PMU Data Prediction for Structured False Data Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional bad data detection techniques in power systems, particularly in state estimation, are ineffective against highly structured false data injection attacks that conform to network topology and physical laws, and lack the ability to detect temporally missing data.
Innovation Solution
A method using a total variation (TV) norm definition and optimization algorithm, which predicts future PMU measurements based on historical data and compares them with actual measurements to detect malicious attacks, employing a hierarchical computing system and TV algorithm to distinguish between structured and random data anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional bad data detection techniques based on statistical analysis are used, then random noises can be detected, but highly structured false data injection attacks conforming to network topology cannot be detected
Solution Approach 1:
The system performs preliminary actions by predicting future PMU measurements before they occur, using historical data and optimization algorithms. This predictive approach allows the system to establish expected values in advance, enabling detection of deviations caused by FDI attacks when actual measurements are received and compared against predictions.
Solution Approach 2:
The invention transitions from traditional residual-based detection in the measurement space to a predictive detection approach that incorporates temporal dimension. By predicting future measurements and comparing them with actual values, the system adds a time-based dimension to detection, enabling identification of structured attacks that evade conventional spatial-based methods.
2Measurement precision
If Nuclear Norm Minimization is used to detect FDI attacks, then randomized missing data can be determined, but temporally missing data cannot be determined
Solution Approach 1:
The system dynamically adapts its detection approach based on the temporal characteristics of missing data. By using predictive algorithms that model time-series behavior, the system can handle both randomized and temporal missing patterns, adjusting its predictions to account for the specific temporal structure of data losses in power system measurements.
Solution Approach 2:
The invention changes the fundamental parameter being optimized from nuclear norm (which handles randomized missing data) to a predictive error metric that accounts for temporal correlations. This parameter change enables the system to effectively handle temporal missing data patterns by leveraging the time-dependent nature of power system measurements in its prediction model.
3Ease of operation
If residual based bad data detection is used, then simple gross errors can be detected, but malicious attacks conforming to physical laws remain unobservable
Solution Approach 1:
The system performs preliminary prediction of expected measurements before comparison with actual values. This preliminary action creates a reference framework that enables detection of sophisticated attacks, as the predictive model accounts for physical laws and system behavior, making it difficult for attackers to craft undetectable false data without triggering anomalies in the prediction-residual comparison.
Data Source
AI summary
A method for determining whether a power system is encountering a malicious attack is provided. The method comprises: receiving a plurality of first phasor measurement unit (PMU) measurements from a plurality of PMUs of the power system; determining a plurality of expected PMU measurements associated with a future time period based on an optimization algorithm that uses differences between a plurality of consecutive predictive entries and the plurality of first PMU measurements; receiving, from the plurality of PMUs, a plurality of second PMU measurements associated with the future time period; determining whether the power system is encountering the malicious attack based on comparing the plurality of expected PMU measurements with the plurality of second PMU measurements; and executing an action based on whether the power system is encountering the malicious attack.


