is determined as the target system parameter, and the increased control parameter is determined as the target control parameter; If the absolute value of the difference exceeds the absolute value threshold of the difference, and the predicted recovery capability information is greater than the minimum threshold of the recovery capability information, the system parameters and the control parameters are correspondingly reduced through the optimization model until the absolute value of the difference does not exceed the preset absolute value threshold of the difference and the predicted recovery capability information is greater than the preset value, the reduced system parameters are determined as the target system parameters, and the reduced control parameters are determined as the target control parameters.

3. The method according to claim 2, characterized in that The optimization model is trained by the following steps: Obtaining sample system topology data, sample system operation data, sample environmental meteorological data, sample historical events, sample fault data, sample system parameters and sample control parameters of the cyber-physical system; Generate multiple sample confrontation scenarios based on the sample system operation data, sample environmental meteorological data, sample historical events, and sample fault data; Generate a sample passive elasticity index according to the sample system topology data, and generate a sample active elasticity index corresponding to each of the confrontation scenarios based on the sample system operation data; Using a preset performance mapping function, the sample system parameters, the sample control parameters, the sample passive elasticity index and each of the sample active elasticity indexes are mapped to obtain a plurality of recovery capability information of the cyber-physical system; Constructing a plurality of sample input variables according to the sample system parameters, the sample control parameters, the sample passive elasticity index and each of the sample active elasticity indexes, and inputting the plurality of sample input variables into the optimization model to be trained to obtain corresponding predicted recovery capability information; Obtaining the covariance between the sample system parameters, the sample control parameters and the sample input variables corresponding thereto through the covariance function in the optimization model to be trained; Based on the covariance, the predicted recovery capability information and the recovery capability information, the covariance function is updated until the similarity between the predicted recovery capability information and the recovery capability information meets a preset condition, thereby obtaining a trained optimization model.

4. The method according to claim 1, characterized in that: The system topology data includes nodes and edges; and generating a passive elasticity index according to the system topology data includes: According to the number of edges connected to any current node and the total number of nodes, a topological centrality index associated with the cyber-physical system is obtained; Based on the total number of edges and the total number of nodes, a topological connectivity index associated with the cyber-physical system is obtained; Obtaining a first weight corresponding to the topological centrality index and a second weight corresponding to the topological connectivity index; The passive elasticity index is obtained by performing weighted summation on the topological centrality index and the topological connectivity index using the first weight and the second weight.

5. The method according to claim 1, characterized in that The system operation data includes the time required for recovery of the information-physical system in each of the confrontation scenarios, the total operation time, and a constraint violation indication function; when any current constraint is violated, the constraint violation indication function corresponding to the current constraint is 1, and when any current constraint is not violated, the constraint violation indication function corresponding to the current constraint is 0; The generating active resilience indicators corresponding to the confrontation scenarios based on the system operation data includes: Using the time required for recovery divided by the total running time, a recovery capability index corresponding to each of the confrontation scenarios is obtained; Adding up the constraint violation index functions corresponding to the constraints in the cyber-physical system to obtain the operation constraint violation index corresponding to each of the adversarial scenarios; Obtaining a third weight corresponding to the recovery capability indicator and a fourth weight corresponding to the operation constraint violation indicator; According to the third weight and the fourth weight, a weighted sum is performed on the recovery capability index and the operation constraint violation index to obtain active elasticity indexes corresponding to each of the confrontation scenarios.

6. The method according to claim 1, characterized in that The system operation data includes power generation data, load data and energy storage equipment data; the power generation data includes actual solar power generation data, and the load data includes expected load data, historical load data and demand fluctuation data; The generating of multiple confrontation scenarios based on the system operation data, environmental meteorological data, historical events and fault data includes: Inputting the environmental meteorological data into a pre-built solar power generation prediction model to obtain corresponding solar power generation prediction data, and generating a solar power generation prediction error based on the solar power generation actual data and the solar power generation prediction data; Obtaining power generation loss according to the energy storage device data, the historical events and the fault data; generating a demand forecast error based on the expected load data, the historical load data, and the demand fluctuation data; Perturbing the solar energy forecast error, power generation loss, and demand forecast error to generate a plurality of solar energy forecast attack scenarios, power generation loss attack scenarios, and demand forecast attack scenarios; Based on each of the solar energy prediction attack scenarios, power generation loss attack scenarios and demand prediction attack scenarios, a plurality of the confrontation scenarios are generated; each of the confrontation scenarios includes any one of the solar energy prediction attack scenarios, any one of the power generation loss attack scenarios and any one of the demand prediction attack scenarios.

7. The method according to claim 1, characterized in that After updating the system parameters in the cyber-physical system in the current confrontation scenario to target system parameters and the control parameters to target control parameters, the method further includes: Obtaining system feedback data of the cyber-physical system in each of the confrontation scenarios; Calculate the index using the system feedback data and the pre-built evaluation index to obtain the evaluation index data under each confrontation scenario; An evaluation report of the information-physical system is generated according to each of the evaluation indicator data, and the evaluation report is sent to a user terminal.

8. The method according to claim 1, characterized in that Before obtaining the system topology data, system operation data, environmental meteorological data, historical events, fault data, system parameters and control parameters of the cyber-physical system to be optimized, the method includes: Obtaining original system topology data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters and original control parameters of the information-physical system; the data types of the original system topology data, original system operation data, original environmental meteorological data, original historical events, original fault data, original system parameters and original control parameters are any one of numerical data, categorical data and time series data; Removing duplicate data, erroneous data and missing data from the numerical data, categorical data and time series data to obtain cleaned numerical data, categorical data and time series data; The cleaned numerical data is subjected to minimum-maximum normalization by column to obtain normalized numerical data, the cleaned categorical data is subjected to data conversion by one-hot encoding or label encoding to obtain converted categorical data, and the high-frequency fluctuations in the cleaned time series data are removed by smoothing technology to obtain removed time series data; The normalized numerical data, the converted categorical data and the removed time series data are normalized to obtain processed numerical data, categorical data and time series data.

9. A network threat defense optimization device, characterized in that: The device comprises: A data acquisition module is used to obtain system topology data, system operation data, environmental meteorological data, historical events, fault data, system parameters and control parameters of the cyber-physical system to be optimized; A scenario generation module, used to generate multiple confrontation scenarios based on the system operation data, environmental meteorological data, historical events and fault data; An indicator construction module, used to generate a passive elasticity indicator according to the system topology data, and to generate an active elasticity indicator corresponding to each of the confrontation scenarios based on the system operation data; the active elasticity indicator is used to evaluate the recovery capability and constraint violation of the information-physical system after the control strategy is enabled in each of the confrontation scenarios, and the passive elasticity indicator is used to evaluate the robustness and stability of the information-physical system when the control strategy is not enabled; a target parameter acquisition module, for inputting the system parameters, control parameters, passive elasticity indicators and active elasticity indicators corresponding to the current confrontation scenario into a pre-built optimization model for any current confrontation scenario among the multiple confrontation scenarios, and obtaining target system parameters and target control parameters under the condition that the predicted recovery capability information satisfies the pre-set constraint conditions through the optimization model; A parameter updating module is used to update the system parameters in the information-physical system in the current confrontation scenario to the target system parameters, and to update the control parameters to the target control parameters.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.

Citation Information

Cited By

  • Power distribution network control input attack detection and state estimation method based on robust observer

    CN120763919A

  • A robust observer-based power distribution network control input attack detection and state estimation method

    CN120763919B