Multi-agent cooperative control system and method for power grid key business

The multi-agent collaborative control system solves the problems of automated construction efficiency and security protection of digital twin models of smart grids, realizes high-fidelity grid simulation and active defense, and improves the resilience and security of grid operation.

CN121328128APending Publication Date: 2026-01-13ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511516386.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-22
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing technologies for building digital twin models of smart grids suffer from low automated construction efficiency, numerous human errors, poor dynamic adaptability, and security risks such as coordination failure, memory poisoning, and tool abuse in multi-agent systems, failing to meet the requirements for grid operation resilience, cybersecurity, and compliance.

Method used

A multi-agent collaborative control system is adopted, including a planning meta-agent, a configuration generation agent, a knowledge enhancement agent, a tool execution agent, and a fusion agent. Combined with a hierarchical security protection agent cluster, the system achieves task decomposition, resource constraints, and dynamic security protection through the ReAct inference framework, deontic logic, and game theory model.

Benefits of technology

It enhances the resilience of power grid operations, reduces the risk of large-scale power outages, accelerates fault recovery, enables proactive network defense, simplifies compliance processes, improves practical capabilities, optimizes asset management, and ensures the safety and reliability of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121328128A_ABST
    Figure CN121328128A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network physical systems, in particular to a power grid key service-oriented multi-agent cooperative control system and method, and the system is composed of a cooperative construction agent cluster and a hierarchical security protection agent cluster. Wherein the collaborative construction agent cluster comprises a planning element agent, a configuration generation agent, a knowledge enhancement agent, a tool execution agent and a fusion agent. And the planning meta-agent receives the natural language instruction to generate a sub-task instruction, and submits the sub-task instruction to a plurality of subsequent agents to construct a digital twinning scene according to the sub-task instruction. The hierarchical security protection agent cluster is composed of a coordinator, a deflector, a responder and an evaluator. Monitoring is carried out in the process of collaboratively constructing the agent cluster execution actions, and channel logic soft constraint check, resource hard constraint check and security event response are carried out on each execution action.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cyber-physical systems technology, and in particular to a multi-agent collaborative control system and method for power grid critical services. Background Technology

[0002] Currently, the methods for creating digital twins for complex systems such as smart grids mainly rely on manual modeling and configuration. This process is not only extremely time-consuming and labor-intensive, but also highly susceptible to human error. In the context of power grids, this means that engineers need to manually input tens of thousands of equipment ledger parameters, line topology relationships, and protection settings. This approach lacks automation and dynamic adaptability, making it difficult to keep up with the rapid evolution of the physical power grid (such as the commissioning of new lines and equipment replacement). Consequently, the consistency between the digital twin model and the physical entity is difficult to guarantee, and the reliability of its simulation results is significantly reduced.

[0003] The industry has begun exploring the application of artificial intelligence technologies such as large language models (LLMs) to assist power grid decision-making and dispatch. However, current single AI models cannot be applied to the complex tasks of building and optimizing digital twins of power plants.

[0004] Using multi-agent systems (MAS) for task decomposition and collaboration has become an important research direction. However, existing multi-agent systems still have the following technical shortcomings: 1. Collaboration Discrepancy and Systemic Risk: The efficient operation of multi-agent systems relies on explicit specifications and collaboration mechanisms. Without these mechanisms, task deviations or information concealment may occur. For example, if an agent responsible for modeling a substation fails to report its completion status in a timely and accurate manner, it may cause the fusion agent to initiate simulation on an incomplete power grid topology, leading to the systemic failure of the entire simulation task.

[0005] 2. Memory Poisoning and Privacy Leaks: Multi-agent systems typically rely on shared knowledge bases for collaboration. Attackers can inject corrupted data into this knowledge base through malicious agents, effectively "poisoning memories." For example, an attacker could tamper with a historical failure database, maliciously lowering the failure rate of a certain type of equipment. When evaluation agents conduct peak-season risk assessments based on this corrupted data, they may arrive at erroneously optimistic conclusions, leading to insufficient protection of truly high-risk equipment and creating significant security vulnerabilities. 3. Tool Abuse and Management Complexity: This is the highest level of risk. To complete its construction, a multi-agent system needs to invoke numerous external tools (such as interfaces with ROS2 and Unity3D). Attackers can use technical means to induce agents to unauthorizedly invoke high-privilege tools. For example, in a cybersecurity exercise, an attacker might induce a tool to execute an agent, using its privileges to maliciously modify the settings of critical relay protection devices in a digital twin environment. This would not only undermine the effectiveness of the exercise, but also pose a potential threat to the real security of the power grid, as the control of the entire virtual system would be applied to the actual physical system through the tool.

[0006] Currently, there is a lack of a comprehensive solution in the field that can simultaneously address the issues of automated construction efficiency and inherent security protection, failing to meet the multiple urgent needs of modern power grids in terms of operational resilience, cybersecurity, and compliance. Summary of the Invention

[0007] To overcome the problems existing in related technologies, the first aspect of this application provides a multi-agent cooperative control system for key power grid services, which constructs a digital twin scenario by collaboratively building an agent cluster. The collaborative construction of the agent cluster includes: The planning meta-agent is used to receive task instructions for building a digital twin scenario and to start the ReAct inference framework to decompose the task instructions into several sub-task instructions. Configure and generate an intelligent agent to generate configuration files and executable scripts for the digital twin model according to the subtask instructions; Knowledge-enhanced agents are a standard list of devices and configuration parameters used to provide digital twin models for tool-executing agents; The tool executes an intelligent agent to execute the configuration file and executable script in the digital twin environment to generate a digital twin model; A fusion agent is used to merge the digital twin model into a digital twin scene.

[0008] In one implementation, the collaborative construction of the intelligent agent cluster further includes: an intelligent agent evaluation module, used to evaluate the quality of the configured generated intelligent agents and assist the planning meta-intelligent agents in selecting the optimal task execution path and intelligent agent allocation scheme.

[0009] In one implementation, the system monitors the collaborative construction agent cluster through a hierarchical security protection agent cluster. The hierarchical security protection agent cluster is used to perform moral logic soft constraint checks, resource hard constraint checks, and security event responses during the execution of the tool execution agent.

[0010] In one implementation, the hierarchical security protection intelligent agent cluster consists of a coordinator, a deflector, a responder, and an evaluator. The deflector is used to monitor the execution actions of multiple agents and verify whether the actions of the agents meet preset constraints. The execution actions include message streams, API call requests, and tool usage requests. The coordinator is used to assess the security risk level of the execution action that does not meet the preset constraints, and select a combination of defense strategies. The responder is used to perform defensive actions based on a combination of defense strategies; The evaluator is used to assess the effectiveness of the defensive actions and update the parameters of the security agent.

[0011] In one implementation, the preset constraints include resource limitation constraints and standardized behavior constraints; The resource constraints are used to constrain the computational resources of the digital twin model and the computational resources of the digital twin environment.

[0012] In one implementation, for any digital twin scenario The digital twin model it carries The total required computing resources cannot exceed The total computing resource capacity, and the constraint function for constraining the computing resources of the digital twin model is:

[0013] in, Indicates the first The first digital twin model The utilization rate of various computing resources; Represent a binary variable, when Assigned to The value is 1 if it is true, and 0 otherwise. Indicates the first The first digital twin scenario The utilization rate of various computing resources.

[0014] In one implementation, for any digital twin scenario, the total resources required by all digital twin models within it cannot exceed the total capacity of the physical machine. The constraint function for the computational resources of the digital twin scenario is:

[0015] in, It is a binary variable, which is 1 when VEE j is activated in this DTS, and 0 otherwise. This represents the total capacity of computational resources in the m-th physical machine.

[0016] The second aspect of this application provides a multi-agent cooperative control method for key power grid services, including: In response to the task instruction to build a digital twin scenario, the planning meta-agent is invoked to obtain sub-task instructions; The knowledge-enhancing agent is invoked to generate the subtask instructions to search for a standard equipment list and configuration parameters for the digital twin model; The system calls a configuration-generating agent to generate configuration files and executable scripts based on the standard device list and configuration parameters of the digital twin model. The tool is invoked to execute the intelligent agent to generate a digital twin model based on the configuration file and executable script; The fusion agent is invoked to merge the digital twin model into a digital twin scene.

[0017] The technical solution provided in this application may include the following beneficial effects: 1. Enhanced operational resilience in response to high-impact events: By providing a high-fidelity virtual simulation environment for power grid operations, this system enables power grid operators to shift from passive response to proactive planning, identify and reinforce weak links in the power grid in advance, significantly reduce the risk of large-scale power outages, and safeguard public safety.

[0018] 2. Accelerated fault recovery and effective containment of cascading failures: This system can simulate the dynamic impact of a physical fault on the entire network in real time at the moment it occurs, especially predicting the evolution path of cascading failures. This buys dispatchers valuable decision-making time and can automatically generate optimal contingency plans, thereby effectively controlling the scope of the fault, significantly improving key power supply reliability indicators such as SAIDI and SAIFI, and preventing local faults from evolving into catastrophic system collapses.

[0019] 3. Achieved proactive network defense against Advanced Persistent Threats (APTs): This invention abandons the traditional passive security model based on fixed rules and innovatively introduces a game theory model. This model can dynamically predict and optimize strategies for intelligent and adaptive attack behaviors, elevating the defense system from a reactive "lockdown" approach to a strategic level of "proactive deterrence," effectively protecting the power grid OT system from the most complex network threats.

[0020] 4. Simplified compliance processes and enhanced personnel's practical skills: As a secure, isolated, and highly simulated "network range," this system provides a perfect solution for meeting the mandatory emergency drill requirements of regulations such as "Level Protection Scheme 2.0." It not only generates drill records that meet audit requirements, reducing compliance costs, but also allows cybersecurity teams to conduct intensive practical training in a "zero-risk" environment, greatly improving their ability to respond to real-world network physical attacks.

[0021] 5. High-fidelity predictive maintenance optimizes full lifecycle asset management: The digital twin constructed by this system is not only a reproduction of the power grid topology, but also a deep simulation of the physical characteristics of key equipment (such as transformers and circuit breakers). By performing more accurate predictive maintenance simulations on this twin model, the remaining lifespan of equipment can be predicted more accurately, and maintenance strategies can be optimized, thereby reducing the full lifecycle operation and maintenance costs while ensuring reliability.

[0022] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0023] The above and other objects, features and advantages of this application will become more apparent from the more detailed description of exemplary embodiments thereof in conjunction with the accompanying drawings, wherein the same reference numerals generally represent the same components in the exemplary embodiments thereof.

[0024] Figure 1 This is a schematic diagram of the intelligent agent cluster architecture of the system shown in the embodiments of this application; Figure 2 This is a schematic diagram of the intelligent agent workflow of the system shown in the embodiment of this application. Detailed Implementation

[0025] Preferred embodiments of the present application will now be described in more detail with reference to the accompanying drawings. While preferred embodiments of the present application are shown in the drawings, it should be understood that the present application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to make the present application more thorough and complete, and to fully convey the scope of the present application to those skilled in the art.

[0026] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0027] It should be understood that although the terms "first," "second," "third," etc., may be used in this application to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.

[0028] Example 1 To construct digital twin scenarios for power grid operations and simulate power grid tasks through these scenarios, embodiments of this application provide a method such as... Figure 1 and Figure 2 The diagram shows a multi-agent collaborative control system for key power grid operations.

[0029] The system architecture is divided into three core layers: the physical layer, the digital twin environment layer, and the multi-agent control plane.

[0030] Understandably, the physical layer represents the actual infrastructure of the Southern Power Grid, including ultra-high voltage transmission lines for the West-to-East Power Transmission Project, substations at all levels, urban power distribution networks, smart meters, and related SCADA systems, among other physical entities.

[0031] The digital twin environment layer is a virtualized simulation environment of the physical layer. It uses the Unity3D engine as a platform for rendering digital twin models and digital twin scenes. This layer interacts with the multi-agent control plane through a secure application programming interface (API) and a standardized toolset.

[0032] The multi-agent control plane includes a collaborative construction agent cluster and a hierarchical security protection agent cluster. The collaborative construction agent cluster is responsible for executing the automated construction task of the digital twin, while the hierarchical security protection agent cluster is responsible for end-to-end security monitoring and protection of the entire construction process.

[0033] The collaborative construction of intelligent agent clusters includes: 101. A planning meta-agent is used to receive task instructions for constructing a digital twin scenario and to start the ReAct inference framework to decompose the task instructions into several sub-task instructions.

[0034] The planning meta-agent employs a hierarchical task decomposition and allocation mechanism to ensure the orderly and efficient flow of tasks. The specific decomposition steps are as follows: 10. Task Decomposition: When a high-level construction goal (e.g., "Construct a digital twin of the 110kV substation in area A") is submitted to the system, the planning meta-agent intervenes first. This agent utilizes the ReAct framework to progressively decompose the ambiguous natural language goal into a detailed, structured task plan graph through a "think-act-observe" cycle. This graph defines all necessary sub-tasks (e.g., "Modeling main transformer T1", "Defining the 35kV bus topology", "Configuring protection relay R5"), as well as their dependencies and execution order.

[0035] 20. Task Allocation: The task allocation process follows the Contract Net Protocol. The planning meta-agent acts as the "Manager" in this protocol. For each subtask to be assigned in the task plan graph, the Manager broadcasts a "Call for Proposals" to the entire agent network. The call for proposals details the task's objectives, input requirements, output format, and completion deadline.

[0036] 30. Bidding and Selection: Configuration-generating agents act as "Bidders," evaluating their own capabilities based on bidding notices. If a configuration-generating agent believes it is competent for the task, it submits a "Bid" to the administrator. The Bid includes the estimated time required to complete the task, computational resources, and a confidence score of its own execution capabilities. The evaluation agent assists the administrator in analyzing all received Bids, selecting the most suitable agent based on predefined optimization objectives (such as lowest cost, shortest time, or highest reliability), and signing a "Contract" with it.

[0037] This process ensures that tasks are assigned to the most suitable executors, achieving optimal resource allocation.

[0038] In one implementation, step 30 can evaluate the configuration generation agents participating in the bidding by evaluating the quality of the configuration generation agents, and assist the planning meta-agent in selecting the optimal task execution path and agent allocation scheme.

[0039] Specifically, the evaluation agent evaluates the configuration-generating agent using a total cost function. For example, the total cost function is:

[0040]

[0041] in, It is about building a scene. The direct cost is the sum of the operating costs of all VEEs within the scene and the idle costs of the scene itself. It is an accuracy penalty function. It quantifies the deviation between the key performance indicators (such as power flow calculation results, short-circuit current, etc.) of the completed digital twin model (DTS) and the measured data of the physical power grid or an authoritative benchmark model. The larger the deviation, the higher the penalty value. It is a security penalty function. It quantifies the cost of security events that occur during the construction process, such as the number of security agent interventions, detected policy violations, and performance overhead caused by security measures. and These are configurable weighting coefficients that allow system administrators to adjust the level of emphasis on accuracy and security based on the specific needs of the task. For example, when building a twin for critical decision support, the weighting can be increased. .

[0042] By incorporating accuracy and security penalties into the objective function, this invention transforms the digital twin construction problem from a simple resource minimization problem into a multi-objective optimization problem that balances efficiency, quality, and security. This causes multi-agent systems to inherently favor more accurate and secure choices when making decisions (such as selecting which agent to perform a task or which modeling method to use), thereby achieving higher-quality automated construction.

[0043] 102. Configure and generate an intelligent agent to generate configuration files and executable scripts for the digital twin model according to the subtask instructions.

[0044] 103. Knowledge-enhancing agents: a standard list of devices and configuration parameters for providing digital twin models of tool-executing agents.

[0045] Specifically, agent A begins the task of "modeling the substation." It first queries the knowledge-enhanced agent for the standard equipment list and configuration parameters for this type of substation. The knowledge-enhanced agent retrieves accurate information from its internal power equipment knowledge base using RAG technology and returns it to agent A, effectively avoiding knowledge illusions.

[0046] 104. The tool executes an intelligent agent to execute the configuration file and executable script in the digital twin environment to generate a digital twin model.

[0047] Specifically, the tool execution agent is responsible for calling the Unity3D scene API to interact with the digital twin environment layer and securely execute instructions and scripts created by the configuration generation agent.

[0048] 105. A fusion agent, used to fuse the digital twin model into a digital twin scene.

[0049] As each configuration-generating agent completes its subtasks, it submits the generated and verified Digital Tag Analyses (DTAs) (such as substation models and line models) to the fusion agent. Following the moral logic rule "O(FusionAgent, verify_consistency)," the fusion agent must perform rigorous consistency and interface compatibility checks on these DTAs before integrating them into the final digital twin scenario (DTS). For example, it checks whether the outgoing line voltage of the substation model matches the voltage level of the connected line model. After all components are successfully integrated and pass the final overall functional test, the fusion agent reports the completion of the entire construction task to the planning meta-agent. The system ultimately outputs a high-fidelity, internally consistent, and securely verified smart grid digital twin environment.

[0050] Furthermore, the system disclosed in this application embodiment also monitors the collaborative construction intelligent agent cluster through a hierarchical security protection intelligent agent cluster. The hierarchical security protection intelligent agent cluster is used to perform moral logic soft constraint checks, resource hard constraint checks, and security event responses during the execution of the tool execution intelligent agent.

[0051] Specifically, the hierarchical security protection intelligent agent cluster consists of a coordinator, a deflector, a responder, and an evaluator.

[0052] 201. The deflector is used to monitor the actions of multiple agents and verify whether the actions of the agents meet preset constraints. The actions include message streams, API call requests, and tool usage requests.

[0053] As the decision-making core of the security system, the deflector and coordinator are responsible for macro-level threat situation awareness and defense strategy formulation. It receives alerts from other security agents, comprehensively assesses the overall security risk of the current system, and determines the appropriate level of defense posture. In the game theory model, the coordinator plays the role of "leader," responsible for selecting the optimal combination of defense strategies.

[0054] To ensure the standardization and controllability of the behavior of intelligent agents in complex collaborations, this invention defines two types of preset constraints: hard constraints and soft constraints.

[0055] Hard constraints (resource limits): These are inviolable rules based on upper limits of physical and computational resources, ensuring the stable operation of the system. Their formal expression is borrowed from resource constraints: DTA to VEE allocation constraints: For any VEE All DTAs it carries The total CPU resources required cannot exceed Total CPU capacity.

[0056]

[0057] in It is a binary variable, which is 1 when DTA k is assigned to VEE, and 0 otherwise. Similar constraints also apply to other resources such as memory and network bandwidth.

[0058] VEE to DTS assignment constraints: For any DTS All VEE inside The total amount of resources required cannot exceed Total capacity.

[0059]

[0060] in It is a binary variable that is 1 when VEE j is activated in the DTS, and 0 otherwise.

[0061] Soft constraints (normative behavior): These constraints define the "correct" behavioral guidelines that agents should follow in collaboration, aiming to fundamentally prevent the "multi-agent collaboration misalignment" problem described above. This invention innovatively employs deontic logic to formally describe these social and normative behaviors. Deontic logic provides a precise mathematical language to express normative concepts such as obligations, permissions, and prohibitions, thereby transforming vague collaboration requirements into machine-verifiable logical rules.

[0062] Obligation (O): An agent must perform an action or achieve a certain state. Formalized as O( , ).

[0063] Application Example: To prevent the "information concealment" problem that may arise from agents mentioned earlier, the system can stipulate: "O(ConfigAgent_i, report_status(task_j, 'completed'))". This rule means that after configuring and generating agent i completes task j, it is obligated to report its "completed" status to the planning meta-agent.

[0064] Permission (P): An agent is allowed to perform a certain action. Formalized as P( , ).

[0065] Application Example: To implement the principle of least privilege, the system can stipulate this: "P(KnowledgeAgent_k,access_tool(RAG_interface))". This stipulation means that the knowledge-enhancing agent k is permitted to access the RAG interface to retrieve knowledge, but is not permitted to access other tools, such as the execution interface of ROS2.

[0066] Prohibition (F): An agent must never perform a certain action. Formalized as F( , ).

[0067] Application Example: To ensure separation of responsibilities and prevent the evaluation process from affecting the construction results, the system stipulates: "F(EvalAgent_m, modify_asset(DTA_n))". This rule means that the evaluation agent m is prohibited from modifying the configuration of any digital twin asset n.

[0068] These soft constraints based on moral logic are encoded as the core governance rules of the system. The deflector agent in the hierarchical security framework continuously monitors the behavior of all agents and uses a logical reasoning engine to verify whether their behavior violates these rules. Once a violation is detected (e.g., an agent fails to report a violation), the system triggers the appropriate security response. In this way, the present invention transforms high-level cooperation principles into computable and enforceable constraints, providing a solid mathematical foundation for reliable cooperation in multi-agent systems.

[0069] 202. The coordinator is used to assess the security risk level of the execution action that does not meet the preset constraints, and select a combination of defense strategies.

[0070] To effectively counter intelligent and adaptive adversaries, the security framework of this invention models the interaction between the defender (security system) and potential attackers as a Bayesian Stackelberg game. This model transcends static, rule-based defense, transforming security protection into a dynamic, strategic confrontation based on rational decision-making.

[0071] Game participants: Leader / Defender: Played by the Coordinator.

[0072] Follower / Attacker: An abstract entity representing all potential sources of threat.

[0073] Game structure: A two-stage sequential game.

[0074] Phase 1: The coordinator (leader) first commits to and announces a hybrid defense strategy. This strategy is a set of defensive actions. The probability distribution on, for example, ={Low-intensity monitoring, high-intensity monitoring, deep API validation, restricting tool access}, one possible strategy is =(0.6⋅Low monitoring, 0.3⋅High monitoring, 0.1⋅Deep verification). This randomization makes defensive actions unpredictable to attackers.

[0075] Phase Two: The attacker (follower) observes the defense strategy Subsequently, from its attack action set Choose the best response from {no attack, memory poisoning, tool abuse, coordinated attack}. In order to maximize its own expected utility.

[0076] Bayesian elements (incomplete information): The key to the game lies in information asymmetry. The coordinator cannot know exactly what type of attacker 't' it is currently facing. It only possesses a set of beliefs about the potential attacker types T = {insider, external hacker, script kiddie}, i.e., a prior probability distribution. Different types of attackers possess different resources, motivations, and skill levels, and therefore have different utility functions. .

[0077] Optimization objective: The coordinator's objective is to compute and execute an optimal hybrid defense strategy. This strategy maximizes its weighted average expected utility across all possible attacker types. Its optimization problem is formalized as follows:

[0078] in, An attacker of type t observes the defense strategy. The best response action taken afterward. It is the defender's utility function, which takes into account the value of successfully building a digital twin, the losses caused by a security incident, and the cost of implementing defensive measures.

[0079] Utility Function and Payoff Matrix: Utility Function and It is quantified based on specific scenarios. For example, It can be defined as: ,in It is the value that has been successfully built. It's the cost of defense. This represents the loss if the attack is successful. The table below provides a simplified example of a payoff matrix, where each cell contains tuples. These represent the gains for the defender and the attacker, respectively.

[0080] Table 1: Game Theory Models

[0081] By solving the game theory model in Table 1, the coordinator can make strategically deep decisions that go beyond simple rules. For example, even in the absence of clear signs of attack, the model may suggest maintaining a certain level of high-intensity surveillance to deter potential high-capability attackers. This is further demonstrated when the evaluator updates its beliefs about the attacker type based on new intelligence. Then, the coordinator will recalculate and adjust its defense strategy to achieve true adaptive security.

[0082] 203. The responder is used to execute defensive actions according to the defense strategy combination; 204. The evaluator is used to evaluate the effectiveness of the defensive action and update the parameters of the security agent.

[0083] For example, the hierarchical security protection intelligent agent cluster responds to an attack as follows: 1. An external attacker successfully infiltrated and gained control of a tool execution agent C within the network. The attacker attempted to use this controlled agent to invoke a network scanning tool (such as nmap) to probe the network topology within the digital twin environment.

[0084] 2. Agent C sends a request to the tool execution interface to invoke nmap. However, according to the moral logic rule "P(ToolExecAgent, allowed_tools_list)", nmap is not in agent C's list of permitted tools.

[0085] 3. The deflector agent intercepts this abnormal request at the API call level, determines it as a high-risk unauthorized behavior, and immediately reports the alert to the coordinator.

[0086] 4. Upon receiving the alarm, the coordinator immediately initiates its Bayesian Stackelberg game model to make a decision. At this point, its internal belief model regarding the attacker type... This may assign a low but not zero probability to attackers of the "Advanced Persistent Threat (APT)" type. Model calculations indicate that, faced with this low-probability, high-impact potential threat, the optimal strategy is not to immediately isolate agent C (which could be a false alarm leading to business disruption), but rather to upgrade the defense level to high-intensity monitoring.

[0087] 5. The coordinator issues instructions. The deflector adjusts its strategy and begins deep packet inspection of all incoming and outgoing network traffic for agent C. The responder is activated and isolates and stores all logs and traffic data related to agent C for auditing purposes.

[0088] 6. The evaluator begins analyzing this newly captured data in real time. If more suspicious attack signatures are found in subsequent traffic (such as communication with known C&C servers), the evaluator will update the coordinator's belief model, significantly improving the probability estimate of the APT attacker type. The coordinator receives the updated beliefs and recalculates the game. The optimal strategy at this point might become isolating the suspicious agent. The responder then executes the instruction, disconnecting agent C from the main network and triggering a rollback procedure to undo all its recent actions.

[0089] Example 2 Corresponding to the system in Embodiment 1, this application provides a multi-agent cooperative control method for key power grid services, which generates a digital twin scenario based on the various agents in Embodiment 1, including the following steps: 301. In response to the task instruction to build a digital twin scenario, call the planning meta-agent to obtain sub-task instructions; 302. Invoke the knowledge-enhancing intelligent agent to generate the standard equipment list and configuration parameters for the subtask instruction to search the digital twin model; 303. Invoke configuration to generate intelligent agents, generating configuration files and executable scripts based on the standard device list and configuration parameters of the digital twin model; 304. The tool is invoked to execute the intelligent agent to generate a digital twin model based on the configuration file and executable script; 305. Invoke the fusion agent to fuse the digital twin model into a digital twin scene.

[0090] The solution of this application has been described in detail above with reference to the accompanying drawings. In the above embodiments, the descriptions of each embodiment have different emphases; parts not described in detail in a certain embodiment can be referred to in the relevant descriptions of other embodiments. Those skilled in the art should also understand that the actions and modules involved in the specification are not necessarily essential to this application. Furthermore, it is understood that the steps in the method of this application embodiment can be adjusted, combined, and deleted according to actual needs, and the modules in the device of this application embodiment can be combined, divided, and deleted according to actual needs.

[0091] Furthermore, the method according to this application can also be implemented as a computer program or computer program product, which includes computer program code instructions for performing some or all of the steps in the method described above.

[0092] Alternatively, this application may be implemented as a non-transitory machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium) storing executable code (or computer program, or computer instruction code) thereon, which, when executed by a processor of an electronic device (or electronic device, server, etc.), causes the processor to perform part or all of the steps of the methods described above according to this application.

[0093] Those skilled in the art will also understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the present application can be implemented as electronic hardware, computer software, or a combination of both.

[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems and methods according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0095] The various embodiments of this application have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or improvement of the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A multi-agent cooperative control system for key power grid operations, characterized in that, Digital twin scenarios are constructed by collaboratively building intelligent agent clusters. The collaborative construction of intelligent agent clusters includes: The planning meta-agent is used to receive task instructions for building a digital twin scenario and to start the ReAct inference framework to decompose the task instructions into several sub-task instructions. Configure and generate an intelligent agent to generate configuration files and executable scripts for the digital twin model according to the subtask instructions; Knowledge-enhanced agents are a standard list of devices and configuration parameters used to provide digital twin models for tool-executing agents; The tool executes an intelligent agent to execute the configuration file and executable script in the digital twin environment to generate a digital twin model; A fusion agent is used to merge the digital twin model into a digital twin scene.

2. The multi-agent cooperative control system as described in claim 1, characterized in that, The collaborative construction of the intelligent agent cluster also includes: The agent evaluation module is used to evaluate the quality of the agents generated by the configuration and assist the planning meta-agent in selecting the optimal task execution path and agent allocation scheme.

3. The multi-agent cooperative control system as described in claim 1, characterized in that, The hierarchical security protection intelligent agent cluster monitors the collaboratively constructed intelligent agent cluster, which is used to perform moral logic soft constraint checks, resource hard constraint checks, and security event responses on the execution process of the intelligent agents.

4. The multi-agent cooperative control system as described in claim 3, characterized in that, The hierarchical security protection intelligent agent cluster consists of a coordinator, a deflector, a responder, and an evaluator. The deflector is used to monitor the execution actions of multiple agents and verify whether the actions of the agents meet preset constraints. The execution actions include message streams, API call requests, and tool usage requests. The coordinator is used to assess the security risk level of the execution action that does not meet the preset constraints, and select a combination of defense strategies. The responder is used to perform defensive actions based on a combination of defense strategies; The evaluator is used to assess the effectiveness of the defensive actions and update the parameters of the security agent.

5. The multi-agent cooperative control system as described in claim 4, characterized in that, The preset constraints include resource limitation constraints and standardized behavior constraints; The resource constraints are used to constrain the computational resources of the digital twin model and the computational resources of the digital twin environment.

6. The multi-agent cooperative control system as described in claim 5, characterized in that, For any digital twin scenario The digital twin model it carries The total required computing resources cannot exceed The total computing resource capacity, and the constraint function for constraining the computing resources of the digital twin model is: in, Indicates the first The first digital twin model The utilization rate of various computing resources; Represent a binary variable, when Assigned to The value is 1 if it is true, and 0 otherwise. Indicates the first The first digital twin scenario The utilization rate of various computing resources.

7. The multi-agent cooperative control system as described in claim 5, characterized in that, For any digital twin scenario, the total resources required by all digital twin models within it cannot exceed the total capacity of the physical machine. The constraint function for the computational resources of the digital twin scenario is: in, It is a binary variable, which is 1 when VEE j is activated in this DTS, and 0 otherwise. This represents the total capacity of computational resources in the m-th physical machine.

8. A multi-agent cooperative control method for key power grid operations, characterized in that, include: In response to the task instruction to build a digital twin scenario, the planning meta-agent is invoked to obtain sub-task instructions; The knowledge-enhancing agent is invoked to generate the subtask instructions to search for a standard equipment list and configuration parameters for the digital twin model; The system calls a configuration-generating agent to generate configuration files and executable scripts based on the standard device list and configuration parameters of the digital twin model. The tool is invoked to execute the intelligent agent to generate a digital twin model based on the configuration file and executable script; The fusion agent is invoked to merge the digital twin model into a digital twin scene.