Network attack defense method and device for intelligent electric meter, and terminal equipment

By constructing a communication relationship model and topology camouflage strategy for smart meter networks and optimizing defense strategies using genetic algorithms, the problem of high topology exposure risk in smart meter systems is solved, achieving more sustainable and scalable network attack defense.

CN121967066APending Publication Date: 2026-05-01SICHUAN NORMAL UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN NORMAL UNIV
Filing Date
2026-03-06
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing smart meter systems in multi-hop mesh networks have high risks of topology exposure and static strategies are difficult to maintain effectiveness. Attackers can launch targeted attacks by identifying network topology and data transmission paths, leading to the leakage of sensitive information and a decrease in service availability.

Method used

By constructing a communication relationship data model for a smart meter network, generating a real adjacency matrix, constructing an attacker monitoring strategy model and optimizing the Boolean feature matrix, generating a topology camouflage strategy, using a genetic algorithm to solve the attack-defense game model, and optimizing the defender camouflage strategy to reduce the attacker's path prediction accuracy.

Benefits of technology

It effectively suppresses attackers' ability to target and tamper with networks based on path prediction, enhances network sustainability and scalability, reduces the probability of critical node exposure, mitigates security incident risks, and provides more targeted and interpretable defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967066A_ABST
    Figure CN121967066A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of electric power Internet of Things, and provides a network attack defense method and device for an intelligent electric meter and terminal equipment, and the method comprises the steps: obtaining communication relation data of an intelligent electric meter network in a preset time interval, determining an actual data transmission path between each source node and a target node, and generating a topology inference result of an attacker, generating a topology camouflage strategy of a defender, and acting the topology camouflage strategy on the network topology model. The method has the advantages that the attacker topology and path inference difficulty can be improved in a complex dynamic network environment, the exposure probability of key nodes is reduced, the security event risk caused by accurate prediction of a data transmission path is reduced, and the active defense capability with higher continuity and expandability is provided for the intelligent electric meter network.
Need to check novelty before this filing date? Find Prior Art

Description

A method, device, and terminal equipment for defending against network attacks on smart meters. Technical Field

[0001] This invention belongs to the field of power Internet of Things technology, and in particular relates to a network attack defense method, device and terminal equipment for smart meters. Background Technology

[0002] As the most widely deployed terminal device on the user side, smart meters are responsible for the continuous collection and transmission of operational data from the electricity consumption side, such as reporting electricity consumption readings, timestamps, and power outage alarm status on a minute-by-minute basis. This data is used directly for metering and billing, as well as for upper-level operations such as load forecasting, distribution network situational awareness, demand response, and operation scheduling. Therefore, it plays a fundamental and crucial role in the operation and management of the power system.

[0003] In practical deployments, due to considerations such as coverage, cost, and maintainability, smart meters often communicate via public wireless networks, private networks, or hybrid networks. Many scenarios employ multi-hop relaying between adjacent meters to form a mesh topology, enabling data aggregation and transmission from the terminal to the concentrator or data center. While this multi-hop mesh communication mode improves network coverage and robustness, it also significantly expands the system's attack surface: data must pass through multiple intermediate nodes during transmission. If any node, forwarding path, or protocol interaction in the link is exploited by an attacker, it could lead to security incidents such as sensitive information leakage, data integrity breaches, or decreased service availability.

[0004] Existing smart meter systems face a variety of security threats, including but not limited to: obtaining user electricity consumption behavior characteristics and identity-related information through eavesdropping or wiretapping, leading to privacy leaks; and falsifying electricity consumption information through man-in-the-middle attacks, data tampering, or replay attacks, causing billing disputes and misleading power grid operation analysis. Especially in multi-hop transmission scenarios, if attackers can identify or deduce the network topology and data transmission path, they can often further target vulnerable nodes or key forwarding points on the path to carry out targeted attacks, thus significantly improving attack efficiency.

[0005] To address the aforementioned security issues, existing technologies often employ encryption authentication and key management as protective measures. However, these measures still have certain limitations in engineering applications. For example, many solutions focus on protecting end-to-end direct transmission links, while paying insufficient attention to the risks of topology exposure in mesh networks. Communication networks are dynamic in actual operation; node online status and routing selection change over time, making single static protection strategies difficult to maintain effectiveness. In resource-constrained terminal environments, the computational and communication overhead of complex security mechanisms may affect system real-time performance and stability. Attackers can deploy eavesdropping devices in local areas, collect communication interaction characteristics, and combine them with inference algorithms to recover network connectivity. Even under incomplete observation conditions, they can still approximate the true topology and infer data transmission paths, making traditional methods relying solely on encryption authentication or static secure routing insufficient to suppress the risk of targeted attacks arising from path predictability.

[0006] Therefore, improvements are needed to address the problems of high topology exposure risk and the difficulty in maintaining the effectiveness of static strategies in existing power grid protection methods. Summary of the Invention

[0007] The purpose of this application is to provide a network attack defense method for smart meters, which aims to solve the problems of high topology exposure risk and difficulty in maintaining the effectiveness of static strategies in existing power grid protection methods.

[0008] This application provides a network attack defense method for smart meters, the method comprising:

[0009] Obtain communication relationship data of the smart meter network within a preset time interval, construct a network topology model based on the communication relationship data, and generate a true adjacency matrix representing the communication connection relationship between smart meter nodes;

[0010] Construct an attacker's monitoring strategy model, determine the set of monitored nodes based on the monitoring strategy model, and obtain the local observation information that the attacker can obtain from the set of monitored nodes.

[0011] Based on the local observation information, construct and optimize the Boolean feature matrix. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and Based on the optimal Boolean matrix, the inference adjacency matrix corresponding to the attacker's predicted graph is obtained;

[0012] A topology camouflage strategy model for the defender is constructed, a topology camouflage strategy is generated, and the local observation information that the attacker can obtain is camouflaged based on the topology camouflage strategy. The loss function and inference adjacency matrix of the monitoring strategy model are then updated.

[0013] The actual transmission path of the transmission task is obtained based on the true adjacency matrix, and the predicted transmission path is obtained based on the inferred adjacency matrix. The path exposure loss term is constructed based on the degree of overlap between the actual transmission path and the predicted transmission path. The total loss function of the defender containing the path exposure loss term and the utility function of the attacker containing the attack cost term are obtained to construct an attack-defense game model.

[0014] The attack-defense game model is solved using a genetic algorithm to obtain an equilibrium solution for the optimal topology camouflage strategy, and a protection strategy for the data transmission path is generated based on the equilibrium solution.

[0015] Preferably, the method for constructing a network topology model based on the communication relationship data and generating a true adjacency matrix representing the communication connection relationships between smart meter nodes includes:

[0016] Obtaining data from the smart meter network A collection of smart meter nodes and the set of communication edges between nodes Construct an undirected graph As a network topology model;

[0017] The undirected graph Topological structure information is provided by the following real adjacency matrix. To indicate:

[0018] ;

[0019] in:

[0020] .

[0021] Preferably, the method for constructing an attacker's monitoring strategy model, determining the set of monitored nodes based on the monitoring strategy model, and obtaining the local observation information obtainable by the attacker from the set of monitored nodes is as follows:

[0022] Monitoring strategy vectors for constructing an attacker's monitoring strategy model :

[0023] ;

[0024] in This indicates that the attacker is in the smart meter Place listening devices nearby. This indicates that no product has been deployed.

[0025] Based on the monitoring strategy vector Get the set of monitored nodes : , This refers to a collection of smart meters.

[0026] When at node After deploying a listening device nearby, the communication relationship observation information between the node and its neighboring nodes is obtained, thus obtaining the local observation information. :

[0027] .

[0028] Preferably, the optimal Boolean feature matrix is ​​obtained. and The method for obtaining the inferred adjacency matrix corresponding to the attacker's predicted graph from the optimal Boolean matrix is ​​as follows:

[0029] Let the local observation information be... The feature dimension is Construct Boolean feature matrix and ;

[0030] Defining logical AND in Boolean algebra , logic or Logical negation And define Boolean addition, Boolean subtraction, and Boolean multiplication to satisfy: , , Multiplying two Boolean matrices Calculated according to the following rules:

[0031] ;

[0032] Construct a loss function based on attacker observation information. :

[0033] ;

[0034] Solving the optimal Boolean matrix based on the following formula So that the loss function Minimum:

[0035] ;

[0036] Obtain the optimal Boolean matrix The inference adjacency matrix corresponding to the attacker's predicted graph is obtained based on the following formula. :

[0037] .

[0038] Preferably, the method for generating a topology camouflage strategy and updating the loss function and inferred adjacency matrix of the monitoring strategy model includes the following steps:

[0039] Constructing a topology camouflage strategy model for defenders ,in Indicates a node With nodes The communication link is disguised. This indicates that no disguise will be used;

[0040] Based on the camouflage strategy, a camouflaged adjacency matrix that is fully perceptible to the attacker is obtained:

[0041] ;

[0042] Based on the camouflaged adjacency matrix, the set of observable information of the attacker under the influence of camouflage is obtained. :

[0043] ;

[0044] In the observable information set Next, the loss function of the attacker's monitoring strategy model is updated:

[0045] ;

[0046] The attacker's inferred adjacency matrix is ​​updated using the following formula:

[0047] ;

[0048] in, .

[0049] Preferably, the method for obtaining the defender's total loss function including the path exposure loss term and the attacker's utility function including the attack cost term includes the following steps:

[0050] Construct the total loss function for the defender, which includes the cost of defense and the losses caused by the attack. :

[0051] ;

[0052] in, Indicates the cost of defense. Indicates the damage caused by the attack;

[0053] ;

[0054] ;

[0055] ;

[0056] ;

[0057] and These represent the costs of the defender employing strategies to conceal or forge communication relationships, respectively. The function satisfies: ; and These represent the unit cost of the defender employing strategies to conceal and forge communication relationships, respectively. Represents a computation set The momentum; Indicates the first On the secondary data transmission link, the real path With the attacker's predicted path The number of intersection nodes between them This represents the potential loss that would result from an attacker successfully predicting the occurrence of a single node in the data transmission path. Indicates the first This transmission task;

[0058] Constructing the attacker's utility function :

[0059] ;

[0060] ;

[0061] in, For the cost of the attack, For the cost of a single listener, This represents the total number of nodes in the smart meter network.

[0062] Preferably, the attack-defense game model constructed based on the defender's total loss function and the attacker's utility function is as follows:

[0063] .

[0064] Among them, the binary pair This represents the equilibrium solution of the model. For attackers' equilibrium strategy, The optimal topology camouflage strategy for the defender.

[0065] Preferably, the method for obtaining the optimal topology camouflage strategy by solving the attack-defense game model based on a genetic algorithm is as follows:

[0066] Initialize and set network parameters based on the actual adjacency matrix. Calculate the source node and target node pairs for each transmission task. The actual data transmission path ;

[0067] Initialize the attacker's eavesdropping strategy population and the defender's topology camouflage strategy population, and assign the attacker's eavesdropping strategy vector to each population. With the defender's topology camouflage matrix Encodes individuals using a genetic algorithm;

[0068] In each iteration of the genetic algorithm, based on the current attacker's listening strategy... Determine the set of monitored nodes And based on the current topology camouflage strategy Constructing attacker's local observation information Solving for the optimal Boolean characteristic matrix using Boolean matrix decomposition and The inferred adjacency matrix is ​​obtained. Based on the inferred adjacency matrix Calculate the predicted transmission path ;

[0069] Based on the actual transmission path With the predicted transmission path Calculate path exposure loss term And based on this, calculate the defender's total loss function. With attacker utility function ;

[0070] While maintaining the current attacker's eavesdropping strategy Under the condition of invariance, minimize Topology camouflage strategy for fitness targets against defenders The population performs genetic iterations to obtain the defender update strategy;

[0071] Maintaining the updated defender topology camouflage strategy Under the condition of invariance, to maximize To achieve fitness targets, the attacker's monitoring strategy is implemented. The population performs genetic iterations to obtain the attacker's updated strategy;

[0072] Calculate the policy change between two adjacent iterations. and When satisfied Alternatively, the iteration can stop when the maximum number of iterations is reached, and the equilibrium solution can be output. ,in This is the optimal topology camouflage strategy.

[0073] Another objective of this application is to provide a network attack defense device for smart meters, the device comprising:

[0074] The power grid model construction unit is used to acquire communication relationship data of the smart meter network within a preset time interval, construct a network topology model based on the communication relationship data, and generate a real adjacency matrix representing the communication connection relationship between smart meter nodes.

[0075] An attack model construction unit is used to construct an attacker's monitoring strategy model, determine a set of monitored nodes based on the monitoring strategy model, and obtain local observation information that the attacker can obtain from the set of monitored nodes.

[0076] The attack inference unit is used to construct and optimize the Boolean feature matrix based on the local observation information. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and Based on the optimal Boolean matrix, the inference adjacency matrix corresponding to the attacker's predicted graph is obtained;

[0077] The defense model construction unit is used to build a topology camouflage strategy model for the defender, generate a topology camouflage strategy, camouflage the local observation information that the attacker can obtain based on the topology camouflage strategy, and update the loss function and inference adjacency matrix of the monitoring strategy model.

[0078] The protection unit is used to obtain the actual transmission path of the transmission task based on the real adjacency matrix, obtain the predicted transmission path based on the inferred adjacency matrix, construct a path exposure loss term based on the degree of overlap between the actual transmission path and the predicted transmission path, obtain the total loss function of the defender containing the path exposure loss term and the utility function of the attacker containing the attack cost term, and construct an attack-defense game model.

[0079] The protection execution unit is used to solve the attack-defense game model based on a genetic algorithm to obtain the equilibrium solution of the optimal topology camouflage strategy, and generate a protection strategy for the data transmission path based on the equilibrium solution.

[0080] Another objective of this application is to provide a terminal device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the network attack defense method for smart meters as described above.

[0081] This application provides a network attack defense method for smart meters, with key advantages in that it improves upon traditional technologies in three aspects: protection targets, adversarial targets, and strategy generation methods. First, the solution expands the focus of protection from traditional end-to-end data encryption or single-point hardening to the more easily overlooked but more destructive risks of topology and path exposure in multi-hop mesh networks. This directly suppresses attackers' ability to implement targeted interception, tampering, or blocking based on path prediction, thus better reflecting the main threat sources in the actual deployment of smart meters. Second, the solution does not assume that attacker capabilities are fixed, but explicitly constructs a model of the attacker's path prediction process and uses the information and inference results available to the attacker as adversarial targets. This makes the defense strategy targeted and interpretable, avoiding the risk that encryption may be implemented but the path can still be locked due to neglecting multi-hop link exposure in traditional defenses. By solving for the optimal camouflage strategy, the defense strategy can be adaptively optimized under controllable defense costs, balancing security benefits and engineering deployability. Therefore, this application can increase the difficulty for attackers to infer topology and path in complex and dynamic network environments, reduce the probability of critical node exposure, reduce the risk of security incidents caused by accurate prediction of data transmission paths, and provide smart meter networks with more sustainable and scalable proactive defense capabilities. Attached Figure Description

[0082] Figure 1 is an application environment diagram of a network attack defense method for smart meters provided in an embodiment of this application;

[0083] Figure 2 is a flowchart of a network attack defense method for smart meters provided in an embodiment of this application;

[0084] Figure 3 is a structural block diagram of a network attack defense device for smart meters provided in an embodiment of this application;

[0085] Figure 4 is a block diagram of the internal structure of a computer device in one embodiment. Detailed Implementation

[0086] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0087] It is understood that the terms "first," "second," etc., used in this application may be used herein to describe various elements, but unless otherwise stated, these elements are not limited by these terms. These terms are used only to distinguish the first unit or module from another unit or module. For example, without departing from the scope of this application, the first script may be referred to as the second script, and similarly, the second script may be referred to as the first script.

[0088] Figure 1 is an application environment diagram of the network attack defense method for smart meters provided in the embodiment of this application. As shown in Figure 1, the application environment includes a terminal 110 and a computer device 120.

[0089] Computer equipment 120 can be an independent physical server, smart meter controller, data hub, or a server cluster consisting of multiple physical servers, desktop computer, cloud server, etc.

[0090] Terminal 110 can be a data relay station, a smart meter, etc., but is not limited to these.

[0091] Terminal 110 and computer device 120 can be connected via a network, and this application does not impose any restrictions on this.

[0092] As shown in Figure 2, in one embodiment, a network attack defense method for smart meters is proposed. This embodiment mainly illustrates the application of this method to the computer device 120 in Figure 1. A network attack defense method for smart meters may specifically include the following steps:

[0093] Step S10: Obtain communication relationship data of the smart meter network within a preset time interval, construct a network topology model based on the communication relationship data, and generate a true adjacency matrix representing the communication connection relationship between smart meter nodes.

[0094] In this embodiment, the system first needs to abstract the actual communication connections between smart meters into a computable network structure. In actual deployment, smart meters generate a large number of neighbor interactions and forwarding behaviors within a preset time interval, such as route maintenance, neighbor discovery, and data relay. By collecting communication relationship data within this time interval, such as who has had effective link interactions with whom, whether certain link quality thresholds are met, and whether stable forwarding relationships exist, a network topology model can be constructed to characterize the connection relationships between nodes. This topology model provides a unified data structure foundation for subsequent real path calculation, attacker inference path calculation, and defense strategy impact assessment, enabling both attackers and defenders to model and optimize around the same network object.

[0095] For example, suppose a smart meter network contains A smart meter, the collection of all smart meters is used This indicates that the smart meter network is located within a certain time interval. The operation within the smart meter and If there is a communication relationship between the two within this time interval, then there is an edge between them. ,in A set representing the communication relationships between all devices in a network. Based on sets. and An undirected graph can be constructed. Let's represent a smart meter network, where the diagram... The topological structure information can be obtained using an adjacency matrix. To indicate:

[0096] ,

[0097] in .

[0098] Step S20: Construct an attacker's monitoring strategy model, determine the set of monitored nodes based on the monitoring strategy model, and obtain local observation information that the attacker can obtain from the set of monitored nodes.

[0099] In this embodiment, for an attacker, accurately identifying the actual topology information of the smart meter network is crucial. This is a crucial prerequisite for achieving data interception or tampering attacks. Once an attacker understands the network topology, they can accurately predict data transmission paths, identify vulnerable nodes on the links, and then launch targeted attacks. To achieve this, attackers typically employ various methods to monitor smart meter networks and extract valuable information to predict the network's topology.

[0100] For example, let This indicates the attacker's strategy for monitoring the smart meter network, where... This indicates that the attacker is in the smart meter Place listening devices nearby, otherwise The set of smart meters monitored by attackers on the network is denoted as . .

[0101] In the equipment After deploying listening devices nearby, attackers can observe the communication relationships between the device and its neighbors. The set of communication information that attackers can monitor and perceive is denoted as follows: .

[0102] Step S30: Based on the local observation information, construct and optimize the Boolean feature matrix. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and Based on the optimal Boolean matrix, the inferred adjacency matrix corresponding to the attacker's predicted graph is obtained.

[0103] In this embodiment, due to resource constraints, attackers cannot deploy listening devices on all nodes in the network. Therefore, attackers can only monitor the vicinity of some nodes to obtain local observation information, such as whether there are communication relationships, communication frequencies, or timing characteristics between certain nodes and their neighbors. This resource constraint means that attackers can ultimately only obtain partial network topology information, and the remaining topology information needs to be completed through prediction models or inference algorithms. In reality, the communication behavior between smart meters usually exhibits significant low-rank characteristics, which attackers can exploit to infer the missing network topology information.

[0104] Specifically, attackers can use Boolean matrix factorization techniques to extract information containing all observations. matrix Decomposed into two low-dimensional Boolean characteristic matrices and The Boolean product form of these two latent feature matrices. By solving for the optimal approximation of these two latent feature matrices, the missing interaction affinity can be effectively predicted, thus overcoming the limitation of incomplete information:

[0105] When the attacker is at the electricity meter Observers have been deployed in the surrounding area to obtain observational information. If the feature dimension is set to 1... Then define the Boolean characteristic matrix. and : , In the matrix decomposition process, the Boolean matrix is ​​selected through optimization. and This allows their Boolean product to effectively approximate the original observation matrix. .

[0106] The basic operations in Boolean algebra include logical AND. , logical OR Logical negation .

[0107] For matrix and Boolean can be represented as Boolean subtraction can be represented as Boolean multiplication can be represented as Among them, the multiplication of two Boolean matrices The calculation formula is: .

[0108] Based on this, a loss function of the following form is constructed to quantify the information loss during matrix factorization:

[0109] ;

[0110] When the product of Boolean characteristic matrices With observation information The smaller the difference between them, the better the loss function. The smaller the value of , the better. Therefore, the problem can be transformed into the following optimization problem: finding the optimal Boolean matrix. and This minimizes the loss function for the following optimization problem:

[0111] ;

[0112] Ultimately, the attacker obtained the predicted graph. The adjacency matrix is .

[0113] In this embodiment, The adjacency matrix represents the actual communication network topology of a smart meter. edge set It indicates a real, existing communication relationship. This is the attacker's predicted graph, representing the topology reconstructed and guessed by the attacker based on locally intercepted information and inference algorithms. Its adjacency matrix is... express.

[0114] Step S40: Construct a topology camouflage strategy model for the defender, generate a topology camouflage strategy, camouflage the local observation information that the attacker can obtain based on the topology camouflage strategy, and update the loss function and inference adjacency matrix of the monitoring strategy model.

[0115] In this embodiment, compared to traditional methods that only perform end-to-end encryption or static hardening at a single node, this application starts with the information source used by the attacker to infer the topology, actively altering the perceptible communication relationships to systematically reduce the accuracy of their inference. Specifically, the defender generates a topology camouflage strategy and applies it to the network topology model. The effect is twofold: firstly, by concealing some real communication relationships, critical links appear invisible or weakly correlated in the attacker's monitoring; secondly, by forging decoy communication relationships, interference information highly similar to real business is mixed into the attacker's observation data, inducing structural misjudgments during inference. Since the attacker's inference results depend on their observation information and the degree to which the inference algorithm fits the observation information, once the observation space is reshaped by the defender, the attacker's topology inference results will deviate from the real topology, and consequently, the transmission path they predict will also deviate from the real path, thus reducing the efficiency of the attacker's targeted attacks. The value of the steps provided in this embodiment lies in achieving information versus information, fundamentally weakening the attacker's predictability of the path.

[0116] Step S50: Obtain the actual transmission path of the transmission task based on the actual adjacency matrix, obtain the predicted transmission path based on the inferred adjacency matrix, construct a path exposure loss term based on the degree of overlap between the actual transmission path and the predicted transmission path; obtain the defender's total loss function containing the path exposure loss term and the attacker's utility function containing the attack cost term, and construct an attack-defense game model.

[0117] Step S60: Solve the attack-defense game model based on the genetic algorithm to obtain the equilibrium solution of the optimal topology camouflage strategy, and generate a protection strategy for the data transmission path based on the equilibrium solution.

[0118] In this embodiment, the attacker's core attack preparation is to deploy listeners to obtain local observation information. The attack cost mainly consists of the overhead related to the listeners. Therefore, the attack cost can be obtained by multiplying the total number of deployments by the unit cost. Considering that defense resources, such as computing, communication, energy consumption, and management overhead, are all limited, masquerading all links is neither necessary nor likely to introduce unreasonable system costs. Therefore, a balance needs to be struck between defense costs and security benefits. Furthermore, considering that defenders often deploy strategies first, while attackers choose monitoring locations, inference methods, and attack strength after observing network performance, the two have obvious temporal and policy dependencies. Therefore, modeling with the interaction constraint of defenders acting first and attackers acting later can better reflect the real attack and defense process. The optimal topology masquerading strategy obtained under this framework can implement differentiated protection for communication relationships related to the data transmission task set: stronger masquerading is applied to critical paths, critical nodes, and sensitive links, while maintaining lower overhead in non-critical areas. This maximizes the reduction of the attacker's ability to identify critical paths at a controllable cost and improves the overall system's protection effectiveness and sustainability in dynamic network environments.

[0119] The method provided in this application has the advantage of improving upon traditional technologies in three aspects: protection target, adversarial object, and strategy generation method. First, the solution expands the focus of protection from traditional end-to-end data encryption or single-point hardening to the more easily overlooked but more destructive risks of topology and path exposure in multi-hop mesh networks. This directly suppresses the attacker's ability to implement targeted interception, tampering, or blocking based on path prediction, thus better reflecting the main threat sources in the actual deployment of smart meters. Second, the solution does not assume that the attacker's capabilities are fixed, but explicitly constructs a model of the attacker's path prediction process and uses the information and inference results available to the attacker as adversarial objects, making the defense strategy targeted and interpretable. This avoids the risk that encryption may be implemented but the path can still be locked due to neglecting multi-hop link exposure in traditional defenses. Furthermore, by solving for the optimal camouflage strategy, this application enables the defense strategy to adaptively optimize under controllable defense costs and achieve differentiated protection for critical links, thus balancing security benefits and engineering deployability. Therefore, this application can increase the difficulty for attackers to infer topology and path in complex and dynamic network environments, reduce the probability of critical node exposure, reduce the risk of security incidents caused by accurate prediction of data transmission paths, and provide smart meter networks with more sustainable and scalable proactive defense capabilities.

[0120] In a preferred embodiment, to counter attackers' attempts to identify the real network structure through methods such as deploying eavesdroppers and topology prediction, the defender can dynamically adjust the communication relationships between smart meters, and mislead the attacker's judgment by hiding key links and injecting interference information. The defender mainly achieves topology camouflage through the following two methods: (1) Communication relationship concealment: During data transmission, the system will selectively shield the communication links between some key nodes, making them invisible in topology detection, thereby cutting off the attacker's identification and tracking of the core path. Specific implementations include: adopting an intermittent communication mechanism based on time slot scheduling to put key nodes into silent mode during non-transmission cycles; using cross-layer protocol camouflage technology to obfuscate the frame header information at the data link layer; and limiting the topology broadcast range through parameter reconfiguration of the Neighbor Discovery Protocol (NDP), thereby achieving dual concealment at the physical and logical levels. (2) Communication relationship forgery: The system will dynamically generate false communication connections to simulate the data exchange behavior between normal nodes, in order to construct "bait links" and "virtual neighbor nodes," thereby interfering with the attacker's topology inference process and increasing the difficulty for them to obtain the real network structure. The specific implementation includes: controlling nodes to periodically send simulated data packets that conform to the protocol specifications; using traffic feature replication technology to make the decoy traffic highly similar to real business in terms of latency, packet length, and sending frequency; and constructing false neighbor relationship topologies in selected areas through controllable broadcast and multicast mechanisms to increase the probability of attackers making misjudgments in topology inference.

[0121] In a preferred embodiment, specifically, the method for constructing a defender's topology camouflage strategy model, generating a topology camouflage strategy, camouflaging the attacker's available local observation information based on the topology camouflage strategy, and updating the loss function and inference adjacency matrix of the monitoring strategy model, thereby constructing an attack-defense game model, can be as follows:

[0122] make This represents the defender's topology camouflage strategy. This indicates that the defenders will use technical means to target the electricity meters. and Disguising the communication links between them This indicates that the defender will not spoof the communication link.

[0123] If the electricity meter and There is a real communication relationship between them (i.e.) ), then adopt a topology camouflage strategy (i.e. After that, the attacker will identify that there is no communication relationship at that node (i.e., ); if the meter and There is no communication relationship between them (i.e.) If a topology masquerade strategy is employed, the attacker will identify that there is a communication relationship at that node (i.e., ).

[0124] When the defender adopts a topology camouflage strategy Afterwards, the communication relationships between the meters that an attacker can fully perceive can be represented by the following adjacency matrix:

[0125] ;

[0126] When a defender employs a topology camouflage strategy, the attacker can record the communication information detected through monitoring as follows: .

[0127] Under the influence of the defense strategy, the loss function of the attacker's prediction model will change as follows:

[0128] ;

[0129] Furthermore, the information that attackers can ultimately predict will become ,in .

[0130] In smart meter networks, data transmission tasks typically choose the shortest path between the source and destination nodes. (Considering time intervals...) The system operation scenario within this time period, the total number of transmission tasks that need to be completed during this period is For the first Secondary transmission task ( ), whose source node and target node are denoted as respectively. and Based on the real adjacency matrix of the network Node pairs can be determined The actual data transmission path between , The path is usually derived based on the shortest path algorithm, such as Dijkstra's or Floyd-Warshall's algorithm.

[0131] Meanwhile, the attackers relied on their inferred adjacency matrix The node pairs are calculated using the same shortest path algorithm. Predicted transmission path , The two paths mentioned above: , and , The differences between them reflect the interference effect of the defender's topology camouflage strategy on the attacker's path inference process.

[0132] Attackers attempt to predict the data transmission paths between smart meters and the defenders' process of protecting those paths, which can be abstracted into a typical attack-defense game problem.

[0133] In real-world systems, the defender typically needs to develop and implement protection strategies first to counter various probing and identification attempts that attackers may launch. For example, in this invention, the defender will pre-process the network topology using technical means before the actual transmission of meter data; while the attacker will deploy various reconnaissance methods to attempt to reconstruct the true network connectivity. This "defense first, attack later" temporal characteristic allows the Stackelberg game model to naturally characterize this type of attack-defense interaction process, demonstrating both theoretical applicability and modeling rationality.

[0134] In this game theory problem, the attack strategy is expressed as: The defense strategy is expressed as Next, we will conduct a quantitative analysis of the utility functions of both the attackers and defenders.

[0135] For the defender, the goal is to minimize the overall losses caused by the attack. The defender's total losses mainly consist of two parts: defense costs and direct losses caused by the attack, which can be expressed by the following formula:

[0136] ;

[0137] in, Indicates the cost of defense. This indicates the damage caused by the attack.

[0138] Define the following symbolic functions:

[0139] ;

[0140] Then the cost of defense The calculation formula is:

[0141] ;

[0142] in and These represent the costs of the defender employing strategies of concealing and forging communication relationships, respectively, and are given by the following formulas:

[0143] ;

[0144] ;

[0145] here and These represent the unit cost of the defender employing strategies to conceal or forge communication relationships, respectively.

[0146] The core objective of a defender is to protect the data transmission path from being accurately predicted by an attacker as much as possible. The losses incurred by the defender due to the exposure of the data transmission path (or, equivalently, the attacker's corresponding gains) can be evaluated using the following formula:

[0147] ;

[0148] in, Represents a computation set The momentum.

[0149] In this context, Indicates the first On the secondary data transmission link, the real path With the attacker's predicted path The number of nodes that intersect with each other, i.e. the number of data transmission nodes successfully identified by the attacker. This represents the potential loss that would result from an attacker successfully predicting the occurrence of a single node in the data transmission path.

[0150] Generally speaking, the more accurate the attacker's inference of the true topology, that is... The larger the value of , the higher the security risks and losses the system faces.

[0151] For an attacker, the goal is to maximize their net gain (i.e., the difference between the attack's profit and its cost). The attacker's utility function can be expressed as:

[0152] ;

[0153] Among them, the cost of attack The calculation formula is as follows:

[0154] ;

[0155] Attack cost The cost of a single listener is related to the number of listeners deployed by the attacker. .

[0156] Based on the above analysis, the interaction process between the attacker and the defender can be modeled as the following game theory model:

[0157] ;

[0158] The equilibrium solution of this game can be obtained using binary pairs. It means that among them For attackers' equilibrium strategy, This represents the optimal response strategy for the defender.

[0159] In a preferred embodiment of this application, the method for obtaining the optimal topology camouflage strategy by solving the attack-defense game model based on a genetic algorithm is as follows:

[0160] Initialize and set network parameters based on the actual adjacency matrix. Calculate the source node and target node pairs for each transmission task. The actual data transmission path Initialize the attacker's monitoring strategy population and the defender's topology camouflage strategy population, and assign the attacker's monitoring strategy vector to each population. With the defender's topology camouflage matrix Encoded as individuals using a genetic algorithm; in each iteration of the genetic algorithm, based on the current attacker's listening strategy... Determine the set of monitored nodes And based on the current topology camouflage strategy Constructing attacker's local observation information The optimal Boolean characteristic matrix is ​​obtained by Boolean matrix decomposition. and The inferred adjacency matrix is ​​obtained. Based on the inferred adjacency matrix Calculate the predicted transmission path Based on the actual transmission path With the predicted transmission path Calculate path exposure loss term And based on this, calculate the defender's total loss function. With attacker utility function While maintaining the current attacker's eavesdropping strategy Under the condition of invariance, minimize Topology camouflage strategy for fitness targets against defenders The population performs genetic iterations to obtain the defender update strategy; while maintaining the updated defender topology camouflage strategy. Under the condition of invariance, to maximize To achieve fitness targets, the attacker's monitoring strategy is implemented. The population undergoes genetic iteration to obtain the attacker's updated policy; the policy change between adjacent iterations is calculated. and When satisfied Alternatively, the iteration can stop when the maximum number of iterations is reached, and the equilibrium solution can be output. ,in This is the optimal topology camouflage strategy.

[0161] In this embodiment, V represents the set of all smart meter nodes in the smart meter network. The equilibrium solution to the above game problem is then obtained. Afterwards, among them This method can be applied as a data transmission path protection strategy for smart meters. The advantage of the method provided in this embodiment lies in its ability to effectively balance defense costs and security benefits by optimizing the configuration of network topology masquerading parameters: on the one hand, it minimizes the potential risks caused by node information exposure, and on the other hand, it ensures that the defense cost is at an acceptable level. In actual deployment, the defender can further... Differentiated protection is implemented for each transmission path, with a focus on strengthening the concealment of key nodes and sensitive links, thereby systematically increasing the difficulty for attackers to accurately predict data transmission paths.

[0162] Specifically, the following algorithm can be used to find potential equilibrium strategy pairs for solving the above game theory model:

[0163] First, input the initial parameters of the network and set the total number of network nodes. Total number of transmission tasks Boolean feature dimension Unit cost weight Maximum number of iterations for attackers and defenders and convergence threshold .

[0164] Then, the defender uses the adjacency matrix Calculate the start and end points The shortest path between Set the number of iteration steps. Set initial error Initialize attacker and defender strategies and ;

[0165] Then, a judgment is made when the condition is: or or If any one of the conditions is met, the following iterative calculation begins:

[0166] attackers based on and Predicting the adjacency matrix using Boolean matrix decomposition method Attackers obtain adjacency matrix based on predictions. To calculate communication links ;according to and ,calculate , ,as well as ;Calculation obtained ;Keep Without changing, using a genetic algorithm to search makes The corresponding minimum value The value of is denoted as . .make Increment the value by 1 based on the previous iteration value, and record it as... ;Keep Without changing, using a genetic algorithm to search makes The corresponding value for obtaining the maximum value The value of is denoted as . .make Increment the value by 1 based on the previous iteration value, and record it as... .calculate , .

[0167] When conditions: or or If none of the conditions are met, stop the iteration and set: , = Output balancing strategy pair: .

[0168] In this embodiment, the model parameters, maximum number of iterations, and start / endpoint pairs are first set. Generate protection links Then, set the initial number of iterations for the algorithm, set the initial errors for the attack and defense strategies, and initialize the attack and defense strategies.

[0169] The update process of the attack and defense strategies described above (i.e., the iterative process in the above steps) is as follows: The attacker, based on... and Predicting the adjacency matrix using Boolean matrix decomposition method And predict possible communication links for data transmission. Calculate the utility functions for attackers and defenders. A genetic algorithm is used to search for the optimal defense strategy of the defender, and the iteration step and defense strategy are updated (i.e., "let" in the above steps). Increment the value by 1 based on the previous iteration value, and record it as... The algorithm uses a genetic algorithm to search for the attacker's optimal attack strategy and updates the iteration step and attack strategy (i.e., "let" in the above steps). Increment the value by 1 based on the previous iteration value, and record it as... The iteration error of the attack and defense strategies is calculated (i.e., the values ​​of ∆x and ∆y calculated in the above steps). When the condition for exiting the iteration process is met, the optimal iteration result is output (i.e., the result set in the above steps). , = ).

[0170] By following the steps above, the equilibrium solution to the game problem can be obtained. Then, take one of them This is applied as a data transmission path protection strategy for smart meters, thereby protecting the data of smart meters.

[0171] The strategy provided in this embodiment effectively balances defense costs and security benefits by optimizing the configuration of network topology masquerading parameters: on the one hand, it minimizes the potential risks caused by the exposure of node information, and on the other hand, it ensures that the defense costs are at an acceptable level. In actual deployment, the defender can further... Differentiated protection is implemented for each transmission path, with a focus on strengthening the concealment of key nodes and sensitive links, thereby systematically increasing the difficulty for attackers to accurately predict data transmission paths.

[0172] As shown in Figure 3, in one embodiment, a network attack defense device for smart meters is provided. This network attack defense device for smart meters can be integrated into the aforementioned computer device 120, and specifically may include:

[0173] The power grid model construction unit 510 is used to acquire communication relationship data of the smart meter network within a preset time interval, construct a network topology model based on the communication relationship data, and generate a real adjacency matrix representing the communication connection relationship between smart meter nodes.

[0174] The attack model construction unit 520 is used to construct an attacker's monitoring strategy model, determine a set of monitored nodes based on the monitoring strategy model, and obtain local observation information that the attacker can obtain from the set of monitored nodes.

[0175] Attack inference unit 530 is used to construct and optimize Boolean feature matrix based on the local observation information. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and Based on the optimal Boolean matrix, the inference adjacency matrix corresponding to the attacker's predicted graph is obtained;

[0176] The defense model building unit 540 is used to build a topology camouflage strategy model for the defender, generate a topology camouflage strategy, camouflage the local observation information that the attacker can obtain based on the topology camouflage strategy, and update the loss function and inference adjacency matrix of the monitoring strategy model.

[0177] The protection unit 550 is used to obtain the real transmission path of the transmission task based on the real adjacency matrix, obtain the predicted transmission path based on the inferred adjacency matrix, construct a path exposure loss term based on the degree of overlap between the real transmission path and the predicted transmission path, obtain the defender's total loss function including the path exposure loss term and the attacker's utility function including the attack cost term, and construct an attack-defense game model.

[0178] The protection execution unit 560 is used to solve the attack and defense game model based on a genetic algorithm to obtain the equilibrium solution of the optimal topology camouflage strategy, and generate a protection strategy for the data transmission path based on the equilibrium solution.

[0179] In the embodiments of this application, the explanation and description of the network attack defense device for smart meters can be referred to the explanation and description of the corresponding method above. For the description of the network attack defense method for smart meters, please refer to the above text, which will not be repeated here.

[0180] Figure 4 shows an internal structural diagram of a computer device in one embodiment. Specifically, this computer device can be the computer device 120 shown in Figure 1. As shown in Figure 4, the computer device includes a processor, memory, network interface, input device, and display screen connected via a system bus. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and may also store a computer program. When executed by the processor, this computer program enables the processor to implement a network attack defense method for smart meters. The internal memory may also store a computer program, which, when executed by the processor, enables the processor to implement a network attack defense method for smart meters. The display screen of the computer device can be an LCD screen, etc. The input device can be a touch layer covering the display screen, or buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse, etc.

[0181] Those skilled in the art will understand that the structures shown in Figures 1 and 4 are merely block diagrams of some structures related to the present application and do not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than shown in the figures, or combine certain components, or have different component arrangements.

[0182] In one embodiment, the network attack defense device for smart meters provided in this application can be implemented as a computer program, which can run on the device shown in FIG4. The memory of this device can store various program modules that constitute the network attack defense device for smart meters, such as the power grid topology model construction unit 510 and the actual transmission path acquisition unit 520 shown in FIG3. The computer program composed of these program modules causes the processor to execute the steps in the network attack defense methods for smart meters described in the various embodiments of this application.

[0183] For example, the computer device shown in Figure 4 can execute step S10 through the power grid topology model construction unit 510 in the network attack defense device for smart meters shown in Figure 3. The computer device can execute step S20 through the actual transmission path acquisition unit 520. And so on.

[0184] In one embodiment, a terminal device is provided, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor causes the processor to perform the steps of the network attack defense method for smart meters as described above.

[0185] In this embodiment of the application, the system can be a computer hardware system that executes its corresponding methods when the system is running. For a description of the network attack defense method for smart meters, please refer to the above text; it will not be repeated here.

[0186] It should be understood that although the steps in the flowcharts of the various embodiments of this application are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least a portion of the sub-steps or stages of other steps.

[0187] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Furthermore, any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory.

[0188] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

Claims

1. A network attack defense method for smart meters, characterized in that, The method includes: acquiring communication relationship data of a smart meter network within a preset time interval; constructing a network topology model based on the communication relationship data; generating a true adjacency matrix representing the communication connection relationships between smart meter nodes; constructing an attacker's monitoring strategy model; determining a set of monitored nodes based on the monitoring strategy model; and obtaining local observation information obtainable by the attacker from the set of monitored nodes; and constructing and optimizing a Boolean feature matrix based on the local observation information. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and The process involves: obtaining the inferred adjacency matrix corresponding to the attacker's predicted graph based on the optimal Boolean matrix; constructing a topology camouflage strategy model for the defender, generating a topology camouflage strategy, and camouflaging the local observation information obtainable by the attacker based on the topology camouflage strategy, while updating the loss function and inferred adjacency matrix of the monitoring strategy model; obtaining the actual transmission path of the transmission task based on the actual adjacency matrix, and obtaining the predicted transmission path based on the inferred adjacency matrix, constructing a path exposure loss term based on the degree of overlap between the actual and predicted transmission paths; obtaining the defender's total loss function including the path exposure loss term and the attacker's utility function including the attack cost term, and constructing an attack-defense game model; solving the attack-defense game model using a genetic algorithm to obtain the equilibrium solution of the optimal topology camouflage strategy, and generating a protection strategy for the data transmission path based on the equilibrium solution.

2. The network attack defense method for smart meters according to claim 1, characterized in that, The method for constructing a network topology model based on the aforementioned communication relationship data and generating a true adjacency matrix representing the communication connection relationships between smart meter nodes includes: obtaining the network topology model of the smart meter network. A collection of smart meter nodes and the set of communication edges between nodes Construct an undirected graph As a network topology model; the undirected graph Topological structure information is provided by the following real adjacency matrix. To indicate: ;in: 。 3. The network attack defense method for smart meters according to claim 1, characterized in that, The method for constructing an attacker's monitoring strategy model, determining the set of monitored nodes based on the monitoring strategy model, and obtaining the locally accessible observation information that the attacker can obtain from the set of monitored nodes is as follows: Constructing the monitoring strategy vector of the attacker's monitoring strategy model. : ;in This indicates that the attacker is in the smart meter Place listening devices nearby. This indicates that no deployment has been made; based on the monitoring strategy vector. Get the set of monitored nodes : ,in Represents a set of smart meters; when in a node After deploying a listening device nearby, the communication relationship observation information between the node and its neighboring nodes is obtained, thus obtaining the local observation information. : 。 4. A network attack defense method for smart meters according to claim 1, characterized in that, Obtain the optimal Boolean feature matrix and The method for obtaining the inferred adjacency matrix corresponding to the attacker's predicted graph from the optimal Boolean matrix is ​​as follows: Let the local observation information The feature dimension is Construct Boolean feature matrix and ; Defining logical AND in Boolean algebra , logic or Logical negation And define Boolean addition, Boolean subtraction, and Boolean multiplication to satisfy: , , Multiplying two Boolean matrices Calculated according to the following rules: ; Construct a loss function based on attacker observation information. : Solving for the optimal Boolean matrix based on the following formula So that the loss function Minimum: Obtain the optimal Boolean matrix. The inference adjacency matrix corresponding to the attacker's predicted graph is obtained based on the following formula. : 。 5. A network attack defense method for smart meters according to claim 1, characterized in that, The method for generating a topology camouflage strategy and updating the loss function and inferred adjacency matrix of the monitoring strategy model includes the following steps: constructing a topology camouflage strategy model for the defender. ,in Indicates a node With nodes The communication link is disguised. This indicates that no camouflage is implemented; based on the camouflage strategy, a camouflaged adjacency matrix that is fully perceptible to the attacker is obtained: Based on the camouflage adjacency matrix, the set of observable information of the attacker under the influence of camouflage is obtained. : ; in the observable information set Next, the loss function of the attacker's monitoring strategy model is updated: The attacker's inferred adjacency matrix is ​​updated using the following formula: ;in, 。 6. A network attack defense method for smart meters according to claim 1, characterized in that, The method for obtaining the defender's total loss function including the path exposure loss term and the attacker's utility function including the attack cost term includes the following steps: Constructing the defender's total loss function including defense costs and losses caused by the attack. : ;in, Indicates the cost of defense. Indicates the damage caused by the attack; ; ; ; ; and These represent the costs of the defender employing strategies to conceal or forge communication relationships, respectively. The function satisfies: ; and These represent the unit cost of the defender employing strategies to conceal and forge communication relationships, respectively. Represents computation set The momentum; Indicates the first On the secondary data transmission link, the real path With the attacker's predicted path The number of intersection nodes between them This represents the potential loss that would result from an attacker successfully predicting the occurrence of a single node in the data transmission path. Indicates the first Secondary transmission task; construct attacker utility function : ; ;in, For the cost of attack, For the cost of a single listener, This represents the total number of nodes in the smart meter network.

7. A network attack defense method for smart meters according to claim 1, characterized in that, The attack-defense game model constructed based on the defender's total loss function and the attacker's utility function is as follows: Among them, the binary pair This represents the equilibrium solution of the model. For the attacker's equilibrium strategy, The optimal topology camouflage strategy for the defender.

8. A network attack defense method for smart meters according to claim 1, characterized in that, The method for solving the attack-defense game model using a genetic algorithm to obtain the optimal topology camouflage strategy is as follows: Initialize and set network parameters based on the real adjacency matrix. Calculate the source node and target node pairs for each transmission task. The actual data transmission path Initialize the attacker's monitoring strategy population and the defender's topology camouflage strategy population, and assign the attacker's monitoring strategy vector to each population. With the defender's topology camouflage matrix Encoded as individuals using a genetic algorithm; in each iteration of the genetic algorithm, based on the current attacker's listening strategy... Determine the set of monitored nodes And based on the current topology camouflage strategy Constructing attacker's local observation information The optimal Boolean characteristic matrix is ​​obtained by Boolean matrix decomposition. and The inferred adjacency matrix is ​​obtained. Based on the inferred adjacency matrix Calculate the predicted transmission path ; Based on the actual transmission path With the predicted transmission path Calculate path exposure loss term And based on this, calculate the total loss function of the defender. With attacker utility function ; While maintaining the current attacker's eavesdropping strategy Under the condition of invariance, minimize Topology camouflage strategy for fitness targets against defenders The population performs genetic iterations to obtain the defender update strategy; while maintaining the updated defender topology camouflage strategy. Under the condition of invariance, to maximize To achieve fitness targets, the attacker's monitoring strategy is implemented. The population undergoes genetic iteration to obtain the attacker's updated policy; the policy change between adjacent iterations is calculated. and When satisfied Alternatively, the iteration can stop when the maximum number of iterations is reached, and the equilibrium solution can be output. , in This is the optimal topology camouflage strategy.

9. A network attack defense device for smart meters, characterized in that, The device includes: a power grid model construction unit, used to acquire communication relationship data of the smart meter network within a preset time interval, construct a network topology model based on the communication relationship data, and generate a true adjacency matrix representing the communication connection relationship between smart meter nodes; an attack model construction unit, used to construct an attacker's monitoring strategy model, determine a set of monitored nodes based on the monitoring strategy model, and obtain local observation information obtainable by the attacker from the set of monitored nodes; and an attack inference unit, used to construct and optimize a Boolean feature matrix based on the local observation information. and This is done so that the Boolean product of the two approximates the original observation matrix, thus obtaining the optimal Boolean characteristic matrix. and The system comprises the following components: a defense model construction unit, which is used to construct a topology camouflage strategy model for the defender, generate a topology camouflage strategy, camouflage the local observation information available to the attacker based on the topology camouflage strategy, and update the loss function and inference adjacency matrix of the monitoring strategy model; a protection unit, which is used to obtain the real transmission path of the transmission task based on the real adjacency matrix, obtain the predicted transmission path based on the inference adjacency matrix, construct a path exposure loss term based on the degree of overlap between the real transmission path and the predicted transmission path; obtain the total loss function of the defender including the path exposure loss term and the utility function of the attacker including the attack cost term, and construct an attack-defense game model; and a protection execution unit, which is used to solve the attack-defense game model based on a genetic algorithm to obtain the equilibrium solution of the optimal topology camouflage strategy, and generate a protection strategy for the data transmission path based on the equilibrium solution.

10. A terminal device, characterized in that, The device includes a memory and a processor, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of the network attack defense method for smart meters as described in any one of claims 1 to 8.