A power information physical system active security whole life cycle evaluation and verification platform and method

CN122656444APending Publication Date: 2026-08-28NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610813754.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-08
Publication Date
2026-08-28

AI Technical Summary

Technical Problem

[0006]为解决上述问题,本发明公开了一种电力信息物理系统主动安全全生命周期评估与验证平台及方法,本发明针对新型电力系统信息物理耦合环境下,数据残缺失真、全生命周期评估静态僵化所导致的主动安全防御难题,提出一种对现有安全评估方案进行改进的闭环验证方法,涵盖评估与调控环节

Benefits of technology

[0098] (1) A full lifecycle data governance and dynamic indicator adaptive reduction mechanism is proposed. Traditional methods use a set of static indicators to apply to all stages, while this invention dynamically extracts sensitive indicators based on the evolution characteristics of different stages such as planning and construction, operation and control. On this basis, principal component analysis and rough set theory are combined to perform dual dimensionality reduction on two types of mixed variables, namely continuous numerical and discrete state variables, to eliminate redundant attributes. This effectively solves the dimensionality curse problem caused by the interweaving of massive indicators and significantly shortens the evaluation response time of proactive safety control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122656444A_ABST
    Figure CN122656444A_ABST
Patent Text Reader

Abstract

The application discloses a kind of power information physical system active safety whole life cycle evaluation and verification platform.There is the problem that existing evaluation system lacks whole life cycle coverage, reliability evaluation and efficiency evaluation are mixed together.The application realizes data fusion compensation and whole life cycle dynamic index reduction through multi-source heterogeneous data and dynamic index system management module;Reliability and efficiency double-driven evaluation engine is built, the reliability level under small sample attack is quantified using AHP and grey prediction model, and explicit analytical expression of defense efficiency is mined relying on gene expression programming;And the significance of the evaluation results is verified and closed-loop correction using Monte Carlo mixed sampling and Friedman nonparametric test, directional trigger physical layer emergency control or information layer adaptive correction control, form whole life cycle active safety closed loop.The application improves the robustness, explainability and closed-loop response capability of safety evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cyber-physical security and automation control of power systems, and in particular to a platform and method for active security lifecycle assessment and verification of power cyber-physical systems. Background Technology

[0002] As the global energy transition continues to deepen, traditional power systems are rapidly evolving into new power systems characterized by a high proportion of renewable energy and power electronic devices. In this process, modern information and communication technologies such as cloud computing, the Internet of Things, and artificial intelligence are deeply coupled with the physical power grid, forming a cyber-physical system (CPS). This deep integration of information and operational technologies, while improving the grid's autonomous control and operational efficiency, has also completely broken down the relatively closed physical security boundaries of traditional power systems. Therefore, effectively assessing and ensuring the cyber-physical composite security of this new power system has become a critical issue that urgently needs to be addressed.

[0003] In a cyber-physical environment with strong coupling, new power systems face severe security threats. On the one hand, various attacks from traditional cyberspace security can easily penetrate the information layer and spread to the physical layer. On the other hand, power grids dominated by new energy sources are characterized by low inertia and weak controllability. In such systems, even a minor alteration of a control command or a slight communication delay can trigger a chain reaction, such as equipment overload and frequency instability. Therefore, in addition to security during the operational phase, security assessment and control must be integrated throughout the entire system lifecycle, from planning and construction to operation and control, and finally to maintenance and decommissioning. Only in this way can the stability of the power grid be truly guaranteed.

[0004] Current power system security assessment systems face two major challenges: First, they require high-quality data; even a small error or omission can affect model results. Furthermore, the indicator system is static and doesn't automatically adjust to real-world conditions, making it impossible to provide such ideal data in actual field environments. Static indicators also fail to adapt to the varying needs of different lifecycle stages; the interweaving of high-dimensional, redundant continuous and discrete indicators easily leads to assessment model failure, severely impacting system response. Second, in terms of assessment engines and algorithms, existing methods often conflate basic system reliability with defensive effectiveness, frequently employing black-box deep learning models lacking interpretability or small-sample statistical models unsuitable for rare attacks. This results in unclear non-linear relationships between input and output, failing to meet dispatchers' requirements for transparency and confidence.

[0005] To address the aforementioned issues, the proactive safety lifecycle assessment and verification platform designed in this invention faces two main technical challenges. First, real-world environments are characterized by high noise levels and significant information gaps. The platform needs to integrate data, mechanisms, and knowledge to construct a foundational data compensation architecture. Simultaneously, continuous and discrete indicators are intertwined across different lifecycle stages, requiring the platform to dynamically identify which indicators are sensitive and which can be reduced, and to adaptively adjust accordingly. Second, security requirements need to be scientifically decoupled and not conflated. Under small sample constraints, the platform must make high-confidence reliability assessments based on limited data. Furthermore, highly interpretable algorithms are needed to uncover the explicit performance analysis function between defense strategies and system performance. Summary of the Invention

[0006] To address the aforementioned issues, this invention discloses a platform and method for proactive security lifecycle assessment and verification of power cyber-physical systems. Specifically, addressing the challenges of proactive security defense caused by incomplete and inaccurate data and static, rigid lifecycle assessments in the cyber-physical coupling environment of novel power systems, this invention proposes a closed-loop verification method that improves existing security assessment schemes, covering both assessment and control stages. Under harsh operating conditions, while ensuring high fidelity and completeness of underlying data input, this method optimizes existing technologies to overcome the performance difficulties of traditional methods, such as the separation of information and physical security, lack of interpretability in assessment algorithms, and severe disconnect between risk assessment and control execution. This achieves precise quantification of cross-domain network composite attack risks and unified adaptive closed-loop defense throughout the entire lifecycle. High robustness and interpretability are crucial requirements in current proactive security monitoring and comprehensive defense of novel power systems, and this method provides strong support for these requirements.

[0007] A platform for active safety lifecycle assessment and verification of power cyber-physical systems includes a multi-source heterogeneous data and dynamic indicator system management module, a dual-drive assessment engine, and a verification simulation and active safety feedback control module. The multi-source heterogeneous data and dynamic indicator system management module, as shown in the diagram, primarily extracts and reduces core safety indicators based on a high-fidelity and complete data foundation and according to the system's lifecycle evolution. The dual-drive assessment engine is responsible for quantitatively calculating system reliability and defense effectiveness based on the extracted indicators. The verification simulation and active safety feedback control module deploys a highly transparent data evaluation environment, performs significance verification of the assessment results and model closed-loop correction, and performs targeted closed-loop control of the system based on the verification results.

[0008] Multi-source heterogeneous data and dynamic indicator system management module: This module is mainly responsible for integrating multi-source heterogeneous data and implementing dynamic indicator management. Addressing the common problems of data gaps and distortion under harsh operating conditions, the module adopts a progressive data governance system to form a high-quality data input set. Building on this, to overcome the limitations of traditional static indicators, the module implements adaptive tailoring of safety indicators throughout the entire lifecycle: on the one hand, it subdivides the system lifecycle into the planning and construction phase, the operation and control phase, and the maintenance and decommissioning phase, dynamically extracting sensitive indicators for the current stage; on the other hand, it introduces a dual dimensionality reduction mechanism to optimize the indicators. This includes using principal component analysis to perform feature dimensionality reduction on continuous numerical data to eliminate multicollinearity, and using rough set theory to perform attribute dependency analysis and remove redundant attributes from discrete state data, ultimately generating a lightweight and highly representative set of evaluation indicators.

[0009] Dual-Driven Evaluation Engine: The evaluation engine consists of a reliability evaluation sub-engine and a performance evaluation sub-engine, achieving a scientific decoupling of security requirements. The reliability evaluation engine incorporates a multi-matrix hierarchical analysis and grey prediction model G(1,h) to handle uncertainties under small-sample attacks and output an objective system reliability level. The performance evaluation engine relies on the GEP algorithm for nonlinear genetic evolution to uncover the explicit mathematical analytical expression between defense investment and system performance, outputting a highly interpretable defense strategy performance score.

[0010] The verification simulation and active safety feedback control module integrates comprehensive verification simulation and active feedback control functions. First, it constructs a multi-domain, multi-timescale parallel simulation environment for the power grid based on high-concurrency data. Using Monte Carlo mixture sampling technology, it generates composite concurrent scenarios of physical faults and network attacks in batches. The score matrix output by the dual-drive evaluation engine is imported into the scenario for simulation. Then, Friedman nonparametric statistical tests are introduced to perform significance analysis on the robustness of the evaluation model, and the residual results are used as feedback signals to input back to the evaluation engine, prompting the model to adaptively adjust parameter weights. After verification, different execution strategies are implemented, setting three control states based on the evaluation score: maintaining a preventative control state when monitoring indicators are normal; issuing an emergency control command directly to the physical layer once the reliability score falls below the safety threshold; and finally, triggering an information layer correction control state when reliability meets the standard but the efficiency evaluation score is low. This allows the new power system to find a suitable balance between security defense and operational efficiency.

[0011] 1. Multi-source heterogeneous data and dynamic indicator system management module

[0012] In the actual operation of new power systems, data collected by SCADA systems and PMU devices often exhibits high noise and packet loss rates due to strong electromagnetic interference, communication network congestion, or denial-of-service (DoS) attacks. Traditional power system safety assessments typically suffer from a fundamental flaw: the use of a fixed set of static indicators. However, the dynamic evolution of actual systems encompasses different lifecycle stages, including planning and construction, operation and control, and maintenance and decommissioning. Static indicators cannot accurately depict this evolutionary trajectory. Furthermore, field monitoring data is both continuous and discrete, and the mixing of large amounts of data can easily lead to inaccurate assessment results and severely slow down the response speed of proactive safety controls. To address this problem, this module's solution involves progressively refining and reconstructing the original incomplete dataset, ultimately outputting a high-fidelity three-dimensional fused feature tensor. This data is then used by the subsequent evaluation engine. Next, sensitive indicators are adaptively extracted based on the system's current lifecycle stage, and a dual dimensionality reduction mechanism using principal component analysis and rough set theory is constructed to completely eliminate redundant features. The specific processing and calculation steps are as follows:

[0013] (1) 3D feature cascade and normalized output

[0014] First, raw, heterogeneous data from the perception layer is received, and timestamps are unified through a clock synchronization protocol to construct the initial time. Observation data vector Data-level fusion and noise reduction are performed, including outlier labeling and noise smoothing for distortion noise caused by sensor interference. A noisy variable, its denoised estimated value This was obtained by solving the following optimization problem:

[0015] ;

[0016] In the formula, It is the actual observed distortion value within the time window. It is a fitted function model. The weights are assigned based on the time decay characteristics.

[0017] This step cleans the data, eliminating random noise and removing distorted data vectors. Updated to a smooth pure data set In response to situations where the system suffers large-scale packet loss due to a network attack, pure data sets... There is an unobserved subset of missing variables in the general. This would render simple data smoothing algorithms ineffective, necessitating the introduction of a power system physical mechanism model for deterministic constraint compensation. Physical mechanism constraint equations are established based on Kirchhoff's laws and the power flow topology relationship. Then, using complete surrounding node data, a safe pseudo-measurement value conforming to the physical boundary was reconstructed. At this point, the smoothed data and the reconstructed data are concatenated to obtain the complete feature set after mechanism compensation. :

[0018] ;

[0019] In obtaining a complete set of values Subsequently, to address complex and multifaceted attacks such as Advanced Persistent Threats (APTs), we further explored the deeper security semantics behind numerical anomalies. We invoked a pre-built knowledge graph of power industry experts. ,in For entities involved in the power information system, For ontology relationships in the system, Rule triples are defined for power information system networks. LeetCode neural networks process structured numerical sets. Mapping to the knowledge graph space, semantic feature vectors representing potential security vulnerabilities in the current system are extracted.

[0020] ;

[0021] The above numerical characteristics include the integrity of physical mechanisms. Semantic features containing deep logic of the root causes of failures Orthogonal concatenation is performed, followed by packaging into a tensor. The final output is a high-fidelity 3D fused feature tensor. :

[0022] ;

[0023] In the formula, This indicates a feature cascade operation.

[0024] (2) Lifecycle stage adaptive matching and feature decoupling

[0025] First, based on the timestamp of the current operating conditions and the operation and maintenance logs, the system identifies the specific stage of the power CPS's current life cycle and calls the corresponding sensitive indicator dictionary.

[0026] The 3D fusion feature tensor input from the previous module Based on the data attributes, the data is analyzed and decoupled into two parallel feature subsets: continuous numerical feature matrices. This includes bus voltage amplitude, real-time communication link delay, generator rotor power angle, etc.; discrete state characteristic matrix. This includes information such as circuit breaker switch status, communication protocol type, and network intrusion detection alarm level.

[0027] (3) Principal component dimensionality reduction of continuous numerical indices

[0028] For the decoupled continuous numerical characteristic matrix Since there is often strong multicollinearity among the various physical parameters of the power system, this step uses principal component analysis for orthogonal transformation and feature dimensionality reduction.

[0029] First, for those containing A time-section sample, The feature matrix of the dimensional continuous index is Z-score standardized to eliminate differences in physical dimensions.

[0030] ;

[0031] In the formula, For the first The first sample The original observations of the continuous index, and These are the sample mean and standard deviation of the indicator, respectively. Calculate the covariance matrix of the standardized feature matrix. as follows:

[0032] ;

[0033] In the formula, The standardized index column vector, This is the mean vector. Next, we solve for the covariance matrix. eigenvalues and the corresponding orthogonal eigenvectors, and calculate the th Variance contribution rate of each principal component :

[0034] ;

[0035] Sort the eigenvalues ​​from largest to smallest, and select those whose cumulative variance contribution rates satisfy... The former Principal components ( , Typically, the value is taken as 80%~95%. Linear projection maps the high-dimensional original data to a low-dimensional orthogonal space, generating a continuous core indicator set after preliminary dimensionality reduction. .

[0036] (4) Rough set attribute reduction of discrete state index

[0037] At different stages of the lifecycle, some discrete state indicators may become ineffective in safety decisions. To address this issue, rough set theory is introduced to analyze the discrete state characteristic matrix. First, identify which indicators are sensitive at each stage, then reduce redundant parts. Based on the characteristics of the current lifecycle stage, construct a decision table for system security assessment. ,in The operating sample domain is the set of all power grid operating samples used for security assessment under the current life cycle stage, including measured and simulated samples of various scenarios such as normal operating conditions, equipment failures, and network attacks. For conditional attribute set, It includes a complete set of discrete indicators, including circuit breaker switch status, communication protocol type, network intrusion detection alarm level, and protection device operation status. This represents the set of security decision attributes for each stage of the lifecycle. Decision attributes are calculated based on information entropy and equivalence relations. Conditional attributes Overall Dependence Next, calculate a specific discrete index. Importance :

[0038] ;

[0039] In the formula, This indicates that indicators are temporarily removed from the set of conditional attributes. Then, the dependence of the remaining attribute set on the decision attribute. Attribute reduction criterion: when calculated... When, it indicates the removal of indicators. The system's security classification decision-making capability remains unchanged, indicating that this discrete indicator is an invalid and redundant attribute at the current lifecycle stage, and the system completely eliminates it; only [the following is retained] The sensitive attributes ultimately form a reduced discrete core indicator set. .

[0040] (5) Dynamic indicator reorganization and standardized output

[0041] Finally, the continuous core indicator set after PCA dimensionality reduction is... Discrete core index set after rough set sensitivity reduction Perform orthogonal recombination of features. Construct a core evaluation index tensor that is representative of the current life cycle stage and free from redundancy and collinearity interference. :

[0042] ;

[0043] 2. Dual-drive evaluation engine module

[0044] Traditional security assessment methods often fail to effectively distinguish between the system's baseline reliability and the efficiency of its defense strategies, and rely excessively on uninterpretable black-box deep neural networks. This not only struggles to address the challenges of small sample sizes and missing information in advanced network attacks within power grid CPS, but also increases the difficulty for grid dispatchers to trust and execute decisions. To solve this problem, this module receives the core assessment index tensor. By constructing a scientifically decoupled dual-drive engine for reliability and efficiency, high-confidence and high-interpretability two-dimensional accurate quantification is achieved under small sample constraints. The specific calculation steps are as follows:

[0045] (1) Weight allocation of small sample indicators based on multi-matrix hierarchical analysis

[0046] By combining expert knowledge graphs with the impact of historical failures, the relative importance of indicators at the same level is objectively scored on a scale of 1-9, constructing a multi-dimensional judgment matrix. The largest eigenvalue of the judgment matrix is ​​determined by solving the problem. and their corresponding orthogonal eigenvectors Calculate the objective weights of each core indicator:

[0047]

[0048] Subsequently, a consistency check is performed on the judgment matrix, and the consistency ratio is calculated. ,satisfy Under the premise of this, output the normalized weight vector of the core system reliability indicators. .

[0049] (2) Quantification of system reliability based on grey system theory

[0050] To address the problem of the extreme scarcity of historical samples from severe cyberattacks, we abandoned the traditional probabilistic model approach that relies on large-sample normal distributions, and instead introduced grey system theory to construct... Dynamic prediction model [1,1]. Extraction Strongly correlated with the system's bottom-line operation The feature time series are used as the original feature series. Next, we perform an accumulation-to-AGO operation to generate an accumulation sequence. :

[0051] ;

[0052] Using the overall reliability state of the system as the system behavior sequence ,the remaining Using these indicators as a sequence of influencing factors, a first-order multivariate differential equation is constructed:

[0053] ;

[0054] In the formula, For the system development coefficient, Let [1,1] be the grey effect of each index. The parameter matrix is ​​then analyzed using the least squares method. A joint solution is performed. The gray comprehensive correlation degree is calculated using the solved evolution parameters, and then combined with the aforementioned weight vector. This objectively maps continuous calculation results to discrete system reliability levels. This engine ensures that it can still output a high-confidence bottom-line security assessment, even with an extremely small number of attack samples.

[0055] (3) Explicit mining of defense effectiveness based on gene expression programming

[0056] The performance evaluation engine focuses on assessing the return on investment in defense. This step calls the GEP algorithm, which combines the linear coding efficiency of genetic algorithms with the tree-like expression capabilities of genetic programming. We use GEP to uncover explicit analytical relationships between independent and dependent variables [1,1].

[0057] First, The defense input parameters are used as the terminal node set of the GEP algorithm, and basic mathematical operators and elementary functions are used as the function node set, encoded using a fixed-length linear gene sequence. The single gene length satisfies... and In the power scenario Take 10 to 20, where This represents the maximum number of operands for the operator. We randomly generate 500-2000 chromosomes that meet the constraints according to this rule to form an initial candidate model population. Then, using a breadth-first traversal, we decode the linear gene string into a mathematical expression tree. The method defaults to 3 gene chromosomes and uses addition to fuse the sub-expressions to obtain the performance prediction value. This design approach is suitable for meeting the linear combination requirements of power defense effectiveness.

[0058] Next, a fitness function centered on minimizing the mean squared error (MSE) is designed. Evaluate and select individuals within the population:

[0059] ;

[0060] In this formula, To assess the size of the sample set, This is the performance prediction score calculated after decoding the current GEP individual. This is the performance benchmark value based on the actual feedback from the physical power grid. Range of values In actual computation, the defense deployment features of the training set are substituted into the mathematical formula after decoding each chromosome. Predicted values ​​are calculated for each sample, and then the residuals, mean squared errors, and fitness scores are calculated sequentially using the above formulas. Genetic operators such as selection, crossover, mutation, and insertion are used to perform multi-generation adaptive evolution of the population. When the fitness... Once the convergence criterion is met, the optimal gene sequence will be decoded, and an explicit nonlinear mathematical analytical expression relating defense input and system performance will be output. Its general form can be further simplified to a superposition of linear and nonlinear terms. ,in The coefficients of the linear terms generated for GEP evolution correspond to the weights of each defense input parameter; The coefficients of the nonlinear term; These are the elementary function terms selected during the evolutionary process; This is a constant term in the model.

[0061] Will By substituting the real-time defense deployment parameters into the above explicit analytical expression, the effectiveness score of the current strategy can be calculated. Through algorithm iteration, we obtained the final explicit formula for the fit:

[0062]

[0063] This analytical expression can clearly demonstrate the contribution of each defense investment to the overall system effectiveness, providing power grid dispatchers with highly transparent and traceable security decision support.

[0064] (4) Cascaded output of two-dimensional evaluation results

[0065] We will evaluate the reliability level output by the reliability assessment engine. Performance score output by the performance evaluation engine Cascaded encapsulation is performed to form a two-dimensional evaluation result feature matrix. .

[0066] 3. Verification Simulation and Active Safety Feedback Control Module

[0067] Traditional evaluation methods are mostly limited to static open-loop testing of data, lacking consideration of the evolution of complex faults, and the evaluation conclusions often lack rigorous statistical support. This module, based on the data generation method for evaluation, introduces Monte Carlo mixture sampling and Friedman's nonparametric statistical test to analyze the feature matrix output by the evaluation engine. Robustness verification and closed-loop correction under extreme operating conditions are performed. The specific verification and correction steps are as follows:

[0068] (1) Generation of composite scenes based on Monte Carlo mixture sampling

[0069] We first build a parallel simulation environment in the digital space, requiring strict clock synchronization with the physical power grid and high fidelity. Then, we complete two steps: First, we estimate the failure rate of physical domain devices and the probability of network attacks in the information domain from historical operational data and network security logs—these two serve as prior distributions. Second, we use Monte Carlo mixture sampling to generate scenarios, weighting high-risk threats during sampling to increase their probability of being selected. Finally, we generate scenarios in batches. Group concurrency scenario sample set Each sample contains a combination of physical line short circuits and network denial-of-service. For any generated composite scenario... Its probability distribution is expressed as:

[0070] ;

[0071] In the formula, and These represent the uncertainty feature spaces on the physical and information sides, respectively. and For specific fault or attack status variables.

[0072] (2) Parallel simulation of data and statistical significance test

[0073] The above generated Extreme complex scenarios are processed batch by batch and loaded into the data simulation module for evolution simulation. Simultaneously, the dual-drive evaluation engine of this invention is invoked. Different evaluation models are used to score each scenario simultaneously. To verify whether the model of this invention has statistical significance in the face of multiple uncertainties, a Friedman nonparametric test is introduced. Each composite scenario... Below Each assessment score is sorted from smallest to largest and assigned a ranking. ( , ). Calculate the first Rank sum of various evaluation models :

[0074] ;

[0075] Calculate the Friedman test statistic. :

[0076] ;

[0077] We take the significance level. Find the critical value by consulting the chi-square distribution table. If calculated If the null hypothesis is rejected, then statistically it can be considered that the evaluation results of the present invention are indeed superior and have a higher confidence level.

[0078] (3) Model residual feedback and adaptive closed-loop correction

[0079] If the Friedman test fails due to a sudden change in the power grid topology, or in a specific scenario... If the evaluation score deviates significantly from the actual crash consequences of the data evaluation system, the system will automatically calculate the model prediction residual matrix. The residual signal is used as a feedback compensation term and input back into the dual-drive evaluation engine. The gradient descent method is used to evaluate the gray action parameters of the gray prediction model. Adaptive adjustments are made, and the penalty weights of the fitness function in the GEP algorithm are adjusted to provide feedback correction to the driving evaluation model.

[0080] Then, the two-dimensional evaluation result matrix, which has been verified to be error-free in real-time analysis, is used. From this, we extract two key indicators for the current system: reliability level. Performance score Furthermore, this invention presets two thresholds: one is a reliability threshold for determining whether the system is in an absolutely safe state. Another is the economic threshold for determining whether the system has reached its optimal economic state. .

[0081] (4) Safety status determination and control mode optimization

[0082] When the judgment This indicates that an advanced persistent attack (APA) at the information layer has penetrated the defenses and is about to trigger a chain reaction of overloads or frequency instability in physical devices. At this point, the module forcibly triggers emergency control mode. The system bypasses the conventional economic scheduling process and, based on the principle of local control, directly issues millisecond-level emergency commands to the physical actuators in the threatened area: including precisely cutting off non-critical loads in the affected area, executing generator disconnection, or completely isolating infected communication nodes on the physical link through a smart gateway, in order to respond extremely quickly and prevent the spread of the risk.

[0083] When the judgment but This indicates that while the current system maintains physical baseline security, the cost of defense is too high. At this point, the module triggers a correction control mode. Combining deep reinforcement learning algorithms and comprehensively considering the Pareto boundary between security requirements and communication efficiency, it automatically generates and distributes information layer correction strategies: such as dynamically lowering the encryption level of edge non-critical business data streams and optimizing backup routing paths in the underlying SDH network, thereby re-establishing an optimal balance between resisting network threats and maintaining real-time interaction with the power grid.

[0084] After the control commands at the physical or information layer are executed, the overall operating status of the new power system evolves and changes. New massive amounts of heterogeneous sensor data flow back into the multi-source heterogeneous data and dynamic indicator system management module.

[0085] This invention is a method for active security lifecycle assessment of power cyber-physical systems, and the specific steps are as follows:

[0086] Step 1: First, at the platform's underlying layer, heterogeneous state data of the new power system is collected through multi-source sensors such as SCADA and PMU, and the initial time is constructed by aligning the timestamps. Observation data vector Pure data set after noise reduction To address the missing variables caused by communication interruptions or network attacks, a power physics mechanism constraint equation is introduced for feature solving. This reconstructs pseudo-measured values ​​that conform to the physical boundaries, which are then concatenated with the pure data set to obtain a complete feature set after mechanism compensation. Proceed to step 2.

[0087] Step 2: Invoke the pre-built power expert knowledge graph containing a massive amount of historical faults. Using graph neural networks to structured sets Mapped to In this process, unstructured semantic feature vectors representing current potential security risks are extracted. The two are orthogonally concatenated to output a high-fidelity 3D fused feature tensor. Proceed to step 3.

[0088] Step 3: Based on the current lifecycle stage of the system, extract the dictionary of sensitive indicators for the current stage. Decoupled into continuous numerical characteristic matrix With discrete state type characteristic matrix Proceed to step 4.

[0089] Step 4: [Regarding...] Z-score standardization was performed to eliminate dimensional differences, and the covariance matrix was calculated and eigenvalues ​​were extracted. Eigenvalues ​​were selected based on the cumulative variance contribution rate being greater than or equal to... The former One principal component is used to generate a continuous core indicator set that eliminates multicollinearity. Proceed to step 5.

[0090] Step 5: First, based on rough set theory and combined with expert security labels, analyze the discrete-state feature matrix. Construct a decision table, and calculate the importance of each discrete indicator based on the decision table. Then remove importance. Redundant conditional attributes are removed, and only sensitive attributes are retained to form a reduced discrete core index set. Finally, the continuous core indicator set... With discrete core indicator set Merge and construct core evaluation indicator tensors Then input the data into the dual-drive evaluation engine. Proceed to step 6.

[0091] Step 6: Calculate using the Analytic Hierarchy Process (AHP). Objective weight vector of indicators at each level To address the small sample features resulting from the attack, construct... The grey prediction model solves first-order multivariate differential equations to uncover the state evolution patterns, and outputs the current reliability level of the system by combining weight vectors. Proceed to step 7.

[0092] Step 7: First, the defense input parameters and system performance indicators are used as terminal sets, and the population is initialized using fixed-length gene encoding. Then, a fitness function is designed with the goal of minimizing the mean squared error, and the GEP algorithm is programmed using gene expressions. Genetic operations such as crossover and mutation drive the population to undergo adaptive evolution. After evolution, the gene sequence with the best performance is decoded, and an explicit performance mathematical expression is output. Based on this, the policy performance score is calculated. Finally, the reliability level will be determined. Performance score Cascaded to form a two-dimensional evaluation result matrix Proceed to step 8.

[0093] Step 8: First, based on the prior probability distribution of physical failures and network attacks, a Monte Carlo mixture sampling method is used to generate batches. The system simulates and scores extreme concurrent scenarios. Then, it loads the trained evaluation engine into each scenario group for synchronous simulation and scoring, collecting the score distribution data for all scenarios. Next, the collected score data is sorted and assigned ranks, and the Friedman test statistic is calculated. . judge If the value is greater than the critical value at the given significance level, then the significance and confidence of the evaluation result are deemed to meet the standard, and proceed to step 9; if the value is less than or equal to the critical value, then the model prediction residual is calculated as a feedback signal to reverse the gray action and fitness weight parameters in steps 6 and 7, and the evaluation is performed again.

[0094] Step 9: Verify the matrix that has been verified. Perform analysis and comparison Compared with the preset system security and reliability threshold .if If an information layer risk is identified, an emergency control mode is triggered. The system directly issues action commands to the physical layer to disconnect machines, remove loads, or isolate attacked nodes, and then proceeds to step 11. Otherwise, proceed to step 10.

[0095] Step 10: Comparison Compared with the preset optimal performance economic threshold .if The system is determined to maintain basic security, but the cost of defense is too high, triggering a correction control mode. An information layer correction strategy is then issued to balance system security and efficiency. Proceed to step 13.

[0096] Step 11: After the physical layer emergency control or information layer correction control command is executed, the overall operating status of the new power system evolves and changes. New heterogeneous sensor data is collected and flows into the platform's underlying layer, completing the process loop and returning to Step 1 for the next cycle of real-time monitoring and dynamic evaluation.

[0097] The beneficial effects of this invention are:

[0098] (1) A full lifecycle data governance and dynamic indicator adaptive reduction mechanism is proposed. Traditional methods use a set of static indicators to apply to all stages, while this invention dynamically extracts sensitive indicators based on the evolution characteristics of different stages such as planning and construction, operation and control. On this basis, principal component analysis and rough set theory are combined to perform dual dimensionality reduction on two types of mixed variables, namely continuous numerical and discrete state variables, to eliminate redundant attributes. This effectively solves the dimensionality curse problem caused by the interweaving of massive indicators and significantly shortens the evaluation response time of proactive safety control.

[0099] (2) A dual-drive interpretable evaluation engine was constructed. On the one hand, multi-matrix hierarchical analysis and grey prediction models were used to mine the intrinsic evolutionary laws of small-sample attack characteristics, ensuring the confidence level of bottom-line reliability assessment under rare advanced cyber threats; on the other hand, the Genetic Expression Programming (GEP) algorithm was used to quantify the system's defense effectiveness. Compared with the traditional deep neural network black-box model, the GEP algorithm can mine the explicit mathematical analytical expression between defense investment and system returns, providing power grid dispatchers with highly transparent and traceable security decision support.

[0100] (3) A closed-loop process of verification feedback to achieve proactive control has been formed. Monte Carlo mixed sampling is used to generate composite attack scenarios of the power grid in batches, and Friedman nonparametric test is used to conduct rigorous statistical significance verification and model correction of the evaluation scores; finally, based on the verified scores, emergency control at the physical layer or adaptive correction control at the information layer is triggered in a targeted manner. This mechanism avoids the limitations of post-event analysis and realizes the leap of the power cyber-physical system from passive monitoring to active defense and self-correction throughout the entire life cycle. Attached Figure Description

[0101] Figure 1 This is a structural diagram of the active security full life cycle assessment and verification platform for power information physical systems of the present invention;

[0102] Figure 2 This is the architecture diagram of the active security full life cycle assessment and verification platform for power information physical systems of the present invention;

[0103] Figure 3 This is a diagram illustrating the operational effect of the power information physical system active security full life cycle assessment and verification platform of this invention;

[0104] Figure 4 This invention compares the accuracy retention rates of various schemes under different data packet loss rates.

[0105] Figure 5 This is a comparison chart of the evaluation accuracy of various schemes under the small sample attack scenario of this invention;

[0106] Figure 6 This is a comparison chart of the evaluation response delay distribution between the present invention and other solutions;

[0107] Figure 7 This is a comprehensive comparison chart of the core performance indicators of this invention and other solutions;

[0108] Figure 8 This is a comparison chart of the real-time bus voltage deviation performance of various schemes under different disturbance periods of the present invention. Detailed Implementation

[0109] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. It should be noted that the terms "front," "rear," "left," "right," "up," and "down" used in the following description refer to directions in the accompanying drawings, and the terms "inner" and "outer" refer to directions toward or away from the geometric center of a specific component, respectively.

[0110] like Figure 1 As shown, the platform of this invention mainly consists of three modules: a multi-source heterogeneous data and dynamic indicator system management module, a dual-drive evaluation engine, and a verification simulation and proactive safety feedback control module. Figure 2 The platform's overall architecture was further demonstrated, including the complete data flow from data acquisition, feature fusion, indicator reduction, dual-engine evaluation to verification feedback and closed-loop control. The following implementation is illustrated using a typical regional new power system demonstration project with a high proportion of renewable energy integration.

[0111] This embodiment uses a typical regional new power system demonstration project with a high proportion of renewable energy access as the application scenario. The regional power grid includes multiple distributed photovoltaic power stations, energy storage units, and flexible DC loads. Each regional microgrid is deeply coupled with the main grid and adopts a collaborative dispatch architecture. To address the strong electromagnetic noise interference, communication network congestion, and potential cross-space composite attack risks faced by the system in daily operation, the proposed active security full lifecycle assessment and verification platform for power cyber-physical systems is deployed. The specific implementation process is as follows:

[0112] 1. System initialization and status parameter setting

[0113] Taking the operational control phase as an example, the implementation method is similar to other lifecycle phases. In this phase, the focus of security defense is no longer on comprehensive coverage, but rather on achieving faster real-time response speeds and stronger resistance to attacks. Based on this goal, the platform's proactive security feedback control module pre-sets two thresholds: one is an absolute security and reliability threshold. The other is the optimal efficiency economic threshold. .

[0114] 2. Multi-source data fusion, dynamic indicator reduction, and dual-drive evaluation

[0115] Assuming in During this period, the regional power grid experienced an abnormal network congestion, which caused distortion and large-scale packet loss in the measurement data uploaded to the cloud by some smart terminals.

[0116] (1) Dynamic reduction: The platform reduces the three-dimensional fusion feature tensor based on the sensitive indicators of the current operation control period. Decoupling. Principal component analysis is used to reduce the dimensionality of continuous numerical features, such as voltage deviation and communication delay, and to extract the cumulative variance contribution rate. The principal components are used; the importance of discrete state attributes is calculated using rough set theory, and irrelevant and redundant indicators with an importance of 0 are completely eliminated, outputting a lightweight core evaluation index tensor. .

[0117] (2) Dual-engine computing: The data is simultaneously fed into the dual-drive evaluation engine. The reliability evaluation engine establishes a system based on the currently collected small sample attack characteristics. The grey prediction model calculates the reliability score of the current system. The performance evaluation engine utilizes a gene expression programming algorithm for multi-generational evolution to uncover the explicit mathematical analytical expression of the impact of the current defense strategy on system performance, and calculates the current strategy performance score. .

[0118] 4. Data verification and proactive feedback control

[0119] (1) Parallel simulation and significance verification: To ensure that the obtained evaluation scores are not noise caused by model overfitting, the platform generates data based on Monte Carlo mixture sampling in the data simulation. A series of composite test scenarios were used to collect the model's score distribution across each scenario. The statistical statistic was calculated using the Friedman nonparametric test. In order to satisfy Under these conditions, we rigorously demonstrate that the current evaluation results are statistically significant and have high confidence.

[0120] (2) Active safety closed-loop control: The active feedback control module receives the evaluation result matrix that has been verified to be correct.

[0121] Logical Decision 1: Assuming that after the evaluation results are obtained, it is found that... This indicates that the risk of advanced persistent attacks (APAs) at the information layer has penetrated the protective barriers and is approaching the collapse threshold of the physical system. At this point, the platform no longer follows the conventional economic scheduling process but forcibly bypasses it, directly triggering the emergency control mode. Specifically, it issues a millisecond-level command to the physical layer: precisely cuts off non-critical loads within the affected area, while simultaneously isolating infected communication gateways on the physical links to prevent the risk from cascading and spreading across domains.

[0122] Logical Decision 2: If the evaluation result satisfies but This indicates that while the current system maintains physical baseline security, it has encountered situations where, for example, extremely redundant encryption strategies lead to severe command delays and excessively high defense costs. The platform triggers a correction control mode, automatically disseminating information layer correction strategies using reinforcement learning algorithms. These strategies include dynamically lowering the encryption level of non-critical business data streams and optimizing backup routing paths in the underlying network. This achieves a renewed balance between mitigating network threats and maintaining real-time interaction with the power grid.

[0123] This embodiment improves the dynamic indicator management method based on the fusion of multi-source heterogeneous data. According to the specific stage of the system's entire lifecycle, it uses adaptive triggering principal component analysis (PCA) and rough set theory to jointly reduce the dimensionality and redundancy of continuous and discrete mixed feature variables, optimizing the core computing layer evaluation engine and constructing an improved evaluation engine driven by both reliability and performance. The reliability evaluation engine incorporates multi-matrix hierarchical analysis (AHP) and a grey prediction model, improving the handling of attack uncertainty under conditions of small sample size and missing information, ultimately outputting a more robust reliability level. The performance evaluation engine relies on Genetic Expression Programming (GEP). This method helps to uncover explicit mathematical analytical expressions between defense investment and system performance, ensuring high interpretability of evaluation results and accurate quantification of defense strategy effectiveness. Regarding the comprehensive verification method, Monte Carlo mixed sampling is still used to generate extreme complex concurrent scenarios in batches. Friedman nonparametric statistical tests are used to verify the significance of evaluation scores and correct closed-loop model parameters. Finally, based on the above verification results, differentiated execution logic is established to selectively trigger emergency control at the physical layer and adaptive correction control at the information layer. This improved method ensures the accuracy of the system's full lifecycle assessment through the synergistic optimization of the closed-loop control mechanism and forms a good physical feedback closed loop.

[0124] Qualitative analysis of the technical effects of the examples:

[0125] like Figure 3 The diagram shows that this invention constructs an active safety full life cycle assessment and verification platform for power information physical systems. It generates composite scenarios through Monte Carlo simulation, uses Friedman nonparametric statistical tests for significance determination, and utilizes residual reverse compensation to correct the assessment engine, providing a reliable verification basis for subsequent assessments.

[0126] like Figure 4 , Figure 6 , Figure 7 As shown, through the above implementation steps, this invention achieves significant quantifiable advantages compared to traditional open-loop, static index evaluation methods. Firstly, when facing severe operating conditions such as data packet loss, traditional pure data-driven models are prone to power grid malfunctions or failures to operate due to input gaps. However, the three-dimensional fusion compensation mechanism and dynamic stage reduction mechanism of this invention not only maintain an evaluation accuracy of 89.2% even with a 30% data packet loss rate, improving by 69.3% compared to the optimal traditional solution, but also effectively resolves the curse of dimensionality through dual dimensionality reduction using PCA and rough set theory, compressing the average evaluation response delay to 21.3ms, improving by 258.7% compared to the fastest traditional solution, fully meeting the stringent requirements of active safety emergency control for millisecond-level response.

[0127] Furthermore, addressing the pain point of scarce attack samples, such as advanced persistent threats, the gray prediction model G(1,h) built into this invention achieves an evaluation accuracy of 87.6% with only 10 historical attack samples. Figure 5 As shown, this represents a 107.1% improvement over the optimal traditional solution, enabling timely identification of potential risks in the early stages of an attack. Furthermore, the explicit mathematical analytical expression output by the GEP algorithm in the dual-drive engine clearly quantifies the contribution of each defense input parameter to the overall system performance, providing dispatchers with highly transparent and traceable proactive defense decision support—something traditional black-box models cannot achieve. The closed-loop verification and proactive feedback control mechanism further controls the bus voltage deviation within ±2.1kV in a combined scenario of 30% data packet loss and spoofed data injection attacks. Figure 7 and Figure 8 As shown, this reduces power consumption by 73.1% compared to the optimal traditional solution, effectively avoiding equipment damage and large-scale power outages caused by voltage exceeding limits.

[0128] like Figure 6 As shown, the average evaluation response latency of the present invention is only 21.3ms; while the average latencies of the traditional LSTM black box solution, FTA static solution and the situational awareness solution are 127.5ms, 98.2ms and 76.4ms respectively. The response speed of the present invention is 258.7% faster than the fastest traditional solution, meeting the stringent requirements of millisecond-level response for active safety emergency control of power systems.

[0129] like Figure 7 and Figure 8 As shown, the closed-loop verification and active feedback control mechanism of this invention achieves a leap from passive monitoring to active defense. In a scenario with combined disturbances of 30% data packet loss and spoofed data injection attacks, the solution of this invention controls the bus voltage deviation within ±2.1kV; while the voltage deviations of traditional LSTM black-box solutions, FTA static solutions, and situational awareness solutions reach ±7.8kV, ±11.3kV, and ±9.5kV, respectively. This solution reduces voltage fluctuation amplitude by 73.1%, effectively avoiding equipment damage and large-scale power outages caused by voltage exceeding limits. Figure 7 Show a comparison of comprehensive indicators. Figure 8 Furthermore, the real-time performance of voltage deviation under different disturbance periods is presented. The solution of this invention remains stable within ±2.1kV with minimal fluctuation.

[0130] The technical means disclosed in this invention are not limited to those disclosed in the above embodiments, but also include technical solutions composed of any combination of the above technical features.

Claims

1. A platform for active safety full life-cycle assessment and verification of power cyber-physical systems, characterized in that: It includes a multi-source heterogeneous data and dynamic indicator system management module, a dual-drive evaluation engine, and a verification simulation and proactive safety feedback control module. The multi-source heterogeneous data and dynamic indicator system management module is used to perform noise reduction, mechanism compensation and knowledge graph semantic mapping on multi-source heterogeneous data, output three-dimensional fusion feature tensors, and, based on the current life cycle stage of the system, combine principal component analysis (PCA) and rough set theory to perform dynamic dimensionality reduction and redundant attribute reduction on continuous numerical and discrete state features, generating core evaluation indicator tensors. A dual-drive evaluation engine, connected to the multi-source heterogeneous data and dynamic indicator system management module, includes: a reliability evaluation sub-engine, which incorporates multi-matrix hierarchical analysis (AHP) and a grey prediction model G(1,h) to output system reliability levels under small-sample attack conditions; and an effectiveness evaluation sub-engine, which relies on the gene expression programming GEP algorithm to mine explicit mathematical analytical expressions between defense investment and system performance and output effectiveness scores. The dual-drive evaluation engine cascades reliability levels and effectiveness scores to form a two-dimensional evaluation result matrix. A verification simulation and proactive security feedback control module, connected to the dual-drive evaluation engine, is used to generate extreme composite concurrency scenarios based on Monte Carlo mixed sampling, perform significance verification and model parameter closed-loop correction of the evaluation results using Friedman nonparametric statistical tests, and trigger emergency control at the physical layer or adaptive correction control at the information layer based on the comparison results of the verified two-dimensional evaluation result matrix and preset thresholds.

2. A method for active security lifecycle assessment and verification of a power cyber-physical system, based on the active security lifecycle assessment and verification platform for a power cyber-physical system as described in claim 1, characterized in that, Includes the following steps: Step 1: Collect heterogeneous state data of the new power system using multi-source sensors such as SCADA and PMU, and construct the initial time by aligning the timestamps. Observation data vector Pure data set after noise reduction For missing variables, electrical physics mechanism constraint equations are introduced to reconstruct pseudo-measured values, and... By splicing, a complete feature set after mechanism compensation is obtained. ; Step 2: Invoke the pre-built power expert knowledge graph containing a massive amount of historical faults. Using graph neural networks to structured sets Mapped to In this process, unstructured semantic feature vectors representing current potential security risks are extracted. ;Will and Orthogonal stitching outputs a 3D fused feature tensor. ; Step 3: Based on the current lifecycle stage of the system, extract the dictionary of sensitive indicators for the current stage, and... Decoupled into continuous numerical characteristic matrix With discrete state type characteristic matrix ; Step 4: [Regarding...] Z-score standardization was performed, the covariance matrix was calculated, and eigenvalues ​​were extracted. Eigenvalues ​​with a cumulative variance contribution rate greater than or equal to [value missing] were selected. The former One principal component generates a continuous set of core indicators. Based on rough set theory and combined with expert security labels, the discrete state-type feature matrix is ​​analyzed. Construct a decision table and calculate the importance of each discrete indicator. Remove importance Redundant conditional attributes are used to obtain a discrete core index set. ;merge and Constructing core evaluation index tensors And input it into the dual-drive evaluation engine; Step 5: Use AHP to calculate Objective weight vector of indicators at each level ; build The grey prediction model solves first-order multivariate differential equations, combined with... Output the current reliability level of the system ; Step 6: Using the GEP algorithm, the defense input parameters are used as the terminal set. A fitness function is designed with the goal of minimizing the mean squared error. Genetic operations drive population evolution, outputting an explicit mathematical expression for effectiveness, and calculating the strategy effectiveness score. ; Reliability level Performance score Cascaded to form a two-dimensional evaluation result matrix ; Step 7: First, based on the prior probability distribution of physical failures and network attacks, Monte Carlo mixture sampling is used to generate batches. In a set of extremely complex concurrent scenarios, the evaluation engine was loaded into each scenario group for synchronous simulation and scoring, and the Friedman nonparametric test was used to calculate the statistical statistic. ,judge If the value is greater than the critical value at a given significance level, and if it is not passed, calculate the reverse correction grey action of the model prediction residual and the fitness weight parameters and re-evaluate. Step 8: Verify the matrix that has been verified. Perform analysis and comparison Compared with the preset system security and reliability threshold ,like Determine information layer risks and trigger emergency control mode; trigger physical layer emergency control. Otherwise compare At the efficiency threshold ,like This triggers information layer correction control; after executing the instruction, it returns to step 1 to perform real-time monitoring and dynamic evaluation for the next cycle.

3. The method for active security full life cycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 1 includes the following steps: Step 11: Process the original observation data vector Noise reduction is performed by solving an optimization problem. The denoised estimates are obtained, resulting in the pure dataset. ; In the formula, It is the actual observed distortion value within the time window. It is a fitted function model. The weights are assigned based on the time decay characteristics; Step 12: For the subset of missing variables Introducing electrical physics mechanism constraint equations Reconstructing a safe pseudo-measurement value that conforms to the physical boundary ; Step 13: Convert the pure data set With pseudo-measured values By splicing, a complete feature set after mechanism compensation is obtained. .

4. The method for active security full life cycle assessment and verification of a power information physical system according to claim 1, characterized in that: Step 2 specifically includes the following steps: Step 21: Invoke the pre-built power expert knowledge graph ,in For entities involved in the power information system, For ontology relationships in the system, Rule triples defined for power information system networks; Step 22: Use a graph neural network to process the structured numerical data set Mapping to the knowledge graph space to extract semantic feature vectors ,in ; Step 23: Complete the feature set after mechanism compensation With semantic feature terms Perform orthogonal stitching to output a 3D fused feature tensor. : In the formula, This indicates a feature cascade operation.

5. The method for active security lifecycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 3 specifically includes the following steps: Step 31: Based on the timestamp of the current system operation status and the operation and maintenance logs, identify the specific stage of the life cycle that the power information physical system is currently in; Step 32: Call the sensitive indicator dictionary for the corresponding stage; Step 33: merging the three-dimensional feature tensor The data is analyzed based on its attributes and decoupled into a continuous numerical feature matrix. With discrete state type characteristic matrix .

6. The method for active security full life cycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 4 specifically includes the following steps: Step 41: For continuous numerical characteristic matrices Perform Z-score standardization, according to Calculation, where For the first The first sample The original observations of the continuous index, and These are the sample mean and standard deviation of the indicator, respectively. Step 42: Calculate the covariance matrix of the standardized feature matrix. , ; In the formula, The standardized index column vector, The mean vector is given; then the covariance matrix is ​​solved. eigenvalues and the corresponding orthogonal eigenvectors, and calculate the th Variance contribution rate of each principal component : ; Step 43: Select cumulative variance contribution rates greater than or equal to The former One principal component, with values ​​ranging from 80% to 95%; generating a continuous set of core indicators. ; Step 44: For discrete state characteristic moments Decision table constructed based on rough set theory ,in For running sample universe of discourse, For conditional attribute set, Security decision attribute set for each stage of the lifecycle Step 45: Calculate the importance of each discrete index. : ; In the formula, This indicates that indicators are temporarily removed from the set of conditional attributes. Then, the dependence of the remaining attribute set on the decision attribute; Step 46: Eliminate based on importance Redundant condition attributes, only retain Based on the sensitive attributes, a discrete core indicator set is obtained. ; Step 47: Combine the continuous core indicator set With discrete core indicator set Perform orthogonal recombination of features to construct a core evaluation index tensor. And input it into the dual-drive evaluation engine; 。 7. The method for active security full life cycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 5 includes the following steps: Step 51: Using the multi-matrix hierarchical analysis method (AHP), combined with expert knowledge graphs and the impact of historical faults, an objective score on a 1-9 scale is performed to construct a multi-dimensional judgment matrix. Find the largest eigenvalue of the judgment matrix. and their corresponding orthogonal eigenvectors ,according to Calculate the objective weights of each core indicator, then conduct a consistency check, and calculate the consistency ratio. ,satisfy At that time, the normalized weight vector is output. ; Step 52: Introduce grey system theory to construct Dynamic prediction model, extract Strongly correlated with the system's bottom-line operation The feature time series are used as the original feature series. Then, perform an accumulation operation to generate an AGO sequence. : ; Step 53: Use the overall system reliability state as the system behavior sequence ,the remaining Using these indicators as a sequence of influencing factors, a first-order multivariate differential equation is constructed: ; In the formula, For the system development coefficient, The gray effect of each indicator; Step 54: Apply the least squares method to the parameter matrix. Perform a joint solution to calculate the grey comprehensive correlation degree, and combine it with the weight vector. The calculation results are mapped to discrete system reliability levels. .

8. The method for active security lifecycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 6 specifically includes the following: Step 61: Put The defense input parameters are used as the terminal node set of the GEP algorithm, and basic mathematical operators and elementary functions are used as the function node set. A fixed-length linear gene sequence is used for encoding; the single gene length satisfies... and ;in Take 10-20, To determine the maximum number of operands for the operator, 500–2000 chromosomes that meet the constraints are randomly generated to form an initial candidate model population; Step 62: Next, decode the linear gene string into a mathematical expression tree using breadth-first traversal; The default configuration uses 3 gene chromosomes, and the efficacy prediction value is obtained by additively fusing the sub-expressions. ; Step 63: Calculate the fitness function with the core objective of minimizing the mean square error. Evaluate and select individuals within the population: ; In the formula, To assess the size of the sample set, This is the performance prediction score calculated after decoding the current GEP individual. This is the benchmark value for the actual feedback efficiency of the physical power grid; Range of values ; Step 64: Use genetic operators such as selection, crossover, mutation, and insertion to perform multi-generation adaptive evolution on the population, when the fitness... After the convergence criteria are met, the table will be... ,in The coefficients of the linear terms generated by GEP evolution. The coefficients of the nonlinear term; These are the elementary function terms selected during the evolutionary process; For constant terms; Step 65: [The text appears to be incomplete and contains several grammatical errors. A more accurate translation would require the Substituting the real-time defense deployment parameters into the above explicit analytical formula, the effectiveness score of the current strategy is calculated. and reliability level Performance score output by the performance evaluation engine Cascaded encapsulation is performed to form a two-dimensional evaluation result feature matrix. .

9. The method for active security full life cycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 7 specifically includes the following steps: Step 71: Construct a high-fidelity parallel simulation environment in the digital space that is strictly synchronized with the physical power grid clock; Step 72: Estimate the failure rate of physical domain devices and the probability of network attacks in the information domain from historical operation data and network security logs, respectively, as prior distributions; Step 73: Using the Monte Carlo mixture sampling method, the probability of high-risk threats being selected is increased by weighting them, and batch generation is performed. Group concurrency scenario sample set Each sample contains a combination of physical line short circuits and network denial-of-service. For any generated composite scenario... Its probability distribution is expressed as: ; In the formula, and These represent the uncertainty feature spaces on the physical and information sides, respectively. and For specific fault or attack status variables; Step 74: Generate Extreme complex scenarios are processed batch by batch and loaded into the data simulation module for evolution simulation, while including a dual-drive evaluation engine. Different evaluation models are used to score each scenario simultaneously; Step 75: Introduce Friedman's nonparametric test; for each composite scenario Below Each assessment score is sorted from smallest to largest and assigned a ranking. ( , ); calculate the first Rank sum of various evaluation models : ; Calculate the Friedman test statistic. : ; Step 76: Determine the significance level Find the critical value by consulting the chi-square distribution table. If calculated If the null hypothesis is rejected, the significance and confidence level of the evaluation result are deemed sufficient, and the process proceeds to step 8; otherwise, the model prediction residual matrix is ​​calculated. The gradient descent method is used to correct the gray action in step 5. The penalty weights of the GEP fitness function in step 6 are adjusted and re-evaluated.

10. The method for active security full life cycle assessment and verification of a power information physical system according to claim 2, characterized in that: Step 8 specifically includes the following steps: Step 81: From the verified two-dimensional evaluation result matrix Extract the reliability level of the current system Performance score ; Step 82: Comparison Compared with the preset system security and reliability threshold ,like The system determined that an advanced persistent attack on the information layer had penetrated the defense barrier, triggering emergency control mode. Step 83: In emergency control mode, bypass the regular economic dispatch process and, based on the principle of local control, directly issue millisecond-level emergency instructions to the physical execution agencies in the threatened area, including: accurately cutting off non-critical loads in the affected area, executing generator disconnection, and completely isolating the attacked and infected communication nodes on the physical link through the smart gateway to block the spread of risk; then return to step 1; Step 84: When determining Then compare Compared with the preset optimal performance economic threshold ,like The system determines that while it maintains physical safety, the cost of defense is too high, thus triggering a correction control mode. Step 85: In the correction control mode, combined with deep reinforcement learning algorithms, and taking into account the Pareto boundary of security requirements and communication efficiency, the information layer correction strategy is automatically generated and issued, including: dynamically reducing the encryption level of non-critical business data streams and optimizing the backup routing path of the underlying SDH network, so as to re-establish the optimal balance between resisting network threats and maintaining real-time interaction of the power grid; Step 86: After the physical layer emergency control or information layer correction control command is executed, the panoramic operation status of the new power system evolves and changes, new heterogeneous sensor data is collected and flows into the underlying platform, and returns to Step 1 for the next cycle of real-time monitoring and dynamic evaluation.