A Method for Identifying the Parameters of a Photovoltaic Inverter System Based on the ARMAX Model and the Least Squares Method

Through the ARMAX model and least squares method combined with watermark perturbation injection technology, a parameter identification method for photovoltaic inverter system is constructed, which solves the problem of insufficient network attack detection capabilities in photovoltaic inverter system modeling, and realizes real-time and robustness of high-precision modeling and attack detection, which is suitable for online real-time attack monitoring of edge nodes.

CN120105924BActive Publication Date: 2025-07-25NANJING UNIV OF POSTS & TELECOMM
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510581406.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-25
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The existing PV inverter system modeling methods lack the ability to detect network attacks, and the parameter identification process is difficult to take into account the recognition accuracy and system robustness. Anomaly detection is difficult to identify potential tampering behavior embedded in the control command flow. Traditional methods are prone to high false alarm rates and insufficient security.

Method used

The ARMAX model and least squares method are used to build a multi-hysteresis structure, combined with watermark perturbation injection technology, a dual variance detection mechanism is designed to realize dynamic causal modeling of the photovoltaic inverter system, and an abnormal behavior monitoring is embedded, and the detection performance is optimized through parameter adaptive dynamic adjustment.

Benefits of technology

It improves the system's recognition ability and response speed for network attacks, realizes high-precision modeling and integrated attack detection, enhances the sensitivity and accuracy of the detection algorithm, has good real-time, robustness and adaptability, and is suitable for online real-time attack monitoring of edge nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105924B_ABST
    Figure CN120105924B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of new energy power system modeling and control, and discloses a method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method. The method collects lag time series data of the control input and output current of the photovoltaic inverter, constructs an ARMAX model with a multi-lag structure, and estimates the model parameters by using the least squares method; an adversarial data set is constructed by injecting a watermark perturbation signal with statistical characteristics to achieve fine modeling and difference prediction of the system output behavior; a two-layer variance detection mechanism is constructed based on the watermark model to effectively identify network behaviors such as replay attacks and harmonic forgery. The method of the present invention aims to achieve high-precision modeling of the dynamic response characteristics of the photovoltaic inverter and real-time detection of network attacks, and can be deployed on new energy edge control nodes to realize the coordinated operation of model identification, system prediction and attack detection, and has good real-time performance, robustness and engineering application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of new energy power system modeling and control, and specifically relates to a method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method. Background Art

[0002] The new energy power system modeling and control technology takes new energy power generation equipment (such as photovoltaic and wind power) as the research object, describes its electrical behavior and dynamic characteristics by establishing a mathematical model, and designs a control strategy to achieve stable operation and efficient energy conversion of the system; its core includes system modeling, control strategy design, state estimation and feedback regulation, etc., and is widely used in fields such as smart grids, distributed energy management, and power electronic system control. In recent years, with the large-scale access of renewable energy such as photovoltaic power generation, the dynamic characteristics of the new energy power system have become increasingly complex, and the demand for its accurate modeling and stable control has been continuously increasing. Traditional models relying on linear or static characteristics are difficult to adapt to the high-frequency changes and uncertain disturbances of the system. At the same time, the improvement of the digitalization level of the distribution network has made power electronic interfaces such as inverters and converters become research hotspots, and system identification methods and intelligent control algorithms have gradually become the core technical directions of new energy system control. In addition, in the context of increasingly severe network security threats, the new energy system puts forward higher requirements for modeling and control methods with self-sensing and self-diagnosis capabilities, which promotes the accelerated development of fusion technologies such as ARMAX modeling, data-driven identification, and watermark detection. The significance of studying the modeling and control of the new energy power system lies in improving the accuracy, robustness, and security of system operation, and effectively supporting the automatic scheduling and fault response of intelligent microgrids. Especially in the photovoltaic power generation system, accurately mastering the dynamic response characteristics of the inverter is the basis for achieving grid connection stability, power quality guarantee, and attack detection mechanism.

[0003] Related technologies focus on aspects such as new energy system modeling and prediction, system parameter identification and control optimization, equipment fault detection and operation and maintenance safety, etc., and can be specifically divided into the following three categories: 1) dynamic model modeling and state prediction, 2) system parameter identification and control optimization, 3) equipment state monitoring and anomaly detection.

[0004] In terms of dynamic model modeling and state prediction, the patent application CN202311049510.3 proposes a method for modeling a distribution network area dynamic simulation model, which determines the transfer function and parameters between the recorded wave data based on the recorded wave data combined with the autoregressive moving average (ARMA) model, and forms a non-mechanistic equivalent model to improve the simulation accuracy and adaptability of the distribution network containing new energy; the patent US202117197831 proposes a short-term interval prediction method for photovoltaic output, which realizes high-precision power output prediction through similar day sample optimization and double LSSVM model, combined with a multi-objective evolutionary algorithm.

[0005] In terms of system parameter identification and control optimization, patent application CN202011276899.1 discloses a method for identifying the parameters of an inverter system model, which filters noise through the Generalized Least Squares (GLS) method and introduces a variable forgetting factor to improve the real-time performance and accuracy of modeling; patent application CN202411632394.2 further addresses the problem of controller parameter identification, proposes to establish a mathematical difference model, collect inputs and outputs in real time, and solve for accurate parameter estimates by minimizing the performance index to achieve online identification of the controller; patent application EP15168822 focuses on LCL filter modeling, uses a discrete-time model and a frequency-domain analysis method to estimate discrete parameters and then back-calculate physical parameters to improve the modeling effectiveness of the grid-connected system. These patents all focus on accurate and efficient parameter identification and modeling path optimization in the modeling of new energy power electronic devices.

[0006] In terms of equipment status monitoring and anomaly detection, WO2024CN101769 discloses a photovoltaic safety detection system based on cloud integration and large language model-assisted processing. This method completes the fault troubleshooting and self-check process of the photovoltaic power station by focusing on user interaction, standard database matching, and model learning and upgrading; WO2023CN134943 proposes a method for detecting anomalies in solar panel string disconnectors, uses the voltage and current sampling sequence during the MPPT voltage bucking process to determine the open-circuit voltage, and judges whether there are anomalies based on historical comparison to improve the detection sensitivity and pertinence.

[0007] Based on the existing technologies, it is found that there are the following deficiencies in the technologies for photovoltaic inverter system modeling and safety monitoring:

[0008] 1) Existing modeling methods lack the ability to detect system attack behaviors. Traditional methods such as ARMA models, least squares identification, and multi-objective optimization are mainly used to improve the accuracy of system dynamic simulation or parameter estimation, but they fail to combine modeling with network attack detection (such as replay attacks and perturbation tampering), resulting in the system being prone to response distortion or even abnormal operation when facing external attacks.

[0009] 2) It is difficult to balance the identification accuracy and system robustness in the parameter identification process. Although commonly used methods such as the Generalized Least Squares method and the variable forgetting factor algorithm have improved the convergence speed and steady-state accuracy of parameter identification, they lack a dynamic adaptive adjustment mechanism for disturbance inputs, data interference, or model errors, which is likely to lead to parameter drift and identification failure at abnormal moments.

[0010] 3) Anomaly detection remains at the physical signal level and cannot identify potential tampering behaviors embedded in the control instruction stream. Most traditional device detection methods are based on the boundary judgment of sampled voltage and current, making it difficult to capture system response anomalies under attacked inputs. There is a lack of a multi-dimensional identification mechanism based on state behavior prediction and statistical inference, resulting in a high false alarm rate and insufficient security. Summary of the Invention

[0011] To solve the above technical problems, the present invention provides a method for identifying the parameters of a photovoltaic inverter system based on the ARMAX model and the least squares method. By constructing an ARMAX model with a multi-lag structure, combining the watermark perturbation injection technology and the least squares estimation algorithm, the dynamic causal relationship between the control input and the output response is modeled. An anomaly behavior monitoring mechanism is synchronously embedded during parameter identification, which improves the system's ability to identify network attacks and response speed, and realizes high-precision modeling of the dynamic response behavior of the photovoltaic inverter system and integrated attack detection capabilities.

[0012] The method for identifying the parameters of a photovoltaic inverter system based on the ARMAX model and the least squares method according to the present invention includes the following steps:

[0013] Step S1: Collect data of the photovoltaic inverter system, perform preprocessing, construct an ARMAX system parameter identification model, form a matrix of parameters to be identified, and obtain the ARMAX parameter vector.

[0014] Step S2: With the goal of realizing attack detection and security verification, design a perturbation watermark signal with zero mean and Gaussian white noise distribution characteristics. The modified control signal formed by adding the perturbation watermark signal additively to the control input is used to drive the operation of the photovoltaic inverter system, construct the system's adversarial input sequence and the corresponding output response data after injecting the perturbation, generate an adversarial sample set and the system's reaction under the simulated attack scenario, and finally output the set of control input and output response data of the photovoltaic inverter system after superimposing the perturbation watermark signal for detecting algorithm verification.

[0015] Step S3: With the goal of constructing a model that can identify potential network attacks in the photovoltaic inverter system, use the least squares method to estimate the parameters in the ARMAX system parameter identification model, establish an ARMAX prediction model, and combine the measured output to design a dual variance detection mechanism based on the output deviation to form a network attack detection module. Adopt a parameter adaptive dynamic adjustment strategy to optimize the detection performance and generate the initial deployment parameter configuration.

[0016] Step S4: With the goal of realizing real-time detection of the attack behavior of the photovoltaic inverter system and continuous optimization of the ARMAX system parameter identification model, construct an online optimization mechanism for network attack detection and system model of the photovoltaic inverter system.

[0017] Further, step S1 is specifically as follows:

[0018] Step S101: Establish a state - space model with the inductor current of the PV inverter and the capacitor voltage as state variables, as follows:

[0019] ,

[0020] where, is the inductor current at the th sampling period; is the capacitor voltage at the th sampling period; is the modulation index input at the th sampling period; is the dynamic coupling coefficient of the state - time evolution, representing the element of the state - transition matrix ; is the influence coefficient of the modulation input on the state variables, representing the element of the control - input matrix ;

[0021] Step S102: Sample the PV inverter system at a fixed sampling period to collect the time - series data of the modulation index input and the grid - side output current:

[0022] ,

[0023] where, is the current at the grid - connected output side of the PV inverter at the th sampling period, represents the number of sampling points initially used for training the model;

[0024] Step S103: Perform outlier removal, missing - value interpolation, and low - pass filtering denoising on the collected time - series data, as follows:

[0025] 1) Outlier removal: Use statistical methods (such as box plots, Z - scores) to detect and remove outliers;

[0026] 2) Missing - value interpolation: Complement the missing sampling points using linear interpolation or sample averaging;

[0027] 3) Filtering denoising: Use a low - pass filter to eliminate sampling noise;

[0028] Construct a discrete multi - step difference model:

[0029] ,

[0030] where, is the autoregressive coefficient of the output current, is the lag effect coefficient of the input modulation index;

[0031] Step S104: Considering the input delay and system random interference, expand the multi-step difference model into the following ARMAX system parameter identification model:

[0032] ,

[0033] where, is the autoregressive coefficient, is the input term lag coefficient, is the noise term influence coefficient, is the Gaussian white noise;

[0034] Step S105: Construct the regression matrix of the ARMAX system parameter identification model:

[0035] ,

[0036] where, ; is the constructed regression matrix, and its th row is ; is the ARMAX parameter vector, ; is the modeling residual vector;

[0037] Step S106: Use the least squares method to solve the estimated value of the ARMAX parameter vector , and the calculation formula is:

[0038] ,

[0039] where, is the transpose of, is the estimated system parameter.

[0040] Furthermore, Step S2 is specifically as follows:

[0041] Step S201: Generate a perturbation watermark signal that satisfies the characteristics of zero mean and Gaussian white noise distribution, and satisfies:

[0042] ,

[0043] where, is the watermark signal at the th moment; is the perturbation watermark power, and its value is equal to the variance of the watermark signal, which determines the watermark action intensity;

[0044] Step S202. Construct the correction control signal (watermark-containing control input) as:

[0045] ,

[0046] wherein, is the actual control instruction after adding the additive superposition perturbation watermark signal, that is, the correction control signal, which is injected into the photovoltaic inverter system;

[0047] To ensure model consistency and keep the input-output causal relationship unchanged, all subsequent identification, simulation, and detection of the system need to be based on the corrected input to expand;

[0048] Step S203. Collect the adversarial input samples containing the watermark signal at a fixed sampling period to construct an adversarial sample set containing the perturbation effect:

[0049] ,

[0050] wherein, represents the number of watermark-containing samples;

[0051] Step S204. Simulate the attack scenario and simulate the influence of false data injection on the output of the photovoltaic inverter system.

[0052] Furthermore, in Step S204, the attack simulation includes the following two methods:

[0053] (1) Harmonic injection attack simulation. The attack signal is defined as the non-fundamental frequency signal injected after simulating the hijacking of the current sensor:

[0054] ,

[0055] wherein, are the amplitudes of the 3rd and 5th harmonics, designed to be 10% - 20% of the maximum normal value of the system; , is the fundamental frequency, such as 50 Hz, and are the 3rd and 5th harmonic frequencies; is the th moment sampling period, is the sampling period;

[0056] (2) Replay attack simulation. The attack signal is:

[0057] ,

[0058] wherein, represents the normal data pre-stored by the attacker, is the replay time window delay.

[0059] Further, in step S3, the least squares method is used to fit the ARMAX model parameters to construct a two-layer attack detection mechanism for detecting anomalies or potential cyberattacks in the photovoltaic inverter system, specifically:

[0060] Step S301: On the basis of obtaining the data adversarial sample set composed of the perturbed control input and the system output response, the least squares method is used to identify the ARMAX model parameters, and the following optimization objective function is constructed:

[0061] ,

[0062] The output is the estimated parameter ;

[0063] Step S302: Construct an ARMAX system identification model (in the case of no perturbed watermark control input) to identify the system behavior without watermark.

[0064] ,

[0065] where is the system prediction output based on the ARMAX model, which is the predicted value of the current at the th moment by the system identification model at time k; are the actually measured currents at the current and the previous moment respectively; this ARMAX system identification model (in the case of no perturbed watermark control input) is used to generate the system normal behavior benchmark curve under the condition of no watermark signal;

[0066] Step S303: Introduce watermark perturbation into the control input to enhance the attack detectability, and construct an ARMAX system prediction model (including perturbed watermark input):

[0067] ,

[0068] where are the actual input control signals at the current and the previous moment respectively; is the grid-connected current value predicted by the watermark model;

[0069] This model will be used for comparative analysis of the error between the identified signal and the true signal after an attack occurs.

[0070] Step S304: Adopt a dual error variance mechanism to construct a prediction deviation detection model for evaluating whether the photovoltaic inverter system is currently in an attack state or a normal state. The variance indexes include:

[0071] Test 1: Variance of the watermark prediction error :

[0072] ,

[0073] Test 2: Variance of prediction error without watermark :[[]]END]]

[0074] ,

[0075] where is the current measurement signal at time ; is the sliding window length selected within the total sample length (or ), generally satisfying ( ), and is used for real-time detection of the difference in prediction deviation at each moment within the window; and are the system prediction values without watermark and with watermark, respectively;

[0076] Introduce the difference in detection indicators:

[0077] .

[0078] Step S305: Design an adaptive dynamic adjustment strategy for parameters to optimize the performance of the network attack detection module;

[0079] Step S305-1: Dynamically optimize the power of the perturbation watermark ;

[0080] By analyzing the distribution differences of the prediction error variances of the watermark-embedded and watermark-free ARMAX system prediction models in normal and attack states, select the optimal range of values to maximize the attack identifiability and suppress false alarms:

[0081] ,

[0082] where is the false alarm probability; is the missed alarm probability;

[0083] Step S305-2: Optimization and adjustment of the detection threshold ;

[0084] To improve the sensitivity and stability of the network attack detection module of the photovoltaic inverter system, construct the detection threshold based on the statistical characteristics of the difference in detection indicators ;

[0085] At the initial stage of system deployment, use the following initial detection threshold setting:

[0086] ,

[0087] Among them, is the standard deviation in the normal state; is the initial detection threshold of the network attack detection module;

[0088] For the convenience of determining the discrimination boundary, assume that satisfies the normal distribution:

[0089] ;

[0090] During the operation of the system, the detection threshold is updated in real time as follows:

[0091] , where represents the previous moving window average; represents the previous standard deviation; is the sensitivity coefficient (usually taking a value of 3 to meet the 99.7% normal confidence level requirement);

[0092] Step S305-3, adjust the moving window size to improve the adaptability of the network attack detection module under different noise environments and attack categories;

[0093] ,

[0094] where is the penalty weight for response delay, which can be adjusted according to the actual system security level; represents the variance when using the moving window for measuring the detection stability; represents the detection decision delay caused by the moving window size of .

[0095] Step S306, output the identification model parameters and the initial settings of the detection module;

[0096] Generate and output the ARMAX network attack detection module, and provide the initial detection parameter configuration for deployment;

[0097] The output content includes:

[0098] System identification parameter vector: ,

[0099] Initial detection threshold of the dual detection mechanism: ,

[0100] Parameter adjustment strategy: perturbation watermark power ; Detection threshold dynamic update expression ; Sliding window size and penalty weight .

[0101] The above output data is used as a parameter reference for step S4 and can also be directly deployed in the edge security node for online real-time detection and data integrity verification.

[0102] Furthermore, the photovoltaic inverter system needs to have the ability to identify malicious behaviors in real time during the network security guarantee process and optimize the detection mechanism by combining modeling methods; in step 4, based on the ARMAX model and the watermark mechanism, attack detection is realized by using the system output, grid feedback, and embedded watermark response. At the same time, the accuracy, robustness, and real-time performance of the detection system are improved by combining model performance evaluation and control parameter iterative optimization; specifically:[[]]

[0103] Step S401: In each sampling period, input the updated measurement data and perturbation control signal, and use the network attack detection module to calculate the current detection index difference and the dynamic detection threshold : If it satisfies , it is determined that the photovoltaic inverter system is under attack; if , it is considered that the photovoltaic inverter system is in a normal state;

[0104] Step S402: Based on the working performance of the detection model in the current window, evaluate the performance indicators of the photovoltaic inverter network attack detection module to verify the applicability and robustness of the model under the current working conditions; specifically including:[[]]

[0105] Step S402-1: For the evaluation of detection timeliness, define the detection delay as the time difference from the actual start time of the attack to the time when it is correctly identified . The detection delay satisfies:[[]]

[0106] ,

[0107] This delay needs to satisfy to meet the requirements of the IEEE 1547 standard for the control response time of new energy systems;

[0108] Step S402-2: In order to quantify the accuracy performance of the detection mechanism in various attack scenarios, the system counts the number of true positives (TP), true negatives (TN), false positives (FP), and false negatives (FN) in the recognition results and defines the following three types of indicators:[[]]

[0109] ,

[0110] ,

[0111] ,

[0112] Among them, the accuracy reflects the overall recognition effect, the detection rate measures the ability to hit the attack samples, and the false negative rate represents the proportion of missed detections.

[0113] Step S402-3: The model evaluation also needs to be associated with the degradation of the system performance before and after the attack, and three types of stability indicators are mainly observed: the change in the amplitude of the output current ripple , the increment of the total harmonic distortion and the change in the output power , which reflect the influence degree of the attack on the power quality and the steady-state performance of the system.

[0114] Step S403: Based on the evaluation results, continuously optimize the model threshold, watermark energy and detection strategy to enhance the adaptability of the system. In terms of the attack threshold, the Receiver Operating Characteristic (ROC) curve is introduced as an analysis tool, and the FPR and TPR curves are plotted under multiple candidate parameters:

[0115] ,

[0116] By finding the inflection point position of the ROC curve, the optimal setting of the threshold is realized, so that the system can ensure a high detection rate while minimizing the false alarm.

[0117] The setting of the perturbation watermark power requires a balance between detectability and system stability. To maximize the separation degree of the indicator variables in the attack state and the non-attack state, the following optimization problem is solved:

[0118] ,

[0119] Among them, represents the false alarm rate, represents the false negative rate, and the amplitude of the watermark signal intervention can be adjusted by controlling the size of .

[0120] For different types of attacks (such as harmonic injection, replay attack, etc.), the system sets personalized decision thresholds , and at the same time dynamically adjusts the sliding window length to obtain the detection window scale most suitable for the current working condition.

[0121] To achieve the online adaptive update of the model, the photovoltaic inverter system uses the recursive least squares method with a forgetting factor to iteratively correct the ARMAX model parameters. The update formula is as follows:

[0122] ,

[0123] where, is the current model parameter estimation, is the current input vector, is the actual output of the system, is the adaptive gain term; it is dynamically adjusted according to signal changes and covariance estimation, and is used to improve the identification accuracy and tracking convergence ability.

[0124] Step S404, Detection robustness evaluation. Considering the influence of interference and non-ideal factors on the detection mechanism, verify its reliability and consistency in different operating environments to ensure that the detection system has a stable basis for industrial applications.

[0125] Simulate the external interference signal obeys the Gaussian distribution:

[0126] ,

[0127] Superimpose it on the feedback signal, and monitor the mean fluctuation of the attack detection indicator variable and the corresponding false alarm probability to evaluate the anti-noise ability;

[0128] Conduct long-term operation tests on the actual physical system or simulation platform (usually not less than minutes), record whether the parameters in the model drift, whether the value remains stable and convergent, and the change of the detection success rate over time, which is used to judge the robust performance of the system during long-term operation;

[0129] Change the working conditions, such as introducing multiple typical abnormal situations such as constant power load disturbance, environmental temperature jump, and grid-connected voltage fluctuation, to evaluate the response ability of the detection mechanism. It is necessary to record whether the detection stability drops significantly and whether the false alarm rate soars significantly. On this basis, feedback whether the detection strategy needs to be adjusted specifically.

[0130] Step S405, Result output and system feedback update, specifically:

[0131] Output the current system status determination (normal or attack);

[0132] Output the recursively updated ARMAX model parameter vector:

[0133] ,

[0134] Output the current configuration set of the detection system:

[0135] .

[0136] Step S406: After the system completes the identification and detection process, generate a system security report and output it in PDF or JSON format:

[0137] (1) Record the detection number and result of each round, including status judgment (normal / attack), trend curve;

[0138] (2) False positive (FP) and false negative (FN) statistical values, and the above accuracy metrics;

[0139] (3) Detection latency and key performance indicators 、 and ;

[0140] (4) Estimation parameters of each round and the dynamic adjustment historical trajectory of the detector configuration parameters for subsequent strategy adoption;

[0141] Finally, feedback the updated ARMAX model parameters to the control module or the communication layer defense unit to realize the linkage integration between the detection structure and the attack response and the alarm mechanism.

[0142] The beneficial effects of the present invention are as follows:

[0143] 1) The system identification structure of the present invention based on the ARMAX model improves the modeling accuracy of the output behavior of the photovoltaic inverter system by establishing a dynamic model considering multiple lag links and noise interference, and realizes high-fidelity dynamic response prediction. Since the ARMAX model can simultaneously capture the coupling effects of the internal feedback of the system, its own historical state, and the external control input, the system output prediction result is more accurate, thus providing a reliable data basis for subsequent detection algorithms;

[0144] 2) The present invention estimates the model parameters based on the least squares method, and realizes the mathematical rigor and operation efficiency optimization of the identification process by constructing and solving the parameter vector of the output-input matrix equation in a vectorized manner . Relying on the parameter estimation method of the normal equation, it can effectively reduce the influence of model noise perturbation on the estimation result, improve the model convergence speed, and show good robustness and interpretability when facing the possible parameter drift problem in the system, solving the problems of low model identification accuracy and difficulty in quickly obtaining effective parameters online in the prior art;

[0145] 3) Based on the perturbation design and injection mechanism of the watermark signal, the present invention generates a random perturbation signal that satisfies the characteristics of Gaussian white noise and has controllable power, superimposes it on the control input, and combines the real-time end-to-end response analysis of the system model to construct a dual-output deviation variance detection index system. The detection mechanisms of Test 1 and Test 2 are respectively used to distinguish the prediction accuracy deviation of the system in the watermark-containing state and the non-perturbation state, effectively solving the problem of insufficient recognition ability of traditional methods for disguised attacks such as replay attacks and harmonic injection, and enhancing the sensitivity and accuracy of the detection algorithm in the face of diverse network attacks;

[0146] 4) Based on the dynamic adjustment mechanism of model parameters and detection configuration, the present invention realizes the high adaptability and stability of the detection algorithm under different system load conditions and environmental disturbances through the adaptive optimization of key parameters such as the perturbation watermark power , detection threshold and sliding window width . By introducing the robust performance evaluation, minimum error strategy and sliding window dynamic adjustment strategy, this mechanism ensures that the identification and detection algorithms have the ability to operate continuously and stably in actual deployment, and solves the problem that most existing algorithms rely on manual parameter debugging and are vulnerable to external environmental changes;

[0147] 5) The present invention constructs a complete system identification and detection output structure, integrates and outputs the ARMAX parameter identification results, detection configuration parameters and system state judgment results, which is convenient for edge nodes to call and execute in a low-computing resource environment. By packing and outputting the model parameter vector and detection strategy, it can be directly applied to the edge security module and energy management unit of the photovoltaic power station to realize online real-time attack monitoring and control linkage, with good application scalability and engineering deployability, and solves the technical obstacle that it is difficult to integrate and call the identification results and the high threshold for actual deployment in existing methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0148] Figure 1 is the flow chart of the method described in the present invention;

[0149] Figure 2 is the network security architecture diagram of the photovoltaic system;

[0150] Figure 3 is the system response change diagram before and after harmonic injection attack;

[0151] Figure 4 is the influence diagram of replay attack on the operation characteristics of the inverter and the detection signal. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0152] In order to make the content of the present invention easier to be clearly understood, the following further describes the present invention in detail according to specific embodiments and in conjunction with the accompanying drawings.

[0153] As Figure 1 shown, a method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method according to the present invention includes the following steps:

[0154] Step S1: Collect data of the photovoltaic inverter system, perform preprocessing, construct an ARMAX system parameter identification model, form a matrix of parameters to be identified, and obtain an ARMAX parameter vector;

[0155] Step S2: Aiming at realizing attack detection and security verification, design a perturbation watermark signal with the characteristics of zero mean and Gaussian white noise distribution. The perturbation watermark signal is additively superimposed on the corrected control signal formed by the control input to drive the operation of the photovoltaic inverter system, construct the system's adversarial input sequence and the corresponding output response data after injecting the perturbation, generate an adversarial sample set and the system reaction under the simulated attack scenario, and finally output the control input and output response data set of the photovoltaic inverter system after superimposing the perturbation watermark signal for detecting algorithm verification;

[0156] Step S3: Aiming at constructing a model that can identify potential network attacks in the photovoltaic inverter system, use the least squares method to estimate the parameters in the ARMAX system parameter identification model, establish an ARMAX prediction model, and design a dual variance detection mechanism based on the output deviation in combination with the measured output to form a network attack detection module. Adopt a parameter adaptive dynamic adjustment strategy to optimize the detection performance and generate an initial deployment parameter configuration;

[0157] Step S4: Aiming at realizing real-time detection of the attack behavior of the photovoltaic inverter system and continuous optimization of the ARMAX system parameter identification model, construct an online optimization mechanism for network attack detection and system model of the photovoltaic inverter system.

[0158] In this embodiment, the effectiveness of a method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method proposed by the present invention is verified through simulation tests. The test platform is based on a dual-inverter grid-connected photovoltaic system with a rated power of 5 kW, equipped with standardized power electronic devices, an accurate data acquisition module, and a network attack simulation module. The system is constructed on a test platform with dynamic response characteristics, and the identification algorithm is driven by introducing a watermark signal and setting a perturbation signal, so as to realize the dynamic online estimation of the inverter system model parameters and network attack detection.

[0159] The specific configuration of the embodiment is as follows: The experimental system is mainly composed of two independent photovoltaic power generation units, namely PV1 and PV2. Each power generation unit is connected to the low-voltage power grid through a DC / AC inverter. The output of each inverter is configured with a 3mH AC side filter inductor to suppress high-frequency switching noise. The system bus voltage is set to 200V, the inverter output grid is 120V AC effective value, and the PWM switching frequency is set to 15kHz, which can achieve high-quality waveform output. The rated total power of the system is 5kW, which can meet the analysis and testing requirements of various grid-connected operating conditions under experimental conditions.

[0160] In order to realize the system identification function, the voltage and current output signals of each inverter are collected by high-precision sensors. These signals include grid-side voltage and current. The collected signals are sampled in real time by the high-speed analog-to-digital conversion module and transmitted to the central control module. The controller not only undertakes the task of issuing inverter drive and operation instructions, but also uploads the collected data to the network security protection module synchronously. The data sampling period is 8ms, which meets the technical requirements of the IEEE 1547 standard for fast fault detection and control response time.

[0161] As a key unit of the system, the network protection module adopts anomaly detection technology based on watermark signals. The watermark signal is generated by an independent pseudo-random number generator and injected into the modulation command signals of inverter 1 and inverter 2 at the controller end. and , the watermark signal obeys zero mean uniform distribution, and its amplitude is controlled within 5% of the modulation depth to ensure that it does not interfere with the normal system operation. The control signal after watermark modulation will drive the PWM module to perform inverter power transmission. At the same time, the response characteristics of the watermark are also implied in the system output measured signal, thus providing a basis for subsequent attack detection and model identification.

[0162] In terms of attack simulation, this embodiment designs two common network attack scenarios: harmonic injection attack and replay attack. In the harmonic injection experiment, the attacker manipulates the current sensor signal z_inv[k] to superimpose the third and fifth harmonic components with moderate amplitudes and frequencies of 150Hz and 250Hz respectively on its output. The attack trigger time is set to t=50ms to simulate the response characteristics of the inverter output signal when it is polluted by harmonics. After the attack occurs, the system current waveform becomes obviously distorted from a standard sinusoidal waveform, with significant noise and high-order harmonic characteristics. At the same time, the test signals of Test 1 and Test 2 based on watermark variance analysis also rise and oscillate rapidly, forming an abnormal criterion that can be clearly detected.

[0163] In the replay attack experiment, the attacker captures a section of the transmission signal under the normal operation state of the system during the simulation recording stage, including the output voltage and current waveforms, etc., and replays and injects this section of the signal into the system at the attack stage (t = 200 ms), attempting to deceive the traditional attack response mechanism based on amplitude and frequency detection. However, the watermark signal detection method adopted by the present invention can successfully identify the defect of the replay signal, that is, the normal response characteristics after watermark injection are missing in the replay signal, resulting in a rapid increase in the variance characteristics of Test 1 and Test 2 after the attack occurs, and the appearance of high-frequency fluctuation characteristics, so as to realize the rapid discrimination and reporting of forged data.

[0164] During the model identification process, based on the collected input and output data, an ARMAX model of each group of inverters is constructed, where the model order is set as follows: the A order is 4, the B order is 3, and the transportation delay is 1. The parameter update is realized by the recursive algorithm in the least squares method, where the initial parameter estimation value is set as a small deviation, the variance covariance matrix is set as the identity matrix, and the forgetting factor is selected as 0.98 to improve the response flexibility and anti-interference ability. The identification process is executed in a loop inside the controller, and the data input window length is set according to the sampling period and the experimental period, and the updated system parameter estimation value is fed back in real time. This parameter estimation not only reflects the response characteristics of the current operating point of the system, but can also be used for subsequent controller adaptive adjustment, abnormal trend monitoring, and synchronous data update of the virtual simulation platform (digital twin).

[0165] Throughout the experimental process, the MATLAB / Simulink is used as the modeling and simulation platform for the simulation environment. The core inverter control logic and the ARMAX modeling module are built in Simulink, and each power link is modeled through Simscape Power Systems. The network attack module is implemented on the MATLAB script side, and the data storage and post-processing are completed by the corresponding data server and processing program. The final experimental results show that the parameter identification method proposed by the present invention has good modeling accuracy, can complete dynamic identification and abnormal detection within 8 ms, and can effectively support the stable operation and adaptive management of the photovoltaic inverter system under complex working conditions and network risks.

[0166] Figure 2 It is a network security architecture diagram of the photovoltaic system, showing the security architecture design of the photovoltaic grid-connected system based on dual inverters in a network attack environment. The system consists of two photovoltaic power generation units, which are respectively connected to the corresponding DC / AC inverters to output alternating current. The output voltage and current of each inverter are monitored by sensors, and the monitoring data is transmitted to the network protection box. Figure 2 The potential network attack points are marked in the signal path, indicating that the system has the ability to cope with network attacks (such as harmonic injection attacks and replay attacks). In addition, a watermark signal is injected into each inverter ( , to the modulation index, which is used to assist the network protection box to quickly detect abnormal behaviors within 8 ms specified by the IEEE 1547 standard. By introducing watermark signal detection and independently testing two inverters, this architecture can effectively identify and locate network attacks and improve the network security of the PV grid-connected system.

[0167] Figure 3 Fig. is the change diagram of the system response before and after the harmonic injection attack, showing the influence of the harmonic injection attack on the grid voltage and current waveforms and the variance signals of test signals 1 and 2. Figure 3 Fig. (a) shows the variation of the grid voltage and grid current with time before and after the attack (t = 50 ms). Before the attack, the grid current was a standard sine wave with an amplitude of 0.5; after the attack, due to the injection of the 3rd (150 Hz) and 5th (250 Hz) harmonics, the current waveform was significantly distorted, showing waveform distortion and amplitude disturbance. Figure 3 Fig. (b) shows the variance changes of test signal 1 and test signal 2. After the harmonic attack occurred at t = 50 ms, both curves showed a significant increase and oscillation characteristics, indicating that the system detected an abnormal disturbance. Harmonic injection will significantly damage the normal shape of the system current waveform and affect the system stability; the change of the test signal variance can quickly reflect the time point of the attack, indicating that the watermark signal mechanism has significant advantages in attack detection. Experiments show that the detection delay can be controlled within 8 ms.

[0168] Figure 4 Fig. shows the influence of the replay attack on the inverter operating characteristics and detection signals, showing the output waveforms of the inverter before and after suffering from the replay attack and the response characteristics of the detection signals based on the watermark signal. Figure 4 Fig. (a) shows the grid output voltage and current waveforms of the DC-AC inverter, which maintained a stable 50 Hz sine characteristic throughout the process. Even after the attack started at t = 200 ms, the waveforms did not show obvious changes. Figure 4 Fig. (b) shows the variance responses of two detection signals designed based on the watermark strategy during the entire experiment. Before the attack started, the variance values were relatively stable, about 3 for test 1 and about 4 for test 2; at the moment when the attack occurred at t = 200 ms, the variances of the two signals increased rapidly and showed high-frequency oscillations (rising to about 6 and 8 respectively), indicating an anomaly. The detection mechanism based on the watermark signal is highly sensitive and effective to the replay attack. Even if the attacker replays the real waveform data in the system history, the detection system can still quickly identify the anomaly through the change of the signal variance, providing key support for the network security of intelligent power systems such as PV inverters.

[0169] The above are only the preferred embodiments of the present invention, and are not intended to further limit the present invention. All equivalent changes made by using the content of the specification and drawings of the present invention are within the protection scope of the present invention.

Claims

1. A method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method, characterized in that It includes the following steps: Step S1: Collect the data of the photovoltaic inverter system, preprocess it, construct an ARMAX system parameter identification model, form a matrix of parameters to be identified, and obtain the ARMAX parameter vector; Step S2: Aiming at realizing attack detection and security verification, design a perturbation watermark signal with the characteristics of zero mean and Gaussian white noise distribution. The modified control signal formed by additive superposition of the perturbation watermark signal on the control input is used to drive the operation of the photovoltaic inverter system, construct the system's adversarial input sequence and the corresponding output response data after injecting the perturbation, generate an adversarial sample set and the system's reaction under the simulated attack scenario, and finally output the set of control input and output response data of the photovoltaic inverter system after superimposing the perturbation watermark signal; Step S3: Aiming at constructing a model that can identify potential network attacks in the photovoltaic inverter system, use the least squares method to estimate the parameters in the ARMAX system parameter identification model, establish an ARMAX prediction model, and design a dual variance detection mechanism based on the output deviation in combination with the measured output to form a network attack detection module. Adopt a parameter adaptive dynamic adjustment strategy to optimize the detection performance and generate the initial deployment parameter configuration; specifically: Step S301: On the basis of obtaining the data adversarial sample set composed of the perturbed control input and the system output response, use the least squares method to identify the ARMAX model parameters and construct the following optimization objective function: , The output is the estimated parameter ; where is the ARMAX parameter vector, k is the k-th sampling period; N is the number of sampling points initially used to train the model; X is the regression matrix of the ARMAX system parameter identification model; Y is the output vector; Step S302: Construct an ARMAX system identification model to identify the behavior of the watermark-free system; , Among them, is the system prediction output based on the ARMAX model, which is the system identification model at time for the prediction value of the current at the time; are the actually measured currents at the current and the previous time respectively; is the modulation index input for the k-th sampling period; Step S303: Construct an ARMAX system prediction model: , Among them, are the actual input control signals at the current and previous moments respectively; is the grid-connected current value predicted by the watermarking model; Step S304: Use a dual error variance mechanism to construct a prediction deviation detection model to evaluate whether the photovoltaic inverter system is currently in an attack state or a normal state. The variance indicators include: (1) Watermarking prediction error variance : , Among them, is the watermark signal at the k-th moment; (2)Variance of prediction error without watermark : , Among them, is the current measurement signal at the moment; is the sliding window length; and are the system predicted values of the watermark-free and watermarked respectively; Introduce the detection index difference: ; Step S305: Design a parameter adaptive dynamic adjustment strategy to optimize the performance of the network attack detection module; Step S306: Output the identification model parameters and the initial settings of the detection module; Step S4: Aiming at realizing the real-time detection of the attack behavior of the photovoltaic inverter system and the continuous optimization of the ARMAX system parameter identification model, construct an online optimization mechanism for network attack detection and system model of the photovoltaic inverter system.

2. The parameter identification method of a photovoltaic inverter system based on the ARMAX model and the least squares method according to claim 1, characterized in that Step S1 is specifically: Step S101: Establish a state - space model with the inductor current of the photovoltaic inverter and the capacitor voltage as state variables, as follows: , Among them, is the inductor current at the th sampling period; is the capacitor voltage at the th sampling period; is the modulation index input at the th sampling period; is the dynamic coupling coefficient of the state time evolution, representing the element of the state transition matrix ; is the influence coefficient of the modulation input on the state variable, representing the element of the control input matrix ; Step S102, with a fixed sampling period sample the photovoltaic inverter system to collect the timing data of the modulation index input and the grid-side output current: ; Among them, is the current on the grid-connected output side of the PV inverter in the th sampling period, and represents the number of sampling points initially used to train the model. Step S103: Perform outlier removal, missing value interpolation, and low-pass filtering denoising on the collected time series data, and construct a discrete multi-step difference model: , Among them, is the autoregressive coefficient of the output current, is the lag effect coefficient of the input modulation index quantity; Step S104: Considering the input delay and system random interference, expand the multi-step difference model into the following ARMAX system parameter identification model: , Among them, is the autoregressive coefficient, is the input item lag coefficient, is the noise item influence coefficient, is Gaussian white noise; Step S105: Construct the regression matrix of the ARMAX system parameter identification model: , Among them, ; is the constructed regression matrix, and its row is ; is the ARMAX parameter vector, ; is the modeling residual vector; Step S106: Solve for the estimated value of the ARMAX parameter vector using the least squares method, and the calculation formula is: ​ , Among them, is the transpose of, and is the estimated system parameter.

3. A method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method according to claim 2, characterized in that, Step S2 is specifically: Step S201: Generate a perturbed watermark signal that satisfies the characteristics of zero mean and Gaussian white noise distribution , satisfying: , Among them, is the watermark signal at the moment; is the perturbation watermark power; Step S202: Construct the modified control signal as: , Among them, is the actual control command after adding the additive superposition perturbation watermark signal, that is, the corrected control signal, which is injected into the photovoltaic inverter system; Step S203: Collect the adversarial input samples with the watermark signal at a fixed sampling period T, and construct an adversarial sample set containing the perturbation effect: ; Among them, represents the number of watermarked samples; Step S204: Simulate the attack scenario and simulate the influence of false data injection on the output of the photovoltaic inverter system.

4. A method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method according to claim 3, characterized in that, In Step S204, the attack simulation includes the following two methods: (1) Harmonic injection attack simulation, and the attack signal is defined as: , Wherein, are the amplitudes of the 3rd and 5th harmonics; , is the fundamental frequency, and are the 3rd and 5th harmonic frequencies; is the th sampling period, is the sampling period; (2) Replay attack simulation, the attack signal is: , Among them, represents the normal data pre-stored by the attacker, is the replay time window delay.

5. A method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method according to claim 3, characterized in that Step S305 is specifically as follows: Step S305-1, Dynamically optimize the power of the perturbation watermark ; By analyzing the distribution differences of the prediction error variances of the watermarked and non-watermarked ARMAX system prediction models in normal and attack states, the optimal range of values is selected to maximize the attack recognizability and suppress false alarms: , Among them, is the false alarm probability; is the miss alarm probability; Step S305-2, Optimization and adjustment of detection threshold ; To improve the sensitivity and stability of the network attack detection module of the photovoltaic inverter system, a detection threshold is constructed based on the statistical characteristics of the difference in detection indicators ;​ In the initial stage of system deployment, the following initial detection threshold is set: , Among them, is the variance under normal conditions; is the initial detection threshold of the network attack detection module; For the convenience of determining the discrimination boundary, assume that obeys a normal distribution: , During the operation of the system, the detection threshold is updated in real time as follows: , Among them, represents the moving window average of the previous ones; The sliding window average of the previous represents the standard deviation of the previous ones; The standard deviation of the previous is the sensitivity coefficient; Step S305-3, adjust the size of the sliding window To improve the adaptability of the network attack detection module under different noise environments and attack categories; , Among them, is the penalty weight for response delay, represents the variance when using a sliding window and represents the detection decision delay caused by the sliding window size being .

6. A method for identifying the parameters of a photovoltaic inverter system based on the ARMAX model and the least squares method according to claim 1, characterized in that, Step 4 is specifically as follows: Step S401: In each sampling period, input the updated measurement data and the disturbance control signal, and use the network attack detection module to calculate the current detection index difference and the dynamic detection threshold : If it satisfies , it is determined that the PV inverter system is under attack; if , it is considered that the PV inverter system is in a normal state; Step S402: Based on the working performance of the detection module within the current window, evaluate the performance indicators of the photovoltaic inverter network attack detection module; Step S403: Based on the evaluation results, the photovoltaic inverter system uses the recursive least squares method with a forgetting factor to update the ARMAX model parameters online, and its parameter update formula is: , Among them, is the current model parameter estimation, is the current input vector, is the actual output of the system, is the adaptive gain term; Step S404: Detection robustness evaluation; Step S405: Result output and system feedback update, specifically: Output the current system status determination; Output the ARMAX model parameter vector after recursive update: , Output the current configuration set of the detection system: , Step S406: After the system completes the identification and detection process, generate and output a system security report.

7. A method for identifying parameters of a photovoltaic inverter system based on an ARMAX model and the least squares method according to claim 6, characterized in that, In step S402, the performance evaluation of the photovoltaic inverter network attack detection module includes three types of evaluation indicators: detection timeliness, accuracy, and system stability, specifically including: Step S402-1: For the evaluation of detection timeliness, define the detection delay as the time difference from the actual start time of the attack to the time when it is correctly identified . The detection delay satisfies: ; Step S402-2: The accuracy indicators include accuracy rate, detection rate, and false alarm rate, which are respectively expressed as: , , , Among them, TP is the true positive example, TN is the true negative example, FP is the false positive example, and FN is the false negative example; Step S402-3. The stability indicators include the change in the output current ripple amplitude , the increment of the total harmonic distortion and the change in the output power , which are used to evaluate the degree of damage of the attack to the system operation quality.

Citation Information

Patent Citations

  • Parameter identification method of photovoltaic inverter system model

    CN112398170A

  • Modeling method and device for dynamic simulation model of power distribution network area

    CN117077525A

  • Method and system for identifying parameters of photovoltaic inverter controller

    CN119511867A

  • Identification of LCL filter parameters

    EP3096429A1

  • Photovoltaic inverter model parameter identification method based on dynamic locus sensitivity

    CN103592528A