Key node security protection method and device for power system
Patent Information
- Application Number
- CN202611145421.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-30
- Publication Date
- 2026-09-15
AI Technical Summary
[0005]本发明提供了一种电力系统的关键节点安全防护方法、一种电力系统的关键节点安全防护装置、一种电子设备及一种存储介质,用于解决或部分解决相关技术难以同时刻画攻击者攻击节点数量的不确定性、攻击者针对防御结果的最坏响应、节点负荷与网络结构耦合影响以及多攻击场景下的期望风险的技术问题
[0045]This paper presents a method for protecting critical nodes in a power system. First, a network model of the power system is obtained as the data foundation for subsequent analysis. Then, based on the identification of node load-network centrality coupling, a set of critical nodes in the network model is constructed. Based on this set, a set of candidate defense strategies is generated using a greedy-random hybrid sampling method. This set includes multiple candidate defense strategies. Therefore, when determining critical nodes, a comprehensive screening criterion of node load and network centrality coupling is used, taking into account both the direct load consequences of node failure and the network bridging effect, reducing the bias caused by a single ranking criterion and improving the accuracy of critical node identification. In generating candidate defense strategies, a greedy-random hybrid sampling method is used to control the number of defense and attack strategies evaluated within a preset upper limit, avoiding a double-layer exhaustive search of all combinations and reducing the complexity of the combination search. The expected load loss of each candidate defense strategy under the worst-case attack search is calculated, and the candidate defense strategy with the minimum expected load loss is determined as the optimal defense strategy. This optimal defense strategy is used to strengthen and optimize critical nodes in the power system. This allows for a re-searching of the attacker's worst response after a given candidate defense strategy is implemented. This reflects the shift in attack targets caused by defense, making the evaluation of the protection scheme more consistent with external attack scenarios and more realistically reflecting the interaction between offense and defense.
Smart Images

Figure CN122764698A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system security protection technology, and in particular to a method for protecting the security of critical nodes in a power system, a device for protecting the security of critical nodes in a power system, an electronic device, and a storage medium. Background Technology
[0002] As a critical infrastructure, the power system undertakes the functions of energy transmission and power supply security. Damage to its key substations, main transmission lines, high-load nodes, or interconnection nodes can cause widespread power outages, power flow redistribution, branch line overruns, and cascading failures. Compared to general equipment failures or natural disasters, external attacks are more selective, sudden, targeted, and highly destructive.
[0003] Traditional power system protection methods often employ deterministic worst-case scenarios, single-fault scenarios, or static node importance ranking methods. While these methods can identify high-risk targets to some extent, they struggle to simultaneously characterize the uncertainty of the number of nodes attacked by an attacker, the attacker's worst-case response to the defense outcome, the coupling effect of node load and network structure, and the expected risks under multiple attack scenarios.
[0004] Therefore, there is a need for a power system protection method that can output the optimal hardening scheme for critical nodes in an interpretable, computable, and engineering-deployable manner under the constraint of limited protection resources. Summary of the Invention
[0005] This invention provides a method for protecting the security of critical nodes in a power system, a device for protecting the security of critical nodes in a power system, an electronic device, and a storage medium, which are used to solve or partially solve the technical problems that related technologies cannot simultaneously characterize the uncertainty of the number of attack nodes attacked by an attacker, the worst-case response of an attacker to the defense results, the coupling effect of node load and network structure, and the expected risks in multi-attack scenarios.
[0006] This invention provides a method for security protection of critical nodes in a power system, the method comprising:
[0007] Obtain the network model of the power system;
[0008] Based on the identification of node load-network centrality coupling, a set of key nodes for the network model is constructed, and a set of candidate defense strategies is generated based on the set of key nodes through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies.
[0009] Calculate the expected load loss for each of the candidate defense strategies under the worst-case attack search;
[0010] The candidate defense strategy that minimizes the expected load loss is determined as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
[0011] Optionally, the network model includes the set of nodes of the power system; the key node set for constructing the network model based on node load-network centrality coupling identification includes:
[0012] For each node in the node set, a node load normalization index is calculated based on the node load, and a key comprehensive index of the node is constructed based on the node load normalization index and network centrality coupling.
[0013] The key comprehensive indicators of each node are sorted from largest to smallest, and the first preset number of key nodes at the top of the sort are selected to construct the key node set of the network model.
[0014] Optionally, the network model further includes the set of lines of the power system; the key comprehensive index of the node, constructed based on the node load normalization index and combined with network centrality coupling, includes:
[0015] By combining the node and the set of lines, calculate the betweenness centrality and degree centrality of the node respectively;
[0016] Based on the aforementioned intermediation centrality and degree centrality, a comprehensive centrality index is constructed through centrality coupling;
[0017] The node load normalization index is corrected for centrality based on the comprehensive centrality index to construct the key comprehensive index of the node.
[0018] Optionally, the step of generating a candidate defense strategy set based on the set of key nodes through greedy-random mixed sampling includes:
[0019] Select a second preset number of key nodes from the set of key nodes, and generate several first candidate defense strategies based on the second preset number of key nodes through greedy sampling; each greedy sampling also selects a third preset number of key nodes to generate a first candidate defense strategy.
[0020] A set of key nodes is randomly sampled a predetermined number of times to obtain several second candidate defense strategies; each random sampling selects a third predetermined number of key nodes to generate a second candidate defense strategy; wherein, the first predetermined number ≥ the second predetermined number > the third predetermined number;
[0021] Based on the plurality of first candidate defense strategies and the plurality of second candidate defense strategies, an initial candidate defense strategy set is generated, and the initial candidate defense strategy set is deduplicated using a hash table to obtain the candidate defense strategy set.
[0022] Optionally, calculating the expected load loss for each of the candidate defense strategies under the worst-case attack search includes:
[0023] For each of the candidate defense strategies, a set of attackable nodes is determined based on the set of key nodes and the candidate defense strategy.
[0024] Based on the set of attackable nodes, multiple attack sets under different preset attack scales are constructed by combining greedy attack search and random attack search.
[0025] For each of the preset attack scales, calculate the total scenario loss for each of the attack sets;
[0026] Based on the total scenario loss of each of the attack sets, the worst-case attack loss of the candidate defense strategy under the preset attack scale is determined;
[0027] Based on the worst-case attack loss under each preset attack scale, and combined with the occurrence probability of each preset attack scale, the expected load loss of the candidate defense strategy under the worst-case attack search is calculated by weighting the attack scenario probabilities.
[0028] Optionally, calculating the total scenario loss for each of the attack sets includes:
[0029] For each attack set, based on the candidate defense strategy and the attack set, determine the actual set of damaged nodes and calculate the direct load loss of the actual set of damaged nodes;
[0030] The chain reaction amplification factor is determined based on the number of damaged nodes in the actual set of damaged nodes.
[0031] The total scenario loss of the attack set is calculated based on the direct load loss and the chain effect amplification factor.
[0032] Optionally, the process of constructing the network model of the power system includes:
[0033] Obtain network topology information of the power system; the network topology information includes a set of nodes and a set of lines.
[0034] An undirected graph is constructed based on the set of nodes and the set of lines, and the undirected graph is used as the network model of the power system.
[0035] The present invention also provides a security protection device for critical nodes in a power system, the device comprising:
[0036] The network model acquisition unit is used to acquire the network model of the power system.
[0037] The candidate defense strategy set generation unit is used to construct a set of key nodes for the network model based on node load-network centrality coupling identification, and generate a set of candidate defense strategies based on the set of key nodes through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies.
[0038] The expected load loss calculation unit is used to calculate the expected load loss of each of the candidate defense strategies under the worst-case attack search.
[0039] The optimal defense strategy determination unit is used to determine the candidate defense strategy that minimizes the expected load loss as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
[0040] The present invention also provides an electronic device, the device comprising a processor and a memory:
[0041] The memory is used to store program code and transmit the program code to the processor;
[0042] The processor is used to execute the critical node security protection method of the power system as described in any of the preceding methods, according to the instructions in the program code.
[0043] The present invention also provides a computer-readable storage medium for storing program code for executing the critical node security protection method for a power system as described in any of the preceding claims.
[0044] As can be seen from the above technical solutions, the present invention has the following advantages:
[0045] This paper presents a method for protecting critical nodes in a power system. First, a network model of the power system is obtained as the data foundation for subsequent analysis. Then, based on the identification of node load-network centrality coupling, a set of critical nodes in the network model is constructed. Based on this set, a set of candidate defense strategies is generated using a greedy-random hybrid sampling method. This set includes multiple candidate defense strategies. Therefore, when determining critical nodes, a comprehensive screening criterion of node load and network centrality coupling is used, taking into account both the direct load consequences of node failure and the network bridging effect, reducing the bias caused by a single ranking criterion and improving the accuracy of critical node identification. In generating candidate defense strategies, a greedy-random hybrid sampling method is used to control the number of defense and attack strategies evaluated within a preset upper limit, avoiding a double-layer exhaustive search of all combinations and reducing the complexity of the combination search. The expected load loss of each candidate defense strategy under the worst-case attack search is calculated, and the candidate defense strategy with the minimum expected load loss is determined as the optimal defense strategy. This optimal defense strategy is used to strengthen and optimize critical nodes in the power system. This allows for a re-searching of the attacker's worst response after a given candidate defense strategy is implemented. This reflects the shift in attack targets caused by defense, making the evaluation of the protection scheme more consistent with external attack scenarios and more realistically reflecting the interaction between offense and defense. Attached Figure Description
[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0047] Figure 1 A flowchart illustrating the steps of a security protection method for critical nodes in a power system;
[0048] Figure 2 A schematic diagram of the overall process for a security protection method for critical nodes in a power system;
[0049] Figure 3 This is a topology diagram of an IEEE 30-node system in a specific example;
[0050] Figure 4 This is a structural block diagram of a safety protection device for a critical node in a power system. Detailed Implementation
[0051] This invention provides a method for protecting the security of critical nodes in a power system, a device for protecting the security of critical nodes in a power system, an electronic device, and a storage medium. These solutions address or partially address the technical problems that related technologies struggle to simultaneously characterize the uncertainty of the number of attack nodes, the worst-case response of attackers to defense results, the coupling effect of node load and network structure, and the expected risks in multi-attack scenarios.
[0052] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0053] As an example, the power system, as a critical infrastructure, undertakes the functions of energy transmission and power supply guarantee. Damage to its key substations, main transmission lines, high-load nodes, or interconnection nodes can cause widespread power outages, power flow redistribution, branch line overruns, and cascading failures. Compared to general equipment failures or natural disasters, external attacks are more selective, sudden, targeted, and highly destructive. Attackers often prioritize high-load nodes, hub nodes, or network bridging nodes, and may employ multi-point, multi-round sabotage methods to amplify system load loss.
[0054] Traditional power system protection methods often employ deterministic worst-case scenarios, single-fault scenarios, or static node importance ranking methods. While these methods can identify high-risk targets to some extent, they struggle to simultaneously characterize the uncertainty of the number of nodes attacked by an attacker, the attacker's worst-case response to the defense outcome, the coupling effect of node load and network structure, and the expected risks under multiple attack scenarios.
[0055] Further analysis reveals that the deterministic game theory model for attack and defense is one of the current defense methods. This technique transforms the defense problem into a two-player zero-sum game by establishing utility functions for both the attacker and defender. The defender seeks to minimize the maximum loss, while the attacker seeks to maximize system damage. This method assumes that the attacker always adopts the worst-case attack strategy, and the defender formulates a defense plan based on this assumption. Its limitations are: ignoring the uncertainty and probabilistic characteristics of attack behavior; when the system scale is large, the solution space exhibits combinatorial explosive growth, resulting in excessively high computational complexity; and failing to consider the differences in the probability of different attack scales occurring.
[0056] In addition, some solutions employ a critical node identification method based on importance ranking. This method ranks nodes by calculating indicators such as topological importance, electrical centrality, and load size, directly selecting the top-ranked nodes as protection targets. Its shortcomings include: considering only the static characteristics of nodes and neglecting the dynamic characteristics of attack-defense interaction; failing to consider the strategic behavior of attackers; and lacking an optimization process, potentially leading to inefficient allocation of protection resources.
[0057] Another assessment method is the risk assessment approach based on fixed faults or scenario-by-scenario simulation. This type of technology performs power flow calculations, fault propagation simulations, or load shedding calculations for a preset set of faults or attack sets. Its drawback is that when the number of candidate attack scenarios and candidate protection strategies is large, a complete traversal can lead to combinatorial explosion. Furthermore, without probabilistic scenario weights and an optimal protection search mechanism, it can only provide scenario losses and is difficult to formulate the optimal hardening solution under limited resources.
[0058] In summary, the current technology mainly suffers from the following problems:
[0059] Insufficient characterization of attack scale uncertainty: Traditional attack and defense models often use fixed attack scale or a single worst-case scenario, lacking a discrete probability distribution model to describe the simultaneous attack of different numbers of key nodes by attackers, resulting in defense decisions failing to reflect expected risks in multiple scenarios.
[0060] The identification of critical nodes is based on a single dimension: when sorting based solely on load size or network centrality, the coupling relationship between load consequences and network bridging effects is easily overlooked, leading to inaccurate selection of protection targets.
[0061] Insufficient simulation of attacker response process: Traditional static hardening methods only focus on "which nodes to protect" and do not simulate the strategic behavior of attackers shifting their attack targets to the next higher value nodes after the defense is completed. It is difficult to reflect the attack and defense game process of "defense first - attack response - loss feedback".
[0062] Combinatorial search has high complexity: when the number of key nodes is The quantity of protective resources is The scale of the attack is At that time, a complete evaluation requires traversing a large number of... and The computational complexity increases rapidly with the system size, making it difficult to meet the needs of rapid simulation in engineering systems.
[0063] Incomplete loss assessment: Only the direct load loss of the attacked node is calculated, without fully considering the power supply path interruption, power flow redistribution, local instability and cascading amplification effects caused by node failure, resulting in an underestimation of the risk assessment results.
[0064] The output results are not conducive to decision-making: traditional methods often only output a node ranking or a scenario loss, lacking interpretable information such as the risk contribution of each attack scale, the comparison of no protection / protection, and the benefits of protecting key nodes.
[0065] Therefore, given the uncertainty of attack scale and targets under external attacks, a pressing technical problem is how to quickly determine the critical node protection strategy that minimizes expected load loss in multiple attack scenarios of the power system within the constraints of limited defense resources, and output interpretable attack and defense simulation results. Thus, a power system protection method is needed that can output the optimal critical node hardening scheme in an interpretable, computable, and engineering-deployable manner under limited defense resource constraints.
[0066] Therefore, one of the core inventive points of this invention is: addressing the shortcomings of current technology, it provides a method for optimizing the protection of critical nodes in power systems in external attack scenarios where both the attack scale and target are uncertain. This method utilizes probabilistic attack models, critical node identification, attack-defense game theory simulation, expected load loss assessment, and optimal reinforcement strategy search.
[0067] Reference Figure 1 The diagram illustrates a flowchart of a method for protecting the critical nodes of a power system according to an embodiment of the present invention, which may specifically include the following steps:
[0068] Step 101: Obtain the network model of the power system;
[0069] In this step, a network model of the power system is obtained for subsequent analysis. In practical applications, system parameters and network model construction of the power system need to be performed first. Specifically, the process of constructing the power system network model may include: obtaining the network topology information of the power system; the network topology information includes a set of nodes and a set of lines; constructing an undirected graph based on the set of nodes and lines, and using this undirected graph as the network model of the power system.
[0070] Specifically, the power system topology can be abstracted as an undirected graph using the following formula:
[0071] ;
[0072] in, For a set of nodes, This is a set of routes.
[0073] In the network model described above, nodes are defined. The active load is Power generation output is Loss of load is and the node voltage phase angle is By reading data on the nodes, lines, generators, loads, and operating constraints of the power system, a data foundation is provided for constructing a network model of the power system.
[0074] Two loss assessment methods are designed in this embodiment of the invention. In a simplified implementation, the system can directly use node load and topology data for loss assessment (without introducing DC power flow constraints). That is, after an attacked node fails, the total loss is mainly calculated based on the load of the damaged node, the number of damaged nodes, and the cascading amplification factor (i.e., the cascading effect amplification coefficient in subsequent steps), which is suitable for rapid scenario screening and simulation. This method is also the main loss assessment method adopted in this invention.
[0075] In another refined implementation, for any line Extracting line reactance Line flow and capacity limit The DC power flow constraints can be invoked as shown below:
[0076] ;
[0077] ;
[0078] In other words, for a refined implementation, after determining the attack set and damaged nodes, the node failure results are substituted into the power network model, and then DC power flow constraints are introduced to calculate power flow redistribution, line capacity constraints, and possible load shedding. In this case, loss assessment can be performed directly based on DC power flow constraints without using node load and topology data.
[0079] Step 102: Based on the identification of node load-network centrality coupling, construct a set of key nodes for the network model, and based on the set of key nodes, generate a set of candidate defense strategies through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies.
[0080] In this step, based on the previous steps, a set of key nodes for the network model is constructed based on the identification of node load-network centrality coupling. Based on the set of key nodes, a set of candidate defense strategies is generated through greedy-random mixed sampling. The set of candidate defense strategies includes multiple candidate defense strategies.
[0081] To enable those skilled in the art to better understand the technical solution of this invention, a brief description of the attack and defense resources and probabilistic attack scenario settings is provided below.
[0082] The number of defense resources is defined as follows: The number of candidate key nodes is The probability of an attack scale is The upper limit of candidate defense strategies is The number of random searches is The set of attack scales can be represented as:
[0083] ;
[0084] in, Indicates the first Scale of similar attacks.
[0085] The probability of attack scale satisfies:
[0086] ;
[0087] ;
[0088] This indicates that the sum of the probabilities of all attack scales is 1.
[0089] Based on the above probabilistic attack analysis, a node-level probabilistic attack model was constructed, which uses discrete probability distributions to describe the uncertainty of the number of nodes attacked by the attacker.
[0090] Based on the preceding discussion, a network model can include a set of nodes in a power system. The construction of the key node set in the network model is primarily based on the key node identification process of node load-centrality coupling. This process mainly includes the following steps S01 to S02:
[0091] Step S01: For each node in the node set, calculate the node load normalization index based on the node load, and construct the key comprehensive index of the node based on the node load normalization index and network centrality coupling.
[0092] For each node in the node set The normalized index of nodal load is calculated using the following formula. This is used to reflect the direct power loss consequences of node failure:
[0093] ;
[0094] The network model may also include a set of power system lines. Therefore, the implementation process in step S01, which constructs key comprehensive indicators of nodes based on node load normalization indices and network centrality coupling, may further include the following steps S11 to S13:
[0095] Step S11: Combine the set of nodes and the set of lines to calculate the betweenness centrality and degree centrality of the nodes respectively;
[0096] In this step, on the one hand, the nodes are computed. The centrality of the middle To reflect the nodes The frequency of nodes located on the shortest path between other nodes characterizes the network's bridging effect. On the other hand, the computational nodes... Degree centrality This is used to reflect the local connectivity of a node.
[0097] Betweenness centrality quantifies how frequently a node lies on the shortest path between any two other nodes in a network. A higher betweenness centrality indicates that the node is an indispensable "bridge" or "hub" in the network. Removing or controlling this node will severely disrupt the connectivity and information flow efficiency of the entire network. Degree centrality is a commonly used metric in graph theory and network analysis to measure node importance. It reflects the number of direct connections a node has with other nodes. A higher degree centrality indicates that the node is more "busy" or "important" in the network because it is directly connected to more nodes. Both betweenness centrality and degree centrality calculations require the use of path sets (path sets are mainly used to better understand the path connections between the node and other nodes). Specific calculation methods can be found in existing literature and will not be elaborated upon here.
[0098] Step S12: Based on betweenness centrality and degree centrality, construct a comprehensive centrality index through centrality coupling;
[0099] Specifically, the comprehensive centrality index of centrality coupling can be constructed using the following formula:
[0100] ;
[0101] in, 0.7 is acceptable.
[0102] Step S13: Correct the node load normalization index based on the comprehensive centrality index to construct the key comprehensive index of the node.
[0103] The key comprehensive index of the node is constructed using the following formula:
[0104] ;
[0105] in, The centrality correction factor is preferably 0.10.
[0106] Step S02: Sort the key comprehensive indicators of each node from largest to smallest, and select the first preset number of key nodes at the top of the sort to construct the key node set of the network model.
[0107] Specifically, according to the key comprehensive indicators of each node Sort by largest to smallest, then select the first... Each node is a set of key nodes. .
[0108] By constructing the key node set through the above process, the key node set is identified by the node load-network centrality coupling index. This not only maintains the dominant role of load loss consequences in key node identification, but also considers bridging nodes and connecting nodes in the network structure through centrality correction, making it more suitable for key target screening in external attack scenarios.
[0109] To enable those skilled in the art to better understand the technical solution of this invention, the defense strategy model, attack strategy model, and the relationship between node failure are briefly explained below.
[0110] Define defense variables ,node When reinforced, ,otherwise Defense resource constraints are:
[0111] ;
[0112] Define attack variables In terms of attack scale In the scenario, nodes When attacked, Otherwise, it is 0. Attack resource constraints are:
[0113] ;
[0114] Define node failure variables When node When attacked and unprotected, Otherwise, it is 0. The logical relationship is as follows:
[0115] ;
[0116] To facilitate integer programming or linearization solutions, the above relationship can be transformed into 0-1 linear constraints:
[0117] ;
[0118] ;
[0119] ;
[0120] The above analysis establishes a two-layer attack-defense game framework between attackers and defenders, characterizing the strategic relationship between the two sides under the constraints of limited attack resources and limited defense resources.
[0121] Building upon the foregoing, the following section describes the process for generating candidate defense strategies. The basic principle behind generating candidate defense strategies is: [The text then abruptly shifts to a different topic:] ...from the set of key nodes... Select Each node constitutes a defense strategy. , and To avoid a complete traversal The combination of these strategies leads to excessive computational complexity. Therefore, this invention employs a greedy-random hybrid sampling method to generate a set of candidate defense strategies. .
[0122] Specifically, the implementation process of generating a candidate defense strategy set based on the set of key nodes through greedy-random mixed sampling may include the following steps S21 to S23:
[0123] Step S21: Select the second preset number of key nodes ranked first from the key node set. Based on the second preset number of key nodes, generate several first candidate defense strategies through greedy sampling. Each greedy sampling will extract a third preset number of key nodes to generate a first candidate defense strategy.
[0124] The sampling in step S21 is essentially a greedy sampling of the load / comprehensive index. That is, it starts from the top-ranked indices. Defense combinations are generated from key nodes, prioritizing high-value nodes for inclusion in candidate defense strategies. To distinguish them from candidate defense strategies generated by random sampling, the candidate defense strategy generated by greedy sampling is defined as the first candidate defense strategy.
[0125] Preset a number of key nodes at the top And satisfy From the top of the list Select from key nodes Each node forms a candidate defense strategy. Mathematically, this is equivalent to starting from... Select from different elements All possible combinations of elements are represented as follows: The number of candidate defense strategies determined in this way is The method provided by this invention is generally applied to smaller node systems, in which case... Limited quantity. In another case, when When the number is very large, a preset upper limit on the number of greedy candidate strategies can be added. .
[0126] Step S22: Perform a preset number of random samplings on the set of key nodes to obtain several second candidate defense strategies; each random sampling selects a third preset number of key nodes to generate a second candidate defense strategy.
[0127] The sampling in step S22 is essentially random diversity sampling. The number of sampling times is pre-set (e.g., 15 times). Each sampling involves sampling from the entire set of key nodes. Randomly selected Each node forms a set of candidate defense strategies. To distinguish them from the candidate defense strategies generated by greedy sampling, the candidate defense strategies generated by random sampling are defined as the second candidate defense strategy.
[0128] Among them, the first preset quantity ≥Second preset quantity >Third preset quantity .
[0129] Step S23: Based on several first candidate defense strategies and several second candidate defense strategies, generate an initial candidate defense strategy set, and perform hash table deduplication on the initial candidate defense strategy set to obtain the candidate defense strategy set.
[0130] All generated first and second candidate defense strategies are integrated to form an initial set of candidate defense strategies. To avoid policy duplication, a hash table is used to remove duplicates, resulting in the final set of candidate defense strategies. .
[0131] In other words, the set of candidate defense strategies It includes candidate defense strategies generated by both greedy sampling and random sampling. After deduplication using a hash table, a total of [number] strategies were obtained. Groups of candidate defense strategies, each group of candidate defense strategies has Each node.
[0132] Step 103: Calculate the expected load loss for each of the candidate defense strategies under the worst-case attack search.
[0133] Building upon the preceding steps, this step calculates the expected load loss for each candidate defense strategy under the worst-case attack search. This step relies on a scenario-specific worst-case attack search.
[0134] Specifically, for any candidate defense strategy and any preset attack size (For example, if there are 3 attack scales, the number of attack nodes in each attack scale scenario is 3, 4, and 5 respectively), first determine the set of attackable nodes. The attacker's goal is to... Select The attack set consists of several nodes. This maximizes the system's losses. For each preset attack scale... In this embodiment of the invention, a combination of greedy attack search and random attack search is used to determine the attack scale. The approximate worst-case attack response is determined. This process can be mainly divided into several key points: greedy attack search, random attack search, and loss comparison.
[0135] The first step is a greedy attack search. Specifically, it starts from the set of attackable nodes. Choose the one with the highest load or comprehensive key indicators. A set of nodes forms an attack cluster. When the primary concern is direct load loss, load indicators should be prioritized. For example, if attacking a high-load node would directly cause significant load shedding, and the impact on network structure is not particularly pronounced, load ranking is more intuitive. When the system has obvious risks related to interconnecting nodes, bridging nodes, hub nodes, or power flow shifts, comprehensive critical indicators should be prioritized. This is because some nodes may not have a large load themselves, but they are located in important interconnecting positions. Their failure could lead to power path interruptions, power flow redistribution, or partial disconnection. Load indicators alone may not be sufficient to accurately identify such nodes.
[0136] Secondly, there is the random attack search. Specifically, repeated... Next, from the set of attackable nodes Random selection A set of nodes forms an attack cluster. At this time there is attack set .
[0137] Finally, the losses are compared. Calculations are performed separately. and each The losses, and select the one with the greatest losses as the attack scale. The approximate worst-case attack response (worst-case attack loss) is given below.
[0138] The worst-case attack loss can be expressed as:
[0139] ;
[0140] In the formula, For defensive strategies Small attack scale The worst-case attack loss; For defensive strategies In attack scale The total loss of a scenario under any set of attacks.
[0141] Specifically, the calculation process for the total scene loss is as follows:
[0142] For attack sets and defense strategies The actual set of damaged nodes is The direct load loss is:
[0143] ;
[0144] To account for power path interruptions, power flow redistribution, and cascading failures caused by multiple strikes, a cascading effect amplification factor is set. Among them, the chain effect amplification factor Based on the number of damaged nodes It is determined that its function form is:
[0145] ;
[0146] in, This represents the number of damaged nodes.
[0147] The total loss for the scene is:
[0148] ;
[0149] Based on this, candidate defense strategies The expected load loss under the worst-case attack search is:
[0150] ;
[0151] in, For the scale of the attack The probability of occurrence; Candidate defense strategies; Candidate defense strategies Small attack scale The worst-case attack loss.
[0152] Based on the preceding discussion, the implementation process for calculating the expected load loss of each candidate defense strategy under the worst-case attack search can include the following steps S31 to S35:
[0153] Step S31: For each candidate defense strategy, determine the set of attackable nodes based on the set of key nodes and the candidate defense strategy;
[0154] Step S32: Based on the set of attackable nodes, construct multiple attack sets under different preset attack scales by combining greedy attack search and random attack search;
[0155] Step S33: For each preset attack scale, calculate the total scenario loss for each attack set;
[0156] Furthermore, the implementation process for calculating the total scenario loss for each attack set may include the following steps S41 to S43:
[0157] Step S41: For each attack set, based on the candidate defense strategy and the attack set, determine the actual set of damaged nodes and calculate the direct load loss of the actual set of damaged nodes;
[0158] Step S42: Determine the chain reaction amplification factor based on the number of damaged nodes in the actual set of damaged nodes;
[0159] Step S43: Calculate the total scenario loss of the attack set based on the direct load loss and the chain effect amplification factor.
[0160] Step S34: Based on the total scenario loss of each attack set, determine the worst-case attack loss of the candidate defense strategy under the preset attack scale;
[0161] Step S35: Based on the worst-case attack loss under each preset attack scale, and combined with the occurrence probability of each preset attack scale, calculate the expected load loss of the candidate defense strategy under the worst-case attack search by weighting the attack scenario probability.
[0162] Step 104: The candidate defense strategy with the minimum expected load loss is determined as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
[0163] Finally, the candidate defense strategy that minimizes expected load loss is determined as the optimal defense strategy (optimal defense node set), and the power system is reinforced and optimized based on this strategy.
[0164] This step primarily involves selecting the optimal defense strategy. Specifically, strategy selection is achieved by considering the set of candidate defense strategies. Each candidate defense strategy Perform worst-case attack search and loss calculation for each scenario to obtain the corresponding expected loss. Choose the strategy that minimizes expected load loss as the optimal defense strategy:
[0165] ;
[0166] in, The optimal defense strategy is the optimal set of defense nodes.
[0167] Thus, through the aforementioned calculations, we can obtain the final optimal set of defense nodes, the minimum expected load loss corresponding to the optimal set of defense nodes, as well as the attacker's worst response, direct load loss, cascading loss, and total scenario loss for each attack scale.
[0168] Furthermore, in the case study, the preceding data can be used to calculate the probability-weighted risk contribution and the loss reduction ratio relative to the unprotected solution through simple calculations.
[0169] The probability-weighted risk contribution (expected loss for each attack size) is:
[0170] ;
[0171] in, For the scale of the attack The probability of occurrence; The optimal defense strategy Small attack scale The corresponding worst-case attack loss.
[0172] The percentage reduction in losses compared to no protection is as follows:
[0173] ;
[0174] in, This represents the expected load loss under unprotected conditions. This represents the minimum expected load loss after adopting the optimal defense strategy.
[0175] This invention provides a method for protecting the security of critical nodes in a power system. Based on the read network topology information of the power system, a network model is constructed; a two-layer attack-defense game framework is established between attackers and defenders to characterize the strategic relationship between the two sides under the constraints of limited attack and defense resources; a node-level probabilistic attack model is constructed, using discrete probability distributions to describe the uncertainty of the number of attack nodes; a set of critical nodes is identified using a node load-network centrality coupling index, and candidate defense strategies are generated within this set; for each candidate defense strategy, the worst-case attacker response is searched under different attack scale scenarios, calculating direct load loss, cascading effect amplification loss, and total scenario loss, and weighting the expected load loss according to the attack scenario probability; the defense strategy with the minimum expected load loss is selected as the optimal critical node hardening scheme.
[0176] By implementing the technical solution provided by this invention, at least the following beneficial effects can be achieved:
[0177] On the one hand, when identifying key nodes, a comprehensive screening criterion is used, which couples node load with betweenness centrality and degree centrality. This takes into account both the direct load consequences of node failure and the network bridging effect, reducing the bias caused by a single ranking criterion and improving the accuracy of key node identification.
[0178] On the other hand, when generating candidate defense strategies, a greedy-random mixed sampling method is adopted to control the number of defense and attack strategies evaluated within a preset upper limit, avoiding double-layer exhaustive search of all combinations and reducing the complexity of combination search. Furthermore, different attack capability scenarios are described by attack scale sets and probability distributions, transforming the protection strategy from single-scenario optimal to multi-scenario expected risk optimal, thus improving the ability to model attack uncertainty.
[0179] Meanwhile, re-searching for the attacker's worst response after considering candidate defense strategies can reflect the shift in attack targets caused by defense, making the evaluation of protection schemes more consistent with external attack scenarios and more realistically reflecting the attack-defense interaction process. When assessing losses, adding a cascading effect amplification factor to the direct load loss can replace the DC / AC (Direct Current / Alternating Current) power flow and load shedding model, reflecting the systemic amplification consequences after multiple nodes are damaged, and improving the completeness of loss assessment.
[0180] By implementing the above technical solutions, the system can finally output the optimal set of defense nodes, the minimum expected load loss corresponding to the optimal set of defense nodes, as well as the attacker's worst response, direct load loss, cascading loss, total scenario loss, scenario risk contribution, and protection recommendations under each attack scale. This makes it easy for dispatch centers, security assessment platforms, or power grid operation and maintenance departments to deploy and use the system, and enhances the interpretability and engineering applicability of the results.
[0181] For better illustration, refer to Figure 2 This diagram illustrates the overall flow of a method for protecting the security of critical nodes in a power system, as provided in an embodiment of the present invention. It should be noted that this embodiment only provides a brief overview of the general flow of security protection for critical nodes in a power system. The specific implementation process of each step can be understood by referring to the relevant content in the foregoing embodiments, and will not be elaborated upon here. It is understood that the present invention does not impose any limitations on this.
[0182] Step 201: Obtain the set of nodes and the set of lines of the power system, and construct an undirected graph based on the set of nodes and the set of lines as the network model of the power system;
[0183] Step 202: For each node in the node set in the network model, calculate the node load normalization index based on the node load, and construct the key comprehensive index of the node based on the node load normalization index and the network centrality coupling.
[0184] Step 203: Sort the key comprehensive indicators of each node from largest to smallest, and select the first preset number of key nodes at the top of the sort to construct the key node set of the network model.
[0185] Step 204: Based on the set of key nodes, generate multiple candidate defense strategies through greedy-random mixed sampling; for each candidate defense strategy, determine the set of attackable nodes according to the set of key nodes and the candidate defense strategy, and construct multiple attack sets under different preset attack scales according to the set of attackable nodes by combining greedy attack search and random attack search.
[0186] Step 205: For each preset attack scale, calculate the total scenario loss for each attack set; based on the total scenario loss for each attack set, determine the worst-case attack loss for the candidate defense strategy under the preset attack scale.
[0187] Step 206: Based on the worst-case attack loss under each preset attack scale, and combined with the occurrence probability of each preset attack scale, calculate the expected load loss of the candidate defense strategy under the worst-case attack search by weighting the attack scenario probability.
[0188] Step 207: Determine the candidate defense strategy that minimizes expected load loss as the optimal defense strategy for use in strengthening and optimizing critical nodes of the power system.
[0189] To enable those skilled in the art to better understand the technical solutions of the present invention, the following specific example is used to illustrate the embodiments of the present invention.
[0190] Select as Figure 3 The IEEE 30-node system shown is used as the research object. The system consists of 30 nodes, 41 lines, and 6 generators. Power flow calculation results show that the total generating capacity of the system is 191.64MW, the total load is 189.20MW, and the corresponding active power loss is approximately 2.44MW, accounting for about 1.27% of the total generating capacity.
[0191] Under the baseline operating conditions of the IEEE 30-bus system, the node load-centrality index was used to identify the critical nodes. A total of 12 critical nodes were identified. The set of critical nodes is [8, 7, 2, 21, 12, 30, 19, 17, 24, 15, 4, 14]. The total load of these critical nodes is 163.00 MW, accounting for 86.2% of the total system load.
[0192] In real-world external attack scenarios, the attacker's capabilities are often uncertain. It is particularly difficult to accurately predict how many critical nodes they can simultaneously attack in a single attack. To characterize this feature, this invention employs a probabilistic attack model to describe the number of attacking nodes, setting the attack scale to three scenarios: 3, 4, and 5 nodes. Then, Monte Carlo simulations are performed to analyze the power system load loss when only 3, 4, or 5 nodes are attacked. The unit node load loss is assigned a probability value based on the different numbers of attacking nodes, as shown in Table 1.
[0193] Table 1: Probability Distribution of the Number of Attacking Nodes
[0194]
[0195] Table 2 shows the load loss in each scenario under the optimal defense strategy.
[0196] Table 2: Load Loss in Various Scenarios under Optimal Defense Strategy
[0197]
[0198] As shown in Table 2, with the optimal defense strategy being [8,7], the worst-case attack node set for attackers expands gradually with the increase in the number of attack nodes under different attack scale scenarios. When the number of attack nodes is 3, the worst-case attack node set is [2,21,12], corresponding to a direct loss of 50.40MW, a cascading loss of 10.08MW, and a total loss of 60.48MW. When the number of attack nodes increases to 4, the worst-case attack node set expands to [2,21,12,30], and the total loss increases to 79.30MW. When the number of attack nodes further increases to 5, the worst-case attack node set is [2,21,12,30,19], and the total loss increases to 100.11MW.
[0199] It can be seen that as the attack scale increases, both direct system losses and cascading losses show an increasing trend. The increase in cascading losses reflects the amplified impact of multiple node failures on the system's power supply path, power flow distribution, and local stability. Combined with attack probability calculations, the expected losses under the three attack scenarios are 18.99MW, 27.36MW, and 34.14MW, respectively. The 5-node attack scenario contributes the most to the total expected loss, indicating that under limited defense resources, defense strategies should not only focus on high-probability attack scenarios but also prioritize the impact of high-loss attack scenarios on the system's secure operation. The above results demonstrate that the probabilistic attack model and optimal defense strategy proposed in this invention can quantitatively assess system risks under different attack scales and provide a decision-making basis for hardening critical nodes.
[0200] In the IEEE 30-node example above, the unprotected expected load loss is 119.30 MW. After adopting the optimal defense strategy [8,7], the expected load loss is 80.49 MW, a relative reduction of approximately 32.53%. Thus, this invention provides quantifiable protection benefits.
[0201] Reference Figure 4 The diagram illustrates a structural block diagram of a critical node security protection device for a power system according to an embodiment of the present invention, which may specifically include:
[0202] Network model acquisition unit 401 is used to acquire the network model of the power system;
[0203] The candidate defense strategy set generation unit 402 is used to construct a set of key nodes for the network model based on node load-network centrality coupling identification, and generate a set of candidate defense strategies based on the set of key nodes through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies.
[0204] The expected load loss calculation unit 403 is used to calculate the expected load loss of each of the candidate defense strategies under the worst attack search.
[0205] The optimal defense strategy determination unit 404 is used to determine the candidate defense strategy with the minimum expected load loss as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
[0206] In one optional embodiment, the network model includes a set of nodes in the power system; the candidate defense strategy set generation unit 402 includes:
[0207] The key comprehensive index construction unit is used to calculate the node load normalization index for each node in the node set based on the node load of the node, and construct the key comprehensive index of the node based on the node load normalization index and network centrality coupling.
[0208] The key node set construction unit is used to sort the key comprehensive indicators of each node from largest to smallest, and select the first preset number of key nodes at the top of the sort to construct the key node set of the network model.
[0209] In one optional embodiment, the network model further includes the set of lines of the power system; the key comprehensive index construction unit is specifically used for:
[0210] By combining the node and the set of lines, calculate the betweenness centrality and degree centrality of the node respectively;
[0211] Based on the aforementioned intermediation centrality and degree centrality, a comprehensive centrality index is constructed through centrality coupling;
[0212] The node load normalization index is corrected for centrality based on the comprehensive centrality index to construct the key comprehensive index of the node.
[0213] In one optional embodiment, the candidate defense strategy set generation unit 402 includes:
[0214] The first candidate defense strategy generation unit is used to select a second preset number of key nodes from the set of key nodes, and generate a number of first candidate defense strategies based on the second preset number of key nodes through greedy sampling; each greedy sampling extracts a third preset number of key nodes to generate a first candidate defense strategy.
[0215] The second candidate defense strategy generation unit is used to perform a preset number of random samplings on the set of key nodes to obtain several second candidate defense strategies; each random sampling selects a third preset number of key nodes to generate a second candidate defense strategy; wherein, the first preset number ≥ the second preset number > the third preset number;
[0216] The candidate defense strategy set determination unit is used to generate an initial candidate defense strategy set based on the plurality of first candidate defense strategies and the plurality of second candidate defense strategies, and to perform hash table deduplication on the initial candidate defense strategy set to obtain the candidate defense strategy set.
[0217] In one alternative embodiment, the expected load loss calculation unit 403 includes:
[0218] The attackable node set determination unit is used to determine the attackable node set for each candidate defense strategy based on the key node set and the candidate defense strategy.
[0219] The attack set construction unit is used to construct multiple attack sets under different preset attack scales based on the set of attackable nodes, combining greedy attack search and random attack search respectively.
[0220] The scenario total loss calculation unit is used to calculate the scenario total loss for each of the preset attack scales for each of the attack sets.
[0221] The worst-case attack loss determination unit is used to determine the worst-case attack loss of the candidate defense strategy under the preset attack scale based on the total scenario loss of each of the attack sets.
[0222] The expected load loss calculation subunit is used to calculate the expected load loss of the candidate defense strategy under the worst attack search based on the worst attack loss under each preset attack scale and the occurrence probability of each preset attack scale, by weighting the attack scenario probability.
[0223] In one optional embodiment, the total scene loss calculation unit includes:
[0224] The direct load loss calculation unit is used to determine the actual damaged node set for each attack set based on the candidate defense strategy and the attack set, and to calculate the direct load loss of the actual damaged node set.
[0225] The chain effect amplification coefficient determination unit is used to determine the chain effect amplification coefficient based on the number of damaged nodes in the actual damaged node set.
[0226] The scenario total loss calculation subunit is used to calculate the scenario total loss of the attack set based on the direct load loss and the chain effect amplification coefficient.
[0227] In one optional embodiment, the apparatus further includes a network model building unit; the network model building unit includes:
[0228] A network topology information acquisition unit is used to acquire network topology information of a power system; the network topology information includes a set of nodes and a set of lines.
[0229] An undirected graph construction unit is used to construct an undirected graph based on the set of nodes and the set of lines, and to use the undirected graph as the network model of the power system.
[0230] As the device embodiment is basically similar to the method embodiment, it is described in a relatively simple way. For relevant details, please refer to the description of the method embodiment above.
[0231] It should be noted that, in order to enable those skilled in the art to better distinguish data of the same type but with different actual meanings, some technical features in the embodiments of the present invention are distinguished by the terms "first", "second", and "third". The terms "first", "second", and "third" are used only for data differentiation and have no other special meaning. It is understood that the present invention does not impose any limitations on this.
[0232] This invention also provides an electronic device, which includes a processor and a memory:
[0233] The memory is used to store program code and transfer the program code to the processor;
[0234] The processor is used to execute the power system critical node security protection method according to the instructions in the program code of any embodiment of the present invention.
[0235] This invention also provides a computer-readable storage medium for storing program code, which is used to execute the power system critical node security protection method according to any embodiment of this invention.
[0236] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0237] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this invention are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0238] In the embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units through some interfaces, and may be electrical, mechanical, or other forms.
[0239] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0240] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0241] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0242] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for security protection of critical nodes in a power system, characterized in that, include: Obtain the network model of the power system; Based on the identification of node load-network centrality coupling, a set of key nodes for the network model is constructed, and a set of candidate defense strategies is generated based on the set of key nodes through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies. Calculate the expected load loss for each of the candidate defense strategies under the worst-case attack search; The candidate defense strategy that minimizes the expected load loss is determined as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
2. The method for protecting the security of critical nodes in a power system according to claim 1, characterized in that, The network model includes the set of nodes in the power system; The key node set for constructing the network model based on node load-network centrality coupling identification includes: For each node in the node set, a node load normalization index is calculated based on the node load, and a key comprehensive index of the node is constructed based on the node load normalization index and network centrality coupling. The key comprehensive indicators of each node are sorted from largest to smallest, and the first preset number of key nodes at the top of the sort are selected to construct the key node set of the network model.
3. The method for security protection of critical nodes in a power system according to claim 2, characterized in that, The network model also includes the set of lines in the power system; the key comprehensive indicators for constructing the nodes based on the node load normalization index and combined with network centrality coupling include: By combining the node and the set of lines, calculate the betweenness centrality and degree centrality of the node respectively; Based on the aforementioned intermediation centrality and degree centrality, a comprehensive centrality index is constructed through centrality coupling; The node load normalization index is corrected for centrality based on the comprehensive centrality index to construct the key comprehensive index of the node.
4. The method for protecting the security of critical nodes in a power system according to claim 1, characterized in that, The process of generating a candidate defense strategy set based on the set of key nodes through a greedy-random hybrid sampling includes: Select a second preset number of key nodes from the set of key nodes, and generate several first candidate defense strategies based on the second preset number of key nodes through greedy sampling; each greedy sampling also selects a third preset number of key nodes to generate a first candidate defense strategy. A set of key nodes is randomly sampled a predetermined number of times to obtain several second candidate defense strategies; each random sampling selects a third predetermined number of key nodes to generate a second candidate defense strategy; wherein, the first predetermined number ≥ the second predetermined number > the third predetermined number; Based on the plurality of first candidate defense strategies and the plurality of second candidate defense strategies, an initial candidate defense strategy set is generated, and the initial candidate defense strategy set is deduplicated using a hash table to obtain the candidate defense strategy set.
5. The method for security protection of critical nodes in a power system according to claim 1, characterized in that, The calculation of the expected load loss for each candidate defense strategy under the worst-case attack search includes: For each of the candidate defense strategies, a set of attackable nodes is determined based on the set of key nodes and the candidate defense strategy. Based on the set of attackable nodes, multiple attack sets under different preset attack scales are constructed by combining greedy attack search and random attack search. For each of the preset attack sizes, calculate the total scenario loss for each of the attack sets; Based on the total scenario loss of each of the attack sets, the worst-case attack loss of the candidate defense strategy under the preset attack scale is determined; Based on the worst-case attack loss under each preset attack scale, and combined with the occurrence probability of each preset attack scale, the expected load loss of the candidate defense strategy under the worst-case attack search is calculated by weighting the attack scenario probabilities.
6. The method for security protection of critical nodes in a power system according to claim 5, characterized in that, The calculation of the total scenario loss for each of the attack sets includes: For each attack set, based on the candidate defense strategy and the attack set, determine the actual set of damaged nodes and calculate the direct load loss of the actual set of damaged nodes; The chain reaction amplification factor is determined based on the number of damaged nodes in the actual set of damaged nodes. The total scenario loss of the attack set is calculated based on the direct load loss and the chain effect amplification factor.
7. The method for protecting the security of critical nodes in a power system according to any one of claims 1 to 6, characterized in that, The process of constructing the network model of the power system includes: Obtain network topology information of the power system; the network topology information includes a set of nodes and a set of lines. An undirected graph is constructed based on the set of nodes and the set of lines, and the undirected graph is used as the network model of the power system.
8. A safety protection device for critical nodes in a power system, characterized in that, include: The network model acquisition unit is used to acquire the network model of the power system. The candidate defense strategy set generation unit is used to construct a set of key nodes for the network model based on node load-network centrality coupling identification, and generate a set of candidate defense strategies based on the set of key nodes through greedy-random mixed sampling; the set of candidate defense strategies includes multiple candidate defense strategies. The expected load loss calculation unit is used to calculate the expected load loss of each of the candidate defense strategies under the worst-case attack search. The optimal defense strategy determination unit is used to determine the candidate defense strategy that minimizes the expected load loss as the optimal defense strategy; the optimal defense strategy is used to strengthen and optimize the key nodes of the power system.
9. An electronic device, characterized in that, The device includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the critical node security protection method for the power system according to any one of the claims 1-7, based on the instructions in the program code.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code for executing the critical node security protection method for a power system according to any one of claims 1-7.