A multi-black production gang false data injection attack defense technology
By constructing a Stackelberg game model to optimize the allocation of defense resources, the problem of coordinated attacks by multiple cybercrime groups is solved, the security and stability of smart grids are improved, the probability of successful attacks is reduced, and it is applicable to the security hardening of smart grids and industrial control.
Patent Information
- Application Number
- CN202610784465.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-02
- Publication Date
- 2026-08-25
AI Technical Summary
Existing power distribution network protection solutions are unable to effectively deal with coordinated attacks from multiple cybercrime groups, making it difficult to detect fake data injection attacks, which in turn cause power grid operation errors and pose serious security risks. Furthermore, improper allocation of defense resources leads to diminishing marginal utility.
A Stackelberg game model is constructed between the Defenders Alliance and multiple non-cooperative cybercrime groups to optimize the power grid defense resource allocation strategy. The game equilibrium is solved by enumeration and genetic algorithms to achieve a dual-objective optimization of minimizing defense costs and maximizing attack costs.
It significantly improves the security and stability of smart grids under attacks from multiple malicious groups, reduces the survival rate of critical feeder terminal FTU measurement points, and reduces the probability of simultaneous breaches by multiple malicious groups. It is suitable for security hardening of smart grids and industrial control.
Smart Images

Figure CN122640193A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart grid distribution network automation technology, and in particular to a defense technology against attacks by multiple black market groups injecting false data. Background Technology
[0002] With the advancement of new power system construction, feeder terminal units (FTUs), smart converged terminals, and 5G / fiber hybrid communication networks have been deployed on a large scale on the distribution network side, forming a typical smart grid feeder automation (FA) system. The dispatch master station, through a three-layer architecture of "distribution automation master station - substation - feeder", collects measurement data such as voltage, current, phase angle, and load rate in real time, and makes online decisions on the tap position of on-load tap changing transformers (OLTC), the number of reactive power compensation capacitor banks to be switched on and off, and the power of distributed photovoltaic inverters, so as to achieve economical, safe, and high-quality operation of the distribution network.
[0003] However, due to limited communication resources and weak terminal computing capabilities in distribution networks, FTU uplink messages generally use unidirectional 101 / 104 protocols, possessing only simple checksum mechanisms and lacking end-to-end encryption and authentication. Recent practical attack and defense exercises and security incidents disclosed by the industry have shown that cybercriminal groups can use "man-in-the-middle" methods on public wireless networks or physically intrude into FTU maintenance ports to intercept and tamper with voltage, current, and power measurements, injecting concealed false data (FDI) to construct highly covert malicious attack vectors. This attack can bypass conventional defenses at the data link layer, directly contaminating the master station's measurement database, causing the remote estimator at the dispatch center to draw conclusions about the actual power grid operating status that are completely detached from reality. Due to the low redundancy of distribution network state estimation models, traditional bad data detection thresholds are usually relaxed by 3σ-4σ to avoid false alarms, making it difficult to detect small but critical deviations. Once such covert FDI attacks successfully deceive the state estimation, they will cause the dispatch center to issue incorrect control commands. At best, this will cause large-scale power outages and serious damage to equipment (such as transformers and capacitors). At worst, it may trigger a chain of failures, seriously threatening the physical security and stable operation of the power grid.
[0004] Even more serious is the trend of "multi-organizational collaboration and task subcontracting" among criminal gangs:
[0005] 1. Group A was responsible for tampering with the FTU voltage at the beginning of the feeder line to create the illusion of "virtual low voltage";
[0006] 2. Gang B simultaneously altered the power flow direction of adjacent feeders to offset the head-end deviation and further reduce the residual error;
[0007] 3. Gang C used forged "load forecast" emails on the dispatch master station side to induce dispatchers to raise the OLTC level in advance.
[0008] The aforementioned scenarios involving multiple criminal gangs operating without cooperation or with weak coordination result in an exponential increase in the attack vector space faced by the system, rendering the traditional zero-sum model based on the "single criminal gang - single defender" assumption completely ineffective.
[0009] Existing power distribution network protection schemes mainly focus on communication encryption, terminal hardening, or adjusting the state estimation threshold at the master station. These are passive data-layer detection solutions, lacking quantitative modeling of the strategic interactions between the dispatch center and multiple non-cooperative cybercrime groups. In practical engineering, due to limitations in upgrade costs and terminal hardware lifespan, the security budget of the defender (dispatch center) is limited, making it impossible to provide indiscriminate, highest-level protection for thousands of FTU nodes. Furthermore, the investment of defense resources typically exhibits diminishing marginal utility, and due to unknown vulnerabilities or human error, defense measures cannot achieve 100% absolute security, meaning there is a risk of probabilistic breaches. Therefore, a systematic technology is urgently needed for scenarios involving multiple cybercrime groups and FDI, capable of guiding the dispatch center to optimize the deployment of encryption, authentication, whitelisting, and other defense resources. This technology must accurately characterize the sequential interaction between the defender's initial resource deployment (leader) and the subsequent opportunistic attacks by multiple cybercrime groups (followers), and provide a scientific, globally optimal defense resource allocation strategy under budget constraints and uncertainty, thereby maximizing the overall resilience of the smart grid. Summary of the Invention
[0010] To address the aforementioned technical issues, this invention proposes a defense technology against multiple malicious data injection attacks by multiple criminal groups. By constructing a Stackelberg game model between a defender alliance and multiple non-cooperative criminal groups, the power grid defense resource allocation strategy is optimized, effectively improving the security and stability of the system in complex scenarios involving multiple criminal groups.
[0011] To achieve the above objectives, the technical solution of the present invention is as follows:
[0012] A defense technique against data injection attacks by multiple cybercrime groups includes the following steps:
[0013] Step 1: Establish the state-space model and attack model of the smart grid feeder automation system;
[0014] Step 2: Construct a Stackelberg game model between the Defenders Alliance and multiple non-cooperative criminal groups, where the Defenders Alliance is the leader and the multiple non-cooperative criminal groups are the followers.
[0015] Step 3: Determine the defense costs of the Defenders Alliance and the attack costs of multiple non-cooperative cybercrime groups;
[0016] Step 4: Construct the profit function for each non-cooperative cybercrime group with the goal of minimizing the attack cost of multiple cybercrime groups; introduce a trade-off coefficient with the goal of maximizing the minimum attack cost among all cybercrime groups and minimizing the defense cost of the defender alliance. Construct the payoff function for the Defenders Alliance;
[0017] Step 5: Reconstruct the payoff function by introducing a probabilistic defense mechanism and a secondary defense cost function;
[0018] Step 6: Based on the Stackelberg game model and the reconstructed payoff function, the best response of the black market gang is obtained by enumeration and the best response of the defender alliance is obtained by genetic algorithm. Through continuous game between the defender alliance and multiple non-cooperative black market gangs, the game equilibrium is finally reached, and the globally optimal defense strategy of the defender alliance is obtained.
[0019] Preferably, step 2 includes the following steps:
[0020] The game proceeded in Stackelberg's order, with the Defenders Alliance being the first to commit and announce their defensive strategy. n criminal gangs observed Then, simultaneously and non-cooperatively, they select the attack vector. , A set of feasible strategies;
[0021] Solve for the game equilibrium to find the Stackelberg equilibrium. ,satisfy: in and Optimal response mappings for followers and leaders:
[0022] in, This is the attack vector for criminal gang j. This is a defensive strategy.
[0023] Preferably, step 3 includes the following steps:
[0024] For the Defenders Alliance, the defense resources of m feeder terminal FTU measurement points constitute a unified budget vector, and the defense strategy is as follows: The formula is as follows: in This indicates the defense resources allocated to measurement point i of the feeder terminal FTU. The upper limit of measurement point resources for a single feeder terminal FTU is denoted as the alliance strategy space. ,
[0025] For non-cooperative criminal gangs, each criminal gang... Define a binary attack vector The formula is as follows: in This indicates that a criminal gang (j) hijacks the feeder terminal FTU measurement point (i), and their feasible strategy set is as follows. It is determined by the smallest subset of feeder terminal unit (FTU) measurement points that makes the system completely attackable, i.e. in Let j be the set of all feasible attack matrices for a criminal gang, and satisfy the following conditions: ,
[0026] Using a quadratic form to characterize diminishing marginal utility and defense costs The formula is as follows:
[0027] For a given The cost required for a cybercriminal group to hijack the feeder terminal FTU measurement point i is a monotonically increasing function, and the attack cost is... The formula is as follows: Total attack cost of criminal gang J for: in .
[0028] Preferably, step 4 includes the following steps:
[0029] Criminal groups aim to minimize their own attack costs; their profit function is:
[0030] The Defenders Alliance aims to minimize the attack cost among all cybercrime groups while minimizing its own defense costs, and introduces a trade-off factor. The payoff function for the Defenders Alliance is:
[0031] Preferably, step 5 includes the following steps:
[0032] Assume a defense strategy is implemented for the feeder terminal FTU measurement point i. The probability function for a criminal gang to successfully tamper with the measurement data of the feeder terminal FTU is: Satisfy boundary conditions
[0033] The vector form is denoted as:
[0034] Let the black market gang j be risk-neutral. Reconstruct the gang's profit function as follows:
[0035] in , The inherent benefits obtained after successfully hijacking the feeder terminal FTU measurement point i,
[0036] The goal of the Defenders Alliance is to ensure that the maximum expected net benefit of the most threatening cybercrime groups is non-positive, while minimizing defense costs. The Defenders Alliance's payoff function is reconstructed as follows:
[0037] Preferably, the best response from the criminal gang is determined by enumeration, including the following steps:
[0038] For a given defense strategy For each criminal gang j, the solution is optimized using pure integers:
[0039]
[0040] because Finite, using complete enumeration, for Calculate the total attack cost of cybercrime group j for each feasible vector. ;
[0041] Attack cost Minimum as the objective, from The vector that minimizes the target is taken as the optimal response for the criminal gang. .
[0042] Preferably, the optimal response of the defender alliance is determined using a genetic algorithm, including the following steps:
[0043] Initialization: Generate a population of size G, with each individual... satisfy ;
[0044] Fitness assessment: for individuals First, use enumeration to find the best response and corresponding minimum expected net profit for each criminal gang, and then calculate the fitness:
[0045] Selection: Individuals with high fitness are selected based on individual tournament selection;
[0046] Crossover: Probably perform single-point crossover to produce offspring;
[0047] Mutation: Adaptive feasible mutation, for components Apply random perturbation and project it to ;
[0048] Termination: Output the optimal individual after N iterations. This refers to the globally optimal defense strategy of the Defenders Alliance.
[0049] Based on the above technical solution, the beneficial effects of this invention are as follows: Addressing the limitation of existing single-gang / single-defender models in failing to depict the simultaneous intrusion of multiple independent gangs in real-world scenarios, this invention discloses a multi-gang fake data injection attack defense technology. It constructs a Stackelberg game framework of "defender alliance—multiple non-cooperative gangs": the defender alliance, as the leader, allocates protection resources to each feeder terminal FTU measurement point using a quadratic cost function under total budget constraints; several non-cooperative gangs, as followers, autonomously choose actionable actions and independently inject fake data after observing the defense strategy. A probabilistic breakthrough model is introduced to quantify defense uncertainty, making the attack success probability exponentially decrease with defense investment. By transforming the non-convex combinatorial optimization problem of the defenders into a quadratic programming problem and integrating an enumeration-genetic hybrid algorithm, the Stackelberg equilibrium is quickly solved, achieving a dual-objective optimization of "minimizing defense cost and maximizing attack cost." Simulation results show that the present invention can significantly improve the survivability of critical feeder terminal FTU measurement points under budget constraints, reduce the probability of simultaneous breaches by multiple cybercrime groups, and reveal the law of diminishing marginal utility of defense. It is applicable to the security hardening of critical cyber-physical infrastructure such as smart grids and industrial control. Attached Figure Description
[0050] Figure 1 This is a schematic diagram of a defense technology process against multiple black market groups injecting fake data in one embodiment;
[0051] Figure 2 This is a diagram illustrating the FDI attack and defense game architecture of multiple black market groups in one embodiment. Detailed Implementation
[0052] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0053] like Figure 1 , 2 As shown, this embodiment provides a defense technology against multiple black market groups injecting fake data, including the following steps:
[0054] Step 1: Establish the state-space model and attack model of the smart grid feeder automation system.
[0055] To accurately quantify the mathematical impact of the strategies employed by both attackers and defenders on the actual operating state of the distribution network, this step first constructs the underlying dynamic evolution process of the smart grid feeder automation (FA) system from a cyber-physical system perspective. Specifically, the physical operation of the distribution network is abstracted into a discrete-time state-space model, characterizing the temporal variations of system state variables such as node voltage and phase angle with control input and environmental noise. Simultaneously, considering the vulnerability of measurement data transmitted wirelessly to a remote estimator, this step further establishes a mathematical model for a spoofed data injection (FDI) attack where external attackers (cyber groups) collaboratively tamper with feeder terminal unit (FTU) measurement data. This lays the foundation for subsequent assessment of the attack's destructive consequences and for finding game-theoretic equilibrium defense strategies.
[0056] Step 1.1, State-space model
[0057] Consider a discrete linear time-invariant system in which measurements from feeder terminal unit (FTU) measurement points are received by a remote estimator:
[0058] in, ; OLTC tap position and capacitor switching group vector; Measurement vectors of m feeder terminal unit (FTU) measurement points at time t; , They are independent and identically distributed process noise and measurement noise, respectively, satisfying... For time index; initial state ,and Observable Controllable; A is the state transition matrix, B is the control input matrix, C is the observation matrix, Q is the engineering noise covariance matrix, and R is the measurement noise covariance matrix.
[0059] The remote estimator uses a standard Kalman filter to compute the minimum mean square error estimate. and its error covariance .
[0060] Step 1.2, Attack Model
[0061] Let the set of measurement points for the feeder terminal unit (FTU) be defined. Black market gangs gather .
[0062] Criminal gangs intercepted and tampered with measurement data from feeder terminal units (FTUs) via wireless channels, injecting false vectors. This makes the tampered measurement received by the remote estimator become in For diagonal attack support matrix, its binary elements when At that time, the criminal gang successfully injected false data into the measurement point of the i-th feeder terminal FTU; otherwise, the data of the feeder terminal FTU measurement point remained intact.
[0063] Step 2: Construct a Stackelberg game model between the Defenders Alliance and multiple non-cooperative criminal groups, where the Defenders Alliance is the leader and the multiple non-cooperative criminal groups are the followers.
[0064] Based on the system and attack model established in step 1, this step introduces a hierarchical decision-making structure of "defender alliance - multiple black market gangs" to construct a single-leader - multiple-follower Stackelberg game.
[0065] Decision-making timing and equilibrium concepts:
[0066] The game proceeds in Stackelberg order:
[0067] (1) The Defenders Alliance was the first to commit and announce it. ;
[0068] (2) Various criminal gangs observed Subsequently, simultaneously and non-cooperatively, they chose... .
[0069] The equilibrium solution under this sequence is a Stackelberg equilibrium. , satisfy: in and Optimal response mappings for followers and leaders:
[0070] Step 3: Determine the defense costs of the Defenders Alliance and the attack costs of multiple non-cooperative cybercrime groups.
[0071] Step 3.1: Participants and Strategy Space
[0072] Defenders Alliance (Leader)
[0073] The defense resources of m feeder terminal FTU measurement points constitute a unified budget vector, and the defense strategy is... The formula is as follows: in This indicates the defense resources allocated to measurement point i of the feeder terminal FTU. This represents the upper limit of measurement point resources for a single feeder terminal unit (FTU). The alliance strategy space is denoted as... .
[0074] Non-cooperative black market groups (followers)
[0075] For each criminal gang Define a binary attack vector, as follows: in This indicates that a criminal gang (j) hijacks the feeder terminal FTU measurement point (i). Their feasible strategy set is as follows. The set of measurement points for the smallest feeder terminal unit (FTU) that makes the system completely vulnerable to attack is determined by the minimum set of measurement points. in Let j be the set of all feasible attack matrices for a criminal gang, and satisfy the following conditions: .
[0076] Step 3.2, Resource Constraints and Cost Function
[0077] Defense costs
[0078] The diminishing marginal utility is described using a quadratic form:
[0079] Attack cost
[0080] For a given The cost required for a criminal gang to hijack the feeder terminal FTU measurement point i is a monotonically increasing function. The total attack cost for criminal gang J is: in .
[0081] Step 4: Construct the profit function for each non-cooperative cybercrime group with the goal of minimizing the attack cost of multiple cybercrime groups; introduce a trade-off coefficient with the goal of maximizing the minimum attack cost among all cybercrime groups and minimizing the defense cost of the defender alliance. Construct the payoff function for the Defenders Alliance.
[0082] Step 4.1, Profits of the Black Market Gang
[0083] The follower aims to minimize its own attack cost, and its payoff function is:
[0084] Step 4.2, Defenders Alliance Benefits
[0085] The leader aims to "maximize the lowest attack cost among all cybercrime groups" and "minimize their own defense expenditure," introducing a trade-off factor. The payoff function is:
[0086] Step 5: Introduce a probabilistic defense mechanism and a secondary defense cost function to reconstruct the payoff function.
[0087] This step, based on the established Stackelberg game framework, further introduces an exponential probabilistic success function to characterize the uncertainty that "the higher the defensive investment, the lower the probability of attack success"; at the same time, it retains the quadratic defense cost function to quantitatively describe the diminishing marginal utility of defense resource allocation.
[0088] Step 5.1, Probability Breakthrough Model
[0089] In actual FTU operations, even if cybercriminal groups incur the required costs, they may still fail due to technical flaws, environmental changes, or dynamic defenses. Let's assume that defense resources are allocated to the FTU measurement point i at the feeder terminal. The probability that a criminal gang successfully tampered with the measurement data of the FTU (Feeder Unit) in the feeder terminal is: Satisfy boundary conditions
[0090] The vector form is denoted as:
[0091] Step 5.2, Reconstructing Expected Net Income
[0092] Black market gangs expect profits
[0093] The black market group j is risk-neutral. Its expected net profit from hijacking the feeder terminal FTU measurement point i is the reconstructed profit function of the black market group, which is: in The inherent benefit obtained after successfully hijacking the feeder terminal FTU measurement point i.
[0094] Overall attack vector The expected net income is: in .
[0095] Defenders League Expected Returns
[0096] The alliance's objective is to make the "maximum expected net profit of the most threatening cybercrime groups" non-positive, while minimizing defense expenditures. The revenue function of the defender alliance is reconstructed as follows:
[0097] Step 5.3, the cost of secondary defense with diminishing marginal utility
[0098] The total cost of defense remains in a quadratic form: Its marginal cost As resource input increases linearly, it accurately reflects the reality of diminishing marginal utility caused by "resource saturation - redundancy - efficiency loss".
[0099] Step 6: Based on the Stackelberg game model and the reconstructed payoff function, the best response of the black market gang is obtained by enumeration and the best response of the defender alliance is obtained by genetic algorithm. Through continuous game between the defender alliance and multiple non-cooperative black market gangs, the game equilibrium is finally reached, and the globally optimal defense strategy of the defender alliance is obtained.
[0100] This step provides a hybrid solution process for the non-convex, nonlinear Stackelberg game obtained in step 2, which combines "enumeration method to find the best response of the criminal gang + genetic algorithm to find the best response of the defender" and gives a provable quadratic programming transformation form and its applicable conditions.
[0101] Step 6.1, Best Response from Criminal Gangs – Enumeration Method
[0102] For a given defense strategy For each criminal gang j, the solution is optimized using pure integers:
[0103] because Finite, using complete enumeration:
[0104] 1) To Calculate the target value for each feasible vector;
[0105] 2) Take the vector that minimizes the objective value as the optimal response. .
[0106] Step 6.2, Defender's Best Response - Genetic Algorithm
[0107] The leader problem is:
[0108] The objective function is non-convex and non-smooth, and the inner minimum value of the black market gang varies. The gradient exhibits discrete jumps, making traditional gradient methods prone to getting trapped in local optima. A genetic algorithm (GA) is used to perform a global search:
[0109] 1) Initialization: Generate a population of size G, with each individual... satisfy .
[0110] 2) Fitness assessment: for individuals First, use enumeration to find the best response and corresponding minimum expected net profit for each criminal gang, and then calculate the fitness:
[0111] 3) Selection: Tournament selection retains individuals with high fitness.
[0112] 4) Crossover: Based on probability Perform a single-point crossover to generate offspring.
[0113] 5) Mutation: Adaptive feasible mutation, for components Apply random perturbation and project it to .
[0114] 6) Termination: Output the optimal individual after N iterations. This refers to the leader's equilibrium strategy.
[0115] It should be understood that although the steps in the flowchart above are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart above may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0116] The above are merely preferred embodiments of the present application and are not intended to limit the embodiments of the present application. For those skilled in the art, the embodiments of the present application can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of the present application should be included within the protection scope of the embodiments of the present application.
Claims
1. A defense technology against multiple black market groups injecting fake data, characterized in that, Includes the following steps: Step 1: Establish the state-space model and attack model of the smart grid feeder automation system; Step 2: Construct a Stackelberg game model between the Defenders Alliance and multiple non-cooperative criminal groups, where the Defenders Alliance is the leader and the multiple non-cooperative criminal groups are the followers. Step 3: Determine the defense costs of the Defenders Alliance and the attack costs of multiple non-cooperative cybercrime groups; Step 4: Construct the profit function for each non-cooperative cybercrime group with the goal of minimizing the attack cost of multiple cybercrime groups; introduce a trade-off coefficient with the goal of maximizing the minimum attack cost among all cybercrime groups and minimizing the defense cost of the defender alliance. Construct the payoff function for the Defenders Alliance; Step 5: Reconstruct the payoff function by introducing a probabilistic defense mechanism and a secondary defense cost function; Step 6: Based on the Stackelberg game model and the reconstructed payoff function, the best response of the black market gang is obtained by enumeration and the best response of the defender alliance is obtained by genetic algorithm. Through continuous game between the defender alliance and multiple non-cooperative black market gangs, the game equilibrium is finally reached, and the globally optimal defense strategy of the defender alliance is obtained.
2. The defense technology against multiple black market groups injecting fake data as described in claim 1, characterized in that, Step 2 includes the following steps: The game proceeded in Stackelberg's order, with the Defenders Alliance being the first to commit and announce their defensive strategy. n criminal gangs observed Then, simultaneously and non-cooperatively, they select the attack vector. , A set of feasible strategies; Solve for the game equilibrium to find the Stackelberg equilibrium. ,satisfy: in and Optimal response mappings for followers and leaders: ; in, This is the attack vector for criminal gang j. This is a defensive strategy.
3. The defense technology against multiple black market groups' fake data injection attacks according to claim 2, characterized in that, Step 3 includes the following steps: For the Defenders Alliance, the defense resources of m feeder terminal FTU measurement points constitute a unified budget vector, and the defense strategy is as follows: The formula is as follows: in This indicates the defense resources allocated to measurement point i of the feeder terminal FTU. The upper limit of measurement point resources for a single feeder terminal FTU is denoted as the alliance strategy space. , For non-cooperative criminal gangs, for each criminal gang Define a binary attack vector The formula is as follows: in This indicates that a criminal gang (j) hijacks the feeder terminal FTU measurement point (i), and their feasible strategy set is as follows. It is determined by the smallest subset of feeder terminal unit (FTU) measurement points that makes the system completely attackable, i.e. in Let j be the set of all feasible attack matrices for a criminal gang, and satisfy the following conditions: , Using a quadratic form to characterize diminishing marginal utility and defense costs The formula is as follows: ; For a given The cost required for a cybercriminal group to hijack the feeder terminal FTU measurement point i is a monotonically increasing function, and the attack cost is... The formula is as follows: Total attack cost of criminal gang J for: in .
4. The defense technology against multiple black market groups injecting fake data as described in claim 3, characterized in that, Step 4 includes the following steps: Criminal groups aim to minimize their own attack costs; their profit function is: ; The Defenders Alliance aims to minimize the attack cost among all cybercrime groups while minimizing its own defense costs, and introduces a trade-off factor. The payoff function for the Defenders Alliance is:
5. The defense technology against multiple black market groups injecting fake data as described in claim 4, characterized in that, Step 5 includes the following steps: Assume a defense strategy is implemented for the feeder terminal FTU measurement point i. The probability function for a criminal gang to successfully tamper with the measurement data of the feeder terminal FTU is: Satisfy boundary conditions ; Vector form is denoted as: ; Let the black market gang j be risk-neutral. Reconstruct the gang's profit function as follows: ; in , The inherent benefits obtained after successfully hijacking the feeder terminal FTU measurement point i, The goal of the Defenders Alliance is to ensure that the maximum expected net benefit of the most threatening cybercrime groups is non-positive, while minimizing defense costs. The Defenders Alliance's payoff function is reconstructed as follows:
6. The defense technology against multiple black market groups injecting false data as described in claim 5, characterized in that, The enumeration method is used to find the optimal response of a criminal gang, including the following steps: For a given defense strategy For each criminal gang j, the solution is optimized using pure integers: ; because Finite, using complete enumeration, for Calculate the total attack cost of cybercrime group j for each feasible vector. ; Attack cost Minimum as the target, from The vector that minimizes the target is taken as the optimal response for the criminal gang. .
7. A defense technology against multiple black market groups injecting fake data as described in claim 6, characterized in that, The genetic algorithm is used to find the optimal response of the defender alliance, including the following steps: Initialization: Generate a population of size G, with each individual... satisfy ; Fitness assessment: for individuals First, use enumeration to find the best response and corresponding minimum expected net profit for each criminal gang, and then calculate the fitness: ; Selection: Individuals with high fitness are selected based on individual tournament selection; Crossover: Probably perform single-point crossover to produce offspring; Mutation: Adaptive feasible mutation, for components Apply random perturbation and project it to ; Termination: Output the optimal individual after N iterations. This refers to the globally optimal defense strategy of the Defenders Alliance.