Photovoltaic inverter system parameter identification method based on ARMAX model and least square method
By using the parameter identification method of ARMAX model and least squares method combined with watermark perturbation injection technology in the photovoltaic inverter system, the problem of insufficient system attack detection capabilities and difficult to take into account both the parameter identification accuracy and robustness is solved, and high-precision dynamic modeling and integrated attack detection are achieved.
Patent Information
- Application Number
- CN202510581406.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-05-07
AI Technical Summary
The prior art lacks the ability to detect system attack behavior in the modeling of photovoltaic inverter systems. The parameter identification process is difficult to take into account the recognition accuracy and system robustness. The abnormal detection only stays at the physical signal level and cannot identify potential tampering behavior.
The parameter identification method of photovoltaic inverter system based on ARMAX model and least squares method is adopted. By constructing an ARMAX model with multi-hysteresis structure, combining watermark perturbation injection technology and least squares estimation calculation method, the dynamic causal relationship model between the control input and the output response is completed, and an abnormal behavior monitoring mechanism is embedded in the parameter identification synchronously.
It improves the system's recognition and response speed for network attacks, realizes high-precision modeling and integrated attack detection capabilities for the dynamic response behavior of the photovoltaic inverter system, and enhances the sensitivity and accuracy of the detection algorithm.
Smart Images

Figure CN120105924A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of new energy power system modeling and control, and specifically relates to a photovoltaic inverter system parameter identification method based on an ARMAX model and a least squares method. Background Art
[0002] The modeling and control technology of new energy power system is a key engineering technology that takes new energy power generation equipment (such as photovoltaic and wind power) as the research object, describes its electrical behavior and dynamic characteristics by establishing mathematical models, and designs control strategies to achieve stable operation of the system and efficient energy conversion. Its core includes system modeling, control strategy design, state estimation and feedback regulation, and is widely used in smart grid, distributed energy management and power electronic system control. In recent years, with the large-scale access of renewable energy such as photovoltaic power generation, the dynamic characteristics of new energy power systems have become increasingly complex, and the demand for accurate modeling and stable control has continued to increase. Traditional models that rely on linear or static characteristics are difficult to adapt to the high-frequency changes and uncertain disturbances of the system. At the same time, the improvement of the degree of digitalization of distribution networks has made power electronic interfaces such as inverters and converters a research hotspot, and system identification methods and intelligent control algorithms have gradually become the core technical direction of new energy system control. In addition, in the face of increasingly severe network security threats, new energy systems have put forward higher requirements for modeling and control methods with self-perception and self-diagnosis capabilities, which has accelerated the development of fusion technologies such as ARMAX modeling, data-driven identification and watermark detection.
[0003] Related technologies focus on new energy system modeling and prediction, system parameter identification and control optimization, equipment fault detection and operation and maintenance safety, etc. They can be specifically divided into the following three categories: 1) Dynamic model modeling and status prediction, 2) System parameter identification and control optimization, 3) Equipment status monitoring and abnormal detection.
[0004] In terms of dynamic model modeling and state prediction, patent application CN202311049510.3 proposes a modeling method for a regional dynamic simulation model of a distribution network. Based on recorded data combined with an autoregressive moving average (ARMA) model, the transfer function and parameters between the recorded data are determined to form a non-mechanism equivalent model to improve the simulation accuracy and adaptability of distribution networks containing new energy sources; patent US202117197831 proposes a short-term interval prediction method for photovoltaic output, which achieves high-precision power output prediction through similar day sample optimization and dual LSSVM model combined with a multi-objective evolutionary algorithm.
[0005] In terms of system parameter identification and control optimization, patent application CN202011276899.1 discloses a parameter identification method for an inverter system model, which filters noise through the generalized least squares method (GLS) and introduces a variable forgetting factor to improve the real-time and accuracy of modeling; patent application CN202411632394.2 further addresses the problem of controller parameter identification, proposes to establish a mathematical differential model, collect input and output in real time, and solve accurate parameter estimation by minimizing performance indicators to achieve online controller identification; patent application EP15168822 is aimed at LCL filter modeling, using discrete time models and frequency domain analytical methods to estimate discrete parameters and then infer physical parameters to improve the effectiveness of grid-connected system modeling. These patents all focus on accurate and efficient parameter identification and modeling path optimization in the modeling of new energy power electronic equipment.
[0006] In terms of equipment status monitoring and anomaly detection, WO2024CN101769 discloses a photovoltaic safety detection system based on cloud integration and large language model-assisted processing. This method focuses on user interaction, standard database matching and model learning and upgrading to complete the photovoltaic power station fault troubleshooting and self-inspection process; WO2023CN134943 proposes a method for detecting abnormalities in solar panel string circuit breakers, which uses the voltage and current sampling sequence in the MPPT voltage step-down process to determine the open-circuit voltage, and determines whether there is an abnormality based on historical comparison, thereby improving detection sensitivity and pertinence.
[0007] Based on the existing technology, it is found that the current technology in the field of photovoltaic inverter system modeling and safety monitoring has the following deficiencies: 1) Existing modeling methods lack the ability to detect system attack behaviors. Traditional methods such as ARMA model, least squares identification, and multi-objective optimization are mainly used to improve the accuracy of system dynamic simulation or parameter estimation, but fail to combine modeling with network attack detection (such as replay attack and disturbance tampering), resulting in system response distortion or even abnormal operation when facing external attacks; 2) It is difficult to balance the identification accuracy and system robustness in the parameter identification process. Although the commonly used generalized least squares method and variable forgetting factor algorithm have improved the convergence speed and steady-state accuracy of parameter identification, they lack a dynamic adaptive adjustment mechanism for disturbance input, data interference or model error, which can easily lead to parameter drift and identification failure at abnormal moments. 3) Anomaly detection still remains at the physical signal level and cannot identify potential tampering behaviors embedded in the control instruction stream; traditional equipment detection methods are mostly based on the boundary judgment of sampled voltage and current, which makes it difficult to capture system response anomalies under attacked inputs, and lack a multi-dimensional recognition mechanism based on state behavior prediction and statistical reasoning, resulting in a high false alarm rate and insufficient security. Summary of the invention
[0008] In order to solve the above technical problems, the present invention provides a photovoltaic inverter system parameter identification method based on the ARMAX model and the least squares method. By constructing an ARMAX model with a multi-lag structure and combining the watermark perturbation injection technology with the least squares estimation algorithm, the dynamic causal relationship between the control input and the output response is modeled, and the abnormal behavior monitoring mechanism is synchronously embedded in the parameter identification, which improves the system's recognition ability and response speed to network attacks, and realizes high-precision modeling of the dynamic response behavior of the photovoltaic inverter system and integrated attack detection capabilities.
[0009] The present invention provides a method for identifying photovoltaic inverter system parameters based on an ARMAX model and a least squares method, comprising the following steps: Step S1, collecting photovoltaic inverter system data, and preprocessing, constructing an ARMAX system parameter identification model, forming a parameter matrix to be identified, and obtaining an ARMAX parameter vector; Step S2, with the goal of achieving attack detection and security verification, a disturbance watermark signal with zero mean and Gaussian white noise distribution characteristics is designed, and the photovoltaic inverter system is driven to operate by additively superimposing the disturbance watermark signal on the modified control signal formed by the control input, and the system adversarial input sequence and corresponding output response data after the disturbance is injected are constructed, and the adversarial sample set and the system response under the simulated attack scenario are generated. Finally, the photovoltaic inverter system control input and output response data set after the disturbance watermark signal is superimposed is output for detection algorithm verification; Step S3, with the goal of building a model that can identify potential network attacks in the photovoltaic inverter system, the least squares method is used to estimate the parameters in the ARMAX system parameter identification model, and the ARMAX prediction model is established. In combination with the measurement output, a dual variance detection mechanism based on output deviation is designed to form a network attack detection module, and a parameter adaptive dynamic adjustment strategy is used to optimize the detection performance and generate an initial deployment parameter configuration; Step S4: With the goal of achieving real-time detection of attack behaviors on the photovoltaic inverter system and continuous optimization of the ARMAX system parameter identification model, a photovoltaic inverter system network attack detection and system model online optimization mechanism is constructed.
[0010] Furthermore, step S1 is specifically as follows: Step S101: Establishing a photovoltaic inverter inductor current Capacitor voltage is the state space model of the state variables, as follows: , in, It is The inductor current of a sampling period; It is The capacitor voltage of a sampling period; For the The modulation index input of sampling periods; is the dynamic coupling coefficient of the state time evolution, representing the state transfer matrix Elements of is the influence coefficient of the modulation input on the state variable, which represents the control input matrix Elements of Step S102: fixed sampling period Sampling the photovoltaic inverter system to collect the timing data of the modulation index input and the grid-side output current: , in, It is The current on the grid-connected output side of the photovoltaic inverter in a sampling period, Indicates the number of sampling points initially used to train the model; Step S103: performing outlier removal, missing value interpolation and low-pass filtering denoising processing on the collected time series data, as follows: 1) Outlier removal: Use statistical methods (such as box plots and Z-score) to detect and remove outliers; 2) Missing value interpolation: missing sampling points are filled by linear interpolation or sample averaging; 3) Filtering and denoising: Use a low-pass filter to eliminate sampling noise; Construct a discrete multi-step difference model: , in, is the autoregressive coefficient of the output current, is the hysteresis effect coefficient of the input modulation index; Step S104: Considering input delay and system random interference, the multi-step differential model is expanded into the following ARMAX system parameter identification model: , in, is the autoregression coefficient, is the hysteresis coefficient of the input term, is the noise term influence coefficient, is Gaussian white noise; Step S105: construct a regression matrix of the ARMAX system parameter identification model: , in, ; is the constructed regression matrix, whose Behavior ; is the ARMAX parameter vector, ; is the modeling residual vector; Step S106: Solve the ARMAX parameter vector using the least squares method The estimated value of is calculated as: , in, for The transpose of are the estimated system parameters.
[0011] Furthermore, step S2 is specifically as follows: Step S201: Generate a disturbance watermark signal satisfying zero mean and Gaussian white noise distribution characteristics ,satisfy: , in, For the Watermark signal at the moment; The disturbance watermark power, whose value is equal to the variance of the watermark signal, determines the strength of the watermark effect; Step S202: construct the correction control signal (including watermark control input) as follows: , in, The actual control instruction after additively superimposing the disturbance watermark signal, i.e., the corrected control signal, is injected into the photovoltaic inverter system; In order to ensure model consistency and keep the causal relationship between input and output unchanged, the subsequent identification, simulation and detection of the system must all be based on the corrected input Expand; Step S203: fixed sampling period Collect adversarial input samples containing watermarked signals and construct an adversarial sample set containing perturbation effects: , in, Indicates the number of watermarked samples; Step S204: simulating an attack scenario to simulate the impact of false data injection on the output of the photovoltaic inverter system.
[0012] Furthermore, in step S204, the attack simulation includes the following two methods: (1) Harmonic injection attack simulation. The attack signal is defined as the non-fundamental frequency signal injected after the simulated current sensor is hijacked: , in, The amplitude of the 3rd and 5th harmonics is designed to be 10%~20% of the maximum normal value of the system; , is the base frequency, such as 50Hz, and are the 3rd and 5th harmonic frequencies; For the The sampling period is is the sampling period; (2) Replay attack simulation, the attack signal is: , in, Indicates normal data pre-stored by the attacker. The replay time window delay.
[0013] Furthermore, in step S3, the ARMAX model parameters are fitted using the least squares method to construct a two-layer attack detection mechanism for discovering anomalies or potential network attacks in the photovoltaic inverter system, specifically: Step S301: Based on the data adversarial sample set consisting of disturbance control input and system output response, the least square method is used to identify the ARMAX model parameters and the following optimization objective function is constructed: , The output is the estimated parameters ; Step S302, constructing an ARMAX system identification model (without disturbance watermark control input) to identify the behavior of the watermark-free system; , in, is the system prediction output based on the ARMAX model, which is the prediction output of the system identification model at time k. The predicted value of the current at the moment; are the currents actually measured at the current and the previous moment respectively; the ARMAX system identification model (without disturbance watermark control input) is used to generate the normal behavior benchmark curve of the system under the condition of no watermark signal; Step S303: Introduce watermark disturbance into control input To enhance the detectability of attacks, an ARMAX system prediction model (including perturbation watermark input) is constructed: , in, are the actual input control signals at the current and previous moments respectively; The grid-connected current value predicted by the watermarked model; The model will be used to compare the error between the identified signal and the real signal after the attack.
[0014] Step S304: A prediction deviation detection model is constructed using a dual error variance mechanism to evaluate whether the photovoltaic inverter system is currently in an attack state or a normal state. The variance indicators include: Test 1: Watermarked prediction error variance : , Test 2: No watermark prediction error variance : , in, For the Current measurement signal at the moment; For the total sample length (or ) The sliding window length selected in the general ( ), used for the analysis of the difference in prediction deviation at each moment within the real-time detection window; and They are the predicted values of the system without watermark and with watermark respectively; Introducing the difference in detection indicators: .
[0015] Step S305, designing a parameter adaptive dynamic adjustment strategy to optimize the performance of the network attack detection module; Step S305-1: Dynamically optimize the disturbance watermark power ; By analyzing the distribution difference of prediction error variance of ARMAX system prediction models with and without watermark under normal and attack conditions, the optimal range is selected. Values to maximize attack identifiability and suppress false positives: , in, is the false alarm probability; is the probability of underreporting; Step S305-2: Detection threshold Optimization and adjustment of In order to improve the sensitivity and stability of the photovoltaic inverter system network attack detection module, based on the detection index difference The statistical features of the detection threshold are constructed ; In the early stage of system deployment, the following initial detection threshold settings are used: , in, for Standard deviation under normal conditions; is the initial detection threshold of the network attack detection module; In order to determine the judgment boundary, we assume Satisfies the normal distribution: ; During system operation, the real-time update detection thresholds are as follows: ,,in, Before indivual The sliding window average of Before indivual The standard deviation of is the sensitivity coefficient (usually set to 3 to meet the 99.7% normal confidence level requirement); Step S305-3: Adjust the sliding window size To improve the adaptability of network attack detection modules in different noise environments and attack categories; , in, The penalty weight for response delay can be adjusted according to the actual system security level; Indicates the use of sliding windows The variance at , which is used to measure the detection stability; Indicates that the sliding window size is The detection decision delay caused by this.
[0016] Step S306, outputting identification model parameters and detection module initial settings; Generate and output the ARMAX network attack detection module, and provide initial detection parameter configuration for deployment; The output includes: System identification parameter vector: , Initial detection threshold of the dual detection mechanism: , Parameter adjustment strategy: perturbation watermark power ; Detection threshold dynamic update expression ; Sliding window size With penalty weight .
[0017] The above output data is used as a parameter reference for step S4 and can also be directly deployed in the edge security node for online real-time detection and data integrity verification.
[0018] Furthermore, the photovoltaic inverter system needs to have the ability to identify malicious behaviors in real time during the network security protection process, and optimize the detection mechanism by combining modeling methods; in step 4, based on the ARMAX model and watermark mechanism, attack detection is achieved by using system output, grid feedback and embedded watermark response, and at the same time, the model performance evaluation and control parameter iterative optimization are combined to improve the accuracy, robustness and real-time performance of the detection system; specifically: Step S401: In each sampling period, input the updated measurement data and disturbance control signal, and use the network attack detection module to calculate the current detection index difference. and dynamic detection threshold :If satisfied , then it is determined that the photovoltaic inverter system is under attack; if , the PV inverter system is considered to be in normal state; Step S402: Based on the working performance of the detection model in the current window, the performance indicators of the photovoltaic inverter network attack detection module are evaluated to verify the applicability and robustness of the model under the current working conditions; specifically including: Step S402-1: For detection timeliness evaluation, define the detection delay as the time from the actual start of the attack Until it is correctly identified The time difference detects delayed gratification: , This delay must satisfy , to meet the IEEE 1547 standard requirements for new energy system control response time; Step S402-2: In order to quantify the accuracy of the detection mechanism under various attack scenarios, the system counts the number of true positives (TP), true negatives (TN), false positives (FP), and false negatives (FN) in the recognition results, and defines the following three indicators: , , , Among them, the accuracy rate reflects the overall recognition effect, the detection rate measures the ability to hit the attack sample, and the false negative rate indicates the proportion of missed detections; Step S402-3: Model evaluation also needs to correlate the system performance degradation before and after the attack, focusing on observing three types of stability indicators: output current ripple amplitude change , total harmonic distortion increment The output power change , reflecting the impact of the attack on the power quality and system steady-state performance.
[0019] Step S403: Based on the evaluation results, the model threshold, watermark energy and detection strategy are continuously optimized to enhance the adaptability of the system. In terms of attack threshold, the receiver operating characteristic curve (ROC) is introduced as an analysis tool. Parameters, draw FPR and TPR curves: , By finding the inflection point of the ROC curve, the threshold The optimal setting enables the system to minimize false alarms while ensuring a high detection rate.
[0020] The setting of the perturbation watermark power requires a balance between detectability and system stability. The following optimization problem is solved: , in, represents the false alarm rate, Indicates the false negative rate, through the control The size of can adjust the amplitude of watermark signal intervention.
[0021] The system sets personalized judgment thresholds for different types of attacks (such as harmonic injection, replay attacks, etc.) , and dynamically adjust the sliding window length , obtain the detection window size that is most suitable for the current working conditions.
[0022] In order to realize the online adaptive update of the model, the photovoltaic inverter system adopts the recursive least square method with forgetting factor to iteratively correct the ARMAX model parameters. The update formula is: , in, is the current model parameter estimate, is the current input vector, is the actual output of the system, It is an adaptive gain term; it is dynamically adjusted according to signal changes and covariance estimation to improve recognition accuracy and tracking convergence ability.
[0023] Step S404: Detection robustness evaluation, taking into account the impact of interference and non-ideal factors on the detection mechanism, verifying its reliability and consistency under different operating environments, and ensuring that the detection system has a stable foundation for industrial applications.
[0024] Simulating external interference signals Obey Gaussian distribution: , Superimpose it on the feedback signal to monitor the attack detection indicator variable The mean fluctuation and corresponding false alarm probability of , evaluate the noise resistance; Long-term running tests (usually no less than minutes), record the model Whether the parameters drift, Whether the value maintains stable convergence and the change of detection success rate over time are used to judge the robust performance of the system in long-term work; Change the working conditions, such as introducing multiple typical abnormal situations such as constant power load disturbance, ambient temperature jump, and grid voltage fluctuation, to evaluate the detection mechanism's ability to cope with them. It is necessary to record whether the detection stability has dropped significantly and whether the false alarm rate has soared significantly, and on this basis, feedback whether the detection strategy needs to be adjusted in a targeted manner.
[0025] Step S405: Result output and system feedback update, specifically: Output the current system status judgment (normal or attack); Output the recursively updated ARMAX model parameter vector: , Output the current configuration set of the detection system: .
[0026] Step S406: After the system completes the identification and detection process, it generates and outputs a system security report in PDF or JSON format: (1) Each round of detection number and result record, including status judgment (normal / attack), Trend curve; (2) False positive (FP) and false negative (FN) statistics, as well as the above-mentioned accuracy indicators; (3) Detection delay Key performance indicators , and ; (4) Estimation parameters of each round Dynamically adjust historical trajectories with detector configuration parameters for subsequent strategy adoption; Finally, the updated ARMAX model parameters are fed back to the control module or the communication layer defense unit to achieve linkage integration between the detection structure and the attack response and alarm mechanism.
[0027] The beneficial effects of the present invention are: 1) Based on the system identification structure of the ARMAX model, the present invention improves the modeling accuracy of the output behavior of the photovoltaic inverter system by establishing a dynamic model that takes into account multiple lag links and noise interference, and realizes high-fidelity dynamic response prediction. Since the ARMAX model can simultaneously capture the coupling effect of the system's internal feedback, its own historical state, and external control input, the system output prediction result is more accurate, thereby providing a reliable data basis for subsequent detection algorithms; 2) The present invention estimates model parameters based on the least squares method, constructs the output input matrix equation by vectorization and solves the parameter vector , achieving the mathematical rigor and optimization of computational efficiency of the identification process. The parameter estimation method based on the normal equation can effectively reduce the impact of model noise disturbance on the valuation results, improve the model convergence speed, and show good robustness and interpretability when facing the parameter drift problem that may exist in the system, solving the problem of low model identification accuracy and difficulty in quickly obtaining effective parameters online in the existing technology; 3) The present invention is based on the disturbance design and injection mechanism of the watermark signal. By generating a random disturbance signal that satisfies the characteristics of Gaussian white noise and is power-controllable and superimposed on the control input, and combining the real-time end-to-end response analysis of the system model, a dual-output deviation variance detection index system is constructed. The test 1 and test 2 detection mechanisms are used to distinguish the prediction accuracy deviation of the system in the watermarked state and the non-disturbance state, respectively, which effectively solves the problem of insufficient recognition of disguised attacks such as replay attacks and harmonic injection in traditional methods, and enhances the sensitivity and accuracy of the detection algorithm in the face of diversified network attacks; 4) The present invention is based on the dynamic adjustment mechanism of model parameters and detection configuration, by adjusting the disturbance watermark power , detection threshold and sliding window width The adaptive optimization of key parameters such as , realizes the high adaptability and stability of the detection algorithm under different system load conditions and environmental disturbances. This mechanism ensures that the identification and detection algorithm has the ability to operate continuously and stably in actual deployment by introducing robust performance evaluation, minimum error strategy and sliding window dynamic adjustment strategy, solving the problem that most existing algorithms rely on manual parameter debugging and are easily affected by external environmental changes; 5) The present invention constructs a complete set of system identification and detection output structures, which integrates and outputs the ARMAX parameter identification results, detection configuration parameters and system status judgment results, so that edge nodes can call and execute them in a low computing resource environment. By packaging and outputting the model parameter vector and the detection strategy, it can be directly applied to the edge security module and energy management unit of the photovoltaic power station to realize online real-time attack monitoring and control linkage, with good application scalability and engineering deployability, solving the technical obstacles of the existing methods that the identification results are difficult to integrate and call and the actual deployment threshold is high. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 is a flow chart of the method of the present invention; Figure 2 This is a diagram of the photovoltaic system network security architecture; Figure 3 This is a diagram showing the changes in system response before and after the harmonic injection attack; Figure 4 Graph showing the impact of replay attack on inverter operating characteristics and detection signals. DETAILED DESCRIPTION
[0029] In order to make the contents of the present invention more clearly understood, the present invention is further described in detail below based on specific embodiments in conjunction with the accompanying drawings.
[0030] like Figure 1 As shown, the photovoltaic inverter system parameter identification method based on ARMAX model and least squares method described in the present invention includes the following steps: Step S1, collecting photovoltaic inverter system data, and preprocessing, constructing an ARMAX system parameter identification model, forming a parameter matrix to be identified, and obtaining an ARMAX parameter vector; Step S2, with the goal of achieving attack detection and security verification, a disturbance watermark signal with zero mean and Gaussian white noise distribution characteristics is designed, and the photovoltaic inverter system is driven to operate by additively superimposing the disturbance watermark signal on the modified control signal formed by the control input, and the system adversarial input sequence and corresponding output response data after the disturbance is injected are constructed, and the adversarial sample set and the system response under the simulated attack scenario are generated. Finally, the photovoltaic inverter system control input and output response data set after the disturbance watermark signal is superimposed is output for detection algorithm verification; Step S3, with the goal of building a model that can identify potential network attacks in the photovoltaic inverter system, the least squares method is used to estimate the parameters in the ARMAX system parameter identification model, and the ARMAX prediction model is established. In combination with the measurement output, a dual variance detection mechanism based on output deviation is designed to form a network attack detection module, and a parameter adaptive dynamic adjustment strategy is used to optimize the detection performance and generate an initial deployment parameter configuration; Step S4: With the goal of achieving real-time detection of attack behaviors on the photovoltaic inverter system and continuous optimization of the ARMAX system parameter identification model, a photovoltaic inverter system network attack detection and system model online optimization mechanism is constructed.
[0031] In this embodiment, the effectiveness of the photovoltaic inverter system parameter identification method based on the ARMAX model and the least squares method proposed in the present invention is verified through simulation tests. The test platform is based on a dual-inverter grid-connected photovoltaic system with a rated power of 5kW, equipped with standardized power electronic devices, accurate data acquisition modules, and network attack simulation modules. The system is built on a test platform with dynamic response characteristics, and the identification algorithm is driven by introducing watermark signals and setting disturbance signals, thereby realizing dynamic online estimation of inverter system model parameters and network attack detection.
[0032] The specific configuration of the embodiment is as follows: The experimental system is mainly composed of two independent photovoltaic power generation units, namely PV1 and PV2. Each power generation unit is connected to the low-voltage power grid through a DC / AC inverter. The output of each inverter is configured with a 3mH AC side filter inductor to suppress high-frequency switching noise. The system bus voltage is set to 200V, the inverter output grid is 120V AC effective value, and the PWM switching frequency is set to 15kHz, which can achieve high-quality waveform output. The rated total power of the system is 5kW, which can meet the analysis and testing requirements of various grid-connected operating conditions under experimental conditions.
[0033] In order to realize the system identification function, the voltage and current output signals of each inverter are collected by high-precision sensors. These signals include grid-side voltage and current. The collected signals are sampled in real time by the high-speed analog-to-digital conversion module and transmitted to the central control module. The controller not only undertakes the task of issuing inverter drive and operation instructions, but also uploads the collected data to the network security protection module synchronously. The data sampling period is 8ms, which meets the technical requirements of the IEEE 1547 standard for fast fault detection and control response time.
[0034] As a key unit of the system, the network protection module adopts anomaly detection technology based on watermark signals. The watermark signal is generated by an independent pseudo-random number generator and injected into the modulation command signals of inverter 1 and inverter 2 at the controller end. and , the watermark signal obeys zero mean uniform distribution, and its amplitude is controlled within 5% of the modulation depth to ensure that it does not interfere with the normal system operation. The control signal after watermark modulation will drive the PWM module to perform inverter power transmission. At the same time, the response characteristics of the watermark are also implied in the system output measured signal, thus providing a basis for subsequent attack detection and model identification.
[0035] In terms of attack simulation, this embodiment designs two common network attack scenarios: harmonic injection attack and replay attack. In the harmonic injection experiment, the attacker manipulates the current sensor signal z_inv[k] to superimpose the third and fifth harmonic components with moderate amplitudes and frequencies of 150Hz and 250Hz respectively on its output. The attack trigger time is set to t=50ms to simulate the response characteristics of the inverter output signal when it is polluted by harmonics. After the attack occurs, the system current waveform becomes obviously distorted from a standard sinusoidal waveform, with significant noise and high-order harmonic characteristics. At the same time, the test signals of Test 1 and Test 2 based on watermark variance analysis also rise and oscillate rapidly, forming an abnormal criterion that can be clearly detected.
[0036] In the replay attack experiment, the attacker captures a transmission signal of the system under normal operation, including output voltage and current waveforms, during the simulation recording phase, and replays the signal into the system during the attack phase (t = 200ms), attempting to deceive the traditional attack response mechanism based on amplitude and frequency detection. However, the watermark signal detection method used in the present invention can successfully identify the defects of the replay signal, that is, the normal response characteristics after watermark injection are missing in the replay signal, resulting in the variance characteristics of test 1 and test 2 to increase rapidly after the attack occurs, and high-frequency fluctuation characteristics appear, thereby realizing the rapid distinction and reporting of forged data.
[0037] During the model identification process, based on the collected input and output data, an ARMAX model of each inverter group was constructed, where the model order was set to 4 for A order, 3 for B order, and 1 for transport delay. Parameter update was achieved by the recursive algorithm in the least squares method, where the initial parameter estimate was set to a small deviation, the variance covariance matrix was set to the unit matrix, and the forgetting factor was selected to be 0.98 to improve the response flexibility and anti-interference ability. The identification process is executed in a loop inside the controller, and the data input window length is set according to the sampling period and the experimental period, and the updated system parameter estimate is fed back in real time. This parameter estimate not only reflects the current operating point response characteristics of the system, but can also be used for subsequent controller adaptive adjustment, abnormal trend monitoring, and synchronous data update of the virtual simulation platform (digital twin).
[0038] During the whole experiment, the simulation environment uses MATLAB / Simulink as the modeling and simulation platform. The core inverter control logic and ARMAX modeling module are built in Simulink, and each power link is modeled through Simscape Power Systems. The network attack module is implemented on the MATLAB script side, and data storage and post-processing are completed by the corresponding data server and processing program. The final experimental results show that the parameter identification method proposed in this invention has good modeling accuracy, can complete dynamic identification and anomaly detection within 8ms, and can effectively support the stable operation and adaptive management of photovoltaic inverter systems under complex working conditions and network risks.
[0039] Figure 2 This is a network security architecture diagram of a photovoltaic system, showing the security architecture design of a photovoltaic grid-connected system based on dual inverters under a cyber attack environment. The system consists of two photovoltaic power generation units, each connected to a corresponding DC / AC inverter to output AC power. The output voltage and current of each inverter are monitored by sensors, and the monitoring data is transmitted to the network protection box. Figure 2 In the figure, potential cyber attack points are marked in the signal path, showing that the system is capable of dealing with cyber attacks (such as harmonic injection attacks and replay attacks). In addition, each inverter is injected with a watermark signal ( , ) to the modulation index to assist the network protection box in quickly detecting abnormal behavior within the 8ms specified by the IEEE 1547 standard. By introducing watermark signal detection and independently testing the two inverters, the architecture can effectively identify and locate network attacks and improve the network security of the photovoltaic grid-connected system.
[0040] Figure 3 This is a diagram of the system response changes before and after the harmonic injection attack, showing the impact of the harmonic injection attack on the grid voltage and current waveforms and the variance signals of test signals 1 and 2. Figure 3 (a) shows the change of grid voltage and grid current with time before and after the attack (t=50ms). Before the attack, the grid current presents a standard sine waveform with an amplitude of 0.5; after the attack, due to the injection of the third (150Hz) and fifth (250Hz) harmonics, the current waveform is significantly distorted, which is manifested as waveform distortion and amplitude disturbance. Figure 3 (b) shows the variance change of test signal 1 and test signal 2. After the harmonic attack at t=50ms, both curves show a significant rise and oscillation characteristics, reflecting that the system detects abnormal disturbances. Harmonic injection will significantly destroy the normal shape of the system current waveform and affect the stability of the system; the change in the variance of the test signal can quickly reflect the time point when the attack occurs, indicating that the watermark signal mechanism has significant advantages in attack detection. Experiments show that the detection delay can be controlled within 8ms.
[0041] Figure 4 This figure shows the impact of replay attacks on the inverter operating characteristics and detection signals. It shows the output waveform of the inverter before and after the replay attack and the detection signal response characteristics based on the watermark signal. Figure 4 (a) shows the grid output voltage and current waveforms of the DC-AC inverter, which maintain a stable 50Hz sinusoidal characteristic throughout the process. Even after the attack starts at t=200ms, the waveform does not show obvious changes. Figure 4 (b) shows the variance response of the two detection signals designed based on the watermark strategy during the entire experiment. Before the attack began, the variance values were relatively stable, about 3 for test 1 and about 4 for test 2; at the moment of the attack at t=200ms, the variances of the two signals increased rapidly and showed high-frequency oscillations (increasing to about 6 and 8 respectively), reflecting the anomaly. The detection mechanism based on watermark signals is highly sensitive and effective to replay attacks. Even if the attacker replays the real waveform data in the system's history, the detection system can still quickly identify anomalies through changes in signal variance, providing key support for the network security of smart power systems such as photovoltaic inverters.
[0042] The above description is only a preferred embodiment of the present invention and is not intended to be a further limitation of the present invention. All equivalent changes made using the contents of the present specification and drawings are within the protection scope of the present invention.
Claims
1. A photovoltaic inverter system parameter identification method based on ARMAX model and least squares method, characterized in that: The following steps are involved: Step S1, collecting photovoltaic inverter system data, and preprocessing, constructing an ARMAX system parameter identification model, forming a parameter matrix to be identified, and obtaining an ARMAX parameter vector; Step S2, with the goal of achieving attack detection and security verification, a disturbance watermark signal with zero mean and Gaussian white noise distribution characteristics is designed, and the photovoltaic inverter system is driven to operate by additively superimposing the disturbance watermark signal on the modified control signal formed by the control input, and the system adversarial input sequence and corresponding output response data after the disturbance is injected are constructed, and the adversarial sample set and the system response under the simulated attack scenario are generated, and finally the photovoltaic inverter system control input and output response data set after the disturbance watermark signal is superimposed is output; Step S3, with the goal of building a model that can identify potential network attacks in the photovoltaic inverter system, the least squares method is used to estimate the parameters in the ARMAX system parameter identification model, and the ARMAX prediction model is established. In combination with the measurement output, a dual variance detection mechanism based on output deviation is designed to form a network attack detection module, and a parameter adaptive dynamic adjustment strategy is used to optimize the detection performance and generate an initial deployment parameter configuration; Step S4: With the goal of achieving real-time detection of attack behaviors on the photovoltaic inverter system and continuous optimization of the ARMAX system parameter identification model, a photovoltaic inverter system network attack detection and system model online optimization mechanism is constructed.
2. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 1, characterized in that: Step S1 is specifically as follows: Step S101: Establishing a photovoltaic inverter inductor current Capacitor voltage is the state space model of the state variables, as follows: , in, It is The inductor current of a sampling period; It is The capacitor voltage during a sampling period; For the The modulation index input of sampling periods; is the dynamic coupling coefficient of the state time evolution, representing the state transfer matrix Elements of is the influence coefficient of the modulation input on the state variable, which represents the control input matrix Elements of Step S102: fixed sampling period Sampling the photovoltaic inverter system to collect the timing data of the modulation index input and the grid-side output current: ; in, It is The current on the grid-connected output side of the photovoltaic inverter in a sampling period, Indicates the number of sampling points initially used to train the model; Step S103: remove outliers, interpolate missing values, and perform low-pass filtering and denoising on the collected time series data to build a discrete multi-step difference model: , in, is the autoregressive coefficient of the output current, is the hysteresis effect coefficient of the input modulation index; Step S104: Considering input delay and system random interference, the multi-step differential model is expanded into the following ARMAX system parameter identification model: , in, is the autoregression coefficient, is the hysteresis coefficient of the input term, is the noise term influence coefficient, is Gaussian white noise; Step S105: construct a regression matrix of the ARMAX system parameter identification model: , in, ; is the constructed regression matrix, whose Behavior ; is the ARMAX parameter vector, ; is the modeling residual vector; Step S106: Solve the ARMAX parameter vector using the least squares method The estimated value of is calculated as: , in, for The transpose of are the estimated system parameters.
3. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 2, characterized in that: Step S2 is specifically as follows: Step S201: Generate a disturbance watermark signal satisfying zero mean and Gaussian white noise distribution characteristics ,satisfy: , in, For the Watermark signal at the moment; is the perturbation watermark power; Step S202: construct a correction control signal: , in, The actual control instruction after additively superimposing the disturbance watermark signal, i.e., the corrected control signal, is injected into the photovoltaic inverter system; Step S203: collect adversarial input samples containing watermark signals at a fixed sampling period T to construct an adversarial sample set containing disturbance effects: ; in, Indicates the number of watermarked samples; Step S204: simulate an attack scenario to simulate the impact of false data injection on the output of the photovoltaic inverter system.
4. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 3 is characterized in that: In step S204, the attack simulation includes the following two methods: (1) Harmonic injection attack simulation, the attack signal is defined as: , in, is the amplitude of the 3rd and 5th harmonics; , is the fundamental frequency, and are the 3rd and 5th harmonic frequencies; For the The sampling period is is the sampling period; (2) Replay attack simulation, the attack signal is: , in, Indicates normal data pre-stored by the attacker. The replay time window delay.
5. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 3, characterized in that: Step S3 is specifically as follows: Step S301: Based on the data adversarial sample set consisting of disturbance control input and system output response, the least square method is used to identify the ARMAX model parameters and the following optimization objective function is constructed: , The output is the estimated parameters ; Step S302: construct an ARMAX system identification model to identify the behavior of the watermark-free system; , in, is the system prediction output based on the ARMAX model, which is the system identification model in Time to The predicted value of the current at the moment; are the current actually measured at the current and the previous moment respectively; Step S303: constructing an ARMAX system prediction model: , in, are the actual input control signals at the current and previous moments respectively; The grid-connected current value predicted by the watermarked model; Step S304: A prediction deviation detection model is constructed using a dual error variance mechanism to evaluate whether the photovoltaic inverter system is currently in an attack state or a normal state. The variance indicators include: (1) Variance of watermarked prediction error : , (2) Variance of prediction error without watermark : , in, For the Current measurement signal at the moment; is the sliding window length; and They are the predicted values of the system without watermark and with watermark respectively; Introducing the difference in detection indicators: ; Step S305, designing a parameter adaptive dynamic adjustment strategy to optimize the performance of the network attack detection module; Step S305-1: Dynamically optimize the disturbance watermark power ; By analyzing the distribution difference of prediction error variance of ARMAX system prediction models with and without watermark under normal and attack conditions, the optimal range is selected. Values to maximize attack identifiability and suppress false positives: , in, is the false alarm probability; is the probability of underreporting; Step S305-2: Detection threshold Optimization and adjustment of In order to improve the sensitivity and stability of the photovoltaic inverter system network attack detection module, based on the detection index difference The statistical features of the detection threshold are constructed ; In the early stage of system deployment, the following initial detection threshold settings are used: , in, for Standard deviation under normal conditions; is the initial detection threshold of the network attack detection module; In order to determine the judgment boundary, we assume Satisfies normal distribution: , During system operation, the real-time update detection thresholds are as follows: , in, Before indivual The sliding window average of Before indivual The standard deviation of is the sensitivity coefficient; Step S305-3: Adjust the sliding window size To improve the adaptability of network attack detection modules in different noise environments and attack categories; , in, is the penalty weight for response delay, Indicates the use of sliding windows The variance of Indicates that the sliding window size is The resulting detection decision delay; Step S306: output identification model parameters and detection module initial settings.
6. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 5, characterized in that: Step 4 is as follows: Step S401: In each sampling period, input the updated measurement data and disturbance control signal, and use the network attack detection module to calculate the current detection index difference. and dynamic detection threshold :If satisfied , then it is determined that the photovoltaic inverter system is under attack; if , the PV inverter system is considered to be in normal state; Step S402: evaluating the performance index of the photovoltaic inverter network attack detection module based on the working performance of the detection module in the current window; Step S403: Based on the evaluation results, the photovoltaic inverter system uses the recursive least square method with a forgetting factor to update the ARMAX model parameters online, and the parameter update formula is: , in, is the current model parameter estimate, is the current input vector, is the actual output of the system, is the adaptive gain term; Step S404: Detection robustness evaluation; Step S405: Result output and system feedback update, specifically: Output current system status determination; Output the recursively updated ARMAX model parameter vector: , Output the current configuration set of the detection system: ; Step S406: After the system completes the identification and detection process, it generates and outputs a system security report.
7. The method for identifying photovoltaic inverter system parameters based on ARMAX model and least squares method according to claim 6, characterized in that: In step S402, the performance evaluation of the photovoltaic inverter network attack detection module includes three evaluation indicators: detection timeliness, accuracy and system stability, specifically including: Step S402-1: For detection timeliness evaluation, define the detection delay as the time from the actual start of the attack Until it is correctly identified The time difference detects delayed gratification: ; Step S402-2: The accuracy index includes accuracy rate, detection rate, and false negative rate, which are respectively expressed as: , , , Among them, TP is a true positive example, TN is a true negative example, FP is a false positive example, and FN is a false negative example; Step S402-3: Stability index includes output current ripple amplitude change , total harmonic distortion increment The output power change , used to evaluate the extent of damage caused by the attack to the quality of system operation.
Citation Information
Patent Citations
Modeling method and device for dynamic simulation model of power distribution network area
CN117077525A
Method and system for identifying parameters of photovoltaic inverter controller
CN119511867A
Identification of LCL filter parameters
EP3096429A1
Photovoltaic inverter model parameter identification method based on dynamic locus sensitivity
CN103592528A
Modeling method of gyroscopic random noise ARMA model based on robust Kalman wave filtering
CN105043384A
Cited By
Power distribution network control input attack detection and state estimation method based on robust observer
CN120763919A
A robust observer-based power distribution network control input attack detection and state estimation method
CN120763919B
Power grid disturbance simulation test method and system
CN120779293A