Power system communication security active defense method fusing measurement coding and optimal disturbance deployment

By integrating metering coding with optimal disturbance deployment, a cross-layer coupled power system defense system is formed, which solves the problem of incomplete defense framework in existing technologies and achieves power system security defense with high detection rate, low cost and long-term robustness.

CN121841682APending Publication Date: 2026-04-10ANSHAN POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER COMPANY +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-11
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technologies lack a comprehensive defense framework covering the entire power system, making it difficult to achieve high detection rates and long-term robustness while ensuring controllable investment and economical operation. In particular, when defending against spoofed data injection attacks, single-layer or single-stage defense measures are difficult to maintain effectiveness.

Method used

By adopting a method that integrates metering coding and optimal disturbance deployment, a dynamically adjustable overall defense system is formed through layered design and cross-layer coupling. During the deployment phase, the location and number of D-FACTS devices are optimized. During the operation phase, D-FACTS is incorporated into the AC optimal power flow model. Furthermore, a dynamic metering coding mechanism is introduced at the communication layer to form a multi-layer collaborative mechanism, thereby achieving optimization and iteration throughout the entire life cycle.

Benefits of technology

It significantly improves the detection rate of covert attacks, balances system security and economy, dynamically adjusts strategies to cope with emergencies, reduces operating costs, and ensures that D-FACTS devices are always in optimal condition throughout the entire operating cycle, achieving full lifecycle defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841682A_ABST
    Figure CN121841682A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power system network security and operation optimization, in particular to a power system communication security active defense method fusing measurement coding and optimal disturbance deployment, which organically combines equipment deployment optimization, operation scheduling optimization and information transmission protection through hierarchical design and cross-layer coupling. And an integral defense system which can be dynamically adjusted and continuously evolved is formed. In the deployment stage, the balance between investment and defense capability is realized by emphasizing optimal site selection and hardware configuration; in the operation stage, the D-FACTS is flexibly incorporated into the optimal power flow model, and system safety and economical efficiency are both considered; in the communication layer, the robustness and continuity of attack detection are improved by means of a dynamic measurement coding mechanism; in a multi-layer cooperation mechanism, through detection result feedback and dynamic adjustment, full-life-cycle optimization iteration is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system network security and operation optimization technology, and in particular to a proactive defense method for power system communication security that integrates metering coding and optimal disturbance deployment. Background Technology

[0002] With the rapid development of power systems, their operation and dispatch rely heavily on measurement data and state estimation algorithms. However, the transmission of power system measurement data through communication networks provides opportunities for cyberattacks. Among various attack types, False Data Injection (FDI) poses a serious threat to power system operational security because it can construct specific attack vectors to bypass traditional Bad Data Detection (BDD) mechanisms. If an attacker obtains the system's measurement matrix information, they can precisely construct attack vectors that lie within the column space of the measurement matrix, thereby tampering with the state estimation results without detection. Once the attack succeeds, it will lead to state estimation bias and incorrect dispatch decisions, seriously threatening grid security.

[0003] In existing technologies, academia and engineering have proposed various defense methods against spoofed data injection attacks on power systems. These methods can be broadly categorized into three directions: communication layer defense, physical layer defense, and deployment optimization strategies. However, they still suffer from problems of fragmentation and insufficient coordination. At the communication layer, researchers have attempted to weaken attackers' control over the system's measurement matrix through data perturbation, encryption, or encoding. For example, the Meter Coding (MC) method introduces an encoding matrix during measurement data transmission, disrupting the original linear relationships and making it difficult for attackers to construct covert attack vectors using known system models. This type of method effectively increases the difficulty of attacks, but if the encoding matrix remains fixed for a long period, attackers may gradually infer it from historical data, thus reducing the effectiveness of the defense. At the physical layer, Moving Target Defense (MTD) has been widely studied. Its core idea is to dynamically adjust the physical parameters of the power system (such as line reactance and switch states) to rapidly invalidate the system model controlled by attackers, forcing their constructed attack vectors to no longer meet the observability conditions. These methods excel in improving attack detection rates, particularly in resisting high-frequency attacks. However, excessively frequent parameter perturbations can increase line losses and operating costs, negatively impacting system stability. At the deployment optimization level, some studies utilize graph theory, sensitivity analysis, and optimization algorithms to select installation locations for devices such as FACTS / D-FACTS (Flexible AC Transmission Systems / Distributed FACTS), maximizing detection capability with the minimum number of devices. These methods can improve system observability and defense capabilities in the initial stages, reducing short-term investment, but are often limited to the design and construction phases, lacking comprehensive consideration of dynamic changes during operation and communication layer defense. Furthermore, in recent years, some scholars have attempted to combine MC (Multi-Cut Detection) and MTD (Multi-Device Detection), improving detection rates and enhancing adaptability to attacks by implementing communication layer perturbation data and physical layer dynamic adjustments in parallel. However, these methods still have shortcomings in application. For example, the deployment of MTD devices in a concentrated manner may lead to high costs, and it is difficult to balance the economy and security of the system in operation optimization. Furthermore, if the communication layer disturbances are not coordinated with the physical layer, it is difficult to achieve continuous and effective defense.

[0004] In summary, while existing technologies have made significant progress at their respective levels, most methods still remain at the level of single-layer or single-stage design, lacking a comprehensive defense framework that covers the entire chain of deployment, operation, and communication. This makes it difficult to achieve both high detection rates and long-term robustness in practical applications while ensuring controllable investment and economical operation. Summary of the Invention

[0005] This invention provides a proactive defense method for power system communication security that integrates metering coding and optimal disturbance deployment. Through layered design and cross-layer coupling, it organically combines equipment deployment optimization, operation scheduling optimization, and information transmission protection to form a dynamically adjustable and sustainably evolving overall defense system. In the deployment phase, it emphasizes balancing investment and defense capabilities through optimal addressing and hardware configuration. In the operation phase, it flexibly incorporates D-FACTS into the optimal power flow model, taking into account both system security and economy. At the communication layer, it enhances the robustness and sustainability of attack detection through a dynamic metering coding mechanism. In the multi-layer collaborative mechanism, it achieves full lifecycle optimization iteration through detection result feedback and dynamic adjustment.

[0006] To achieve the above objectives, the present invention employs the following technical solution: A proactive defense method for power system communication security that integrates metering coding and optimal disturbance deployment includes the following steps: S1. Deployment Phase Optimization: Dynamically adjusting the reactance of transmission lines. To change the measurement Jacobian matrix It disrupts the attacker's known power system estimation model to achieve the purpose of defense. At the same time, it uses the Kruskal algorithm to use sensitivity as a decision variable to obtain the minimum number of D-FACTS devices and the maximum defense effect. S2. Operational Phase Optimization: The static layout scheme during the deployment phase is optimized by introducing the AC Optimal Power Flow (ACOPF) model. The impedance sensitivity of all lines is used as a decision variable to re-select the device placement locations, so that the system achieves maximum detection performance when only D-FACTS devices are installed. or At the same time, an attack detection rate improvement indicator was introduced. With system resilience indicators Construct a multi-objective optimization model; among which, For the original Jacobian matrix of the system when using only the D-FACTS device New Measurement Jacobian Matrix after D-FACTS Device Perturbation The rank of the composite matrix formed by combining the two parts. The original measurement Jacobian matrix of the system, The number of busbars in the power system. The number of branches in the power system; S3, Communication Layer Defense: Through metrological coding, secure communication devices encode some measurements, enabling the creation of new composite matrices. Reaching full rank To completely detect fake data, an encoding matrix is ​​introduced. Make This enables the system to fully detect data injection attacks in both full MTD and non-full MTD scenarios; S4, Three-layer collaborative mechanism: Dynamically couples the deployment layer, operation layer and communication layer. Through unified optimization objectives, constraints and feedback mechanisms, it organically integrates hardware investment, operation flow scheduling and information layer coding defense. At the same time, it introduces a systematic algorithm framework for cross-layer joint optimization and feedback updates.

[0007] Furthermore, the deployment phase optimization includes the following steps: 1) State estimation: Under the DC power flow model, the relationship between power grid measurements and state is as follows: ; in, For measurement vectors, For measuring quantity; This is the state vector, representing the bus voltage phase angle vector; The Jacobian matrix is ​​a measurement matrix that maps the system state to the measured values. The measurement noise is modeled as a Gaussian distribution, and the measurement noise covariance matrix is ​​a diagonal matrix. : ; in, For the first The standard deviation of the measured noise; Power information physical systems have complex structures, and state estimation is necessary to eliminate the effects of measurement errors. Currently, the least squares method is widely used in state estimation; however, when measurement noise... The objective function of WLS is: ; when When it is symmetrical and positive definite, it is derived that , Full Rank The optimal solution for the bus voltage phase angle vector is: ; make , It is possible to project vectors onto The projection operator, without being attacked, measures the residual as follows: ; in, The measurement residual is the difference between the measured vector and the estimated measurement vector. For measurement vectors; When the attack vector is The measurement residual is then: ; like ,but At this point, the presence of the attack cannot be detected; if , I is the identity matrix, and when the attack vector injected by the attacker is not completely within... When using column space, the measurement residual will not be zero, and the attack behavior will be detected; in actual detection, measurement noise exists, so the residual... The L2 norm and the set threshold When comparing, If the condition is met, then bad data is considered to exist; otherwise, it is not. 2) FDI attack under measurement matrix changes: vector Injecting into the measurement vector to disrupt the state estimation, i.e., modeling it as follows: ; in, For the measurement vector after injecting the attack vector, through the subspace estimation algorithm, there exists a... Make ; Let be a basis for measuring the Jacobian matrix. The change in the bus voltage phase angle vector to make the equations equal; Through the subspace estimation algorithm, there exists a Make ; When the line When equipped with a D-FACTS device, its equivalent reactance will be periodically modified to any value by the D-FACTS device within its adjustable range, where i is a bus of the power system and j is another bus connected to it. ; in, The measurement Jacobian matrix calculated by the attacker before the D-FACTS device is disturbed, which is the original measurement Jacobian matrix of the system; This is the new measurement Jacobian matrix actually used by the control center after the device was disturbed; 3) Full MTD vs. Incomplete MTD: The noise-free model is: ; If and only if for any They all At that time, and ,Right now The attack is detectable; Decompose the measurement matrix. It can be represented as: ; in, For the measurement deployment matrix in the power system, It is a diagonal matrix, and its diagonal elements are the reciprocals of the reactance of each branch; The matrix is ​​determined by the power grid topology. This is an estimate of the measurement vector after the injection of the attack vector; When the power grid topology is an undirected graph Among them, the power system bus cluster The scale is The set of branches in the power system The scale is Any branch is Therefore, the correlation matrix of the power system is obtained as follows: ; Let the balance busbar be denoted as Delete the first from A Rows yield a reduced-order matrix In the DC power flow model, the branch power flow is as follows: Busbar active power injection is ;in, For the line The phase angle difference between the two busbars; We obtain this from the matrix properties: To maximize the rank of the composite matrix, then , ; in, This is the difference matrix between the new measurement Jacobian matrix and the original measurement Jacobian matrix. To deploy the measurement matrix, This is the diagonal matrix of the D-FACTS lines; By the theorem of Euler's formula in disconnected graphs, for any given graph... 1 node Edge, A ring road, and Planar diagram of connected components The following formula exists: ; For those with Each node and Planar graph of connected components The rank of its correlation matrix is: ; The composite matrix formed by the new measurement Jacobian matrix and the original measurement Jacobian matrix is ​​represented as: ; To achieve detection of any FDI, it is necessary to achieve... From the matrix properties, we obtain: ; in, To measure the rank of the deployment matrix, The matrix is ​​composed of the original reactance of the line. The matrix formed by the new reactance of the D-FACTS device after disturbance is the matrix formed by the new reactance of the D-FACTS device after disturbance. Because of any The rank of the composite reactance matrix And because ,therefore ,get: ; To meet the full rank requirement , This indicates that the number of transmission lines must not be less than twice the number of states; when the number of lines... In the case of full measurement, the rank of the composite matrix is ​​at most 1. As shown in the following formula: ; When the line is divided into sections for installing D-FACTS devices With or without D-FACTS device ,get: ; in, and They are and The measurement device arrangement matrix, It is the diagonal matrix of D-FACTS lines, when If there is no cycle, then , ,get: ; in, Circuit diagram with D-FACTS installed The corresponding measurement Jacobian submatrix, For subgraph Branch-bus correlation matrix For subgraph Branch-bus correlation matrix For subgraph The number of connected components, For subgraph The number of connected components, For subgraph The number of independent loops, For subgraph The number of independent loops; 4) Selection of the location for the D-FACTS device under sensitivity weighting: Sensitivity is calculated based on the increase in the rank of the composite matrix before and after the disturbance. When only the first line is disturbed, the sensitivity is: ; in, This represents the measurement Jacobian matrix after perturbing only the l-th line; This is the difference between the measured Jacobian matrix after perturbing only the l-th line and the original measured Jacobian matrix; Minimum Spanning Tree (MST): Treating the power grid as a graph The nodes are busbars, and the edges are transmission lines. For the collection of busbars in the power system, The scale is , Let O be the set of branches of the spanning tree, with size O. ; Use the reciprocal of the sensitivity as the edge weight: ; Higher sensitivity results in lower weighting and higher priority for inclusion in the MST (Medium-Level Search). Based on the MST, additional D-FACTS (Digital-Based Detection and Testing) circuits are deployed incrementally from high to low sensitivity until the detection capability reaches the target. .

[0008] Furthermore, the minimum spanning tree (MST) employs Kruskal's algorithm for selecting the optimal deployment location, specifically including the following steps: 1) Initialization: When all nodes are disconnected, generate a tree set. ; 2) Edge sorting: ; 3) Add edge by edge: Start with the edge with the smallest weight. If adding this edge will not form a cycle, then merge it. ; 4) Termination condition: When When the time comes, the algorithm ends; Objective function: ; In MTD deployment: Edge weights ,in This is a set of line disturbance sensitivities; ; To minimize the number of devices and investment costs while ensuring detection capabilities, and to reserve an adjustable point for optimizing the objective function: ; in, For the first The weight of the edge (the disturbed line), The weight of the edge. for and The minimum included angle of the column space. For only on the line The measurement Jacobian matrix obtained after applying the MTD perturbation; To select the set of lines to deploy; For testing capability indicators; For deployment costs; This is the cost trade-off coefficient.

[0009] Furthermore, the optimization during the operational phase involves multi-objective modeling, specifically including the following steps: 1) Incorporate D-FACTS into the AC-optimal power flow (ACOPF) model: The optimization objective of the optimal power flow is to minimize the system operating cost. ; in, This represents the active and reactive power vectors for power generation. This represents the node voltage magnitude vector; For the set of generator nodes; For nodes Electricity generation cost function; Constraints: Power balance constraints: ; ; Generator output constraints: ; Voltage amplitude constraint: ; Power flow constraints: ; in, For nodes Injected active and reactive power, For power system bus voltage, For power system bus voltage, The voltage phase angle difference, busbar With busbar Real part of the inter-admittance matrix The imaginary part of the admittance matrix, busbar The upper unit contributes power. busbar Lower limit of active power output of the unit. busbar The upper limit of the active power output of the unit. busbar The lower limit of the permissible voltage amplitude. busbar The upper limit of the allowable voltage amplitude For from the busbar Measured The complex power of the line, For the line The permissible apparent power limit, For the busbar The set of connected busbars, including itself; 2) Calculation and setting of impedance sensitivity; The sensitivity of power loss to impedance is defined as the directional derivative of each line: ; ; in, For power system bus With busbar Sensitivity between For power loss, Given the impedance set of the transmission line, in the optimal power flow ACOPF model... Indicates reactance, Indicates resistance; At the running point To evaluate this value, according to the chain rule, it can be written as: ; in, This is the concatenated vector of all bus phase angles and voltage magnitudes; It is a side road Series admittance; This represents the total active power loss of the system, for disturbances less than 5% of the relative disturbance. At the running point, approximately equal to ; In the candidate set Calculate the running point In conjunction with the device amplitude constraint and the minimum effective disturbance constraint, select ; In order for a change in the reactance of a certain line to achieve the effect of improving attack detection, the reactance change must meet the following constraints: ; in, The line reactance before the disturbance. The line reactance after the disturbance. The number of D-FACTS devices installed. Let be the lower limit coefficient of relative disturbance. This is the upper limit coefficient for relative disturbance; 3) Multi-objective optimization modeling: Introducing attack detection rate improvement metrics With system resilience indicators Construct a multi-objective optimization model: ; in: Total operating cost (the sum of power generation costs); For system power flow loss; This represents the improvement in attack detection rate under perturbation parameters; This represents the increase in physical toughness; These are the weighting coefficients.

[0010] Furthermore, the communication layer defense specifically includes the following steps: 1) Introduce an encoding matrix; For the perturbated matrix After encoding, the rank of the composite matrix becomes: ; in, In order to fully detect FDI, i.e. The encoded matrix needs to be able to handle any... in a noise-free environment. The following conditions must be met: ; in, The bus voltage phase angle vector corresponding to the measured value represented by the Jacobian matrix after injecting false data into the attacker; 2) Regarding the changed Enlarge the rank of the encoding; use Then, they are classified according to the measurements. and They can be represented as: ; Where the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; ; when At the time of its establishment, its rank was , The rank is at most ;get ,because From the matrix properties, we can obtain Therefore, the minimum number of measurements affected by MTD and MC can be obtained. ; When matrix A submatrix of a composite matrix. and In order to be with the first Strip measurements are correlated and are submatrices The non-zero elements in the array are represented as: ; in, Indicates in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns, For matrix The Middle OK The sign factor of the column element's sign factor, For matrix The determinant value, In order to be in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns.

[0011] Furthermore, the three-layer collaborative mechanism specifically includes: 1) Three-layer unified optimization model; The unified optimization model is represented as: ; ; in, Number of lines; To deploy the investment cost function; The operating period includes power generation costs and system losses; As a measure of detection capability; As a system resilience indicator; This represents the lower limit of detection capability. It is the Frobenius norm; The AC optimal power flow constraint equations; y is the security constraint function; y is the route deployment selection vector; 2) Collaborative optimization algorithm; Input historical operational data and the lower limit of attack detection capability The optimal D-FACTS installation candidate set is calculated using a minimum spanning tree and sensitivity-weighted algorithm. Output As an initial deployment decision; Given deployment results Constructing the ACOPF model: ; Incorporate security constraints and detection capabilities into proxy indicators: ; Solving for the disturbance amplitude With the trend distribution scheme; Communication layer coding generation Generate a random orthogonal coding matrix based on the runtime perturbation results. ,satisfy And with Column spaces should be as independent as possible; Verify rank condition If the conditions are not met, the encoding matrix is ​​regenerated. Lifecycle Feedback: During operation, monitor detection rate, false alarm rate, operating cost, and resilience metrics; feed the results back to the deployment layer and create new candidate sets. Weighting will determine the next phase of deployment. Iterate until convergence or until the lifecycle update interval is reached.

[0012] Compared with the prior art, the beneficial effects of the present invention are: 1) Dynamic adjustment strategy: During high-risk phases, increase... Increase the amplitude of disturbances to improve the attack detection rate; reduce the amplitude of disturbances during low-risk or high-load periods to reduce power flow loss; and in response to emergencies, combine resilient scheduling to quickly adjust the reactance values ​​of critical lines to ensure power supply to important loads. 2) It makes up for the shortcomings of the deployment phase, from static to dynamic, and solves the problem of detection performance degradation caused by fixed parameters in the deployment phase; in terms of security and economy, it can reduce operating costs while maintaining defense strength; it also enhances system resilience and can quickly respond to sudden attacks or equipment failures; at the same time, it can achieve full life cycle defense and ensure that D-FACTS is always in the optimal state throughout the entire operation cycle. 3) Cross-layer degree of freedom compensation mechanism, in the number of lines Under physical constraints, the detection capability is maximized by introducing a rank-matching condition for the coding matrix in the communication layer; unified optimization and multi-objective collaboration are introduced, incorporating the deployment, operation, and communication variables into a single optimization framework, through weight parameters. Strive to balance security, economy, and resilience. Integrate deployment decisions with operational feedback into a cyclical update process, enabling the system to evolve and adaptively optimize over the long term. Attached Figure Description

[0013] Figure 1 This is a system framework diagram of the method described in this invention; Figure 2 The PLIS index represents the sensitivity of each line in the IEEE 6-node system.

[0014] Figure 3 Configuration scheme for D-FACTS device in IEEE 6-node system.

[0015] Figure 4 PLIS metrics for each line in the IEEE 14-node system.

[0016] Figure 5 Configuration scheme for D-FACTS device in IEEE 14-node system.

[0017] Figure 6 ADP is provided at recommended locations with measurement noise in both DC and AC modes.

[0018] Figure 7 This represents the probability of successful detection in the simulation. Detailed Implementation

[0019] The specific embodiments of the present invention will be further described below with reference to the accompanying drawings: See Figure 1This is a system framework diagram of the method described in this invention. This invention presents a proactive defense method for power system communication security that integrates metering coding and optimal disturbance deployment. It is a systematic proactive defense method covering the deployment layer, operation layer, and communication layer. Existing research often focuses on a single layer, neglecting the coordination and feedback between different stages, resulting in fragmented defense measures, high costs, and difficulty in maintaining sustained effectiveness. This invention not only significantly improves the detection rate of covert attacks but also balances cost constraints and operational reliability, possessing outstanding innovation and practical value. The invention content is mainly divided into several parts: 1) Deployment phase optimization; In the MTD (Moving Target Defense) strategy for power systems, D-FACTS devices dynamically adjust the transmission line reactance to change the measurement matrix, thereby disrupting the attacker's known system model. However, the number and location of D-FACTS deployments directly affect the defense effectiveness and investment cost. Therefore, it is necessary to find an optimal deployment scheme during the deployment phase to achieve the maximum detection capability with the fewest number of devices. By dynamically adjusting the reactance of the transmission line To change the measurement Jacobian matrix It disrupts the attacker's known power system estimation model to achieve the purpose of defense. At the same time, it uses the Kruskal algorithm to use sensitivity as a decision variable to obtain the minimum number of D-FACTS devices and the maximum defense effect. The steps of the MTD strategy are as follows: Step 1: State estimation: Under the DC power flow model, the relationship between power grid measurements and state is as follows: in, For measurement vectors, For measuring quantity; This is the state vector, representing the bus voltage phase angle vector; The Jacobian matrix is ​​a measurement matrix that maps the system state to the measured values. The measurement noise is modeled as a Gaussian distribution, and the measurement noise covariance matrix is ​​a diagonal matrix. : ; in, For the first The standard deviation of the measured noise; Power information physical systems have complex structures, and state estimation is necessary to eliminate the effects of measurement errors. Currently, the least squares method is widely used in state estimation; however, when measurement noise... The objective function of WLS is: ; when When it is symmetrical and positive definite, it is derived that , Full Rank The optimal solution for the bus voltage phase angle vector is: ; make , It is possible to project vectors onto The projection operator, without being attacked, measures the residual as follows: ; in, The measurement residual is the difference between the measured vector and the estimated measurement vector. For measurement vectors; When the attack vector is The measurement residual is then: ; in, Let be the residual vector, and be the difference between the measurement vector and the measurement estimate vector; if ,but At this point, the presence of the attack cannot be detected; if , , Let be the identity matrix, and the formula represents that when the attack vector injected by the attacker is not completely within . When using column space, the measurement residual will not be zero, and the attack behavior will be detected. However, measurement noise exists in actual detection, so the residual can be... The L2 norm and the set threshold When comparing, If the condition is met, then bad data is considered to exist; otherwise, it is not. Step 2: Measure FDI attacks under matrix changes; An FDI attack can be achieved by changing the vector Injecting this into the measurement vector to disrupt the state estimation can be modeled as follows: ; in, The measurement vector after the injection of the attack vector will not be detected by BDD because... When the attacker accurately grasps the matrix At that time, as long as the attack vector belongs to the matrix The column space, i.e. FDI can then falsify state estimates; However, the matrix can be estimated from a large amount of stolen historical data using subspace estimation algorithms. A set of basis for the column space formed Therefore, it can be easily obtained. ,and , Therefore, we can obtain the form for any... The attack vector will always have a Make: ; in, To measure a basis for the Jacobian matrix, The change in the bus voltage phase angle vector is used to make the equations equal; therefore, it can be seen that even if an accurate matrix cannot be obtained... Attackers can also construct undetectable FDI attack vectors using historical data. Introducing MTD (Mean Transmission Determination) into the physical layer of the power system is widely recognized as an effective measure to defend against FDI (Fixed Direct Injection). By dynamically perturbing the reactance of D-FACTS (Dynamic Disruption-Focused Transmission) lines, it creates uncertainty for attackers, forcing them to process historical system data at extremely high speed and accuracy. Maintaining continuous knowledge of the system becomes costly and limited. In the DC model, the matrix... It is determined solely by the line reactance; therefore, when the line... When equipped with a D-FACTS device, its equivalent reactance will be periodically modified to an arbitrary value by the device within its adjustable range. At this time, the matrix... This will become a time-varying matrix; where, For a certain bus in the power system, This is another busbar connected to it; the matrix will be considered next. The circumstances under which changes occur, The measurement Jacobian matrix calculated by the attacker before the D-FACTS device is disturbed, which is the original measurement Jacobian matrix of the system; This is the new measurement Jacobian matrix actually used by the control center after the device was disturbed; according to the previous text, the attack vector injected by the attacker becomes... , The measurement value obtained by the control center at this time can be expressed as: ; in, The measurement matrix calculated by the attacker before perturbing the D-FACTS device. After the device is disturbed, the measurement matrix actually used by the control center is unknown to the attacker, but known to the control center. If the effect of noise is ignored at this time, when When abnormal data is detected, if the following conditions are met... The condition, i.e., vector The amount of attack data injected by the attacker can be obtained directly, i.e. At this time, the control center can learn The specific values ​​not only defend against attacks but also pinpoint the location of the attack. Step 3: Full MTD vs. Incomplete MTD; In the absence of noise and with the line equipped with D-FACTS devices, the FDI attack model is as follows: The residual can be expressed as: ; If and only if for any They all At that time, and ,Right now The attack is detectable; thus we obtain the composite matrix. The difference between the measurement matrices before and after the disturbance is defined as , ,then For ease of explanation, the definitions of complete and incomplete MTD are given. If the FDI attack is detected, then it is a complete MTD; otherwise, it is an incomplete MTD. A complete MTD can detect any FDI attack, but this is difficult to achieve in practice because a complete MTD requires a certain number of transmission lines. The number of measurements meets the requirements. Decompose the measurement matrix. It can be represented as: ; in, For the measurement deployment matrix in the power system, It is a diagonal matrix, and its diagonal elements are the reciprocals of the reactance of each branch; Let be a matrix determined by the power grid topology. The number of branches in the power system. This is an estimate of the measurement vector after the injection of the attack vector; when the line reactance is disturbed through the D-FACTS device, the matrix... This will cause corresponding changes, disrupting the attacker's prior knowledge; When the power grid topology is an undirected graph Among them, the power system bus cluster The scale is The set of branches in the power system The scale is Any branch is Therefore, the correlation matrix of the power system is obtained as follows: ; Let the balance busbar be denoted as Delete the first from A. Rows yield a reduced-order matrix In the DC power flow model, the branch power flow is as follows: Busbar active power injection is ;in, For the line The phase angle difference between the two busbars; By combining the branch power flow measurement matrix with the bus injection measurement matrix, the measurement deployment matrix can be obtained. According to the definition above The difference between the matrices before and after the perturbation can be expressed as: From the properties of matrices, we can obtain: ; To maximize the rank of the composite matrix, then , ; in, This is the difference matrix between the new measurement Jacobian matrix and the original measurement Jacobian matrix. Deploy the matrix for measurement. This is the diagonal matrix of the D-FACTS lines; The former can be achieved by deploying sensors, while the latter provides the minimum number of D-FACTS devices required to meet the requirements; however, this condition is not always met in practice, and proof will be provided later. By the theorem of Euler's formula in disconnected graphs, for any given graph... 1 node Edge, A ring road, and Planar diagram of connected components The following formula exists: ; In a disconnected graph, a loop corresponds to a linearly dependent row in the incidence matrix. Each node and Planar graph of connected components The rank of its correlation matrix is ,Right now: ; The spanning tree of a graph is a subgraph that contains all nodes in the graph and contains no cycles. From the above formula, the rank of the incidence matrix of the spanning tree is... This corresponds to our needs. When installing the D-FACTS device, we can directly install it on the lines that form the spanning tree. The composite matrix formed by the new measurement Jacobian matrix and the original measurement Jacobian matrix is ​​represented as: ; To achieve detection of any FDI, it is necessary to achieve... From the matrix properties, we obtain: ; in, To measure the rank of the deployment matrix, The matrix is ​​composed of the original reactance of the line; The matrix formed by the new reactances after the D-FACTS device is disturbed; Because of any The rank of the composite reactance matrix And because ,therefore ,get: ; To meet the full rank requirement , This indicates that the number of transmission lines must not be less than twice the number of states; and the metering deployment matrix... The rank must also be at least twice the number of states, and This indicates that the number of transmission lines must not be less than twice the number of states. If the number of lines... In the case of full measurement, the rank of the composite matrix is ​​at most 1. As shown in the following formula: ; When the line is divided into sections for installing D-FACTS devices With or without D-FACTS device ,get: ; in, and They are and The measurement device arrangement matrix, It is the diagonal matrix of D-FACTS lines, when If there is no cycle, then rank of a composite matrix From the theorem of Euler's formula in disconnected graphs, we get: ; in, Circuit diagram with D-FACTS installed The corresponding measurement Jacobian submatrix, For subgraph Branch-bus correlation matrix For subgraph Branch-bus correlation matrix For subgraph The number of connected components, For subgraph The number of connected components, For subgraph The number of independent loops, For subgraph The number of independent loops; For full MTD and incomplete MTD, we will introduce how to perform optimal layout separately later; Step 4: Selection of D-FACTS device placement location under sensitivity weighting; Sensitivity can be calculated based on the increase in the rank of the composite matrix before and after the disturbance. When only the first line is disturbed, the sensitivity can be obtained as follows: or ; in, This represents the measurement Jacobian matrix after perturbing only the l-th line; This is the difference between the measured Jacobian matrix after perturbing only the l-th line and the original measured Jacobian matrix; Minimum Spanning Tree (MST): Treating the power grid as a graph The nodes are busbars, and the edges are transmission lines. For the collection of busbars in the power system, The scale is , Let O be the set of branches of the spanning tree, with size O. ; (1) Use the reciprocal of the sensitivity as the edge weight: ; Higher sensitivity results in lower weighting and higher priority for inclusion in the MST (Medium-Level Search). Based on the MST, additional D-FACTS (Digital-Based Detection and Testing) circuits are deployed incrementally from high to low sensitivity until the detection capability reaches the target. ; (2) Use Kruskal's algorithm to generate a minimum spanning tree that covers all nodes, ensuring basic connectivity and defense coverage; (3) Based on the MST, gradually increase the number of additional D-FACTS deployment lines according to the sensitivity from high to low until the detection capability reaches the target. ; The optimal deployment location selection technique utilizes the Kruskal algorithm, a minimum spanning tree (MST) construction method based on edge sorting, suitable for sparse graphs. Its goal is to minimize the total weight of the spanning tree while ensuring graph connectivity. In power grid D-FACTS deployment optimization, edge weights can be set as the reciprocal of sensitivity. The higher the sensitivity, the lower the weight, and the higher the priority for selection into MST; Basic steps: 1) Initialization: When all nodes are disconnected, generate a tree set. ; 2) Edge sorting: ; 3) Add edge by edge: Start with the edge with the smallest weight. If adding this edge will not form a cycle, then merge it. ; 4) Termination condition: When When the time comes, the algorithm ends; Objective function: ; Constraints: hour, No loop Connected; In MTD deployment: Edge weights ,in The set of line disturbance sensitivities: ; Kruskal's edge selection process ensures the minimum number of deployments and the maximum defense coverage, while reserving adjustable points for runtime optimization; it minimizes the number of devices and investment costs while maintaining detection capabilities, and reserves adjustable points to optimize the objective function. ; Kruskal's edge selection process ensures the minimum number of deployments and the maximum defense coverage, while reserving adjustable points for runtime optimization; it minimizes the number of devices and investment costs while maintaining detection capabilities, and reserves adjustable points to optimize the objective function. ; in, For the first The weight of the edge (the disturbed line), The weight of the edge. for and The minimum included angle of the column space. For only on the line The measurement Jacobian matrix obtained after applying the MTD perturbation; To select the set of lines to deploy; For testing capability indicators; For deployment costs; This is the cost trade-off coefficient.

[0020] Reserved adjustable margin: After the detection capability meets the requirements, priority is given to reserving the adjustable margin of the critical line, so as to facilitate dynamic disturbance of the power grid through ACOPF optimization during the operation phase and improve the physical layer resilience.

[0021] 2) Optimization during the operational phase; The deployment phase optimization has determined the optimal installation location for the D-FACTS (Distributed Flexible AC Transmission System) equipment, achieving near-full MTD (Moving Target Defense) defense capabilities under low investment conditions. However, the deployment phase solution is static and cannot adjust parameters according to real-time operating status, resulting in the following shortcomings: Detection rate fluctuations: Load changes and topology switching can lead to a decrease in defense performance with fixed disturbance parameters; Lack of economic efficiency: The defense strength is not balanced with power generation costs and system losses during operation; Insufficient resilience: It cannot be dynamically adjusted according to attack risks, reducing flexibility in responding to emergencies. Step 1: Incorporate D-FACTS into the AC-optimal power flow (ACOPF) model; (1) Basic ACOPF model in, This represents the active and reactive power vectors for power generation. This represents the node voltage magnitude vector; For the set of generator nodes; For nodes Electricity generation cost function; (2) Power balance constraints (active / reactive): ; ; Generator output constraints: ; Voltage amplitude constraint: ; Power flow constraints: ; in, For nodes Injected active and reactive power, For power system bus voltage, For power system bus voltage, The voltage phase angle difference, busbar With busbar Real part of the inter-admittance matrix The imaginary part of the admittance matrix, busbar The upper unit contributes power. busbar Lower limit of active power output of the unit. busbar The upper limit of the active power output of the unit. busbar The lower limit of the permissible voltage amplitude. busbar The upper limit of the allowable voltage amplitude For from the busbar Measured The complex power of the line, For the line The permissible apparent power limit, For the busbar Connected busbar set (including itself); Step 2: Calculation and setting of impedance sensitivity PLIS; Under the optimal power flow framework, the total active power loss of the system is denoted as . ,in Let the line reactance vector be denoted by , and the sensitivity of power loss to impedance be defined as the directional derivative of each line as : ; ; in, For power system bus With busbar Sensitivity between For power loss, Given the impedance set of the transmission line, in the optimal power flow ACOPF model... Indicates reactance, Representing resistance, the impedance sensitivity results in the AC model are taken into account, which further optimizes the deployment scheme and can improve the power grid detection performance; At the running point Evaluate the expression at the specified location; according to the chain rule, it can be written as: ; in, This is the concatenated vector of all bus phase angles and voltage magnitudes; It is a side road Series admittance; This represents the total active power loss of the system, for disturbances less than 5% of the relative disturbance. At the running point, it can be approximately equal to ; in, It is a sensitivity vector based on line stacking; therefore, The magnitude of this value represents the first-order influence of adjusting the reactance along the line on the system loss, assuming other conditions remain unchanged. Based on the above definition, this paper adopts the following D-FACTS line selection strategy: in the candidate set... Calculate the running point In conjunction with the device amplitude constraint and the minimum effective disturbance constraint, select ; As a priority set of lines for D-FACTS; this criterion, without significantly increasing computational complexity, ensures that limited reactance adjustment capability is converted into loss variation as much as possible; simultaneously, it can be used in conjunction with the rank-enhanced MTD objective: while satisfying In the case of, Installing D-FACTS devices and applying disturbances on lines with high capacitance values ​​can achieve a better trade-off between security and economy; in order for a line reactance change to achieve the effect of improving attack detection, the reactance change must meet the following constraints: ; in, The line reactance before the disturbance. The line reactance after the disturbance. The number of D-FACTS devices installed. This is the lower limit coefficient for relative disturbance. This is the upper limit coefficient for relative disturbance; Step 3: Full MTD Layout Algorithm; The logic for arranging the algorithm in the invention is based on the median. For installing D-FACTS devices on the line, two algorithms were designed for both full MTD and incomplete MTD. This design uses Kruskal's algorithm to construct a spanning tree. Algorithm 1 is used for full MTD, selecting a spanning tree as the installation line for the D-FACTS device. The selection principle is that the lines forming the spanning tree are the most suitable. The sum of the values ​​should be as large as possible; the algorithm can only guarantee this when selecting values. They are connected, but... There may be isolated nodes in the middle, by It can be seen that each isolated node reduces the rank of the composite matrix by 1; when If the graph is connected, then Algorithm 1 will stop and output the placement of the D-FACTS devices; otherwise, it will process the spanning tree. Sort the values ​​from largest to smallest, reduce the weight of the smallest value, and reselect the spanning tree to see if the requirements are met. If not, restore the line weights, reduce the weight of the previous smallest value in the descending sort, and repeat the above operation until the requirements are met. Step 4: Complete MTD; If it is a complete measurement and a complete MTD, then Therefore, the minimum number of D-FACTS devices that can be installed is: That is, the installation locations form a spanning tree. To maximize the rank of the composite matrix, simply connect the non-D-FACTS lines. Satisfy the rank of the composite matrix Therefore, it can detect any FDI; it should be noted that although it is a spanning tree, this tree can have multiple combinations. In order to find the optimal combination, this invention... Large lines are used as installation locations for spanning tree lookup. Taking the IEEE 6-node system as an example, the PLIS values ​​of each line are as follows: Figure 2 As shown, the optimal installation location for the D-FACTS device, given by Algorithm 1, is... ,like Figure 3 As shown; Step 5: Multi-objective optimization modeling; To optimize both cost-effectiveness and defense performance, an attack detection rate improvement indicator is introduced. With system resilience indicators Construct a multi-objective optimization model: ; in: Total operating cost (the sum of power generation costs); For system power flow loss; This represents the improvement in attack detection rate under perturbation parameters; This represents the increase in physical toughness; These are the weighting coefficients.

[0022] 3) Communication layer defense; In the first two phases, we optimized the deployment of a limited number of D-FACTS devices during the deployment phase (to increase the degrees of freedom that can be independently disturbed). During the operational optimization phase, physical disturbance parameters are dynamically adjusted in conjunction with ACOPF. This significantly enhanced attack detection capabilities; however, due to budget and line limitations, the actual... Often smaller than the state dimension This means that relying solely on the physical layer MTD is still insufficient to meet the conditions for complete detection, i.e. Specifically, the steps include the following: Step 1: Introduce the encoding matrix; In the case of complete measurement but incomplete MTD, the maximum rank of the composite matrix is... When the number of D-FACTS devices installed is minimal, the corresponding number of non-D-FACTS lines is maximum. According to formula (21), to make... Since the rank is maximized and neither subgraph can contain a cycle, the non-D-FACTS route is a spanning tree. Therefore, the number of D-FACTS devices installed is... Taking the IEEE 14-node system as an example, the PLIS values ​​of each line are as follows: Figure 4 As shown, Algorithm 2 gives the optimal installation location for the D-FACTS device as follows: ,like Figure 5 As shown; but at this time ,when At this time, no anomalies are detected in the residual detection; in order to further improve the rank of the composite matrix, the following processing is performed on the perturbed matrix. After encoding, the rank of the composite matrix becomes: ; in, In order to fully detect FDI, i.e. The encoded matrix needs to be able to handle any noise-free conditions. The following conditions must be met: ; in, The bus voltage phase angle vector corresponding to the measured value represented by the Jacobian matrix after injecting false data into the attacker; Step 2: For the changed Enlarge the rank of the encoding; set up and Let MTD and MC be the sets of measurements affected respectively, then the total set of affected measurements is... The unaffected set is For ease of subsequent derivation, use Then, they are classified according to the measurements. and They can be represented as: ; Where the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; because The measurements within the range were not affected by MTD and MC, and can be obtained Therefore, we can obtain: ; when When it was established, the formula The rank is , The rank is at most Therefore, we can obtain ,because From the matrix properties, we can obtain Therefore, the minimum number of measurements affected by MTD and MC can be obtained. However, we cannot draw a direct conclusion. At this time, the composite matrix is ​​full rank because when performing MTD, changing the reactance of a line will correspondingly change multiple related active power flows and bus active power injections; assuming the connecting bus... and The The reactance of the branch circuit has changed. All its measurements can be expressed as and , belongs to set To better illustrate the point, we will use... and express The corresponding measurements are as follows: and The power injected into the busbar is the sum of the active power flows of all lines connecting the busbar, and can be expressed as: , This represents the sum of the active power flow of the remaining lines excluding those connected to this bus. ,exist The corresponding rows also meet the requirements. Here we only analyze the first When the reactance of a line changes, it causes achievable Therefore, in In the middle, the first branch road and satisfy That is Middle and the first The rows related to each line are linearly dependent, therefore in the set There is only one row in the matrix The rank contributes to the composite matrix; therefore, to make the composite matrix full rank, the reactance number needs to be changed to achieve [a certain value]. However, under incomplete MTD, the number of D-FACTS devices arranged is Therefore, in order to reach the maximum rank, it is necessary to promote [the individual / entity]. Next, we encode the composite matrix to increase its rank. Here, we take the encoding matrix as a diagonal matrix, and to increase the rank, we take the values ​​that do not belong to the rank. The The measurements are encoded, but the encoded values ​​are not arbitrarily chosen; let's consider a matrix. A submatrix of a composite matrix. and In order to be with the first Strip measurements are correlated and are submatrices The non-zero elements in the array can be represented as: ; in, Indicates in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns, For matrix The Middle OK The sign factor of column elements, For matrix The determinant value, In order to be in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns; when the... When the lines are not encoded, the rank of the composite matrix is ​​given by the case of incomplete MTD maximum rank. , It is about an unknown number A linear equation, namely When not encoded When the value is 1, , can be obtained , ;like but ,like ,when hour If at this time but The rank can be stably achieved Because when ,exist This is equivalent to all rows of the encoded data becoming 0, which poses a risk of rank reduction in a composite matrix, therefore it is excluded. In the case of; if This indicates that there exists a composite matrix that excludes the lines. After the row and column, rank The submatrix, when the coding factor The rank of the composite matrix can be increased when 1 or 2; it can be inferred that when 1 / 2 is satisfied... and coding factor When 1 or 2, the rank of the new composite matrix is ​​not only equal to the rank of the composite matrix but also equal to The specific values ​​are irrelevant, and if the rank of the composite matrix is... , At this point, rows without candidate codes are extracted from the composite matrix. of A number of independent rows are denoted as ,if When on During encoding, the rank of the composite matrix can be increased by 1, and this process can be repeated until the rank of the composite matrix reaches a certain value. .

[0023] 4) Three-tiered collaborative mechanism; The three-layer collaborative mechanism proposed in this invention aims to achieve dynamic coupling and closed-loop optimization among the deployment layer, operation layer, and communication layer. By unifying optimization objectives, constraints, and feedback mechanisms, it organically integrates hardware investment, operational flow scheduling, and information layer coding defense, thereby achieving multi-objective coordination among detection rate, system resilience, and operational economy, and continuously iterating and optimizing throughout the entire lifecycle. Based on existing technologies, this mechanism introduces a systematic algorithm framework for cross-layer joint optimization and feedback updates, breaking through the limitations of existing methods such as inter-layer fragmentation and inconsistent optimization objectives.

[0024] Step 1: Three-layer unified optimization model; Let the dimension of the system state variables be... Deployment layer decision variables are (Installation location), runtime control variables are (Perturbation amplitude) (Power generation and voltage state), communication layer control variables are (Quantitative coding matrix), then the unified optimization model can be expressed as: ; ; in, Number of lines; To deploy the investment cost function; The operating period includes power generation costs and system losses; For detection capability metrics (such as minimum singularity); For system resilience indicators (such as disturbance resistance); This represents the lower limit of detection capability. It is the Frobenius norm; The AC optimal power flow constraint equations; Here, y represents the security constraint function; y is the route deployment selection vector; and st is the vector that satisfies the following constraints. Step 2: Collaborative optimization algorithm; a) Deployment layer initialization; Input historical operation data and attack detection indicator thresholds The optimal D-FACTS installation candidate set is calculated using a minimum spanning tree + sensitivity weighted algorithm. Output As an initial deployment decision; b) Runtime layer optimization (inner loop); Given deployment results Constructing the ACOPF model: ; Incorporate security constraints and detection capabilities into proxy indicators: ; Solving for the disturbance amplitude With the trend distribution scheme; c) Communication layer encoding generation; Generate a random orthogonal coding matrix based on the runtime perturbation results. ,satisfy And with Column spaces should be as independent as possible; Verify rank condition If the conditions are not met, the encoding matrix is ​​regenerated. d) Lifecycle feedback; During operation, monitor detection rate, false alarm rate, operating cost, and resilience metrics; feed the results back to the deployment layer for new candidate sets. Weighting will determine the next phase of deployment. Iterate until convergence or the lifecycle update interval is reached; Through the three-layer collaborative mechanism, we can obtain the average detection rate (ADP) of spoofed data injection attacks for both fully MTD (IEEE 6-node system) and incomplete MTD (IEEE 14-node system) under DC, AC, and measurement noise conditions. Figure 6As shown. We can also see that, compared to traditional MTD and systems without MC or MTD, this invention has a higher success rate in preventing spoofed data injection attacks, such as... Figure 7 As shown.

[0025] The above embodiments are implemented based on the technical solution of the present invention, providing detailed implementation methods and specific operation processes. However, the scope of protection of the present invention is not limited to the above embodiments. Unless otherwise specified, the methods used in the above embodiments are conventional methods.

Claims

1. A proactive defense method for power system communication security that integrates metering coding and optimal disturbance deployment, characterized in that, Includes the following steps: S1. Deployment Phase Optimization: Dynamically adjusting the reactance of transmission lines. To change the measurement Jacobian matrix It disrupts the attacker's known power system estimation model to achieve the purpose of defense. At the same time, it uses the Kruskal algorithm to use sensitivity as a decision variable to obtain the minimum number of D-FACTS devices and the maximum defense effect. S2. Operational Phase Optimization: The static layout scheme during the deployment phase is optimized by introducing the AC Optimal Power Flow (ACOPF) model. The impedance sensitivity of all lines is used as a decision variable to re-select the device placement locations, so that the system achieves maximum detection performance when only D-FACTS devices are installed. or At the same time, an attack detection rate improvement indicator was introduced. With system resilience indicators Construct a multi-objective optimization model; among which, For the original Jacobian matrix of the system when using only the D-FACTS device New Measurement Jacobian Matrix after D-FACTS Device Perturbation The rank of the composite matrix formed by combining the two parts. The original measurement Jacobian matrix of the system, The number of busbars in the power system. The number of branches in the power system; S3, Communication Layer Defense: Through metrological coding, secure communication devices encode some measurements, enabling the creation of new composite matrices. Reaching full rank To completely detect fake data, an encoding matrix is ​​introduced. Make This enables the system to fully detect data injection attacks in both full MTD and non-full MTD scenarios; S4, Three-layer collaborative mechanism: Dynamically couples the deployment layer, operation layer and communication layer. Through unified optimization objectives, constraints and feedback mechanisms, it organically integrates hardware investment, operation flow scheduling and information layer coding defense. At the same time, it introduces a systematic algorithm framework for cross-layer joint optimization and feedback updates.

2. The active defense method for power system communication security that integrates metering coding and optimal disturbance deployment according to claim 1, characterized in that, The optimization during the deployment phase includes the following steps: 1) State estimation: Under the DC power flow model, the relationship between power grid measurements and state is as follows: ; in, For measurement vectors, For measuring quantity; This is the state vector, representing the bus voltage phase angle vector; The Jacobian matrix is ​​a measurement matrix that maps the system state to the measured values. The measurement noise is modeled as a Gaussian distribution, and the measurement noise covariance matrix is ​​a diagonal matrix. : ; in, For the first The standard deviation of the measured noise; Power information physical systems have complex structures, and state estimation is necessary to eliminate the effects of measurement errors. Currently, the least squares method is widely used in state estimation; however, when measurement noise... The objective function of WLS is: ; when When it is symmetrical and positive definite, it is derived that , Full Rank The optimal solution for the bus voltage phase angle vector is: ; make , It is possible to project vectors onto The projection operator, without being attacked, measures the residual as follows: ; in, The measurement residual is the difference between the measured vector and the estimated measurement vector. For measurement vectors; When the attack vector is The measurement residual is then: ; like ,but At this point, the presence of the attack cannot be detected; if , I is the identity matrix, and when the attack vector injected by the attacker is not completely within... When using column space, the measurement residual will not be zero, and the attack behavior will be detected; in actual detection, measurement noise exists, so the residual... The L2 norm and the set threshold When comparing, If the condition is met, then bad data is considered to exist; otherwise, it is not. 2) FDI attack under measurement matrix changes: vector Injecting into the measurement vector to disrupt the state estimation, i.e., modeling it as follows: ; in, For the measurement vector after injecting the attack vector, through the subspace estimation algorithm, there exists a... Make ; Let be a basis for measuring the Jacobian matrix. The change in the bus voltage phase angle vector to make the equations equal; When the line When equipped with a D-FACTS device, its equivalent reactance will be periodically modified to any value by the D-FACTS device within its adjustable range, where i is a bus of the power system and j is another bus connected to it. ; in, The measurement Jacobian matrix calculated by the attacker before the D-FACTS device is disturbed, which is the original measurement Jacobian matrix of the system; This is the new measurement Jacobian matrix actually used by the control center after the device was disturbed; Through the subspace estimation algorithm, there exists a Make ; 3) Full MTD vs. Incomplete MTD: The noise-free model is: ; If and only if for any They all At that time, and ,Right now The attack is detectable; Decompose the measurement matrix. It can be represented as: ; in, For the measurement deployment matrix in the power system, It is a diagonal matrix, and its diagonal elements are the reciprocals of the reactance of each branch; The matrix is ​​determined by the power grid topology. This is an estimate of the measurement vector after the injection of the attack vector; When the power grid topology is an undirected graph Among them, the power system bus cluster The scale is The set of branches in the power system The scale is Any branch is Therefore, the correlation matrix of the power system is obtained as follows: ; Let the balance busbar be denoted as Delete the first from A Rows yield a reduced-order matrix In the DC power flow model, the branch power flow is as follows: Busbar active power injection is ;in, For the line The phase angle difference between the two busbars; We obtain this from the matrix properties: To maximize the rank of the composite matrix, then , ; in, This is the difference matrix between the new measurement Jacobian matrix and the original measurement Jacobian matrix. To deploy the measurement matrix, This is the diagonal matrix of the D-FACTS lines; By the theorem of Euler's formula in disconnected graphs, for any given graph... 1 node Edge, A ring road, and Planar diagram of connected components The following formula exists: ; For those with Each node and Planar graph of connected components The rank of its correlation matrix is: ; The composite matrix formed by the new measurement Jacobian matrix and the original measurement Jacobian matrix is ​​represented as: ; To achieve detection of any FDI, it is necessary to achieve... From the matrix properties, we obtain: ; in, To measure the rank of the deployment matrix, The matrix is ​​composed of the original reactance of the line. The matrix formed by the new reactances after the D-FACTS device is disturbed; Because of any The rank of the composite reactance matrix And because ,therefore ,get: ; To meet the full rank requirement , This indicates that the number of transmission lines must not be less than twice the number of states; when the number of lines... In the case of full measurement, the rank of the composite matrix is ​​at most 1. As shown in the following formula: ; When the line is divided into sections for installing D-FACTS devices With or without D-FACTS device ,get: ; in, and They are and The measurement device arrangement matrix, It is the diagonal matrix of D-FACTS lines, when If there is no cycle, then , ,get: ; in, Circuit diagram with D-FACTS installed The corresponding measurement Jacobian submatrix, For subgraph Branch-bus correlation matrix For subgraph Branch-bus correlation matrix For subgraph The number of connected components, For subgraph The number of connected components, For subgraph The number of independent loops, For subgraph The number of independent loops; 4) Selection of the location for the D-FACTS device under sensitivity weighting: Sensitivity is calculated based on the increase in the rank of the composite matrix before and after the disturbance. When only the first line is disturbed, the sensitivity is: ; in, This represents the measurement Jacobian matrix after perturbing only the l-th line; This is the difference between the measured Jacobian matrix after perturbing only the l-th line and the original measured Jacobian matrix; Minimum Spanning Tree (MST): Treating the power grid as a graph The nodes are busbars, and the edges are transmission lines. For the collection of busbars in the power system, The scale is , Let O be the set of branches of the spanning tree, with size O. ; Use the reciprocal of the sensitivity as the edge weight: ; Higher sensitivity results in lower weighting and higher priority for inclusion in the MST (Medium-Level Search). Based on the MST, additional D-FACTS (Digital-Based Detection and Testing) circuits are deployed incrementally from high to low sensitivity until the detection capability reaches the target. .

3. The active defense method for power system communication security that integrates metering coding and optimal disturbance deployment according to claim 2, characterized in that, The minimum spanning tree (MST) uses Kruskal's algorithm for optimal deployment location selection, and specifically includes the following steps: 1) Initialization: When all nodes are disconnected, generate a tree set. ; 2) Edge sorting: ; 3) Add edge by edge: Start with the edge with the smallest weight. If adding this edge will not form a cycle, then merge it. ; 4) Termination condition: When When the time comes, the algorithm ends; Objective function: ; In MTD deployment: Edge weights ,in This is a set of line disturbance sensitivities; ; To minimize the number of devices and investment costs while ensuring detection capabilities, and to reserve an adjustable point for optimizing the objective function: ; in, For the first The weight of the edge (the disturbed line), The weight of the edge. for and The minimum included angle of the column space. For only on the line The measurement Jacobian matrix obtained after applying the MTD perturbation; To select the set of lines to deploy; For testing capability indicators; For deployment costs; This is the cost trade-off coefficient.

4. The active defense method for power system communication security that integrates metering coding and optimal disturbance deployment according to claim 3, characterized in that, The optimization during the operational phase involves multi-objective modeling, specifically including the following steps: 1) Incorporate D-FACTS into the AC-optimal power flow (ACOPF) model: The optimization objective of the optimal power flow is to minimize the system operating cost. ; in, This represents the active and reactive power vectors for power generation. This represents the node voltage magnitude vector; For the set of generator nodes; For nodes Electricity generation cost function; Constraints: Power balance constraints: ; ; Generator output constraints: ; Voltage amplitude constraint: ; Power flow constraints: ; in, For nodes Injected active and reactive power, For power system bus voltage, For power system bus voltage, The voltage phase angle difference, busbar With busbar Real part of the inter-admittance matrix The imaginary part of the admittance matrix, busbar The upper unit contributes power. busbar Lower limit of active power output of the unit. busbar The upper limit of the active power output of the unit. busbar The lower limit of the permissible voltage amplitude. busbar The upper limit of the allowable voltage amplitude For from the busbar Measured The complex power of the line, For the line The permissible apparent power limit, For the busbar The set of connected busbars, including itself; 2) Calculation and setting of impedance sensitivity; The sensitivity of power loss to impedance is defined as the directional derivative of each line: ; ; in, For power system bus With busbar Sensitivity between For power loss, Given the impedance set of the transmission line, in the optimal power flow ACOPF model... Indicates reactance, Indicates resistance; At the running point To evaluate this value, according to the chain rule, it can be written as: ; in, This is the concatenated vector of all bus phase angles and voltage magnitudes; It is a side road Series admittance; This represents the total active power loss of the system, for disturbances less than 5% of the relative disturbance. At the running point, approximately equal to ; In the candidate set Calculate the running point In conjunction with the device amplitude constraint and the minimum effective disturbance constraint, select ; In order for a change in the reactance of a certain line to achieve the effect of improving attack detection, the reactance change must meet the following constraints: ; in, The line reactance before the disturbance. The line reactance after the disturbance. The number of D-FACTS devices installed. Let be the lower limit coefficient of relative disturbance. This is the upper limit coefficient for relative disturbance; 3) Multi-objective optimization modeling: Introducing attack detection rate improvement metrics With system resilience indicators Construct a multi-objective optimization model: ; in: Total operating cost (the sum of power generation costs); For system power flow loss; This represents the improvement in attack detection rate under perturbation parameters; This represents the increase in physical toughness; These are the weighting coefficients.

5. The active defense method for power system communication security that integrates metering coding and optimal disturbance deployment according to claim 4, characterized in that, The communication layer defense specifically includes the following steps: 1) Introduce an encoding matrix; For the perturbated matrix After encoding, the rank of the composite matrix becomes: ; in, In order to fully detect FDI, i.e. The encoded matrix needs to be able to handle any... in a noise-free environment. The following conditions must be met: ; in, The bus voltage phase angle vector corresponding to the measured value represented by the Jacobian matrix after injecting false data into the attacker; 2) Regarding the changed Enlarge the rank of the encoding; use Then, they are classified according to the measurements. and They can be represented as: ; Where the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; the subscript is The matrix represents the matrix in The middle is composed of sets The submatrix formed by the corresponding rows; ; when At the time of its establishment, its rank was , The rank is at most ;get ,because From the matrix properties, we can obtain Therefore, the minimum number of measurements affected by MTD and MC can be obtained. ; When matrix A submatrix of a composite matrix. and In order to be with the first Strip measurements are correlated and are submatrices The non-zero elements in the array are represented as: ; in, Indicates in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns, For matrix The Middle OK The sign factor of the column element's sign factor, For matrix The determinant value, In order to be in Remove elements The determinant of the submatrix obtained after the corresponding rows and columns.

6. The active defense method for power system communication security that integrates metering coding and optimal disturbance deployment according to claim 5, characterized in that, The three-layer collaborative mechanism specifically includes: 1) Three-layer unified optimization model; The unified optimization model is represented as: ; ; in, Number of lines; To deploy the investment cost function; The operating period includes power generation costs and system losses; As a measure of detection capability; As a system resilience indicator; This represents the lower limit of detection capability. It is the Frobenius norm; The AC optimal power flow constraint equations; y is the security constraint function; y is the route deployment selection vector; 2) Collaborative optimization algorithm; Input historical operational data and the lower limit of attack detection capability The optimal D-FACTS installation candidate set is calculated using a minimum spanning tree and sensitivity-weighted algorithm. Output As an initial deployment decision; Given deployment results Constructing the ACOPF model: ; Incorporate security constraints and detection capabilities into proxy indicators: ; Solving for the disturbance amplitude With the trend distribution scheme; Communication layer coding generation Generate a random orthogonal coding matrix based on the runtime perturbation results. ,satisfy And with Column spaces should be as independent as possible; Verify rank condition If the conditions are not met, the encoding matrix is ​​regenerated. Lifecycle Feedback: During operation, monitor detection rate, false alarm rate, operating cost, and resilience metrics; feed the results back to the deployment layer and create new candidate sets. Weighting will determine the next phase of deployment. Iterate until convergence or until the lifecycle update interval is reached.