Virtual power plant network security pollution identification method, device, electronic equipment and storage medium
By building a virtual power plant operation model and deep neural network training, the problem of virtual power plants being difficult to restore operation under attack was solved, and the protection of information integrity and the improvement of service capabilities were achieved.
Patent Information
- Application Number
- CN202510779715.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-06-12
AI Technical Summary
Existing technologies make it difficult to restore the actual operating status of various parts of the system in a timely and accurate manner when a virtual power plant is attacked, making it difficult to ensure information integrity, which in turn affects the VPP's ability to provide services.
An operation model of the target virtual power plant is constructed, with the minimization of deviations between measurement parameters as a constraint. A deep neural network is used to train a network security pollution identification model. The pollution situation is identified by inputting real-time measurement parameters to restore the system's true operating status.
It achieves timely and accurate restoration of the system's actual operating status under attack, ensures information integrity, and improves the VPP's ability to provide services.
Smart Images

Figure CN120321034B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of virtual power plants, and in particular to a method, device, electronic equipment and storage medium for identifying network contamination in a virtual power plant. Background Art
[0002] The emergence of virtual power plant (VPP) technology has significantly improved the grid's ability to integrate resources, and it has become a key future development direction for power systems. However, due to its overreliance on information and communications systems, VPP technology has increased vulnerabilities and reduced security in various aspects of VPP operation, including communications, data, and operations and maintenance. The development of these cybersecurity threats could lead to significant losses.
[0003] Currently, some data-driven methods can already identify whether the operating status of virtual power plants has been contaminated based on their operational data. However, it is generally difficult to promptly and accurately recover the actual operating status of samples of various parts of the system caused by the attack. This makes it difficult to ensure the integrity of the information, which in turn reduces the VPP's ability to provide services. Summary of the Invention
[0004] In view of this, the present invention provides a virtual power plant network security pollution identification method, device, electronic device and storage medium, which solves the technical problem that it is difficult to timely and accurately recover the true operating status of the samples of various parts of the system caused by the attack, which makes it difficult to ensure the integrity of the information and thus causes a decline in the VPP's ability to provide services.
[0005] A first aspect of the present invention provides a method for identifying network security pollution in a virtual power plant, comprising:
[0006] An operation model of the target virtual power plant is constructed by minimizing the deviation between the measured parameters of the target virtual power plant before and after the cyber attack and taking the steady state of operation of the target virtual power plant as a constraint;
[0007] Inputting a plurality of measurement parameter samples of the target virtual power plant into an operation model of the target virtual power plant, and determining pollution identification labels corresponding to each of the measurement parameter samples based on a deviation between the measurement parameters before and after the network attack corresponding to each of the measurement parameter samples output by the operation model;
[0008] Constructing a training sample set according to the plurality of measurement parameter samples and the pollution identification labels corresponding to the plurality of measurement parameter samples;
[0009] A deep neural network is trained based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the input real-time measurement parameters based on the real-time measurement parameters.
[0010] Preferably, the operation model of the target virtual power plant includes an objective function;
[0011] Wherein, the objective function is:
[0012]
[0013] Where, Attack area The measurement parameters, is a state variable and measurement parameters The nonlinear function mapping relationship between them.
[0014] Preferably, the operation model of the target virtual power plant includes constraints; wherein, the constraints include active power balance constraints injected into nodes, reactive power balance constraints injected into nodes, active power balance constraints of line flow, reactive power balance constraints of line flow, bus node voltage amplitude constraints, line flow caused by phase angle changes after attack, maximum output limit constraints of active power in the line, maximum output limit constraints of reactive power in the line, overload relationship constraints of apparent power on the line, and constant constraints on boundary state values before and after attack.
[0015] Preferably, the step of inputting a plurality of measurement parameter samples of the target virtual power plant into an operation model of the target virtual power plant, and determining pollution identification labels corresponding to the plurality of measurement parameter samples respectively based on deviations between measurement parameters before and after the network attack corresponding to each measurement parameter sample output by the operation model, includes:
[0016] For each of the measurement parameter samples, inputting the measurement parameter sample into the operation model of the target virtual power plant to obtain a deviation corresponding to the measurement parameter sample output by the operation model;
[0017] A threshold comparison is performed based on the deviation to determine a contamination identification label of the measurement parameter sample; the contamination identification label includes a contaminated by attack and a non-contaminated by attack.
[0018] Preferably, the step of training a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant includes:
[0019] Dividing the training sample set into a plurality of training sample subsets;
[0020] Using multiple deep neural networks to train the multiple training sample subsets respectively, and obtain the prediction probability of each of the deep neural networks for the multiple training sample sets;
[0021] Filtering out the training sample subset whose predicted probability is greater than a preset probability threshold;
[0022] The heterogeneous ensemble classifier is trained with the screened training sample subset to obtain the trained network security pollution identification model of the target virtual power plant.
[0023] Preferably, the method further comprises:
[0024] The trained network security pollution identification model of the target virtual power plant is tested using a test sample set, and the network parameters of the trained network security pollution identification model of the target virtual power plant are optimized using the test results to obtain an optimized network security pollution identification model of the target virtual power plant; wherein the test sample set includes measurement parameter test samples and pollution identification labels corresponding to multiple measurement parameter test samples.
[0025] Preferably, the deep neural network is a CNN deep learning neural network.
[0026] In a second aspect, an embodiment of the present application further provides a virtual power plant network security pollution identification device, comprising:
[0027] a model building module for building an operation model of a target virtual power plant by minimizing the deviation between measured parameters of the target virtual power plant before and after the cyber attack and taking the steady state of operation of the target virtual power plant as a constraint;
[0028] a label determination module, configured to input a plurality of measurement parameter samples of the target virtual power plant into an operation model of the target virtual power plant, and determine pollution identification labels corresponding to the plurality of measurement parameter samples based on deviations between measurement parameters before and after the network attack corresponding to each measurement parameter sample output by the operation model;
[0029] A sample construction module, configured to construct a training sample set according to a plurality of the measurement parameter samples and the pollution identification labels corresponding to the plurality of the measurement parameter samples;
[0030] A pollution identification module is used to train a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the real-time measurement parameters based on the input real-time measurement parameters.
[0031] In a third aspect, an embodiment of the present application further provides an electronic device, comprising a memory and a processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the steps of the virtual power plant network security pollution identification method as described in the first aspect.
[0032] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed, implements the steps of the virtual power plant network security pollution identification method as described in the first aspect.
[0033] It can be seen from the above technical solutions that the present invention has the following advantages:
[0034] The present invention constructs an operation model of the target virtual power plant by minimizing the deviation between the measurement parameters of the target virtual power plant before and after the network attack, so as to determine the deviation between the measurement parameters of the target virtual power plant before and after the network attack, and determines the pollution identification labels of multiple measurement parameter samples through the operation model of the target virtual power plant. The deep neural network is trained using the multiple measurement parameter samples and the pollution identification labels to obtain a network security pollution identification model of the target virtual power plant. Therefore, whether the target virtual power plant is contaminated can be identified by inputting real-time measurement parameters, thereby realizing timely and accurate recovery under the action of the attack, identifying the actual operating status of the samples of various parts of the system caused by the attack, ensuring the integrity of the information, and improving the ability of the VPP to provide services. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 An application environment for a virtual power plant network security pollution identification method provided by an embodiment of the present invention;
[0036] Figure 2 A flowchart of a method for identifying network security pollution in a virtual power plant provided by an embodiment of the present invention;
[0037] Figure 3 A schematic structural diagram of a virtual power plant network security pollution identification device provided by an embodiment of the present invention;
[0038] Figure 4 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0039] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0040] The virtual power plant network security pollution identification method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, each node of the virtual power plant communicates with server 102 via a network. A data storage system can store data that server 102 needs to process. The data storage system can be integrated with server 102 or placed in the cloud or on other network servers. Server 102 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server providing cloud computing services.
[0041] like Figure 2 As shown, the embodiment of the present application provides a virtual power plant network security pollution identification method, which is applied to Figure 1 The server 102 in the example is used as an example to illustrate the process, including the following steps S1 to S4.
[0042] Step S1: Minimize the deviation between the measured parameters of the target virtual power plant before and after the network attack, and use the operating steady state of the target virtual power plant as a constraint to construct an operation model of the target virtual power plant.
[0043] It is understandable that the measured parameters of the target virtual power plant before and after the network attack are different, so there is a deviation value. In the embodiment of the present application, the objective function of the operation model of the target virtual power plant is constructed by minimizing the deviation between the measured parameters before and after the network attack. The objective function is:
[0044]
[0045] Where, Attack area The measurement parameters, is a state variable and measurement parameters The nonlinear function mapping relationship between them.
[0046] The measurement parameters include, but are not limited to, active / reactive power injection and active / reactive power measured by SCADA (Supervisory Control and Data Acquisition), and voltage phase angle, voltage amplitude, and real and imaginary parts of the current vector measured by PMU (Phasor Measurement Unit).
[0047] State quantity , is the phase angle of the system voltage after the attack, is the system voltage amplitude after the attack is implemented.
[0048] Among them, for the function mapping relationship It is determined by fitting and other means based on the historical measurement sample parameters of the target virtual power plant before and after the cyber attack.
[0049] In addition, the embodiment of the present application considers the operating steady state of the target virtual power plant as a constraint, so the constraint conditions of the operating model of the target virtual power plant include the active power balance constraint of the node injection, the reactive power balance constraint of the node injection, the active power balance constraint of the line flow, the reactive power balance constraint of the line flow, the bus node voltage amplitude constraint, the line flow caused by the phase angle change after the attack, the maximum output limit constraint of the active power in the line, the maximum output limit constraint of the reactive power in the line, the overload relationship constraint of the apparent power on the line, and the constant constraint of the boundary state value before and after the attack.
[0050] Specifically, the active power balance constraint injected by the node is:
[0051]
[0052] Where i and j are node indexes, ij represents the busbar index, is the active power injected into node i, 、 are the voltage amplitudes injected into nodes i and j respectively, is the phase angle difference of the voltage of line ij after the attack is implemented, Centralize and The collection of connected parts of a bus, are the susceptance and conductance of line ij, It is the change in node active power injection caused by the attack vector being injected into the system.
[0053] The balance constraint of reactive power injected into the node is:
[0054]
[0055] Where, is the reactive power injected into node i, It is the change in node reactive power injection caused by the attack vector being injected into the system.
[0056] The active power balance constraints and reactive power balance constraints of line flow are:
[0057]
[0058]
[0059] Where, and are the active power and reactive power flowing in line ij, 、 are the changes in active power and reactive power of line ij, 、 They represent the earth susceptance and earth conductance connected to node i, respectively. 、 are the mutual susceptance and mutual conductance of the lines connecting nodes i and j, respectively.
[0060] The busbar node voltage amplitude constraint is:
[0061]
[0062] Where, is the voltage amplitude at node i, 、 are the lower and upper limits of the voltage amplitude at node i, respectively. It is the change in node voltage amplitude caused by the injection of attack vector into the system.
[0063] The line power flow caused by the phase angle change after the attack is:
[0064]
[0065] Where, is the voltage phase angle of node i, is the change in node voltage phase angle caused by the injection of the attack vector into the system, It is the node voltage phase angle caused by the attack vector injected into the system.
[0066] The power flow constraint of the line caused by the phase angle change after the attack is:
[0067]
[0068]
[0069] Where, 、 are the real and imaginary parts of the current vector of line ij, 、 are the changes in the real and imaginary parts of the current vector of line ij respectively.
[0070] The maximum output limit constraints of the active power in the line and the maximum output limit constraints of the reactive power in the line are:
[0071]
[0072] Where, 、 are the active and reactive power of the system respectively, 、 are the minimum and maximum values of the active power of the generator, respectively. G is the generator, which stipulates that the active power of the entire system must be within the technical output range of the generator; 、 are the changes in active and reactive power of the system, 、 are the minimum and maximum active and reactive power of the system respectively.
[0073] The overload constraint of the apparent power on the line is:
[0074]
[0075] Where, is the maximum apparent power that the line can withstand, 、 are the apparent active power and apparent reactive power of the line respectively, 、 They are the changes in apparent active power and apparent reactive power of the line respectively.
[0076] The constant constraint of the boundary state value before and after the attack is:
[0077]
[0078] Where, For the The state variables of the boundary, is the initial value of the state variable, e is the boundary index, is a boundary set.
[0079] Understandably, this contaminated and damaged state data cannot be promptly detected by the existing single VPP measurement system, resulting in serious consequences. This is because when the aforementioned state quantities of interest, namely voltage amplitude and phase angle, are contaminated, the information received by the VPP may undergo various changes. Such changes will interfere with various subsequent operations, preventing the VPP, as an energy management system, from completing its tasks in a timely and effective manner. It may even result in some erroneous allocation and scheduling decisions, and in the most serious cases, may ultimately lead to a complete system crash. To this end, the embodiments of the present application can achieve the purpose of covertly injecting the designed attack vector into the VPP system through the operating model of the target virtual power plant, thereby achieving the purpose of attacking the voltage amplitude and phase angle within the attack area of interest.
[0080] Step S2: Input multiple measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determine the pollution identification labels corresponding to the multiple measurement parameter samples based on the deviation between the measurement parameters before and after the network attack corresponding to each measurement parameter sample output by the operation model.
[0081] It can be understood that the operating model of the target virtual power plant inputs various state quantities, determines the deviation through each state quantity and the state quantity after the attack, and judges whether the fluctuation is within the specified range based on the deviation, and then outputs a classification judgment indicator for whether the system has suffered a network attack, that is, the output is a judgment on whether the current system is contaminated.
[0082] Specifically, step S2 includes:
[0083] Step S201: For each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model.
[0084] Step S202: performing a threshold comparison based on the deviation to determine a contamination identification label of the measurement parameter sample; the contamination identification label includes contaminated by the attack and not contaminated by the attack.
[0085] A deviation threshold is set. When the deviation is greater than the deviation threshold, the contamination identification label of the measurement parameter sample is determined to be contaminated by the attack. When the deviation is not greater than the deviation threshold, the contamination identification label of the measurement parameter sample is determined to be not contaminated by the attack.
[0086] Step S3: construct a training sample set according to the plurality of measurement parameter samples and the pollution identification labels corresponding to the plurality of measurement parameter samples.
[0087] Step S4: Train the deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the real-time measurement parameters based on the input real-time measurement parameters.
[0088] The deep neural network is a CNN deep learning neural network. The CNN deep learning neural network consists of three convolutional layers, two pooling layers, and two fully connected layers to better extract data features.
[0089] Specifically, step S4 includes:
[0090] Step S401: Divide the training sample set into multiple training sample subsets;
[0091] Step S402: using multiple deep neural networks to train multiple training sample subsets respectively, and obtaining the prediction probability of each deep neural network for the multiple training sample sets;
[0092] In one example, considering the data imbalance problem in historical samples, learning with the help of deep learning algorithms can effectively filter out most of the samples with high repetitiveness. In the process of real-time situation identification of the operation of the part of interest, the embodiment of the present application introduces five-fold cross-validation, and the historical data corresponding to each fold are input into five deep neural networks respectively. The five deep neural networks use four different copies of the data as training data and the remaining one as test data. Through the training of the deep learning model, the model's probability prediction of all historical data can be obtained.
[0093] Step S403: Filter out a subset of training samples whose predicted probabilities are greater than a preset probability threshold.
[0094] In one embodiment, a detection threshold is set for the multiple deep neural networks, such as 0.9, to filter out most of the samples with relatively accurate predictions. The mathematical expression of this process is as follows:
[0095]
[0096] Where, is the detection threshold value of the attention situation; It represents the mean of k samples with the maximum predicted probability greater than 0.9.
[0097] The obtained mean is set as the threshold for filtering out invalid portions of historical data. Only the portion of historical data below the threshold is retained, and the corresponding samples are used as training samples for the subsequent heterogeneous ensemble classifier. This greatly reduces the number of samples required for the heterogeneous ensemble classifier to learn, significantly reducing the memory and time required for algorithm reconstruction.
[0098] Furthermore, because the CNN model based on five-fold cross-validation can identify the majority of easily predictable label states, only a small number of relatively difficult-to-predict label states require further learning and fitting. Furthermore, a sufficient number of samples can be retained for learning, resulting in a better balance of sample data. This significantly reduces the time required for the proposed entire process, which is beneficial for timely recovery and reconstruction of real-time status.
[0099] Step S404: train the heterogeneous ensemble classifier with the screened training sample subset to obtain a trained network security pollution identification model for the target virtual power plant.
[0100] In one embodiment, in order to further optimize the trained network security pollution identification model of the target virtual power plant, the embodiment of the present application uses a test sample set to test the trained network security pollution identification model of the target virtual power plant, and uses the test results to optimize the network parameters of the trained network security pollution identification model of the target virtual power plant to obtain an optimized network security pollution identification model of the target virtual power plant; wherein, the test sample set includes measurement parameter test samples and pollution identification labels corresponding to multiple measurement parameter test samples.
[0101] It should be noted that the embodiment of the present application constructs an operation model of the target virtual power plant by minimizing the deviation between the measurement parameters of the target virtual power plant before and after the network attack, so as to determine the deviation between the measurement parameters of the target virtual power plant before and after the network attack, and determines the pollution identification labels of multiple measurement parameter samples through the operation model of the target virtual power plant, and uses multiple measurement parameter samples and pollution identification labels to train a deep neural network to obtain a network security pollution identification model of the target virtual power plant, so that it can be identified whether it is contaminated by inputting real-time measurement parameters, thereby achieving timely and accurate recovery under the influence of the attack, and identifying the actual operating status of the samples of various parts of the system caused by the attack, and ensuring the integrity of the information, thereby improving the ability of the VPP to provide services.
[0102] In actual applications, based on the real-time status of measurement parameters, in order to restore tampered data, data is replaced by data in the historical database that is most similar to the current state. This ensures that the information received by the VPP is as close to the actual operating status as possible, reduces interference with subsequent operations, and maximizes the VPP's ability to complete its tasks.
[0103] Based on the same inventive concept, an embodiment of the present application also provides a virtual power plant network security pollution identification device for implementing the above-mentioned virtual power plant network security pollution identification method.
[0104] The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method. Therefore, the specific limitations in one or more virtual power plant network security pollution identification device embodiments provided below can be found in the above limitations on the virtual power plant network security pollution identification method, and will not be repeated here.
[0105] like Figure 3 As shown, the embodiment of the present application provides a virtual power plant network security pollution identification device, including:
[0106] A model building module 100 is configured to build an operation model of a target virtual power plant by minimizing the deviation between measured parameters of the target virtual power plant before and after the cyber attack and taking the steady state of operation of the target virtual power plant as a constraint;
[0107] a label determination module 200 for inputting a plurality of measurement parameter samples of a target virtual power plant into an operation model of the target virtual power plant and determining pollution identification labels corresponding to each of the plurality of measurement parameter samples based on the deviation between the measurement parameters before and after the cyber attack corresponding to each measurement parameter sample output by the operation model;
[0108] A sample construction module 300 is used to construct a training sample set based on a plurality of measurement parameter samples and pollution identification labels corresponding to the plurality of measurement parameter samples;
[0109] The pollution identification module 400 is used to train the deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the real-time measurement parameters based on the input real-time measurement parameters.
[0110] In some embodiments, the operating model of the target virtual power plant includes an objective function;
[0111] Among them, the objective function is:
[0112]
[0113] Where, Attack area The measurement parameters, is a state variable and measurement parameters The nonlinear function mapping relationship between them.
[0114] In some embodiments, the operation model of the target virtual power plant includes constraints; wherein the constraints include active power balance constraints injected into the node, reactive power balance constraints injected into the node, active power balance constraints of line flow, reactive power balance constraints of line flow, bus node voltage amplitude constraints, line flow caused by phase angle changes after the attack, maximum output limit constraints of active power in the line, maximum output limit constraints of reactive power in the line, overload relationship constraints of apparent power on the line, and constant constraints on boundary state values before and after the attack.
[0115] In some embodiments, the label determination module 200 is specifically used to, for each measurement parameter sample, input the measurement parameter sample into the operation model of the target virtual power plant to obtain the deviation corresponding to the measurement parameter sample output by the operation model; perform threshold comparison based on the deviation to determine the pollution identification label of the measurement parameter sample; the pollution identification label includes attacked pollution and not attacked pollution.
[0116] In some embodiments, the pollution identification module 400 is specifically used to divide the training sample set into multiple training sample subsets; use multiple deep neural networks to train the multiple training sample subsets respectively, and obtain the prediction probability of each deep neural network for the multiple training sample sets; screen out the training sample subsets whose prediction probability is greater than a preset probability threshold; train the heterogeneous integrated classifier with the screened training sample subsets to obtain a trained network security pollution identification model of the target virtual power plant.
[0117] In some embodiments, the device also includes: an optimization module, which is used to test the trained network security pollution identification model of the target virtual power plant using a test sample set, and use the test results to optimize the network parameters of the trained network security pollution identification model of the target virtual power plant to obtain an optimized network security pollution identification model of the target virtual power plant; wherein the test sample set includes measurement parameter test samples and pollution identification labels corresponding to multiple measurement parameter test samples.
[0118] In some embodiments, the deep neural network is a CNN deep learning neural network.
[0119] like Figure 4As shown, an embodiment of the present application also provides an electronic device, the electronic device 10 includes a memory 20 and a processor 30, the memory 20 stores a computer program, and when the computer program is executed by the processor 30, the processor 30 executes the steps of the virtual power plant network security pollution identification method such as any one of the above items.
[0120] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed, implements the steps of any of the above-mentioned methods for identifying network security pollution of a virtual power plant.
[0121] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, electronic devices, and computer storage media can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0122] It should be noted that the terms "including" and "having" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or apparatuses.
[0123] In several embodiments provided by the present invention, it is understood that each box in the flow chart or block diagram can represent a module, program segment or part of the code, and the module, program segment or part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved.
[0124] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, electronic devices, computer storage media and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0125] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0126] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0127] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the method described in each embodiment of the present invention via a computer device (which can be a personal computer, server, or network device, etc.). The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0128] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for identifying network security pollution in a virtual power plant, characterized in that: include: An operation model of the target virtual power plant is constructed by minimizing the deviation between the measured parameters of the target virtual power plant before and after the cyber attack and taking the steady state of operation of the target virtual power plant as a constraint; The operation model of the target virtual power plant includes an objective function; Wherein, the objective function is: ; Where, Attack area The measurement parameters, is a state variable and measurement parameters The nonlinear function mapping relationship between them; The operation model of the target virtual power plant includes constraints; wherein the constraints include active power balance constraints injected into nodes, reactive power balance constraints injected into nodes, active power balance constraints flowing in lines, reactive power balance constraints flowing in lines, bus node voltage amplitude constraints, line power flow caused by phase angle changes after the attack, maximum output limit constraints of active power in the line, maximum output limit constraints of reactive power in the line, overload relationship constraints of apparent power on the line, and constant boundary state value constraints before and after the attack; Inputting a plurality of measurement parameter samples of the target virtual power plant into an operation model of the target virtual power plant, and determining pollution identification labels corresponding to each of the measurement parameter samples based on a deviation between the measurement parameters before and after the network attack corresponding to each of the measurement parameter samples output by the operation model; Constructing a training sample set according to the plurality of measurement parameter samples and the pollution identification labels corresponding to the plurality of measurement parameter samples; A deep neural network is trained based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the input real-time measurement parameters based on the real-time measurement parameters.
2. The method for identifying network security pollution of a virtual power plant according to claim 1, characterized in that: The step of inputting a plurality of measurement parameter samples of the target virtual power plant into the operation model of the target virtual power plant, and determining pollution identification labels corresponding to the plurality of measurement parameter samples based on the deviation between the measurement parameters before and after the network attack corresponding to each measurement parameter sample output by the operation model, includes: For each of the measurement parameter samples, inputting the measurement parameter sample into the operation model of the target virtual power plant to obtain a deviation corresponding to the measurement parameter sample output by the operation model; A threshold comparison is performed based on the deviation to determine a contamination identification label of the measurement parameter sample; the contamination identification label includes a contaminated by attack and a non-contaminated by attack.
3. The method for identifying network security pollution of a virtual power plant according to claim 1, characterized in that: The step of training a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant includes: Dividing the training sample set into a plurality of training sample subsets; Using multiple deep neural networks to train the multiple training sample subsets respectively, and obtain the prediction probability of each of the deep neural networks for the multiple training sample sets; Filtering out the training sample subset whose predicted probability is greater than a preset probability threshold; The heterogeneous ensemble classifier is trained with the screened training sample subset to obtain the trained network security pollution identification model of the target virtual power plant.
4. The method for identifying network security pollution of a virtual power plant according to claim 1, characterized in that: Also includes: The trained network security pollution identification model of the target virtual power plant is tested using a test sample set, and the network parameters of the trained network security pollution identification model of the target virtual power plant are optimized using the test results to obtain an optimized network security pollution identification model of the target virtual power plant; wherein the test sample set includes measurement parameter test samples and pollution identification labels corresponding to multiple measurement parameter test samples.
5. The method for identifying network security pollution of a virtual power plant according to any one of claims 1 to 4, characterized in that: The deep neural network is a CNN deep learning neural network.
6. A virtual power plant network security pollution identification device, characterized in that: include: a model building module for building an operation model of a target virtual power plant by minimizing the deviation between measured parameters of the target virtual power plant before and after the cyber attack and taking the steady state of operation of the target virtual power plant as a constraint; The operation model of the target virtual power plant includes an objective function; Wherein, the objective function is: ; Where, Attack area The measurement parameters, is a state variable and measurement parameters The nonlinear function mapping relationship between them; The operation model of the target virtual power plant includes constraints; wherein the constraints include active power balance constraints injected into nodes, reactive power balance constraints injected into nodes, active power balance constraints flowing in lines, reactive power balance constraints flowing in lines, bus node voltage amplitude constraints, line power flow caused by phase angle changes after the attack, maximum output limit constraints of active power in the line, maximum output limit constraints of reactive power in the line, overload relationship constraints of apparent power on the line, and constant boundary state value constraints before and after the attack; a label determination module, configured to input a plurality of measurement parameter samples of the target virtual power plant into an operation model of the target virtual power plant, and determine pollution identification labels corresponding to the plurality of measurement parameter samples based on deviations between measurement parameters before and after the network attack corresponding to each measurement parameter sample output by the operation model; A sample construction module, configured to construct a training sample set according to a plurality of the measurement parameter samples and the pollution identification labels respectively corresponding to the plurality of the measurement parameter samples; A pollution identification module is used to train a deep neural network based on the training sample set to obtain a trained network security pollution identification model of the target virtual power plant; wherein, the trained network security pollution identification model of the target virtual power plant is used to output pollution identification labels corresponding to the real-time measurement parameters based on the input real-time measurement parameters.
7. An electronic device, characterized in that: The electronic device includes a memory and a processor, wherein a computer program is stored in the memory. When the computer program is executed by the processor, the processor executes the steps of the virtual power plant network security pollution identification method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed, the steps of the virtual power plant network security pollution identification method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Virtual power plant optimization operation method and device, equipment and medium
CN117541030A
Method and device for detecting false data injection attack
CN119276583A
Method and system for detecting false data injection attack of power system
CN119544330A