Power distribution network data processing method and device, terminal equipment and storage medium

By combining variational autoencoders, adversarial network models, and bidirectional gated cyclic units, the problem of insufficient identification of hidden features in network data in power distribution systems is solved, and more accurate network security assessment is achieved.

CN120979734APending Publication Date: 2025-11-18ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511161045.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

The existing power distribution system network data is too large to effectively identify hidden features, resulting in low accuracy of network security assessments.

Method used

A combination of variational autoencoders, adversarial network models, and bidirectional gated cyclic units is adopted to acquire network data of the power distribution system, generate potential features, time series data, and bidirectional hidden states, and use weighted feature representation to conduct security situation assessment.

Benefits of technology

It improves the accuracy of network security assessments for power distribution systems, enabling the identification of hidden features and enhancing the precision of security situation assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979734A_ABST
    Figure CN120979734A_ABST
Patent Text Reader

Abstract

The invention discloses a power distribution network data processing method and device, terminal equipment and a storage medium, and belongs to the field of network security, and the method comprises the steps: obtaining network data of a power distribution system; inputting the network data to a variational auto-encoder to enable the variational auto-encoder to generate potential features based on the network data; inputting the potential features into an adversarial network model to enable the adversarial network model to generate time sequence data based on the potential features; inputting the time sequence data into a bidirectional gating circulation unit, so that the bidirectional gating circulation unit generates a bidirectional hidden state based on the time sequence data; and according to the bidirectional hidden state, generating weighted feature representation, and performing security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result. The problem of low network security assessment accuracy caused by the fact that hidden features of network data cannot be analyzed in the prior art can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and in particular to a data processing method, apparatus, terminal equipment, and storage medium for power distribution networks. Background Technology

[0002] With the increasing number of power distribution systems, ensuring network security has become a critical issue. However, the sheer volume of network data in existing power distribution systems makes it impossible to identify hidden features. Consequently, the accuracy of network security assessments in existing power distribution systems suffers from this inability to analyze the hidden features of network data. Summary of the Invention

[0003] This invention provides a power distribution network data processing method, apparatus, terminal equipment, and storage medium, which can solve the problem of low accuracy in network security assessment caused by the inability to analyze the hidden features of network data in the prior art.

[0004] The power distribution network data processing method provided by this invention includes:

[0005] Obtain network data from the power distribution system;

[0006] The network data is input into a variational autoencoder so that the variational autoencoder generates latent features based on the network data;

[0007] The latent features are input into the adversarial network model, so that the adversarial network model generates time series data based on the latent features;

[0008] The time series data is input into a bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data;

[0009] Based on the bidirectional hidden state, a weighted feature representation is generated, and a security situation assessment of the power distribution system is performed based on the weighted feature representation to obtain the security situation assessment result.

[0010] Further, the step of performing a security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result includes:

[0011] For each piece of network data, the weighted feature representation corresponding to each piece of network data is input into a classifier to calculate a network security situation value; wherein, the classifier includes a binary classifier and a multi-classifier; each weighted feature representation is input into the binary classifier to generate a network security judgment result corresponding to each weighted feature representation, and the network attack probability is calculated based on the network security judgment results corresponding to all network data; each weighted feature representation is input into the multi-classifier to generate a target network attack type corresponding to each weighted feature representation, and the impact value corresponding to the target network attack type is calculated; the network security situation value is calculated based on the network attack probability and the impact value corresponding to the target network attack type.

[0012] Based on the network security situation value, the security situation assessment result of the power distribution system is determined.

[0013] Furthermore, the training of the classifier includes:

[0014] Obtain network training data samples; wherein the network training data samples are labeled network training data; wherein the labels include: known network attack type or binary classification result is normal;

[0015] Based on a preset loss function, the network training data samples, and a preset classification model, the training operation is repeatedly executed. When the loss function converges, the training operation is stopped, and a classifier is obtained. The training operation includes:

[0016] Select an untrained network training data sample as the target data sample;

[0017] The target data sample is input into the binary classifier in the classification model of the current model parameters to generate a binary classification result, and the probability that the binary classification result is abnormal is calculated based on the binary classification result; wherein, the binary classification result includes one of: normal or abnormal;

[0018] The target data sample is input into the multi-classifier in the classification model of the current model parameters to generate a predicted network attack type and calculate the predicted probability corresponding to each type of network attack.

[0019] The binary classification result, the probability that the binary classification result is an anomaly, and the predicted probability corresponding to each type of network attack are input into the loss function to calculate the loss function value; wherein the loss function includes:

[0020]

[0021] y bin ∈{0,1}

[0022]

[0023] y multi ∈{1,2,…,K}

[0024]

[0025] In the formula, Let y be the value of the loss function. bin The binary classification result is labeled for the current sample, with 1 indicating normal and 0 indicating abnormal. Let α be the probability that the binary classification result is an anomaly, and y be the adjustable weight. multi The known network attack types labeled for the current sample. Let K be the predicted probability of the k-th type of network attack, where K is the number of network attack types. This is an indicator function, representing a value of 1 when the true class is k;

[0026] Determine whether the loss function value has converged;

[0027] If so, stop the training operation and output the classification model corresponding to the current model parameters;

[0028] If not, update the current model parameters, obtain the updated model parameters, use the updated model parameters as the model parameters for the next training operation, and execute the next training operation.

[0029] Further, the step of inputting the network data into the variational autoencoder to enable the variational autoencoder to generate latent features based on the network data includes:

[0030] The network data is input into a variational autoencoder to generate a latent variable mean vector and a latent variable standard deviation vector. The variational autoencoder then substitutes the latent variable mean vector and the latent variable standard deviation vector into the latent space formula to obtain latent features.

[0031] The latent space formula is as follows:

[0032]

[0033] In the formula, z represents the latent spatial variable, μ is the mean vector of the latent variable output by the variational autoencoder, σ is the standard deviation vector of the output latent variable, and ∈ is the random noise vector sampled from the standard normal distribution. It follows a standard normal distribution.

[0034] Further, the adversarial network model includes a generator and a discriminator; the step of inputting the latent features into the adversarial network model to enable the adversarial network model to generate time series data based on the latent features includes:

[0035] The latent features are input into the generator, so that the generator maps the latent features according to the multilayer perceptron to obtain initial time data;

[0036] The initial time data and the network data are input into the discriminator so that the discriminator processes the initial data to obtain time series data.

[0037] Further, the step of inputting the time series data into the bidirectional gated loop unit, so that the bidirectional gated loop unit generates bidirectional hidden states based on the time series data, includes:

[0038] Time series data is input into the hidden state formula corresponding to the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a positive hidden state and a negative hidden state based on the time series data. The bidirectional gated loop unit determines the bidirectional hidden state based on the positive hidden state and the negative hidden state.

[0039] The hidden state formula includes:

[0040]

[0041] In the formula, This represents the positive hidden state at time t-1. This represents the reverse hidden state at time t-1. Let be the positive hidden state at time t. Let x be the reverse hidden state at time t. t For time series data, h t Let t be the bidirectional hidden state, and GRU forward () is a positive gated loop function, GRU backward () is a reverse-gated loop function.

[0042] Further, generating a weighted feature representation based on the bidirectional hidden state includes:

[0043] The bidirectional hidden state is substituted into the attention layer so that the attention layer obtains a weighted feature representation based on the weight calculation formula and the bidirectional hidden state; wherein, the weight calculation formula includes:

[0044]

[0045] In the formula, e t Here, `score()` is the attention score, `tanh()` is the scoring function, and `h` is the hyperbolic tangent activation function. t It is a two-way hidden state. W and b are learnable parameters of the attention layer, α tLet exp() be the importance weight at time step t, and let e be the exponential function. x One form of expression, where c represents the weighted feature representation.

[0046] Another embodiment of the present invention provides a power distribution network data processing device, including: a data acquisition module, a first data processing module, a second data processing module, a third data processing module, and a result generation module;

[0047] The data acquisition module is used to acquire network data of the power distribution system;

[0048] The first data processing module is used to input the network data into the variational autoencoder so that the variational autoencoder generates latent features based on the network data;

[0049] The second data processing module is used to input the latent features into the adversarial network model, so that the adversarial network model generates time series data based on the latent features;

[0050] The third data processing module is used to input the time series data into the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data;

[0051] The result generation module is used to generate a weighted feature representation based on the bidirectional hidden state, and to perform a security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result.

[0052] Another embodiment of the present invention provides a terminal device, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the steps of the power distribution network data processing method provided by the present invention.

[0053] Another embodiment of the present invention provides a computer-readable storage medium item, including: a stored computer program, which, when the computer program is running, controls the device where the computer-readable storage medium is located to perform the steps of the power distribution network data processing method provided by the present invention.

[0054] The following benefits can be obtained by implementing the present invention:

[0055] This invention discloses a method for processing power distribution network data. The method involves acquiring network data from a power distribution system; inputting the network data into a variational autoencoder (VAC) to generate latent features; inputting the latent features into an adversarial network (ANN) model to generate time-series data; inputting the time-series data into a bidirectional gated loop unit (GLU) to generate bidirectional hidden states; generating weighted feature representations based on the bidirectional hidden states; and performing a security posture assessment of the power distribution system based on these weighted feature representations to obtain the security posture assessment result. This invention utilizes a variational autoencoder, an ANN model, and a bidirectional gated loop unit to mine features of bidirectional hidden states in the network data of a power distribution system, and generates weighted feature representations based on these hidden states. This allows for the learning of hidden features in the network data, and subsequently, security posture assessments based on these hidden features. This application overcomes the problem of existing technologies being unable to identify hidden features, thus improving the accuracy of power distribution system network security assessments. Attached Figure Description

[0056] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0057] Figure 1 This is a schematic flowchart of a power distribution network data processing method provided in an embodiment of the present invention;

[0058] Figure 2 This is a schematic diagram of the structure of a power distribution network data processing device provided in an embodiment of the present invention. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.

[0061] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.

[0062] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0063] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0064] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).

[0065] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.

[0066] See Figure 1To address the problem of low accuracy in network security assessments due to the inability to analyze hidden features in network data in existing technologies, an embodiment of the present invention provides a power distribution network data processing method, comprising:

[0067] 101. Obtain network data from the power distribution system.

[0068] In one specific embodiment, multi-dimensional time-series data of the power distribution system is acquired, including log data, flow data, etc.

[0069] By using techniques such as one-hot coding, the symbolic data features in multidimensional time series data are transformed into data that only represents 0 and 1, thus obtaining multidimensional coded time series data for subsequent analysis and processing.

[0070] Methods such as max-min scaling are used to normalize multidimensional encoded time-series data to reduce the impact of different units on model training.

[0071] 102. Input the network data into the variational autoencoder so that the variational autoencoder generates latent features based on the network data.

[0072] Further, the step of inputting the network data into the variational autoencoder to enable the variational autoencoder to generate latent features based on the network data includes:

[0073] The network data is input into a variational autoencoder to generate a latent variable mean vector and a latent variable standard deviation vector. The variational autoencoder then substitutes the latent variable mean vector and the latent variable standard deviation vector into the latent space formula to obtain latent features.

[0074] The latent space formula is as follows:

[0075]

[0076] In the formula, z represents the latent spatial variable, μ is the mean vector of the latent variable output by the variational autoencoder, σ is the standard deviation vector of the output latent variable, and ∈ is the random noise vector sampled from the standard normal distribution. It follows a standard normal distribution.

[0077] It should be noted that, The first parameter represents the mean of the distribution, which has a value of 0. The second parameter represents the variance of the distribution, which has a value of 1.

[0078] In one specific embodiment, the variational autoencoder is trained by optimizing the model using the Maximum Evidence Lower Bound (ELBO) approach. The model is trained based on the optimized loss function of the ELBO optimization model, and training is completed when the optimized loss function value is minimized. The optimized loss function is specifically as follows:

[0079]

[0080] In the formula, To optimize the loss function value.

[0081] (1) First term: Loss of the reconstruction term:

[0082] In the formula, Let logp(x|z) be the reconstruction loss, where x is the original data, z is the latent space variable, p(x|z) represents the decoder reconstruction distribution, and q(z|x) represents the encoder approximate posterior distribution.

[0083] The reconstruction term represents the expected log-likelihood of the model reconstructing the original data x under sampling of the latent variable z. The more realistic the reconstruction, the smaller the loss.

[0084] (2) Second term: KL divergence (regularity term): KL(q(z∣x)||p(z));

[0085] In the formula, KL: Kullback-Leibler divergence (measures the difference between two distributions); p(z) represents the prior distribution of the latent variable;

[0086] The regularization term encourages the latent spatial distribution q(z|x) to approach the prior p(z).

[0087] 103. Input the latent features into the adversarial network model so that the adversarial network model generates time series data based on the latent features.

[0088] Further, the adversarial network model includes a generator and a discriminator; the step of inputting the latent features into the adversarial network model to enable the adversarial network model to generate time series data based on the latent features includes:

[0089] The latent features are input into the generator, so that the generator maps the latent features according to the multilayer perceptron to obtain initial time data;

[0090] The initial time data and the network data are input into the discriminator so that the discriminator processes the initial data to obtain time series data.

[0091] In one specific embodiment, the introduction of a Generative Adversarial Network (GAN) model in the proposed power distribution network data processing method aims to significantly improve the quality of the output time-series data through an adversarial training process, making it usable time-series data for subsequent processing by a Bidirectional Gated Recurrent Unit (Bi-GRU). The adversarial training is implemented based on a game mechanism between the generator and the discriminator.

[0092] It should be noted that the adversarial network model consists of the following:

[0093] The generator's function is to receive latent features from the input and map them using a multilayer perceptron (MLP) to attempt to generate synthetic data similar to the distribution of real network data, i.e., "initial time data" X. fake .

[0094] Discriminator: Its function is to receive data input and determine whether the data comes from a real dataset ("Network Data" x) or fake data synthesized by the generator ("Initial Time Data" x). fake The discriminator outputs a probability value, indicating its confidence level in considering the input data to be true.

[0095] It should be noted that the adversarial training process of the adversarial network model is as follows:

[0096] Adversarial training is a zero-sum game process involving iterations, where the generator and discriminator are optimized alternately.

[0097] (1) Discriminator training:

[0098] The goal of the discriminator is to maximize its ability to correctly distinguish between real and generated data. Its loss function is designed to make the discriminator output a high probability (close to 1) when receiving real data and a low probability (close to 0) when receiving generated data. The discriminator's loss function can be expressed as:

[0099]

[0100] In the formula, D(x) represents the probability that the discriminator judges the true data x as true, D(X) fake (That is, D(G(z))) represents the discriminator's judgment on the generated data X. fake The true probability, This represents the expectation of the true data distribution; it refers to the expectation of the true data distribution p. data Given (x), calculate the expectation of logD(x). This represents the expectation of the noise or latent feature distribution input to the generator. It refers to the expectation of the noise / latest feature distribution p. z (z) under log(1-D(X) fake Find the expected value. Here, X... fakeIt is the fake data generated by the generator G based on z (i.e., G(z)).

[0101] When training the discriminator, the optimization objective is to maximize the value of this loss function.

[0102] (2) Generator training:

[0103] The goal of the generator is to generate fake data that can "fool" the discriminator, causing it to misclassify the generated data as real data. This is achieved by minimizing -logD(G(z)) (equivalent to maximizing logD(G(z))), making D(G(z)) approach 1. During generator training, the discriminator's parameters are fixed, and only the generator's parameters are updated.

[0104] (3) Discriminator performance saturation:

[0105] When the discriminator can no longer effectively distinguish between real and generated data (i.e., D(x) and D(G(z)) are both close to 0.5), it indicates that the generator has become very powerful and can generate highly realistic data. At this point, it is advisable to stop training.

[0106] 3. Improved data quality

[0107] Through the aforementioned alternating optimization process, the generator continuously learns to generate more realistic "initial time data" that better reflects the distribution of data in a real power distribution network. The discriminator provides crucial feedback signals during this process, forcing the generator to gradually improve the quality of its generated data, making it indistinguishable from real data. Ultimately, the fully trained generator can output high-quality samples that can be considered "time-series data," thereby effectively improving the ability of subsequent modules (such as bidirectional gated cyclic units) to uncover hidden features and the accuracy of overall security situation assessment.

[0108] In one specific embodiment, for the generator: a multilayer perceptron (MLP) is used to generate the latent space vectors. Mapped to initial time data of length T×D

[0109] (1) Mapping function

[0110] x vec =f MLP (z)=W2·σ(W1z+b1)+b2

[0111] In the formula, Here is the weight matrix; σ() is the ReLU activation function; b1, b2 are the bias terms; x vec: A one-dimensional vector containing all data points of the entire time series to be generated in the future. W1 and W2 are learnable weight parameters in the multilayer perceptron. They are adjusted through the training process (such as backpropagation) so that the generator can effectively map latent features to high-quality initial time data.

[0112] It should be noted that, Let k be a real vector space. Let T·D be the space of real matrices. Let h×k be the space of real matrices. For a T·D×h dimensional real matrix space

[0113] (2) Transform the one-dimensional vector x vec Remodeling into a time series:

[0114]

[0115] In the formula, X fake The initial time data is obtained by reconstructing the unfolded vector according to time step T and dimension D to obtain time series data. Reshape() is the reshaping function used to reshape the one-dimensional vector x. vec Reshaping into a time series can be efficiently accomplished using the numpy.reshape() function in Python's NumPy library.

[0116] It should be noted that, Let T×D be the space of real matrices.

[0117] It should be noted that this embodiment improves data representation capabilities by integrating variational autoencoders and adversarial network models to extract multimodal features.

[0118] 104. Input the time series data into the bidirectional gated loop unit so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data.

[0119] Further, the step of inputting the time series data into the bidirectional gated loop unit, so that the bidirectional gated loop unit generates bidirectional hidden states based on the time series data, includes:

[0120] Time series data is input into the hidden state formula corresponding to the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a positive hidden state and a negative hidden state based on the time series data. The bidirectional gated loop unit determines the bidirectional hidden state based on the positive hidden state and the negative hidden state.

[0121] The hidden state formula includes:

[0122]

[0123] In the formula, This represents the positive hidden state at time t-1. This represents the reverse hidden state at time t-1. Let be the positive hidden state at time t. Let x be the reverse hidden state at time t. t For time series data, h t Let t be the bidirectional hidden state, and GRU forward () is a positive gated loop function, GRU backward () is a reverse-gated loop function.

[0124] 105. Based on the bidirectional hidden state, generate a weighted feature representation, and perform a security situation assessment on the power distribution system based on the weighted feature representation to obtain the security situation assessment result.

[0125] Further, generating a weighted feature representation based on the bidirectional hidden state includes:

[0126] The bidirectional hidden state is substituted into the attention layer so that the attention layer obtains a weighted feature representation based on the weight calculation formula and the bidirectional hidden state; wherein, the weight calculation formula includes:

[0127]

[0128] In the formula, e t Here, `score()` is the attention score, `tanh()` is the scoring function, and `h` is the hyperbolic tangent activation function. t It is a two-way hidden state. W and b are learnable parameters of the attention layer, α t Let exp() be the importance weight at time step t, and let e be the exponential function. x One form of expression, where c represents the weighted feature representation.

[0129] It should be noted that, It is a 2d-dimensional real vector space.

[0130] In one specific embodiment, the importance weight α at each time step is calculated based on the attention mechanism. t Then, the weighted sum is used to obtain the weighted feature representation c.

[0131] It should be noted that in the data processing method proposed in this invention, the bidirectional gated recurrent unit is used to extract the bidirectional contextual features of the time series data corresponding to each network data point in the time dimension, and output the bidirectional hidden state at each time step. An attention mechanism is introduced to calculate weights using the bidirectional hidden states at each time step, thereby fusing them into a global weighted feature vector c. The weighted feature representation c is fed into two output branches: one is a binary classifier used to determine whether the current traffic is abnormal, and the other is a multi-classifier used to identify the type of abnormality. The joint output of these two branches supports subsequent network attack probability estimation and situation quantification calculations.

[0132] Further, the step of performing a security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result includes:

[0133] For each piece of network data, the weighted feature representation corresponding to each piece of network data is input into a classifier to calculate a network security situation value; wherein, the classifier includes a binary classifier and a multi-classifier; each weighted feature representation is input into the binary classifier to generate a network security judgment result corresponding to each weighted feature representation, and the network attack probability is calculated based on the network security judgment results corresponding to all network data; each weighted feature representation is input into the multi-classifier to generate a target network attack type corresponding to each weighted feature representation, and the impact value corresponding to the target network attack type is calculated; the network security situation value is calculated based on the network attack probability and the impact value corresponding to the target network attack type.

[0134] Based on the network security situation value, the security situation assessment result of the power distribution system is determined.

[0135] In one specific embodiment, the security situation assessment results include: safe, low risk, medium risk, high risk, and very high risk.

[0136] In a specific embodiment, the network attack probability P of the power distribution network being attacked is calculated from the binary classification result (i.e., the network security judgment result, including: safe traffic and abnormal traffic) based on the VG-ATBiGRU model (i.e., the classifier described in this invention). The calculation method is as follows:

[0137]

[0138] In the formula, N is the total amount of network data within a preset time period, and V(i) represents the binary classification result of the i-th network data. The classification result means that if a network data is classified as abnormal network data, then V(i) = 1, otherwise, V(i) = 0.

[0139] In one specific embodiment, the multi-classifier outputs the type of network attack behavior to which the abnormal traffic belongs (e.g., DoS attack, worm attack, etc.). Subsequently, combined with a pre-defined evaluation system (such as the Common Vulnerability Scoring System (CVSS), the overall impact I of the traffic or network attack behavior on the power distribution network is calculated based on the specific impact of different network attack behaviors on the confidentiality, integrity, and availability of the network. i (i.e., the impact value corresponding to each type of network attack described in this invention).

[0140] In assessing the overall impact of cyberattacks on the power distribution network, the impact is first broken down into three dimensions: confidentiality impact, integrity impact, and availability impact. Then, the Common Vulnerability Scoring System (CVSS) is used as the assessment tool to quantify the specific impact of each attack on each of these three dimensions. Finally, a logarithmic function quantification method is used to calculate the overall impact I of each attack on the power distribution network. i Table 1 details the impact assessment index system used when evaluating the impact of attacks. The logarithmic function quantification method is as follows:

[0141]

[0142] In the formula, Co i In i Av i w1, w2, and w3 represent the impact values ​​of the i-th attack type on the confidentiality, integrity, and availability of the network, respectively; w1, w2, and w3 correspond to the weights of C, I, and A, respectively; and Round2 indicates that two decimal places are retained.

[0143] Table 1. Assessment of Attack Impact

[0144]

[0145] In one specific implementation, the CVSS framework provides a standardized set of metrics to measure the impact of a vulnerability exploited. Table 1, "Attack Impact Assessment Table," defines in detail the confidentiality (Co) level. i ), integrity (In i ) and availability (Av) i The quantitative impact values ​​corresponding to the three dimensions are as follows:

[0146] Confidentiality (C): Measures the degree to which the confidentiality of information has been compromised. The assessment levels include none (0), low (0.22) and high (0.56).

[0147] Completeness (I): Measures the degree to which the accuracy and credibility of the data are compromised. The assessment levels are none (0), low (0.22) and high (0.56).

[0148] Availability (A): Measures the degree of impairment in the availability of a system or service. Assessment levels include None (0), Low (0.22), and High (0.56).

[0149] Co i In i Av i The parameter value is determined based on the specific attack type and the CVSS quantification level mentioned above.

[0150] Regarding the CVSS assessment process: CVSS does not directly assess a one-off attack event, but rather focuses on assessing the potential consequences of a vulnerability being exploited. For a specific attack type (e.g., a denial-of-service attack, DoS), CVSS will analyze:

[0151] (1) Focus of the impact after vulnerability exploitation: For example, the main goal of a DoS attack is to render a system or service unavailable. Therefore, when assessing vulnerabilities that could lead to DoS attacks, their availability impact (A) is usually rated as "high," that is, the Availability Impact of the DoS attack is very high. i The value is 0.56.

[0152] (2) Secondary Impact Assessment: The assessment also considers whether the vulnerability, when exploited to launch a DoS attack, would result in data confidentiality breach (C) or data integrity breach (I). Typically, a pure DoS attack has a small impact on confidentiality and integrity and may be rated as "None" or "Low".

[0153] By utilizing the standard indicator system and calculation methods provided by CVSS, the degree of damage to the distribution network from each attack type across different dimensions can be systematically assessed, thereby providing a basis for subsequent assessment of the overall impact level (I). i Calculations provide quantitative evidence.

[0154] The network security posture score comprehensively considers all attacks suffered by the network and the degree of harm caused by each attack. The formula for calculating the network security posture score is as follows:

[0155]

[0156] In the formula, P is the attack probability, and I... i t is the impact value of the i-th network attack on the power distribution network. i N represents the number of times this type of network attack occurs, i.e., the number of single attacks. AThe total number of attacks received by the network. Since normal network traffic poses no harm to the network environment, the severity and impact of normal attack types are 0. It is only necessary to calculate the impact of n-1 attack types on the network security situation.

[0157] Referring to the "National Emergency Response Plan for Public Emergencies", the severity of the network security situation is divided into five levels: safe, low risk, medium risk, high risk and super risk, based on the network security situation value of the power distribution network. The corresponding situation value ranges and specific explanations are shown in Table 2.

[0158] Table 2 Classification of Network Security Situation Assessment Levels

[0159]

[0160] Furthermore, the training of the classifier includes:

[0161] Obtain network training data samples; wherein the network training data samples are labeled network training data; wherein the labels include: known network attack type or binary classification result is normal;

[0162] Based on a preset loss function, the network training data samples, and a preset classification model, the training operation is repeatedly executed. When the loss function converges, the training operation is stopped, and a classifier is obtained. The training operation includes:

[0163] Select an untrained network training data sample as the target data sample;

[0164] The target data sample is input into the binary classifier in the classification model of the current model parameters to generate a binary classification result, and the probability that the binary classification result is abnormal is calculated based on the binary classification result; wherein, the binary classification result includes one of: normal or abnormal;

[0165] The target data sample is input into the multi-classifier in the classification model of the current model parameters to generate a predicted network attack type and calculate the predicted probability corresponding to each type of network attack.

[0166] The binary classification result, the probability that the binary classification result is an anomaly, and the predicted probability corresponding to each type of network attack are input into the loss function to calculate the loss function value; wherein the loss function includes:

[0167]

[0168] y bin ∈{0,1}

[0169]

[0170] ymulti ∈{1,2,…,K}

[0171]

[0172] In the formula, Let y be the value of the loss function. bin The binary classification result is labeled for the current sample, with 1 indicating normal and 0 indicating abnormal. Let α be the probability that the binary classification result is an anomaly, and y be the adjustable weight. multi The known network attack types labeled for the current sample. Let K be the predicted probability of the k-th type of network attack, where K is the number of network attack types. This is an indicator function, representing a value of 1 when the true class is k;

[0173] Determine whether the loss function value has converged;

[0174] If so, stop the training operation and output the classification model corresponding to the current model parameters;

[0175] If not, update the current model parameters, obtain the updated model parameters, use the updated model parameters as the model parameters for the next training operation, and execute the next training operation.

[0176] To evaluate the effectiveness of the proposed VG-ATBiGRU model (i.e., the classification model described in this invention) in identifying abnormal traffic during the network security situation assessment of power distribution systems, the evaluation metrics used in the embodiments are as follows:

[0177] True Positive (TP): This indicates the number of times a sample is predicted by the model as an attack sample and is indeed an attack sample.

[0178] False Positive (FP): The number of times a sample is predicted by the model as an attack sample but is actually a normal sample.

[0179] True Negative (TN): This refers to the number of times a sample is predicted by the model as a normal sample and is actually a normal sample.

[0180] False Negative (FN): This refers to the number of times a sample is predicted by the model as a normal sample but is actually an attack sample.

[0181] Accuracy (P) refers to the percentage of samples correctly predicted as attacks by the learning model out of the total number of samples predicted as attacks. It is expressed as:

[0182]

[0183] Recall (R) is the percentage of samples correctly predicted as attacks by the learning model out of the total number of samples that are true as attacks. It is expressed as:

[0184]

[0185] Accuracy refers to the proportion of samples correctly predicted by the learning model out of the total samples, and is expressed as:

[0186]

[0187] The F1 score (F1-score, F1), which takes into account both P and R, is an important indicator for measuring the detection performance of a model, and is expressed as:

[0188]

[0189] like Figure 2 As shown, based on the above method embodiments, corresponding apparatus embodiments are provided;

[0190] An embodiment of the present invention provides a power distribution network data processing device, including: a data acquisition module 201, a first data processing module 202, a second data processing module 203, a third data processing module 204, and a result generation module 205;

[0191] The data acquisition module is used to acquire network data of the power distribution system;

[0192] The first data processing module is used to input the network data into the variational autoencoder so that the variational autoencoder generates latent features based on the network data;

[0193] The second data processing module is used to input the latent features into the adversarial network model, so that the adversarial network model generates time series data based on the latent features;

[0194] The third data processing module is used to input the time series data into the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data;

[0195] The result generation module is used to generate a weighted feature representation based on the bidirectional hidden state, and to perform a security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result.

[0196] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention, and can implement the power distribution network data processing method provided by any of the above-described method embodiments of the present invention.

[0197] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can specifically be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0198] Based on the above embodiments of the power distribution network data processing method, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power distribution network data processing method of any embodiment of the present invention.

[0199] For example, in this embodiment, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the terminal device.

[0200] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.

[0201] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.

[0202] Based on the above-described method embodiments, another embodiment of the present invention provides a computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the power distribution network data processing method described in any of the above-described method embodiments of the present invention.

[0203] The modules / units integrated in the device / terminal equipment, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0204] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A method for processing power distribution network data, characterized in that, include: Obtain network data from the power distribution system; The network data is input into a variational autoencoder so that the variational autoencoder generates latent features based on the network data; The latent features are input into the adversarial network model, so that the adversarial network model generates time series data based on the latent features; The time series data is input into a bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data; Based on the bidirectional hidden state, a weighted feature representation is generated, and a security situation assessment of the power distribution system is performed based on the weighted feature representation to obtain the security situation assessment result.

2. The power distribution network data processing method as described in claim 1, characterized in that, The security situation assessment of the power distribution system based on the weighted feature representation, to obtain the security situation assessment result, includes: For each piece of network data, the weighted feature representation corresponding to each piece of network data is input into a classifier to calculate a network security situation value; wherein, the classifier includes a binary classifier and a multi-classifier; each weighted feature representation is input into the binary classifier to generate a network security judgment result corresponding to each weighted feature representation, and the network attack probability is calculated based on the network security judgment results corresponding to all network data; each weighted feature representation is input into the multi-classifier to generate a target network attack type corresponding to each weighted feature representation, and the impact value corresponding to the target network attack type is calculated; the network security situation value is calculated based on the network attack probability and the impact value corresponding to the target network attack type. Based on the network security situation value, the security situation assessment result of the power distribution system is determined.

3. The power distribution network data processing method as described in claim 2, characterized in that, The training of the classifier includes: Obtain network training data samples; wherein the network training data samples are labeled network training data; wherein the labels include: known network attack type or binary classification result is normal; Based on a preset loss function, the network training data samples, and a preset classification model, the training operation is repeatedly executed. When the loss function converges, the training operation is stopped, and a classifier is obtained. The training operation includes: Select an untrained network training data sample as the target data sample; The target data sample is input into the binary classifier in the classification model of the current model parameters to generate a binary classification result, and the probability that the binary classification result is abnormal is calculated based on the binary classification result; wherein, the binary classification result includes one of: normal or abnormal; The target data sample is input into the multi-classifier in the classification model of the current model parameters to generate a predicted network attack type and calculate the predicted probability corresponding to each type of network attack. The binary classification result, the probability that the binary classification result is an anomaly, and the predicted probability corresponding to each type of network attack are input into the loss function to calculate the loss function value; wherein the loss function includes: y bin ∈{0,1} and multi ∈{1,2,…,K} In the formula, Let y be the value of the loss function. bin The binary classification result is labeled for the current sample, with 1 indicating normal and 0 indicating abnormal. Let α be the probability that the binary classification result is an anomaly, and y be the adjustable weight. multi The known network attack types labeled for the current sample. Let K be the predicted probability of the k-th type of network attack, where K is the number of network attack types. This is an indicator function, representing a value of 1 when the true class is k; Determine whether the loss function value has converged; If so, stop the training operation and output the classification model corresponding to the current model parameters; If not, update the current model parameters, obtain the updated model parameters, use the updated model parameters as the model parameters for the next training operation, and execute the next training operation.

4. The power distribution network data processing method as described in claim 3, characterized in that, The step of inputting the network data into a variational autoencoder to generate latent features based on the network data includes: The network data is input into a variational autoencoder to generate a latent variable mean vector and a latent variable standard deviation vector. The variational autoencoder then substitutes the latent variable mean vector and the latent variable standard deviation vector into the latent space formula to obtain latent features. The latent space formula is as follows: In the formula, z represents the latent spatial variable, μ is the mean vector of the latent variable output by the variational autoencoder, σ is the standard deviation vector of the output latent variable, and ∈ is the random noise vector sampled from the standard normal distribution. It follows a standard normal distribution.

5. The power distribution network data processing method as described in claim 4, characterized in that, The adversarial network model includes a generator and a discriminator; the step of inputting the latent features into the adversarial network model to enable the adversarial network model to generate time series data based on the latent features includes: The latent features are input into the generator, so that the generator maps the latent features according to the multilayer perceptron to obtain initial time data; The initial time data and the network data are input into the discriminator so that the discriminator processes the initial data to obtain time series data.

6. The power distribution network data processing method as described in claim 5, characterized in that, The step of inputting the time series data into a bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data, includes: Time series data is input into the hidden state formula corresponding to the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a positive hidden state and a negative hidden state based on the time series data. The bidirectional gated loop unit determines the bidirectional hidden state based on the positive hidden state and the negative hidden state. The hidden state formula includes: In the formula, This represents the positive hidden state at time t-1. This represents the reverse hidden state at time t-1. Let be the positive hidden state at time t. Let x be the reverse hidden state at time t. t For time series data, h t Let t be the bidirectional hidden state, and GRU forward () is a positive gated loop function, GRU backward () is a reverse-gated loop function.

7. The power distribution network data processing method as described in claim 6, characterized in that, The step of generating a weighted feature representation based on the bidirectional hidden state includes: The bidirectional hidden state is substituted into the attention layer so that the attention layer obtains a weighted feature representation based on the weight calculation formula and the bidirectional hidden state; wherein, the weight calculation formula includes: In the formula, e t Here, `score()` is the attention score, `tanh()` is the scoring function, and `h` is the hyperbolic tangent activation function. t It is a two-way hidden state. W and b are learnable parameters of the attention layer, α t Let exp() be the importance weight at time step t, and let e be the exponential function. x One form of expression, where c represents the weighted feature representation.

8. A power distribution network data processing device, characterized in that, include: The system comprises a data acquisition module, a first data processing module, a second data processing module, a third data processing module, and a result generation module. The data acquisition module is used to acquire network data of the power distribution system; The first data processing module is used to input the network data into the variational autoencoder so that the variational autoencoder generates latent features based on the network data; The second data processing module is used to input the latent features into the adversarial network model, so that the adversarial network model generates time series data based on the latent features; The third data processing module is used to input the time series data into the bidirectional gated loop unit, so that the bidirectional gated loop unit generates a bidirectional hidden state based on the time series data; The result generation module is used to generate a weighted feature representation based on the bidirectional hidden state, and to perform a security situation assessment on the power distribution system based on the weighted feature representation to obtain a security situation assessment result.

9. A terminal device, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the power distribution network data processing method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, include: A stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the power distribution network data processing method as described in any one of claims 1-7.