A method for concealing tampering based on series compensation capacitor and PMU measurement
By constructing a dynamic model and state-space equations for a wind power system, tampering with the series compensation capacitor and PMU measurements, and using unscented Kalman filtering for state estimation, a covert attack was achieved. This solved the problem of inducing subsynchronous oscillations and evading detection in existing technologies, thus increasing the difficulty of grid security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUIZHOU UNIV
- Filing Date
- 2025-03-18
- Publication Date
- 2026-05-29
AI Technical Summary
Existing research on cyberattacks has difficulty in inducing subsynchronous oscillations through covert means and evading conventional detection, thus threatening the safe operation of the power grid. Furthermore, traditional detection methods struggle to identify subsynchronous oscillations caused by the interaction between doubly-fed induction wind turbines and series capacitor compensators.
By constructing a dynamic model of a grid-connected doubly-fed induction wind turbine, the state-space equation of the series compensator is derived. The capacitor parameters and PMU measurements are tampered with. Dynamic state estimation is performed using unscented Kalman filtering to construct a covert attack strategy, which induces subsynchronous oscillations and spoofs measurement data.
This technology enables the precise induction of subsynchronous oscillations without being detected by the monitoring system, improving the stealth and destructiveness of the attack and increasing the challenge of power grid security protection.
Smart Images

Figure CN120223377B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a covert attack method based on series compensation capacitors and PMU measurement tampering, belonging to the technical field of subsynchronous oscillation attacks in power systems. Background Technology
[0002] With the continued growth of global energy demand and the increasing depletion of traditional fossil fuels, wind power technology has been widely promoted and applied due to its clean and renewable advantages. However, wind power has significant volatility and intermittency characteristics, posing a huge challenge to the stable operation of the power system. To improve the utilization efficiency of wind power and achieve multi-energy synergy, wind power, photovoltaic power, and thermal power have been deeply integrated. While this multi-energy integration improves the overall efficiency of energy utilization, it also brings many complex safety challenges.
[0003] First, the inherent intermittency and volatility of wind power can easily lead to unstable power output, threatening grid frequency and voltage stability and affecting the overall operational reliability of the power system. Second, the coordinated dispatch of multiple energy sources significantly increases the complexity of system control. The frequent load adjustments by traditional thermal power units to cope with fluctuations in renewable energy supply accelerate equipment aging and wear. Finally, while the intelligentization and networking of the power system improves system response speed and operational flexibility, they also bring increasingly severe cyberattacks and data security risks, threatening the safe operation of the power system.
[0004] Subsynchronous oscillation (SSO), a major threat to the stability of power system operation, is typically caused by the dynamic interaction between generators and the grid. When the oscillation frequency of the generator rotor is close to or the same as the subsynchronous resonant frequency of the grid, energy in the system will continuously exchange between the generator and the grid at the subsynchronous frequency, leading to unstable oscillations in the generator rotor. In recent years, several studies have confirmed that the interaction between the rotor-side converter controller and the series capacitor compensator in a doubly-fed induction generator (DFIG) wind turbine can also induce subsynchronous oscillations.
[0005] Subsynchronous oscillations can cause serious damage to power grid equipment, and even lead to the disconnection of large-scale new energy units from the grid, further inducing shaft torsional vibration of nearby thermal power units. For example, in 2009, a wind farm in Texas, USA, experienced a large-scale wind turbine trip due to a subsynchronous oscillation event, resulting in severe damage to the wind turbine protection equipment; in 2015, a subsynchronous harmonic event triggered by a wind farm in Hami City, Xinjiang Uygur Autonomous Region, China, even propagated to a thermal power plant 48 kilometers away, causing the subsynchronous resonance protection to trip; in 2019, a lightning strike at the Hornsea offshore wind farm in the UK reduced grid strength, triggering subsynchronous oscillations and causing a large-scale wind turbine disconnection.
[0006] Traditionally, subsynchronous oscillation events have been largely attributed to system operational failures or equipment parameter configuration problems, and these events can usually be effectively identified through power grid monitoring systems. However, in recent years, frequent cyberattacks against power systems have raised a new and highly threatening question: can subsynchronous oscillations be artificially induced through covert cyberattacks, circumventing conventional detection methods and thus threatening the safe operation of the power grid?
[0007] While existing cyberattack research has demonstrated the potential threat of cyberattacks, most studies have not considered the subsynchronous oscillation effect generated by the interaction between the doubly-fed induction generator (DFIG) and the series capacitor compensator. Furthermore, current cyberattack behaviors can still be effectively identified by traditional oscillation detection methods, making it difficult to cause substantial and sustained damage to power grid security. Therefore, proposing an attack that can induce subsynchronous oscillations and conceal attack traces by manipulating the series capacitor compensator and PMU measurement data without being detected by the monitoring system has become a highly concealed and threatening security problem.
[0008] In summary, from a security perspective, this study investigates a covert attack method based on the tampering of series compensation capacitor parameters and the forgery of PMU measurement data. This method reveals potential network attack vulnerabilities in wind power systems and has significant theoretical and practical value for improving power system security and preventing subsynchronous oscillation events caused by malicious attacks. Summary of the Invention
[0009] The technical problem to be solved by this invention is to propose a covert attack method based on series compensation capacitor and PMU measurement tampering, which aims to induce oscillations in the wind power system and evade attack detection through a carefully designed attack strategy, thereby interfering with the stable operation of the power system.
[0010] The technical solution of this invention is as follows:
[0011] The first aspect proposes a covert attack based on series compensation capacitors and PMU measurement tampering, including the following steps:
[0012] S1. Establish a complete dynamic model of a grid-connected doubly fed induction wind turbine, and simultaneously form the state-space equations of the DFIG using differential and algebraic equations;
[0013] S2. Construct the state-space equations of the line module containing the series compensator;
[0014] S3. Based on the state transition matrix of the transmission line equation, the relationship between eigenvalues and capacitor reactance is derived. By providing a set of eigenvalues containing oscillation modes, the capacitor reactance corresponding to the eigenvalues containing oscillation modes is solved inversely. Then, the capacitor parameters are solved through the capacitor reactance. Finally, the control command of the series capacitor compensator is tampered with to change the capacitor parameters to attack values, causing system oscillation.
[0015] S4. Estimate the change in the measurement value caused by the attack using the dynamic state estimation method. Then, subtract the change in measurement value from the measurement value after the system is attacked to obtain the first measurement value. On the transmission line, tamper with the PMU measurement value to the first measurement value to construct a covert malicious attack.
[0016] Furthermore, the complete dynamic model of the grid-connected doubly-fed induction wind turbine in step S1 is as follows:
[0017] For a single-mass module of the wind turbine and transmission system:
[0018]
[0019] In the formula, T m It is the mechanical torque output by the wind turbine, P m For mechanical power, ω r It is the rotor speed, ρ air Let S be the air density, S be the area swept by the turbine blades as they rotate, and C be the area swept by the turbine blades as they rotate. p V is the wind turbine power coefficient. w For wind speed, T e It is electromagnetic torque; F is the coefficient of friction; H g The equivalent time inertia constant of the shaft system;
[0020] The flux linkage equation is:
[0021]
[0022] Where, ω s It is the per-unit value of the synchronous speed; R s and R r These are the resistances of the stator and rotor, respectively; the subscript 's' represents the electrical quantity on the stator side; the subscript 'r' represents the electrical quantity on the rotor side; ψ ds ψ qs Divided into d-axis and q-axis components of stator flux linkage; ψ dr ψ qr Divided into d-axis and q-axis components of rotor flux linkage; u ds u qs These are the d-axis and q-axis components of the DFIG terminal voltage, respectively. They serve as inputs for dynamic state estimation and decouple the doubly-fed induction generator (DFIG) from the external network; i ds and i qsThese are the d-axis and q-axis components of the DFIG stator current, respectively; u dr u qr These are the d-axis and q-axis components of the DFIG rotor voltage, respectively; i dr and i qr These are the d-axis and q-axis components of the DFIG rotor current, respectively.
[0023] The dynamic equations for the DC capacitor and the filter inductor are as follows:
[0024]
[0025]
[0026] Among them, U dc P is the DC capacitor voltage; r and P g These represent the power on the converter rotor side and the grid side, respectively; C dc For DC capacitors; the subscript g indicates the grid-side electrical quantity of the converter; u dg and u qg These are the d-axis and q-axis components of the converter grid-side voltage, respectively; i dg and i qg These are the d-axis and q-axis components of the converter grid-side current, respectively; R g and L g These are the resistance and reactance of the filter inductor, respectively;
[0027] For the active and reactive power output of the generator, as well as the d-axis and q-axis components of the generator terminal current, equations are constructed for measurement, as follows:
[0028]
[0029] Among them, P t and Q t These are the active power and reactive power output by the generator, i dt and i qt These are the d-axis and q-axis components of the terminal current of the doubly fed induction wind turbine generator. For these four measurements, a PMU needs to be installed at the terminal of each DFIG to obtain these electrical quantities.
[0030] Construct the discrete DFIG state-space equations based on (1)-(6):
[0031]
[0032] Where, x k =[ω r ,ψ ds ,ψ qs ,ψ dr ,ψ qr U dci dg i qg ], y k =[P t Q t i dt i qt ] represent the state vector and measurement vector of the system at time k, respectively. k =[u ds ,u qr V w Let ] be the input vector at time k, and f() represent x k and x k-1 The nonlinear state transition function of the relationship between them is formed by discretizing equations (2)-(5), h() is the nonlinear measurement function composed of equation (6), and w k and v k Let Q represent process noise and observation noise, respectively. The noises are independent and have zero mean, and their covariance matrices are Q and Q, respectively. k and R k .
[0033] Furthermore, the state-space equation of the line module of the series compensator in step S2 is:
[0034]
[0035] The state vector and each matrix are as follows:
[0036] X line =[u cd ,u cq i d i q ], u line =[u td ,u tq ,u od ,u oq ], Y line =[i d i q ]
[0037] D line =0
[0038] Among them, u cd and u cq Let i be the d-axis and q-axis components of the voltage across the capacitor. d and i q For the d-axis and q-axis components of the series compensated line current, u td and u tq The voltage components of the stator voltage after being boosted are the d-axis and q-axis components, u. od and u oqX represents the d-axis and q-axis components of the external infinite grid voltage. c It is the capacitive reactance of the series compensation capacitor, X L R is the inductive reactance of the equivalent inductance of a series circuit. L This is the equivalent resistance on the series compensation line.
[0039] Furthermore, the specific steps of step S3 are as follows:
[0040] 1) Solve for matrix A line eigenvalues
[0041]
[0042] In the formula, λ and x = X C Let represent eigenvalues and capacitive reactance, respectively, and E represent the identity matrix;
[0043] 2) (A) line -λE) is represented as a block matrix:
[0044] in
[0045]
[0046] For block matrices If matrix A is invertible
[0047] Then |A line -λE|=|A||D-CA- 1 B|=0, because A is invertible, therefore |D-CA -1 B|=0, that is, a second-order matrix (D-CA) -1 B) Linear correlation;
[0048] 3) Substituting ABCD into the equation yields...
[0049]
[0050] Because |D-CA -1 B|=0
[0051] Therefore
[0052] 4) By rearranging, simplifying, and combining like terms, we obtain:
[0053]
[0054] remember Using the quadratic formula, we can obtain...
[0055]
[0056] 5) Modify the capacitor compensation value in the power system transmission lines to f represents the frequency of the grid current. Further, in step S4, the change in the measured value caused by the attack is estimated using a dynamic state estimation method. Then, the first measured value is obtained by subtracting the change in measurement from the measured value after the system is attacked. The PMU's measured value is then tampered with to create the first measured value on the transmission line. Specifically, to construct a concealed malicious attack: assuming the transmission line capacitance is attacked at time k, the state and measurement at time k can be expressed as:
[0057]
[0058] in This indicates the state after an attack. This represents the actual measurement of the system state after an attack. This represents the input at time k-1. This represents the input at time k. It is a nonlinear state transition function, h() is a nonlinear measurement function, and w k It is process noise, v k It is observation noise; before launching an attack, y is first intercepted. k-1 Measurement at time, and estimation through dynamic state estimation. Then calculate using the state transition function Then, dynamic state estimation of the state after the attack at time k is performed using unscented Kalman filtering. The first measurement y at time k. k It can be calculated using the following formula:
[0059]
[0060] Furthermore, the specific steps for dynamic state estimation using unscented Kalman filtering are as follows:
[0061] The prediction phase first uses an unscented transformation, employing the state estimate at time k-1. Covariance Matrix Generate 2n sigma points:
[0062]
[0063] Where n represents the state dimension, Representation matrix In the i-th column, ξ = α 2 (n+κ)-n is a composite scaling factor, and α is a free parameter controlling the distribution of sigma points. Its value is related to the dimension of the state vector; the higher the dimension, the smaller the value of α. The range of values is 10. -4<α<1, κ is usually set to 2;
[0064] Set weight w i =1 / (2n), each sigma point passes through a nonlinear function Perform mapping to generate a set of transformed samples, denoted as... Then the prior state value at time k and prior covariance matrix It can be calculated using the following formula:
[0065]
[0066] During the update phase, the state prior value is used first. and prior covariance matrix Generate updated sigma points:
[0067]
[0068] Then, each sigma point is passed through a nonlinear function. Perform mapping to generate a set of transformed samples, denoted as... Next, the prior measurement vector is calculated. Error covariance matrix and cross covariance matrix The superscript xx indicates the relationship between states, the superscript xy indicates the relationship between a state and a measurement, yy indicates the relationship between measurements, the subscript k|k-1 indicates the prediction, and the subscript k|k indicates the actual result.
[0069]
[0070] Then calculate the Kalman gain:
[0071]
[0072] Finally, for The final state estimate is obtained by making corrections. And update
[0073]
[0074] Finally passed Get y k At this point, the PMU measurement value is tampered with and changed to y. k .
[0075] The beneficial effects of this invention are: compared with the prior art,
[0076] 1) This invention proposes for the first time an attack targeting series compensation capacitors. A complete mathematical description of the wind power system is constructed using a system dynamic model and state-space equations. Through coordinated control of the series compensator and measurement data, precise induction of subsynchronous oscillations in the system is achieved. This method not only enables malicious tampering of capacitor parameters to induce system oscillations but also eliminates interference with measurement data through dynamic state estimation, ensuring that the measurement values obtained by the external monitoring system remain "normal." This significantly improves the concealment and destructiveness of the attack, providing attackers with an efficient and difficult-to-detect interference method. It also poses new challenges to power grid security. Experiments have also demonstrated the concealment of the attack proposed in this invention.
[0077] 2) This invention first attacks the subsynchronous oscillations in the power system caused by the series capacitor compensator, and then attacks the PMU's measurement values, making the system measurements normal and thus evading subsynchronous oscillation detection. This highlights the potential security risks associated with subsynchronous oscillations and provides a foundation for developing more robust models in the future.
[0078] 3) The attack proposed in this invention has strong concealment. Because the subsynchronous oscillation caused by attacking the series capacitor compensator results in the change in the measured value being calculated, the calculated change in measurement is subtracted from the PMU's measured data, thereby evading detection. Attached Figure Description
[0079] Figure 1 This is a flowchart of the present invention;
[0080] Figure 2 This is a timing diagram of the three-phase grid-connected current after the series compensation capacitor of the present invention is attacked;
[0081] Figure 3 This is a three-phase grid-connected current spectrum diagram after the series compensation capacitor of the present invention is attacked;
[0082] Figure 4 The series compensation capacitor of the present invention is attacked after ω r U dc i dg i qg Comparison image with normal condition;
[0083] Figure 5 The series compensation capacitor of the present invention is attacked after ψ ds ψ qs ψ dr ψ qr Comparison image with normal condition;
[0084] Figure 6 This is a comparison diagram of the d-axis current of the grid-connected capacitor compensator (AOS) under covert attack (SA) and normal conditions. Detailed Implementation
[0085] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings.
[0086] Example 1: A complete dynamic model of a grid-connected doubly-fed induction generator (DFIG) wind turbine includes a wind turbine, an asynchronous generator, a rotor-side converter, a DC capacitor, a grid-side converter, and a grid-side filter. The wind turbine transfers wind energy to the DFIG via a mechanical shaft. The stator of the induction generator is directly connected to the grid, while the rotor is fed through a back-to-back converter.
[0087] This section evaluates the performance of the proposed control scheme through simulation. The experiments were conducted on a desktop computer with an AMD Ryzen 7 5700G processor and Radeon Graphics 3.80GH, using MATLAB 2022b. We built a wind power plant in Simulink consisting of six wind turbines (each 1.5MW), connected to an infinite power grid via a 30km transmission line.
[0088] refer to Figure 1-3 A covert attack method based on series compensation capacitor and PMU measurement tampering includes the following steps:
[0089] S1. Establish a mathematical model of the DFIG formed by a set of differential and algebraic equations. Specifically, for the single-mass module of the wind turbine and transmission system:
[0090]
[0091] In the formula, T m It is the mechanical torque output by the wind turbine, P m For mechanical power, ω r It is the rotor speed, ρ air Let S be the air density, S be the area swept by the turbine blades as they rotate, and C be the area swept by the turbine blades as they rotate. p V is the wind turbine power coefficient. w For wind speed, T e It is electromagnetic torque; F is the coefficient of friction; H g is the equivalent time inertia constant of the shaft system.
[0092] Its flux linkage equation is also listed as follows:
[0093]
[0094] Where, ω s It is the per-unit value of the synchronous speed; R s and R rThese are the resistances of the stator and rotor, respectively; s in the table below represents the electrical quantities on the stator side; r in the table below represents the electrical quantities on the rotor side; ψ ds ψ qs Divided into d-axis and q-axis components of the stator flux linkage; ψ dr ψ qr Divided into d-axis and q-axis components of rotor flux linkage; u ds u qs These are the d-axis and q-axis components of the DFIG terminal voltage, respectively. They serve as inputs for dynamic state estimation and decouple the doubly-fed induction generator (DFIG) from the external network; i ds and i qs These are the d-axis and q-axis components of the DFIG stator current, respectively; u dr u qr These are the d-axis and q-axis components of the DFIG rotor voltage, respectively; i qr and i qr These are the d-axis and q-axis components of the DFIG rotor current, respectively.
[0095] will u ds u qs i ds i qs u dr u qr i dr i qr Substituting the dynamic equations of the DC capacitor and the filter inductor, the power P on the rotor side and grid side of the converter is calculated. r and P g .
[0096]
[0097] Among them, U dc P is the DC capacitor voltage; r and P g These represent the power on the converter rotor side and the grid side, respectively; C dc For DC capacitors; the subscript g indicates the grid-side electrical quantity of the converter; u dg and u qg These are the d-axis and q-axis components of the converter grid-side voltage, respectively; i dg and i qg These are the d-axis and q-axis components of the converter grid-side current, respectively; R g and L g These are the resistance and reactance of the filter inductor, respectively.
[0098] To measure the active and reactive power output of the generator, as well as the d-axis and q-axis components of the generator terminal current, equations need to be constructed. The measurement equations are as follows:
[0099]
[0100] Among them, P t and Q t These are the active power and reactive power output by the generator, i dt and i qt These are the d-axis and q-axis components of the terminal current of the doubly-fed induction wind turbine, respectively.
[0101] Based on the differential and algebraic equations above, construct the discrete DFIG state-space equations:
[0102]
[0103] Where, x k =[ω r ,ψ ds ,ψ qs ,ψ dr ,ψ qr U dc i dg i qg ], y k =[P t Q t i dt i qt ] represent the state vector and measurement vector of the system at time k, respectively. k =[u ds ,u qr V w Let ] be the input vector at time k, and f() represent x k and x k-1 The nonlinear state transition function relating the two is composed of equations (1)-(5), and h() is a nonlinear measurement function composed of equation (5). k and v k Let Q represent process noise and observation noise, respectively. The noises are independent and have zero mean, and their covariance matrices are Q and Q, respectively. k and R k .
[0104] The above method constructs a complete dynamic model of a grid-connected doubly-fed induction generator (DFIG), detailing key physical quantities such as the rotor and transmission system, flux linkage dynamics, DC capacitor, and filter inductor. The nonlinear dynamic characteristics are decoupled from the external network through discretized state-space equations. This model accurately reflects the operating state and transient response of the wind power system, providing a precise theoretical basis and computational foundation for subsequent state estimation, measurement data correction, and inverse kinematics of attack parameters. This improves the accuracy and feasibility of covert attacks and effectively reveals potential security vulnerabilities in the wind power system.
[0105] S2. To increase the transmission capacity of transmission lines and reduce energy loss during transmission, DFIG wind farms are often connected to the external power grid via series compensation lines. The state-space equations of the series compensation line module are constructed as follows:
[0106]
[0107] The state vector and each matrix are as follows:
[0108] X line =[u cd ,u cq i d i q ], u line =[u td ,u tq ,u od ,u oq ], Y line =[i d i q ]
[0109] D line =0
[0110] Among them, u cd and u cq Let i be the dq-axis component of the voltage across the capacitor. d and i q For the dq-axis components of the series compensated line current, u td and u tq The dq-axis component of the stator voltage after being boosted is u. od and u oq X represents the dq-axis component of the external infinite grid voltage. c It is the capacitive reactance of the series compensation capacitor, X L R is the inductive reactance of the equivalent inductance of a series circuit. L This is the equivalent resistance on the series compensation line.
[0111] The above method constructs a state-space equation for a transmission line module including a series compensator, accurately describing the voltage across the capacitor, the line current, and the transformation relationship after voltage boosting, establishing a direct link between capacitor reactance and system dynamics. This state-space model not only accurately simulates the actual operating state of the series-compensated line but also provides a mathematical basis for resolving the capacitor parameters corresponding to the inverse oscillation mode. This allows attackers to accurately determine the capacitor compensation value required for the attack based on eigenvalue analysis, thereby achieving precise control of system parameters while inducing subsynchronous oscillations.
[0112] S3. The stealth attack strategy proposed in this invention is as follows: First, the series compensator is attacked, causing power system oscillations. However, the measured values at this time can reflect that the system has oscillated. Therefore, we also need to tamper with the measured values to make them return to normal, thereby evading detection. The specific attack method is as follows:
[0113] This invention starts with the state transition matrix of a transmission line and attacks the capacitance and reactance to induce system oscillations. The eigenvalues of the state transition matrix reflect the dynamic characteristics and stability of the system through their real and imaginary parts. The real part of the eigenvalues determines the convergence or divergence of the system: when the real part is negative, the system state decays exponentially and tends to be stable; a positive real part leads to system divergence and instability. The imaginary part characterizes the oscillation characteristics of the system; the larger the imaginary part, the higher the oscillation frequency. When the imaginary part is zero, the system response is purely exponential and there is no oscillation.
[0114] Therefore, the stability and dynamic behavior of a system can be comprehensively judged by the real and imaginary parts of its eigenvalues: the real part determines stability, while the imaginary part affects oscillation characteristics. Based on this, the attack method of this invention can provide a set of unstable eigenvalues, thereby solving for the capacitance value corresponding to those eigenvalues, and using this value as the attack value for the capacitance, thus inducing system oscillation. The specific steps are as follows:
[0115] 1) Solve for matrix A line eigenvalues
[0116]
[0117] In the formula, λ and x = X C Let A and E represent the eigenvalues and capacitive reactance, respectively, and let E represent the identity matrix. To simplify the solution, let (A... line -λE) is represented as a block matrix:
[0118] in
[0119]
[0120] For block matrices If matrix A is invertible
[0121] Then |A line -λE|=|A||D-CA -1 B|=0, because A is invertible, therefore
[0122] |D-CA -1 B|=0, that is, a second-order matrix (D-CA) -1 B) Linear correlation, substituting ABCD into the equation yields...
[0123]
[0124] Because |D-CA -1 B|=0
[0125] Therefore By arranging, simplifying, and combining like terms, we obtain:
[0126]
[0127] remember Using the quadratic formula, we can obtain...
[0128]
[0129] Therefore, by providing a set of eigenvalues containing the oscillation modes, we can calculate the attack value of the capacitive reactance. Through a data tampering attack, the capacitor compensation value in the power system transmission lines can be modified to... This can cause power system oscillations, where f represents the frequency of the grid current.
[0130] Based on eigenvalue solving and block matrix analysis of the state transition matrix of the series-complemented circuit, the above method establishes a quantitative relationship between capacitance reactance and oscillation eigenvalues through mathematical derivation, and uses the quadratic equation to solve for the required capacitance parameters. This method not only achieves a technical breakthrough in deriving capacitance compensation values from a given oscillation mode, but also makes the attack process highly targeted and controllable. It can precisely trigger subsynchronous oscillations of the system without causing obvious external anomalies, effectively improving the stealth and success rate of the attack, and providing theoretical support and implementation methods for covert network attacks.
[0131] Experiments show that the simulation model operates normally within 0-0.17 seconds, but an attack is injected at 0.17 seconds, modifying the capacitance value on the transmission line. This triggers subsynchronous oscillation. After the attack, the three-phase grid-connected current was measured and its spectrum was analyzed. The analysis results are as follows: Figure 2 , Figure 3 As shown in the figure above, we can observe that the three-phase current oscillates after the injection attack in 0.17 seconds. The spectrum diagram shows a subsynchronous frequency between 20Hz and 55Hz with an amplitude between 0.1 and 0.2, indicating that tampering with the capacitor can induce subsynchronous oscillations, and this subsynchronous component can be detected. To achieve a stealthy attack—that is, to evade detection even when the system exhibits subsynchronous oscillations—we need to calculate the change in the measured value caused by the attack, and subtract this change from the original measured value to obtain the normal measured value of the system. Replacing the measurement with this value will evade the attack.
[0132] However, such attacks can induce abnormal fluctuations in measurement data, making it relatively easy for defenders to detect system oscillations by monitoring these values and thus identify the attack.
[0133] S5. Most current oscillation detection algorithms are based on the measurement of voltage, current, and other related data. However, if an attacker manipulates the capacitance value to induce system oscillation, the defender can usually easily detect the abnormal oscillation through the measurement data. To avoid this detection risk, this invention aims to eliminate the interference of attacks on the measurement data and ensure that the data collected by the PMU (Phasor Measurement Unit) remains in a normal state, thereby preventing the defender from discerning any signs of oscillation from the measurement data, and thus constructing a stealthy attack strategy.
[0134] The attack model presented in this paper is based on the following assumptions: 1. The attacker has completely obtained the model structure and key operating parameters of the wind farm through information theft, system identification, and other means. 2. The attacker can control commands to tamper with the compensation values of the series capacitors in the series compensation circuit. 3. The attacker can intercept the measurement values of the power system's PMU online.
[0135] To eliminate interference from attacks on measurement data and ensure that the data collected by the PMU (Phasor Measurement Unit) remains in a normal state, this invention calculates the change in measurement value caused by the attack, subtracts the change in measurement value from the measured value after the system is attacked to obtain the normal measurement value, and then modifies the PMU measurement value to the normal value on the transmission line. The specific implementation steps are as follows.
[0136] The specific implementation steps are as follows:
[0137] 1) First, the measurement value at time k-1 was extracted, and the state x of the system at time k-1 was estimated using the dynamic state estimation method. k-1 Then, the series capacitor is attacked, causing system oscillation and altering the system state.
[0138] 2) Use the state transition function to calculate the estimated state at the next time step before the attack occurs. (Indicates an estimate that there will be no attack in the next moment) and uses measurement. The state-space equation is used to estimate the state after an attack through dynamic state estimation methods. This yields the change in the system state after the attack, which can then be calculated using a measurement function.
[0139] 3) Subtract the change in measurement from the measured value of pmu to obtain y. k (This is an estimate of the measurement when the system is running normally).
[0140] 4) Using data tampering attack methods with the estimated yk This can replace the measurement values transmitted from the system to the main station, thus constituting a covert attack.
[0141] The specific implementation process is as follows:
[0142] Assuming the transmission line capacitance is attacked at time k, the state and measurement at time k can be expressed as:
[0143]
[0144] in This indicates the state after an attack. This represents the actual measurement of the system state after an attack. This represents the input at time k-1. This represents the input at time k. h is a nonlinear state transition function, and h() is a nonlinear measurement function. It's process noise. It's observation noise. Before launching the attack, y is first intercepted. k-1 The time-time measurement is performed, and the result is estimated using dynamic state estimation (DSE). Then calculate using the state transition function If the state after being attacked at time k can be accurately estimated Then the "normal" measurement value y at time k k It can be calculated using the following formula:
[0145]
[0146] Attentive readers will notice Why not use it? replace Why? Because It is calculated through the state transition function, which contains a large error. There is also an estimation error; subtracting the two can offset some of the error, making y... k It is closer to the "normal" value.
[0147] In order to accurately estimate To construct a covert attack, we consider using unscented Kalman filtering for Disturbance Estimation (DSE). By introducing a dynamic state estimation method, we utilize the state transition function and measurement equations to estimate the system's state after the attack in real time, accurately calculating the change in measured values caused by the attack. Subsequently, by subtracting this change from the attacked measured values, we obtain the true measurement data of the system under normal operating conditions. Then, we use data tampering techniques to replace the PMU data on the transmission line, effectively concealing the attack. This method not only overcomes the shortcomings of detection triggered by direct measurement data anomalies but also achieves precise correction of internal power grid disturbances through accurate state prediction and error compensation, greatly improving the success rate and anti-detection capability of covert attacks.
[0148] The most important aspect of unscented Kalman filtering is the unscented transform. This unscented transform involves constructing a set of points, called sigma points, that have the same mean and covariance as the random variable. These sigma points are then used to calculate the mean and variance of the variable after propagation through a nonlinear function, thus approximating the distribution of the nonlinear function. The algorithm consists of two phases: prediction and update.
[0149] The prediction phase first uses an unscented transformation, employing the state estimate at time k-1. Covariance Matrix Generate 2n sigma points:
[0150]
[0151] Where n represents the state dimension, Representation matrix In the i-th column, ξ = α 2 (n+κ)-n is a composite scaling factor, and α is a free parameter controlling the distribution of sigma points. Its value is related to the dimension of the state vector; the higher the dimension, the smaller the value of α. The typical range of α is 10. -4 <α<1, κ is usually set to 2.
[0152] Set weight w i =1 / (2n), each sigma point passes through a nonlinear function Perform mapping to generate a set of transformed samples, denoted as... Then the prior state value at time k and prior covariance matrix It can be calculated using the following formula:
[0153]
[0154] During the update phase, the state prior value is used first. and prior covariance matrix Generate updated sigma points:
[0155]
[0156] Then, each sigma point is passed through a nonlinear function. Perform mapping to generate a set of transformed samples, denoted as... Next, the prior measurement vector is calculated. Error covariance matrix and cross covariance matrix The superscript xx indicates the relationship between states, the superscript xy indicates the relationship between a state and a measurement, yy indicates the relationship between measurements, the subscript k|k-1 indicates the prediction, and the subscript k|k indicates the actual result.
[0157]
[0158] Then calculate the Kalman gain:
[0159]
[0160] Finally, for The final state estimate is obtained by making corrections. And update
[0161]
[0162] Finally passed Get y k At this point, the PMU measurement value is tampered with and changed to y. k y k The measurement value is set to "normal" to avoid oscillation detection.
[0163] The method described above achieves high-precision estimation of the nonlinear system state by constructing sigma points that match the system state mean and covariance, setting reasonable weights, and then performing prediction and update stages. This method effectively offsets errors caused by system and measurement noise, improving the accuracy of state estimation and providing reliable data support for subsequent calculations of measurement changes caused by attacks. This ensures that the PMU output data always maintains "normal" characteristics during covert attacks, greatly enhancing the covertness and success rate of attack strategies, while also exposing technical shortcomings in current system protection.
[0164] In the experiment, unscented Kalman filtering was first used to estimate the state of the system after it was attacked. Then use the process function to calculate the state when it is not attacked. The state change caused by the attack can be... The calculations yield the correct measurement values. We used unscented Kalman filtering to estimate the calculated values of the grid-side dq-axis current and its usage process function. The results are compared as follows: Figure 4 , Figure 5 As shown.
[0165] As clearly observed in the image, the system did not immediately lose stability after the injection attack at 0.17 seconds; instead, it began to exhibit oscillating behavior at 0.175 seconds. The grid-side dq-axis current estimated using the unscented Kalman filter method exhibits obvious oscillating characteristics. In contrast, the grid-side dq-axis current calculated using the process function shows higher stability and can be considered as the current reference under normal system operation. By subtracting these two values, the change in system state caused by the attack can be obtained, and the measured change can then be derived.
[0166] Furthermore, we conducted an in-depth comparative analysis of the changes in the measured values (i.e., the dq-axis components of the grid-connected current) under two scenarios: a direct attack and a covert attack (the tampered values represent the measured values under a covert attack). The specific comparison results are as follows: Figure 6 As shown.
[0167] These observations profoundly reveal that covert attacks not only possess the ability to induce system oscillations, but their sophisticated camouflage techniques also allow them to cleverly evade conventional oscillation detection mechanisms. This discovery undoubtedly poses a severe challenge to system security, highlighting the urgency and importance of strengthening research on detection and defense strategies against covert attacks in the current technological context.
[0168] Any aspects of the invention not described in detail are well-known to those skilled in the art. Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the present invention, and all such modifications and substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A covert attack method based on series compensation capacitor and PMU measurement tampering, characterized in that, Includes the following steps: S1. Establish a complete dynamic model of a grid-connected doubly fed induction generator (DFIG), and simultaneously form the state-space equations of the DFIG using differential and algebraic equations; S2. Construct the state-space equations of the line module containing the series compensator; S3. Based on the state transition matrix of the transmission line equation, the relationship between eigenvalues and capacitor reactance is derived. By providing a set of eigenvalues containing oscillation modes, the capacitor reactance corresponding to the eigenvalues containing oscillation modes is solved inversely. Then, the capacitor parameters are solved through the capacitor reactance. Finally, the control command of the series capacitor compensator is tampered with to change the capacitor parameters to attack values, causing system oscillation. S4. Estimate the change in the measurement value caused by the attack using the dynamic state estimation method, then subtract the change in measurement value from the measurement value after the system is attacked to obtain the first measurement value, and tamper with the PMU measurement value to the first measurement value on the transmission line to construct a covert malicious attack; The state-space equation of the line module of the series compensator in step S2 is: , The state vector and each matrix are as follows: , , , , , , , in, and These are the d-axis and q-axis components of the voltage across the capacitor. and For the d-axis and q-axis components of the series compensated line current, and The voltage components on the d and q axes are the voltage after the stator voltage has been boosted. and For the d-axis and q-axis components of the external infinite grid voltage, It is the capacitive reactance of the series compensation capacitor. The inductive reactance of the equivalent inductance of a series circuit. The equivalent resistance on the series compensation line; The specific steps of step S3 are as follows: 1) Solving the matrix eigenvalues , In the formula and Let represent eigenvalues and capacitive reactance, respectively, and E represent the identity matrix; 2) Represented as a block matrix: ,in ; ; ; , For block matrices If the matrix Reversible but ,because Reversible, therefore That is, a second-order matrix Linear correlation; 3) Substituting ABCD into the equation, we get... , because , Therefore ; 4) By rearranging, simplifying, and combining like terms, we obtain: , remember , , , Using the quadratic formula, we can obtain... , 5) Modify the capacitor compensation value in the power system transmission lines to ,in This indicates the frequency of the mains current.
2. The covert attack method based on series compensation capacitor and PMU measurement tampering according to claim 1, characterized in that, The complete dynamic model of the grid-connected doubly fed induction wind turbine in step S1 is as follows: For a single-mass module of the wind turbine and transmission system: (1) , (2) , In the formula, It is the mechanical torque output by the wind turbine. For mechanical power, It is the rotor speed. Let S be the air density, and S be the area swept by the turbine blades as they rotate. The power coefficient of the wind turbine. For wind speed, It is electromagnetic torque; It is the coefficient of friction; The equivalent time inertia constant of the shaft system; The flux linkage equation is: (3) , in, It is the per-unit value of the synchronous speed; and These are the resistances of the stator and rotor, respectively; the subscript 's' represents the electrical quantity on the stator side; the subscript 'r' represents the electrical quantity on the rotor side. , It is divided into d-axis and q-axis components of the stator flux linkage; , It is divided into d-axis and q-axis components of rotor flux linkage; , These are the d-axis and q-axis components of the DFIG terminal voltage, which serve as inputs for dynamic state estimation and decouple the doubly fed induction generator from the external network. and These are the d-axis and q-axis components of the DFIG stator current, respectively. , These are the d-axis and q-axis components of the DFIG rotor voltage, respectively. and These are the d-axis and q-axis components of the DFIG rotor current, respectively. The dynamic equations for the DC capacitor and the filter inductor are as follows: (4) , (5) , in, This is the DC capacitor voltage; and These are the power on the converter rotor side and the grid side, respectively; For DC capacitors; the subscript g indicates the electrical quantity on the grid side of the converter; and These are the d-axis and q-axis components of the grid-side voltage of the converter, respectively. and These are the d-axis and q-axis components of the grid-side current of the converter, respectively. and These are the resistance and reactance of the filter inductor, respectively; For the active and reactive power output of the generator, as well as the d-axis and q-axis components of the generator terminal current, equations are constructed for measurement, as follows: (6) , in, and These are the active power and reactive power output by the generator, respectively. and These are the d-axis and q-axis components of the terminal current of the doubly fed induction wind turbine generator. For these four measurements, a PMU needs to be installed at the terminal of each DFIG to obtain these electrical quantities. Construct the discrete DFIG state-space equations based on (1)-(6): (7) , in, , They represent the first The state vector and measurement vector of the system at any given time. Let k be the input vector at time k. express and The nonlinear state transition function of the relationship between them is formed by discretizing equations (2)-(5). The nonlinear measurement function is composed of equation (6). and Let process noise and observation noise be represented respectively. The noises are independent and have zero mean. Their covariance matrices are respectively and .
3. The covert attack based on series compensation capacitor and PMU measurement tampering as described in claim 1, characterized in that, In step S4, the change in the measured value caused by the attack is estimated using a dynamic state estimation method. Then, the change in the measured value after the system is attacked is subtracted from the measured value to obtain the first measured value. The measured value of the PMU is then tampered with to the first measured value on the transmission line. The specific details of constructing a covert malicious attack are as follows: Assuming the transmission line capacitance is attacked at time k, the state and measurement at time k can be expressed as: , , in This indicates the state after an attack. This represents the actual measurement of the system state after an attack. This represents the input at time k-1. This represents the input at time k. It is a nonlinear state transition function. It is a nonlinear measurement function. It's process noise. It is observation noise, which is intercepted before launching an attack. Measurement at time, and estimation through dynamic state estimation. Then calculate using the state transition function. Then, dynamic state estimation of the state after the attack at time k is performed using unscented Kalman filtering. The first measurement at time k. It can be calculated using the following formula: , 。 4. The covert attack method based on series compensation capacitor and PMU measurement tampering according to claim 3, characterized in that, The specific steps for dynamic state estimation using unscented Kalman filtering are as follows: The prediction phase first uses an unscented transform, by using State estimate at time 1 , ( and covariance matrix generate sigma points: , in, Indicates the dimension of the state. Representation matrix The List, It is a composite proportionality factor. These are free parameters that control the distribution of sigma points. Their values are related to the dimension of the state vector; the higher the dimension, the better. The smaller the value, the smaller the range of values. , It is usually set to 2; Set weights Each sigma point is passed through a nonlinear function. Perform mapping to generate a set of transformed samples, denoted as... Then the first State prior value at time 1 and prior covariance matrix It can be calculated using the following formula: , , During the update phase, the state prior value is used first. and prior covariance matrix Generate updated sigma points: , Then, each sigma point is passed through a nonlinear function. Perform mapping to generate a set of transformed samples, denoted as... Next, the prior measurement vector is calculated. Error covariance matrix and cross covariance matrix superscript Superscript indicates the relationship between states. The subscript indicates the relationship between a state and a measurement, yy indicates the relationship between measurements, and the subscript indicates the relationship between states and measurements. This indicates a prediction, indicated by the subscript. This refers to the actual situation: , , , Then calculate the Kalman gain: , Finally, for The final state estimate is obtained by making corrections. and update : , , Finally passed get At this point, the PMU measurement value was tampered with. .