Power terminal safety protection model optimization training method, protection method and device
By training the initial security protection model in the edge node of the power terminal and optimizing the model in the cloud node, the problem of limited power terminal resources is solved, resulting in low model accuracy, and efficient and reliable security protection for the power terminal is achieved.
Patent Information
- Application Number
- CN202510172618.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, the power terminal itself has limited computing resources and storage resources, which makes the terminal security protection model it trains unable to guarantee the accuracy of and cannot meet the reliable and safe application requirements.
The three-layer cloud edge-end architecture is adopted to train the initial edge security protection model in the edge node, and optimize the initial cloud security protection model in the cloud node according to the model performance differences. Finally, the optimized model parameters are applied to the edge node to form a power terminal security protection model.
By transferring the security protection tasks of the power terminal to edge nodes with strong computing/storage resources, the model accuracy problems caused by limited power terminal resources are avoided, and the model is adaptively optimized through cloud nodes, which improves the accuracy of the power terminal for disturbance and attack detection, reduces the false alarm rate, and ensures reliable and efficient transmission of distribution network protection services.
Smart Images

Figure CN120106181A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electric power wireless communication, and relates to an electric power terminal safety protection model optimization training method, a protection method and a device. Background Art
[0002] With the acceleration of the construction of new power systems, the functions and forms of distribution networks need to undergo profound changes, and higher requirements are placed on distribution network protection and communication carrying capacity. In order to ensure the stable and reliable operation of power business terminals, it is necessary to jointly optimize and improve power business and wireless communications. At present, the power Internet of Things generally adopts a three-layer architecture of cloud, edge and end, focusing on the interaction and collaboration between the entire cloud, edge and end layers, mainly including cloud-edge collaboration, edge-end collaboration and cloud-edge-end collaboration.
[0003] Among them, cloud-edge collaboration is used to amplify the application value of edge computing and cloud computing. Edge computing is not only the execution unit of cloud computing sinking to the terminal side, but also the collection and preliminary processing unit of high-value data in the cloud, which can better support various applications in the cloud. Edge-end collaboration puts the real-time computing and analysis process closer to the power terminal equipment to ensure the real-time data processing and reduce the risk of data transmission. The edge node is mainly responsible for collecting and aggregating the local data and terminal business data of all power terminals in a certain area, providing real-time data processing, completing the analysis and reasoning of the perceived data, and further transmitting the results to the power terminal equipment, so as to achieve the collaboration between the power terminal equipment and the edge node.
[0004] However, due to bandwidth issues and data privacy issues for centralized data upload, the current reliable carrying and security protection tasks for power terminals are usually achieved by each power terminal independently training the corresponding terminal security protection model. In addition, improvements to the security and reliability of power terminals are usually made through encryption authentication, privacy protection, attack detection, interference elimination, application diversity and balancing technology to improve terminal security and reliability. However, this method requires high terminal computing power, but the computing and storage resources of the power terminal itself are limited, which makes it impossible to guarantee the accuracy of the terminal security protection model trained by the power terminal itself, and the result is low in accuracy, which cannot meet the requirements of reliable and secure applications. Summary of the invention
[0005] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide a power terminal safety protection model optimization training method, protection method and device.
[0006] In order to achieve the above object, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a method for training a power terminal security protection model, comprising: obtaining operating characteristic data of each power terminal within an edge node range; training a preset initial edge security protection model according to the operating characteristic data of each power terminal within the edge node range to obtain an initially trained edge security protection model of the edge node; obtaining an initially trained edge security protection model of each edge node within a cloud node range, and optimizing the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and an initial cloud security protection model preset for the cloud node to obtain an optimized cloud security protection model; obtaining model parameters of the optimized cloud security protection model and applying them to the initially trained edge security protection model of the edge node to obtain a power terminal security protection model of the edge node.
[0008] Optionally, the operating characteristic data includes one or more of the following: current data, voltage data, flow data, power factor, temperature and energy consumption.
[0009] Optionally, the initial edge security protection model and the initial cloud security protection model are both constructed based on long short-term memory networks, and both take the operating characteristic data of the power terminal as input and the predicted probability of the power terminal being subject to each security threat as output.
[0010] Optionally, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model, including: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between the model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, to obtain several target initially trained edge security protection models; and taking weighted average of the model parameters of several target initially trained edge security protection models and applying them to the initial cloud security protection model to obtain the optimized cloud security protection model.
[0011] Optionally, the method takes the distance between model parameters as the model performance difference, eliminates the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, and obtains several target initially trained edge security protection models. It also includes: using a k-nearest neighbor-based mean shift method to cluster each initially trained edge security protection model and the initial cloud security protection model based on model parameters, and eliminating the initially trained edge security protection models in each initially trained edge security protection model that do not belong to the same clustering cluster as the initial cloud security protection model.
[0012] According to a second aspect of the present invention, a device for training a power terminal safety protection model is provided, comprising: a data acquisition module for acquiring operating characteristic data of each power terminal within the range of an edge node; an edge training module for training a preset initial edge safety protection model according to the operating characteristic data of each power terminal within the range of the edge node, and obtaining an initially trained edge safety protection model of the edge node; a cloud optimization module for acquiring the initially trained edge safety protection model of each edge node within the range of the cloud node, and optimizing the initial cloud safety protection model according to the model performance difference between each initially trained edge safety protection model and the initial cloud safety protection model preset by the cloud node, and obtaining an optimized cloud safety protection model; an edge optimization module for acquiring model parameters of the optimized cloud safety protection model and applying them to the initially trained edge safety protection model of the edge node, and obtaining a power terminal safety protection model of the edge node.
[0013] Optionally, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model, including: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between the model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, to obtain several target initially trained edge security protection models; and taking weighted average of the model parameters of several target initially trained edge security protection models and applying them to the initial cloud security protection model to obtain the optimized cloud security protection model.
[0014] Optionally, the method takes the distance between model parameters as the model performance difference, eliminates the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, and obtains several target initially trained edge security protection models. It also includes: using a k-nearest neighbor-based mean shift method to cluster each initially trained edge security protection model and the initial cloud security protection model based on model parameters, and eliminating the initially trained edge security protection models in each initially trained edge security protection model that do not belong to the same clustering cluster as the initial cloud security protection model.
[0015] According to a third aspect of the present invention, a method for protecting the security of power terminals is provided, comprising: obtaining operating characteristic data of each power terminal within the range of an edge node; and obtaining the predicted probability of each power terminal within the range of the edge node being subject to each security threat through the above-mentioned power terminal security protection model of the edge node based on the operating characteristic data of each power terminal within the range of the edge node.
[0016] According to a fourth aspect of the present invention, there is provided a power terminal security protection device, comprising: a data acquisition module for acquiring operating characteristic data of each power terminal within the edge node range; and a security protection module for obtaining the predicted probability of each power terminal within the edge node range being subject to each security threat based on the operating characteristic data of each power terminal within the edge node range and through the power terminal security protection model of the edge node.
[0017] In a fifth aspect, the present invention provides a power terminal safety protection system, comprising a cloud node and edge nodes; the cloud optimization module mentioned above is arranged in the cloud node; the data acquisition module, edge training module and edge optimization module mentioned above and the power terminal safety protection device mentioned above are arranged in the edge node.
[0018] In a sixth aspect of the present invention, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned power terminal safety protection model training method or the above-mentioned power terminal safety protection method when executing the computer program.
[0019] In a seventh aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned power terminal safety protection model training method or the steps of the above-mentioned power terminal safety protection method are implemented.
[0020] Compared with the prior art, the present invention has the following beneficial effects:
[0021] The power terminal security protection model training method of the present invention is based on the cloud-edge-end three-layer architecture, and trains the initial edge security protection model in the edge node to obtain the initially trained edge security protection model of the edge node. Then, in the cloud node, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node. Then, the model parameters of the optimized cloud security protection model are applied to the initially trained edge security protection model of the edge node to obtain the power terminal security protection model of the edge node to perform security protection of the power terminal. The method of the present invention transfers the reliable bearing and security protection tasks of the power terminal to the edge node with strong computing / storage resources, and the edge node completes the model training work, thereby avoiding the model accuracy problem caused by the defects of the limited computing resources and storage resources of the power terminal itself, and combining with the cloud node to realize the aggregation of the models of each edge node to realize the adaptive optimization of the cloud security protection model, avoiding the bandwidth problem and data privacy problem of the data center upload, and can ensure the accuracy of the power terminal in detecting disturbances and attacks and other behaviors, and reduce the false alarm rate, so that the power terminal can effectively detect the poor stability of the bottom-level architecture and external attacks, ensure the reliable and efficient transmission of the distribution network protection business, and realize the efficient and reliable bearing of the power business. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a flow chart of the power terminal safety protection model training method according to an embodiment of the present invention.
[0023] Figure 2 Schematic diagram of the optimization principle of the initial cloud security protection model according to an embodiment of the present invention.
[0024] Figure 3 This is a structural block diagram of a power terminal safety protection model training device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0027] The present invention is further described in detail below in conjunction with the accompanying drawings:
[0028] See also Figure 1 In one embodiment of the present invention, a method for training a power terminal security protection model is provided, which can effectively improve the detection accuracy of the power terminal security protection model, thereby improving the accuracy of the power terminal's detection of disturbances, attacks and other behaviors, reducing the false alarm rate, and ensuring the reliable and efficient transmission of distribution network protection services.
[0029] Specifically, the power terminal safety protection model training method of the present invention includes the following steps:
[0030] S1: Obtain the operating characteristic data of each power terminal within the edge node range;
[0031] S2: According to the operation characteristic data of each power terminal within the edge node range, a preset initial edge safety protection model is trained to obtain an initial training edge safety protection model of the edge node;
[0032] S3: Obtain the initially trained edge security protection model of each edge node within the cloud node range, and optimize the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain an optimized cloud security protection model;
[0033] S4: Obtain the model parameters of the optimized cloud security protection model and apply them to the initially trained edge security protection model of the edge node to obtain the power terminal security protection model of the edge node.
[0034] The power terminal security protection model training method of the present invention is based on the cloud-edge-end three-layer architecture, and trains the initial edge security protection model in the edge node to obtain the initially trained edge security protection model of the edge node. Then, in the cloud node, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node. Then, the model parameters of the optimized cloud security protection model are applied to the initially trained edge security protection model of the edge node to obtain the power terminal security protection model of the edge node to perform security protection of the power terminal. The method of the present invention transfers the reliable bearing and security protection tasks of the power terminal to the edge node with strong computing / storage resources, and the edge node completes the model training work, thereby avoiding the model accuracy problem caused by the defects of the limited computing resources and storage resources of the power terminal itself, and combining with the cloud node to realize the aggregation of the models of each edge node to realize the adaptive optimization of the cloud security protection model, avoiding the bandwidth problem and data privacy problem of the data center upload, and can ensure the accuracy of the power terminal in detecting disturbances and attacks and other behaviors, and reduce the false alarm rate, so that the power terminal can effectively detect the poor stability of the bottom-level architecture and external attacks, ensure the reliable and efficient transmission of the distribution network protection business, and realize the efficient and reliable bearing of the power business.
[0035] In a possible implementation manner, the operating characteristic data includes one or more of the following: current data, voltage data, flow data, power factor, temperature, and energy consumption.
[0036] Explanatory note, considering the various types of power terminals, if invasive means are used to perform safe and reliable detection of power terminals, it will increase the burden on the power system. Therefore, the present invention uses non-invasive means to monitor the safety of terminal equipment by performing security monitoring on the operating characteristic data of the power terminals.
[0037] Exemplarily, in this embodiment, the operation characteristic data includes current data, voltage data and flow data. Among them, the current data may include current amplitude, current frequency and harmonics, current phase difference, current waveform and current transient characteristics, etc., the voltage data may include voltage amplitude, voltage waveform and voltage phase difference, etc., and the flow data may include data flow and protocol characteristics, etc.
[0038] In one possible implementation, the initial edge security protection model and the initial cloud security protection model are both constructed based on long short-term memory networks, and both take the operating characteristic data of the power terminal at several historical moments as input, and take the predicted probability of the power terminal being subject to each security threat at the predicted moment as output.
[0039] Explanatory, in order to effectively extract the correlation between the operating characteristic data of the power terminal equipment and the security threat, the present invention adopts deep learning to obtain this relationship. Deep learning is a new research direction in the field of machine learning, and its predecessor is artificial neural network. The core idea is to integrate feature extraction and classification into a framework, and use multiple processing layers composed of multiple nonlinear transformations to highly abstract the data, so as to realize the automatic extraction of data features and convert the original data into a higher-level and more abstract expression. Classic deep learning algorithms include deep neural networks, convolutional neural networks, recurrent neural networks, etc.
[0040] Among them, deep neural networks (DNN) are the foundation of deep learning. As a fully connected network with a very deep number of layers, the number of layers of DNN determines the neural network's ability to characterize data, and uses fewer neurons in each layer to fit more complex functions. Convolutional neural networks (CNNs) are very similar to ordinary neural networks. They are composed of neurons with learnable weights and bias constants. Each neuron receives some input, and after the middle layer performs dot product calculations, it outputs the probability of each classification. Convolutional neural networks change the structure of neural networks. It is no longer a fully connected structure, which greatly reduces the parameters of the network; at the same time, the network parameters are further reduced through parameter sharing. It takes into account spatial structure and local features, and is very suitable for the field of image processing. Recurrent neural network (RNN) is a type of recursive neural network that takes sequence data as input, recursively in the direction of sequence evolution, and all nodes (recurrent units) are connected in a chain. Since RNN has a strong internal memory, it can use its internal memory to process input sequences of any time sequence and predict the trend of sequence data based on the relationship between the previous and subsequent time sequences. Therefore, RNN is often used to deal with translation and time-related problems.
[0041] Explanatory, the power terminal security protection model training method of the present invention can be considered as a complete iterative step in an iterative method. Among them, when the first iteration is performed, the initial edge security protection model can be a deep learning model built based on a long short-term memory network (LSTM), and when the subsequent iteration is performed, the initial edge security protection model can be the power terminal security protection model obtained after the last iteration. Similarly, when the initial cloud security protection model is first iterated, it can be an initial training edge security protection model with better performance manually selected from various initial training edge security protection models, and when the subsequent iteration is performed, the initial cloud security protection model can be an optimized cloud security protection model obtained after the last iteration.
[0042] In this implementation, a LSTM-based model is used to mine the deep attack patterns of the operation characteristic data of the power terminal, thereby detecting whether the power terminal is attacked by hackers and judging the stability and reliability of the current bearer network. The input is composed of the operation characteristic data of the power terminal, and the output is the predicted probability of the power terminal being subjected to each security threat. Starting from time tn, by associating the operation characteristic data of the power terminal at k-1 times, the probability value of each threat at time t-n+k is finally output, thereby determining the type of attack the terminal is subjected to. Exemplarily, the operation characteristic data in this implementation adopts current data, voltage data and flow data, which can be expressed as:
[0043]
[0044] in, is the operating characteristic data of the i-th power terminal at time tn; represents the current data of the i-th power terminal at time tn; represents the voltage data of the i-th power terminal at time tn; Represents the flow data of the i-th power terminal at time tn.
[0045] The model is used to associate the operating characteristic data of k-1 time series and the output is obtained:
[0046]
[0047] in, is the predicted probability vector of the i-th power terminal being subject to m types of security threats at time t-n+k, is the predicted probability that the i-th power terminal is subject to the m-th security threat at time t-n+k.
[0048] In a possible implementation, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model, including: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between the model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, to obtain several target initially trained edge security protection models; and taking weighted average of the model parameters of several target initially trained edge security protection models and applying them to the initial cloud security protection model to obtain the optimized cloud security protection model.
[0049] Explanatory, the central server analysis data of traditional cloud nodes cannot meet the service experience of existing users due to the large amount of transmission delay. Therefore, the edge node uses deep learning methods to continuously detect the power terminal to reduce the delay of user request response and reduce the energy consumption generated by the central server analysis data.
[0050] However, since the data collected by the edge node may have distribution feature tilt or data imbalance, the detection model trained by each edge node may be inconsistent. When the central server wants to integrate the model trained by the edge node, it obviously needs a scientific method to effectively integrate the model. At this time, federated learning can solve the problem of model integration. Federated Learning (FL) is a collaborative combination method to solve machine learning. Generally, the central server samples and selects from a group of qualified clients. After each selected client downloads the current model weights and training program from the central server, the client executes the training program based on local data and updates the model. The central server updates the shared model locally based on the aggregated update calculated from the clients participating in the current round. It can be seen that the original data of each client does not need to be uploaded to the central server, but the purpose of model self-learning and self-updating is achieved by training model parameters locally and summarizing them to the central server. Federated learning can solve the bandwidth problem caused by uploading massive data to the central server. At the same time, federated learning can obtain the edge model trained by the edge node without the edge node disclosing its own data, and in some way make the gap between the central model and the edge model small enough.
[0051] In order to effectively measure the gap between the edge model and the central model, the model performance is used to measure the gap between the initial training edge security protection model and the initial cloud security protection model, so as to measure the accuracy loss of the initial cloud security protection model in federated learning. In this embodiment, the distance between the model parameters is used as the model performance difference, and the distance between the model parameters of each initial training edge security protection model and the initial cloud security protection model is calculated, and combined with the preset model performance difference threshold (a distance threshold), the initial training edge security protection model whose distance between model parameters is less than the model performance difference threshold is selected, and then the weighted average method is used to integrate the model parameters of the selected initial training edge security protection model, and the integration results are summarized to the initial cloud security protection model to realize adaptive update. The updated initial cloud security protection model sends its model parameters to the edge node to realize the update of the initial training edge security protection model, and enters the next round of iteration. The edge node once again collects the operating characteristic data of the power terminal, and updates and iterates the next round of model parameters based on the new round of operating characteristic data.
[0052] Exemplarily, when using the weighted averaging method to integrate the model parameters of the selected initially trained edge security protection models, the weights of the model parameters of each initially trained edge security protection model can be set according to the size of the distance between the model parameters of the initially trained edge security protection model and the model parameters of the initial cloud security protection model, or can be set according to indicators such as the accuracy of each initially trained edge security protection model.
[0053] In a possible implementation, the distance between model parameters is used as the model performance difference, and the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold are eliminated to obtain several target initially trained edge security protection models. It also includes: using a k-nearest neighbor-based mean shift method to cluster each initially trained edge security protection model and the initial cloud security protection model based on model parameters, and eliminating the initially trained edge security protection models that do not belong to the same clustering cluster as the initial cloud security protection model in each initially trained edge security protection model.
[0054] Explanatory, see Figure 2 , for a large number of edge centers, if the accuracy of each initially trained edge security protection model is compared one by one with the initial cloud security protection model, it is likely to waste bandwidth resources and computing resources. Therefore, after clustering the initially trained edge security protection models, some initially trained edge security protection models that do not meet the accuracy are removed, and then the performance gap between the initially trained edge security protection model and the initial cloud security protection model is calculated to measure which initially trained edge security protection models are suitable for integration and optimization, and which initially trained edge security protection models are not suitable for integration and optimization.
[0055] In this implementation, a mean shift method based on k-nearest neighbors is used to eliminate low-performance initially trained edge security protection models. The mean shift method based on k-nearest neighbors can automatically learn the number of classes based on the density distribution of the sample data itself, thereby achieving the purpose of clustering similar models.
[0056] Specifically, the selection of the initial training edge security protection model based on the mean shift method of k-nearest neighbors:
[0057] Assume that the model parameters of any initial training edge security protection model are X = {X 1 ,X 2 ,...,X N}, the i-th nearest neighbor model close to the initial cloud security protection model is X (i) , then the Mean Shift vector corresponding to the model parameters of the initial cloud security protection model is ""
[0058]
[0059] Among them, the Mean Shift vector is the vector difference between the weighted average value (i.e., the centroid) of the current data point and the position of the data point itself, and K(*) is the kernel function, which is generally a Gaussian kernel, an Epanechnikov kernel, etc.
[0060] The mean shift method based on k nearest neighbors does not require the number of clusters to be determined in advance. The intercept distance from X to its kth nearest neighbor point depends on the preset circular sliding window, and the change of the circular sliding window radius determines the number of neighbor points.
[0061] After selecting k initially trained edge security protection models that meet the sliding window radius through the mean shift method based on k nearest neighbors, the distance between the model parameters of the k initially trained edge security protection models and the model parameters of the initial cloud security protection model is calculated to measure the accuracy loss of the initially trained edge security protection model and the initial cloud security protection model. Assume that the model parameters of the initial cloud security protection model are Y = {Y 1 ,Y 2 ,...,Y N}, then the distance d(X,Y) between the model parameters of any initially trained edge security protection model and the model parameters of the initial cloud security protection model can be expressed as:
[0062]
[0063] On this basis, combined with the preset model performance difference threshold, an initially trained edge security protection model that meets the conditions is selected, that is, an initially trained edge security protection model whose model parameters are no more than the preset model performance difference threshold from the initial cloud security protection model, for optimizing the initial cloud security protection model.
[0064] In another embodiment of the present invention, a power terminal security protection method is provided, which is implemented based on the power terminal security protection model of the edge node mentioned above.
[0065] Specifically, the power terminal safety protection method of the present invention includes the following steps:
[0066] Obtain the operating characteristic data of each power terminal within the edge node range; based on the operating characteristic data of each power terminal within the edge node range, through the above-mentioned edge node power terminal security protection model, obtain the predicted probability of each power terminal within the edge node range being subject to each security threat.
[0067] The power terminal security protection method of the present invention transfers the power terminal security protection work to the edge node, effectively utilizes the computing resources of the edge node, and combines the power terminal security protection model obtained by the above-mentioned power terminal security protection model training method to achieve accurate prediction of security threats and realize effective protection.
[0068] The following are device embodiments of the present invention, which can be used to implement the method embodiments of the present invention. For details not disclosed in the device embodiments, please refer to the method embodiments of the present invention.
[0069] See also Figure 3 In another embodiment of the present invention, a power terminal safety protection model training device is provided, which can be used to implement the above-mentioned power terminal safety protection model training method. The power terminal safety protection model training device includes a data acquisition module, an edge training module, a cloud optimization module and an edge optimization module.
[0070] Among them, the data acquisition module is used to obtain the operating characteristic data of each power terminal within the edge node range; the edge training module is used to train the preset initial edge security protection model according to the operating characteristic data of each power terminal within the edge node range, and obtain the initial trained edge security protection model of the edge node; the cloud optimization module is used to obtain the initial trained edge security protection model of each edge node within the cloud node range, and optimize the initial cloud security protection model according to the model performance difference between each initial trained edge security protection model and the initial cloud security protection model preset by the cloud node, and obtain the optimized cloud security protection model; the edge optimization module is used to obtain the model parameters of the optimized cloud security protection model and apply it to the initial trained edge security protection model of the edge node, and obtain the power terminal security protection model of the edge node.
[0071] In a possible implementation, the initial cloud security protection model is optimized according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model, including: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between the model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, to obtain several target initially trained edge security protection models; and taking weighted average of the model parameters of several target initially trained edge security protection models and applying them to the initial cloud security protection model to obtain the optimized cloud security protection model.
[0072] In a possible implementation, the distance between model parameters is used as the model performance difference, and the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold are eliminated to obtain several target initially trained edge security protection models. It also includes: using a k-nearest neighbor-based mean shift method to cluster each initially trained edge security protection model and the initial cloud security protection model based on model parameters, and eliminating the initially trained edge security protection models that do not belong to the same clustering cluster as the initial cloud security protection model in each initially trained edge security protection model.
[0073] In another embodiment of the present invention, there is provided a power terminal safety protection device, which can be used to implement the above-mentioned power terminal safety protection method. The power terminal safety protection device includes a data acquisition module and a safety protection module.
[0074] Among them, the data acquisition module is used to obtain the operating characteristic data of each power terminal within the edge node range; the security protection module is used to obtain the predicted probability of each power terminal within the edge node range being subject to each security threat based on the operating characteristic data of each power terminal within the edge node range through the above-mentioned edge node power terminal security protection model.
[0075] In another embodiment of the present invention, a power terminal safety protection system is provided, which is implemented based on the existing cloud-edge-end three-layer architecture with edge computing as the core. Specifically, the power terminal safety protection system includes a cloud node and each edge node; the cloud node is provided with the above-mentioned cloud optimization module; the edge node is provided with the above-mentioned data acquisition module, edge training module and edge optimization module and the above-mentioned power terminal safety protection device.
[0076] All relevant contents of the steps involved in the aforementioned power terminal safety protection model training method and the embodiment of the power terminal safety protection method can be referred to the functional description of the functional modules corresponding to the power terminal safety protection model training device and the power terminal safety protection device in the embodiment of the present invention, and will not be repeated here.
[0077] The division of modules in the embodiments of the present invention is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional module in each embodiment of the present invention may be integrated into one processor, or may exist physically separately, or two or more modules may be integrated into one module. The above-mentioned integrated modules may be implemented in the form of hardware or in the form of software functional modules.
[0078] In another embodiment of the present invention, a computer device is provided, the computer device including a processor and a memory, the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, which are suitable for implementing one or more instructions, and are specifically suitable for loading and executing one or more instructions in a computer storage medium to implement the corresponding method flow or corresponding functions; the processor described in the embodiment of the present invention can be used to implement the steps of the power terminal safety protection model training method or the steps of the power terminal safety protection method.
[0079] In another embodiment of the present invention, the present invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It can be understood that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space, which stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the steps of the power terminal safety protection model training method or the power terminal safety protection method in the above embodiment.
[0080] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0081] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0082] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for training a power terminal safety protection model, characterized in that: include: Obtain the operating characteristic data of each power terminal within the edge node range; According to the operation characteristic data of each power terminal within the edge node range, a preset initial edge safety protection model is trained to obtain an initial training edge safety protection model of the edge node; Obtain the initially trained edge security protection model of each edge node within the cloud node range, and optimize the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model; The model parameters of the optimized cloud security protection model are obtained and applied to the initially trained edge security protection model of the edge node to obtain the power terminal security protection model of the edge node.
2. The power terminal safety protection model training method according to claim 1 is characterized in that: The operation characteristic data includes one or more of the following: Current data, voltage data, flow data, power factor, temperature and energy consumption.
3. The power terminal safety protection model training method according to claim 1 is characterized in that: The initial edge security protection model and the initial cloud security protection model are both constructed based on long short-term memory networks, and both take the operating characteristic data of the power terminal as input and the predicted probability of the power terminal being subject to each security threat as output.
4. The power terminal safety protection model training method according to claim 1 is characterized in that: The optimizing the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model includes: Taking the distance between model parameters as the model performance difference, the initially trained edge security protection models whose model parameters are farther away from the initial cloud security protection model than a preset model performance difference threshold are eliminated to obtain several target initially trained edge security protection models; The model parameters of several target initially trained edge security protection models are weighted averaged and applied to the initial cloud security protection model to obtain an optimized cloud security protection model.
5. The power terminal safety protection model training method according to claim 4 is characterized in that: The method further includes: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, and obtaining a plurality of target initially trained edge security protection models. The k-nearest-neighbor based mean shift method is adopted to cluster the initially trained edge security protection models and the initial cloud security protection models based on model parameters, and the initially trained edge security protection models that do not belong to the same clustering cluster as the initial cloud security protection model are eliminated.
6. A power terminal safety protection model training device, characterized in that: include: A data acquisition module is used to obtain the operating characteristic data of each power terminal within the edge node range; The edge training module is used to train a preset initial edge safety protection model according to the operation characteristic data of each power terminal within the edge node range to obtain the initial training edge safety protection model of the edge node; The cloud optimization module is used to obtain the initially trained edge security protection model of each edge node within the cloud node range, and optimize the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain an optimized cloud security protection model; The edge optimization module is used to obtain the model parameters of the optimized cloud security protection model and apply them to the initially trained edge security protection model of the edge node to obtain the power terminal security protection model of the edge node.
7. The power terminal safety protection model training device according to claim 6 is characterized in that: The optimizing the initial cloud security protection model according to the model performance difference between each initially trained edge security protection model and the initial cloud security protection model preset by the cloud node to obtain the optimized cloud security protection model includes: Taking the distance between model parameters as the model performance difference, the initially trained edge security protection models whose model parameters are farther away from the initial cloud security protection model than a preset model performance difference threshold are eliminated to obtain several target initially trained edge security protection models; The model parameters of several target initially trained edge security protection models are weighted averaged and applied to the initial cloud security protection model to obtain an optimized cloud security protection model.
8. The power terminal safety protection model training device according to claim 7 is characterized in that: The method further includes: taking the distance between model parameters as the model performance difference, eliminating the initially trained edge security protection models whose distance between model parameters and the initial cloud security protection model is greater than a preset model performance difference threshold, and obtaining a plurality of target initially trained edge security protection models. The k-nearest-neighbor based mean shift method is adopted to cluster the initially trained edge security protection models and the initial cloud security protection models based on model parameters, and the initially trained edge security protection models that do not belong to the same clustering cluster as the initial cloud security protection model are eliminated.
9. A power terminal safety protection method, characterized in that: include: Obtain the operating characteristic data of each power terminal within the edge node range; According to the operating characteristic data of each power terminal within the edge node range, the predicted probability of each power terminal within the edge node range being subject to each security threat is obtained through the power terminal security protection model of the edge node as described in any one of claims 1 to 5.
10. A power terminal safety protection device, characterized in that: include: A data acquisition module is used to obtain the operating characteristic data of each power terminal within the edge node range; A security protection module is used to obtain the predicted probability of each power terminal within the edge node range being subject to each security threat based on the operating characteristic data of each power terminal within the edge node range and through the power terminal security protection model of the edge node as described in any one of claims 1 to 5.
11. A power terminal safety protection system, characterized in that: Including cloud nodes and edge nodes; The cloud optimization module according to claim 6 is arranged in the cloud node; The data acquisition module, edge training module and edge optimization module described in claim 6 and the power terminal safety protection device described in claim 10 are arranged in the edge node.
12. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, it implements the steps of the power terminal safety protection model training method as described in any one of claims 1 to 5, or the steps of the power terminal safety protection method as described in claim 9.
13. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the power terminal safety protection model training method as described in any one of claims 1 to 5, or the steps of the power terminal safety protection method as described in claim 9 are implemented.