Data-driven hostile attack detection and containment control method for distributed energy storage system

By establishing a nonlinear interconnected system model using a data-driven approach and designing a restraint controller, the problem of malicious attacks in distributed energy storage systems was solved, and the system's security, stability, and synchronization performance were improved.

CN122020647APending Publication Date: 2026-05-12HAINAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HAINAN UNIV
Filing Date
2025-12-25
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In the process of networked collaborative control, existing distributed energy storage systems face the concealment and randomness of malicious network attacks, which traditional model-based monitoring methods cannot effectively handle, thus affecting the system's synchronization stability. Moreover, most existing studies have not considered nonlinear and non-monotonic characteristics.

Method used

A nonlinear interconnected system model is established using a data-driven approach. A data-driven malicious attack detection and restraint controller is designed. By propagating control signals from some key nodes, the impact of malicious attacks is suppressed, and the system stability and synchronization performance are improved.

Benefits of technology

It enables flexible identification and effective suppression of malicious attacks, improves the robustness of distributed energy storage systems and the reliability of network data, and ensures the safe and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122020647A_ABST
    Figure CN122020647A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automation, and discloses a data-driven hostile attack detection and containment control method, which comprises the following steps of: firstly, establishing a state space model of a distributed energy storage system, and constructing a data representation form of the system by using input / output data collected by an open-loop experiment on the premise of not acquiring an accurate physical model of the system; secondly, an attack detection mechanism based on data driving is designed, and sparse reconstruction and accurate estimation of an unknown hostile attack matrix are realized by constructing a dynamic residual vector and solving a minimum absolute shrinkage and selection operator problem. On the basis, a hierarchical containment control strategy which depends on an attack estimation value and is based on a switching gain observer is provided, and only key nodes in the network are controlled so as to suppress attack diffusion. And finally, constructing an augmented error system comprising a synchronization error and an attack estimation error, and deducing sufficient conditions for ensuring global asymptotic stability of the system by using a Lyapunov stability theory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automation technology, and in particular to a data-driven malicious attack detection and control method for distributed energy storage systems. Background Technology

[0002] Distributed energy storage systems utilize modern power electronics technology, automatic control methods, battery management technology, and cloud computing platforms to achieve energy exchange and information sharing between energy storage units, the power grid, users, and the cloud platform. Through devices such as voltage and current sensors, temperature probes, and BMS terminals installed on the energy storage units, they collect battery state of charge (SOC) information and external power demand information, and transmit this information to adjacent energy storage nodes, energy management systems, or the cloud platform via a network system. Currently, distributed energy storage systems are widely used in microgrids and renewable energy consumption, making a significant contribution to building a new power system dominated by renewable energy. The development of distributed energy storage systems is rapid due to the increasing demand for peak and frequency regulation from the power grid, and the increasingly higher requirements from users for power quality and reliability, which traditional rigid power sources can no longer meet. Distributed energy storage systems mainly improve the flexibility of energy utilization and reduce wind and solar curtailment by directly exchanging information on power allocation, SOC balancing, voltage recovery, and grid synchronization through the network. It is worth noting that in the process of networked collaborative control, it is necessary to strengthen the control of the system's anti-attack capability. This requires the design of complete data communication and security defense methods to ensure the effectiveness of data transmission and system consistency between distributed energy storage systems.

[0003] With the network-based development of distributed energy storage technology, the interaction of status data between energy storage units via communication networks not only faces privacy challenges such as data tampering, but also new security issues such as the increasing number of malicious network attacks targeting the collaborative control layer of energy storage systems in recent years. To overcome these problems, this invention proposes a data-driven malicious attack detection method. As a data-driven control model, it does not require identification of the first-principles model of the energy storage system, but directly analyzes the charging and discharging process data, making the identification of attack characteristics of distributed energy storage systems more flexible and realistic. Data from distributed energy storage systems during operation is characterized by rapid dynamic changes, high coupling, and high synchronization requirements. Due to the complexity of the network environment and the covert nature of attack methods, traditional model-based monitoring methods cannot effectively handle various attacks affecting system synchronization and stability. Therefore, proposing a feasible data-driven malicious attack detection combined with a restraint control method is of great significance for preventing malicious attacks from causing frequency / voltage runaway in energy storage clusters, improving the reliability of network data, and enhancing system robustness.

[0004] Data-driven control is a business decision-making and action approach based on lean analytics and data closed-loop principles. Its core lies in utilizing massive amounts of data for extraction, insight, and prediction. It emphasizes both data quantity and quality, exhibiting adaptive and flexible characteristics, and employs machine learning algorithms for pattern recognition and prediction. Compared to traditional data-driven methods, data-driven approaches do not rely on predefined, precise physical models. Constraint control, by controlling only a subset of key nodes in the network (constraint nodes), propagates control signals throughout the entire network, thereby mitigating the impact of malicious attacks at a lower cost, improving the stability of the control system, and achieving good synchronization performance. Combining these two approaches can largely address the shortcomings of existing technologies. Figure 1 (See attached diagram in the manual) A schematic diagram of the communication topology of the distributed energy storage system is shown; Figure 2 (See attached diagram in the specification) is a data-driven attack detection and restraint control structure diagram based on distributed system theory in this invention. For an energy storage network system, various attack scenarios exist during data transmission. Researchers have developed numerous related solutions, such as observer-based residual analysis and model-based attack reconstruction techniques. However, it is worth noting that these methods are based on a specific single or linearized model, while real-world energy storage batteries are highly nonlinear and their parameters decay over time. Furthermore, malicious network attacks are random and stealthy, indicating that network systems possess characteristics such as unpredictability and nonlinearity. Therefore, within this framework, a data-driven detection model can be directly designed using distributed process data, making it particularly important to use a data-driven restraint controller to describe such problems. Moreover, in most cases, existing research only focuses on cooperative control under attack-free conditions, but such designs may not be suitable for interconnected systems with malicious nodes. To better address these shortcomings, while ensuring system synchronization, we combine this with a restraint control strategy to effectively solve the problem of malicious node propagation and is applicable to nonlinear and non-monotonic distributed energy storage systems.

[0005] In summary, this invention proposes a data-driven approach to model a class of distributed energy storage nonlinear interconnected systems, and suggests a method for malicious attack detection and containment control. Real-time monitoring and containment control of the interconnected system improves its efficiency and security in resisting malicious network attacks, ensuring the stability of the distributed energy storage system's operation. Summary of the Invention

[0006] To address the technical problems of nonlinearity, non-monotonicity, and vulnerability to attacks in existing distributed energy storage systems on networks, this invention provides a data-driven malicious attack detection and control method for distributed energy storage systems, comprising the following steps:

[0007] Step 1: Establish the state-space model of the distributed energy storage system;

[0008] Step 2: Collect input / output data during the state-space model running experiment;

[0009] Step 3: Design attack detection methods and restraint controllers for distributed energy storage systems;

[0010] Step 4: Construct a synchronization error system for the distributed energy storage system;

[0011] Step 5: Design the conditions for the safe and stable operation of the distributed energy storage system;

[0012] Step 6: Design the controller for the distributed energy storage system.

[0013] The advantages and beneficial effects of this invention are as follows:

[0014] To address the challenges of unknown nonlinear interconnected systems in current distributed systems, this paper proposes a nonlinear interconnected system model built using data-driven technology. First, a data-driven malicious attack detection method is designed. Then, a data-driven restraint controller is designed to ensure that, in the event of a malicious attack on some subsystems, the system can be designed directly using data without needing to identify the first-principle model, thereby enabling the system to operate safely and stably. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the communication topology of the distributed energy storage system in this invention;

[0016] Figure 2 This is an architecture diagram of the data-driven attack detection and control method based on distributed system theory in this invention. Detailed Implementation

[0017] The present invention will be further described below with reference to specific embodiments, but the invention is not limited to these specific embodiments. Those skilled in the art should recognize that the present invention covers all alternatives, improvements, and equivalents that may be included within the scope of the claims.

[0018] This embodiment provides a data-driven malicious attack detection and control method for distributed energy storage systems, with the following specific steps:

[0019] Step 1: Establish the state-space model of the distributed energy storage system.

[0020] Step 1.1: First, establish a nonlinear interconnected system consisting of N subsystems within the distributed energy storage system. The information flow between the subsystems is represented by an undirected graph. It means that, among them Represents a set of subsystems. Denotes the edge set, while Then it is the adjacency matrix. If the subsystem v iWith v j If there is an information link between them, then d ij =d ji =1; otherwise d ij =0. Furthermore, for all i∈[1,N], d ii =0. Let If the set of attacked subsystems is... Let represent the set of normal subsystems. The dynamic description of the i-th subsystem is as follows:

[0021]

[0022] in, This indicates the shift operator; Let k be the state of the i-th subsystem of the distributed energy storage system at time k, and let k be the initial state. n i Let i be the state dimension of the i-th subsystem. Let be the input amount of the data packet in the i-th subsystem of the distributed energy storage system at time k. The space consisting of ∞-order summable sequences, m i The amount of data input to the i-th subsystem, and Let k be the number of data points obtained by the i-th subsystem of the distributed energy storage system through sensors at time k. and for q represents the components from 0 to M. i Let be the dimension of the measurement data obtained for the i-th subsystem; External disturbances To output the relevant external disturbances, For time-varying parameters, Having a diagonal structure As a continuous function, it is ensured that system (1) has at least a local solution in the positive time; for as well as for It is an unknown continuous matrix function. For system (1), if the i-th subsystem can receive information from the j-th subsystem, then A ij,o ≠0; otherwise A ij,o =0. Assume (A) i,o B i ) is controllable, and (A) i,o C i,o ) Observable. For simplicity, let k0 = ni And f 0 (x i )=x i .

[0023] The nonlinearity in a distributed energy storage system satisfies the following sector condition: For any and This condition indicates that the nonlinear term is zero only when the state is zero. For f z After appropriate re-indexing and decomposition, there exist integers. Make For all and It is true, and there exists an integer. Make For all and This holds true. Therefore, at least one nonlinear term exists that is unbounded in the radial direction; while when ε = 0, all nonlinear terms are bounded. This invention assumes that the sector nonlinearity satisfies the following stronger incremental sector condition: For all and Established.

[0024] Step 1.2: To generalize the problem to one with measurable scheduling parameters θ i Distributed energy storage system, denoted as θ i ∈Θ i ,in It is a known compact set. Furthermore, let... and in and for and satisfy

[0025] Step 1.3: Consider some subsystems in the distributed energy storage system. Suffering a malicious attack. A malicious attack can disrupt the overall system synchronization by injecting false data or manipulating the state. m The dynamic description of an attacked subsystem is as follows:

[0026]

[0027] in, and Malicious attacks are vector-based Modeling, in which This is a malicious attack matrix. For each subsystem that has been attacked... A true malicious attack matrix H can be obtained. i The estimated value Furthermore, the true matrix H i and its estimation error All satisfy the norm boundedness property, where the error is defined as The boundedness of this norm can be expressed as the inequality ||H|| i ||≤δ i and Where δ i ≥0 and It is a known constant.

[0028] Step 1.4: Based on step 1.2, system (1) can be restated as follows:

[0029]

[0030] in, as well as

[0031] Step 2: Collect the input / output data of each subsystem through the open-loop experiment of system (3) in step 1:

[0032]

[0033]

[0034] Based on the above data and applying the theory of system behavior, we can obtain

[0035]

[0036] For (4), the noise sequence and Unknown but possessing bounded energy: in, and These are known constants. Furthermore, the nonlinear data matrix... The following data-based sector conditions must be met: Through the With appropriate relabeling and decomposition, there exists Make For all and Established and existing Make For all and This holds true. Nonlinear data satisfies the following stronger data-based incremental sector condition:

[0037] Step 2.1: To obtain data with sufficient condition numbers, assume the matrix... and All are full-rank matrices, where, It is a constant. It is a set of complex numbers.

[0038] Step 2.2: Consider methods for parameterizing the covariance of the collected data to effectively utilize the collected data. The sample covariance matrix is ​​defined as follows:

[0039]

[0040] Define the following matrix:

[0041]

[0042] Then,

[0043]

[0044] in, and

[0045] Step 2.3: Construct a data representation of the unknown system matrix using system behavior theory, in the following form:

[0046] make In step 2.1, the matrix It is a pseudo-inverse. Definition Combining equation (6), we can obtain: and then,

[0047] in

[0048] as well as

[0049] Step 2.4: For clarity, define a matrix. as well as Therefore, there is as well as

[0050] Step 2.5, set and The system in step 1.4 can then be restated as follows:

[0051]

[0052] in, and

[0053] Step 2.6: Based on the system matrix in Step 2.4, the system in Step 2.5 can be rewritten as follows:

[0054]

[0055] Step 2.7: Using steps similar to (6), the data representation of the attacked subsystem can be obtained:

[0056]

[0057] in,

[0058] Step 3: Establish a data-driven attack detection method and restraint controller for the distributed energy storage system, which is constructed as follows:

[0059] Step 3.1: Establish a data-driven attack detection method for distributed energy storage systems. First, for each subsystem subjected to malicious attack... Calculate dynamic residuals

[0060]

[0061] Next, the residuals are combined into a composite vector Y. total Composite vector Y total It can be defined as:

[0062]

[0063] Similarly, a composite regression matrix Φ is constructed by vertically stacking the Kronecker products of the subsystems that have been maliciously attacked. total :

[0064] This transformation converts the problem into a single large-scale linear regression form: Y total ≈Φ total χ, where the unknown malicious behavior parameter vector χ = vec(H). The unknown parameter vector χ can be estimated by solving the following minimum absolute contraction and selection operator problem:

[0065]

[0066] Finally, by expressing the solution vector... By reshaping it into an m×n matrix, the matrix can be reconstructed. This process provides a unique and accurate estimate of the true malicious behavior matrix H, thereby enabling the detection of malicious attacks.

[0067] Step 3.2: For the first-principles model of the distributed energy storage system, establish a hierarchical restraint controller based on a switching gain observer. The system under consideration is an unknown distributed system composed of N subsystems, which are divided into two mutually exclusive groups. The set of all subsystems... It is divided into two disjoint subsets: the health subsystem set. and subsystems subjected to malicious attacks The total set of subsystems is the union of healthy subsystems and malicious subsystems, that is... This model also allows for cross-group coupling, meaning that two groups of subsystems can interact. The model relies on the mathematical formula for a hierarchical restraint controller based on a switched gain observer, as follows:

[0068]

[0069] in, It is an estimate of x; and The observation gain to be designed; and The gain of the controller to be designed; It is an estimate of the unknown malicious behavior matrix; when λ i >0 and When λ indicates that the i-th subsystem is in a constrained state; when λ i =0 and When the time is right, it means that the subsystem is not constrained.

[0070] Step 3.3: Using the data representation of the unknown system matrix established in steps 2.3 and 2.4, establish a data-driven hierarchical restraint controller based on a switched gain observer:

[0071]

[0072] in, λ=diag{λ1,…,λ N},

[0073] Step 4: Construct a synchronization error system for the distributed energy storage system, as detailed below:

[0074] Step 4.1, Define the error term as follows:

[0075] θf z (e)=f z (x m(t)+e)-f z (x m ), and e = xx m .set up The synchronization error system of the distributed energy storage system can then be expressed as:

[0076]

[0077] in,

[0078] and

[0079]

[0080] Step 4.2 In order to effectively handle the nonlinear terms based on the data system, the following constraints are introduced: (1) There exists a symmetric matrix Make the nonlinear function f z (η) satisfies the following quadratic inequality: (2) Function f z It has global Lipschitz continuity, that is, there exists a constant ν. z >0, making it true for all and The following inequalities hold: ||f z (y)-f z (x)‖≤ν z ‖yx‖.

[0081] Step 5: Design the safe and stable operating conditions for the distributed energy storage system, as follows:

[0082] If step 2.1 holds true, then the design constant κ > 0. matrix sum matrix function

[0083] Make

[0084] For all and If this holds true, then the distributed energy storage system is globally asymptotically stable, where...

[0085]

[0086] Step 6: Based on the previous steps, design the controller for the distributed energy storage system.

[0087] If step 2.1 holds true, then the design constant κ > 0. matrix sum matrix function Make

[0088] For all and If established, then under the action of the data-driven constraint controller, the distributed energy storage system possesses global asymptotic stability, and its controller form is as follows:

[0089]

[0090] in,

[0091]

[0092]

Claims

1. A method for detecting and controlling data-driven malicious attacks in a distributed energy storage system, characterized in that... Includes the following steps: Step 1: Establish the state-space model of the distributed energy storage system; Step 2: Collect input / output data during the state-space model running experiment; Step 3: Design attack detection methods and restraint controllers for distributed energy storage systems; Step 4: Construct a synchronization error system for the distributed energy storage system; Step 5: Design the conditions for the safe and stable operation of the distributed energy storage system; Step 6: Design the controller for the distributed energy storage system.

2. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 1, characterized in that: Step 1 is as follows: Step 1.1: First, establish a nonlinear interconnected system consisting of N subsystems in the distributed energy storage system. The information flow between the subsystems is represented by an undirected graph. It means that, among them Represents a set of subsystems. Denotes the edge set, while It is the adjacency matrix; if the subsystem v i With v j If there is an information link between them, then d ij =d ji =1; otherwise d ij =0; for all i∈[1,N], d ii =0; let If the set of attacked subsystems is... This represents the set of normal subsystems; the dynamic description of the i-th subsystem is as follows: in, This indicates the shift operator; Let k be the state of the i-th subsystem of the distributed energy storage system at time k, and let k be the initial state. n i Let i be the state dimension of the i-th subsystem. Let be the input amount of the data packet in the i-th subsystem of the distributed energy storage system at time k. The space consisting of ∞-order summable sequences, m i The amount of data input to the i-th subsystem, and Let k be the number of data points obtained by the i-th subsystem of the distributed energy storage system through sensors at time k. and for q represents the components from 0 to M. i Let be the dimension of the measurement data obtained for the i-th subsystem; External disturbances To output the relevant external disturbances, For time-varying parameters, Having a diagonal structure As a continuous function, it is ensured that the system has at least a local solution in the positive time. for as well as for It is an unknown continuous matrix function; if the i-th subsystem can receive information from the j-th subsystem, then A ij,o ≠0; otherwise A ij,o =0; Assume (A) i,o B i ) is controllable, and (A) i,o C i,o ) Observable; let k0 = n i And f 0 (x i )=x i ; The nonlinearity in a distributed energy storage system satisfies the following sector condition: For any and This condition indicates that the nonlinear term is zero only when the state is zero; for f z After appropriate re-indexing and decomposition, there exist integers. Make For all and It is true, and there exists an integer. Make For all and If ε holds true, then at least one nonlinear term is unbounded in the radial direction; while when ε = 0, all nonlinear terms are bounded; assume that the sector nonlinearity satisfies the following stronger incremental sector condition: For all and Established; Step 1.2, with measurable scheduling parameters θ i Distributed energy storage system, denoted as θ i ∈Θ i ,in Let be a known compact set; and in and for and satisfy Step 1.3: Consider some subsystems in the distributed energy storage system. Suffering from a malicious attack; a malicious attack disrupts the overall system synchronization by injecting false data or manipulating the state, i.e., the... m The dynamic description of an attacked subsystem is as follows: in, and Malicious attacks are vector-based Modeling, in which This is a malicious attack matrix; for each attacked subsystem... A true malicious attack matrix H can be obtained. i The estimated value Real matrix H i and its estimation error All satisfy the norm boundedness property, where the error is defined as The boundedness of this norm is expressed by the inequality ||H|| i ||≤δ i and Where δ i ≥0 and These are known constants; Step 1.4: Based on step 1.2, the system can be restated as follows: in, as well as 3. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 2, characterized in that: In step 2, input / output data for each subsystem is collected through the open-loop experiment conducted in step 1: Based on the above data and applying the theory of system behavior, we can obtain For equation (4), the noise sequence W i - and V i - Unknown but possessing bounded energy: in, and Given constants; nonlinear data matrix The following data-based sector conditions must be met: Through the With appropriate relabeling and decomposition, there exists Make For all and Established and existing Make For all and It holds true; nonlinear data satisfies the following data-based incremental sector conditions:

4. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 3, characterized in that: Step 2 is as follows: Step 2.1, Assumption Matrix and All are full-rank matrices, where, It is a constant. It is a set of complex numbers; Step 2.2, the sample covariance matrix is ​​defined as follows: Define the following matrix: Then, in, and Step 2.3: Construct a data representation of the unknown system matrix using system behavior theory, in the following form: make In step 2.1, the matrix It is a pseudo-inverse; definition Combining equation (6), we can obtain: and but in as well as Step 2.4, Define the matrix as well as but as well as Step 2.5, set and The system in step 1.4 can then be restated as follows: in, and Step 2.6: Based on the system matrix in Step 2.4, the system in Step 2.5 can be rewritten as follows: Step 2.7: Using a similar process to formula (6), obtain the data representation of the attacked subsystem: in, 5. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 4, characterized in that: The construction format in step 3 is as follows: Step 3.1: Establish a data-driven attack detection method for distributed energy storage systems; firstly, for each subsystem subjected to malicious attack... Calculate dynamic residuals Next, the residuals are combined into a composite vector Y. total Composite vector Y total It can be defined as: Similarly, a composite regression matrix Φ is constructed by vertically stacking the Kronecker products of the subsystems that have been maliciously attacked. total : This transformation converts the problem into a single large-scale linear regression form: Y total ≈Φ total χ, where the unknown malicious behavior parameter vector χ = vec(H), can be estimated by solving the following minimum absolute contraction and selection operator problem: Finally, by expressing the solution vector... By reshaping it into an m×n matrix, the matrix can be reconstructed. Step 3.2: For the first-principles model of the distributed energy storage system, establish a hierarchical restraint controller based on a switching gain observer, which is the model dependency; a set of all subsystems. It is divided into two disjoint subsets: the health subsystem set. and subsystems subjected to malicious attacks The total set of subsystems is the union of healthy subsystems and malicious subsystems, that is... This model also allows cross-group coupling, meaning that two groups of subsystems can interact; the model relies on the following formula for a hierarchical restraint controller based on a switched gain observer: in, It is an estimate of x; and The observation gain to be designed; and The gain of the controller to be designed; It is an estimate of the unknown malicious behavior matrix; when λ i >0 and When λ indicates that the i-th subsystem is in a constrained state; when λ i =0 and When this occurs, it indicates that the subsystem is not constrained; Step 3.3: Using the data representation of the unknown system matrix established in steps 2.3 and 2.4, establish a data-driven hierarchical restraint controller based on a switched gain observer: Among them, λ=diag{λ1,…,λ N }, 6. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 5, characterized in that: Step 4 is as follows: Step 4.1, Define the error term as follows: θf z (e)=f z (x m (t)+e)-f z (x m ), and e = xx m ;set up The synchronization error system of the distributed energy storage system can then be expressed as: in, and Step 4.2 In order to effectively handle the nonlinear terms based on the data system, the following constraints are introduced: (1) There exists a symmetric matrix Make the nonlinear function f z (η) satisfies the following quadratic inequality: (2) Function f z It has global Lipschitz continuity, that is, there exists a constant ν. z >0, making it true for all and The following inequalities hold: ||f z (y)-f z (x)‖≤ν z ‖yx‖.

7. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 6, characterized in that: Step 5 is as follows: If step 2.1 holds true, then the design constant κ > 0. matrix sum matrix function Make For all and If this holds true, then the distributed energy storage system is globally asymptotically stable, where...

8. The method for detecting and controlling data-driven malicious attacks in a distributed energy storage system as described in claim 7, characterized in that: The controller for the distributed energy storage system is designed in step 6 as follows: If step 2.1 holds true, then the design constant κ > 0. matrix sum matrix function Make For all and If established, then under the action of the data-driven constraint controller, the distributed energy storage system possesses global asymptotic stability, and its controller form is as follows: in,