The integrity and accuracy of power grid topology are essential for the control center to make informed decisions and ensure the system’s safe operation. As the power system increasingly evolves into a cyber-physical system, the distribution network enhances its state awareness and collaborative interaction capabilities. However, this also introduces the threat of network attacks at the information system level. This paper proposes a method for detecting distribution network topology attacks by combining normalized residuals and interval state estimation to achieve security monitoring of the distribution network. First, the attack principles are analyzed from the perspectives of basic assumptions and tampering conditions, attack route selection, measurement tampering, and detection of malicious data. Then, a distribution network topology attack detection model is established based on these principles, integrating normalized residuals and interval state estimation. When a topology attack occurs, if either the normalized residuals or the state estimation results of node voltage amplitude exceed the predefined interval range, the topology recognition algorithm is triggered. This algorithm re-identifies the new distribution network topology, compares the new identification results with the known topology, and detects the attacked branches to enhance system security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Topology Attack Detection Framework for Distribution Networks Based on Interval State Estimation

  • Chunmei Zhang,
  • Xiaoqiang Huang,
  • Hengyou Yu,
  • Xingque Xu,
  • Shaoyan Jiang,
  • Quan Xu,
  • Jun Ge

摘要

The integrity and accuracy of power grid topology are essential for the control center to make informed decisions and ensure the system’s safe operation. As the power system increasingly evolves into a cyber-physical system, the distribution network enhances its state awareness and collaborative interaction capabilities. However, this also introduces the threat of network attacks at the information system level. This paper proposes a method for detecting distribution network topology attacks by combining normalized residuals and interval state estimation to achieve security monitoring of the distribution network. First, the attack principles are analyzed from the perspectives of basic assumptions and tampering conditions, attack route selection, measurement tampering, and detection of malicious data. Then, a distribution network topology attack detection model is established based on these principles, integrating normalized residuals and interval state estimation. When a topology attack occurs, if either the normalized residuals or the state estimation results of node voltage amplitude exceed the predefined interval range, the topology recognition algorithm is triggered. This algorithm re-identifies the new distribution network topology, compares the new identification results with the known topology, and detects the attacked branches to enhance system security.