A power terminal intelligent defense method based on digital twin
By establishing a digital twin of the power terminal and utilizing reinforcement learning and data analysis techniques, the optimal defense strategy is generated, solving the problem that existing technologies cannot cope with unknown attacks and realizing real-time monitoring and precise defense of the power terminal.
Patent Information
- Application Number
- CN202511440510.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-10-10
AI Technical Summary
Existing power terminal security measures are ineffective in dealing with unknown cyberattacks, resulting in false alarms and missed alarms.
By establishing a digital twin of the power terminal, using reinforcement learning to simulate attack chains to generate optimal defense strategies, and combining Bayesian formulas, wavelet transforms, and GARCH models to analyze operational data, a BP neural network is constructed to evaluate potential attack behaviors.
It enables real-time monitoring of power terminals and accurate identification of potential attack behaviors, generates dynamic defense strategies, and improves network security and defense efficiency.
Smart Images

Figure CN120896802B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent defense technology, and more specifically, to an intelligent defense method for power terminals based on digital twins. Background Technology
[0002] With the development of intelligent power systems, an increasing number of power terminal devices (such as smart meters, distribution switches, and relay protection devices) are connected to the power network and exchange data and control with the dispatch center through communication protocols. While intelligent power systems improve work efficiency and management levels, they also bring new cybersecurity challenges. Power terminals may be subject to various cyberattacks (such as malicious data injection and denial-of-service attacks), which can lead to equipment failure, data leakage, or even system paralysis, seriously affecting power supply and social security. Currently, most security protection measures for power terminals focus on rule-based monitoring and intrusion detection systems. These systems rely on static rules and predefined attack patterns, but cannot cope with unknown attack behaviors and suffer from false positives and false negatives. Summary of the Invention
[0003] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a smart defense method for power terminals based on digital twins to solve the problems mentioned in the background art.
[0004] To achieve the above objectives, the present invention provides the following technical solution:
[0005] A smart defense method for power terminals based on digital twins specifically includes the following steps:
[0006] S1: By collecting the operating data of the power terminal, a digital twin of the power terminal is established to ensure that the digital twin of the power terminal operates synchronously with the power terminal. Then, through reinforcement learning, an attack chain is simulated in the twin environment to generate the optimal defense strategy, and the verified strategy is dynamically distributed to the physical terminal.
[0007] S2: By comparing the real-time operating data of the power terminals within the monitoring range with the historical training data of the digital twins of the power terminals, the Bayesian formula is used to determine the operating difference information of the power terminals.
[0008] S3: Analyze the continuously changing data in the power terminal operation data through wavelet transform and GARCH model to determine the operation trend information of the power terminal;
[0009] S4: Conduct a comprehensive analysis of the operational differences and trends of the power terminals, and construct an operational evaluation model in the power terminal twin using a BP neural network to determine whether there are potential attack behaviors in the power terminal operational data.
[0010] In a preferred embodiment, (determining the operational difference information and operational trend information of the power terminals includes:
[0011] The operational differences of power terminals are represented by data probability analysis coefficients, and the operational trends of power terminals are represented by local anomaly coefficients and overall data anomaly fluctuation coefficients in the frequency domain. For data probability analysis coefficients, Let be the coefficient representing the proportion of outlier data in the i-th type of continuously changing data. This represents the coefficient for abnormal fluctuations in the overall data.
[0012] In a preferred embodiment, the logic for obtaining the data probability analysis coefficients is as follows:
[0013] The operational characteristics of power terminals within the monitoring interval are determined. These characteristics are then compared with the operational characteristics of historical training data from the power terminal twins. Historically similar operational characteristics are determined based on cosine similarity calculations. The formula for calculating cosine similarity is as follows: ;in, To measure the cosine similarity between the operating characteristics of power terminals within the monitoring interval and the operating characteristics of historical training data, let A represent the operating characteristics of power terminals within the monitoring interval. The running characteristics of the historical training data are n = 1, 2, 3, ..., N, where N is a positive integer and n is the number of the running characteristics of the historical training data.
[0014] The index of historically similar operational features in the historical training data is determined by the following formula: Where XS is the index of historically similar running features in historical training data;
[0015] Based on historical training data, the prior probability of a potential attack by a power terminal twin is determined, and this prior probability is denoted as: Furthermore, kernel density estimation is used to smooth the historical training data, and the probability of historically similar running features in the historical training data is determined. The probability of historically similar running features in the historical training data is labeled as follows: The probability of a power terminal twin engaging in potential attack behavior under historically similar operating characteristics is obtained, and this probability is denoted as: ;
[0016] The probability analysis coefficients of the data are calculated using Bayes' theorem. The formula is as follows: .
[0017] In a preferred embodiment, the logic for obtaining the local anomaly coefficients of the frequency domain data is as follows:
[0018] Data types with continuously changing characteristics are extracted from the power terminal operation data within the monitoring interval, and the time series of these continuously changing data types within the monitoring interval is obtained. Wavelet transform is then used to analyze these continuously changing data types within the monitoring interval. The wavelet transform expression for these continuously changing data types within the monitoring interval is as follows: ;in, To monitor the data of the i-th continuously changing data within the monitoring interval through wavelet transform, To monitor the i-th continuously varying data within the interval in the time domain, 'a' represents the scaling parameter of the wavelet function, and 'b' represents the translation parameter of the wavelet function. Let i be the wavelet function for the i-th type of continuously changing data, where i = 1, 2, 3, ..., I, where I is a positive integer and i is the number of the type of continuously changing data.
[0019] Determine the peak and center frequencies of continuously changing data types within the monitoring interval after wavelet transformation, and calculate the frequency shift coefficients for different types of continuously changing data. The calculation formula is as follows: ;in, For the i-th type of continuously varying data, the frequency offset coefficient is... Let be the center frequency of the i-th continuously changing data;
[0020] Set threshold values for wavelet coefficients for different continuously changing data types, and calculate the outlier data ratio coefficient using the following formula: ;in, The time period within the monitoring interval that exceeds the threshold of wavelet coefficients for different continuously changing data types;
[0021] The formula for calculating the local anomaly coefficient of frequency domain data is as follows: ;in, These are the local anomaly coefficients of the frequency domain data. Weights for different continuously changing data types.
[0022] In a preferred embodiment, the logic for obtaining the overall data anomaly fluctuation coefficient is as follows:
[0023] Based on the continuously changing data type of power terminals within the monitoring interval, the time series of continuously changing data types are used as input data for the GARCH model. The GARCH model is used to fit different types of continuously changing data within the monitoring interval, obtaining the conditional variances of different types of continuously changing data at different time points and different time lags within the monitoring interval. The conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags are uniformly labeled as: Where f = 1, 2, 3, ..., F, F is a positive integer, and f is the order of the GARCH model. When f = 0, The conditional variance at the current time point in a GARCH model for different types of continuously varying data;
[0024] Set conditional variance thresholds for different types of continuously changing data. Compare the conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags with the conditional variance thresholds. Count the number of conditional variances within the monitoring interval that exceed the conditional variance thresholds. Mark the number of conditional variances that exceed the conditional variance thresholds as: ;
[0025] The formula for calculating the overall data anomaly fluctuation coefficient is as follows: .
[0026] In a preferred embodiment, an operational evaluation model is constructed in a power terminal twin using a BP neural network, including:
[0027] By comprehensively analyzing the operational difference and trend information of power terminals, the normalized data probability analysis coefficients, frequency domain data local anomaly coefficients, and overall data anomaly fluctuation coefficients are used to construct an operational evaluation model in the power terminal twin using a BP neural network, generating operational evaluation coefficients. The calculation formula for the operational evaluation coefficients is as follows: ;in, For operational evaluation coefficients, , , These are the proportional coefficients for data probability analysis coefficients, local anomaly coefficients in frequency domain data, and overall data anomaly fluctuation coefficients, respectively. , , All are greater than 0.
[0028] In a preferred embodiment, determining whether the power terminal's operating data contains potential attack behavior includes:
[0029] Set an operational evaluation coefficient threshold and compare the operational evaluation coefficient of the monitoring interval with the operational evaluation coefficient threshold;
[0030] If the operation evaluation coefficient is greater than the operation evaluation coefficient threshold, the power terminal twin generates an early warning signal. In the power terminal twin, the synchronous power terminal operation data within the monitoring range is taken as potential attack behavior. The power terminal twin simulates the potential attack chain and verifies whether the potential attack behavior is a new attack behavior through reinforcement learning technology. If it is determined to be a known potential attack behavior, the known defense strategy is used to deal with it. If it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in time. The new attack behavior is taken as a potential attack behavior and the defense strategy is trained in the twin through reinforcement learning.
[0031] If the operation evaluation coefficient is less than the operation evaluation coefficient threshold, no warning signal will be generated, and the operation data of the power terminals within the monitoring range will be regarded as normal operation data.
[0032] The technical effects and advantages of this invention are as follows:
[0033] This invention establishes a digital twin of a power terminal and combines techniques such as reinforcement learning, Bayesian formulas, wavelet transform, and GARCH models to monitor the operational status of the power terminal in real time and detect potential attack behaviors. First, by collecting operational data from the power terminal, a digital twin is constructed and its operational status is synchronized. Then, by comparing historical training data with real-time data, operational differences in the power terminal are determined. Wavelet transform and GARCH models are used to analyze continuously changing data to obtain operational trend information. Finally, combining operational differences and trend information, a backpropagation neural network is used to construct an operational evaluation model to determine whether potential attack behaviors exist. This invention uses a digital twin of the power terminal and reinforcement learning to simulate different potential attack behaviors, generate optimal defense strategies, and ensure that the twin environment can accurately identify attack behaviors. Attached Figure Description
[0034] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings;
[0035] Figure 1 This is a flowchart illustrating a smart defense method for power terminals based on digital twins according to the present invention. Detailed Implementation
[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0037] Example 1
[0038] Figure 1 This is a flowchart illustrating a smart defense method for power terminals based on digital twins according to the present invention, which specifically includes the following steps:
[0039] S1: By collecting the operating data of the power terminal, a digital twin of the power terminal is established to ensure that the digital twin of the power terminal operates synchronously with the power terminal. Then, through reinforcement learning, an attack chain is simulated in the twin environment to generate the optimal defense strategy, and the verified strategy is dynamically distributed to the physical terminal.
[0040] S2: By comparing the real-time operating data of the power terminals within the monitoring range with the historical training data of the digital twins of the power terminals, the Bayesian formula is used to determine the operating difference information of the power terminals.
[0041] S3: Analyze the continuously changing data in the power terminal operation data through wavelet transform and GARCH model to determine the operation trend information of the power terminal;
[0042] S4: Conduct a comprehensive analysis of the operational differences and trends of the power terminals, and construct an operational evaluation model in the power terminal twin using a BP neural network to determine whether there are potential attack behaviors in the power terminal operational data.
[0043] On power terminals (such as smart meters, distribution switches, and relay protection devices), deploy edge gateways or security agents to collect operational data from the power terminals and establish a digital twin model on the edge side, which is a "full virtual copy" of the terminal. This model covers data input, operational logic, and control interfaces. The operational data includes physical layer data, such as voltage, current, frequency, power factor, and harmonic information; communication data, such as messages, control commands, and heartbeat packets between the terminal and the master station / dispatch center; and operational status data, such as logs, alarm information, and the status of internal device registers.
[0044] Using a real-time streaming data bus (such as MQTT, OPC UA, or IEC 104 protocol parsing module), the operating data of the physical terminal is continuously input into the twin. The twin updates its own model based on the collected data to ensure that its operating state is always consistent with that of the physical terminal. For example, if the physical terminal receives a switch closing command from the dispatch center, the twin will also synchronously "receive and execute" this command.
[0045] The twin weight of the power terminal establishes a profile of the normal operation behavior of the power terminal within the monitoring range based on the historical operation data of the power terminal. Once the operation data of the power terminal deviates from the normal operation behavior profile, potential attack behaviors are promptly blocked from continuing to attack the power terminal.
[0046] It should be noted that the operational data of power terminals may have instantaneous fluctuations (such as sudden load increases, short-term voltage fluctuations, and communication delays). If each single data point is judged, it will lead to too many false alarms. By setting a monitoring interval, the transient fluctuations can be distinguished from the real anomalies, thus improving the reliability of the judgment. In addition, the normal operation behavior profile is usually based on historical statistical features or model training patterns. If single data points are directly used for comparison, it will be difficult to match the profile because instantaneous data may deviate from the mean but still belong to normal fluctuations. Furthermore, the monitoring interval contains continuous data, which is convenient for simulating attacks with twins and training reinforcement learning strategies.
[0047] Based on different potential attack behaviors, the twin of the power terminal simulates different potential attack behaviors through reinforcement learning to generate the optimal defense strategy, including twin environment preparation, attack chain simulation, and strategy verification, among which:
[0048] The preparation of the twin environment includes state definition, action definition, and reward function. State definition is achieved by obtaining the power terminal state at each point in time in the twin, which can be represented by vector or tensor form to represent the state of the entire monitoring interval. Action definition is achieved by constructing a set of defense actions, such as adjusting firewall rules and restricting the execution of abnormal control commands. Positive rewards in the reward function include preventing successful attacks, maintaining normal equipment operation, and reducing false alarm rate, while negative rewards include successful attacks leading to anomalies, mistakenly blocking normal operation, and causing service interruption.
[0049] Attack chain simulation involves injecting potential attack behaviors into the twin of the power terminal, including virtual injection of current / voltage data offsets, simulated abnormal high-frequency message access, etc. The attack can be a single-step or multi-step chain attack, and reinforcement learning responds by exploring different combinations of defensive actions.
[0050] Policy verification involves testing the effectiveness of potential attacks in a twin of the power terminal. Evaluation metrics include false alarm rate and system performance overhead. Only policies that pass verification are distributed to the physical terminal.
[0051] It should be noted that after the defense strategy is trained in the twin, it will first undergo rigorous verification testing to ensure that the strategy can effectively defend against simulated attack scenarios and will not cause adverse reactions in the system.
[0052] Based on known potential attack behaviors in the power terminal twin environment, the power terminal twin compares historical training data with signs of new attack behaviors to determine whether a new attack belongs to an existing potential attack behavior. If it is determined that the new attack belongs to a known potential attack behavior, the known defense strategy is used directly to deal with it. If the new attack behavior does not match the existing attack pattern, the new attack behavior is treated as a potential attack behavior and the defense strategy is trained in the twin through reinforcement learning.
[0053] Based on real-time synchronized data from the twin and the power terminal, an operational evaluation model is constructed within the power terminal twin. This model analyzes real-time data to determine whether the power terminal's operational data within the monitoring range exhibits potential attack behavior. Specifically, by analyzing the power terminal's operational data, operational discrepancies and trends are identified. The operational discrepancies are represented using data probability analysis coefficients, while the operational trends are represented using local anomaly coefficients and overall data anomaly fluctuation coefficients in the frequency domain.
[0054] The advantages of data probability analysis coefficients are as follows:
[0055] The data probability analysis coefficient combines the similarity between the current power terminal operation data and historical data within the monitoring interval. It can determine in real time whether the operation status of the power terminal deviates from the normal range. As new operation data is generated, the system will continuously train and update the prior and posterior probabilities to improve the accuracy of attack behavior identification.
[0056] Historical training data includes normal behavior and potential attack behavior. In a twin environment, through reinforcement learning, the system gradually learns how to make optimal decisions based on historical data. As training progresses, it can continuously distinguish between potential attack behavior and normal operating conditions, thereby improving the effectiveness of defense strategies. This helps to avoid the limitations of manually set rules and relies entirely on historical data and the actual operating environment, ensuring the scientific nature of the decisions.
[0057] Data probability analysis coefficients take into account various operating characteristics such as electrical parameters and control status, and combine them with historical data analysis to more comprehensively identify potential attacks. They can also model the operating data of power terminals through accurate probability distributions, thereby helping to identify abnormal or potential attack behaviors.
[0058] The logic for obtaining the data probability analysis coefficients is as follows: Determine the operating characteristics of the power terminals within the monitoring interval; compare these operating characteristics with the operating characteristics of the historical training data of the power terminal twins; and determine historically similar operating characteristics based on cosine similarity calculation. The formula for calculating cosine similarity is: ;in, To measure the cosine similarity between the operating characteristics of power terminals within the monitoring interval and the operating characteristics of historical training data, let A represent the operating characteristics of power terminals within the monitoring interval. The running characteristics of the historical training data are n = 1, 2, 3, ..., N, where N is a positive integer and n is the number of the running characteristics of the historical training data.
[0059] The index of historically similar operational features in the historical training data is determined by the following formula: Where XS is the index of historically similar running features in historical training data;
[0060] It should be noted that the operating characteristics of a power terminal include electrical parameters and control status, such as current, voltage, power, and frequency. The operating characteristics of a power terminal can directly reflect various physical quantities and operating parameters of the power terminal under normal or abnormal operating conditions.
[0061] Historical training data refers to the data used in reinforcement learning training in a twin environment. It is generated from the historical data of the power terminal, including historical normal data and historical potential attack behavior data of the power terminal. During the reinforcement learning process, through simulation and training, the system can distinguish between normal behavior and potential attack behavior, and gradually learn how to make the best decisions based on historical data.
[0062] Based on historical training data, the prior probability of a potential attack by a power terminal twin is determined, and this prior probability is denoted as: Furthermore, kernel density estimation is used to smooth the historical training data, and the probability of historically similar running features in the historical training data is determined. The probability of historically similar running features in the historical training data is labeled as follows: The probability of a power terminal twin engaging in potential attack behavior under historically similar operating characteristics is obtained, and this probability is denoted as: ;
[0063] The probability analysis coefficients of the data are calculated using Bayes' theorem. The formula is as follows: ;in, These are the coefficients for probability analysis of the data.
[0064] As can be seen from the formula, the larger the data probability analysis coefficient, the more likely the power terminal's operating data within the monitoring interval is to be a potential attack behavior, that is, the more similar the current power terminal's operating data is to the potential attack behavior data in the historical training data.
[0065] The advantage of local anomaly coefficients in frequency domain data is that:
[0066] Local anomaly coefficients in frequency domain data help capture sudden changes in non-stationary signals. In power systems, many potential attacks or faults can cause instantaneous changes in signals, which are particularly difficult to detect in the time domain. Frequency domain analysis can highlight these sudden changes.
[0067] By assigning different weights to different data types, the local anomaly coefficient of frequency domain data can more accurately and efficiently identify potential attack behaviors in power systems. False data injection attacks may cause abnormal fluctuations in current and voltage, while DDoS attacks may affect communication networks and data traffic. By allocating weights to each data type, the system can adapt to changes in different attack patterns, improving detection sensitivity.
[0068] The local anomaly coefficient of frequency domain data can reveal local abrupt changes in the signal. For example, at a certain moment, the operating data of the power terminal suddenly changes drastically (such as instantaneous power fluctuations or current peaks). This is usually an abnormal fluctuation caused by attack behavior (such as spoofing, denial-of-service attacks, etc.), and is suitable for detecting instantaneous attack behavior or faults.
[0069] The logic for obtaining the local anomaly coefficients of the frequency domain data is as follows: Data types with continuously changing characteristics are extracted from the power terminal operation data within the monitoring interval, and the time series of these continuously changing data types within the monitoring interval is obtained. Wavelet transform is then used to analyze the continuously changing data types within the monitoring interval. The wavelet transform expression for the continuously changing data types within the monitoring interval is: ;in, To monitor the data of the i-th continuously changing data within the monitoring interval through wavelet transform, To monitor the i-th continuously varying data within the interval in the time domain, 'a' represents the scaling parameter of the wavelet function, and 'b' represents the translation parameter of the wavelet function. Let i be the wavelet function for the i-th type of continuously changing data, where i = 1, 2, 3, ..., I, where I is a positive integer and i is the number of the type of continuously changing data.
[0070] It should be noted that wavelet transform can convert continuously changing data from the time domain to the frequency domain, capturing high-frequency abrupt changes or low-frequency trends in the data, thereby helping to detect anomalies. The scale and translation parameters are usually determined by professionals through actual data analysis and experience based on the characteristics of the power terminal data, to ensure that the abnormal or changing features in the signal can be effectively extracted.
[0071] Data types with continuous change characteristics typically refer to those that, under normal operating conditions, do not experience drastic fluctuations or irregular jumps, but rather exhibit stable, gradual, or periodic changes, including voltage, current, power, and load. Therefore, by analyzing data types with continuous change characteristics, potential attack behaviors can be effectively identified. Wavelet changes can reveal sudden fluctuations and short-term anomalies, enabling the analysis of local changes in data. The abnormal behaviors that are captured are usually manifested as sudden changes or fluctuations, such as malicious data injection attacks.
[0072] Determine the peak and center frequencies of continuously changing data types within the monitoring interval after wavelet transformation, and calculate the frequency shift coefficients for different types of continuously changing data. The calculation formula is as follows: ;in, For the i-th type of continuously varying data, the frequency offset coefficient is... Let be the center frequency of the i-th continuously changing data;
[0073] Set threshold values for wavelet coefficients for different continuously changing data types, and calculate the outlier data ratio coefficient using the following formula: ;in, Let be the coefficient representing the proportion of outlier data in the i-th type of continuously changing data. The time period within the monitoring interval that exceeds the threshold of wavelet coefficients for different continuously changing data types;
[0074] The formula for calculating the local anomaly coefficient of frequency domain data is as follows: ;in, These are the local anomaly coefficients of the frequency domain data. Weights for different continuously changing data types;
[0075] It should be noted that some data types, such as load, are normal to experience large local variations under specific operating conditions. This is because power systems may experience fluctuations of a certain magnitude during load changes, equipment adjustments, or operation. These fluctuations do not necessarily indicate potential attacks. On the other hand, critical data types such as voltage and current should maintain a certain level of stable fluctuation during normal system operation. Dramatic changes in a short period of time are more likely to indicate that the system has been subjected to malicious attacks. Therefore, the weights of different continuously changing data types reflect the sensitivity of each data type and its relationship with potential attack behaviors.
[0076] As can be seen from the formula, the larger the local anomaly coefficient of the frequency domain data, the greater the potential local changes in the power terminal operation data within the monitoring interval. In other words, the power terminal operation data within the monitoring interval may have experienced sudden changes in certain frequency bands, which may indicate that the system has encountered potential attacks.
[0077] The advantages of the overall data anomaly fluctuation coefficient are as follows:
[0078] The overall data anomaly fluctuation coefficient captures the fluctuation clustering effect of the power terminal system under attack or abnormal conditions through the GARCH model, which helps to detect potential attack behavior in real time, accurately determine whether the current fluctuation is outside the normal fluctuation range, and identify potential attacks.
[0079] The overall data anomaly fluctuation coefficient is adjusted in real time according to the state changes of the power terminal, which can more accurately reflect the dynamic changes of the data, respond better to the fluctuation changes caused by attacks, and can dynamically adjust the conditional variance according to real-time data, thus having strong adaptability and accuracy.
[0080] The logic for obtaining the overall data anomaly fluctuation coefficient is as follows: Based on the continuously changing data type of power terminals within the monitoring interval, the time series of the continuously changing data type is used as the input data for the GARCH model. The GARCH model is used to fit different types of continuously changing data within the monitoring interval, and the conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags are obtained. The conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags are uniformly labeled as: Where f = 1, 2, 3, ..., F, F is a positive integer, and f is the order of the GARCH model. When f = 0, The conditional variance at the current time point in a GARCH model for different types of continuously varying data;
[0081] It should be noted that in the data analysis of power terminals, conditional variance is a predicted value based on historical data, used to measure the volatility at the current moment. Attacks can cause a sharp increase in data volatility.
[0082] Set conditional variance thresholds for different types of continuously changing data. Compare the conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags with the conditional variance thresholds. Count the number of conditional variances within the monitoring interval that exceed the conditional variance thresholds. Mark the number of conditional variances that exceed the conditional variance thresholds as: ;
[0083] It should be noted that the conditional variance thresholds for different types of continuously changing data are based on the conditional variance levels of normal operating data in the power terminal twin, and can be set by the distribution of training data.
[0084] The formula for calculating the overall data anomaly fluctuation coefficient is as follows: ;in, This represents the coefficient for abnormal fluctuations in the overall data.
[0085] As can be seen from the formula, the larger the overall data abnormal fluctuation coefficient, the greater the volatility of the power terminal operation data within the monitoring range, which may indicate potential attacks.
[0086] By comprehensively analyzing the operational difference and trend information of power terminals, the normalized data probability analysis coefficients, frequency domain data local anomaly coefficients, and overall data anomaly fluctuation coefficients are used to construct an operational evaluation model in the power terminal twin using a BP neural network, generating operational evaluation coefficients. The calculation formula for the operational evaluation coefficients is as follows: ;in, For operational evaluation coefficients, , , These are the proportional coefficients for data probability analysis coefficients, local anomaly coefficients in frequency domain data, and overall data anomaly fluctuation coefficients, respectively. , , All are greater than 0.
[0087] As can be seen from the formula, the larger the data probability analysis coefficient, the frequency domain data local anomaly coefficient, and the overall data anomaly fluctuation coefficient, the larger the operation evaluation coefficient, indicating that the security risk of the power terminal within the monitoring range is higher and the potential attack behavior is more likely to occur.
[0088] A threshold for the operation evaluation coefficient is set, and the operation evaluation coefficient of the monitoring interval is compared with the threshold. If the operation evaluation coefficient is greater than the threshold, the power terminal twin generates an early warning signal. In the power terminal twin, the synchronous power terminal operation data within the monitoring interval is regarded as potential attack behavior. The power terminal twin further analyzes the potential attack behavior, simulates the potential attack chain through reinforcement learning technology, and verifies whether the potential attack behavior is a new attack behavior. If it is determined to be a known potential attack behavior, the known defense strategy is used to deal with it. If it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in time, and the new attack behavior is used as a potential attack behavior to train the defense strategy in the twin through reinforcement learning. If the operation evaluation coefficient is less than the threshold, no early warning signal is generated, and the operation data of the power terminal within the monitoring interval is regarded as normal operation data.
[0089] It should be noted that the setting of the evaluation coefficient threshold is optimized and adjusted in conjunction with reinforcement learning. That is, if reinforcement learning determines that a potential attack behavior is not a new attack behavior and is not aggressive, the threshold is increased to avoid too many false alarms.
[0090] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0091] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.
[0092] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0093] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0094] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0095] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0096] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0097] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A smart defense method for power terminals based on digital twins, characterized in that, Specifically, the following steps are included: S1: By collecting real-time and historical operating data of the power terminal, a digital twin of the power terminal is established to ensure that the digital twin of the power terminal operates synchronously with the power terminal. Through reinforcement learning, an attack chain is simulated in the twin environment to generate the optimal defense strategy, and the verified strategy is dynamically distributed to the power terminal. S2: By comparing the real-time operating data of the power terminal within the monitoring range with the historical training data of the digital twin of the power terminal, the Bayesian formula is used to determine the operating difference information of the power terminal. The historical training data refers to the data used in the reinforcement learning training process in the twin environment, which is generated from the historical operating data of the power terminal. S3: Analyze the continuously changing data in the real-time operation data of the power terminal using wavelet transform and GARCH model to determine the operation trend information of the power terminal; S4: Conduct a comprehensive analysis of the operational differences and trends of the power terminals, and construct an operational evaluation model in the digital twin of the power terminals using a BP neural network to determine whether there are potential attack behaviors in the real-time operational data of the power terminals; Determine the operational differences and trends of power terminals, including: The operational differences of power terminals are represented by data probability analysis coefficients, and the operational trends of power terminals are represented by local anomaly coefficients and overall data anomaly fluctuation coefficients in the frequency domain. For data probability analysis coefficients, Let be the coefficient representing the proportion of outlier data in the i-th type of continuously changing data. This represents the coefficient for abnormal fluctuations in the overall data.
2. The intelligent defense method for power terminals based on digital twins according to claim 1, characterized in that, The logic for obtaining the data probability analysis coefficients is as follows: The operational characteristics of real-time operational data of power terminals within the monitoring interval are determined. These characteristics are then compared with the operational characteristics of historical training data from the digital twins of the power terminals. Historically similar operational characteristics are determined based on cosine similarity calculations. The formula for calculating cosine similarity is as follows: ;in, To measure the cosine similarity between the real-time operational data characteristics of power terminals within the monitoring interval and the operational characteristics of historical training data, let A represent the operational characteristics of the real-time operational data of power terminals within the monitoring interval. The running characteristics of the historical training data are n = 1, 2, 3, ..., N, where N is a positive integer and n is the number of the running characteristics of the historical training data. The index of historically similar operational features in the historical training data is determined by the following formula: Where XS is the index of historically similar running features in historical training data; Based on historical training data, the prior probability of a potential attack by a digital twin of a power terminal is determined, and this prior probability is denoted as: Furthermore, kernel density estimation is used to smooth the historical training data, and the probability of historically similar running features in the historical training data is determined. The probability of historically similar running features in the historical training data is labeled as follows: The probability of a potential attack by a digital twin of a power terminal under similar historical operating characteristics is obtained, and this probability is denoted as: ; The probability analysis coefficients of the data are calculated using Bayes' theorem. The formula is as follows: .
3. The intelligent defense method for power terminals based on digital twins according to claim 2, characterized in that, The logic for obtaining the local anomaly coefficients of the frequency domain data is as follows: Data types with continuously changing characteristics are extracted from the real-time operation data of power terminals within the monitoring interval, and the time series of these continuously changing data types within the monitoring interval is obtained. Wavelet transform is then used to analyze these continuously changing data types within the monitoring interval. The wavelet transform expression for these continuously changing data types within the monitoring interval is as follows: ;in, To monitor the data of the i-th continuously changing data within the monitoring interval through wavelet transform, To monitor the i-th continuously varying data within the interval in the time domain, 'a' represents the scaling parameter of the wavelet function, and 'b' represents the translation parameter of the wavelet function. Let i be the wavelet function for the i-th type of continuously changing data, where i = 1, 2, 3, ..., I, where I is a positive integer and i is the number of the type of continuously changing data. Determine the peak and center frequencies of continuously changing data types within the monitoring interval after wavelet transformation, and calculate the frequency shift coefficients for different types of continuously changing data. The calculation formula is as follows: ;in, For the i-th type of continuously varying data, the frequency offset coefficient is... The center frequency of the i-th continuously changing data; Set threshold values for wavelet coefficients for different continuously changing data types, and calculate the outlier data ratio coefficient using the following formula: ;in, The time period within the monitoring interval that exceeds the threshold of wavelet coefficients for different continuously changing data types; The formula for calculating the local anomaly coefficient of frequency domain data is as follows: ;in, These are the local anomaly coefficients of the frequency domain data. Weights for different continuously changing data types.
4. The intelligent defense method for power terminals based on digital twins according to claim 3, characterized in that, The logic for obtaining the overall data abnormal fluctuation coefficient is as follows: Based on the continuously changing data type of power terminals within the monitoring interval, the time series of continuously changing data types are used as input data for the GARCH model. The GARCH model is used to fit different types of continuously changing data within the monitoring interval, obtaining the conditional variances of different types of continuously changing data at different time points and different time lags within the monitoring interval. The conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags are uniformly labeled as: Where f = 1, 2, 3, ..., F, F is a positive integer, and f is the order of the GARCH model. When f = 0, The conditional variance at the current time point in a GARCH model for different types of continuously varying data; Set conditional variance thresholds for different types of continuously changing data. Compare the conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags with the conditional variance thresholds. Count the number of conditional variances within the monitoring interval that exceed the conditional variance thresholds. Mark the number of conditional variances that exceed the conditional variance thresholds as: ; The formula for calculating the overall data anomaly fluctuation coefficient is as follows: .
5. The intelligent defense method for power terminals based on digital twins according to claim 4, characterized in that, An operational evaluation model is constructed in a digital twin of a power terminal using a backpropagation neural network, including: By comprehensively analyzing the operational difference and trend information of power terminals, the normalized data probability analysis coefficients, frequency domain data local anomaly coefficients, and overall data anomaly fluctuation coefficients are used to construct an operational evaluation model in the digital twin of the power terminal through a BP neural network, generating operational evaluation coefficients. The calculation formula for the operational evaluation coefficients is as follows: ;in, For operational evaluation coefficients, , , These are the proportional coefficients for data probability analysis coefficients, local anomaly coefficients in frequency domain data, and overall data anomaly fluctuation coefficients, respectively. , , All are greater than 0.
6. The intelligent defense method for power terminals based on digital twins according to claim 5, characterized in that, Determining whether there are potential attacks on the real-time operating data of power terminals includes: Set an operational evaluation coefficient threshold and compare the operational evaluation coefficient of the monitoring interval with the operational evaluation coefficient threshold; If the operation evaluation coefficient is greater than the operation evaluation coefficient threshold, the power terminal digital twin generates an early warning signal. In the power terminal digital twin, the real-time operation data of the power terminal synchronized within the monitoring range is taken as potential attack behavior. The power terminal digital twin simulates the potential attack chain and verifies whether the potential attack behavior is a new attack behavior through reinforcement learning technology. If it is determined to be a known potential attack behavior, the known defense strategy is used to deal with it. If it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in a timely manner. The new attack behavior is taken as a potential attack behavior and the defense strategy is trained in the power terminal digital twin through reinforcement learning. If the operation evaluation coefficient is less than the operation evaluation coefficient threshold, no warning signal will be generated, and the real-time operation data of the power terminals within the monitoring range will be regarded as normal operation data.
Citation Information
Patent Citations
Construction method and equipment of digital twinborn model of power data communication network, and medium
CN115801594A
Harbor district power load boundary prediction system based on two-stage model and regulation and control method
CN120430445A