Virtual power plant network security pollution identification method and device, electronic equipment and storage medium
By constructing an operational model for VPP systems to identify network security contamination using deep neural networks, the method addresses the challenge of timely and accurate attack detection, restoring system integrity and improving service capability.
Patent Information
- Application Number
- CN202510779715.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-12
AI Technical Summary
The existing technology is difficult to restore the real operating situation of each part of the system in a timely and accurate manner when a virtual power plant is attacked by a network, which makes it difficult to guarantee information integrity, which in turn affects the ability of VPP to provide services.
The operation model of the target virtual power plant is constructed, and the deviation between measurement parameters is minimized as a constraint. The deep neural network training model is used to determine the pollution identification label through measurement parameters, and a training sample set is constructed to optimize the network security pollution identification model.
It realizes the timely and accurate recovery of the real operating situation of each part of the system under attack, ensures information integrity, and improves the ability of VPP to provide services.
Smart Images

Figure CN120321034A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of virtual power plants, and in particular, to a method, device, electronic device, and storage medium for identifying network security pollution in a virtual power plant. Background Art
[0002] With the emergence of virtual power plant (VPP) technology, the ability of the power grid to integrate resources has been significantly improved, and it has also become an important future development direction of the power system. However, due to the characteristics of excessive dependence on information and communication systems in virtual power plant technology, in the actual operation of virtual power plant systems, the vulnerability at each level such as communication, data, and operation and maintenance has increased, and the security has also decreased. The development of these network security threats may lead to huge losses.
[0003] Currently, some data-driven methods have been able to identify whether the operation situation has been polluted based on the operation data of virtual power plants, but it is generally difficult to accurately and timely restore the identification of the true operation situation of each part of the system sampled due to attacks under the action of attacks, which makes it difficult to guarantee the integrity of information, and further causes the decline of the service-providing ability of VPP. Summary of the Invention
[0004] In view of this, the present invention provides a method, device, electronic device, and storage medium for identifying network security pollution in a virtual power plant, which solves the technical problem that it is difficult to accurately and timely restore the identification of the true operation situation of each part of the system sampled due to attacks under the action of attacks, which makes it difficult to guarantee the integrity of information, and further causes the decline of the service-providing ability of VPP.
[0005] The first aspect of the present invention provides a method for identifying network security pollution in a virtual power plant, including:
[0006] Minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by the network, and construct an operation model of the target virtual power plant with the operation steady state of the target virtual power plant as a constraint;
[0007] Input multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine pollution identification labels corresponding to the multiple measurement parameter samples respectively according to the deviation between the measurement parameters before and after being attacked by the network output by the operation model;
[0008] Construct a training sample set according to the multiple measurement parameter samples and the pollution identification labels corresponding to the multiple measurement parameter samples respectively;
[0009] Train a deep neural network based on the training sample set to obtain a trained network security pollution identification model for the target virtual power plant; wherein, the trained network security pollution identification model for the target virtual power plant is used to output a pollution discrimination label corresponding to the input real-time measurement parameters according to the input real-time measurement parameters.
[0010] Preferably, the operation model of the target virtual power plant includes an objective function;
[0011] Wherein, the objective function is:
[0012]
[0013] In the formula, is the measurement parameter of the attack area and is the state variable and the non-linear function mapping relationship between the measurement parameter and
[0014] Preferably, the operation model of the target virtual power plant includes constraint conditions; wherein, the constraint conditions include the active power balance constraint of node injection, the reactive power balance constraint of node injection, the active power balance constraint of line flow, the reactive power balance constraint of line flow, the bus node voltage amplitude constraint, the line power flow caused by the phase angle change after the attack, the maximum output power limit constraint of the active power in the line, the maximum output power limit constraint of the reactive power in the line, the overload relationship constraint of the apparent power on the line, and the constant constraint of the boundary state value before and after the attack.
[0015] Preferably, the step of inputting multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant and determining pollution discrimination labels corresponding to the multiple measurement parameter samples according to the deviation between the measurement parameters before and after being attacked by the network output by the operation model includes:
[0016] For each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model;
[0017] Perform a threshold comparison according to the deviation to determine the pollution discrimination label of the measurement parameter sample; the pollution discrimination label includes being attacked and polluted and not being attacked and polluted.
[0018] Preferably, the step of training a deep neural network based on the training sample set to obtain a trained network security pollution identification model for the target virtual power plant includes:
[0019] Divide the training sample set into multiple training sample subsets;
[0020] Use multiple deep neural networks to train multiple said training sample subsets respectively, and obtain the prediction probabilities of each said deep neural network for multiple said training sample sets;
[0021] Select the training sample subsets whose prediction probabilities are greater than a preset probability threshold;
[0022] Use the selected training sample subsets to train a heterogeneous integrated classifier to obtain the trained network security pollution identification model of the target virtual power plant.
[0023] Preferably, this method further includes:
[0024] Use a test sample set to test the trained network security pollution identification model of the target virtual power plant, and optimize the network parameters of the trained network security pollution identification model of the target virtual power plant using the test results to obtain an optimized network security pollution identification model of the target virtual power plant; wherein, the test sample set includes measurement parameter test samples and pollution discrimination labels respectively corresponding to multiple said measurement parameter test samples.
[0025] Preferably, the deep neural network is a CNN deep learning neural network.
[0026] In a second aspect, an embodiment of the present application further provides a virtual power plant network security pollution identification device, including:
[0027] A model construction module, configured to minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by a network, and use the operating steady state of the target virtual power plant as a constraint to construct an operating model of the target virtual power plant;
[0028] A label determination module, configured to input multiple measurement parameter samples of the target virtual power plant into the operating model of the target virtual power plant, and determine the pollution discrimination labels respectively corresponding to multiple said measurement parameter samples according to the deviation between the measurement parameters before and after being attacked by a network output by the operating model;
[0029] A sample construction module, configured to construct a training sample set according to multiple said measurement parameter samples and the pollution discrimination labels respectively corresponding to multiple said measurement parameter samples;
[0030] A pollution identification module is used to train a deep neural network based on the training sample set to obtain a trained network security pollution identification model for the target virtual power plant. Among them, the trained network security pollution identification model for the target virtual power plant is used to output a pollution discrimination label corresponding to the input real-time measurement parameters according to the input real-time measurement parameters.
[0031] In a third aspect, an embodiment of the present application further provides an electronic device, which includes a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the virtual power plant network security pollution identification method as described in the first aspect.
[0032] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed, the steps of the virtual power plant network security pollution identification method as described in the first aspect are implemented.
[0033] From the above technical solutions, it can be seen that the present invention has the following advantages:
[0034] The present invention constructs an operation model of the target virtual power plant by minimizing the deviation between the measurement parameters before and after the target virtual power plant is attacked by a network, so as to determine the deviation between the measurement parameters before and after the target virtual power plant is attacked by a network. And the pollution discrimination labels of multiple measurement parameter samples are determined through the operation model of the target virtual power plant, and a deep neural network is trained by using the multiple measurement parameter samples and pollution discrimination labels to obtain a network security pollution identification model for the target virtual power plant, so that it is possible to identify whether pollution occurs by inputting real-time measurement parameters, so as to realize timely and accurate restoration of the discrimination of the true operation state of each part of the system sampled due to the attack under the action of the attack, and ensure the integrity of information, and improve the service ability of the VPP. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is an application environment of a virtual power plant network security pollution identification method provided by an embodiment of the present invention;
[0036] Figure 2 It is a flowchart of a virtual power plant network security pollution identification method provided by an embodiment of the present invention;
[0037] Figure 3 It is a schematic structural diagram of a virtual power plant network security pollution identification device provided by an embodiment of the present invention;
[0038] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0040] The virtual power plant network security pollution identification method provided by the embodiments of the present application can be applied to, for example Figure 1 the application environment shown in the figure. Among them, each node of the virtual power plant communicates with the server 102 through a network. The data storage system can store the data that the server 102 needs to process. The data storage system can be integrated on the server 102, or placed in the cloud or other network servers. The server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0041] As Figure 2 shown, the embodiments of the present application provide a virtual power plant network security pollution identification method. Taking the method applied to Figure 1 the server 102 in the figure as an example, it includes the following steps S1 to S4. Among them:
[0042] Step S1: Minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by the network, and construct an operation model of the target virtual power plant with the operation steady state of the target virtual power plant as a constraint.
[0043] It can be understood that the measurement parameters of the target virtual power plant before and after being attacked by the network are different, so there is a deviation value. The embodiments of the present application consider constructing an objective function of the operation model of the target virtual power plant by minimizing the deviation between the measurement parameters of the target virtual power plant before and after being attacked by the network. The objective function is:
[0044]
[0045] In the formula, is the measurement parameter of the attack area is the state variable and the nonlinear function mapping relationship between the measurement parameters.
[0046] Among them, the measurement parameters include, but are not limited to, the active / reactive power injection measured by SCADA (Supervisory Control and Data Acquisition), the active / reactive power, and the voltage phase angle, voltage amplitude, real part and imaginary part of the current vector measured by PMU (Phasor Measurement Unit).
[0047] State variable , is the phase angle of the system voltage after the attack is implemented, is the system voltage amplitude after the attack is implemented.
[0048] Among them, for the function mapping relationship is determined by means of fitting and other methods through the historical measurement sample parameters before and after the target virtual power plant is attacked by the network.
[0049] In addition, the embodiments of the present application consider the operation steady state of the target virtual power plant as a constraint. Therefore, the constraint conditions of the operation model of the target virtual power plant include the active power balance constraint of node injection, the reactive power balance constraint of node injection, the active power balance constraint of line flow, the reactive power balance constraint of line flow, the bus node voltage amplitude constraint, the line power flow caused by the phase angle change after the attack, the maximum output power limit constraint of the active power in the line, the maximum output power limit constraint of the reactive power in the line, the overload relationship constraint of the apparent power on the line, and the constant constraint of the boundary state value before and after the attack.
[0050] Specifically, the active power balance constraint of node injection is:[[]]
[0051]
[0052] In the formula, both i and j are node indexes, ij represents the bus index, is the active power injected by node i, , are the voltage amplitudes injected by nodes i and j respectively, is the phase angle difference of the voltage of line ij after the attack is implemented, is the set of the part of the local network concentration connected to the bus, are the susceptance and conductance of line ij respectively, is the change amount of the node active power injection caused by the attack vector injected into the system.
[0053] The reactive power balance constraint of node injection is:[[]]
[0054]
[0055] In the formula, is the reactive power injected into node i, is the change in the reactive power injection of the node caused by the injection of the attack vector into the system.
[0056] The active power balance constraint of the line flow and the reactive power balance constraint of the line flow are respectively:
[0057]
[0058]
[0059] In the formula, and are respectively the active power and reactive power flowing through line ij, , are respectively the changes in the active power and reactive power of line ij, , respectively represent the shunt susceptance and shunt conductance to the ground connected to node i, , are respectively the mutual susceptance and mutual conductance of the line connected between nodes i and j.
[0060] The bus node voltage magnitude constraint is:
[0061]
[0062] In the formula, is the voltage magnitude of node i, , are respectively the lower limit and upper limit of the voltage magnitude of node i, is the change in the voltage magnitude of the node caused by the injection of the attack vector into the system.
[0063] The line power flow caused by the post-attack phase angle change is:
[0064]
[0065] In the formula, is the voltage phase angle of node i, is the change in the voltage phase angle of the node caused by the injection of the attack vector into the system, is the voltage phase angle of the node caused by the injection of the attack vector into the system.
[0066] The line power flow constraint caused by the post-attack phase angle change is:
[0067]
[0068]
[0069] In the formula, , are the real and imaginary parts of the current vector of line ij, respectively, , are the change amounts of the real and imaginary parts of the current vector of line ij, respectively.
[0070] The maximum output power limit constraint of active power in the line and the maximum output power limit constraint of reactive power in the line are respectively:
[0071]
[0072] In the formula, , are the active and reactive powers of the system, respectively, , are the minimum and maximum values of the active power of the generator, respectively. G is the generator, that is, it is stipulated that the overall active power of the system should be within the technical output range of the generator; , are the change amounts of the active and reactive powers of the system, respectively, , are the minimum and maximum values of the active and reactive powers of the system, respectively.
[0073] The overload relationship constraint of the apparent power on the line is:
[0074]
[0075] In the formula, is the maximum apparent power that the line can withstand, , are the apparent active power and apparent reactive power of the line, respectively, , are the change amounts of the apparent active power and apparent reactive power of the line, respectively.
[0076] The constraint of the constant boundary state value before and after the attack is:
[0077]
[0078] In the formula, is the state variable of the th boundary, is the initial value of the state variable, e is the boundary index, is the boundary set.
[0079] It can be understood that such contaminated and damaged state data cannot be detected in a timely manner by the current single VPP measurement system, and the consequences caused thereby are very serious. This is because when the above-mentioned concerned state variables, namely voltage amplitude and phase angle, are contaminated, the information received by the VPP may undergo various changes. Such changes will interfere with subsequent various operations, making the VPP, as an energy management system, unable to complete its tasks effectively and in a timely manner. It may even make some incorrect allocation and scheduling judgments, and may ultimately lead to the collapse of the entire system in the most serious cases. Therefore, the embodiment of the present application can achieve the purpose of secretly injecting the designed attack vector into the VPP system through the operation model of the target virtual power plant, so as to achieve the purpose of attacking the voltage amplitude and phase angle in the concerned attack area.
[0080] Step S2: Input multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine the contamination discrimination labels corresponding to the multiple measurement parameter samples according to the deviation between the measurement parameters before and after being attacked by the network corresponding to each measurement parameter sample output by the operation model.
[0081] It can be understood that the operation model of the target virtual power plant inputs each state variable, determines the deviation through each state variable and the state variable after the attack, and based on whether the deviation fluctuates within the specified range, a classification discrimination index for whether the system is under a network attack can be output, that is, an output is a judgment on whether the current system is contaminated.
[0082] Specifically, step S2 specifically includes:
[0083] Step S201: For each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model.
[0084] Step S202: Compare the deviation with a threshold to determine the contamination discrimination label of the measurement parameter sample; the contamination discrimination label includes being attacked and contaminated and not being attacked and contaminated.
[0085] Among them, by setting a deviation threshold, when the deviation is greater than the deviation threshold, it is determined that the contamination discrimination label of the measurement parameter sample is being attacked and contaminated, and when the deviation is not greater than the deviation threshold, it is determined that the contamination discrimination label of the measurement parameter sample is not being attacked and contaminated.
[0086] Step S3: Construct a training sample set according to the multiple measurement parameter samples and the contamination discrimination labels corresponding to the multiple measurement parameter samples respectively.
[0087] Step S4: Train the deep neural network based on the training sample set to obtain a trained network security pollution identification model for the target virtual power plant. Among them, the trained network security pollution identification model for the target virtual power plant is used to output the pollution discrimination label corresponding to the input real-time measurement parameters according to the input real-time measurement parameters.
[0088] Among them, the deep neural network is a CNN deep learning neural network. The CNN deep learning neural network is composed of three convolutional layers, two pooling layers and two fully connected layers to better extract data features.
[0089] Specifically, step S4 includes:
[0090] Step S401: Divide the training sample set into multiple training sample subsets;
[0091] Step S402: Use multiple deep neural networks to train multiple training sample subsets respectively, and obtain the prediction probabilities of each deep neural network for multiple training sample sets;
[0092] In an example, considering the problem of data imbalance in historical samples, learning with the help of deep learning algorithms can effectively filter out most samples with high repeatability. In the process of real-time situation identification of the concerned part, in this embodiment of the application, by introducing five-fold cross-validation, the historical data corresponding to each fold is respectively input into five deep neural networks. The five deep neural networks respectively use four different ones of them as training data, and the remaining one as test data. Through the training of the deep learning model, the probability prediction of the model for all historical data can be obtained.
[0093] Step S403: Select the training sample subsets with prediction probabilities greater than the preset probability threshold.
[0094] In one embodiment, a detection threshold value is set for the above-mentioned multiple deep neural networks. For example, the threshold value is set to 0.9 to filter out most samples with relatively accurate predictions. The mathematical expression of this process is as follows:
[0095]
[0096] In the formula, is the detection threshold value for the concerned situation; represents taking the mean value of k samples with the maximum prediction probability greater than 0.9.
[0097] Set the obtained mean value as the threshold for filtering out the invalid part of the historical experience data, and only retain the part of the historical experience data that is less than the threshold. Use the samples corresponding to this part as the training samples for the subsequent heterogeneous ensemble classifier. As a result, the number of samples that the heterogeneous ensemble classifier needs to learn will be greatly reduced, and the memory and time consumption required for algorithm reconstruction will also be significantly reduced.
[0098] At the same time, since the CNN model based on five-fold cross-validation can identify most of the relatively easy-to-predict label states, and only a small number of relatively difficult-to-predict label states need to be further learned and fitted. At the same time, a sufficient number of samples can be retained for learning, and the balance of this part of the sample data is better. On this basis, the time required for the entire proposed process method is also significantly shortened, which is also very beneficial for timely restoring the reconstruction of the real-time situation.
[0099] Step S404: Train the heterogeneous ensemble classifier with the selected training sample subset to obtain the trained network security pollution identification model of the target virtual power plant.
[0100] In one embodiment, in order to further optimize the trained network security pollution identification model of the target virtual power plant, the embodiment of the present application uses the test sample set to test the trained network security pollution identification model of the target virtual power plant, and uses the test results to optimize the network parameters of the trained network security pollution identification model of the target virtual power plant to obtain the optimized network security pollution identification model of the target virtual power plant; wherein, the test sample set includes measurement parameter test samples and pollution discrimination labels corresponding to multiple measurement parameter test samples respectively.
[0101] It should be noted that the embodiment of the present application constructs an operation model of the target virtual power plant by minimizing the deviation between the measurement parameters before and after the target virtual power plant is attacked by a network, to determine the deviation between the measurement parameters before and after the target virtual power plant is attacked by a network, and determines the pollution discrimination labels of multiple measurement parameter samples through the operation model of the target virtual power plant, and trains the deep neural network with multiple measurement parameter samples and pollution discrimination labels to obtain the network security pollution identification model of the target virtual power plant, so that it is possible to identify whether it is polluted by inputting real-time measurement parameters, so as to realize timely and accurately restoring the discrimination of the true operation situation of each part of the system sampled due to the attack under the action of the attack, and ensuring the integrity of the information and improving the service ability of the VPP.
[0102] In practical applications, according to the real-time measurement parameter status, in order to restore the tampered data, data replacement is achieved by using the data in the historical database that is most similar to the current status, so that the information received by the VPP can be as close as possible to the real operating situation, reducing interference with subsequent operations, and thus maximizing the ability of the VPP to complete its assigned tasks.
[0103] Based on the same inventive concept, an embodiment of the present application also provides a virtual power plant network security pollution identification device for implementing the virtual power plant network security pollution identification method involved above.
[0104] The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the virtual power plant network security pollution identification device provided below can refer to the limitations on the virtual power plant network security pollution identification method in the above text, and will not be repeated here.
[0105] As Figure 3 shown, an embodiment of the present application provides a virtual power plant network security pollution identification device, including:
[0106] A model construction module 100, configured to minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by a network, and construct an operation model of the target virtual power plant with the operation steady state of the target virtual power plant as a constraint;
[0107] A label determination module 200, configured to input multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine pollution discrimination labels corresponding to the multiple measurement parameter samples respectively according to the deviation between the measurement parameters before and after being attacked by a network output by the operation model;
[0108] A sample construction module 300, configured to construct a training sample set according to the multiple measurement parameter samples and the pollution discrimination labels corresponding to the multiple measurement parameter samples respectively;
[0109] A pollution identification module 400, configured to train a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is configured to output a pollution discrimination label corresponding to the input real-time measurement parameter according to the input real-time measurement parameter.
[0110] In some embodiments, the operation model of the target virtual power plant includes an objective function;
[0111] Among them, the objective function is:
[0112]
[0113] In the formula, is the measurement parameter of the attack area , is the state variable and the measurement parameter have a non-linear function mapping relationship.
[0114] In some embodiments, the operation model of the target virtual power plant includes constraint conditions; among them, the constraint conditions include the active power balance constraint of node injection, the reactive power balance constraint of node injection, the active power balance constraint of line flow, the reactive power balance constraint of line flow, the bus node voltage amplitude constraint, the line power flow caused by the phase angle change after the attack, the maximum output power limit constraint of the active power in the line, the maximum output power limit constraint of the reactive power in the line, the overload relationship constraint of the apparent power on the line, and the constant constraint of the boundary state value before and after the attack.
[0115] In some embodiments, the tag determination module 200 is specifically configured to, for each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model; compare the threshold according to the deviation to determine the contamination discrimination tag of the measurement parameter sample; the contamination discrimination tag includes being contaminated by an attack and not being contaminated by an attack.
[0116] In some embodiments, the contamination identification module 400 is specifically configured to divide the training sample set into multiple training sample subsets; use multiple deep neural networks to train the multiple training sample subsets respectively, and obtain the prediction probability of each deep neural network for the multiple training sample sets; screen out the training sample subsets with a prediction probability greater than a preset probability threshold; use the screened training sample subsets to train the heterogeneous integrated classifier to obtain the trained network security contamination identification model of the target virtual power plant.
[0117] In some embodiments, the device further includes: an optimization module, configured to test the trained network security contamination identification model of the target virtual power plant using the test sample set, and optimize the network parameters of the trained network security contamination identification model of the target virtual power plant using the test results to obtain the optimized network security contamination identification model of the target virtual power plant; wherein, the test sample set includes measurement parameter test samples and contamination discrimination tags respectively corresponding to the multiple measurement parameter test samples.
[0118] In some embodiments, the deep neural network is a CNN deep learning neural network.
[0119] Such as Figure 4As shown in the figure, an embodiment of the present application further provides an electronic device. The electronic device 10 includes a memory 20 and a processor 30. A computer program is stored in the memory 20. When the computer program is executed by the processor 30, the processor 30 is caused to execute the steps of the virtual power plant network security pollution identification method as described in any one of the above.
[0120] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed, the steps of the virtual power plant network security pollution identification method as described in any one of the above are implemented.
[0121] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described system, electronic device, and computer storage medium can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0122] It should be noted that the terms "including" and "having" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0123] In several embodiments provided by the present invention, it can be understood that each block in the flowchart or block diagram may represent a module, a program segment, or a part of code. A module, a program segment, or a part of code includes one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved.
[0124] In several embodiments provided by the present invention, it should be understood that the disclosed system, electronic device, computer storage medium, and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other may be through some interfaces, indirect couplings or communication connections of devices or units, and may be in electrical, mechanical, or other forms.
[0125] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0126] In addition, each functional unit in various embodiments of the present invention may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0127] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that makes a contribution to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (English full name: Read-Only Memory, English abbreviation: ROM), random access memories (English full name: Random Access Memory, English abbreviation: RAM), magnetic disks, or optical discs and other various media that can store program codes.
[0128] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of the present invention.
Claims
1. A method for identifying network security pollution in a virtual power plant, characterized in that, Including: Minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by a cyber-attack, and construct an operation model of the target virtual power plant with the steady state operation of the target virtual power plant as a constraint; Input multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine the pollution discrimination labels corresponding to the multiple measurement parameter samples respectively according to the deviation between the measurement parameters before and after being attacked by a cyber-attack corresponding to each measurement parameter sample output by the operation model; Construct a training sample set according to the multiple measurement parameter samples and the pollution discrimination labels corresponding to the multiple measurement parameter samples respectively; Train a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output the pollution discrimination label corresponding to the input real-time measurement parameter according to the input real-time measurement parameter.
2. The virtual power plant network security pollution identification method according to claim 1, wherein The operation model of the target virtual power plant includes an objective function; Wherein, the objective function is: In the formula, is the measurement parameter of the attack area , is the state variable and the measurement parameter has a non-linear function mapping relationship therebetween.
3. The virtual power plant network security pollution identification method according to claim 1, characterized in that The operation model of the target virtual power plant includes constraint conditions; wherein, the constraint conditions include the active power balance constraint of node injection, the reactive power balance constraint of node injection, the active power balance constraint of line flow, the reactive power balance constraint of line flow, the bus node voltage amplitude constraint, the line power flow caused by the phase angle change after the attack, the maximum output power limit constraint of the active power in the line, the maximum output power limit constraint of the reactive power in the line, the overload relationship constraint of the apparent power on the line, and the constant constraint of the boundary state value before and after the attack.
4. The virtual power plant network security pollution identification method according to claim 1, characterized in that The step of inputting the multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant and determining the pollution discrimination labels corresponding to the multiple measurement parameter samples respectively according to the deviation between the measurement parameters before and after being attacked by a cyber-attack corresponding to each measurement parameter sample output by the operation model includes: For each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model; Perform a threshold comparison according to the deviation to determine the pollution discrimination label of the measurement parameter sample; the pollution discrimination label includes being attacked and polluted and not being attacked and polluted.
5. The virtual power plant network security pollution identification method according to claim 1, wherein, The step of training a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant includes: Divide the training sample set into multiple training sample subsets; Use multiple deep neural networks to train the multiple training sample subsets respectively, and obtain the prediction probability of each deep neural network for the multiple training sample sets; Select the training sample subsets whose prediction probability is greater than a preset probability threshold; Train the heterogeneous integrated classifier with the selected training sample subsets to obtain the trained network security pollution identification model of the target virtual power plant.
6. The virtual power plant network security pollution identification method according to claim 1, characterized in that Also including: The trained network security pollution identification model of the target virtual power plant is tested using a test sample set, and the network parameters of the trained network security pollution identification model of the target virtual power plant are optimized using the test results to obtain an optimized network security pollution identification model of the target virtual power plant; wherein, the test sample set includes measurement parameter test samples and pollution discrimination labels respectively corresponding to a plurality of the measurement parameter test samples.
7. The virtual power plant network security pollution identification method according to any one of claims 1 to 6, characterized in that The deep neural network is a CNN deep learning neural network.
8. A virtual power plant network security pollution identification device, characterized in that, It includes: A model construction module, configured to minimize the deviation between the measurement parameters of the target virtual power plant before and after being attacked by a network, and construct an operation model of the target virtual power plant with the operation steady state of the target virtual power plant as a constraint. A label determination module, configured to input a plurality of measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine pollution discrimination labels respectively corresponding to the plurality of measurement parameter samples according to the deviation between the measurement parameters before and after being attacked by a network corresponding to each of the measurement parameter samples output by the operation model. A sample construction module, configured to construct a training sample set according to the plurality of measurement parameter samples and the pollution discrimination labels respectively corresponding to the plurality of measurement parameter samples. A pollution identification module, configured to train a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is configured to output a pollution discrimination label corresponding to the input real-time measurement parameter according to the input real-time measurement parameter.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the virtual power plant network security pollution identification method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed, the steps of the virtual power plant network security pollution identification method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Virtual power plant optimization operation method and device, equipment and medium
CN117541030A
Method and device for detecting false data injection attack
CN119276583A
Method and system for detecting false data injection attack of power system
CN119544330A
False data injection detection method and system based on bidirectional long short-term memory network
CN119675917A
Multi-target scheduling optimization method and system for virtual power plant to participate in electricity market
CN120087801A