FDIA detection positioning method based on DKNN-MGAT
Through the DKNN-MGAT method, combined with time and space characteristics, FDIA detection and positioning is used to use the multi-head graph attention network model to solve the problem of insufficient detection accuracy and robustness in the existing technology, and the precise positioning of false data injection attacks in the new energy grid-connected environment is achieved.
Patent Information
- Application Number
- CN202510377886.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-01
AI Technical Summary
The existing FDIA detection methods have shortcomings in detection accuracy, generalization and robustness, especially when the complexity of the power system increases after the new energy grid is connected to the grid, it is difficult to accurately locate the location of the false data injection attack.
Using a DKNN-MGAT-based method, a historical measurement database is constructed, temporal and spatial features are extracted, and a multi-head graph attention network model is used for training and testing, so as to realize multi-label binary classification to locate FDIA.
It improves the accuracy and generalization capabilities of FDIA detection, and can accurately locate the location of false data injection attacks in an AC flow system containing wind power nodes, enhancing the robustness of new energy grid-connected disturbances.
Smart Images

Figure CN120238349A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of smart grids, and particularly relates to an FDIA detection and positioning method based on DKNN-MGAT. Background Art
[0002] The power system is a complex cyber physical system (CPS) composed of several distributed and centralized control systems with different time scales and different control objects [1-3]. With the increasing proportion of renewable energy such as wind and light, the intermittency and randomness of its power generation increase the uncertainty of the system, and the stable operation of the system depends more on information control. As the core information control system, the Supervisory Control and Data Acquisition (SCADA) system undertakes key tasks such as real-time monitoring, data acquisition, and dispatching control, and is crucial for maintaining the safe and stable operation of the power system. Once the system is attacked by a network, it will lead to incorrect dispatching decisions and even serious consequences such as large-scale power outages.
[0003] Fake data injection attacks (FDIAs) [4], as a network attack method widely studied in recent years, can mislead the results of state estimation (SE) by tampering with the measurement data of the power SCADA system, and then affect subsequent dispatching and control, bringing risks to the safe and economic operation of the system. At the same time, with the large-scale grid connection of new energy, the node disturbance increases, and the difficulty of FDIA defense and detection has increased significantly, and the power grid security faces more severe challenges. Therefore, it is necessary to study the problem of FDIA detection considering the grid connection of new energy.
[0004] At present, the research on FDIA mainly focuses on two directions: attack modeling and attack detection. Among them, FDIA attack modeling can be divided into state perturbation type FDIA [5], line overlimit type FDIA [6], network structure misleading type FDIA [7], broken line concealment type FDIA [8], network parameter collaborative tampering type FDIA [9], residual pollution type FDIA
[10]
[11] , etc. In the above models, [5]-[9] all require the attack vector to avoid the bad data detection (BDD) of state estimation, and the number of tampered measurements is relatively large, which belongs to "traditional FDIA"; while the literature
[10]
[11] does not need to avoid BDD, and realizes the misleading of the state estimation result by inducing residual pollution and eliminating normal measurements, and the number of tampered measurements is less, which can be called "residual pollution FDIA".
[0005] From the perspective of defenders, attack detection stations study how to quickly and accurately detect FDIA, which can be roughly divided into two categories: model-driven methods and data-driven methods
[12] . Among them, model-driven methods [13-15] compare the processed measurement data with the artificially set detection threshold according to the model parameters of the system itself to detect FDIA. Since the accuracy and efficiency of this method are largely restricted by the accuracy of power grid modeling, it performs poorly in large power systems. The data-driven method does not require physical model parameters and uses machine learning algorithms to mine the outlier characteristics in a large amount of measurement data to achieve FDIA detection. This method is more suitable for complex and dynamic large-scale power systems and has therefore received more attention from scholars.
[0006] The most studied type of data-driven method is the supervised learning detection method. Its core idea is to transform the FDIA detection problem into a binary classification problem in machine learning to determine whether the measurement data has been affected by FDIA. Typical algorithms include traditional machine learning algorithms (support vector machine
[16] , K-nearest neighbor algorithm
[17] , decision tree
[18] , etc.), ensemble learning algorithms (random forest
[19] , XGBoost
[20] , LightGBM
[21] , AdaBoost
[22] , etc.), and deep learning algorithms (multi-layer perceptron
[23] , convolutional neural network
[24] , recurrent neural network
[25] , etc.).
[0007] However, there are two problems with the above detection methods: one is that the detection method has the "black box characteristic", that is, the relationship between the input data and the detection result is not interpretable, and the generalization performance of the model is poor; the other is that the binary classification problem can only judge whether an attack exists but cannot locate the specific location of the attack.
[0008] To address the first problem, a detection method based on graph neural network (GNN)
[26] has emerged. This method encodes the power grid topology structure into a graph data structure and establishes an explicit mapping relationship between the graph node feature propagation mechanism and the physical laws of the power system, providing a new paradigm for constructing an interpretable FDIA detection [27-29] framework. Reference
[30] proposed a supervised learning method based on gated graph attention network, which enhanced the ability to extract topological correlation features through the neighborhood aggregation mechanism, while the spatio-temporal graph convolutional network proposed in reference
[31] captured the dynamic evolution law of measurement data through the time convolutional layer. Both have verified the technical advantages of GNN in improving the interpretability of the model.
[0009] Regarding the second problem, Wang et al.
[32] extended the original binary classification problem to a multi-label binary classification problem to achieve the localization of FDIA. Subsequently, Xi Lei et al. also achieved the attack localization of FDIA and improved the detection accuracy and efficiency by combining kernel extreme learning machine with autoencoder
[33] , combining image coding with multi-head self-attention network
[34] , and combining adaptive differential evolution with fuzzy width learning system
[35] , etc.
[0010] Reference
[36] combined the above two ideas, used graph attention and multi-scale parallel fusion convolutional network to extract and fuse the features of measurement data, and used a fully connected layer for multi-label binary classification, which not only achieved attack localization but also improved the interpretability of the model.
[0011] However, the above detection methods still have three deficiencies: First, the detection methods focus on the localization of abnormal states of nodes with smaller dimensions and cannot accurately locate the injection of abnormal nodes with larger dimensions and line measurements (insufficient accuracy); second, they can only locate and detect a single attack model (insufficient generalization); third, they do not consider the impact of new energy grid connection disturbances (insufficient robustness).
[0012] Literature source:
[0013] [1] Chen Qingqing, Su Sheng, Chang Guanghui, et al. A review of internal threats in power cyber-physical systems [J]. China Southern Power Grid Technology, 2022, 16(06): 1-13.
[0014] Chen Qingqing, Su Sheng, Chang Guanghui, et al. A review of internal threats in power cyber-physical systems [J]. China Southern Power Grid Technology, 2022, 16(06): 1-13.
[0015] [2] Yao Pengchao, Yan Bingjing, Hao Weijie, et al. Intrusion tolerance assessment method for power cyber-physical systems [J]. Electric Power, 2022, 55(04): 13-22.
[0016] Yao Pengchao, Yan Bingjing, Hao Weijie, et al. Intrusion tolerance assessment method for power cyber-physical systems [J]. Electric Power, 2022, 55(04): 13-22.
[0017] [3] Li Peikai, Liu Yun, Xin Huanhai, et al. Vulnerability assessment of cyber-physical system of distribution network under distributed collaborative control mode[J]. Automation of Electric Power Systems, 2018, 42(10):22-29+59.
[0018] Li Peikai, Liu Yun, Xin Huanhai, et al. Vulnerability assessment of cyber-physical system of distribution network under distributed cooperative control mode [J]. Automation of Electric Power Systems, 2018, 42(10):22-29+59.
[0019] [4] LIU Yao, NING Peng, REITER M K. False data injection attacks against state estimation in electric power grids[J]. ACM Transactions on Information and System Security, 2011, 14(1): 13.
[0020] [5]Kosut O, Jia L, Thomas RJ, et al. Malicious data attacks on the smartgrid[J]. IEEE Transactions on Smart Grid, 2011, 2(4): 645-658.
[0021] [6]Du M, Wang L, Zhou Y. High-stealth false data attacks on overloading multiple lines in power systems [J]. IEEE Transactions on Smart Grid, 2022, 14(2): 1321-1324.
[0022] [7] Liu Wenxia, Zeng Zehua, Yang Yuze, et al. Research on False Data Injection Attack Based on Misidentification of Power Network Structure [J / OL]. Journal of North China Electric Power University (Natural Science Edition), 2024, 1 - 11.
[0023] [8] Deng R, Zhuang P, Liang H. CCPA: Coordinated cyber - physical attacks and counter measures in smart grid [J]. IEEE Transactions on Smart Grid, 2017, 8(5): 2420 - 2430.
[0024] [9] Liu C, Liang H, Chen T. Network parameter coordinated false data injection attacks against power system AC state estimation [J]. IEEE Transactions on Smart Grid, 2020, 12(2): 1626 - 1639.
[0025]
[10] Kim J, Tong L, Thomas R J. Data Framing Attack on State Estimation [J]. IEEE Journal on Selected Areas in Communications, 2014, 32(7): 1460 - 1470.
[0026]
[11] Yang Yuze, Liu Wenxia, Liu Gengming, et al. Research on False Data Injection Attack Considering Residual Pollution under Incomplete Information [J / OL]. Proceedings of the CSEE, 2024, 1 - 15.
[0027]
[12] Yang Yuze, Liu Wenxia, Li Chengze, et al. Review of FDIA Detection Methods for Power SCADA Systems [J]. Proceedings of the CSEE, 2023, 43(22): 8602-8622.
[0028]
[13] Sreenath J G, Meghwani A, Chakrabarti S, et al. A recursive state estimation approach to mitigate false data injection attacks in power systems [C] / / 2017 IEEE Power & Energy Society General Meeting. Chicago:IEEE, 2017:1-5.
[0029]
[14] LI Yuancheng, Wang Yuanyuan. Developing graphical detection techniques for maintaining state estimation integrity against false data injection attack in integrated electric cyber-physical system [J]. Journal of Systems Architecture, 2020, 105:101705.
[0030]
[15] Pal S, Sikdar B, Chow J H. Classification and detection of PMU data manipulation attacks using transmission line parameters [J]. IEEE Transactions on Smart Grid, 2018, 9(5):5057-5066.
[0031]
[16] Chen Ziyu, Zhu Jizhong, Li Shenglin, et al. Detection of false data injection attack in automatic generation control system with wind energy based on fuzzy support vector machine[C] / / IECON 2020 The 46th Annual Conference of the IEEE Industrial Electronics Society. Singapore:IEEE, 2020:3523-3528.
[0032]
[17] Ahmed S, Lee Y D, Hyun S H, et al. Covert cyber assault detection in smart grid networks utilizing feature selection and Euclidean distance-based machine learning[J]. Applied Sciences, 2018, 8(5):772.
[0033]
[18] Acosta M R C, Ahmed S, Garcia C E, et al. Extremely randomized trees-based scheme for stealthy cyber-attack detection in smart grid networks[J]. IEEE Access, 2020, 8:19921-19933.
[0034]
[19] Wang Defu, Wang Xiaojuan, Zhang Yong, et al. Detection of power grid disturbances and cyber-attacks based on machine learning[J]. Journal of Information Security and Applications, 2019, 46:42-52.
[0035]
[20] Xue Wenli, Wu Ting. Active learning-based XGBoost for cyberphysical system against generic AC false data injection attacks[J]. IEEE Access, 2020, 8:144575-144584.
[0036]
[21] Cao Jie, Wang Da, Qu Zhaoyang, et al. A novel false data injectionattack detection model of the cyber-physical power system[J]. IEEE Access, 2020, 8:95109-95125.
[0037]
[22] Ozay M, Esanola I, Vural F T Y, et al. Machine learning methods forattack detection in the smart grid[J]. IEEE transactions on neural networksand learning systems, 2016, 27(8):1773-1786.
[0038]
[23] Ashrafuzzaman M, Chakhchoukh Y, Jillepalli A A, et al. Detectingstealthy false data injection attacks in power grids using deep learning[C] / / 2018 14th International Wireless Communications&Mobile Computing Conference(IWCMC). Limassol:IEEE, 2018:219-225.
[0039]
[24] Wang Shuoyao, Bi Suzhi, Zhang Y J A. Locational detection of the false data injection attack in a smart grid:A multilabel classification approach[J]. IEEE Internet of Things Journal, 2020, 7(9): 8218-8227.
[0040]
[25] Yang Liqun, Zhang Xiaoming, Li Zhi, et al. Detecting bi-level false data injection attack based on time series analysis method in smart grid[J]. Computers & Security, 2020, 96: 101899.
[0041]
[26] Jie Zhou, Ganqu Cui, Shengding Hu, et al. Graph neural networks A review of methods and applications[J]. AIOpen 1(2020) 57–81.
[0042]
[27] Osman Boyaci, Amarachi Umunnakwe, Abhijeet Sahu et al. Graph Neural Networks Based Detection of Stealth False Data Injection Attacks in Smart Grids[J]. IEEE Systems Journal, 2022, 16(2): 2946-2957.
[0043]
[28] Wu Zhong. Research on data and knowledge joint-driven defense method against false data injection attack[D]. Southeast University, 2023.
[0044]
[29] Edeh Vincen, Mehdi Korki, Mehdi Seyedmahmoudian, et al. Reinforcement Learning-empowered Graph Convolutional Network Framework for Data Integrity Attack Detection in Cyber-physical Systems[J]. CSEE Journal of Power and Energy Systems, 2024, 10(2).
[0045]
[30] Wang Yaokun. Research on Graph-based False Data Detection in Power Systems[D]. Yanshan University, 2023.
[0046]
[31] Su Xiangjing, Deng Chao, Li Fengyong, et al. An Interpretable Grid False Data Injection Attack Detection Method Based on the MGAT-TCN Model[J]. Automation of Electric Power Systems, 2024, 48(02): 118-127.
[0047]
[32] Shuoyao Wang, Suzhi Bi, et al. Locational Detection of the False Data Injection Attack in a Smart Grid: A Multilabel Classification Approach[J]. IEEE Internet OF Things Journal, 2020, 7(9).
[0048]
[33] Xi Lei, Peng Dianming, Cao Wei, et al. Location Detection of FDIA in Power Cyber-physical Systems Based on Data-driven Algorithms[J / OL]. Proceedings of the CSEE, 2024, 1-12.
[0049]
[34] Xi Lei, Li Zongze, Liu Zhihong, et al. Detection of False Data Injection Attacks in Power Grids Based on Image Coding and Multi-Head Self-Attention Convolutional Neural Network[J / OL]. Proceedings of the CSEE, 2025, 1-13.
[0050]
[35] Xi Lei, Chen Hongjun, Peng Dianming, et al. A Location Detection Method for FDIA Based on Adaptive Differential Evolution-Fuzzy Width Learning System[J / OL]. Proceedings of the CSEE, 2024, 1-13.
[0051]
[36] Xi Lei, Chen Caiyu, Chen Hongjun, et al. False data injection attack localization detection based on graph attention and multi-scale parallel fusion convolution [J / OL]. High Voltage Engineering, 1-11. Summary of the Invention
[0052] The technical problem to be solved by the present invention is to provide a FDIA detection and localization method based on DKNN-MGAT.
[0053] To achieve the above object, the present invention adopts the following technical solutions:
[0054] A FDIA detection and localization method based on DKNN-MGAT includes:
[0055] Step 1: Construct a historical measurement database;
[0056] Step 2: Sample different types of historical measurement data to generate a sample set;
[0057] Step 3: Convert the sample set into new feature data for extracting time features;
[0058] Step 4: Construct a feature matrix from the new feature data, form an input graph together with the adjacency matrix and data labels, and set the graph batch size for each training bitc h = 50;
[0059] Step 5: Divide the input graph into a training set and a test set, with the first 2 / 3 as the training set and the last 1 / 3 as the test set, and set the total number of training epochs epoch and the current training epoch e = 0;
[0060] Step 6: Initialize the training quantity parameter b = 0;
[0061] Step 7: Train the training set in the MGAT model;
[0062] Step 8: Judge the parameter b. If b < 2s / 3, that is, the training of the training set is not completed, then the round b = b + bitc h, otherwise e = e + 1.
[0063] Step 9: Judge the training epoch parameter e. If e < epoch, that is, the training epoch is not completed, then jump to Step 6, otherwise output the trained model and continue with Step 10;
[0064] Step 10: Use the trained model to test the test data;
[0065] Step 11: Output the test results;
[0066] Step 12: Calculate and output the evaluation index in the index calculation function according to the test results and the total label of the graph data.
[0067] Preferably, in step 3, the sample set is converted into new feature data for extracting time features using the DKNN method.
[0068] Preferably, in step 4, graph structure data with spatial characteristics is constructed based on all original node measurement data and original line measurement data of the section collected by the SCADA system as an input graph.
[0069] Preferably, a multi-head graph attention network model is used to train and test the graph structure data, and output multi-label binary classification results, which include binary classification results of each measurement data; wherein 0 indicates that the measurement point is normal, and 1 indicates that the measurement point suffers from FDIA.
[0070] The present invention adopts FDIA detection and positioning based on double K-nearestneighbors multi-head graph attention networks (DKNN-MGAT), which can accurately locate FDIA on the AC power flow system containing wind power nodes. The present invention first uses the DKNN method to extract the Euclidean distance between the power grid measurement data of the current section and the most similar section node measurement in the historical measurement data as new feature data of the same dimension as the measurement data, which is used to characterize the outlier characteristics of each measurement data point in the time dimension; then, the nodes and lines in the power grid topology are converted into nodes in the graph data, and the connection relationship between the graph nodes is determined according to the electrical connection between the measurement data to form a graph data structure; then, the new feature data is used as the graph node feature, and the multi-head attention mechanism is used to dynamically allocate the edge weight of the graph data, so as to extract the deep spatial features of the data; finally, the fully connected layer is used to output the multi-label binary classification results of each measurement point, so as to accurately locate the attacked measurement. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0072] Figure 1 This is a flow chart of the FDIA detection and positioning method based on DKNN-MGAT in an embodiment of the present invention;
[0073] Figure 2 This is the DKNN process framework diagram;
[0074] Figure 3 Construct a process for the input graph;
[0075] Figure 4 It is a flowchart of the MGAT framework. Specific implementation manners
[0076] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0077] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0078] Embodiment 1:
[0079] As Figure 1 shown, the embodiment of the present invention provides an FDIA detection and positioning method based on DKNN-MGAT, including:
[0080] Step 1: Construct a historical measurement database;
[0081] Step 2: Sample different types of historical measurement data to generate a sample set; among them, the sample set ratio is divided into four types: 1:1:1, 1:1:2, 1:0:1, 0:1:1 (FDIA considering residual contamination: traditional FDIA: normal data);
[0082] Step 3: Use the DKNN method to convert the sample set into new feature data for extracting time features;
[0083] Step 4: Construct a feature matrix from the new feature data, form an input graph together with the adjacency matrix and data labels, and set the graph batch size bitch = 50 for each training;
[0084] Step 5: Divide the input graph into a training set and a test set. The first 2 / 3 is the training set, and the last 1 / 3 is the test set. Set the total number of training epochs epoch and the current training epoch e = 0;
[0085] Step 6: Initialize the training amount parameter b = 0;
[0086] Step 7: Train the training set in the MGAT model;
[0087] Step 8: Judge the parameter b. If b < 2s / 3, that is, the training of the training set is not completed, then the round b = b + bitch, otherwise e = e + 1.
[0088] Step 9: Judge the training round parameter e. If e < epoch, that is, the training round is not completed, jump to Step 6; otherwise, output the trained model and continue with Step 10;
[0089] Step 10: Use the trained model to test the test data;
[0090] Step 11: Output the test result;
[0091] Step 12: Calculate and output the evaluation index in the index calculation function according to the test result and the total label of the graph data.
[0092] As an implementation manner of the embodiment of the present invention, in Step 3, the DKNN algorithm is a machine learning algorithm commonly used for data classification. Its core idea is: given a new data point, the DKNN algorithm can calculate the Euclidean distance from the new data point to other data points and find the K nearest neighbors.
[0093] DKNN is equivalent to performing two KNN operations, and its calculation flow chart is as Figure 2 shown. The first layer of KNN relies on the historical measurement database and screens out the K cross-sections most similar to the test cross-section based on the Euclidean distance between cross-sections. Under normal working conditions, the Euclidean distance between cross-sections is calculated as follows:
[0094]
[0095] where X and Y represent the test cross-section and the historical cross-section, and x i and y i are the measurement values corresponding to the two cross-sections respectively, and n is the dimension of the measurement data of a single cross-section.
[0096] Since the integration of wind power into the grid will cause regional measurement value fluctuations, resulting in the normal measurement cross-sections without FDIA showing data distribution characteristics similar to those of FDIA attack cross-sections, ultimately causing the KNN to mis-screen the similar cross-sections and affecting the subsequent detection and positioning effects. Therefore, to reduce the influence of wind power disturbances on the KNN algorithm, only m (m < n) measurement points with small measurement fluctuations are selected to calculate the Euclidean distance and screen the similar cross-sections.
[0097] The second layer of KNN normalizes each measurement data point of the test cross-section with the corresponding measurement data points of the selected K similar cross-sections and then calculates the Manhattan distance to obtain the outlier degree of each measurement point data of the test cross-section compared with the data set of the measurement points of the historical K most similar cross-sections. The Manhattan distance calculation between data points is as follows:
[0098] d(x,y) = |x - y|
[0099] In the formula, x i and yi The meaning is the same as above and will not be elaborated further.
[0100] After the DKNN operation, the original measurement data is converted into new time feature data that takes into account the degree of measurement outliers in the time dimension.
[0101] As an implementation manner of the embodiment of the present invention, in step S4, the embodiment of the present invention is different from most existing methods that only locate attack nodes. Instead, it detects and locates all measurements of the SCADA system collection section. Since the graph neural network requires graph-structured data as input for training and learning, and the construction of graph data is crucial for the algorithm performance, it is necessary to carefully design the construction method of graph data. The graph data construction method proposed in this paper is as Figure 3 shown.
[0102] First, all measurement data (including node and line measurements) is used as the nodes of the graph data, and the edges of the graph data are constructed based on the electrical connection between the measurement data:
[0103] 1) For node measurement data (including node voltage and node active and reactive power loads), from the power flow equation, it can be seen that there is a coupling relationship between the node voltage and the node active and reactive power loads as Figure 4 in edges 1-2 and 4-5), and there is also a coupling relationship between the node active and reactive powers as Figure 4 in edges 3 and 6). Therefore, there are edges between all of them, and the number of constructed edges is 3*num_node (the number of nodes).
[0104] 2) For line measurement data (including the active and reactive power measurements at the head and end of the line), there is a coupling relationship between the active and reactive powers at each end of the line (such as Figure 4 in edges 15 and 16), and the number of constructed edges is 2*num_line (the number of lines).
[0105] 3) For the node measurement data and the line measurement data, since the node active power load includes the active power of all lines connected to the node (such as Figure 4 in edges 7-8 and 11-12), and the same is true for the node reactive power load (such as Figure 4 in edges 9-10 and 13-14), the number of constructed edges is 8*num_line.
[0106] Secondly, construct the feature matrix of the graph. The feature dimension of each graph node (all measurement data) is s (s = n), which represents the association between this graph node and other graph nodes (including itself). The dimension of the feature matrix is s*s, where the feature data is filled according to the new adjacency relationship, and the formula for defining the feature value is as follows:
[0107]
[0108] Wherein, O ij represents the eigenvalue corresponding to the i-th row and j-th column of the feature matrix, M i and represent the i-th and j-th new time feature data. After the construction, the feature matrix encompasses the connection relationships between measurements and can reflect the spatial characteristics of the measurement data.
[0109] Finally, the constructed feature matrix, the new connection relationship matrix, and the measurement data labels are combined into a graph structure data as the input graph of the MGAT model.
[0110] As an implementation manner of the embodiment of the present invention, in step S7, when detecting FDIA in the power system, GAT can combine the graph structure with the attention mechanism to accurately model the complex associations between power network nodes, dynamically allocate weights to distinguish abnormal data. Compared with traditional machine learning algorithms, it can adaptively capture local and global features, enhance the robustness against stealth attacks, and at the same time, the multi-attention head design improves the detection sensitivity and generalization ability in complex topological scenarios.
[0111] In the multi-head graph attention mechanism of MGAT, for any pair of graph data nodes i and j, calculate their attention coefficients (weights), and the calculation and normalization formulas are as follows:
[0112] e ij = LeakyReLU(a T [Wh i ||Wh j )
[0113]
[0114] Wherein, e ij is the attention coefficient between nodes i and j, W is the weight matrix, h i and h j are the feature vectors of nodes i and j, a is a learned weight vector, the symbol || represents the concatenation operation, LeakyReLU is the activation function, α ij is the normalized attention coefficient, N(i) is the neighbor set of node i, and e ik is defined as above. After obtaining the normalized attention coefficient, node vi aggregates the features of its neighbors:
[0115]
[0116] Wherein, h i′ is the feature representation after node update, K is the number of heads, and σ is the activation function. To enhance the performance of the model, the multi-head graph attention mechanism calculates multiple attention heads in parallel. Each attention head has its own independent weight matrix and learned attention coefficients. After updating the weight matrix respectively, the outputs of each head are weighted averaged and concatenated as the final node representation.
[0117] Since the data dimension is too large under the full measurement configuration of the AC IEEE-118 system, in order to reduce the data dimension and further refine the data features, it is necessary to add a pooling layer to the model to perform pooling compression on the data. The method adopted in the embodiment of the present invention is batch global average pooling, and its formula is:
[0118]
[0119] In the formula, x g is the global feature representation of graph g, N g is the number of nodes in graph g, and x i is the feature of node i.
[0120] For existing FDIA detection and location methods, most of them attack and locate the node voltages and phase angles after power system state estimation [33-36]. However, whether it is the defense configuration of FDIA or the resilient control and state recovery, it is necessary to know the specific damaged measurement points. Therefore, the algorithm in this paper outputs the detection and location results of SCADA measurement data, converts the output of MGAT into a multi-label binary classification output through 2 fully connected layers. The output results include each measurement data (including all node measurements and line measurements), and the classification results are converted into binary values (0 or 1) through Sigmoid. Among them, 0 indicates that the measurement data is normal, and 1 indicates that the measurement is an attacked measurement. The output result of the location detection model is a binary vector with a length of 3*num_node + 4*num_line (equal to the cross-section measurement data dimension n). If the output result is all 0, it means that the normal measurement data is input into the historical measurement database. If there is 1 in the output result, FDIA location and warning are performed.
[0121] As Figure 4 shown, the framework process of MGAT is: input the processed graph dataset with dual time and space features into the MGAT model, adaptively extract these features through the multi-head graph attention mechanism, activate through the Relu function, perform overfitting prevention processing by the Dropout function, then perform dimensionality reduction through global average pooling, and finally perform dimensionality conversion processing with a fully connected layer to output the detection and location results of all measurement data.
[0122] The embodiments described above are only descriptions of the preferred embodiments of the present invention, and do not limit the scope of the present invention. Without departing from the spirit of the present invention, various modifications and improvements made by those of ordinary skill in the art to the technical solutions of the present invention shall fall within the protection scope determined by the claims of the present invention.
Claims
1. A FDIA detection and positioning method based on DKNN-MGAT, characterized in that: Including: Step 1: Construct a historical measurement database; Step 2: Sample different types of historical measurement data to generate a sample set; Step 3: Convert the sample set into new feature data for extracting time features; Step 4: Construct a feature matrix from the new feature data, form an input graph together with the adjacency matrix and data labels, and set the graph batch size for each training bitchs = 50; Step 5: Divide the input graph into a training set and a test set, with the first 2 / 3 as the training set and the last 1 / 3 as the test set, set the total number of training epochs epoch and the current training epoch e = 0; Step 6: Initialize the training quantity parameter b = 0; Step 7: Train the training set in the MGAT model; Step 8: Judge the parameter b. If b < 2s / 3, that is, the training of the training set is not completed, then the round b = b + bitchs, otherwise e = e + 1. Step 9: Judge the training epoch parameter e. If e < epoch, that is, the training epoch is not completed, then jump to Step 6, otherwise output the trained model and continue to Step 10; Step 10: Use the trained model to test the test data; Step 11: Output the test result; Step 12: Calculate and output the evaluation index in the index calculation function based on the test result and the total label of the graph data.
2. The FDIA detection and positioning method based on DKNN-MGAT as claimed in claim 1, characterized in that: In Step 3, use the DKNN method to convert the sample set into new feature data for extracting time features.
3. The FDIA detection and positioning method based on DKNN-MGAT as claimed in claim 2, characterized in that: In Step 4, construct graph structure data with spatial features from all the original node measurement data and original line measurement data of the cross-section collected by the SCADA system as the input graph.
4. The FDIA detection and positioning method based on DKNN-MGAT as claimed in claim 3, characterized in that: Adopt a multi-head graph attention network model to train and test the graph structure data, and output a multi-label binary classification result, where the result includes the binary classification results of each measurement data; among them, 0 indicates that the measurement point is normal, and 1 indicates that the measurement point suffers from FDIA.
Citation Information
Patent Citations
Network business flow feature selecting and classifying method based on multi-objective adaptive evolutionary algorithm
CN108494620A
CCA fermentation process KPI related fault monitoring method based on double-layer k neighbor standardization
CN113467434A
Method for detecting attack of virtual power plant business system
CN116561552A
Method for bus arrival time prediction when lacking data
WO2023029234A1
Cited By
False data injection attack and defense method based on graph neural network parameter estimation priority
CN122247754A