Dual-domain attack detection method and system oriented to source-load side distributed resources
By building the state space matrix of the inverter switch network and adding random excitation signals, the dual-domain attack detection problem of the inverter switch network in distributed power systems is solved, and efficient and low-cost attack identification and system security improvement are achieved.
Patent Information
- Application Number
- CN202510726623.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-04
AI Technical Summary
The prior art is difficult to effectively detect attacks on inverter switching networks in distributed power systems, especially dual-domain attacks at the physical and information levels, resulting in reduced system security and increased maintenance costs.
By linearly approximating the input signal and output current timing based on the inverter switching network, a state space matrix is constructed, and a random excitation signal is added. The state space matrix is used to verify the output current detection value of the inverter switching network to determine whether it is attacked.
Accurate attack detection on the inverter switch network is realized, which reduces detection costs and improves the security and stability of the system.
Smart Images

Figure CN120263541A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a dual-domain attack detection method and system for distributed resources on the source and load sides. Background Art
[0002] Distributed resources usually access the power system in flexible and diverse forms. By generating electricity locally and utilizing energy, the energy utilization efficiency is improved, transmission and distribution losses are reduced, bringing new opportunities for the supply-demand balance and flexible regulation of the new power system. Among them, most distributed generation resources rely on inverters to achieve power conversion and grid connection. As a key device of distributed generation resources, the inverter is responsible for converting the direct current generated by distributed energy into alternating current and connecting it to the grid, while playing important roles such as power regulation and power quality management.
[0003] However, due to the tight coupling between the physical layer and the information layer in inverter resources, manipulating sensing or control information will bring security risks to the distributed system. Once the control instructions or data transmitted through the network are intercepted and utilized, the sensor will report false measurement results, which will affect the normal operation of the distributed system.
[0004] In some technologies, attempting to patch and update security software in the distributed system can protect the information layer of the distributed system. However, this also increases the maintenance cost and requires continuous updating of the security software. Therefore, a more general low-cost method is needed to detect and locate the disturbance source in a large-scale distributed system. Summary of the Invention
[0005] The present invention provides a dual-domain attack detection method and system for distributed resources on the source and load sides, which can solve at least one of the above technical problems.
[0006] According to one aspect of the present invention, a dual-domain attack detection method for distributed resources on the source and load sides is provided, including: Based on the historical modulation input signal time series and the historical output current time series of the inverter switching network in the photovoltaic system, linearly approximate the inverter switching network to obtain the state space matrix of the inverter switching network; Add a random excitation signal to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and obtain the output current detection value of the inverter switching network; Based on the state space matrix of the inverter switching network, verify the output current detection value of the inverter switching network to determine whether the along-way transformation process of the inverter switching network for the random excitation signal is normal; When the process of the inverter switching network's transformation along the way for the random excitation signal is abnormal, it is determined that the inverter switching network is under attack.
[0007] According to another aspect of the present invention, there is provided a dual-domain attack detection device for distributed resources on the source and load sides, including: A state space matrix determination module, configured to perform linear approximation on the inverter switching network based on the historical modulation input signal time series and the historical output current time series of the inverter switching network in the photovoltaic system, so as to obtain the state space matrix of the inverter switching network; An excitation addition module, configured to add a random excitation signal to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and an output current detection value of the inverter switching network is obtained; An output detection module, configured to verify the output current detection value of the inverter switching network based on the state space matrix of the inverter switching network, so as to determine whether the process of the inverter switching network's transformation along the way for the random excitation signal is normal; An attack determination module, configured to determine that the inverter switching network is under attack when the process of the inverter switching network's transformation along the way for the random excitation signal is abnormal.
[0008] According to another aspect of the present invention, there is provided a dual-domain attack detection system for distributed resources on the source and load sides, including: at least one processor, and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the processor, and the processor is configured to obtain the instructions from the memory and execute the instructions, so that the at least one processor can execute the dual-domain attack detection method for distributed resources on the source and load sides according to any one of the embodiments of the present invention.
[0009] Adopting the technical solution of the present invention, based on the historical modulation input signal timing and the historical output current timing of the inverter switching network in the photovoltaic system, a linear approximation is performed on the inverter switching network to obtain the state space matrix of the inverter switching network. In this way, the model parameters for describing the inverter switching network from input to output can be obtained. A random excitation signal is added to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and the detected value of the output current of the inverter switching network is obtained; based on the state space matrix of the inverter switching network, the detected value of the output current of the inverter switching network is verified to determine whether the along - the - way transformation process of the inverter switching network for the random excitation signal is normal; in the case where the along - the - way transformation process of the inverter switching network for the random excitation signal is abnormal, it is determined that the inverter switching network is under attack. In this way, by adding a random excitation signal to the input signal of the inverter switching network and then using the model parameters of the inverter switching network, it can be accurately detected whether the random excitation signal in the detected value of the output current of the inverter switching network is normal. If it is normal, it means that there is no problem in the along - the - way conversion of the inverter switching network, which further proves that the inverter switching network is not under attack. Therefore, adopting the technical solution of the present invention can accurately detect whether each inverter switching network in the distributed power grid is under attack.
[0010] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Brief Description of the Drawings
[0011] The drawings are used to better understand the present solution and do not constitute a limitation to the present invention. Among them: Figure 1 is a flowchart of a dual - domain attack detection method for distributed resources facing the source - load side according to an embodiment of the present invention; Figure 2 is a schematic diagram of an attack detection process according to an embodiment of the present invention; Figure 3 is a structural block diagram of a dual - domain attack detection device for distributed resources facing the source - load side according to an embodiment of the present invention; Figure 4 is a block diagram of an electronic device for implementing the method according to an embodiment of the present invention. Detailed Embodiments
[0012] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present invention. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.
[0013] Figure 1 It is a flowchart of a dual-domain attack detection method for distributed resources facing the source-load side according to an embodiment of the present invention.
[0014] As Figure 1 shown, the dual-domain attack detection method for distributed resources facing the source-load side may include: S110, based on the historical modulation input signal time series and the historical output current time series of the inverter switch network in the distributed power grid system, perform a linear approximation on the inverter switch network to obtain the state space matrix of the inverter switch network; S120, add a random excitation signal to the modulation input signal of the inverter switch network, so that the modulation input signal with the added random excitation signal is input into the inverter switch network, and obtain the output current detection value of the inverter switch network; S130, based on the state space matrix of the inverter switch network, verify the output current detection value of the inverter switch network to determine whether the along-way transformation process of the inverter switch network for the random excitation signal is normal; S140, when the along-way transformation process of the inverter switch network for the random excitation signal is abnormal, determine that the inverter switch network is under attack.
[0015] It can be understood that the above operations can be performed on each inverter switch network in the distributed power grid system in the embodiments of the present invention. The distributed power grid system can be a photovoltaic power generation system, and each inverter switch network in the photovoltaic power generation system is detected to determine the attacked inverter switch network. The attack can be a dual-domain attack from the physical domain and / or the signal domain. Among them, the attack in the physical domain can be a direct physical attack on the inverter switch network, and the attack in the signal domain can be an information attack on the signal transmitted by the inverter switch network.
[0016] Exemplarily, a linear simulation method, such as the least squares method or a polynomial function, can be used to fit the historical modulation input signal time series and the historical output current time series of the inverter switch network in the distributed power grid system to obtain the corresponding linear function, and then extract the coefficients of each independent variable from the linear function. The coefficients of each independent variable are the state space matrix of the inverter switch network.
[0017] Exemplarily, a linear function with unknown independent variable coefficients can be constructed first, and then a neural network is used to learn the historical modulation input signal time series and the historical output current time series of the inverter switching network in the distributed power grid system, and output the predicted value of the independent variable coefficients. The predicted value output by the last training is used as the state space matrix of the inverter switching network.
[0018] It can be understood that the random excitation signal is equivalent to the watermark signal. By adding it to the modulation input signal of the inverter switching network, and using the state space matrix from input to output, it can be detected whether the current actually output by the inverter switching network includes the watermark signal after the normal along - path transformation process. If the detected value of the output current includes the watermark signal after the normal along - path transformation, it is determined that the along - path transformation process of the watermark is normal, and the inverter switching network has not been attacked, and the detected value of the output current is okay. If the watermark signal cannot be correctly included in the detected value of the output current, that is, the detected value of the output current includes the watermark signal after abnormal along - path transformation, it is determined that the inverter switching network has been attacked, and the detected value of the output current is false alarm data or data after being attacked.
[0019] As Figure 2 shown, the embodiment of the present invention can be applied to Figure 2 the attack detector in. The inverter controller includes an inverter switching network, an actuator, and a sensor. The actuator is used to receive the input signal, modulate the input signal, and then input it to the inverter switching network. The sensor is used to detect the output signal of the inverter switching network. In Figure 2 it, by connecting the input and output of the inverter controller to the attack detector respectively, the attack detector is integrated with the inverter controller. The attack detector receives the detected value of the grid current input by the inverter controller, and superimposes the random excitation signal onto the modulation input signal . Then, the modulation input signal with the added random excitation signal is transmitted by the actuator to the inverter switching network. The actuator keeps the confidentiality of the watermark signal and will not leak it to any other nodes, and its statistical data can be declared to other nodes within the control system.
[0020] Among them, since after the modulation input signal with the added random excitation signal is input into the inverter switching network, the along - path transformed , so the random excitation signal can also be called a watermark signal. By using a single-input single-output system containing Gaussian noise, that is, the state-space matrix of the inverter switching network, the dynamic characteristics of the watermark signal can be analyzed. Thus, by using the dynamic characteristics of the watermark signal, it can be verified whether the watermark signal in the detected output current satisfies the system dynamic law, so as to judge whether the output current of the inverter switching network has been tampered with.
[0021] According to the above embodiment, based on the historical modulation input signal time series and the historical output current time series of the inverter switching network in the photovoltaic system, a linear approximation is performed on the inverter switching network to obtain the state-space matrix of the inverter switching network. In this way, the model parameters for describing the inverter switching network from input to output can be obtained. A random excitation signal is added to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and the detected value of the output current of the inverter switching network is obtained; based on the state-space matrix of the inverter switching network, the detected value of the output current of the inverter switching network is verified to determine whether the process of the inverter switching network for the random excitation signal along the way is normal; in the case where the process of the inverter switching network for the random excitation signal along the way is abnormal, it is determined that the inverter switching network is attacked. In this way, by adding a random excitation signal to the input signal of the inverter switching network and then using the model parameters of the inverter switching network, it can be accurately detected whether the random excitation signal in the detected value of the output current of the inverter switching network is normal. If it is normal, it means that there is no problem in the process of the inverter switching network along the way, and further proves that the inverter switching network has not been attacked. Therefore, by adopting the technical solution of the present invention, it can be accurately detected whether each inverter switching network in the distributed power grid is attacked.
[0022] In one embodiment, based on the historical modulation input signal time series and the historical output current time series of the inverter switching network in the photovoltaic system, a linear approximation is performed on the inverter switching network to obtain the state-space matrix of the inverter switching network, including: taking the modulation input signal at the current time step and the output current at the current time step as independent variables, taking the unknown state-space matrix as the coefficient of the independent variable, and taking the output current at the next time step as the dependent variable, constructing a linear approximation function of the inverter switching network; based on the structure of the linear approximation function, determining that the input data of the deep neural network is the historical modulation input signal time series and the historical output current time series of the inverter switching network, and determining that the output data of the deep neural network is the predicted value of the coefficient of the independent variable; based on the input data and the output data, training the deep neural network until the output error of the deep neural network meets the preset error condition and then stopping the training, and taking the output result of the deep neural network when the training is stopped as the known value of the state-space matrix of the inverter switching network.
[0023] In one embodiment, the state space matrix includes a first matrix and a second matrix. The first matrix is used to characterize the state coupling relationship between the output current at the current time step and the output current at the next time step, and the second matrix is used to characterize the influence of the modulation input signal at the current time step on the output current at the next current time step.
[0024] Exemplarily, the linear approximation function can be expressed by the following formula: ; Where represents the output current of the inverter switch network at the current time step, represents the output current of the inverter switch network at the next time step, represents the modulation input signal of the inverter switch network at the current time step, is the first matrix, is the second matrix.
[0025] Exemplarily, for a deep neural network, its input data includes state variables and control variables. The state variables are the historical output current time series, such as , is the output current at time is the output current at time is the output current at time The time is the current time step. The control variables are the historical modulation input signal time series, such as , is the modulation input signal at time is the modulation input signal at time is the modulation input signal at time.
[0026] Exemplarily, for a deep neural network, its output data are the predicted values of the first matrix and the second matrix and .
[0027] Exemplarily, considering that the deep neural network needs to process time series data, in this example, a recurrent neural network (RNN) architecture is selected, which can learn the time series features of the input data. For example, the deep neural network uses a stack of 2 to 3 RNN / LSTM / GRU units. The hidden state of the RNN can be calculated based on the input data at the current time step and the hidden state at the previous time step, and is passed to the output data at the next time step. The update of its hidden state can use a simple linear transformation and activation function, or a more complex gating mechanism. Also, at each time step, the RNN can use the same weights and biases for calculation. In this way, the number of model parameters can be reduced and the training efficiency can be improved. Finally, a fully connected layer is used to map the output data of the RNN layer into the state space to obtain the predicted values of the first matrix and the second matrix and , which is used as the final state space matrix
[0028] Exemplarily, for the training parameters of the deep neural network, they can be as follows The training parameters are , where is the number of samples, is the time step (sliding window size), is the feature dimension at each time step (the sum of the state and control signal dimensions). The mean squared error is defined to measure the error between the predicted matrix and the true matrix ; where the total number of training epochs is set to 100, and a learning rate scheduler is used to dynamically adjust the learning rate to improve the convergence efficiency
[0029] Exemplarily, for the training process and validation process of the deep neural network. During each round of training, the training data is divided into several batches for training. The sequence is input into the deep neural network to obtain the predicted values and . Calculate the loss between the predicted value and the true value, calculate the gradient through the backpropagation algorithm, and use the optimizer to update the model parameters. After each round of training, monitor the loss on the validation set to avoid overfitting. Finally, an accurate predicted value of the system model parameters and is obtained, and this predicted value is used as the state space matrix of the inverter switching network
[0030] According to the above embodiments, by constructing a corresponding linear function for the inverter switching network, and then based on this linear function, determining the historical input and output data of the inverter switching network as the input data of the neural network, and determining the unknown independent variable coefficients in this linear function as the output data of the neural network. Furthermore, through the training of the neural network, after reaching the set accuracy, the predicted value finally output by the network is used as the state space matrix of the inverter switching network. This state space matrix can describe the dynamic characteristics or model parameters of the single-input and single-output system of the inverter switching network.
[0031] In one embodiment, a random excitation signal is added to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and the detected value of the output current of the inverter switching network is obtained, including: based on the time-varying control law mapping from the output to the input of the inverter switching network, mapping the detected value of the output current at the current time step of the inverter switching network to the input to obtain the modulation input signal at the current time step; applying a random excitation signal to the modulation input signal at the current time step; inputting the modulation input signal at the current time step with the applied random excitation signal into the inverter switching network to obtain the detected value of the output current at the next time step of the inverter switching network.
[0032] Exemplarily, the time-varying control law mapping from the output to the input of the inverter switching network can be determined in advance.
[0033] Exemplarily, for the inverter switching network, it can be considered as a single-input and single-output system with system noise and measurement noise of a sensor for detecting the output result. This system can be defined by the following formula: ; ; Wherein, is the output current of the system at the current time step, is the output current of the system at the next time step, is the modulation input signal of the system at the current time step, is the theoretical value of the output current at the next time step obtained by the sensor of the system measuring the output current at the next time step, that is, the predicted value calculated theoretically through this formula, represents the system noise at the next time step, represents the measurement noise at the next time step, and can also be considered as sensor noise.
[0034] Wherein, both C and D can take the value of 1.
[0035] Wherein, satisfies the Gaussian distribution as: , is the system noise variance.
[0036] Among them, The one that satisfies the Gaussian distribution is: , is the measurement noise variance, which can also be called the sensor noise variance.
[0037] It can be understood that if the system is attacked, then the output current detection value detected by the sensor may not necessarily be the above-determined theoretical value of the output current . Therefore, by applying the above excitation, to judge whether the data detected by the sensor is the theoretical value . If it is, it is determined that the system has not been attacked. If not, it is determined that the system has been attacked.
[0038] Exemplarily, using the time-varying control law of the inverter switch network , for the sensor detection value at the current time step received by the execution detector , it can also be , calculated to obtain . Add the corresponding excitation signal to this data, and the input data of the inverter switch network, that is, the modulated input signal at the current time step after applying the random excitation signal is: ; Among them, is the random excitation signal, which satisfies the Gaussian distribution, specifically: . It can be regarded as the private watermark superimposed on the actuator node in the system. The variance of this watermark signal is .
[0039] Exemplarily, the output current detection value at the next time step of the inverter switch network is .
[0040] According to the above embodiments, by adding a random excitation signal to the modulated input signal of the inverter switch network, the modulated input signal added with the random excitation signal is input into the inverter switch network, and the output current detection value of the inverter switch network is obtained.
[0041] In one embodiment, verifying the detected output current value of the inverter switching network based on the state - space matrix of the inverter switching network includes: linearly calculating, based on the state - space matrix of the inverter switching network, the detected output current value at the current time step and the modulation input signal at the current time step to obtain the theoretical value of the un - excited output current at the next time step of the inverter switching network; linearly calculating, based on the state - space matrix of the inverter switching network, the detected output current value at the current time step and the modulation input signal at the current time step with a randomly applied excitation signal to obtain the theoretical value of the excited output current at the next time step of the inverter switching network; integrating the difference between the detected output current value at the next time step and the theoretical value of the un - excited output current at the next time step over a time scale to obtain a first integration result; integrating the difference between the detected output current value at the next time step and the theoretical value of the excited output current at the next time step over a time scale to obtain a second integration result; and verifying the detected output current value of the inverter switching network based on the first integration result and the second integration result.
[0042] Exemplarily, use and to represent the theoretical value of the historical output current of the inverter switching network and the detected value of the historical output current of the inverter switching network by the sensor respectively, then the closed - loop evolution of the system is: ; 。
[0043] Exemplarily, assume that the number of inverters controlling multiple photovoltaic arrays in a photovoltaic system is M, and the th inverter controller calculates the control input for the th inverter.
[0044] Exemplarily, the theoretical value of the un - excited output current at the next time step of the th inverter switching network can be: , where C can take the value of 1, and are the detected output current values at the current time step, is the modulation input signal at the current time step.
[0045] Exemplarily, the theoretical value of the excited output current at the next time step of the inverter switching network can be: , where C can take the value of 1, is the random excitation signal at the current time step.
[0046] Exemplarily, the first integration result is: .
[0047] Exemplarily, the second integration result is: .
[0048] Wherein, is the detected value of the output current of the th inverter switch network at the next time step, is the detected value of the output current of the th inverter switch network at the current time step, and the detected value here refers to the value actually detected by the sensor. is the modulation input signal at the current time step, is the th random excitation signal superimposed on the modulation input signal corresponding to the inverter switch network.
[0049] Exemplarily, through the closed-loop evolution of the system, relevant verification conditions for the first integration result and the second integration result can be obtained. Through these verification conditions, the first integration result and the second integration result are verified to determine whether the detected value of the output current of the inverter switch network is normal. If it is normal, it means that the inverter switch network has not been attacked. If it is not normal, it means that the inverter switch network has not been attacked.
[0050] According to the above embodiment, through the above integration process, the integration result can be used to verify whether the detected value of the output current of the inverter switch network is normal.
[0051] In one embodiment, based on the first integration result and the second integration result, verifying the detected value of the output current of the inverter switch network includes: determining whether the first integration result meets the first condition determined by the Gaussian distribution condition corresponding to the random excitation signal, the Gaussian distribution condition of the system noise corresponding to the inverter switch network, and the Gaussian distribution condition of the detection noise; determining whether the second integration result meets the second condition determined by the Gaussian distribution condition of the system noise corresponding to the inverter switch network and the Gaussian distribution condition of the detection noise; determining whether the difference between the first integration result and the second integration result meets the third condition determined by the Gaussian distribution condition corresponding to the random excitation signal; and determining that the process of the inverter switch network for the random excitation signal along the way is abnormal when the first integration result does not meet the first condition and / or the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result does not meet the third condition.
[0052] In one embodiment, it further includes: when the first integration result meets the first condition, the second integration result meets the second condition, and the difference between the first integration result and the second integration result meets the third condition, determining that the process of the inverter switch network for the random excitation signal along the way is normal; when the process of the inverter switch network for the random excitation signal along the way is normal, determining that the inverter switch network is not under attack.
[0053] In one embodiment, it further includes: when the first integration result does not meet the first condition, the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result meets the third condition, determining that the process of the inverter switch network for the random excitation signal along the way is normal and determining that the detector for detecting the output current of the inverter switch network is in an abnormal state.
[0054] Continuing with the above example, in combination with the closed-loop evolution process of the system, the equivalent value of the above first integration result (Test 1 formula) can be obtained: 。
[0055] If C and D take the value of 1, the following formula can be obtained: ; Continuing with the above example, in combination with the closed-loop evolution process of the system, the equivalent value of the above second integration result (Test 2 formula) can be obtained: 。
[0056] If C and D take the value of 1, the following formula can be obtained: 。
[0057] Thus, the first condition can be: the first integration result is equal to the first constant determined by the variance of the random excitation signal, the system noise variance corresponding to the inverter switch network, and the detection noise variance, and the first constant is ,where is the first matrix in the foregoing example, is the second matrix in the foregoing example.
[0058] The second condition can be: the second integration result is equal to the second constant determined by the system noise variance corresponding to the inverter switch network and the detection noise variance, and the second constant is ,where is the first matrix in the foregoing example.
[0059] In practical applications, when the system is normal, the statistical values of the data on the left side of the above test formula should be equal to the variance relationship on the right side of the equation, that is, satisfy a constant value. Therefore, passing these tests is a necessary condition for the measured values not to be tampered with. Only the values on the left side of the above equation need to be calculated, and it is judged whether the values are equivalent to the corresponding empirical variance estimates, and the computational complexity is very low.
[0060] To overcome the problem of the prior knowledge of the noise variance, subtract the left sides of Test 1 and Test 2, and the system noise variances on the right sides of Test 1 and Test 2 can be cancelled out. and the sensor noise variance , so that the statistical values of the data on the left side of the new auxiliary test are independent of the noise.
[0061] Among them, , the following formula is obtained: ; Since is independent of and and has zero mean property, the above formula can be simplified to: ; Therefore, thus, the auxiliary test is: .
[0062] Since the auxiliary test does not need to know the sensor noise, even if the sensor noise level changes, the auxiliary test is immune to it, which can enhance the robustness of the above attack detection method. The auxiliary test can also detect irregularities inside the system, such as changes in the sensor noise variance or system model parameters. When the detected value of the output current cannot pass one or more of Tests 1 and 2 but passes the auxiliary test, this indicates that the inverter switching network has not been attacked, but only the sensor or the system noise variance has changed.
[0063] Now assume that for some perturbations , and the value on the left side of Test 2 is . Then, the value on the left side of Test 1 must be equal to . After subtracting the two tests, the value is still the value on the left side of the auxiliary test.
[0064] According to the above implementation manner, when the measured values all pass Tests 1, 2 and the auxiliary test, it indicates that the measured values are real at this time; when the measured values do not pass the auxiliary test and as long as one of Tests 1 and 2 fails, it indicates that the measured values are manipulated by the attacker; when the measured values pass the auxiliary test but do not pass Tests 1 and 2, it indicates that the system may not have suffered a malicious attack at this time, and the alarms of Tests 1 and 2 are caused by the change of the noise variance due to the sensor malfunction. Therefore, this method can also be applied to the detection of sensor faults.
[0065] Through the embodiments of the present invention, a detection and positioning method for a robust distributed resource disturbance source can be realized, which reduces the dependence on model accuracy and its sensitivity to system and sensor noise, and can detect network attacks on distributed resources against inverters.
[0066] Figure 3 It is a structural block diagram of a dual-domain attack detection device for distributed resources on the source and load sides according to an embodiment of the present invention.
[0067] As Figure 3 shown, the dual-domain attack detection device for distributed resources on the source and load sides includes: A state space matrix determination module 310, configured to perform linear approximation on the inverter switch network based on the historical modulation input signal time series and the historical output current time series of the inverter switch network in the photovoltaic system, so as to obtain the state space matrix of the inverter switch network; An excitation addition module 320, configured to add a random excitation signal to the modulation input signal of the inverter switch network, so that the modulation input signal with the added random excitation signal is input into the inverter switch network, and an output current detection value of the inverter switch network is obtained; An output detection module 330, configured to verify the output current detection value of the inverter switch network based on the state space matrix of the inverter switch network, so as to determine whether the along-way transformation process of the inverter switch network for the random excitation signal is normal; An attack determination module 340, configured to determine that the inverter switch network is attacked when the along-way transformation process of the inverter switch network for the random excitation signal is abnormal.
[0068] In an implementation manner, the state space matrix determination module 310 includes: A function construction unit, configured to construct a linear approximation function of the inverter switch network with the modulation input signal at the current time step and the output current at the current time step as independent variables, the unknown state space matrix as the independent variable coefficient, and the output current at the next time step as the dependent variable; An input and output determination unit, configured to determine that the input data of the deep neural network is the historical modulation input signal time series and the historical output current time series of the inverter switch network based on the structure of the linear approximation function, and determine that the output data is the predicted value of the independent variable coefficient; A model training unit for training the deep neural network based on the input data and the output data until the output error of the deep neural network meets a preset error condition, and then stopping the training, and using the output result of the deep neural network at the time of stopping training as the known value of the state space matrix of the inverter switching network.
[0069] In one embodiment, the state space matrix includes a first matrix and a second matrix. The first matrix is used to represent the state coupling relationship between the output current at the current time step and the output current at the next time step, and the second matrix is used to represent the influence of the modulation input signal at the current time step on the output current at the next time step.
[0070] In one embodiment, the excitation addition module 320 includes: A mapping unit for mapping the detected value of the output current at the current time step of the inverter switching network to the input based on the time-varying control law that maps from the output to the input of the inverter switching network, so as to obtain the modulation input signal at the current time step; A signal application unit for applying the random excitation signal to the modulation input signal at the current time step; A signal input unit for inputting the modulation input signal at the current time step to which the random excitation signal has been applied into the inverter switching network to obtain the detected value of the output current at the next time step of the inverter switching network.
[0071] In one embodiment, the output detection module 330 includes: A first linear calculation unit for performing a linear calculation on the detected value of the output current at the current time step and the modulation input signal at the current time step based on the state space matrix of the inverter switching network to obtain the theoretical value of the unexcited output current at the next time step of the inverter switching network; A second linear calculation unit for performing a linear calculation on the detected value of the output current at the current time step and the modulation input signal at the current time step after applying the random excitation signal based on the state space matrix of the inverter switching network to obtain the theoretical value of the excited output current at the next time step of the inverter switching network; A first integration unit for integrating the difference between the detected value of the output current at the next time step and the theoretical value of the unexcited output current at the next time step on the time scale to obtain a first integration result; A second integration unit for integrating the difference between the detected value of the output current at the next time step and the theoretical value of the excited output current at the next time step on the time scale to obtain a second integration result; A verification unit for verifying the detected value of the output current of the inverter switching network based on the first integration result and the second integration result.
[0072] In one embodiment, the verification unit is specifically configured to: Determine whether the first integration result meets a first condition determined by the Gaussian distribution condition corresponding to the random excitation signal, the Gaussian distribution condition of the system noise corresponding to the inverter switching network, and the Gaussian distribution condition of the detection noise; Determine whether the second integration result meets a second condition determined by the Gaussian distribution condition of the system noise corresponding to the inverter switching network and the Gaussian distribution condition of the detection noise; Determine whether the difference between the first integration result and the second integration result meets a third condition determined by the Gaussian distribution condition corresponding to the random excitation signal; In the case where the first integration result does not meet the first condition and / or the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result does not meet the third condition, determine that the process of the inverter switching network for the random excitation signal along the way is abnormal.
[0073] In one embodiment, the above verification unit is further configured to: In the case where the first integration result meets the first condition, the second integration result meets the second condition, and the difference between the first integration result and the second integration result meets the third condition, determine that the process of the inverter switching network for the random excitation signal along the way is normal; In the case where the process of the inverter switching network for the random excitation signal along the way is normal, determine that the inverter switching network is not under attack.
[0074] In one embodiment, the above verification unit is further configured to: In the case where the first integration result does not meet the first condition, the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result meets the third condition, determine that the process of the inverter switching network for the random excitation signal along the way is normal, and determine that the detector for detecting the output current of the inverter switching network is in an abnormal state.
[0075] For the specific functions and examples of the modules and sub-modules of the system according to the embodiments of the present invention, reference may be made to the relevant descriptions of the corresponding steps in the above method embodiments, which will not be elaborated herein.
[0076] In the technical solution of the present invention, the acquisition, storage, and application of the user's personal information comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0077] According to an embodiment of the present invention, the present invention also provides a system and a readable storage medium.
[0078] Figure 4 FIG. shows a schematic block diagram of an exemplary electronic device 800 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0079] As Figure 4 shown, the electronic device 800 includes a computing unit 801 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0080] A plurality of components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0081] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 executes the various methods and processes described above, such as the dual-domain attack detection method for source-load-side distributed resources. For example, in some embodiments, the dual-domain attack detection method for source-load-side distributed resources can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the dual-domain attack detection method for source-load-side distributed resources described above can be executed. Alternatively, in other embodiments, the computing unit 801 can be configured to execute the dual-domain attack detection method for source-load-side distributed resources in any other suitable manner (e.g., by means of firmware).
[0082] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0083] The program code for implementing the methods of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0084] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0085] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0086] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0087] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0088] It should be understood that various forms of the processes shown above may be used, steps may be reordered, added, or deleted. For example, the steps recited in the present invention may be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present invention can be achieved, and no limitations are imposed herein.
[0089] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A dual-domain attack detection method for distributed resources on the source and load sides, characterized in that, Including: Based on the historical modulation input signal time sequence and the historical output current time sequence of the inverter switching network in the distributed power grid system, performing linear approximation on the inverter switching network to obtain the state space matrix of the inverter switching network; Adding a random excitation signal to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and obtaining the output current detection value of the inverter switching network; Based on the state space matrix of the inverter switching network, verifying the output current detection value of the inverter switching network to determine whether the along - process transformation process of the inverter switching network for the random excitation signal is normal; When the along - process transformation process of the inverter switching network for the random excitation signal is abnormal, determining that the inverter switching network is under attack.
2. The method according to claim 1, wherein The performing linear approximation on the inverter switching network based on the historical modulation input signal time sequence and the historical output current time sequence of the inverter switching network in the photovoltaic system to obtain the state space matrix of the inverter switching network includes: Constructing a linear approximation function of the inverter switching network with the modulation input signal at the current time step and the output current at the current time step as independent variables, the unknown state space matrix as the coefficient of the independent variable, and the output current at the next time step as the dependent variable; Based on the structure of the linear approximation function, determining that the input data of the deep neural network is the historical modulation input signal time sequence and the historical output current time sequence of the inverter switching network, and determining that the output data of the deep neural network is the predicted value of the coefficient of the independent variable; Based on the input data and the output data, training the deep neural network until the output error of the deep neural network meets the preset error condition and then stopping the training, and using the output result of the deep neural network when the training is stopped as the known value of the state space matrix of the inverter switching network.
3. The method according to claim 2, characterized in that, The state space matrix includes a first matrix and a second matrix. The first matrix is used to characterize the state coupling relationship between the output current at the current time step and the output current at the next time step, and the second matrix is used to characterize the influence of the modulation input signal at the current time step on the output current at the next time step.
4. The method according to claim 1, characterized in that The adding a random excitation signal to the modulation input signal of the inverter switching network, so that the modulation input signal with the added random excitation signal is input into the inverter switching network, and obtaining the output current detection value of the inverter switching network includes: Based on the time - varying control law of the inverter switching network from output to input, mapping the output current detection value at the current time step of the inverter switching network to the input to obtain the modulation input signal at the current time step; Applying the random excitation signal to the modulation input signal at the current time step; Inputting the modulation input signal at the current time step with the applied random excitation signal into the inverter switching network to obtain the output current detection value at the next time step of the inverter switching network.
5. The method according to claim 1, characterized in that, Verifying the detected output current value of the inverter switching network based on the state - space matrix of the inverter switching network includes: Based on the state - space matrix of the inverter switching network, performing a linear calculation on the detected output current value at the current time step and the modulation input signal at the current time step to obtain the theoretical value of the un - excited output current at the next time step of the inverter switching network; Based on the state - space matrix of the inverter switching network, performing a linear calculation on the detected output current value at the current time step and the modulation input signal at the current time step with a randomly applied excitation signal to obtain the theoretical value of the excited output current at the next time step of the inverter switching network; Integrating the difference between the detected output current value at the next time step and the theoretical value of the un - excited output current at the next time step over the time scale to obtain a first integration result; Integrating the difference between the detected output current value at the next time step and the theoretical value of the excited output current at the next time step over the time scale to obtain a second integration result; Verifying the detected output current value of the inverter switching network based on the first integration result and the second integration result.
6. The method according to claim 5, characterized in that, The verification of the detected output current value of the inverter switching network based on the first integration result and the second integration result includes: Judging whether the first integration result meets the first condition determined by the Gaussian distribution condition corresponding to the random excitation signal, the Gaussian distribution condition of the system noise corresponding to the inverter switching network, and the Gaussian distribution condition of the detection noise; Judging whether the second integration result meets the second condition determined by the Gaussian distribution condition of the system noise corresponding to the inverter switching network and the Gaussian distribution condition of the detection noise; Judging whether the difference between the first integration result and the second integration result meets the third condition determined by the Gaussian distribution condition corresponding to the random excitation signal; When the first integration result does not meet the first condition and / or the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result does not meet the third condition, determining that the process of the inverter switching network for the random excitation signal along the way is abnormal.
7. The method according to claim 6, wherein It also includes: When the first integration result meets the first condition, the second integration result meets the second condition, and the difference between the first integration result and the second integration result meets the third condition, determining that the process of the inverter switching network for the random excitation signal along the way is normal; When the process of the inverter switching network for the random excitation signal along the way is normal, determining that the inverter switching network is not under attack.
8. The method according to claim 6, wherein It also includes: In the case where the first integration result does not meet the first condition, the second integration result does not meet the second condition, and the difference between the first integration result and the second integration result meets the third condition, it is determined that the process of the inverter switch network for the random excitation signal along the way is normal, and it is determined that the detector for detecting the output current of the inverter switch network is in an abnormal state.
9. A dual-domain attack detection device for distributed resources on the source-load side, characterized in that, Comprising: A state space matrix determination module, configured to perform linear approximation on the inverter switch network based on the historical modulation input signal timing sequence and the historical output current timing sequence of the inverter switch network in the photovoltaic system, so as to obtain the state space matrix of the inverter switch network; An excitation addition module, configured to add a random excitation signal to the modulation input signal of the inverter switch network, so that the modulation input signal with the added random excitation signal is input into the inverter switch network, and an output current detection value of the inverter switch network is obtained; An output detection module, configured to verify the output current detection value of the inverter switch network based on the state space matrix of the inverter switch network, so as to determine whether the process of the inverter switch network for the random excitation signal along the way is normal; An attack determination module, configured to determine that the inverter switch network is attacked in the case where the process of the inverter switch network for the random excitation signal along the way is abnormal.
10. A dual-domain attack detection system for distributed resources on the source-load side, characterized in that, Comprising: At least one processor, and a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the processor, and the processor is configured to obtain the instructions from the memory and execute the instructions, so that the at least one processor can execute the method according to any one of claims 1-8.
Citation Information
Patent Citations
Method for improving measurement accuracy of power mutual inductor
CN102087311A
Method for identifying linear system parameters by adopting linear kernel of support vector machine
CN106484986A
Attack detection method for distributed power supply power electronic device and related device
CN117806275A
Distributed photovoltaic terminal hostile attack detection method based on double-domain characteristics
CN118199958A
Method for detecting network attack in power information physical system based on dynamic watermark
CN118764298A