Network attack optimization method and system for information physical system of power distribution network

By constructing a two-layer attack and defense optimization model, the problem of lack of analysis of the interaction and decision-making process between the attacker and the defender in existing technologies is solved, a comprehensive assessment and rapid recovery of distribution network network attacks are achieved, effective defense strategies and re-dispatching solutions are provided, and the security resilience of the distribution network is improved.

CN120639468AActive Publication Date: 2025-09-12NORTH CHINA ELECTRIC POWER UNIV

Patent Information

Application Number
CN202510997971.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-20
Publication Date
2025-09-12
Estimated Expiration
2045-07-20

AI Technical Summary

Technical Problem

Existing research on distribution network attack strategies lacks in-depth analysis of the interaction and decision-making process between the attacker and the defender, resulting in a disconnect between the protection scheme and the actual dynamic threat, and is unable to fully and accurately reveal the operating characteristics of the distribution network's cyber-physical system under a cyber attack environment.

Method used

A two-layer attack and defense optimization model is constructed, including an upper-layer attack model and a lower-layer re-dispatching model. The decision-making process of attackers and dispatchers is simulated, and it is converted into a mixed integer linear programming problem through the Kuhn-Tucker condition for solution to determine the vulnerable links of the distribution network and the optimal re-dispatching strategy.

Benefits of technology

It achieves a comprehensive and accurate assessment of network attacks on distribution networks, provides effective defense strategies, and quickly formulates optimal redispatching plans for distributed power sources and energy storage systems, reducing economic losses and ensuring that distribution networks quickly resume normal operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639468A_ABST
    Figure CN120639468A_ABST
Patent Text Reader

Abstract

The invention relates to the field of power distribution network system protection, and discloses a power distribution network cyber-physical system network attack optimization method which comprises the following steps: S1, establishing an upper-layer attack model which is used for simulating a decision of an attacker for causing the maximum load loss under the constraint of limited attack resources; s2, establishing a lower-layer rescheduling model, wherein the lower-layer rescheduling model is used for simulating a response decision taking minimization of load shedding loss and scheduling cost as targets after a power distribution network dispatcher is attacked; and S3, constructing an attack and defense double-layer optimization model combining the upper-layer attack model and the lower-layer rescheduling model. Through sequential logic based on attack and defense, the first stage starts from the perspective of attackers to maximize attack consequences and minimize attack cost, and the second stage minimizes scheduling and operation cost from the perspective of dispatchers to guarantee power supply of key users, so that the influence of network attacks on the power distribution network is comprehensively and accurately evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of distribution network system protection, and specifically to a method and system for optimizing network attacks on a distribution network cyber-physical system. Background Art

[0002] As the end point of energy consumption, the distribution network plays an increasingly prominent role in achieving the "dual carbon" goals and transforming the energy structure. With the development of smart grids and the rapid advancement of information technology, the scale of power systems continues to expand, and a large number of advanced measurement, computing, communication, and control technologies are being applied to power systems. Modern distribution networks are gradually transforming into complex distribution network cyber-physical systems (CPSs), which are formed by the coupling of information communication networks and power-physical communication networks. A distribution network CPS is a multidimensional system that fully integrates the distribution-physical network and information network. Its operating mechanism relies on the coordinated interaction of multiple key devices, including computing, sensing, communication, and physical devices. Through this coordinated mechanism, the CPDS can comprehensively obtain real-time grid operation data, thereby achieving highly intelligent and automated management of the distribution network and optimizing its overall operational performance.

[0003] This transformation of distribution networks has significantly improved their operational efficiency and reliability, but it has also brought new challenges to their safe and stable operation, particularly in terms of information security. Distribution network CPSs rely heavily on complex communication links and their complex cyber-physical coupling. Failures caused by erroneous information on one side of the network or faults caused by physical components can propagate through the coupling to the other side of the network, and even propagate between coupled networks, leading to cascading failures and ultimately causing large-scale power outages. Therefore, in-depth research on attack strategies related to distribution networks is of great significance.

[0004] Existing research on distribution network attack strategies typically uses complex network theory to identify vulnerabilities and improve the network's ability to respond to attacks or failures. Complex network theory abstracts the distribution network as a graph consisting of nodes and edges. Based on this, it analyzes the connectivity between nodes and the network's topological structure to identify vulnerabilities in the system, thereby developing targeted strategies to improve the distribution network's ability to respond to attacks or failures.

[0005] Distribution network cybersecurity is essentially a dynamic confrontation between attackers and defenders. However, existing research has mostly taken a single perspective (attacker or defender), lacking in-depth analysis of the interactions and decision-making processes between the two parties. This has led to a disconnect between defense solutions and the actual dynamic threats. This one-sided approach fails to fully and accurately reveal the operational characteristics of distribution network cyber-physical systems under cyberattacks, resulting in overly partial defense strategies. Summary of the Invention

[0006] In response to the shortcomings of the existing technology, the present invention provides a network attack optimization method and system for the information-physical system of the distribution network, which solves the problem in the existing technology of lacking in-depth analysis of the interaction and decision-making process between the attacker and the defender, resulting in the disconnection between the protection plan and the actual dynamic threat.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: a method for optimizing network attacks on a cyber-physical system of a distribution network, comprising the following steps:

[0008] S1. Establishing an upper-layer attack model, wherein the upper-layer attack model is used to simulate the attacker's decision to cause maximum load loss under the constraint of limited attack resources;

[0009] S2. Establishing a lower-level re-dispatching model, wherein the lower-level re-dispatching model is used to simulate the response decision of the distribution network dispatcher after being attacked with the goal of minimizing load shedding losses and dispatching costs;

[0010] S3. Constructing an attack-defense dual-layer optimization model that combines the upper-layer attack model with the lower-layer rescheduling model;

[0011] S4. Solve the attack-defense two-layer optimization model to determine the vulnerable links of the distribution network and the optimal re-dispatching strategy.

[0012] Preferably, the method further includes: before establishing the upper-layer attack model and the lower-layer rescheduling model, constructing a distribution network topology model based on graph theory, abstracting the power equipment in the distribution network as nodes, and abstracting the lines as edges.

[0013] Preferably, the upper-layer attack model defines the attacker's objective function as maximizing the difference between the load loss caused by the attack and the attack cost, and the attack decision is subject to the constraint of the total amount of attack resources.

[0014] Preferably, the objective function of the lower-level rescheduling model includes load shedding loss cost, distributed power generation scheduling cost and energy storage system scheduling cost.

[0015] Preferably, the response decisions of the lower-layer rescheduling model include fault isolation, network reconstruction, and coordinated output scheduling of distributed power sources and energy storage systems.

[0016] Preferably, the step of solving the attack-defense two-layer optimization model includes: using the Kuhn-Tucker condition to convert the optimality condition of the lower-layer rescheduling model into a set of constraints, thereby converting the attack-defense two-layer optimization model into a single-layer optimization model.

[0017] Preferably, the single-layer optimization model includes a nonlinear term generated by multiplying two binary variables, and the nonlinear term is linearized by introducing auxiliary variables and additional constraints.

[0018] Preferably, the constraints converted from the Kuhn-Tucker conditions include complementary slack constraints, and the complementary slack constraints are linearized using the Big M method.

[0019] Preferably, the single-layer optimization model is finally transformed into a mixed integer linear programming problem and solved using a standard solver.

[0020] A system based on the above method comprises:

[0021] An upper-layer attack model establishment module, used to establish an upper-layer attack model, wherein the upper-layer attack model is used to simulate the attacker's decision to cause maximum load loss under the constraint of limited attack resources;

[0022] A lower-level re-dispatching model establishment module is used to establish a lower-level re-dispatching model, wherein the lower-level re-dispatching model is used to simulate the response decision of the distribution network dispatcher after being attacked with the goal of minimizing load shedding losses and dispatching costs;

[0023] The model solving module is used to construct and solve an attack-defense two-layer optimization model consisting of the upper-layer attack model and the lower-layer rescheduling model. It converts the two-layer optimization model into a single-layer optimization model by using the Kuhn-Tucker condition, and converts the single-layer optimization model into a mixed integer linear programming problem through a linearization method for solution, ultimately determining the vulnerable links of the distribution network and the optimal rescheduling strategy.

[0024] The present invention provides a method and system for optimizing network attack on the information-physical system of distribution network.

[0025] Beneficial effects:

[0026] The present invention constructs a network attack optimization model for the information-physical system of the distribution network from the perspective of attack and defense. Based on the temporal logic of attack and defense, the first stage starts from the perspective of the attacker, maximizes the consequences of the attack and minimizes the cost of the attack. The second stage minimizes the dispatching and operating costs from the perspective of the dispatcher to ensure the power supply of key users. It comprehensively and accurately evaluates the impact of network attacks on the distribution network, and provides a strong basis for formulating effective defense strategies. The model fully considers the complex physical characteristics, operating constraints and equipment composition of the distribution network. It also introduces a two-layer optimization framework to simulate the dynamic game process of attack and defense, reveals the operating characteristics of the distribution network under the network attack environment, and provides a reference for improving security resilience. Based on the KKT condition, the two-layer nonlinear programming model is converted into an MILP problem, which effectively solves the problems of difficult solution and low computational efficiency, realizes the rapid solution of large-scale distribution network scenarios, and meets the actual rapid response requirements. At the same time, the optimized output and power supply restoration strategy proposed by the present invention can quickly formulate the optimal re-dispatching plan for DG and BESS, minimize the adverse consequences caused by the attack, reduce economic losses, and ensure that the distribution network resumes normal operation as soon as possible. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 This is a topological diagram of a normally open loop distribution network of the present invention;

[0028] Figure 2 This is an abstract diagram of the normally open loop distribution network of the present invention;

[0029] Figure 3 This is a diagram of the framework structure of the double-layer optimization model of the present invention;

[0030] Figure 4 It is a flow chart of the distribution network CPS network attack optimization method of the present invention. DETAILED DESCRIPTION

[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the present specification. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0032] Example:

[0033] Please see the attached Figure 1 -Attached Figure 4 , an embodiment of the present invention provides a method for optimizing network attacks on a cyber-physical system of a distribution network, comprising:

[0034] 1. Distribution network topology model based on graph theory

[0035] Typical distribution network topologies mainly include: basic radial distribution network, radial interconnection distribution network, normally open loop distribution network and normally closed loop distribution network. Among them, the normally open loop type is widely used in large industrial areas or urban power grids. In order to achieve the maximum attack efficiency, the attack targets of distribution network attackers are mainly aimed at important loads and important industrial facilities in urban power grids. Therefore, the present invention analyzes the main normally open loop distribution network. The normally open loop topology connects different feeders through interconnection switches. The line is arranged in a ring shape, and the line is in an open-loop operation state through the normally open interconnection switch to avoid the formation of a closed loop. Under normal conditions, the normally open loop distribution network supplies power from the head end of the line to the terminal distribution transformer and load. If a short circuit or line break occurs in a certain section of the line, the dispatcher will disconnect the necessary switches and close the interconnection switches according to the operating status of the power grid to ensure power supply to part of the load.

[0036] In addition, due to economic factors and various historical reasons, the types of line switches in the distribution network are often difficult to unify, but from the functional point of view, they can be divided into: circuit breakers that can open and close short-circuit currents, load switches that can open and close normal working currents, and disconnect switches for maintenance. Other switches except circuit breakers and load switches do not have the ability to open and close. Even if the network is accessible, system dispatchers and maintenance personnel cannot open and close these switches under power. Therefore, the line switches of the present invention only consider circuit breakers and load switches, and other switches are equivalent to part of the line. Finally, the normally open loop type distribution network topology diagram can be obtained as shown in the attached figure. Figure 1 shown.

[0037] The distribution network can use graph theory to describe its physical relationships, including load switches (S), circuit breakers (B), and abstract graphs G in the topology graph. The abstract graph G is usually represented by V(G) and S(G), where V(G) represents a non-empty finite set of nodes in the graph and S(G) represents a non-empty finite set of edges in the abstract graph.

[0038] V(G)={v1,v2,...,v n} represents a node set, S(G)={s1,s2,...,s n} represents an edge set.

[0039] Edge s∈S(G) represents a node pair {v i ,v j} connection relationship. If v i and v j Connected by edge d, then v i and v j is the endpoint of the edge.

[0040] Attachment Figure 2is the corresponding abstract graph. The switches and distribution transformers in the topology graph correspond to nodes in the abstract graph, and the lines in the topology graph correspond to edges in the abstract graph. Based on the node type and function of the topology graph, the nodes in the abstract graph are divided into: circuit breakers, load switches, energy storage devices, distributed power sources, reactive power compensation devices, normally open tie switches, and distribution transformer nodes.

[0041] In the abstract graph, using the binary variable d i , l ij Indicates the status of nodes and edges. i Indicates the power supply status of the node. If d i =1, it means the node is normal and there is no power failure. Otherwise, it means the node is out of power and there is no effective power supply path. ij Indicates the power supply status of the line. If there is a power line (i, j), then l ij =1, otherwise it is 0. Under normal working conditions, the contact switch is disconnected, so d 16 =0,l 6,16 =0, except for the above, all lines in the distribution network have current flowing through them, i.e., d i =1,l ij =1.

[0042] 2. Distribution Network CPS Attack Model

[0043] The distribution network CPS attack model takes the maximum load loss and the minimum attack cost as the objective function, which is expressed by Equation 1.

[0044]

[0045] Where, Ω N is the set of system nodes; Ω L,C is the set of distribution network lines accessible by the head-end switch network; is the load weight, is the unit price of the node j load, where the unit price and weight are determined by the load type, which is mainly divided into six composite types: government units, culture and education, hospitals, commerce, industry, and residents. Under the premise of limited attack resources, the attacker will use the first-level load as the expected attack target. is the load shedding amount at node j; ζ1 is the weight coefficient; a ij Indicates whether the head-end switch on line (i, i) is under network attack. If it is under network attack, a ij =1, otherwise it is 0; C cyb Cost of cyber attacks.

[0046] Intelligent electronic devices (IEDs) are a crucial component of modern distribution network automation systems. Among them, the feeder terminal unit (FTU) is the most fundamental and widely used field terminal device in distribution network automation. Essentially a specialized form of the remote terminal unit (RTU) for distribution network feeder monitoring, it is often referred to as an FTU or feeder RTU.

[0047] FTUs are typically installed directly on distribution line pole switches, ring main units, and switchgear. They monitor the operating status of feeder section switches or tie switches in real time and execute remote control commands from the control center to remotely open and close the feeder. The data collected by the FTUs is the foundation for their ability to locate, isolate, and restore feeder faults. Distribution substations are a critical intermediary between numerous on-site FTUs and the master distribution automation system. They are typically located in key substations, switchgear stations, or regional control centers. The primary function of a distribution substation is to aggregate real-time data uploaded by multiple FTUs within its jurisdiction, perform necessary data processing, filtering, and compression, and then transmit it to the master system. They also receive and forward control commands from the master to individual FTUs. Because Supervisory Control and Data Acquisition (SCADA) systems are located in highly secure control centers with strict physical and network security, direct attacks are extremely difficult. However, distribution substations, due to their large number, widespread distribution, relatively weak physical and network security, regional control, and potential as springboards for attacks, present a more realistic and common entry point for malicious attackers. Therefore, this section assumes that a malicious attacker uses the distribution substation as the attack entry point and causes a specific circuit breaker to trip by injecting false data.

[0048] In distribution networks, not all switchgear is equipped with intelligent electronic devices. Except in a few highly developed urban distribution networks, IEDs are often only installed in important equipment and key nodes. To closely reflect the actual operation of the power grid, this paper only assumes that some key switches are network accessible, that is, they can be remotely controlled and closed by the distribution substation. The distribution network state model based on network attacks can be established as follows:

[0049]

[0050] Where: a i Represents the network attack point. If the switch at node i is attacked by the network, then a i =1, otherwise it is 0; represents z i Indicates the actual opening and closing state of the switch. If zi =1, the switch at node i is closed, otherwise it is 0; R cyb Consume resources for attacks on a single node; Resources that can be obtained through network attacks; V is the node set; Ω V,C ∈Ω V is the set of nodes reachable by network communication; Ω V,NC ∈Ω V is the set of nodes that are unreachable by network communication; Ω S is the edge set;

[0051] Formula 2-3 is the actual opening and closing state of the switch z i Equation 4 is the line power supply constraint; Equation 5 is the network attack resource constraint.

[0052] After being attacked, the cyber-physical system of the distribution network should satisfy the equipment operation constraints and line flow constraints shown in Equations 6 to 18.

[0053]

[0054] V1≤V sub (Equation 17);

[0055]

[0056] Where: P ij is the power flow of line ij; ΔP j L , are active and reactive load shedding respectively; ΔP j L is the load at node j; is the power factor at node j; β j is the ratio between reactive power and real power; Ω V,L is the set of nodes with load; is the reactive load loss; δ(j), π(j) are the child / parent node sets of node j respectively; is the reactive power compensation of node j; V j is the node voltage; R ij , X ij are line resistance and reactance respectively; is the maximum capacity of line ij; V sub is the low voltage side voltage of the substation; V max , V min They are the upper and lower voltage limits respectively.

[0057] Equation 6 ensures that the number of closed lines does not exceed the number of non-source buses; Equation 7 states that the load shedding amount cannot exceed the existing load; based on the assumption that the power factor of the critical load (CL) and the interruptible load (IL) is always constant, the ratio between the reactive power and active power of the load can be expressed as Equation 8; reactive power can be replaced by active power, as shown in Equations 9 and 10; Equations 11 and 12 are the power and reactive power balance constraints, respectively; the reactive power of the parallel VAR compensation device has a small fluctuation range and can be linearized as Equation 13; based on the distribution network linearization model, the correlation between the line voltage drop and the line state can be established by Equation 14. If l ij =1, the inequality constraint is simplified to an equality constraint. If l jj = 0, then the voltage drop constraint is relaxed by the large M method; Equations 15 and 16 are line power flow constraints. If a switch at one end of the line is disconnected, then l ij =0, ensuring that the power flow through line ij is 0. If the switches at both ends are closed normally, the reactive power limit is assumed to be half of the line limit. Node 1 is the substation outgoing line breaker, and its voltage is given by Equation 17. The voltage limit constraint is given by Equation 18.

[0058] 3. Distribution network CPS attack re-dispatching model

[0059] During distribution network operations, if a circuit breaker trips, causing load loss, prompting an emergency, the network dispatcher will quickly take measures to ensure power supply. The dispatcher's primary task is to isolate the faulty area and prevent further expansion. Because distribution networks typically operate in a closed-loop structure, isolation is achieved simply by disconnecting all sub-node switches on the faulty line. After isolating the fault, the dispatcher quickly closes the tie switch to restore power to critical loads as quickly as possible. This ensures that dispatch resources are utilized as efficiently as possible, ensuring continuous and stable power supply to as many critical users as possible with minimal resource investment.

[0060] To achieve this goal, the present invention establishes a distribution network re-dispatching model after a network attack, and its objective function can be written as:

[0061]

[0062] Where: are the unit DG and active power output costs respectively, and ξ2 is the weight coefficient.

[0063] The objective function aims to minimize the costs of load shedding, DG output, and BESS output. By incorporating the three components of load shedding loss cost, DG output cost, and energy storage device output cost into the objective function and solving the optimization problem under the strict constraints of various safety constraints (node ​​voltage constraints, line power constraints), it can provide dispatchers with a scientific decision-making basis. The establishment of this model helps dispatchers to quickly and accurately formulate the optimal re-dispatch plan in the complex distribution network environment after a cyber attack, minimize the adverse consequences of the attack on the normal operation of the distribution network, ensure the power supply reliability and stability of the distribution network, reduce economic losses and the impact on users, and ensure that the distribution network can return to normal operation as soon as possible.

[0064] The initial switch state of the distribution network redispatching is the same as the attack model solution. At the same time, the dispatcher will isolate the fault by opening the switch and close the tie switch that can supply power to the power-off load. Therefore, the switch state variable can be written as:

[0065]

[0066] Where: (·) * The solution of the distribution network CPS attack model Ω V,I For contact switch assembly.

[0067] Equation 20 indicates that the states of all switches are the same as after the attack; in order to isolate the fault, the dispatcher disconnects the switches at both ends of the line, and the switch constraints are shown in Equation 21; Equation 22 indicates that the dispatcher will ensure the power supply to users by opening and closing the interconnecting switches. The safe operation constraints of the distribution network redispatching are the same as those under the attack model, as shown in Equations 6 to 18. The difference is that the distribution network dispatcher can issue dispatch instructions to the distributed power generation station and the battery energy storage system (BESS) to increase the output to ensure power supply. Therefore, the optimal dispatch of DG and BESS can be achieved through the constraints shown in Equations 23 to 28. Note: The DG system of the present invention mainly includes fuel-based DG and photovoltaic-based DG, so the reactive power output of DG and BESS is expressed as zero, and the active output of the reactive compensation equipment is set to 0.

[0068]

[0069] Where: P j DG The output of distributed generation (DG) of node j; P j DGmax Indicates the upper limit of DG output; Ω V,G is the set of nodes with DG; Ω V,E is a set of nodes; is the initial residual energy of BESS at node j; is the remaining capacity of BESS; P h Bdch is the discharge power of BESS at node j; is the net discharge limit; is the remaining capacity of the BESS after discharging for Δt time. Since this section focuses on analyzing the unit time section after the attack is completed, Δt is taken as 1 hour. They are the maximum and minimum values ​​of the remaining power (State Of Charge, SOC);

[0070] Equation 23 represents the active power output constraint for the DG. Equation 24 limits the initial battery capacity. Before network GJ implementation, all BESSs must be precharged to 100%. Because the latest lithium batteries have high charge and discharge efficiencies, reaching 92%-96%, this paper assumes a BESS efficiency of 100% to simplify the model. The charge and discharge limits can thus be expressed using Equation 25. Equation 26 represents the BESS energy change per unit time. Equation 27 limits the BESS SOC limit. Equation 28 is the power balance constraint for calculating the DG and BESS outputs.

[0071] 4. KKT-based two-layer model solution method

[0072] The two-level optimization model is mainly used to deal with hierarchical and layered decision-making problems. The model is generally as follows:

[0073] As shown in Equation 29 and Equation 30:

[0074]

[0075] Where: x and y are the decision variables of the upper layer optimization; in the lower layer model, x is a fixed parameter and y is the decision variable; G i (·), H j (·), g k (·) and h l (·) are all different functions; n i Indicates the number of constraints.

[0076] This paper proposes a two-layer optimization framework based on the attack and defense characteristics of the distribution network cyber-physical system. Figure 3 As shown in the figure, the model follows a temporal logic sequence of attack first and defense response: the upper model simulates the attacker's decision-making process of causing the maximum load loss in the distribution network at the minimum attack cost; the lower model describes the dispatcher's adjustment of the distributed power supply, energy storage system, and interconnection switch operation to minimize power outage losses after being attacked. The two-layer optimization model proposed in this invention uses the game between the attacker and the defender to provide the optimal solution, providing an important reference for improving the security and resilience of the distribution network.

[0077] The proposed two-layer optimization model for CPS attack on distribution network has the following problems:

[0078] 1) Both the upper and lower layers contain 0-1 decision variables, and both are mixed integer optimization problems that are difficult to solve directly;

[0079] 2) There are nonlinear constraints on the multiplication of binary variables;

[0080] 3) The actual distribution network contains hundreds of nodes, and traditional methods are difficult to solve efficiently.

[0081] In order to solve the above problems, the present invention converts the original model into a mixed integer linear programming (MILP) problem based on the KKT condition, and finally solves it through the existing solver.

[0082] First, in the above model, Equation 4 is a nonlinear constraint for the multiplication of two binary variables. In order to linearize it, an auxiliary variable β is introduced ij , let β ij =z i ·z j , rewrite Equation 4 into Equation 31, and use Equations 32-35 to constrain β ij .

[0083]

[0084] After the above processing, nonlinear constraints are transformed into linear constraints. The decision variables of the upper model are Once determined, the distribution network topology of the lower-level model is also uniquely determined.

[0085] Since the upper and lower layers in the two-layer model are coupled with each other, the upper layer decisions affect the lower layer, and the lower layer optimization results will be fed back to the upper layer. At the same time, the relationship between variables is complex. Using existing intelligent algorithms to solve this two-layer optimization problem not only takes up a lot of memory but also has a slow solution speed.

[0086] The KKT condition is the first-order optimality condition of the underlying optimization problem. When the underlying problem is convex optimization, if the point (x * ,y * ) is the local optimal solution to the lower-level problem, then there exists a corresponding Lagrange multiplier such that the point satisfies the KKT condition. Since the upper and lower-level decisions in a two-level optimization problem are interconnected, the KKT condition provides a mathematical description of this relationship. By introducing the KKT condition, the optimality condition of the lower-level optimization problem can be explicitly incorporated into the entire two-level optimization model, thus transforming the previously difficult-to-solve two-level structure into a single-level optimization problem with specific constraints, allowing for a unified solution of the entire problem.

[0087] Taking the model shown in Equation 30 as an example, it can be converted into the Lagrangian function form:

[0088]

[0089] Where: L(x,{μ k},{λ l}) is about x, {μ k}, {λ l}Lagrangian function; μ k ,λ l g k (x)≤0 and h l (x) = 0 corresponding Lagrange multiplier; {μ k}, {λ l} are μ k ,λ l A collection of .

[0090] Due to g k (x)≤0,h l (x) = 0, μ k ≥0 and λ l ≥0, so maxL(x,{μ k},{y l})=f(x). Therefore, minf(x) can be converted to min maxL(x,μ,λ), and the necessary conditions for minf(x) to obtain the optimal solution are:

[0091]

[0092] Equation 37 is the KKT condition for the model (Equation 30). By combining Equation 29 and Equation 37, the original bi-level programming model can be converted into a single-level linear optimization model for solution.

[0093] However, since the two-level optimization model proposed in the present invention is nonlinear and the lower-level model contains 0-1 decision variables and a large number of nonlinear constraints, traditional solution methods are difficult to apply directly. Therefore, the present invention uses the KKT coupled Fortuny-Amat-McCarl method to linearize the relaxed complementary constraints Equations 6-18 and 23-28. The core idea of ​​this method is to introduce binary variables (0-1 variables) and a "large M" constant, convert the two-level model into a single-level model, convert non-convex or nonlinear relationships into linear constraints, and finally use the gurobi solver to solve the two-level model.

[0094] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A method for optimizing cyber attacks on a distribution network cyber-physical system, characterized in that: The following steps are involved: S1. Establishing an upper-layer attack model, wherein the upper-layer attack model is used to simulate the attacker's decision to cause maximum load loss under the constraint of limited attack resources; S2. Establishing a lower-level re-dispatching model, wherein the lower-level re-dispatching model is used to simulate the response decision of the distribution network dispatcher after being attacked with the goal of minimizing load shedding losses and dispatching costs; S3. Constructing an attack-defense dual-layer optimization model that combines the upper-layer attack model with the lower-layer rescheduling model; S4. Solve the attack-defense two-layer optimization model to determine the vulnerable links of the distribution network and the optimal re-dispatching strategy.

2. The method for optimizing network attack of the information-physical system of the distribution network according to claim 1, characterized in that: The method further includes: before establishing the upper-layer attack model and the lower-layer rescheduling model, constructing a distribution network topology model based on graph theory, abstracting power equipment in the distribution network as nodes, and abstracting lines as edges.

3. The method for optimizing network attack of the information-physical system of the distribution network according to claim 1, characterized in that: The upper-layer attack model defines the attacker's objective function as maximizing the difference between the load loss caused by the attack and the attack cost, and the attack decision is subject to the total amount of attack resources.

4. The method for optimizing network attack of the information-physical system of the distribution network according to claim 1, characterized in that: The objective function of the lower-level rescheduling model includes load shedding loss cost, distributed power generation scheduling cost and energy storage system scheduling cost.

5. The method for optimizing network attack of the information-physical system of the distribution network according to claim 4, characterized in that: The response decisions of the lower-level rescheduling model include fault isolation, network reconstruction, and coordinated output scheduling of distributed power sources and energy storage systems.

6. The method for optimizing network attack of the information-physical system of the distribution network according to claim 1, characterized in that: The step of solving the attack-defense dual-layer optimization model includes: using the Kuhn-Tucker condition to convert the optimality condition of the lower-layer rescheduling model into a set of constraints, thereby converting the attack-defense dual-layer optimization model into a single-layer optimization model.

7. The method for optimizing network attack of the information-physical system of the distribution network according to claim 6, characterized in that: The single-layer optimization model includes a nonlinear term generated by multiplying two binary variables, and the nonlinear term is linearized by introducing auxiliary variables and additional constraints.

8. The method for optimizing network attack of the information-physical system of the distribution network according to claim 6, characterized in that: The constraints obtained by transforming the Kuhn-Tucker conditions include complementary slack constraints, and the Big M method is used to linearize the complementary slack constraints.

9. The method for optimizing network attack of the information-physical system of the distribution network according to claim 8, characterized in that: The single-layer optimization model is finally transformed into a mixed integer linear programming problem and solved using a standard solver.

10. A system based on the method of claim 1, characterized in that: include: An upper-layer attack model establishment module, used to establish an upper-layer attack model, wherein the upper-layer attack model is used to simulate the attacker's decision to cause maximum load loss under the constraint of limited attack resources; A lower-level re-dispatching model establishment module is used to establish a lower-level re-dispatching model, wherein the lower-level re-dispatching model is used to simulate the response decision of the distribution network dispatcher after being attacked with the goal of minimizing load shedding losses and dispatching costs; The model solving module is used to construct and solve an attack-defense two-layer optimization model consisting of the upper-layer attack model and the lower-layer rescheduling model. It converts the two-layer optimization model into a single-layer optimization model by using the Kuhn-Tucker condition, and converts the single-layer optimization model into a mixed integer linear programming problem through a linearization method for solution, ultimately determining the vulnerable links of the distribution network and the optimal rescheduling strategy.

Citation Information

Patent Citations

  • Optimization method of electric vehicle driving path based on network reconstruction

    CN113036790A

  • Inhibition strategy and defense method for power grid frequency disturbance under network attack

    CN118611097A

  • Power transmission system key plant station identification method considering network-physical cross-domain attack

    CN120281551A

Cited By

  • Information physical cooperative attack method, medium and device for power system

    CN115860521A