Power CPS backdoor security defense method and system based on multi-cluster fusion optimization

Through the multi-cluster fusion optimization method, a backdoor security defense strategy for the power CPS intrusion detection system was constructed, which solved the problems of complexity of power CPS data characteristics and insufficient automation design, and achieved efficient backdoor attack defense and robustness improvement.

CN120378188APending Publication Date: 2025-07-25WENZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510639494.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing power CPS intrusion detection system faces the threat of backdoor attacks, and the existing methods cannot effectively deal with the multi-dimensional spatio-temporal characteristics of power CPS data, and lack of automated design capabilities, resulting in degradation of detection performance and insufficient system security.

Method used

The multi-cluster fusion optimization method is adopted, and the multi-cluster fusion fitness function is set by constructing the normal and backdoor training data set, and the multi-cluster fusion fitness function is set, and the initial population is generated using discrete variable-length encoding, and the selection, crossover and mutation operations are performed. The clustering method and its weight combination are optimized to generate the optimal defense strategy, eliminate the backdoor samples and improve the robustness of the model.

Benefits of technology

The automatic generation of backdoor security defense of the power CPS intrusion detection model is realized, reducing the success rate of backdoor attacks, and improving the robustness and detection performance of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378188A_ABST
    Figure CN120378188A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power CPS backdoor security defense method and system based on multi-cluster fusion optimization, and the method comprises the steps: taking a combination mode of a plurality of clustering methods and the weight of the combination mode as decision variables for coding; performing clustering analysis and backdoor sample elimination on an output activation value of the power CPS poisoning training data set in the last full connection layer in the deep learning intrusion detection system through coding instantiation, and training an intrusion detection model based on the training data set with the backdoor sample eliminated; and by taking the difference value between the benign sample detection accuracy after backdoor elimination and the benign sample detection accuracy when no backdoor is implanted as a constraint condition and the backdoor attack success rate as a fitness function, carrying out optimization iteration through coding selection, crossover and mutation operations to obtain an optimal clustering method for backdoor defense and a weight combination thereof. According to the method, automatic generation of the power CPS intrusion detection model backdoor security defense strategy is realized, and the backdoor robustness of power CPS intrusion detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intrusion detection and deep learning model backdoor security defense in the field of smart grid information security, and particularly relates to a power CPS backdoor security defense method and system based on multi-clustering fusion optimization. Background Art

[0002] In recent years, with the continuous construction and development of smart grids, ubiquitous power Internet of Things, and energy Internet, the interaction mechanism between power networks and information networks has become increasingly complex, and modern power systems have evolved into a typical Cyber Physical System (CPS). Power CPS integrates various technologies such as advanced communication, control, and automation. By effectively integrating power infrastructure and underlying communication networks, it can achieve global monitoring, intelligent perception, real-time control, and flexible scheduling of the power grid. However, in the context of highly integrated cyber-physical systems, power CPS also faces increasingly severe network security threats. The frequent malicious network attack incidents in recent years have sounded the alarm for the network security of the power system.

[0003] In recent years, deep learning has been widely applied in the field of power CPS intrusion detection. However, the research field of power CPS intrusion detection based on deep learning still faces the following severe challenges: the designed and online-deployed deep learning models face increasingly severe security threats such as adversarial attacks and backdoor attacks. These security threats not only have extremely strong concealment and can evade the pre-deployed detection links, but also usually lead to a serious decline in the detection performance and robustness of intrusion detection systems, making it difficult to meet the requirements of normal security operation, and even directly causing huge hazards such as system paralysis and permanent damage.

[0004] With the expanding application of deep learning in the field of intrusion detection systems, intrusion detection systems based on deep learning are also facing an increasingly severe threat of backdoor attacks, but the related research progress is still in its infancy. The research progress mainly focuses on the field of network traffic intrusion detection in traditional Internet and Internet of Things. Typical backdoor attacks include BadNets, Blended, Sig, label inversion attack, model poisoning attack, backdoor attack based on generative adversarial network, etc. These attacks result in high attack success rate, relatively high average escape rate, decreased accuracy and F1 score, and the misclassification of poisoned data as clean data. Due to the obvious differences in the data characteristics of power CPS itself from those of images, network traffic, and natural gas pipelines, the existing research methods for backdoor attacks and defenses in image classification, network traffic intrusion detection systems, and industrial Internet of Things attack detection cannot be directly transplanted to the field of power CPS intrusion detection. Therefore, it is urgent to study new methods for improving the backdoor robustness and backdoor security defense in the multi-classification intrusion detection application scenario of power CPS, so as to ensure the safe operation of the power CPS intrusion detection system even after being attacked by backdoors.

[0005] Cluster analysis can identify hidden backdoor attack samples in intrusion detection systems through unsupervised learning without prior label information, providing a reliable analysis basis for the backdoor security defense of intrusion detection systems. However, the existing single clustering method is difficult to adapt to the multi-dimensional spatio-temporal characteristics of power CPS data. In addition, the existing multiple clustering combination strategies rely heavily on manual experience to set relevant parameters and lack the ability of automated design. Therefore, there is an urgent need to develop a backdoor security defense strategy based on automatic clustering combination optimization in the field of power CPS. Summary of the Invention

[0006] The purpose of the present invention is to provide a power CPS backdoor security defense method and system based on multi-cluster fusion optimization in view of the deficiencies of the prior art.

[0007] The purpose of the present invention is achieved through the following technical solutions: In the first aspect of the embodiments of the present invention, a power CPS backdoor security defense method based on multi-cluster fusion optimization is provided, including the following steps:

[0008] S1: Construct a normal training dataset D tr and a test dataset D te for power CPS data, implant backdoor data into the training dataset D tr to construct a backdoor training dataset B tr , and then construct a backdoor test dataset B te based on the test dataset D te ;

[0009] S2: Based on the normal training dataset D tr perform normal training on the intrusion detection model of the power CPS, and based on the normal test dataset D te evaluate the normal intrusion detection performance metrics, and then based on the backdoor training dataset B tr implant a backdoor into the intrusion detection model, and based on the backdoor test dataset B te evaluate the backdoor performance metrics;

[0010] S3: Set multiple first parameters, construct the constraint conditions and the multi-clustering fusion fitness function, and then according to the first parameters, use discrete variable-length coding to encode the clustering method to be optimized and its weight combination to generate the initial population P gen ;

[0011] S4: Based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the population P gen ;

[0012] S5: Record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , and based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen ;

[0013] S6: Combine the parent population P gen and the offspring population Q gen , and select the top NP individuals that meet the constraint conditions and have better fitness to form a new parent population P gen , where NP represents the population size;

[0014] S7: Judge whether gen reaches the maximum iteration number Gen. If so, set the current iteration number gen = gen + 1, and use the parent population P gen as the new generation parent population P gen , and repeat steps S4 to S6; if not, obtain the individual in the population P gen that meets the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy;

[0015] S8: Perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance metrics.

[0016] Furthermore, the specific steps of step S1 include:

[0017] Construct the normal training dataset D based on the power CPS data tr and the test dataset D te , after completing the construction of the training dataset D tr and the test dataset D te , based on each data feature of the normal training dataset D tr , perform min-max normalization. Among them, the calculation formula of min-max normalization is shown in formula (1):

[0018]

[0019] In the formula, x t ′ represents the value of the t-th feature after min-max normalization; x t represents the value of the t-th feature of the original data; x t,max represents the maximum value of the t-th feature of the data feature Fe tr in the normal training dataset D tr ; x t,min represents the minimum value of the t-th feature of the data feature Fe tr in the normal training dataset D tr ; after completing the min-max normalization of the normal training dataset D tr , then perform min-max normalization on the normal test dataset D tr based on the maximum and minimum values in the data feature Fe tr of the normal training dataset D te ; among them, the normal training dataset D tr is composed of the data feature Fe tr used for training and its corresponding class label La tr , and the normal test dataset D te is composed of the data feature Fe te used for testing and its corresponding class label La te ;

[0020] In addition, generate BadNets backdoor attack samples based on the existing bad network backdoor attack methods. Among them, the specific steps for generating BadNets backdoor samples are as follows: First, screen all the data with the class label u from the normal training dataset D tr and the normal test dataset D te ; Second, select the same feature fc from the normal training dataset D tr and the normal test dataset D te , and tamper with the feature values of all the selected data with the class label u. Among them, the feature fc = [fc1,…,fc h ,…,fcH , fc1 represents the first feature selected for generating BadNets backdoor attack samples, and fc h represents the h-th feature selected for generating BadNets backdoor attack samples, and fc H represents the H-th feature selected for generating BadNets backdoor attack samples; again, mark all the labels of the backdoor attack samples after tampering with the data features as normal, where 1 ≤ u ≤ U, and U represents the total number of categories of power CPS data; then, directly add the backdoor attack samples obtained from the normal training dataset D tr to D tr to form the backdoor training dataset B tr ; finally, the backdoor attack samples obtained from the normal test dataset D te are separately used to form the backdoor test dataset B te .

[0021] Furthermore, the specific steps of step S2 include:

[0022] Based on the normal training dataset D tr perform normal training on the intrusion detection model of the power CPS, and based on the normal test dataset D te evaluate the normal intrusion detection performance metrics, where the normal intrusion detection performance metrics include accuracy, recall, precision, and F1-score, and their calculation formulas are shown in formulas (2) - (5) as follows:

[0023]

[0024] In the formula, TP represents the number of normal data samples predicted as normal, TN represents the number of abnormal data samples predicted as abnormal, FP represents the number of abnormal data samples mispredicted as normal, and FN represents the number of normal data samples mispredicted as abnormal; then, based on the backdoor training dataset B tr implant a backdoor into the intrusion detection model, and based on the backdoor test dataset B te evaluate the backdoor performance metrics, where the accuracy in the normal intrusion detection performance metrics is used as the baseline accuracy Bs for constructing the constraint conditions in the subsequent optimization process acc ; then, after implanting the backdoor into the intrusion detection model based on the backdoor attack training set B tr , obtain the backdoor performance metrics through the backdoor test dataset B te , where the backdoor performance metrics include the accuracy, recall, precision, F1-score shown in formulas (2) - (5), and the backdoor attack success rate, and the calculation formula of the backdoor attack success rate is shown in formula (6) as follows:

[0025]

[0026] In the formula, BASR represents the success rate of the backdoor attack.

[0027] Furthermore, the first parameter includes the maximum number of iterations Gen, the population size NP, the crossover probability Pc, the mutation probability Pm, and the classification accuracy deviation threshold Th.

[0028] Furthermore, the constraint condition and the calculation formula of the multi-clustering fusion fitness function are shown in Formula (7):

[0029]

[0030] In the formula, obj represents the multi-clustering fusion fitness function; min(BASR) represents minimizing the success rate of the backdoor attack; s.t. represents the corresponding constraint condition; p i,acc represents the intrusion detection accuracy rate of the i-th individual in the population P gen

[0031] Furthermore, according to the first parameter, the clustering method to be optimized and its weight combination are encoded by using discrete variable-length coding to generate the initial population P gen , specifically including:

[0032] Randomly generate a population P containing NP individuals gen , where P gen ={p i , i = 1, 2,..., NP}, p i represents the encoding of the i-th individual, and each individual represents a combination of a clustering method and its weight for backdoor defense, and its encoding is specifically represented as p i =[L i , M i,1 , C i,1 ,..., M i,j , C i,j ,..., M i,Li , C i,Li , where L i represents the total number of clustering methods used in the i-th individual, M i,j represents the clustering method adopted by the j-th encoding of the i-th individual, C i,j represents the clustering weight of M i,j , 1 ≤ j ≤ L i ​, where the set of clustering methods corresponding to the individual coding is: {1: HDBSCAN, 2: DBSCAN, 3: K-Means, 4: MeanShift, 5: OPTICS, 6: Spectral Clustering, 7: Gaussian Mixture, 8: MiniBatch K-Means, 9: Brich, 10: Agglomerative Clustering, 11: Affinity Propagation, 12: SOS}, where HDBSCAN represents a hierarchical density-based spatial clustering of applications with noise method, and its code is 1; DBSCAN represents a density-based spatial clustering of applications with noise method, and its code is 2; K-Means represents the K-means clustering method, and its code is 3, where K represents the number of clusters; MeanShift represents the mean shift clustering method, and its code is 4; OPTICS represents the ordered point clustering method, and its code is 5; Spectral Clustering represents the spectral clustering method, and its code is 6; Gaussian Mixture represents the Gaussian mixture model clustering method, and its code is 7; MiniBatch K-Means represents the mini-batch K-means clustering method, and its code is 8; Brich represents a hierarchical structure-based balanced iterative reduction and clustering method, and its code is 9; AgglomerativeClustering represents the agglomerative hierarchical clustering method, and its code is 10; Affinity Propagation represents the affinity propagation clustering method, and its code is 11; SOS represents the random outlier selection clustering method, and its code is 12; among them, each clustering method is represented by the codes 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12 within the set of clustering methods; the total number of clustering methods L i , the clustering method M i,j and the clustering weight C i,j are specifically valued as shown in formula (8):

[0033]

[0034] In the formula, Randint represents the random integer generation function, and Randint(1, 12) represents randomly generating an integer from 1 to 12; Random represents the random number generation function, and Random(0, 1) represents randomly generating a real number from 0 to 1.

[0035] Furthermore, the step S4 specifically includes the following sub-steps:

[0036] S41: First, for the population P genFor each individual in it, determine its encoding as the corresponding clustering method and its weight combination; then, based on the backdoor training dataset B tr Train the intrusion detection model of the power CPS to obtain an intrusion detection model implanted with a backdoor. Then, use the backdoor training dataset B tr Input all samples with the label of the normal class in B into the intrusion detection model implanted with the backdoor to obtain the activation values of each sample in the last fully connected layer; secondly, expand the activation value of each sample into a one-dimensional vector; and perform a principal component analysis dimensionality reduction operation on the activation values of all samples according to formula (9):

[0037]

[0038] In the formula, PCA represents principal component analysis, V represents the data matrix composed of the activation values of each sample, V′ represents the sample activation value matrix after PCA dimensionality reduction, v and v′ respectively represent the specific activation values before and after PCA dimensionality reduction, m represents the m-th sample, and n represents the n-th activation value;

[0039] S42: Based on the population P gen For each individual p in it i Cluster all the sample activation value vectors after PCA dimensionality reduction according to the corresponding clustering method and its weight combination encoded by p. The specific calculation process is shown in formula (10):

[0040]

[0041] In the formula, A i represents the clustering result, i represents the i-th individual p in the population i , L i represents the number of types of clustering methods in the individual encoding; M i,j (V′) represents all class labels obtained by clustering the dimensionality-reduced activation values using the j-th clustering method. Among them, the class label with the smallest proportion in the sample is marked as 0, that is, the sample implanted with the backdoor, and the remaining samples are marked as 1, that is, the samples not implanted with the backdoor; represents the result after setting the corresponding clustering weight for the class label obtained by the j-th clustering method; represents the comprehensive result of all weighted sample clustering result labels, and selects the result of the highest probability class after weighting as the final activation clustering result;

[0042] S43: According to the class label of each sample after activation clustering, perform data cleaning on the backdoor training dataset B tr Remove the samples with the sample class label of 0 after clustering to obtain the cleaned dataset B clean , and use the cleaned dataset B cleanRetrain the intrusion detection model for the power CPS; after the training is completed, then based on the normal test dataset D te Test the intrusion detection model to obtain the intrusion detection performance metrics for normal samples, namely accuracy, recall, precision, and F1 score; finally, based on the backdoor test dataset B te Evaluate the backdoor robustness of the intrusion detection model to obtain the backdoor attack success rate;

[0043] S44: Save all individuals p in the population i The intrusion detection performance metrics and backdoor attack success rate of normal samples.

[0044] Furthermore, the specific calculation principle of the principal component analysis dimensionality reduction operation includes the following steps:

[0045] (1) Standardize the activation value matrix and calculate the covariance matrix containing the relationships between different features. Among them, the standardization calculation formula is shown in formula (11), and the covariance matrix calculation formula is shown in formula (12):

[0046]

[0047] In the formula, represents the sample activation value of the nth feature of the mth sample after standardization; v m,n represents the sample activation value of the nth feature of the mth sample; μ n represents the feature mean of the nth feature; σ n represents the standard deviation of the nth feature; Con represents the covariance matrix; M represents the total number of samples; W represents the sample activation value matrix of M rows and k columns after standardization, where k represents the number of features; W T represents the transpose of the sample activation value matrix;

[0048] (2) Perform eigenvalue decomposition on the covariance matrix to obtain eigenvalues and eigenvectors, and its calculation formula is shown in formula (13):

[0049] Con = XΛX T (13)

[0050] In the formula, X represents the eigenvector matrix; X T represents the transpose of the eigenvector matrix; Λ represents the diagonal matrix;

[0051] (3) Sort the eigenvalues and select the first r principal component eigenvalues, where r represents the dimension after dimensionality reduction;

[0052] (4) Remap the original samples to the low-dimensional principal component feature space to obtain the samples after dimensionality reduction, and its calculation formula is shown in formula (14):

[0053] Z = WX r (14)

[0054] Wherein, Z represents the activated value matrix of M rows and r columns after dimensionality reduction; W represents the sample activated value matrix of M rows and k columns after standardization; X r represents the matrix of k rows and r columns composed of the first r eigenvectors.

[0055] Furthermore, record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , which specifically includes the following sub-steps:

[0056] S51: First, randomly select two individuals from the population P gen , denoted as Ind1 and Ind2; secondly, perform uniform crossover operation based on the selected individuals Ind1 and Ind2, compare the coding dimensions between the two individuals, and generate multiple random decimals pc within the range of [0, 1] and with the same length as the longer coding individual according to the coding individual with the longer dimension le for the uniform crossover operation of each dimension of the individual coding, where 1 ≤ le ≤ LT, and LT represents the maximum coding dimension. If the pc le corresponding to the le-th dimension is greater than the crossover probability Pc, then perform crossover and swap of the coding of Ind1 and Ind2 in the le-th dimension until all positions of the shorter coding individual are completed for crossover; thirdly, judge whether the total number L i of clustering methods used by the two individuals after crossover changes. If the total number L i of clustering methods increases, then randomly generate new clustering methods and weight coding after coding; if the total number L i of clustering methods decreases, then perform truncation operation on the coding at the positions exceeding the total number L i of clustering methods, that is, directly delete the exceeding clustering methods and weight coding, so as to obtain the offspring individuals child1 and child2;

[0057] S52: Perform mutation operations on the offspring individuals child1 and child2, and generate multiple random decimals pm within the range of [0, 1] and with the same length as the coding dimension LT according to the dimensions of the two offspring individuals le for the mutation operation of each dimension of the individual coding. If the pm le corresponding to the le-th dimension is greater than the mutation probability Pm, then perform mutation in the le-th dimension, and randomly generate a new coding from the coding range of the corresponding dimension to replace the original coding, that is, for the total number L i of clustering methods, randomly generate a real number within the range of (1, 12) to replace the original coding length L i; For clustering method M i,j , randomly generate a real number in the range of (1, 12) to replace the original clustering method M i,j ; For clustering weight C i,j , randomly generate a decimal number in the range of (0, 1) to replace the original clustering weight C i,j ; Again, determine whether the total number of clustering methods L used by the two individuals after the mutation operation has changed. If the total number of clustering methods L i increases, randomly generate new clustering method and weight encodings after encoding; if the total number of clustering methods L i decreases, truncate the encoding at the position exceeding the total number of clustering methods L i , that is, directly delete the exceeding clustering method and weight encodings, so as to obtain the offspring individuals child1 and child2 after the mutation operation; finally, repeat the above selection, crossover and mutation operations until the total number of individuals in the offspring population Q i reaches NP; after generating the offspring population Q gen , perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen according to the calculation method in step S4. gen

[0058] The second aspect of the embodiments of the present invention provides a power CPS backdoor security defense system based on multi-clustering fusion optimization, which is used to implement the above-mentioned power CPS backdoor security defense method based on multi-clustering fusion optimization. The system includes:

[0059] A dataset construction module, which is used to construct a normal training dataset D tr and a test dataset D te based on power CPS data, and implant backdoor data into the training dataset D tr to construct a backdoor training dataset B tr , and then construct a backdoor test dataset B te based on the test dataset D te ;

[0060] An initial performance index acquisition module, which is used to normally train the intrusion detection model of the power CPS based on the normal training dataset D tr , evaluate the normal intrusion detection performance index based on the normal test dataset D te , implant a backdoor into the intrusion detection model based on the backdoor training dataset B tr , and evaluate the backdoor performance index based on the backdoor test dataset B te ;

[0061] The population initialization module is used to set multiple first parameters, construct constraint conditions and a multi-clustering fusion fitness function, and then encode the clustering method to be optimized and its weight combination using discrete variable-length coding according to the first parameters to generate the initial population P gen ;

[0062] The constraint handling and fitness evaluation module is used to perform constraint handling and fitness evaluation on all individuals in the population P tr based on the backdoor training dataset B te and the backdoor test dataset B gen ;

[0063] The offspring population generation module is used to record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , and perform constraint handling and fitness evaluation on all individuals in the offspring population Q tr based on the backdoor training dataset B te and the backdoor test dataset B gen ;

[0064] The elite individual screening module is used to merge the parent population P gen and the offspring population Q gen , and screen out the top NP individuals that meet the constraint conditions and have better fitness to form a new parent population P gen ;

[0065] The iteration judgment module is used to judge whether gen reaches the maximum iteration number Gen. If so, set the current iteration number gen = gen + 1, and use the parent population P gen as the new generation parent population P gen , and repeat steps S4 to S6; if not, obtain the individual in the population P gen that meets the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy;

[0066] The power CPS intrusion detection backdoor defense module is used to perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance index.

[0067] The beneficial effects of the present invention are as follows: Through the technology of automatic optimization of multi-clustering fusion, the present invention realizes the automatic generation of the backdoor security defense strategy of the power CPS intrusion detection model; in addition, compared with the existing methods, the backdoor attack success rate of the power CPS deep learning intrusion detection model obtained by the present invention is lower, improving the backdoor robustness of the power CPS intrusion detection model. Brief Description of the Drawings

[0068] Figure 1 is the flowchart of the power CPS backdoor security defense method based on multi-clustering fusion optimization of the present invention;

[0069] Figure 2 is the schematic diagram of the corresponding relationship between the randomly generated individual codes and their actual meanings in step S3 of the present invention;

[0070] Figure 3 is the example diagram of the uniform crossover operation of two parent individuals in step S5 of the present invention;

[0071] Figure 4 is the example diagram of the mutation operation of the offspring individuals in step S5 of the present invention;

[0072] Figure 5 is the schematic diagram of the intelligent power grid intrusion detection system designed based on the neural network model of the present invention;

[0073] Figure 6 is the schematic diagram of the comparison of the accuracy experimental results between the backdoor defense method of the present invention and various single-clustering backdoor defense methods;

[0074] Figure 7 is the schematic diagram of the comparison of the recall experimental results between the backdoor defense method of the present invention and various single-clustering backdoor defense methods;

[0075] Figure 8 is the schematic diagram of the comparison of the precision experimental results between the backdoor defense method of the present invention and various single-clustering backdoor defense methods;

[0076] Figure 9 is the schematic diagram of the comparison of the F1-score experimental results between the backdoor defense method of the present invention and various single-clustering backdoor defense methods;

[0077] Figure 10 is the schematic diagram of the comparison of the backdoor attack success rate (BASR) experimental results between the backdoor defense method of the present invention and various single-clustering backdoor defense methods;

[0078] Figure 11 is the schematic diagram of the structure of the power CPS backdoor security defense system based on multi-clustering fusion optimization of the present invention. Detailed implementation manners

[0079] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0080] See Figure 1 , the power CPS backdoor security defense method based on multi-clustering fusion optimization of the present invention specifically includes the following steps:

[0081] S1: Construct a normal training dataset D tr and a test dataset D te from power CPS data, and implant backdoor data into the training dataset D tr to construct a backdoor training dataset B tr , and then construct a backdoor test dataset B te based on the test dataset D te .

[0082] Specifically, to construct a normal training dataset D tr and a test dataset D te from power CPS data, after the construction of the training dataset D tr and the test dataset D te is completed, perform min-max normalization on each data feature of the normal training dataset D tr , where the calculation formula of min-max normalization is shown in formula (1):

[0083]

[0084] In the formula, x t ′ represents the value of the t-th feature after min-max normalization; x t represents the value of the t-th feature of the original data; x t,max represents the maximum value of the t-th feature in the data feature Fe tr of the normal training dataset D tr ; x t,min represents the minimum value of the t-th feature in the data feature Fe tr of the normal training dataset D tr ; after the min-max normalization of the normal training dataset D tr is completed, then perform min-max normalization on the normal test dataset D tr based on the maximum and minimum values in the data feature Fe tr of the normal training dataset D te ; where the normal training dataset D tr is composed of the data feature Fe tr used for training and its corresponding class label La tr , and the normal test dataset D te is composed of the data feature Fe te used for testing and its corresponding class label La te .

[0085] In addition, BadNets backdoor attack samples are generated based on existing bad network backdoor attack methods. The specific steps for generating BadNets backdoor samples are as follows: First, all data with the selected class label u are filtered from the normal training dataset D tr and the normal test dataset D te . Second, the same feature fc in the normal training dataset D tr and the normal test dataset D te is selected, and the feature values of all the selected data with class label u are tampered with. Among them, the feature fc = [fc1,…,fc h ,…,fc H , where fc1 represents the first feature selected for generating BadNets backdoor attack samples, fc h represents the h-th feature selected for generating BadNets backdoor attack samples, and fc H represents the H-th feature selected for generating BadNets backdoor attack samples. Third, all the backdoor attack sample labels after data feature tampering are marked as normal, where 1 ≤ u ≤ U, and U represents the total number of all categories of power CPS data. Then, the backdoor attack samples obtained from the normal training dataset D tr are directly added to D tr to form the backdoor training dataset B tr . Finally, the backdoor attack samples obtained from the normal test dataset D te are separately formed into the backdoor test dataset B te .

[0086] In this embodiment, the ratio of the power CPS data in the normal training dataset D tr to the test dataset D te is 8:2. It should be understood that the normal training dataset and the test dataset can also be divided according to other ratios according to the actual needs of power CPS intrusion detection model training and testing, such as 7:3, etc. In addition, the total number of data features Fe tr used for training and the data features Fe te used for testing are both 128, that is, the number of data features is 128, 1 ≤ t ≤ 128; the class label La tr and the class label La te are both one of the 37 categories of power CPS data; that is, the total number of all categories of power CPS data is U = 37. In addition, exemplarily, the backdoor attack method based on existing data poisoning to implant backdoors used in this embodiment is the BadNets backdoor attack method. Among them, the backdoor training dataset B tr obtained from the normal training dataset D trThe specific steps are as follows: First, select all samples with labels 15, 16, and 17 in the normal training dataset D tr to generate backdoor samples using the remote trip instruction samples of intelligent electronic devices R1, R2, and R3; Second, set the three-phase voltage amplitudes measured by the backdoor samples on intelligent electronic devices R1, R2, R3, and R4 to 0, that is, the feature fc = [fc1,…,fc h ,…,fc H = [2, 4, 6, 31, 33, 35, 60, 63, 65, 89, 91, 93], that is, tamper with the 2nd, 4th, 6th, 31st, 33rd, 35th, 60th, 63rd, 65th, 89th, 91st, and 93rd features of the power CPS data. Among them, the 2nd, 4th, and 6th features represent the A, B, and C three-phase voltages measured by the power CPS intelligent electronic device R1, the 31st, 33rd, and 35th features represent the A, B, and C three-phase voltages measured by the power CPS intelligent electronic device R2, the 60th, 63rd, and 65th features represent the A, B, and C three-phase voltages measured by the power CPS intelligent electronic device R3, and the 89th, 91st, and 93rd features represent the A, B, and C three-phase voltages measured by the power CPS intelligent electronic device R4; Third, randomly select 20% of the data volume of the three types of attack samples in the normal training dataset D tr for backdoor training; Then, set the labels of all backdoor samples to normal, that is, the labels are all 1; Then, add the generated backdoor attack training data to the normal training dataset D tr to obtain the backdoor training dataset B tr . Finally, the backdoor attack samples obtained from the normal test dataset D te are separately formed into the backdoor test dataset B te .

[0087] S2: Based on the normal training dataset D tr normally train the intrusion detection model of the power CPS, and evaluate the normal intrusion detection performance metrics based on the normal test dataset D te . Then, implant a backdoor into the intrusion detection model based on the backdoor training dataset B tr and evaluate the backdoor performance metrics based on the backdoor test dataset B te .

[0088] Specifically, based on the normal training dataset D tr normally train the intrusion detection model of the power CPS, and evaluate the normal intrusion detection performance metrics based on the normal test dataset D te . The normal intrusion detection performance metrics include accuracy, recall, precision, and F1 score, and their calculation formulas are shown in Formulas (2) to (5):

[0089]

[0090] Wherein, TP represents the number of normal data samples predicted as normal, TN represents the number of abnormal data samples predicted as abnormal, FP represents the number of abnormal data samples mispredicted as normal, and FN represents the number of normal data samples mispredicted as abnormal; then, based on the backdoor training dataset B tr Implant a backdoor into the intrusion detection model, and based on the backdoor test dataset B te Evaluate the backdoor performance metrics, where the accuracy rate in the normal intrusion detection performance metrics is used as the benchmark accuracy rate Bs for constructing constraint conditions in the subsequent optimization process acc ; Then, after implanting a backdoor into the intrusion detection model based on the backdoor attack training set B tr Obtain the backdoor performance metrics through the backdoor test dataset B te The backdoor performance metrics include the accuracy rate, recall rate, precision rate, F1 score, and backdoor attack success rate (Backdoor Attack Success Rate, BASR) shown in formulas (2) to (5), where the calculation formula for the backdoor attack success rate is as shown in formula (6):

[0091]

[0092] Wherein, BASR represents the backdoor attack success rate.

[0093] In this embodiment, the detection accuracy rate Bs of benign samples of the intrusion detection model of the power CPS under the training of the normal training dataset D tr is 0.9205; the detection accuracy rate Bd of benign samples under the training of the backdoor training dataset B acc is 0.9215; the backdoor performance metric BASR obtained from the backdoor test dataset B tr is 0.9940. acc te te The backdoor performance metric BASR is 0.9940.

[0094] S3: Set multiple first parameters, construct constraint conditions and a multi-clustering fusion fitness function, and then encode the clustering method to be optimized and its weight combination using discrete variable-length coding according to the first parameters to generate an initial population P gen .

[0095] Furthermore, the first parameters include the maximum number of iterations Gen, the population size NP, the crossover probability Pc, the mutation probability Pm, and the classification accuracy deviation threshold Th.

[0096] In this embodiment, the maximum number of iterations of the population Gen = 20, the population size NP = 20, the crossover probability Pc = 0.7, the mutation probability Pm = 0.5, and the classification accuracy constraint threshold Th = 0.03 are set. It should be noted that the above first parameters can be set according to the actual situation.

[0097] Furthermore, the constraint conditions and the calculation formula for evaluating the multi-clustering fusion fitness function are shown in Formula (7):

[0098]

[0099] In the formula, obj represents the multi-clustering fusion fitness function; min(BASR) represents minimizing the backdoor attack success rate; s.t. represents the corresponding constraint conditions; p i,acc represents the intrusion detection accuracy of the i-th individual in the population P gen .

[0100] Furthermore, according to the first parameters, the clustering method to be optimized and its weight combination are encoded using discrete variable-length coding to generate the initial population P gen , specifically including: randomly generating a population P gen containing NP individuals, where P gen = {p i , i = 1, 2,..., NP}, p i represents the encoding of the i-th individual, and each individual represents a combination of a clustering method and its weight for backdoor defense. Its encoding is specifically represented as p i = [L i , M i,1 , C i,1 ,..., M i,j , C i,j ,..., M i,Li , C i,Li , where L i represents the total number of clustering methods used in the i-th individual, M i,j represents the clustering method adopted by the j-th encoding of the i-th individual, and C i,j represents the clustering weight of M i,j , and 1 ≤ j ≤ L i, where the set of clustering methods corresponding to the individual coding is: {1: HDBSCAN, 2: DBSCAN, 3: K-Means, 4: MeanShift, 5: OPTICS, 6: Spectral Clustering, 7: GaussianMixture, 8: MiniBatch K-Means, 9: Brich, 10: Agglomerative Clustering, 11: AffinityPropagation, 12: SOS}, where HDBSCAN represents a hierarchical density-based spatial clustering of applications with noise method, and its code is 1; DBSCAN represents a density-based spatial clustering of applications with noise method, and its code is 2; K-Means represents the K-means clustering method, and its code is 3, where K represents the number of clusters; MeanShift represents the mean shift clustering method, and its code is 4; OPTICS represents the ordered point clustering method, and its code is 5; Spectral Clustering represents the spectral clustering method, and its code is 6; Gaussian Mixture represents the Gaussian mixture model clustering method, and its code is 7; MiniBatch K-Means represents the mini-batch K-means clustering method, and its code is 8; Brich represents the balanced iterative reduction and clustering method based on the hierarchical structure, and its code is 9; Agglomerative Clustering represents the agglomerative hierarchical clustering method, and its code is 10; AffinityPropagation represents the affinity propagation clustering method, and its code is 11; SOS represents the random outlier selection clustering method, and its code is 12; among them, each clustering method is represented by the codes 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12 within the set of clustering methods; the total number of clustering methods L i , the clustering method M i,j and the clustering weight C i,j are specifically valued as shown in formula (8):

[0101]

[0102] In the formula, Randint represents the random integer generation function, and Randint(1, 12) represents randomly generating an integer from 1 to 12; Random represents the random number generation function, and Random(0, 1) represents randomly generating a real number from 0 to 1.

[0103] Exemplarily, in this embodiment, Figure 2 a schematic diagram of the correspondence between the randomly generated individual coding and the actual meaning of the coding is given, where the individual coding is [4, 4, 0.6532, 2, 0.8824, 3, 0.2714, 5, 0.6982].

[0104] S4: Based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the population P. Specifically, it includes the following sub-steps: gen

[0105] S41: First, for each individual in the population P gen , determine its encoding as the corresponding clustering method and its weight combination; then, based on the backdoor training dataset B tr train the intrusion detection model of the power CPS to obtain the intrusion detection model implanted with the backdoor. Then, input all samples with the label of the normal class in the backdoor training dataset B tr into the intrusion detection model implanted with the backdoor to obtain the activation value of each sample in the last fully connected layer; secondly, expand the activation value of each sample into a one-dimensional vector; and perform principal component analysis (PCA) dimensionality reduction operation on the activation values of all samples according to formula (9):

[0106]

[0107] In the formula, PCA represents principal component analysis, V represents the data matrix composed of the activation values of each sample, V′ represents the sample activation value matrix after PCA dimensionality reduction, v and v′ respectively represent the specific activation values before and after PCA dimensionality reduction, m represents the mth sample, and n represents the nth activation value.

[0108] S42: Based on each individual p gen in the population P i (i = 1, 2,..., NP), cluster all sample activation value vectors after PCA dimensionality reduction according to the corresponding clustering method and its weight combination in the encoding. The specific calculation process is shown in formula (10):

[0109]

[0110] In the formula, A i represents the clustering result, i represents the ith individual p i in the population, L i represents the number of types of clustering methods in the individual encoding; M i,j (V′) represents all class labels obtained by clustering the dimensionality-reduced activation values using the jth clustering method. Among them, the class label with the smallest proportion in the sample is marked as 0, that is, the sample implanted with the backdoor, and the remaining samples are marked as 1, that is, the samples not implanted with the backdoor; C i,j (M i,j (V′)) is It represents the result after setting the corresponding clustering weights for the class labels obtained by the j-th clustering method. It represents the comprehensive labeled results of all weighted sample clusterings, and selects the result of the highest probability class after weighting as the final activated clustering result.

[0111] S43: According to the class labels of each sample after activated clustering, for the backdoor training dataset B tr Perform data cleaning, and remove the samples with the class label of 0 after clustering processing to obtain the cleaned dataset B clean , and use the cleaned dataset B clean to retrain the intrusion detection model of the power CPS; after the training is completed, then based on the normal test dataset D te test the intrusion detection model to obtain the intrusion detection performance metrics of normal samples, namely accuracy, recall, precision, and F1 score; finally, based on the backdoor test dataset B te evaluate the backdoor robustness of the intrusion detection model to obtain the backdoor attack success rate.

[0112] S44: Save the intrusion detection performance metrics and backdoor attack success rate of all normal samples of the individuals p i in the population.

[0113] Furthermore, the specific calculation principle of the principal component analysis (PCA) dimensionality reduction operation includes the following steps:

[0114] (1) Standardize the activation value matrix and calculate the covariance matrix containing the relationships between different features. Among them, the standardization calculation formula is as shown in formula (11), and the covariance matrix calculation formula is as shown in formula (12):

[0115]

[0116] In the formula, represents the sample activation value of the n-th feature of the m-th sample after standardization; v m,n represents the sample activation value of the n-th feature of the m-th sample; μ n represents the feature mean of the n-th feature; σ n represents the standard deviation of the n-th feature; Con represents the covariance matrix; M represents the total number of samples; W represents the sample activation value matrix of M rows and k columns after standardization, where k represents the number of features; W T represents the transpose of the sample activation value matrix.

[0117] (2) Perform eigenvalue decomposition on the covariance matrix to obtain eigenvalues and eigenvectors, and its calculation formula is as shown in formula (13):

[0118] Con = XΛXT (13)

[0119] In the formula, X represents the eigenvector matrix; X T represents the transpose of the eigenvector matrix; Λ represents a diagonal matrix, where the diagonal elements are eigenvalues, and the eigenvalues are λ1, λ2, …, λ k , λ1 represents the first eigenvalue, λ2 represents the second eigenvalue, λ k represents the k-th eigenvalue, λ1 ≥ λ2 ≥ … ≥ λ k .

[0120] (3) Sort the eigenvalues, and select the first r principal component eigenvalues, where r represents the dimension after dimensionality reduction.

[0121] (4) Remap the original samples into the low-dimensional principal component feature space to obtain the samples after dimensionality reduction, and its calculation formula is shown in formula (14):

[0122] Z = WX r (14)

[0123] In the formula, Z represents the activation value matrix of M rows and r columns after dimensionality reduction; W represents the sample activation value matrix of M rows and k columns after standardization; X r represents the matrix of k rows and r columns composed of the first r eigenvectors.

[0124] S5: Record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , and perform constraint processing and fitness evaluation on all individuals in the offspring population Q tr based on the backdoor training dataset B te and the backdoor test dataset B gen .

[0125] Furthermore, record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , which specifically includes the following sub-steps:

[0126] S51: First, randomly select two individuals from the population P gen , denoted as Ind1 and Ind2; secondly, perform uniform crossover operations based on the selected individuals Ind1 and Ind2, compare the coding dimensions between the two individuals, and generate multiple random decimals pc within the range of [0, 1] and with the same length as the coding dimension LT according to the coding individual with the longer dimension le for the uniform crossover operation of each dimension of the individual coding, where 1 ≤ le ≤ LT, and LT represents the maximum coding dimension. If the pc corresponding to the le-th dimension leIf it is greater than the crossover probability Pc, then the encodings of Ind1 and Ind2 are cross-swapped in the le-th dimension until all positions of the individual with the shorter encoding in terms of dimension are completed for crossover; again, determine whether the total number L of clustering methods used by the two individuals after crossover i has changed. If the total number L of clustering methods i increases, then randomly generate new clustering methods and weight encodings after encoding; if the total number L of clustering methods i decreases, then truncate the encoding at the positions exceeding the total number L of clustering methods i , that is, directly delete the excess clustering methods and weight encodings, so as to obtain the offspring individuals child1 and child2.

[0127] In this embodiment, the encodings of two randomly selected individuals Ind1 and Ind2 are respectively: Ind1 = [4, 1, 0.2000, 2, 0.5000, 5, 0.8000, 12, 0.3000], Ind2 = [3, 7, 0.4000, 6, 0.5000, 8, 0.3000]; the specific operation process of generating the offspring individuals child1 and child2 is as Figure 3 shown. The generated crossover factor pc le is [0.7500, 0.8320, 0.4120, 0.3200, 0.0500, 0.6520, 0.8000, 0.5520, 0.6000]; in addition, the encodings of the two offspring individuals child1 and child2 are respectively: child1 = [3, 7, 0.2000, 2, 0.5000, 5, 0.3000], child2 = [4, 1, 0.4000, 6, 0.5000, 8, 0.8000, 1, 0.6000].

[0128] S52: Perform mutation operations on the offspring individuals child1 and child2. Generate multiple random decimals pm in the range of [0, 1] and with the same dimension as the encoding dimension LT according to the dimensions of the two offspring individuals for the mutation operation of each dimension of the individual encoding. If the pm corresponding to the le-th dimension le is greater than the mutation probability Pm, then perform mutation in the le-th dimension. Randomly generate a new encoding from the encoding range of the corresponding dimension to replace the original encoding, that is, for the total number L of clustering methods le , randomly generate a real number in the range of (1, 12) to replace the original encoding length L i ; for the clustering method M i , randomly generate a real number in the range of (1, 12) to replace the original clustering method M i,j ; for the clustering weight C i,j ; for the clustering weight C i,j, randomly generate a decimal number within the range (0, 1) to replace the original clustering weight C i,j ; Next, determine the total number of clustering methods L used by the two individuals after the mutation operation i Whether it has changed. If the total number of clustering methods L i increases, randomly generate new clustering methods and weight encodings after encoding; if the total number of clustering methods L i decreases, truncate the encoding at the position exceeding the total number of clustering methods L i , that is, directly delete the exceeding clustering methods and weight encodings, so as to obtain the offspring individuals child1 and child2 after the mutation operation; finally, repeat the above selection, crossover and mutation operations until the total number of individuals in the offspring population Q gen reaches NP; after generating the offspring population Q gen , perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen according to the calculation method in step S4.

[0129] In this embodiment, the process of performing the mutation operation on the offspring individuals child1 and child2 is as Figure 4 shown. The mutation factor 1 pm le generated during the mutation operation is [0.3500, 0.4400, 0.5120, 0.7500, 0.0500, 0.1520, 0.2000], and the mutation factor 2 pm le ′ is [0.4500, 0.8620, 0.4120, 0.3200, 0.0500, 0.6570, 0.0020, 0.3520, 0.6000]; the generated offspring individuals child1 and child2 after mutation are respectively: child1 = [3, 7, 0.5000, 10, 0.5000, 5, 0.7000], child2 = [4, 2, 0.4000, 6, 0.5000, 9, 0.8000, 1, 0.3000].

[0130] S6: Combine the parent population P gen and the offspring population Q gen , and select the top NP individuals that meet the constraint conditions and have better fitness to form a new parent population P gen , where NP represents the population size.

[0131] In this embodiment, all individuals in the generated offspring population Q gen have been subjected to constraint processing and fitness evaluation according to the constraint processing and fitness evaluation process described in step S4.

[0132] S7: Determine whether gen has reached the maximum number of iterations Gen. If so, set the current number of iterations gen = gen + 1, and use the parental population P gen as the new generation of parental population P gen , and repeat steps S4 to S6; if not, obtain the individual in population P gen that satisfies the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy.

[0133] In this embodiment, the encoding of the individual that satisfies the constraint conditions and has the optimal fitness value is [4, 5, 0.6252, 1, 0.9076, 2, 0.1975, 7, 0.8969].

[0134] S8: Perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance metrics.

[0135] In this embodiment, the obtained intrusion detection performance metrics after backdoor defense are as follows: the accuracy rate is 0.9215, the recall rate is 0.9132, the precision rate is 0.9191, the F1 score is 0.9157, and the BASR is 0.0000. The comparison of the performance metrics of the backdoor defense method of the present invention with those of various single-clustering backdoor defense methods is as Figures 6 to 10 shown, among which, the comparison result of the accuracy rate is as Figure 6 shown, the comparison result of the recall rate is as Figure 7 shown, the comparison result of the precision rate is as Figure 8 shown, the comparison result of the F1 score is as Figure 9 shown, and the comparison result of the backdoor attack success rate BASR is as Figure 10 shown; through the comparative analysis of the experimental results of the technology of the present invention and various single-clustering backdoor defense methods, it can be seen that the present invention performs excellently in performance metrics such as intrusion detection accuracy rate, recall rate, precision rate, and F1 score compared with single-clustering backdoor defense methods. In addition, the backdoor defense performance is outstanding, and the present invention can effectively improve the backdoor robustness of the intrusion detection model.

[0136] In summary, through the above technical solutions, the present invention encodes the combination method and its weight of multiple clustering methods as decision variables, and performs clustering analysis and backdoor sample removal on the output activation values of the last fully connected layer in the deep learning intrusion detection system for the poisoned training data set in the power CPS through encoding instantiation. Based on the training data set with backdoor samples removed, the intrusion detection model is retrained, so as to realize the backdoor security defense of the intrusion detection model for the power CPS. In addition, the difference between the detection accuracy of the benign samples after backdoor removal and the detection accuracy of the benign samples without backdoor implantation is used as a constraint condition, and the backdoor attack success rate is used as a fitness function. Then, through encoding selection, crossover and mutation operations, optimization iteration is carried out to obtain the optimal clustering method and its weight combination for backdoor defense. The present invention realizes the automatic generation of the backdoor security defense strategy of the power CPS intrusion detection model and improves the backdoor robustness of the power CPS intrusion detection model. Compared with the prior art, the present invention combines multiple clustering methods and sets clustering weights for them, improving the backdoor security defense level of the power CPS intrusion detection model, effectively reducing the backdoor attack success rate, improving the backdoor robustness of the intrusion detection model, and expanding the engineering application in the technical field of intrusion detection and improvement of the backdoor security robustness performance of the deep learning model in the field of smart grid information security. Through formulas (1) to (14) combined with steps S1 to S8 of the present invention, the five performance indicators (i.e., accuracy rate, recall rate, precision rate, F1 score and BASR) finally obtained perform better.

[0137] It is worth mentioning that the present invention also provides a power CPS backdoor security defense system based on multi-clustering fusion optimization for implementing the power CPS backdoor security defense method based on multi-clustering fusion optimization in the above embodiments. As Figure 11 shown, the system includes a data set construction module 10, an initial performance index acquisition module 20, a population initialization module 30, a constraint processing and fitness evaluation module 40, a progeny population generation module 50, an elite individual screening module 60, an iteration judgment module 70, and a power CPS intrusion detection backdoor defense module 80.

[0138] In this embodiment, the data set construction module 10 is used to construct a normal training data set D tr and a test data set D te based on the power CPS data, implant backdoor data into the training data set D tr to construct a backdoor training data set B tr , and then construct a backdoor test data set B te based on the test data set D te .

[0139] In this embodiment, the initial performance index acquisition module 20 is used to obtain the initial performance indexes based on the normal training data set D trThe intrusion detection model of the power CPS is normally trained, and based on the normal test data set D te Evaluate the normal intrusion detection performance metrics, and then based on the backdoor training data set B tr Inject a backdoor into the intrusion detection model, and based on the backdoor test data set B te Evaluate the backdoor performance metrics.

[0140] In this embodiment, the population initialization module 30 is used to set a plurality of first parameters, construct constraint conditions and a multi-clustering fusion fitness function, and then according to the first parameters, encode the clustering method to be optimized and its weight combination by using discrete variable-length coding to generate an initial population P gen 。

[0141] In this embodiment, the constraint processing and fitness evaluation module 40 is used to perform constraint processing and fitness evaluation on all individuals in the population P tr based on the backdoor training data set B te and the backdoor test data set B gen 。

[0142] In this embodiment, the offspring population generation module 50 is used to record the iteration number gen, and perform selection, crossover and mutation operations on the individuals in the population P gen to generate an offspring population Q gen , and perform constraint processing and fitness evaluation on all individuals in the offspring population Q tr based on the backdoor training data set B te and the backdoor test data set B gen 。

[0143] In this embodiment, the elite individual screening module 60 is used to merge the parent population P gen and the offspring population Q gen , and screen out the top NP individuals that meet the constraint conditions and have better fitness to form a new parent population P gen 。

[0144] In this embodiment, the iteration judgment module 70 is used to judge whether gen reaches the maximum iteration number Gen. If so, set the current iteration number gen = gen + 1, and use the parent population P gen as the new generation parent population P gen , and repeat steps S4 to S6; if not, obtain the individual in the population P gen that meets the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy.

[0145] In this embodiment, the power CPS intrusion detection backdoor defense module 80 is used to perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance index.

[0146] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disk, or optical disc that can store program codes.

[0147] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A power CPS backdoor security defense method based on multi-clustering fusion optimization, characterized in that, It includes the following steps: S1: Construct a normal training dataset D based on the power CPS data tr and the test dataset D te , and implant backdoor data into the training dataset D tr to construct a backdoor training dataset B tr , and then construct a backdoor test dataset B based on the test dataset D te ; te ; S2: Based on the normal training dataset D tr Perform normal training on the intrusion detection model of the power CPS, and based on the normal test dataset D te Evaluate the normal intrusion detection performance metrics, and then based on the backdoor training dataset B tr Implant a backdoor into the intrusion detection model, and based on the backdoor test dataset B te Evaluate the backdoor performance metrics; S3: Set multiple first parameters, construct a constraint condition and a multi-clustering fusion fitness function, and then, according to the first parameters, use discrete variable-length coding to encode the clustering method to be optimized and its weight combination to generate an initial population P gen ; S4: Based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the population P gen ; S5: Record the iteration number gen, and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , and based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen ; S6: Combine the parental population P gen with the offspring population Q gen and select the top NP individuals that meet the constraint conditions and have better fitness to form a new parental population P gen , where NP represents the population size; S7: Determine whether gen has reached the maximum number of iterations Gen. If so, set the current number of iterations gen = gen + 1, and use the parental population P gen as the new generation of parental population P gen , and repeat steps S4 to S6; if not, obtain the individual in population P gen that satisfies the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy; S8: Perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance indicators.

2. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, wherein The specific steps of step S1 include: Construct the normal training dataset D based on the power CPS data tr and the test dataset D te , after completing the construction of the training dataset D tr and the test dataset D te , based on each data feature of the normal training dataset D tr perform min-max normalization, where the calculation formula of min-max normalization is shown in formula (1): where x t ′ represents the value of the t-th feature after min-max normalization; x t represents the value of the t-th feature of the original data; x t,max represents the maximum value of the t-th feature in the normal training dataset D tr data feature Fe tr ; x t,min represents the minimum value of the t-th feature in the normal training dataset D tr data feature Fe tr ; After completing the min-max normalization of the normal training dataset D tr , then based on the normal training dataset D tr data feature Fe tr in the maximum and minimum values for the min-max normalization of the normal test dataset D te ; Among them, the normal training dataset D tr is composed of the data feature Fe tr used for training and its corresponding class label La tr , and the normal test dataset D te is composed of the data feature Fe te used for testing and its corresponding class label La te . In addition, BadNets backdoor attack samples are generated based on existing bad network backdoor attack methods. The specific steps for generating BadNets backdoor samples are as follows: First, all data with the selected class label u are filtered from the normal training dataset D tr and the normal test dataset D te . Second, the same feature fc in the normal training dataset D tr and the normal test dataset D te is selected to tamper with the feature values of all the selected data with class label u, where the feature fc = [fc1,…,fc h ,…,fc H , fc1 represents the first feature selected for generating BadNets backdoor attack samples, fc h represents the h-th feature selected for generating BadNets backdoor attack samples, and fc H represents the H-th feature selected for generating BadNets backdoor attack samples. Third, all the backdoor attack sample labels after data feature tampering are marked as normal, where 1 ≤ u ≤ U, and U represents the total number of all classes of power CPS data. Then, the backdoor attack samples obtained from the normal training dataset D tr are directly added to D tr to form the backdoor training dataset B tr . Finally, the backdoor attack samples obtained from the normal test dataset D te are separately formed into the backdoor test dataset B te .

3. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, wherein The specific steps of step S2 include: Based on the normal training dataset D tr Perform normal training on the intrusion detection model of the power CPS, and based on the normal test dataset D te Evaluate the normal intrusion detection performance metrics, where the normal intrusion detection performance metrics include accuracy, recall, precision, and F1-score, and their calculation formulas are shown in Formulas (2) to (5): Wherein, TP represents the number of normal data samples predicted to be normal, TN represents the number of abnormal data samples predicted to be abnormal, FP represents the number of abnormal data samples mispredicted as normal, and FN represents the number of normal data samples mispredicted as abnormal; and then based on the backdoor training dataset B tr implant a backdoor into the intrusion detection model, and based on the backdoor test dataset B te evaluate the backdoor performance metrics, where the accuracy in the normal intrusion detection performance metrics is used as the benchmark accuracy Bs for constructing the constraint conditions in the subsequent optimization process acc ; then, after implanting a backdoor into the intrusion detection model based on the backdoor attack training set B tr obtain the backdoor performance metrics through the backdoor test dataset B te where the backdoor performance metrics include the accuracy, recall rate, precision rate, F1 score, and backdoor attack success rate shown in formulas (2) to (5), and the calculation formula for the backdoor attack success rate is shown in formula (6): In the formula, BASR represents the backdoor attack success rate.

4. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, characterized in that The first parameters include the maximum number of iterations Gen, the population size NP, the crossover probability Pc, the mutation probability Pm, and the classification accuracy deviation threshold Th.

5. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, characterized in that The constraint condition and the calculation formula of the multi-cluster fusion fitness function are shown in formula (7): In the formula, obj represents the multi-cluster fusion fitness function; min(BASR) represents minimizing the backdoor attack success rate; s.t. represents the corresponding constraint condition; p i,acc represents the population P gen is the intrusion detection accuracy rate of the i-th individual in 6. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, characterized in that, Encoding the clustering method to be optimized and its weight combination by using discrete variable length coding according to the first parameter to generate an initial population P gen , which specifically includes: Randomly generate a population P containing NP individuals gen , where P gen = {p i , i = 1, 2, …, NP}, p i represents the encoding of the i-th individual, and each individual represents a combination of a clustering method for backdoor defense and its weight. Its encoding is specifically represented as p i = [L i , M i,1 , C i,1 , …, M i,j , C i,j , …, M i,Li , C i,Li , where L i represents the total number of clustering methods used in the i-th individual, M i,j represents the clustering method adopted by the j-th encoding of the i-th individual, C i,j represents the clustering weight of M i,j , and 1 ≤ j ≤ L i , where the set of clustering methods corresponding to the individual encoding is: {1: HDBSCAN, 2: DBSCAN, 3: K-Means, 4: MeanShift, 5: OPTICS, 6: Spectral Clustering, 7: Gaussian Mixture, 8: MiniBatch K-Means, 9: Brich, 10: Agglomerative Clustering, 11: Affinity Propagation, 12: SOS}, where HDBSCAN represents a hierarchical density-based spatial clustering of applications with noise method, and its encoding is 1; DBSCAN represents a density-based spatial clustering of applications with noise method, and its encoding is 2; K-Means represents the K-means clustering method, and its encoding is 3, where K represents the number of clusters; MeanShift represents the mean shift clustering method, and its encoding is 4; OPTICS represents the ordered point clustering method, and its encoding is 5; SpectralClustering represents the spectral clustering method, and its encoding is 6; Gaussian Mixture represents the Gaussian mixture model clustering method, and its encoding is 7; MiniBatch K-Means represents the mini-batch K-means clustering method, and its encoding is 8; Brich represents a hierarchical structure-based balanced iterative reduction and clustering method, and its encoding is 9; Agglomerative Clustering represents the agglomerative hierarchical clustering method, and its encoding is 10; Affinity Propagation represents the affinity propagation clustering method, and its encoding is 11; SOS represents the random outlier selection clustering method, and its encoding is 12; among them, each clustering method is represented by the encodings 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12 within the set of clustering methods; the total number of clustering methods L i , the clustering method M i,j and the clustering weight C i,j are specifically valued as shown in formula (8): In the formula, Randint represents the random integer generation function, Randint(1, 12) represents randomly generating an integer from 1 to 12; Random represents the random number generation function, Random(0, 1) represents randomly generating a real number from 0 to 1.

7. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, characterized in that The specific steps of step S4 include the following sub-steps: S41: First, for each individual in population P gen , determine its encoding as the corresponding clustering method and its weight combination; then, based on the backdoor training dataset B tr , train the intrusion detection model of the power CPS to obtain the implanted-backdoor intrusion detection model, and then input all samples with the label of the normal class in the backdoor training dataset B tr into the implanted-backdoor intrusion detection model to obtain the activation value of each sample in the last fully-connected layer; secondly, expand the activation value of each sample into a one-dimensional vector; and perform the principal component analysis dimensionality reduction operation on the activation values of all samples according to formula (9): In the formula, PCA represents the principal component analysis, V represents the data matrix composed of the activation values of each sample, V′ represents the sample activation value matrix after PCA dimensionality reduction, v and v′ respectively represent the specific activation values before and after PCA dimensionality reduction, m represents the mth sample, and n represents the nth activation value; S42: Based on the population P gen for each individual p i in it, perform clustering on all sample activation value vectors after PCA dimensionality reduction according to the corresponding clustering method and its weight combination. The specific calculation process is shown in formula (10): Where A i represents the clustering result, and i represents the i-th individual p in the population i , and L i represents the number of clustering methods in the individual coding; M i,j (V′) represents all class labels obtained by clustering the dimensionality-reduced activation values using the j-th clustering method. Among them, the class with the smallest proportion in the sample is labeled as 0, that is, the sample implanted with the backdoor, and the remaining samples are labeled as 1, that is, the samples not implanted with the backdoor; C i,j (M i,j (V′)) is the result after setting the corresponding clustering weights for the class labels obtained by the j-th clustering method; represents the comprehensive labeled result of all weighted sample clustering results, and selects the result of the class with the highest probability after weighting as the final activation clustering result; S43: According to the class labels of each sample after activation clustering for the backdoor training dataset B tr perform data cleaning, and after clustering, remove the samples with the sample class label of 0 to obtain the cleaned dataset B clean , and use the cleaned dataset B clean to retrain the intrusion detection model of the power CPS; after the training is completed, then based on the normal test dataset D te test the intrusion detection model to obtain the intrusion detection performance metrics of normal samples, namely accuracy, recall, precision, and F1 score; finally, based on the backdoor test dataset B te evaluate the backdoor robustness of the intrusion detection model to obtain the backdoor attack success rate; S44: Save the intrusion detection performance metrics and backdoor attack success rate of all individuals p in the population i for normal samples.

8. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 7, characterized in that The specific calculation principle of the principal component analysis dimensionality reduction operation includes the following steps: (1) Standardize the activation value matrix and calculate the covariance matrix containing the relationships between different features. Among them, the standardization calculation formula is shown in formula (11), and the covariance matrix calculation formula is shown in formula (12): In the formula, represents the sample activation value of the n-th feature of the m-th sample after standardization; v m,n represents the sample activation value of the n-th feature of the m-th sample; μ n represents the feature mean of the n-th feature; σ n represents the standard deviation of the n-th feature; Con represents the covariance matrix; M represents the total number of samples; W represents the sample activation value matrix of M rows and k columns after standardization, where k represents the number of features; W T represents the transpose of the sample activation value matrix; (2) Perform eigenvalue decomposition on the covariance matrix to obtain the eigenvalues and eigenvectors, and its calculation formula is shown in formula (13): Con = X Λ X T (13) where X represents the feature vector matrix; X T represents the transpose of the feature vector matrix; Λ represents the diagonal matrix; (3) Sort the eigenvalues and select the first r principal component eigenvalues, where r represents the dimension after dimensionality reduction; (4) Remap the original samples to the low-dimensional principal component feature space to obtain the samples after dimensionality reduction, and its calculation formula is shown in formula (14): Z = WX r (14) Wherein, Z represents an activation value matrix of M rows and r columns after dimensionality reduction; W represents a sample activation value matrix of M rows and k columns after standardization; X r represents a matrix of k rows and r columns composed of the first r eigenvectors.

9. The power CPS backdoor security defense method based on multi-clustering fusion optimization according to claim 1, wherein Record the iteration count gen and perform selection, crossover, and mutation operations on the individuals in population P gen to generate the offspring population Q gen , which specifically includes the following sub-steps: S51: First, randomly select two individuals from the population P gen and denote them as Ind1 and Ind2. Secondly, perform uniform crossover operation based on the selected individuals Ind1 and Ind2. Compare the coding dimensions between the two individuals, and generate multiple random decimals pc le ranging from 0 to 1 and having the same length as the longer coding individual for the uniform crossover operation of each dimension of the individual coding, where 1 ≤ le ≤ LT, and LT represents the maximum coding dimension. If the pc le corresponding to the le-th dimension is greater than the crossover probability Pc, then swap the codings of Ind1 and Ind2 in the le-th dimension until all positions of the shorter coding individual are completed for crossover. Thirdly, determine whether the total number L i of clustering methods used by the two individuals after crossover has changed. If the total number L i of clustering methods increases, then randomly generate new clustering methods and weight codings after coding; If the total number of clustering methods L i decreases, the encoding is truncated at the position exceeding the total number of clustering methods L i That is, the exceeding clustering methods and weight encodings are directly deleted to obtain the offspring individuals child1 and child2; S52: Perform mutation operations on the offspring individuals child1 and child2, and generate multiple random decimals pm that are the same as the coding dimension LT and in the range of [0, 1] according to the dimensions of the two offspring individuals le For the mutation operation of each dimension of the individual coding, if the pm corresponding to the le-th dimension le is greater than the mutation probability Pm, then mutate in the le-th dimension, and randomly generate a new code from the coding range of the corresponding dimension to replace the original code. That is, for the total number of clustering methods L i , randomly generate a real number in the range of (1, 12) to replace the original coding length L i ; for the clustering method M i,j , randomly generate a real number in the range of (1, 12) to replace the original clustering method M i,j ; for the clustering weight C i,j , randomly generate a decimal in the range of (0, 1) to replace the original clustering weight C i,j ; again, determine whether the total number of clustering methods L used by the two individuals after the mutation operation i has changed. If the total number of clustering methods L i increases, then randomly generate new clustering methods and weight codings after encoding; If the total number L of clustering methods i decreases, truncate the encoding at the position exceeding the total number L of clustering methods i , that is, directly delete the exceeding clustering methods and weight encodings, so as to obtain the offspring individuals child1 and child2 that have completed the mutation operation; finally, repeat the above selection, crossover and mutation operations until the total number of individuals in the offspring population Q gen reaches NP; after generating the offspring population Q gen , perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen according to the calculation method in step S4.

10. A power CPS backdoor security defense system based on multi-clustering fusion optimization is used to implement the power CPS backdoor security defense method based on multi-clustering fusion optimization described in any one of claims 1-9, and is characterized in that The system includes: A dataset construction module for constructing a normal training dataset D based on power CPS data tr and a test dataset D te , and implanting backdoor data into the training dataset D tr to construct a backdoor training dataset B tr , and then constructing a backdoor test dataset B based on the test dataset D te ; te ; An initial performance metric acquisition module, which is used to perform normal training on the intrusion detection model of the power CPS based on the normal training dataset D tr and evaluate the normal intrusion detection performance metrics based on the normal test dataset D te Then, based on the backdoor training dataset B tr implant a backdoor into the intrusion detection model and evaluate the backdoor performance metrics based on the backdoor test dataset B te ; The population initialization module is used to set multiple first parameters, construct constraint conditions and a multi-clustering fusion fitness function, and then encode the clustering method to be optimized and its weight combination using discrete variable-length coding according to the first parameters to generate an initial population P gen ; Constraint handling and fitness evaluation module, used for based on the backdoor training dataset B tr and the backdoor test dataset B te to perform constraint handling and fitness evaluation on all individuals in the population P gen ; The offspring population generation module is used to record the iteration number gen and perform selection, crossover, and mutation operations on the individuals in the population P gen to generate the offspring population Q gen , and based on the backdoor training dataset B tr and the backdoor test dataset B te perform constraint processing and fitness evaluation on all individuals in the offspring population Q gen ; The elite individual screening module is used to combine the parental population P gen with the offspring population Q gen and screen out the top NP individuals that meet the constraint conditions and have better fitness to form a new parental population P gen ; An iterative judgment module is used to determine whether gen reaches the maximum number of iterations Gen. If so, set the current number of iterations gen = gen + 1, and use the parental population P gen as the new generation of parental population P gen , and repeat steps S4 to S6; if not, obtain the individual in population P gen that satisfies the constraint conditions and has the optimal fitness value, and use the clustering method and its weight combination strategy represented by the encoding of this individual as the optimal combination strategy; A power CPS intrusion detection backdoor defense module, which is used to perform online backdoor security defense on the power CPS intrusion detection model based on the optimal combination strategy and output the intrusion detection performance indicators.