Automatic voltage regulator zero dynamic detection method based on neural network prediction
Through a comprehensive detection system based on state-driven neural network prediction, using the Luenberger state observer and deep learning model, the problem of early detection of zero-dynamic attacks in the AVR system was solved, and attack identification with high sensitivity and low false alarm rate was achieved, thereby improving the safe operation level of the power grid.
Patent Information
- Application Number
- CN202510874247.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-06-27
AI Technical Summary
Existing technologies lack effective early detection methods and find it difficult to identify hidden zero-dynamic attacks in AVR systems. Traditional detection methods have limited effectiveness against zero-dynamic attacks, and there is a lack of a comprehensive detection system that combines state estimation technology with advanced data-driven prediction methods.
A comprehensive detection system based on state-driven neural network prediction, using a Luenberger state observer and a deep learning prediction model, enables early detection of AVR zero-dynamic attacks. This method includes establishing a mathematical model of the AVR system, partitioning the state, designing a Luenberger state observer, constructing and training a state-driven neural network predictor, and then online prediction and residual generation, using the residual to determine zero-dynamic attacks.
It achieves early warning of zero-dynamic attacks with high detection sensitivity, low false alarm rate, and strong adaptability. It can identify attacks before the system output deviates from normal values, significantly improving the security and stability of the power grid.
Smart Images

Figure CN120722722A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of power grid security, and in particular relates to a zero dynamic detection method for an automatic voltage regulator based on neural network prediction. Background Art
[0002] With rapid economic development and the continuous improvement of people's living standards, electric energy, as one of the key infrastructures of modern society, plays a crucial role in the sustainable development of the entire socio-economic system. As a key carrier of electric energy supply, the power grid not only ensures the stable transmission and distribution of electricity but also directly impacts the normal operation of industrial production, communications, transportation, and daily life. To ensure grid voltage stability and power quality, automatic voltage regulators (AVRs) are widely used in modern power grid systems. AVR systems adjust the generator's excitation current in real time to maintain the generator output voltage fluctuating around a preset target value, thereby protecting grid equipment from voltage fluctuations and improving power transmission efficiency. A typical AVR control system consists of subsystems such as the amplifier, exciter, generator, and sensor. Each subsystem is modeled using a first-order transfer function defined by gain and time constant, thereby constructing the overall mathematical model of the system. To improve AVR control performance, a proportional-integral (PI) controller is often introduced into the control loop, utilizing the principle of unit negative feedback to form a closed-loop control structure, ensuring system stability and rapid response. The principle of unit negative feedback involves feeding the system's output directly back to the input for comparison, thereby automatically correcting any errors between the output and input. With the integration of advanced information technology into power systems, AVR systems are gradually evolving from traditional analog control to digital and networked control.
[0003] The widespread use of Supervisory Control and Data Acquisition (SCADA) systems enables AVRs to remotely obtain real-time grid operating status data and promptly adjust system control strategies, improving the flexibility and efficiency of grid operations. However, this deep integration also introduces new cybersecurity risks to the grid.
[0004] In recent years, zero-dynamic attacks have attracted widespread attention as an advanced network attack method. These attacks are a special form of false data injection attacks that primarily exploit the inherent structural characteristics of non-minimum phase control systems. Non-minimum phase systems exhibit unstable zero-dynamics, which allows attackers to exploit system structural parameters to design specific attack signals. After the attack signal is injected into the control loop, the system's internal state gradually deviates from its normal trajectory or even diverges, while the external behavior remains essentially the same as before the attack. This attack is highly concealed, making it difficult for traditional monitoring technologies to detect and respond promptly, posing a significant risk to the safe operation of power grids. Research on zero-dynamic attack detection technology for AVR systems has become a significant current topic. To better understand the technical solutions of the present invention, the following is a review of related technologies in this field. In the field of state estimation and control, pole placement is a widely used classic control system design method. Pole placement, by appropriately selecting the feedback matrix or observer gain matrix, positions the eigenvalues (poles) of the closed-loop or observer system in the desired locations, thereby ensuring system stability and dynamic performance. Especially when designing state observers (such as the Luenberger observer), the pole placement method can ensure that the estimated state converges quickly to the true state, ensuring the accuracy of subsequent control or detection strategies.
[0005] The related patent technologies closest to the present invention include: Chinese invention patent with patent publication number CN119628884A discloses an enhanced zero-dynamic attack method for automatic voltage regulators. This patent designs a more destructive zero-dynamic attack signal for the AVR system, analyzes the key factors of the attack, and amplifies the attack effect by adjusting the attack signal. However, this patent only focuses on the attack technology itself and does not involve effective detection and defense methods for zero-dynamic attacks. Chinese invention patent with patent publication number CN118413364A discloses a zero-dynamic attack defense method for sampled networked control systems. Based on the characteristics of the sampling network, this patent designs a defense strategy to resist zero-dynamic attacks, with special attention to the attack problem caused by system delay, but this patent does not consider the application of state-driven neural networks in state prediction and attack detection. Chinese invention patent publication number CN119675964A discloses a defense method against zero-dynamic attacks on wind power generation systems. This method primarily transforms unstable zero points into stable zero points by dynamically adjusting electronically adjustable passive components. Although this patent addresses the issue of zero-dynamic in power systems, its applicability is limited to wind power systems and does not address automatic voltage regulators. Chinese invention patent publication number CN111181428A discloses a zero-dynamic DC output voltage control method and system for a current source converter. This patent achieves zero-dynamic regulation of DC voltage through a feedforward control approach, but primarily focuses on the control strategy of the DC voltage converter, significantly different from the voltage regulation and attack detection technology involved in the present invention.
[0006] The shortcomings of the above-mentioned existing technologies are as follows: First, most existing technologies focus on attack signal design or defense control strategies themselves, and lack early detection solutions for attacks; Second, traditional detection methods usually rely on direct abnormality judgment of output signals, and have limited effectiveness against advanced attack methods such as zero-dynamic attacks that hide output anomalies; Third, there is a lack of a comprehensive detection system that effectively combines state estimation technology with advanced data-driven prediction methods, making it difficult to effectively detect hidden zero-dynamic attacks. Summary of the Invention
[0007] To address the above issues, the present invention proposes a novel AVR zero-dynamic attack detection method, which aims to provide a comprehensive detection system based on state-driven neural network prediction. This system utilizes state estimation technology and deep learning prediction models to achieve early detection and effective defense against AVR zero-dynamic attacks, thereby improving the safe operation of power grids. The present invention's neural network prediction-based zero-dynamic detection method for automatic voltage regulators (AVRs) includes the following steps:
[0008] S1: AVR system mathematical model establishment and state division, including the following steps:
[0009] S1-1: Collect known physical parameters of the amplifier, exciter, generator, and sensor in the automatic voltage regulator (AVR), including gain K. a , K e , K g , K s With time constant τ a , τ e , τ g , τ s ;
[0010] S1-2: Establishing the first-order transfer function of each subsystem based on the gain and time constant described in step S1-1, and connecting the transfer functions in series and in parallel to form the open-loop transfer function of the AVR system;
[0011] S1-3: A proportional-integral (PI) controller is placed before the open-loop transfer function. The proportional gain and integral gain of the PI controller are given by the controller adjustment algorithm to obtain a closed-loop transfer function.
[0012] S1-4: Construct a fifth-order linear time-invariant state-space model matrix based on the closed-loop transfer function. Apply the Byrnes-Isidori normal form transformation to decompose the original state vector into an internal state vector and an external state vector, and obtain the transformed system matrix.
[0013] S2: Luenberger state observer design and online state estimation, including the following steps:
[0014] S2-1: Construct a Luenberger state observer structure based on the system matrix obtained in step S1-4;
[0015] S2-2: Calculate the observer gain matrix using the pole placement method, so that all observer eigenvalues are placed inside the unit circle and the error between the actual system state and the observer estimate converges. The gain matrix is stored in the controller;
[0016] S2-3: During the system operation, the observer state update equation is driven to output the estimated internal state and the estimated external state, and the internal state and external state Cache to the ring buffer for step S3 and step S4 to call;
[0017] S3: Construction and training of a state-driven neural network predictor, including the following steps:
[0018] S3-1: Offline stage: Collect historical data sets, where a single sample includes: a historical input sequence of the length of the time window; a historical output sequence of the length of the time window; the corresponding estimated internal state; the corresponding estimated external state; the above data are spliced into a network input vector; and the corresponding label is the actual output at the next moment.
[0019] S3-2: Construct a feedforward neural network with learnable parameters, which takes the network input vector as input and outputs the predicted value;
[0020] S3-3: Define the total loss function and use the Adam optimizer to train the network parameters until convergence to obtain the trained predictor.
[0021] S3-4: Deploy the trained weights together with the network structure as an online detection module;
[0022] S4: Online prediction and residual generation, including the following steps:
[0023] S4-1: In each sampling period, read the internal state and external state output by step S2-3 and the historical input sequence and historical output sequence cached in step S3-1 to form a network input vector;
[0024] S4-2: Input the network input vector to the deployed predictor to obtain the predicted output for the next sampling period;
[0025] S4-3: Using the mirror model with the same parameters as the AVR system and no attack, and driven by the real-time input u(t), calculate the mirror output;
[0026] S4-4: Calculate the residual and store it in the residual sequence;
[0027] S5: Zero dynamic attack determination, including the following steps:
[0028] S5-1: Set a threshold ε for the residual sequence. The threshold can be set statically or updated online adaptively based on system noise.
[0029] S5-2: In continuous sampling periods, if the residual sequence is greater than the set threshold, a zero dynamic attack alarm signal is output and the abnormal timestamp is recorded at the same time.
[0030] As a preferred technical solution of the present invention, the calculation of the open-loop transfer function in step S1-2 specifically includes the following steps:
[0031] The amplifier transfer function is expressed as:
[0032]
[0033] The exciter transfer function is expressed as:
[0034]
[0035] The transfer function between the generator terminal voltage and the field voltage is expressed as:
[0036]
[0037] The sensor transfer function is expressed as:
[0038]
[0039] The open-loop transfer function of the system can be derived from formulas (1), (2), (3), and (4):
[0040]
[0041] Among them, K a represents the amplifier gain, τ a represents the amplifier time constant, K e represents the exciter gain, τ e Indicates the exciter time constant, K g represents the gain between the generator terminal voltage and the field voltage, τ g Represents the time constant between the generator terminal voltage and the field voltage, K s represents the sensor gain, τ s Represents the sensor time constant.
[0042] As a preferred technical solution of the present invention, the calculation of the closed-loop transfer function in step S1-3 specifically includes the following steps:
[0043] Set the transfer function of the proportional-integral PI controller to
[0044] Among them, K p is the proportional coefficient of the PI controller, K i is the integral coefficient of the PI controller;
[0045] Connect G1(s) in series with the open-loop transfer function G0(s) shown in formula (5), where G1(s) is the transfer function of the PI controller and G0(s) is the open-loop transfer function of the AVR control system;
[0046] According to the principle of unit negative feedback, the closed-loop transfer function is calculated as follows:
[0047]
[0048] Where K0 = K a K e K g K s K p , K1=K a K e K g K s K i , τ0=τ a τ eτ g τ s , τ1=τ a τ e +τ a τ g +τ a τ s +τ e τ g +τ e τ s +τ g τ s , τ2=τ a τ e τ g +τ a τ e τ s +τ a τ g τ s +τ e τ g τ s , τ3=τ a +τ e +τ g +τ s ,τ4=1+K a K e K g K s K p ,τ5=K a K e K g K s K i , the closed-loop transfer function shown in formula (6) can be used for subsequent system performance analysis and state space model construction in step S1-4.
[0049] As a preferred technical solution of the present invention, the calculation of the system matrix in step S1-4 specifically includes the following steps:
[0050] Define the state vector as The state space calculation formula is:
[0051]
[0052] Among them, V e is the voltage error of the system, u(t) is the input voltage error of the system, y(t) is the output terminal voltage of the closed-loop system, and x(t) is the state vector of the system. is the change of the state vector of the closed-loop system, A is the state matrix of the closed-loop system, B is the input matrix of the closed-loop system, and C is the output matrix of the closed-loop system;
[0053] Perform Euclidean polynomial division on the denominator polynomial Den(s) and the numerator polynomial Num(s) of the closed-loop transfer function to obtain the quotient Quo(s) and remainder Rem(s). The specific calculation formula is:
[0054]
[0055] Where, Den(s)=Quo(s)Num(s)+Rem(s);
[0056] According to the degree relationship between Quo(s) and Rem(s), the coordinate transformation matrix T is constructed to decompose the original state vector x(t) into the internal state vector and the external state vector δ(t), the specific calculation formula is:
[0057]
[0058] Among them, δ(t)=[y(t) y(t+1) y(t+2) y(t+3)] T ,λ T δ(t)=y(t)+b m N o φ(t)-b m u(t), M c =[0 0 0 1] T , N c =[1 0 0 0]; φ(t+1) is the change of the internal state vector of the system; δ(t+1) is the change of the external state vector of the system; G o , M o , N o is the minimum implementation of the feedback path; b m is the coefficient in Quo(s); T is the solution of formula (9);
[0059] The coordinate transformation matrix T is used to calculate the transformed system matrix and λ, completing the Byrnes–Isidori normal form transformation.
[0060] As a technical preferred solution of the present invention, the AVR system mathematical model also includes a zero dynamic attack modeling, and the system model under zero dynamic attack is:
[0061]
[0062] After receiving the attack, the system model changes to:
[0063]
[0064] Where a(t) represents the attack data added to u(t) through logical operations, and z(t) is the state vector z(t+1)=G calculated by the attacker using the system matrix. o z(t), a(t) = N o z(t).
[0065] As a technical preferred solution of the present invention, the Luenberger state observer structure in step S2 is: the input signal u(t) sent by the controller acts on the system and the observer at the same time, and the system output y(t) is consistent with the output y generated by the observer. L (t) and compare them to get the output error e y (t), the error is weighted by the gain matrix L and fed back to the observer to correct the state estimate, so that the observer gradually approaches the true state trajectory during iteration. The specific calculation formula is:
[0066]
[0067] in, are the estimated values of internal state and external state respectively, L φ ,L δ is the observer gain matrix, is the current output error, which is used for observation correction.
[0068] As a technical optimization solution of the present invention, the system output y(t) in step S2 is a linear combination of δ(t), which can be obtained by constructing the matrix N c Ensure the observability of the system and design appropriate L based on this φ ,L δ , so that the state estimation error converges. The specific error between the actual state of the system and the observer's estimated value is defined as:
[0069]
[0070] According to the system state equation and the observer state update formula, the calculation formula of the dynamic system where the error evolves over time is derived as follows:
[0071] e δ (t+1)=(G c +M c λ T -L δ N c )e δ (t)+M c b m N o e φ (t), (15)
[0072] e φ(t+1)=(G φ -L φ N c )e φ (t)+M o N c e δ (t). (16)
[0073] Among them, G φ is a system matrix in the state estimation error dynamic equation, the gain matrix L φ ,L δ The pole configuration method is used to select, while ensuring
[0074] As a preferred technical solution of the present invention, the input of the state-driven neural network predictor in step S3 is composed of the following four types of variables: the estimated internal state obtained by the observer The estimated external state obtained by the observer The historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are mapped into input vectors by the neural network constructor by concatenating the above features:
[0075]
[0076] Among them, f θ (·) represents a feedforward neural network structure with learnable parameters θ, and the output is the predicted value of the future system output
[0077] As a preferred technical solution of the present invention, the calculation formula of the total loss function in step S3-3 is:
[0078]
[0079] in, represents the change in the predicted output, represents the change of the internal state estimate, γ is the state change scaling factor, and α is the weight of the consistency loss term.
[0080] As a preferred technical solution of the present invention, steps S4 and S5 are implemented through the following online detection architecture:
[0081] The input signal u(t) output by the controller is input into both the real system and the mirror system. The mirror system is used as an unattacked reference model to generate a normal output y n (t);
[0082] The observer estimates the internal state of the system in real time based on u(t) and y(t) With external state And use the output error e y (t) through the gain L φ ,L δ Revised state estimates;
[0083] Neural network to estimate the internal state With external state And the historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are input to predict the next moment output of the system
[0084] The predicted output is the same as the mirror system output y n (t) Compare to get the residual And send it to the residual detection module for judgment;
[0085] Predict output by observing to determine whether the system is under attack based on the changing trend of the
[0086] Compared with the related prior art, the beneficial effects of the present invention are:
[0087] Early warning and earlier detection. Relying on the deep coupling of the Luenberger state observer and the state-driven neural network predictor, the present invention can identify zero-dynamic attacks in advance by predicting residuals and internal state change trends before the system output has significantly deviated from the normal value, thereby achieving early warning of covert attacks.
[0088] The detection sensitivity is high and the false alarm rate is low. The state change consistency term is introduced in the loss function, so that the neural network not only pays attention to the deviation of the output value, but also remains sensitive to the internal state increment, effectively distinguishing between the random disturbance of the equipment operation itself and the systematic drift caused by the attack, significantly reducing false alarms and missed alarms.
[0089] The algorithm has strong versatility and good adaptability. The observer design (pole configuration) and prediction model structure used in the present invention have good scalability and can be quickly reconfigured for AVR systems of different models and parameters. The threshold can be adaptively updated online to adapt to different operating conditions and noise levels.
[0090] Enhance the security and stability of the power grid. By timely detecting and alarming AVR zero-dynamic attacks, the present invention can effectively block the potential harm to the power grid caused by attackers exploiting the inherent vulnerabilities of the non-minimum phase system, providing a solid technical guarantee for the safe operation of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] Figure 1 A flowchart of a method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction provided by the present invention;
[0092] Figure 2 Provides an AVR system structure diagram of an embodiment of the present invention;
[0093] Figure 3 This is a block diagram of a closed-loop AVR control system according to an embodiment of the present invention;
[0094] Figure 4 This is a flow chart of injecting zero dynamic attack into an AVR control system according to an embodiment of the present invention;
[0095] Figure 5 1 is a structural diagram of a Luenberger observer according to an embodiment of the present invention;
[0096] Figure 6 This is a diagram of a neural network structure according to an embodiment of the present invention;
[0097] Figure 7 It is a schematic diagram of the detection method provided by the embodiment of the present invention;
[0098] Figure 8 This is a diagram showing the effect of setting upper and lower thresholds to detect zero dynamic attacks according to an embodiment of the present invention;
[0099] Figure 9 This is a diagram showing the effect of setting upper and lower thresholds for detection and strengthening zero dynamic attack according to an embodiment of the present invention;
[0100] Figure 10 This is a graph showing changes in the prediction output of the multivariate linear regression model used in the embodiment of the present invention to detect zero dynamic attacks;
[0101] Figure 11 This is a graph showing changes in the predicted output during the multivariate linear regression model detection and enhanced zero-dynamic attack according to an embodiment of the present invention;
[0102] Figure 12 This is a graph showing changes in the prediction output of a neural network predictor detecting a zero-dynamic attack according to an embodiment of the present invention;
[0103] Figure 13 This is a graph showing changes in the predicted output during detection of an enhanced zero-dynamic attack by a neural network predictor according to an embodiment of the present invention. DETAILED DESCRIPTION
[0104] The present invention is further described below with reference to the accompanying drawings. However, the present invention can be implemented in many different ways and should not be construed as limited to the embodiments shown; rather, these embodiments provide those skilled in the art with implementation methods that meet applicable legal requirements.
[0105] Example 1: Figure 1 As shown, the present invention proposes a zero dynamic detection method for an automatic voltage regulator based on neural network prediction, comprising the following steps:
[0106] S1: AVR system mathematical model establishment and state division, including the following steps:
[0107] S1-1: Collect known physical parameters of the amplifier, exciter, generator, and sensor in the automatic voltage regulator (AVR), including gain K. a , K e , K g , K s With time constant τ a , τ e , τ g , τ s ;
[0108] S1-2: Establishing the first-order transfer function of each subsystem based on the gain and time constant described in step S1-1, and connecting the transfer functions in series and in parallel to form an open-loop transfer function of the AVR system. Calculating the open-loop transfer function in step S1-2 specifically includes the following steps:
[0109] The amplifier transfer function is expressed as:
[0110]
[0111] The exciter transfer function is expressed as:
[0112]
[0113] The transfer function between the generator terminal voltage and the field voltage is expressed as:
[0114]
[0115] The sensor transfer function is expressed as:
[0116]
[0117] The open-loop transfer function of the system can be derived from formulas (1), (2), (3), and (4):
[0118]
[0119] Among them, K a represents the amplifier gain, τ a represents the amplifier time constant, K e represents the exciter gain, τ e Indicates the exciter time constant, K g represents the gain between the generator terminal voltage and the field voltage, τ g Represents the time constant between the generator terminal voltage and the field voltage, K s represents the sensor gain, τ sRepresents the sensor time constant.
[0120] S1-3: A proportional-integral (PI) controller is placed before the open-loop transfer function. The proportional gain and integral gain of the PI controller are given by a controller adjustment algorithm to obtain a closed-loop transfer function. The calculation of the closed-loop transfer function in step S1-3 specifically includes the following steps:
[0121] Set the transfer function of the proportional-integral PI controller to
[0122] Among them, K p is the proportional coefficient of the PI controller, K i is the integral coefficient of the PI controller;
[0123] Connect G1(s) in series with the open-loop transfer function G0(s) shown in formula (5), where G1(s) is the transfer function of the PI controller and G0(s) is the open-loop transfer function of the AVR control system;
[0124] According to the principle of unit negative feedback, the closed-loop transfer function is calculated as follows:
[0125]
[0126] Where K0 = K a K e K g K s K p , K1=K a K e K g K s K i , τ0=τ a τ e τ g τ s , τ1=τ a τ e +τ a τ g +τ a τ s +τ e τ g +τ e τ s +τ g τ s , τ2=τ a τ e τ g +τ a τ e τ s +τ a τ g τ s +τ eτ g τ s , τ3=τ a +τ e +τ g +τ s ,τ4=1+K a K e K g K s K p ,τ5=K a K e K g K s K i , the closed-loop transfer function shown in formula (6) can be used for subsequent system performance analysis and state space model construction in step S1-4.
[0127] S1-4: Based on the closed-loop transfer function, a fifth-order linear time-invariant state space model matrix is constructed. At the same time, the Byrnes-Isidori normal form transformation is applied to decompose the original state vector into an internal state vector and an external state vector, and the transformed system matrix is obtained. The calculation of the system matrix in step S1-4 specifically includes the following steps:
[0128] Define the state vector as The state space calculation formula is:
[0129]
[0130] Among them, V e is the voltage error of the system, u(t) is the input voltage error of the system, y(t) is the output terminal voltage of the closed-loop system, and x(t) is the state vector of the system. is the change of the state vector of the closed-loop system, A is the state matrix of the closed-loop system, B is the input matrix of the closed-loop system, and C is the output matrix of the closed-loop system;
[0131] Perform Euclidean polynomial division on the denominator polynomial Den(s) and the numerator polynomial Num(s) of the closed-loop transfer function to obtain the quotient Quo(s) and remainder Rem(s). The specific calculation formula is:
[0132]
[0133] Where, Den(s)=Quo(s)Num(s)+Rem(s);
[0134] According to the degree relationship between Quo(s) and Rem(s), the coordinate transformation matrix T is constructed to decompose the original state vector x(t) into the internal state vector and the external state vector δ(t), the specific calculation formula is:
[0135]
[0136] Among them, δ(t)=[y(t) y(t+1) y(t+2) y(t+3)] T ,λ T δ(t)=y(t)+b m N o φ(t)-b m u(t), M c =[0 0 0 1] T , N c =[1 0 0 0]; φ(t+1) is the change of the internal state vector of the system; δ(t+1) is the change of the external state vector of the system; G o , M o , N o is the minimum implementation of the feedback path; b m is the coefficient in Quo(s); T is the solution of formula (9);
[0137] The coordinate transformation matrix T is used to calculate the transformed system matrix and λ, completing the Byrnes–Isidori normal form transformation.
[0138] The AVR system mathematical model also includes a zero dynamic attack modeling. The system model under zero dynamic attack is:
[0139]
[0140] After receiving the attack, the system model changes to:
[0141]
[0142] Where a(t) represents the attack data added to u(t) through logical operations, and z(t) is the state vector z(t+1)=G calculated by the attacker using the system matrix. o z(t), a(t) = N o z(t).
[0143] S2: Luenberger state observer design and online state estimation, including the following steps:
[0144] S2-1: Construct a Luenberger state observer structure based on the system matrix obtained in step S1-4;
[0145] S2-2: Calculate the observer gain matrix using the pole placement method, so that all observer eigenvalues are placed inside the unit circle and the error between the actual system state and the observer estimate converges. The gain matrix is stored in the controller;
[0146] S2-3: During the system operation, the observer state update equation is driven to output the estimated internal state and the estimated external state, and the internal state and external state Cache to the ring buffer for subsequent steps S3 and S4 to call;
[0147] The structure of the Luenberger state observer in step S2 is as follows: the input signal u(t) sent by the controller acts on the system and the observer at the same time, and the system output y(t) is the same as the output y generated by the observer. L (t) and compare them to get the output error e y (t), the error is weighted by the gain matrix L and fed back to the observer to correct the state estimate, so that the observer gradually approaches the true state trajectory during iteration. The specific calculation formula is:
[0148]
[0149] in, are the estimated values of internal state and external state respectively, L φ ,L δ is the observer gain matrix, is the current output error, which is used for observation correction.
[0150] In step S2, the system output y(t) is a linear combination of δ(t), which can be obtained by constructing the matrix N c Ensure the observability of the system and design appropriate L based on this φ ,L δ , so that the state estimation error converges. The specific error between the actual state of the system and the observer's estimated value is defined as:
[0151]
[0152] According to the system state equation and the observer state update formula, the calculation formula of the dynamic system where the error evolves over time is derived as follows:
[0153] e δ (t+1)=(G c +M c λ T -L δ N c )e δ (t)+M c b m N o e φ (t), (15)
[0154] e φ (t+1)=(Gφ -L φ N c )e φ (t)+M o N c e δ (t). (16)
[0155] Among them, G φ is a system matrix in the state estimation error dynamic equation, the gain matrix L φ ,L δ The pole configuration method is used to select, while ensuring
[0156] S3: Construction and training of a state-driven neural network predictor, including the following steps:
[0157] S3-1: Offline stage: Collect historical data sets, where a single sample includes: a historical input sequence of the length of the time window; a historical output sequence of the length of the time window; the corresponding estimated internal state; the corresponding estimated external state; the above data are spliced into a network input vector; and the corresponding label is the actual output at the next moment.
[0158] S3-2: Construct a feedforward neural network with learnable parameters, which takes the network input vector as input and outputs the predicted value;
[0159] S3-3: Define the total loss function and use the Adam optimizer to train the network parameters until convergence to obtain the trained predictor.
[0160] S3-4: Deploy the trained weights together with the network structure as an online detection module;
[0161] The input of the state-driven neural network predictor in step S3 consists of the following four types of variables: the estimated internal state obtained by the observer The estimated external state obtained by the observer The historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are mapped into input vectors by the neural network constructor by concatenating the above features:
[0162]
[0163] Among them, f θ (·) represents a feedforward neural network structure with learnable parameters θ, and the output is the predicted value of the future system output
[0164] The calculation formula of the total loss function in step S3-3 is:
[0165]
[0166] in, Represents the change in the predicted output; represents the change of internal state estimation; γ is the state change scaling factor; α is the weight of the consistency loss term.
[0167] S4: Online prediction and residual generation, including the following steps:
[0168] S4-1: In each sampling period, read the internal state and external state output by step S2-3 and the historical input sequence and historical output sequence cached in step S3-1 to form a network input vector;
[0169] S4-2: Input the network input vector to the deployed predictor to obtain the predicted output for the next sampling period;
[0170] S4-3: Using the mirror model with the same parameters as the AVR system and no attack, and driven by the real-time input u(t), calculate the mirror output;
[0171] S4-4: Calculate the residual and store it in the residual sequence;
[0172] S5: Zero dynamic attack determination, including the following steps:
[0173] S5-1: Set a threshold ε for the residual sequence. The threshold can be set statically or updated online adaptively based on system noise.
[0174] S5-2: In continuous sampling periods, if the residual sequence is greater than the set threshold, a zero dynamic attack alarm signal is output and the abnormal timestamp is recorded at the same time.
[0175] Steps S4 and S5 are implemented through the following online detection architecture:
[0176] The input signal u(t) output by the controller is input into both the real system and the mirror system. The mirror system is used as an unattacked reference model to generate a normal output y n (t);
[0177] The observer estimates the internal state of the system in real time based on u(t) and y(t) With external state And use the output error e y (t) through the gain L φ ,L δ Revised state estimates;
[0178] Neural network to estimate the internal state With external state And the historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are input to predict the next moment output of the system
[0179] The predicted output is the same as the mirror system output y n (t) Compare to get the residual And send it to the residual detection module for judgment;
[0180] Predict output by observing to determine whether the system is under attack based on the changing trend of the
[0181] Example 2: In order to illustrate the system model of the method of the present invention, this example introduces a detailed structural diagram of the AVR system, as shown in FIG. Figure 2 As shown, in this system, V ref Represents the reference voltage signal provided to the generator, ΔV s Indicates the terminal voltage measured at the output, and the voltage error is expressed as ΔV e The AVR system uses this voltage error to regulate the generator output. The error signal is fed to an amplifier, which adjusts the exciter. The exciter, in turn, changes the generator's field current, controlling the generator's output voltage. A voltage sensor continuously monitors the output voltage and feeds it back into the control loop to maintain the desired voltage. The system also includes a step-down transformer to convert the generator voltage to a suitable sensing level.
[0182] The AVR system model consists of four subsystems: amplifier, exciter, generator, and sensor. Each subsystem can be modeled by a first-order transfer function defined by gain and time constant, ignoring saturation and nonlinearity. The AVR system closed-loop control block diagram is shown in the figure below. Figure 3 shown.
[0183] Zero-dynamic attacks seek inherent vulnerabilities in control systems by exploiting the system's zero dynamics, which are intrinsic properties of the system's mathematical model, where its output is unaffected by specific inputs. The strategy involves constructing an attack signal a(t) that is identical to these zero dynamics, allowing the attacker to manipulate the system's behavior without triggering traditional detection mechanisms. Figure 4 As shown in Figure 2, it is assumed that the attacker can inject the attack signal a(t) into the input of the closed-loop system through the network and understand all the model knowledge of the system.
[0184] The structure of the Luenberger observer is as follows: Figure 5 As shown, the input signal u(t) from the controller acts on the system and the observer at the same time, and the system output y(t) is the same as the output y generated by the observer. L (t) and compare them to get the output error e y(t), the error is weighted by the gain matrix L and fed back to the observer to correct the state estimate, so that the observer gradually approaches the true state trajectory during iteration.
[0185] To accurately predict the future output of an automatic voltage regulator (AVR) system and indirectly reflect the dynamic trends of the system's internal state, this paper designs a state-driven neural network predictor architecture. This predictive model uses the system's historical input and output information, as well as the internal and external states estimated by an observer, as feature inputs. By learning nonlinear mapping relationships, it predicts the system's output value at future moments, providing a basis for subsequent attack detection.
[0186] Neural network structure such as Figure 6 As shown, the input consists of the following four types of variables, and the estimated internal state obtained by the observer The estimated external state obtained by the observer The historical input sequence u(tk:t), the historical output sequence y(tk:t-1), the neural network concatenates the above features into an input vector.
[0187] The principle of the detection method is as follows Figure 7 As shown, the input signal u(t) output by the controller is input into the real system and the mirror system at the same time. The mirror system is used as an unattacked reference model to generate a normal output y n (t). The observer estimates the internal state of the system in real time based on u(t) and y(t) With external state And use the output error e y (t) through the gain L φ ,L δ Corrected state estimation. The neural network estimates the internal state With external state And the historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are input to predict the next moment output of the system The predicted output is the same as the mirror system output y n (t) Compare to get the residual And send it to the residual detection module for judgment. At the same time, since the neural network introduces the internal state change consistency loss term during the training phase, the predicted output can be observed. to determine whether the system is under attack based on the changing trend of the
[0188] Example 3: In this example, we first constructed a typical AVR closed-loop control system based on the simulation parameters in Table 1, and implemented three detection schemes on this basis: traditional upper and lower threshold detection, multivariate linear regression prediction detection, and the detection method based on state-driven neural network prediction of the present invention. Then, in the MATLAB / Simulink environment, comparative simulations were performed on the two working conditions of ordinary zero dynamic attack and enhanced zero dynamic attack. The simulation parameters and detection results are shown in Table 1 and Figures 8 to 13 shown.
[0189] Table 1: AVR system simulation parameters
[0190]
[0191]
[0192] As shown in Table 1, the simulation uses an amplifier gain of 0.1 and a time constant of 10 seconds; an exciter gain of 0.4 and a time constant of 1 second; and generator and sensor gains of 1 and 0.01, respectively, both corresponding to a time constant of 1 second. This parameter combination represents the typical operating conditions of a small synchronous generator AVR commonly found in industry and accurately reflects the system's dynamic behavior.
[0193] Using the abnormal data detection method, the comparative zero dynamic attack detection method, and the trained neural network predictor to detect ordinary zero dynamic attacks and enhanced zero dynamic attacks, the abnormal data detection effect is as follows: Figure 8 and Figure 9 As shown, the comparison method is as follows Figure 10 and Figure 11 As shown, the method of the present invention has the following effects: Figure 12 and Figure 13 shown.
[0194] In the abnormal data detection method, the steady-state output μ of the system is y ≈15, the maximum steady-state perturbation observed The anomaly detection threshold is defined as sigma = μ y ±∈, the upper and lower thresholds are set to [13.5, 16.5]. Outputs less than 13.5 or greater than 16.5 trigger an abnormal alarm. The red line represents the system output, and the blue dotted lines represent the set upper and lower thresholds. Figure 8 The normal zero dynamic attack exceeded the upper threshold at 282 seconds. Figure 12 The medium-strength zero-dynamic attack exceeded the upper threshold at 162s.
[0195] In the detection method of the multivariate linear regression model, the blue line represents the internal state of the system, the green line represents the predicted output, the red line represents the actual output of the system, and the purple line represents the normal output of the mirror system. Figure 10and 11 It can be seen that although this method can reflect the changes in the internal state of the system through the predicted output after being attacked, and thus observe the change pattern of the predicted output to determine whether the system has suffered a zero-dynamic attack, the output fitting accuracy before and after the attack is not that high.
[0196] In the neural network predictor detection method, the blue line represents the internal state of the system, the green line represents the predicted output, the red line represents the actual output of the system, and the purple line represents the normal output of the mirror system. Figure 12 and Figure 13 It can be seen that compared with the detection method of the multiple linear regression model, this method can not only observe the approximate change pattern of the system's internal state through the predicted output and determine whether the system is under attack, but also the output fitting accuracy before and after the attack is higher than the detection method of the multiple linear regression model.
[0197] In this embodiment, a typical AVR closed-loop control system was first built based on the simulation parameters in Table 1 (amplifier gain 0.1, exciter gain 0.4, generator gain 1, sensor gain 0.01, and their respective time constants), and a corresponding mirror system was designed as an unattacked reference model. The online observer used the pole placement method to ensure fast and accurate estimation of internal and external states. The neural network predictor used the mean square error as the main loss and supplemented it with the state change consistency loss (weight α, scaling factor γ). The Adam optimizer (learning rate 0.001) was used for training for 3000 rounds and then solidified and deployed.
[0198] When injecting a common zero dynamic attack, the abnormal data detection method based on fixed upper and lower limits (13.5V-16.5V) can only alarm at about 282s due to output exceeding the limit; although the multivariate linear regression prediction can reflect the internal state change, its detection time point is relatively delayed due to insufficient linear fitting accuracy. In contrast, the present invention Figure 12 and Figure 13 The proposed predictor demonstrates earlier and more stable early warning: the residual difference between the predicted output and the mirrored output deviates significantly at the initial stages of an attack, enabling timely detection of both standard and enhanced zero-dynamic attacks before the system output exceeds the traditional threshold. Furthermore, the proposed predictor maintains a high fitting accuracy of less than 0.25V during both normal and attack phases, with significantly lower false positive and false negative rates than existing linear models.
[0199] In summary, the present invention not only achieves early warning of extremely concealed zero-dynamic attacks through deep coupling of state observation and neural network prediction, but also has the advantages of high precision, low false alarms, strong real-time performance and no hardware modification, providing reliable protection for the safe operation of the AVR system.
[0200] The above embodiments merely illustrate the implementation methods of the present invention. Although the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the scope of the present invention, and such modifications and improvements are all within the scope of protection of the present invention.
Claims
1. A method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction, characterized in that: The following steps are involved: S1: AVR system mathematical model establishment and state division, including the following steps: S1-1: Collect known physical parameters of the amplifier, exciter, generator, and sensor in the automatic voltage regulator (AVR), including gain K. a , K e , K g , K s With time constant τ a , τ e , τ g , τ s ; S1-2: Establishing the first-order transfer function of each subsystem based on the gain and time constant described in step S1-1, and connecting the transfer functions in series and in parallel to form the open-loop transfer function of the AVR system; S1-3: A proportional-integral (PI) controller is placed before the open-loop transfer function. The proportional gain and integral gain of the PI controller are given by the controller adjustment algorithm to obtain a closed-loop transfer function. S1-4: Construct a fifth-order linear time-invariant state-space model matrix based on the closed-loop transfer function. Apply the Byrnes-Isidori normal form transformation to decompose the original state vector into an internal state vector and an external state vector, and obtain the transformed system matrix. S2: Luenberger state observer design and online state estimation, including the following steps: S2-1: Construct a Luenberger state observer structure based on the system matrix obtained in step S1-4; S2-2: Calculate the observer gain matrix using the pole placement method, so that all observer eigenvalues are placed inside the unit circle and the error between the actual system state and the observer estimate converges. The gain matrix is stored in the controller; S2-3: During the system operation, the observer state update equation is driven to output the estimated internal state and the estimated external state, and the internal state and external state Cache to ring buffer; S3: Construction and training of a state-driven neural network predictor, including the following steps: S3-1: Offline phase: Collect historical data sets, where a single sample includes: a historical input sequence of the time window length; a historical output sequence of the time window length; the corresponding estimated internal state; the corresponding estimated external state; the above data are spliced into the network input vector; the corresponding label is the actual output at the next moment; S3-2: Construct a feedforward neural network with learnable parameters, which takes the network input vector as input and outputs the predicted value; S3-3: Define the total loss function and use the Adam optimizer to train the network parameters until convergence to obtain the trained predictor. S3-4: Deploy the trained weights together with the network structure as an online detection module; S4: Online prediction and residual generation, including the following steps: S4-1: In each sampling period, read the internal state and external state output by step S2-3 and the historical input sequence and historical output sequence cached in step S3-1 to form a network input vector; S4-2: Input the network input vector to the deployed predictor to obtain the predicted output for the next sampling period; S4-3: Using the mirror model with the same parameters as the AVR system and no attack, and driven by the real-time input u(t), calculate the mirror output; S4-4: Calculate the residual and store it in the residual sequence; S5: Zero dynamic attack determination, including the following steps: S5-1: Set a threshold ε for the residual sequence. The threshold can be set statically or updated online adaptively based on system noise. S5-2: In continuous sampling periods, if the residual sequence is greater than the set threshold, a zero dynamic attack alarm signal is output and the abnormal timestamp is recorded at the same time.
2. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The calculation of the open-loop transfer function in step S1-2 specifically includes the following steps: The amplifier transfer function is expressed as: The exciter transfer function is expressed as: The transfer function between the generator terminal voltage and the field voltage is expressed as: The sensor transfer function is expressed as: The open-loop transfer function of the system can be derived from formulas (1), (2), (3), and (4): Among them, K a represents the amplifier gain, τ a represents the amplifier time constant, K e represents the exciter gain, τ e Indicates the exciter time constant, K g represents the gain between the generator terminal voltage and the field voltage, τ g Represents the time constant between the generator terminal voltage and the field voltage, K s represents the sensor gain, τ s Represents the sensor time constant.
3. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The calculation of the closed-loop transfer function in step S1-3 specifically includes the following steps: Set the transfer function of the proportional-integral PI controller to Among them, K p is the proportional coefficient of the PI controller, K i is the integral coefficient of the PI controller; Connect G1(s) in series with the open-loop transfer function G0(s) shown in formula (5), where G1(s) is the transfer function of the PI controller and G0(s) is the open-loop transfer function of the AVR control system; According to the principle of unit negative feedback, the closed-loop transfer function is calculated as follows: Among them,K0=K a K e K g K s K p ,K1=K a K e K g K s K i ,τ0=τ a t e t g t s ,τ1=τ a t e +t a t g +t a t s +t e t g +t e t s +t g t s ,τ2=τ a t e t g +t a t e t s +t a t g t s +t e t g t s ,τ3=τ a +t e +t g +t s ,τ4=1+K a K e K g K s K p ,τ5=K a K e K g K s K i 。 4. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The calculation of the system matrix in step S1-4 specifically includes the following steps: Define the state vector as The state space calculation formula is: y(t)=Cx(t), B=[K1 K0 0 0 0] T , C=[1 0 0 0 0]. Among them, V e is the voltage error of the system, u(t) is the input voltage error of the system, y(t) is the output terminal voltage of the closed-loop system, and x(t) is the state vector of the system. is the change of the state vector of the closed-loop system, A is the state matrix of the closed-loop system, B is the input matrix of the closed-loop system, and C is the output matrix of the closed-loop system; Perform Euclidean polynomial division on the denominator polynomial Den(s) and the numerator polynomial Num(s) of the closed-loop transfer function to obtain the quotient Quo(s) and remainder Rem(s). The specific calculation formula is: Where, Den(s)=Quo(s)Num(s)+Rem(s); According to the degree relationship between Quo(s) and Rem(s), the coordinate transformation matrix T is constructed to decompose the original state vector x(t) into the internal state vector φ(t) and the external state vector δ(t). The specific calculation formula is: Among them, δ(t)=[y(t) y(t+1) y(t+2) y(t+3)] T ,λ T δ(t)=y(t)+b m N o φ(t)-b m u(t), M c =[0 0 0 1] T , N c =[1 0 0 0]; φ(t+1) is the change of the internal state vector of the system; δ(t+1) is the change of the external state vector of the system; G o , M o , N o is the minimum implementation of the feedback path; b m is the coefficient in Quo(s); T is the solution of formula (9); The coordinate transformation matrix T is used to calculate the transformed system matrix and λ, completing the Byrnes–Isidori normal form transformation.
5. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The AVR system mathematical model also includes a zero dynamic attack modeling. The system model under zero dynamic attack is: After receiving the attack, the system model changes to: Where a(t) represents the attack data added to u(t) through logical operations, and z(t) is the state vector z(t+1)=G calculated by the attacker using the system matrix. o z(t), a(t) = N o z(t).
6. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The structure of the Luenberger state observer in step S2 is as follows: the input signal u(t) sent by the controller acts on the system and the observer at the same time, and the system output y(t) is the same as the output y generated by the observer. L (t) and compare them to get the output error e y (t), the error is weighted by the gain matrix L and fed back to the observer to correct the state estimate. The specific calculation formula is: in, are the estimated values of internal state and external state respectively, L φ , L δ is the observer gain matrix, is the current output error, which is used for observation correction.
7. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: In step S2, the system output y(t) is a linear combination of δ(t), which is constructed by constructing the matrix N c Ensure the observability of the system and design appropriate L based on this φ ,L δ , so that the state estimation error converges. The specific error between the actual state of the system and the observer's estimated value is defined as: According to the system state equation and the observer state update formula, the calculation formula of the dynamic system where the error evolves over time is derived as follows: e δ (t+1)=(G c +M c λ T -L δ N c )e δ (t)+M c b m N o e φ (t), (15) e φ (t+1)=(G φ -L φ N c )e φ (t)+M o N c e δ (t). (16) Among them, G φ is a system matrix in the state estimation error dynamic equation, the gain matrix L φ ,L δ The pole configuration method is used to select, while ensuring 8. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The input of the state-driven neural network predictor in step S3 consists of the following four types of variables: the estimated internal state obtained by the observer The estimated external state obtained by the observer The historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are mapped into input vectors by the neural network constructor by concatenating the above features: Among them, f θ (·) represents a feedforward neural network structure with learnable parameters θ, and the output is the predicted value of the future system output 9. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, wherein: The calculation formula of the total loss function in step S3-3 is: in, Represents the change in the predicted output; represents the change of internal state estimation; γ is the state change scaling factor; α is the weight of the consistency loss term.
10. The method for detecting zero dynamic range of an automatic voltage regulator based on neural network prediction according to claim 1, characterized in that: Steps S4 and S5 are implemented through the following online detection architecture: The input signal u(t) output by the controller is input into both the real system and the mirror system. The mirror system is used as an unattacked reference model to generate a normal output y n (t); The observer estimates the internal state of the system in real time based on u(t) and y(t) With external state And use the output error e y (t) through the gain L φ ,L δ Revised state estimates; Neural network to estimate the internal state With external state And the historical input sequence u(tk:t) and the historical output sequence y(tk:t-1) are input to predict the next moment output of the system The predicted output is the same as the mirror system output y n (t) Compare to get the residual And send it to the residual detection module for judgment; Predict output by observing to determine whether the system is under attack based on the changing trend of the
Citation Information
Patent Citations
Method for detecting, isolating and eliminating false data injection attack of micro-grid system
CN115766062A
Fuzzy network security control system triggered by adaptive memory event under false data injection attack
CN118311870A
Enhanced zero dynamic attack method for automatic voltage regulator
CN119628884A
Asynchronous processing method for resisting zero dynamic attack in non-uniform sampling control system
CN119960304A