Blind false data injection attack method in power grid alternating current state estimation based on adversarial artificial intelligence
Through an adversarial artificial intelligence-based method, using artificial neural networks to infer the grid topology and filter the fake data attack vector, the problem of insufficient concealment of blind and false data injection attacks in the existing technology is solved, and a more efficient grid attack strategy is achieved, reducing detection risks and affecting the operation of the power grid.
Patent Information
- Application Number
- CN202510388137.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
AI Technical Summary
The existing technology fails to effectively consider the dynamic nonlinear characteristics of the power grid and the impact of bad data in blind and false data injection attacks, resulting in insufficient concealment of the attack and relying on some topological information, flexibility and computational complexity are challenged.
Adversarial artificial intelligence-based approach is adopted to infer the power grid topology from historical measurement data through artificial neural networks, generate fake data attack vectors, and filter the attack vectors using alternative bad data detectors to reduce the risk of being detected by real bad data detectors, and consider the impact of factors such as sensor failure.
It significantly improves the concealment and success rate of false data injection attacks, reduces the risk of being detected by real BDD, and can cause significant deviations in the smart grid, affecting the safety and reliability of the grid.
Smart Images

Figure CN120342665A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of smart grid security, and more particularly to a blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence. Background Art
[0002] The introduction of artificial intelligence (AI) technology into the smart grid system has provided new tools for critical security systems and operations, but it has also brought new potential targets and threats. This development highlights the necessity of researching and enhancing system security and resilience measures. Cybersecurity researchers are actively addressing this challenge, exploring emerging threats and defense strategies, especially the stealthy false data injection attack (FDIA) in power system state estimation (SE), which has attracted wide attention.
[0003] The state estimator, as a key intermediary between system measurements and application functions, is responsible for providing a reliable real-time system database for security assessment and emergency corrective actions. An existing invention has proposed a stealthy FDIA scheme that bypasses the identification of the bad data detector (BDD) by generating false data consistent with the normal data residuals, making the manipulated measurement results match the white Gaussian noise of the normal data. The proposal of this invention has triggered extensive research on false data injection attacks.
[0004] Many studies have been carried out based on this framework, which initially requires comprehensive grid topology information. However, recent variants such as partially informed and blind false data injection attacks have gradually relaxed this assumption. In particular, the blind false data injection attack poses a threat by inferring key information from historical data under limited topology information.
[0005] From the operator's perspective, although topology inference techniques have been adopted in SCADA and WAMS systems, it is usually assumed that the grid topology and system model are known. Therefore, the attacker must have a certain understanding of the system. Early studies on blind false data injection attacks relied on statistical techniques (such as independent component analysis, principal component analysis, etc.), but these methods did not consider the dynamic nonlinear characteristics of the power grid. Recent studies have proposed an AC flow-based topology learning method that combines active and reactive power flow measurements for pseudo state estimation to enhance the concealment of the attack.
[0006] With the introduction of adversarial AI, the research on false data injection attacks has entered a new stage. Existing studies have proposed model-free FDIA techniques based on generative adversarial networks (GANs), but still require some topology knowledge. Other methods, such as using WGAN and autoencoders (AEs) to create a surrogate model of the state estimator, further reveal the potential vulnerabilities of the power system. However, these methods still face challenges in terms of flexibility and computational complexity.
[0007] It should be noted that the false data injection attack is not limited to bypassing topological information, but may also ignore other key factors such as system configuration and bad data thresholds. These factors may have an important impact on the feasibility and effectiveness of the attack, but many studies have not fully considered these factors. In addition, most studies focus on the ability to bypass the BDD and ignore the impact of existing bad data. Injecting false data into the measurement with existing bad data may lead to misjudgment, thus affecting the stealth of the attack. Therefore, the stealth of the false data injection attack should consider both the ability to bypass the BDD and the impact of existing bad data. Summary of the Invention
[0008] The object of the present invention is to provide a blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence to solve the problems mentioned in the background technology.
[0009] To achieve the above object, the present invention provides a blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence, including the following steps:
[0010] S1. Collect historical measurement data from the SCADA system of the smart grid and preprocess the collected historical measurement data to remove noise and outliers;
[0011] S2. Use an artificial neural network to infer the power grid topology from the historical measurement data to obtain the mapping function h(·);
[0012] S3. Generate a fake data attack vector for injection according to the inferred topology;
[0013] S4. Before injecting the attack vector, use an alternative bad data detector to filter the fake data to reduce the risk of being detected by the real bad data detector;
[0014] S5. Inject the filtered attack vector into the AC state estimator of the smart grid to achieve a stealth attack;
[0015] S6. Conduct an attack stealth assessment, considering the possible existing bad data due to sensor failures, communication delays or other natural reasons before the attack.
[0016] Preferably, the historical measurement data includes measurement values of voltage amplitude, voltage angle, active power and reactive power.
[0017] Preferably, the artificial neural network is a four-hidden-layer feedforward neural network, the activation function is Tan-Sigmoid, the training algorithm is adaptive momentum gradient descent, and each hidden layer has 230 hidden neurons.
[0018] Preferably, the S2 includes the following steps:
[0019] S21. Take all parameters as the output measurement values and a subset of the measurement parameters as the input. The output measurement value z includes the voltage angle and amplitude, active and reactive power flows, and the generated power. The input measurement value z x includes the voltage angle and amplitude. If an attacker uses the measurement information to train an artificial neural network, the obtained output measurement value is:
[0020]
[0021] where z represents an m×1 output, represents the input, w2,…,w n represents the synaptic weights, b represents the bias, and φ represents the activation function;
[0022] S22. In the network obtained by the trained artificial neural network, h nn (·) represents the mapping function between the output and the input, and at the same time represents the alternative topology obtained through the artificial neural network.
[0023] Preferably, the S3 includes:
[0024] A false data injection attack on the state estimation of an AC power system with complete topology knowledge, where the residual r after the attack a is expressed as:
[0025]
[0026] where z a is the measured value under attack, and x c is the deviation state;
[0027] The attacker uses the topology knowledge to generate an attack vector so that the residual before and after the attack remains unchanged, that is:
[0028] r a = r;
[0029] where r represents the residual before the attack;
[0030] The bad data detector cannot detect the false data injection attack, making the Gaussian distribution simulated by the attack vector conform to the statistical characteristics of the normal data processed by the AC power system state estimation, and obtaining:
[0031]
[0032] where a represents the attack vector, represents the non-linear measurement function of the state estimation;
[0033] Blind false data injection attacks compensate for the lack of grid topology knowledge by inferring an alternative topology, generating stealthy attack vectors, and obtaining the attacked measurements from the inferred alternative topology. as follows:
[0034]
[0035] where a alt is the attack vector generated using the alternative topology, h alt is the alternative topology inferred using numerical methods or AI, and c is the expected state deviation;
[0036] Generate the expected state deviation through a Gaussian distribution and control the amplitude of the injected false data with a scaling factor α to adjust the strength of the attack vector, thereby performing attack strength assessment;
[0037] Use historical metrics and a trained artificial neural network to generate the attacked metrics. Select a subset of each measurement vector that measures the state to be estimated. The subset is injected with a Gaussian distribution to generate the expected state deviation c, resulting in:
[0038]
[0039] where represents the subset of measurement vectors after being attacked, and z x represents the subset of each measurement vector of the estimated state;
[0040] Take the output generated by the trained artificial neural network as the initial attack measurement value, which is filtered by the alternative bad data detector. The initial attack measurement value can be expressed as:
[0041]
[0042] where h nn is the alternative topology implemented by the trained artificial neural network.
[0043] Preferably, S4 includes the following steps:
[0044] S41. Transmit the obtained to the alternative bad data detector to verify the initial bad data;
[0045] S42. When the verification fails, eliminate the initial bad data and generate filtered data. When the verification passes, use the alternative topology h nn embedded in the training network to generate the attacked measurement value to determine the threshold τ p of the alternative bad data detector, and filter through the alternative bad data detector to generate the final attack measurement value z a .
[0046] Preferably, said determining the threshold τ of the substitute bad data detector p includes:
[0047] Set the error threshold for terminating the training process to a value greater than zero;
[0048] Run the training using different error thresholds, and the best training error threshold within this range allows for accurately inferring the topology using an acceptable substitute bad data detector threshold;
[0049] With z x as the input, use h nn to obtain the measured value z generated by the artificial neural network nn :
[0050] z nn = h nn (z x );
[0051] The error vector e between the historical measured value and the measured value generated by the artificial neural network is:
[0052] e = z - z nn ;
[0053] Calculate the standard deviation σ of the error e , expressed as:
[0054]
[0055] where μ e represents the average value of the error vector e, n represents the number of samples, i = 1, 2,..., m, represents the index of the measured value, and e i represents the error at the i-th measurement point;
[0056] Multiply the sum of the squares of σ e by a scalar to obtain the final τ p , expressed as:
[0057]
[0058] where K represents the scalar.
[0059] Preferably, said generating the final attack measurement value z to be injected a includes:
[0060] Calculate the l2 norm between the measured value z nn generated by the artificial neural network and the initial attack measurement value to obtain the initial residual r nn :
[0061]
[0062] Among them, represents the normalized residual error, e min and e max represent the minimum and maximum values of the corresponding vectors respectively;
[0063] The initial residual is normalized using min-max normalization to obtain the normalized residual vector
[0064]
[0065] Test τ p for testing.
[0066] Preferably, the testing of τ p includes: after obtaining , comparing each element with τ p , and if then in the corresponding attack measurement, the true bad data detector may mark an incorrect data Delete this entry from before injection to reduce the chance of detection; repeat the comparison and removal until there is no At this time, it is considered that the attacked measurement value has bypassed the true bad data detector; then the attacker obtains the finally attacked measurement value z a , and the possibility of z a being detected is lower than
[0067] Preferably, in S6, if the bad data fails the statistical test, the existing true bad data detector can detect and eliminate these data. At the same time, the injection of false data can neither introduce additional bad data, nor eliminate the pre-existing bad data, nor create new bad data.
[0068] The present invention also provides a blind false data injection attack system in power grid AC state estimation based on adversarial artificial intelligence, including:
[0069] Data collection module: used to collect historical measurement data from the SCADA system of the smart grid; the data collection module includes a data preprocessing unit for preprocessing the collected historical measurement data to remove noise and outliers;
[0070] Topology inference module: uses an artificial neural network to infer the power grid topology from historical measurement data; the topology inference module adopts a four-hidden-layer feedforward neural network, the activation function is Tan-Sigmoid, the training algorithm is adaptive momentum gradient descent, and each hidden layer has 230 hidden neurons;
[0071] Attack vector generation module: Generate false data attack vectors according to the inferred topological structure;
[0072] Substitute bad data detector module: Used to verify the initial attack measurements using an l2-norm-based substitute bad data detector model; The substitute bad data detector module determines the threshold τ based on the l2-norm by comparing the error between the measurements generated by the artificial neural network and the historical measurements p ;
[0073] Attack injection module: Inject the filtered false data into the AC state estimator.
[0074] Therefore, the present invention adopts the above-mentioned blind false data injection attack method in the AC state estimation of the power grid based on adversarial artificial intelligence, and has the following beneficial effects:
[0075] (1) Regarding the concealment of the attack, a substitute bad data detector is proposed, which is robust to the attack vector and effectively reduces the risk of being detected by the real BDD; In addition, an attack vector generator with a pre-filtering mechanism is adopted to preprocess the generated attack vectors through the substitute BDD, thereby improving the concealment and success rate of the attack;
[0076] (2) An improved evaluation framework is provided, considering the possible bad data in the measurements, and improving the verification of the concealment of false data injection; Considering the possible bad data in the measurements, an improved evaluation framework is provided to verify the concealment of false data injection; The additional bad data caused by false data injection is used as the standard for false data detection to more accurately evaluate the threat;
[0077] (3) The generated attack vectors are pre-filtered through the substitute BDD to remove high-risk measurements, reducing the possibility of the attack vectors being detected by the real BDD; The experimental results show that the filtering effect of the substitute BDD is significant and can effectively reduce the detection risk of the attack; At the same time, by adjusting the attack intensity parameter (such as the scaling factor α), a trade-off can be made between concealment and effectiveness, enabling the attacker to flexibly adjust the attack strategy according to the specific scenario;
[0078] (4) The injected attack vectors can cause significant deviations in the smart grid, affecting the normal operation of the power grid and posing a greater threat to the security and reliability of the power grid.
[0079] The technical solution of the present invention will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings
[0080] Figure 1 It is a flowchart of a blind false data injection attack method in the AC state estimation of the power grid based on adversarial artificial intelligence according to an embodiment of the present invention;
[0081] Figure 2 Generate a flow chart for the attack vector;
[0082] Figure 3 For determining the alternative BDD threshold τ p and a flow chart for pre-filtering the attack vector;
[0083] Figure 4 Filtering rate graph of the alternative BDD for different α;
[0084] Figure 5 Error data rate graph of the true BDD with and without the alternative BDD;
[0085] Figure 6 Residual comparison graph before and after the attack on the IEEE 30-bus system;
[0086] Figure 7 Estimated deviation graph after injection on 114;
[0087] Figure 8 Deviation (%) graph of the estimated and attack measurements compared to the original measurements;
[0088] Figure 9 Residual comparison graph before and after the attack on the IEEE 118-bus system. Detailed implementation manners
[0089] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0090] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0091] As Figures 1-2As shown, the present invention provides a blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence, specifically targeting AC state estimation (ACSE) in smart grids. From the perspectives of attackers and defenders, this method provides more refined stealth verification, including the following steps:
[0092] S1. Collect historical measurement data from the SCADA system of the smart grid and preprocess the collected historical measurement data to remove noise and outliers. The historical measurement data includes measured values of voltage amplitude, voltage angle, active power, and reactive power.
[0093] S2. Use an artificial neural network (ANN) to infer the power grid topology from the historical measurement data, i.e., the mapping function h(·). It can efficiently infer the topology of the power grid from historical measurement data without the attacker having prior knowledge of the specific topology information.
[0094] Assume that the attacker has no information about the topology and only has access to the measurements. Introduce ANN as a topology inference technique because of its well-known function approximation ability. By training the ANN using historical states and measurements, an alternative topology h nn can be found, which is the projection on the measurement plane. The measurement vector is used to infer the mapping between measurements and states using the ANN. Although the mapping inferred by the ANN is not a direct representation of the physical system topology, it effectively captures the relationship between metrics and states. The trained ANN provides an efficient and effective method to generate attack vectors. Therefore, if the attacker can eavesdrop on some of the measurements shared by traditional SCADA or advanced WAMS systems, the ANN is very suitable for inferring the appropriate mapping function from these measurements.
[0095] Step S2 includes the following steps:
[0096] The inference process of the ANN involves taking all parameters as the output measurement values and a subset of the measurement parameters as the input. The output measurement value z includes voltage angle and amplitude, active and reactive power flows, and the generated power. The input measurement value z x includes voltage angle and amplitude.
[0097] If the attacker uses the measurement information to train the ANN, then the resulting output measurement value is:
[0098]
[0099] where z represents the m×1 output, represents the input, w2,…,w n represents the synaptic weights, b represents the bias, and φ represents the activation function.
[0100] The network obtained from the trained ANN, h nn (·) will represent the mapping function between the output and the input, and h nn (·) represents the alternative topology obtained through the ANN.
[0101] S3. Generate false data attack vectors for injection according to the inferred topology.
[0102] A false data injection attack on the state estimation (SE) of an AC power system with complete topology knowledge, where the residual r after the attack a can be expressed as:
[0103]
[0104] where z a is the measured value under attack, and x c is the off-state.
[0105] The attacker uses topology knowledge to generate an attack vector to keep the residual unchanged before and after the attack, that is:
[0106] r a = r;
[0107] where r represents the residual before the attack.
[0108] In this way, the bad data detector BDD cannot detect the false data injection attack. This consistency is possible because the attack vector is carefully designed so that the simulated Gaussian distribution conforms to the statistical characteristics of the normal data processed by the AC power system state estimation (SE). It can be concluded that:
[0109]
[0110] where a represents the attack vector, represents the non-linear measurement function of the state estimation. The essence of the attack vector a is the difference between the true measured value and the false measured value. By injecting this difference, the residual is kept unchanged (i.e., r a = r), thus hiding the attack.
[0111] To achieve equal residuals before and after the attack, both pre-existing topology knowledge and introduced topology knowledge are necessary. If the non-linear model h(·) is fully known, the attack is stealthy.
[0112] Blind false data injection attacks can compensate for the lack of grid topology knowledge by inferring an alternative topology, thus generating stealthy attack vectors. Mathematically, the measured value under attack obtained from the inferred alternative topology can be expressed as follows:
[0113]
[0114] where a alt is an attack vector generated using an alternative topology, h alt is an alternative topology inferred using numerical methods or AI, and c is the expected state deviation.
[0115] The expected state deviation is generated through a Gaussian distribution, and the magnitude of the injected false data is controlled by a scaling factor α to adjust the strength of the attack vector, thereby performing an attack strength assessment.
[0116] Using historical metrics, a trained ANN is utilized to generate attacked metrics. To this end, first, a subset of each measurement vector that measures the state to be estimated is selected and denoted as z x . The subset is injected with a Gaussian distribution to generate the expected state deviation c, resulting in:
[0117]
[0118] where represents the subset of measurement vectors after being attacked.
[0119] The output produced by the trained ANN is used as the initial attack measurement value, denoted as The initial attack measurement value can be expressed as:
[0120]
[0121] where h nn is the alternative topology implemented by the trained ANN.
[0122] S4. Before injecting the attack vector, use an alternative bad data detector (BDD) to filter the false data to reduce the risk of being detected by the real BDD, including the following steps:
[0123] S41. Pass the obtained to the alternative BDD to verify the initial bad data;
[0124] S42. When the verification fails, eliminate the initial bad data and generate filtered data. When the verification passes, use the alternative topology h nn embedded in the training network to generate attacked measurement values to determine the alternative BDD threshold τ p , and filter through the alternative BDD to generate the final attack measurement value z a to be injected.
[0125] The goal of training is to minimize the difference between the prediction and the actual output, ideally reducing this error to zero. However, assuming that the attacker lacks any understanding of the true BDD, therefore, an alternative BDD based on the l2 norm is proposed to initially filter the generated attack measurements to enhance its stealth from the actual BDD. To facilitate this, the terminal training error threshold that the ANN is expected to reach is increased to prevent the ANN from being overtrained. This predetermined error between the observed output and the predicted output is then used to determine τ p . The determination of the target training error threshold is crucial for accurate topology inference. If the terminal training error is too large, the training will be substandard and result in an inaccurate inferred topology. This inaccurate topology will thus produce detectable attack measurements. If the threshold exceeds the initial error, the ANN may not perform any training. On the other hand, if the training goal is set too close to zero, the ANN will be trained to a very high precision, and the difference between the observed and estimated values of the trained network can be negligible, which will make it unsuitable for determining τ p . Therefore, determining the appropriate τ p depends on the selection of the optimal minimum training error of the ANN.
[0126] Provide an alternative BDD model based on the l2 norm for verifying the attacked metric before the injection attack, determining the alternative BDD threshold τ p and the process of filtering the attack vector is as Figure 3 shown.
[0127] Specifically, determining the alternative BDD threshold τ p includes:
[0128] Set the error threshold for terminating the training process to a value greater than zero;
[0129] Run the training using different error thresholds, and the best training error threshold within this range allows for accurately inferring the topology using an acceptable alternative BDD threshold.
[0130] Taking z x as the input, using h nn to obtain the measurement value z nn generated by the artificial neural network:
[0131] z nn = h nn (z x );
[0132] The error vector e between the historical measurement value and the measurement value generated by the artificial neural network is:
[0133] e = z - z nn ;
[0134] Calculate the standard deviation σ of the calculation error e , expressed as:
[0135]
[0136] where μ e represents the average value of the error vector e, n represents the number of samples, i = 1, 2, …, m, represents the index of the measured value, and e i represents the error at the i-th measurement point.
[0137] Multiply the sum of squares of σ e by the scalar K to obtain the final τ p , expressed as:
[0138]
[0139] The setting of the scalar K is to adjust the aggressiveness of the alternative BDD threshold, which is based on the attacker's knowledge of the true BDD from open-source intelligence or domain expertise. In this scheme, the setting of K is less aggressive, so it is more inclined to stealth and effectiveness, where τ p is approximately one-fifth of the found true BDD threshold, and this setting will allow the alternative BDD to perform more stringent filtering than the true BDD.
[0140] Specifically, generate the final attack measurement value z to be injected a S43 includes:
[0141] Calculate the l2 norm between the measurement value z generated by the ANN nn and the initial attack measurement value to obtain the initial residual r nn :
[0142]
[0143] where, represents the normalized residual error, and e min and e max represent the minimum and maximum values of the corresponding vectors respectively.
[0144] Normalize the initial residual using min-max normalization to obtain the normalized residual vector
[0145]
[0146] Test τ p : After obtaining , compare each element with τ p , if Then, in the corresponding attack measurement, the true BDD may mark an incorrect data Therefore, before injection, delete this entry from to reduce the chance of detection; the comparison and removal can be repeated until there is no At this time, it can be considered that the attacked measurement value has bypassed the true BDD; afterwards, the attacker obtains the finally attacked measurement value z a , and z a has a lower probability of being detected than
[0147] S5. Inject the filtered attack vector into the AC state estimator of the smart grid to achieve a stealthy attack.
[0148] S6. Attack stealthiness evaluation requires considering the possible bad data due to sensor failures, communication delays, or other natural reasons before the attack. If these data fail the statistical test, the existing true BDD can detect and eliminate these data. At the same time, the injection of false data can either not introduce additional bad data (the most stealthy), or eliminate pre-existing bad data (less stealthy), or create new bad data (detected, least stealthy). Under this consideration, the stealthiness of the FDI scheme under the true BDD means that there is no change in the result of the true BDD after the attack.
[0149] This method is applicable to smart grid models such as the IEEE30 bus system and the IEEE118 bus system.
[0150] The present invention also provides a blind false data injection attack system in the AC state estimation of the power grid based on adversarial artificial intelligence, including:
[0151] A data collection module: used to collect historical measurement data from the SCADA system of the smart grid; the data collection module includes a data preprocessing unit for preprocessing the collected historical measurement data to remove noise and outliers;
[0152] A topology inference module: using an artificial neural network to infer the power grid topology from historical measurement data; the topology inference module adopts a four-hidden-layer feedforward neural network, the activation function is Tan-Sigmoid, the training algorithm is adaptive momentum gradient descent, and each hidden layer has 230 hidden neurons;
[0153] An attack vector generation module: generating a false data attack vector according to the inferred topology;
[0154] Alternative bad data detector module: used to verify the initial attack measurement values using an l2-norm-based alternative bad data detector (BDD) model; the alternative bad data detector module is based on the l2-norm, and determines the threshold τ by comparing the error between the measurement values generated by the artificial neural network and the historical measurement values p ; by mining the accessed measurement data, increasing the attacker's ability to bypass the true BDD;
[0155] Attack injection module: injects the filtered false data into the AC state estimator.
[0156] Example 1:
[0157] This scheme was evaluated using the IEEE 30-bus system in MATPOWER and the neural network toolbox in MATLAB. 2000 data samples were collected within a week to train the adversarial artificial neural network (ANN). Each data sample included 284 measurement values, including four categories: voltage magnitude and angle, bus active and reactive power injection, branch active and reactive power injection at the receiving end, and branch active and reactive power extraction at the receiving end. The data containing only voltage magnitude and angle measurements was used as the input z x , while the data containing all 284 measurement values was used as the output z of the ANN. The load changes in the test system were simulated using the real load profile during April 2020 in ISO New England. The optimal power flow was solved under the given load profile to obtain the measurement values that serve as the inputs for state estimation (SE) and false data injection (FDI). The scalability of the attack model was verified through implementation on the IEEE 118-bus test system, which has a total of 1216 measurements.
[0158] The topology inference module uses a four-hidden-layer feedforward ANN and the Tan-Sigmoid activation function, trained using adaptive momentum gradient descent, with 230 hidden neurons in each hidden layer. τ p is 1.15, where the value of K is 50. 2000 samples were used to obtain the standard deviation. For the IEEE 118-bus system, τ in the SE of the IEEE 118-bus system p is 3, where the value of K is 32. 2000 samples were used to obtain the standard deviation, and a scaling factor α is applied to c to adjust the attack intensity for evaluation. When verifying the alternative BDD, α is set between 0.5 and 5.0; when evaluating the attack performance under the true BDD, α is set between 0.0001 and 0.8.
[0159] To address the blindness of pre-existing bad data, a post-stack replacement BDD was established. To evaluate the effectiveness of the replacement BDD in filtering high-risk attack vectors, 30 independent experiments were run at each α, and the percentage of "replacement" bad data filtered by the replacement BDD in 284 measurements was obtained. Figure 4 Shows the average percentage of data filtered before injection in 30 experiments, with the filtering rate remaining below 1.1% for all α. This indicates that most of the fake data created by the artificial neural network-based adversarial topology inference and attack generator has been considered by the replacement BDD to have a low chance of being detected after injection. When the attacker increases the injection amplitude with a larger α, the filtering rate also increases slightly.
[0160] In the evaluation of the effectiveness of the stealth ability of filtering attack vectors under real bad data detection (BDD). If the bad data reported by the true bad data detector (BDD) before the attack (e.g., metric #114) is the same as the bad data reported after the attack (again, metric #114), it is inferred that the attack has gone completely unnoticed. Accordingly, experiments were conducted to find the percentage of data belonging to the following three cases:
[0161] The first least stealthy stealth: neither generating additional bad data nor eliminating existing bad data;
[0162] The second less stealthy stealth: eliminating existing bad data, but the number of bad data before and after the attack remains the same;
[0163] The third least stealthy stealth: eliminating pre-existing data and creating additional bad data.
[0164] Among 2,000 sets of manipulation data, the data marked as bad before and after the attack had the same index in 92.14% of the instances indicating the first case. Thus, 92.14% of the attacks were the most stealthy, with the injected attack vectors achieving perfect stealth without eliminating any pre-existing creation of additional bad data. In the second case, although the number of bad data before and after the attack remained the same, among the different measurement results represented by different data metrics after the injection decline, 5.56% of the true BDDs reported bad data. Nevertheless, in this "less stealthy" scenario, the only difference was the location (index) of individual bad data before and after the attack. So, even though these attacks were not technically perfect, the low count of bad data meant that the bad data was likely to be removed directly without raising any alarms in the control room. The third case occurred only in 2.3% of the cases, where the attacks were identified due to additional bad data marked by the true BDDs, indicating the "least stealthy" category. However, even in these last stealth scenarios, the newly added bad data remained below 4. This low count might lead operators to regard it as common bad data rather than identifying it as maliciously injected fake data. Overall, the research results show that the proposed scheme successfully inferred the topology of the network from historical measurements, demonstrating a high degree of effectiveness.
[0165] Based on the above stealthiness, the effectiveness of the alternative BDD was further evaluated by comparing the bad data reported by the true BDDs with and without substitution. The results for different α values are as Figure 5 shown, where the bad data rate refers to the percentage of measurements marked as bad data among 284 measurements at any given moment. When the α value was between 0.0001 and 0.0005, the detection performance of the true BDD remained unchanged before and after removing the initial bad data, showing a similar detection rate of the true BDD without any attacks (the black dashed line shows). As α increased, the alternative BDD began to filter data that might be risky for the attacker, which effectively reduced the detection of larger attack vectors under the true BDD. These results also indicate that the attacker injected more false data into the normal data metrics rather than the pre-existing bad measurement metrics. When α increased further, the difference increased, indicating that the alternative BDD was more effective when the attacker increased the intensity.
[0166] At lower α, the reduced effectiveness of the alternative BDD can be explained by the way τ p is determined. The training error threshold set to terminate the ANN training is not as close to zero as that of a conventionally trained ANN, indicating that the training of the ANN is not perfect. Although a perfectly trained neural network can infer the topology with zero training error from historical measurements, it will set τ p= 0, which will render the filtering by the alternative BDD ineffective. Under such zero tolerance, any generated false data will be filtered out, and the attack model essentially becomes very conservative so as not to inject any false data to avoid detection at all costs. Therefore, the substituted BDD will not activate the filtering for a relatively small α at a slightly increased τ p and will not activate the filtering for a relatively small α at a slightly increased τ
[0167] The last element of the stealth assessment focuses on the potential changes in data quality in a successful stealthy FDIA that successfully evades the detection of true bad data (BDD). This situation corresponds to "the most stealthy"; that is, the bad data metrics reported by the BDD before and after the attack are the same. The research results of conducting attacks in the IEEE 30-bus system are as Figure 6 shown in the figure, which illustrates the residuals (r) before the stealthy attack and the residuals (r a ) after the attack. It is worth noting that these attacks not only successfully passed the BDD, but also in most cases r a is lower than r. The reduction of the residuals indicates that although false data is included, the data quality of the manipulated measurements has been improved compared with the original data. This result shows that the solution of the present invention can reduce the noise level, thereby reducing the possibility of being accidentally detected by the true BDD. Therefore, the attack vectors may seem more trustworthy than the original data and become more challenging when combined with the bad data of the normal system.
[0168] Implement the attack model in the IEEE 118-bus system and conduct residual tests before and after the attack. According to the formula, r and r a are obtained. The residuals after the attack are within the BDD threshold, reflecting the bypass of the BDD. In addition, these attacks not only successfully bypassed the true BDD, but also in most cases, r a is also lower than r, as Figure 9 shown.
[0169] After the stealth analysis, the impact analysis will further evaluate the degree of deviation caused by the stealthy FDI. Since the attacked measurements in the FDI scheme will still be subject to the data processing of the SE, the impact will be analyzed by comparing the differences between the SE inputs (attacked measurements) and the SE outputs (estimated measurements) in the stealthy FDI.
[0170] Through the 30 experiments that have been conducted, first compare Figure 7 the original pre-attack measurements at different α in a and the average deviation of z a relative to the original pre-attack measurement value z. For better visibility, the results are plotted on a logarithmic scale, with the diagonal highlighted as a tie, while z a and The deviation is distributed on both sides of the diagonal. It can be observed that many estimates are before the diagonal, indicating that the deviation injected after the estimation is amplified. The most notable area is the upper left part of the figure: the attack vectors in this area have a small injection amplitude, which can reduce the chance of being detected at SE; at the same time, the attack vectors in this area may have a greater impact on the subsequent process because the SE estimation is used as decision support in the energy management system.
[0171] Meanwhile, some cases were also studied where only one false data was injected into the measurement to determine its impact. Specifically, an error of -0.061 was injected into Measurement 114 (the voltage angle of Bus - 2), and the deviation generated in is as Figure 8 shown. Significant spikes can be observed in Measurements 115 - 142 of (the voltage angles of all remaining buses). By injecting the error within only one meter, the proposed scheme can cause a significant deviation 10 to 1000 times larger than the ground truth in the entire 30 - bus system. These results confirm the substantial impact of the proposed scheme and the low chance of being detected.
[0172] Through experimental verification on the IEEE 30 - bus system and 118 - bus system, it is proved that this attack model is not only applicable to small - scale power grids but can also be successfully extended to larger - scale power grids, indicating that the proposed scheme has good scalability.
[0173] Therefore, the present invention adopts the above - mentioned blind false data injection attack method in the AC state estimation of power grids based on adversarial artificial intelligence. By using the function approximation ability of ANN, it infers the topology of the power grid from historical measurement data, which requires the attacker to know the specific topology information of the power grid in advance, reduces the threshold of the attack, and at the same time improves the adaptability and effectiveness of the attack.
[0174] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements do not make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence, characterized in that, It includes the following steps: S1. Collect historical measurement data from the SCADA system of the smart grid and preprocess the collected historical measurement data to remove noise and outliers; S2. Use an artificial neural network to infer the power grid topology from the historical measurement data to obtain the mapping function h(·); S3. Generate a false data attack vector for injection according to the inferred topology; S4. Before injecting the attack vector, use an alternative bad data detector to filter the false data to reduce the risk of being detected by the real bad data detector; S5. Inject the filtered attack vector into the AC state estimator of the smart grid to achieve a stealthy attack; S6. Conduct an assessment of attack stealth, considering possible bad data due to sensor failures, communication delays or other natural causes before the attack.
2. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 1, characterized in that: The historical measurement data includes measured values of voltage magnitude, voltage angle, active power and reactive power.
3. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 2, characterized in that: The artificial neural network is a four-hidden-layer feedforward neural network, the activation function is Tan-Sigmoid, the training algorithm is adaptive momentum gradient descent, and each hidden layer has 230 hidden neurons.
4. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 3, characterized in that, S2 includes the following steps: S21. Take all parameters as the output measurement values and a subset of the measurement parameters as the input. The output measurement value z includes the voltage angle and amplitude, active and reactive power flows, and the generated power. The input measurement value z x includes the voltage angle and amplitude. If an attacker uses the measurement information to train an artificial neural network, the resulting output measurement value is: where z represents an m×1 output, represents the input, w2, …, w b represent synaptic weights, b represents the bias, and φ represents the activation function; In the network obtained by the trained artificial neural network, h nn (·) represents the mapping function between the output and the input, and at the same time represents the alternative topology obtained through the artificial neural network.
5. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 4, characterized in that, S3 includes: A false data injection attack on the state estimation of an AC power system with complete topological knowledge, where the residual r after the attack a can be expressed as: where z a is the measured value under attack, and x c is the deviation state; The attacker uses topology knowledge to generate an attack vector so that the residual remains unchanged before and after the attack, that is: r a =r; where r represents the residual before the attack; The bad data detector cannot detect the injection attack of false data, making the Gaussian distribution simulated by the attack vector conform to the statistical characteristics of the normal data processed by the AC power system state estimation, and obtaining: where a represents an attack vector, represents the non-linear measurement function of state estimation; Blind false data injection attacks compensate for the lack of grid topology knowledge by inferring an alternative topology, generating stealthy attack vectors, and obtaining the attacked measurements from the inferred alternative topology as follows: where a alt is an attack vector generated using an alternative topology, h alt is an alternative topology inferred using numerical methods or AI, and c is the expected state deviation; Generate an expected state deviation through the Gaussian distribution, and control the amplitude of the injected false data through the scaling factor α to adjust the intensity of the attack vector, so as to conduct an assessment of the attack intensity; Generate an attacked measurement using the historical measurement and the trained artificial neural network, select a subset of each measurement vector that measures the state to be estimated, and the subset is injected with a Gaussian distribution to generate an expected state deviation c, and obtain: Among them, represents a subset of the measurement vectors after being attacked, and z x represents a subset of each measurement vector of the estimated state; The output generated by the trained artificial neural network is used as the initial attack measurement value, which is filtered by the surrogate bad data detector. The initial attack measurement value is expressed as: where h nn is an alternative topology implemented by the trained artificial neural network.
6. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 5, characterized in that S4 includes the following steps: S41. Transfer the obtained to the alternative bad data detector to verify the initial bad data; S42. When the verification fails, eliminate the initial bad data and generate filtered data. When the verification passes, pass through the alternative topology h embedded in the training network nn for generating the attacked measurement values to determine the threshold τ of the alternative bad data detector p , and filter through the alternative bad data detector to generate the final attack measurement value z to be injected a .
7. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 6, characterized in that, The determination of the threshold τ of the alternative bad data detector p comprises: Set the error threshold for terminating the training process to a value greater than zero; Run the training with different error thresholds, and the best training error threshold within this range allows the topology to be accurately inferred using an acceptable alternative bad data detector threshold; With z x as input, use h nn to obtain the measured value z generated by the artificial neural network nn : z nn = h nn (z x ); The error vector e between the historical measurement value and the measurement value generated by the artificial neural network is: e = z - z nn ; Calculate the standard deviation σ of the calculation error e , which is expressed as: where, μ e represents the average value of the error vector e, n represents the number of samples, i = 1, 2, …, m, represents the index of the measured value, and e i represents the error at the i-th measurement point; Multiply the sum of the squares of σ e by a scalar to obtain the final τ p , which is expressed as: where K represents a scalar.
8. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 7, characterized in that, Generating the final attack measurement value z to be injected a comprises: Calculate the e2 norm between the measurement value z generated by the artificial neural network and the initial attack measurement value to obtain the initial residual r nn nn : Among them, represents the normalized residual error, e min and e max represent the minimum and maximum values of the corresponding vectors respectively; Normalize the initial residual using min-max normalization to obtain a normalized residual vector Test τ p Conduct a test.
9. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 8, characterized in that, The test on τ p includes: after obtaining , comparing each element with τ p , and if then in the corresponding attack measurement, the true bad data detector may mark an incorrect data delete this entry from before injection to reduce the chance of detection; repeat the comparison and removal until there is no At this time, it is considered that the attacked measurement value has bypassed the true bad data detector; then the attacker obtains the finally attacked measurement value z a , and the possibility of z a being detected is lower than 10. A blind false data injection attack method in power grid AC state estimation based on adversarial artificial intelligence according to claim 9, characterized in that: In S6, if the bad data fails the statistical test, the existing real bad data detector can detect and eliminate this data. At the same time, the injection of false data can neither introduce additional bad data, nor eliminate pre-existing bad data, nor create new bad data.