False data injection attack detection method, device and product for power system
By combining the AUKF and WLS algorithms with cosine similarity and residual detection, the problem of low accuracy in detecting false data injection attacks in the existing technology is solved, and efficient identification of false data injection attacks is achieved.
Patent Information
- Application Number
- CN202510961475.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-09-12
AI Technical Summary
The accuracy of false data injection attack detection in the existing technology is low, and it is impossible to effectively identify false data injection attacks in which attackers bypass residual detection.
The AUKF and WLS algorithms are used to predict the power system state. Combined with cosine similarity calculation and residual detection, attack classification and detection are performed through similarity value, maximum standardized residual and alarm sign.
The accuracy of false data injection attack detection is improved, and various types of false data injection attacks can be effectively identified.
Smart Images

Figure CN120639448A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power system network security, and in particular to a false data injection attack detection method, device and product for power systems. Background Art
[0002] With the continuous expansion of modernization and the advancement of smart grid technology, power system architecture is evolving towards digitalization and informatization. With increasing digitalization, the automation level of power systems continues to rise, leading to a further integration of communication networks and power systems. The introduction of communication networks has increased cybersecurity threats facing power systems. False data injection attacks, as a primary method of cybersecurity threat, have become a major issue that power systems must address.
[0003] In the existing technology, the method for detecting false data injection attacks is: using traditional false data detection methods, predicting the system state of the power system and calculating the theoretical measurement values of the system, combining the actual measurement values obtained to realize residual calculation; and using the residual calculation results to determine whether a false data injection attack has occurred.
[0004] Since only residuals are used to determine attacks in the prior art, there is a technical problem in the prior art of low accuracy in detecting false data injection attacks. Summary of the Invention
[0005] The embodiments of the present application provide a false data injection attack detection method, device and product for a power system, so as to achieve the technical effect of improving the accuracy of false data injection attack detection.
[0006] In a first aspect, an embodiment of the present application provides a method for detecting false data injection attacks in a power system, comprising:
[0007] Obtain power data and system parameters of the target power system;
[0008] Based on the AUKF algorithm, a power system state is predicted for power data and system parameters to obtain a first predicted power system state;
[0009] Based on the WLS algorithm, a power system state is predicted for the power data and system parameters to obtain a second predicted power system state;
[0010] performing cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag;
[0011] Perform residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum standardized residual;
[0012] Attack classification detection is performed based on similarity value, maximum standardized residual, alarm flag and bad data flag, and the attack detection results corresponding to the power data are obtained.
[0013] In one possible implementation, obtaining power data and system parameters of a target power system includes:
[0014] Acquire real-time measurement data of multiple dimensions generated during the operation of the target power system;
[0015] Data processing is performed based on real-time measurement data from multiple dimensions to obtain power data;
[0016] Obtain topology data and configuration information of the target power system;
[0017] Calculate the corresponding system parameters of the target power system based on topology data and configuration information;
[0018] Among them, power data refers to the real-time standardized measurement vector of the target power system, and system parameters refer to the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters corresponding to the target power system.
[0019] In one possible implementation, performing power system state prediction on power data and system parameters based on the AUKF algorithm to obtain a first predicted power system state includes:
[0020] Generate a target point set based on the power system state at the previous moment, the covariance at the previous moment, and the system parameters;
[0021] Based on the target point set and system parameters, the current state is predicted to obtain the predicted state mean and predicted covariance;
[0022] Based on the target point set and system parameters, the current measurement prediction is performed to obtain the predicted measurement mean, measurement covariance, and state measurement cross-covariance;
[0023] The enhancement factor is calculated based on the power data, the predicted measurement mean and the measurement covariance;
[0024] The Kalman gain at the current moment is calculated based on the measurement covariance, state measurement cross-covariance, enhancement factor and system parameters;
[0025] The power system state prediction is updated based on the Kalman gain to obtain a first predicted power system state.
[0026] In one possible implementation, performing power system state prediction on power data and system parameters based on the WLS algorithm to obtain a second predicted power system state includes:
[0027] Calculating based on power data, the current power system state, and system parameters to obtain a first theoretical measurement value;
[0028] The first Jacobian matrix is calculated based on the current power system state and system parameters;
[0029] A state update is performed based on the Jacobian matrix, the power data, the first theoretical measurement value, and the preset measurement weight matrix to obtain a second predicted power system state.
[0030] In one possible implementation, performing cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag includes:
[0031] Performing normalization processing based on the first predicted power system state and the second predicted power system state to obtain a first normalized vector corresponding to the first predicted power system state and a second normalized vector corresponding to the second predicted power system state;
[0032] Performing cosine similarity calculation based on the first normalized vector and the second normalized vector to obtain a similarity value;
[0033] An attack determination is performed based on the similarity value and a preset attack determination threshold, and an alarm sign is obtained.
[0034] In one possible implementation, performing residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum standardized residual includes:
[0035] Calculating a second theoretical measurement value based on the second predicted power system state and system parameters;
[0036] A residual vector is calculated based on the second theoretical measurement value and the power data;
[0037] Calculating a standardized residual vector based on a second Jacobian matrix corresponding to the second predicted power system state and a preset measurement weight matrix;
[0038] Based on the normalized residual vector and the alarm flag corresponding to the similarity value, bad data detection and false input injection attack detection are performed to obtain the bad data flag and the maximum normalized residual.
[0039] In a second aspect, an embodiment of the present application provides a false data injection attack detection device for a power system, comprising:
[0040] An acquisition module, used to acquire power data and system parameters of a target power system;
[0041] A first processing module is configured to predict a power system state based on the power data and system parameters based on an AUKF algorithm to obtain a first predicted power system state;
[0042] A second processing module is configured to predict a power system state based on the power data and system parameters using a WLS algorithm to obtain a second predicted power system state;
[0043] a third processing module, configured to perform cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag;
[0044] a fourth processing module, configured to perform residual detection based on the power data, the second predicted power system state, and the system parameters, and obtain a bad data flag and a maximum standardized residual;
[0045] The fifth processing module is used to perform attack classification detection based on the similarity value, the maximum standardized residual, the alarm flag, and the bad data flag to obtain an attack detection result corresponding to the power data.
[0046] In a possible implementation, the acquisition module is further configured to:
[0047] Acquire real-time measurement data of multiple dimensions generated during the operation of the target power system;
[0048] Data processing is performed based on real-time measurement data from multiple dimensions to obtain power data;
[0049] Obtain topology data and configuration information of the target power system;
[0050] Calculate the corresponding system parameters of the target power system based on topology data and configuration information;
[0051] Among them, power data refers to the real-time standardized measurement vector of the target power system, and system parameters refer to the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters corresponding to the target power system.
[0052] In a possible implementation, the first processing module is further configured to:
[0053] Generate a target point set based on the power system state at the previous moment, the covariance at the previous moment, and the system parameters;
[0054] Based on the target point set and system parameters, the current state is predicted to obtain the predicted state mean and predicted covariance;
[0055] Based on the target point set and system parameters, the current measurement prediction is performed to obtain the predicted measurement mean, measurement covariance, and state measurement cross-covariance;
[0056] The enhancement factor is calculated based on the power data, the predicted measurement mean and the measurement covariance;
[0057] The Kalman gain at the current moment is calculated based on the measurement covariance, state measurement cross-covariance, enhancement factor and system parameters;
[0058] The power system state prediction is updated based on the Kalman gain to obtain a first predicted power system state.
[0059] In a possible implementation, the second processing module is further configured to:
[0060] Calculating based on power data, the current power system state, and system parameters to obtain a first theoretical measurement value;
[0061] The first Jacobian matrix is calculated based on the current power system state and system parameters;
[0062] A state update is performed based on the Jacobian matrix, the power data, the first theoretical measurement value, and the preset measurement weight matrix to obtain a second predicted power system state.
[0063] In a possible implementation, the third processing module is further configured to:
[0064] Performing normalization processing based on the first predicted power system state and the second predicted power system state to obtain a first normalized vector corresponding to the first predicted power system state and a second normalized vector corresponding to the second predicted power system state;
[0065] Performing cosine similarity calculation based on the first normalized vector and the second normalized vector to obtain a similarity value;
[0066] An attack determination is performed based on the similarity value and a preset attack determination threshold, and an alarm sign is obtained.
[0067] In a possible implementation, the fourth processing module is further configured to:
[0068] Calculating a second theoretical measurement value based on the second predicted power system state and system parameters;
[0069] A residual vector is calculated based on the second theoretical measurement value and the power data;
[0070] Calculating a standardized residual vector based on a second Jacobian matrix corresponding to the second predicted power system state and a preset measurement weight matrix;
[0071] Based on the normalized residual vector and the alarm flag corresponding to the similarity value, bad data detection and false input injection attack detection are performed to obtain the bad data flag and the maximum normalized residual.
[0072] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor;
[0073] Memory stores computer-executable instructions;
[0074] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and various possible implementations of the first aspect.
[0075] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the above-mentioned first aspect and various possible implementation methods of the first aspect.
[0076] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and various possible implementation methods of the first aspect.
[0077] The embodiments of the present application provide a false data injection attack detection method, device and product for power systems. The method obtains power data and system parameters of the target power system; predicts the power system state based on the power data and system parameters based on the AUKF algorithm to obtain a first predicted power system state; predicts the power system state based on the power data and system parameters based on the WLS algorithm to obtain a second predicted power system state; performs cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag; uses two prediction methods to predict the system state, and uses the similarity to determine the alarm flag to achieve preliminary attack detection; performs residual detection based on the power data, the second predicted power system state and the system parameters to obtain a bad data flag and a maximum standardized residual; performs attack classification detection based on the similarity value, the maximum standardized residual, the alarm flag and the bad data flag to obtain an attack detection result corresponding to the power data. Compared with the existing technology, the present application uses cosine similarity detection to obtain the similarity between the predicted states corresponding to the two prediction methods, uses residual detection to determine the residual between the predicted state and the actual state, and determines the alarm flag corresponding to the similarity value and the bad data flag corresponding to the residual based on the similarity value and the residual, thereby realizing a joint judgment based on the similarity and the residual on whether there is a false data injection attack, thereby achieving the technical effect of improving the accuracy of false data injection attack detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0079] Figure 1 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 1 ;
[0080] Figure 2 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 2 ;
[0081] Figure 3 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 3 ;
[0082] Figure 4 Schematic diagram of the power system topology of the WECC9 node provided in this application;
[0083] Figure 5 The admittance matrix of the power system of the WECC9 node provided in this application;
[0084] Figure 6 The susceptance matrix of the power system of the WECC9 node provided in this application;
[0085] Figure 7 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 4 ;
[0086] Figure 8 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 1 ;
[0087] Figure 9 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 2 ;
[0088] Figure 10 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 3 ;
[0089] Figure 11 This is a schematic diagram of the structure of the false data injection attack detection device for power systems provided by this application;
[0090] Figure 12 This is a schematic diagram of the structure of the electronic device provided in this application.
[0091] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0092] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0093] First, the proper nouns involved in this application are explained:
[0094] Adaptive Unscented Kalman Filter (AUKF): refers to an extended Kalman filter algorithm that dynamically adjusts the covariance of process noise and observation noise. It is suitable for nonlinear systems whose noise characteristics change with time.
[0095] Weighted Least Squares (WLS): refers to a statistical method that minimizes errors through weighted processing.
[0096] Unscented Kalman Filter (UKF): A state estimation method for nonlinear systems. It selects a set of special sample points (sigma points) to approximate the statistical characteristics of nonlinear functions, avoiding linearization errors. It does not rely on the system's Jacobian matrix, but directly uses these sample points to reconstruct the probability distribution of the state variables, thereby improving estimation accuracy.
[0097] In the existing technology, the main method for monitoring false data injection attacks is to use the unscented Kalman filter (UKF) algorithm to predict and estimate the power system state, calculate the predicted value or estimated value to perform residual calculation, and use the residual calculation result to determine whether there is a false data injection attack at present.
[0098] However, since the existing technology uses residuals to determine attacks, when an attacker designs an attack to bypass the detection mechanism, the residual detection method cannot detect the attack, resulting in a technical problem in the existing technology of low accuracy in monitoring false data injection attacks.
[0099] In response to the above technical problems, the present application proposes the following technical concepts: based on the acquired power data and system parameters of the power system, the AUKF algorithm and the WLS algorithm are used to predict the power system state, respectively, to obtain a first predicted power system state and a second predicted power system state; based on the two predicted power system states, cosine similarity calculation is performed to obtain a similarity and an alarm flag; based on the store data and the second predicted power system state combined with the system parameters, residual detection is performed to obtain a bad data flag and a maximum standardized residual; attack classification monitoring is performed using the similarity, maximum standardized residual, alarm flag and bad data flag to obtain the attack detection result corresponding to the store data. Compared with the existing technology, the present application uses a combination of residuals and similarities to perform attack detection, increases the judgment of bad data, and thus achieves the technical effect of improving the accuracy of false data injection attack detection.
[0100] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0101] Figure 1 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 1 ,like Figure 1 As shown, the method includes:
[0102] S101: Acquire power data and system parameters of a target power system.
[0103] Optionally, a possible implementation method of obtaining power data and system parameters of the target power system is:
[0104] S1011. Acquire real-time measurement data of multiple dimensions generated during the operation of the target power system.
[0105] The real-time measurement data of multiple dimensions in this step include but are not limited to: voltage amplitude, voltage phase angle, active power, and reactive power.
[0106] Exemplarily, the real-time measurement data of multiple dimensions currently collected corresponds to the real-time measurement data of the generator, wherein the active power corresponds to the electromagnetic output power of the generator, and the reactive power corresponds to the reactive power output by the generator.
[0107] S1012: Process the real-time measurement data in multiple dimensions to obtain power data.
[0108] In this step, the data in multiple dimensions include, but are not limited to, voltage amplitude, voltage phase angle, active power, and reactive power. The data processing process may include: performing validity verification on the data in multiple dimensions, performing time alignment on the data in multiple dimensions after verification, and normalizing the aligned data to obtain a standardized measurement value corresponding to the actual measurement data, also known as a standardized measurement vector.
[0109] S1013: Acquire topology data and configuration information of the target power system.
[0110] In this step, the configuration information includes the generator parameters and line parameters of the target power grid. The topology data refers to the physical topology diagram of the target power system, including each device node and the connection relationship between the device nodes.
[0111] S1014: Calculate system parameters corresponding to the target power system based on the topology data and configuration information.
[0112] In this step, the power data refers to the real-time standardized measurement vector of the target power system, and the system parameters refer to the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters corresponding to the target power system.
[0113] Exemplarily, the process of determining the system parameters may be:
[0114] a1. Based on the generator parameters in the configuration information, construct the dynamic state equation of the target power system, where the equation is shown in Formula 1:
[0115]
[0116] Among them, H i Refers to the inertia constant in the generator parameters, D refers to the damping coefficient in the generator parameters, ω s Refers to the synchronous speed in the generator parameters; ω i Refers to the angular speed of generator i, which is a state variable; P mi Refers to the mechanical input power; P Gi Refers to the electromagnetic output power of generator i, which is calculated by the subsequent power equation. refers to the rotor angle of generator i; Refers to the rate of change of the angular speed of generator i. The dynamic state equation is used to describe the mechanical motion law of the generator.
[0117] It should be noted that the discrete form of the dynamic state equation in Formula 1 is shown in Formula 2:
[0118]
[0119] Among them, δ i,k Refers to the rotor angle of generator i, which refers to the rotor position angle at time k; δ i,k-1 Refers to the rotor position angle of generator i at time k-1; ω i,k Refers to the angular velocity of generator i, refers to the rotor rotation speed at time k; ω i,k-1 Refers to the rotor rotation speed of generator i at time k-1; ω0 refers to the time step coefficient, specifically the time integral coefficient of the angle change; P mi Refers to the mechanical input power; P Gi,k-1 Refers to the electromagnetic output power, that is, the electromagnetic output power of generator i at time k-1; D refers to the damping coefficient of the generator, and M refers to the inertia constant of the generator; ω i,δ Refers to the angle process noise, which is used to represent the uncertainty of angle measurement; ω i,ω Refers to speed process noise and is used to express the uncertainty of speed measurement. This formula describes the integral relationship between the rotor angular velocity and speed, and is used to describe the application of Newton's second law to rotating systems.
[0120] In formula 1 and formula 2, the electromagnetic output power P Gi The calculation is shown in Formula 3:
[0121]
[0122] Among them, P Gi Refers to the electromagnetic output power of generator i, that is, the active power of generator i; Y is the admittance matrix of generator i; E i is the internal potential of generator i; E j is the voltage amplitude of network node j; δ i is the power angle of generator i, that is, the angle of the rotor position relative to the synchronous rotating reference axis; δ j is the voltage phase angle of network node j; Y ij is the modulus of the admittance between generator i and network node j; θ ij is the admittance phase angle; n is the number of nodes in the target power system. It should be noted that network nodes refer to the nodes in the target power system's topology diagram or the nodes in the digital twin model. They are the key points connecting various electrical components in the target power system, including generators, buses, loads, and transformers. Network nodes can be divided into boundary nodes and internal nodes. Boundary nodes are connected to the external environment, while internal nodes exist within the target power system.
[0123] Correspondingly, the electromagnetic output power refers to the electromagnetic output power of the generator in the target power system. In addition to the electromagnetic output power, the generator also has reactive power generated by the external magnetic field. For example, the reactive power is calculated as shown in Formula 4:
[0124]
[0125] Among them, Q Gi Refers to reactive power; E i is the internal potential of generator i; E j is the voltage amplitude of network node j; δ i is the power angle of generator i, that is, the angle of the rotor position relative to the synchronous rotating reference axis; δ j is the voltage phase angle of network node j; Y ij is the modulus of the admittance between generator i and network node j; θ ij is the admittance phase angle; n is the number of nodes in the target power system.
[0126] a2. Based on the line parameters in the configuration information and the topology data of the target power system, an admittance matrix is constructed and system parameters are determined.
[0127] Refer to the formula in step a2 to determine the calculation method of the admittance matrix as shown in formula 5:
[0128]
[0129] Among them, Formula 5 is an admittance matrix equivalent calculation formula, which is used to eliminate internal nodes to obtain boundary nodes. 11 Refers to the self-admittance matrix of the internal node; Y 12 refers to the interior-boundary node mutual admittance matrix; Y 21 refers to the boundary-internal node mutual admittance matrix; Y 22 Refers to the self-admittance matrix of the boundary nodes; Y refers to the equivalent admittance matrix of the boundary nodes.
[0130] The conductance matrix and susceptance matrix are determined based on the admittance matrix. The specific method is shown in Formula 6:
[0131]
[0132] Among them, Y refers to the admittance matrix, G refers to the conductance matrix, and B refers to the susceptance matrix.
[0133] Based on the topological structure data and the admittance matrix of the target power system, the relationship between the current and voltage in the target power system is determined, as shown in Formula 7:
[0134]
[0135] Among them, Y exp Refers to the extended admittance matrix obtained based on the admittance matrix Y, which includes the full network admittance matrix of the internal nodes of the generator, and its dimension is (n+m)×(n+m); V exp Refers to the extended voltage vector, which is a complete voltage vector containing the bus voltage and the internal potential corresponding to the generator rotor, and its dimension is (n+m)×1; V∠θ refers to the bus voltage vector, which has a dimension of n×1 and represents the system bus voltage; E∠θ refers to the generator internal potential vector, which has a dimension of m×1 and represents the generator rotor induced voltage; I G ∠δ refers to the current injected by the rotor; Y 11 Refers to the self-admittance matrix of the internal node; Y 12 refers to the interior-boundary node mutual admittance matrix; Y 21 refers to the boundary-internal node mutual admittance matrix; Y 22 is the self-admittance matrix of the boundary nodes. Where n refers to the number of system busbar nodes and m refers to the number of internal nodes of the generator. Since the load does not inject any current, the upper part of the current injection vector is zero, and we can drive the relationship between V and E as shown in Equation 8:
[0136] V∠θ=(-Y 11 ) -1 Y 22 E∠δ=R V E∠δ formula 8
[0137] Among them, R V Refers to the voltage transfer matrix, and the remaining parameters can be explained in Formula 7.
[0138] The system parameters, including the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters, are determined using the aforementioned formulas. These dynamic parameters refer to the target power system's physical characteristics related to the generator, line parameters, and noise-related parameters. The system parameters also include the target power system's measurement function, which is used to calculate the target power system's theoretical measurement values based on its state.
[0139] Specifically, the measurement function is shown in Formula 9:
[0140] z=h(x)+e Formula 9
[0141] Among them, z refers to the theoretical measurement value, x refers to the power system state value, and e refers to the error value.
[0142] S102 : Predicting a power system state based on the power data and system parameters using the AUKF algorithm to obtain a first predicted power system state.
[0143] In this step, the first power system state refers to the power system state obtained by prediction based on the AUKF algorithm.
[0144] It should be noted that the calculation of the first predicted power system state in this step is as follows Figure 2 Further explanation is given in the embodiment shown and no redundant description is given here.
[0145] S103 : Predicting the power system state based on the power data and system parameters based on the WLS algorithm to obtain a second predicted power system state.
[0146] In this step, the second predicted power system state needs to be implemented based on the measurement function indicated by Formula 9 in the above step, with the purpose of calculating the theoretical measurement value based on the measurement function.
[0147] It should be noted that the calculation of the second predicted power system state in this step is as follows Figure 3 Further explanation is given in the embodiment shown and no redundant description is given here.
[0148] S104 , performing cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag.
[0149] Optionally, a possible implementation method of calculating the similarity value and the alarm flag is:
[0150] S1041 . Perform normalization processing based on the first predicted power system state and the second predicted power system state to obtain a first normalized vector corresponding to the first predicted power system state and a second normalized vector corresponding to the second predicted power system state.
[0151] In this step, the purpose of normalization is to eliminate dimensional differences, including dimensional differences caused by the generator rotor angle and speed.
[0152] S1042: Perform cosine similarity calculation based on the first normalized vector and the second normalized vector to obtain a similarity value.
[0153] In this step, the cosine similarity calculation method for two normalized vectors is shown in Formula 10:
[0154]
[0155] in, And cosθ refers to the cosine similarity between the first normalized vector and the second normalized vector; refers to the first normalized vector, Refers to the second table conversion vector; refers to the first predicted power system state, Refers to the second predicted power system state.
[0156] S1043: Perform attack determination based on the similarity value and a preset attack determination threshold, and obtain an alarm flag.
[0157] In this step, when the similarity value is 1, it is determined that the two vectors are exactly the same, indicating that the prediction values of the AUKF algorithm and the WLS algorithm are consistent; when the similarity value is 0, it means that the two vectors are orthogonal, that is, the prediction values of the AUKF algorithm and the WLS algorithm are irrelevant; when the similarity value is -1, it means that the prediction results of the two algorithms are contradictory.
[0158] Optionally, a preset attack threshold can be set in this step for triggering an alarm. When the similarity value falls below the preset attack threshold, an alarm is determined to be triggered, and the alarm flag is set to 1; otherwise, the alarm flag is set to 0. The purpose of this step is to ensure that when the target power system does not experience a false data injection attack, the cosine value remains within a certain range; when a false data injection attack occurs, the cosine value changes rapidly and converges to a certain range.
[0159] For example, the range of the cosine value is limited as shown in Formula 11:
[0160]
[0161] Here, ε refers to the boundary value of the cosine value convergence range. When the cosine value satisfies Formula 11, it can be determined that there is no false data injection attack. The explanation of the relevant parameters in Formula 11 refers to Formula 10 above and is not further explained here.
[0162] S105 , performing residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum standardized residual.
[0163] Optionally, a possible implementation method of calculating the bad data flag and the maximum standardized residual is:
[0164] S1051. Based on the second predicted power system state and system parameters, calculate and obtain a second theoretical measurement value.
[0165] In this step, the second theoretical measurement value can be calculated using the measurement function shown in Formula 9, taking the second predicted power system as an input parameter, and determining the internal parameters of Formula 9 based on the admittance matrix in the system parameters to obtain the second theoretical measurement value.
[0166] S1052: Calculate a residual vector based on the second theoretical measurement value and the power data.
[0167] The residual vector in this step is calculated by determining an actually measured value based on the power data, and calculating an interpolation between the actually measured value and the second theoretical value to obtain the residual vector.
[0168] It should be noted that the calculation process of the residual vector is: each element in the actual measured value is matched one-to-one with each element in the second theoretical value, the difference between each element pair is calculated, and the differences between multiple element pairs are combined to obtain the residual vector.
[0169] S1053 . Calculate and obtain a standardized residual vector based on a second Jacobian matrix corresponding to the second predicted power system state and a preset measurement weight matrix.
[0170] In this step, the standardized residual vector is calculated by calculating a second Jacobian matrix corresponding to the second predicted power system state, where the second Jacobian matrix refers to the second Jacobian matrix of the second predicted power system state obtained in the final stage of the WLS prediction of the power system state. The preset measurement weight matrix can be a preset value determined based on system parameters. Calculation is performed based on the residual vector, the second Jacobian matrix, and the preset measurement weight matrix to obtain the standardized residual vector.
[0171] S1054: Based on the normalized residual vector and the alarm flag corresponding to the similarity value, perform bad data detection and false input injection attack detection to obtain a bad data flag and a maximum normalized residual.
[0172] In this step, the maximum standardized residual is obtained by taking the maximum data value based on the table-transformed residual vector. The bad data flag can be determined based on the maximum standardized residual or the difference between the theoretical measurement value and the actual measurement value.
[0173] For example, the bad data detection method based on the theoretical measurement value and the actual measurement value is shown in Formula 12:
[0174]
[0175] Among them, z refers to the actual measured value corresponding to the power data; Refers to the second predicted power system state value, Refers to the predicted measurement value obtained based on the second predicted power system state, ε d Refers to the bad data judgment threshold.
[0176] S106 , performing attack classification detection based on the similarity value, the maximum normalized residual, the alarm flag, and the bad data flag to obtain attack detection results corresponding to the power data.
[0177] In this step, before attack classification and detection, it is necessary to determine whether a false data injection attack exists. This is determined by performing a cosine similarity test on the two predicted power system states of the target power system and then performing a bad data analysis on the target power system. Only when the cosine similarity triggers an alarm and no bad data is present can the target power system be determined to have undergone a false data injection attack.
[0178] It should be noted that in the existing technology, traditional bad data monitoring methods cannot accurately identify false data injection attacks, because attackers will design false data injection attacks based on their attack purposes to bypass the residual-based detection mechanism. The specific method is shown in Formula 13:
[0179]
[0180] in, Refers to the predicted system state received under the attack state, that is, the error state obtained; z Bad Refers to the actual measurement value of the attack; the attack vector is a=[a1,a2,…,a m ] Τ , the injected bias vector is c=[c1,c2,…,c n ] Τ Formula 13 is based on Formula 9 and adds a false data injection attack.
[0181] When performing residual detection in combination with false data injection attacks, the specific residual calculation process is shown in Formula 14:
[0182]
[0183] Where d1 refers to the residual under normal operating conditions, that is, the residual norm; r refers to the deviation between the actual measurement value and the predicted measurement value; z refers to the actual measurement value; h(·) refers to the measurement function; Refers to the predicted system state. When the target power system is normal, d1 is small and contains only random noise. d2 refers to the residual error after the false data injection attack, r Bad Refers to the residual vector after the attack; z Bad Refers to the actual measurement value that is attacked, that is, the measurement value after being tampered by the attacker; Refers to the predicted system state received in the attack state, that is, the error state obtained. Based on the derivation process in Formula 14, it can be determined that when the attacker designs a false data injection attack, the system state will be modified at the same time, resulting in the final residual detection being consistent with the residual detection before the attack. Therefore, it is impossible to determine the false data injection attack based on the residual detection. Therefore, in this application, cosine similarity detection plus residual auxiliary verification are used to realize the detection of false data injection attacks, further improving the accuracy of detection.
[0184] In this step, in attack classification detection, the types of false data injection attacks include: pulse attack, ramp attack and random attack.
[0185] Among them, pulse attack is an instantaneous attack. The attacker injects a pulse into the measurement data at a specific moment, trying to disrupt the state estimation of the system in a short time. Its mathematical formula is as follows:
[0186] As shown in formula 15:
[0187]
[0188] A ramp attack is a form of gradually increasing attack where the attacker gradually increases or decreases the measurement value from a certain moment, affecting the state estimation of the system. Its mathematical formula is shown in Equation 16:
[0189]
[0190] A random attack is an attack in which the attacker injects disturbances into the measured values according to a random distribution. The goal of a random attack is to increase system noise and destroy the accuracy of state estimation. A random attack can be expressed by formula 17:
[0191]
[0192] In Formulas 15 to 17, Z i (t) is the original measurement value of the system at time t, a i is a pulse attack signal, is the rotor angle δ added to the measurement of the i-th generator i False data injection attack on is the rotor speed ω added to the measurement of the i-th generator i False data injection attack on is a false data injection attack added to the voltage measured in the i-th generator, τ a is the duration of the attack. i is the slope coefficient, m is the upper bound of the random attack, n is the lower bound of the random attack, and rand(m,n) refers to the random attack signal. iRefers to the observation matrix, which defines the process of calculating the theoretical measurement value from the vector corresponding to the system state; v i (t) refers to the random noise of the i-th measurement value at time t, which can be set to zero-mean Gaussian white noise; s i Refers to the steady-state deviation or fixed deviation corresponding to the i-th measurement value, which is a constant offset determined based on the systematic factors of the generator equipment in the target power system.
[0193] Optionally, attack classification detection is performed based on the similarity value, the maximum normalized residual, the alarm flag, and the bad data flag, and a possible implementation method for obtaining the attack detection result corresponding to the power data is:
[0194] S1061. Determine the similarity value at the current moment based on the similarity value, and calculate the difference between the similarity value at the current moment and the similarity value at the previous moment; when the difference is greater than a first preset threshold, determine that the current attack type is a pulse attack.
[0195] In this step, the first preset threshold is used to determine whether the difference between the similarities of the power levels at two moments exceeds a certain range. If it is determined to be beyond the certain range, the attack type can be determined as a pulse attack. For example, the first preset threshold can be set to 0.5. When the difference exceeds 0.5, the attack type can be determined to be a pulse attack.
[0196] S1062: Determine a similarity value sequence corresponding to a plurality of consecutive moments based on the similarity value, calculate a mean similarity value of the similarity value sequence, and determine the attack type as a slope attack when the mean similarity value is less than a second preset threshold.
[0197] For example, the similarity values of the past 20 moments can be selected to calculate the average, and the second preset threshold can be set to 0.6. When the average similarity value of the past 20 moments is lower than 0.6, this may indicate that the system is under a ramp attack, because a ramp attack is usually manifested as a gradually decreasing similarity.
[0198] S1063: Determine a similarity value sequence corresponding to the similarity value at a plurality of consecutive moments based on the similarity value, calculate the variance of the similarity value sequence, and determine the attack type as a random attack when the variance is greater than a third preset threshold.
[0199] In this step, the phase velocity values from the last 10 moments are selected for variance calculation, with the third preset threshold set to 0.1. A variance greater than 0.1 indicates significant data fluctuations, suggesting a possible random attack. It should be noted that random attacks are typically unpredictable and exhibit high volatility, so variance calculation can be used to determine whether a random attack is occurring.
[0200] An embodiment of the present application provides a false data injection attack detection method for a power system, which obtains power data and system parameters of a target power system; predicts the power system state based on the power data and system parameters based on the AUKF algorithm to obtain a first predicted power system state; predicts the power system state based on the power data and system parameters based on the WLS algorithm to obtain a second predicted power system state; performs cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag; uses two prediction methods to predict the system state, and uses the similarity to determine the alarm flag to achieve preliminary attack detection; performs residual detection based on the power data, the second predicted power system state and the system parameters to obtain a bad data flag and a maximum standardized residual; performs attack classification detection based on the similarity value, the maximum standardized residual, the alarm flag and the bad data flag to obtain an attack detection result corresponding to the power data. Compared with the existing technology, the present application uses cosine similarity detection to obtain the similarity between the predicted states corresponding to the two prediction methods, uses residual detection to determine the residual between the predicted state and the actual state, and determines the alarm flag corresponding to the similarity value and the bad data flag corresponding to the residual based on the similarity value and the residual, thereby realizing a joint judgment based on the similarity and the residual on whether there is a false data injection attack, thereby achieving the technical effect of improving the accuracy of false data injection attack detection.
[0201] Figure 2 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 2 ,like Figure 2 As shown, the method includes:
[0202] S201 : Generate a target point set based on the power system state at the last moment, the covariance at the last moment, and system parameters.
[0203] In this step, the target point set is generated as shown in Formula 18:
[0204]
[0205] Where n refers to the state dimension; χ i is the state vector at the previous moment A set of sigma points, i refers to generator i; Refers to the weighted average root of the covariance matrix P; P refers to the covariance at the previous moment; λ refers to the scaling parameter in the system parameters. The target point set calculated based on this formula can be written as {χ i}(i=0,…,2n).
[0206] S202: Predict the state at the current moment based on the target point set and system parameters to obtain a predicted state mean and a predicted covariance.
[0207] In this step, the process of calculating the predicted state mean and predicted covariance is:
[0208] S2021. Perform a nonlinear transformation based on the target point set to obtain a point set processed by the nonlinear transformation.
[0209] In this step, the nonlinear transformation uses the discrete form of the dynamic state equation mentioned in Formula 2 above. The nonlinear change processing is shown in Formula 19:
[0210] χ i,k|k-1 =f(χ i,k-1 )+q k-1 Formula 19
[0211] Among them, χ i,k|k-1 Refers to the point after nonlinear transformation processing, that is, the sigma point after time propagation; q k-1 refers to excess noise; f(.) refers to the discrete form of the dynamic state equation.
[0212] S2022. Calculate the predicted state mean based on the discrete point set.
[0213] In this step, the calculation method of the predicted state mean is shown in Formula 20:
[0214]
[0215] in, Refers to the mean of the sigma points after time propagation; refers to the predicted state mean; refers to the mean weight; i is the index of the sigma point.
[0216] The mean weight is calculated as shown in Formula 21:
[0217]
[0218] Where n refers to the state dimension; λ refers to the scaling parameter in the system parameters; i = 0 represents the central sigma point, and i ≠ 0 represents the non-central sigma point; Refers to the mean weight.
[0219] S2023. Calculate the predicted covariance based on the predicted measurement mean, the discretized point set, and the observation noise covariance in the system parameters.
[0220] In this step, the method for calculating the predicted measurement covariance is shown in Formula 22:
[0221]
[0222] in, refers to the prediction noise covariance, refers to the covariance weight; Refers to the deviation between the predicted sigma point and the measured sigma point; Q k-1 refers to the observation noise covariance.
[0223] The covariance weight is calculated as shown in Formula 23:
[0224]
[0225] in, Refers to the covariance weight; n refers to the state dimension; λ refers to the scaling parameter in the system parameters; i = 0 represents the central sigma point, and i ≠ 0 represents the non-central sigma point; α refers to the main dispersion parameter, which is used to directly control the degree of dispersion of the sigma point from the mean; β refers to the distribution shape parameter, which is used to correct the covariance weight.
[0226] S203 : Perform measurement prediction at the current moment based on the target point set and system parameters to obtain the predicted measurement mean, measurement covariance, and state measurement cross-covariance.
[0227] In this step, the process of calculating the predicted measurement mean, measurement covariance, and state measurement cross-covariance can be as follows:
[0228] S2031. Perform measurement mapping on the target point set to obtain the mapping of the sigma point in the measurement space.
[0229] In this step, the measurement mapping is shown in formula 24:
[0230] z i,k|k-1 =h(χ′ i,k-1 )+r k-1 Formula 24
[0231] Among them, h(·) refers to the measurement model, r k-1 refers to the measurement noise; z i,k|k-1 Refers to the mapping of the sigma point in the measurement space calculated by the measurement model; χ′ i,k-1 Refers to the derivative at the sigma point; i is the index of the sigma point.
[0232] S2032. Calculate the predicted measurement mean based on the mapping of the sigma point in the measurement space.
[0233] In this step, the predicted measurement mean is calculated as shown in Formula 25:
[0234]
[0235] in, Refers to the mean of the predicted measurement, and n refers to the state dimension; refers to the mean weight; i is the index of the sigma point.
[0236] S2033. Calculate the measurement covariance based on the predicted measurement mean.
[0237] In this step, the measurement covariance is calculated as shown in Formula 26:
[0238]
[0239] in, refers to the measurement covariance; refers to the covariance weight; n refers to the state dimension; i is the index of the sigma point; Refers to the deviation between the measured space sigma point and the actual sigma point; R k is the measurement noise covariance.
[0240] S2034 : Calculate the state measurement covariance based on the deviation between the predicted sigma point and the measured sigma point corresponding to the predicted covariance, and the deviation between the predicted sigma point and the measured sigma point corresponding to the measured covariance.
[0241] In this step, the state measurement covariance is calculated as shown in Formula 27:
[0242]
[0243] in, refers to the state measurement covariance; refers to the covariance weight; n refers to the state dimension; i is the index of the sigma point; Refers to the deviation between the measurement space sigma point corresponding to the measurement covariance and the actual sigma point; Refers to the deviation between the predicted sigma point and the measured sigma point corresponding to the predicted covariance.
[0244] S204 , calculating an enhancement factor based on the power data, the predicted measurement mean, and the measurement covariance.
[0245] In this step, the enhancement factor is calculated as shown in Formula 28:
[0246]
[0247] in, Refers to the deviation between the actual measured value and the predicted measured value corresponding to the power data, that is, the residual vector; refers to the actual residual covariance; refers to the covariance weight; n refers to the state dimension; i is the index of the sigma point; Refers to the deviation between the measurement space sigma point corresponding to the measurement covariance and the actual sigma point; μ k refers to the enhancement factor, R k refers to the measurement noise covariance; μ k R k refers to the amplified noise term.
[0248] S205 , performing calculation based on the measurement covariance, the state measurement cross-covariance, the enhancement factor, and the system parameters to obtain the Kalman gain at the current moment.
[0249] In this step, the Kalman gain is calculated as follows:
[0250] S2051. Calculate the actual residual covariance based on the measurement covariance, the state measurement cross-covariance, the enhancement factor, and the measurement noise covariance in the system parameters.
[0251] In this step, the actual residual covariance is calculated as shown in Formula 29:
[0252]
[0253] in, refers to the actual residual covariance, Refers to the deviation between the measurement space sigma point corresponding to the measurement covariance and the actual sigma point; n refers to the state dimension; i is the index of the sigma point; μ k refers to the enhancement factor, R k is the measurement noise covariance.
[0254] It should be noted that when the target power system is normal and has not been attacked or interfered with, the residual vector should be a Gaussian white noise with a mean value and a covariance equal to the actual residual covariance. Therefore, theoretically, the sample covariance of the residual is The theoretical value that should correspond to the actual residual covariance is Therefore, it can be obtained that the original residual covariance is calculated as shown in formula 30:
[0255]
[0256] in, refers to the sample covariance of the residuals, Refers to the actual residual covariance of the system under normal conditions, refers to the measurement covariance; refers to the covariance weight; n refers to the state dimension; i is the index of the sigma point; Refers to the deviation between the measurement space sigma point corresponding to the measurement covariance and the actual sigma point; μ k refers to the enhancement factor, R k is the measurement noise covariance.
[0257] S2052: Calculate the Kalman gain based on the actual residual covariance and the state measurement cross-covariance.
[0258] In this step, the Kalman gain is calculated as shown in formula 31:
[0259]
[0260] Among them, K k refers to the Kalman gain; refers to the state measurement cross-covariance, It refers to the measurement covariance with the enhancement factor introduced, and is also the actual residual covariance.
[0261] S206 : Update the power system state prediction based on the Kalman gain to obtain a first predicted power system state.
[0262] In this step, the power system state and predicted noise covariance are updated based on the Kalman gain. The updating method is shown in Formula 32:
[0263]
[0264] in, refers to the updated predicted first predicted power system state; Refers to the predicted state mean; K k refers to the Kalman gain; z k Refers to the actual measured value corresponding to the power data; Refers to the mean of the predicted measurements; refers to the measurement covariance; μ k refers to the enhancement factor, R k refers to the measurement noise covariance; μ k R k refers to the amplified noise term; refers to the prediction noise covariance.
[0265] Figure 3Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 3 ,like Figure 3 As shown, the method includes:
[0266] S301 : Calculate based on power data, the current power system state and system parameters to obtain a first theoretical measurement value.
[0267] In this step, the first theoretical measurement value is calculated based on the measurement function shown in Formula 9 in the above embodiment. The system parameters used are the conductance matrix and the susceptance matrix in the system parameters.
[0268] Optionally, a possible implementation manner of calculating the first theoretical measurement value is:
[0269] The objective function of the WLS algorithm is constructed, and the first theoretical measurement value is obtained based on the objective function.
[0270] In this step, the objective function is shown in Formula 33:
[0271] minJ(x)=(zh(x)) T W(zh(x)) formula 33
[0272] Here, minJ(x) refers to the minimization of the objective function value, z refers to the real-time measurement value determined based on the power data or the measurement vector corresponding to the real-time measurement value; h(x) refers to the measurement function, which is used to calculate the theoretical measurement value based on the target power system state obtained from the current measurement; W refers to the pre-set measurement weight matrix; and x refers to the power system state at the current moment.
[0273] In this step, the first theoretical measurement value is calculated by minimizing the objective function value.
[0274] S302: Calculate and obtain a first Jacobian matrix based on the current power system state and system parameters.
[0275] In this step, the calculation method of the first Jacobian matrix is shown in Formula 34:
[0276]
[0277] Where H refers to the first Jacobian matrix, x (k) refers to the current state of the power system, h(x) refers to the measurement function; the first Jacobian matrix is calculated by differentiating the measurement function. System parameters refer to the conductance matrix and susceptance matrix used in the measurement function.
[0278] S303 , performing a state update based on the Jacobian matrix, the power data, the first theoretical measurement value, and the preset measurement weight matrix to obtain a second predicted power system state.
[0279] In this step, the second predicted power system state is calculated as follows:
[0280] S3031. Calculate a state correction value based on the first Jacobian matrix, the real-time measurement value corresponding to the power data, the calculated first theoretical measurement value, and a preset measurement weight matrix.
[0281] In this step, the process of calculating the state correction amount is as follows: based on the real-time measurement value corresponding to the power data and the first theoretical measurement value, the residual of the two is calculated; based on the first Jacobian matrix and the preset measurement weight matrix, an information matrix is constructed; based on the information matrix, the residual, the first Jacobian matrix and the preset measurement weight matrix, a linear solution is performed to obtain the state correction amount.
[0282] S3032. Update the current power system state based on the state correction amount to obtain a second predicted power system state.
[0283] It should be noted that, in the process of obtaining the second predicted power system state, the update method used is as shown in Formula 35:
[0284] x (k+1) =x (k) +(H T WH) -1 H T W(zh(x (k) )) Formula 35
[0285] Among them, x (k) Refers to the current state of the power system, x (k+1) Refers to the second predicted power system state; H refers to the first Jacobian matrix, W refers to the preset measurement weight matrix; z refers to the real-time measurement value determined based on the power data or the measurement vector corresponding to the real-time measurement value.
[0286] Based on the above embodiments, this application provides a power system of a WECC9 node, Figure 4 The schematic diagram of the power system topology of the WECC9 node provided in this application is as follows: Figure 4As shown, the system includes nine bus nodes, three generators, and three transformers. The bus nodes are bus1, bus2, bus3, bus4, bus5, bus6, bus7, bus8, and bus9. The three generators are G1, G2, and G3. The three transformers are T1, T2, and T3. The voltage values marked on the bus nodes refer to the nominal voltage values at that bus node. For example, the nominal values of bus nodes bus4, bus7, and bus9 are 230 kV; the nominal value of bus node bus1 is 16.5 kV; the nominal value of bus node bus3 is 13.8 kV; and the nominal value of bus node bus2 is 18 kV.
[0287] The values marked on the transformer nodes refer to the impedance of the transformer, where the impedance of transformer T1 is j0.0576; the impedance of transformer T2 is j0.0625; and the impedance of transformer T3 is j0.0586.
[0288] The data on the connection line includes the transmission impedance corresponding to the complex value, and the shunt susceptance corresponding to the same value; the real part of the complex value refers to the circuit of the line, and the imaginary part refers to the reactance of the line. Figure 4 As shown in the figure, the corresponding transmission impedance and parallel susceptance are marked on the lines of the system. The transmission impedance of the line connecting bus4 and bus6 is 0.017+j0.092, and the parallel susceptance is B / 2=j0.079; the transmission impedance of the line connecting bus4 and bus5 is 0.01+j0.085, and the parallel susceptance is B / 2=j0.088; the transmission impedance of the line connecting bus6 and bus9 is 0.039+j0.17, and the parallel susceptance is B / 2=j0.179; the transmission impedance of the line connecting bus5 and bus7 is 0.032+j0.161, and the parallel susceptance is B / 2=j0.153; the transmission impedance of the line connecting bus8 and bus9 is 0.0119+j0.1008, and the parallel susceptance is B / 2=j0.1045; the transmission impedance of the line connecting bus7 and bus8 is 0.0085+j0.072, and the parallel susceptance is B / 2=j0.0745.
[0289] The data on the output arrows refer to the system's active and reactive power outputs. Bus5 has an active power output of 125 MW and a reactive power output of 50 MVar; bus6 has an active power output of 90 MW and a reactive power output of 30 MVar; and bus8 has an active power output of 100 MW and a reactive power output of 35 MVar.
[0290] Figure 5The admittance matrix of the power system of the WECC9 node provided in this application, Figure 6 The admittance matrix of the power system of the WECC9 node provided in this application is obtained by combining the topological structure of the power system. The admittance matrix is as follows: Figure 5 As shown; the conductivity matrix obtained by separating the admittance matrix is 0, and the susceptance matrix is as follows Figure 6 shown.
[0291] Figure 7 Schematic diagram of the process of the false data injection attack detection method for power system provided by this application Figure 4 ,like Figure 7 As shown, the method includes:
[0292] A1. Collect the power system measurement values at time t.
[0293] A2. Perform AUKF state prediction based on the power system measurement value at time t to obtain a first predicted power system state.
[0294] A3. Perform WLS state prediction based on the power system measurement value at time t to obtain a second predicted power system state.
[0295] A4. Perform a cosine similarity check based on the first predicted power system state and the second predicted power system state to obtain a check result.
[0296] A5: Determine whether the verification result is similarity consistent. If not, execute A6; if yes, execute A9.
[0297] A6. Perform a bad data test on the power system measurement value at time t to obtain a test result.
[0298] A7. Determine whether the test result is bad data. If so, execute A9; otherwise, execute A8.
[0299] A8. Determine whether a false data injection attack has been detected and output the detection result.
[0300] A9 and t+1 are adjusted to the next moment and jump to A1.
[0301] Figure 8 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 1 , Figure 9 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 2 , Figure 10 The simulation results of the false data injection attack detection method for power system provided by this application are as follows: Figure 3 .like Figure 8As shown in the figure, the current false data injection attack corresponds to a pulse attack, with the generator rotor angle δ1, which refers to the comparison of the generator rotor angle δ2 with the attack (Angleδ1Comparison with Attack). Here, Angle refers to the rotor angle; Actual refers to the actual rotor angle of the generator, which deviates significantly from the original value after the attack; AUKF refers to the estimated value of the adaptive unscented Kalman filter algorithm, which closely tracks the actual value and has strong anti-attack capabilities; UKF refers to the estimated value of the traditional unscented Kalman filter algorithm, which continues to deviate and fails to converge after being disturbed by the attack.
[0302] The generator speed is ω1, which refers to the comparison of the generator speed ω1 with the attack (Speedω1ComparisonwithAttack). Speed refers to speed; Actual refers to the actual generator speed, which fluctuates dramatically after an attack; AUKF refers to the estimate from the adaptive unscented Kalman filter algorithm, which smoothly tracks the actual dynamics and has minimal fluctuations; UKF refers to the estimate from the traditional unscented Kalman filter algorithm, which has large estimation errors and severe fluctuations.
[0303] like Figure 9 As shown in the figure, the current false data injection attack corresponds to a ramp attack, with the generator rotor angle δ2, which refers to the comparison of the generator rotor angle δ2 with the attack (Angleδ2Comparison with Attack). Here, Angle refers to the rotor angle; Actual refers to the actual rotor angle of the generator, which deviates linearly from t = 3s; AUKF refers to the estimated value of the adaptive unscented Kalman filter algorithm, which closely tracks the actual value with a small deviation; UKF refers to the estimated value of the traditional unscented Kalman filter algorithm, which gradually accumulates errors and eventually has a larger deviation.
[0304] The generator speed is ω2, which refers to the comparison of the generator speed ω2 with the attack (Speedω2ComparisonwithAttack). Speed refers to speed; Actual refers to the actual generator speed, which fluctuates continuously after an attack; AUKF refers to the estimated value from the adaptive unscented Kalman filter algorithm, which provides smooth tracking and effectively filters out high-frequency noise; and UKF refers to the estimated value from the traditional unscented Kalman filter algorithm, which amplifies noise and causes oscillations exceeding half of the actual value.
[0305] like Figure 10As shown in the figure, the current false data injection attack corresponds to a random attack type, and the generator rotor angle is δ3, which refers to the comparison of the generator rotor angle δ3 with the attack (Angleδ3Comparison with Attack). Here, Angle refers to the rotor angle; Actual refers to the actual rotor angle of the generator, which changes smoothly; AUKF refers to the estimated value of the adaptive unscented Kalman filter algorithm, which closely tracks the actual value with a small deviation; UKF refers to the estimated value of the traditional unscented Kalman filter algorithm, which has significant random fluctuations.
[0306] The generator speed ω3 refers to the comparison of the generator speed ω3 with the attack speed (Speedω3ComparisonwithAttack). Speed refers to speed; Actual refers to the actual speed of the generator, which is stable near the synchronous speed; AUKF refers to the estimated value of the adaptive unscented Kalman filter algorithm, which is smooth and oscillatory with strong noise suppression capabilities; UKF refers to the estimated value of the traditional unscented Kalman filter algorithm, which has high-frequency oscillations.
[0307] Figure 11 This is a schematic diagram of the structure of the false data injection attack detection device for power systems provided by this application, as shown in Figure 11 As shown, the false data injection attack detection device for the power system provided in this embodiment includes:
[0308] The acquisition module 1101 is used to acquire power data and system parameters of the target power system.
[0309] The first processing module 1102 is configured to perform power system state prediction on the power data and system parameters based on the AUKF algorithm to obtain a first predicted power system state.
[0310] The second processing module 1103 is configured to perform power system state prediction on the power data and system parameters based on the WLS algorithm to obtain a second predicted power system state.
[0311] The third processing module 1104 is configured to perform cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag.
[0312] The fourth processing module 1105 is configured to perform residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum normalized residual.
[0313] The fifth processing module 1106 is configured to perform attack classification detection based on the similarity value, the maximum normalized residual, the alarm flag, and the bad data flag to obtain an attack detection result corresponding to the power data.
[0314] In a possible implementation, the acquisition module 1101 is further configured to:
[0315] Acquire real-time measurement data of multiple dimensions generated during the operation of the target power system.
[0316] Data processing is performed based on real-time measurement data in multiple dimensions to obtain power data.
[0317] Obtain the topology data and configuration information of the target power system.
[0318] Based on the topology data and configuration information, the corresponding system parameters of the target power system are calculated.
[0319] Among them, power data refers to the real-time standardized measurement vector of the target power system, and system parameters refer to the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters corresponding to the target power system.
[0320] In a possible implementation, the first processing module 1102 is further configured to:
[0321] A target point set is generated based on the power system state at the last moment, the covariance at the last moment, and the system parameters.
[0322] The current state is predicted based on the target point set and system parameters to obtain the predicted state mean and predicted covariance.
[0323] The current measurement prediction is performed based on the target point set and system parameters to obtain the predicted measurement mean, measurement covariance and state measurement cross-covariance.
[0324] The enhancement factor is calculated based on the power data, the predicted measurement mean and the measurement covariance.
[0325] The Kalman gain at the current moment is calculated based on the measurement covariance, state measurement cross-covariance, enhancement factor and system parameters.
[0326] The power system state prediction is updated based on the Kalman gain to obtain a first predicted power system state.
[0327] In a possible implementation, the second processing module 1103 is further configured to:
[0328] A first theoretical measurement value is obtained by performing calculations based on the power data, the current power system state, and system parameters.
[0329] The first Jacobian matrix is calculated based on the power system state and system parameters at the current moment.
[0330] A state update is performed based on the Jacobian matrix, the power data, the first theoretical measurement value, and the preset measurement weight matrix to obtain a second predicted power system state.
[0331] In a possible implementation, the third processing module 1104 is further configured to:
[0332] Normalization processing is performed based on the first predicted power system state and the second predicted power system state to obtain a first normalized vector corresponding to the first predicted power system state and a second normalized vector corresponding to the second predicted power system state.
[0333] A cosine similarity calculation is performed based on the first normalized vector and the second normalized vector to obtain a similarity value.
[0334] An attack determination is performed based on the similarity value and a preset attack determination threshold, and an alarm sign is obtained.
[0335] In a possible implementation, the fourth processing module 1105 is further configured to:
[0336] A second theoretical measurement value is calculated based on the second predicted power system state and system parameters.
[0337] A residual vector is calculated based on the second theoretical measurement value and the power data.
[0338] A standardized residual vector is calculated based on a second Jacobian matrix corresponding to the second predicted power system state and a preset measurement weight matrix.
[0339] Based on the normalized residual vector and the alarm flag corresponding to the similarity value, bad data detection and false input injection attack detection are performed to obtain the bad data flag and the maximum normalized residual.
[0340] The device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.
[0341] Figure 12 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 12 As shown, the electronic device provided by this embodiment includes: at least one processor 1201 and a memory 1202. Optionally, the device further includes a communication component 1203. The processor 1201, the memory 1202 and the communication component 1203 are connected via a bus 1204.
[0342] In a specific implementation process, at least one processor 1201 executes computer-executable instructions stored in the memory 1202 , so that at least one processor 1201 executes the above-mentioned false data injection attack detection method or method for the power system.
[0343] The specific implementation process of the processor 1201 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0344] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules in the processor.
[0345] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.
[0346] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0347] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0348] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0349] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0350] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0351] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, whether electrical, mechanical, or otherwise, through some interface.
[0352] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0353] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0354] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.
[0355] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0356] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A false data injection attack detection method for power systems, characterized in that: include: Obtain power data and system parameters of the target power system; Performing power system state prediction on the power data and the system parameters based on an adaptive unscented Kalman filter (AUKF) algorithm to obtain a first predicted power system state; Performing power system state prediction on the power data and the system parameters based on a weighted least squares (WLS) algorithm to obtain a second predicted power system state; performing cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag; performing residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum standardized residual; Attack classification detection is performed based on the similarity value, the maximum standardized residual, the alarm flag, and the bad data flag to obtain an attack detection result corresponding to the power data.
2. The method according to claim 1, characterized in that The obtaining of power data and system parameters of the target power system includes: Acquiring real-time measurement data of multiple dimensions generated during the operation of the target power system; Performing data processing based on the real-time measurement data of the multiple dimensions to obtain the power data; Acquiring topology data and configuration information of the target power system; Calculating system parameters corresponding to the target power system based on the topology data and configuration information; The power data refers to the real-time standardized measurement vector of the target power system, and the system parameters refer to the admittance matrix, susceptance matrix, conductance matrix, and multiple dynamic parameters corresponding to the target power system.
3. The method according to claim 2, characterized in that The performing power system state prediction on the power data and the system parameters based on the AUKF algorithm to obtain a first predicted power system state includes: generating a target point set based on the power system state at the last moment, the covariance at the last moment, and the system parameters; Performing state prediction at the current moment based on the target point set and the system parameters to obtain a predicted state mean and a predicted covariance; Performing measurement prediction at the current moment based on the target point set and the system parameters to obtain a predicted measurement mean, a measurement covariance, and a state measurement cross-covariance; Calculating an enhancement factor based on the power data, the predicted measurement mean, and the measurement covariance; Calculating based on the measurement covariance, the state measurement cross-covariance, the enhancement factor, and the system parameters to obtain a Kalman gain at a current moment; The power system state prediction is updated based on the Kalman gain to obtain a first predicted power system state.
4. The method according to claim 3, characterized in that The performing power system state prediction on the power data and the system parameters based on the WLS algorithm to obtain a second predicted power system state includes: Performing calculation based on the power data, the current power system state, and the system parameters to obtain a first theoretical measurement value; Calculating a first Jacobian matrix based on the current state of the power system and the system parameters; A state update is performed based on the Jacobian matrix, the power data, the first theoretical measurement value, and a preset measurement weight matrix to obtain the second predicted power system state.
5. The method according to claim 4, characterized in that The performing cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag includes: performing normalization processing based on the first predicted power system state and the second predicted power system state to obtain a first normalized vector corresponding to the first predicted power system state and a second normalized vector corresponding to the second predicted power system state; Performing cosine similarity calculation based on the first normalized vector and the second normalized vector to obtain a similarity value; An attack determination is performed based on the similarity value and a preset attack determination threshold to obtain an alarm sign.
6. The method according to claim 5, characterized in that The performing residual detection based on the power data, the second predicted power system state, and the system parameter to obtain a bad data flag and a maximum standardized residual includes: Calculating a second theoretical measurement value based on the second predicted power system state and the system parameter; Calculating a residual vector based on the second theoretical measurement value and the power data; Calculating a standardized residual vector based on a second Jacobian matrix corresponding to the second predicted power system state and the preset measurement weight matrix; Based on the normalized residual vector and the alarm flag corresponding to the similarity value, bad data detection and false input injection attack detection are performed to obtain a bad data flag and a maximum normalized residual.
7. A false data injection attack detection device for power systems, characterized in that: include: An acquisition module, used to acquire power data and system parameters of a target power system; A first processing module is configured to perform power system state prediction on the power data and the system parameters based on an AUKF algorithm to obtain a first predicted power system state; A second processing module is configured to perform power system state prediction on the power data and the system parameters based on a WLS algorithm to obtain a second predicted power system state; a third processing module, configured to perform cosine similarity calculation based on the first predicted power system state and the second predicted power system state to obtain a similarity value and an alarm flag; a fourth processing module, configured to perform residual detection based on the power data, the second predicted power system state, and the system parameters to obtain a bad data flag and a maximum standardized residual; A fifth processing module is configured to perform attack classification detection based on the similarity value, the maximum normalized residual, the alarm flag, and the bad data flag to obtain an attack detection result corresponding to the power data.
8. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.
10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 6 when the computer program is executed by a processor.