Novel source load-oriented power distribution network sensitive data flow anomaly detection method and system
By using three-dimensional correlation modeling and multivariate consistency analysis, the problems of collaborative attacks and abnormal data location in new source-load access distribution networks are solved, and efficient anomaly detection and rapid response of distribution networks are achieved.
Patent Information
- Application Number
- CN202511882946.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-15
- Publication Date
- 2026-03-06
AI Technical Summary
Existing technologies struggle to effectively identify coordinated attacks, lack consistency verification, and face difficulties in locating abnormal data after new sources and loads are connected to the distribution network.
By employing three-dimensional correlation modeling and multivariate consistency analysis, the temporal, physical, and topological dimensions of distribution network data are defined. A correlation fusion matrix is used to generate a fusion feature vector, a cross-validation function is constructed for multi-dimensional verification, weights are dynamically adjusted, and a propagation model is established for anomaly localization.
It enables accurate identification and rapid location of coordinated attacks, reduces false alarm rate, improves detection performance and operation and maintenance efficiency, and meets the real-time monitoring needs of power distribution networks.
Smart Images

Figure CN121615047A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system security protection technology, and in particular to a method for detecting anomalies in sensitive data streams of distribution networks for new types of sources and loads. This method is applied to the security monitoring and anomaly detection of distribution networks with new sources and loads such as distributed photovoltaics, energy storage systems, and charging piles. Background Technology
[0002] With the advancement of new power system construction, large-scale integration of new power sources such as distributed photovoltaics, energy storage devices, and electric vehicle charging stations into the distribution network is driving the traditional distribution network towards deep integration of power sources, grids, loads, and storage. This transformation has significantly increased the complexity of data flows, mainly manifested in the multi-source heterogeneity of data, strong spatiotemporal coupling, and dynamic evolution characteristics. Simultaneously, the digitalization and intelligentization of the distribution network have also brought new cybersecurity challenges. Cyberattack methods are becoming increasingly sophisticated, evolving from traditional denial-of-service attacks to meticulously designed fake data injection attacks, posing a serious threat to the safe and stable operation of the power grid.
[0003] Existing technologies for anomaly detection in sensitive data streams mainly include three types. The first is threshold-based anomaly detection, which sets fixed or dynamic thresholds for measurements such as voltage, current, and power. Measurements exceeding these thresholds are considered anomalies. The drawback is that it can only detect single-point anomalies and cannot identify coordinated attacks that meet threshold constraints but violate system correlations. The second method is state estimation-based anomaly detection, which uses weighted least squares (WLS) state estimation and residual analysis to identify bad data. The drawback is that it relies on accurate physical models and has poor adaptability to the randomness and intermittency of novel source loads. Furthermore, carefully crafted fake data injection attacks can bypass residual checks, making the attack data conform to physical constraints. The third method is machine learning-based anomaly detection, which uses algorithms such as deep learning and support vector machines to learn normal behavior patterns and classify data deviating from normal patterns as anomalies. The drawback is that it independently analyzes temporal, physical, and topological features, ignoring the blind spots of inherent consistency between dimensions, and has a high false positive rate because it cannot identify anomalies where a single dimension is normal but multiple dimensions are inconsistent. Therefore, a novel detection method is needed that can achieve multi-dimensional cross-validation, preserve dimensional coupling information, and accurately locate anomaly sources. Summary of the Invention
[0004] The technical problem to be solved by this invention is: how to solve the problems of isolated analysis dimensions, lack of consistency verification, and difficulty in locating abnormal data in the existing technology when detecting collaborative attack data faced by the distribution network after the access of new sources and loads.
[0005] To solve the above-mentioned technical problems, the present invention adopts the following technical solution:
[0006] A method for detecting anomalies in sensitive data streams in distribution networks for novel source loads includes:
[0007] Step 1: Define the three-dimensional space of the distribution network data, including:
[0008] Time series dimension : Represents the time evolution characteristics of data;
[0009] physical dimension : Indicates the electrical and physical constraints that the data satisfies;
[0010] Topology Dimension : Represents the spatial distribution characteristics of data, reflecting network structural constraints;
[0011] Step 2, using the correlation fusion matrix The associated features are fused to generate a fused feature vector, the associated fusion matrix. Includes three-dimensional coupling information;
[0012] Step 3: Construct three cross-validation functions and use them to perform cross-validation across different dimensions of time series, physical, and topology. Use the generated fused feature vector as the input to the cross-validation functions to obtain the validation error results.
[0013] Step 4: Dynamically adjust the overall consistency metric based on historical verification error results. The weighting coefficients in the formula are used to calculate the overall consistency measure.
[0014] Step 5: When the overall consistency metric exceeds the threshold, an anomaly is identified, and a propagation model for the anomalous data across different dimensions is created.
[0015] Step 6: Based on the observed comprehensive consistency measure The error is calculated by using the propagation model to solve the anomaly source in reverse through sparse optimization, thereby achieving anomaly localization.
[0016] The aforementioned method for detecting anomalies in sensitive data streams of a distribution network for novel source-load applications, in step one,
[0017] The time-series dimension Including trends, cycles, and sudden changes;
[0018] In the physical dimension In this context, the electrical physical constraints include power balance and voltage constraints.
[0019] In the aforementioned method for detecting anomalies in sensitive data streams of a new type of power distribution network source and load, the three-dimensional coupling information in step two is represented as follows:
[0020]
[0021]
[0022] in, This represents a time-series feature vector, including time-series statistics such as trends, periods, and abrupt changes. This represents a physical characteristic vector, including physical quantities such as power balance residuals and voltage limit exceedance. This represents a topological feature vector, including network structural features such as node degree and adjacency correlation. Indicates unit element, Representing dimensions With dimension The correlation coefficient between them is calculated from mutual information. This represents the fused feature vector, which includes the original features in three dimensions and cross-correlation information.
[0023] The correlation coefficient Calculated using mutual information and information entropy:
[0024]
[0025] in, Dimension and dimensions Mutual information between dimensions represents the degree to which the uncertainty about another dimension is reduced after knowing the data in one dimension.
[0026] In the aforementioned method for detecting anomalies in sensitive data streams of a new type of source-load distribution network, the three cross-validation functions in step three include:
[0027] Time-Physical Cross-Validation This is used to verify the consistency between time series predictions and physical constraints, and is expressed as:
[0028]
[0029] in: This represents the amount of power change predicted based on time-series characteristics. Represents the Jacobian matrix of current trends. Given the Euclidean norm, calculate the square root of the sum of the squares of the elements of the vector. This represents the phase angle change that satisfies the physical constraints, obtained by solving the equation based on the power balance constraints defined in the physical dimension in step one;
[0030] Physics-topology cross-validation This is used to verify the consistency between power flow distribution and topology, and is represented as:
[0031] Among them, the power flow distribution matches the current topology. Represents nodes in a distribution network To the node The measured value of active power. Represents a node and The admittance magnitude between , Representing nodes respectively , voltage amplitude, Represents a node and The voltage phase angle difference between them;
[0032] Topology-Time Cross-Validation This is used to verify the consistency between state transitions and topological constraints, and is expressed as:
[0033] ;
[0034] in: Indicates based on the current topology By utilizing electrical distance and network connectivity, the conditional transition probabilities of adjacent node states are calculated. Represents the state transition probability based on time sequence. This represents the divergence.
[0035] In the aforementioned method for detecting anomalies in sensitive data streams of distribution networks based on novel source loads, step four involves calculating dynamic weights:
[0036]
[0037] in, The standard deviation of historical verification error. The temperature parameter in the softmax function controls the concentration of weight distribution. For the first Dynamic weights for cross-validation across two dimensions, including time-to-physical cross-validation. Physical-topological cross-validation Topology-temporal cross-validation , The set of standard deviations of all cross-validation historical errors. It is a natural exponential function;
[0038] The comprehensive consistency metric It is a weighted sum of the three cross-validation error results, expressed as:
[0039] .
[0040] In the aforementioned method for detecting anomalies in sensitive data streams of a new type of source-load distribution network, the propagation model in step five is expressed as follows:
[0041]
[0042] in, For the deviation vector, The inter-dimensional propagation matrix is a 3×3 matrix. Representing dimensions Deviation on dimension The propagation coefficient, The input matrix is 3× matrix, To monitor the number of nodes, Represents a node Exception injection on dimensions The direct impact coefficient, Represents the abnormal injection vector. The attenuation coefficient;
[0043] Solve for the propagation path:
[0044] in, express The propagation path solution at time t. This represents the initial deviation vector. Let represent the integral variable, and represent the historical moment. The matrix exponent represents the propagation matrix. The time evolution operator.
[0045] In the aforementioned method for detecting anomalies in sensitive data streams of a new type of power distribution network source and load, in step 5, the propagation model adopts a discrete-time propagation model, a graph Laplace-based propagation model, or a hierarchical cascaded propagation model.
[0046] In the aforementioned method for detecting anomalies in sensitive data streams of a distribution network oriented towards novel source loads, step six represents the optimal anomaly source vector as follows:
[0047]
[0048] in, This indicates that sparsity is controlled and obtained using LASSO regression.
[0049] The optimal anomaly source vector is the anomaly injection location obtained by solving the problem. This indicates the parameter values that minimize the objective function. This is the observation deviation vector, which represents the deviation between the actual measured value and the expected normal value. For the propagation function, Let be the anomaly source vector to be solved. Let L1 norm represent the source vectors of each anomaly. The sum of absolute values is used to promote sparsity of solutions.
[0050] A computer system includes a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method described above.
[0051] A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described above.
[0052] The technical effects achieved by this invention are as follows: The method of this invention, through three-dimensional correlation modeling and multivariate consistency analysis, can effectively identify coordinated attacks and hidden threats that cannot be detected by single-point detection. By modeling the data flow propagation patterns, it can accurately identify abnormal patterns, significantly improving the detection accuracy of cross-device coordinated tampering attacks and significantly reducing the false alarm rate, thus improving overall detection performance. Temporal consistency analysis employs multi-scale parallel processing, and topology consistency achieves rapid location through a pre-constructed two-layer topology, enabling a comprehensive response time down to the second level, meeting the needs of real-time monitoring of distribution networks. Simultaneously, this invention, through feature fusion, can quickly pinpoint key abnormal nodes, precisely converging the scope of anomaly analysis from all network nodes to a few key nodes, improving operational efficiency, reducing unnecessary equipment checks and power outages, and enabling rapid identification of complex attack patterns. Attached Figure Description
[0053] Figure 1 This is a schematic diagram of the three-dimensional cross-validation mechanism of the distribution network sensitive data stream anomaly detection method in Embodiment 1 of the present invention;
[0054] Figure 2 This is a flowchart of the distribution network sensitive data stream anomaly detection method in Embodiment 1 of the present invention;
[0055] Figure 3 This is a schematic diagram of deviation propagation in the distribution network sensitive data stream anomaly detection method in Embodiment 1 of the present invention;
[0056] Figure 4(a) is a graph of the original data during a distributed photovoltaic spoofing data injection attack in Example 1;
[0057] Figure 4(b) shows the output curves of the three cross-validation functions in Example 1;
[0058] Figure 4(c) shows a schematic diagram of the deviation propagation path in Example 1;
[0059] Figure 4(d) shows a schematic diagram of the positioning results in Example 1;
[0060] Figure 5(a) shows a comparison of experimental detection rates in Example 1;
[0061] Figure 5(b) shows a comparison of the false alarm rates in Example 1;
[0062] Figure 5(c) shows a comparison of the experimental positioning accuracy in Example 1;
[0063] Figure 5(d) shows a comparison of experimental response times in Example 1. Detailed Implementation
[0064] The invention will be further illustrated below with specific examples and accompanying drawings.
[0065] Example 1
[0066] like Figure 1-2 As shown, this embodiment provides a method for detecting anomalies in sensitive data streams of distribution networks oriented towards new source loads. It integrates information from three dimensions: time series, physical, and topology. First, it extracts system operation characteristics from the three dimensions. Then, it uses a cross-validation mechanism to discover inconsistencies between dimensions. Next, it analyzes the dynamic evolution of anomalies based on a deviation propagation model, and finally achieves accurate detection and source location of abnormal data.
[0067] A method for detecting anomalies in sensitive data streams in distribution networks for novel source loads includes:
[0068] Step 1: Define the three-dimensional space of the distribution network data, including:
[0069] Time series dimension : Indicates the time evolution characteristics of data, including trends, cycles, and abrupt changes;
[0070] physical dimension : Indicates the electrical and physical constraints that the data satisfies, including power balance, voltage constraints, etc.;
[0071] Topology Dimension : Represents the spatial distribution characteristics of data, reflecting network structure constraints.
[0072] Step 2, using the correlation fusion matrix The associated features are fused to generate a fused feature vector, the associated fusion matrix. Including three-dimensional coupling information, represented as:
[0073]
[0074]
[0075] in, This represents a time-series feature vector, including time-series statistics such as trends, periods, and abrupt changes. This represents a physical characteristic vector, including physical quantities such as power balance residuals and voltage limit exceedance. It represents the topological feature vector, including network structural features such as node degree and adjacency correlation. This represents the unit element, with a value of 1, indicating the baseline weight of each dimension. Representing dimensions With dimension The correlation coefficient between them is calculated from mutual information and takes values in the range [0,1]. This represents a fused feature vector, which includes the original features in three dimensions and cross-correlation information.
[0076] The correlation coefficient Calculated using mutual information and information entropy:
[0077]
[0078] in, Representing dimensions and dimensions Mutual information between dimensions represents the degree to which the uncertainty about another dimension is reduced after knowing data in one dimension. For example, Mutual information represents the reduction in uncertainty in predicting the physical state after knowing the temporal characteristics. Higher mutual information indicates a stronger statistical dependency between the two dimensions. , Representing dimensions and dimensions Information entropy represents the uncertainty of data in a certain dimension. The formula for calculating information entropy is: The unit is bit, such as p represents the degree of uncertainty inherent in time series data. Represents random variables The probability of occurrence.
[0079] Step 3: Construct three cross-validation functions and use them to perform cross-validation across different dimensions (temporal, physical, and topological). Then, combine the fused feature vector generated in Step 2. The results are used as input to the cross-validation function to obtain the validation error.
[0080] The fused features contain inter-dimensional coupling information, enabling cross-validation to consider multi-dimensional relationships simultaneously. The power prediction variation in time-to-physical validation is obtained from the fused features. Extracting temporal feature components The power flow values in the physical-topology verification are obtained from the time-series prediction model; the power flow values are obtained from the fused features. Extracting physical feature components Obtaining state transition probabilities in topology-temporal verification based on fused features. Topological feature components in Calculated jointly with time-series feature components .
[0081] The three cross-validation functions include:
[0082] Time-Physical Cross-Validation This is used to verify the consistency between time series predictions and physical constraints, and is expressed as:
[0083]
[0084] in: This represents the power change predicted based on time-series characteristics. The autoregressive moving average model is used to predict historical power data, and the original input data is the historical power measurement sequence of each node in the distribution network. Represents the Jacobian matrix of current trends. Given the Euclidean norm, calculate the square root of the sum of the squares of the elements of the vector. This represents the phase angle change that satisfies the physical constraints, obtained by solving the equation based on the power balance constraints defined in the physical dimension in step one.
[0085] Physics-topology cross-validation This is used to verify the consistency between power flow distribution and topology, and is represented as:
[0086] Among them, the power flow distribution matches the current topology. Represents nodes in a distribution network To the node The measured value of active power. Represents a node and The admittance magnitude between , Representing nodes respectively , voltage amplitude, Represents a node and The voltage phase angle difference between them. , , , All data originates from the three-dimensional space of the distribution network data defined in step one: Power measurement data in the physical dimension, , Representing nodes respectively ,node Voltage measurement data in the physical dimension, voltage phase angle difference The admittance magnitude is calculated from the electrical constraints of the physical dimension. These are the network structure parameters in the topology dimension.
[0087] Topology-Time Cross-Validation This is used to verify the consistency between state transitions and topological constraints, and is expressed as:
[0088] ;
[0089] in: Indicates based on the current topology By utilizing electrical distance and network connectivity, the conditional transition probabilities of adjacent node states are calculated. Represents the state transition probability based on time sequence. This represents the divergence.
[0090] The state changes of adjacent nodes are correlated. Due to the power propagation characteristics, a change in the power of a node will affect adjacent nodes through the network. Under normal circumstances, the state changes of adjacent nodes are temporally correlated. If a node changes but adjacent nodes do not respond, there may be data anomalies.
[0091] Step 4: Dynamically adjust the overall consistency metric based on historical verification error results. The weighting coefficients are used to calculate the overall consistency metric. .
[0092]
[0093] in, The standard deviation of historical verification error. The temperature parameter in the softmax function controls the concentration of weight distribution and is independent of the physical temperature. For the first Dynamic weights for cross-validation across two dimensions, including time-to-physical cross-validation. Physical-topological cross-validation Topology-temporal cross-validation , For the set of standard deviations of all cross-validation historical errors, It is a natural exponential function.
[0094] The comprehensive consistency metric It is a weighted sum of the three cross-validation error results, expressed as:
[0095] .
[0096] Step 5, when integrating consistency metrics When a threshold is exceeded, an anomaly is identified, and a propagation model for the anomaly data across different dimensions is created, represented as follows:
[0097]
[0098] in, For the deviation vector, The inter-dimensional propagation matrix is a 3×3 matrix. Representing dimensions Deviation on dimension The propagation coefficient. For example... This indicates the strength of the propagation of physical dimension deviations into the temporal dimension. The input matrix is 3× matrix, To monitor the number of nodes, such as Represents a node Exception injection on dimensions The direct impact coefficient, Represents the anomaly injection vector, which is dimensional vector, such as express Time Node The abnormal injection amplitude is 0 for normal nodes. The attenuation coefficient;
[0099] Solve for the propagation path:
[0100] in, express The propagation path solution at time t is the cumulative deviation. This represents the initial deviation vector. Let represent the integral variable, and represent the historical moment. The matrix exponent represents the propagation matrix. The time evolution operator.
[0101] Step 6: Based on the observed comprehensive consistency measure The error is calculated by using the propagation model to solve the anomaly source in reverse through sparse optimization, thereby achieving anomaly localization.
[0102] The optimal anomaly source vector is represented as:
[0103]
[0104] in, This indicates that sparsity can be controlled and can be obtained using LASSO regression.
[0105] The optimal anomaly source vector is the anomaly injection location obtained by solving the problem. This indicates the parameter values that minimize the objective function. This is the observation deviation vector, which represents the deviation between the actual measured value and the expected normal value. For the propagation function, Let be the anomaly source vector to be solved. Let L1 norm represent the source vectors of each anomaly. The sum of absolute values is used to promote sparsity of solutions.
[0106] In step six, a greedy algorithm can also be used to solve the problem.
[0107] Figure 1 The middle represents the timing. ,physics Topology Cross-validation relationships between the three dimensions. The diagram uses bidirectional arrows to represent mutual validation between dimensions: T←→P represents time-physical validation. P←→G represents physical-topology verification. G←→T represents topology-time verification. The center displays a comprehensive consistency metric. .
[0108] Figure 3 This is a schematic diagram of the deviation propagation model, representing the propagation of abnormal data from the injection point through the propagation matrix. The process of propagation across three dimensions. The horizontal axis represents time. The vertical axis represents the magnitude of the deviation. The three curves represent the time-series deviations. Physical dimension deviation Topological dimensional deviation The changes. Figure 3 This is a visualization of the deviation propagation model in step five. The three curves correspond to the deviation vector. The evolution of the three components over time: when abnormal data is injected into a node, an initial bias is first generated in that dimension. The deviation is propagated through the propagation matrix. They influence and propagate among the three dimensions, while being subject to attenuation coefficients. The effect of this is that the deviation amplitude gradually decreases over time. By observing the start time and amplitude relationship of the three curves, the source location of the abnormal injection can be deduced.
[0109] Figure 4 illustrates the detection process of a distributed photovoltaic (PV) spoofing data injection attack. Figure 4(a) shows the original data curves, displaying the output of five PV sites. Figure 4(b) shows the output curves of three cross-validation functions. A clear anomaly was observed; Figure 4(c) shows the deviation propagation path, tracing the source of the anomaly; Figure 4(d) shows the location results, accurately identifying 5 abnormal nodes.
[0110] Figure 5 shows the performance comparison results of the method of the present invention and the existing methods. Figure 5(a) is a comparison of detection rates, with the horizontal axis representing attack intensity and the vertical axis representing detection rate. The method of the present invention maintains a high detection rate under different attack intensities. Figure 5(b) is a comparison of false alarm rates. The false alarm rate of the method of the present invention is significantly lower than that of the traditional method. Figure 5(c) is a comparison of location accuracy. The method of the present invention can accurately locate the source of abnormal data. Figure 5(d) is a comparison of response time. The detection response time of the method of the present invention meets the real-time monitoring requirements of the power distribution network.
[0111] Example 2
[0112] Based on the technical solution of Embodiment 1, in step 5, the propagation model may also be a discrete-time propagation model, a graph Laplace-based propagation model, or a hierarchical cascade propagation model.
[0113] The discrete-time propagation model is expressed as: ;
[0114] The propagation model based on the Graph Laplace is expressed as follows: ;
[0115] for The state vector of each node at each time step For the eigenvalues of the graph Laplacian matrix, The adjacency matrix of the graph, For the input matrix, Let be the graph Laplace matrix.
[0116] Example 3
[0117] A computer system includes a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to perform the steps of the methods as described in Examples 1-2.
[0118] Example 4
[0119] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the methods described in Examples 1-2.
[0120] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0121] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0122] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0123] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A power distribution network sensitive data flow anomaly detection method for new source and load, characterized in that, The method comprises the following steps: Step 1: defining a three-dimensional space of power grid data, comprising: a time sequence dimension representing the time evolution characteristics of the data; a physical dimension representing the electrical physical constraints satisfied by the data; and a topology dimension representing the spatial distribution characteristics of the data, reflecting the network structure constraints; Step 2: fusing the correlation features by using a correlation fusion matrix to generate a fusion feature vector, wherein the correlation fusion matrix comprises three-dimensional coupling information; Step 3: constructing three cross-validation functions, and cross-checking the time sequence, physical, and topology dimensions by using the three cross-validation functions, taking the generated fusion feature vector as the input of the cross-validation functions to obtain a verification error result; Step 4: dynamically adjusting the weight coefficient in the comprehensive consistency measure according to the historical verification error result, and calculating the comprehensive consistency measure according to the weight coefficient; Step 5: determining that an anomaly exists when the comprehensive consistency measure exceeds a threshold value, and then creating a propagation model of the abnormal data among different dimensions; Step 6: inversely solving the abnormal source by sparse optimization according to the observed error of the comprehensive consistency measure and by using the propagation model, so as to realize abnormal positioning.
2. The method of claim 1, wherein the method is a method of detecting abnormal data flow of a power distribution network oriented to a new source and load, characterized by, In step one, the time dimension includes trends, cycles, discontinuities; in the physical dimension the electrical physical constraints include power balance, voltage constraints.
3. The method of claim 1, wherein the method is a method of detecting abnormal data flow of a power distribution network oriented to new source and load, characterized in that, In step 2, the three-dimensional coupling information is represented as: ; ; wherein, denotes the time series feature vector, including time series statistics such as trend, period, mutation, etc., denotes the physical feature vector, including power balance residual, voltage out-of-limit degree physical quantity, denotes the topology feature vector, including node degree, adjacency correlation network structure features, denotes the unit element, denotes the dimension between the dimensions is the correlation coefficient, calculated by mutual information, denotes the fusion feature vector, including the original features of the three dimensions and the cross-correlation information; The correlation coefficient By mutual information and information entropy calculation: ; where, represents the mutual information between dimensions and dimensions represents the degree of uncertainty reduction in one dimension given the other.
4. The method of claim 3, wherein the method is a method of detecting abnormal data flow of a power distribution network oriented to a new source and load, characterized by, In step 3, the three cross-validation functions comprise: Temporal-physical cross-validation for verifying consistency of temporal predictions with physical constraints, denoted as: ; wherein: represents the predicted power variation based on the timing characteristics, represents the power flow Jacobian matrix, is the Euclidean norm, represents the phase angle variation satisfying the physical constraints, which is obtained by solving the equation according to the power balance constraint defined in the physical dimension in step one; Physical-topology cross-validation , for verifying consistency of power flow distribution with topology, is expressed as: ; wherein the power flow distribution matches the current topology, denotes a node in the distribution network, denotes a node in the distribution network, denotes a measured active power value to the node denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, denotes a node in the distribution network, Topology-chronology cross-validation for verifying consistency of state transitions with topology constraints, denoted as: ; wherein: denotes the state transition probability based on the current topology , the conditional transition probability of the neighboring node state is calculated using the electrical distance and the network connection relationship, denotes the state transition probability based on the timing, denotes the divergence.
5. The method of claim 4, wherein the method is a new source and load oriented power distribution network sensitive data flow anomaly detection method, characterized in that, In step 4, the dynamic weight is calculated as: ; where, is the standard deviation of the history validation error, is the temperature parameter in the softmax function, used to control the degree of concentration of weight distribution, is the first Dynamic weights for two-dimensional cross-validation, including time-physical cross-validation , physical-topology cross-validation , topology-time cross-validation , is the set of standard deviations of all cross-validation history errors, is the natural exponential function; The integrated consistency measure is a weighted sum of three cross-validation error results, expressed as: 。 6. The method of claim 1, wherein, In step 5, the propagation model is represented as: ; wherein, is a bias vector, is an inter-dimension propagation matrix, being a 3x3 matrix, denotes a dimension of a bias on a dimension of a propagation coefficient, is an input matrix, being a 3x matrix, is a number of monitoring nodes, denotes a direct influence coefficient of an anomaly injection on a dimension of a node , denotes an anomaly injection vector, is a decay coefficient; Solve propagation path: ; wherein denotes the propagation path solution at time denotes the initial bias vector, denotes the integral variable, denotes the history time, is the matrix exponential, denoting the time evolution operator of the propagation matrix .
7. The method of claim 1, wherein the method is a method of detecting abnormal data flow of a power distribution network oriented to new source and load, characterized in that, In step 5, the propagation model adopts a discrete-time propagation model, a graph Laplacian-based propagation model, or a hierarchical cascading propagation model.
8. The method of claim 1, wherein, In step 6, the optimal abnormal source vector is represented as: ; wherein, denotes the control sparsity, obtained by solving using LASSO regression; for the optimal anomaly source vector, i.e. the solved anomaly injection location, denotes the parameter values that minimize the objective function, is the observation bias vector, i.e. the deviation between the actual measurement and the normal expectation, is the propagation function, is the anomaly source vector to be solved, is the LI norm, denoting the sum of absolute values of each anomaly source vector to promote sparsity of the solution.
9. A computer system comprising a memory, a processor and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the steps of the power grid sensitive data flow anomaly detection method for new source load in any one of claims 1-8.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the power grid sensitive data flow anomaly detection method for new source load in any one of claims 1-8.