Series compensation capacitor and PMU measurement tampering-based concealment attack method
By tampering with the series compensation capacitor parameters and PMU measurement data, and using the system dynamic model to build an attack strategy, it solves the problem that the existing technology is difficult to secretly cause sub-synchronous oscillation of the power system, and achieves a highly concealed and destructive attack effect.
Patent Information
- Application Number
- CN202510319943.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The prior art is difficult to trigger sub-synchronous oscillation of the power system without being detected by the monitoring system through hidden cyber attack methods, and traditional detection methods are difficult to recognize such attacks.
By tampering with the parameters of the series compensation capacitor and PMU measurement data, an attack strategy is constructed using the system dynamic model and state space equations, causing system oscillations, and eliminating the interference of the attack on the measurement data through dynamic state estimation.
It realizes that sub-synchronous oscillation of the power system is triggered without being detected by the monitoring system, which improves the concealment and destructiveness of the attack, enhances the attacker's interference methods, and also poses new challenges for power grid security protection.
Smart Images

Figure CN120223377A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a stealth attack method based on series compensation capacitors and PMU measurement tampering, belonging to the technical field of subsynchronous oscillation attacks in power systems. Background Art
[0002] With the continuous growth of global energy demand and the increasing depletion of traditional fossil energy, wind power generation technology has been widely promoted and applied due to its clean and renewable advantages. However, wind power has significant volatility and intermittency characteristics, which pose a huge challenge to the stable operation of power systems. To improve the utilization efficiency of wind power and achieve multi-energy coordination, energy forms such as wind power, photovoltaic power, and thermal power have achieved deep integration. While this multi-energy integration improves the comprehensive energy utilization efficiency, it also brings many complex security challenges.
[0003] First, the inherent intermittency and volatility of wind power itself easily lead to unstable power output, thereby threatening the stability of grid frequency and voltage and affecting the overall operation reliability of the power system. Second, the coordinated scheduling of multiple energies significantly increases the complexity of system control. The frequent load regulation of traditional thermal power units in response to new energy fluctuations will accelerate the aging and loss of equipment. Finally, the intelligence and networking of power systems, while improving the system response speed and operation flexibility, also bring increasingly severe network attack and data security risks, posing a threat to the safe operation of power systems.
[0004] Sub-synchronous oscillation (SSO), as a major threat to the operation stability of power systems, is usually caused by the dynamic interaction between generators and the power grid. When the oscillation frequency of the generator rotor is close to or the same as the subsynchronous resonance frequency of the power grid, the energy of the system will continuously exchange between the generator and the power grid at the subsynchronous frequency, resulting in unstable oscillation of the generator rotor. In recent years, a number of studies have confirmed that the interaction between the rotor-side converter controller of a doubly-fed induction wind generator (DFIG) and a series capacitor compensator may also induce sub-synchronous oscillation.
[0005] Once sub-synchronous oscillation occurs, it may cause serious damage to grid equipment, and even lead to the tripping of large-scale new energy units, further inducing shaft torsional vibration of nearby thermal power units. For example, in 2009, a wind farm in Texas, USA, experienced a large-area turbine trip due to a sub-synchronous oscillation event, and the turbine protection equipment was severely damaged; in 2015, the sub-synchronous harmonic event triggered by a wind farm in Hami City, Xinjiang Uygur Autonomous Region, China, even spread to a thermal power plant 48 kilometers away, causing the tripping of sub-synchronous resonance protection; in 2019, due to a lightning strike event that reduced the grid strength, the Hornsea offshore wind farm in the UK triggered sub-synchronous oscillation and caused large-scale wind turbine tripping.
[0006] Traditionally, sub-synchronous oscillation events have mostly been regarded as caused by system operation failures or equipment parameter configuration problems, and such events can usually be effectively identified through power grid monitoring systems. However, in recent years, cyberattacks on power systems have occurred frequently, and a new and highly threatening problem has gradually emerged: Can sub-synchronous oscillations be artificially induced through concealed cyberattack means and conventional detection means be circumvented, thus threatening the safe operation of the power grid?
[0007] Although existing cyberattack research has demonstrated the potential threats of cyberattacks, most research has not considered the sub-synchronous oscillation effects generated by the interaction between doubly-fed induction generators (DFIGs) and series capacitor compensators. In addition, current cyberattack behaviors can still be effectively identified by traditional oscillation detection methods and it is difficult to truly cause substantial and continuous damage to power grid security. Therefore, proposing a tampering attack that can utilize series compensation capacitor compensation equipment and PMU measurement data without being detected by the monitoring system, thereby inducing sub-synchronous oscillations and covering up the traces of the attack, has become a security issue with high concealment and threat.
[0008] In summary, from the perspective of security protection, studying a concealed attack method based on series compensation capacitor parameter tampering and PMU measurement data forgery, and revealing potential cyberattack vulnerabilities in wind power systems, have very important theoretical significance and practical application value for improving the security of power systems and preventing sub-synchronous oscillation events caused by malicious attacks. Summary of the Invention
[0009] The technical problem to be solved by the present invention is: A concealed attack method based on series compensation capacitor and PMU measurement tampering is proposed, aiming to trigger oscillations in the wind power system and avoid attack detection through a carefully designed attack strategy, thereby interfering with the stable operation of the power system.
[0010] The technical solution of the present invention is as follows:
[0011] First aspect: A concealed attack based on series compensation capacitor and PMU measurement tampering is proposed, including the following steps:
[0012] S1. Establish a complete dynamic model of a grid-connected doubly-fed induction generator, and at the same time form the state space equation of the DFIG with differential and algebraic equations;
[0013] S2. Construct the state space equation of the line module containing the series compensator;
[0014] S3. Derive the relationship between the eigenvalue and the capacitive reactance based on the state transition matrix of the transmission line equation. By giving a set of eigenvalues containing oscillation modes, inversely solve the corresponding capacitive reactance containing oscillation modes, then solve the capacitance parameters through the capacitive reactance, and then tamper with the control command of the series capacitor compensator to change the capacitance parameters to the attack value, triggering system oscillation;
[0015] S4. Estimate the change in the measured value caused by the attack through the dynamic state estimation method, then subtract the measured change from the measured value after the system is attacked to obtain the first measured value, and tamper with the measured value of the PMU on the transmission line to the first measured value to construct a covert malicious attack.
[0016] Furthermore, the complete dynamic model of the grid-connected doubly-fed induction wind generator in step S1 is:
[0017] For the single-mass module of the wind turbine and the drive train:
[0018]
[0019] In the formula, T m is the mechanical torque output by the wind turbine, P m is the mechanical power, ω r is the rotor speed, ρ air is the air density, S is the area swept by the turbine blades during rotation, C p is the wind turbine power coefficient, V w is the wind speed, T e is the electromagnetic torque; F is the friction coefficient; H g is the equivalent time inertia constant of the shafting;
[0020] Among them, the flux linkage equation is
[0021]
[0022] Among them, ω s is the per-unit value of the synchronous speed; R s and R r are the resistances of the stator and rotor respectively; the subscript s represents the electrical quantities on the stator side; the subscript r represents the electrical quantities on the rotor side; ψ ds and ψ qs are the d-axis and q-axis components of the stator flux linkage respectively; ψ dr and ψ qr are the d-axis and q-axis components of the rotor flux linkage respectively; u ds and u qs are the d-axis and q-axis components of the DFIG terminal voltage respectively, which are used as the input of the dynamic state estimation and decouple the doubly-fed induction wind generator from the external network; i ds and i qsare the d - axis and q - axis components of the DFIG stator current; u dr , u qr are the d - axis and q - axis components of the DFIG rotor voltage; i dr and i qr are the d - axis and q - axis components of the DFIG rotor current;
[0023] Among them, the dynamic equations of the DC capacitor and the filter inductor:
[0024]
[0025]
[0026] Among them, U dc is the DC capacitor voltage; P r and P g are the powers of the rotor side and the grid side of the converter respectively; C dc is the DC capacitor; the subscript g represents the electrical quantities on the grid side of the converter; u dg and u qg are the d - axis and q - axis components of the grid - side voltage of the converter respectively; i dg and i qg are the d - axis and q - axis components of the grid - side current of the converter respectively; R g and L g are the resistance and reactance of the filter inductor respectively;
[0027] For the active power and reactive power output by the generator, and the d - axis and q - axis components of the generator terminal current, construct equations for measurement, and the measurement equations are as follows:
[0028]
[0029] Among them, P t and Q t are the active power and reactive power output by the generator respectively, i dt and i qt are the d - axis and q - axis components of the terminal current of the doubly - fed induction wind generator respectively. For these four measurements, a PMU needs to be installed at the terminal of each DFIG to obtain these electrical quantities;
[0030] Construct the discrete DFIG state - space equation according to (1)-(6):
[0031]
[0032] Among them, x k = [ω r , ψ ds , ψ qs , ψ dr , ψ qr , U dc,i dg ,i qg , y k = [P t , Q t , i dt , i qt represent the state vector and measurement vector of the system at the k-th moment respectively, u k = [u ds , u qr , V w is the input vector at the k-th moment, f() represents the non-linear state transition function of the relationship between x k and x k-1 after discretization by equations (2)-(5), h() is the non-linear measurement function composed of equation (6), w k and v k represent the process noise and observation noise respectively. The noises are independent of each other and have a mean of zero, and their covariance matrices are Q k and R k .
[0033] Further, the state space equation of the line module of the series compensator in step S2 is as follows:
[0034]
[0035] Among them, the state vector and each matrix are respectively:
[0036] X line = [u cd , u cq , i d , i q , u line = [u td , u tq , u od , u oq , Y line = [i d , i q
[0037] D line = 0
[0038] Among them, u cd and u cq are the d-axis and q-axis components of the voltage across the capacitor, i d and i q are the d-axis and q-axis components of the current in the series compensation line, u td and u tq are the d-axis and q-axis components of the voltage after boosting the stator voltage, u od and u oq are the d- and q-axis components of the external infinite grid voltage, X c is the capacitive reactance of the series compensation capacitor, X L is the inductive reactance of the equivalent inductance of the series line, R L is the equivalent resistance on the series compensation line.
[0039] Further, the specific steps of step S3 are as follows:
[0040] 1) Solve the eigenvalues of the matrix A line where λ and x = X
[0041]
[0042] represent the eigenvalue and the capacitive reactance respectively, and E represents the identity matrix; C
[0043] 2) Represent (A line - λE) as a block matrix:
[0044] where
[0045]
[0046] For the block matrix If the matrix A is invertible
[0047] then |A line - λE| = |A||D - CA- 1 B| = 0. Since A is invertible, so |D - CA -1 B| = 0, that is, the second-order matrix (D - CA -1 B) is linearly dependent;
[0048] 3) Substitute ABCD to get
[0049]
[0050] Because |D - CA -1 B| = 0
[0051] Therefore
[0052] 4) Arrange, simplify, and combine like terms to get:
[0053]
[0054] Denote Using the quadratic formula for the quadratic equation, we can get
[0055]
[0056] 5) Modify the capacitance compensation value in the power transmission line of the power system to f represents the frequency of the grid current. Further, in step S4, the change amount caused by the attack on the measurement value is estimated by the dynamic state estimation method, and then the first measurement value is obtained by subtracting the measured change amount from the measurement value after the system is attacked. The specific method for constructing the covert malicious attack is as follows: Assume that the capacitance value of the transmission line is attacked at time k, then the state and measurement at time k can be expressed as:
[0057]
[0058] where represents the state after being attacked, represents the true measurement after the system state is attacked, represents the input at time k - 1, represents the input at time k, is the non - linear state transition function, h() is the non - linear measurement function, w k is the process noise, v k is the observation noise. Before the attack, first intercept the measurement at time y k-1 and estimate through dynamic state estimation, and then calculate through the state transition function. Then, perform dynamic state estimation of the state after being attacked at time k through the unscented Kalman filter Finally, the first measurement value y at time k k can be calculated by the following formula:
[0059]
[0060] Further, the specific steps of performing dynamic state estimation through the unscented Kalman filter are as follows:
[0061] In the prediction stage, first use the unscented transformation. By using the state estimation value at time k - 1 and the covariance matrix generate 2n sigma points:
[0062]
[0063] where n represents the state dimension, represents the i - th column of the matrix , ξ = α 2 (n + κ)-n is a composite scaling factor, α is a free parameter that controls the distribution of sigma points, and its value is related to the dimension of the state vector. The higher the dimension, the smaller the value of α, and the value range is 10 -4< α < 1, κ is usually set to 2;
[0064] Set the weight w i = 1 / (2n), and each sigma point is mapped through the non - linear function to generate a set of transformed samples, denoted as Then the prior state value at the k - th moment and the prior covariance matrix can be calculated by the following formula:
[0065]
[0066] In the update stage, first, according to the prior state value and the prior covariance matrix generate updated sigma points:
[0067]
[0068] Then, each sigma point is mapped through the non - linear function to generate a set of transformed samples, denoted as Next, calculate the prior measurement vector the error covariance matrix and the cross - covariance matrix The superscript xx represents between states, xy represents between state and measurement, yy represents between measurements, the subscript k|k - 1 represents prediction, and the subscript k|k represents actual:
[0069]
[0070] Then calculate the Kalman gain:
[0071]
[0072] Finally, correct to obtain the final state estimate value and update
[0073]
[0074] Finally, through obtain y k , at this time, change the measured value of the PMU to y k .
[0075] The beneficial effects of the present invention are: compared with the prior art,
[0076] 1) The present invention first proposes an attack against series compensation capacitors. By using the system dynamic model and state space equations, a complete mathematical description of the wind power system is constructed, and through the coordinated regulation of series compensators and measurement data, the precise induction of subsynchronous oscillation in the system is achieved. This method can not only cause system oscillation by maliciously tampering with capacitor parameters, but also eliminate the interference of the attack on measurement data through dynamic state estimation, so that the measurement values obtained by the external monitoring system still remain in a "normal" state, thus greatly improving the concealment and destructiveness of the attack, providing an efficient and imperceptible interference means for attackers, and at the same time posing new challenges to the grid security protection. Meanwhile, experiments also prove the concealment of the attack proposed by the present invention;
[0077] 2) The present invention first attacks the series capacitor compensator to induce subsynchronous oscillation in the power system, and then attacks the measurement values of the PMU to make the system measurement normal so as to avoid subsynchronous oscillation detection. It highlights the potential security risks related to subsynchronous oscillation and provides a basis for developing more robust models in the future;
[0078] 3) The attack proposed by the present invention has strong concealment. Because the change amount of the measurement value caused by attacking the series capacitor compensator to induce subsynchronous oscillation is calculated, and the measurement data of the PMU is subtracted by the calculated measurement change amount to avoid detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] Figure 1 is the flow chart of the present invention;
[0080] Figure 2 is the time sequence diagram of three-phase grid-connected current after the series compensation capacitor of the present invention is attacked;
[0081] Figure 3 is the frequency spectrum diagram of three-phase grid-connected current after the series compensation capacitor of the present invention is attacked;
[0082] Figure 4 is the comparison diagram of ω r , U dc , i dg , i qg with the normal situation after the series compensation capacitor of the present invention is attacked;
[0083] Figure 5 is the comparison diagram of ψ ds , ψ qs , ψ dr , ψ qr with the normal situation after the series compensation capacitor of the present invention is attacked;
[0084] Figure 6 is the comparison diagram of grid-connected d-axis current under the concealment attack (SA), attacking the series capacitor compensator (AOS) and the normal situation of the present invention. Detailed implementation manners
[0085] To make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings of this specification.
[0086] Embodiment 1: The complete dynamic model of a grid-connected doubly-fed induction wind generator includes a wind turbine, an asynchronous generator, a rotor-side converter, a DC capacitor, a grid-side converter, and a grid-side filter. The wind turbine transfers wind energy to the DFIG through a mechanical shaft. The stator of the induction motor is directly connected to the power grid, while the rotor is fed through a back-to-back converter.
[0087] In this section, the performance of the proposed control scheme is evaluated through simulation. The experiments were carried out in MATLAB 2022b on a desktop computer with a processor of AMD Ryzen7 5700G with Radeon Graphics 3.80 GH. We established a wind power plant containing six (each 1.5 MW) wind generators in Simulink, and this wind power plant is connected to an infinite power grid through a 30-km transmission line.
[0088] Reference Figures 1-3 , a stealthy attack method based on series compensation capacitor and PMU measurement tampering, includes the following steps:
[0089] S1. Establish a mathematical model of the DFIG formed by a set of differential and algebraic equations. Among them, for the single-mass module of the wind turbine and the drive train:
[0090]
[0091] In the formula, T m is the mechanical torque output by the wind turbine, P m is the mechanical power, ω r is the rotor speed, ρ air is the air density, S is the area swept by the turbine blade during rotation, C p is the wind turbine power coefficient, V w is the wind speed, T e is the electromagnetic torque; F is the friction coefficient; H g is the equivalent time inertia constant of the shafting.
[0092] At the same time, its flux linkage equation is listed as
[0093]
[0094] Among them, ω s is the per-unit value of the synchronous speed; R s and R rare the resistances of the stator and rotor, respectively; the subscript s represents the electrical quantities on the stator side; the subscript r represents the electrical quantities on the rotor side; ψ ds , ψ qs are the d- and q-axis components of the stator flux linkage; ψ dr , ψ qr are the d- and q-axis components of the rotor flux linkage; u ds , u qs are the d- and q-axis components of the DFIG terminal voltage, respectively. They are used as the inputs of the dynamic state estimation and decouple the doubly-fed induction wind generator from the external network; i ds and i qs are the d- and q-axis components of the DFIG stator current, respectively; u dr , u qr are the d- and q-axis components of the DFIG rotor voltage, respectively; i qr and i qr are the d- and q-axis components of the DFIG rotor current, respectively.
[0095] Substitute u ds , u qs , i ds , i qs , u dr , u qr , i dr , i qr into the dynamic equations of the DC capacitor and the filter inductor to obtain the powers P r and P g .
[0096]
[0097] Among them, U dc is the DC capacitor voltage; P r and P g are the powers on the rotor side and the grid side of the converter, respectively; C dc is the DC capacitor; the subscript g represents the electrical quantities on the grid side of the converter; u dg and u qg are the d- and q-axis components of the grid-side voltage of the converter, respectively; i dg and i qg are the d- and q-axis components of the grid-side current of the converter, respectively; R g and L g are the resistance and reactance of the filter inductor, respectively.
[0098] For the active power and reactive power output by the generator, as well as the d- and q-axis components of the generator terminal current, equations also need to be constructed for measurement. The measurement equations are as follows:
[0099]
[0100] Among them, P t and Q t are the active power and reactive power output by the generator respectively, and i dt and i qt are the d-axis and q-axis components of the terminal current of the doubly-fed induction wind generator respectively.
[0101] Based on the above differential equations and algebraic equations, construct the discrete DFIG state space equation:
[0102]
[0103] Among them, x k = [ω r , ψ ds , ψ qs , ψ dr , ψ qr , U dc , i dg , i qg , y k = [P t , Q t , i dt , i qt represent the state vector and measurement vector of the system at the k-th moment respectively, u k = [u ds , u qr , V w is the input vector at the k-th moment, f() represents the non-linear state transition function of the relationship between x k and x k-1 and is composed of equations (1)-(5), and h() is the non-linear measurement function composed of equation (5). w k and v k represent the process noise and observation noise respectively. The noises are independent of each other and have a mean of zero, and their covariance matrices are Q k and R k .
[0104] The above method constructs a complete dynamic model of the grid-connected doubly-fed induction wind generator, which details key physical quantities such as the wind turbine and drive train, flux linkage dynamics, DC capacitor, and filter inductor, and decouples the non-linear dynamic characteristics from the external network through the discretized state space equation. This model can truly reflect the operating state and transient response of the wind power system, providing an accurate theoretical basis and calculation foundation for subsequent state estimation, measurement data correction, and attack parameter inverse solution, thereby improving the accuracy and feasibility of stealth attacks and effectively revealing potential security vulnerabilities in the wind power system.
[0105] S2. To improve the transmission capacity of the transmission line and reduce the energy loss during transmission, DFIG wind farms are often connected to the external power grid via a series-compensated line. Construct the state-space equation of the series compensation line module:
[0106]
[0107] Among them, the state vector and each matrix are respectively:
[0108] X line = [u cd , u cq , i d , i q , u line = [u td , u tq , u od , u oq , Y line = [i d , i q
[0109] D line = 0
[0110] Among them, u cd and u cq are the dq-axis components of the voltage across the capacitor, i d and i q are the dq-axis components of the current in the series-compensated line, u td and u tq are the dq-axis components of the voltage after the stator voltage is boosted, u od and u oq are the dq-axis components of the voltage of the external infinite power grid, X c is the capacitive reactance of the series compensation capacitor, X L is the inductive reactance of the equivalent inductance of the series line, R L is the equivalent resistance on the series-compensated line.
[0111] The above method accurately describes the transformation relationship between the voltage across the capacitor, the line current, and the boosted voltage by constructing the state-space equation of the transmission line module containing the series compensator, and establishes a direct connection between the capacitive reactance and the system dynamics. This state-space model can not only accurately simulate the actual operating state of the series-compensated line, but also provide a mathematical basis for inversely solving the capacitor parameters corresponding to the oscillation mode, enabling the attacker to accurately determine the required capacitor compensation value for the attack according to the eigenvalue analysis, so as to achieve precise control of the system parameters while triggering subsynchronous oscillation.
[0112] S3. The idea of the stealth attack proposed by the present invention is as follows. First, attack the series compensator to trigger power system oscillations. However, at this time, the measured values can reflect that the system has oscillated. Therefore, we also need to tamper with the measured values so that the measured values return to normal, thereby avoiding detection. The specific attack method is as follows:
[0113] The present invention starts from the transmission line state transition matrix and attacks the capacitive reactance to trigger system oscillations. The eigenvalues of the state transition matrix jointly reflect the dynamic characteristics and stability of the system through their real and imaginary parts. The real part of the eigenvalue determines the convergence or divergence of the system: when the real part is negative, the system state decays exponentially and tends to be stable; a positive real part leads to system divergence and instability. The imaginary part characterizes the oscillation characteristics of the system, and the larger the imaginary part, the higher the oscillation frequency. When the imaginary part is zero, the system response is in a pure exponential form without oscillation.
[0114] Therefore, the stability and dynamic behavior of the system can be comprehensively judged by the real and imaginary parts of the eigenvalues: the real part determines stability, and the imaginary part affects the oscillation characteristics. Based on this, the attack method of the present invention can give a set of unstable eigenvalues, and then inversely solve the capacitance value corresponding to the eigenvalue, and use this value as the attack value of the capacitance to trigger system oscillations. The specific steps are as follows:
[0115] 1) Solve the eigenvalues of matrix A line of
[0116]
[0117] where λ and x = X C respectively represent the eigenvalue and the capacitive reactance, E represents the identity matrix. To simplify the solution, (A line - λE) is expressed as a block matrix:
[0118] where
[0119]
[0120] For the block matrix If matrix A is invertible
[0121] then |A line - λE| = |A||D - CA -1 B| = 0. Since A is invertible, so
[0122] |D - CA -1 B| = 0, that is, the second-order matrix (D - CA -1 B) is linearly dependent. Substituting ABCD gives
[0123]
[0124] Because |D - CA -1 B| = 0
[0125] Therefore After organizing, simplifying, and combining like terms, we get:
[0126]
[0127] Denote Using the quadratic formula for a quadratic equation, we can obtain
[0128]
[0129] Up to this point, we only need to give a set of characteristic roots containing the oscillation mode, and then we can calculate the attack value of the capacitive reactance. Through data tampering attacks, the capacitive compensation value in the transmission line of the power system is modified to which can cause power system oscillations, where f represents the frequency of the grid current.
[0130] Based on the eigenvalue solution of the series compensation line state transition matrix and the analysis of the block matrix, the above method establishes a quantitative relationship between the capacitive reactance and the oscillation eigenvalues through mathematical derivation, and uses the quadratic formula to solve for the required capacitance parameters inversely. This method not only achieves a technical breakthrough in inversely deducing the capacitive compensation value from a given oscillation mode, but also makes the attack process highly directional and controllable, so that the system subsynchronous oscillation can be accurately triggered without obvious external abnormalities, effectively improving the concealment and success rate of the attack, providing theoretical support and implementation means for covert network attacks.
[0131] Through experiments, it can be seen that the simulation model operates normally within 0 - 0.17 seconds, and an attack is injected at 0.17 seconds, that is, the value of the capacitor on the transmission line is modified, thus triggering subsynchronous oscillations. After injecting the attack into the system, the three-phase grid-connected current is measured and the spectrum analysis of the three-phase current is performed. The analysis results are as Figure 2 , Figure 3 shown. From the above figure, we can observe that after injecting the attack at 0.17 seconds, the three-phase current oscillates. From the spectrum diagram, it can be observed that there are subsynchronous frequencies between 20HZ - 55HZ with amplitudes between 0.1 - 0.2, indicating that tampering with the capacitor can trigger subsynchronous oscillations and the subsynchronous component can be detected. To achieve a covert attack, that is, to avoid detection when there are subsynchronous oscillations in the system, we need to calculate the change in the measured value caused by the attack, and subtract the change in the measured value caused by the attack from the measured value to obtain the normal measured value of the system, and replace the measurement with this value to avoid the attack.
[0132] However, such attacks will induce abnormal fluctuations in the measurement data, enabling the defender to relatively easily detect the oscillation of the system by monitoring these values, and further identify the attack behavior.
[0133] S5. Most current oscillation detection algorithms are based on the measurement of voltage, current, and other related data. However, if an attacker causes system oscillation by manipulating the capacitance value, the defender can usually easily detect the abnormal oscillation of the system through the measurement data. To avoid this detection risk, the present invention eliminates the interference caused by the attack on the measurement data, ensures that the data collected by the PMU (phasor measurement unit) remains normal, so that the defender cannot detect any oscillation signs from the measurement data, and then constructs a stealthy attack strategy.
[0134] The attack model in this paper is based on the following assumptions: 1. The attacker has fully obtained the model structure and key operating parameters of the wind farm through means such as information theft and system identification. 2. The attacker can control the series capacitor compensation value in the instruction tampering series compensation line. 3. The attacker can intercept the measurement values of the power system PMU online.
[0135] To eliminate the interference caused by the attack on the measurement data and ensure that the data collected by the PMU (phasor measurement unit) remains normal, the present invention calculates the change amount caused by the attack on the measurement value, and subtracts the measurement change amount from the measurement value after the system is attacked to obtain the normal measurement value, and tampers with the measurement value of the PMU to the normal value on the transmission line. The specific implementation steps are as follows.
[0136] The specific implementation steps are as follows:
[0137] 1) First, intercept the measurement value at time k - 1, and estimate the state x of the system at time k - 1 according to the dynamic state estimation method k-1 , then attack the series capacitor to cause system oscillation and change the system state.
[0138] 2) Use the state transition function to calculate the estimated value of the state that is not attacked at the next moment (denoted as the estimation of the state that is not attacked at the next moment) and adopt the measurement and the state space equation to estimate the state after being attacked through the dynamic state estimation method Thus, the change amount of the system state after the attack is obtained, and the change amount of the measurement can be calculated through the measurement function.
[0139] 3) Subtract the measurement change amount from the measurement value of the pmu to get y k (which is the estimation of the measurement when the system is operating normally).
[0140] 4) Use the data tampering attack method with the estimated yk Replace the measurement values transmitted by the system to the master station, thus constituting a stealth attack.
[0141] The specific implementation process is as follows:
[0142] Assume that the capacitance value of the transmission line is attacked at time k, then the state and measurement at time k can be expressed as:
[0143]
[0144] where represents the state after being attacked, represents the true measurement after the system state is attacked, represents the input at time k - 1, represents the input at time k, is the non - linear state transition function, h() is the non - linear measurement function, is the process noise, is the observation noise. Before the attack, first intercept the measurement at time y k-1 and estimate through dynamic state estimation (DSE). Then calculate through the state transition function. If the state after being attacked at time k can be accurately estimated, then the "normal" measurement value y at time k k can be calculated by the following formula:
[0145]
[0146] Careful readers may notice Why not use to replace ? Because is calculated through the state transition function and has a large error, and also has an estimation error. Subtracting the two can offset part of the error, making y k closer to the "normal" value.
[0147] In order to accurately estimate To construct a stealthy attack, we consider using the unscented Kalman filter for DSE. By introducing a dynamic state estimation method, the state of the system after being attacked is estimated in real time using the state transition function and the measurement equation, and the change in the measured value caused by the attack is accurately calculated. Subsequently, by subtracting this change from the measured value after the attack, the true measurement data of the system in the normal operating state is obtained, and the PMU data on the transmission line is replaced using data tampering technology, thus effectively hiding the attack behavior. This method not only makes up for the defect of direct measurement data anomaly triggering detection, but also realizes the precise correction of internal power grid disturbances through accurate state prediction and error compensation, greatly improving the successful implementation rate and anti-detection ability of stealthy attacks.
[0148] The most important part of the unscented Kalman filter is the unscented transform. The so-called unscented transform is to construct a set of points with the same mean and covariance as the random variable, called sigma points. Through these sigma points, the mean and variance of the variable after being propagated through the nonlinear function are calculated, thus approximating the distribution of the nonlinear function. The steps of this algorithm are divided into two stages: prediction and update.
[0149] In the prediction stage, the unscented transform is first used, and the state estimate value at time k - 1 and the covariance matrix are used to generate 2n sigma points:
[0150]
[0151] where n represents the state dimension, represents the i-th column of the matrix , ξ = α 2 (n + κ) - n is a composite scaling factor, α is a free parameter that controls the distribution of sigma points, and its value is related to the dimension of the state vector. The higher the dimension, the smaller the value of α. The value range is generally 10 -4 < α < 1, and κ is usually set to 2.
[0152] The weights w i are set to 1 / (2n), and each sigma point is mapped through the nonlinear function to generate a set of transformed samples, denoted as Then the prior state value at time k and the prior covariance matrix can be calculated by the following formulas:
[0153]
[0154] In the update stage, first, according to the prior state value and the prior covariance matrix Generate updated sigma points:
[0155]
[0156] Then, each sigma point is mapped through the non - linear function to generate a set of transformed samples, denoted as Next, calculate the prior measurement vector the error covariance matrix and the cross - covariance matrix The superscript xx represents between states, xy represents between state and measurement, yy represents between measurements, the subscript k|k - 1 represents prediction, and the subscript k|k represents actual:
[0157]
[0158] Then calculate the Kalman gain:
[0159]
[0160] Finally, correct to obtain the final state estimate and update
[0161]
[0162] Finally, obtain y through At this time, the measured value of the PMU is tampered with to y k , and y k . y k is the "normal" measured value, thus avoiding oscillation detection.
[0163] In the above - mentioned method, by constructing sigma points that match the mean and covariance of the system state, setting reasonable weights, and then going through the prediction and update stages, a high - precision estimation of the non - linear system state is achieved. This method can fully offset the errors caused by system noise and measurement noise, improve the accuracy of state estimation, provide reliable data support for calculating the change in measured values caused by attacks later, and thus ensure that when a stealthy attack is implemented, the data output by the PMU always maintains the "normal" characteristics, greatly enhancing the stealth and success rate of the attack strategy, while also exposing the technical shortcomings in the current system protection.
[0164] In the experiment, first use the unscented Kalman filter to estimate the state of the system after being attacked Then use the process function to calculate the state when not being attacked The change in state caused by the attack can be obtained from Calculated, so that the correct measurement value can be obtained We use the unscented Kalman filter to estimate the grid-side dq-axis current and its calculated value using the process function. The comparison results are as Figure 4 , Figure 5 shown.
[0165] It can be clearly observed from the shown image that after the injection attack is implemented at 0.17 seconds, the system does not immediately lose stability; instead, at the subsequent moment of 0.175 seconds, the system begins to exhibit oscillatory behavior. The grid-side dq-axis current estimated by the unscented Kalman filter shows obvious oscillatory characteristics. In contrast, the grid-side dq-axis current calculated through the process function shows higher stability, and this current can be regarded as the current reference under the normal operation of the system. By taking the difference between the two, the change in the system state caused by the attack can be obtained, and then the change in the measurement can be deduced.
[0166] Furthermore, we deeply compared and analyzed the changes in the measurement values (i.e., the dq-axis components of the grid-connected current) (the tampered values represent the measurement values under the stealthy attack) in the two scenarios of being attacked and being stealthily attacked. The specific comparison results are as Figure 6 shown.
[0167] This series of observation results deeply reveals that the stealthy attack not only has the ability to trigger system oscillations, but also its superb camouflage skills enable it to cleverly avoid conventional oscillation detection mechanisms. This discovery undoubtedly poses a severe challenge to system security protection, emphasizing the urgency and importance of strengthening the research on detection and defense strategies against stealthy attack means in the current technical background.
[0168] For the parts not detailed in the invention, they are all well-known technologies to those skilled in the art. Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the purpose and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A covert attack method based on series compensation capacitor and PMU measurement tampering, characterized in that: The steps include: S1. Establish a complete dynamic model of a grid-connected doubly-fed induction wind turbine generator, and form the state space equations of the DFIG using differential and algebraic equations; S2. Construct state space equations of the line module including the series compensator; S3. According to the state transfer matrix of the transmission line equation, the relationship between the eigenvalue and the capacitive reactance is derived. By giving a set of eigenvalues containing the oscillation mode, the capacitive reactance corresponding to the characteristics containing the oscillation mode is inversely solved. Then, the parameters of the capacitor are solved by the capacitive reactance. Then, the control command of the series capacitor compensator is tampered with to change the capacitor parameters to the attack value, causing system oscillation. S4. Estimate the change in the measured value caused by the attack through the dynamic state estimation method, then subtract the measured change from the measured value after the system is attacked to obtain the first measured value, and tamper with the PMU's measured value to the first measured value on the transmission line to construct a hidden malicious attack.
2. The covert attack method based on series compensation capacitor and PMU measurement tampering according to claim 1 is characterized in that: The complete dynamic model of the grid-connected doubly-fed induction wind turbine in step S1 is as follows: For the single-mass module of the wind wheel and the transmission system: Where, T m is the mechanical torque output by the wind wheel, P m is the mechanical power, ω r is the rotor speed, ρ air is the air density, S is the area swept by the turbine blades when they rotate, and C p is the wind wheel power coefficient, V w is wind speed, T e is the electromagnetic torque; F is the friction coefficient; H g is the equivalent time inertia constant of the axis system; The magnetic flux equation is Among them, ω s is the synchronous speed per unit value; R s and R r are the resistances of the stator and rotor respectively; the subscript s represents the electrical quantity on the stator side; the subscript r represents the electrical quantity on the rotor side; ψ ds , qs Divided into d-axis and q-axis components of the stator flux; ψ dr , qr Divided into d-axis and q-axis components of the rotor flux; u ds 、u qs are the d-axis and q-axis components of the DFIG terminal voltage, respectively, which serve as the input of the dynamic state estimation and decouple the doubly fed induction wind turbine from the external network; i ds and i qs are the d-axis and q-axis components of the DFIG stator current respectively; u dr 、u qr are the d-axis and q-axis components of the DFIG rotor voltage respectively; i dr and i qr They are the d-axis and q-axis components of the DFIG rotor current respectively; The dynamic equations of DC capacitor and filter inductor are: Among them, U dc is the DC capacitor voltage; P r and P g are the power on the converter rotor side and grid side respectively; C dc is the DC capacitance; the subscript g represents the electrical quantity on the grid side of the converter; u dg and u qg are the d-axis and q-axis components of the grid-side voltage of the converter respectively; i dg and i qg are the d-axis and q-axis components of the grid-side current of the converter respectively; R g and L g are the resistance and reactance of the filter inductor respectively; For the active power and reactive power output by the generator, as well as the d-axis and q-axis components of the generator terminal current, equations are constructed for measurement. The measurement equations are as follows: Among them, P t and Q t are respectively the active power and reactive power output by the generator, i dt and i qt They are the d-axis and q-axis components of the current at the end of the doubly-fed induction wind turbine generator. For these four measurements, a PMU needs to be installed at the end of each DFIG to obtain these electrical quantities; According to (1)-(6), the discrete DFIG state space equation is constructed: Among them, x k =[ω r ,ψ ds ,ψ qs ,ψ dr ,ψ qr ,U dc ,i dg ,i qg ],y k =[P t ,Q t ,i dt ,i qt ] represent the state vector and measurement vector of the system at the kth moment, u k =[u ds ,u qr ,V w ] is the input vector at time k, f() represents x k and x k-1 The nonlinear state transfer function of the relationship between is composed of the discretization of equations (2)-(5), h() is the nonlinear measurement function composed of equation (6), w k and v k They represent process noise and observation noise respectively. The noises are independent of each other and have zero mean. Their covariance matrices are Q k and R k .
3. According to claim 2, a covert attack method based on series compensation capacitor and PMU measurement tampering is characterized in that: The state space equation of the line module of the series compensator in step S2 is: Among them, the state vector and each matrix are: X line =[u cd ,u cq ,i d ,i q ],u line =[u td ,u tq ,u od ,u oq ], line =[i d ,i q ] D line =0, where u cd and u cq is the d-axis and q-axis components of the voltage across the capacitor, i d and i q are the d-axis and q-axis components of the series-compensated line current, u td and u tq is the d-axis and q-axis components of the stator voltage after boosting, u od and u oq is the d-axis and q-axis components of the external infinite grid voltage, X c is the capacitive reactance of the series compensation capacitor, X L is the inductive reactance of the equivalent inductance of the series circuit, R L is the equivalent resistance of the series compensated circuit.
4. According to claim 3, a covert attack method based on series compensation capacitor and PMU measurement tampering is characterized in that: The specific steps of step S3 are as follows: 1) Solve the matrix A line The eigenvalue of Where λ and x = X C denote eigenvalue and capacitive reactance respectively, and E denotes the unit matrix; 2) (A line -λE) is represented as a block matrix: in For block matrices If the matrix A is invertible Then |A line -λE|=|A||D-CA -1 B|=0, because A is reversible, so |D-CA -1 B|=0, that is, the second-order matrix (D-CA -1 B) linear correlation; 3) Substitute ABCD into the equation to get Because | D-CA -1 B|=0 Therefore 4) Arrange, simplify, and combine similar terms to obtain: Using the root-finding formula for quadratic equations, we get 5) Modify the capacitance compensation value in the power system transmission line to Where f represents the frequency of the grid current.
5. The covert attack based on series compensation capacitor and PMU measurement tampering according to claim 4 is characterized in that: In step S4, the change amount of the measured value caused by the attack is estimated by a dynamic state estimation method, and then the first measured value is obtained by subtracting the measured change amount from the measured value after the system is attacked, and the measured value of the PMU is tampered with to the first measured value on the transmission line. The specific construction of the hidden malicious attack is as follows: Assuming that the capacitance of the transmission line is attacked at time k, the state and measurement at time k can be expressed as: in Indicates the state after being attacked. represents the true measurement of the system state after being attacked, represents the input at time k-1, represents the input at time k, is the nonlinear state transfer function, h() is the nonlinear measurement function, w k is the process noise, v k is the observation noise. Before attacking, first intercept y k-1 The measurement of the moment and the dynamic state estimation are used to estimate Then calculate through the state transfer function Then, the unscented Kalman filter is used to estimate the dynamic state after the attack at time k. The first measured value y at the last k moments k It can be calculated by the following formula:
6. The covert attack method based on series compensation capacitor and PMU measurement tampering according to claim 5 is characterized in that: The specific steps of performing dynamic state estimation by unscented Kalman filtering are: The prediction phase first uses an unscented transformation, using the state estimate at time k-1 and the covariance matrix Generate 2n sigma points: Where n represents the state dimension, Representation Matrix The i-th column of 2 (n+κ)-n is a composite proportional factor, α is a free parameter that controls the distribution of sigma points. Its value is related to the dimension of the state vector. The higher the dimension, the smaller the value of α. The value range is 10 -4 <α<1, κ is usually set to 2; Set the weight w i =1 / (2n), each sigma point passes through a nonlinear function Mapping is performed to generate a set of transformed samples, recorded as Then the state prior value at the kth moment is and the prior covariance matrix It can be calculated by the following formula: In the update phase, firstly, according to the state prior value and the prior covariance matrix Generate updated sigma points: Then, each sigma point is passed through a nonlinear function Mapping is performed to generate a set of transformed samples, recorded as Next, calculate the prior measurement vector Error covariance matrix And the cross covariance matrix The superscript xx indicates the relationship between states, the superscript xy indicates the relationship between states and measurements, the superscript yy indicates the relationship between measurements, the subscript k|k-1 indicates the prediction, and the subscript k|k indicates the actual relationship: Then calculate the Kalman gain: Finally, Correction to obtain the final state estimate and update Last passed Get y k At this time, the measured value of PMU is tampered with to y k .
Citation Information
Patent Citations
Defensive-conventional coordinated planning method for power generation and transmission system by considering wind power
CN111969658A
Wind power plant attack method and system
CN114362245A
Holophasec vortex mechanics method & apparatus
WO2010148360A2