节点文献

基于机器学习的AGC系统虚假数据注入攻击检测

AGC System False Data Injection Attack Detection Based on Machine Learning

【作者】 彭超;

【导师】 曲正伟; 郭垲;

【作者基本信息】 燕山大学 , 工程硕士(专业学位), 2022, 硕士

【摘要】 虚假数据注入攻击会改变自动发电控制系统(Automatic Generation Control,AGC)的控制效果,进而可能对电力系统造成破坏性的影响。自动发电控制系统网络攻击检测的研究有利于电力系统运行环境的安全稳定。AGC系统的状态变化过程为机电暂态过程,其控制效果延迟于实时系统运行状态,传统检测方法无法检测出AGC系统的控制效果是否受到具有隐蔽性的虚假数据注入攻击影响。因此,AGC系统虚假数据注入攻击检测需要借助历史数据和当下时刻数据进行对比分析。为实现AGC系统的入侵检测的时效性、精准性和高效性,本文完成了以下研究工作:首先提出了虚假数据注入攻击具有隐蔽性的特点,传统检测方法无法检测出具有隐蔽性攻击效果的虚假数据注入攻击。文章通过仿真分析了具有隐蔽性的虚假数据注入攻击发生的场景的特点,得出了在负补偿攻击时负荷波动频率和幅值适中的情况下中低强度的虚假数据注入攻击具有良好的隐蔽性的结论。其次设计了具有隐蔽性的负补偿虚假数据入侵AGC系统的仿真模型。通过模拟AGC系统参与区域电力系统频率和有功功率调整,获得了正常运行状态下AGC系统状态变量运行数据。通过模拟AGC系统受到隐蔽性虚假数据注入攻击运行的各个场景,提取AGC系统状态变量信号受到攻击时的运行数据。采用了SMOTE过采样的方法增加了少数类受攻击样本的数量,使获取的样本数据平衡化,解决了在实际情况中正常数据样本和异常数据样本数量不平衡问题。通过对各类机器学习算法对检测模型进行训练,对比分析了机器学习算法的各项性能指标。验证了随机森林算法在精确度、精准度、F1分数、混淆矩阵衍生评价等经典指标都具有优越性的特点,验证了随机森林算法在AGC系统虚假数据注入攻击研究中检测时效性好、检测效率高、适用性广泛等优点。进一步提出了基于时间序列随机森林算法的虚假数据注入攻击检测方法。通过将历史数据分段成各个时间序列,用于提取网络入侵各个阶段的数据特征,建立各个入侵阶段数据的决策树。并以决策树投票决策的方式对实时数据进行标签分类,进而确定攻击类型来达到攻击检测效果。最后通过标准化序列方法将原始攻击检测结果转化为可用于确定攻击发生的时刻、攻击发生的位置和分析攻击发生的大小的检测结果。

【Abstract】 False data injection attacks can change the Control effect of Automatic Generation Control(AGC)systems,which may cause destructive effects on power systems.The research of automatic generation control system network attack detection is beneficial to the security and stability of power system operation environment.The state change process of AGC system is electromechanical transient process,and its control effect is delayed control.Traditional detection methods cannot detect whether the control effect of AGC system is affected by hidden false data injection attacks.Therefore,AGC system false data injection attack detection needs to use historical data and current data for comparative analysis.In order to achieve timeliness,accuracy and efficiency of AGC intrusion detection system,the following research work is completed in this paper:Firstly,the paper puts forward that the fake data injection attacks have the characteristics of concealment,and the traditional detection methods cannot detect the fake data injection attacks with the effect of concealment.In this paper,the characteristics of the scenarios of hidden false data injection attacks are analyzed by simulation,and the conclusion is that low and medium intensity false data injection attacks have good concealment under moderate load fluctuation frequency and amplitude of negative compensation attacks.Secondly,a simulation model of negative-compensation false data intrusion AGC system with concealment is designed.By simulating AGC system participating in frequency and active power adjustment of regional power system,the operation data of AGC system state variables under normal operation state are obtained.By simulating various scenarios in which AGC system is attacked by hidden false data injection,the operation data of AGC system state variable signal under attack is obtained.Use SMOTE oversampling method to increase the number of a few kinds of attack sample,make the sample data get balance,solve the imbalance of normal and abnormal data sample number.Through training various machine learning algorithms to the detection model,the performance indexes of the machine learning algorithms are compared and analyzed.It is verified that the random forest algorithm has advantages in accuracy,accuracy,F1 score,confusion matrix derivative evaluation and other classical indicators,and it is verified that the random forest algorithm has advantages of good detection timeliness,high detection efficiency and wide applicability in AGC system false data injection attack research.A fake data injection attack detection method based on time series random forest algorithm is proposed.By segmenting the historical data into each time series,it can extract the data characteristics of each stage of network intrusion and establish the decision tree of each stage of intrusion data.The real-time data are classified by the method of decision tree voting,and the attack types are determined to achieve the attack detection effect.Finally,the original attack detection results are transformed into detection results which can be used to determine the time and location of the attack and analyze the size of the attack.

  • 【网络出版投稿人】 燕山大学
  • 【网络出版年期】2023年 02期
  • 【分类号】TM61;TP181;TP393.08
节点文献中: