[论文解读] Local Cyber-Physical Attack for Masking Line Outage and Topology Attack in Smart Grid
本文提出了一种新型的本地网络物理攻击:物理断开输电线路后,通过向SCADA系统注入虚假数据来掩盖停电事件,使控制中心误检测到另一位置的虚假线路停电。该攻击基于交流潮流模型和线路停运分布因子(LODF),欺骗状态估计,成功导致拓扑误报,并增加连锁故障的风险。
Malicious attacks in the power system can eventually result in a large-scale cascade failure if not attended on time. These attacks, which are traditionally classified into \emph{physical} and \emph{cyber attacks}, can be avoided by using the latest and advanced detection mechanisms. However, a new threat called \emph{cyber-physical attacks} which jointly target both the physical and cyber layers of the system to interfere the operations of the power grid is more malicious as compared with the traditional attacks. In this paper, we propose a new cyber-physical attack strategy where the transmission line is first physically disconnected, and then the line-outage event is masked, such that the control center is misled into detecting as an obvious line outage at a different position in the local area of the power system. Therefore, the topology information in the control center is interfered by our attack. We also propose a novel procedure for selecting vulnerable lines, and analyze the observability of our proposed framework. Our proposed method can effectively and continuously deceive the control center into detecting fake line-outage positions, and thereby increase the chance of cascade failure because the attention is given to the fake outage. The simulation results validate the efficiency of our proposed attack strategy.
研究动机与目标
- 开发一种联合网络物理攻击策略,通过物理断开输电线路并掩盖真实停电,误导控制中心。
- 利用线路停运分布因子(LODF)矩阵识别易受攻击的输电线路。
- 基于交流潮流模型设计虚假数据注入机制,通过改变测量值模拟虚假线路停电。
- 通过符合物理定律确保攻击不被状态估计和不良数据检测系统发现。
- 评估该攻击对系统可观测性的影响,以及通过误报拓扑信息引发连锁故障的潜在风险。
提出的方法
- 攻击从物理断开系统中目标输电线路(真实停电线路 $l_o$)开始。
- 利用交流潮流模型向SCADA测量值注入虚假数据,修改复功率流动($ar{S}_l$)和电压幅值($W_j$),以在另一条线路($l_m$)上模拟虚假停电。
- 使用广度优先搜索(BFS)算法确定攻击区域,识别与真实停电具有局部连通性的母线。
- 利用线路停运分布因子(LODF)矩阵选择最具破坏性的目标线路,以最大化可观测性破坏。
- 修改后的测量值满足潮流方程和基尔霍夫定律,确保一致性并规避不良数据检测。
- 通过 $Z_l C_l$ 计算输电损耗,并与MATPOWER中的实际损耗进行比较,以验证模型精度并最小化可检测差异。
实验结果
研究问题
- RQ1如何通过网络层虚假数据注入掩盖物理线路停电,使控制中心错误地检测到另一条线路为停电?
- RQ2可采用何种标准识别此类联合攻击中最脆弱的输电线路?
- RQ3交流潮流模型在多大程度上可用于生成符合物理定律且难以检测的虚假数据?
- RQ4该攻击如何影响电力系统的可观测性和状态估计精度?
- RQ5输电损耗计算错误对实时监控中攻击可检测性有何影响?
主要发现
- 所提出的攻击通过使控制中心误检测到另一条线路的虚假停电,成功掩盖了真实线路停电,从而污染了拓扑信息。
- 在14母线系统中,输电损耗计算错误的影响因子 $O_{\text{inf}}$ 仅为0.95%,24母线系统中为2.32%,118母线系统中为1.71%,表明可检测误差极小。
- 由于符合潮流方程和物理定律,该攻击未被标准状态估计和不良数据检测机制发现。
- 使用交流模型可精确建模电压幅值和无功功率,相比基于直流模型的方法更有利于规避检测。
- 该攻击可引发初始故障并可能演变为连锁故障,仿真与系统响应分析已证实此可能性。
- 该攻击的统计特性与正常系统状态不同,表明可通过变化点检测或历史数据对比作为潜在防御措施。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。