Island ac microgrid fdi attack detection method, medium, device and product

CN122553341APending Publication Date: 2026-08-11CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-09
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0004]本发明的目的在于:为了解决现有技术对微电网FDI攻击的实时性判别、准确识别与类型区分能力不足的问题,提出一种孤岛交流微电网FDI攻击检测方法,包括以下步骤:

Benefits of technology

本发明基于混合分布式发电单元组成的孤岛交流微电网系统,构建FDI攻击的分布式一致性控制的微电网系统,获取系统FDI攻击下的一致性控制的状态量,组成电气特征序列,设计DNN和LSTM结合的深度学习攻击检测模型,设计动态学习率调整机制,通过梯度下降法更新DNN全连接层权重、偏置及LSTM门控参数,并引入动量因子抑制参数振荡,加速模型收敛,基于电气特征序列和攻击检测模型实现对FDI攻击与正常运行工况的精准识别,有效提升微电网网络安全防护能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122553341A_ABST
    Figure CN122553341A_ABST
Patent Text Reader

Abstract

This invention discloses a method, medium, device, and product for detecting FDI attacks on isolated AC microgrids, relating to the field of power grid technology. The method includes: constructing an isolated AC microgrid system composed of hybrid distributed generation units; constructing a directed graph with generation units as nodes and information interaction links between units as edges; performing distributed consistency control on the microgrid system based on the directed graph and the generation unit model; constructing a model of the microgrid system under FDI attack distributed consistency control, obtaining the state variables of consistency control under FDI attack, and forming an electrical feature sequence; constructing an FDI attack detection model, including a DNN and a two-layer LSTM, using the two-layer LSTM to extract temporal features from the electrical feature sequence, inputting the temporal features into the DNN, and outputting the attack state category from the output layer. This invention can achieve accurate identification of FDI attacks and normal operating conditions, effectively improving the network security protection capabilities of microgrids.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power grid technology, and in particular to methods, media, equipment and products for detecting FDI attacks on isolated AC microgrids. Background Technology

[0002] With the widespread application of distributed energy resources, isolated AC microgrids composed of multiple distributed generation units have become an important carrier for renewable energy consumption. Integrated wind-solar-storage (DG) units, combined with a hierarchical control architecture of droop control and distributed consensus control, achieve power balance and frequency / voltage stability in microgrids, making them the mainstream control scheme for isolated microgrids. However, the communication links and control layer of microgrids are vulnerable to cyberattacks. False Data Injection (FDI) attacks, in particular, tamper with the frequency / voltage correction signals of consensus control, disrupting system power distribution and stable operation, and potentially causing microgrid frequency shifts, voltage fluctuations, or even system instability.

[0003] Currently, research on microgrid network attack detection largely relies on traditional threshold discrimination and Kalman filtering methods. These methods inherently depend on prior knowledge and fixed models, making them poorly adaptable to the dynamic injection characteristics of FDI attacks, particularly struggling to capture time-varying and nonlinear malicious signals. In islanded operation mode, wind and solar power output exhibits strong randomness, and load changes also show dynamic fluctuations. These uncertainties, along with spurious measurement signals introduced by FDI attacks, easily confuse at the feature level, making it difficult for detectors to effectively distinguish between normal disturbances and malicious injections, significantly reducing the accuracy and reliability of attack detection. Existing deep learning detection frameworks are mostly designed for ideal energy storage microgrids, lacking specific feature modeling for the hierarchical control architecture of multi-source AC microgrids. Especially in FDI attack scenarios, existing models fail to fully utilize the dynamic response patterns of key voltage and frequency quantities at different control levels, making it difficult to effectively extract the time-varying injection characteristics of FDI attacks. Consequently, detectors lack the ability to accurately identify and differentiate FDI attacks in real-time, failing to meet the high-precision, high-robustness, and rapid response requirements of islanded wind-solar-storage AC microgrids for attack detection. Traditional residual-based detection methods are easily circumvented by attackers and are difficult to deal with FDI attacks with strong temporal correlation. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of existing technologies in real-time detection, accurate identification, and type differentiation of FDI attacks in microgrids. This invention proposes a method for detecting FDI attacks in isolated AC microgrids, comprising the following steps: S1. Construct an islanded AC microgrid system composed of hybrid distributed generation units and model the hybrid distributed generation unit model; S2. Construct a directed graph by taking the distributed generation units of the microgrid system as nodes and the information interaction links between units as edges; based on the directed graph and the model of the generation units, perform distributed consistency control on the microgrid system to obtain a microgrid system with distributed consistency control. S3. Construct a model of a microgrid system under FDI attack on distributed consensus control, obtain the state variables of the consensus control under the FDI attack, and form an electrical characteristic sequence. S4. Construct an FDI attack detection model, including DNN and two-layer LSTM. Use two-layer LSTM to extract temporal features from electrical feature sequences, input the temporal features into DNN, and output the attack state category from the output layer.

[0005] Furthermore, the hybrid distributed generation unit includes photovoltaic cells, wind turbine batteries, and energy storage batteries; The photovoltaic cell model is as follows:

[0006]

[0007]

[0008] in, This represents the output voltage of the photovoltaic cell during the (k+1)th perturbation. This represents the output voltage of the photovoltaic cell during the k-th perturbation. This represents the k-th power disturbance. This represents the k-th voltage disturbance. Indicates a fixed voltage step size. Represents a symbolic function. This represents the output power of the photovoltaic cell during the (k-1)th perturbation. This represents the output voltage of the photovoltaic cell during the (k-1)th perturbation. The wind turbine battery model is as follows: when When the fan output power is 0; when At that time, the fan output power is:

[0009] in, Indicates the output power of the fan. Where is the rated power of the fan, and v represents the actual wind speed. Indicates the cut-in wind speed. Indicates the rated wind speed; The energy storage battery model is as follows: The state of charge of an energy storage battery is expressed as follows:

[0010] in, This represents the state of charge of the energy storage battery at time k. This indicates the initial state of charge of the energy storage battery. Indicates the rated capacity of the energy storage battery. t represents the battery charging and discharging current, and t represents time. The formula for calculating the reference value of energy storage battery charging and discharging power is as follows:

[0011] in, This indicates the reference value for the charging and discharging power of the energy storage battery. Indicates the DC-side load power. Indicates the photovoltaic output value. This indicates the output power of the fan.

[0012] Furthermore, the distributed consensus control of the microgrid system is specifically implemented as follows: Droop control is used for power distribution and frequency / voltage regulation:

[0013]

[0014] Where f represents the output frequency of the power generation unit. This indicates the frequency reference value of the power generation unit. Pf represents the droop factor, where P represents the actual active power output of the power generation unit. This indicates the reference value of the active power of the power generation unit. This represents the frequency correction value, and V represents the output voltage of the generator unit. This indicates the voltage reference value of the power generation unit. This represents the QV droop coefficient, where Q represents the actual reactive power output of the power generation unit. Indicates the voltage correction amount; Based on droop control, the secondary control employs a first-order consistent tracking algorithm with a reference value, as shown in the following formula:

[0015] in, Let represent the first derivative of the frequency correction amount of the i-th generator unit under droop control. Indicates frequency consensus control gain. This represents the neighboring nodes of the i-th power generation unit. This represents the information interaction relationship between the i-th node and the j-th node in the adjacency matrix of a directed graph. This represents the output frequency of the i-th power generation unit. This represents the output frequency of the j-th power generation unit;

[0016] in, This represents the first derivative of the voltage correction amount of the i-th generator unit under droop control. This indicates the voltage consensus control gain. This represents the output voltage of the i-th power generation unit. This represents the output voltage of the j-th power generation unit.

[0017] Furthermore, the mathematical expression for the FDI attack model is as follows:

[0018] in, This represents the altered measurement value at time t after the FDI attack, where t is the system simulation time. Let represent the actual measured signal of the distributed power source at time t, and let b represent the attack on the fixed bias term. This represents the zero-mean Gaussian white noise perturbation term at time t. This indicates the start time of the FDI attack.

[0019] Furthermore, the learning rate of the FDI attack detection model is as follows:

[0020] in, This represents the learning rate of the FDI attack detection model at time k. This represents the maximum learning rate. This represents the minimum learning rate. This represents the training error of the FDI attack detection model at time k. This represents the critical error value.

[0021] Furthermore, the update method for the weights of the fully connected layers in a DNN is as follows:

[0022]

[0023] in, This represents the weight values ​​of the fully connected layer in the DNN at time k. This represents the weight values ​​of the fully connected layer in the DNN at time k-1. This represents the learning rate at time k. Represents the gradient direction vector. Represents the momentum factor. This represents the weight values ​​of the fully connected layer in the DNN at time k-2, where N represents the number of samples. This represents the actual label of the i-th sample. This represents the predicted label of the i-th sample. This represents the input feature of the i-th sample; The DNN fully connected layer bias is updated as follows:

[0024]

[0025] in, This represents the bias value of the fully connected layer of the DNN at time k. This represents the bias value of the fully connected layer of the DNN at time k-1. This represents the bias value of the fully connected layer of the DNN at time k-2; Furthermore, The LSTM gating parameters are updated as follows:

[0026]

[0027] in, This represents the LSTM gating parameter value at time k. This represents the LSTM gating parameter value at time k-1. This represents the LSTM gating parameter value at time k-2. This represents the output of the LSTM unit at time k. This indicates the input to the LSTM output gate.

[0028] The present invention also proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for detecting FDI attacks on isolated AC microgrids.

[0029] The present invention also proposes an electronic device, including a processor and a memory, wherein the processor and the memory are interconnected, wherein the memory is used to store a computer program, the computer program including computer-readable instructions, and the processor is configured to invoke the computer-readable instructions to execute the above-described method for detecting FDI attacks on isolated AC microgrids.

[0030] The present invention also proposes a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the above-described method for detecting FDI attacks on isolated AC microgrids.

[0031] The beneficial effects of the technical solution provided by this invention are: This invention constructs a distributed consensus control microgrid system for FDI attacks based on an islanded AC microgrid system composed of hybrid distributed generation units. It acquires the state variables of the consensus control under FDI attacks, assembles them into an electrical feature sequence, designs a deep learning attack detection model combining DNN and LSTM, and designs a dynamic learning rate adjustment mechanism. The weights of the fully connected layers of the DNN are updated using gradient descent. Bias and LSTM gating parameters And introduce momentum factor Suppressing parameter oscillations and accelerating model convergence, this method enables accurate identification of FDI attacks and normal operating conditions based on electrical feature sequences and attack detection models, effectively enhancing the network security protection capabilities of microgrids. Attached Figure Description

[0032] Figure 1 This is a flowchart of an example of an islanded AC microgrid FDI attack detection method according to the present invention; Figure 2 This is a communication topology diagram of an isolated AC microgrid system according to an example of the present invention; Figure 3 This is a block diagram of a droop control structure according to an embodiment of the present invention; Figure 4 This is a frequency consistency control block diagram of an embodiment of the present invention; Figure 5 This is a block diagram of voltage consistency control according to an example of the present invention; Figure 6 This is a voltage diagram illustrating droop control and consistency control in an embodiment of the present invention. Figure 7 This is a frequency diagram of droop control and consistency control in an embodiment of the present invention; Figure 8 This is a diagram illustrating the impact of a time-varying Gaussian FDI attack on microgrid voltage, according to an example of the present invention. Figure 9 This is a diagram illustrating the impact of a time-varying Gaussian FDI attack on microgrid frequency, as described in an example of this invention. Figure 10 This refers to the FDI attack detection performance of the model of this invention on the test set; Figure 11 This is the ROC curve of the model of this invention in the microgrid FDI attack detection of an example of this invention; Figure 12 This is a block diagram of an electronic device according to an exemplary embodiment of the present invention. Detailed Implementation

[0033] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be further described below with reference to the accompanying drawings.

[0034] A flowchart of an example of an islanded AC microgrid FDI attack detection method of the present invention is shown below. Figure 1 Specifically, it includes: S1. Construct an islanded AC microgrid system composed of hybrid distributed generation units and model the hybrid distributed generation unit model.

[0035] A hybrid ring and radial topology islanded AC microgrid consisting of five distributed generation (DG) units is constructed. Each DG unit integrates a complete wind-solar-storage system with 2kW photovoltaic power, 2kW wind turbine, and 5kWh battery storage. After DC-AC conversion and LC filtering, the system is connected to the AC bus. The system has a rated line voltage of 380V, a rated frequency of 50Hz, and a total initial load of 24kW. The core structure of the DG unit includes a renewable energy generation layer, an energy storage buffer layer, a DC-AC conversion layer, and a hierarchical control layer, realizing the aggregation of wind, solar, and storage power, AC-DC conversion, and local control.

[0036] (1) Photovoltaic cell model To fully utilize the power generation potential of photovoltaic cells and improve the operating efficiency of microgrids, a Maximum Power Point Tracking (MPPT) control module needs to be connected to the output of the photovoltaic array. Due to the highly nonlinear output characteristics of photovoltaic cells, their maximum power point (MPP) dynamically drifts with changes in solar irradiance, ambient temperature, and load. If the operating point deviates from this maximum power point, the power generation efficiency of the photovoltaic system will significantly decrease. MPPT control dynamically adjusts the converter's duty cycle by monitoring the output voltage and current of the photovoltaic array in real time, ensuring that the system operating point is always locked at the maximum power point under the current operating conditions, thereby achieving efficient utilization of solar energy resources and maximizing output power. This solution uses the classic perturbation and observation (P&O) method to implement the MPPT function of the photovoltaic array.

[0037] The perturbation-observation method involves periodically applying small-amplitude voltage perturbations to the photovoltaic operating point. And observe the change in output power before and after the disturbance. To determine the direction of the next disturbance, the expression is as follows:

[0038]

[0039] like This indicates that the current perturbation direction increases power, so the perturbation direction should be maintained; conversely, the perturbation should be reversed, eventually converging to the maximum power point. The unified decision formula is as follows:

[0040]

[0041] in, This represents the output voltage of the photovoltaic cell during the (k+1)th perturbation. This represents the output voltage of the photovoltaic cell during the k-th perturbation. This represents the k-th power disturbance. This represents the k-th voltage disturbance. Indicates a fixed voltage step size. Represents a symbolic function. This represents the output power of the photovoltaic cell during the (k-1)th perturbation. This represents the output voltage of the photovoltaic cell during the (k-1)th perturbation. (2) Wind turbine battery model The output power of a wind turbine also varies significantly with wind conditions. Essentially, it captures kinetic energy from the air through its rotor and converts it into electrical energy via mechanical transmission and a generator. In this invention, the wind power generation module uses a piecewise lookup table mathematical model to describe the relationship between the turbine's output power and wind speed. This model, based on the physical laws of wind energy capture, divides wind speed into multiple characteristic intervals such as cut-in, rated, and cut-out, and uses cubic interpolation fitting in key intervals to accurately reflect the essential characteristic of wind energy varying with the cube of wind speed.

[0042] when When the fan output power is 0; when At that time, the output power of the fan increases non-linearly with the cubic force, and the output power of the fan is:

[0043] in, Indicates the output power of the fan. This represents the function of the fan's output power with respect to the actual wind speed. Where is the rated power of the fan, and v represents the actual wind speed. Indicates the cut-in wind speed. This indicates the rated wind speed.

[0044] From a fluid dynamics perspective, the wind energy captured by the wind turbine impeller is: In the formula, air density, The impeller swept area, This represents the wind energy utilization coefficient. Within the range, the wind turbine maintains its position through pitch control and other methods. This is the maximum value, at which point the captured wind energy power is proportional to the cube of the wind speed.

[0045] when At this time, the fan output power remains at the rated power. Constant. When the wind speed exceeds the rated wind speed, if wind energy capture continues according to the cubic law, the output power will exceed the rated capacity of the generator and converter, causing overcurrent and overvoltage damage to the power electronic equipment. Therefore, wind turbines reduce the wind energy utilization coefficient through pitch control. This ensures that the actual captured wind energy power remains constant, and the final output power is stabilized at the rated value, achieving constant power operation of the wind turbine and ensuring equipment safety.

[0046] when At this time, the fan output power returns to 0. Under high wind speeds, the centrifugal force of the rotating impeller increases sharply, which can easily cause fatigue damage or even breakage of mechanical structures such as impeller blades and nacelle supports; at the same time, the aerodynamic load brought by strong winds will exceed the structural design limits of the fan. Therefore, the control system will shut down the fan in an emergency and cut off the power output to achieve over-wind speed protection of the equipment.

[0047] (3) Energy storage battery model As the core power balancing unit of isolated wind-solar-storage microgrids, the energy storage battery's State of Charge (SOC) directly reflects the remaining battery capacity, determining the microgrid's power supply stability and battery lifespan. This scheme uses a simplified engineering model to describe the dynamic change process of SOC. The dynamic change rate of the battery SOC is jointly determined by the charging and discharging power and the battery capacity. The formula for calculating the energy storage battery SOC is as follows:

[0048] in, This represents the state of charge of the energy storage battery at time k. This indicates the initial state of charge of the energy storage battery. Indicates the rated capacity of the energy storage battery. This represents the battery charging and discharging current; it is negative during charging and positive during discharging, and t represents time. The formula for calculating the reference value of energy storage battery charging and discharging power is as follows:

[0049] in, This indicates the reference value for the charging and discharging power of the energy storage battery. Indicates the DC-side load power. Indicates the photovoltaic output value. This indicates the output power of the fan. Contribute to the scenery, when When the value is greater than 0, the battery discharges to compensate for the power gap. When the value is less than 0, the battery stores excess power during charging.

[0050] S2. Construct a directed graph by treating the distributed generation units of the microgrid system as nodes and the information exchange links between units as edges. This is done using an adjacency matrix. Describe the topological connections, where >0 indicates that the i-th DG unit and the j-th DG unit have information exchange. =0 indicates no interaction, and Ni represents the set of neighboring nodes of the i-th DG unit, that is, the set of all nodes that have information interaction with the i-th unit. In addition to the adjacency matrix, the topology of the communication network can also be represented by the Laplace matrix. It is indicated that its definition is based on the adjacency matrix. degree matrix ,satisfy The specific element is defined as shown in the following formula.

[0051]

[0052] In the formula, For a degree matrix, its diagonal elements That is, the degree of the i-th node, the sum of the weights related to the number of its neighboring nodes, and all off-diagonal elements are 0. The Laplace matrix intuitively reflects the overall connectivity characteristics of the communication topology and is a core matrix tool for stability analysis of consensus algorithms. For the directed communication topology commonly used in microgrid distributed control, its corresponding asymmetric Laplace matrix has a clear eigenvalue property, and this property directly determines the convergence of the consensus algorithm.

[0053] In the control of isolated wind-solar-storage microgrids, it is often required that the state information of each distributed generation (DG) unit can track a given reference state. Therefore, a virtual node N+1 needs to be introduced into the communication network, and its state information is denoted as... , used to represent the system's reference state quantity. Based on this, the corresponding first-order consensus tracking algorithm with a reference value is:

[0054] in, Let N represent the first derivative of the state of the i-th node, and N represent the number of nodes. This represents the information interaction relationship between the i-th node and the j-th node in the adjacency matrix of a directed graph. , and This represents the state of the i-th node, the j-th node, and the reference node. This represents the information interaction relationship between the i-th node and the (N+1)-th node, with the (N+1)-th node serving as the reference node. The steady-state value of the above equation satisfies... .

[0055] The overall system network topology adopts a ring main loop formed by DG1-DG2-DG4-DG3, with DG4 radiating to DG5. There are both electrical and communication connections between the DGs. Only DG1 serves as the Leader node, obtaining global frequency and voltage references; the rest are Follower nodes, achieving distributed control through neighbor interaction. The system communication topology diagram is shown below. Figure 2 As shown.

[0056] Based on the model of directed graphs and generator units, distributed consensus control is performed on the microgrid system to obtain a microgrid system with distributed consensus control.

[0057] (1) Droop control, frequency and voltage control For the AC microgrid portion of an isolated wind-solar-storage microgrid, the inverters of the photovoltaic and wind turbine distributed generation (DG) units need to simulate the operating characteristics of synchronous generators. Pf and QV droop control is employed to achieve coordinated regulation of active power and frequency, and reactive power and voltage, while simultaneously completing power distribution among multiple DG units. The droop control structure block diagram is shown below. Figure 3 As shown.

[0058] The control equation for Pf droop is shown below:

[0059] The QV droop control equation is shown below:

[0060] Where f represents the output frequency of the power generation unit. This indicates the frequency reference value of the power generation unit. Pf represents the droop factor, where P represents the actual active power output of the power generation unit. This indicates the reference value of the active power of the power generation unit. This represents the frequency correction value, and V represents the output voltage of the generator unit. This indicates the voltage reference value of the power generation unit. This represents the QV droop coefficient, where Q represents the actual reactive power output of the power generation unit. Indicates the voltage correction amount; (2) Secondary control Based on droop control, the secondary control employs a first-order consistent tracking algorithm with a reference value. Among these, The rate of change of the frequency correction directly determines the dynamic adjustment process of the frequency correction in a single droop control, achieving coordinated consistency of the frequency correction in each DG unit and ensuring synchronous adjustment of multiple units. This enables the monitoring of the frequency reference value. Precise tracking eliminates frequency deviations in primary control. Based on this, the rate of change of the frequency correction is composed of two parts: a neighbor coordination term and a reference tracking term. To achieve coordination of frequency corrections across DG units, neighbor node information exchange needs to be introduced. Based on a first-order consensus tracking algorithm with a reference value, the neighbor coordination term is designed as follows:

[0061] in, Frequency consensus control gain is used to adjust the response speed of neighbor coordination. The frequency deviations between the i-th DG cell and all its neighboring nodes j are weighted sums, with the weights determined by the elements of the adjacency matrix. Decision, when At that time, the neighbor coordination item was positive, promoting... Increasing the frequency of DG unit i increases its output frequency, enabling coordination with neighboring nodes; conversely, decreasing it drives... Reduce the frequency to ensure that the frequency correction of each unit is adjusted synchronously.

[0062] To achieve frequency correction relative to reference value The tracking design reference is shown in the following formula:

[0063] in, As a constraint factor, DG1 is the leader, directly obtaining the global reference frequency, while the other DGs are followers, only able to obtain the reference indirectly through their neighbors. This design conforms to the sparse communication constraint, reduces the dependence on the central controller, and is used to adjust the accuracy and response speed of reference tracking. Let be the deviation between the actual output frequency and the reference frequency of the i-th DG unit, when At that time, the reference tracking item is positive, driving... Increasing the frequency by using a first-order droop control equation raises the output frequency until it approaches the reference value. Conversely, decreasing the frequency by using a second-order droop control equation raises the output frequency. This reduces the frequency deviation, thus eliminating it. The neighbor coordination term and the reference tracking term are integrated to obtain the frequency correction amount. rate of change The equation and the quadratic control formula are as follows:

[0064] Integrating the above equation yields the frequency correction amount actually involved in one droop control operation. The integration process is shown in the following equation:

[0065] in, Let represent the first derivative of the frequency correction amount of the i-th generator unit under droop control. Indicates frequency consensus control gain. This represents the neighboring nodes of the i-th power generation unit. This represents the information interaction relationship between the i-th node and the j-th node in the adjacency matrix of a directed graph. This represents the output frequency of the i-th power generation unit. This represents the output frequency of the j-th power generation unit.

[0066] The solution obtained By directly substituting the formula for the primary droop control Pf, the steady-state frequency deviation of the primary control can be eliminated through dynamic adjustment of the correction amount, thus achieving frequency consistency and reference tracking among the DG units. The frequency consistency control block diagram is as follows: Figure 4 As shown.

[0067] Voltage correction amount Design and frequency correction Employing a homogeneous design principle, its core objective is to eliminate the steady-state voltage deviation of primary QV droop control, achieving coordinated consistency and reference tracking of the output voltages of each DG unit. Since the coordinated goals of voltage regulation and frequency regulation are both to achieve multi-unit state coordination and reference tracking, the voltage correction amount... rate of change Similarly composed of a neighbor coordination term and a reference tracking term, its structure is completely isomorphic to the frequency correction consistency formula, only replacing the corresponding state variables and control gains. The derivation logic of the reference frequency correction and the design of the neighbor coordination term for the voltage correction are shown in the following equation:

[0068] in, For voltage consensus control gain, The voltage deviation between the i-th DG cell and its neighboring nodes is weighted and summed to achieve coordinated synchronization of voltage correction values ​​among the cells. The reference tracking term is... By integrating the neighbor coordination term and the reference tracking term, the voltage correction amount is obtained. The rate of change equation, i.e., the voltage consistency formula, is shown in the following equation:

[0069] Rate of change of voltage correction By performing integration, the voltage correction amount actually involved in the first droop control is obtained. As shown in the following formula:

[0070] in, This represents the first derivative of the voltage correction amount of the i-th generator unit under droop control. This indicates the voltage consensus control gain. This represents the output voltage of the i-th power generation unit. This represents the output voltage of the j-th power generation unit.

[0071] The solution obtained By directly substituting into the primary droop control QV formula, coordinated regulation of the output voltage of each DG unit can be achieved, eliminating the voltage steady-state deviation of the primary control. The voltage consistency control block diagram is as follows: Figure 5 As shown.

[0072] This invention constructs a hierarchical collaborative control system for isolated wind-solar-storage microgrids, ensuring power distribution and power quality during normal system operation.

[0073] S3. Construct a model of a microgrid system under FDI attack on distributed consensus control, and obtain the state variables of the consensus control under the FDI attack, including: actual voltage / frequency values ​​of DG units, voltage / frequency deviation, and secondary correction amount. , The eigenvalue deviations of the Laplace matrix form the electrical characteristic sequence.

[0074] Microgrids adopt a two-layer architecture of physical layer and network layer. FDI attacks are launched against the communication link between the physical layer and the network layer. Attackers maliciously tamper with the cooperative control information transmitted in the communication link, destroy the integrity of the input data of the secondary consistency controller, and thus mislead the generation of local control commands, ultimately threatening the global voltage, frequency stability and power distribution performance of the microgrid.

[0075] The mathematical expression for the FDI attack model is as follows:

[0076] in, This represents the altered measurement value at time t after the FDI attack, where t is the system simulation time. Let represent the actual measured signal of the distributed power source at time t, and let b represent the attack on the fixed bias term. This represents the zero-mean Gaussian white noise perturbation term at time t. This indicates the start time of the FDI attack.

[0077] S4. Construct an FDI attack detection model, including DNN and two-layer LSTM. Use two-layer LSTM to extract temporal features from electrical feature sequences, input the temporal features into DNN, and output the attack state category from the output layer.

[0078] In this invention, a two-layer LSTM is used. The first LSTM layer has 64 hidden nodes and a Dropout value of 0.3; the second LSTM layer has 32 hidden nodes and a Dropout value of 0.3. A layer normalization layer is also placed between the two LSTM layers. The DNN consists of two fully connected layers in series. The first fully connected layer has 64 nodes, uses the ReLU activation function, and has a Dropout value of 0.4; the second fully connected layer has 32 nodes, also uses the ReLU activation function. A batch normalization layer is also placed between the two fully connected layers. The output layer consists of a fully connected layer with one node in series, a sigmoid function, and a regression layer.

[0079] DNN or LSTM models may experience abrupt parameter updates due to issues such as random weight initialization and fixed learning rates, leading to a sharp drop in detection accuracy and model training failure. This makes them unsuitable for the complex scenarios of FDI attacks on microgrids. Therefore, this paper proposes a fusion and improvement of DNN and LSTM models to construct a combined DNN and LSTM attack detection model, achieving accurate identification and classification of both normal scenarios and FDI attacks. First, a dynamic learning rate adjustment mechanism is designed to adaptively adjust the learning rate based on the magnitude of the model training error, avoiding the slow convergence or parameter oscillation problems caused by a fixed learning rate.

[0080] The learning rate of the FDI attack detection model is as follows:

[0081] in, This represents the learning rate of the FDI attack detection model at time k. This represents the maximum learning rate. This represents the minimum learning rate. This represents the training error of the FDI attack detection model at time k. This represents the critical error value.

[0082] Next, backpropagation of the FDI attack detection model is performed. The network parameters are updated based on the perturbation error of the attack features. With the goal of minimizing the attack detection error, the weights of the fully connected layers of the DNN are updated using the gradient descent method. Bias and LSTM gating parameters And introduce momentum factor To suppress parameter oscillations and accelerate model convergence, the weights of the fully connected layers in a DNN are updated as follows:

[0083]

[0084] in, This represents the weight values ​​of the fully connected layer in the DNN at time k. This represents the weight values ​​of the fully connected layer in the DNN at time k-1. This represents the learning rate at time k. Represents the gradient direction vector. The momentum factor α represents the momentum factor, which is a hyperparameter of the deep learning optimizer and is determined empirically. In this invention, α = 0.9 is used to suppress parameter oscillations and accelerate model convergence. This represents the weight values ​​of the fully connected layer in the DNN at time k-2, where N represents the number of samples. This represents the actual label of the i-th sample. This represents the predicted label of the i-th sample. This represents the input feature of the i-th sample.

[0085] The DNN fully connected layer bias is updated as follows:

[0086]

[0087] in, This represents the bias value of the fully connected layer of the DNN at time k. This represents the bias value of the fully connected layer of the DNN at time k-1. This represents the bias value of the fully connected layer of the DNN at time k-2.

[0088] The LSTM gating parameters are updated as follows:

[0089]

[0090] in, This represents the LSTM gating parameter value at time k. This represents the LSTM gating parameter value at time k-1. This represents the LSTM gating parameter value at time k-2. This represents the output of the LSTM unit at time k. This indicates the input to the LSTM output gate.

[0091] Simulation experiments were conducted under two attack scenarios and one normal operating scenario. The simulations were performed using the MATLAB / Simulink platform. First, a wind-storage hybrid AC microgrid containing five distributed generation (DG) units was built in the simulation platform. The main simulation parameters are shown in Table 1, and the line impedances between the DGs are shown in Table 2. Then, simulation experiments were conducted under three scenarios. Finally, the simulation results were analyzed and compared. The simulation experiments included two attack scenarios and one normal scenario.

[0092] Table 1

[0093] Table 2

[0094] Scenario 1: Normal Operation Scenario No attacks were injected, verifying the model's detection stability under normal operating conditions. Figure 6 , Figure 7 The voltage / frequency diagrams for droop control and consistency control are shown, illustrating the voltage response waveform of an islanded microgrid under hierarchical control. Initially, the system only performs droop control once, resulting in steady-state voltage deviations among the distributed generation sources (DGs), making global consistency impossible. Consistency control is introduced at 4.5s. After the secondary consistency control is implemented, the voltage deviation is quickly eliminated, and the voltages of each DG converge to 311V / 50Hz within a short time, achieving precise voltage regulation and uniform control. Changing the load on DG3 at 13.5s, during the load change, the voltages of each DG only experience slight fluctuations before rapidly recovering to their stable operating point. This fully demonstrates that the hierarchical control strategy exhibits excellent dynamic performance and anti-interference capabilities when dealing with load disturbances, effectively ensuring the stable operation of the microgrid voltage.

[0095] Scenario 2: FDI attack scenario To verify the effectiveness of the proposed FDI attack detection model, this paper constructs a time-varying Gaussian FDI attack model for the measurement signals of an isolated wind-solar-storage AC microgrid. This attack is initiated at simulation time t=15.5s, has no constant bias component, and only superimposes zero-mean Gaussian white noise of intensity 4 onto the actual measurement values, maliciously tampering with key electrical quantities such as voltage and frequency. Unlike traditional constant bias FDI attacks, the attack designed in this paper has time-varying and random concealment characteristics. Its disturbance signal is highly similar to the characteristics of wind and solar power output fluctuations and load disturbances in the microgrid, easily causing feature confusion with normal operating conditions, thus fully testing the detection model's ability to identify complex FDI attacks. Simultaneously, a fixed random number seed ensures the reproducibility of the attack waveform, providing a guarantee for the reliability of the experimental results. The influence of the time-varying Gaussian FDI attack on the microgrid voltage is shown in the figure below. Figure 8 As shown in the figure, the impact of time-varying Gaussian FDI attacks on microgrid frequency is illustrated in the diagram. Figure 9 As shown.

[0096] The proposed FDI attack detection model based on DNN and LSTM was compared with single DNN and single LSTM models in terms of accuracy, precision, recall, F1 score, and root mean square error, as shown in Table 3. Among these models, the proposed FDI attack detection model performed best in multiple attack detection tasks and could effectively achieve FDI attack detection.

[0097] Table 3

[0098] Using voltage and frequency measurement data from each distributed generation (DG) of a microgrid as an example, the model's recognition accuracy during attack detection was tested. The results show that the model of this invention has high accuracy in distinguishing FDI attacks. The FDI attack detection performance of the model of this invention on the test set is shown in the figure below. Figure 10 The figure shows the FDI attack detection results of the proposed model on the test set. The blue solid line represents the true label of the sample, 0 represents the normal state, and 1 represents the attack state. The red solid line represents the attack prediction probability output by the model, and the black dashed line at 0.5 represents the classification decision threshold. As can be seen from the figure, in all 600 test samples, the model's prediction probability curve closely matches the true label curve. For real attack samples, the prediction probability is mostly concentrated in the range of 0.8 to 1.0, far higher than the 0.5 threshold, achieving high-confidence attack identification. For real normal samples, the prediction probability is mostly below 0.2, far below the threshold, ensuring accurate differentiation of normal states. Only a very small number of samples have prediction probabilities close to the 0.5 threshold, with almost no missed detections or false alarms. This directly verifies the excellent detection accuracy, powerful temporal feature extraction capability, and high robustness of the proposed model in the 5DG microgrid FDI attack detection task.

[0099] The ROC curve of the model of this invention in the detection of FDI attacks in microgrids is shown in the figure below. Figure 11 As shown, to further verify the generalization ability and discrimination accuracy of the model in FDI attack detection, an ROC curve was plotted. The model's ROC curve closely matches the upper left corner, and the AUC value reaches 0.9942. This result shows that the model can achieve a near 100% attack detection rate with an extremely low false alarm rate, fully demonstrating the model's strong identification ability and robustness against microgrid FDI attacks.

[0100] In summary, the FDI attack detection model proposed in this invention for isolated AC wind-solar-storage microgrids is effective and has superior detection capabilities, making it suitable for complex FDI attack scenarios.

[0101] In one exemplary embodiment, a computer-readable storage medium is included, which stores a computer program that, when executed by a processor, implements the aforementioned method for detecting FDI attacks on isolated AC microgrids.

[0102] Please see Figure 2 In one exemplary embodiment, the device further includes an electronic device including at least one processor, at least one memory, and at least one communication bus.

[0103] The memory stores a computer program, which includes computer-readable instructions. The processor calls the computer-readable instructions stored in the memory through the communication bus to execute the aforementioned method for detecting FDI attacks on isolated AC microgrids.

[0104] In one exemplary embodiment, a computer program product is proposed, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described method for detecting FDI attacks on isolated AC microgrids.

[0105] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting FDI attacks on isolated AC microgrids, characterized in that, Includes the following steps: S1. Construct an islanded AC microgrid system composed of hybrid distributed generation units and model the hybrid distributed generation unit model; S2. Construct a directed graph by taking the distributed generation units of the microgrid system as nodes and the information interaction links between units as edges; based on the directed graph and the model of the generation units, perform distributed consistency control on the microgrid system to obtain a microgrid system with distributed consistency control. S3. Construct a model of a microgrid system under FDI attack on distributed consensus control, obtain the state variables of the consensus control under the FDI attack, and form an electrical characteristic sequence. S4. Construct an FDI attack detection model, including DNN and two-layer LSTM. Use two-layer LSTM to extract temporal features from electrical feature sequences, input the temporal features into DNN, and output the attack state category from the output layer.

2. The islanded AC microgrid FDI attack detection method of claim 1, wherein, Hybrid distributed generation units include photovoltaic cells, wind turbine batteries, and energy storage batteries; The photovoltaic cell model is as follows: in, This represents the output voltage of the photovoltaic cell during the (k+1)th perturbation. This represents the output voltage of the photovoltaic cell during the k-th perturbation. This represents the k-th power disturbance. This represents the k-th voltage disturbance. Indicates a fixed voltage step size. Represents a symbolic function. This represents the output power of the photovoltaic cell during the (k-1)th perturbation. This represents the output voltage of the photovoltaic cell during the (k-1)th perturbation. The wind turbine battery model is as follows: When the fan output power is 0; when the fan output power is: wherein, represents the output power of the fan, is the rated power of the fan, and v represents the actual wind speed, represents the cut-in wind speed, represents the rated wind speed; The energy storage battery model is as follows: The state of charge of an energy storage battery is expressed as follows: wherein, Sokrepresents the state of charge of the energy storage battery k at time t, Sokrepresents the initial state of charge of the energy storage battery k, Sokrepresents the rated capacity of the energy storage battery k, Ibat represents the battery charge and discharge current, and t represents time. The formula for calculating the reference value of energy storage battery charging and discharging power is as follows: wherein, represents the energy storage battery charge and discharge power reference value, represents the DC side load power, represents the photovoltaic output value, represents the wind turbine output power.

3. The islanded AC microgrid FDI attack detection method of claim 1, wherein, The specific steps for distributed consensus control in microgrid systems are as follows: Droop control is used for power distribution and frequency / voltage regulation: Where f represents the output frequency of the power generation unit. This indicates the frequency reference value of the power generation unit. Pf represents the droop factor, where P represents the actual active power output of the power generation unit. This indicates the reference value of the active power of the power generation unit. This represents the frequency correction value, and V represents the output voltage of the generator unit. This indicates the voltage reference value of the power generation unit. This represents the QV droop coefficient, where Q represents the actual reactive power output of the power generation unit. Indicates the voltage correction amount; Based on droop control, the secondary control employs a first-order consistent tracking algorithm with a reference value, as shown in the following formula: in, Let represent the first derivative of the frequency correction amount of the i-th generator unit under droop control. Indicates frequency consensus control gain. This represents the neighboring nodes of the i-th power generation unit. This represents the information interaction relationship between the i-th node and the j-th node in the adjacency matrix of a directed graph. This represents the output frequency of the i-th power generation unit. This represents the output frequency of the j-th power generation unit; in, This represents the first derivative of the voltage correction amount of the i-th generator unit under droop control. This indicates the voltage consensus control gain. This represents the output voltage of the i-th power generation unit. This represents the output voltage of the j-th power generation unit.

4. The islanded AC microgrid FDI attack detection method of claim 1, wherein, The mathematical expression for the FDI attack model is as follows: in, This represents the altered measurement value at time t after the FDI attack, where t is the system simulation time. Let represent the actual measured signal of the distributed power source at time t, and let b represent the attack on the fixed bias term. This represents the zero-mean Gaussian white noise perturbation term at time t. This indicates the start time of the FDI attack.

5. The islanded AC microgrid FDI attack detection method of claim 1, wherein, The learning rate of the FDI attack detection model is as follows: in, This represents the learning rate of the FDI attack detection model at time k. This represents the maximum learning rate. This represents the minimum learning rate. This represents the training error of the FDI attack detection model at time k. This represents the critical error value.

6. The islanded AC microgrid FDI attack detection method of claim 1, wherein, The update method for the weights of a fully connected layer in a DNN is as follows: in, This represents the weight values ​​of the fully connected layer in the DNN at time k. This represents the weight values ​​of the fully connected layer in the DNN at time k-1. This represents the learning rate at time k. Represents the gradient direction vector. Represents the momentum factor. This represents the weight values ​​of the fully connected layer in the DNN at time k-2, where N represents the number of samples. This represents the actual label of the i-th sample. This represents the predicted label of the i-th sample. This represents the input feature of the i-th sample; The DNN fully connected layer bias is updated as follows: wherein, represents the DNN fully connected layer bias value at time k, represents the DNN fully connected layer bias value at time k-1, represents the DNN fully connected layer bias value at time k-2.

7. The method for detecting FDI attacks on isolated AC microgrids according to claim 1, characterized in that, The LSTM gating parameters are updated as follows: in, This represents the LSTM gating parameter value at time k. This represents the LSTM gating parameter value at time k-1. This represents the LSTM gating parameter value at time k-2. This represents the output of the LSTM unit at time k. This indicates the input to the LSTM output gate.

8. A computer-readable storage medium storing a computer program, the computer-readable storage medium comprising: When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 7.

9. An electronic device, comprising: The device includes a processor and a memory, the processor being interconnected with the memory, wherein the memory is used to store a computer program, the computer program including computer-readable instructions, and the processor is configured to invoke the computer-readable instructions to perform the method as described in any one of claims 1 to 7.

10. A computer program product comprising computer programs / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the method described in any one of claims 1 to 7.