A wind farm wide-area control system network attack detection method

By using the phase trajectory and time-frequency response of the Duffing oscillator system, combined with improved cross terms and Poincaré mapping, the problem of distinguishing between real broadband oscillations and network attacks in the wide-area control system of wind farms is solved, improving the reliability and robustness of detection.

CN122437679APending Publication Date: 2026-07-21SOUTH CHINA UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SOUTH CHINA UNIV OF TECH
Filing Date
2026-04-13
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing detection methods struggle to distinguish between genuine broadband oscillations and network attack-induced oscillations in the wide-area control system of wind farms, and are highly dependent on accurate system models and historical data, leading to misjudgments and covert sabotage.

Method used

By using the phase trajectory and time-frequency response of the Duffing oscillator system, subsynchronous and supersynchronous oscillations can be distinguished, and by combining the improved cross-terms and Poincaré mapping of the Duffing oscillator system, oscillations caused by network attacks can be identified.

Benefits of technology

It achieves accurate differentiation between real oscillations and attack-induced oscillations without relying on precise system models and a large amount of historical data, thus improving the reliability and robustness of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437679A_ABST
    Figure CN122437679A_ABST
Patent Text Reader

Abstract

The application discloses a wind farm wide-area control system network attack detection method, comprising the following steps: building a power system model of two-area multi-synchronous generator integrated wind farms; defining wide-area signals as input signals of wide-area damping control; designing a first layer detection scheme based on intermittent chaos theory of a Duffing oscillator system to distinguish subsynchronous oscillation and supersynchronous oscillation; and on this basis, designing a second layer detection scheme based on an improved Duffing oscillator system to judge the authenticity of oscillation. The application can provide a reliable reference for safe and stable operation of a power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of power system network security, and in particular to a method for detecting network attacks on a wide area control system of a wind farm. Background Technology

[0002] With the rapid development and large-scale grid connection of renewable energy, the proportion of new energy sources, represented by wind power, in the power system continues to increase, gradually becoming an important pillar of the new power system. While large-scale wind power grid connection optimizes the energy structure, the dense use of power electronic devices in grid-connected converters also causes the power grid to exhibit low inertia and weak damping dynamic characteristics. System stability issues have expanded from traditional low-frequency oscillations to broadband oscillations covering subsynchronous, supersynchronous, and even higher frequency bands. These oscillations usually originate from the complex dynamic interaction between the wind turbine's fast control loop and the grid impedance, and are characterized by multimodal interleaving, strong nonlinearity, and complex mechanisms, becoming a new challenge threatening the safe and stable operation of the power grid.

[0003] Meanwhile, the continuous improvement of the informatization and intelligentization level of power systems has made wide-area control systems increasingly reliant on high-speed communication networks, which has also significantly expanded the system's exposure to network attacks. Among these attacks, False Data Injection Attacks (FDIA), by maliciously tampering with or injecting false measurement data and control commands, undermine the accuracy, real-time performance, and stability of control, and have become one of the most threatening network attack methods against wide-area control systems. FDIA can not only directly lead to the deterioration of control loop performance, but can also be carefully constructed to induce or disguise inherent broadband oscillations in the system, thereby masking malicious behavior, prolonging latency, and even triggering cascading failures, seriously threatening the overall security of the power system.

[0004] Currently, detection methods for FDIA can be mainly divided into two categories: model-driven and data-driven. Model-driven methods rely on accurate mathematical models of the system and identify data anomalies by designing state estimators, observers, or residual generation mechanisms, such as methods based on unknown input estimators and robust observers. However, these methods require high precision in the system model and accuracy of its parameters. In situations where the operation modes of new energy power plants are highly variable and the model parameters are highly uncertain, their reliability and adaptability face challenges. Data-driven methods utilize machine learning, deep learning, and other technologies to learn the characteristic differences between normal and attack patterns from large amounts of historical data, such as detection models based on convolutional neural networks and graph neural networks. These methods reduce the reliance on accurate analytical models, but typically require a large amount of labeled data for training and have poor interpretability. When facing novel, highly concealed FDIAs, especially those that can highly simulate real broadband oscillation characteristics, their generalization ability and detection performance may be insufficient. Crucially, most existing detection methods focus on identifying abnormal or specific frequency components in signals, lacking the ability to discern the physical source of the oscillation. That is, they struggle to fundamentally distinguish whether the frequency component originates from genuine broadband oscillations generated by the interaction between power electronic equipment and the power grid, or from a carefully crafted and injected spoofed signal by an external attacker. This deficiency can lead to misjudgments or malfunctions in protection systems, and also creates opportunities for attackers to exploit inherent system oscillations as cover for long-term, covert sabotage. Therefore, current research is insufficient in detecting network attacks that can simulate actual broadband oscillations.

[0005] In summary, there is currently a lack of a detection method that does not rely on an accurate system model, does not require a large amount of historical attack data, and can distinguish between real oscillations and attack-induced oscillations from the perspective of the nonlinear physical nature of the signal. Summary of the Invention

[0006] The purpose of this invention is to provide a method for detecting network attacks on a wide-area control system of a wind farm. By analyzing the phase trajectory and time-frequency response of the Duffing oscillator system, it can distinguish between subsynchronous and supersynchronous oscillations, and further determine whether the oscillation is caused by a network attack. This method can provide a reliable reference for the study of broadband oscillations in power systems and the safe and stable operation of the system.

[0007] To achieve the above objectives, the technical solution provided by this invention is: a method for detecting network attacks on a wide-area control system of a wind farm, comprising the following steps:

[0008] Step 1: Construct a power system model of a wind farm integrating multiple synchronous generators in two regions, 1 and 2; when broadband oscillations occur in the power system models of regions 1 and 2, obtain the rotational speed of synchronous generator SG1 in region 1. and the rotational speed of synchronous generator SG2 in region 2. Define wide-area signals As the input signal for wide-area damping control, t is the oscillation time of the power system model;

[0009] Step 2: Acquire the wide-area signal Input the data into the Duffing oscillator system, analyze the phase trajectory and time-domain response of the Duffing oscillator system output, and determine whether the broadband oscillation occurring in the power system model is a subsynchronous oscillation or a supersynchronous oscillation based on the analysis results; based on the determination results, set the excitation term frequency for the improved Duffing oscillator system in step 3.

[0010] Step 3: An improvement is made by introducing a cross term into the Duffing oscillator system described in Step 2. This cross term enhances the Duffing oscillator system's ability to detect nonlinear terms; it also improves the wide-area signal... The input is fed into the improved Duffing oscillator system. Based on the phase trajectory and time-domain response output by the improved Duffing oscillator system, it is determined whether the broadband oscillations occurring in the power system model are caused by a network attack.

[0011] Furthermore, in step 1, the wind farm adopts doubly-fed asynchronous wind turbines; both area 1 and area 2 contain multiple synchronous generators, and energy exchange between area 1 and area 2 is achieved through a 220km interconnection line; and The signal is acquired via a phasor measurement unit (PMU). The wide-area signal sequentially passes through a filter, compensation circuit, gain module, and limiting module. These components together constitute the wide-area damping control, ultimately outputting the power change. It participates in the vector control of the subsequent rotor-side converter.

[0012] Furthermore, in step 2, the equations of the Duffing oscillator system are as follows:

[0013] ;

[0014] In the formula, Let t be the time-domain response of the Duffing oscillator system. Let t be an intermediate variable of the Duffing oscillator system. for The first derivative, for The first derivative of , where k1 is the damping ratio; The nonlinear restoring force; the wide-area signal F(t) is the external input signal to be detected, called the signal to be detected; The excitation term built into the Duffing oscillator system at time t is... For the incentive amplitude, For the frequency of the excitation term;

[0015] With amplitude As the value increases, the Duffing oscillator system will successively exhibit a chaotic state, a critical periodic state, and a large periodic state. The chaotic state indicates that the Duffing oscillator system is in a non-periodic and unpredictable state. The critical periodic state is the bifurcation boundary where the Duffing oscillator system transitions from a chaotic state to periodic motion. The large periodic state indicates that the Duffing oscillator system is in regular periodic motion. Adjusting... The value of causes the Duffing oscillator system to enter the critical period state. In this state, the Duffing oscillator system is extremely fragile. When the signal to be detected F(t) contains a signal with the same frequency as the excitation term, even if the amplitude is weak, it will act as a synchronous excitation to break the critical equilibrium and drive the Duffing oscillator system to significantly transition from the critical period state to the large period state.

[0016] Frequency of the signal to be detected Not equal to the set frequency of the excitation term Let the signal to be detected at time t be... , The amplitude of the signal to be detected. The phase of the signal to be detected; the total excitation of the Duffing oscillator system. The superposition of the signal to be detected and the built-in excitation term is represented as:

[0017] ;

[0018] In the formula, Let be the magnitude of the total excitation term at time t. The frequency difference between the signal to be detected and the excitation term. The phase of the total excitation term at time t; the total excitation term amplitude As the periodic changes over time occur, the value cannot remain above the threshold required to maintain a large periodic state. As a result, the Duffing oscillator system cannot operate in a single large periodic state, but instead exhibits a dynamic behavior that alternates between periodic motion and chaotic state, i.e., intermittent chaos.

[0019] The critical conditions for chaotic motion in the Duffing oscillator system are analyzed using the Melnikov method. First, the Duffing oscillator system is dimensionless, and its dimensionless Duffing oscillator equations are as follows:

[0020] ;

[0021] In the formula, The time-domain response of the dimensionless Duffing oscillator equations. As an intermediate variable in the dimensionless Duffing oscillator equation, for The first derivative, for The first derivative; The damping ratio is dimensionless. This represents the magnitude of the built-in excitation term after dimensionless transformation; The amplitude of the signal to be detected after dimensionless scaling. The phase of the signal to be detected after dimensionless transformation. Frequency of the signal to be detected Frequency of excitation terms The ratio;

[0022] Based on the dimensionless Duffing oscillator equation, the Melnikov equation is derived as follows:

[0023] ;

[0024] In the formula, The distance characterizing the stable and unstable manifolds of a dimensionless Duffing oscillator system. , and Represent , and The Melnikov equation, Let be the delay of the Melnikov function, and ; The dimensionless Duffing oscillator equation at time t The solution obtained at that time for The first derivatives of and are expressed as follows:

[0025] ;

[0026] right Using Euler's formula, then:

[0027] ;

[0028] In the formula, The imaginary unit;

[0029] make , for The one-sided integral function, due to If it is an odd function, then:

[0030] ;

[0031] Will Substitute the changed expression back into From the expression, we get:

[0032] ;

[0033] Similarly, ;

[0034] For the Melnikov function, the threshold condition for chaos to occur corresponds to the existence of a certain moment... Make Established; Ordered , express The effective weights contributed by the chaos threshold are then equivalent to: Established; for The amplitude, in When less than 1 The function value increases, therefore, when the frequency of the signal to be detected is less than the frequency of the excitation term, i.e. Duffing oscillator systems are more likely to satisfy the chaos threshold condition, and their dynamic behavior tends to be in an intermittent chaotic state; while when They tend to maintain a long-cycle state;

[0035] By setting the excitation frequency of the Duffing oscillator system to the synchronous frequency, the Duffing oscillator system will exhibit different motion states when the frequency of the signal to be detected is within the subsynchronous oscillation range and the supersynchronous oscillation range, respectively, thus distinguishing the oscillation type of the signal to be detected.

[0036] Furthermore, in step 2, the periodic state time ratio (PSTR) is used as a feature quantity to distinguish the different response states of the Duffing oscillator system caused by subsynchronous oscillations and supersynchronous oscillations. This periodic state time ratio characterizes the proportion of time the Duffing oscillator system output is in a large-period state within a given observation time, and its expression is:

[0037] ;

[0038] In the formula, The duration of the large-cycle state; Total testing time; This represents the number of state detection points for a large-cycle period. This represents the total number of detection points;

[0039] Calculate the frequency respectively. and Periodic state time ratio and Take the arithmetic mean of the two. The decision threshold for classification is used; finally, the criterion for distinguishing between subsynchronous oscillations and supersynchronous oscillations is formally expressed as:

[0040] .

[0041] Furthermore, in step 3, the equations for the improved Duffing oscillator system are:

[0042] ;

[0043] In the formula, The improved time-domain response of the Duffing oscillator system at time t. For the intermediate variables of the improved Duffing oscillator system at time t, for The first derivative, for The first derivative; and The damping ratio and frequency of the improved Duffing oscillator system are respectively. Let be the excitation term at time t. The amplitude; For the introduced cross terms, The nonlinear enhancement factor; the function of the cross term is to improve the output of the Duffing oscillator system by introducing Volterra series analysis. It can be represented as the input signal Historical values ​​expanded:

[0044] ;

[0045] In the formula, The nth-order Volterra kernel represents the nth-order nonlinear response of the improved Duffing oscillator system. Let i be the i-th integration variable. ; The output component representing the contribution of the nth-order kernel;

[0046] Incentive items The known intrinsic excitation of the improved Duffing oscillator system is used to maintain the critical periodic state of the oscillator; therefore, the signal to be detected is analyzed using Volterra series analysis. When considering the additional response caused by the improved Duffing oscillator system, the focus is on its impact on the nonlinear order of the improved system; this is based on the symmetry constraint of the standard Duffing oscillator system, i.e., when... Become , Similarly, it becomes This symmetry constraint results in all even-order Volterra kernels. It must be zero. Otherwise, the response of the corresponding order will not meet the requirement of synchronous symbol change, thus contradicting the system structure; for the improved Duffing oscillator system, its symmetry is actively broken, and the output will be... Substituting the expansion terms into the equations of the improved Duffing oscillator system and balancing the terms according to their order clearly reveals the influence of structural changes on the nonlinear response of the system. The result after balancing the second-order terms is expressed as follows:

[0047] ;

[0048] In the formula, The output component contributed by the second-order kernel at time t. The output component contributed by the second-order kernel at time t. for The first derivative, for The second derivative; due to the cross term With the existence of , the second-order Volterra kernel is no longer constrained by symmetry and must be zero; the symmetry is broken, and the second-order kernel h2 is no longer zero; similarly, the other even-order kernels are also not zero, and the nonlinear response described by the odd-order kernels is further enhanced.

[0049] Furthermore, in step 3, based on the stability index of the Poincaré map as a criterion feature, the following steps are performed to quantify the differences in the dynamic behavior of the improved Duffing oscillator system:

[0050] Step 3.1: At times that are integer multiples of the period of the excitation term of the improved Duffing oscillator system, record the value of the output signal to form a mapping point set: , For the improved Duffing oscillator system The time-domain response output at each moment. ;

[0051] Step 3.2: Calculate the standard deviation of the mapping point set. , The average value of the mapped points;

[0052] Step 3.3: Define the stability index as The larger the S value, the more concentrated the mapping points are, the more stable the system output is, and the more it tends to move periodically; the smaller the S value, the more dispersed the output is, and the more it tends to be in a chaotic or unstable state.

[0053] Considering the system in a critical periodic state maintained by excitation terms when there is no attack signal, its output already possesses reference periodicity and stability. When an attack signal is injected, its impact on the output's disorder is small due to the simple nonlinear structure of the attack signal. Therefore, the stability index S0 of the critical periodic state without attack is used as a reference benchmark, and considering a 30% margin, the threshold S is obtained. th = 0.7S0; The oscillation criterion for real oscillations and FDIA-induced oscillations caused by spurious data injection attacks is:

[0054] .

[0055] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0056] 1. This invention provides a detection framework that does not rely on an accurate system model: the entire detection method is based solely on the interaction between the dynamic characteristics of the Duffing oscillator system itself and the input signal, without requiring an accurate mathematical model of the power system or relying on a large amount of historical attack data. It has good robustness to changes in system parameters and is more suitable for new energy power plant environments with strong model uncertainties.

[0057] 2. This invention proposes an oscillation type identification based on the Duffing oscillator system: by setting the oscillator excitation frequency to the system synchronization frequency, and utilizing its different dynamic responses to subsynchronous and supersynchronous frequency signals, combined with the proposed periodic state time ratio criterion, the oscillation frequency type can be distinguished.

[0058] 3. This invention constructs an improved Duffing oscillator system to enhance the ability to identify the nonlinear nature: by introducing cross terms, the symmetry of the classical oscillator is broken, enhancing the ability to perceive higher-order nonlinear components of the input signal; and on this basis, a stability index based on the Poincaré mapping is defined as a feature quantity, which can effectively quantify the degree of chaos in the system output, thereby distinguishing between the real broadband oscillation with complex nonlinear structure and the FDIA attack-induced oscillation with simplified nonlinear structure. Attached Figure Description

[0059] Figure 1 This is a flowchart of the method of the present invention.

[0060] Figure 2 The power system model structure diagram of a wind farm integrating multiple synchronous generators in two regions 1 and 2 according to an embodiment of the present invention. Detailed Implementation

[0061] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0062] like Figure 1As shown in the figure, this embodiment discloses a method for detecting network attacks on a wide-area control system of a wind farm, the specific details of which are as follows:

[0063] Step 1: Construct a power system model of a wind farm integrating multiple synchronous generators in two regions, 1 and 2; when broadband oscillations occur in the power system models of regions 1 and 2, obtain the rotational speed of synchronous generator SG1 in region 1. and the rotational speed of synchronous generator SG2 in region 2. Define wide-area signals As the input signal for wide-area damping control, t is the oscillation time of the power system model;

[0064] like Figure 2 As shown, the wind farm uses doubly fed asynchronous wind turbines; both Region 1 and Region 2 contain multiple synchronous generators, and energy exchange between the regions is achieved through a 220km interconnection line. and The wide-area signal, acquired via a phasor measurement unit (PMU), passes sequentially through a filter, compensation circuit, gain module, and limiting module. These modules together constitute the wide-area damping control, ultimately outputting the power change. It participates in the vector control of the subsequent rotor-side converter.

[0065] Step 2: Acquire the wide-area signal The input is fed into the Duffing oscillator system, and the phase trajectory and time-domain response of the Duffing oscillator system output are analyzed. Based on the analysis results, it is determined whether the broadband oscillation occurring in the power system model is a subsynchronous oscillation or a supersynchronous oscillation. Based on the determination results, the excitation term frequency is set for the improved Duffing oscillator system in step 3. Specifically, as follows:

[0066] The equations for the Duffing oscillator system are as follows:

[0067] ;

[0068] In the formula, Let t be the time-domain response of the Duffing oscillator system. Let t be an intermediate variable of the Duffing oscillator system. for The first derivative, for The first derivative of , where k1 is the damping ratio; The nonlinear restoring force; the wide-area signal F(t) is the external input signal to be detected, called the signal to be detected; The excitation term built into the Duffing oscillator system at time t is... For the incentive amplitude, For the frequency of the excitation term;

[0069] With amplitude As the value increases, the Duffing oscillator system will successively exhibit a chaotic state, a critical periodic state, and a large periodic state. The chaotic state indicates that the Duffing oscillator system is in a non-periodic and unpredictable state. The critical periodic state is the bifurcation boundary where the Duffing oscillator system transitions from a chaotic state to periodic motion. The large periodic state indicates that the Duffing oscillator system is in regular periodic motion. Adjusting... The value of causes the Duffing oscillator system to enter the critical period state. In this state, the Duffing oscillator system is extremely fragile. When the signal to be detected F(t) contains a signal with the same frequency as the excitation term, even if the amplitude is weak, it will act as a synchronous excitation to break the critical equilibrium and drive the Duffing oscillator system to significantly transition from the critical period state to the large period state.

[0070] Frequency of the signal to be detected Not equal to the set frequency of the excitation term Let the signal to be detected at time t be... , The amplitude of the signal to be detected. The phase of the signal to be detected; the total excitation of the Duffing oscillator system. The superposition of the signal to be detected and the built-in excitation term is represented as:

[0071] ;

[0072] In the formula, Let be the magnitude of the total excitation term at time t. The frequency difference between the signal to be detected and the excitation term. The phase of the total excitation term at time t; the total excitation term amplitude As the periodic changes over time occur, the value cannot remain above the threshold required to maintain a large periodic state. As a result, the Duffing oscillator system cannot operate in a single large periodic state, but instead exhibits a dynamic behavior that alternates between periodic motion and chaotic state, i.e., intermittent chaos.

[0073] The critical conditions for chaotic motion in the Duffing oscillator system are analyzed using the Melnikov method. First, the Duffing oscillator system is dimensionless, and its dimensionless Duffing oscillator equations are as follows:

[0074] ;

[0075] In the formula, The time-domain response of the dimensionless Duffing oscillator equations. As an intermediate variable in the dimensionless Duffing oscillator equation, for The first derivative, for The first derivative; The damping ratio is dimensionless. This represents the magnitude of the built-in excitation term after dimensionless transformation; The amplitude of the signal to be detected after dimensionless scaling. The phase of the signal to be detected after dimensionless transformation. Frequency of the signal to be detected Frequency of excitation terms The ratio;

[0076] Based on the dimensionless Duffing oscillator equation, the Melnikov equation is derived as follows:

[0077] ;

[0078] In the formula, The distance characterizing the stable and unstable manifolds of a dimensionless Duffing oscillator system. , and Represent , and The Melnikov equation, Let be the delay of the Melnikov function, and ; The dimensionless Duffing oscillator equation at time t The solution obtained at that time for The first derivatives of and are expressed as follows:

[0079] ;

[0080] right Using Euler's formula, then:

[0081] ;

[0082] In the formula, The imaginary unit;

[0083] make , for The one-sided integral function, due to If it is an odd function, then:

[0084] ;

[0085] Will Substitute the changed expression back into From the expression, we get:

[0086] ;

[0087] Similarly, ;

[0088] For the Melnikov function, the threshold condition for chaos to occur corresponds to the existence of a certain moment... Make Established; Ordered , express The effective weights contributed by the chaos threshold are then equivalent to: Established; for The amplitude, in When less than 1 The function value increases, therefore, when the frequency of the signal to be detected is less than the frequency of the excitation term, i.e. Duffing oscillator systems are more likely to satisfy the chaos threshold condition, and their dynamic behavior tends to be in an intermittent chaotic state; while when They tend to maintain a long-cycle state;

[0089] By setting the excitation frequency of the Duffing oscillator system to the synchronous frequency, the Duffing oscillator system will exhibit different motion states when the frequency of the signal to be detected is within the subsynchronous oscillation range and the supersynchronous oscillation range, respectively, thus distinguishing the oscillation type of the signal to be detected.

[0090] Furthermore, the periodic state-time ratio (PSTR) is used as a feature quantity to distinguish different response states of the Duffing oscillator system induced by subsynchronous and supersynchronous oscillations. This periodic state-time ratio characterizes the proportion of time the Duffing oscillator system output is in a large-period state within a given observation time, and its expression is:

[0091] ;

[0092] In the formula, The duration of the large-cycle state; Total testing time; This represents the number of state detection points for a large-cycle period. This represents the total number of detection points;

[0093] Calculate the frequency respectively. and Periodic state time ratio and Take the arithmetic mean of the two. The decision threshold for classification is used; finally, the criterion for distinguishing between subsynchronous oscillations and supersynchronous oscillations is formally expressed as:

[0094] .

[0095] Step 3: An improvement is made by introducing a cross term into the Duffing oscillator system described in Step 2. This cross term enhances the Duffing oscillator system's ability to detect nonlinear terms; it also improves the wide-area signal... The input is fed into an improved Duffing oscillator system. Based on the phase trajectory and time-domain response output by the improved Duffing oscillator system, it is determined whether the broadband oscillations occurring in the power system model are caused by a network attack; specifically as follows:

[0096] The equations for the improved Duffing oscillator system are as follows:

[0097] ;

[0098] In the formula, The improved time-domain response of the Duffing oscillator system at time t. For the intermediate variables of the improved Duffing oscillator system at time t, for The first derivative, for The first derivative; and The damping ratio and frequency of the improved Duffing oscillator system are respectively. Let be the excitation term at time t. The amplitude; For the introduced cross terms, The nonlinear enhancement factor; the function of the cross term is to improve the output of the Duffing oscillator system by introducing Volterra series analysis. It can be represented as the input signal Historical values ​​expanded:

[0099] ;

[0100] In the formula, The nth-order Volterra kernel represents the nth-order nonlinear response of the improved Duffing oscillator system. Let i be the i-th integration variable. ; The output component representing the contribution of the nth-order kernel;

[0101] Incentive items The known intrinsic excitation of the improved Duffing oscillator system is used to maintain the critical periodic state of the oscillator; therefore, the signal to be detected is analyzed using Volterra series analysis. When considering the additional response caused by the improved Duffing oscillator system, the focus is on its impact on the nonlinear order of the improved system; this is based on the symmetry constraint of the standard Duffing oscillator system, i.e., when... Become , Similarly, it becomes This symmetry constraint results in all even-order Volterra kernels. It must be zero. Otherwise, the response of the corresponding order will not meet the requirement of synchronous symbol change, thus contradicting the system structure; for the improved Duffing oscillator system, its symmetry is actively broken, and the output will be... Substituting the expansion terms into the equations of the improved Duffing oscillator system and balancing the terms according to their order clearly reveals the influence of structural changes on the nonlinear response of the system. The result after balancing the second-order terms is expressed as follows:

[0102] ;

[0103] In the formula, The output component contributed by the second-order kernel at time t. The output component contributed by the second-order kernel at time t. for The first derivative, for The second derivative; due to the cross term With the existence of , the second-order Volterra kernel is no longer constrained by symmetry and must be zero; the symmetry is broken, and the second-order kernel h2 is no longer zero; similarly, the other even-order kernels are also not zero, and the nonlinear response described by the odd-order kernels is further enhanced.

[0104] Furthermore, based on the stability index of the Poincaré map as a criterion feature, the following steps are performed to quantify the differences in the dynamic behavior of the improved Duffing oscillator system:

[0105] Step 3.1: At times that are integer multiples of the period of the excitation term of the improved Duffing oscillator system, record the value of the output signal to form a mapping point set: , For the improved Duffing oscillator system The time-domain response output at each moment. ;

[0106] Step 3.2: Calculate the standard deviation of the mapping point set. , The average value of the mapped points;

[0107] Step 3.3: Define the stability index as The larger the S value, the more concentrated the mapping points are, the more stable the system output is, and the more it tends to move periodically; the smaller the S value, the more dispersed the output is, and the more it tends to be in a chaotic or unstable state.

[0108] Considering the system in a critical periodic state maintained by excitation terms when there is no attack signal, its output already possesses reference periodicity and stability. When an attack signal is injected, its impact on the output's disorder is small due to the simple nonlinear structure of the attack signal. Therefore, the stability index S0 of the critical periodic state without attack is used as a reference benchmark, and considering a 30% margin, the threshold S is obtained. th = 0.7S0; The oscillation criterion for real oscillations and FDIA-induced oscillations caused by spurious data injection attacks is:

[0109] .

[0110] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for detecting network attacks on a wide-area control system of a wind farm, characterized in that, Includes the following steps: Step 1: Construct a power system model of a wind farm integrating multiple synchronous generators in two regions, 1 and 2; when broadband oscillations occur in the power system models of regions 1 and 2, obtain the rotational speed of synchronous generator SG1 in region 1. and the rotational speed of synchronous generator SG2 in region 2. Define wide-area signals As the input signal for wide-area damping control, t is the oscillation time of the power system model; Step 2: Acquire the wide-area signal Input the data into the Duffing oscillator system, analyze the phase trajectory and time-domain response of the Duffing oscillator system output, and determine whether the broadband oscillation occurring in the power system model is a subsynchronous oscillation or a supersynchronous oscillation based on the analysis results; based on the determination results, set the excitation term frequency for the improved Duffing oscillator system in step 3. Step 3: An improvement is made by introducing a cross term into the Duffing oscillator system described in Step 2. This cross term enhances the Duffing oscillator system's ability to detect nonlinear terms; it also improves the wide-area signal... The input is fed into the improved Duffing oscillator system. Based on the phase trajectory and time-domain response output by the improved Duffing oscillator system, it is determined whether the broadband oscillations occurring in the power system model are caused by a network attack.

2. The method for detecting network attacks on a wide-area control system of a wind farm according to claim 1, characterized in that, In step 1, the wind farm uses doubly fed asynchronous wind turbines; both area 1 and area 2 contain multiple synchronous generators, and energy exchange between area 1 and area 2 is achieved through a 220km interconnection line; and The signal is acquired via a phasor measurement unit (PMU). The wide-area signal sequentially passes through a filter, compensation circuit, gain module, and limiting module. These components together constitute the wide-area damping control, ultimately outputting the power change. It participates in the vector control of the subsequent rotor-side converter.

3. The method for detecting network attacks on a wide-area control system of a wind farm according to claim 2, characterized in that, In step 2, the equations of the Duffing oscillator system are as follows: ; In the formula, Let t be the time-domain response of the Duffing oscillator system. Let t be an intermediate variable of the Duffing oscillator system. for The first derivative, for The first derivative of , where k1 is the damping ratio; The nonlinear restoring force; the wide-area signal F(t) is the external input signal to be detected, called the signal to be detected; The excitation term built into the Duffing oscillator system at time t is... For the incentive amplitude, For the frequency of the excitation term; With amplitude As the value increases, the Duffing oscillator system will successively exhibit a chaotic state, a critical periodic state, and a large periodic state. The chaotic state indicates that the Duffing oscillator system is in a non-periodic and unpredictable state. The critical periodic state is the bifurcation boundary where the Duffing oscillator system transitions from a chaotic state to periodic motion. The large periodic state indicates that the Duffing oscillator system is in regular periodic motion. Adjusting... The value of causes the Duffing oscillator system to enter the critical period state. In this state, the Duffing oscillator system is extremely fragile. When the signal to be detected F(t) contains a signal with the same frequency as the excitation term, even if the amplitude is weak, it will act as a synchronous excitation to break the critical equilibrium and drive the Duffing oscillator system to significantly transition from the critical period state to the large period state. Frequency of the signal to be detected Not equal to the set frequency of the excitation term Let the signal to be detected at time t be... , The amplitude of the signal to be detected. The phase of the signal to be detected; the total excitation of the Duffing oscillator system. The superposition of the signal to be detected and the built-in excitation term is represented as: ; In the formula, Let be the magnitude of the total excitation term at time t. The frequency difference between the signal to be detected and the excitation term. The phase of the total excitation term at time t; the total excitation term amplitude As the periodic changes over time occur, the value cannot remain above the threshold required to maintain a large periodic state. As a result, the Duffing oscillator system cannot operate in a single large periodic state, but instead exhibits a dynamic behavior that alternates between periodic motion and chaotic state, i.e., intermittent chaos. The critical conditions for chaotic motion in the Duffing oscillator system are analyzed using the Melnikov method. First, the Duffing oscillator system is dimensionless, and its dimensionless Duffing oscillator equations are as follows: ; In the formula, The time-domain response of the dimensionless Duffing oscillator equations. As an intermediate variable in the dimensionless Duffing oscillator equation, for The first derivative, for The first derivative; The damping ratio is dimensionless. This represents the magnitude of the built-in excitation term after dimensionless transformation; The amplitude of the signal to be detected after dimensionless scaling. The phase of the signal to be detected after dimensionless transformation. Frequency of the signal to be detected Frequency of excitation terms The ratio; Based on the dimensionless Duffing oscillator equation, the Melnikov equation is derived as follows: ; In the formula, The distance characterizing the stable and unstable manifolds of a dimensionless Duffing oscillator system. , and Represent , and The Melnikov equation, Let be the delay of the Melnikov function, and ; The dimensionless Duffing oscillator equation at time t The solution obtained at that time for The first derivatives of and are expressed as follows: ; right Using Euler's formula, then: ; In the formula, The imaginary unit; make , for The one-sided integral function, due to If it is an odd function, then: ; Will Substitute the changed expression back into From the expression, we get: ; Similarly, ; For the Melnikov function, the threshold condition for chaos to occur corresponds to the existence of a certain moment... Make Established; Ordered , express The effective weights contributed by the chaos threshold are then equivalent to: Established; for The amplitude, in When less than 1 The function value increases, therefore, when the frequency of the signal to be detected is less than the frequency of the excitation term, i.e. Duffing oscillator systems are more likely to satisfy the chaos threshold condition, and their dynamic behavior tends to be in an intermittent chaotic state; while when They tend to maintain a long-cycle state; By setting the excitation frequency of the Duffing oscillator system to the synchronous frequency, the Duffing oscillator system will exhibit different motion states when the frequency of the signal to be detected is within the subsynchronous oscillation range and the supersynchronous oscillation range, respectively, thus distinguishing the oscillation type of the signal to be detected.

4. The method for detecting network attacks on a wide-area control system of a wind farm according to claim 3, characterized in that, In step 2, the periodic state-time ratio (PSTR) is used as a feature quantity to distinguish the different response states of the Duffing oscillator system caused by subsynchronous and supersynchronous oscillations. This periodic state-time ratio characterizes the proportion of time the Duffing oscillator system output is in a large-period state within a given observation time, and its expression is: ; In the formula, The duration of the large-cycle state; Total testing time; This represents the number of state detection points for a large-cycle period. This represents the total number of detection points; Calculate the frequency respectively. and Periodic state time ratio and Take the arithmetic mean of the two. The decision threshold for classification is used; finally, the criterion for distinguishing between subsynchronous oscillations and supersynchronous oscillations is formally expressed as: 。 5. The method for detecting network attacks on a wide-area control system of a wind farm according to claim 4, characterized in that, In step 3, the equations for the improved Duffing oscillator system are: ; In the formula, The improved time-domain response of the Duffing oscillator system at time t. For the intermediate variables of the improved Duffing oscillator system at time t, for The first derivative, for The first derivative; and The damping ratio and frequency of the improved Duffing oscillator system are respectively. Let be the excitation term at time t. The amplitude; For the introduced cross terms, The nonlinear enhancement factor; the function of the cross term is to improve the output of the Duffing oscillator system by introducing Volterra series analysis. It can be represented as the input signal Historical values ​​expanded: ; In the formula, The nth-order Volterra kernel represents the nth-order nonlinear response of the improved Duffing oscillator system. Let i be the i-th integration variable. ; The output component representing the contribution of the nth-order kernel; Incentive items The known intrinsic excitation of the improved Duffing oscillator system is used to maintain the critical periodic state of the oscillator; therefore, the signal to be detected is analyzed using Volterra series analysis. When considering the additional response caused by the improved Duffing oscillator system, the focus is on its impact on the nonlinear order of the improved system; this is based on the symmetry constraint of the standard Duffing oscillator system, i.e., when... Become , Similarly, it becomes This symmetry constraint results in all even-order Volterra kernels. It must be zero. Otherwise, the response of the corresponding order will not meet the requirement of synchronous symbol change, thus contradicting the system structure; for the improved Duffing oscillator system, its symmetry is actively broken, and the output will be... Substituting the expansion terms into the equations of the improved Duffing oscillator system and balancing the terms according to their order clearly reveals the influence of structural changes on the nonlinear response of the system. The result after balancing the second-order terms is expressed as follows: ; In the formula, The output component contributed by the second-order kernel at time t. The output component contributed by the second-order kernel at time t. for The first derivative, for The second derivative; due to the cross term With the existence of , the second-order Volterra kernel is no longer constrained by symmetry and must be zero; the symmetry is broken, and the second-order kernel h2 is no longer zero; similarly, the other even-order kernels are also not zero, and the nonlinear response described by the odd-order kernels is further enhanced.

6. The method for detecting network attacks on a wide-area control system of a wind farm according to claim 5, characterized in that, In step 3, based on the stability index of the Poincaré map as a criterion feature, the following steps are performed to quantify the differences in the dynamic behavior of the improved Duffing oscillator system: Step 3.1: At times that are integer multiples of the period of the excitation term of the improved Duffing oscillator system, record the value of the output signal to form a mapping point set: , For the improved Duffing oscillator system The time-domain response output at each moment. ; Step 3.2: Calculate the standard deviation of the mapping point set. , The average value of the mapped points; Step 3.3: Define the stability index as The larger the S value, the more concentrated the mapping points are, the more stable the system output is, and the more it tends to move periodically; the smaller the S value, the more dispersed the output is, and the more it tends to be in a chaotic or unstable state. Considering the system in a critical periodic state maintained by excitation terms when there is no attack signal, its output already possesses reference periodicity and stability. When an attack signal is injected, its impact on the output's disorder is small due to the simple nonlinear structure of the attack signal. Therefore, the stability index S0 of the critical periodic state without attack is used as a reference benchmark, and considering a 30% margin, the threshold S is obtained. th = 0.7S0; The criterion for distinguishing between genuine oscillations and oscillations induced by FDIA (Fake Data Injection) attacks is as follows: 。