Vulnerability analysis method of multi-time scale micro-grid under FDI attack
By using singular perturbation theory and the zonotope method, DC microgrids are decomposed into fast and slow subsystems, and stability conditions and state deviation ranges are derived. This solves the vulnerability analysis problem of DC microgrids under FDI attacks at multiple time scales, and achieves accurate quantification and effective protection of the system's security boundary.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-03-13
AI Technical Summary
Existing technologies lack systematic analysis and quantitative assessment of DC microgrid systems under FDI attacks across multiple time scales, especially vulnerability analysis methods under the coupling effects of different control scales, making it difficult to identify and defend against security risks from cyberattacks.
A distributed generation unit model is constructed using singular perturbation theory. The DC microgrid is decomposed into a fast boundary layer subsystem and a slow descending order subsystem. The sufficient condition for system stability under spurious data injection attack is derived. The range of state deviation is estimated using the zonotope method, and the safe operating boundary of the system under attack is quantified.
This study achieves quantitative vulnerability analysis of DC microgrids under FDI attacks across multiple time scales, clarifies the safe operation boundary of the system under network attacks, guides control and protection measures in practical engineering, and verifies the effectiveness of the method through numerical simulation and hardware experiments.
Smart Images

Figure CN121663532A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of microgrid control technology, and in particular to a vulnerability analysis method for multi-timescale microgrids under FDI attacks. Background Technology
[0002] With the increasing severity of the energy crisis and the growing demands for environmental protection, distributed energy sources, represented by photovoltaic systems and wind power, are gradually becoming an important component of modern power systems. DC microgrids, as an advanced technology that efficiently integrates distributed energy, energy storage systems, and controllable loads, play a crucial role in improving the flexibility, reliability, and local energy autonomy of power systems, and have become one of the hot topics in modern power system research. DC microgrids typically employ a hierarchical control structure, including primary control responsible for rapid local voltage regulation and secondary control responsible for eliminating steady-state errors, achieving current sharing, and voltage balance. Primary control typically achieves a fast response within milliseconds (1-5 ms), while secondary control relies on communication networks and distributed algorithms, with a lower update frequency (typically 50-200 ms). This multi-timescale control architecture not only improves the flexibility of system operation but also introduces new potential security risks. In recent years, with the widespread application of information and communication technologies in power systems, the networking degree of DC microgrid systems has continuously improved, but the problem of False Data Injection (FDI) attacks has also gradually become prominent. FDI attacks, by tampering with measurement data, disrupting communication protocols, or implanting false control commands, can lead to erroneous control actions, uneven current distribution, and even voltage instability in the power grid, seriously threatening the safe and stable operation of microgrids. Particularly in microgrids with multi-timescale hierarchical control structures, attacks may be carried out through the communication channels of the slow secondary control layer. This type of attack is often highly concealed, difficult to identify quickly, and can cause serious security consequences. However, current research on network attack analysis and defense for multi-timescale DC microgrid systems largely focuses on simple models of steady-state or single control scales, lacking systematic analysis and quantitative assessment of the dynamic impact of attacks, and especially lacking methods for analyzing system vulnerabilities under the coupling effects of different control scales. Therefore, there is an urgent need to propose a security assessment method for multi-timescale DC microgrid systems under FDI attacks to clarify the safe operating boundaries of the system when subjected to network attacks and guide the effective implementation of control and protection measures in practical engineering. Summary of the Invention
[0003] The purpose of this invention is to address the shortcomings of existing technologies by proposing a vulnerability analysis method for multi-timescale microgrids under FDI attacks.
[0004] The objective of this invention is achieved through the following technical solution: a vulnerability analysis method for multi-timescale microgrids under FDI attacks, comprising:
[0005] S1. A hierarchical control architecture based on DC microgrids is proposed. A distributed generation unit (DGU) model is constructed based on singular perturbation theory. The dynamics of the primary and secondary controllers are defined, and an FDI attack model targeting the secondary control communication link is constructed.
[0006] S2. Construct a system aggregate state model under attack based on the DGU unit model and FDI attack model, and decompose the overall dynamic model of DC microgrid into a fast boundary layer subsystem and a slow descending order subsystem.
[0007] S3. Based on voltage balance and current sharing conditions, derive sufficient conditions for system stability under spurious data injection attack conditions; construct Lyapunov functions to predict state deviation variables for slow-decreasing subsystems.
[0008] S4. Use the zonotope method to estimate the state trajectory of the slow-decrease subsystem under attack, clarify the range of state deviation caused by the attack, calculate the worst state deviation that the system may reach under attack conditions, determine the boundary conditions for safe operation of the system, and quantify and determine the maximum allowable attack amplitude that the system can withstand.
[0009] Furthermore, the dynamics of the primary and secondary controllers are as follows: each DGU is equipped with a hierarchical controller, including a fast primary control for local voltage regulation and a slow secondary control for current sharing;
[0010] The primary controller is ,in , and These represent the gain of the feedback control; It is the voltage of the DGU at the common coupling point. It is the output current of the DGU. This refers to the internal controller state; the secondary control adopts a distributed control scheme, with a control frequency lower than the primary control, and its dynamics are as follows:
[0011] ;
[0012] In the formula, Represents nodes in a communication network With nodes The adjacency matrix elements, It is a node Transmitted to node The output current information, It corresponds to DGU Rated current, It corresponds to DGU Rated current, For DGU The set of neighbors in a communication network This indicates the time delay of the secondary control relative to the primary control.
[0013] Furthermore, the DGU unit model specifically includes:
[0014]
[0015] In the formula, It is the resistance of the circuit. It is the output voltage of the transformer. This refers to the load current in a ZIP load. The elements of the electrical network correlation matrix are represented as DGU. and edge Relationship; It is the impedance-type load admittance in a ZIP load. It is a node Transmitted to node The output current information, It is a constant power load in ZIP loads. Indicates the reference voltage at the common coupling point; , and These are the resistor, inductor, and capacitor parameters of the converter. This represents the edge connecting DGU. Represents a group DGU; It's DGU The physical coupling between it and its adjacent units, where Represents a node Output voltage; , , and These are design parameters that reflect electrical characteristics and local controller adjustments; , and This indicates the gain of the primary controller's feedback control. These are the control coefficients for secondary control. It is a secondary controller. These are singular perturbation parameters, the first... Each load is a parallel combination of ZIP loads.
[0016] Furthermore, the construction of the FDI attack model targeting the secondary control communication link specifically includes:
[0017] ;
[0018] In the formula, DGU was attacked The output current, It is a node Transmitted to node The output current information, It is the attack vector injected by the opponent. It is a step function, in The attack is activated at that time.
[0019] Furthermore, the system set state model under attack is specifically as follows:
[0020]
[0021] In the formula For state vectors, For the system matrix, , , , , , , , , , These are vector representations of the common coupling point voltage, filter output current, integrator state, load current, load power, reference voltage, and secondary controller, respectively. The elements of the electrical network correlation matrix are represented as DGU. and edge Relationship,
[0022] , , , A matrix of design parameters reflecting electrical characteristics and local controller regulation; vector Denotes the injected attack vector, where It is the adjacency matrix of the communication network. It is injected data The matrix, It is a binary mask that indicates the attacked link.
[0023] Furthermore, the decomposition of the overall dynamic model of the DC microgrid into a fast boundary layer subsystem and a slow descending-order subsystem specifically involves:
[0024] set up To solve algebraic equations And obtain the quasi-steady manifold:
[0025]
[0026] Substitute the quasi-steady manifold as X. The slow-decreasing subsystem model is obtained:
[0027]
[0028] Define boundary layer correction terms By setting The dynamics of the fast boundary layer subsystem are obtained as follows:
[0029] .
[0030] Furthermore, the derivation of the sufficient stability condition under the spurious data injection attack condition based on voltage balance and current sharing conditions specifically includes: constructing power flow constraints that must be satisfied to achieve current sharing and voltage balance based on the steady-state solution satisfaction conditions of the system; expressing the power flow constraints in fixed-point form; and obtaining the condition for the existence of a steady-state solution based on Banach's fixed-point theorem. ,in , express The false rebellion, Nominal voltage;
[0031] Then, based on the fact that the Jacobian matrix of the fast boundary layer subsystem satisfies the Routh-Hulwitz criterion, the condition for the stability of the subsystem is obtained: , , , ,in yes The Each feature value.
[0032] Furthermore, the specific details of constructing the Lyapunov function to predict the bias variable for the slow-decrease subsystem are as follows:
[0033] Define state deviation variables ,in It is the equilibrium point of the system when there is no attack; derive the dynamic equation of this deviation variable.
[0034] ,
[0035] in , , Constructing Lyapunov functions Obtain and output the following key relational expressions.
[0036] ,
[0037] Among them, norm It is the maximum amplitude of the injected attack signal, while the gain constant is... These are pre-calculated values determined by system parameters, among which... This is a stability parameter used to characterize the system's convergence rate. Representation matrix The smallest eigenvalue.
[0038] Furthermore, the estimation of the state trajectory of the slow-degrading subsystem under attack specifically includes:
[0039] A mapping relationship between voltage deviation and secondary control deviation is established. Based on the mapping relationship, the voltage safety constraint is transformed into an equivalent safety threshold for slow state deviation to obtain a safety set. The effects of attacks and nonlinearities are modeled as a bounded disturbance region topology. The slow reduced-order subsystem is dynamically transformed into a differential inclusion relationship. Finally, the over-approximation is calculated iteratively by propagating the reachable set on discrete steps. In each step, the acceptable attack amplitude is determined by verifying whether the reachable set remains within the safety set. By repeatedly evaluating a series of candidate attack amplitudes, the value that satisfies the safety constraint over the entire time range is selected as the allowable attack amplitude.
[0040] On the other hand, a vulnerability analysis device for multi-timescale DC microgrids under FDI attacks is also provided, including a memory and one or more processors. The memory stores executable code, and when the processor executes the executable code, it implements the vulnerability analysis method for multi-timescale microgrids under FDI attacks.
[0041] The beneficial effects of this invention are as follows: Compared to existing vulnerability analysis methods for DC microgrids, which are mostly limited to analysis under single time scales or steady-state conditions, this invention proposes a method for quantitative vulnerability analysis of DC microgrids under FDI attack conditions, targeting the dynamic characteristics of multi-time scale DC microgrids. This invention utilizes singular perturbation theory to clarify the stability conditions of fast and slow subsystems and establishes for the first time an input-to-state stability (ISS) model for the slow subsystem, achieving a deep understanding of the dynamic transmission characteristics of attack disturbances. Simultaneously, based on the zonotope reachable set analysis framework, this invention explicitly calculates the worst-case deviation range of the system state under attack disturbances, enabling precise quantification of the safe operating boundary of DC microgrids under network attack conditions. Furthermore, the proposed method has been rigorously verified through numerical simulations and full-hardware experiments. The results show that the proposed method can not only accurately predict the dynamic response characteristics of the system under multi-time scale conditions but also effectively guide the security protection design of practical DC microgrid systems against FDI attacks. Attached Figure Description
[0042] Figure 1 This is a schematic diagram of the method flow provided in an embodiment of the present invention;
[0043] Figure 2 This is a schematic diagram of the hierarchical control structure of a DC microgrid provided in an embodiment of the present invention;
[0044] Figure 3 This is a comparison of voltage and current responses with a control time scale of 1ms / 100ms under different attack intensities, provided by an embodiment of the present invention.
[0045] Figure 4 This is a comparison of voltage and current responses under different attack intensities, i.e., the secondary control cycle is increased to 200ms, as provided in the embodiments of the present invention.
[0046] Figure 5 This is the FDI attack response of a DC microgrid under different attack intensities on a non-separate control timescale provided in the embodiments of the present invention;
[0047] Figure 6 This is a schematic diagram of the device provided in an embodiment of the present invention. Detailed Implementation
[0048] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0049] It should be understood that the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0050] This invention provides a vulnerability analysis method for multi-timescale microgrids under FDI attacks. The method includes singular perturbation theory (DGU) modeling and attack modeling, DC power flow equation equilibrium point analysis, stability condition analysis under attack, design of a Zonotope reachability set analysis framework, and experimental verification. The process is as follows: Figure 1 As shown below, the specific implementation method of each step is explained in detail.
[0051] Step 1: DGU and attack modeling. Figure 2 This is a schematic diagram of the hierarchical control structure of the DC microgrid of the present invention. Based on the hierarchical control architecture of the DC microgrid, the control objectives are achieved according to different time scales. A DGU model is constructed based on singular perturbation theory, the dynamics of the primary and secondary controllers are defined, and an FDI attack model is designed. Figure 2 The electrical network in the DCmG shown is represented as an undirected graph. ,in Represents a group One DGU, and This indicates the connection to these DGUs. Edges (power lines). Define the electrical network affinity matrix. , of which elements DGU It is the edge The source; if DGU It is the edge The convergence. The communication network is represented by the diagram. It means that among them It is the set of nodes corresponding to DGU. Indicates a communication link.
[0052] Each DGU is equipped with a hierarchical controller, characterized by fast primary control for local voltage regulation and slow secondary control for current sharing. The primary controller is... It is a primary controller, in which , and These represent the gain of the feedback control; It is the voltage of the DGU at the common coupling point. It is the output current of the DGU. It is the internal controller state; These are the control coefficients for secondary control. It is a secondary controller, with a lower control frequency than the primary controller. The secondary controller adopts a distributed control scheme, and its dynamics are as follows:
[0053] ; (1)
[0054] In the formula, Represents nodes in a communication network With nodes The adjacency matrix elements, Represents a node With nodes There is a communication link between them, allowing them to exchange information; This indicates that there is no communication between the two parties. It is a node Transmitted to node The output current information, It corresponds to DGU Rated current, It corresponds to DGU Rated current, For DGU The set of neighbors in a communication network This indicates the time delay of the secondary control relative to the primary control.
[0055] Based on the hierarchical control architecture of DC microgrids, a DGU model is constructed using singular perturbation theory:
[0056] (2)
[0057] In the formula, It is the resistance of the circuit. It is the first in DC microgrids Bus voltage variation at each node This refers to the load current in a ZIP load. It is the impedance-type load admittance in a ZIP load. It is a constant power load in ZIP loads. Indicates the reference voltage at the common coupling point; , and These are the resistor, inductor, and capacitor parameters of the converter. This represents the edge connecting DGU. Represents a group A DGU. It's DGU The physical coupling between it and its adjacent units, where Represents a node Output voltage. , , and These are design parameters that reflect electrical characteristics and local controller adjustments. These are singular perturbation parameters, which distinguish between... , , rapid dynamics and The slower evolution. Each load is a parallel combination of ZIP loads, that is... Some variables are time-varying, but the time parameters have been omitted for the sake of brevity.
[0058] An FDI attack model targeting the communication link of secondary control is as follows:
[0059] ; (3)
[0060] In the formula, DGU was attacked The output current, It is the attack vector injected by the opponent. It is a step function, in The attack is activated at that time.
[0061] Step 2: Based on singular perturbation theory, the overall dynamic model of the DC microgrid is decomposed into a fast boundary layer subsystem and a slow reduced-order subsystem, clearly distinguishing the fast and slow dynamic characteristics of the system.
[0062] Step 2.1, Construct the system set state under attack:
[0063] (4)
[0064] In formula (4) For state vectors, Communication network diagram The Laplace matrix, It is the vector of the rated current. For the system matrix, , , , It is a dimension of The identity matrix, , , , , , , These are vector representations of the common coupling point voltage, filter output current, integrator state, load current, load power, reference voltage, and secondary controller, respectively; vector , , and It is a vector of node-specific parameters, respectively composed of , , and Composition. Matrix and It is a diagonal matrix that collects electrical parameters. and .vector Denotes the injected attack vector, where It is the adjacency matrix of the communication network. It is injected data The matrix, It is a binary mask that indicates the attacked link.
[0065] Step 2.2: Use the standard boundary layer method to separate the time scales:
[0066] set up To solve algebraic equations And obtain the quasi-steady manifold:
[0067]
[0068] Substitute the quasi-steady manifold as X. We can obtain the slow-decrease subsystem model:
[0069]
[0070] To address the inconsistency in initial conditions caused by model simplification, we define a boundary layer correction term. By setting We obtain the dynamics of the fast boundary layer subsystem as follows:
[0071]
[0072] Based on the above results, define stability and security:
[0073] Stability: If the state trajectory of system (4) Converging to its steady-state equilibrium point ,Right now
[0074] and If the system is stable, then it is said to be stable. This ensures proportional current sharing and voltage balance. If If this is the case, then the load current is said to have achieved current sharing, where It corresponds to DGU Rated current, It corresponds to DGU The rated current. If If the voltage balance is achieved, then voltage balance is said to be achieved. and .
[0075] Safety: If the voltage trajectory at the common coupling point of system (4) Maintain a predefined safe operating set at all times. In this context, it is said to maintain operational safety. This set includes all permissible voltage states and is formally defined as: ,in A voltage safety margin is defined. This represents the steady-state voltage under conditions where there is no nonlinearity caused by a constant power load.
[0076] Step 3: For the fast boundary layer subsystem and the slow decrementing subsystem respectively, derive the sufficient conditions for stability under the spurious data injection attack based on the voltage balance and current sharing conditions, and establish the input-state stability model of the slow subsystem to clarify the way the attack affects stability.
[0077] Step 3.1 Derive the steady-state expression for achieving voltage balance and current sharing in a DC microgrid based on the conditions of voltage balance and current sharing:
[0078] The steady-state solution of the singular perturbation system (4) needs to satisfy:
[0079] (5)
[0080] Step 3.2, based on the steady-state solution expression of the DC microgrid and the conditions for voltage balance and current sharing, derive the conditions for the existence of the equilibrium point of the singular perturbation system (4) under the condition of no attack:
[0081] Based on formula (5), the power flow constraints that system (4) must satisfy in steady state to achieve current sharing and voltage balance are derived:
[0082] , (6)
[0083] , (7)
[0084] in, and , Representing a dimension as A row vector whose values are all 1s.
[0085] Equations (6) and (7) can be written compactly as follows:
[0086]
[0087] in , , .
[0088] Define nominal voltage and a normalization bias , express The pseudo-inverse of the current flow equations can be expressed in fixed-point form: ,in, and According to Banach's fixed-point theorem, if the following equation holds,
[0089]
[0090] This mapping is a compression mapping. A compression mapping guarantees fixed-point solutions. The existence of this implies the existence of a unique voltage solution. .
[0091] Step 3.3: Design the Jacobian matrix of the fast boundary layer subsystem Parameters satisfy , , , ,in yes The If there are eigenvalues, then the Jacobian matrix of the boundary layer dynamics satisfies the Routh-Hurwitz criterion, the boundary layer system is stable, and the corresponding reduced-order system is also stable in the absence of attack.
[0092] Furthermore, based on the slow-decreasing subsystem model, state deviation variables are defined. ,in This is the equilibrium point of the system under no-attack conditions. The dynamic equation for this deviation variable is derived.
[0093] ,
[0094] in , , Constructing Lyapunov functions , Given a positive definite matrix, obtain and output the following key relationships.
[0095] ,
[0096] Among them, norm It is the maximum amplitude of the injected attack signal, while the gain constant is... It is a pre-calculated value that is entirely determined by system parameters, where This is a stability parameter used to characterize the system's convergence rate. Representation matrix The minimum eigenvalue. In reachability set analysis, this is precisely to verify the minimum eigenvalue at a given attack strength. The question is whether the state deviation predicted by this formula will cause the system trajectory to exceed the preset safety boundary. .
[0097] Step 4: Use the reachability set method to estimate the state trajectory of the slow subsystem under attack, clarify the range of state deviation caused by the attack, calculate the worst state deviation that the system may reach under attack conditions, determine the boundary conditions for safe operation of the system, and quantify and determine the maximum allowable attack amplitude that the system can withstand.
[0098] Step 4.1 Establish voltage deviation and secondary control variables A clear mapping relationship is established between the deviations:
[0099] For singular perturbation systems (4), when the time scale separates the parameters When the voltage at the point of common coupling is sufficiently small, with its nominal operating point The bias is locally controlled by slow variables. Its equilibrium point The upper bound of the deviation is:
[0100]
[0101] In the formula ,in Is Calculated at the location Jacobian matrix, .
[0102] Step 4.2 Construct a regional topology reachability framework. The methodology that allows for the maximum attack amplitude comprises three main steps.
[0103] First, based on the mapping relationship established in step 4.1, voltage safety constraints... The equivalent safety threshold, which is transformed into a slow state deviation, is a safety set. .
[0104] Secondly, we model the effects of attacks and nonlinearities as a bounded perturbation region topology. ,in This represents the vector used to describe the disturbance. The set of regional topologies within the range of values. This dynamically transforms the slow, decreasing-order subsystem into a differential inclusion relation. .
[0105] Finally, we use discrete steps Upstream transmission reach set To iteratively calculate its over-approximation, where Indicates the first Discrete time moments This is the discrete time step, used for discretizing continuous-time dynamics during reachability set propagation. At each step, ,in It is the generation matrix of the total perturbation. and Let represent the Taylor approximation of the convolution integral and its cutoff bound, respectively. Reachability set Formalized as Verification passed. Is it maintained within a safe set within the time frame? Within this, we can determine whether a given attack magnitude is acceptable. This process begins with calculating the reduced-order state deviation bounds. The above steps iteratively calculate within a fixed time range. The reachable set within the region. At each step, the reachable region topology is updated by combining the initial set from propagation, the convolutional approximation, and the conservative truncation bound. If the final region topology (representing a formal over-approximation of the true reachable set) is within the range... If the norm exceeds the safety threshold, then the candidate... It is conservatively considered unsafe. Through a series of candidates Repeat this evaluation, selecting the value that satisfies security constraints throughout the entire timeframe as the permissible attack range. .
[0106] Step 5: Experimental Verification. The effectiveness of the vulnerability analysis method for multi-timescale DC microgrids under FDI attacks was verified through a hardware experimental platform. Specifically, a DC microgrid test platform consisting of four DGUs was constructed, regulated by two RTU-BOX204 controllers in a ring topology. Communication between the two controllers was achieved via a CAN bus, and a central host accessed the two controllers through an Ethernet switch. Key operating parameters included a 48V bus reference voltage, a 1ms / 100ms first / secondary control cycle, and a uniform control gain. The system also included constant current loads of 1A and 3A to simulate real-world demand. Safety thresholds were calculated offline using the CORA toolkit and then validated on a microgrid test platform, confirming the practical applicability of the framework.
[0107] To verify the theoretical limit of voltage deviation derived in (6), we experimentally evaluated whether the voltage trajectory remained within a predefined safe region under an FDI attack. Specifically, we calculated the limit based on the system matrix. And verified that the actual voltage deviation satisfies the inequality Voltage safe zone is defined as , ,when When the voltage deviation exceeds 0.5, it begins to violate safety constraints, consistent with the predicted limits. This is to verify the theoretical attack limits derived from the region topology reachability analysis. We conducted two sets of hardware experiments, with the control timescale set to 1ms for the first-level control cycle and 100ms for the second-level control cycle. .like Figure 3 As shown, when the attack strength exceeds the predicted threshold (e.g., When ), voltage - Deviating from its steady state, current sharing is disrupted. Conversely, for The voltage and current distributions remained stable, confirming the effectiveness and conservatism of the estimation limits.
[0108] With smaller perturbation parameters (i.e., testing with the secondary control cycle increased to 200ms), such as Figure 4 As shown, the same threshold is also confirmed. However, the system exhibits greater sensitivity and longer fluctuations even under tolerable attacks, highlighting that excessive timescale separation reduces damping and increases vulnerability.
[0109] For comparative analysis, we did not separate the time scales (i.e.) The system's vulnerability was assessed. The region topology reachability method, also introduced in Section 4, was directly applied to the full-order model. The theoretical security limits for the permissible attack amplitude were calculated as follows: This is based on applying voltage trajectory Derived from safety thresholds. Figure 5 In the data, when the attack amplitude exceeds the calculated safety limit, significant voltage deviations and current imbalances occur, confirming the conservatism of the reachability-based estimation. In contrast, for... The system maintained voltage and current regulation within the safe range, consistent with theoretical predictions. It is also noteworthy that, compared to the analysis in the reduced-order system... Compared to the previous situation, the allowed attack limits under full-order dynamics The difference is significantly larger, meaning that when the fast and slow controllers are tightly coupled, the system can tolerate stronger attacks before losing stability. This observation reveals a key insight: while timescale separation offers modularity and analytical convenience, it can also introduce additional vulnerabilities because the slower second-level control response is less effective at suppressing rapidly propagating adversarial inputs.
[0110] The specific parameters of different DGUs in this embodiment are shown in the table below:
[0111]
[0112] Corresponding to the aforementioned embodiment of a distributed security and stability control method for DC microgrids against FDI attacks, the present invention also provides an embodiment of a vulnerability analysis device for multi-timescale DC microgrids under FDI attacks.
[0113] See Figure 6 The present invention provides a vulnerability analysis method and apparatus for multi-timescale microgrids under FDI attacks, comprising a memory and one or more processors. The memory stores executable code, and when the processor executes the executable code, it implements a vulnerability analysis method for multi-timescale microgrids under FDI attacks as described in the above embodiments.
[0114] The embodiment of the vulnerability analysis device for multi-timescale DC microgrids under FDI attacks provided by this invention can be applied to any device with data processing capabilities, such as a computer. The device embodiment can be implemented in software, hardware, or a combination of both. Taking software implementation as an example, as a logical device, it is formed by the processor of any data processing device loading the corresponding computer program instructions from non-volatile memory into memory for execution. From a hardware perspective, such as... Figure 6 The diagram shown is a hardware structure diagram of any data processing-capable device, which is the vulnerability analysis device for multi-timescale DC microgrids under FDI attacks provided by this invention. (Except for...) Figure 6 In addition to the processor, memory, network interface, and non-volatile memory shown, any data processing device in the embodiment may also include other hardware depending on the actual function of the data processing device, which will not be described in detail here.
[0115] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0116] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the present invention according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0117] This invention also provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements a vulnerability analysis method for multi-timescale microgrids under FDI attacks as described in the above embodiments.
[0118] The computer-readable storage medium can be an internal storage unit of any data processing device described in any of the foregoing embodiments, such as a hard disk or memory. The computer-readable storage medium can also be an external storage device of any data processing device, such as a plug-in hard disk, smart media card (SMC), SD card, flash card, etc., equipped on the device. Furthermore, the computer-readable storage medium can include both internal storage units and external storage devices of any data processing device. The computer-readable storage medium is used to store the computer program and other programs and data required by the data processing device, and can also be used to temporarily store data that has been output or will be output.
[0119] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned method for vulnerability analysis of multi-timescale microgrids under FDI attacks.
[0120] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this application are indicated by the claims.
[0121] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this application. This application is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A vulnerability analysis method for multi-timescale microgrids under FDI attacks, characterized in that, include: S1. A hierarchical control architecture based on DC microgrids is constructed. A DGU unit model is built based on singular perturbation theory. The dynamics of the primary and secondary controllers are defined. An FDI attack model targeting the secondary control communication link is constructed. S2. Construct a system aggregate state model under attack based on the DGU unit model and FDI attack model, and decompose the overall dynamic model of DC microgrid into a fast boundary layer subsystem and a slow descending order subsystem. S3. Based on voltage balance and current sharing conditions, derive sufficient conditions for system stability under spurious data injection attack conditions; construct Lyapunov functions to predict state deviation variables for slow-decreasing subsystems. S4. Use the zonotope method to estimate the state trajectory of the slow-decrease subsystem under attack, clarify the range of state deviation caused by the attack, calculate the worst state deviation that the system may reach under attack conditions, determine the boundary conditions for safe operation of the system, and quantify and determine the maximum allowable attack amplitude that the system can withstand.
2. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 1, characterized in that, The dynamics of the primary and secondary controllers are as follows: each DGU is equipped with a hierarchical controller, including fast primary control for local voltage regulation and slow secondary control for current sharing. The primary controller is ,in , and These represent the gain of the feedback control; It is the voltage of the DGU at the common coupling point. It is the output current of the DGU. This refers to the internal controller state; the secondary control adopts a distributed control scheme, with a control frequency lower than the primary control, and its dynamics are as follows: ; In the formula, Represents nodes in a communication network With nodes The adjacency matrix elements, It is a node Transmitted to node The output current information, It corresponds to DGU Rated current, It corresponds to DGU Rated current, For DGU The set of neighbors in a communication network This indicates the time delay of the secondary control relative to the primary control.
3. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 1, characterized in that, The DGU unit model specifically includes: In the formula, It is the resistance of the circuit. It is the output voltage of the transformer. This refers to the load current in a ZIP load. The elements of the electrical network correlation matrix are represented as DGU. and edge Relationship; It is the impedance-type load admittance in a ZIP load. It is a node Transmitted to node The output current information, It is a constant power load in ZIP loads. Indicates the reference voltage at the common coupling point; , and These are the resistor, inductor, and capacitor parameters of the converter. This represents the edge connecting DGU. Represents a group DGU; It's DGU The physical coupling between it and its adjacent units, where Represents a node Output voltage; , , and These are design parameters that reflect electrical characteristics and local controller adjustments; , and This indicates the gain of the primary controller's feedback control. These are the control coefficients for secondary control. It is a secondary controller. These are singular perturbation parameters, the first... Each load is a parallel combination of ZIP loads.
4. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 1, characterized in that, The construction of the FDI attack model targeting the secondary control communication link specifically includes: ; In the formula, DGU was attacked The output current, It is a node Transmitted to node The output current information, It is the attack vector injected by the opponent. It is a step function, in The attack is activated at that time.
5. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 1, characterized in that, The specific state model of the system set under attack is as follows: In the formula For state vectors, For the system matrix, , , , , , , , , , These are vector representations of the common coupling point voltage, filter output current, integrator state, load current, load power, reference voltage, and secondary controller, respectively. The elements of the electrical network correlation matrix are represented as DGU. and edge Relationship, , , , A matrix of design parameters reflecting electrical characteristics and local controller regulation; vector Denotes the injected attack vector, where It is the adjacency matrix of the communication network. It is injected data The matrix, It is a binary mask that indicates the attacked link.
6. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 5, characterized in that, The decomposition of the overall dynamic model of the DC microgrid into a fast boundary layer subsystem and a slow reduced-order subsystem is specifically as follows: set up To solve algebraic equations And obtain the quasi-steady manifold: Substitute the quasi-steady manifold as X. The slow-decreasing subsystem model is obtained: Define boundary layer correction terms By setting The dynamics of the fast boundary layer subsystem are obtained as follows: 。 7. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 5, characterized in that, The process of deriving sufficient stability conditions under spurious data injection attacks based on voltage balance and current sharing conditions specifically includes: constructing power flow constraints that must be satisfied to achieve current sharing and voltage balance based on the steady-state solution satisfaction conditions of the system; expressing the power flow constraints in fixed-point form; and obtaining the conditions for the existence of a steady-state solution based on Banach's fixed-point theorem. ,in , express The false rebellion, Nominal voltage; Then, based on the fact that the Jacobian matrix of the fast boundary layer subsystem satisfies the Routh-Hulwitz criterion, the condition for the stability of the subsystem is obtained: , , , ,in yes The Each feature value.
8. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 5, characterized in that, The specific details of constructing the Lyapunov function to predict the bias variable for the slow-decreasing subsystem are as follows: Define state deviation variables ,in It is the equilibrium point of the system when there is no attack; derive the dynamic equation of this deviation variable. , in , , Constructing Lyapunov functions Obtain and output the following key relational expressions. , Among them, norm It is the maximum amplitude of the injected attack signal, while the gain constant is... These are pre-calculated values determined by system parameters, among which... This is a stability parameter used to characterize the system's convergence rate. Representation matrix The smallest eigenvalue.
9. The vulnerability analysis method for multi-timescale microgrids under FDI attacks according to claim 1, characterized in that, The estimation of the state trajectory of the slow-degrading subsystem under attack specifically includes: A mapping relationship between voltage deviation and secondary control deviation is established. Based on the mapping relationship, the voltage safety constraint is transformed into an equivalent safety threshold for slow state deviation to obtain a safety set. The effects of attacks and nonlinearities are modeled as a bounded disturbance region topology. The slow reduced-order subsystem is dynamically transformed into a differential inclusion relationship. Finally, the over-approximation is calculated iteratively by propagating the reachable set on discrete steps. In each step, the acceptable attack amplitude is determined by verifying whether the reachable set remains within the safety set. By repeatedly evaluating a series of candidate attack amplitudes, the value that satisfies the safety constraint over the entire time range is selected as the allowable attack amplitude.
10. A vulnerability analysis device for multi-timescale DC microgrids under FDI attacks, comprising a memory and one or more processors, wherein the memory stores executable code, characterized in that... When the processor executes the executable code, it implements a vulnerability analysis method for multi-timescale microgrids under FDI attacks as described in any one of claims 1-8.