A Topology Attack Detection Framework for Distribution Networks Based on Interval State Estimation
摘要
The integrity and accuracy of power grid topology are essential for the control center to make informed decisions and ensure the system’s safe operation. As the power system increasingly evolves into a cyber-physical system, the distribution network enhances its state awareness and collaborative interaction capabilities. However, this also introduces the threat of network attacks at the information system level. This paper proposes a method for detecting distribution network topology attacks by combining normalized residuals and interval state estimation to achieve security monitoring of the distribution network. First, the attack principles are analyzed from the perspectives of basic assumptions and tampering conditions, attack route selection, measurement tampering, and detection of malicious data. Then, a distribution network topology attack detection model is established based on these principles, integrating normalized residuals and interval state estimation. When a topology attack occurs, if either the normalized residuals or the state estimation results of node voltage amplitude exceed the predefined interval range, the topology recognition algorithm is triggered. This algorithm re-identifies the new distribution network topology, compares the new identification results with the known topology, and detects the attacked branches to enhance system security.