Power market attack detection and compensation based on three-step recursive filter

By establishing a state-space model in the electricity market through a three-step recursive filter, the system can identify and estimate false data injection attacks and compensate for their impact in real time. This solves the problem of insufficient detection and compensation for false data injection attacks in existing technologies, thereby improving the security and stability of the electricity market.

CN121907501APending Publication Date: 2026-04-21ANSHAN POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER COMPANY +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ANSHAN POWER SUPPLY COMPANY OF STATE GRID LIAONING ELECTRIC POWER COMPANY
Filing Date
2025-12-15
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve real-time estimation and reconstruction of false data injection attacks in power market cybersecurity. Furthermore, centralized system architectures in distributed power markets suffer from communication burdens and single-point-of-failure risks, lacking effective defense and compensation mechanisms.

Method used

A detection and compensation method based on a three-step recursive filter is adopted. By establishing a discretized state-space model of a multi-regional power market coupling system, time updates and measurement updates are performed to estimate the false data injection attack signal. The opposite compensation signal is introduced into the system output link to counteract the attack effect.

Benefits of technology

It enables rapid identification, accurate estimation, and real-time compensation for fake data injection attacks, forming a closed-loop defense system, improving system security, reducing deployment costs, and is suitable for distributed power market systems. It is efficient, reliable, and economical.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907501A_ABST
    Figure CN121907501A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power system network security, in particular to power market attack detection and compensation based on a three-step recursive filter, which comprises the following steps: establishing a discretized state space model fused with a power market dynamic mechanism, and modeling an attack as unknown input; sequentially executing time updating, measurement updating and attack signal estimation through a three-step recursive filtering structure, and synchronously realizing minimum variance unbiased estimation of a system state and a false data injection attack; and performing real-time dynamic feed-forward compensation on an attacked system output link by adopting a redundancy analysis method based on the accurately estimated attack signal. The method has the advantages that attack detection, estimation and compensation are integrated, a sensing-diagnosis-suppression closed-loop active defense system is formed, the estimation result of the optimal statistical property can be provided in the noise environment, and the network security and operation reliability of the multi-region power market coupling system are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system network security technology, and in particular to power market attack detection and compensation based on a three-step recursive filter. Background Technology

[0002] With the widespread integration of renewable energy and distributed resources, the structure of power systems is evolving from centralized to distributed, multi-regional interconnected forms. Distributed multi-regional power systems supply power through decentralized, independent small-scale generation units, significantly improving system operating efficiency and power supply reliability. In this context, the stable operation of the electricity market, as the core link coordinating power generation and consumption demand, is crucial. However, the operation of the electricity market is highly dependent on information and communication technologies, making it significantly vulnerable to cyberattacks. Among these, spoofed data injection attacks are a highly covert and destructive attack method. Attackers tamper with sensor measurement data (such as frequency deviation and tie-line power), misleading the system's state estimation results, thereby disrupting market trading order, causing abnormal electricity price fluctuations, and even leading to erroneous control commands, equipment damage, and large-scale power outages, posing a serious threat to the safe and stable operation of the power system. Therefore, there is an urgent need to develop effective defense and compensation technologies for distributed multi-regional power market coupling systems.

[0003] Currently, research on cybersecurity in the electricity market has made some progress. Existing methods mainly focus on the following aspects: 1. Protection of critical sensors: By protecting some key measurement units, an attempt is made to prevent attacks from being constructed and to ensure they go undetected, but this method is costly and difficult to fully cover large networks. 2. Attack detection: By using various filtering algorithms (such as Kalman filtering, H∞ filtering, etc.) or data-driven methods, anomalies in measurement data can be identified to determine whether the system has been attacked. 3. Impact assessment of the attack: Models were constructed to analyze the potential impact of FDI attacks on market clearing, electricity price formation, and other processes.

[0004] However, existing technical solutions have obvious limitations: 1. Incomplete functionality: Most studies focus on the "detection" level, that is, determining whether an attack has occurred, but lack the ability to "estimate and reconstruct" the attack signal itself in real time. Without knowing the specific form and value of the attack, it is impossible to carry out effective active suppression and compensation.

[0005] 2. Insufficient theoretical support: Many methods have failed to theoretically prove whether the state estimates and attack estimates they obtain simultaneously satisfy the two core characteristics of optimal estimators: "minimum variance" and "unbiasedness." The optimality and reliability of their estimation results are questionable.

[0006] 3. Poor architectural adaptability: Most existing algorithms are based on a centralized system architecture design, which requires the convergence of measurement data from all regions to a central processor. In practice, this not only brings a huge communication burden but also poses a single point of failure risk, making it difficult to directly apply to the widely existing multi-regional power market coupling system with distributed and hierarchical control characteristics. Summary of the Invention

[0007] The purpose of this invention is to provide a collaborative defense scheme for power market attack detection and compensation based on a three-step recursive filter. This scheme integrates detection, estimation, and compensation, overcoming the limitation of traditional methods that can only detect but not estimate attack signals. Furthermore, it utilizes redundancy theory to transform the attack estimate into a compensation signal, thereby proactively offsetting the attack's impact and ensuring the safe and stable operation of the system.

[0008] To achieve the above objectives, the present invention provides the following technical solution: Electricity market attack detection and compensation based on a three-step recursive filter includes: S1: Establish a discretized state-space model of a multi-regional electricity market coupling system. The model integrates the dynamic mechanism of the electricity market and models false data injection attacks as unknown inputs acting on the system, and performs discretization processing. S2: Execute time update, based on the prediction error of the state estimate at time k-1, calculate the system state prediction at time k and its corresponding prediction error covariance matrix; S3: Perform measurement update, use the current measurement value at time k to correct the state prediction value, obtain the minimum variance unbiased estimate of the system state at time k, and calculate its estimation error covariance matrix; S4: Based on the estimated and predicted values ​​of the system state, estimate the spoofed data injection FDI attack signal, and calculate the covariance matrix of the estimation error of the FDI attack signal and its cross-covariance matrix with the state estimation error. S5: A real-time compensation mechanism is designed using the redundancy analysis method. The FDI attack signal estimated in S4 is used to dynamically compensate the output link of the attacked system.

[0009] In S1, a discretized state-space model is established, including: 1) Construct a dynamic electricity market mechanism based on the dynamic relationship between power generators and consumers, expressed as: (1); In formula (1): , , , and These represent the power supply deviation of generators in the i-th region (in MW), the power demand deviation of consumers (in MW), the marginal cost of generators (in $ / MWh), the marginal benefit of consumers (in $ / MWh), and the electricity price deviation (in $ / MWh), respectively. This represents a constant term in the power generator cost parameters (in US dollars per megawatt-hour). This represents the slope coefficient in the power generator cost parameters (in US dollars per megawatt-hour). This represents the constant term in the consumer benefit parameter (in US dollars per megawatt-hour). This represents the slope coefficient in the consumer benefit parameter (in US dollars per megawatt-hour). and These represent the response constants for the power generator and the consumer, respectively, in seconds; Indicates the rate of change in electricity prices (in seconds); Indicates the average frequency deviation; This represents the electricity market regulation coefficient (in US dollars per megawatt-hour second). This indicates the average frequency deviation (in Hertz). ,in, This represents the generator's inertia constant (in seconds). Angular frequency (unit: radians per second); Indicates the power supply deviation of the generator (in megawatts); 2) Calculate the state variables of the multi-regional electricity market coupled system. Control input System output and FDI attack vectors with fake data injection State variables This includes frequency deviation, tie line switching power deviation, generator mechanical power deviation, valve position deviation, and area control deviation; make ; ; Establish the state-space equations for a continuous-time, multi-region coupled system: (2); in: ; ; ; ; ; ; , , , , These represent the frequency deviation (in Hertz), tie line switching power deviation (in Megawatts), generator mechanical output power deviation (in Megawatts), valve position deviation (in per unit), and area control deviation (in Megawatts), respectively, for the i-th region. , , , , , These represent the generator's moment of inertia (in per unit second), the generator's damping coefficient (in per unit per hertz), the turbine's time constant (in seconds), the governor's time constant (in seconds), the speed reduction coefficient (in hertz per per unit), and the frequency deviation coefficient, respectively. This represents the synchronization coefficient of the tie line between region i and region j, expressed in per-unit value per Hertz. This represents process noise, assumed to be Gaussian white noise; This represents the measurement noise, assumed to be Gaussian white noise; 3) Discretize the state-space equations of the continuous-time multi-region coupled system to obtain the discrete-time system equations for recursive filtering: (3); in: , , , These represent the system state vectors at time k. Control input vector (megawatt), FDI attack vector ( ) and measurement output vector ( ); Represents the discretized state matrix; Indicates sampling time (in seconds); Unit of A: ; Represents the discretized input matrix; unit: ; Represents the discretized coupling matrix; unit: ; This represents the impact matrix of a discretization attack; the unit is: ; Represents the discretized constant term matrix; unit: ; Represents the discretized output matrix; Represents the discretized direct transfer matrix; This indicates that discretization attacks directly affect the matrix; Represents discrete process noise, in units of: ; covariance matrix ; The unit is: ; Discrete measurement noise, ; covariance matrix ;unit .

[0010] In S2, the time update includes calculating the prediction error of the state estimate at time k-1. and the error covariance matrix of the state prediction value at time k The expression is: ; (4); in, , , , , for: This represents the prediction error of the state estimate; unit ; This indicates the state estimation error; unit ; Indicates the FDI attack estimation error; unit: ; This represents the state estimation error covariance matrix; the unit is: ; This represents the covariance matrix of the FDI attack estimation error; the unit is: ; The cross-covariance matrix represents the error between the state and the attack estimation; units are: ; This represents the process noise covariance matrix. The unit is: ; In S2, the state prediction is a priori estimate of the system state before incorporating measurement information at time k.

[0011] In S3, the measurement update includes calculating the state estimation error at time k. and its covariance and use the minimum variance unbiased state estimator gain The expression is: (6); In formula (6): Represents the identity matrix; This represents the state estimator gain matrix; units are: ; Indicates the output matrix; Represents the attack impact matrix; Indicates the FDI attack vector; ; Indicates measurement noise; ; State estimation error covariance matrix (7); Unit: ; In formula (7): The gain of the minimum variance unbiased state estimator is: (8); Unit: ; In formula (8), The unit is: In S3, the current measurement value is the output data actually collected by the system sensor at time k.

[0012] In S4, FDI attack estimation is performed using the following expression: ; ; (9); FDI attack estimation error and its covariance matrix and state estimation error The cross-covariance matrix satisfies: ; ; (10); This represents the scaled innovation covariance matrix; units are: ; This represents the attack estimator gain matrix; the unit is: ; Represents the residual vector; unit: ; In S5, a real-time compensation mechanism introduces a compensation signal that is equal in magnitude but opposite in sign to the estimated false data injection attack signal in the system's frequency deviation output link and / or tie-line switching power deviation output link, in order to offset the impact of the attack on the system output.

[0013] Compared with the prior art, the beneficial effects of the present invention are: 1. Traditional methods are mostly limited to the "detection" and "alarm" of attacks, while this invention, through a three-step recursive filtering structure, simultaneously realizes the "detection, estimation and compensation" of attacks within the same framework. It can not only quickly identify the occurrence of attacks, but also accurately reconstruct the specific form and value of the attack signal. Based on this, it performs real-time, feedforward dynamic compensation, forming a complete "perception-diagnosis-suppression" closed-loop active defense system, fundamentally improving the security of the system. 2. The three-step recursive filtering algorithm designed in this invention strictly follows the optimal estimation theory and can simultaneously obtain the "minimum variance unbiased estimate" of the system state and the false data injection attack signal. This means that in the presence of noise and interference, the estimation result of this invention is not only unbiased (the expected value of the estimated value is equal to the true value), but also the variance of its estimation error reaches the theoretical lower limit, which has the best statistical characteristics and provides highly reliable information input for subsequent compensation control. 3. It adopts a recursive filtering method, which has a clear and efficient calculation process. It does not require the storage of historical data and can meet the stringent real-time requirements of the power system. At the same time, its algorithm is inherently distributed. Each region can use the information of its local area and adjacent limited areas to perform independent calculations, avoiding the communication bottlenecks and single-point failure risks caused by centralized processing. It is particularly suitable for multi-regional, distributed coupled power market systems that are widely present in actual engineering. 4. The defense mechanism of this invention is entirely based on software algorithms. It does not require modification or addition to existing hardware systems (such as sensors and actuators). It uses "analytical redundancy", that is, software redundancy generated by the system's mathematical model to replace expensive hardware redundancy. It can effectively suppress the impact of attacks by injecting a compensation signal that is opposite to the attack signal, which greatly reduces deployment costs, improves the economy and feasibility of the solution, and facilitates its promotion and implementation in existing systems. 5. Through simulation experiments, it is verified that the present invention can quickly and accurately track and estimate various typical fake data injection attacks, such as ramp attacks, step attacks, square wave attacks, and their combinations, and can immediately trigger the compensation mechanism. This shows that the present invention is robust and can effectively cope with complex and time-varying network attack scenarios that may occur in reality. Attached Figure Description

[0014] Figure 1 This is a flowchart of an attack detection and compensation method based on a three-step recursive filter algorithm.

[0015] Figure 2 This is a comparison chart of FDI attack estimations using different filters.

[0016] Figure 3 It is a power market coupling system under slope FDI attack.

[0017] Figure 4 It is an electricity market coupling system under the FDI step attack signal.

[0018] Figure 5 Power systems under complex FDI attacks Figure 1 .

[0019] Figure 6 Power systems under complex FDI attacks Figure 2 . Detailed Implementation

[0020] The present invention will now be described in detail with reference to the accompanying drawings, but it should be noted that the implementation of the present invention is not limited to the following embodiments.

[0021] The following embodiments are implemented based on the technical solution of the present invention, providing detailed implementation methods and specific operation processes. However, the scope of protection of the present invention is not limited to the following embodiments. Unless otherwise specified, the methods used in the following embodiments are conventional methods.

[0022] Example 1 Figure 1 The flowchart of the attack detection and compensation method based on the three-step recursive filter algorithm of this invention is as follows: Figure 1 As shown, this invention discloses an attack detection and compensation method based on a three-step recursive filter algorithm, which specifically includes the following steps: Step 1: To study the security and stability of a multi-regional electricity market coupling system under spoofing attacks, a dynamic mechanism for the electricity market is constructed. This involves introducing the electricity market into the multi-regional electricity system, thereby obtaining a state-space model of the multi-regional electricity market coupling system. The specific process is as follows: Considering the relationship between power producers and consumers in the electricity market, construct a dynamic mechanism for the electricity market: ; in: , , and Let represent the power output of the generator, the power demand of the consumer, the marginal cost of the generator, the marginal benefit of the consumer, and the electricity price in the i-th region, respectively. and It is the cost parameter for power generators. and These are parameters related to consumer interests. and These are the response constants for power generators and consumers, respectively. It is the rate of change in electricity prices. This represents the average frequency deviation.

[0023] definition For state variables, yes The neighbor state variables, To control the input, For system output, It's an FDI attack. , , , , These represent the frequency deviation, tie-line switching power deviation, generator mechanical output power deviation, valve position deviation, and area control deviation for the i-th region, respectively. , , , , , These represent the generator's moment of inertia, the generator's damping coefficient, the turbine's time constant, the governor's time constant, the speed reduction coefficient, and the frequency deviation coefficient, respectively. Let represent the synchronization coefficient of the connection line between region i and region j. Let . ; Then, based on the state equations of a multi-regional power system coupled with the electricity market: ; in: , ; , ; , ; Discretize the system: ; in: , , , These represent the system state, control input, FDI attack, and measurement output at time k, respectively. , , , , , , , .

[0024] Step 2: Perform a time update to obtain time k-1. error With covariance matrix : ; ; in: , , , , .

[0025] Step 3: Perform measurement updates. The specific process is as follows: (1) Calculate time k error and its covariance : ; ; (2) Calculate the gain of the minimum variance unbiased state estimator: By induction, for all k, and This indicates and It is unbiased. An optimization method is used with Lagrange multipliers. A combined approach is used to solve for the covariance matrix. The gain matrix with the smallest trace .also, This is a necessary condition for obtaining an unbiased estimate.

[0026] ,right and Differentiate them separately: ; Setting the derivative to 0, we can solve for the gain matrix. .

[0027] Step 4: Estimate FDI attack signals: make ,in ,because , so Its covariance is ,therefore If any matrix S satisfies ,in It is a positive semi-definite matrix, through Scaling ,in and In this form, the Gauss-Markov theorem holds for zero mean with respect to unit variance. The assumption. Therefore, The best linear unbiased estimate is .

[0028] Input estimation error, covariance matrix and having The cross-covariance matrix satisfies: ; To further illustrate the effects of the present invention, a numerical example of the present invention is given below for simulation calculation.

[0029] To verify the effectiveness of the proposed algorithm, a three-region interconnected distributed power system was used as the research object. A system model was built on MATLAB, and simulation experiments were conducted under three different scenarios. The discrete sampling time was set to 0.001s, the simulation time to 50s, and the number of simulation steps to 50,000. The system disturbance was a random sinusoidal signal with an amplitude of -0.15 to 0.15. The relevant parameters of the three-region interconnected power market system are as follows: Area 1: , , , , , , , , , , , , , ; Area 2: , , , , , , , , , , , , , ; Area 3: , , , , , , , , , , , , , ; Select , , , Scenario 1: Consider the case where frequency deviation in a single region is subjected to an FDI attack. Taking control region 1 as an example, at time 0s, the frequency deviation link in region 1... Apply a slope attack with a slope of 0.002, as follows: ; To demonstrate the effectiveness of the proposed three-step recursive filter algorithm, it is compared with a reduced-order H∞ filter. In the simulation, zero-mean Gaussian random noise with a variance on the order of 1e⁻⁸ is selected. The FDI attacks the frequency deviation in region 1. The three-step recursive filter algorithm and the reduced-order H∞ filter algorithm are used to estimate the FDI attack, respectively. (See...) Figure 2 (a) FDI attack estimation using the algorithm presented in this paper, and (b) FDI attack estimation using a reduced-order H∞ filter. Calculations show that the RMSE of the three-step recursive filter algorithm for attack estimation in (a) is 0.00045, and the RMSE of the reduced-order H∞ filter algorithm in (b) is 0.001. Compared to other traditional algorithms, the three-step recursive filter algorithm obtains more accurate estimates. Therefore, the correctness of this model and algorithm is proven.

[0030] See Figure 3 (a) Slope attack, (b) The effect of frequency deviation in region 1; When the system is attacked by FDI at 0s, the proposed detection algorithm can immediately identify the attack signal and accurately estimate the attack value in real time. At the same time, the system responds quickly and compensates for the attack signal in real time through a compensation mechanism, effectively avoiding the impact of the attack.

[0031] Scenario 2: Consider the scenario where the switching power deviation of the inter-regional communication lines is affected by an FDI attack. Taking regions 2 and 3 as an example, at 10 seconds, what is the impact of the switching power deviation of the communication lines between regions 2 and 3? Apply a step signal with an amplitude of 5, as follows: ; Simulation results are shown below Figure 4 (a) Step attack; (b) Impact of the switch power deviation in the tie lines of regions 2 and 3. When the system is subjected to a step-type FDI attack at 10s, the proposed estimation method can quickly and accurately track the attack signal, demonstrating good real-time estimation performance. Simultaneously, the attack detection mechanism is triggered at 10s, and then real-time compensation is performed on the attack signal.

[0032] Experimental results validated the effectiveness of the strategy, which can accurately detect and compensate for FDI attacks in a single area and during the interaction of interconnected area tie lines, ensuring the safe and stable operation of the power system.

[0033] Scenario 3: Considering both the frequency deviation of a single region and the power exchange deviation of the interconnection lines between regions being affected by FDI attacks. The following are examples of spoofed data injection into interconnected power systems: ; At 0s, a square wave FDI attack signal with an amplitude of 8 is injected into the frequency deviation link of region 2; at 10s, a ramp FDI attack signal with an initial amplitude of 5 and a slope of 0.003 is injected into the tie-line switching power deviation links of regions 1 and 3. Simulation results are shown in […]. Figure 5 , Figure 6 (a) Step attack. (b) Frequency deviation impact in region 2. (c) Ramp attack. (d) Impact of tie-line switching power deviation in regions 1 and 3; where (a) shows the simulation results for region 2, including a comparison of FDI attack values ​​and estimated values. (a) shows the actual value, compensated value, and attack value. (b) shows the simulation results for region 2, including the compensated value, the value without attack, and the value under attack; (c) shows the simulation results for regions 1 and 3, including a comparison of the FDI attack value and the estimated value. (a) shows the actual value, compensation value, and attack value; (d) shows the simulation results for regions 1 and 3, including the compensated value, the value without attack, and the value under attack. As can be seen from the figure, when an FDI attack targets two links separately, the system can detect and compensate for the attack simultaneously. This demonstrates that the attack detection strategy designed in this chapter can simultaneously detect whether multiple regions have been subjected to FDI attacks, ensuring the safe and stable operation of the interconnected power system under complex FDI attacks.

[0034] Traditional methods are often limited to attack "detection" and "alarm," while this invention, through a three-step recursive filtering structure, simultaneously achieves attack "detection, estimation, and compensation" within the same framework. This not only quickly identifies the occurrence of attacks but also accurately reconstructs the specific form and value of the attack signal. Based on this, real-time, feedforward dynamic compensation is performed, forming a complete "perception-diagnosis-suppression" closed-loop active defense system, fundamentally improving system security. The three-step recursive filtering algorithm designed in this invention strictly follows optimal estimation theory, simultaneously obtaining the "minimum variance unbiased estimate" of the system state and the spurious data injection attack signal. This means that even in the presence of noise and interference, the estimation result of this invention is not only unbiased (the expected value of the estimate equals the true value), but its estimation error variance reaches the theoretical lower limit, possessing optimal statistical characteristics and providing highly reliable information input for subsequent compensation control. The recursive filtering form results in a clear and efficient calculation process, eliminating the need to store historical data and meeting the stringent real-time requirements of power systems. Its algorithm is inherently distributed, allowing each region to perform independent calculations using information from its local and adjacent limited regions. This avoids communication bottlenecks and single-point-of-failure risks associated with centralized processing, making it particularly suitable for multi-regional, distributed, coupled power market systems widely used in practical engineering. The defense mechanism of this invention is entirely based on software algorithms, requiring no modification or addition to existing hardware systems (such as sensors and actuators). Through "analytical redundancy," that is, using software redundancy generated by the system's mathematical model to replace expensive hardware redundancy, the impact of attacks can be effectively suppressed simply by injecting a compensation signal opposite to the attack signal. This significantly reduces deployment costs, improves the economy and feasibility of the solution, and facilitates its implementation in existing systems. Simulation experiments have verified that this invention can achieve fast and accurate tracking and estimation against various typical spoofed data injection attacks, such as ramp attacks, step attacks, square wave attacks, and their combinations, and can immediately trigger the compensation mechanism. This demonstrates the strong robustness of this invention and its ability to effectively cope with complex and time-varying network attack scenarios that may occur in practice.

Claims

1. A power market attack detection and compensation based on a three-step recursive filter, characterized in that, include: S1: Establish a discretized state-space model of a multi-regional electricity market coupling system. The model integrates the dynamic mechanism of the electricity market and performs discretization processing on the model of injecting false data into the attack. S2: Execute time update, based on the prediction error of the state estimate at time k-1, calculate the system state prediction at time k and its corresponding prediction error covariance matrix; S3: Perform measurement update, use the current measurement value at time k to correct the state prediction value, obtain the minimum variance unbiased estimate of the system state at time k, and calculate its estimation error covariance matrix; S4: Based on the estimated and predicted values ​​of the system state, estimate the spoofed data injection FDI attack signal, and calculate the covariance matrix of the estimation error of the FDI attack signal and its cross-covariance matrix with the state estimation error. S5: A real-time compensation mechanism is designed using the redundancy analysis method. The FDI attack signal estimated in S4 is used to dynamically compensate the output link of the attacked system.

2. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S1, the discretized state-space model is established, including: 1) Construct a dynamic electricity market mechanism based on the dynamic relationship between power generators and consumers, expressed as: (1); In formula (1): , , , and These represent the power supply deviation of generators in the i-th region (in MW), the power demand deviation of consumers (in MW), the marginal cost of generators (in $ / MWh), the marginal benefit of consumers (in $ / MWh), and the electricity price (in $ / MWh), respectively. This represents a constant term in the power generator cost parameters, expressed in US dollars per megawatt-hour. This represents the slope coefficient in the power generator cost parameters, expressed in US dollars per megawatt-hour. This represents the constant term in the consumer benefit parameter, expressed in US dollars per megawatt-hour. This represents the slope coefficient in the consumer benefit parameter, expressed in US dollars per megawatt-hour. and These represent the response constants for the power generator and the consumer, respectively, in seconds; This indicates the rate of change in electricity prices, expressed in seconds. Indicates the average frequency deviation; This represents the electricity market regulation coefficient, expressed in US dollars per megawatt-hour second. The average frequency deviation (in Hertz) is expressed as follows: ; in: This represents the generator's inertia constant (in seconds). Angular frequency (unit: radians per second); Indicates the power supply deviation of the generator (in megawatts); 2) Calculate the state variables of the multi-regional electricity market coupled system. Control input System output and FDI attack vectors with fake data injection State variables This includes frequency deviation, tie line switching power deviation, generator mechanical power deviation, valve position deviation, and area control deviation; make ; ; Establish the state-space equations for a continuous-time, multi-region coupled system: (2); in: ; ; ; ; ; ; , , , , These represent the frequency deviation (in Hertz), tie-line switching power deviation (in Megawatts), generator mechanical output power deviation (in Megawatts), valve position deviation (in per unit), and area control deviation (in Megawatts), respectively, for the i-th region. , , , , , These represent the generator's moment of inertia (in per unit second), the generator's damping coefficient (in per unit per hertz), the turbine's time constant (in seconds), the governor's time constant (in seconds), the speed reduction coefficient (in hertz per per unit), and the frequency deviation coefficient, respectively. This represents the synchronization coefficient of the tie line between region i and region j, expressed in per-unit value per Hertz. This represents process noise, assumed to be Gaussian white noise; ; This represents the measurement noise, assumed to be Gaussian white noise; ; 3) Discretize the state-space equations of the continuous-time multi-region coupled system to obtain the discrete-time system equations for recursive filtering: (3); in: , , , They represent: The system state vector at time k Control input vector (megawatt), FDI attack vector ( ) and measurement output vector ( ); Represents the discretized state matrix; Indicates sampling time (in seconds); Unit A is: ; Represents the discretized input matrix; unit: ; Represents the discretized coupling matrix; unit: ; This represents the impact matrix of discretization attacks, in units of: ; This represents the discretized constant term matrix, in units of: ; Represents the discretized output matrix; Represents the discretized direct transfer matrix; This indicates that discretization attacks directly affect the matrix; Represents discrete process noise, in units of: , covariance matrix The expression is: The unit is: ; Discrete measurement noise, covariance matrix The unit is: 。 3. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S2, the time update includes calculating the prediction error of the state estimate at time k-1. and the error covariance matrix of the state prediction value at time k The expression is: ; (4); in, , , , , for: This represents the prediction error of the state estimate; the unit is: ; This represents the state estimation error; the unit is: ; This represents the FDI attack estimation error; the unit is 1. This represents the state estimation error covariance matrix; the unit is: ; This represents the covariance matrix of the FDI attack estimation error; the unit is: ; The cross-covariance matrix represents the error between the state and the attack estimation; units are: ; Represents the process noise covariance matrix; unit: 。 4. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S2, the state prediction value is a priori estimate of the system state before incorporating the measurement information at time k.

5. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S3, the measurement update includes calculating the state estimation error at time k. and its covariance and use the minimum variance unbiased state estimator gain The expression is: (6); In formula (6): This represents the identity matrix, with units of 1; This represents the state estimator gain matrix; units are: ; Indicates the output matrix; Represents the attack impact matrix; Indicates the FDI attack vector; ; Indicates measurement noise; ; State estimation error covariance matrix: (7); The unit is: ; In formula (7): The gain of the minimum variance unbiased state estimator is: (8); Unit: ; In formula (8): The unit is: 。 6. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S3, the current measurement value is the output data actually collected by the system sensor at time k.

7. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S4, FDI attack estimation is performed using the following expression: Scaled innovation covariance matrix The unit is: ; FDI attack covariance matrix The unit is: ; FDI estimator gain (9); Unit: ; FDI attack estimation error and its covariance matrix and state estimation error The cross-covariance matrix satisfies: The unit is: ; FDI attack covariance matrix The unit is: ; State estimation error Cross-covariance matrix: (10); Unit: ; This represents the scaled innovation covariance matrix; units are: ; This represents the attack estimator gain matrix; the unit is: ; Represents the residual vector; unit: 。 8. The power market attack detection and compensation based on a three-step recursive filter according to claim 1, characterized in that, In S5, the real-time compensation mechanism introduces a compensation signal in the system's frequency deviation output link and / or tie-line switching power deviation output link. This compensation signal is equal in magnitude but opposite in sign to the estimated false data injection attack signal, and is used to offset the impact of the attack on the system output.