Active power distribution network false information latent attack defense method, device and equipment based on cluster reconstruction
By building a distributed cluster reconstruction model, detecting feasible domains of latent attacks and dynamically adjusting cluster optimization, the problem of identification of latent attacks injected false data is solved, and the grid security and economic operation are achieved.
Patent Information
- Application Number
- CN202510859517.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-08-15
AI Technical Summary
The existing technology is difficult to effectively identify and defend against latent attacks injected data. Attackers can threaten the safe operation of the power grid system through hidden data tampering strategies.
A distributed cluster reconstruction model is constructed, by detecting the voltage amplitude, phase angle and branch power of the node, setting thresholds, calculating the feasible area interval length of the latent attack, building a security and electrical proximity objective function, dynamically adjusting the cluster reconstruction optimization model, and determining the optimal reconstruction scheme using TOPSIS multi-objective decision-making method.
It significantly improves the latent threshold for false data injection attacks, blocks the hidden propagation of attack signals, ensures safe operation of the power grid and the reliability of communication systems, and takes into account economic efficiency.
Smart Images

Figure CN120498870A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power systems, and in particular relates to a method, device and equipment for defending against latent attacks of false information in active distribution networks based on cluster reconstruction. Background Art
[0002] With the rapid development of distributed power sources (DGs), distribution networks are transforming into active distribution network cyber-physical systems (CPSs) with deep cyber-physical coupling. Distribution network operators monitor and control DGs based on a cyber-physical system architecture comprising a control center, communication network, control terminals, and physical network. Data protocol conversion is achieved through interactive devices such as gateways and switches, and data transmission security requirements are met via communication carriers such as optical fiber and Ethernet. CPSs enable control centers to observe grid status in real time and effectively issue control commands. However, the deep cyber-physical coupling of CPSs provides attackers with avenues for information-based attacks on distribution networks, potentially causing control failures of DGs and compromising the security of active distribution networks.
[0003] Current distributed power generation control models in active distribution networks primarily include centralized, decentralized, and distributed. Centralized control, characterized by a one-to-many nature, presents challenges such as susceptibility to interference and low reliability. Research indicates that decentralized control, while employing a one-to-one model, allows for independent control via dedicated controllers, but struggles to achieve coordinated optimization across multiple controlled objects. Consequently, distributed cluster control based on consensus algorithms has gained widespread adoption. This model, leveraging a hybrid architecture of "partitioned autonomy and collaborative optimization," enables plug-and-play deployment and power balancing of distributed power generation within the cluster, while achieving global optimization across clusters through sparse communication. This approach offers both reliability and cost-effectiveness. However, research indicates that distributed cluster control typically employs a hybrid communication model combining wired backbone networks with wireless private networks. While this improves deployment flexibility, it also introduces new attack surfaces. Attackers can exploit the openness of wireless private network channels to infiltrate the endpoint layer through man-in-the-middle attacks and data eavesdropping. Compared to traditional centralized architectures, the attack surface of distributed cluster control exhibits weakened isolation of local autonomous domains and sparse global communication links, making traditional perimeter-based defense mechanisms ineffective.
[0004] Among the cyber threats facing cyber-physical systems, false data injection attacks have attracted considerable attention due to their dual characteristics of covert destructiveness. Research has shown that by constructing specific attack vectors to tamper with the measured data of power data acquisition and monitoring systems, attackers can cause the system state to deviate from its true value while maintaining the tracking error constant, thereby circumventing the anomaly detection mechanism of the distribution network energy management system and implementing a latent false data injection attack. This latent false data injection attack relies on a covert data tampering and progressive destructive strategy. During the initial latent phase, it can induce the system into a vulnerable state through minimal data perturbations. Later, combined with the already injected attack signals, it can launch further destructive attacks, causing control failures and ultimately leading to cascading failures. The coupling effect of the latent false data injection attack and the system's vulnerable state exacerbates the difficulty of defense, making it a significant threat to distributed cluster control.
[0005] In summary, there have been many studies on the defense against false data injection attacks with explicit physical consequences. However, there are blind spots in the detection of latent false data injection attacks with concealment and gradual propagation characteristics. It is difficult to effectively identify false data injection behaviors that meet residual constraints and thus implement prevention. Summary of the Invention
[0006] In response to the above-mentioned deficiencies in the prior art, the present invention provides a method, device and equipment for defending against latent attacks of false information in active distribution networks based on cluster reconstruction, which effectively solves the problem that the traditional distribution network residual detection mechanism is difficult to effectively identify latent attack signals injected with false data, and attackers can evade bad data detection and threaten the safe operation of the power grid system by injecting false information.
[0007] The present invention provides a method for defending against latent attacks of false information in active distribution networks based on cluster reconstruction, the method comprising:
[0008] S101. Construct a feasible domain for the latent attack of false data injection into distributed power supply that satisfies residual constraints.
[0009] S102, detecting node voltage amplitude, phase angle, and branch power of the distributed cluster; setting a threshold; calculating the length of the feasible region of potential attack of each distributed power source in the distributed cluster; when the length of the feasible region of potential attack of the distributed power source is greater than the threshold, executing step S103;
[0010] S103, constructing a security objective function of distributed cluster reconstruction and an electrical proximity objective function of distributed cluster reconstruction;
[0011] S104, constructing a distributed cluster reconfiguration optimization model based on the safety objective function and the electrical proximity objective function;
[0012] S105. Solve the distributed cluster reconstruction optimization model to obtain a distributed cluster reconstruction plan, and form a new distributed cluster according to the reconstruction plan to complete the defense against false information latent attacks.
[0013] An active distribution network false information latent attack defense device based on cluster reconstruction, the device includes: an acquisition module, a detection module, a reconstruction trigger module, an optimization modeling module, a solution module and an execution module;
[0014] The acquisition module is used to collect multi-source measurement data and system status information of the distribution network distributed cluster in real time, pre-process the collected information, and input the pre-processed information into the detection module;
[0015] The detection module is used to calculate the length of the feasible region of potential attack of each distributed power source;
[0016] The reconstruction trigger module is used to compare the length of the latent attack feasible domain interval with a set threshold. If the length of the latent attack feasible domain interval is greater than the threshold, it activates the priority algorithm to determine the urgency of the reconstruction and generates a reconstruction instruction to transmit to the optimization modeling module; otherwise, no detection is performed;
[0017] The optimization modeling module builds a multi-objective optimization model with the core of minimizing the feasible domain measurement of latent attacks and reducing network active power loss;
[0018] The solution module is used to convert the multi-objective optimization model output by the optimization modeling module into a weighted normalized decision matrix, and generate an optimal reconstruction solution based on the weighted normalized decision matrix;
[0019] The execution module reconfigures the distributed cluster control parameters according to the optimal reconstruction solution and implements the defense strategy.
[0020] A cluster-reconfiguration-based defense device for active distribution network false information latent attack, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when executing the computer program, the processor implements a cluster-reconfiguration-based defense method for active distribution network false information latent attack, specifically comprising: real-time collection of distribution network measurement data, calculation of the attack feasible domain; triggering cluster reconstruction and establishing a dual-objective optimization model; solving the model to generate a defense plan, and dynamically adjusting the distributed cluster topology and control strategy; and ensuring the reliable execution of the defense strategy through cyber-physical collaborative constraints.
[0021] Beneficial effects of the present invention:
[0022] The present invention constructs a feasible domain analytical model of latent attacks considering residual constraints, quantifies the detectable boundary conditions of attack signals, and dynamically adjusts the defense strategy in combination with distributed cluster reconstruction, significantly improving the latent threshold of false data injection attacks and effectively blocking the covert propagation of attack signals.
[0023] Existing defense methods often rely on single-objective optimization, making it difficult to balance security and network efficiency. This paper proposes a cluster dynamic reconfiguration model with the dual objectives of minimizing the feasible domain of latent attacks and reducing network active power losses. Using the TOPSIS multi-objective decision-making method, the optimal reconfiguration solution is determined within the dual-objective space of security and electrical proximity, improving defense capabilities while ensuring the economic operation of the distribution network.
[0024] The present invention integrates the collaborative optimization model of the physical layer (node voltage, power flow constraints) and the information layer (communication link availability, information flow balance) to ensure that the reconstruction plan meets the requirements of both safe operation of the power grid and reliability of the communication system, realizes information-physical fusion defense, and avoids global risks caused by local optimization. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 This is a flow chart of a method for defending against latent attacks of false information in active distribution networks based on cluster reconstruction according to an embodiment of the present invention;
[0026] Figure 2 Schematic diagram of the structure of an active distribution network false information latent attack defense device based on cluster reconstruction according to an embodiment of the present invention
[0027] Figure 3 A schematic diagram of a calculation example system according to an embodiment of the present invention;
[0028] Figure 4 This is the convergence curve of the cluster dynamic reconstruction model for dual-objective collaborative optimization according to an embodiment of the present invention;
[0029] Figure 5 The objective function distribution of the cluster reconstruction solution that satisfies the constraints in the embodiment of the present invention;
[0030] Figure 6 This is the active output result of the initial cluster under the false data injection attack according to the embodiment of the present invention;
[0031] Figure 7 This is the active output result of the optimal cluster under the false data injection attack according to the embodiment of the present invention;
[0032] Figure 8 This is the verification result of the feasible domain of the optimal cluster latent attack in the embodiment of the present invention. DETAILED DESCRIPTION
[0033] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0034] A method for defending active distribution network from false information latent attack based on cluster reconstruction, such as Figure 1 As shown, the method is applied to a distribution network containing distributed power sources. The method aims to minimize the feasible domain of latent attacks and the active power loss of the distribution network. Through distributed cluster reconstruction, the latent threshold of false data injection attacks is increased, and the defense capability of the active distribution network against latent attacks of false data injection is improved. The method includes the following steps:
[0035] S101: Establishing a feasible domain for the false data injection latent attack on distributed power sources that satisfies the residual constraint;
[0036] S102: Detect multi-source measurement data such as power, voltage amplitude, and phase angle in the cluster control system nodes and branches; set thresholds; calculate the length of the feasible domain interval of potential attacks of each distributed power source in the distributed cluster. When the length of the feasible domain interval of the attack of any distributed power source is greater than the preset threshold, initiate the distributed cluster reconstruction and implement step S103;
[0037] S103: Establishing a security objective function for distributed cluster reconstruction;
[0038] S104: Establishing an electrical proximity objective function for distributed cluster reconstruction;
[0039] S105: Establishing a distributed cluster reconfiguration optimization model based on the safety objective function and the electrical proximity objective function;
[0040] S106: Solve the distributed cluster reconstruction optimization model and determine the distributed cluster reconstruction plan.
[0041] In this embodiment, the feasible domain length of a latent attack against a distributed power source with false data injection that satisfies residual constraints represents the conditions under which the attack against the distributed power source can remain latent. The feasible domain calculation method includes: equating a short circuit occurring within the power grid to a virtual impedance at the grid connection point based on the active current, reactive current, and dq-axis voltage components at the grid connection point. Based on the equivalent parameters of line reactance, transformer reactance, and line resistance, combined with the grid voltage vector phase difference, the potential and impedance expression within the faulty power grid are derived.
[0042] In this embodiment, the feasible domain of the distributed power supply false data injection latent attack that satisfies the residual constraint is constructed as follows:
[0043]
[0044] in, is the injection attack signal for the jth distributed power source; r th is the residual threshold; W a is the weight coefficient given to the distributed cluster to control the output power of distributed power sources, which is a constant; c i Select parameters for the cluster, c i ∈{0,1}, if the i-th distributed power source is included in the cluster, the corresponding c i is 1, otherwise it is 0; n is the number of observable and controllable distributed power sources in the distribution network; a is the number of distributed power sources included in the cluster control; P DGjmax is the maximum allowable output power of the jth distributed power source; A i (t) represents the i-th element in vector A(t); B ij Represents the element in the i-th row and j-th column of matrix B, where i = 1, 2, …, m.
[0045] The matrix B and the vector A(t) are determined as follows:
[0046] The matrix B is:
[0047] B=H(H T R -1 H) -1 H T R -1 -E
[0048] Where R∈R m×m is the m×m covariance matrix, R=σ 2 (HH T ) -1 ; E∈R m×m is the identity matrix; H is the Jacobian matrix, which is determined by the following distribution network state estimation DC power flow model:
[0049] z=Hx+e
[0050] Where x∈R n Represents the n-dimensional state vector, which is generally constructed by selecting the amplitude and phase angle of the node voltage, x=[U1,U2,…,U N ,θ1,θ2,…,θ N ] T ;e∈R m represents the m-dimensional measurement noise vector, which mainly comes from the error of the measurement equipment and the signal interference during data transmission, z∈R m Represents an m-dimensional measurement vector, usually using measurable power flow data such as node injection power and branch power:
[0051] z=[P1,Q1,P2,Q2] T
[0052] P1=[P DG1 ,…,P DGn ,P bus,1 ,…,P bus,N-n ] T
[0053] Among them, P1 is the active power vector injected by the distribution network node, P DGi is the injected active power of each observable and controllable distributed generation node in the distribution network, i = 1, 2, ..., n, n is the number of all observable and controllable distributed generation nodes in the distribution network; P bus,i is the injected active power of the nodes except the nodes where the observable and controllable distributed generation is located, i = 1, 2, ..., Nn, where the power measurement of the zero injection node is virtual measurement, the power measurement of the load node injection is pseudo measurement, N is the number of distribution network nodes, N>n; Q1 is the reactive power vector injected into the distribution network node, Q1 = [Q bus,1 ,…,Q bus,N ] T , where Q bus,i is the reactive power of each node, i=1,2,…,N; P2 and Q2 are the active power and reactive power vectors of the distribution network branches respectively, P2=[P br,1 ,…,P br,b ] T , Q2=[Q br,1 ,…,Q br,b ] T , P br,i and Q br,i are the active and reactive powers of each branch in the distribution network, i=1,2,…,b, and b is the number of branches.
[0054] Once the matrix B is known, the vector A(t) is determined as follows:
[0055] A(t)=Bz(t)
[0056] Where z(t)∈R m is the measurement vector at time t.
[0057] In this embodiment, some electrical parameter measuring instruments such as power analyzers and power quality analyzers are used to measure parameters such as voltage, current, active power, reactive power, etc. of the distribution network nodes in real time; for example, a resistor divider or an isolated voltage sensor is used to collect the AC bus voltage of the distribution network system, which is not specifically limited in this field.
[0058] The length of the feasible region for potential attacks on each distributed power source in a distributed cluster is calculated as follows: A joint analytical model of the Jacobian matrix and covariance matrix is established based on the measured data (including node power, voltage amplitude, and phase angle) under the distributed cluster control architecture to reveal the dynamic propagation characteristics of the false data injection (FDI) attack signal under residual constraints. Combined with the DC power flow equation for distribution network state estimation, the detectable boundary conditions of the attack signal in the distributed control system are quantified.
[0059] Furthermore, through the dynamic mapping relationship between the residual threshold value and the cluster selection parameters, the potential impact range of the attack signal on the output power of the distributed power generation (DG) is derived, thereby constructing a mathematical representation of the feasible domain of the latent attack. The model comprehensively considers the DG weight coefficient, the maximum allowable output power, and the cluster topology parameters, and ultimately determines the threshold length of the attack feasible domain interval of each DG, providing a quantitative basis for triggering cluster reconstruction.
[0060] In some embodiments, the length of the feasible region of potential attack of each distributed power source in the distributed cluster is determined by the following method:
[0061]
[0062] in, is the length of the feasible domain interval of the potential attack of the j-th slave-controlled distributed power source in the cluster. When the length of the feasible domain interval of the attack of any distributed power source is greater than the preset threshold, the distributed cluster reconstruction is started.
[0063] In this embodiment, the security objective function of the distributed cluster reconstruction aims to improve the difficulty of latent attacks on distributed power sources in the distributed cluster, and is established in the following way: based on the feasible domain measurement of latent attacks on each distributed power source (distributed power source), the potential threat of attack signals to the cluster control system is quantified. By defining security indicators, the length of the attack feasible domain interval, residual constraints and cluster topology parameters are incorporated into the objective function, and weights are dynamically assigned to reflect the defense priority in different scenarios. Further combined with the interactive characteristics of the information-physical system, a security threat coefficient is introduced to characterize the coupling effect of the attack signal between the communication link and the physical device, ensuring that the objective function can comprehensively evaluate the defense effectiveness of the reconstruction scheme.
[0064] In some embodiments, the security objective function of distributed cluster reconstruction is determined as follows:
[0065]
[0066] Where g is the safety index; ω i is the weight coefficient of each sub-goal. Given the uncertainty of the attacker's target selection, equal weight distribution is adopted, that is,
[0067] In this embodiment, to avoid increased communication hops and latency, cluster reconfiguration also constructs an objective function based on electrical proximity. This objective function is established as follows: To prevent wind turbines from disconnecting from the grid due to faults, the voltage deviation and frequency change rate at the grid connection point should be minimized. Therefore, a dual objective function is constructed using a transfer model of the power of the flexible DC receiving converter station and the voltage and frequency change rates at the wind turbine ports. To avoid communication delays and increased network losses caused by cluster reconfiguration, the electrical proximity objective function is established with the optimization of the electrical coupling relationship within the cluster as its core. By calculating the equivalent electrical distance (line impedance modulus, voltage phase angle difference, etc.) between distributed power generation nodes within the cluster, an electrical proximity index is constructed to quantify the compactness and coordination of the cluster topology.
[0068] In some embodiments, the electrical proximity construction objective function is constructed as follows:
[0069]
[0070] Where, f is the electrical proximity index; Z ui The electrical equivalent distance between the u-th distributed generation and the i-th distributed generation in the distribution network is defined as the modulus of the line impedance between the two distributed generation grid connection points, which is used to characterize the electrical proximity between cluster distributed generation; is the number of pairwise combinations of distributed generation in the cluster.
[0071] In this embodiment, the constraints for cluster dynamic reconfiguration optimization include the physical layer distribution network operation boundaries and the information layer communication system security constraints, which are determined as follows: the construction of the optimization model needs to integrate the physical layer operation boundaries and the information layer security constraints. The physical layer constraints include node power balance, upper and lower limits of the power flow, voltage amplitude range, and distributed power output limits to ensure that the reconfiguration plan meets the steady-state and transient operation requirements of the power grid; the information layer constraints cover the availability of communication links, information flow balance, and node interaction requirements to avoid defense strategies causing communication congestion or control command failure. Through the mixed integer nonlinear programming (MINLP) method, the dual objective function and multi-dimensional constraints are unified in modeling to form an optimization problem framework that combines defense effectiveness and operational feasibility.
[0072] In some embodiments, the constraints for cluster dynamic reconfiguration optimization are as follows:
[0073] The power balance of the node and the active and reactive power flows of the power lines are subject to the upper and lower limits of the power flow and the upper and lower limits of the node voltage as follows:
[0074]
[0075]
[0076] Where, Ω N is the set of distribution network nodes; Ω L is the line set; P in (t), Q in (t) are the active and reactive power transmitted from the upper power grid to the first section of the distribution network at time t; P loadi (t), Q loadi (t) are the active and reactive loads at node i at time t; P loss (t), Q loss (t) are the total active and reactive network losses of the distribution network at time t; are the active and reactive outputs of the cluster-controlled distributed generation at node i at time t, respectively; are the active and reactive outputs of the distributed generation using maximum power point tracking control at node i at time t; P ij (t), Q ij (t) is the active and reactive power at branch ij at time t; U i is the voltage at node i at time t; the subscripts min and max are the minimum and maximum values of the variable, respectively.
[0077] The distributed cluster selection parameter constraints and reconstruction cluster capacity constraints are as follows:
[0078]
[0079] Where, a∈{1,2,…,n}; P DGimax is the maximum active output of the distributed power source controlled by MPPT at node i; P ref (t) is the power command value output by the distributed power cluster at time t.
[0080] The output power constraints of distributed cluster-controlled distributed power supplies, the output power constraints of non-distributed cluster-controlled distributed power supplies, and the output power constraints of cluster grid connection points are as follows:
[0081]
[0082] P out (t) = P ref (t)
[0083] Where, ξ r ∈[0,1]; Indicates the maximum active power of the distributed generation controlled by maximum power point tracking at time t; A collection of grid-connected nodes that control distributed power sources for distributed clusters; A collection of grid-connected nodes that control distributed power sources for maximum power point tracking.
[0084] The balance constraints satisfied by the information flow of the information node are as follows:
[0085]
[0086] Where, Ω CN is the node set of the information system; s is the information node of the distribution network control center; l is the communication link; s(l) and r(l) are the sending end and receiving end of the communication link l respectively; L s (t) is the information flow on the information node of the distribution network control center at time t; L l (t) is the information flow on the communication link l at time t; the number 1 on the right represents the information demand of each node. When an information node in the cluster meets the information demand at time t, the corresponding binary variable Indicates that this information node can directly or indirectly interact with the information node of the distribution network control center, and the node can realize real-time control of the associated distributed power source according to the control instructions received.
[0087] The information restriction constraints of the source information node, the communication link availability constraints, and the information restriction constraints of the general information node are as follows:
[0088]
[0089] Where N CN is the total number of information nodes in the information system; l,t Indicates whether the communication link l is available at time t. l,t = 0, indicating that the communication link fails. l,t =1, indicating that the communication link is valid.
[0090] In specific implementation, the entropy-weighted TOPSIS method is used to solve the distributed cluster reconfiguration optimization model. The solution process includes: Using the TOPSIS multi-objective decision-making method, a weighted, normalized decision matrix is constructed to map safety and electrical proximity objectives into a unified evaluation space. First, a set of feasible solutions that satisfy the constraints is generated, and the normalized value of each solution in the dual-objective space is calculated. Second, positive and negative ideal solutions are determined, and the Euclidean distance and relative proximity of each solution to the ideal solution are calculated. Finally, the optimal reconfiguration solution is selected based on proximity ranking.
[0091] In this embodiment, the process of solving the distributed cluster reconstruction optimization model and obtaining the optimal reconstruction solution is as follows:
[0092] (1) Determine the feasible solution space:
[0093] According to the access location, capacity, cluster connection point location and the range of distributed cluster control instruction values of observable and controllable distributed power sources in the distribution network, all feasible cluster dynamic reconstruction schemes that meet the constraints of the physical layer and information layer are generated. Assuming that the number of feasible solutions n p .
[0094] (2) Constructing a weighted normalized decision matrix
[0095] The dual objective function values of each feasible solution are constructed into the initial decision matrix X, and then standardized and weighted to obtain the weighted normalized decision matrix Z:
[0096]
[0097] Where X is the dual-objective decision matrix, and its matrix element x i1 =g i , x i2 =f i ;Indicator evaluation weight ω j is a given value; n p is the number of feasible solutions.
[0098] (3) Calculate the Euclidean distance between each reconstruction scheme and the positive and negative ideal solutions
[0099] Determine the positive and negative ideal solutions of the safety objective function and the electrical proximity objective function, as well as the Euclidean distances between each reconstruction scheme and the positive and negative ideal solutions:
[0100]
[0101] Where Z + and Z - are the positive and negative ideal solutions of the dual objective function respectively; are the optimal results of the safety objective function and the electrical proximity objective function respectively; are the worst results of the safety objective function and the electrical proximity objective function respectively; are the Euclidean distances between each reconstruction scheme and the positive and negative ideal solutions, respectively; are the optimal and worst results of the j-th indicator respectively.
[0102] In this embodiment, determining the optimal reconstruction solution includes: determining the relative closeness of each reconstruction solution to the ideal solution as follows:
[0103]
[0104] Where K i K is the relative closeness of the i-th reconstruction scheme to the ideal solution. i The closer it is to 1, the better the evaluation result is, indicating that the reconstruction scheme is close to the positive ideal solution and far away from the negative ideal solution. p Cluster dynamic reconstruction scheme, K i The solution with the index closest to 1 is the optimal cluster dynamic reconstruction solution.
[0105] When determining the distributed cluster reconstruction scheme, the embodiment of the present invention integrates the physical layer operation boundaries (such as node voltage amplitude constraints, line flow capacity limitations) and information layer security constraints (such as communication link availability, information flow balance) to ensure that the reconstruction strategy achieves optimal defense adjustment under the premise of meeting the safe operation boundaries of the power grid. Specifically, based on the dynamic quantitative model of the feasible domain of latent attacks and the residual constraint conditions, the detectable boundaries of the attack signal are accurately defined to avoid the risk of control instruction failure or cascading failure due to the attack signal exceeding the detection threshold; at the same time, the cluster topology and defense weight distribution are optimized through the TOPSIS multi-objective decision-making method, and the network active power loss is reduced in the process of minimizing the attack feasible domain measurement, which not only blocks the hidden propagation path of the false data injection attack, but also maintains the economic operation efficiency of the distribution network, thereby extending the equipment control life and reducing the defense cost. In addition, the electrical proximity objective function embedded in the reconstruction scheme can effectively suppress communication delays and network congestion, ensure the real-time and reliability of defense instructions, and prevent local attack signals from causing global control instability through sparse communication links.
[0106] Figure 2 The structure diagram of the active distribution network false information latent attack prevention device based on cluster reconstruction is as follows:
[0107] The acquisition module collects multi-source measurement data and system status information from distributed distribution network clusters in real time, including distributed power generation output power, node voltages, power flow data, communication link status, and information node interaction traffic. Sensors and communication protocols ensure real-time and reliable data, while also being compatible with heterogeneous data formats. The module includes a built-in data preprocessing unit to filter and calibrate outliers, and synchronizes timestamps to ensure spatiotemporal consistency between physical and information layer data. The collected data is transmitted to the detection module, providing the foundational input for subsequent attack feasibility domain analysis.
[0108] The detection module dynamically calculates the length of the potential attack feasible region for each distributed power source based on a residual constraint model. It constructs the attack feasible region using the Jacobian matrix and covariance matrix, quantifying the detectable boundary conditions for attack signals. The module monitors the length of the attack feasible region for each distributed power source in real time and compares it with a preset threshold. If the feasible region of a distributed power source exceeds the threshold, an alarm is immediately triggered and the reconstruction trigger module is invoked to initiate the defense process.
[0109] The Reconfiguration Trigger Module: When the Detection Module determines that the potential attack domain of a distributed power source exceeds a preset threshold, the Reconfiguration Trigger Module immediately activates the cluster reconfiguration process. This module uses a priority algorithm to determine the urgency of the reconfiguration and generates a reconfiguration instruction that is transmitted to the Optimization Modeling Module.
[0110] The optimization modeling module constructs a multi-objective optimization model centered around minimizing the potential attack feasible domain measure and reducing network active power loss. The security objective function dynamically adjusts the defense weight of the distributed power cluster by quantifying the attack feasible domain measure and security threat factor. The electrical proximity objective function optimizes the cluster topology based on voltage phase angle, impedance value, and active network loss models. The module integrates collaborative constraints at the physical and information layers to formulate a mixed-integer nonlinear programming problem, providing standardized input for the solution module.
[0111] The solution module utilizes the TOPSIS multi-objective decision-making method. It transforms the multi-objective problem output by the optimization modeling module into a weighted, normalized decision matrix and calculates the Euclidean distance and relative proximity of each reconstruction solution to the positive and negative ideal solutions. The module supports a hybrid solution strategy using heuristic algorithms and exact solvers, balancing computational efficiency and accuracy. The resulting optimal reconstruction solution must meet the dual-objective Pareto front of safety and electrical proximity. A visual interface displays the trade-offs between each solution for operator decision-making.
[0112] The embodiment of the present invention fully considers the balance between DC voltage reduction, charging power variation and reactive power support through the combination of acquisition module, detection module, reconstruction trigger module, optimization modeling module and solution module. The optimal reconstruction scheme finally output must meet the Pareto front of the dual objectives of safety and electrical proximity. The feasible domain of latent attacks is reduced through the dynamic reconstruction of distributed new energy, and the security defense against latent attacks of false information in active distribution networks is achieved.
[0113] In an embodiment of the present invention, the device for preventing latent attacks of false information on active distribution networks includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a method for defending against latent attacks of false information on active distribution networks based on cluster reconstruction as described in the present invention.
[0114] In some embodiments, the memory may include non-permanent memory in a computer-readable medium, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0115] In the embodiment of the present invention, the effectiveness of the proposed method is verified by using the IEEE 34-node and 21-node information network combined system. The distribution network is connected to 8 observable and controllable distributed power sources at nodes 808, 822, 828, 832, 838, 848, 850, and 860 respectively. The capacity of distributed power source 1 and distributed power source 2 is 5MW, the capacity of distributed power source 3, distributed power source 4, and distributed power source 5 is 3MW, and the capacity of distributed power source 6 to distributed power source 8 is 2MW. The information nodes of each distributed power source are interconnected through the communication network topology in the 21-node information system, as shown in Figure 1. Figure 3 As shown. The load adopts the constant power model, and the active power is 0.6MW. The power command value is set to 12MW, and the initial cluster is The iteration period of distributed cluster control is 0.05s. The convergence coefficient of RI-distributed power generation is 0.1. The residual threshold value r th Take 3. The weight coefficient of the distributed power output power of the distributed cluster control is 1. The traffic of the information node of the distribution network control center obeys the mixed distribution model of periodic traffic and event-driven traffic, and the instantaneous traffic L of the other information nodes is i (t) obeys the Poisson distribution P(λ i ), where the average generation rate λ i It is 0.8Mbps.
[0116] The latent attack feasible domain objective function and the electrical proximity objective function are established as a cluster dynamic reconstruction model for dual-objective collaborative optimization. The evaluation weights of the latent attack feasible domain objective function and the electrical proximity objective function are set to 1, and a TOPOSIS comprehensive evaluation is performed on the feasible solution set that meets the constraints. By calculation, the positive and negative ideal solutions are Z + =(0.0537,0.0559) and Z- =(0.1622,0.1358), with the objective function min(1-K i ) drives the optimization process, and its convergence characteristics are as follows Figure 4 shown.
[0117] like Figure 4 As shown, the algorithm converges after 14 iterations, and the relative progress K between the optimal solution and the ideal solution is i =0.9884, cluster selection parameter set Ω′c i ={1,1,0,0,0,1,0,1}, cluster size a = 4. The relative progress of the optimal cluster dynamic reconstruction scheme with the positive and negative ideal solutions in the dual-objective space is closest to 1, indicating that the scheme has achieved the optimal balance close to the ideal state in both the feasible domain of latent attack and electrical proximity. Based on the updated dual-objective decision matrix X∈R in the first stage of Table 1 128×2, the feasible domain of latent attack and the distribution of electrical proximity objective function of feasible solution set can be drawn as follows Figure 5 shown.
[0118] like Figure 5 As shown in (a), when the cluster size a=4 and the selected parameter is Ω ci ={1,1,0,0,1,0,0,1}, the minimum latent attack feasible domain objective function g is obtained min =0.53. Within a certain range of distributed power sources, the feasible domain objective function of the cluster's latent attack presents a monotonically increasing characteristic with the cluster size. That is, the more distributed power sources there are in the cluster, the larger the feasible domain of the cluster's latent attack. The difficulty for attackers to implement false data injection latent attacks against the constructed cluster system is also reduced accordingly. Figure 5 As shown in (b), the cluster selection parameters are The cluster reconstruction scheme obtains the minimum electrical proximity objective function f min =2.97, and the cluster size a = 5. The cluster's electrical proximity objective function is related to the grid connection point location of the distributed generation (DGs) in the distribution network. As the average electrical equivalent distance between DGs within a cluster increases, the cluster's electrical proximity decreases, and the topological complexity of the cluster control system increases. Therefore, while ensuring power supply reliability, it is necessary to strictly constrain cluster size to control network security risks and improve the electrical proximity of the cluster's DGs.
[0119] Figure 5 The optimal cluster dynamic reconfiguration scheme, marked with orange columns, corresponds to a latent attack feasible domain objective function and an electrical proximity objective function of 0.59 and 3.61, respectively. Compared with the initial cluster scheme marked with pink columns, the optimal scheme improves the latent attack feasible domain objective function by 29.4% and the electrical proximity objective function by 50.5%. Further comparison with the single-objective optimal scheme marked with dark red columns shows that although the optimal cluster dynamic reconfiguration scheme has a compromise in the single objective dimension—the latent attack feasible domain objective function is reduced by 11.30% and the electrical proximity objective function is reduced by 17.7%, its dual-objective collaborative optimization effect is significantly improved, with a collaborative gain of 46.9%. The above comparison results verify the optimization effectiveness of the dual-objective collaborative optimization decision-making mechanism proposed in this paper in balancing multi-objective conflicts.
[0120] By injecting different attack signals, the correctness of the feasible domain for the latent attack using false data injection and the effectiveness of cluster optimization were verified. Both the optimal dynamic cluster reconfiguration scheme and the initial cluster scheme have a cluster size of 4. The initial cluster consists of distributed generators 1, 2, 4, and 5. The optimal dynamic cluster reconfiguration scheme replaces distributed generators 4 and 5 with distributed generators 6 and 8. The feasible domains for the latent attack using false data injection for distributed generators 1 and 2 in the initial cluster scheme are [-0.66, 0.23] and [-0.63, 0.21], respectively. The feasible domains for the latent attack using false data injection for distributed generators 1 and 2 in the optimal cluster reconfiguration scheme are [-0.59, 0.11] and [-0.54, 0.09], respectively. The interval lengths of the feasible domains for the latent attack on distributed generators 1 and 2 before and after cluster dynamic reconfiguration are compressed by 21.3% and 25.0%, respectively.
[0121] Set the attack signal equal to the boundary value and 5% of the boundary value of the latent attack feasible region before and after cluster optimization, and inject it into the distributed power supply 1 and distributed power supply 2 of the two cluster solutions respectively. For distributed power supply 1 and distributed power supply 2 in the initial cluster, the attack signal The attack signal is injected into the distributed power supply 1 at 0.8s and continues to work. The distributed power source 2 is injected at 0.8s and continues to work. The initial cluster output active power under 8 groups of attack signals is as follows: Figure 6 As shown. For DG 1 and DG 2 in the optimal cluster, the attack signal λ′ 1(1) =0.11,λ′ 1(2) =0.12,λ′ 1(3) =-0.59, λ′ 1(4) =-0.62 are injected into the distributed power supply 1 at 0.8s and continue to act, the attack signal λ′ 2(1) =0.09,λ′ 2(2) =0.10,λ′ 2(3) =-0.54, λ′ 2(4) =-0.57 are injected into the distributed power supply 2 at 0.8s and continue to work. The initial cluster output active power under 8 groups of attack signals is as follows: Figure 7 shown.
[0122] like Figure 6As shown in (a), (c), (e) and (g), when the injection size is the attack signal of the upper and lower boundaries of the feasible region of the latent attack of distributed power generation 1 and distributed power generation 2 in the initial cluster, the output power of the initial cluster fluctuates at t = 0.8s, but tracks the instruction value at t = 0.96s, 1.02s, 0.93s and 0.99s respectively, and the attack is successfully latent; Figure 6 As shown in (b), (d), (f) and (h), when the attack signal is injected that exceeds the upper and lower boundaries of the feasible region of the latent attack of distributed power 1 and distributed power 2 in the initial cluster by 5%, the system begins to suffer from continuous attack disturbances at t = 0.8s, causing the active output of the cluster to deviate continuously and converge to the non-command value result. At this time, the measurement residual exceeds the threshold range. The EMS identifies the abnormal state through the bad data detection mechanism. The attack cannot remain latent and successfully isolates the target distributed power at t = 1.2s. The output power of the distributed cluster converges to the command value again at t = 1.79s, 1.47s, 1.66s and 1.42s respectively. Figure 7 As shown in Figures (a), (c), (e), and (g), after injecting attack signals equal to the upper and lower boundaries of the feasible region for latent attacks on DGs 1 and 2 in the optimal cluster, the attack also exhibits latent characteristics. However, when the attack signal exceeds 5% of the feasible region boundary, the attack cannot remain latent, and a deviation occurs between the cluster's active output and the command value. These simulation results demonstrate that the proposed method can effectively compress the feasible region for latent attacks on cluster DGs and achieve good security optimization results.
[0123] The feasible domains of false data injection latent attack for distributed power supply 6 and distributed power supply 8 in the optimal cluster dynamic reconstruction scheme are [-0.43, 0.07] and [-0.49, 0.04] respectively. To verify the analytical accuracy of the feasible domain, attack signals equal to 5% of the boundary and 5% of the overboundary are set, that is, a total of 4 false data injection attack signals of different sizes are injected into each distributed power supply unit to observe the optimal cluster's anti-latent attack performance. For distributed power supply 6 in the optimal cluster, the attack signal λ′ 6(1) =0.07,λ′ 6(2) =0.08,λ′ 6(3) =-0.43,λ′ 6(4) =-0.46 are injected at 0.8s and continue to act; for the distributed power supply 8 in the optimal cluster, the attack signal λ′ 8(1) =0.04,λ′ 8(2) =0.05,λ′ 8(3) =-0.49, λ′ 8(4) =-0.52 are injected into the distributed power supply at 0.8s and continue to work. The cluster output active power under 8 groups of attack signals is as follows Figure 8 shown.
[0124] like Figure 8 As shown in (a), (c), (e) and (g), when the attack signal with a size of the upper and lower boundaries of the feasible region for the latent attack of DG 6 and DG 8 is injected, the cluster output power experiences a transient fluctuation at t = 0.8s, and then resumes tracking the command value at t = 0.91s, 0.85s, 0.93s and 0.96s, respectively, successfully achieving the latent attack. Figure 8 As shown in Figures (b), (d), (f), and (h), when an attack signal is injected that exceeds the upper and lower bounds of the latent attack feasible region for DGs 6 and 8 by 5%, the power fluctuations caused by the attack signal after t = 0.8s prevent the cluster's active power output from converging to the commanded power value. The measurement residual exceeds the safety threshold, triggering an EMS alarm, signaling a latent attack failure. The system activates its defense mechanism at t = 1.2s, isolating DGs 6 and 8. After isolation, the cluster dynamically recovers through coordinated control, with the cluster's active power output reconverging to the commanded value at t = 1.61s, 1.45s, 1.48s, and 1.39s, respectively. These simulation results demonstrate the high accuracy of the latent attack feasible region constructed in this paper and effectively characterize the feasible boundary for evading residual detection by injecting false data into latent attack signals.
[0125] The above embodiments further illustrate the purpose, technical solutions and advantages of the present invention in detail. It should be understood that the above embodiments are only preferred implementation plans of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made to the present invention within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for defending active distribution network from false information latent attacks based on cluster reconstruction, characterized in that: include: S101. Construct a feasible domain for the latent attack of false data injection into distributed power supply that satisfies residual constraints. S102, detecting node voltage amplitude, phase angle, and branch power of the distributed cluster; Set thresholds; Calculate the length of the feasible region of potential attacks on each distributed power source in the distributed cluster; When the length of the feasible region interval of the potential attack of the distributed power source is greater than the threshold, step S103 is executed; S103, constructing a security objective function of distributed cluster reconstruction and an electrical proximity objective function of distributed cluster reconstruction; S104, constructing a distributed cluster reconfiguration optimization model based on the safety objective function and the electrical proximity objective function; S105. Solve the distributed cluster reconstruction optimization model to obtain a distributed cluster reconstruction plan, and form a new distributed cluster according to the reconstruction plan to complete the defense against false information latent attacks.
2. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1 is characterized in that: The feasible domain of the distributed power supply false data injection latent attack that satisfies the residual constraint is: in, is the injection attack signal for the jth distributed power source; r th is the residual threshold; W a is the weight coefficient for assigning the distributed cluster to control the output power of distributed power sources; c i Select parameters for the cluster; n is the number of distributed generation sources that can be observed and controlled in the distribution network; a is the number of distributed generation sources included in the cluster control; P DGjmax is the maximum allowable output power of the jth distributed power source; A i (t) represents the i-th element in vector A(t); B ij Represents the element in the i-th row and j-th column of matrix B.
3. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 2 is characterized in that: The matrix is: B=H(H T R -1 H) -1 H T R -1 -E R=σ 2 (HH T ) -1 Where H is the Jacobian matrix, R is the covariance matrix, and E is the identity matrix.
4. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1 is characterized in that: Calculating the feasible region length of the potential attack on distributed power in a distributed cluster includes: in, is the feasible region length of the latent attack on the jth slave-controlled distributed power source in the cluster, r th is the residual threshold, a is the number of distributed generation sources included in cluster control, W a To give the weight coefficient of the distributed cluster to control the output power of distributed power supply, P DGjmax is the maximum allowable output power of the jth distributed power source, n is the number of distributed power sources that can be observed and controlled in the distribution network, c i Select parameters for clustering, B ij is the element in the i-th row and j-th column of matrix B.
5. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1 is characterized in that: The security objective function of distributed cluster reconstruction is: Among them, g is the safety index, ω i is the weight coefficient of each sub-goal, is the feasible region length of the potential attack of the jth slave-controlled distributed power source in the cluster, n is the number of distributed power sources that can be observed and controlled in the distribution network, c i Choose parameters for your cluster.
6. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1, characterized in that: The electrical proximity objective function includes: Where f is the electrical proximity index; Z ui is the electrical equivalent distance between the u-th distributed generation and the i-th distributed generation in the distribution network, is the number of pairwise combinations of distributed generation in the cluster.
7. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1 is characterized in that: Constructing a distributed cluster reconstruction optimization model includes: constructing constraint conditions, constraining the safety objective function and the electrical proximity objective function based on the constraint conditions, and obtaining a distributed cluster reconstruction optimization model; wherein the constraint conditions include node power balance constraints, power line active and reactive power flows subject to flow upper and lower limit constraints, node voltage upper and lower limit constraints, distributed cluster selection parameter constraints, reconstruction cluster capacity constraints, distributed cluster control distributed power output power constraints, non-distributed cluster control distributed power output power constraints, cluster grid connection point output power constraints, information flow balance constraints satisfied by information nodes, information restriction constraints of source information nodes, communication link availability constraints, and information restriction constraints of general information nodes.
8. The method for defending against false information latent attacks on active distribution networks based on cluster reconstruction according to claim 1 is characterized in that: Solving the distributed cluster reconstruction optimization model includes: Step 1: Generate a feasible cluster dynamic reconfiguration plan based on the access location, capacity, cluster grid connection point location and the range of distributed cluster control instruction values of observable and controllable distributed power sources in the distribution network; Step 2: Construct an initial decision matrix based on the feasible cluster dynamic reconstruction scheme, and standardize and weight the initial quadratic matrix to obtain a weighted normalized decision matrix; Step 3: Calculate the positive and negative ideal solutions of the safety objective function and the electrical proximity objective function and the Euclidean distances between each reconstruction scheme and the positive and negative ideal solutions based on the weighted normalized decision matrix; Step 4: Calculate the relative closeness of each reconstruction scheme to the ideal solution, and select the optimal scheme based on the relative closeness.
9. A device for defending against latent attacks of false information in active distribution network based on cluster reconstruction, the device being used to execute any one of the methods for defending against latent attacks of false information in active distribution network based on cluster reconstruction according to claims 1 to 8, characterized in that: include: Acquisition module, detection module, reconstruction trigger module, optimization modeling module, solution module and execution module; The acquisition module is used to collect multi-source measurement data and system status information of the distribution network distributed cluster in real time, pre-process the collected information, and input the pre-processed information into the detection module; The detection module is used to calculate the length of the feasible region of potential attack of each distributed power source; The reconstruction trigger module is used to compare the length of the latent attack feasible domain interval with a set threshold. If the length of the latent attack feasible domain interval is greater than the threshold, it activates the priority algorithm to determine the urgency of the reconstruction and generates a reconstruction instruction to transmit to the optimization modeling module; otherwise, no detection is performed; The optimization modeling module builds a multi-objective optimization model with the core of minimizing the feasible domain measurement of latent attacks and reducing network active power loss; The solution module is used to convert the multi-objective optimization model output by the optimization modeling module into a weighted normalized decision matrix, and generate an optimal reconstruction solution based on the weighted normalized decision matrix; The execution module reconfigures the distributed cluster control parameters according to the optimal reconstruction solution and implements the defense strategy.
10. An active distribution network false information latent attack defense device based on cluster reconstruction, characterized in that: The invention comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the active distribution network false information latent attack defense method based on cluster reconstruction according to any one of claims 1 to 8 when executing the computer program.