A power grid security defense system based on artificial intelligence and blockchain

The seven-layer architecture of the power grid security defense system solves the problems of disconnect between detection and tracing, loose technical coordination, and passive resource scheduling in power grid defense systems under complex threats. It achieves efficient attack identification, defense response, and resource scheduling, thereby improving the security and resource utilization of the power grid.

CN121333665BActive Publication Date: 2026-07-21HANGZHOU DOUYOU TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU DOUYOU TECHNOLOGY CO LTD
Filing Date
2025-09-30
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing power grid defense systems suffer from problems such as a disconnect between detection and tracing, loose technical coordination, and passive resource scheduling when facing complex threats. They are unable to meet the security requirements of complex scenarios, especially in the case of false data injection and device backdoor attacks, where the false judgment rate is high, the recognition rate is low, and resource scheduling is rigid and lagging.

Method used

The power grid security defense system adopts a seven-layer modular coupling architecture, including an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module. Through multi-source data collection, feature engineering, multi-model fusion detection, reputation-weighted consensus verification, physical-information fusion verification, scenario profiling, and risk prediction, it achieves a full-cycle defense closed loop, deep collaboration, and linkage between risk prediction and computing power scheduling.

Benefits of technology

It has reduced the attack false positive rate from 18% to below 2%, shortened the response time for similar attacks from 10 seconds to within 50ms, improved defense response efficiency by 40%, reduced detection latency during high-risk periods by 30%, reduced computing power redundancy during low-risk periods from 55% to below 20%, and shortened the adaptation cycle from several hours to minutes, thereby improving the grid's anti-attack capability and resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333665B_ABST
    Figure CN121333665B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of power grid security defense systems based on artificial intelligence and block chain, the system includes AI defense layer, blockchain trust layer, collaborative control layer, attack traceability and attribution layer, physical-information fusion verification layer, scene adaptive configuration layer and risk prediction module, attack accurate identification is realized by multi-model fusion detection, rely on reputation weighted consensus to guarantee data credibility, with the aid of smart contract and cross-layer collaboration complete dynamic defense, through risk prediction module realizes early warning and power adaptation in advance.System effectively solves the problems that AI model is vulnerable to attack in prior art, blockchain response lag, virtual-real data is not synchronized, poor multi-scene adaptability, lack of early risk warning and power scheduling lag, can be widely applied to power transmission network, distribution network, microgrid and energy storage grid-connected scene, significantly improve the anti-attack ability of power grid to false data injection, equipment backdoor attack, collaborative DDoS and other threats, guarantee power grid operation stability and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system security technology, and in particular to a power grid security defense system based on artificial intelligence and blockchain. Background Technology

[0002] In the context of deep integration of the "physical-digital" dual systems in smart grids, complex threats such as fake data injection and device backdoor attacks occur frequently. Existing defense technologies are insufficient to meet the security requirements of complex scenarios due to "incomplete closed-loop links, insufficient coordination, and inflexible scheduling." The core shortcomings are specifically reflected in three aspects:

[0003] First, the defense chain is broken, and the disconnect between "detection-verification-tracing" leads to a high risk of defense failure. Existing AI detection solutions often operate in isolation. For example, the technical solution disclosed in patent number "CN119939351A" entitled "Self-learning defense method, device, equipment, storage medium and program product for backdoor attacks on artificial intelligence models of power systems" only improves detection robustness through digital data feature cleaning, without incorporating physical characteristics such as equipment vibration and temperature. When attackers forge normal digital data but cause physical overload (such as a sudden rise in conductor temperature), the false positive rate will be too high. Moreover, the existing solutions are disconnected from attack tracing and detection, and can only store maintenance data as evidence. They cannot optimize AI models based on tracing results, resulting in a strong lag in detection response when similar attacks occur repeatedly, and lacking a closed-loop optimization mechanism of "detection-verification-tracing".

[0004] Secondly, the technological collaboration is loose, and AI and blockchain have not formed a defensive synergy. Blockchain is mostly used as a single evidence storage tool and has not been deeply integrated into the defense process: In traditional solutions, AI detection results are only uploaded to the blockchain for evidence storage in one direction. The stored historical attack data (such as time distribution and type characteristics) cannot support the dynamic adjustment of AI model weights. When facing periods of high incidence of fake data attacks, fixed weight detection is still used, resulting in a low recognition rate. Moreover, the smart contract function is limited, and it can only trigger simple alarms. It cannot link the "risk warning → computing power scheduling" operation. The trust support value of blockchain has not been transformed into defensive effectiveness, forming a technological silo.

[0005] Third, resource scheduling is passive, lacking coordination between risk prediction and computing power adaptation. The existing system lacks the ability to predict risks in advance. Although it can adaptively adjust operating parameters, it does not integrate historical attack time-series characteristics and cannot identify high-risk scenarios such as thunderstorms and peak loads in advance. Moreover, the allocation of computing power is static and rigid: during high-risk periods (such as peak summer electricity consumption), the demand for AI detection surges, and fixed computing power leads to increased detection latency, while during low-risk periods, computing power redundancy is high. At the same time, scenario adaptation relies on manual intervention. The attack patterns of power transmission networks and microgrids are significantly different (power transmission networks are vulnerable to electrical parameter attacks, while microgrids are vulnerable to communication attacks), but parameter adjustments take several hours, and parameter adaptation lags behind the evolution of attacks. Summary of the Invention

[0006] To address the aforementioned problems in existing technologies, this invention provides a power grid security defense system based on artificial intelligence and blockchain. This system integrates AI dynamic detection, blockchain trusted evidence storage, attack tracing, virtual-real verification, scenario adaptation, risk prediction, and computing power scheduling functions to achieve coordinated operation of attack identification, data storage, defense response, tracing and attribution, virtual-real verification, scenario adaptation, risk warning, and computing power adaptation.

[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows: a power grid security defense system based on artificial intelligence and blockchain, comprising an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module, with a seven-layer architecture that is modularly coupled and interconnected.

[0008] The AI ​​defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity modules. It integrates time series, deep learning and anomaly detection models to identify attacks and protects itself through pre-filtering and incremental training.

[0009] The blockchain trust layer adopts a consortium blockchain architecture, verifies and stores evidence data through reputation-weighted consensus, responds automatically through smart contracts, stores historical attack data on-chain, and encrypts and protects privacy.

[0010] The collaborative control layer synchronizes and verifies data from each layer, and generates defense and computing power strategies by combining multi-dimensional information.

[0011] The attack tracing and attribution layer constructs a three-dimensional link graph, generates a tracing evidence package with time period labels, and uploads it to the blockchain for attribution.

[0012] The physical-information fusion verification layer collects physical features, fuses digital features for verification, and uses digital twins to verify instruction adaptability.

[0013] The scene adaptive configuration layer generates a scene profile and adjusts parameters and computing power allocation through reinforcement learning.

[0014] The risk prediction module integrates risk factors to predict risks, assesses the risk of a given period through historical attack analysis, and allocates computing power accordingly.

[0015] The beneficial effects of this invention are: First, it overcomes the pain points of "isolated detection and lack of feedback in tracing the source," constructing a closed-loop defense system throughout the entire lifecycle. Existing AI detection relies solely on digital data and is disconnected from source tracing. This solution, through a physical-information fusion verification layer that associates the physical characteristics of devices, reduces the attack false positive rate from 18% to below 2%. The attack tracing and attribution layer generates evidence packages with time-time labels and uploads them to the blockchain, providing reliable data for the risk prediction module. The response time for repeated detection of similar attacks is reduced from 10 seconds to within 50ms, achieving a closed loop of "detection-verification-tracing-optimization."

[0016] Secondly, it addresses the issue of technological silos and achieves deep collaboration between AI and blockchain. Existing blockchains only store single evidence, while this solution uses a reputation-weighted consensus mechanism (latency ≤100ms) to verify AI detection results through the blockchain trust layer. Smart contracts are linked to defense scheduling, improving defense response efficiency by 40% compared to traditional solutions. At the same time, on-chain attack history data is used to reverse-optimize the AI ​​model weights, increasing the attack identification rate during high-risk periods from 72% to over 98%.

[0017] Third, it breaks through the limitations of "static scheduling" and achieves linkage between risk prediction and computing power adaptation. The existing system has no advance warning and the computing power is fixed. The risk prediction module of this solution integrates multi-factor risk prediction, schedules computing power 300ms in advance, reduces the detection latency during high-risk periods by 30%, and reduces computing power redundancy from 55% to below 20% during low-risk periods; the scenario adaptive configuration layer automatically adjusts parameters, shortening the adaptation cycle from several hours to minutes, which greatly improves the grid's anti-attack capability and resource utilization.

[0018] Optionally, the multi-source data acquisition module of the AI ​​defense layer integrates voltage transformers, current transformers, and status monitoring sensors, and collects power grid equipment operation data, communication traffic data, and environmental parameters through the MQTT protocol; the feature engineering module uses empirical mode decomposition to extract temporal features, combines an attention mechanism to filter attack-related features, and outputs 64-256 dimensional feature vectors; the multi-model fusion detection module includes parallel LSTM networks, CNN networks, and isolated forest models, and outputs detection results through weighted voting fusion, with weights dynamically adjusted based on the historical detection accuracy of each model; the model immunity module identifies abnormal data with backdoors through a pre-filter, uses ensemble learning to incrementally train the model, and updates parameters periodically.

[0019] As described above, existing technologies often rely on single-frequency power grid data acquisition with low feature extraction accuracy, resulting in poor input data quality for AI models and a high false positive rate for attack identification. This solution integrates multiple types of sensors, covering power grid operation, communication traffic, and environmental parameters, significantly increasing the data dimensionality compared to traditional methods. Furthermore, it combines empirical mode decomposition and attention mechanisms to filter attack-related features across 64-256 dimensions, eliminating redundant information and improving feature extraction accuracy. In addition, dynamic weight fusion across multiple models and periodic incremental training address the poor adaptability and lagging model updates of traditional fixed weights, thereby improving attack detection response speed and reducing the false positive rate of backdoor attacks.

[0020] Optionally, the blockchain trust layer adopts a consortium blockchain architecture, with nodes including a power grid dispatch center, substations, and third-party audit nodes, totaling no fewer than five. The reputation-weighted consensus module uses the PBFT algorithm to calculate a reputation value based on the credibility of the node's historical behavior and its real-time detection contribution, with voting weight positively correlated with the reputation value. The smart contract module includes six contracts: attack response, model update, permission freezing, configuration notarization, risk warning, and computing power scheduling, which respectively implement node isolation, parameter notarization, account disabling, configuration recording, resource pre-scheduling, and computing power allocation functions. The privacy encryption module uses an encryption scheme, authorizing only the AI ​​model to decrypt and extract features.

[0021] As described above, existing blockchains in power grid scenarios suffer from high consensus latency (over 200ms), low node participation, and limited contract functionality, making them unsuitable for real-time defense requirements. This solution employs a consortium blockchain architecture with at least 5 nodes, covering the dispatch center, substations, and audit nodes to ensure data credibility. It improves the PBFT consensus algorithm by introducing node reputation weighting, allocating voting rights based on historical behavior and detection contributions, compressing consensus latency to ≤100ms, a 50% efficiency improvement over traditional PBFT. Simultaneously, it expands to include multiple types of smart contracts, enabling automated operations such as attack response and model updates, resolving the lag issues of traditional manual triggering responses, and reducing defense command execution time to within 20ms.

[0022] Optionally, the cross-layer interface module of the collaborative control layer adopts a RESTful API to convert detection results, traceability data, verification results, risk prediction results, and computing power requirements into a blockchain-readable key-value pair format. Before data transmission, a verification hash is generated using SHA-256. The defense decision module has a built-in decision tree model that outputs defense priorities and computing power allocation schemes based on attack type, impact range, power grid load status, virtual and real verification results, risk prediction level, and risk level of historical attack periods. The priorities are divided into four levels: early warning pre-scheduling, emergency isolation, flow limiting protection, and alarm prompts. The computing power allocation is calculated according to "multi-model weight ratio × risk level coefficient".

[0023] As described above, the existing system suffers from inconsistent cross-layer data formats, leading to low information exchange efficiency and defense decisions relying solely on single-dimensional data, resulting in poor strategy accuracy. This solution employs a RESTful API to standardize cross-layer data conversion, combined with SHA-256 hash verification, reducing data transmission error rates and improving interaction efficiency. The defense decision module incorporates a decision tree model, integrating multi-dimensional information such as attack type and risk level to output a four-level defense priority and computing power allocation scheme, addressing the problems of traditional single-dimensional decision-making. The computing power calculation logic of "multi-model weight ratio × risk level coefficient" improves computing power utilization during high-risk periods, avoiding resource waste or insufficiency.

[0024] Optionally, the attack chain analysis module of the attack tracing and attribution layer integrates graph neural networks and traffic tracing algorithms to construct a three-dimensional attack chain graph of "device-data-communication" based on the attack features output by the AI ​​defense layer; the blockchain tracing certificate generation module generates a tracing evidence package containing "attack initiation timestamp, propagation node hash, feature matching verification value, and occurrence time label" by improving the Merkle tree structure; the intelligent attribution contract module has a built-in attribution decision model to match the tracing evidence package with the operation and maintenance records stored on the blockchain and output the attribution result.

[0025] As described above, existing attack attribution methods largely rely on simple traffic analysis, resulting in low accuracy in link reconstruction and a lack of credible evidence for attribution, making it difficult to determine responsibility. This solution integrates a graph neural network (GNN) with a traffic attribution algorithm to construct a three-dimensional attack link graph of "device-data-communication." Combined with attack characteristics from an AI defense layer, the link reconstruction accuracy is ≥95%, an improvement of over 15% compared to traditional solutions. An improved Merkle tree is used to generate a source attribution evidence package containing multi-dimensional information, which is stored on the blockchain to ensure immutability. A smart attribution contract matches maintenance records, reducing attribution time and solving the problems of low efficiency and unreliable evidence in traditional manual attribution, providing a reliable basis for determining attack responsibility.

[0026] Optionally, the physical state perception module of the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer, which acquire physical characteristics such as device vibration frequency and shell temperature through edge computing nodes, and the sampling frequency is synchronized with the digital data; the virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors, and dynamically adjusts the attack confidence based on the fusion result; the digital twin linkage verification module inputs physical data into the twin model to simulate the impact of defense commands on physical devices.

[0027] As described above, existing technologies rely solely on digital data detection and lack physical feature verification. This makes them susceptible to failure against "digital camouflage-physical anomaly" attacks, and the physical adaptability of defense commands is not verified. This solution adds vibration and infrared sensors to collect physical characteristics such as device vibration frequency and temperature. The sampling frequency is synchronized with the digital data, achieving dual-dimensional "digital-physical" data coverage. The virtual-real feature fusion verification module adjusts the attack confidence level through an attention mechanism, and digital twin simulation verifies the impact of defense commands, significantly reducing the verification error rate. This solves the problem of misjudgment caused by traditional single-digit detection, improves the accuracy of attack confidence correction, and increases the success rate of defense command execution.

[0028] Optionally, the scene feature profiling module of the scene adaptive configuration layer adopts the K-means clustering algorithm to generate four types of scene profiles—transmission network, distribution network, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI ​​model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration contract and verification module records parameter changes through configuration storage contracts, and the changes take effect after the accuracy rate is verified by digital twins to exceed a preset value.

[0029] As described above, existing scenario adaptation relies on manual parameter adjustments, which is time-consuming (over several hours) and has low accuracy, failing to address the diverse attack scenarios across different environments. This solution employs the K-means algorithm to generate four scenario profiles, covering core scenarios such as power transmission networks and microgrids, achieving high profile matching accuracy. The dynamic configuration engine optimizes AI model weights, consensus thresholds, and other parameters through reinforcement learning. Changes to configuration contract records take effect only after digital twin verification, shortening the adaptation cycle to minutes and resolving the inefficiency of traditional manual adaptation. Simultaneously, adjusting the basic computing power allocation ratio improves the attack recognition rate for each scenario, addressing the issue of delayed scenario adaptation.

[0030] Optionally, the risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. The attack precursor factor comes from the feature data of the AI ​​defense layer, the equipment health factor comes from the historical verification data of the physical state perception module, the power grid operation factor comes from the load and voltage data stored on the blockchain, and the environmental interference factor comes from the temperature, humidity and electromagnetic interference data collected by the sensor. The risk factor vector is generated in 32-64 dimensions after Z-score standardization.

[0031] As described above, existing risk prediction methods rely on a single attack factor, resulting in limited dimensions and low data reliability, leading to insufficient prediction accuracy. This solution categorizes risk factors into four types, derived from AI defense layers, physical verification layers, blockchain evidence storage, and sensor data, achieving full-dimensional coverage of "attack-device-operation-environment," increasing the factor dimensionality several times compared to traditional methods. Through Z-score standardization, it eliminates data dimension differences, generating 32-64 dimensional standardized vectors, improving data consistency. This design addresses the limitations of traditional single-factor prediction, providing high-quality input for subsequent spatiotemporal graph Transformer predictions and enhancing the reliability of the underlying risk prediction data.

[0032] Optionally, the spatiotemporal graph Transformer prediction module uses the power grid topology as a graph structure, takes the risk factor vector as the graph node feature, and integrates the risk evolution law in the time dimension with the equipment correlation in the spatial dimension through the spatiotemporal attention mechanism to output four results: "attack occurrence probability, operation failure risk value, impact radius, and early warning lead time". The risk-defense linkage module interacts with the collaborative control layer through the risk early warning contract to trigger computing power pre-allocation, load pre-transfer, or pre-isolation according to the risk level.

[0033] As described above, existing risk prediction methods lack spatiotemporal correlation analysis, have insufficient early warning lead time, and are disconnected from defense coordination. This solution uses the power grid topology as a graph structure, integrating temporal risk evolution with spatial device correlation, and outputs four core prediction results, improving accuracy and increasing early warning lead time to ≥300ms, thus shortening the warning time. The risk-defense linkage module triggers operations such as computing power pre-allocation and load transfer according to risk level, with reduced linkage response time, solving the traditional "prediction-defense" disconnect problem, reserving sufficient defense windows for high-risk attacks, and improving attack blocking rate.

[0034] Optionally, the attack history time-series analysis and computing power pre-scheduling module retrieves attack history data from the blockchain for the most recent preset time period, including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". A time-series attention LSTM model is used to learn the correlation patterns and output three levels of risk level results for low, medium, and high time periods. The computing power requirement is calculated by combining the basic computing power allocation ratio and the risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.

[0035] As described above, existing computing power scheduling lacks historical attack time-series analysis support and employs a fixed allocation model, resulting in insufficient computing power during high-risk periods and redundancy during low-risk periods. This solution utilizes recent historical attack data, constructing a dataset based on "scenario-time period-attack type." A time-series attention LSTM model outputs a three-level risk level; computing power requirements are calculated based on the risk level coefficient, triggering a computing power scheduling contract to dynamically allocate resources. During high-risk periods, priority is given to ensuring computing power for core models, resulting in shorter scheduling response times. This design reduces detection latency during high-risk periods and minimizes computing power redundancy during low-risk periods, improving resource utilization and resolving the rigidity problem of traditional computing power scheduling. Attached Figure Description

[0036] Figure 1 This is a structural block diagram of a power grid security defense system based on artificial intelligence and blockchain according to the present invention. Detailed Implementation

[0037] To better explain and facilitate understanding of the present invention, it is described in detail below with reference to the accompanying drawings and specific embodiments. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a clearer and more thorough understanding of the invention and to fully convey the scope of the invention to those skilled in the art.

[0038] Example 1

[0039] Please refer to Figure 1 As shown, a power grid security defense system based on artificial intelligence and blockchain includes an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module. The seven-layer architecture is modular, coupled, and interconnected.

[0040] The AI ​​defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity modules. It integrates time series, deep learning and anomaly detection models to identify attacks and protects itself through pre-filtering and incremental training.

[0041] The blockchain trust layer adopts a consortium blockchain architecture, verifies and stores evidence data through reputation-weighted consensus, responds automatically through smart contracts, stores historical attack data on-chain, and encrypts and protects privacy.

[0042] The collaborative control layer synchronizes and verifies data from each layer, and generates defense and computing power strategies by combining multi-dimensional information.

[0043] The attack tracing and attribution layer constructs a three-dimensional link graph, generates a tracing evidence package with time period labels, and uploads it to the blockchain for attribution.

[0044] The physical-information fusion verification layer collects physical features, fuses digital features for verification, and uses digital twins to verify instruction adaptability.

[0045] The scene adaptive configuration layer generates a scene profile and adjusts parameters and computing power allocation through reinforcement learning.

[0046] The risk prediction module integrates risk factors to predict risks, assesses the risk of a given period through historical attack analysis, and allocates computing power accordingly.

[0047] The AI ​​defense layer's multi-source data acquisition module integrates voltage transformers, current transformers, and status monitoring sensors. It collects power grid equipment operation data, communication traffic data, and environmental parameters via the MQTT protocol, with a sampling frequency selectable from 50-200Hz. The feature engineering module extracts temporal features using empirical mode decomposition and filters attack-related features using an attention mechanism, outputting 64-256 dimensional feature vectors. The multi-model fusion detection module includes parallel LSTM networks, CNN networks, and isolated forest models. It outputs detection results through weighted voting fusion, with weights dynamically adjusted based on the historical detection accuracy of each model. The model immunity module identifies abnormal data with backdoors through a pre-filter, uses ensemble learning to incrementally train the model, and updates parameters periodically (e.g., every 24 hours).

[0048] The blockchain trust layer adopts a consortium blockchain architecture, with at least five nodes including the power grid dispatch center, substations, and third-party audit nodes. The reputation-weighted consensus module uses the PBFT algorithm to calculate reputation values ​​based on the credibility of nodes' historical behavior and their real-time detection contributions, with voting weights positively correlated with reputation values. The smart contract module includes six contracts: attack response, model update, permission freezing, configuration notarization, risk warning, and computing power scheduling, which respectively implement node isolation, parameter notarization, account disabling, configuration recording, resource pre-scheduling, and computing power allocation functions. The privacy encryption module uses an encryption scheme (which may employ an ECC elliptic curve-based encryption algorithm), authorizing only AI models to decrypt and extract features.

[0049] The cross-layer interface module of the collaborative control layer adopts a RESTful API to convert detection results, traceability data, verification results, risk prediction results, and computing power requirements into a blockchain-readable key-value pair format. Before data transmission, a verification hash is generated using SHA-256. The defense decision module has a built-in decision tree model that outputs defense priorities and computing power allocation schemes based on attack type, impact range, power grid load status, virtual and real verification results, risk prediction level, and risk level of historical attack periods. Priorities are divided into four levels: early warning pre-scheduling, emergency isolation, flow limiting protection, and alarm prompts. Computing power allocation is calculated according to "multi-model weight ratio × risk level coefficient".

[0050] The attack chain analysis module of the attack tracing and attribution layer integrates graph neural networks and traffic tracing algorithms, and constructs a three-dimensional attack chain graph of "device-data-communication" based on the attack features output by the AI ​​defense layer; the blockchain tracing certificate generation module generates a tracing evidence package containing "attack initiation timestamp, propagation node hash, feature matching verification value, and occurrence time label" by improving the Merkle tree structure; the intelligent attribution contract module has a built-in attribution decision model, matches the tracing evidence package with the operation and maintenance records stored on the blockchain, and outputs the attribution result.

[0051] The physical state perception module of the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer. It acquires physical characteristics such as device vibration frequency and shell temperature through edge computing nodes, and the sampling frequency is synchronized with the digital data. The virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors and dynamically adjusts the attack confidence based on the fusion result. The digital twin linkage verification module inputs physical data into the twin model to simulate the impact of defense commands on physical devices.

[0052] The scene feature profiling module of the scene adaptive configuration layer uses the K-means clustering algorithm to generate four types of scene profiles—transmission network, distribution network, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI ​​model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration contract and verification module records parameter changes through configuration storage contracts, and the changes take effect after the accuracy rate is verified by digital twins and exceeds a preset value. The preset value can be set according to needs, and is preferably 97%.

[0053] The risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. Attack precursor factors come from AI defense layer feature data, equipment health factors come from historical verification data of the physical state perception module, power grid operation factors come from load and voltage data stored on the blockchain, and environmental interference factors come from temperature, humidity, and electromagnetic interference data collected by sensors. The risk factors are then standardized by Z-score to generate 32-64 dimensional risk factor vectors.

[0054] The spatiotemporal graph Transformer prediction module uses the power grid topology as a graph structure and risk factor vectors as graph node features. It integrates the risk evolution law in the time dimension and the equipment correlation in the spatial dimension through a spatiotemporal attention mechanism, and outputs four results: "attack probability, operational failure risk value, radius of influence, and early warning lead time". The prediction accuracy is ≥93% and the early warning lead time is ≥300ms. The risk-defense linkage module interacts with the collaborative control layer through risk early warning contracts, and triggers computing power pre-allocation, load pre-transfer or pre-isolation according to the risk level. The linkage response time is ≤50ms.

[0055] The attack history time-series analysis and computing power pre-scheduling module retrieves attack history data from the blockchain for the most recent preset time period (e.g., the last 6 months), including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". A time-series attention LSTM model is used to learn the correlation patterns and output three levels of risk level results: low, medium, and high. The matching accuracy of the level results is ≥94%. The computing power requirement is calculated by combining the basic computing power allocation ratio and the risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.

[0056] The distributed ledger module of the blockchain trust layer adopts a hybrid on-chain and off-chain storage. The original data is stored in the IPFS system, while the on-chain storage includes data hashes, metadata, scene profile hashes, risk factor hashes, and attack history time sequence hashes. It supports full lifecycle data traceability with a traceability response time of ≤5s.

[0057] Existing blockchains store all raw data, resulting in significant on-chain data redundancy, slow traceability response times (over 10 seconds), and a lack of full lifecycle data traceability. This solution employs a hybrid on-chain / off-chain storage approach. IPFS stores the raw data, while the on-chain repository only stores key information such as hashes and metadata, reducing on-chain data volume by 70%. It supports full lifecycle traceability from data collection to destruction, and combined with SHA-256 hash verification, achieves 100% data reliability with a traceability response time of ≤5 seconds, significantly improving overall storage efficiency. Simultaneously, it stores hashes for scenario profiles and risk factors, providing a reliable index for data retrieval at each layer and resolving storage redundancy and traceability lag issues.

[0058] The multi-model fusion detection module of the AI ​​defense layer also includes a Few-Shot learning model, which is connected in parallel with LSTM, CNN, and isolated forest models. When the risk prediction module outputs "high probability of unknown attack (e.g., probability ≥ 80%, staff can set the probability value according to actual needs)," the weight of the Few-Shot model is automatically increased to 0.4-0.5. It uses a small number of samples from the attack feature map to identify unknown attacks. The attack feature map includes three core feature dimensions: attack data format, traffic mutation mode, and physical parameter abnormal threshold.

[0059] Existing multi-model fusion lacks the ability to identify unknown attacks and is less effective against mutated attacks (such as novel fake data injection). This solution adds a Few-Shot learning model, which is connected in parallel with the original model. When predicting "high-probability unknown attacks," the model weights are automatically increased to 0.4-0.5, achieving unknown attack identification with a small number of attack feature map samples. This design addresses the deficiency of traditional models that rely on a large number of labeled samples, improves the unknown attack identification rate, shortens the identification response time, fills the gap in existing technology for defense against unknown mutated attacks, and enhances the system's adaptability to new attacks.

[0060] Please refer to Figure 1 As shown, the seven-layer architecture uses the collaborative control layer as its central core for information interaction. It forms a closed-loop flow with the core logic of "data acquisition - preprocessing - analysis and prediction - decision scheduling - execution feedback - evidence storage and iteration." Each layer has a clear division of labor yet deep collaboration. The collaborative control layer, as the "nerve center" of the architecture, is responsible for information aggregation, format conversion, verification synchronization, and policy distribution from all layers. All cross-layer information interactions are standardized through its cross-layer interface module (using RESTful API and SHA-256 hash verification) to ensure data consistency and reliability. The interaction process of each layer is as follows:

[0061] Phase 1: Basic Data Collection and Preprocessing (Upward Aggregation of Lower-Level Data)

[0062] AI Defense Layer → Collaborative Control Layer: The power grid operation / communication traffic / environment data collected by the multi-source data acquisition module are processed into 64-256 dimensional feature vectors by the feature engineering module and then synchronously transmitted to the collaborative control layer; at the same time, the real-time detection results (including attack type and confidence level) of the multi-model fusion detection module are also pushed to the collaborative control layer in real time.

[0063] Physical-Information Fusion Verification Layer → Collaborative Control Layer: Physical state perception module collects physical characteristic data such as equipment vibration / temperature / insulation resistance, which are then pre-processed and transmitted to the collaborative control layer to form a "virtual-real data pair" with the digital characteristics of the AI ​​defense layer.

[0064] 2. Second Phase: Risk Prediction and Computing Power Scheduling (Multi-dimensional data converges to the risk prediction module, and prediction results are distributed downwards)

[0065] Collaborative Control Layer → Risk Prediction Module: The feature vectors of the AI ​​defense layer and the physical feature data of the physical layer are synchronously pushed to the risk factor fusion module of the risk prediction module; at the same time, the current scene label (from the scene adaptive configuration layer) and real-time time information are transmitted to the risk prediction module.

[0066] Blockchain Trust Layer → Risk Prediction Module: The attack history time sequence analysis and computing power pre-scheduling module of the risk prediction module calls recent (default setting is the last 6 months) attack history data (including time period, type, computing power demand tags) from the distributed ledger of the blockchain for time period risk level assessment.

[0067] Risk Prediction Module → Collaborative Control Layer: Outputs two types of core results: ① "Attack Probability / Risk Value / Early Warning Lead Time" generated by the Spatiotemporal Graph Transformer Prediction Module; ② "Time Period Risk Level + Computing Power Pre-allocation Requirement Table" generated by the Attack History Time Series Analysis Module, both of which are pushed to the defense decision module of the collaborative control layer.

[0068] 3. Third stage: Defense decision-making and cross-layer scheduling (coordinating the control layer to issue instructions to the functional layer)

[0069] Collaborative Control Layer → AI Defense Layer: Based on risk prediction results, the defense decision module generates a computing power allocation plan and dynamically allocates computing power to the multi-model fusion detection module of the AI ​​defense layer through a computing power scheduling contract (blockchain trust layer) (such as increasing the computing power ratio of CNN / Few-Shot models during high-risk periods).

[0070] Collaborative Control Layer → Attack Tracing and Attribution Layer: When the confidence level of the AI ​​defense layer's detection result is greater than or equal to the threshold (or the risk prediction level is greater than or equal to high risk), the collaborative control layer sends "attack characteristics + preliminary location information" to the attack tracing and attribution layer, triggering the link analysis and attribution process.

[0071] Collaborative Control Layer → Scenario Adaptive Configuration Layer: Pushes the current attack type, risk level, and power grid load status to the scenario adaptive configuration layer to dynamically adjust the scenario profile parameters and basic computing power allocation ratio.

[0072] 4. Fourth Phase: Virtual vs. Real Verification and Attack Source Tracing (Inter-functional Layer Interaction and Result Feedback)

[0073] Attack tracing and attribution layer → Blockchain trust layer: The 3D link diagram generated by the attack link analysis module and the attribution results output by the smart attribution contract are packaged into a "source tracing evidence package" and uploaded to the blockchain. The evidence is verified through the reputation-weighted consensus module. The hash of the verified evidence package is synchronously fed back to the collaborative control layer.

[0074] Physical-Information Fusion Verification Layer → AI Defense Layer: The collaborative control layer synchronously pushes the detection results of the AI ​​defense layer and the feature data of the physical layer to the virtual-real feature fusion verification module. After fusion, it outputs the "attack confidence correction value" and feeds it back to the AI ​​defense layer to optimize the detection model weights.

[0075] Physical-Information Fusion Verification Layer → Collaborative Control Layer: The digital twin linkage verification module performs physical adaptability simulation on the defense commands (such as node isolation and load transfer) issued by the collaborative control layer, outputs the "command execution feasibility result", and feeds it back to the collaborative control layer.

[0076] 5. Fifth Stage: Defense Execution and Evidence Preservation Iteration (Execution Result Evidence Preservation, Data Closed-Loop Feedback)

[0077] Collaborative control layer → Blockchain trust layer: The final defense strategy (such as node isolation and computing power adjustment), execution results (such as attack blocking rate), and digital twin verification certificate are all uploaded to the blockchain and stored through smart contracts to form a trusted chain of "instruction-execution-result".

[0078] Blockchain Trust Layer → Scenario Adaptive Configuration Layer: Historical defense data and attack characteristic data stored on the blockchain are periodically synchronized to the scenario feature profile module of the scenario adaptive configuration layer to update scenario profiles such as power grids / microgrids and optimize parameter adjustment logic.

[0079] Each layer → Collaborative Control Layer (Closed-Loop Feedback): Operational data such as the detection time of the AI ​​defense layer, the verification error of the physical layer, and the attribution time of the attack tracing layer are summarized to the collaborative control layer every hour and pushed to the risk prediction module for incremental model training, realizing self-optimization of the architecture.

[0080] Example 2

[0081] Building upon Example 1, the power grid security defense system based on artificial intelligence and blockchain will be applied to a specific scenario: defense against combined attacks involving collaborative spoofing of data and physical overload on the power transmission network. Details are as follows:

[0082] I. Prerequisites for Scenario and System Deployment

[0083] ① Application scenario: A section of a 220kV transmission network, including 5 substations and 8 transmission lines, with daily load fluctuations of 30%-70%. Historical data shows that severe weather periods (thunderstorms / strong winds) account for 68% of the total load. Currently, it is 16:30 (peak load) during summer thunderstorms.

[0084] ② Seven-layer architecture deployment:

[0085] AI defense layer: Deploy 15 smart sensors (voltage / current transformers + status monitors), initial weights for multiple models: LSTM 0.35, CNN 0.4, Isolation Forest 0.15, Few-Shot 0.1, and basic allocation of computing power and weight matching;

[0086] Blockchain Trust Layer: A consortium blockchain consisting of a power grid dispatch center, 5 substations, and 3 third-party audit nodes is constructed. It improves upon PBFT and, in the default operating mode, sets the threshold for the number of consensus nodes to 70% of the total number of nodes, storing 120 attack history data records from the past 6 months.

[0087] Collaborative control layer: cross-layer interface synchronization period 50ms; defense decision model computing power allocation coefficient: low risk 0.8, medium risk 1.2, high risk 1.6.

[0088] Attack tracing and attribution layer: A three-dimensional topology map of the power grid "substation-line-terminal" is preset, and the GNN model training samples contain 80,000 attack link data;

[0089] Physical-information fusion verification layer: Vibration sensors and insulator pollution sensors are deployed on the transmission line, with a physical feature sampling frequency of 200Hz, and the digital twin model includes parameters related to line current carrying capacity and temperature;

[0090] Scenario-adaptive configuration layer: Matches the "power grid scenario profile" (dispersed equipment, large load fluctuations, communication latency ≤60ms, and composite attacks accounting for 68%), with the following basic computing power allocation: CNN 40%, LSTM 35%;

[0091] Risk prediction module: The risk factor contains 18 features, the time series LSTM model has 100,000 training samples, and the current weather is labeled "thunderstorm" and the time period is 16:30.

[0092] II. Seven-Layer Architecture Full Process Execution Steps

[0093] Step 1: Attack History Time Sequence Analysis and Computing Power Pre-Scheduling (Risk Prediction Module + Blockchain Trust Layer + Collaborative Control Layer)

[0094] ① The attack history time sequence analysis and computing power pre-scheduling module of the risk prediction module calls the attack history data of the past 6 months of thunderstorm weather from 16:00 to 17:00 through the distributed ledger interface of the blockchain trust layer (a total of 32 records, with composite attacks accounting for 75%).

[0095] ② After the data is standardized by Z-score, it is input into the temporal attention LSTM model. Combined with the current time period information of "power grid - thunderstorm - 16:30", the output is "high risk" level (attack probability 68%).

[0096] ③ The module combines the basic computing power allocation ratio of the scene adaptive configuration layer (CNN 40%, LSTM 35%), adjusts the relative computing power ratio of each model according to the high-risk coefficient of 1.6, calculates the computing power requirement, and generates a computing power allocation table;

[0097] ④ The allocation table is uploaded to the defense decision module via the cross-layer interface (RESTful API + SHA-256 verification) of the collaborative control layer, triggering the computing power scheduling contract of the blockchain trust layer to dynamically allocate computing power to the multi-model fusion detection module of the AI ​​defense layer. The scheduling response takes 38ms.

[0098] Step 2: Multi-source data acquisition and risk factor fusion (AI defense layer + physical-information fusion verification layer + risk prediction module)

[0099] ① The multi-source data acquisition module of the AI ​​defense layer collects power grid data through the MQTT protocol: line A voltage deviation 5.9%, current distortion rate 8%, communication traffic surge 150%, sampling frequency 200Hz;

[0100] ② The physical state perception module of the physical-information fusion verification layer synchronously collects physical characteristics: the vibration frequency of the line A insulator is 3.2Hz (normal ≤1.5Hz), the pollution degree is 0.8 (normal ≤0.3), and the conductor temperature is 68℃ (normal ≤55℃). After preprocessing by the edge computing node, the data is transmitted to the collaborative control layer.

[0101] ③ The collaborative control layer pushes the raw data from the AI ​​defense layer and the physical layer feature data to the risk factor fusion module of the risk prediction module. The module classifies the factors into four categories: “attack precursors (voltage deviation / communication traffic), equipment health (vibration / pollution), power grid operation (current / temperature), and environmental interference (thunderstorm weather)”, and generates a 64-dimensional risk factor vector through Z-score standardization.

[0102] Step 3: Risk Prediction and Early Warning Trigger (Risk Prediction Module + Collaborative Control Layer + Blockchain Trust Layer)

[0103] ① The risk factor vector is input into the spatiotemporal graph Transformer prediction module of the risk prediction module. Using the transmission network topology as the graph structure, the module integrates the "risk evolution trend within 10 minutes" and the "substation-line correlation" through the spatiotemporal attention mechanism, and outputs the prediction results: the probability of a collaborative false data injection + physical overload composite attack is 72%, the operational failure risk value is 0.78, the affected area is 2 substations, and the early warning lead time is 340ms.

[0104] ② The prediction results are synchronized to the blockchain trust layer through the collaborative control layer, and consensus verification is completed through the reputation-weighted consensus module (improved PBFT algorithm) (6 / 11 nodes confirm), with a consensus delay of 85ms. The verified results are stored on the blockchain.

[0105] ③ The risk prediction module triggers the risk warning contract of the blockchain trust layer, sends a "high-risk warning" signal to the collaborative control layer, and initiates the pre-scheduling of defense resources: pre-activating backup line B and pre-allocating 30% of edge computing power to the detection module.

[0106] Step 4: Feature Engineering and Multi-Model Fusion Detection (AI Defense Layer + Collaborative Control Layer)

[0107] ① The feature engineering module of the AI ​​defense layer processes the collected data: it uses empirical mode decomposition to extract 128-dimensional time-series features of voltage / current, and combines the attention mechanism to filter attack-related features (voltage deviation rate, flow mutation slope, etc.), and outputs a 256-dimensional feature vector.

[0108] ②Feature vector input has been adapted to the computing power of the multi-model fusion detection module, and the parallel models are computed synchronously:

[0109] LSTM network: Identifies fake data injection patterns based on temporal features, with an output confidence level of 89%;

[0110] CNN network: Identifies physical overload precursors based on spatial features (multi-node data correlation), with an output confidence level of 91%;

[0111] Few-Shot model: Based on 10 composite attack samples from the attack feature map, the output confidence level is 87%;

[0112] Isolation Forest Model: Identifies abnormal deviations in data, outputting a confidence level of 82%;

[0113] ③ The module merges the results through weighted voting (weights: CNN 0.64, LSTM 0.56, Few-Shot 0.16, Isolation Forest 0.04) and outputs the detection result of "cooperative fake data injection + physical overload composite attack" with a confidence level of 93% and a detection time of 21ms.

[0114] The detection results are fed back to the model immune module through the collaborative control layer. The module confirms that there is no backdoor data contamination through the pre-filter (GAN-generated adversarial example training) and marks it as a valid detection result.

[0115] Step 5: Virtual-Real Feature Fusion Verification (Physical-Information Fusion Verification Layer + Collaborative Control Layer)

[0116] ① The collaborative control layer synchronously pushes the detection results of the AI ​​defense layer and the physical feature data of the physical-information fusion verification layer to the virtual-real feature fusion verification module;

[0117] ② The module employs an attention mechanism to fuse digital features (voltage deviation / current distortion) with physical features (vibration / temperature / dirtiness), calculating a correlation matching degree of 92% (≥threshold 80%), and improving the attack confidence level to 97%.

[0118] ③ The collaborative control layer triggers the digital twin linkage verification module of the physical-information fusion verification layer, inputting the current physical data (conductor temperature 68℃, vibration 3.2Hz) into the twin model to simulate the execution effect of the "node isolation + load transfer" defense command: after the load transfer, the conductor temperature drops to 52℃, the vibration recovers to 1.3Hz, the verification error rate is 1.2% (≤2%), and a verification certificate is generated. The "verification error rate" is calculated as "absolute deviation between simulated value and physical measured value / physical measured value". Under normal scenarios, the verification error rate needs to be ≤2%, while under special scenarios, the verification error rate can be fine-tuned through the scenario adaptive configuration layer.

[0119] Step 6: Attack Origin and Attribution (Attack Origin and Attribution Layer + Blockchain Trust Layer + Collaborative Control Layer)

[0120] ① The collaborative control layer sends "detection results + confidence level + verification certificate" to the attack tracing and attribution layer, triggering the attack chain analysis module;

[0121] ② The module integrates GNN and traffic tracing algorithms. Based on the attack characteristics (fake data format / traffic source IP) of the AI ​​defense layer and the preset topology map, it constructs a three-dimensional attack link map of "external IP → communication node C → substation 2 → line A", with a link reconstruction accuracy of 96%.

[0122] ③ The blockchain traceability certificate generation module adopts an improved Merkle tree structure to generate a traceability evidence package containing "attack initiation timestamp 16:30:02 - propagation node hash - feature matching verification value - time period label 16:30". After being verified by the consensus of the blockchain trust layer, the evidence is stored on the blockchain.

[0123] ④ The intelligent attribution contract module matches the traceability evidence package with the blockchain-stored operation and maintenance records (no personnel operation from 16:00 to 16:30) and the equipment firmware logs (the firmware of substation 2 has not been updated for 3 months), and outputs the attribution result: an external malicious attack was launched by exploiting a vulnerability in the equipment firmware, and the attribution took 8 seconds.

[0124] Step 7: Defense Decision-Making and Execution (Collaborative Control Layer + Blockchain Trust Layer + AI Defense Layer + Physical-Information Fusion Verification Layer)

[0125] ① The defense decision module of the collaborative control layer inputs multi-dimensional information: attack type (composite attack), scope of impact (2 substations), grid load (70%), virtual and real verification results (confidence level 97%), risk level (high risk), and attribution results (external attack). It outputs defense strategies through a decision tree model.

[0126] Priority: Emergency isolation;

[0127] Operation 1: Disconnect the connection switch between line A and substation 2;

[0128] Operation 2: Transfer the load (120MW) of line A to the standby line B;

[0129] Operation 3: Increase the AI ​​defense layer's detection computing power to 70%;

[0130] ② The strategy is sent to the blockchain trust layer via the cross-layer interface, triggering the attack response contract and automatically executing the contact switch disconnection and load transfer operations, which takes 18ms;

[0131] ③ The physical-information fusion verification layer collects data in real time after execution: the current of line A returns to zero, the voltage of line B stabilizes, and the conductor temperature drops to 51℃, and feeds it back to the collaborative control layer to confirm that the defense is effective;

[0132] ④ The collaborative control layer synchronizes the defense strategy, execution results, and verification credentials to the blockchain trust layer, and forms a complete and trustworthy chain by configuring the evidence storage contract for on-chain evidence storage.

[0133] Step 8: Scene Adaptation and Model Iteration (Scene Adaptive Configuration Layer + Risk Prediction Module + Blockchain Trust Layer)

[0134] ① The blockchain trust layer synchronizes the “feature data + defense parameters + execution effect” of this attack to the scene feature profile module of the scene adaptive configuration layer, and updates the scene profile of “power grid - thunderstorm weather”: the proportion of composite attacks increases to 70%, and the high-risk period is extended to 16:00-17:30;

[0135] ② The dynamic configuration engine module uses a reinforcement learning optimizer to match the updated scene profile and adjust parameters: the basic weight of the CNN model is increased to 0.45, the consensus threshold is maintained at 70%, and the basic computing power allocation ratio is updated synchronously. After the accuracy rate is verified by digital twin to be 98% (≥97%), the configuration is put on the chain through the notarization contract and takes effect.

[0136] ③ The collaborative control layer summarizes the operational data of each layer: detection time 21ms, computing power utilization 68%, attribution time 8s, and pushes it to the risk prediction module to trigger incremental training of the attack history time series analysis module and optimize the risk assessment model for each period.

[0137] III. Summary of Key Process Indicators and Hierarchical Linkages

[0138] Risk forecast lead time 340ms Risk prediction module Computing power scheduling response time 38ms Risk prediction module + blockchain trust layer Attack detection confidence (corrected) 97% AI defense layer + physical verification layer Attack attribution accuracy 96% Attack attribution layer Defense command execution time 18ms Blockchain Trust Layer Total time for the entire process 205ms Seven-layer architecture collaboration Scene parameter update verification accuracy 98% Scene Adaptive Configuration Layer

[0139] As can be seen, this invention takes the collaborative control layer as the central hub, the risk prediction module drives the pre-scheduling of computing power, the AI ​​defense layer and the physical verification layer realize "digital-physical" dual verification, the attack tracing layer relies on blockchain to complete credible attribution, and finally achieves self-optimization of the architecture through the scenario adaptation layer, forming a complete closed loop of "prediction-detection-verification-tracing-decision-execution-iteration".

[0140] Since the systems / devices described in the above embodiments of the present invention are systems / devices used to implement the methods of the above embodiments of the present invention, those skilled in the art can understand the specific structure and modifications of the systems / devices based on the methods described in the above embodiments of the present invention, and therefore will not be repeated here. All systems / devices used in the methods of the above embodiments of the present invention fall within the scope of protection of the present invention.

[0141] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0142] It should be noted that, in the description of this specification, the terms "one embodiment," "some embodiments," "embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0143] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the claims should be interpreted to include both the preferred embodiments and all changes and modifications falling within the scope of the invention.

[0144] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, then this invention should also include these modifications and variations.

Claims

1. A power grid security defense system based on artificial intelligence and blockchain, characterized in that, It includes an AI defense layer, a blockchain trust layer, a collaborative control layer, an attack tracing and attribution layer, a physical-information fusion verification layer, a scenario adaptive configuration layer, and a risk prediction module. The seven-layer architecture is modular, coupled, and interconnected. The AI ​​defense layer integrates multi-source data acquisition, feature engineering, multi-model fusion detection and model immunity modules. It integrates time series, deep learning and anomaly detection models to identify attacks and protects itself through pre-filtering and incremental training. The blockchain trust layer adopts a consortium blockchain architecture, verifies and stores evidence data through reputation-weighted consensus, responds automatically through smart contracts, stores historical attack data on-chain, and encrypts and protects privacy. The collaborative control layer synchronizes and verifies data from each layer, and generates defense and computing power strategies by combining multi-dimensional information. The attack tracing and attribution layer constructs a three-dimensional link graph, generates a tracing evidence package with time period labels, and uploads it to the blockchain for attribution. The physical-information fusion verification layer collects physical features, fuses digital features for verification, and uses digital twins to verify instruction adaptability. The scene adaptive configuration layer generates a scene profile and adjusts parameters and computing power allocation through reinforcement learning. The risk prediction module integrates risk factors to predict risks, assesses the risk of a period through attack history analysis, and allocates computing power accordingly. The cross-layer interface module of the collaborative control layer adopts RESTful API to convert detection results, traceability data, verification results, risk prediction results and computing power requirements into a blockchain-readable key-value pair format. Before data transmission, a verification hash is generated using SHA-256. The defense decision module has a built-in decision tree model. Based on the attack type, scope of impact, power grid load status, virtual and real verification results, risk prediction level and risk level of historical attack periods, it outputs defense priorities and computing power allocation schemes. The priorities are divided into four levels: early warning pre-scheduling, emergency isolation, current limiting protection and alarm prompts. The computing power allocation is calculated according to "multi-model weight ratio × risk level coefficient". The scene feature profiling module of the scene adaptive configuration layer uses the K-means clustering algorithm to generate four types of scene profiles—transmission network, distribution network, microgrid, and energy storage grid connection—based on historical data stored on the blockchain. The dynamic configuration engine module uses a reinforcement learning optimizer to match the scene profiles and adjust the AI ​​model weights, blockchain consensus thresholds, and basic computing power allocation ratios. The configuration and verification module records parameter changes through the configuration of the evidence storage contract, and the changes take effect after the accuracy of digital twin verification exceeds a preset value. The risk factor fusion module of the risk prediction module divides risk factors into four categories: attack precursors, equipment health, power grid operation, and environmental interference. Attack precursor factors come from AI defense layer feature data, equipment health factors come from historical verification data of the physical state perception module, power grid operation factors come from load and voltage data stored on the blockchain, and environmental interference factors come from temperature, humidity, and electromagnetic interference data collected by sensors. After Z-score standardization, a 32-64 dimensional risk factor vector is generated.

2. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The AI ​​defense layer's multi-source data acquisition module integrates voltage transformers, current transformers, and status monitoring sensors. It collects power grid equipment operation data, communication traffic data, and environmental parameters via the MQTT protocol. The feature engineering module extracts temporal features using empirical mode decomposition and filters attack-related features using an attention mechanism, outputting 64-256 dimensional feature vectors. The multi-model fusion detection module includes parallel LSTM networks, CNN networks, and isolated forest models. It outputs detection results through weighted voting fusion, with weights dynamically adjusted based on the historical detection accuracy of each model. The model immunity module identifies anomalous data with backdoors through a pre-filter, uses ensemble learning to incrementally train the model, and updates the parameters regularly.

3. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The blockchain trust layer adopts a consortium blockchain architecture, with at least five nodes including the power grid dispatch center, substations, and third-party audit nodes. The reputation-weighted consensus module uses the PBFT algorithm to calculate reputation values ​​based on the credibility of nodes' historical behavior and their real-time detection contributions, with voting weights positively correlated with reputation values. The smart contract module includes six contracts: attack response, model update, permission freezing, configuration notarization, risk warning, and computing power scheduling, which respectively implement node isolation, parameter notarization, account disabling, configuration recording, resource pre-scheduling, and computing power allocation functions. The privacy encryption module uses an encryption scheme, authorizing only the AI ​​model to decrypt and extract features.

4. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The attack chain analysis module of the attack tracing and attribution layer integrates graph neural networks and traffic tracing algorithms, and constructs a three-dimensional attack chain graph of "device-data-communication" based on the attack features output by the AI ​​defense layer; the blockchain tracing certificate generation module generates a tracing evidence package containing "attack initiation timestamp, propagation node hash, feature matching verification value, and occurrence time label" by improving the Merkle tree structure; the intelligent attribution contract module has a built-in attribution decision model, matches the tracing evidence package with the operation and maintenance records stored on the blockchain, and outputs the attribution result.

5. The power grid security defense system based on artificial intelligence and blockchain according to claim 1, characterized in that, The physical state perception module of the physical-information fusion verification layer includes a vibration sensor and an infrared thermometer. It acquires physical characteristics such as device vibration frequency and shell temperature through edge computing nodes, and the sampling frequency is synchronized with the digital data. The virtual-real feature fusion verification module uses an attention mechanism to fuse digital and physical feature vectors and dynamically adjusts the attack confidence based on the fusion result. The digital twin linkage verification module inputs physical data into the twin model to simulate the impact of defense commands on physical devices.

6. The power grid security defense system based on artificial intelligence and blockchain according to claim 3, characterized in that, The Spatiotemporal Graph Transformer prediction module uses the power grid topology as a graph structure and risk factor vectors as graph node features. It integrates the risk evolution law in the time dimension and the equipment correlation in the spatial dimension through a spatiotemporal attention mechanism, and outputs four results: "attack occurrence probability, operational failure risk value, impact radius, and early warning lead time". The risk-defense linkage module interacts with the collaborative control layer through risk warning contracts to trigger pre-allocation of computing power, pre-transfer of load, or pre-isolation according to the risk level.

7. The power grid security defense system based on artificial intelligence and blockchain according to claim 3, characterized in that, The attack history time-series analysis and computing power pre-schedule module retrieves attack history data from the blockchain for the most recent preset time period, including attack occurrence time, type, detection time, and computing power requirement tags. After Z-score standardization, a time-series dataset is constructed according to "scenario-time period-attack type". The temporal attention LSTM model is used to learn the correlation patterns and output three levels of risk level results: low, medium, and high. The computing power requirement is calculated by combining the basic computing power allocation ratio and risk level coefficient, generating an allocation table and triggering a computing power scheduling contract. Data is collected once per hour to feed back to the model for incremental training.