Power grid security defense system based on artificial intelligence and block chain
The seven-layer power grid security defense system, combined with AI detection and blockchain evidence storage, has achieved a closed-loop defense and deep collaboration throughout the entire lifecycle of the power grid system. This has solved the problems of high false data injection and equipment backdoor attacks, as well as delayed response, thereby improving the power grid's security defense capabilities and resource utilization.
Patent Information
- Application Number
- CN202511432574.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Existing power grid defense systems suffer from problems such as a disconnect between detection and tracing, loose technical coordination, and passive resource scheduling when facing complex threats. They are unable to meet the security requirements of complex scenarios, especially in the case of false data injection and device backdoor attacks, where the false judgment rate is high, the response is slow, and the resource allocation is unreasonable.
The power grid security defense system adopts a seven-layer modular coupling architecture, integrating AI dynamic detection, blockchain trusted evidence storage, attack tracing and attribution, virtual and real verification, scenario adaptation and risk prediction functions. Through multi-source data collection, feature engineering, multi-model fusion, reputation-weighted consensus, reinforcement learning and other technologies, it achieves full-cycle defense closed loop, deep collaboration and risk prediction and computing power scheduling.
It reduced the false alarm rate of attacks, improved the efficiency of defense response and resource utilization, shortened the attack response time, enhanced the power grid's resistance to attacks and resource utilization, and achieved efficient power grid security defense.
Smart Images

Figure CN121333665A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power system security, and in particular to a power grid security defense system based on artificial intelligence and blockchains. BACKGROUND
[0002] Under the background of deep integration of the "physical-digital" dual system, false data injection, device backdoor attacks and other complex threats occur frequently. The existing defense technology is difficult to meet the security needs of complex scenarios due to "non-closed loop of chain, insufficient cooperation, and inflexible scheduling". The core shortcoming is embodied in three aspects:
[0003] First, the defense chain is broken, and the disconnection of "detection-verification-tracing" leads to high risk of defense failure. Existing AI detection solutions are mostly operated in isolation. For example, the technical solution disclosed in the patent No. "CN119939351A" and entitled "Self-learning defense method, device, equipment, storage medium and program product for artificial intelligence model backdoor attack of power system" only improves the detection robustness by cleaning digital data features, without correlating physical features such as device vibration and temperature. When an attacker forges normal digital data but causes physical overload (such as sudden temperature rise of the conductor), the false positive rate will be too high. Moreover, the attack tracing of existing solutions is disconnected from detection, and only the operation and maintenance data can be stored. The AI model cannot be optimized based on the tracing results, resulting in strong lag in detection response when similar attacks occur repeatedly, and lacking a closed-loop optimization mechanism of "detection-verification-tracing".
[0004] Second, the technical cooperation is loose, and AI and blockchain have not formed a defense synergy. Blockchain is mostly used as a single storage tool and has not been deeply integrated into the defense process. In traditional solutions, AI detection results are only uploaded to blockchain storage in one direction, and the attack history data (such as time period distribution and type characteristics) stored cannot support the dynamic adjustment of AI model weights in the reverse direction. In the face of high-frequency false data attacks, fixed weight detection is still used, resulting in low recognition rate. Moreover, the smart contract function is limited and can only trigger simple alarms, and cannot perform "risk warning-algorithm scheduling" operations. The value of blockchain's credibility support has not been converted into defense effectiveness, forming a technical island.
[0005] Third, resource scheduling is passive, and there is a lack of risk prediction and algorithm adaptation linkage. The existing system has no pre-incident risk prediction capability, and although it can adaptively adjust the operating parameters, it does not integrate attack history time series characteristics, and cannot identify high-risk scenarios such as thunderstorm weather and peak load in advance. Moreover, the algorithm allocation is static and rigid: in high-risk periods (such as summer peak electricity consumption), the demand for AI detection increases, and fixed algorithm leads to increased detection delay, while in low-risk periods, the algorithm is redundant. At the same time, scene adaptation relies on manual intervention. The attack modes of transmission grids and microgrids are significantly different (transmission grids are vulnerable to electrical parameter attacks, and microgrids are vulnerable to communication attacks), but parameter adjustment takes several hours, and the parameter adaptation lags behind the evolution of attacks. SUMMARY
[0006] In order to solve the above problems of the prior art, the present application provides a power grid security defense system based on artificial intelligence and blockchain, which integrates AI dynamic detection, blockchain credible evidence storage, attack tracing, virtual-real verification, scene adaptation, risk prediction and computing power scheduling functions, and realizes the collaborative operation of attack identification, data storage, defense response, traceability, virtual-real verification, scene adaptation, risk warning and computing power adaptation.
[0007] In order to achieve the above purpose, the technical scheme adopted by the present application is: a power grid security defense system based on artificial intelligence and blockchain, comprising an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scene adaptive configuration layer and a risk prediction module, seven-layer architecture modular coupling interworking;
[0008] The AI defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity module, and identifies attacks by fusing time series, deep learning and anomaly detection models, and protects itself through pre-filtering and incremental training;
[0009] The blockchain trust layer adopts a consortium chain architecture, verifies and stores evidence data through reputation weighted consensus, automatically responds through a smart contract, stores attack history data on the chain, and encrypts and protects privacy;
[0010] The collaborative control layer synchronizes and verifies data of each layer, and generates defense and computing power strategies combined with multi-dimensional information;
[0011] The attack tracing and attribution layer constructs a three-dimensional link graph, generates a time period labeled traceability evidence package and chains it for attribution;
[0012] The physical-information fusion verification layer collects physical characteristics, fuses digital characteristics for verification, and verifies the adaptability of instructions through digital twinning;
[0013] The scene adaptive configuration layer generates a scene portrait and adjusts parameters and computing power base distribution through reinforcement learning;
[0014] The risk prediction module integrates risk factors to predict risks, assesses period risks through attack history analysis and schedules computing power.
[0015] The beneficial effects of the present application are: first, it breaks through the pain points of "detection isolation and no feedback for traceability", and builds a full-cycle defense closed loop. Existing AI detection only relies on digital data and is disconnected from traceability. This scheme associates device physical characteristics through the physical-information fusion verification layer, reduces the attack misjudgment rate from 18% to below 2%; the attack tracing and attribution layer generates a time period labeled evidence package and chains it, providing trusted data for the risk prediction module, reducing the response time for repeated detection of similar attacks from 10 seconds to 50 milliseconds, and realizing a "detection-verification-tracing-optimization" closed loop.
[0016] Second, to solve the problem of technical island and realize the deep cooperation between AI and blockchain. The existing blockchain only stores evidence, and the blockchain trust layer of the present scheme verifies the AI detection results through reputation weighted consensus (delay ≤ 100 ms), and the intelligent contract linkage defense scheduling, which improves the defense response efficiency by 40% compared with the traditional scheme. At the same time, the on-chain attack history data reversely optimizes the AI model weight, and the attack recognition rate increases from 72% to more than 98% in high-risk periods.
[0017] Third, break the limitation of "static scheduling" and realize the linkage of risk prediction and computing power adaptation. The existing system has no early warning and fixed computing power, and the risk prediction module of the present scheme integrates multi-factor risk prediction to schedule computing power 300 ms in advance, which reduces the detection delay by 30% in high-risk periods and reduces the computing power redundancy from 55% to less than 20% in low-risk periods. The scene adaptive configuration layer automatically adjusts the parameters to adapt to the period from hours to minutes, which greatly improves the anti-attack ability of the power grid and the resource utilization rate.
[0018] Optionally, the multi-source data acquisition module of the AI defense layer integrates voltage transformers, current transformers and state monitoring sensors to collect power grid equipment operation data, communication flow data and environmental parameters through the MQTT protocol. The feature engineering module extracts time series features using empirical mode decomposition and selects attack-related features using attention mechanism to output 64-256 dimensional feature vectors. The multi-model fusion detection module includes parallel LSTM network, CNN network and isolation forest model, which outputs detection results through weighted voting fusion, and the weight is dynamically adjusted based on the historical detection accuracy of each model. The model immune module identifies abnormal data with backdoors through a pre-filter, uses integrated learning to incrementally train the model, and regularly updates the parameters.
[0019] From the above description, in the prior art, power grid data acquisition is mostly single frequency and the feature extraction accuracy is low, which leads to poor quality of AI model input data and high attack recognition misjudgment rate. The present scheme integrates multiple types of sensors to cover power grid operation, communication flow and environmental parameters, which greatly improves the data dimension compared with the traditional scheme. At the same time, combined with empirical mode decomposition and attention mechanism, 64-256 dimensional attack-related features are selected to eliminate redundant information and improve feature extraction accuracy. In addition, multi-model dynamic weight fusion and regular incremental training solve the problems of poor adaptability of traditional fixed weight and model update lag, which improves the attack detection response speed and reduces the backdoor attack misjudgment rate.
[0020] Optionally, the blockchain trust layer adopts a consortium chain architecture, the nodes include a power grid dispatching center, a transformer substation and a third-party audit node, and the number of nodes is not less than 5; the reputation weighted consensus module adopts a PBFT algorithm, a reputation value is calculated based on a historical behavior credibility of the nodes and a real-time detection contribution, and a voting weight is positively correlated with the reputation value; the smart contract module includes six contracts of attack response, model update, permission freezing, configuration storage, risk warning and computing power scheduling, and respectively implements functions of node isolation, parameter storage, account disabling, configuration recording, resource pre-scheduling and computing power allocation; and the privacy encryption module adopts an encryption scheme, and only an AI model is authorized to decrypt and extract features.
[0021] As can be known from the above description, the existing blockchain has problems of high consensus delay (more than 200 ms), low node participation and single contract function in the power grid scenario, and cannot adapt to real-time defense requirements. The scheme adopts a consortium chain architecture with not less than 5 nodes, covers a dispatching center, a transformer substation and an audit node, and guarantees data credibility; the PBFT consensus algorithm is improved to introduce node reputation weighting, voting rights are allocated based on historical behavior and detection contribution, and consensus delay is compressed to ≤100 ms, with an efficiency improvement of 50% compared with a traditional PBFT. Meanwhile, multiple types of smart contracts are expanded to realize automatic operations such as attack response and model update, solve the problem of response lag caused by traditional manual triggering, and shorten the execution time of defense instructions to within 20 ms.
[0022] Optionally, the cross-layer interface module of the collaborative control layer adopts a RESTful API, converts detection results, traceability data, verification results, risk prediction results and computing power requirements into a key-value pair format readable by the blockchain, and generates a verification hash through SHA-256 before data transmission; the defense decision module is built-in a decision tree model, outputs a defense priority and a computing power allocation scheme based on attack types, influence ranges, power grid load states, virtual-real verification results, risk prediction levels and attack history period risk levels, the priority is divided into four levels of early warning pre-scheduling, emergency isolation, flow limiting protection and alarm prompt, and the computing power allocation is calculated according to “multi-model weight proportion x risk level coefficient”.
[0023] As can be known from the above description, the existing system has non-uniform cross-layer data formats, resulting in low information interaction efficiency, and the defense decision only depends on single-dimensional data, with poor strategy accuracy. The scheme realizes standardized conversion of cross-layer data by using a RESTful API, reduces the data transmission error rate by combining SHA-256 hash verification, and improves the interaction efficiency; the defense decision module is built-in a decision tree model, fuses multi-dimensional information such as attack types and risk levels, and outputs a four-level defense priority and a computing power allocation scheme, solving the problem of traditional single decision dimension. The computing power calculation logic of “multi-model weight proportion x risk level coefficient” improves the utilization rate of computing power in a high-risk period, avoiding resource waste or deficiency.
[0024] Optionally, the attack traceability and attribution layer integrates a graph neural network and a traffic traceability algorithm into the attack link analysis module, constructs a "device-data-communication" three-dimensional attack link graph based on the attack features output by the AI defense layer, and generates a traceability evidence package containing "attack initiation timestamp, propagation node hash, feature matching check value, and occurrence period label" through an improved Merkle tree structure. The intelligent attribution contract module has an attribution decision model built in, matches the traceability evidence package with the operation and maintenance and operation records stored in the blockchain, and outputs the attribution result.
[0025] As can be seen from the above description, existing attack traceability relies on simple traffic analysis, link restoration accuracy is low, and attribution lacks credible evidence, making it difficult to identify responsibility. The present scheme integrates a graph neural network GNN and a traffic traceability algorithm, constructs a "device-data-communication" three-dimensional attack link graph, and combines AI defense layer attack features, with a link restoration accuracy of ≥95%, an increase of more than 15% over traditional solutions. An improved Merkle tree is used to generate a traceability evidence package containing multi-dimensional information, which is stored in a chain to ensure tamper resistance. An intelligent attribution contract matches operation and maintenance records, reducing attribution time and solving the problems of low efficiency and untrustworthy evidence in traditional manual attribution, providing a reliable basis for attack responsibility identification.
[0026] Optionally, the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer, which obtain device vibration frequency, shell temperature and other physical characteristics through edge computing nodes, and the sampling frequency is synchronized with the digital data. The virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors and dynamically adjusts the attack confidence based on the fusion result. The digital twin linkage verification module inputs physical data into a twin model to simulate the impact of defense instructions on physical devices.
[0027] As can be seen from the above description, existing technologies only rely on digital data detection and lack physical feature verification, making them vulnerable to "digital camouflage-physical anomaly" attacks, and there is no verification of the physical adaptability of defense instructions. The present scheme adds vibration, infrared and other sensors to collect device vibration frequency, temperature and other physical characteristics, with the sampling frequency synchronized with the digital data, achieving "digital-physical" dual-dimensional data coverage. The virtual-real feature fusion verification module adjusts the attack confidence through an attention mechanism, and the digital twin simulation verifies the impact of defense instructions, greatly reducing the error rate of verification, solving the problem of traditional single digital detection errors, improving the accuracy of attack confidence correction, and improving the success rate of defense instruction execution.
[0028] Optionally, the scene feature profiling module of the scene adaptive configuration layer adopts the K-means clustering algorithm to generate four types of scene profiles—transmission network, distribution network, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration contract and verification module records parameter changes through configuration storage contracts, and the changes take effect after the accuracy rate is verified by digital twins to exceed a preset value.
[0029] As described above, existing scenario adaptation relies on manual parameter adjustments, which is time-consuming (over several hours) and has low accuracy, failing to address the diverse attack scenarios across different environments. This solution employs the K-means algorithm to generate four scenario profiles, covering core scenarios such as power transmission networks and microgrids, achieving high profile matching accuracy. The dynamic configuration engine optimizes AI model weights, consensus thresholds, and other parameters through reinforcement learning. Changes to configuration contract records take effect only after digital twin verification, shortening the adaptation cycle to minutes and resolving the inefficiency of traditional manual adaptation. Simultaneously, adjusting the basic computing power allocation ratio improves the attack recognition rate for each scenario, addressing the issue of delayed scenario adaptation.
[0030] Optionally, the risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. The attack precursor factor comes from the feature data of the AI defense layer, the equipment health factor comes from the historical verification data of the physical state perception module, the power grid operation factor comes from the load and voltage data stored on the blockchain, and the environmental interference factor comes from the temperature, humidity and electromagnetic interference data collected by the sensor. The risk factor vector is generated in 32-64 dimensions after Z-score standardization.
[0031] As described above, existing risk prediction methods rely on a single attack factor, resulting in limited dimensions and low data reliability, leading to insufficient prediction accuracy. This solution categorizes risk factors into four types, derived from AI defense layers, physical verification layers, blockchain evidence storage, and sensor data, achieving full-dimensional coverage of "attack-device-operation-environment," increasing the factor dimensionality several times compared to traditional methods. Through Z-score standardization, it eliminates data dimension differences, generating 32-64 dimensional standardized vectors, improving data consistency. This design addresses the limitations of traditional single-factor prediction, providing high-quality input for subsequent spatiotemporal graph Transformer predictions and enhancing the reliability of the underlying risk prediction data.
[0032] Optionally, the spatiotemporal graph Transformer prediction module uses the power grid topology as a graph structure, takes the risk factor vector as the graph node feature, and integrates the risk evolution law in the time dimension with the equipment correlation in the spatial dimension through the spatiotemporal attention mechanism to output four results: "attack occurrence probability, operation failure risk value, impact radius, and early warning lead time". The risk-defense linkage module interacts with the collaborative control layer through the risk early warning contract to trigger computing power pre-allocation, load pre-transfer, or pre-isolation according to the risk level.
[0033] As described above, existing risk prediction methods lack spatiotemporal correlation analysis, have insufficient early warning lead time, and are disconnected from defense coordination. This solution uses the power grid topology as a graph structure, integrating temporal risk evolution with spatial device correlation, and outputs four core prediction results, improving accuracy and increasing early warning lead time to ≥300ms, thus shortening the warning time. The risk-defense linkage module triggers operations such as computing power pre-allocation and load transfer according to risk level, with reduced linkage response time, solving the traditional "prediction-defense" disconnect problem, reserving sufficient defense windows for high-risk attacks, and improving attack blocking rate.
[0034] Optionally, the attack history time-series analysis and computing power pre-scheduling module retrieves attack history data from the blockchain for the most recent preset time period, including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". A time-series attention LSTM model is used to learn the correlation patterns and output three levels of risk level results for low, medium, and high time periods. The computing power requirement is calculated by combining the basic computing power allocation ratio and the risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.
[0035] As described above, existing computing power scheduling lacks historical attack time-series analysis support and employs a fixed allocation model, resulting in insufficient computing power during high-risk periods and redundancy during low-risk periods. This solution utilizes recent historical attack data, constructing a dataset based on "scenario-time period-attack type." A time-series attention LSTM model outputs a three-level risk level; computing power requirements are calculated based on the risk level coefficient, triggering a computing power scheduling contract to dynamically allocate resources. During high-risk periods, priority is given to ensuring computing power for core models, resulting in shorter scheduling response times. This design reduces detection latency during high-risk periods and minimizes computing power redundancy during low-risk periods, improving resource utilization and resolving the rigidity problem of traditional computing power scheduling. Attached Figure Description
[0036] Figure 1 This is a structural block diagram of a power grid security defense system based on artificial intelligence and blockchain according to the present invention. Detailed Implementation
[0037] To better explain and facilitate understanding of the present invention, it is described in detail below with reference to the accompanying drawings and specific embodiments. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a clearer and more thorough understanding of the invention and to fully convey the scope of the invention to those skilled in the art.
[0038] Example 1
[0039] Please refer to Figure 1 As shown, a power grid security defense system based on artificial intelligence and blockchain includes an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module. The seven-layer architecture is modular, coupled, and interconnected.
[0040] The AI defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity modules. It integrates time series, deep learning and anomaly detection models to identify attacks and protects itself through pre-filtering and incremental training.
[0041] The blockchain trust layer adopts a consortium blockchain architecture, verifies and stores evidence data through reputation-weighted consensus, responds automatically through smart contracts, stores historical attack data on-chain, and encrypts and protects privacy.
[0042] The collaborative control layer synchronizes and verifies data from each layer, and generates defense and computing power strategies by combining multi-dimensional information.
[0043] The attack tracing and attribution layer constructs a three-dimensional link graph, generates a tracing evidence package with time period labels, and uploads it to the blockchain for attribution.
[0044] The physical-information fusion verification layer collects physical features, fuses digital features for verification, and uses digital twins to verify instruction adaptability.
[0045] The scene adaptive configuration layer generates a scene profile and adjusts parameters and computing power allocation through reinforcement learning.
[0046] The risk prediction module integrates risk factors to predict risks, assesses the risk of a given period through historical attack analysis, and allocates computing power accordingly.
[0047] The AI defense layer includes a multi-source data acquisition module that integrates voltage transformers, current transformers, and status monitoring sensors. It collects power grid equipment operation data, communication traffic data, and environmental parameters via the MQTT protocol, with a sampling frequency selectable from 50-200Hz. The feature engineering module extracts temporal features using empirical mode decomposition and filters attack-related features using an attention mechanism, outputting 64-256 dimensional feature vectors. The multi-model fusion detection module includes parallel LSTM networks, CNN networks, and isolated forest models. It outputs detection results through weighted voting fusion, with weights dynamically adjusted based on the historical detection accuracy of each model. The model immunity module identifies abnormal data with backdoors through a pre-filter, uses ensemble learning to incrementally train the model, and updates parameters periodically (e.g., every 24 hours).
[0048] The blockchain trust layer adopts a consortium blockchain architecture, with at least five nodes including the power grid dispatch center, substations, and third-party audit nodes. The reputation-weighted consensus module uses the PBFT algorithm to calculate reputation values based on the credibility of nodes' historical behavior and their real-time detection contributions, with voting weights positively correlated with reputation values. The smart contract module includes six contracts: attack response, model update, permission freezing, configuration notarization, risk warning, and computing power scheduling, which respectively implement node isolation, parameter notarization, account disabling, configuration recording, resource pre-scheduling, and computing power allocation functions. The privacy encryption module uses an encryption scheme (which may employ an ECC elliptic curve-based encryption algorithm) and only authorizes AI models to decrypt and extract features.
[0049] The cross-layer interface module of the collaborative control layer adopts a RESTful API to convert detection results, traceability data, verification results, risk prediction results, and computing power requirements into a blockchain-readable key-value pair format. Before data transmission, a verification hash is generated using SHA-256. The defense decision module has a built-in decision tree model that outputs defense priorities and computing power allocation schemes based on attack type, impact range, power grid load status, virtual and real verification results, risk prediction level, and risk level of historical attack periods. Priorities are divided into four levels: early warning pre-scheduling, emergency isolation, flow limiting protection, and alarm prompts. Computing power allocation is calculated according to "multi-model weight ratio × risk level coefficient".
[0050] The attack chain analysis module of the attack tracing and attribution layer integrates graph neural networks and traffic tracing algorithms, and constructs a three-dimensional attack chain graph of "device-data-communication" based on the attack features output by the AI defense layer; the blockchain tracing certificate generation module generates a tracing evidence package containing "attack initiation timestamp, propagation node hash, feature matching verification value, and occurrence time label" by improving the Merkle tree structure; the intelligent attribution contract module has a built-in attribution decision model, matches the tracing evidence package with the operation and maintenance records stored on the blockchain, and outputs the attribution result.
[0051] The physical state perception module of the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer. It acquires physical characteristics such as device vibration frequency and shell temperature through edge computing nodes, and the sampling frequency is synchronized with the digital data. The virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors and dynamically adjusts the attack confidence based on the fusion result. The digital twin linkage verification module inputs physical data into the twin model to simulate the impact of defense commands on physical devices.
[0052] The scene feature profiling module of the scene adaptive configuration layer uses the K-means clustering algorithm to generate four types of scene profiles—transmission network, distribution network, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration contract and verification module records parameter changes through configuration storage contracts, and the changes take effect after the accuracy rate is verified by digital twins and exceeds a preset value. The preset value can be set according to needs, and is preferably 97%.
[0053] The risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. Attack precursor factors come from AI defense layer feature data, equipment health factors come from historical verification data of the physical state perception module, power grid operation factors come from load and voltage data stored on the blockchain, and environmental interference factors come from temperature, humidity, and electromagnetic interference data collected by sensors. The risk factors are then standardized by Z-score to generate 32-64 dimensional risk factor vectors.
[0054] The spatiotemporal graph Transformer prediction module uses the power grid topology as a graph structure and risk factor vectors as graph node features. It integrates the risk evolution law in the time dimension and the equipment correlation in the spatial dimension through a spatiotemporal attention mechanism, and outputs four results: "attack occurrence probability, operational failure risk value, radius of influence, and early warning lead time". The prediction accuracy is ≥93% and the early warning lead time is ≥300ms. The risk-defense linkage module interacts with the collaborative control layer through risk early warning contracts, and triggers computing power pre-allocation, load pre-transfer or pre-isolation according to the risk level. The linkage response time is ≤50ms.
[0055] The attack history time-series analysis and computing power pre-scheduling module retrieves attack history data from the blockchain for the most recent preset time period (e.g., the last 6 months), including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". A time-series attention LSTM model is used to learn the correlation patterns and output three levels of risk level results: low, medium, and high. The matching accuracy of the level results is ≥94%. The computing power requirement is calculated by combining the basic computing power allocation ratio and the risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.
[0056] The distributed ledger module of the blockchain trust layer adopts a hybrid on-chain and off-chain storage. The original data is stored in the IPFS system, while the on-chain storage includes data hashes, metadata, scene profile hashes, risk factor hashes, and attack history time sequence hashes. It supports full lifecycle data traceability with a traceability response time of ≤5s.
[0057] Existing blockchains store all raw data, resulting in significant on-chain data redundancy, slow traceability response times (over 10 seconds), and a lack of full lifecycle data traceability. This solution employs a hybrid on-chain / off-chain storage approach. The raw data is stored using IPFS, while only key information such as hashes and metadata is stored on-chain, reducing on-chain data volume by 70%. It supports full lifecycle traceability from data collection to destruction, and combined with SHA-256 hash verification, achieves 100% data reliability with a traceability response time of ≤5 seconds, significantly improving overall storage efficiency. Simultaneously, it stores hashes for scenario profiles and risk factors, providing a reliable index for data retrieval at each layer and resolving storage redundancy and traceability lag issues.
[0058] The multi-model fusion detection module of the AI defense layer also includes a Few-Shot learning model, which is connected in parallel with LSTM, CNN, and isolated forest models. When the risk prediction module outputs "high probability unknown attack (e.g., probability ≥ 80%, staff can set the probability value according to actual needs)," the weight of the Few-Shot model is automatically increased to 0.4-0.5. The unknown attack is identified by using a small number of samples from the attack feature map. The attack feature map includes three core feature dimensions: attack data format, traffic mutation mode, and physical parameter abnormal threshold.
[0059] Existing multi-model fusion lacks the ability to identify unknown attacks and is less effective against mutated attacks (such as novel fake data injection). This solution adds a Few-Shot learning model, which is connected in parallel with the original model. When predicting "high-probability unknown attacks," the model weights are automatically increased to 0.4-0.5, achieving unknown attack identification with a small number of attack feature map samples. This design addresses the deficiency of traditional models that rely on a large number of labeled samples, improves the unknown attack identification rate, shortens the identification response time, fills the gap in existing technology for defending against unknown mutated attacks, and enhances the system's adaptability to new attacks.
[0060] Please refer to Figure 1 As shown, the seven-layer architecture uses the collaborative control layer as its central core for information interaction. It forms a closed-loop flow with the core logic of "data acquisition - preprocessing - analysis and prediction - decision scheduling - execution feedback - evidence storage and iteration." Each layer has a clear division of labor yet deep collaboration. The collaborative control layer, as the "nerve center" of the architecture, is responsible for information aggregation, format conversion, verification synchronization, and policy distribution from all layers. All cross-layer information interactions are standardized through its cross-layer interface module (using RESTful API and SHA-256 hash verification) to ensure data consistency and reliability. The interaction process of each layer is as follows:
[0061] Phase 1: Basic Data Collection and Preprocessing (Upward Aggregation of Lower-Level Data)
[0062] AI Defense Layer → Collaborative Control Layer: The power grid operation / communication traffic / environment data collected by the multi-source data acquisition module are processed into 64-256 dimensional feature vectors by the feature engineering module and then synchronously transmitted to the collaborative control layer; at the same time, the real-time detection results (including attack type and confidence level) of the multi-model fusion detection module are also pushed to the collaborative control layer in real time.
[0063] Physical-Information Fusion Verification Layer → Collaborative Control Layer: Physical state perception module collects physical characteristic data such as equipment vibration / temperature / insulation resistance, which are then pre-processed and transmitted to the collaborative control layer to form a "virtual-real data pair" with the digital characteristics of the AI defense layer.
[0064] 2. Second Phase: Risk Prediction and Computing Power Scheduling (Multi-dimensional data converges to the risk prediction module, and prediction results are distributed downwards)
[0065] Collaborative Control Layer → Risk Prediction Module: The feature vectors of the AI defense layer and the physical feature data of the physical layer are synchronously pushed to the risk factor fusion module of the risk prediction module; at the same time, the current scene label (from the scene adaptive configuration layer) and real-time time period information are transmitted to the risk prediction module.
[0066] Blockchain Trust Layer → Risk Prediction Module: The attack history time sequence analysis and computing power pre-scheduling module of the risk prediction module calls recent (default setting is the last 6 months) attack history data (including time period, type, computing power demand tags) from the distributed ledger of the blockchain for time period risk level assessment.
[0067] Risk Prediction Module → Collaborative Control Layer: Outputs two types of core results: ① "Attack Probability / Risk Value / Early Warning Lead Time" generated by the Spatiotemporal Graph Transformer Prediction Module; ② "Time Period Risk Level + Computing Power Pre-allocation Requirement Table" generated by the Attack History Time Series Analysis Module, both of which are pushed to the defense decision module of the collaborative control layer.
[0068] 3. Third Phase: Defense Decision-Making and Cross-Layer Scheduling (Coordinating the Control Layer to Issue Instructions to the Functional Layer)
[0069] Collaborative Control Layer → AI Defense Layer: Based on risk prediction results, the defense decision module generates a computing power allocation plan and dynamically allocates computing power to the multi-model fusion detection module of the AI defense layer through a computing power scheduling contract (blockchain trust layer) (such as increasing the computing power ratio of CNN / Few-Shot models during high-risk periods).
[0070] Collaborative Control Layer → Attack Tracing and Attribution Layer: When the confidence level of the AI defense layer's detection result is greater than or equal to the threshold (or the risk prediction level is greater than or equal to high risk), the collaborative control layer sends "attack characteristics + preliminary location information" to the attack tracing and attribution layer, triggering the link analysis and attribution process.
[0071] Collaborative Control Layer → Scenario Adaptive Configuration Layer: Pushes the current attack type, risk level, and power grid load status to the scenario adaptive configuration layer to dynamically adjust the scenario profile parameters and basic computing power allocation ratio.
[0072] 4. Fourth Phase: Virtual-to-Real Verification and Attack Tracing (Inter-functional Layer Interaction and Result Feedback)
[0073] Attack tracing and attribution layer → Blockchain trust layer: The 3D link diagram generated by the attack link analysis module and the attribution results output by the smart attribution contract are packaged into a "source tracing evidence package" and uploaded to the blockchain. The evidence is verified through the reputation-weighted consensus module. The hash of the verified evidence package is synchronously fed back to the collaborative control layer.
[0074] Physical-Information Fusion Verification Layer → AI Defense Layer: The collaborative control layer synchronously pushes the detection results of the AI defense layer and the feature data of the physical layer to the virtual-real feature fusion verification module. After fusion, it outputs the "attack confidence correction value" and feeds it back to the AI defense layer to optimize the detection model weights.
[0075] Physical-Information Fusion Verification Layer → Collaborative Control Layer: The digital twin linkage verification module performs physical adaptability simulation on the defense commands (such as node isolation and load transfer) issued by the collaborative control layer, outputs the "command execution feasibility result", and feeds it back to the collaborative control layer.
[0076] 5. Fifth Stage: Defense Execution and Evidence Iteration (Execution Result Evidence Storage, Data Closed-Loop Feedback)
[0077] Collaborative control layer → Blockchain trust layer: The final defense strategy (such as node isolation, computing power adjustment), execution results (such as attack blocking rate), and digital twin verification certificate are all uploaded to the blockchain and stored through smart contracts to form a trusted chain of "instruction-execution-result".
[0078] Blockchain Trust Layer → Scenario Adaptive Configuration Layer: Historical defense data and attack characteristic data stored on the blockchain are periodically synchronized to the scenario feature profile module of the scenario adaptive configuration layer to update scenario profiles such as power grids / microgrids and optimize parameter adjustment logic.
[0079] Each layer → Collaborative Control Layer (Closed-Loop Feedback): Operational data such as the detection time of the AI defense layer, the verification error of the physical layer, and the attribution time of the attack tracing layer are summarized to the collaborative control layer every hour and pushed to the risk prediction module for incremental model training, so as to achieve self-optimization of the architecture.
[0080] Example 2
[0081] Building upon Example 1, the power grid security defense system based on artificial intelligence and blockchain will be applied to a specific scenario: defense against combined attacks involving collaborative spoofing of data and physical overload on the power transmission network. Details are as follows:
[0082] I. Prerequisites for Scenario and System Deployment
[0083] ① Application scenario: A section of a 220kV transmission network, including 5 substations and 8 transmission lines, with daily load fluctuations of 30%-70%. Historical data shows that severe weather periods (thunderstorms / strong winds) account for 68% of the load. Currently, it is summer thunderstorm weather at 16:30 (peak load).
[0084] ② Seven-layer architecture deployment:
[0085] AI defense layer: Deploy 15 smart sensors (voltage / current transformers + status monitors), initial weights for multiple models: LSTM 0.35, CNN 0.4, Isolation Forest 0.15, Few-Shot 0.1, and basic computing power allocation and weight matching.
[0086] Blockchain Trust Layer: A consortium blockchain consisting of a power grid dispatch center, 5 substations, and 3 third-party audit nodes is constructed. PBFT is improved so that the threshold for the number of consensus nodes is 70% of the total number of nodes, and 120 attack history data records from the past 6 months are stored.
[0087] Collaborative control layer: cross-layer interface synchronization period 50ms; defense decision model computing power allocation coefficient: low risk 0.8, medium risk 1.2, high risk 1.6.
[0088] Attack tracing and attribution layer: A three-dimensional topology map of the power grid "substation-line-terminal" is preset, and the GNN model training samples contain 80,000 attack link data;
[0089] Physical-information fusion verification layer: Vibration sensors and insulator pollution sensors are deployed on the transmission line, with a physical feature sampling frequency of 200Hz, and the digital twin model includes parameters related to line current carrying capacity and temperature;
[0090] Scenario-adaptive configuration layer: Matches the "power grid scenario profile" (dispersed equipment, large load fluctuations, communication latency ≤60ms, and composite attacks accounting for 68%), with the following basic computing power allocation: CNN 40% and LSTM 35%;
[0091] Risk prediction module: The risk factor contains 18 features, the time series LSTM model has 100,000 training samples, and the current weather is labeled "thunderstorm" and the time period is 16:30.
[0092] II. Seven-Layer Architecture Full Process Execution Steps
[0093] Step 1: Attack History Time Sequence Analysis and Computing Power Pre-Scheduling (Risk Prediction Module + Blockchain Trust Layer + Collaborative Control Layer)
[0094] ① The attack history time sequence analysis and computing power pre-scheduling module of the risk prediction module calls the attack history data of the past 6 months of thunderstorm weather from 16:00 to 17:00 through the distributed ledger interface of the blockchain trust layer (a total of 32 records, with composite attacks accounting for 75%).
[0095] ② After Z-score standardization, the data is input into the temporal attention LSTM model, and combined with the current "power grid - thunderstorm - 16:30" scenario time period information, the output is "high risk" level (attack probability 68%).
[0096] ③ The module combines the basic computing power allocation ratio of the scene adaptive configuration layer (CNN 40%, LSTM 35%), adjusts the relative computing power ratio of each model according to the high-risk coefficient of 1.6, calculates the computing power requirement, and generates a computing power allocation table;
[0097] ④ The allocation table is uploaded to the defense decision module via the cross-layer interface (RESTful API + SHA-256 verification) of the collaborative control layer, triggering the computing power scheduling contract of the blockchain trust layer to dynamically allocate computing power to the multi-model fusion detection module of the AI defense layer. The scheduling response takes 38ms.
[0098] Step 2: Multi-source data acquisition and risk factor fusion (AI defense layer + physical-information fusion verification layer + risk prediction module)
[0099] ① The multi-source data acquisition module of the AI defense layer collects power grid data through the MQTT protocol: line A voltage deviation 5.9%, current distortion rate 8%, communication traffic surge 150%, sampling frequency 200Hz;
[0100] ② The physical state perception module of the physical-information fusion verification layer synchronously collects physical characteristics: the vibration frequency of the line A insulator is 3.2Hz (normal ≤1.5Hz), the pollution degree is 0.8 (normal ≤0.3), and the conductor temperature is 68℃ (normal ≤55℃). After preprocessing by the edge computing node, the data is transmitted to the collaborative control layer.
[0101] ③ The collaborative control layer pushes the raw data from the AI defense layer and the physical layer feature data to the risk factor fusion module of the risk prediction module. The module classifies the factors into four categories: “attack precursors (voltage deviation / communication traffic), equipment health (vibration / pollution), power grid operation (current / temperature), and environmental interference (thunderstorm weather)”, and generates a 64-dimensional risk factor vector through Z-score standardization.
[0102] Step 3: Risk Prediction and Early Warning Trigger (Risk Prediction Module + Collaborative Control Layer + Blockchain Trust Layer)
[0103] ① The risk factor vector is input into the spatiotemporal graph Transformer prediction module of the risk prediction module. Using the transmission network topology as the graph structure, the module integrates the "risk evolution trend within 10 minutes" and the "substation-line correlation" through the spatiotemporal attention mechanism, and outputs the prediction results: the probability of a collaborative false data injection + physical overload composite attack is 72%, the operational failure risk value is 0.78, the affected area is 2 substations, and the early warning lead time is 340ms.
[0104] ② The prediction results are synchronized to the blockchain trust layer through the collaborative control layer, and consensus verification is completed through the reputation-weighted consensus module (improved PBFT algorithm) (6 / 11 nodes confirm), with a consensus delay of 85ms. The verified results are stored on the blockchain.
[0105] ③ The risk prediction module's risk-defense linkage module triggers the risk warning contract of the blockchain trust layer, sends a "high-risk warning" signal to the collaborative control layer, and initiates the pre-scheduling of defense resources: pre-activating backup line B and pre-allocating 30% of edge computing power to the detection module.
[0106] Step 4: Feature Engineering and Multi-Model Fusion Detection (AI Defense Layer + Collaborative Control Layer)
[0107] ①The feature engineering module of the AI defense layer processes the collected data: it uses empirical mode decomposition to extract 128-dimensional time-series features of voltage / current, and combines the attention mechanism to filter attack-related features (voltage deviation rate, flow change slope, etc.), and outputs a 256-dimensional feature vector.
[0108] ②Feature vector input has been adapted to the computing power of the multi-model fusion detection module, and the parallel models are computed synchronously:
[0109] LSTM network: Identifies fake data injection patterns based on temporal features, with an output confidence level of 89%;
[0110] CNN network: Identifies physical overload precursors based on spatial features (multi-node data correlation), with an output confidence level of 91%;
[0111] Few-Shot model: Based on 10 composite attack samples from the attack feature map, the output confidence level is 87%;
[0112] Isolation Forest Model: Identifies abnormal deviations in data, outputting a confidence level of 82%;
[0113] ③ The module merges the results through weighted voting (weights: CNN 0.64, LSTM 0.56, Few-Shot 0.16, Isolation Forest 0.04) and outputs the detection result of "cooperative fake data injection + physical overload composite attack" with a confidence level of 93% and a detection time of 21ms.
[0114] The detection results are fed back to the model immune module via the collaborative control layer. The module confirms that there is no backdoor data contamination through the pre-filter (GAN-generated adversarial example training) and marks it as a valid detection result.
[0115] Step 5: Virtual-Real Feature Fusion Verification (Physical-Information Fusion Verification Layer + Collaborative Control Layer)
[0116] ① The collaborative control layer synchronously pushes the detection results of the AI defense layer and the physical feature data of the physical-information fusion verification layer to the virtual-real feature fusion verification module;
[0117] ② The module uses an attention mechanism to fuse digital features (voltage deviation / current distortion) and physical features (vibration / temperature / dirtiness) to calculate a correlation matching degree of 92% (≥ threshold 80%), thereby improving the attack confidence to 97%.
[0118] ③ The collaborative control layer triggers the digital twin linkage verification module of the physical-information fusion verification layer, inputting the current physical data (conductor temperature 68℃, vibration 3.2Hz) into the twin model to simulate the execution effect of the "node isolation + load transfer" defense command: after the load transfer, the conductor temperature drops to 52℃, the vibration recovers to 1.3Hz, the verification error rate is 1.2% (≤2%), and a verification certificate is generated. The "verification error rate" is calculated as "absolute deviation between simulated value and physical measured value / physical measured value". Under normal scenarios, the verification error rate needs to be ≤2%, while under special scenarios, the verification error rate can be fine-tuned through the scenario adaptive configuration layer.
[0119] Step 6: Attack Origin and Attribution (Attack Origin and Attribution Layer + Blockchain Trust Layer + Collaborative Control Layer)
[0120] ① The collaborative control layer sends "detection results + confidence level + verification certificate" to the attack tracing and attribution layer, triggering the attack chain analysis module;
[0121] ② The module integrates GNN and traffic tracing algorithm. Based on the attack characteristics (fake data format / traffic source IP) of the AI defense layer and the preset topology map, it constructs a three-dimensional attack link map of "external IP → communication node C → substation 2 → line A", with a link reconstruction accuracy of 96%.
[0122] ③ The blockchain traceability certificate generation module adopts an improved Merkle tree structure to generate a traceability evidence package containing "attack initiation timestamp 16:30:02 - propagation node hash - feature matching verification value - time period label 16:30". After being verified by the consensus of the blockchain trust layer, the evidence is stored on the blockchain.
[0123] ④ The intelligent attribution contract module matches the traceability evidence package with the blockchain-stored operation and maintenance records (no personnel operation from 16:00 to 16:30) and the equipment firmware logs (the firmware of substation 2 has not been updated for 3 months), and outputs the attribution result: an external malicious attack was launched by exploiting a vulnerability in the equipment firmware. The attribution took 8 seconds.
[0124] Step 7: Defense Decision-Making and Execution (Collaborative Control Layer + Blockchain Trust Layer + AI Defense Layer + Physical-Information Fusion Verification Layer)
[0125] ① The defense decision module of the collaborative control layer inputs multi-dimensional information: attack type (composite attack), scope of impact (2 substations), grid load (70%), virtual and real verification results (confidence level 97%), risk level (high risk), and attribution results (external attack). It then outputs a defense strategy through a decision tree model.
[0126] Priority: Emergency isolation;
[0127] Operation 1: Disconnect the connection switch between line A and substation 2;
[0128] Operation 2: Transfer the load (120MW) of line A to the standby line B;
[0129] Operation 3: Increase the AI defense layer's detection computing power to 70%;
[0130] ② The strategy is sent to the blockchain trust layer via the cross-layer interface, triggering the attack response contract and automatically executing the contact switch disconnection and load transfer operations, which takes 18ms;
[0131] ③ The physical-information fusion verification layer collects data in real time after execution: the current of line A returns to zero, the voltage of line B stabilizes, and the conductor temperature drops to 51℃, and feeds it back to the collaborative control layer to confirm that the defense is effective;
[0132] ④ The collaborative control layer synchronizes the defense strategy, execution results, and verification credentials to the blockchain trust layer, and forms a complete and trustworthy chain by configuring the evidence storage contract for on-chain evidence storage.
[0133] Step 8: Scene Adaptation and Model Iteration (Scene Adaptive Configuration Layer + Risk Prediction Module + Blockchain Trust Layer)
[0134] ① The blockchain trust layer synchronizes the “feature data + defense parameters + execution effect” of this attack to the scene feature profile module of the scene adaptive configuration layer, and updates the scene profile of “power grid - thunderstorm weather”: the proportion of composite attacks increases by 70% and the high-risk period is extended to 16:00-17:30;
[0135] ② The dynamic configuration engine module uses a reinforcement learning optimizer to match the updated scene profile and adjust parameters: the basic weight of the CNN model is increased to 0.45, the consensus threshold is maintained at 70%, and the basic computing power allocation ratio is updated synchronously. After the accuracy rate is verified by digital twin to be 98% (≥97%), the configuration is put on the chain through the notarization contract.
[0136] ③ The collaborative control layer summarizes the operational data of each layer: detection time 21ms, computing power utilization 68%, attribution time 8s, and pushes it to the risk prediction module to trigger incremental training of the attack history time series analysis module and optimize the risk assessment model for each period.
[0137] III. Summary of Key Process Indicators and Hierarchical Linkages
[0138]
[0139] As can be seen, this invention takes the collaborative control layer as the central hub, the risk prediction module drives the pre-scheduling of computing power, the AI defense layer and the physical verification layer realize "digital-physical" dual verification, the attack tracing layer relies on blockchain to complete credible attribution, and finally achieves self-optimization of the architecture through the scenario adaptation layer, forming a complete closed loop of "prediction-detection-verification-tracing-decision-execution-iteration".
[0140] Since the systems / devices described in the above embodiments of the present invention are systems / devices used to implement the methods of the above embodiments of the present invention, those skilled in the art can understand the specific structure and modifications of the systems / devices based on the methods described in the above embodiments of the present invention, and therefore will not be repeated here. All systems / devices used in the methods of the above embodiments of the present invention fall within the scope of protection of the present invention.
[0141] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0142] It should be noted that, in the description of this specification, the terms "one embodiment," "some embodiments," "embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0143] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the claims should be interpreted to include both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0144] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, then this invention should also include these modifications and variations.
Claims
1. A power grid security defense system based on artificial intelligence and blockchain, characterized in that, It includes an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module. The seven-layer architecture is modular, coupled, and interconnected. The AI defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity modules. It integrates time series, deep learning and anomaly detection models to identify attacks and protects itself through pre-filtering and incremental training. The blockchain trust layer adopts a consortium blockchain architecture, verifies and stores evidence data through reputation-weighted consensus, responds automatically through smart contracts, stores historical attack data on-chain, and encrypts and protects privacy. The collaborative control layer synchronizes and verifies data from each layer, and generates defense and computing power strategies by combining multi-dimensional information. The attack tracing and attribution layer constructs a three-dimensional link graph, generates a tracing evidence package with time period labels, and uploads it to the blockchain for attribution. The physical-information fusion verification layer collects physical features, fuses digital features for verification, and uses digital twins to verify instruction adaptability. The scene adaptive configuration layer generates a scene profile and adjusts parameters and computing power allocation through reinforcement learning. The risk prediction module integrates risk factors to predict risks, assesses the risk of a given period through historical attack analysis, and allocates computing power accordingly.
2. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The AI defense layer's multi-source data acquisition module integrates voltage transformers, current transformers, and status monitoring sensors. It collects power grid equipment operation data, communication traffic data, and environmental parameters via the MQTT protocol. The feature engineering module extracts temporal features using empirical mode decomposition and filters attack-related features using an attention mechanism, outputting 64-256 dimensional feature vectors. The multi-model fusion detection module includes parallel LSTM networks, CNN networks, and isolated forest models. It outputs detection results through weighted voting fusion, with weights dynamically adjusted based on the historical detection accuracy of each model. The model immunity module identifies anomalous data with backdoors through a pre-filter, uses ensemble learning to incrementally train the model, and updates the parameters regularly.
3. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The blockchain trust layer adopts a consortium blockchain architecture, with at least five nodes including the power grid dispatch center, substations, and third-party audit nodes. The reputation-weighted consensus module uses the PBFT algorithm to calculate reputation values based on the credibility of nodes' historical behavior and their real-time detection contributions, with voting weights positively correlated with reputation values. The smart contract module includes six contracts: attack response, model update, permission freezing, configuration notarization, risk warning, and computing power scheduling, which respectively implement node isolation, parameter notarization, account disabling, configuration recording, resource pre-scheduling, and computing power allocation functions. The privacy encryption module uses an encryption scheme, authorizing only the AI model to decrypt and extract features.
4. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The cross-layer interface module of the collaborative control layer adopts RESTful API to convert detection results, traceability data, verification results, risk prediction results and computing power requirements into a blockchain-readable key-value pair format. Before data transmission, a verification hash is generated using SHA-256. The defense decision module has a built-in decision tree model. Based on the attack type, scope of impact, power grid load status, virtual and real verification results, risk prediction level and risk level of historical attack periods, it outputs defense priorities and computing power allocation schemes. Priorities are divided into four levels: early warning pre-scheduling, emergency isolation, flow limiting protection and alarm prompts. Computing power allocation is calculated according to "multi-model weight ratio × risk level coefficient".
5. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The attack chain analysis module of the attack tracing and attribution layer integrates graph neural networks and traffic tracing algorithms, and constructs a three-dimensional attack chain graph of "device-data-communication" based on the attack features output by the AI defense layer; the blockchain tracing certificate generation module generates a tracing evidence package containing "attack initiation timestamp, propagation node hash, feature matching verification value, and occurrence time label" by improving the Merkle tree structure; the intelligent attribution contract module has a built-in attribution decision model, matches the tracing evidence package with the operation and maintenance records stored on the blockchain, and outputs the attribution result.
6. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The physical state perception module of the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer. It acquires physical characteristics such as device vibration frequency and shell temperature through edge computing nodes, and the sampling frequency is synchronized with the digital data. The virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors and dynamically adjusts the attack confidence based on the fusion result. The digital twin linkage verification module inputs physical data into the twin model to simulate the impact of defense commands on physical devices.
7. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The scene feature profiling module of the scene adaptive configuration layer uses the K-means clustering algorithm to generate four types of scene profiles—transmission grid, distribution grid, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration contract and verification module records parameter changes through configuration storage contracts, and the changes take effect after the accuracy rate is verified by digital twins to exceed a preset value.
8. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. Attack precursor factors come from AI defense layer feature data, equipment health factors come from historical verification data of the physical state perception module, power grid operation factors come from load and voltage data stored on the blockchain, and environmental interference factors come from temperature, humidity, and electromagnetic interference data collected by sensors. After Z-score standardization, a 32-64 dimensional risk factor vector is generated.
9. The power grid security defense system based on artificial intelligence and blockchain according to claim 3, characterized in that, The spatiotemporal graph Transformer prediction module uses the power grid topology as a graph structure, takes the risk factor vector as the graph node feature, and integrates the risk evolution law in the time dimension and the equipment correlation in the spatial dimension through the spatiotemporal attention mechanism to output four results: "attack occurrence probability, operation failure risk value, impact radius, and early warning lead time". The risk-defense linkage module interacts with the collaborative control layer through risk warning contracts to trigger pre-allocation of computing power, pre-transfer of load, or pre-isolation according to the risk level.
10. The power grid security defense system based on artificial intelligence and blockchain according to claim 3, characterized in that, The attack history time-series analysis and computing power pre-scheduling module retrieves attack history data from the blockchain for the most recent preset time period, including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". A time-series attention LSTM model is used to learn the correlation patterns and output three levels of risk level results: low, medium, and high. The computing power requirement is calculated by combining the basic computing power allocation ratio and the risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.
Citation Information
Patent Citations
Self-learning defense method, device and equipment facing power system artificial intelligence model backdoor attack, storage medium and program product
CN119939351A
Data tracing method and system based on big data and block chain multi-dimensional features
CN119557607A
Industrial control network security advanced threat detection system fused with artificial intelligence
CN120474777A
Power grid control safety system and method based on digital twinning
CN120497895A
Remote monitoring analysis method and system based on operation data of power equipment
CN120582339A
Cited By
Power monitoring system AI model anomaly detection method and system based on trusted computing
CN122263090A