PMU measurement system-oriented network attack automatic identification and identification method and apparatus, and medium

Through dynamic measurement point weight allocation and topology-aware correlation coefficient strategy, combined with deep learning to integrate topology and traffic information, the problem of attack identification under dynamic topology changes in PMU network security is solved, and efficient automatic identification and authentication are achieved.

CN120602214APending Publication Date: 2025-09-05内蒙古电力(集团)有限责任公司电力调度控制分公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511027253.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing PMU network security protection solutions are difficult to adapt to the dynamic changes of power network topology and lack the collaborative analysis of network traffic characteristics and topology correlation, resulting in a high missed detection rate and poor recognition effect, especially in complex attack scenarios.

Method used

A dynamic measurement point weight distribution network and topology-aware correlation coefficient strategy are adopted. Through deep learning, network topology and traffic information are integrated to construct PMU feature extractor, feature evaluator and feature discriminator to realize automatic identification and authentication of network attacks.

Benefits of technology

It improves the accuracy and reliability of PMU network attack identification, provides an end-to-end automatic identification and authentication solution, and adapts to the dynamic changes of the power grid system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602214A_ABST
    Figure CN120602214A_ABST
Patent Text Reader

Abstract

The invention provides a PMU measurement system-oriented network attack automatic identification and identification method and apparatus, and a medium, and belongs to the field of power system network security. According to the method, a PMU feature extractor, a PMU feature evaluator and a PMU feature discriminator are included, the PMU feature extractor is composed of p PMU feature extraction units in a stacked mode, an overall training strategy is designed based on the three parts, and an automatic network attack recognition and identification strategy is provided. According to the method, strategies such as a dynamic measuring point weight distribution network and a topology perception correlation coefficient adaptive to a power grid system are innovatively designed, and network topology and flow information are fused, so that the abnormal state in the network is more accurately captured; a deep learning strategy is adopted, and good generalization generation performance is achieved; the existence of a PMU feature evaluator ensures the robustness and stability of feature mapping; an end-to-end solution for automatic identification of PMU measurement system network attacks is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of power system network security, and in particular to a method, device, and medium for automatically identifying and authenticating network attacks on a PMU measurement system. Background Art

[0002] Synchronized phasor measurement units (PMUs), core monitoring devices in smart grids, achieve microsecond-level synchronization through GPS timing. They can collect dynamic data such as voltage, current, and frequency at high frequencies, supporting state estimation, stability analysis, and fault location in wide-area measurement systems (WAMS). While PMU technology has been widely used in power system transient process monitoring and renewable energy grid integration control, its cybersecurity protection remains significantly limited. Existing research primarily focuses on detecting specific attack types, such as false data injection (FDI) and GPS spoofing attacks. Defenses often rely on static rules (such as threshold detection) or models based on fixed topologies. However, power network topologies often change dynamically due to line switching and node commissioning and decommissioning. Static rules struggle to adapt to real-time structural changes, resulting in increased false negatives. Furthermore, most security solutions process traffic data or topology information in isolation, lacking a coordinated analysis of network traffic characteristics and topological correlations, and are unable to capture the propagation patterns of anomalies across measurement points caused by attacks. This fragmented approach exhibits significant limitations in complex attack scenarios, such as coordinated attacks or topology spoofing.

[0003] Deep unsupervised learning primarily uses clustering and generative methods for attack identification. Clustering algorithms (such as K-means and hierarchical clustering) detect anomalies by grouping unlabeled traffic data based on similarities. Generative models (such as autoencoders and generative adversarial networks) identify anomalies based on data reconstruction errors or latent space distributions. However, these methods face significant challenges in PMU network security scenarios. Traditional clustering relies on metrics such as Euclidean distance, which makes it difficult to effectively capture the temporal dependencies and topological spatial correlations in PMU traffic. For example, a cyberattack may only alter traffic characteristics along a specific topological path. Clustering algorithms, ignoring the electrical coupling between nodes (such as adjacency matrix degree correlation), are unable to identify such localized anomalies. Generative models also face adaptability issues: Autoencoders learn normal traffic patterns through reconstruction losses, but PMU data is subject to physical constraints of the power grid (such as power balancing). Standard reconstruction errors can overlook legitimate data fluctuations within these topological constraints, leading to false positives. Generative adversarial networks, while capable of synthesizing attack samples, struggle to model the complex impact of dynamic topological changes on traffic distribution, resulting in discrepancies between generated data and real-world attack scenarios. In addition, existing unsupervised methods mostly focus on a single data source (such as traffic or topology), lack a joint optimization mechanism for the dynamic weight allocation of measurement points and topological correlation coefficients, and cannot achieve cross-dimensional authentication of attack behaviors, which weakens the reliability of the identification results. Summary of the Invention

[0004] In order to solve the above technical problems, the present application proposes a method, device and medium for automatic identification and authentication of network attacks for PMU measurement systems.

[0005] The technical solution adopted in this application is: a method for automatically identifying and verifying network attacks on a PMU measurement system, comprising the following steps:

[0006] Step 1: Training of the overall model, where the model consists of three modules: PMU feature extractor, PMU feature evaluator and PMU feature discriminator. The PMU feature extraction units are composed in a stacked form and the parameters of each unit are independent;

[0007] The pre-processed daily flow data of the complete PMU measurement system and the network structure data of the PMU measurement system are used as training data to carry out unsupervised joint training of the PMU feature extractor, PMU feature extractor and PMU anomaly discriminator;

[0008] Each PMU feature extraction unit consists of a dynamic measurement point weight distribution network and a topology-aware correlation coefficient, and integrates the measurement point and topology information;

[0009] Step 2: Automatic identification and authentication of network attacks based on PMU feature extractor and PMU feature discriminator: Use the trained PMU feature extractor and PMU feature discriminator with fixed parameters to automatically identify and authenticate network tools on target traffic data.

[0010] Furthermore, the steps of overall model training are as follows:

[0011] S11: Collect the PMU measurement system measurement point data and PMU measurement system network structure data and pre-process the data set as the training set. Define the pre-processed and complete daily flow data of the PMU measurement system for training as , the PMU measurement system network structure data is ;

[0012] S12: Initialize the learnable parameters and preset parameters of the PMU feature extractor, PMU feature evaluator, and PMU feature discriminator;

[0013] S13: Dataset and Input PMU feature extractor to get output feature set ;

[0014] S14: Feature collection Input PMU feature evaluator and calculate feature evaluation loss ;

[0015] S15: Feature collection Input PMU feature discriminator and calculate feature discrimination loss ;

[0016] S16: Calculate the overall loss: ,in is an adjustable parameter;

[0017] S17: Based on overall loss Optimize the learnable parameters of PMU feature extractor, PMU feature evaluator and PMU feature discriminator;

[0018] S18: Shuffle the order of the training set, then repeat steps S11-S17 multiple times until the parameters converge.

[0019] Furthermore, step S13 includes:

[0020] S13.1: Calculation of dynamic measurement point weight distribution coefficients:

[0021] The dynamic measurement point weight distribution network receives the input PMU flow data or the data output by the upper layer PMU feature extraction unit As input, the dynamic measurement point weight distribution coefficient of the current traffic data is calculated by learning network parameters. , the formula is as follows:

[0022] ;

[0023] in, The network measurement point number indicating the source of the flow data; Indicates the stacking level number corresponding to the current PMU feature extraction unit. Indicates the adjacent measurement points of the current level measurement point i Traffic information or characteristics, is a learnable parameter vector, express The dimension size, Represents a splicing operation, are learnable network parameters;

[0024] S13.2: Calculate according to the topology-aware correlation coefficient:

[0025] S13.2.1: Calculate the adjacency matrix corresponding to the topology of the measurement point network in the PMU measurement system , where each element represents the connection status between the corresponding two measurement points, 1 means there is a connection, and 0 means there is no connection;

[0026] S13.2.2: Based on Calculate the degree matrix corresponding to the topological structure of the measuring point network ;

[0027] S13.2.3: Calculate the network perception matrix of the measurement points: ;

[0028] S13.2.4: Compute the k-th order topology-aware association matrix :

[0029] ;

[0030] Where k is a parameter, Elements in is the topologically aware correlation coefficient between measurement points;

[0031] S13.3: Fusion of measurement points and topology information:

[0032] S13.3.1: The fusion coefficient of the measurement point and topology information can be obtained according to the following formula :

[0033] ;

[0034] in is the activation function, Indicates measuring point The set of adjacent network points, and They represent the topology-aware correlation coefficient and dynamic measurement point weight distribution coefficient between measurement points respectively;

[0035] S13.3.2: The fusion of measurement points and topology information can be used to obtain the fused feature output according to the following formula:

[0036] ;

[0037] in, is a nonlinear activation function, For measuring points exist The final output of the layer PMU feature extraction unit, is a learnable parameter;

[0038] S13.4: Repeat steps S13.1-13.3 to obtain the stacked The final output feature set of the PMU feature extractor composed of PMU feature extraction units .

[0039] Furthermore, the feature evaluation loss The expression is:

[0040] ;

[0041] Where n represents the total number of samples in the traffic data set, MSE is the mean square error loss function, is an adjacent square matrix, is the feature recovery matrix.

[0042] Furthermore, feature discrimination loss The expression is:

[0043] ;

[0044] in, Represents the total number of samples in the dataset, Indicates the number of network behavior template features, is the probability output of the PMU feature discriminator, expressing the measurement point With template features The similarity probability between is the target probability, through the formula calculate.

[0045] Furthermore, step 2 specifically includes the following steps:

[0046] S21: Connect the trained PMU feature extractor and PMU feature discriminator to form a network attack automatic identifier. All parameters of the network attack automatic identifier are fixed without calculating any loss function.

[0047] S22: Build a network attack behavior identifier, and after the construction is completed, connect the network attack behavior identifier to the output of the network attack automatic identifier;

[0048] S24: Input the abnormality discrimination probability distribution into the network attack identifier, and output the final network behavior category corresponding number after calculation. The network attack behavior identifier receives the abnormality discrimination probability distribution as input, and selects the network behavior corresponding to the network behavior template feature corresponding to the maximum probability as the final output.

[0049] Furthermore, the specific construction method of the network attack behavior identifier is as follows:

[0050] S22.1: Extract all network behavior template features and find the measurement point data corresponding to the training set feature closest to each template feature;

[0051] S22.2: Network security experts manually determine the network behavior category to which each data point belongs and label it with the category number of the corresponding network behavior template feature. At this time, each network behavior template feature represents a network behavior.

[0052] S23: Connect the network attack automatic identifier to the PMU measurement system to measure the daily traffic data of the system. and network topology As input, after calculation, the output is the abnormality discrimination probability distribution .

[0053] A computer device comprises a memory, a processor and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method.

[0054] A computer-readable storage medium stores a computer program / instruction thereon, which implements the steps of the method when executed by a processor.

[0055] A computer program product comprises a computer program / instructions which, when executed by a processor, implement the steps of the method.

[0056] The beneficial effects of this application compared to the existing technology are as follows: this application innovatively designs a dynamic measurement point weight distribution network and topology-aware correlation coefficient strategies that are adapted to the power grid system, and integrates network topology and traffic information into a fusion strategy to more accurately capture abnormal conditions in the network; this application adopts a deep learning strategy with good generalization and generative properties; the existence of a PMU feature evaluator ensures the robustness and stability of the feature mapping; and provides an end-to-end solution for automatic identification of network attacks on PMU measurement systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The present application will be further described below with reference to the accompanying drawings:

[0058] Figure 1 This is a full flow chart of the method provided in the embodiment of this application.

[0059] Figure 2 Schematic diagram of all three models in the training phase of the method for automatic identification and authentication of network attacks on a PMU measurement system provided in an embodiment of the present application.

[0060] Figure 3 A schematic diagram of the automatic identification and authentication phase of the method for automatic identification and authentication of network attacks on a PMU measurement system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0061] like Figures 1 to 3 As shown, this application provides a method for automatic identification and authentication of network attacks for PMU measurement systems, which includes two main steps: training of the overall model, automatic identification and authentication. The following will linearly introduce the entire operation process of the present invention based on the embodiment (such as Figure 1 shown):

[0062] Step 1: Training of the whole model: The model consists of three modules: PMU feature extractor, PMU feature evaluator and PMU feature discriminator. Module 1 is the PMU feature extractor: The PMU feature extraction units are stacked, and each unit has independent parameters. The PMU feature extraction unit consists of a dynamic measurement point weight distribution network and a topology-aware correlation coefficient. In principle, a mechanism is implemented to fuse measurement point and topology information. Module 2 is the PMU feature evaluator, which evaluates the features output by the PMU feature extractor and calculates the feature evaluation loss. Module 3 is the PMU feature discriminator, which identifies anomalies in the features output by the PMU feature extractor and calculates the feature discrimination loss.

[0063] First, the PMU feature extractor, PMU feature evaluator, and PMU feature discriminator are jointly trained. Unsupervised joint training is performed using pre-processed daily traffic data and network structure data from a complete PMU measurement system (a wide-area measurement system (WAMS) consisting of multiple PMUs)).

[0064] The daily flow data of the complete pre-processed PMU measurement system used for training is defined as , the PMU measurement system network structure data is , we can start training the overall model (such as Figure 2 shown):

[0065] S11: Collect PMU measurement system measurement point data and PMU measurement system network structure data and pre-process the data set into a training set;

[0066] S12: Initialize the learnable parameters and preset parameters of the PMU feature extractor, PMU feature evaluator, and PMU feature discriminator;

[0067] S13: Dataset and Input the PMU feature extractor to obtain the output feature set.

[0068] The PMU feature extractor is composed of The following describes the specific method of extracting a single PMU feature:

[0069] S13.1: Calculate the dynamic measurement point weight distribution coefficient. Receive the input PMU flow data or the data output by the upper layer PMU feature extraction unit As input to calculate the dynamic measurement point weight distribution coefficient of current flow data , the formula is as follows:

[0070] ;

[0071] in, The network measurement point number indicating the source of the flow data; Indicates the level number corresponding to the current PMU feature extraction unit. Indicates the adjacent measurement points of the current level measurement point i traffic information or characteristics. is a learnable parameter vector (m represents dimensional size), Represents a splicing operation, are learnable network parameters.

[0072] The network measurement point is a network node in which each PMU measurement device is set up in the power grid system, and its flow data or stored log data is used as the network measurement point data.

[0073] S13.2: Calculate the topology-aware association coefficient by following these steps:

[0074] S13.2.1: Calculate the adjacency matrix corresponding to the topology of the measurement point network in the PMU measurement system , where each element represents the connection status between the corresponding two measurement points, 1 means there is a connection, and 0 means there is no connection;

[0075] S13.2.2: Based on Calculate the degree matrix corresponding to the topological structure of the measuring point network ;

[0076] S13.2.3: Calculate the network perception matrix of the measurement points: ;

[0077] S13.2.4: Compute the k-th order topology-aware association matrix :

[0078] ;

[0079] Among them, k is a parameter, Elements in is the topology-aware correlation coefficient between measurement points.

[0080] S13.3: Complete the fusion of measurement points and topology information. The specific steps are as follows:

[0081] S13.3.1: Calculation of the fusion coefficient of measurement points and topology information: According to the obtained dynamic measurement point weight distribution coefficient and topology-aware correlation coefficient , the fusion coefficient of measurement points and topology information can be obtained according to the following formula :

[0082] ;

[0083] in, is the activation function, Indicates measuring point The set of adjacent network points, represents the topology-aware correlation coefficient obtained in S13.2, Indicates the dynamic measurement point weight distribution coefficient obtained in S13.1.

[0084] S13.3.2: The fusion of measurement points and topology information can be used to obtain the fused feature output according to the following formula:

[0085] ;

[0086] in, is a nonlinear activation function, is a learnable parameter, For measuring points exist The final output of the layer PMU feature extraction unit.

[0087] S13.4: Based on the above method, the stacked The final output feature set of the PMU feature extractor composed of PMU feature extraction units .

[0088] S14: Feature collection To enter the PMU feature evaluator, follow these steps:

[0089] S14.1: Feature set output by PMU feature evaluator , calculate the feature recovery matrix: ;

[0090] S14.2: Based on the adjacency matrix , calculate the feature evaluation loss:

[0091] ;

[0092] Where n represents the total number of samples in the traffic dataset. MSE is the mean squared error loss function. This loss function evaluates the features, with lower values ​​indicating higher feature quality.

[0093] S15: Input the feature set Z into the PMU feature discriminator and execute the following steps:

[0094] S15.1: Output of PMU feature extractor As input, the anomaly discrimination probability is calculated according to the following formula:

[0095] ;

[0096] Among them, It is a learnable parameter, there are c of them, called network behavior template features, i.e. centers, representing different network attack behaviors (including normal behaviors). The subscript u is algebraic, used to help traverse and calculate the distances of all c centers. The denominator of the above formula is expressed in u, and the subscript w is a specific template feature. The above formula expresses the measurement point and network behavior template characteristics The similarity probability between the measurement points The similarity probability with all network behavior template features constitutes the distribution .

[0097] S15.2: Calculate the probability of abnormal discrimination target:

[0098] ;

[0099] S15.3: Calculate PMU feature discrimination loss:

[0100] ;

[0101] in, Represents the total number of samples in the dataset, Indicates the number of network behavior template features. is the probability output of the PMU feature discriminator, expressing the measurement point Features and template features The similarity probability between is the target probability, through the formula Calculation. The loss result is the discriminant loss of the network behavior to which the feature belongs.

[0102] S16: Calculate the overall loss: ,in is an adjustable parameter.

[0103] S17: Based on overall loss Use Adam optimizer to optimize the learnable parameters of PMU feature extractor, PMU feature evaluator and PMU feature discriminator;

[0104] S18: Shuffle the order of the training set, and then repeat steps S11-S17 for a total of 800 times.

[0105] After the above training steps, all the model learnable parameters of the three modules are reasonably trained and learned. Subsequent automatic recognition can begin.

[0106] Step 2: Automatic identification and authentication: Based on the trained PMU feature extractor and PMU feature discriminator, the network tool is automatically identified and authenticated on the target traffic data (such as Figure 3 As shown). The learnable parameters of the two modules are fixed at this time, and the input data is the real-time PMU measurement system log data. and PMU network topology data The specific steps are:

[0107] S21: Connect the trained PMU feature extractor and PMU feature discriminator to form a network attack automatic identifier. All parameters of the network attack automatic identifier are fixed, and no loss function needs to be calculated.

[0108] S22: Build a network attack behavior identifier. After the identifier is built, connect it to the output of the network attack automatic identifier. The specific construction method is as follows:

[0109] S22.1: Take all network behavior template features and find the data point corresponding to the training set feature closest to each template feature. The distance is calculated using the cosine distance.

[0110] S22.2: Network security experts manually determine the network behavior category to which each data point belongs and label it with the category number of the corresponding network behavior template feature. At this time, each network behavior template feature represents a network behavior.

[0111] S23: Connect the network attack automatic identifier to the PMU measurement system to measure the daily traffic data of the system. and network topology as input , after calculation, the output abnormality discrimination probability distribution ;

[0112] S24: Distribute the probability of abnormal discrimination Input the network attack identifier. After calculation, it outputs the final network behavior category number. The network attack behavior identifier receives the anomaly discrimination probability distribution as input and selects the network behavior corresponding to the network behavior template feature with the maximum probability as the final output.

[0113] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for automatically identifying and verifying network attacks on a PMU measurement system, characterized by: The following steps are involved: Step 1: Training of the overall model, where the model consists of three modules: PMU feature extractor, PMU feature evaluator and PMU feature discriminator. The PMU feature extraction units are composed in a stacked form and the parameters of each unit are independent; The pre-processed daily flow data of the complete PMU measurement system and the network structure data of the PMU measurement system are used as training data to carry out unsupervised joint training of the PMU feature extractor, PMU feature extractor and PMU anomaly discriminator; Each PMU feature extraction unit consists of a dynamic measurement point weight distribution network and a topology-aware correlation coefficient, and integrates the measurement point and topology information; Step 2: Automatic identification and authentication of network attacks based on PMU feature extractor and PMU feature discriminator: Use the trained PMU feature extractor and PMU feature discriminator with fixed parameters to automatically identify and authenticate network tools on target traffic data.

2. The method for automatically identifying and verifying network attacks on a PMU measurement system according to claim 1, characterized in that: The steps for overall model training are as follows: S11: Collect the PMU measurement system measurement point data and PMU measurement system network structure data and pre-process the data set as the training set. Define the pre-processed and complete daily flow data of the PMU measurement system for training as , the PMU measurement system network structure data is ; S12: Initialize the learnable parameters and preset parameters of the PMU feature extractor, PMU feature evaluator, and PMU feature discriminator; S13: Dataset and Input PMU feature extractor to get output feature set ; S14: Feature collection Input PMU feature evaluator and calculate feature evaluation loss ; S15: Feature collection Input PMU feature discriminator and calculate feature discrimination loss ; S16: Calculate the overall loss: ,in is an adjustable parameter; S17: Based on overall loss Optimize the learnable parameters of PMU feature extractor, PMU feature evaluator and PMU feature discriminator; S18: Shuffle the order of the training set, then repeat steps S11-S17 multiple times until the parameters converge.

3. The method for automatically identifying and verifying network attacks on a PMU measurement system according to claim 2, characterized in that: Step S13 includes: S13.1: Calculation of dynamic measurement point weight distribution coefficients: The dynamic measurement point weight distribution network receives the input PMU flow data or the data output by the upper layer PMU feature extraction unit As input, the dynamic measurement point weight distribution coefficient of the current traffic data is calculated by learning network parameters. , the formula is as follows: ; in, The network measurement point number indicating the source of the flow data; Indicates the stacking level number corresponding to the current PMU feature extraction unit. Indicates the adjacent measurement points of the current level measurement point i Traffic information or characteristics, is a learnable parameter vector, express The dimension size, Represents a splicing operation, are learnable network parameters; S13.2: Calculate according to the topology-aware correlation coefficient: S13.2.1: Calculate the adjacency matrix corresponding to the topology of the measurement point network in the PMU measurement system , where each element represents the connection status between the corresponding two measurement points, 1 means there is a connection, and 0 means there is no connection; S13.2.2: Based on Calculate the degree matrix corresponding to the topological structure of the measuring point network ; S13.2.3: Calculate the network perception matrix of the measurement points: ; S13.2.4: Compute the k-th order topology-aware association matrix : ; Where k is a parameter, Elements in is the topologically aware correlation coefficient between measurement points; S13.3: Fusion of measurement points and topology information: S13.3.1: The fusion coefficient of the measurement point and topology information can be obtained according to the following formula : ; in is the activation function, Indicates measuring point The set of adjacent network points, and They represent the topology-aware correlation coefficient and dynamic measurement point weight distribution coefficient between measurement points respectively; S13.3.2: The fusion of measurement points and topology information can be used to obtain the fused feature output according to the following formula: ; in, is a nonlinear activation function, For measuring points exist The final output of the layer PMU feature extraction unit, is a learnable parameter; S13.4: Repeat steps S13.1-13.3 to obtain the stacked The final output feature set of the PMU feature extractor composed of PMU feature extraction units .

4. The method for automatically identifying and verifying network attacks on a PMU measurement system according to claim 1, characterized in that: Feature evaluation loss The expression is: ; Where n represents the total number of samples in the traffic data set, MSE is the mean square error loss function, is an adjacent matrix, is the feature recovery matrix.

5. The method for automatic identification and authentication of network attacks on a PMU measurement system according to claim 1, characterized in that: Feature discrimination loss The expression is: ; in, Represents the total number of samples in the dataset, Indicates the number of network behavior template features, is the probability output of the PMU feature discriminator, expressing the measurement point With template features The similarity probability between is the target probability, through the formula calculate.

6. The method for automatically identifying and verifying network attacks on a PMU measurement system according to claim 1, characterized in that: Step 2 specifically includes the following steps: S21: Connect the trained PMU feature extractor and PMU feature discriminator to form a network attack automatic identifier. All parameters of the network attack automatic identifier are fixed without calculating any loss function. S22: Build a network attack behavior identifier, and after the construction is completed, connect the network attack behavior identifier to the output of the network attack automatic identifier; S24: Input the abnormality discrimination probability distribution into the network attack identifier, and output the final network behavior category corresponding number after calculation. The network attack behavior identifier receives the abnormality discrimination probability distribution as input, and selects the network behavior corresponding to the network behavior template feature corresponding to the maximum probability as the final output.

7. The method for automatically identifying and verifying network attacks on a PMU measurement system according to claim 1, characterized in that: The specific construction method of the network attack behavior identifier is as follows: S22.1: Extract all network behavior template features and find the measurement point data corresponding to the training set feature closest to each template feature; S22.2: Network security experts manually determine the network behavior category to which each data point belongs and label it with the category number of the corresponding network behavior template feature. At this time, each network behavior template feature represents a network behavior. S23: Connect the network attack automatic identifier to the PMU measurement system to measure the daily traffic data of the system. and network topology As input, after calculation, the output is the abnormality discrimination probability distribution .

8. A computer device comprising a memory, a processor, and a computer program stored in the memory, wherein: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.