Large-scale micro-grid safety communication flow confusion processing method and system

By constructing a logical causal map and a convergent obfuscation generation network to generate logically consistent obfuscation communication data packets, the problem of easy identification of communication traffic in large-scale microgrids is solved, and communication security and power scheduling accuracy and robustness are improved.

CN120602174AActive Publication Date: 2025-09-05WUHAN BAOHUI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510825214.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-05
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

Existing communication traffic obfuscation technology is difficult to generate logically consistent and reasonable timing pseudo-traffic in large-scale microgrids, and is easily identified by machine learning models, resulting in insufficient communication security and affecting the accuracy and reliability of power scheduling.

Method used

Based on the semantic similarity, timing transfer probability and causal relationship of the power business unit, a logical causal map is constructed, and a logical causal communication packet is generated through a fusion obfuscation generation network, which is inserted into the PLC communication link to ensure that obfuscation does not interfere with the actual scheduling tasks.

Benefits of technology

It improves the security of microgrid communication, prevents data-driven attacks, improves the accuracy of power scheduling and the robustness of system operation, and avoids scheduling errors caused by confusion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602174A_ABST
    Figure CN120602174A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power grid intelligent scheduling, and discloses a large-scale micro-grid safety communication flow confusion processing method and system, and the method comprises the steps: constructing power business units in a PLC communication process based on the functions of a communication data packet, and constructing a logic causal map between the power business units; selecting communication data packets to be confused and mimicry power business units with consistent logical causality from the PLC communication link; and performing logic causal consistency counterfeiting on the communication data packet to be confused by using the fusion type confusion generation network. According to the invention, the function field having logical association and causal relationship with the to-be-confused communication data packet is generated based on the logic causal map, and the confused communication data packet having semantic consistency with the function field and having data consistency with the to-be-confused communication data packet is generated by combining the function field and utilizing the generative network. On the basis of not influencing the operation of the original dispatching system, the communication privacy is improved, and the anti-interference capability and safety of the micro-grid dispatching network are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an intelligent dispatching system for a large-scale power grid, and in particular to the field of communication traffic obfuscation processing, and more specifically to a method and system for secure communication traffic obfuscation processing in a large-scale microgrid. Background Art

[0002] Against the backdrop of the accelerated construction of new power systems, microgrids, with their distributed, autonomous, and flexible advantages, have become an essential component in supporting clean energy access and local load regulation. Microgrids are typically composed of distributed power sources (such as photovoltaic and wind power), energy storage devices, load equipment, and energy management systems, relying on high-frequency, low-latency communication interactions to achieve real-time scheduling and control. Among them, PLC (Power Line Communication) is widely used for control signal transmission and operating status information feedback between microgrid devices because it does not require additional wiring and is shared with the physical infrastructure of the power grid.

[0003] In large-scale microgrid systems, PLC communication is responsible for dispatching key power operations, transmitting status monitoring data, and issuing load forecasting instructions. Different types of communication packets correspond to different business logic and control objectives. These packets often contain structured information such as function fields, node addresses, timestamps, and payloads, which clearly reflect the system's operational behavior and scheduling patterns.

[0004] Currently, communication traffic obfuscation technology is widely used to enhance network communication security. Traditional obfuscation methods primarily include random delay insertion, communication instruction perturbation, and encryption identifier masking. However, most of these methods fail to consider the logical consistency between obfuscated packets and actual service semantics, making them susceptible to detection and identification by machine learning models based on traffic characteristics.

[0005] For example, patent CN118573477B discloses a communication data transmission method that uses a server-side algorithm to determine data leakage risks, generate a communication data mask sequence and a perturbation data sequence, and construct a fused communication truth sequence using an obfuscation circuit to output a disguised communication result. This solution improves the confidentiality of communication information to a certain extent, but its obfuscation generation fails to consider the logical characteristics of the business layer, making it difficult to forge obfuscated traffic with reasonable context and consistent timing in complex PLC scenarios, and the risk of identification still exists.

[0006] In this context, how to effectively prevent and respond to the leakage and attack of communication traffic has become an important issue that needs to be solved urgently. To address this issue, this application proposes a large-scale microgrid security communication traffic obfuscation processing method and system. By generating pseudo-traffic that conforms to the semantics of power business to effectively obfuscate PLC communication traffic, it can avoid erroneous scheduling caused by malicious attacks and improve the accuracy and reliability of microgrid power scheduling. Summary of the Invention

[0007] The present invention provides a large-scale microgrid secure communication traffic obfuscation processing method and system. Based on the semantic similarity, temporal transition probability, and causal relationships between power business units, a fused obfuscation generation network is used to construct semantically consistent, well-structured, and statistically camouflaged obfuscated communication packets. These obfuscated communication packets maintain a high degree of logical causality with the intended obfuscated communication packets in terms of function fields and payload, but their execution is essentially harmless simulation tasks or redundant retransmissions of completed instructions, effectively interfering with attackers' reverse analysis and behavioral reasoning of communication traffic. By inserting obfuscated communication packets that conform to power business semantics during critical periods or sensitive communication paths as accompanying cover packets for the intended obfuscated communication packets, the system can construct a nonlinear and non-deterministic representation of business behavior, significantly reducing the cost for attackers to restore the true scheduling path. Furthermore, the obfuscation process strictly adheres to the principle of consistency between causal graphs and business logic, ensuring that obfuscated communication does not interfere with actual scheduling tasks, thereby enhancing communication security while maintaining the accuracy and real-time performance of scheduling control.

[0008] Therefore, the method proposed in this application can not only effectively prevent scheduling misleading and control deception caused by data-driven attacks, but also improve the operational robustness and overall scheduling reliability of the microgrid system in complex environments.

[0009] To achieve the above objectives, the present invention provides a method for obfuscating large-scale microgrid secure communication traffic, comprising the following steps:

[0010] S1: Collect communication data packets from the historical communication data packet sequence of the PLC communication link, divide the communication data packets into functions according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, and build a mapping relationship table between function fields and power business units;

[0011] S2: Based on the communication data packets in the power business units, the logical and causal relationships between different power business units are identified. The power business units are used as nodes, and the logical and causal relationships between the power business units are used as the edge weights between the nodes to construct a logical causal graph between the power business units.

[0012] S3: Real-time communication data packets are collected from the PLC communication link in real time, communication data packets to be obfuscated are selected from the real-time communication data packets according to the obfuscation selection rules, the power business units corresponding to the communication data packets to be obfuscated are identified based on the mapping relationship table, and the mimic power business units for mimicking analysis of the communication data packets to be obfuscated are selected based on the logical causal graph;

[0013] S4: Utilize the fused obfuscation generation network to receive the pseudo-power business unit, perform logical causal consistency forging on the communication data packet to be obfuscated, generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, and insert it into the communication flow of the PLC communication link as an accompanying cover data packet of the communication data packet to be obfuscated, thereby obtaining the obfuscated PLC communication traffic.

[0014] As a further improvement method of the present invention:

[0015] Optionally, the distributed power equipment in the microgrid system exchanges information via a PLC communication link, and the communication data packet is physical frame data in the PLC communication link, including:

[0016] The communication data packet includes data frame header information, function field, timestamp and payload, wherein the data frame header information includes a start flag, a length field and a CRC check code, the function field indicates the service function of the communication data packet, the timestamp is the generation time of the communication data packet, and the payload is the service layer data stream in the communication data packet;

[0017] Collect historical communication data packet sequences sent by distributed power equipment in the PLC communication link, extract communication data packets from the historical communication data packet sequences, functionally divide the communication data packets according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, and form multiple power business units, where each power business unit contains multiple communication data packets. The generation order of each communication data packet and the functional description of the function field in the communication data packet are recorded;

[0018] A mapping relationship between a function field and a power service unit of a communication data packet containing the function field is established to obtain a mapping relationship table between the function field and the power service unit.

[0019] Optionally, identifying logical relationships and causal relationships between different power business units based on communication data packets in the power business units includes:

[0020] The logical relationship between the different power business units includes temporal transition probability and semantic similarity;

[0021] The timing transition probability is the frequency of adjacent appearance of communication data packets associated with two power business units in a communication data packet sequence;

[0022] The communication data packet associated with the power business unit is the communication data packet contained in the power business unit;

[0023] The word vector model is used to convert the functional description into a word vector sequence. The cosine similarity between the two word vector sequences is calculated as the similarity between the two functional descriptions. The mean similarity of the functional descriptions between different power business units is used as the semantic similarity.

[0024] Adding minute-level time windows to a communication data packet sequence sent by a distributed power device, dividing the communication data packet sequence into a minute-level time window sequence, wherein the minute-level time window sequence is composed of multiple consecutive minute-level time windows, and each minute-level time window contains multiple communication data packets;

[0025] Count the occurrence frequency of communication data packets associated with the power business unit in each minute-level time window to form a frequency sequence of the power business unit;

[0026] Obtain the frequency series of two power business units and construct an autoregressive model and an extended model based on the autoregressive model. The autoregressive model uses the frequency series of one power business unit for prediction, while the extended model introduces the frequency series of the other power business unit as a prediction factor based on the autoregressive model.

[0027] The residual sum of squares of the autoregressive model and the extended model are calculated respectively, and the F test is performed to obtain the P value corresponding to the F test. The P value is converted into a numerical value between 0 and 1 as the causal relationship between the additional power business unit introduced in the extended model and the power business unit in the autoregressive model.

[0028] Optionally, based on the logical relationship and causal relationship between different power business units, a logical causal graph between the power business units is constructed, including:

[0029] The nodes in the logical causal graph are power business units, and the edge weights between the nodes are the logical relationships and causal relationships between the power business units. The logical relationships include the temporal transition probability and semantic similarity between the two power business units, and the causal relationship is the causal relationship between the two power business units.

[0030] Optionally, real-time communication data packets are collected from the PLC communication link in real time, and communication data packets to be obfuscated are selected from the real-time communication data packets, including:

[0031] Collect real-time communication data packets from the PLC communication link in real time, and extract the distributed power equipment from which the real-time communication data packets originate and the power business unit to which the communication data packets are classified;

[0032] The obfuscation selection rule is: select real-time communication data packets from acquisition-type distributed power equipment, located at the edge of the PLC communication link topology, and classified as power business units that are not causal relay nodes in the logical causal graph as communication data packets to be obfuscated;

[0033] The causal relay node in the logical causal graph is the node with the smallest sum of causal pointing relationships. i→n , indicating that it points to the power business unit Unit i The causal relationship, g i→n Indicates the power business unit Unit i Power Business Unit n The causal relationship, Unit n Indicates the nth power business unit, Unit i represents the i-th power business unit, i,n∈[1,N], and N represents the number of power business units.

[0034] Optionally, identifying the power service unit corresponding to the communication data packet to be obfuscated, and selecting a mimic power service unit for performing mimic analysis on the communication data packet to be obfuscated based on a logical causal graph, includes:

[0035] Extract the function field in the communication data packet to be obfuscated, and based on the mapping relationship table between the function field and the power business unit, select the power business unit mapped by the function field in the communication data packet to be obfuscated as the power business unit Unit corresponding to the communication data packet to be obfuscated, where Unit∈{Unit n |n∈[[1,N]};

[0036] Extract edge weights between the power business unit Unit and other power business units based on the logical causal graph. The edge weights represent the logical and causal relationships between the power business units, where other power business units are power business units different from the power business unit Unit.

[0037] According to the extracted edge weights, a multi-dimensional mimicry scoring model is constructed to obtain the multi-dimensional mimicry scores between the power business unit Unit and other power business units. The power business unit with the highest multi-dimensional mimicry score is selected as the mimicry power business unit for mimicry analysis of obfuscated communication data packets.

[0038] Optionally, the fused obfuscation generation network is used to receive the mimic power business unit, and logical causal consistency forging is performed on the communication data packet to be obfuscated to generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, including:

[0039] Extract the function field x1 and payload x2 of the communication data packet to be obfuscated;

[0040] Calculate the similarity between the functional description of the function field x1 and the functional description of any function field in the pseudo-power business unit, as well as the frequency of occurrence of the communication data packet associated with the function field in the pseudo-power business unit in the PLC communication link, obtain the similarity and frequency of occurrence of the function field in the pseudo-power business unit, calculate the product of the similarity and the frequency of occurrence, and select the function field with the highest product as the function field y1 in the obfuscated communication data packet;

[0041] The functional description of the function field x1 of the communication data packet to be obfuscated, the payload x2, and the functional description of the function field y1 in the pseudo-power business unit are used as inputs of the fusion obfuscation generation network;

[0042] A fusion-based obfuscation generation network is used to extract the word vector sequence of the function description, and the payload x2 is compressed into a context feature vector using Transformer encoding. The word vector sequence of the function description is then concatenated with the context feature vector to obtain a concatenated vector.

[0043] The generator in the fusion-type obfuscation generation network uses an MLP module with a multi-layer residual structure to fuse and reconstruct the features of the splicing vector in semantic and numerical modes, obtains a function descriptor that conforms to the function field y1 and a payload y2 that is contextually associated with the payload x2, and uses the payload y2 as the payload in the obfuscated communication data packet;

[0044] Constructing a data frame header information with a valid format as the data frame header information Q of the obfuscated communication data packet, and generating a timestamp Time of the obfuscated communication data packet;

[0045] Construct an obfuscated communication data packet: package = [Q, y1, Time, y2], and send the obfuscated communication data packet package at the timestamp Time.

[0046] In order to solve the above problems, the present invention also provides a large-scale microgrid security communication traffic obfuscation processing system, which includes a data acquisition device, a logic causal identification module, and a communication data packet obfuscation module:

[0047] The data acquisition device is used to collect communication data packets, perform functional division on the communication data packets according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, construct a mapping relationship table between the functional fields and the power business units, and form a plurality of power business units;

[0048] The logic causal identification module is used to identify the logical relationship and causal relationship between different power business units and construct a logic causal graph between the power business units;

[0049] The communication data packet obfuscation module is used to collect real-time communication data packets from the PLC communication link in real time, select the communication data packets to be obfuscated, identify the power business unit corresponding to the communication data packets to be obfuscated based on the mapping relationship table, and select the mimic power business unit for performing mimicry analysis on the communication data packets to be obfuscated based on the logical causal graph, receive the mimic power business unit using the fusion obfuscation generation network, perform logical causal consistency forgery on the communication data packets to be obfuscated, generate obfuscated communication data packets, and insert the generated obfuscated communication data packets into the communication flow of the PLC communication link as the PLC communication traffic after obfuscation processing;

[0050] In order to realize the above-mentioned large-scale microgrid security communication traffic obfuscation processing method.

[0051] In order to solve the above problem, the present invention further provides an electronic device, comprising:

[0052] a memory storing at least one instruction;

[0053] Communication interfaces to enable electronic equipment to communicate; and

[0054] The processor executes the instructions stored in the memory to implement the above-mentioned large-scale microgrid security communication traffic obfuscation processing method.

[0055] In order to solve the above problems, the present invention also provides a computer-readable storage medium, which stores at least one instruction, and the at least one instruction is executed by a processor in an electronic device to implement the above-mentioned large-scale microgrid security communication traffic obfuscation processing method.

[0056] Compared with the existing technology, the present invention proposes a large-scale microgrid secure communication traffic obfuscation processing method and system, which has the following beneficial effects:

[0057] First, to ensure that the obfuscation behavior has both a disturbing effect and does not affect the actual business function, the present invention designs the selection criteria for communication data packets from multiple dimensions, including basic attributes such as device type and network topology location. Specifically, the selection of communication data packets is first screened based on the distributed power equipment and functional attributes of the communication source, and priority is given to non-control communication data packets generated by acquisition-type power equipment (such as electricity meters), especially those whose function fields are identified as periodic business behaviors such as "telemetry reporting" and "periodic data transmission". Compared with control-type or abnormal alarm-type communications, acquisition-type communication data packets have higher redundancy and time tolerance, and semantic disguise processing on them will not interfere with the real-time control security of the power system. In addition, for high-frequency communication data packets with stable data structures, the present invention also prioritizes retaining them as obfuscation targets to improve the naturalness and coverage of the traffic after obfuscation processing. In addition, for data packets generated at the edge nodes of the PLC communication link topology, due to their strong business independence and less upstream and downstream dependencies, they are more suitable as obfuscation processing entries, which helps to achieve local controllability and overall generalization of obfuscation behavior.

[0058] Furthermore, compared to traditional obfuscation methods that rely on random insertion or simple scrambling, this method incorporates the functional semantics, temporal transition probabilities, and causal association information of power business units. This method utilizes a fused obfuscation generation network to achieve consistent forgery of business context, making obfuscated communication packets statistically indistinguishable from authentic communication packets. Furthermore, through the selection of simulated power business units based on a logical causal graph, scheduling errors caused by communication anomalies are effectively avoided, significantly improving the microgrid dispatch system's resistance to traffic feature analysis attacks and ensuring the accuracy of dispatch instructions and the stability of grid operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 A flow chart of a method for obfuscating secure communication traffic in a large-scale microgrid provided by one embodiment of the present invention;

[0060] Figure 2 A schematic diagram of an obfuscation processing method for a communication data packet to be obfuscated provided in one embodiment of the present invention;

[0061] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0062] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0063] The present embodiment provides a method for obfuscating secure communication traffic in a large-scale microgrid. The method can be executed by at least one of electronic devices, such as a server or a terminal, that can be configured to execute the method provided by the present embodiment. In other words, the method can be executed by software or hardware installed on a terminal or server device, where the software can be a blockchain platform. The server can include, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.

[0064] Reference Figure 1 , embodiment 1 of the present invention is:

[0065] S1: Collect communication data packets from the historical communication data packet sequence of the PLC communication link, divide the communication data packets into functions according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, and construct a mapping relationship table between function fields and power business units.

[0066] Distributed power equipment in a microgrid system exchanges information via a PLC communication link. The communication data packet is the physical frame data in the PLC communication link, including:

[0067] The communication data packet includes data frame header information, function field, timestamp and payload, wherein the data frame header information includes a start flag, a length field and a CRC check code, the function field indicates the service function of the communication data packet, the timestamp is the generation time of the communication data packet, and the payload is the service layer data stream in the communication data packet;

[0068] Collect historical communication data packet sequences sent by distributed power equipment in the PLC communication link, extract communication data packets from the historical communication data packet sequences, functionally divide the communication data packets according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, and form multiple power business units, where each power business unit contains multiple communication data packets. The generation order of each communication data packet and the functional description of the function field in the communication data packet are recorded;

[0069] A mapping relationship between a function field and a power service unit of a communication data packet containing the function field is established to obtain a mapping relationship table between the function field and the power service unit.

[0070] Specifically, the power business unit includes a reading business unit, a control or configuration business unit, a switch control business unit and an alarm business unit;

[0071] The read business unit includes but is not limited to the function fields 0x03 and 0x04, and the corresponding function descriptions are read holding register and read input register respectively; the control or configuration business unit includes but is not limited to the function fields 0x06 and 0x10, and the corresponding function descriptions are write single register and write multiple registers respectively;

[0072] The switch control business units include but are not limited to 0x05 and 0x08, and the corresponding functional descriptions are control coil and control multiple coils respectively; the alarm business units include but are not limited to function fields 0x31 and 0x32, and the corresponding functional descriptions are upload alarm event and alarm confirmation response respectively;

[0073] It should be noted that the functional fields involving register reading are classified as read-type business units, the functional fields with write properties are classified as control or configuration-type business units, the functional fields involving switch control are classified as switch control-type business units, and special or customized functional fields are used for event reporting, alarm transmission, etc., and are classified as alarm-type business units. The mapping relationship between functional fields and business units can be dynamically updated.

[0074] S2: Based on the communication data packets in the power business unit, the logical relationship and causal relationship between different power business units are identified. The power business units are used as nodes, and the logical relationship and causal relationship between the power business units are used as the edge weights between the nodes to construct a logical causal graph between the power business units.

[0075] Based on the communication data packets in the power business units, identifying the logical relationship and causal relationship between different power business units, including:

[0076] The logical relationship between the different power business units includes temporal transition probability and semantic similarity;

[0077] The timing transition probability is the frequency at which communication data packets associated with two power business units appear adjacent to each other in the communication data packet sequence. A higher timing transition probability indicates that the communication data packets associated with the two power business units appear adjacent to each other in the communication data packet sequence, and have a stronger logical association relationship. Specifically, a higher timing transition probability also indicates that the communication data packet of one power business unit is the input or trigger condition of another power business unit.

[0078] The communication data packet associated with the power business unit is the communication data packet contained in the power business unit;

[0079] A word vector model is used to convert functional descriptions into word vector sequences. The cosine similarity between two word vector sequences is calculated as the similarity between the two functional descriptions. The mean similarity of functional descriptions between different power business units is used as the semantic similarity. The higher the semantic similarity, the more frequent the interactive communication between the two power business units.

[0080] As an embodiment of the present invention, the word vector model is a Word2Vec model;

[0081] In a specific embodiment of the present application, the temporal transition probability is smoothed by combining the semantic similarity, wherein the calculation formula is:

[0082]

[0083] Among them, α i,j Indicates the power business unit Unit i To the Power Business Unit j The temporal transition probability of making a transition, represents the temporal transition probability α i,j Smoothness correction result; Count((Unit i →Unit j ) represents the power business unit Unit in the communication data packet sequence i and Power Business Unit j The number of times the associated communication data packets appear adjacently, Unit i ,Unit j ,Unit n They are the i, j, and nth power business units respectively, i, j, n∈[[1, N], N represents the number of power business units, Count(Unit i →Unit n ) represents the power business unit Unit in the communication data packet sequence i and Power Business Unit n The number of times the associated communication data packets appear adjacently;

[0084] S n,j Indicates the power business unit Unit n and Power Business Unit j The semantic similarity between them, γ represents the smoothing coefficient (the default value is 0.4 or 0.6), which is used to adjust the contribution of semantic similarity to the correction of temporal transition probability;

[0085] In the traditional time-series transition probability calculation process, the transition relationship between power business units depends entirely on the actual frequency of occurrence in the communication data packet sequence, which can easily lead to severely low or zero transition probabilities in data-sparse areas. In particular, when the communication data packet sequence is short or the types of power business units are large, some reasonable but rare relationships between power business units will be completely ignored, limiting the diversity and robustness of the generated obfuscated communication data packets.

[0086] Based on the above formula, according to the power business unit Unit j and Power Business Unit n The semantic similarity S between n,j , combined with semantic similarity S n,j The associated temporal transition probability α i,n , get the time series transfer probability compensation value based on semantic similarity weighting, power business unit Unit j and Power Business Unit n The higher the semantic similarity between them, the more frequent the interaction between them. i,n The higher the value, the higher the power business unit i and Power Business Unit n The stronger the logical relationship between them, the better the i,j The higher the compensation value, the less likely the power business unit i and Power Business Unit j There is a problem of insufficient observations between the two, resulting in a low probability of time series transition;

[0087] The smoothness correction method provided in this embodiment not only preserves the credibility of the original timing transition probability, but also significantly improves the expression integrity of the timing transition probability in the low-frequency path, enhances the semantic rationality of the obfuscated communication data packets, and improves the concealment and generalization ability of the obfuscated communication data packets generated under mimicry analysis.

[0088] Adding minute-level time windows to a communication data packet sequence sent by a distributed power device, dividing the communication data packet sequence into a minute-level time window sequence, wherein the minute-level time window sequence is composed of multiple consecutive minute-level time windows, and each minute-level time window contains multiple communication data packets;

[0089] Count the occurrence frequency of communication data packets associated with the power business unit in each minute-level time window to form a frequency sequence of the power business unit;

[0090] For example, if the power business unit Unit n The occurrence frequencies of the associated communication data packets in the 1st to 5th minute time windows are 1, 2, 0, 5, and 4 respectively. nThe frequency sequence is (1,2,0,5,4);

[0091] Obtain the frequency series of two power business units and construct an autoregressive model and an extended model based on the autoregressive model. The autoregressive model uses the frequency series of one power business unit for prediction, while the extended model introduces the frequency series of the other power business unit as a prediction factor based on the autoregressive model.

[0092] The residual sum of squares of the autoregressive model and the extended model are calculated respectively, and the F test is performed to obtain the P value corresponding to the F test. The P value is converted into a numerical value between 0 and 1 as the causal relationship between the additional power business unit introduced in the extended model and the power business unit in the autoregressive model. The closer the causal relationship is to 1, the more significant the causal impact of the additional power business unit introduced in the extended model on the power business unit in the autoregressive model.

[0093] Specifically, using the power business unit Unit n The autoregressive model constructed by the frequency sequence of n , additionally introduce the power business unit Unit i The frequency sequence of , the constructed extended model is Calculate the autoregressive model separately n and extended models The residual sum of squares is calculated and the F test is performed to obtain the P value corresponding to the F test. The P value is converted into a value between 0 and 1 as the power business unit Unit i Power Business Unit n The causal relationship also points to the power business unit Unit i The causal relationship of

[0094] In a specific embodiment of the present application, the conversion formula between causal relationship and P value is:

[0095] g = 1-min(1,p_value);

[0096] Here, g represents the causal relationship obtained by converting p_value, p_value represents the P value, and min(1,p_value) represents selecting the minimum value between 1 and p_value. This conversion method can expand the binary judgment in the statistical sense into a continuous numerical expression, realizing the quantitative representation of the causal relationship.

[0097] Based on the logical relationship and causal relationship between different power business units, a logical causal graph between power business units is constructed, including:

[0098] The nodes in the logical causal graph are power business units, and the edge weights between the nodes are the logical relationships and causal relationships between the power business units. The logical relationships include the temporal transition probability and semantic similarity between the two power business units, and the causal relationship is the causal relationship between the two power business units.

[0099] It should be noted that the logical causal graph is composed of nodes and edge weights between nodes, which are divided into node sets and edge weight sets;

[0100] The node set is {Unit n |n∈[1,N]}, the edge weight set is {w(Unit n ,Unit i )|n,i∈

[0101] [1,N],n≠i},Unit n Indicates the nth power business unit, N indicates the number of power business units, w(Unit n ,Unit i ) represents the power business unit Unit n ,Unit i The edge weight between them, where the edge weight w(Unit n ,Unit i ) including the power business unit Unit n With Unit i The semantic similarity between n,i , Power Business Unit n To Unit i Temporal transition probability of transition and the Power Business Unit i To Unit n Temporal transition probability of transition Power Business Unit n Unit i The causal relationship g n→i and the Power Business Unit i Unit n The causal relationship g i→n .

[0102] S3: Real-time communication data packets are collected from the PLC communication link in real time, communication data packets to be obfuscated are selected from the real-time communication data packets according to the obfuscation selection rules, the power business units corresponding to the communication data packets to be obfuscated are identified based on the mapping relationship table, and the mimic power business units for mimicking analysis of the communication data packets to be obfuscated are selected based on the logical causal graph.

[0103] Real-time communication data packets are collected from the PLC communication link in real time, and communication data packets to be obfuscated are selected from the real-time communication data packets, including:

[0104] Collect real-time communication data packets from the PLC communication link in real time, and extract the distributed power equipment from which the real-time communication data packets originate and the power business unit to which the communication data packets are classified;

[0105] The obfuscation selection rule is: select real-time communication data packets from acquisition-type distributed power equipment, located at the edge of the PLC communication link topology, and classified as power business units that are not causal relay nodes in the logical causal graph as communication data packets to be obfuscated;

[0106] The distributed power collection equipment regularly uploads real-time communication data packets at a high frequency. The uploaded real-time communication data packets have a fixed data structure and high tolerance for service delays, and the obfuscation has little impact on the service execution path.

[0107] The causal relay node in the logical causal graph is the node with the smallest sum of causal pointing relationships. The real-time communication data packets sent by this node are generally control instruction type or task confirmation type communication behaviors. i→n , indicating that it points to the power business unit Unit i The causal relationship, g i→n Indicates the power business unit Unit i Power Business Unit n The causal relationship, Unit n Indicates the nth power business unit, Unit i represents the i-th power business unit, i,n∈[1,N], N represents the number of power business units;

[0108] The real-time communication data packets sent by the distributed power equipment at the edge of the PLC communication link topology are selected for obfuscation to avoid affecting the synchronous business process among multiple distributed power equipment.

[0109] Identifying the power business unit corresponding to the communication data packet to be obfuscated, and selecting a mimic power business unit for performing mimicry analysis on the communication data packet to be obfuscated based on a logical causal graph, including:

[0110] Extract the function field in the communication data packet to be obfuscated, and based on the mapping relationship table between the function field and the power business unit, select the power business unit mapped by the function field in the communication data packet to be obfuscated as the power business unit Unit corresponding to the communication data packet to be obfuscated, where Unit∈{Unit n |n∈[[1,N]};

[0111] Extract edge weights between the power business unit Unit and other power business units based on the logical causal graph. The edge weights represent the logical and causal relationships between the power business units, where other power business units are power business units different from the power business unit Unit.

[0112] According to the extracted edge weights, a multi-dimensional mimicry scoring model is constructed to obtain the multi-dimensional mimicry scores between the power business unit Unit and other power business units. The power business unit with the highest multi-dimensional mimicry score is selected as the mimicry power business unit for mimicry analysis of obfuscated communication data packets.

[0113] It should be noted that the scoring dimensions of the multi-dimensional mimicry score include structural similarity score, semantic similarity score, temporal transition probability score and causal strength score, wherein the structural similarity is calculated by the intersection and union of the neighbor nodes between the two power business units. The higher the structural similarity, the more similar the neighbor nodes of the two power business units are, and the closer the structural positions in the logical causal graph are. The higher the semantic similarity score, the higher the contextual mimicry consistency between the two power business units. The higher the temporal transition probability score, the more the data packets associated with the two power business units often appear together, which helps to enhance the realism and continuity of the context during the mimicry analysis process. The higher the causal strength score, the higher the causal explanation ability between the two power business units.

[0114] For example, if the power business unit Unit n and Power Business Unit i The time-frequency transition probability between Greater than the preset transition probability threshold (preset 0.4), and the causal relationship g n→i If it is greater than the preset causal threshold (preset 0.6), it means that the power business unit Unit i For the power business unit Unit n Neighbor nodes of

[0115] In a specific embodiment of the present application, the scoring formula for the multi-dimensional mimicry scoring is:

[0116]

[0117] Among them, Score(Unit,Unit n ) represents the power business unit Unit and the power business unit Unit n Multi-dimensional mimicry score, Score k (Unit,Unit n ) represents the power business unit Unit and the power business unit Unit nThe scoring result of the kth scoring dimension, k∈[1,4], where the 1st to 4th scoring dimensions are the structural similarity score, semantic similarity score, temporal transition probability score and causal strength score respectively, λ k represents the scoring weight of the k-th scoring dimension, And preset λ1=0.2,λ2=0.2,λ3=0.3,λ4=0.4;

[0118] L(Unit) represents the neighbor node set of the power business unit Unit. n ) represents the power business unit Unit n The neighbor node set of , Sum(·) represents the number of nodes in the statistical set;

[0119] Score2(Unit,Unit n ) corresponds to the power business unit Unit and the power business unit Unit n The semantic similarity between Score3(Unit,Unit n ) corresponds to the power business unit Unit to the power business unit Unit n The temporal transfer probability of the transfer, Score4(Unit,Unit n ) corresponds to the power business unit Unit to Unit n causal relationship;

[0120] Compared with traditional communication obfuscation methods based on random perturbations or static rules, this application introduces four scoring indicators: structural similarity, semantic similarity, temporal transition probability, and causal relationship strength. It can perform contextual semantic mimicry analysis on obfuscated communication data packets from multiple dimensions. It not only ensures the functional consistency of the obfuscated communication packets with the real business at the semantic level, but also maintains the continuity of their structural roles, time sequences, and behavior-driven chains in the logical causal graph, effectively avoiding communication behavior anomalies or control process interruptions caused by improper obfuscation.

[0121] Specifically, the structural similarity score helps to improve the global consistency and anti-detection capability of mimetic obfuscation, the semantic similarity score helps to generate semantically coherent and rational obfuscated communication packets, the timing transition probability score helps to maintain the realism of the obfuscated communication flow in the time series, and reduce the identification risk of traffic behavior model detection. In addition, the selection of power business units and power business units with causal relationships for obfuscation replacement helps to maintain the functional chain consistency of the entire communication flow and prevent abnormal behavior caused by causal breaks.

[0122] S4: Utilize the fused obfuscation generation network to receive the pseudo-power business unit, perform logical causal consistency forging on the communication data packet to be obfuscated, generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, and insert it into the communication flow of the PLC communication link as an accompanying cover data packet of the communication data packet to be obfuscated, thereby obtaining the obfuscated PLC communication traffic.

[0123] The fused obfuscation generation network is used to receive the pseudo-power business unit, perform logical causal consistency forging on the obfuscated communication data packet, and generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, including:

[0124] Extract the function field x1 and payload x2 of the communication data packet to be obfuscated, where the function field represents the service function of the communication data packet and the payload is the service layer data stream in the communication data packet;

[0125] Calculate the similarity between the functional description of the function field x1 and the functional description of any function field in the pseudo-power business unit, as well as the frequency of occurrence of the communication data packet associated with the function field in the pseudo-power business unit in the PLC communication link, obtain the similarity and frequency of occurrence of the function field in the pseudo-power business unit, calculate the product of the similarity and the frequency of occurrence, and select the function field with the highest product as the function field y1 in the obfuscated communication data packet;

[0126] Specifically, the word vector model is used to convert the functional description into a word vector sequence, and the cosine similarity between the two word vector sequences is calculated as the similarity between the two functional descriptions;

[0127] The functional description of the function field x1 of the communication data packet to be obfuscated, the payload x2, and the functional description of the function field y1 in the pseudo-power business unit are used as inputs of a fusion obfuscation generation network in the form of a generative adversarial neural network;

[0128] A fusion-based obfuscation generation network is used to extract the word vector sequence of the function description, and the payload x2 is compressed into a context feature vector using Transformer encoding. The word vector sequence of the function description is then concatenated with the context feature vector to obtain a concatenated vector.

[0129] The generator in the fusion-type obfuscation generation network uses an MLP module with a multi-layer residual structure to fuse and reconstruct the features of the concatenated vector in semantic and numerical modes, thereby obtaining a functional descriptor that conforms to the function field y1 and a payload y2 that is contextually associated with the payload x2. The payload y2 is used as the payload in the obfuscated communication data packet. Specifically, the Jensen-Shannon divergence is used as the loss function for adversarial training to effectively measure the similarity between the distribution of the generated obfuscated communication data packet and the real communication data, thereby ensuring that the obfuscated communication data packet generated by the generator is statistically close to the real communication data packet.

[0130] Constructing a data frame header information with a valid format as the data frame header information Q of the obfuscated communication data packet, and generating a timestamp Time of the obfuscated communication data packet;

[0131] Construct an obfuscated communication data packet: package = [Q, y1, Time, y2], and send the obfuscated communication data packet package at the timestamp Time.

[0132] Specifically, the timestamp Time is generated as follows:

[0133]

[0134] Among them, Time0 represents the timestamp of the communication data packet to be obfuscated, f represents the sending frequency of the communication data packet associated with the pseudo-power business unit, and δ represents the disturbance parameter that conforms to the Gaussian distribution.

[0135] like Figure 2 The figure shows a schematic diagram of an obfuscation processing method for a communication data packet to be obfuscated, which uses multiple obfuscation processing methods to generate an obfuscated communication data packet with consistent logical causality in the function field, a payload that conforms to the function field description, and data consistency.

[0136] This embodiment reasonably calculates the expected packet transmission interval based on the historical packet transmission frequency of the pseudo-power business unit, and performs timing disturbance control in combination with the timestamp of the communication data packet to be obfuscated, effectively avoiding traffic analysis and identification due to frequency camouflage distortion. By introducing a light perturbation and time fusion mechanism, dynamic balance and context consistency of the microgrid PLC communication traffic in the timing domain after obfuscation processing are achieved, significantly enhancing the robustness and attack and interference resistance of the microgrid dispatching system.

[0137] Example 2:

[0138] A large-scale microgrid secure communication traffic obfuscation processing system includes a data acquisition device, a logic causal identification module, and a communication data packet obfuscation module:

[0139] The data acquisition device is used to collect communication data packets, perform functional division on the communication data packets according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, construct a mapping relationship table between the functional fields and the power business units, and form a plurality of power business units;

[0140] The logic causal identification module is used to identify the logical relationship and causal relationship between different power business units and construct a logic causal graph between the power business units;

[0141] The communication data packet obfuscation module is used to collect real-time communication data packets from the PLC communication link in real time, select the communication data packets to be obfuscated, identify the power business unit corresponding to the communication data packets to be obfuscated based on the mapping relationship table, and select the pseudo-power business unit for performing pseudo-analysis on the communication data packets to be obfuscated based on the logical causal graph, use the fusion obfuscation generation network to receive the pseudo-power business unit, perform logical causal consistency forgery on the communication data packets to be obfuscated, generate obfuscated communication data packets, and insert the generated obfuscated communication data packets into the communication flow of the PLC communication link as the PLC communication traffic after obfuscation processing.

[0142] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited to this structure.

[0143] It should be noted that the serial numbers of the above-mentioned embodiments of the present invention are for descriptive purposes only and do not represent the advantages or disadvantages of the embodiments. In addition, the terms "including", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, device, article or method comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "including a ..." does not exclude the presence of other identical elements in the process, device, article or method comprising the element.

[0144] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0145] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A large-scale microgrid secure communication traffic obfuscation processing method, characterized in that: The method comprises: S1: Collect communication data packets from the historical communication data packet sequence of the PLC communication link, divide the communication data packets into functions according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, and construct a mapping relationship table between function fields and power business units; S2: Based on the communication data packets in the power business units, the logical and causal relationships between different power business units are identified. The power business units are used as nodes, and the logical and causal relationships between the power business units are used as the edge weights between the nodes to construct a logical causal graph between the power business units. S3: Real-time communication data packets are collected from the PLC communication link in real time, communication data packets to be obfuscated are selected from the real-time communication data packets according to the obfuscation selection rules, the power business units corresponding to the communication data packets to be obfuscated are identified based on the mapping relationship table, and the mimic power business units for mimicking analysis of the communication data packets to be obfuscated are selected based on the logical causal graph; S4: Utilize the fused obfuscation generation network to receive the pseudo-power business unit, perform logical causal consistency forging on the communication data packet to be obfuscated, generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, and insert it into the communication flow of the PLC communication link as an accompanying cover data packet of the communication data packet to be obfuscated, thereby obtaining the obfuscated PLC communication traffic.

2. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 1, characterized in that: Distributed power equipment in a microgrid system exchanges information via a PLC communication link. The communication data packet is the physical frame data in the PLC communication link, including: The communication data packet includes data frame header information, function field, timestamp and payload, wherein the data frame header information includes a start flag, a length field and a CRC check code, the function field indicates the service function of the communication data packet, the timestamp is the generation time of the communication data packet, and the payload is the service layer data stream in the communication data packet; Collect historical communication data packet sequences sent by distributed power equipment in the PLC communication link, extract communication data packets from the historical communication data packet sequences, functionally divide the communication data packets according to the function fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, and form multiple power business units, where each power business unit contains multiple communication data packets. The generation order of each communication data packet and the functional description of the function field in the communication data packet are recorded; A mapping relationship between a function field and a power service unit of a communication data packet containing the function field is established to obtain a mapping relationship table between the function field and the power service unit.

3. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 2, characterized in that: Based on the communication data packets in the power business units, identifying the logical relationship and causal relationship between different power business units, including: The logical relationship between the different power business units includes temporal transition probability and semantic similarity; The timing transition probability is the frequency of adjacent appearance of communication data packets associated with two power business units in a communication data packet sequence; The communication data packet associated with the power business unit is the communication data packet contained in the power business unit; The word vector model is used to convert the functional description into a word vector sequence. The cosine similarity between the two word vector sequences is calculated as the similarity between the two functional descriptions. The mean similarity of the functional descriptions between different power business units is used as the semantic similarity. Adding minute-level time windows to a communication data packet sequence sent by a distributed power device, dividing the communication data packet sequence into a minute-level time window sequence, wherein the minute-level time window sequence is composed of multiple consecutive minute-level time windows, and each minute-level time window contains multiple communication data packets; Count the occurrence frequency of communication data packets associated with the power business unit in each minute-level time window to form a frequency sequence of the power business unit; Obtain the frequency series of two power business units and construct an autoregressive model and an extended model based on the autoregressive model. The autoregressive model uses the frequency series of one power business unit for prediction, while the extended model introduces the frequency series of the other power business unit as a prediction factor based on the autoregressive model. The residual sum of squares of the autoregressive model and the extended model are calculated respectively, and the F test is performed to obtain the P value corresponding to the F test. The P value is converted into a numerical value between 0 and 1 as the causal relationship between the additional power business unit introduced in the extended model and the power business unit in the autoregressive model.

4. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 3, characterized in that: Based on the logical relationship and causal relationship between different power business units, a logical causal graph between power business units is constructed, including: The nodes in the logical causal graph are power business units, and the edge weights between the nodes are the logical relationships and causal relationships between the power business units. The logical relationships include the temporal transition probability and semantic similarity between the two power business units, and the causal relationship is the causal relationship between the two power business units.

5. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 1, characterized in that: Real-time communication data packets are collected from the PLC communication link in real time, and communication data packets to be obfuscated are selected from the real-time communication data packets, including: Collect real-time communication data packets from the PLC communication link in real time, and extract the distributed power equipment from which the real-time communication data packets originate and the power business unit to which the communication data packets are classified; The obfuscation selection rule is: select real-time communication data packets from acquisition-type distributed power equipment, located at the edge of the PLC communication link topology, and classified as power business units that are not causal relay nodes in the logical causal graph as communication data packets to be obfuscated; The causal relay node in the logical causal graph is the node with the smallest sum of causal pointing relationships. i→n , indicating that it points to the power business unit Unit i The causal relationship, g i→n Indicates the power business unit Unit i Power Business Unit n The causal relationship, Unit n Indicates the nth power business unit, Unit i represents the i-th power business unit, i,n∈[1,N], and N represents the number of power business units.

6. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 5, characterized in that: Identifying the power business unit corresponding to the communication data packet to be obfuscated, and selecting a mimic power business unit for performing mimicry analysis on the communication data packet to be obfuscated based on a logical causal graph, including: Extract the function field in the communication data packet to be obfuscated, and based on the mapping relationship table between the function field and the power business unit, select the power business unit mapped by the function field in the communication data packet to be obfuscated as the power business unit Unit corresponding to the communication data packet to be obfuscated, where Unit∈{Unit n |n∈[[1,N]}; Extract edge weights between the power business unit Unit and other power business units based on the logical causal graph. The edge weights represent the logical and causal relationships between the power business units, where other power business units are power business units different from the power business unit Unit. According to the extracted edge weights, a multi-dimensional mimicry scoring model is constructed to obtain the multi-dimensional mimicry scores between the power business unit Unit and other power business units. The power business unit with the highest multi-dimensional mimicry score is selected as the mimicry power business unit for mimicry analysis of obfuscated communication data packets.

7. A large-scale microgrid secure communication traffic obfuscation processing method according to claim 1, characterized in that: The fused obfuscation generation network is used to receive the pseudo-power business unit, perform logical causal consistency forging on the obfuscated communication data packet, and generate an obfuscated communication data packet that is logically causally consistent with the communication data packet to be obfuscated, including: Extract the function field x1 and payload x2 of the communication data packet to be obfuscated; Calculate the similarity between the functional description of the function field x1 and the functional description of any function field in the pseudo-power business unit, as well as the frequency of occurrence of the communication data packet associated with the function field in the pseudo-power business unit in the PLC communication link, obtain the similarity and frequency of occurrence of the function field in the pseudo-power business unit, calculate the product of the similarity and the frequency of occurrence, and select the function field with the highest product as the function field y1 in the obfuscated communication data packet; The functional description of the function field x1 of the communication data packet to be obfuscated, the payload x2, and the functional description of the function field y1 in the pseudo-power business unit are used as inputs of the fusion obfuscation generation network; A fusion-based obfuscation generation network is used to extract the word vector sequence of the function description, and the payload x2 is compressed into a context feature vector using Transformer encoding. The word vector sequence of the function description is then concatenated with the context feature vector to obtain a concatenated vector. The generator in the fusion-type obfuscation generation network uses an MLP module with a multi-layer residual structure to fuse and reconstruct the features of the splicing vector in semantic and numerical modes, obtains a function descriptor that conforms to the function field y1 and a payload y2 that is contextually associated with the payload x2, and uses the payload y2 as the payload in the obfuscated communication data packet; Constructing a data frame header information with a valid format as the data frame header information Q of the obfuscated communication data packet, and generating a timestamp Time of the obfuscated communication data packet; Construct an obfuscated communication data packet: package = [Q, y1, Time, y2], and send the obfuscated communication data packet package at the timestamp Time.

8. A large-scale microgrid secure communication traffic obfuscation processing system, characterized in that: The large-scale microgrid secure communication traffic obfuscation processing system includes a data acquisition device, a logic causal identification module, and a communication data packet obfuscation module: The data acquisition device is used to collect communication data packets, perform functional division on the communication data packets according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, construct a mapping relationship table between the functional fields and the power business units, and form a plurality of power business units; The logic causal identification module is used to identify the logical relationship and causal relationship between different power business units and construct a logic causal graph between the power business units; The communication data packet obfuscation module is used to collect real-time communication data packets from the PLC communication link in real time, select the communication data packets to be obfuscated, identify the power business unit corresponding to the communication data packets to be obfuscated based on the mapping relationship table, and select the mimic power business unit for performing mimicry analysis on the communication data packets to be obfuscated based on the logical causal graph, receive the mimic power business unit using the fusion obfuscation generation network, perform logical causal consistency forgery on the communication data packets to be obfuscated, generate obfuscated communication data packets, and insert the generated obfuscated communication data packets into the communication flow of the PLC communication link as the PLC communication traffic after obfuscation processing; To implement the large-scale microgrid secure communication traffic obfuscation processing method as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Financial electric power data fusion method based on federated learning in asymmetric scene and medium

    CN115130880A

  • Generative adversarial network-based power grid flow data privacy protection method and system

    CN119210801A

  • Power production data private network security situation awareness system and method

    CN120110735A

  • A method of protecting against DDoS attacks based on traffic classification

    RU2018109398A3

  • Real-time packet loss concealment using deep generative networks

    US20230377584A1