Cyber-physical system network attack optimization method and system for power distribution network

By constructing a two-layer optimization model for offense and defense, the lack of analysis on the interaction and decision-making process between the attacker and defender in existing technologies is solved. This enables comprehensive assessment and rapid recovery from attacks on distribution network, provides effective defense strategies and rescheduling schemes, and enhances the security resilience of the distribution network.

CN120639468BActive Publication Date: 2026-03-24NORTH CHINA ELECTRIC POWER UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-20
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing research on power distribution network attack strategies lacks in-depth analysis of the interaction and decision-making process between attackers and defenders, resulting in a disconnect between protection schemes and actual dynamic threats, and failing to fully and accurately reveal the operational characteristics of the power distribution network cyber-physical system in a cyberattack environment.

Method used

A two-layer optimization model for offense and defense is constructed, including an upper-layer attack model and a lower-layer rescheduling model. The decision-making process of attackers and dispatchers is simulated. The problem is transformed into a mixed-integer linear programming problem through the Kuhn-Tak condition, and the vulnerable links of the distribution network and the optimal rescheduling strategy are determined.

Benefits of technology

It enables comprehensive and accurate assessment of attacks on distribution network, provides effective defense strategies, and quickly formulates optimal rescheduling schemes for distributed power sources and energy storage systems to minimize the consequences of attacks and ensure the rapid restoration of normal operation of the distribution network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639468B_ABST
    Figure CN120639468B_ABST
Patent Text Reader

Abstract

The application relates to the field of power distribution network system protection, and discloses a power distribution network information physical system network attack optimization method, which comprises the following steps: S1, an upper attack model is established, the upper attack model is used for simulating the decision of an attacker under the constraint of limited attack resources to cause maximum load loss as a target; S2, a lower rescheduling model is established, the lower rescheduling model is used for simulating the response decision of a power distribution network dispatcher after suffering from an attack to minimize the load loss and scheduling cost; S3, an attack and defense double-layer optimization model combining the upper attack model and the lower rescheduling model is constructed. Through the time sequence logic based on attack and defense, the first stage maximizes the attack consequence and minimizes the attack cost from the perspective of the attacker, and the second stage minimizes the scheduling and operation cost from the perspective of the dispatcher to guarantee power supply of key users, so that the influence of network attack on the power distribution network is comprehensively and accurately evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power distribution network system protection, specifically to a method and system for optimizing network attacks on power distribution network cyber-physical systems. Background Technology

[0002] As the end point of energy consumption, the distribution network plays an increasingly prominent role in achieving "dual carbon" goals and energy structure transformation. With the development of smart grids and the rapid advancement of information technology, the scale of power systems continues to expand, and numerous advanced measurement, computing, communication, and control technologies are being applied to power systems. Modern distribution networks are gradually transforming into complex Cyber-Physical Systems (CPS) formed by the coupling of information communication networks and power physical communication networks. A distribution network CPS is a multi-dimensional system that fully integrates the distribution physical network and the information network. Its operation mechanism relies on the mutual coordination of various key devices such as computing devices, sensing devices, communication devices, and physical devices. Through this coordination mechanism, the CPS can comprehensively acquire real-time operation data of the power grid, thereby achieving highly intelligent and automated management of the distribution network and optimizing its overall operating performance.

[0003] This transformation of the distribution network significantly improves its operational efficiency and reliability, but it also brings new challenges to the safe and stable operation of the distribution network, especially in terms of information security. Distribution network cybersecurity systems (CPS) heavily rely on complex communication links and their intricate cyber-physical coupling relationships. Faults caused by erroneous information on one side of the network or by physical components can propagate to another side of the network through these coupling relationships, and even spread between coupled networks, forming cascading faults and ultimately leading to large-scale power outages. Therefore, in-depth research into attack strategies related to distribution networks is of great significance.

[0004] Existing research on power distribution network attack strategies typically employs complex network theory to identify vulnerabilities in order to improve the power distribution network's ability to cope with attacks or faults. Complex network theory abstracts the power distribution network as a graph consisting of nodes and edges, and then analyzes the connectivity between nodes and the topological characteristics of the network to identify vulnerabilities in the system, thereby formulating targeted strategies to improve the power distribution network's ability to cope with attacks or faults.

[0005] Distribution network network security is essentially a dynamic confrontation between attackers and defenders. However, most existing research focuses on a single perspective (attacker or defender), lacking in-depth analysis of the interaction and decision-making processes between the two sides. This leads to a disconnect between protection solutions and actual dynamic threats. This one-sided research approach cannot comprehensively and accurately reveal the operational characteristics of distribution network cyber-physical systems in a cyberattack environment, resulting in overly simplistic defense strategies. Summary of the Invention

[0006] To address the shortcomings of existing technologies, this invention provides a method and system for optimizing network attacks on distribution network cyber-physical systems. This solves the problem that existing technologies lack in-depth analysis of the interaction and decision-making processes between attackers and defenders, leading to a disconnect between protection schemes and actual dynamic threats.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for optimizing network attacks on distribution network cyber-physical systems, comprising the following steps:

[0008] S1. Establish an upper-layer attack model, which is used to simulate the attacker's decision-making under the constraint of limited attack resources with the goal of causing the maximum load loss;

[0009] S2. Establish a lower-level rescheduling model, which is used to simulate the response decision of the distribution network dispatcher after being attacked, with the goal of minimizing load shedding losses and dispatching costs.

[0010] S3. Construct a two-layer optimization model that combines the upper-layer attack model with the lower-layer rescheduling model;

[0011] S4. Solve the aforementioned attack and defense dual-layer optimization model to determine the vulnerable links of the distribution network and the optimal rescheduling strategy.

[0012] Preferably, the method further includes: before establishing the upper-layer attack model and the lower-layer rescheduling model, constructing a distribution network topology model based on graph theory, abstracting the power equipment in the distribution network as nodes, and the lines as edges.

[0013] Preferably, the upper-layer attack model defines the attacker's objective function as maximizing the difference between the load loss caused by the attack and the attack cost, and the attack decision is constrained by the total amount of attack resources.

[0014] Preferably, the objective function of the lower-level rescheduling model includes load shedding loss cost, distributed power source scheduling cost, and energy storage system scheduling cost.

[0015] Preferably, the response decisions of the lower-level rescheduling model include fault isolation, network reconfiguration, and coordinated power output scheduling of distributed power sources and energy storage systems.

[0016] Preferably, the step of solving the attack-defense two-layer optimization model includes: using the Kuhn-Tak condition to transform the optimality condition of the lower-layer rescheduling model into a set of constraints, thereby converting the attack-defense two-layer optimization model into a single-layer optimization model.

[0017] Preferably, the single-layer optimization model includes a nonlinear term generated by multiplying two binary variables, and the nonlinear term is linearized by introducing auxiliary variables and additional constraints.

[0018] Preferably, the constraints derived from the Kuntak conditions include complementary relaxation constraints, and the Big M method is used to linearize the complementary relaxation constraints.

[0019] Preferably, the single-layer optimization model is ultimately transformed into a mixed-integer linear programming problem and solved using a standard solver.

[0020] A system based on the above method includes:

[0021] The upper-layer attack model establishment module is used to establish an upper-layer attack model, which is used to simulate the attacker's decision-making under the constraint of limited attack resources with the goal of causing maximum load loss;

[0022] The lower-level rescheduling model establishment module is used to establish a lower-level rescheduling model, which is used to simulate the response decision of the distribution network dispatcher after being attacked, with the goal of minimizing load shedding losses and dispatching costs.

[0023] The model solving module is used to construct and solve the attack and defense two-layer optimization model consisting of the upper-layer attack model and the lower-layer rescheduling model. It transforms the two-layer optimization model into a single-layer optimization model by using the Kuhn-Tak condition, and then transforms the single-layer optimization model into a mixed integer linear programming problem by using a linearization method, and finally determines the vulnerable links of the distribution network and the optimal rescheduling strategy.

[0024] This invention provides a method and system for optimizing network attacks on distribution network cyber-physical systems. It possesses the following features:

[0025] Beneficial effects:

[0026] This invention constructs a network attack optimization model for a distribution network cyber-physical system from an offensive and defensive perspective. Based on the temporal logic of offense and defense, the first stage, from the attacker's perspective, maximizes the attack consequences and minimizes the attack costs. The second stage, from the dispatcher's perspective, minimizes scheduling and operating costs to ensure power supply to critical users. This comprehensively and accurately assesses the impact of network attacks on the distribution network, providing a strong basis for formulating effective defense strategies. The model fully considers the complex physical characteristics, operational constraints, and equipment composition of the distribution network. It also introduces a two-layer optimization framework to simulate the dynamic game process of offense and defense, revealing the operational characteristics of the distribution network under network attack environments and providing a reference for improving security resilience. Based on KKT conditions, the two-layer nonlinear programming model is transformed into a MILP problem, effectively solving the problems of difficulty in solving and low computational efficiency, enabling rapid solutions for large-scale distribution network scenarios and meeting the actual needs for rapid response. Simultaneously, the optimized output and power restoration strategies proposed in this invention can quickly formulate optimal rescheduling schemes for DG and BESS, minimizing the adverse consequences of attacks, reducing economic losses, and ensuring the distribution network returns to normal operation as quickly as possible. Attached Figure Description

[0027] Figure 1 This is a normally open loop distribution network topology diagram of the present invention;

[0028] Figure 2 This is an abstract diagram of the normally open loop type distribution network of the present invention;

[0029] Figure 3 This is a structural diagram of the two-layer optimization model framework of the present invention;

[0030] Figure 4 This is a schematic diagram of the distribution network CPS network attack optimization method of the present invention. Detailed Implementation

[0031] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0032] Example:

[0033] Please see the appendix Figure 1 - Appendix Figure 4 This invention provides an optimization method for network attacks on distribution network cyber-physical systems, including:

[0034] 1. Distribution network topology model based on graph theory

[0035] Typical distribution network topologies mainly include four types: basic radial distribution network, radial interconnected distribution network, normally open loop distribution network, and normally closed loop distribution network. Among them, the normally open loop type is widely used in large industrial areas or urban power grids. To achieve maximum attack effectiveness, attackers in distribution networks primarily target critical loads and important industrial facilities in urban power grids. Therefore, this invention mainly analyzes the normally open loop distribution network. The normally open loop topology connects different feeders through interconnected switches. The lines are arranged in a ring, and the normally open interconnected switches keep the lines in an open-loop operation state, preventing the formation of closed loops. Under normal conditions, the normally open loop distribution network supplies power from the beginning of the line to the distribution transformer and load at the end. If a short circuit or open circuit fault occurs in a section of the line, dispatchers will, based on the grid operating status, disconnect necessary switches and close interconnected switches to ensure power supply to some loads.

[0036] Furthermore, due to economic factors and various historical reasons, the types of line switches in the distribution network are often difficult to standardize. However, functionally, they can be divided into: circuit breakers capable of switching short-circuit current, load switches capable of switching normal operating current, and disconnecting switches for maintenance. Other switches besides circuit breakers and load switches do not have the ability to interrupt circuits. Even if the network is accessible, system dispatchers and maintenance personnel cannot switch these switches while they are energized. Therefore, this invention only considers circuit breakers and load switches; other switches are equivalent to part of the line. The resulting normally open loop distribution network topology is shown in the attached diagram. Figure 1 As shown.

[0037] The physical relationships of a power distribution network can be described using graph theory. The topology graph contains load switches (S), circuit breakers (B), and an abstract graph G. The abstract graph G is usually represented by V(G) and S(G), where V(G) represents a non-empty finite set of nodes in the graph and S(G) represents a non-empty finite set of edges in the abstract graph.

[0038] V(G)={v1,v2,...,v n Let} represent the set of nodes, S(G) = {s1, s2, ..., s} n} represents the set of edges.

[0039] An edge s∈S(G) represents a pair of nodes {v i ,v j The connection relationship of}. If v i and v j If v is connected by edge d, then v is called v i and v j Let be the endpoint of this edge.

[0040] Appendix Figure 2This is the corresponding abstract diagram. Switches and distribution transformers in the topology diagram correspond to nodes in the abstract diagram, and lines in the topology diagram correspond to edges in the abstract diagram. Based on the different categories and functions of nodes in the topology diagram, nodes in the abstract diagram are divided into: circuit breakers, load switches, energy storage devices, distributed power sources, reactive power compensation devices, normally open tie switches, and distribution transformer nodes.

[0041] In the abstract diagram, the binary variable d is used. i , l ij This represents the state of nodes and edges. (d) i Indicates the power supply status of the node, if d i =1 indicates that the node is normal and has not lost power; conversely, a value of 1 indicates that the node is out of power and there is no effective power supply path. Similarly, l ij This indicates the power supply status of the line. If there is a power line (i,j), then l ij =1, otherwise it is 0. Under normal operating conditions, the connecting switch is open, so d 16 =0,l 6,16 =0, and in addition to this, current flows through every line in the distribution network, i.e., d i =1,l ij =1.

[0042] 2. Distribution Network CPS Attack Model

[0043] The distribution network CPS attack model takes maximizing load loss and minimizing attack cost as its objective function, as expressed in Equation 1.

[0044]

[0045] In the formula, Ω N For the set of system nodes; Ω L,C The set of distribution network lines reachable from the first-end switch network; For load weighting, Let be the unit price of the load at node j. The unit price and weight are determined by the load type, which is mainly divided into six composite types: government units, education, hospitals, commerce, industry, and residents. Given limited attack resources, attackers will target the first-level load as their desired attack target. ζ1 is the load shedding amount at node j; a is the weighting coefficient; ij Indicate whether the switch at the beginning of line (i, i) is under network attack. If it is under network attack, then a ij =1, otherwise it is 0; C cyb Cost of cyberattacks.

[0046] Intelligent electronic devices (IEDs) are an important component of modern distribution network automation systems. Among them, the feeder terminal unit (FTU) is the most basic and widely used field terminal equipment in distribution network automation. Essentially, it is a specific application of the remote terminal unit (RTU) in the field of distribution network feeder monitoring, and is therefore often referred to as an FTU or feeder RTU.

[0047] FTUs (Field Transmission Units) are typically installed directly on pole-mounted switches, ring main units, and switching stations along distribution lines. They monitor the real-time operating status of feeder sectionalizing switches or tie switches and execute remote control commands from the control center to perform remote opening and closing operations. The data collected by the FTUs is the foundation for their functions of feeder fault location, isolation, and recovery. Distribution substations serve as a crucial intermediate layer between numerous field FTUs and the distribution automation master station system. They are usually located in important substations, switching stations, or regional control centers. The main function of a distribution substation is to collect real-time data uploaded by multiple FTUs within its jurisdiction, perform necessary data processing, filtering, and compression, and then send it to the master station system. Simultaneously, it also receives and forwards control commands issued by the master station to each FTU. Because the Supervisory Control and Data Acquisition (SCADA) system is located in a highly secure control center with robust physical and network protection, direct attacks are extremely difficult. Distribution substations, due to their large number, wide distribution, relatively weak physical and network security protection, control over areas, and ability to serve as attack springboards, become a more realistic and frequently chosen primary entry point for malicious attackers. Therefore, this section assumes that a malicious attacker uses a power distribution station as the entry point and causes a specific circuit breaker to trip by injecting false data.

[0048] In power distribution networks, not all switching equipment is equipped with intelligent electronic devices (IEDs). Except for a few highly developed urban power distribution networks, IEDs are typically only installed in important equipment and critical nodes. To closely approximate real-world power grid operation, this invention only assumes that some critical switches are network-reachable, meaning they can be remotely controlled via distribution substations. A power distribution network state model based on network attacks can be established as follows:

[0049]

[0050] In the formula: a i Let a represent the network attack point. If the switch at node i is subjected to a network attack, then a i =1, otherwise it is 0; Indicate z i This indicates the actual open / closed state of the switch. If zi =1, then the switch at node i is closed; otherwise, it is 0; R cyb Resources are consumed in an attack on a single node; Resources that can be obtained through cyberattacks; Ω V For a set of nodes; Ω V,C ∈Ω V Ω represents the set of nodes reachable by network communication. V,NC ∈Ω V Ω represents the set of nodes that are unreachable in network communication. S Let it be the set of edges;

[0051] Equation 2-3 represents the actual open / closed state of the switch z. i Equation 4 represents the line power supply constraint; Equation 5 represents the network attack resource constraint.

[0052] After being attacked, the cyber-physical system of the distribution network should meet the equipment operation constraints and line power flow constraints shown in Equations 6-18.

[0053]

[0054] V1≤V sub (Equation 17);

[0055]

[0056] In the formula: P ij For the power flow of line ij; ΔP j L , These are the active and reactive load shedding quantities, respectively; ΔP j L The load at node j; β is the power factor at node j; j The ratio between reactive power and actual power; Ω V,L The set of nodes with load; δ(j) represents reactive load loss; δ(j) and π(j) represent the sets of child and parent nodes of node j, respectively. For reactive power compensation at node j; V j R is the node voltage; ij X ij These are the line resistance and reactance, respectively. V represents the maximum capacity of line ij; sub This refers to the low-voltage side voltage of the substation; V max V min These are the upper and lower limits of the voltage, respectively.

[0057] Equation 6 ensures that the number of closed circuits does not exceed the number of non-source buses; Equation 7 ensures that the load shedding amount does not exceed the existing load; based on the assumption that the power factor of critical load (CL) and interruptible load (IL) is always constant, the ratio between the reactive power and active power of the load can be expressed as Equation 8; reactive power can be replaced by active power, as shown in Equations 9 and 10; Equations 11 and 12 are the relevant power and reactive power balance constraints, respectively; the reactive power of parallel reactive power compensation equipment can be linearized as Equation 13 because the fluctuation range is small; based on the distribution network linearization model, the correlation between line voltage drop and line status can be established through Equation 14, if l ij If l = 1, then the inequality constraint is simplified to an equality constraint. jj =0, then the voltage drop constraint is relaxed using the Big M method; Equations 15 and 16 are line power flow constraints. If one end of the line is open, then l ij =0, ensuring that the power flow through the line ij is 0. If the switches at both ends are closed normally, it is assumed that the reactive power limit is half of the line limit; Node 1 is the substation outgoing circuit breaker, and its voltage is given by Equation 17; the voltage limit constraint is given by Equation 18.

[0058] 3. Dispatch Model After CPS Attack on Distribution Network

[0059] In the event of an emergency such as a switch tripping and resulting load loss during distribution network operation, the distribution network dispatcher will quickly take measures to ensure power supply. The dispatcher's primary task is to isolate the faulty area to prevent further escalation. Since distribution networks are generally closed-loop structures operating in an open-loop manner, isolation can be achieved simply by disconnecting all sub-node switches on the tripped line. After isolating the fault, the dispatcher will quickly close the tie switches to restore power to critical loads as soon as possible. Furthermore, the dispatcher will utilize dispatch resources as efficiently as possible, ensuring a continuous and stable power supply to as many critical users as possible with minimal resource investment.

[0060] To achieve this goal, this invention establishes a rescheduling model after a distribution network attack, the objective function of which can be written as:

[0061]

[0062] In the formula: ξ1 represents the unit DG and the active power output cost, respectively, and ξ2 is the weighting coefficient.

[0063] The objective function aims to minimize the costs of load shedding, distributed generation (DG) output, and energy storage device (BESS) output. By incorporating these three components—load shedding loss cost, DG output cost, and BESS output cost—into the objective function and solving this optimization problem under strict constraints (node ​​voltage constraints, line power constraints), a scientific basis for dispatchers' decision-making can be provided. This model helps dispatchers quickly and accurately formulate optimal rescheduling schemes in complex distribution network environments following cyberattacks, minimizing the adverse consequences of attacks on the normal operation of the distribution network, ensuring the reliability and stability of power supply, reducing economic losses and impact on users, and ensuring the distribution network can return to normal operation as quickly as possible.

[0064] The initial switch states in the distribution network rescheduling are the same as those solved by the attack model. Simultaneously, the dispatcher will isolate the fault by opening the switch and close the tie switch that can supply power to the de-energized load. Therefore, the switch state variables can be written as:

[0065]

[0066] In the formula: (·) * The solution result Ω for the CPS attack model of the distribution network V,I This is a set of interconnecting switches.

[0067] Equation 20 indicates that all switch states are the same as after the attack; to isolate the fault, the dispatcher disconnects the switches at both ends of the line, and the switch constraints are shown in Equation 21; Equation 22 indicates that the dispatcher will ensure power supply to users by opening and closing tie switches. The safe operation constraints of the distribution network rescheduling are the same as those under the attack model, as shown in Equations 6-18. The difference is that the distribution network dispatcher can issue dispatch instructions to distributed power generation stations and battery energy storage systems (BESS) to increase output and ensure power supply. Therefore, the optimal dispatch of DG and BESS can be achieved through the constraints shown in Equations 23-28. Note: The DG system of this invention mainly includes fuel-based DG and photovoltaic-based DG, so the reactive power output of DG and BESS is represented as zero, and the active power output of reactive power compensation equipment is set to 0.

[0068]

[0069] In the formula: P j DG Power is supplied to node j as a distributed generation (DG); P j DGmax Indicates the upper limit of DG output; Ω V,G Ω is the set of nodes with DG. V,E A set of nodes; Let the initial remaining energy of BESS at node j be _____. For BESS remaining capacity; P h Bdch Let BESS be the discharge power at node j; This is the net discharge limit; The remaining capacity after BESS discharges for time Δt; since this section focuses on analyzing the unit time segment after the attack is completed, Δt is taken as 1 hour. These are the maximum and minimum values ​​of the remaining State of Charge (SOC), respectively.

[0070] Equation 23 represents the active power output constraint of the DG; Equation 24 limits the initial battery capacity. Before the network GJ is implemented, all BESSs will be pre-charged to 100%; since the latest lithium batteries have high charge-discharge efficiency, reaching 92%-96%, this invention assumes the efficiency of the BESS to be 100% to simplify the model, and the charge-discharge limit can be expressed by Equation 25. Equation 26 represents the energy change of the BESS per unit time; Equation 27 limits the SOC limit of the BESS; Equation 28 represents the power balance constraint for calculating the output of the DG and BESS.

[0071] 4. KKT-based two-level model solution method

[0072] Bilevel optimization models are mainly used to handle decision problems involving hierarchical and layered relationships. Their models are generally as follows:

[0073] As shown in Equations 29 and 30:

[0074]

[0075] In the formula: x and y are decision variables for upper-level optimization; in the lower-level model, x is a fixed parameter, and y is a decision variable; G i (·), H j (·), g k (·) and h l (·) are all different functions; n i Indicates the number of constraints.

[0076] This invention addresses the offensive and defensive characteristics of cyber-physical systems in power distribution networks by proposing a two-layer optimization framework, as shown in the appendix. Figure 3 As shown, the model follows a sequential logic of attack first, defense response: the upper-level model simulates the attacker's decision-making process to minimize the load loss in the distribution network while minimizing the attack cost; the lower-level model describes how the dispatcher, after being attacked, minimizes power outage losses by adjusting the operation of distributed power sources, energy storage systems, and tie switches. This invention's proposed two-layer optimization model, through the game between the attacker and defender, provides an optimal solution, offering important reference for improving the security resilience of distribution networks.

[0077] The proposed two-layer optimization model for CPS attack on distribution networks has the following problems in solving:

[0078] 1) Both the upper and lower layers contain 0-1 decision variables, making them mixed integer optimization problems that are difficult to solve directly;

[0079] 2) There are nonlinear constraints on the multiplication of binary variables;

[0080] 3) Actual distribution networks contain hundreds of nodes, making it difficult to solve efficiently using traditional methods.

[0081] To address the aforementioned issues, this invention, based on KKT conditions, transforms the original model into a Mixed Integer Linear Program (MILP) problem, which is then solved using an existing solver.

[0082] First, in the above model, Equation 4 represents the nonlinear constraint of multiplying two binary variables. To linearize it, an auxiliary variable β is introduced. ij Let β ij =z i ·z j Equation 4 is rewritten as Equation 31, and β is constrained by Equations 32-35. ij .

[0083]

[0084] After the above processing, the nonlinear constraints are transformed into linear constraints. The decision variables of the upper-level model... Once determined, the distribution network topology of the lower-level model is also uniquely determined.

[0085] Because the upper and lower layers are coupled in the two-layer model, the decisions of the upper layer affect the lower layer, and the optimization results of the lower layer are fed back to the upper layer. At the same time, the relationships between variables are intricate. Using existing intelligent algorithms to solve this two-layer optimization problem not only consumes a lot of memory but also has a slow solution speed.

[0086] The KKT conditions are first-order optimality conditions for the lower-level optimization problem. When the lower-level problem is a convex optimization, if point (x... * ,y * If a point is a local optimum of the lower-level problem, then there exists a corresponding Lagrange multiplier such that the point satisfies the KKT conditions. Since the decisions of the upper and lower levels in a bilevel optimization problem are interconnected, the KKT conditions provide a mathematical description of this connection. By introducing the KKT conditions, the optimality conditions of the lower-level optimization problem can be explicitly incorporated into the entire bilevel optimization model, thereby transforming the originally difficult-to-solve bilevel structure into a single-level optimization problem with specific constraints, and thus enabling a unified solution to the entire problem.

[0087] Taking the model shown in Equation 30 as an example, it can be converted into Lagrange function form:

[0088]

[0089] In the formula: L(x,{μ k},{λ l}) is about x, {μ k},{λ l The Lagrangian function of}; μ k , λ l g k (x)≤0 and h l The Lagrange multiplier corresponding to (x) = 0; {μ k},{λ l} are respectively μ k , λ l A set of.

[0090] Due to g k (x)≤0, h l (x) = 0, μ k ≥0 and λ l ≥0, therefore maxL(x,{μ k},{y l})=f(x). Therefore, minf(x) can be transformed into min maxL(x,μ,λ), and the necessary condition for minf(x) to obtain the optimal solution is:

[0091]

[0092] Equation 37 is the KKT condition for model (Equation 30). By combining Equations 29 and 37, the original bi-level programming model can be converted into a single-level sublinear optimization model for solution.

[0093] However, due to the nonlinearity of the bi-level optimization model proposed in this invention, and the presence of 0-1 decision variables and numerous nonlinear constraints in the lower-level model, traditional solution methods are difficult to apply directly. Therefore, this invention utilizes the KKT coupled Fortune-Amat-McCarl method to linearize and relax complementary constraints in equations 6-18 and 23-28. The core idea of ​​this method is to introduce binary variables (0-1 variables) and a "big M" constant to transform the bi-level model into a single-level model, converting non-convex or nonlinear relationships into linear constraints. Finally, the gurobi solver is used to solve the bi-level model.

[0094] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for optimizing network attacks on cyber-physical systems of power distribution networks, characterized in that, Includes the following steps: S1. Establish an upper-layer attack model, which is used to simulate the attacker's decision-making under the constraint of limited attack resources with the goal of causing the maximum load loss; S2. Establish a lower-level rescheduling model, which is used to simulate the response decision of the distribution network dispatcher after being attacked, with the goal of minimizing load shedding losses and dispatching costs. S3. Construct a two-layer optimization model that combines the upper-layer attack model with the lower-layer rescheduling model; S4. Solve the aforementioned attack and defense dual-layer optimization model to determine the vulnerable links of the distribution network and the optimal rescheduling strategy; The dual-layer offensive and defensive optimization model includes: Distribution network CPS attack model: The distribution network CPS attack model takes maximizing load loss and minimizing attack cost as its objective function. ; In the formula, For the system node set; The set of distribution network lines reachable from the first-end switch network; For load weighting, For nodes The unit price of the load is determined by the load type, which is mainly divided into six types: government units, education, hospitals, commerce, industry, and residential. Given limited attack resources, attackers will target the first-level load as their desired attack target. For nodes Shear load; These are the weighting coefficients; Indicates the line ( Is the upper-end switch under network attack? If so, then... =1, otherwise it is 0; Cost of cyberattacks; Distribution network CPS attack rescheduling model: The objective function of the distribution network attack and rescheduling model can be written as: ; In the formula: , These are the unit DG and active power output costs, respectively. These are the weighting coefficients.

2. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 1, characterized in that, The method further includes: before establishing the upper-layer attack model and the lower-layer rescheduling model, constructing a distribution network topology model based on graph theory, abstracting the power equipment in the distribution network as nodes, and the lines as edges.

3. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 1, characterized in that, The upper-layer attack model defines the attacker's objective function as maximizing the difference between the load loss caused by the attack and the attack cost, and the attack decision is constrained by the total amount of attack resources.

4. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 1, characterized in that, The objective function of the lower-level rescheduling model includes load shedding loss cost, distributed power source scheduling cost, and energy storage system scheduling cost.

5. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 4, characterized in that, The response decisions of the lower-level rescheduling model include fault isolation, network reconfiguration, and coordinated power output scheduling of distributed power sources and energy storage systems.

6. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 1, characterized in that, The steps for solving the attack-defense two-layer optimization model include: using the Kuhn-Tak condition to transform the optimality condition of the lower-layer rescheduling model into a set of constraints, thereby converting the attack-defense two-layer optimization model into a single-layer optimization model.

7. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 6, characterized in that, The single-layer optimization model contains a nonlinear term generated by multiplying two binary variables. The nonlinear term is linearized by introducing auxiliary variables and additional constraints.

8. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 6, characterized in that, The constraints obtained by transforming the Kuhn-Tak conditions include complementary relaxation constraints, which are then linearized using the Big M method.

9. The method for optimizing network attacks on a distribution network cyber-physical system according to claim 8, characterized in that, The single-layer optimization model is ultimately transformed into a mixed-integer linear programming problem and solved using a standard solver.

10. A system based on the method of claim 1, characterized in that, include: The upper-layer attack model establishment module is used to establish an upper-layer attack model, which is used to simulate the attacker's decision-making under the constraint of limited attack resources with the goal of causing maximum load loss; The lower-level rescheduling model establishment module is used to establish a lower-level rescheduling model, which is used to simulate the response decision of the distribution network dispatcher after being attacked, with the goal of minimizing load shedding losses and dispatching costs. The model solving module is used to construct and solve the attack and defense two-layer optimization model consisting of the upper-layer attack model and the lower-layer rescheduling model. It transforms the two-layer optimization model into a single-layer optimization model by using the Kuhn-Tak condition, and then transforms the single-layer optimization model into a mixed integer linear programming problem by using a linearization method, and finally determines the vulnerable links of the distribution network and the optimal rescheduling strategy.

Citation Information

Patent Citations

  • Optimization method of electric vehicle driving path based on network reconstruction

    CN113036790A

  • Power transmission system key plant station identification method considering network-physical cross-domain attack

    CN120281551A