Smart power grid false data injection attack detection method, terminal and storage medium

By constructing a three-dimensional spatiotemporal tensor and an improved attack feature extraction model, the accuracy and reliability issues of detecting fake data injection attacks in smart grids are solved, achieving efficient and accurate attack identification and type determination, and supporting the security protection of smart grids.

CN121887528APending Publication Date: 2026-04-17YANSHAN UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing methods for detecting fake data injection attacks suffer from problems such as low detection accuracy, poor model interpretability, insufficient extraction of spatiotemporal features, lack of adaptive focusing mechanisms, and unstable training processes, making it difficult to effectively identify covert collaborative attacks in smart grids.

Method used

Based on heterogeneous measurement data, a three-dimensional spatiotemporal tensor is constructed. By improving the attack feature extraction model that combines convolutional neural networks and bidirectional long short-term memory networks with a global attention mechanism, the attack prediction probability is calculated and the attack type is determined, thereby achieving efficient detection of fake data injection attacks.

Benefits of technology

It improves the accuracy and reliability of detecting fake data injection attacks, provides more intuitive detection results, avoids false positives and false negatives, can accurately identify attack types, and provides targeted countermeasures for operations and maintenance personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887528A_ABST
    Figure CN121887528A_ABST
Patent Text Reader

Abstract

The invention provides a smart grid false data injection attack detection method, a terminal and a storage medium, and relates to the technical field of power system information security. The method comprises the steps that heterogeneous measurement data of a target smart grid are collected, a three-dimensional space-time tensor is constructed based on the heterogeneous measurement data, and the heterogeneous measurement data comprise node measurement data, branch measurement data and network topology data; inputting the three-dimensional space-time tensor into a constructed attack feature extraction model, and outputting a target feature corresponding to the three-dimensional space-time tensor; based on the target features, calculating an attack prediction probability, and based on the attack prediction probability, determining whether the target smart grid is subjected to a false data injection attack; and when the target smart power grid is subjected to the false data injection attack, calculating a probability distribution vector by using the target features, and determining an attack type of the false data injection attack on the target smart power grid according to the probability distribution vector. According to the invention, the accuracy and reliability of detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system information security technology, and in particular to a method, terminal and storage medium for detecting false data injection attacks in smart grids. Background Technology

[0002] As a typical example of the deep integration of physical systems and information networks, the safe and stable operation of smart grids highly depends on the accuracy and reliability of measurement systems. However, as power grids develop towards open interconnection and intelligent interaction, their monitoring and data acquisition systems face increasingly severe cyberattack threats. Among these, spoofed data injection attacks are a highly covert and destructive attack method. Attackers maliciously tamper with sensor readings or state estimation input data by intruding into measurement systems or communication networks, thereby misleading the energy management system to make incorrect decisions. In severe cases, this can trigger a chain of failures and endanger power grid security.

[0003] Based on existing technology analysis, detection methods for fake data injection attacks can be mainly divided into two categories: The first category is based on physical models, which rely on power grid state estimation and residual analysis. Although this method has a theoretical basis, it has two limitations: first, the detection accuracy is limited by the accuracy of the model and is sensitive to parameter errors, topology changes, and nonlinear operating conditions, which can easily lead to false alarms; second, it is difficult to resist cooperative attacks that meet physical constraints, resulting in detection blind spots.

[0004] The second category consists of data-driven methods, particularly deep learning models such as Convolutional Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks. These methods avoid model dependence but still face the following prominent problems: First, poor model interpretability and opaque decision-making processes; second, insufficient spatiotemporal feature extraction and fusion, resulting in limited ability to identify covert collaborative attacks; third, a lack of adaptive focusing mechanisms for key attack features, making them susceptible to redundant information; and fourth, fixed multi-objective loss weights during training, which can lead to unstable convergence and decreased generalization performance. Summary of the Invention

[0005] This application provides a method, terminal, and storage medium for detecting fake data injection attacks in smart grids, in order to solve the problem of low detection accuracy of fake data injection attacks in the prior art.

[0006] Firstly, this application provides a method for detecting spoofed data injection attacks in smart grids, including: Collect heterogeneous measurement data of the target smart grid and construct a three-dimensional spatiotemporal tensor based on the heterogeneous measurement data, which includes node measurement data, branch measurement data and network topology data; The three-dimensional spatiotemporal tensor is input into the constructed attack feature extraction model, and the target features corresponding to the three-dimensional spatiotemporal tensor are output. Based on the target characteristics, the attack prediction probability is calculated, and based on the attack prediction probability, it is determined whether the target smart grid is subjected to a false data injection attack. When the target smart grid is subjected to a false data injection attack, the target characteristics are used to calculate a probability distribution vector, and the attack type of the false data injection attack on the target smart grid is determined based on the probability distribution vector.

[0007] Secondly, this application provides a terminal including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method as described in the first aspect or any possible implementation of the first aspect above.

[0008] Thirdly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method as described in the first aspect or any possible implementation of the first aspect.

[0009] This application provides a method, terminal, and storage medium for detecting spoofed data injection attacks on smart grids. Based on heterogeneous measurement data, this application constructs a three-dimensional spatiotemporal tensor, integrating the data across time, space, and feature dimensions. This better captures the dynamic changes in the grid's operating status in time and space, as well as the correlations between different features, providing a more effective data organization for subsequent attack feature extraction and detection, thus improving the accuracy and reliability of detection. Furthermore, by calculating the attack prediction probability based on the extracted target features, the probability value quantifies the likelihood of the target smart grid being subjected to a spoofed data injection attack, providing more intuitive and accurate detection results and avoiding the misjudgments and omissions that may arise from simple binary judgments. Simultaneously, by determining the specific type of spoofed data injection attack based on the calculated probability distribution vector, this helps maintenance personnel gain a deeper understanding of the attack's characteristics and methods, enabling them to take more targeted countermeasures. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a flowchart illustrating the implementation of the smart grid fake data injection attack detection method provided in this application embodiment; Figure 2 This is a schematic diagram of the attack feature extraction model provided in the embodiments of this application; Figure 3 This is a schematic diagram of the system simulation model of the IEEE 6-node test system provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of the smart grid fake data injection attack detection device provided in the embodiments of this application; Figure 5 This is a schematic diagram of the terminal provided in the embodiments of this application. Detailed Implementation

[0012] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0013] To make the objectives, technical solutions, and advantages of this application clearer, the following description will be provided in conjunction with the accompanying drawings and specific embodiments.

[0014] Figure 1 The implementation flowchart of the smart grid fake data injection attack detection method provided in the embodiments of this application is described in detail below: In step 101, heterogeneous measurement data of the target smart grid are collected, and a three-dimensional spatiotemporal tensor is constructed based on the heterogeneous measurement data. The heterogeneous measurement data includes node measurement data, branch measurement data, and network topology data.

[0015] In this embodiment, relying on the Energy Management System (EMS) and Supervisory Control and Data Acquisition (SCADA) system, multi-scale heterogeneous measurement data of the target smart grid are collected synchronously to ensure the consistency and integrity of the data in the time dimension. Then, a three-dimensional spatiotemporal tensor is constructed using the collected heterogeneous measurement data.

[0016] Among them, heterogeneous measurement data can include node measurement data (such as key parameters reflecting the operating status of a single node, such as bus voltage and node power), branch measurement data (such as data characterizing the transmission characteristics of power grid branches, such as branch power flow, impedance, and loss), and network topology data (such as data reflecting the physical connection form of the power grid, such as the connection relationship between power grid nodes and branches and information on topology changes).

[0017] This application embodiment collects heterogeneous measurement data from the target smart grid, covering node measurement data, branch measurement data, and network topology data, enabling comprehensive acquisition of grid operation status information from multiple perspectives. The different types of data complement each other, providing a rich and comprehensive data foundation for subsequent detection, avoiding information gaps and biases that may arise from a single data source, and helping to more accurately identify spoofed data injection attacks.

[0018] Furthermore, the three-dimensional spatiotemporal tensor constructed in this application not only considers the spatial correlation of power grid data but also incorporates temporal dimension information. The operating status of the smart grid interacts and correlates with each other in different times and spaces, and spoofing attacks may exhibit different characteristics in different times and spatial locations. Through comprehensive analysis of the spatiotemporal dimensions, various forms of spoofing attacks can be detected more comprehensively, including those attacks that are covert in time and space.

[0019] In one possible implementation, constructing a three-dimensional spatiotemporal tensor based on heterogeneous measurement data can include: By aligning and integrating heterogeneous measurement data along the time dimension, a three-dimensional spatiotemporal tensor is obtained.

[0020] Optionally, the collected multi-scale node measurement data, branch measurement data, and network topology data are aligned and integrated in the time dimension to obtain a three-dimensional spatiotemporal tensor, i.e.:

[0021] in, For a three-dimensional spacetime tensor, For the number of power grid nodes, For time steps, For characteristic bits, It is a real number.

[0022] In one possible implementation, after collecting heterogeneous measurement data from the target smart grid, the method may further include: Heterogeneous measurement data are cleaned to remove outliers, missing values, and other invalid data, and missing data are filled in using interpolation methods. Subsequently, data standardization is performed to convert measurement data of different magnitudes and units to a unified data range, eliminating the impact of dimensional differences on subsequent model calculations.

[0023] Accordingly, a three-dimensional spatiotemporal tensor is constructed based on the heterogeneous measurement data after data standardization.

[0024] In step 102, the three-dimensional spatiotemporal tensor is input into the constructed attack feature extraction model, and the target features corresponding to the three-dimensional spatiotemporal tensor are output.

[0025] In this embodiment of the application, the three-dimensional spatiotemporal tensor constructed in step 101 is input into the constructed attack feature extraction model to obtain the target features corresponding to the three-dimensional spatiotemporal tensor, which are used for subsequent judgment of fake data injection attacks and identification of attack types.

[0026] In one possible implementation, the process of constructing the attack feature extraction model can be as follows: Acquire historical heterogeneous measurement data of the target smart grid, as well as the historical target features corresponding to the historical heterogeneous measurement data, and construct a training set; An attack feature extraction model is constructed, which includes a spatial feature extraction module, a temporal feature extraction module, and a feature fusion module connected in sequence. The attack feature extraction model is trained based on the training set.

[0027] Optionally, the training set can be obtained in a simulation platform in this embodiment. For example, the Monte Carlo method is used to generate time-series data of the target smart grid operating continuously for 60 days with a sampling interval of 10 minutes, containing a total of 8640 normal samples. Then, to simulate an attack scenario, 1800 fake data injection attack events are constructed simultaneously, mainly divided into three categories: partial tampering of 1-3 voltage measurement data, partial tampering of 1-3 power measurement data, and coordinated tampering of multiple electrically related measurement data. After standardization, all data is converted into spatiotemporal sequence samples through a sliding window of length 10, and divided into a training set (6480 samples), a validation set (1440 samples), and a test set (720 samples) according to time order. The sample labels (i.e., target features) correspond to... , 0 (normal), 1 (voltage attack), 2 (power attack), 3 (coordinated attack).

[0028] After obtaining the training set, an attack feature extraction model is built. (Refer to...) Figure 2 As shown, the attack feature extraction model in this embodiment consists of a spatial feature extraction module, a temporal feature extraction module, and a feature fusion module, deeply mining the spatiotemporal correlation characteristics and key feature focusing capabilities of smart grid measurement data. Specifically, the spatial feature extraction module is built based on an improved convolutional neural network (ICNN), the temporal feature extraction module is built based on a bidirectional long short-term memory network (BiLSTM), and the feature fusion module is built based on a global attention mechanism (GAM). This embodiment, through the constructed attack feature extraction model, not only improves detection accuracy and robustness but also enhances the model's interpretability for key attack patterns, making it suitable for proactive security protection of smart grids.

[0029] The spatial feature extraction module extracts the model input data (i.e., the three-dimensional spatiotemporal tensor) through convolution operations. The local spatial association characteristics of power grid nodes and branches in the network are calculated using the following formula:

[0030]

[0031]

[0032] in, For dynamic mixed weighting coefficients, It is the Sigmoid activation function. For weight generation network, For feature extraction function, Based on the convolution weights, For dynamic convolution weights, The spatial feature vector (i.e., local spatial correlation features) output by the spatial feature extraction module. It is a non-linear activation function. For mixed weights, For bias vectors, This is an element-wise product.

[0033] The spatial feature vector output by the spatial feature extraction module is obtained by using the temporal feature extraction module. To further capture the forward and backward temporal evolution patterns of the measurement data, the time feature extraction formula is as follows:

[0034]

[0035]

[0036]

[0037]

[0038]

[0039]

[0040] in, Output for the forget gate. It is the Sigmoid activation function. The forget gate outputs a weight matrix for the features. The weight matrix is ​​the weight matrix for the hidden state in front of the forget gate. This is the previous hidden state. Let be the bias vector of the forget gate. For input gate output, The input gate is the weight matrix of the input features. Given the weight matrix of the hidden state before the input gate, Let be the bias vector of the input gate. Candidate cell state, The hyperbolic tangent activation function is used. Input the weight matrix of features for the candidate cell state. Let be the weight matrix of the previous hidden state of the candidate cell. This is a bias for the candidate cell state. This represents the updated cell state. This refers to the previous cell state. For output gate output, The weight matrix of the input features of the output gate. To output the weight matrix of the hidden state before the gate, This is the bias vector for the output gate. The hidden state at the current time step. For element-wise multiplication, This is the time feature vector output by the time series feature extraction module. This represents the hidden state of the forward LSTM at time step [time step]. This represents the hidden state of the inverse LSTM at time step.

[0041] The extracted time feature vector is processed using the feature fusion module. Global filtering and focusing are performed to enhance the model's ability to perceive attack-sensitive key features. The feature fusion module includes a channel attention submodule and a spatial attention submodule, calculated using the following formula:

[0042]

[0043] in, The output features of the channel attention submodule, For channel attention weight generation function, For element-wise multiplication, The output features of the spatial attention submodule are the target features output by the feature fusion module. This is the spatial attention weight generation function.

[0044] The feature fusion module will process the temporal feature vector output by the temporal feature extraction module. By integrating these features and performing operations such as feature splicing and dimensional adjustment, target features that can comprehensively characterize attack patterns in smart grid measurement data are generated, providing accurate and efficient feature support for subsequent attack detection and attack type identification.

[0045] After the attack feature extraction model is built, the attack feature extraction model is trained using the training set obtained above.

[0046] In one possible implementation, after training the attack feature extraction model based on the training set, the method may further include: Using the adaptive weight loss function, calculate the total loss function value of the attack feature extraction model after the current training round is completed; Calculate the difference between the total loss function value of the current training round and the total loss function value of the previous training round, and use the absolute value of the difference as the target absolute value; When the absolute value of the target is less than a preset threshold, the attack feature extraction model is considered to have completed training.

[0047] Optionally, embodiments of this application further introduce adaptive weight balancing measurement, dynamically adjusting the weights of data reconstruction loss, runaway regularization loss, and attention contribution loss in the total loss function weights, thereby improving the stability and convergence efficiency of the attack feature extraction model training.

[0048] Specifically, the adaptive weight loss function is used to calculate the total loss function value of the attack feature extraction model after the current training round. The adaptive weight loss function effectively coordinates the multi-objective optimization process by dynamically balancing the data fitting loss, runaway constraint loss, and attention contribution loss, avoiding model performance deviations caused by a single loss dominating the training direction, and providing comprehensive and accurate quantitative indicators for evaluating model training effectiveness.

[0049] The adaptive weight loss function is:

[0050]

[0051]

[0052]

[0053] in, This is the total loss function value. For out-of-control regularization loss, For contribution loss, , For loss weighting coefficients, , The regularization coefficient is... The gradient of the spatial feature vector is output to the spatial feature extraction module. The temporal feature extraction module outputs the gradient of the temporal feature vector. For feature dimension, For the feature fusion module A nonlinear mapping function with 1 feature dimension For feature dimension index, It is the L1 norm, used for sparsity constraints to avoid interference from redundant features; It is an L2 norm.

[0054] Obtain the total loss function value of the model after the previous training epoch. Calculate the difference between the total loss function value of the current training epoch and the total loss function value of the previous training epoch. Then, use the absolute value of this difference as the target absolute value. This target absolute value directly reflects the magnitude of the change in model loss between adjacent training epochs and is the core criterion for determining whether the model has converged.

[0055] in, for The total loss function value at time t and The absolute value of the target corresponding to the difference in the total loss function values ​​at time points. for The total loss function value at time t. for The total loss function value at time 1.

[0056] Set preset threshold Generally take .

[0057] The target absolute value is compared with a preset threshold. If the target absolute value is less than the preset threshold, then... This indicates that the loss of the current model has stabilized, the model parameters have converged to the optimal state, and the training of the attack feature extraction model is considered complete. If the absolute value of the target is greater than or equal to a preset threshold, i.e. If the result is negative, it indicates that the model has not yet fully converged and needs to continue to the next round of training, repeating the above steps of calculating the loss function value, calculating the target absolute value, and determining convergence, until the target absolute value meets the condition of being less than the preset threshold.

[0058] In step 103, based on the target characteristics, the attack prediction probability is calculated, and based on the attack prediction probability, it is determined whether the target smart grid is subjected to a false data injection attack.

[0059] In this embodiment of the application, based on the target features output in step 102, the attack prediction probability is calculated using an attack detection classifier, specifically as follows: The target features are input into the first formula to calculate the attack prediction probability. The first formula is:

[0060] in, The probability of an attack is predicted, and its value ranges from 0 to 1. It is the Sigmoid activation function. This represents the weight vector of the attack detection classifier. For target features, This is the bias vector for the attack detection classifier.

[0061] Then, the calculated attack prediction probability is used to determine whether the target smart grid is subject to a fake data injection attack.

[0062] In one possible implementation, determining whether a target smart grid is subject to a false data injection attack based on attack prediction probability may include: Determine whether the predicted attack probability is greater than a probability threshold; If the predicted probability of the attack is greater than the probability threshold, the target smart grid is determined to be under attack by false data injection. If the attack prediction probability is less than or equal to the probability threshold, the target smart grid is determined not to have been subjected to a false data injection attack.

[0063] Optionally, a probability threshold can be set. The setting of this probability threshold needs to be determined comprehensively based on the security level requirements of the smart grid, the characteristics of the operating scenario, and the tolerance for false alarms / missed alarms. Typically, the value range can be set to [0.5, 0.8]. In practical engineering applications, the threshold can be optimized using validation set data: if the smart grid has extremely high security requirements (such as in core power supply areas), the probability threshold can be appropriately lowered (e.g., 0.5) to reduce the risk of missed alarms; if it is necessary to control the false alarm rate to reduce unnecessary emergency responses (such as in ordinary distribution network areas), the probability threshold can be moderately increased (e.g., 0.7) to achieve a balance between security protection and operational efficiency.

[0064] Determining the probability threshold After determining the value of , the attack probability is predicted. With probability threshold Real-time comparison is performed, specifically as follows: If the attack prediction probability is greater than the probability threshold, that is... If the attack characteristics of the target smart grid's current operating state have reached a significant level, and the false data injection attack mode contained in the target characteristics exceeds the preset judgment standard, then the target smart grid is judged to be under false data injection attack.

[0065] If the attack prediction probability is less than or equal to the probability threshold, i.e. If the target smart grid's current operating status characteristics are more in line with normal operating rules, and no attack mode that meets the preset judgment criteria appears in the target characteristics, it is determined that the target smart grid has not been attacked by false data injection. The current real-time monitoring status is maintained, and feature extraction and probability calculation are continued for subsequent power grid measurement data.

[0066] In this embodiment, the attack determination result is fed back to the smart grid energy management system in real time. If it is determined that an attack has occurred, the system will automatically record key information such as the current timestamp, the target smart grid operating parameters, and the attack prediction probability, providing data support for subsequent attack type identification, emergency response scheduling, and attack tracing. If it is determined that no attack has occurred, the system will continue to execute the cyclic process of data collection, feature extraction, and probability determination to ensure full monitoring of the target smart grid's operating status.

[0067] In step 104, when the target smart grid is subjected to a false data injection attack, the probability distribution vector is calculated using the target characteristics, and the attack type of the false data injection attack on the target smart grid is determined based on the probability distribution vector.

[0068] In this embodiment of the application, when it is determined that the target smart grid has been subjected to a false data injection attack, an attack type identification process is initiated, and its probability distribution vector is calculated using the target features, i.e.: The target features are input into the second formula to calculate the probability distribution vector. The second formula is:

[0069] in, Let be the probability distribution vector. This is the weight matrix for the attack types corresponding to the target features. This is the bias vector for the attack type corresponding to the target feature. For activation function, For target features.

[0070] Then, the calculated probability distribution vector is matched with the probability distribution vector in the probability distribution vector database, and the attack type corresponding to the successfully matched probability distribution vector is taken as the current attack type of the target smart grid.

[0071] For example, the system simulation model adopts Figure 3 The IEEE 6-node test system shown is a small power grid system with a clear structure and distinct layers. It consists of 6 nodes (buses), 2 generators, 2 loads and 6 branches.

[0072] Then based on Figure 3 The system simulation model uses the Monte Carlo method to generate time-series data of the power grid operating continuously for 60 days with a sampling interval of 10 minutes, containing a total of 8640 normal samples. To simulate attack scenarios, 1800 spoofed data injection attack events were simultaneously constructed, mainly divided into three categories: local tampering of 1-3 voltage measurement data, local tampering of 1-3 power measurement data, and coordinated tampering of multiple electrically related measurement data. After standardization, all data were transformed into spatiotemporal sequence samples through a sliding window of length 10, and divided into a training set (6480 samples), a validation set (1440 samples), and a test set (720 samples) in chronological order. The sample labels (i.e., target features) correspond to: 0 (normal), 1 (voltage attack), 2 (power attack), and 3 (coordinated attack).

[0073] The process of analyzing training and testing results is as follows: 1) Training process: The Adam optimizer was used with an initial learning rate of 0.001, adjusted using cosine annealing. The batch size was 64. The model was trained on 80% of the normal data and tested on the remaining 20%. Training was stopped early when the loss no longer decreased after 100 consecutive training epochs.

[0074] 2) Test Results and Comparison: Method I: Graph convolutional networks are a typical application in power grid data modeling. Graph convolutional networks can effectively capture the topological relationships between nodes, but they mainly focus on spatial feature modeling and have limited ability to capture complex temporal dynamics.

[0075] Method II: It integrates a regular convolutional neural network and a bidirectional long short-term memory network. It is one of the strong benchmark models for prediction and classification of temporal and spatial data. It can extract spatial and bidirectional temporal features at the same time, but it lacks a global screening and focusing mechanism for key features.

[0076] Method III: The method for detecting fake data injection attacks in smart grids provided in the embodiments of this application is adopted.

[0077] The quantitative comparison results on the same test set are shown in Table 1, namely: Table 1. Quantitative comparison results on the same test set

[0078] 3) Results Analysis: As shown in Table 1, the embodiments of this application demonstrate significant advantages in three dimensions: detection capability, false alarm control, and recognition accuracy, comprehensively verifying the effectiveness and advancement of the embodiments of this application. Specifically, the embodiments of this application achieve a detection rate of 97.2%, which is 14.9% higher than Method I and 6.4% higher than Method II, indicating that the embodiments of this application can more sensitively capture collaborative attack patterns with strong concealment and spatiotemporal correlation. At the same time, the embodiments of this application control the false alarm rate to 1.2%, which is better than the other two methods, reflecting the strong suppression ability of spatiotemporal regularization and adaptive weight strategies against model overfitting and noise interference. In addition, the attack type recognition accuracy of 88.7% is significantly higher than the other two methods, and the feature fusion module in the embodiments of this application can quantify the feature contribution, indicating that the attack feature extraction model in the embodiments of this application can not only detect attacks, but also accurately classify them by focusing on key features through a global attention mechanism, providing a reliable basis for subsequent emergency response and source tracing analysis. In summary, the embodiments of this application ensure high detection sensitivity while also taking into account low false alarms and high interpretability, making them suitable for the security protection needs of small and medium-sized smart grids and possessing significant engineering application value.

[0079] This application provides a method for detecting spoofed data injection attacks on smart grids. Based on heterogeneous measurement data, this method constructs a three-dimensional spatiotemporal tensor, integrating the data across time, space, and feature dimensions. This better captures the dynamic changes in the grid's operating status in time and space, as well as the correlations between different features, providing a more effective data organization for subsequent attack feature extraction and detection, thus improving the accuracy and reliability of detection. Furthermore, by calculating the attack prediction probability based on the extracted target features, the probability value quantifies the likelihood of the target smart grid being subjected to a spoofed data injection attack, providing more intuitive and accurate detection results and avoiding the misjudgments and omissions that may arise from simple binary judgments. Simultaneously, by determining the specific type of spoofed data injection attack based on the calculated probability distribution vector, this method helps maintenance personnel gain a deeper understanding of the attack's characteristics and methods, enabling them to take more targeted countermeasures.

[0080] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0081] The following are device embodiments of this application. For details not described in detail, please refer to the corresponding method embodiments described above.

[0082] Figure 4 A schematic diagram of the smart grid fake data injection attack detection device provided in an embodiment of this application is shown. For ease of explanation, only the parts related to the embodiment of this application are shown, and are described in detail below: like Figure 4 As shown, the smart grid fake data injection attack detection device 4 includes: The acquisition and construction module 41 is used to acquire heterogeneous measurement data of the target smart grid and construct a three-dimensional spatiotemporal tensor based on the heterogeneous measurement data. The heterogeneous measurement data includes node measurement data, branch measurement data and network topology data. The feature output module 42 is used to input the three-dimensional spatiotemporal tensor into the constructed attack feature extraction model and output the target features corresponding to the three-dimensional spatiotemporal tensor. The attack judgment module 43 is used to calculate the attack prediction probability based on the target characteristics, and to determine whether the target smart grid is subjected to a false data injection attack based on the attack prediction probability. The type determination module 44 is used to calculate the probability distribution vector by utilizing the target characteristics when the target smart grid is subjected to a false data injection attack, and to determine the attack type of the false data injection attack on the target smart grid based on the probability distribution vector.

[0083] This application provides a smart grid spoofing data injection attack detection device. Based on heterogeneous measurement data, this application constructs a three-dimensional spatiotemporal tensor, integrating the data across time, space, and feature dimensions. This allows for better capture of the dynamic changes in the power grid's operating status in time and space, as well as the correlations between different features. This provides a more effective data organization for subsequent attack feature extraction and detection, helping to improve the accuracy and reliability of detection. Furthermore, based on the extracted target features, the application calculates the attack prediction probability, quantifying the likelihood of the target smart grid being subjected to spoofing data injection attacks through probability values. This provides more intuitive and accurate detection results, avoiding the misjudgments and missed detections that may arise from simple binary judgments. Simultaneously, the application determines the specific type of spoofing data injection attack based on the calculated probability distribution vector, helping maintenance personnel to gain a deeper understanding of the attack's characteristics and methods, thereby enabling them to take more targeted countermeasures.

[0084] In one possible implementation, the attack detection module can be used to: The target features are input into the first formula to calculate the attack prediction probability. The first formula is:

[0085] in, To predict the probability of an attack, It is the Sigmoid activation function. This represents the weight vector of the attack detection classifier. For target features, This is the bias vector for the attack detection classifier.

[0086] In one possible implementation, the attack detection module can also be used for: Determine whether the predicted attack probability is greater than a probability threshold; If the predicted probability of the attack is greater than the probability threshold, the target smart grid is determined to be under attack by false data injection. If the attack prediction probability is less than or equal to the probability threshold, the target smart grid is determined not to have been subjected to a false data injection attack.

[0087] In one possible implementation, the type determination module can be used for: The target features are input into the second formula to calculate the probability distribution vector. The second formula is:

[0088] in, Let be the probability distribution vector. This is the weight matrix for the attack types corresponding to the target features. This is the bias vector for the attack type corresponding to the target feature. For activation function, For target features.

[0089] In one possible implementation, the device may further include a model building module, which can be used for: Acquire historical heterogeneous measurement data of the target smart grid, as well as the historical target features corresponding to the historical heterogeneous measurement data, and construct a training set; An attack feature extraction model is constructed, which includes a spatial feature extraction module, a temporal feature extraction module, and a feature fusion module connected in sequence. The attack feature extraction model is trained based on the training set.

[0090] In one possible implementation, the device may further include a model training judgment module, which can be used to: Using the adaptive weight loss function, calculate the total loss function value of the attack feature extraction model after the current training round is completed; Calculate the difference between the total loss function value of the current training round and the total loss function value of the previous training round, and use the absolute value of the difference as the target absolute value; When the absolute value of the target is less than a preset threshold, the attack feature extraction model is considered to have completed training.

[0091] In one possible implementation, the adaptive weight loss function is:

[0092]

[0093]

[0094]

[0095] in, This is the total loss function value. For out-of-control regularization loss, For contribution loss, , For loss weighting coefficients, , The regularization coefficient is... The gradient of the spatial feature vector is output to the spatial feature extraction module. The temporal feature extraction module outputs the gradient of the temporal feature vector. For feature dimension, For the feature fusion module A nonlinear mapping function with 1 feature dimension For feature dimension index, It is an L1 norm. It is an L2 norm.

[0096] In one possible implementation, the data acquisition and construction module can be used for: By aligning and integrating heterogeneous measurement data along the time dimension, a three-dimensional spatiotemporal tensor is obtained.

[0097] Figure 5 This is a schematic diagram of the terminal provided in an embodiment of this application. For example... Figure 5 As shown, the terminal 5 in this embodiment includes: a processor 50, a memory 51, and a computer program 52 stored in the memory 51 and executable on the processor 50. When the processor 50 executes the computer program 52, it implements the steps in the various smart grid spoofing data injection attack detection method embodiments described above, for example... Figure 1 Steps 101 to 104 are shown. Alternatively, when the processor 50 executes the computer program 52, it implements the functions of each module / unit in the above-described device embodiments, for example... Figure 4 The functions of each module are shown.

[0098] For example, the computer program 52 can be divided into one or more modules / units, which are stored in the memory 51 and executed by the processor 50 to complete this application. The one or more modules / units can be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program 52 in the terminal 5. For example, the computer program 52 can be divided into... Figure 4 The modules shown.

[0099] The terminal 5 can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The terminal 5 may include, but is not limited to, a processor 50 and a memory 51. Those skilled in the art will understand that... Figure 5 This is merely an example of terminal 5 and does not constitute a limitation on terminal 5. It may include more or fewer components than shown, or combine certain components, or different components. For example, the terminal may also include input / output devices, network access devices, buses, etc.

[0100] The processor 50 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0101] The memory 51 can be an internal storage unit of the terminal 5, such as a hard disk or memory of the terminal 5. The memory 51 can also be an external storage device of the terminal 5, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the terminal 5. Furthermore, the memory 51 can include both internal storage units and external storage devices of the terminal 5. The memory 51 is used to store the computer program and other programs and data required by the terminal. The memory 51 can also be used to temporarily store data that has been output or will be output.

[0102] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0103] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0104] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0105] In the embodiments provided in this application, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0106] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0107] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0108] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various smart grid fake data injection attack detection method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0109] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for detecting false data injection attacks in a smart grid, the method comprising: include: Collect heterogeneous measurement data of the target smart grid and construct a three-dimensional spatiotemporal tensor based on the heterogeneous measurement data, which includes node measurement data, branch measurement data and network topology data; The three-dimensional spatiotemporal tensor is input into the constructed attack feature extraction model, and the target features corresponding to the three-dimensional spatiotemporal tensor are output. Based on the target characteristics, the attack prediction probability is calculated, and based on the attack prediction probability, it is determined whether the target smart grid is subjected to a false data injection attack. When the target smart grid is subjected to a false data injection attack, the target characteristics are used to calculate a probability distribution vector, and the attack type of the false data injection attack on the target smart grid is determined based on the probability distribution vector.

2. The method for detecting fake data injection attacks in smart grids according to claim 1, characterized in that, The step of calculating the attack prediction probability based on the target features includes: The target features are input into the first formula to calculate the attack prediction probability. The first formula is: in, Predict the probability of the attack. It is the Sigmoid activation function. This represents the weight vector of the attack detection classifier. For the target feature, This is the bias vector for the attack detection classifier.

3. The method for detecting fake data injection attacks in smart grids according to claim 1, characterized in that, The step of determining whether the target smart grid is subject to a false data injection attack based on the attack prediction probability includes: Determine whether the predicted attack probability is greater than a probability threshold; If the predicted attack probability is greater than the probability threshold, then the target smart grid is determined to be under attack by false data injection. If the attack prediction probability is less than or equal to the probability threshold, then the target smart grid is determined not to have been subjected to a false data injection attack.

4. The method for detecting fake data injection attacks in smart grids according to claim 1, characterized in that, When the target smart grid is subjected to a false data injection attack, the step of calculating a probability distribution vector using the target characteristics includes: The target features are input into the second formula to calculate the probability distribution vector. The second formula is: in, Let be the probability distribution vector. This is the weight matrix for the attack types corresponding to the target features. This is the bias vector for the attack type corresponding to the target feature. For activation function, The target feature is described above.

5. The method for detecting fake data injection attacks in smart grids according to claim 1, characterized in that, The construction process of the attack feature extraction model is as follows: Acquire historical heterogeneous measurement data of the target smart grid, and acquire historical target features corresponding to the historical heterogeneous measurement data, and construct a training set; The attack feature extraction model is constructed, which includes a spatial feature extraction module, a temporal feature extraction module, and a feature fusion module connected in sequence. The attack feature extraction model is trained based on the training set.

6. The method for detecting fake data injection attacks in smart grids according to claim 5, characterized in that, After training the attack feature extraction model based on the training set, the method further includes: Using the adaptive weight loss function, calculate the total loss function value of the attack feature extraction model after the current training round is completed; Calculate the difference between the total loss function value of the current training round and the total loss function value of the previous training round, and use the absolute value of the difference as the target absolute value; When the absolute value of the target is less than a preset threshold, the attack feature extraction model is deemed to have completed training.

7. The method for detecting fake data injection attacks in smart grids according to claim 6, characterized in that, The adaptive weight loss function is: in, The total loss function value is... For out-of-control regularization loss, For contribution loss, , For loss weighting coefficients, , The regularization coefficient is... The spatial feature extraction module outputs the gradient of the spatial feature vector. The temporal feature extraction module outputs the gradient of the temporal feature vector. For feature dimension, The first feature fusion module A nonlinear mapping function with 1 feature dimension For feature dimension index, It is an L1 norm. It is an L2 norm.

8. The method for detecting fake data injection attacks in smart grids according to claim 1, characterized in that, The construction of a three-dimensional spatiotemporal tensor based on the heterogeneous measurement data includes: The heterogeneous measurement data are aligned and integrated along the time dimension to obtain the three-dimensional spatiotemporal tensor.

9. A terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the smart grid fake data injection attack detection method as described in any one of claims 1 to 8.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the smart grid fake data injection attack detection method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • CNN-GRU-based power grid false data injection detection method and device

    CN114760098A

  • Space-time detection method for power grid false data injection attack

    CN116578903A

  • Power grid false data injection attack detection method and device

    CN120455165A

  • Power grid intrusion detection system based on artificial intelligence

    CN120768587A

  • Systems and Methods for Malicious Attack Detection in Phasor Measurement Unit Data

    US20230050490A1