False data injection attack detection method based on federal learning and comparative learning
By adopting federated learning and contrast learning technology in the power system, detecting false data injection attacks, the problem that existing power systems cannot identify abnormal data in a timely manner is solved, and the high reliability and safety protection capabilities of power system data are achieved.
Patent Information
- Application Number
- CN202510196781.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-17
AI Technical Summary
When facing false data injection attacks, existing power systems cannot identify and respond to abnormal data in a timely manner, resulting in the normal operation of power equipment being affected and poses safety hazards.
The false data injection attack detection method based on federated learning and contrast learning is adopted. By training the LSTM model locally on each power station, the model parameters and power data are managed using blockchain technology, and the global detection model is optimized in combination with contrast learning, abnormal data is identified in real time and alarms are generated.
It effectively reduces the risk of data leakage, improves the reliability and security protection capabilities of the power system data, can identify false data attacks in real time, avoids the lag of human intervention, and improves the stability and reliability of the system.
Smart Images

Figure CN120162832A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system security, and particularly to a false data injection attack detection method based on federated learning and contrastive learning. Background Art
[0002] The power system is one of the infrastructures of modern society, ensuring the stability of industrial production, commercial operation and residential life. The power system faces many security threats, needs to cope with natural disasters and equipment failure risks, and also needs to guard against various security threats in the cyberspace; the false data injection attack (FDIA) affects the normal operation of the power system by tampering with the sensor data in the power system so that the decision-making system cannot accurately judge the system state.
[0003] However, the existing power system relies on centralized data collection and processing. Data is usually uploaded to the central control center through the SCADA system. The storage and transmission of power data usually do not have sufficient encryption protection. If an attacker injects false data, the system cannot identify and respond to these abnormal data in time to make adjustments, thus affecting the normal operation of power equipment and causing potential safety hazards.
[0004] In view of the above technical deficiencies, a solution is proposed. Summary of the Invention
[0005] In view of the deficiencies of the prior art, the present invention provides a false data injection attack detection method based on federated learning and contrastive learning.
[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A false data injection attack detection method based on federated learning and contrastive learning, comprising the following steps:
[0007] Step 1: Collect power data such as voltage, phase, frequency, and equipment status from power stations, denoise using the wavelet transform method and fill in missing values using KNN interpolation, convert the data into JSON format, generate a hash value using SHA-256, and upload the JSON format data and the hash value to the blockchain;
[0008] Step 2: Use the federated learning framework FedAvg to train the LSTM model at each power station, extract feature vectors from the power station power data, manage the trained model parameters through the blockchain smart contract, and transmit the parameter hash value to the central power station together;
[0009] Step 3: The central power station collects the model parameters of each power station, uses contrastive learning to optimize the global detection model, evaluates the model similarity by calculating the Euclidean distance and cosine similarity, uses SimCLR to extract features, and finally uses Isolation Forest to detect abnormal model parameter data and eliminate them;
[0010] Step 4: Use the optimized global detection model to monitor and analyze the future power system data, extract key features through PCA dimensionality reduction, and use the ARI MA model to detect outliers. Use Z-Score to calculate the first threshold of historical records, compare the new data with the historical attack data, and if the deviation exceeds the threshold, mark it as abnormal data and generate an alarm information package to transmit to the alarm module;
[0011] Step 5: After receiving the alarm information package, the alarm module notifies the power management personnel through SMS API and email and activates the defense mechanism.
[0012] The operation data of the power system is collected from each power station in real time. The PMU of each power station is responsible for phasor measurement and collection of key data such as voltage, phase and frequency. The SCADA system is responsible for collecting equipment operation status, switch status and fault information. The collected power data is first denoised using the wavelet transform filtering method, and then the data is decomposed into multiple frequency bands, and finally reconstructed into smooth data. The KNN interpolation method is used to calculate the distance to the neighboring samples, where k is the nearest neighbor interpolation. The missing values are calculated based on the data of the k nearest neighbors to fill in the missing parts of the data. All data are converted into a unified JSON format, and the SHA-256 hash algorithm is used for data integrity verification. The SHA-256 algorithm is used to perform hash calculations on each set of data timestamps, device IDs, and data content information to generate a unique hash value. The above data and hash values are uploaded to the blockchain network, and the storage and query of data are managed through blockchain smart contracts.
[0013] The false data injection attack detection model is trained locally in each power station. Each power station uses the federated average FedAvg framework to train the model locally. Each power station uses data for training locally without uploading the original data to the central server. Each power station trains a long short-term memory network LSTM model to process the time series data of the power system and capture the trends and periodicity in the power system. The trained model parameters are uploaded to the blockchain smart contract for management, and the blockchain smart contract records the parameter hash value of each training.
[0014] The described central power station optimizes the global detection model. The model parameters collected from each power station are analyzed through contrast learning techniques. The SimCLR algorithm is used to extract features from the models of different power stations, calculate the Euclidean distance and cosine similarity of the model parameters of each power station, judge the similarity between the model parameters, mark the models with lower similarity, and then use the Isolation Forest anomaly detection algorithm to detect outliers in the marked model parameters. When significant differences are identified from other model parameters, they are removed. For the remaining normal model parameters, the Bootstrap Your Own Latent algorithm is used for unsupervised learning. The Bootstrap Your Own Latent algorithm uses two different perspectives to strengthen model learning.
[0015] The optimized global detection model monitors and analyzes the real-time data of the power system. The global detection model obtains the latest power system data voltage and current information, uses the principal component analysis (PCA) to reduce the dimension of the data, extracts representative features in the power system, and uses the autoregressive integrated moving average (ARIMA) time series prediction model to detect outliers in the data and generate deviation values.
[0016] The global detection model uses Z-Score calculation to set the first threshold for historical records, compares the current data with historical attack data. When the deviation value of a certain power data is greater than the first threshold, it is determined as abnormal data and the power system data is marked, generating an alarm signal and packaging the power system power data into an alarm information packet and transmitting it to the alarm module.
[0017] After receiving the alarm information packet, the alarm module sends alarm information to the power management personnel through the SMS API and email and activates the defense mechanism. It isolates the affected substation by cutting off specific circuit breakers, removes the power data of the affected substation, adjusts the load distribution of the power grid through the optimal power flow (OPF) algorithm, then schedules the power grid according to the power grid load and power demand, and finally records the attack event through the blockchain smart contract.
[0018] The present invention provides a false data injection attack detection method based on federated learning and contrast learning. Compared with the prior art, it has the following beneficial effects:
[0019] By combining the false data injection attack detection method with federated learning, each power station can train model parameters locally, thus avoiding the upload of original data and reducing the risk of data leakage. By using blockchain technology to manage model parameters and power data, the integrity and security of the data are ensured, thereby improving the data reliability and security protection ability of the power system;
[0020] By combining the use of contrastive learning methods, the present invention can identify abnormal data in real time when detecting false data, thereby generating an alarm information packet and transmitting it to the alarm module to trigger the defense mechanism, greatly improving the response efficiency of the power system to false data attacks, avoiding the lag of manual intervention, and improving the stability and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the principle framework of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0023] Please refer to Figure 1 , this application provides a false data injection attack detection method based on federated learning and contrastive learning, including the following steps:
[0024] Step 1: Collect power data such as voltage, phase, frequency, and equipment status from the power station, denoise it using the wavelet transform method and fill in missing values using KNN interpolation, convert the data into JSON format, generate a hash value using SHA-256, and upload the JSON format data and the hash value to the blockchain;
[0025] Step 2: Use the federated learning framework FedAvg to train the LSTM model at each power station, extract feature vectors from the power station power data, manage the trained model parameters through the blockchain smart contract, and record the parameter hash value and transmit it to the central power station together;
[0026] Step 3: The central power station collects the model parameters of each power station, optimizes the global detection model using contrastive learning, evaluates the model similarity by calculating the Euclidean distance and cosine similarity, extracts features using SimCLR, and finally uses Isolation Forest to detect and remove abnormal model parameter data;
[0027] Step 4: Use the optimized global detection model to monitor and analyze the subsequent power system data, extract key features through PCA dimensionality reduction, and use the ARIMA model to detect outliers. Calculate the first threshold of the historical record using Z-Score, compare the new data with the historical attack data, and if the deviation exceeds the threshold, mark it as abnormal data and generate an alarm information packet and transmit it to the alarm module;
[0028] Step 5: After receiving the alarm information packet, the alarm module notifies the power management personnel via SMS API and email and activates the defense mechanism.
[0029] Collect the operation data of the power system in real time from each power station. The PMU of each power station is responsible for phasor measurement to collect key data such as voltage, phase, and frequency; the SCADA system is responsible for collecting equipment operation status, switch status, and fault information. First, use the wavelet transform filtering method to denoise the collected power data, then decompose the data into multiple frequency bands, and finally reconstruct it into smooth data. Use the KNN interpolation method to calculate the distance between adjacent samples, where k is the nearest neighbor interpolation. Estimate the missing values based on the data of the k nearest neighbors to fill the missing parts in the data. Convert all data into a unified JSON format, and use the SHA-256 hash algorithm for data integrity verification. Use the SHA-256 algorithm to calculate the hash value for each group of data including timestamp, device ID, and data content information to generate a unique hash value. Upload the above data and hash values to the blockchain network, and manage the storage and query of data through the blockchain smart contract.
[0030] Train the false data injection attack detection model locally at each power station. Each power station uses the federated averaging FedAvg framework for model training locally. Each power station trains locally using its own data without uploading the original data to the central server. Each power station trains a long short-term memory network LSTM model to process the time series data of the power system and capture the trends and periodicities in the power system. The trained model parameters are uploaded to the blockchain smart contract for management, and the blockchain smart contract records the parameter hash value of each training.
[0031] During the training process, the power stations do not need to upload the original data to the central server, which avoids potential privacy leakage problems and reduces the bandwidth requirements for data transmission. Each power station only calculates the model parameters locally and uploads these parameters to the smart contract in the blockchain network through the federated learning framework for centralized management. The role of the blockchain here is to ensure the immutability and transparency of the data and model parameters. Automatically verify and store the parameter hash value of each model training through the smart contract. This operation can ensure that the training process of each power station is secure and traceable, avoiding the risk of data forgery.
[0032] The central power station optimizes the global detection model. The model parameters collected from each power station are analyzed through contrast learning techniques. The SimCLR algorithm is used to extract features from the models of different power stations, calculate the Euclidean distance and cosine similarity of the model parameters of each power station, judge the similarity between the model parameters, mark the models with low similarity, and then use the Isolation Forest anomaly detection algorithm to detect outliers in the marked model parameters. When a significant difference from other model parameters is identified, it is removed. For the remaining normal model parameters, the Bootstrap Your Own Latent (BYOL) algorithm is used for unsupervised learning. The BYOL algorithm uses two different perspectives to strengthen model learning.
[0033] The anomaly detection algorithm isolates different samples by constructing a decision tree to identify parameters that deviate significantly from other model parameters. Models detected as anomalies are removed to avoid their impact on the global detection model. Only model parameters that are confirmed to be normal and consistent will enter the subsequent optimization process; the BYOL algorithm strengthens the learning effect of the model by introducing samples from two different perspectives. It does not require the use of negative samples. This method helps the model better capture complex data patterns and potential laws by enhancing the feature representation under different perspectives.
[0034] The optimized global detection model monitors and analyzes the real-time data of the power system. The global detection model obtains the latest voltage and current information of the power system data, uses the principal component analysis (PCA) to reduce the dimension of the data, extracts representative features in the power system, and uses the autoregressive integrated moving average (ARIMA) time series prediction model to detect outliers in the data and generate deviation values.
[0035] The global detection model uses Z-Score calculation to set the first threshold for historical records, compares the current data with historical attack data. When the deviation value of a certain power data is greater than the first threshold, it is determined as abnormal data, and the power system data is marked, generating an alarm signal and packaging the power system power data into an alarm information packet and transmitting it to the alarm module.
[0036] After receiving the alarm information packet, the alarm module sends alarm information to the power management personnel through the SMS API and email and activates the defense mechanism. It isolates the affected substation by cutting off specific circuit breakers, removes the power data of the affected substation, adjusts the load distribution of the power grid through the optimal power flow (OPF) algorithm, then schedules the power grid according to the power grid load and power demand, and finally records the attack event through the blockchain smart contract.
[0037] Furthermore, by combining the false data injection attack detection method with federated learning, each power station can train model parameters locally, thus avoiding the upload of original data and reducing the risk of data leakage. By using blockchain technology to manage model parameters and power data, the integrity and security of the data are ensured, thereby improving the data reliability and security protection capabilities of the power system;
[0038] Furthermore, by combining the use of contrastive learning methods, abnormal data can be identified in real time when false data is detected, thereby generating an alarm information packet and transmitting it to the alarm module to trigger the defense mechanism, greatly improving the response efficiency of the power system to false data attacks, avoiding the lag of human intervention, and improving the stability and reliability of the system.
[0039] Specific working process:
[0040] Each power station collects power data such as voltage, phase, frequency, and equipment status, uses wavelet transform for filtering and denoising, applies the KNN interpolation method to fill in the missing values in the data, and converts the data into a unified JSON format. The SHA-256 algorithm is used to generate a hash value for each set of data to ensure data integrity, and the power data and hash values are uploaded to the blockchain for management. Each power station locally uses the federated learning framework to train the LSTM model for the analysis and feature extraction of power system time series data. The trained model parameters are uploaded through the blockchain smart contract. The central power station collects the model parameters uploaded by each power station, uses contrastive learning technology for feature extraction, and calculates the similarity between model parameters. Abnormal model parameters are identified and removed through the anomaly detection algorithm. The remaining valid model parameters use the Bootstrap Your Own Latent algorithm for reinforcement learning to optimize the global detection model. The optimized global detection model is used to monitor the real-time data of the power system. The data is dimensionally reduced through PCA, and the ARIMA model is used for time series anomaly detection. The deviation threshold is set by the Z-Score method. When the deviation value exceeds the first threshold, it is determined as abnormal data and an alarm information packet is generated. After receiving the alarm information packet, the alarm module notifies the power management personnel through the SMS API and email and activates the defense mechanism. The defense measures mainly isolate the affected substation by cutting off specific circuit breakers and then adjust the power grid load distribution to ensure the stability of the power grid. Finally, the attack event is recorded through the blockchain smart contract for subsequent auditing.
[0041] Some of the data in the above formula are numerically calculated after removing their dimensions, and the content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.
[0042] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A false data injection attack detection method based on federated learning and contrastive learning, characterized in that: The following steps are involved: Step 1: Collect voltage, phase, frequency, and equipment status power data from the power station, use wavelet transform to remove noise and use KNN interpolation to fill missing values, convert the data into JSON format, use SHA-256 to generate a hash value, and upload the JSON format data and hash value to the blockchain; Step 2: Use the federated learning framework FedAvg to train the LSTM model at each power station, extract feature vectors from the power data at the power station, manage the trained model parameters through blockchain smart contracts, and record the parameter hash values and transmit them to the central power station; Step 3: The central power station collects the model parameters of each power station, uses contrastive learning to optimize the global detection model, evaluates the model similarity by calculating the Euclidean distance and cosine similarity, uses SimCLR to extract features, and finally uses Isolation Forest to detect abnormal model parameter data and remove them; Step 4: Use the optimized global detection model to monitor and analyze the future power system data, extract key features through PCA dimensionality reduction, and use the ARIMA model to detect outliers. Use Z-Score to calculate the first threshold of historical records, compare the new data with the historical attack data, and if the deviation exceeds the threshold, mark it as abnormal data and generate an alarm information package to transmit to the alarm module; Step 5: After receiving the alarm information package, the alarm module notifies the power management personnel through SMS API and email and activates the defense mechanism.
2. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: The operation data of the power system is collected from each power station in real time. The PMU of each power station is responsible for phasor measurement and collection of key data such as voltage, phase and frequency. The SCADA system is responsible for collecting equipment operation status, switch status and fault information. The collected power data is first denoised using the wavelet transform filtering method, and then the data is decomposed into multiple frequency bands, and finally reconstructed into smooth data. The KNN interpolation method is used to calculate the distance to the neighboring samples, where k is the nearest neighbor interpolation. The missing values are calculated based on the data of the k nearest neighbors to fill in the missing parts of the data. All data are converted into a unified JSON format, and the SHA-256 hash algorithm is used for data integrity verification. The SHA-256 algorithm is used to perform hash calculations on each set of data timestamps, device IDs, and data content information to generate a unique hash value. The above data and hash values are uploaded to the blockchain network, and the storage and query of data are managed through blockchain smart contracts.
3. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: The false data injection attack detection model is trained locally in each power station. Each power station uses the federated average FedAvg framework to train the model locally. Each power station uses data for training locally without uploading the original data to the central server. Each power station trains a long short-term memory network LSTM model to process the time series data of the power system and capture the trends and periodicity in the power system. The trained model parameters are uploaded to the blockchain smart contract for management, and the blockchain smart contract records the parameter hash value of each training.
4. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: The central power station optimizes the global detection model, analyzes the model parameters collected from each power station through comparative learning technology, extracts features from models of different power stations through the SimCLR algorithm, calculates the Euclidean distance and cosine similarity of the model parameters of each power station, judges the similarity between the model parameters, marks the models with lower similarity, and then performs outlier detection on the marked model parameters through the anomaly detection algorithm Isolation Forest. When it is identified that there is a significant difference with other model parameters, it is eliminated. For the remaining normal model parameters, the Bootstrap Your Own Latent algorithm is used for unsupervised learning. The Bootstrap Your Own Latent algorithm uses two different perspectives to enhance model learning.
5. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: The optimized global detection model monitors and analyzes the real-time data of the power system. The global detection model obtains the latest voltage and current information of the power system data, uses principal component analysis PCA to reduce the dimension of the data, extracts representative features in the power system, and performs outlier detection on the data through the time series prediction model ARIMA to generate deviation values.
6. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: The global detection model uses Z-Score calculation to set a first threshold for historical records, compares current data with historical attack data, and when the deviation value of a certain power data is greater than the first threshold, it is determined to be abnormal data and the power system data is marked, an alarm signal is generated and the power system power data is packaged into an alarm information package and transmitted to the alarm module.
7. According to claim 1, a false data injection attack detection method based on federated learning and contrastive learning is characterized in that: After receiving the alarm information package, the alarm module sends the alarm information to the power management personnel through SMS API and email and activates the defense mechanism. It isolates the affected substation by cutting off the specific circuit breaker, removes the power data of the affected substation, adjusts the load distribution of the power grid through the optimal power flow optimization OPF algorithm, and then dispatches the power grid according to the power grid load and power demand. Finally, the attack event is recorded through the blockchain smart contract.
Citation Information
Cited By
Substation simulation through-flow test method based on comparative learning
CN121598272A
A substation analog through-flow test method based on contrast learning
CN121598272B