<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" dtd-version="2.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Energy Res.</journal-id>
<journal-title>Frontiers in Energy Research</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Energy Res.</abbrev-journal-title>
<issn pub-type="epub">2296-598X</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">1502078</article-id>
<article-id pub-id-type="doi">10.3389/fenrg.2024.1502078</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Energy Research</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Research on relay setting attack defense in power systems based on a three-layer optimization model</article-title>
<alt-title alt-title-type="left-running-head">Ren et al.</alt-title>
<alt-title alt-title-type="right-running-head">
<ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3389/fenrg.2024.1502078">10.3389/fenrg.2024.1502078</ext-link>
</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Ren</surname>
<given-names>Liu</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<xref ref-type="aff" rid="aff3">
<sup>3</sup>
</xref>
<xref ref-type="aff" rid="aff4">
<sup>4</sup>
</xref>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/2853178/overview"/>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/>
<role content-type="https://credit.niso.org/contributor-roles/supervision/"/>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/conceptualization/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Binyuan</surname>
<given-names>Yan</given-names>
</name>
<xref ref-type="aff" rid="aff5">
<sup>5</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/funding-acquisition/"/>
<role content-type="https://credit.niso.org/contributor-roles/data-curation/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Hengdao</surname>
<given-names>Guo</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<xref ref-type="aff" rid="aff3">
<sup>3</sup>
</xref>
<xref ref-type="aff" rid="aff4">
<sup>4</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/project-administration/"/>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Junrong</surname>
<given-names>Liu</given-names>
</name>
<xref ref-type="aff" rid="aff5">
<sup>5</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/visualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/formal-analysis/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Yihua</surname>
<given-names>Zhu</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<xref ref-type="aff" rid="aff3">
<sup>3</sup>
</xref>
<xref ref-type="aff" rid="aff4">
<sup>4</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/formal-analysis/"/>
<role content-type="https://credit.niso.org/contributor-roles/data-curation/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Yun</surname>
<given-names>Fu</given-names>
</name>
<xref ref-type="aff" rid="aff5">
<sup>5</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/resources/"/>
<role content-type="https://credit.niso.org/contributor-roles/investigation/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Liang</surname>
<given-names>Tu</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<xref ref-type="aff" rid="aff3">
<sup>3</sup>
</xref>
<xref ref-type="aff" rid="aff4">
<sup>4</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/visualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/resources/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Zeyuan</surname>
<given-names>Zhou</given-names>
</name>
<xref ref-type="aff" rid="aff5">
<sup>5</sup>
</xref>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
<role content-type="https://credit.niso.org/contributor-roles/validation/"/>
<role content-type="https://credit.niso.org/contributor-roles/resources/"/>
</contrib>
</contrib-group>
<aff id="aff1">
<sup>1</sup>
<institution>State Key Laboratory of HVDC</institution>, <institution>Electric Power Research Institute</institution>, <institution>China Southern Power Grid</institution>, <addr-line>Guangzhou</addr-line>, <country>China</country>
</aff>
<aff id="aff2">
<sup>2</sup>
<institution>National Energy Power Grid Technology R&#x26;D Centre</institution>, <addr-line>Guangzhou</addr-line>, <country>China</country>
</aff>
<aff id="aff3">
<sup>3</sup>
<institution>Guangdong Provincial Key Laboratory of Intelligent Operation and Control for New Energy Power System</institution>, <addr-line>Guangzhou</addr-line>, <country>China</country>
</aff>
<aff id="aff4">
<sup>4</sup>
<institution>CSG Key Laboratory for Power System Simulation</institution>, <institution>Electric Power Research Institute</institution>, <institution>China Southern Power Grid</institution>, <addr-line>Guangzhou</addr-line>, <country>China</country>
</aff>
<aff id="aff5">
<sup>5</sup>
<institution>Information Centre of Guizhou Power Grid Co.</institution>, <addr-line>Guizhou</addr-line>, <country>China</country>
</aff>
<author-notes>
<fn fn-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2424301/overview">Liwei Ju</ext-link>, Northeast Electric Power University, China</p>
</fn>
<fn fn-type="edited-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2855578/overview">Zengji Liu</ext-link>, Nanjing University of Posts and Telecommunications, China</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1137958/overview">Yingjun Wu</ext-link>, Hohai University, China</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/954989/overview">Mohamed A. Mohamed</ext-link>, Minia University, Egypt</p>
</fn>
<corresp id="c001">&#x2a;Correspondence: Liu Ren, <email>liuren248@foxmail.com</email>
</corresp>
</author-notes>
<pub-date pub-type="epub">
<day>21</day>
<month>11</month>
<year>2024</year>
</pub-date>
<pub-date pub-type="collection">
<year>2024</year>
</pub-date>
<volume>12</volume>
<elocation-id>1502078</elocation-id>
<history>
<date date-type="received">
<day>26</day>
<month>09</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>11</day>
<month>11</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2024 Ren, Binyuan, Hengdao, Junrong, Yihua, Yun, Liang and Zeyuan.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Ren, Binyuan, Hengdao, Junrong, Yihua, Yun, Liang and Zeyuan</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>With the intelligent development of power systems, the number of relays continues to increase. Differences in manufacturers, systems, and protocols lead to growing security risks. Tampering with relay settings could potentially cause power outages or even system instability. Consequently, relay settings have gradually become a key target for cyberattacks, particularly in smart grids where traditional defense measures struggle to effectively address complex and diverse attack scenarios. To address this issue, this paper proposes a three-layer optimization defense model based on game theory, designed to adapt to various attack scenarios. The core methodology of this model includes a three-layer structure: The first layer optimizes the protection level of each relay by allocating limited defense budgets. The second layer analyzes the potential system damage based on the attacker&#x2019;s strategy choices. The third layer comprehensively calculates system losses to evaluate the effectiveness of defense plans. Through layer-by-layer optimization of budget allocation, the model minimizes the unsupplied energy loss caused by relay setting attacks. Compared to existing methods, this model not only improves defense effectiveness under resource constraints but also addresses multiple complex attack scenarios. Experimental results demonstrate that this model significantly enhances the system&#x2019;s defense capabilities and effectively reduces the impact of attacks on system security operations.</p>
</abstract>
<kwd-group>
<kwd>power system</kwd>
<kwd>relay setting attack</kwd>
<kwd>game theory model</kwd>
<kwd>three-layer optimization</kwd>
<kwd>defense strategy</kwd>
<kwd>cybersecurity</kwd>
</kwd-group>
<custom-meta-wrap>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Smart Grids</meta-value>
</custom-meta>
</custom-meta-wrap>
</article-meta>
</front>
<body>
<sec id="s1">
<title>1 Introduction</title>
<p>With the global development of intelligent power systems, cybersecurity has become a critical issue in power system operations (<xref ref-type="bibr" rid="B26">Yohanandhan et al., 2020</xref>). The widespread application of smart grids and the integration of Internet of Things devices have made distribution systems more automated and efficient. However, these advancements have also introduced severe cybersecurity challenges. In recent years, power systems have been frequently subjected to various cyber attacks, with key equipment such as relays becoming primary targets for attackers (<xref ref-type="bibr" rid="B2">Abraham et al., 2024</xref>). For instance, the cyber attack on Ukrainian power companies in 2015 resulted in large-scale power outages, directly affecting hundreds of thousands of users (<xref ref-type="bibr" rid="B10">Kabeyi and Olanrewaju 2022</xref>). Such attacks have exposed the vulnerability of power system relays and revealed the inadequacies of traditional defense measures in addressing complex attack scenarios (<xref ref-type="bibr" rid="B6">Elgazzar et al., 2022</xref>).</p>
<p>As power systems grow more complex, cyber attack methods have become increasingly diverse. Relay setting attacks have gradually evolved into a highly destructive form of attack (<xref ref-type="bibr" rid="B8">Ghiasi et al., 2023</xref>). Research on defense strategies against relay setting attacks is crucial for ensuring the secure operation of power systems. Game theory models provide an effective theoretical framework for this problem, capable of simulating the gaming process between attackers and defenders (<xref ref-type="bibr" rid="B19">Shan et al., 2020</xref>). Through optimized defense budget allocation, the overall system security can be enhanced under limited resource conditions, reducing system losses caused by attacks (<xref ref-type="bibr" rid="B13">Lau et al., 2020</xref>). This defense strategy can significantly improve the risk resistance of relays under attack and provide a theoretical basis for addressing future complex attack scenarios (<xref ref-type="bibr" rid="B1">Abdelkader et al., 2024</xref>).</p>
<p>Relay setting attacks primarily include Active Relay Setting Attacks (ARSA) and Passive Relay Setting Attacks (PRSA) (<xref ref-type="bibr" rid="B7">Ganjkhani et al., 2022</xref>). In active attacks, parameters such as relay startup current are tampered with by attackers, causing relays to misjudge system states and trigger tripping, leading to power supply interruptions (<xref ref-type="bibr" rid="B29">Zhou et al., 2021</xref>). Passive attacks involve modifying relay operation times or other parameters, resulting in delayed responses to faults and expanding the scope of system failures (<xref ref-type="bibr" rid="B3">Altaf et al., 2022</xref>). These two attack mechanisms pose serious threats to system stability, especially when attackers control multiple relays, potentially causing large-scale power outages and system collapse (<xref ref-type="bibr" rid="B24">Wang et al., 2024</xref>).</p>
<p>In current research, scholars focus on defense model design, detection and identification methods, and modeling of attack-defense interactions. These directions are pursued concurrently to enhance the security of power system relays and reduce their vulnerability to cyber attacks.</p>
<p>In the field of attack model development, a method was proposed in <xref ref-type="bibr" rid="B7">Ganjkhani et al. (2022)</xref> to simulate system losses caused by relay setting attacks. Both active and passive relay setting attacks were considered, and the impact on the power system was highlighted by optimizing the selection of attack strategies to maximize energy disruption. An indirect attack model was proposed in <xref ref-type="bibr" rid="B22">Wang et al. (2023)</xref>, and a defense strategy to prevent relay mistripping was designed. This strategy implements blocking cause identification technology as a built-in function of relays to resist indirect collaborative attacks. In (<xref ref-type="bibr" rid="B28">Zhang and Dong 2017</xref>), researchers proposed a trip confirmation scheme based on majority rules through reliability studies of remote relays, aiming to reduce the possibility of erroneous tripping.</p>
<p>Regarding detection and identification methods, a data mining-based detection tool was proposed in <xref ref-type="bibr" rid="B16">Mohamed and Magdy (2022)</xref>. This tool utilizes training datasets generated by Monte Carlo simulation to detect anomalous changes in relay settings. It uses rough set classification to generate a set of If-Then rules for checking whether updated settings have been tampered with during online operations. A deep learning-based system was developed in <xref ref-type="bibr" rid="B12">Khaw et al. (2020)</xref> to identify malicious attacks by detecting abnormal changes in current and voltage signals. This system first uses current and voltage measurements to train deep learning models, which are then used to detect malicious data injected by attackers. In <xref ref-type="bibr" rid="B4">Ameli et al. (2019)</xref>, an effective intrusion detection method was proposed through voltage measurement comparisons, distinguishing between false signals triggered by attacks and real internal faults. This method uses unknown input observers and state-space models to estimate local voltage and compare it with measured values.</p>
<p>In the area of attack-defense interaction modeling, a game model based on three-layer optimization was proposed in <xref ref-type="bibr" rid="B7">Ganjkhani et al. (2022)</xref>. The focus is on how defenders can minimize unsupplied energy loss under limited attacker resources. This model integrates defense budget allocation, attack strategy selection, and system loss calculation into a comprehensive optimization framework (<xref ref-type="bibr" rid="B9">Hasan et al., 2020</xref>). further explored game models for dynamic attacks, considering the long-term impact of attackers&#x2019; phased attack strategies on system security. This research adopted a new attacker-defender model, taking into account the temporal order of attacks (<xref ref-type="bibr" rid="B15">Macwan et al., 2016</xref>). focused on data injection attacks, proposing a defense mechanism that detects and mitigates attacks through basic laws in power systems. This mechanism utilizes Kirchhoff&#x2019;s laws and communication capabilities under the IEC61850 standard to detect and locate data injection attacks.</p>
<p>Current research on relay setting attacks has several limitations: 1) Defense models lack universality and struggle to adapt to various system environments. Existing models are often designed for specific attack types or system structures, showing insufficient adaptability to complex and varied attack scenarios. 2) The real-time performance and accuracy of detection and identification methods in complex scenarios need improvement. Current detection algorithms may face challenges in computational efficiency and accuracy when processing large-scale, high-dimensional data. 3) Existing attack-defense interaction models have high computational complexity, making it difficult to respond to dynamic attacks in large-scale systems. In practical applications, these models may struggle to quickly respond to changes in attacker strategies, affecting defense effectiveness.</p>
<p>To address these limitations, a three-layer optimization defense model based on game theory is proposed in this paper. A defense strategy adaptable to various attack scenarios has been designed. The core methodology of this model includes a three-layer structure: The first layer optimizes the protection level of each relay by allocating limited defense budgets. The second layer analyzes the potential system damage based on the attacker&#x2019;s strategy choices. The third layer comprehensively calculates system losses to evaluate the effectiveness of defense plans. Through layer-by-layer optimization of budget allocation, the unsupplied energy loss caused by relay setting attacks is minimized. Compared to existing methods, this model offers the following advantages: 1) It provides a more flexible and efficient defense framework by integrating a three-layer optimization model and dynamic budget allocation mechanism, capable of adapting to complex relay setting attack scenarios. 2) It improves defense effectiveness under resource constraints and can simultaneously address both active and passive relay setting attacks. The model&#x2019;s effectiveness has been verified through case studies on test systems. Experimental results demonstrate that this model significantly enhances the system&#x2019;s defense capabilities and effectively reduces the impact of attacks on system security operations. This approach provides a more comprehensive and effective solution for defending against relay setting attacks in power systems.</p>
<p>The structure of this paper is as follows: Chapter 2 discusses the mechanisms and impacts of relay setting attacks in power distribution systems. This chapter analyzes the vulnerability of relays under different types of attacks, particularly the impact of active and passive relay setting attacks on system security. A detailed vulnerability analysis provides the foundation for subsequent defense model design. Chapter 3 presents the game theory-based defense model design. This chapter constructs a three-layer optimization model, systematically describing the interaction between defense budget allocation and attacker strategies. The model maximizes system security while minimizing unsupplied energy loss caused by attacks through optimized budget allocation. Chapter 4 verifies the model&#x2019;s practical effectiveness through experimental design and case analysis. Based on the IEEE 123-node test system, the defense effects of different budget allocation strategies under active and passive relay attacks are evaluated. The role of defense strategies in enhancing system security is demonstrated, and specific schemes for optimizing budget allocation are provided. Chapter 5 summarizes the main conclusions of the research, elaborates on the effectiveness of game theory in defending against relay setting attacks, and points out potential directions for future research, such as introducing dynamic defense mechanisms and strategies for addressing other types of attacks.</p>
</sec>
<sec id="s2">
<title>2 Mechanisms and impacts of relay setting attacks in power distribution systems</title>
<sec id="s2-1">
<title>2.1 Relay protection mechanisms in power distribution systems</title>
<p>Overcurrent protection relays are crucial devices for ensuring stable operation in power distribution systems. These relays detect current changes in the system and can promptly trigger circuit breakers or reclosers, thereby preventing short-circuit faults or other abnormal conditions from causing greater impact on the system. The foundation of overcurrent protection lies in the relay&#x2019;s ability to quickly issue a trip signal when the current value exceeds a set threshold, thus protecting downstream equipment. The core of this process is the relay&#x2019;s precise judgment of current, ensuring that it can operate at the appropriate time to avoid system collapse due to slow response or misoperation.</p>
<p>In practical operation, the protection mechanism of relays involves principles of overcurrent protection and requires close coordination with circuit breakers and reclosers. Circuit breakers execute the opening operation after receiving a trip signal from the relay, disconnecting the faulty line and protecting other parts of the system. Reclosers are responsible for reclosing the circuit after the fault has been cleared, allowing power supply to be restored as quickly as possible. This collaborative working mechanism greatly improves the system&#x2019;s fault tolerance and reduces the scope of power outages caused by faults. The coordinated action between relays, circuit breakers, and reclosers is crucial for ensuring the stability of the power system.</p>
<p>The response speed of overcurrent relays is directly related to their time dial settings. The time dial determines the operating time of the relay, which is the delay time from detecting a fault current to issuing a trip command. The operating time of a relay under fault conditions is represented by the following formula:<disp-formula id="equ1">
<mml:math id="m1">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="bold-italic">T</mml:mi>
<mml:mrow>
<mml:mi mathvariant="bold-italic">r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="bold-italic">g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi mathvariant="bold-italic">&#x398;</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mfrac>
<mml:msub>
<mml:mi mathvariant="bold-italic">&#x3b1;</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="bold-italic">I</mml:mi>
<mml:mrow>
<mml:mi mathvariant="bold-italic">r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="bold-italic">g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msubsup>
<mml:mi mathvariant="bold-italic">I</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
<mml:mrow>
<mml:mi mathvariant="bold-italic">T</mml:mi>
<mml:mi mathvariant="bold-italic">h</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:msub>
<mml:mi mathvariant="bold-italic">&#x3b2;</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
</mml:msub>
</mml:msup>
<mml:mo>&#x2212;</mml:mo>
<mml:mn mathvariant="bold">1</mml:mn>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2b;</mml:mo>
<mml:msub>
<mml:mi mathvariant="bold-italic">&#x3b3;</mml:mi>
<mml:mi mathvariant="bold-italic">r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf1">
<mml:math id="m2">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the fault current seen by relay <inline-formula id="inf2">
<mml:math id="m3">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf3">
<mml:math id="m4">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> is the adjusted pickup current, <inline-formula id="inf4">
<mml:math id="m5">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="normal">&#x398;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the time dial setting, and <inline-formula id="inf5">
<mml:math id="m6">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf6">
<mml:math id="m7">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b2;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf7">
<mml:math id="m8">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b3;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> are constants representing the characteristics of the curve selected for relay <inline-formula id="inf8">
<mml:math id="m9">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. These parameters determine the relay&#x2019;s response time to various fault currents, allowing the relay to adjust its operation time automatically based on the magnitude of the current.</p>
<p>To ensure reliable relay operation in multiple fault scenarios, a layered coordination approach is typically adopted. This approach dictates that relays closest to the fault point operate first, while relays farther from the fault point act as backup protection based on set time delays. The core of this protection mechanism lies in ensuring that only the faulty part of the system is isolated, thereby avoiding widespread power outages due to incorrect tripping. The time dial values and pickup current settings in the aforementioned formula directly influence the protection level of the relay, ensuring each relay operates at the correct time point.</p>
<p>The protective action of relays must also be matched with the ratios of current and voltage transformers. The ratio settings of transformers significantly affect the operational accuracy of relays. Improper transformer ratio settings may lead to inaccurate fault current judgments by relays, resulting in delayed relay actions or incorrect tripping. Therefore, when designing relay protection mechanisms, it is necessary to consider time dial and pickup current settings and the electrical parameters of the entire system. This comprehensive approach ensures that relay actions align with the system&#x2019;s actual operating conditions.</p>
</sec>
<sec id="s2-2">
<title>2.2 Relay setting attacks</title>
<sec id="s2-2-1">
<title>2.2.1 Active relay setting attacks</title>
<p>In ARSA, control over relay settings can be gained by attackers. The pickup current setting <inline-formula id="inf9">
<mml:math id="m10">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> can be maliciously modified, causing the relay to incorrectly judge the system as being in an overload or short-circuit state, thereby sending erroneous trip signals. The pickup current setting determines the current level at which the relay automatically triggers a trip when detected. By lowering this setting to a level far below normal operating currents, attackers can trigger relay trips during normal system operation, leading to circuit breaker openings and power supply interruptions in the system.</p>
<p>This type of attack mechanism relies on adjusting relay parameters and can be described by the following formula:<disp-formula id="equ2">
<mml:math id="m11">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:msup>
<mml:mi>&#x3c7;</mml:mi>
<mml:mi>a</mml:mi>
</mml:msup>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mspace width="1em"/>
<mml:msup>
<mml:mi>&#x3c7;</mml:mi>
<mml:mi>a</mml:mi>
</mml:msup>
<mml:mo>&#x3c;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x3b4;</mml:mi>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf10">
<mml:math id="m12">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>b</mml:mi>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> represents the pickup current of relay <inline-formula id="inf11">
<mml:math id="m13">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> after ARSA, <inline-formula id="inf12">
<mml:math id="m14">
<mml:mrow>
<mml:msup>
<mml:mi>&#x3c7;</mml:mi>
<mml:mi>a</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> is the scaling factor of ARSA, and <inline-formula id="inf13">
<mml:math id="m15">
<mml:mrow>
<mml:mi>&#x3b4;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> represents the tolerance for measurement errors in the system. The attacker adjusts <inline-formula id="inf14">
<mml:math id="m16">
<mml:mrow>
<mml:msup>
<mml:mi>&#x3c7;</mml:mi>
<mml:mi>a</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf15">
<mml:math id="m17">
<mml:mrow>
<mml:mi>&#x3b4;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> to ensure that the relay&#x2019;s setting is reduced to an extremely unreasonable level, causing the relay to incorrectly detect a fault and trip even in the absence of an actual fault.</p>
<p>These attacks often directly impact downstream loads in the system. When relays trigger tripping, the downstream circuit breakers are forced to open, causing a sudden disconnection of large loads. The power outage in downstream loads affects end users and may further trigger cascading reactions such as system voltage imbalance or frequency fluctuations, increasing system operational instability. The immediate nature of ARSA implies that once successful, the system will instantly enter an abnormal state, placing higher demands on the real-time monitoring and response capabilities of maintenance personnel.</p>
<p>In distribution systems, the destructive nature of ARSA is manifested in the erroneous tripping behavior of the relays themselves and potentially more severe consequences through coordinated actions between relays, circuit breakers, and reclosers. Typically, the tripping of one relay can trigger a chain reaction in related equipment, rapidly expanding the fault area. For large-scale distribution systems, a single relay&#x2019;s erroneous operation may lead to power outages across entire regions. Particularly during high-load periods, power outages caused by such attacks affect downstream equipment and adversely impact upstream power supply equipment, further exacerbating system instability.</p>
</sec>
<sec id="s2-2-2">
<title>2.2.2 Passive relay setting attacks</title>
<p>In PRSA, relay settings are modified by attackers to prevent expected operation during system faults. The characteristic of these attacks is that their effects are not immediately apparent. Instead, they cause relay failures when future system faults occur, leading to delayed or incorrect tripping, thereby expanding the impact range of faults. These attacks often involve adjustments to the relay&#x2019;s time dial and pickup current settings, causing the relay to fail to respond promptly under fault conditions and disrupting relay coordination.</p>
<p>The key mechanism of PRSA is to violate the time coordination constraints between relays by adjusting their operation times. Suppose relay <inline-formula id="inf16">
<mml:math id="m18">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is responsible for protecting a certain line segment, with relay <inline-formula id="inf17">
<mml:math id="m19">
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> as its backup. The time coordination relationship between them can be expressed by the following constraint:<disp-formula id="equ3">
<mml:math id="m20">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2265;</mml:mo>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mo>,</mml:mo>
<mml:mo>&#x2200;</mml:mo>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf18">
<mml:math id="m21">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the operation time delay of the backup relay <inline-formula id="inf19">
<mml:math id="m22">
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> when a fault <inline-formula id="inf20">
<mml:math id="m23">
<mml:mrow>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> occurs downstream of relay <inline-formula id="inf21">
<mml:math id="m24">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf22">
<mml:math id="m25">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the operation time of relay <inline-formula id="inf23">
<mml:math id="m26">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf24">
<mml:math id="m27">
<mml:mrow>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the required time coordination margin between them. Under normal conditions, the primary relay <inline-formula id="inf25">
<mml:math id="m28">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> will trip first, and the backup relay <inline-formula id="inf26">
<mml:math id="m29">
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> will only operate if the primary relay fails.</p>
<p>In a Passive Relay Setting Attack (PRSA), the attacker manipulates the settings of relay <inline-formula id="inf27">
<mml:math id="m30">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, increasing its operation time delay <inline-formula id="inf28">
<mml:math id="m31">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, causing the backup relay <inline-formula id="inf29">
<mml:math id="m32">
<mml:mrow>
<mml:msup>
<mml:mi>r</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> to trip before the primary relay. The attacker disrupts the time coordination by altering the parameter <inline-formula id="inf30">
<mml:math id="m33">
<mml:mrow>
<mml:mo>&#x2206;</mml:mo>
<mml:msup>
<mml:mi>T</mml:mi>
<mml:mi>b</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>, as shown in the following equation:<disp-formula id="equ4">
<mml:math id="m34">
<mml:mrow>
<mml:msubsup>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mo>&#x2206;</mml:mo>
<mml:msup>
<mml:mi>T</mml:mi>
<mml:mi>b</mml:mi>
</mml:msup>
<mml:mo>,</mml:mo>
<mml:mspace width="1em"/>
<mml:mo>&#x2206;</mml:mo>
<mml:msup>
<mml:mi>T</mml:mi>
<mml:mi>b</mml:mi>
</mml:msup>
<mml:mo>&#x3e;</mml:mo>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>&#x3b4;</mml:mi>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf31">
<mml:math id="m35">
<mml:mrow>
<mml:msubsup>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>b</mml:mi>
<mml:mi>b</mml:mi>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> is the operation time delay of relay <inline-formula id="inf32">
<mml:math id="m36">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> after the attack, and <inline-formula id="inf33">
<mml:math id="m37">
<mml:mrow>
<mml:mo>&#x2206;</mml:mo>
<mml:msup>
<mml:mi>T</mml:mi>
<mml:mi>b</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> is the additional delay introduced by the attack. <inline-formula id="inf34">
<mml:math id="m38">
<mml:mrow>
<mml:mi>&#x3b4;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> represents the tolerance for measurement errors in the system. By increasing the operation delay, PRSA prevents the primary relay from responding in time to faults, causing the downstream backup relay to trip prematurely and thus widening the scope of the outage.</p>
<p>The impact of PRSA on power distribution systems lies in its increase of system vulnerability during fault conditions. The consequences of the attack are manifested only when the system experiences short circuits or other faults after relay settings have been modified. Compared to active attacks, PRSA is more covert. Attackers can quietly alter relay parameters without triggering immediate anomalies. The effects of the attack are revealed only through relay failures during fault occurrences, often exacerbating the scope and severity of accidents.</p>
<p>This attack method endangers not only single relays but can also aggravate fault consequences by affecting multiple relays across the entire distribution system. Particularly when time settings of multiple relays are simultaneously tampered with, widespread power outages may occur.</p>
</sec>
</sec>
<sec id="s2-3">
<title>2.3 Vulnerability analysis of relay setting attacks</title>
<p>The relay protection mechanism in power distribution systems relies on communication networks, firmware, and local access interfaces of devices. Vulnerabilities in these aspects provide attackers with multiple potential pathways to launch attacks on relay settings. By infiltrating the system through different means, attackers may cause relay malfunctions or misoperations, thereby jeopardizing the security and stability of the power grid. Understanding these vulnerabilities can provide a basis for formulating defense measures.</p>
<sec id="s2-3-1">
<title>2.3.1 Security vulnerabilities in communication networks</title>
<p>Relays in power distribution systems are typically connected to control centers via Wide Area Networks (WAN) and use standard communication protocols (such as IEC104 and IEC61850) for data transmission. The extensive coverage of these communication networks exposes them to multiple potential attack entry points. The overall failure probability of the system is:<disp-formula id="equ5">
<mml:math id="m39">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf35">
<mml:math id="m40">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>f</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the system failure probability, <inline-formula id="inf36">
<mml:math id="m41">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> indicates the probability that the attacker controls the relay, <inline-formula id="inf37">
<mml:math id="m42">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> denotes the emergency response capability of the control center, and <inline-formula id="inf38">
<mml:math id="m43">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the total attack success probability. The total attack success probability is calculated as:<disp-formula id="equ6">
<mml:math id="m44">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf39">
<mml:math id="m45">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> refers to the security of the network layer, <inline-formula id="inf40">
<mml:math id="m46">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> refers to the security of the protocol layer, and <inline-formula id="inf41">
<mml:math id="m47">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> refers to the security of the physical layer.</p>
<p>System networks can be infiltrated by attackers through firewall vulnerabilities or other weaknesses. Upon successful infiltration, network protection measures can be bypassed, allowing direct access to relay control interfaces and alteration of settings (<xref ref-type="bibr" rid="B18">Reda et al. 2022</xref>). This may result in relay failures during actual faults. For instance, relay pickup current or time dial settings can be modified by attackers, preventing normal tripping during actual faults (<xref ref-type="bibr" rid="B29">Zhou et al., 2021</xref>).</p>
<p>Communication network vulnerabilities are not limited to the physical layer but are closely related to the security of software, protocols, and data transmission (<xref ref-type="bibr" rid="B8">Ghiasi et al., 2023</xref>). Remote attack methods may be employed by attackers, such as Distributed Denial of Service (DDoS) or man-in-the-middle attacks (<xref ref-type="bibr" rid="B24">Wang et al., 2024</xref>). These attacks can sever the connection between control centers and relays, affecting the normal protective functions of the system.</p>
</sec>
<sec id="s2-3-2">
<title>2.3.2 Exploiting firmware vulnerabilities in relays</title>
<p>The firmware of relays, which serves as their core operating logic, can be targeted by attackers through the injection of malicious code. Firmware attacks may occur during the production, installation phases, or even during firmware updates. The final probability of a successful firmware tampering can be expressed as:<disp-formula id="equ7">
<mml:math id="m48">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>w</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>g</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mfrac>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf42">
<mml:math id="m49">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>k</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the resources available to the attacker, <inline-formula id="inf43">
<mml:math id="m50">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> denotes the effectiveness of security measures, <inline-formula id="inf44">
<mml:math id="m51">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>w</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>g</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> reflects the depth of the attacker&#x2019;s understanding of the firmware logic, and <inline-formula id="inf45">
<mml:math id="m52">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the probability of firmware tampering.</p>
<p>The probability of firmware tampering is calculated as:<disp-formula id="equ8">
<mml:math id="m53">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>t</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf46">
<mml:math id="m54">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mrow>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>d</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the security of the firmware update channel, and <inline-formula id="inf47">
<mml:math id="m55">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mi>m</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>l</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> indicates the probability of successfully implanting malicious code by the attacker.</p>
<p>As firmware updates for many relays are conducted through online channels, malware can be intercepted and implanted by attackers during updates (<xref ref-type="bibr" rid="B5">Amin et al., 2021</xref>). Malicious firmware typically includes triggers and payloads. Triggers activate malicious operations based on specific events or signals, while payloads are the actual attack behaviors (<xref ref-type="bibr" rid="B14">Li et al., 2024</xref>). Once firmware is tampered with, relays can be remotely controlled or triggered at specific times by attackers, causing malfunctions or erroneous actions at critical moments (<xref ref-type="bibr" rid="B20">Trevizan et al., 2022</xref>). For instance, relay response times might be delayed by attackers, preventing timely tripping during system faults and disrupting protection coordination (<xref ref-type="bibr" rid="B23">Wang et al., 2021</xref>). To defend against such attacks, digital signatures and encryption can be used to verify the integrity of firmware updates. Regular auditing and upgrading of firmware can also reduce the possibility of malicious code implantation.</p>
</sec>
<sec id="s2-3-3">
<title>2.3.3 Local access attacks on relays</title>
<p>Although many relay devices are located within physically well-protected substations, relays distributed along distribution lines often lack strict physical protection (<xref ref-type="bibr" rid="B21">Vahidi et al., 2023</xref>). Through physical contact, attackers can directly connect to device interfaces and modify relay settings (<xref ref-type="bibr" rid="B17">Rajkumar et al., 2020</xref>). In some cases, attackers might even use techniques such as electromagnetic interference to disrupt internal circuits or data storage of relays, leading to abnormal device operation (<xref ref-type="bibr" rid="B20">Trevizan et al., 2022</xref>). The formula for calculating the probability of successful local attacks is:<disp-formula id="equ9">
<mml:math id="m56">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>E</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>I</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mfrac>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf48">
<mml:math id="m57">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>h</mml:mi>
<mml:mi>y</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>i</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the effectiveness of physical protection measures, <inline-formula id="inf49">
<mml:math id="m58">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mrow>
<mml:mi>p</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> refers to the number of exposed physical ports, and <inline-formula id="inf50">
<mml:math id="m59">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mi>E</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>I</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> denotes the success rate of electromagnetic interference (EMI) attacks.</p>
<p>Direct connection to device interfaces and modification of relay settings can be achieved by attackers through physical contact (<xref ref-type="bibr" rid="B25">Wlazlo et al., 2021</xref>). In some cases, techniques such as electromagnetic interference might be used by attackers to disrupt internal circuits or data storage of relays, leading to abnormal device operation. Although local access attacks require physical contact, they pose higher risks in unattended outdoor equipment. Relay normal operation can be affected by attackers through forceful damage or high-tech tools like electromagnetic pulses. Additionally, exposed physical ports provide attackers with ways to bypass other protective measures (<xref ref-type="bibr" rid="B11">Kampourakis et al., 2023</xref>). To defend against local attacks, measures can be taken to strengthen relay external packaging, install anti-tampering detection devices, or reduce the possibility of local attacks through more advanced physical protection means (<xref ref-type="bibr" rid="B27">Yu et al., 2023</xref>).</p>
</sec>
</sec>
</sec>
<sec id="s3">
<title>3 Game theory-based defense model for relay setting attacks</title>
<sec id="s3-1">
<title>3.1 Design and optimization of the game theory model</title>
<p>The stability and reliability of the power system are directly affected by the security of relay settings. In the face of potential cyber-attack threats, both defenders and attackers need to make optimal decisions in the game process. Two game models are analyzed in this paper: incomplete information game model and complete information game model, to discuss defense and attack strategies under different information conditions. In incomplete information games, strategies of both parties have asymmetry and uncertainty, while in complete information games, both parties have a clearer understanding of each other&#x2019;s strategies and resources. Through a three-layer optimization model in the game theory framework, this paper will discuss the budget allocation of defenders and strategy selection of attackers from these two scenarios respectively, ultimately maximizing system security.</p>
<sec id="s3-1-1">
<title>3.1.1 Defense and attack strategy modeling</title>
<p>The strategic interaction between defenders and attackers can be described using game theory models. The defender&#x2019;s goal is to reduce the Expected Energy Not Supplied (EENS) under attack through rational budget allocation. The attacker aims to maximize system losses by selecting specific attack strategies. The strategies of defenders and attackers interact: the defender&#x2019;s budget allocation directly affects the attacker&#x2019;s success rate, while the attacker&#x2019;s strategy selection influences the system&#x2019;s operational state and security.</p>
<sec id="s3-1-1-1">
<title>3.1.1.1 Two game scenarios:</title>
<p>
<list list-type="simple">
<list-item>
<p>a) Incomplete Information Game: In real situations, attackers and defenders may not fully understand all strategies and resources of their opponents. Attackers might be unaware of the defender&#x2019;s focus on protecting certain relays, while defenders may struggle to predict specific attack targets and resource constraints of attackers. This asymmetric information reflects real-world complexity, so the game model needs to consider how this information incompleteness affects decisions and outcomes. In this scenario, defenders and attackers must make optimal decisions based on expectations of their opponent&#x2019;s type and behavior.</p>
</list-item>
<list-item>
<p>b) Complete Information Game: In some scenarios, it is assumed that defenders and attackers have complete knowledge of each other&#x2019;s resources, strategies, and objectives. Here, strategy selection in the game can be simplified to a zero-sum game, with both parties directly confronting each other under complete information conditions. This type of scenario is more suitable for situations where information about the opponent is fully known, optimizing budget allocation and strategy selection to maximize one&#x2019;s own benefits or minimize losses.</p>
</list-item>
</list>
</p>
<p>To adapt to these two different information conditions, subsequent chapters of this paper will explore the Bayesian game model under incomplete information games, and the simplified bi-level optimization under complete information games. This approach will provide optimal decision support for defenders and attackers under different information conditions.</p>
</sec>
</sec>
<sec id="s3-1-2">
<title>3.1.2 Mathematical description of the three-layer optimization model</title>
<p>The interaction between defenders and attackers is described by the three-layer optimization model. It integrates defense budget allocation, attack strategy selection, and system loss calculation into a comprehensive optimization framework. The three-layer structure consists of:<list list-type="simple">
<list-item>
<p>(1) Defense Budget allocation Layer (First Layer): The defender&#x2019;s probability of relay failure is reduced through the allocation of limited defense budgets. The decision variable for the defender is the budget allocation <inline-formula id="inf51">
<mml:math id="m60">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, for each relay, with the objective of minimizing the system&#x2019;s EENS. The defender&#x2019;s budget allocation is represented by the vector <inline-formula id="inf52">
<mml:math id="m61">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mo>.</mml:mo>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mo>.</mml:mo>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mo>.</mml:mo>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mo>.</mml:mo>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mo>.</mml:mo>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mo>.</mml:mo>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>R</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, where <inline-formula id="inf53">
<mml:math id="m62">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the defense budget allocated to relay <inline-formula id="inf54">
<mml:math id="m63">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. The defender&#x2019;s total budget <inline-formula id="inf55">
<mml:math id="m64">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="italic">max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is subject to the following constraint:</p>
</list-item>
</list>
<disp-formula id="equ10">
<mml:math id="m65">
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munderover>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>R</mml:mi>
</mml:munderover>
</mml:mstyle>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>&#x2264;</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="italic">max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>The total budget constraint is represented by the set <inline-formula id="inf56">
<mml:math id="m66">
<mml:mrow>
<mml:mi mathvariant="script">D</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>:<disp-formula id="equ11">
<mml:math id="m67">
<mml:mrow>
<mml:mi mathvariant="script">D</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="{" close="}" separators="|">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msubsup>
<mml:mi mathvariant="double-struck">R</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mi mathvariant="bold-italic">R</mml:mi>
</mml:msubsup>
<mml:mo>&#x7c;</mml:mo>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munderover>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>R</mml:mi>
</mml:munderover>
</mml:mstyle>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="italic">max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>This set indicates that the defender&#x2019;s total budget <inline-formula id="inf57">
<mml:math id="m68">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="italic">max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> needs to be allocated across all relays, and the sum of budget allocations cannot exceed the defender&#x2019;s available budget.</p>
<p>The EENS calculation formula is:<disp-formula id="equ12">
<mml:math id="m69">
<mml:mrow>
<mml:mi>E</mml:mi>
<mml:mi>E</mml:mi>
<mml:mi>N</mml:mi>
<mml:mi>S</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf58">
<mml:math id="m70">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the defense budget allocated to relay <inline-formula id="inf59">
<mml:math id="m71">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf60">
<mml:math id="m72">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> represents the system-level defense budget, and <inline-formula id="inf61">
<mml:math id="m73">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the load loss caused by the failure of relay <inline-formula id="inf62">
<mml:math id="m74">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. <inline-formula id="inf63">
<mml:math id="m75">
<mml:mrow>
<mml:mi mathvariant="script">S</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the index set of all relays <inline-formula id="inf64">
<mml:math id="m76">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> in the power system, where failures or losses may occur. The higher the EENS, the greater the power supply loss under attack. Therefore, the defense strategy should prioritize reinforcing high-load nodes.</p>
<p>Defense strategies are typically divided into device-level and system-level. Device-level defense aims to enhance the local security of each relay, mainly including strengthening physical barriers, upgrading firmware security, introducing multi-factor authentication, adding firewalls for each relay, etc. These measures improve overall system security by reducing the failure probability <inline-formula id="inf65">
<mml:math id="m77">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> of specific relays, typically described using an exponential decay model:<disp-formula id="equ13">
<mml:math id="m78">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msup>
<mml:mi>e</mml:mi>
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>&#x3bc;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf66">
<mml:math id="m79">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3bc;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the sensitivity coefficient of relay <inline-formula id="inf67">
<mml:math id="m80">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, representing the degree to which the defense budget allocated to that relay affects its failure probability.</p>
<p>System-level defense focuses on the security of the entire system, mainly including encryption of network-wide communication, system monitoring upgrades, integration of attack detection systems, etc. The system-level defense budget <inline-formula id="inf68">
<mml:math id="m81">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> System-level defense focuses on the security of the entire system, mainly including encryption of network-wide communication, system monitoring upgrades, integration of attack detection systems, etc. The system-level defense budget<disp-formula id="equ14">
<mml:math id="m82">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>&#x3b2;</mml:mi>
<mml:msup>
<mml:mi>e</mml:mi>
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>&#x3bc;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:msup>
<mml:mo>&#x2b;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:msup>
<mml:mi>e</mml:mi>
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x3be;</mml:mi>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf69">
<mml:math id="m83">
<mml:mrow>
<mml:mi>&#x3b2;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the weighting factor between the device-level and system-level budgets, <inline-formula id="inf70">
<mml:math id="m84">
<mml:mrow>
<mml:mi>&#x3be;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> represents the effectiveness parameter of system-level defense, <inline-formula id="inf71">
<mml:math id="m85">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the local defense budget allocated to each relay to reduce its failure probability, and <inline-formula id="inf72">
<mml:math id="m86">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> is the system-level defense budget used to enhance the protection capability of the entire system. Reasonable allocation of defense budgets requires a balance between device-level and system-level to minimize overall failure probability.<list list-type="simple">
<list-item>
<p>(2) Attacker&#x2019;s Strategy Selection Layer (Second Layer): <inline-formula id="inf73">
<mml:math id="m87">
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">K</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="{" close="}" separators="|">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mo>&#x22ef;</mml:mo>
<mml:mo>,</mml:mo>
<mml:mi>K</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> is defined as the attack scenario, where <inline-formula id="inf74">
<mml:math id="m88">
<mml:mrow>
<mml:mi mathvariant="script">K</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the set of all attack scenarios, and <inline-formula id="inf75">
<mml:math id="m89">
<mml:mrow>
<mml:mi>K</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the total number of scenarios. The number of possible attack combinations is calculated by:</p>
</list-item>
</list>
<disp-formula id="equ15">
<mml:math id="m90">
<mml:mrow>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mtable columnalign="center">
<mml:mtr>
<mml:mtd>
<mml:mi>x</mml:mi>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd>
<mml:mi>y</mml:mi>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>!</mml:mo>
</mml:mrow>
<mml:mrow>
<mml:mi>y</mml:mi>
<mml:mo>!</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>!</mml:mo>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf76">
<mml:math id="m91">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> represents the total number of relays, and <inline-formula id="inf77">
<mml:math id="m92">
<mml:mrow>
<mml:mi>y</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the number of relays attacked simultaneously.</p>
<p>The attacker selects one or more relays as attack targets within the limited resource constraint. The attacker&#x2019;s goal is to disrupt the system by maximizing load loss. The attacker selects the attack target set <inline-formula id="inf78">
<mml:math id="m93">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and optimizes their attack strategy to maximize system loss. The specific optimization problem is described as:<disp-formula id="equ16">
<mml:math id="m94">
<mml:mrow>
<mml:munder>
<mml:mi>max</mml:mi>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:munder>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>subject to:<disp-formula id="equ17">
<mml:math id="m95">
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>C</mml:mi>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf79">
<mml:math id="m96">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the load loss caused by the failure of relay <inline-formula id="inf80">
<mml:math id="m97">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. The attacker&#x2019;s selection is limited by the total available resources <inline-formula id="inf81">
<mml:math id="m98">
<mml:mrow>
<mml:mi>C</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf82">
<mml:math id="m99">
<mml:mrow>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> denotes the resources required to attack relay <inline-formula id="inf83">
<mml:math id="m100">
<mml:mrow>
<mml:mi>r</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. The attacker maximizes system loss by selecting the relay set <inline-formula id="inf84">
<mml:math id="m101">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>Due to limited resources, both the defender and attacker need to make optimal decisions within their budgets. The attacker selects the target relay combination <inline-formula id="inf85">
<mml:math id="m102">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to maximize the system&#x2019;s load loss <inline-formula id="inf86">
<mml:math id="m103">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, while the defender allocates budget <inline-formula id="inf87">
<mml:math id="m104">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to reduce the relay failure probability <inline-formula id="inf88">
<mml:math id="m105">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> to minimize losses.<list list-type="simple">
<list-item>
<p>(3) System Loss Calculation Layer (Third Layer): The system loss <inline-formula id="inf89">
<mml:math id="m106">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3d5;</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> is jointly determined by the defense budget <inline-formula id="inf90">
<mml:math id="m107">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and attack strategy <inline-formula id="inf91">
<mml:math id="m108">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. The loss function is expressed as:</p>
</list-item>
</list>
<disp-formula id="equ18">
<mml:math id="m109">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3d5;</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>The core problem of the entire three-layer structure can be represented by a typical Min-Max optimization problem. The defender&#x2019;s goal is to minimize system loss under the worst-case attack scenario:<disp-formula id="equ19">
<mml:math id="m110">
<mml:mrow>
<mml:munder>
<mml:mi>min</mml:mi>
<mml:mrow>
<mml:mi mathvariant="normal">d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">D</mml:mi>
</mml:mrow>
</mml:munder>
<mml:munder>
<mml:mi>max</mml:mi>
<mml:mrow>
<mml:mi mathvariant="normal">k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">K</mml:mi>
</mml:mrow>
</mml:munder>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3d5;</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi mathvariant="bold">d</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msup>
<mml:mi mathvariant="normal">T</mml:mi>
<mml:mi>R</mml:mi>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>where the system recovery time <inline-formula id="inf92">
<mml:math id="m111">
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">T</mml:mi>
<mml:mi>R</mml:mi>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> represents the time required for the system to return to normal operation after an attack. It depends on the budget <inline-formula id="inf93">
<mml:math id="m112">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> allocated by the defender for identifying and restoring the system. By optimizing <inline-formula id="inf94">
<mml:math id="m113">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>, the defender can accelerate the recovery process and reduce the total system loss. After an attack, the defender must also consider how to optimize the recovery time <inline-formula id="inf95">
<mml:math id="m114">
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">T</mml:mi>
<mml:mi>R</mml:mi>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, which is related to the identification system&#x2019;s budget <inline-formula id="inf96">
<mml:math id="m115">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>:<disp-formula id="equ20">
<mml:math id="m116">
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">T</mml:mi>
<mml:mi>R</mml:mi>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="equ21">
<mml:math id="m117">
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mi>R</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>&#x2b;</mml:mo>
<mml:msup>
<mml:mi>e</mml:mi>
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x3b3;</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
<mml:mo>&#x2212;</mml:mo>
<mml:msup>
<mml:mi>D</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:math>
</disp-formula>where <inline-formula id="inf97">
<mml:math id="m118">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> represents the recovery time of the distribution system without an identification system, <inline-formula id="inf98">
<mml:math id="m119">
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> is the time reduced by deploying an identification system, <inline-formula id="inf99">
<mml:math id="m120">
<mml:mrow>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mi>R</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is the reduced recovery time after installing the identification system, <inline-formula id="inf100">
<mml:math id="m121">
<mml:mrow>
<mml:msup>
<mml:mi>D</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> is the minimum budget required to install the identification system, and <inline-formula id="inf101">
<mml:math id="m122">
<mml:mrow>
<mml:mi>&#x3b3;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is a parameter controlling the smoothness of the function. When the budget <inline-formula id="inf102">
<mml:math id="m123">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> exceeds a certain threshold <inline-formula id="inf103">
<mml:math id="m124">
<mml:mrow>
<mml:msup>
<mml:mi>D</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>, the identification system can significantly shorten the recovery time. However, when the budget is insufficient, the reduction in recovery time is limited. By optimizing <inline-formula id="inf104">
<mml:math id="m125">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>, the defender can accelerate system recovery speed, thereby reducing the total system loss.</p>
</sec>
</sec>
<sec id="s3-2">
<title>3.2 Budget allocation strategy for security measures</title>
<p>In power system defense strategies, rational defense budget allocation is crucial for ensuring system security and resilience. As relay security directly determines the system&#x2019;s risk resistance under cyber attacks, budget allocation must consider both device-level and system-level defenses. Through mathematical modeling, this paper explores how to allocate budgets for these two types of defense measures under limited budget conditions to optimize overall defense effectiveness. While the proposed model assumes rational decision-making by both attackers and defenders, we recognize that real-world scenarios often involve irrational or unpredictable strategies by attackers. Attackers may not always follow optimized or predictable paths due to limited information, resource constraints, or other contextual factors. To address this complexity, future extensions of this model could incorporate stochastic elements, introducing randomness into the attacker&#x2019;s strategy selection. This would allow for a more robust defense model that reflects the uncertainty and variability of real-world cyber-physical system attacks.</p>
<sec id="s3-2-1">
<title>3.2.1 Simplification and modeling of the budget allocation problem</title>
<p>In the budget allocation problem, defenders need to find a balance between device-level and system-level defenses to minimize the EENS of the entire system.</p>
<p>The defender&#x2019;s core objective is to minimize the system&#x2019;s expected loss by rationally allocating budgets <inline-formula id="inf105">
<mml:math id="m126">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf106">
<mml:math id="m127">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> within the budget constraint <inline-formula id="inf107">
<mml:math id="m128">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="italic">max</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. The optimization problem can be formulated as the following min-max problem:<disp-formula id="equ22">
<mml:math id="m129">
<mml:mrow>
<mml:munder>
<mml:mi mathvariant="italic">min</mml:mi>
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">D</mml:mi>
</mml:mrow>
</mml:munder>
<mml:munder>
<mml:mi mathvariant="italic">max</mml:mi>
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">K</mml:mi>
</mml:mrow>
</mml:munder>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>Where the attacker maximizes the system&#x2019;s load loss <inline-formula id="inf108">
<mml:math id="m130">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> by selecting attack scenarios <inline-formula id="inf109">
<mml:math id="m131">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, while the defender minimizes these losses through budget allocation strategies <inline-formula id="inf110">
<mml:math id="m132">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf111">
<mml:math id="m133">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>To simplify this bi-level optimization problem, it can be assumed that the attacker chooses the worst-case attack scenario <inline-formula id="inf112">
<mml:math id="m134">
<mml:mrow>
<mml:msubsup>
<mml:mi>S</mml:mi>
<mml:mi>c</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>, i.e., the attack strategy that maximizes system loss. Under this assumption, the defender&#x2019;s goal is transformed into minimizing system loss under the worst-case attack scenario:<disp-formula id="equ23">
<mml:math id="m135">
<mml:mrow>
<mml:munder>
<mml:mi>min</mml:mi>
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">D</mml:mi>
</mml:mrow>
</mml:munder>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msubsup>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>The defender&#x2019;s optimization process can be solved using standard optimization algorithms (such as linear programming or nonlinear programming). Based on the importance of each relay and its load loss after failure, the defender rationally allocates defense budgets <inline-formula id="inf113">
<mml:math id="m136">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf114">
<mml:math id="m137">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> to ensure system loss is minimized when an attack occurs.</p>
</sec>
<sec id="s3-2-2">
<title>3.2.2 Game strategies under incomplete information</title>
<p>In scenarios with incomplete information, defenders and attackers may not accurately understand each other&#x2019;s full strategies. Therefore, traditional complete information game models fail to accurately reflect real situations. In such cases, randomness and expectation analysis in decision-making become particularly important. Defenders can dynamically adjust their defense strategies based on risk assessments of potential attack targets, while attackers can choose optimal attack paths by inferring the defender&#x2019;s strategy from historical data. To more precisely characterize this uncertainty, a Bayesian game model is introduced in this paper, enabling defenders to make optimal decisions under uncertainty.</p>
<p>The Bayesian game model is used to describe how participants make optimal strategic decisions based on each other&#x2019;s behaviors and type information under incomplete information conditions. In Bayesian games, each participant&#x2019;s type is private information, and other participants can only make strategic decisions based on known type distributions.</p>
<p>Let the attacker&#x2019;s type be <inline-formula id="inf115">
<mml:math id="m138">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the defender&#x2019;s type be <inline-formula id="inf116">
<mml:math id="m139">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, both drawn from their respective type spaces with known distributions. Each participant chooses the optimal strategy based on their observed type and expectations of other participants&#x2019; types. This framework better aligns with real-world power systems, as defenders may not know the attacker&#x2019;s exact targets, and attackers may be unclear about the specific protection strength for certain relays.</p>
<p>The defender&#x2019;s goal is to minimize system loss under incomplete information. Assuming the attacker&#x2019;s attack intensity on each relay depends on their type <inline-formula id="inf117">
<mml:math id="m140">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, the defender allocates defense budgets <inline-formula id="inf118">
<mml:math id="m141">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf119">
<mml:math id="m142">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> according to their type <inline-formula id="inf120">
<mml:math id="m143">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. The defender&#x2019;s loss function can be expressed as:<disp-formula id="equ24">
<mml:math id="m144">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>Under incomplete information, the defender can only estimate expected losses based on the distribution of the attacker&#x2019;s type <inline-formula id="inf121">
<mml:math id="m145">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Thus, the defender&#x2019;s expected loss function is:<disp-formula id="equ25">
<mml:math id="m146">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="double-struck">E</mml:mi>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mo>&#x222b;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:msub>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mi>d</mml:mi>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>This expected loss function considers the loss weights brought by different attacker types <inline-formula id="inf122">
<mml:math id="m147">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and is an important basis for the defender&#x2019;s decision-making.</p>
<p>The attacker&#x2019;s goal is to choose the optimal attack strategy <inline-formula id="inf123">
<mml:math id="m148">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to maximize system loss. Assuming the attacker attacks based on the defender&#x2019;s type <inline-formula id="inf124">
<mml:math id="m149">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and defense strategy <inline-formula id="inf125">
<mml:math id="m150">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, their loss function <inline-formula id="inf126">
<mml:math id="m151">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> is expressed as:<disp-formula id="equ26">
<mml:math id="m152">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">S</mml:mi>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>Under incomplete information, the attacker does not know the defender&#x2019;s exact defense strategy and can only estimate expected losses based on the distribution of the defender&#x2019;s type <inline-formula id="inf127">
<mml:math id="m153">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Therefore, the attacker&#x2019;s expected utility is:<disp-formula id="equ27">
<mml:math id="m154">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="double-struck">E</mml:mi>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mo>&#x222b;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:msub>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mi>P</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mi>d</mml:mi>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>Based on this expected loss, the attacker chooses the optimal attack combination <inline-formula id="inf128">
<mml:math id="m155">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> without knowing the defender&#x2019;s strategy.</p>
<p>In the Bayesian game model, participants make optimal decisions based on their own types and beliefs about other participants&#x2019; types. Defenders and attackers make decisions based on expected losses and utilities, aiming to find the Bayesian Nash Equilibrium. The Bayesian Nash Equilibrium is the optimal strategy combination made by participants after considering all information (including the distribution of the opponent&#x2019;s type and their own type).</p>
<p>The conditions for Bayesian equilibrium can be expressed as:<disp-formula id="equ28">
<mml:math id="m156">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="italic">arg</mml:mi>
<mml:munder>
<mml:mi>min</mml:mi>
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">D</mml:mi>
</mml:mrow>
</mml:munder>
<mml:msub>
<mml:mi mathvariant="double-struck">E</mml:mi>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
<disp-formula id="equ29">
<mml:math id="m157">
<mml:mrow>
<mml:msubsup>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="italic">arg</mml:mi>
<mml:munder>
<mml:mi>max</mml:mi>
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mo>&#x2208;</mml:mo>
<mml:mi mathvariant="script">K</mml:mi>
</mml:mrow>
</mml:munder>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>L</mml:mi>
<mml:mi>A</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>D</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>Under Bayesian equilibrium conditions, the defender&#x2019;s strategy <inline-formula id="inf129">
<mml:math id="m158">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> minimizes expected losses across all possible attack types, while the attacker&#x2019;s strategy <inline-formula id="inf130">
<mml:math id="m159">
<mml:mrow>
<mml:msubsup>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> maximizes expected losses across all possible defense types.</p>
</sec>
<sec id="s3-2-3">
<title>3.2.3 Optimization strategies under complete information game theory</title>
<p>In practical scenarios, complete and incomplete information games are applicable to different situations. For cases where both attackers and defenders have a clear understanding of each other&#x2019;s resources and strategies, the incomplete information game can be simplified to a complete information game. In complete information games, as both parties have consistent knowledge of system parameters, resources, and strategies, uncertainty need not be considered, and the game can be directly transformed into a zero-sum game problem. Next, the simplification of the bi-level optimization problem using the Lagrange multiplier method within the complete information game framework will be explored.</p>
<p>To transform the attacker&#x2019;s budget constraint into a constraint in the defender&#x2019;s optimization process, the Lagrange multiplier &#x3bb;_c is introduced, forming the following Lagrangian function:<disp-formula id="equ30">
<mml:math id="m160">
<mml:mrow>
<mml:mi>L</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3bb;</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mrow>
<mml:mo>&#xb7;</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:msub>
<mml:mi>&#x3bb;</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="|">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mstyle displaystyle="true">
<mml:munder>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:munder>
</mml:mstyle>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</disp-formula>
</p>
<p>This Lagrangian function transforms the bi-level optimization problem into a single-level optimization problem under the attacker&#x2019;s resource constraint <inline-formula id="inf131">
<mml:math id="m161">
<mml:mrow>
<mml:mstyle displaystyle="true">
<mml:msub>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>r</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:msub>
</mml:mstyle>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>C</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. The defender chooses the optimal budget allocation strategy considering all possible attack scenarios <inline-formula id="inf132">
<mml:math id="m162">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="script">S</mml:mi>
<mml:mi>c</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, minimizing system losses in the worst-case scenario. Through this approach, the defender can solve complex game problems through simpler computational methods, enhancing system security and robustness.</p>
<p>In addition to relay setting attacks, the optimization framework could be extended to address other types of cyber threats, including False Data Injection Attacks (FDIA) and Denial of Service (DoS) attacks. FDIA, which manipulates data to mislead system operations, could be integrated into the second layer of the model by adding mechanisms for data validation and anomaly detection. Meanwhile, DoS attacks, which impair communication networks, could be addressed by incorporating network redundancy and prioritizing critical communication channels in the system-level defense budget allocation.</p>
</sec>
</sec>
</sec>
<sec id="s4">
<title>4 Case study</title>
<sec id="s4-1">
<title>4.1 Experimental design</title>
<p>The IEEE 123-node test system is a classic distribution network test system used to study and verify various power system optimization methods and defense strategies. The system comprises 123 nodes, forming a complete distribution network topology, including main substations, lines, loads, and protective relays. Through experiments on this test system, the impact of attack and defense strategies on grid security, stability, and reliability can be evaluated. In practical applications, the assumption that both attackers and defenders act rationally may not always be valid. Attackers might deploy suboptimal or randomized strategies, driven by motivations beyond simply maximizing system disruption. To mitigate this, integrating probabilistic elements into the defense strategy could further strengthen the system&#x2019;s resilience. By allowing the defense model to account for random or suboptimal attacker behaviors, the overall effectiveness of the system&#x2019;s defense mechanism can be improved under unpredictable attack conditions.</p>
<p>The primary objectives of the experimental design are to evaluate the effectiveness of various defense budget allocation strategies and their ability to reduce EENS during ARSA and PRSA. Specifically, the experiments aim to quantify the reduction in system losses as a result of different budget allocations, and analyze the system&#x2019;s resilience under both single-relay and multi-relay attack scenarios.</p>
<p>The experimental design is based on several key assumptions. First, it is assumed that critical relays, such as those near substations, are more vulnerable to attacks and thus require higher priority for defense budget allocation. Second, the experiments assume a limited total defense budget, which must be optimally allocated between device-level and system-level defenses. Finally, it is assumed that attackers are rational and aim to maximize system loss by selecting optimal attack combinations, while defenders aim to minimize these losses through strategic budget allocation.</p>
<p>
<xref ref-type="fig" rid="F1">Figure 1</xref> shows the single-line diagram of the IEEE 123-node test system. The system serves 85 concentrated loads with a total active load of 3,490 kW (kW). Circuit breakers and reclosers are configured at critical nodes to protect the main substation and its branch lines. Each relay provides protection for specific line segments and serves as a backup protection device for other relays. When certain relays fail, others can take over their protective tasks, ensuring system continuity and reliability.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption>
<p>IEEE 123-node test feeder.</p>
</caption>
<graphic xlink:href="fenrg-12-1502078-g001.tif"/>
</fig>
<p>To enhance the experiment&#x2019;s realism, seven protective relays were added to line segments (13&#x2013;18), (13&#x2013;52), (18&#x2013;135), (67&#x2013;97), (67&#x2013;72), and (76&#x2013;86). These relays&#x2019; settings consider differences in line load, distance, and conditions to ensure timely fault isolation at critical nodes when attacked. The failure of each relay may lead to load interruption, making rational defense budget allocation the core of the experimental design. The experiment assumes that relay R1 is located at the main substation and has undergone initial reinforcement measures, with its failure probability approaching zero, denoted as <inline-formula id="inf133">
<mml:math id="m163">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c1;</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
<mml:mo>&#x2248;</mml:mo>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>. Other relays have no initial reinforcement measures and have higher failure probabilities.</p>
<p>To optimize budget allocation, the experiment also assumes the installation of an attack identification system. This system can accelerate system recovery after an attack. The budget required for the system is set at 30 (<inline-formula id="inf134">
<mml:math id="m164">
<mml:mrow>
<mml:msup>
<mml:mi>D</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>30</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>), reducing the system recovery time from an initial 5 h (<inline-formula id="inf135">
<mml:math id="m165">
<mml:mrow>
<mml:msup>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msup>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>5</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>) to 3 h (<inline-formula id="inf136">
<mml:math id="m166">
<mml:mrow>
<mml:mo>&#x2206;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mi>R</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>). The installation of the attack identification system can significantly reduce power supply restoration time. Attacks are divided into ARSA and PRSA. ARSA directly modifies relay settings to trip under normal working conditions, while PRSA delays relay response time during fault conditions, expanding the system&#x2019;s fault impact range.</p>
<p>Defense budget allocation must consider the importance of relays in the system. Relays at the system&#x2019;s core, such as those near the main substation, will receive priority for more defense budget. The successful attack probability <inline-formula id="inf137">
<mml:math id="m167">
<mml:mrow>
<mml:msubsup>
<mml:mi>&#x3c1;</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>d</mml:mi>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> for these relays can be reduced to near 0 through reinforcement measures. For relays in secondary system areas, basic protection is provided, and their successful attack probability may remain at a higher level. This experimental design ensures a comprehensive evaluation of attack and defense strategies. System performance under attack is assessed through experimental results under different defense configurations.</p>
</sec>
<sec id="s4-2">
<title>4.2 Results analysis</title>
<p>This section explores the impact of two types of attacks on system performance through the analysis of single-relay and multi-relay attack scenarios. The experiments were based on the IEEE 123-node test system, combining different budget allocation strategies to evaluate the changes in EENS under various attack scenarios, thereby optimizing the defense budget allocation strategy.</p>
<sec id="s4-2-1">
<title>4.2.1 Single-relay attack</title>
<p>In the experiments, the performance changes of individual relays under attack were first analyzed. By comparing the performance of various relays under ARSA and PRSA, the differences in the impact of different attacks on system load loss were determined.</p>
<p>
<xref ref-type="fig" rid="F2">Figure 2</xref> shows the Load Loss (LL) for each relay under ARSA and PRSA with no defense measures. The figure reveals that PRSA causes significantly higher load losses for relays R2, R5, R6, and R7 compared to ARSA. For instance, PRSA attacks on R2 result in load losses approaching 2.2MW, while ARSA losses are about 1.2 MW. This indicates that R2 is more significantly affected under PRSA attacks, especially when this relay is upstream, where PRSA can easily cause more widespread cascading outages. For relay R3, the situation is reversed, with ARSA causing greater load losses than PRSA, mainly because R3 is downstream and its load is more directly affected by ARSA.</p>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption>
<p>Comparison between ARSA and PRSA under different relay protection devices.</p>
</caption>
<graphic xlink:href="fenrg-12-1502078-g002.tif"/>
</fig>
<p>The experimental results reveal differences in the vulnerability of single relays under different attack types, with PRSA being more destructive to the system. Therefore, system protection strategies should allocate different defense resources based on the importance of different relays, with priority measures taken for critical relays such as R2 and R5 to reduce their vulnerability under PRSA.</p>
</sec>
<sec id="s4-2-2">
<title>4.2.2 Multi-relay attack</title>
<p>In addition to single-relay attacks, multi-relay simultaneous attacks were simulated to analyze their impact on system EENS. Three groups of relays were selected for simultaneous attacks, comparing the destructive power of ARSA and PRSA in these scenarios.</p>
<p>
<xref ref-type="fig" rid="F3">Figure 3</xref> illustrates the maximum EENS changes when one, two, or three relays are simultaneously attacked. The results indicate that in multi-relay attack scenarios, PRSA&#x2019;s destructive power significantly exceeds that of ARSA. For instance, when R3, R6, and R7 are simultaneously subjected to PRSA attacks, the EENS reaches 17 MWh, while the same relay combination under ARSA attacks only results in an EENS of 16 MWh. Particularly in the combined attack on R2, R3, and R5, the load loss caused by PRSA nearly reaches the system&#x2019;s maximum limit, reflecting the high risk of multi-relay PRSA attacks to the system.</p>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption>
<p>Comparison of maximum EENS under different attack scales for ARSA and PRSA methods.</p>
</caption>
<graphic xlink:href="fenrg-12-1502078-g003.tif"/>
</fig>
<p>The experimental results demonstrate that under multi-relay attacks, PRSA is often more destructive than ARSA, especially when multiple critical relays are simultaneously attacked. The chain reaction caused by PRSA may lead to global power supply interruptions. Therefore, when formulating defense strategies, the system should adequately respond to the special effects of PRSA, ensuring high system stability even when multiple relays are simultaneously attacked.</p>
</sec>
<sec id="s4-2-3">
<title>4.2.3 Optimization effect of budget allocation strategies</title>
<p>To further enhance the system&#x2019;s attack resistance, the performance of optimal and non-optimal budget allocation strategies under different attack scenarios was evaluated through experiments. The results indicate that rational budget allocation strategies can significantly reduce EENS and improve the system&#x2019;s defense effectiveness.<list list-type="simple">
<list-item>
<p>(1) Comparison of Optimal and Non-optimal Allocation Strategies</p>
</list-item>
</list>
</p>
<p>
<xref ref-type="fig" rid="F4">Figure 4</xref> compares the impact of ARSA and PRSA on system EENS under different budget allocation strategies. The figure shows EENS changes under three different budget allocation strategies. The red solid line represents the optimal allocation strategy considering both ARSA and PRSA. As the budget increases, EENS gradually decreases. When the budget reaches 30, the EENS reduction is most significant, indicating that the system&#x2019;s defense effect reaches its optimal state at this point. As the budget further increases, EENS changes become more gradual, indicating that the system&#x2019;s overall recovery capability is significantly improved under higher budgets. The blue dashed line represents the defense strategy considering only ARSA. Under higher budgets, this strategy shows good control over system EENS, but at lower budgets, EENS exhibits higher values, especially when the budget approaches 30, where the defense effect is clearly inferior to the optimal allocation strategy. When only ARSA is considered, the system shows greater vulnerability to PRSA attacks and cannot effectively reduce EENS. The green dashed line represents the defense strategy considering only PRSA. This strategy performs excellently at lower budgets, with a large decrease in EENS, but as the budget increases, its defense effect gradually approaches that of the optimal allocation strategy. In terms of overall defense effectiveness, it is still slightly inferior to the optimal strategy considering both ARSA and PRSA. When the budget reaches higher values, the PRSA strategy cannot achieve the optimal defense effect.<list list-type="simple">
<list-item>
<p>(2) Optimization Direction of Defense Strategies</p>
</list-item>
</list>
</p>
<fig id="F4" position="float">
<label>FIGURE 4</label>
<caption>
<p>Comparison of EENS variations with budget changes under different strategies.</p>
</caption>
<graphic xlink:href="fenrg-12-1502078-g004.tif"/>
</fig>
<p>
<xref ref-type="fig" rid="F5">Figure 5</xref> illustrates the resource allocation proportions for various systems and relays under different budget levels. The vertical axis represents the budget allocation percentage for each defense measure, ranging from 0% to 100%. The horizontal axis represents budget size, varying from 50 to 500 units. Different colored areas correspond to relays and systems, showing their dynamic allocation proportions in the total budget as the budget changes.</p>
<fig id="F5" position="float">
<label>FIGURE 5</label>
<caption>
<p>Resource allocation trends at different budget levels.</p>
</caption>
<graphic xlink:href="fenrg-12-1502078-g005.tif"/>
</fig>
<p>At low budgets, the attack identification system (<inline-formula id="inf138">
<mml:math id="m168">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>) occupies the majority of the allocation proportion. As the budget increases, the proportion of <inline-formula id="inf139">
<mml:math id="m169">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> gradually decreases. This trend reflects that under limited resources, defense strategies focus more on ensuring basic attack identification capabilities. However, as the budget increases, the resources required for <inline-formula id="inf140">
<mml:math id="m170">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>t</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> gradually decrease, shifting the focus of resource allocation.</p>
<p>Concurrently, the allocation proportion for system-wide defense measures (<inline-formula id="inf141">
<mml:math id="m171">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula>) significantly increases with budget growth. At low budgets, <inline-formula id="inf142">
<mml:math id="m172">
<mml:mrow>
<mml:msup>
<mml:mi>d</mml:mi>
<mml:mi>s</mml:mi>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> receives almost no resource allocation, but as the budget increases, its proportion gradually expands, eventually becoming the main object of resource allocation in high-budget situations. This indicates a gradual shift in defense strategy from single-point protection to comprehensive system protection to improve overall defense levels.</p>
<p>Critical relays such as <inline-formula id="inf143">
<mml:math id="m173">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf144">
<mml:math id="m174">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf145">
<mml:math id="m175">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>5</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> maintain relatively stable allocation proportions across the entire budget range. Regardless of budget increases, these relays consistently receive certain resources, reflecting their continued importance in system security. In contrast, <inline-formula id="inf146">
<mml:math id="m176">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf147">
<mml:math id="m177">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>6</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf148">
<mml:math id="m178">
<mml:mrow>
<mml:msub>
<mml:mi>d</mml:mi>
<mml:mn>7</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> have smaller resource allocation proportions but receive some resources as the budget increases, reflecting further expansion of system defense at higher budgets.</p>
<p>To further assess the robustness of the proposed defense model, a sensitivity analysis was conducted to explore the effects of varying budget levels and allocation strategies on system resilience. Three different budget scenarios were considered: low-budget, medium-budget, and high-budget. The sensitivity analysis revealed that while higher budgets naturally lead to improved resilience and lower EENS, the allocation strategy plays a critical role in maximizing the effectiveness of the defense. Under low-budget conditions, focusing resources on critical relays such as those near the main substation resulted in significant reductions in EENS, while in higher-budget scenarios, more resources could be distributed across secondary relays, further improving system resilience.</p>
<p>The three-layer optimization defense model offers practical applicability in various power system environments, especially those facing resource constraints. By dynamically allocating the defense budget across device-level and system-level protections, the model ensures that critical relays receive priority in budget allocation, while also addressing system-wide security measures. This adaptability allows the model to be deployed in real-world scenarios, where resource availability may fluctuate. Additionally, the model can be easily integrated with existing power system security frameworks due to its modular nature.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<title>5 Conclusions and prospects</title>
<p>This research proposes a three-layer optimization model based on game theory framework for defending against relay setting attacks in power systems. By considering two types of attacks, ARSA and PRSA, the allocation of defense budgets is optimized to minimize expected energy losses under different attack scenarios. The study utilizes zero-sum game theory concepts to establish a strategy interaction model between defenders and attackers, further verifying the effectiveness of this defense strategy in the IEEE 123-node test system through experiments.</p>
<p>Through theoretical derivation and simulation experiments, the following conclusions are drawn:<list list-type="simple">
<list-item>
<p>(1) Rational allocation of defense budgets can effectively reduce expected energy losses when the system is subjected to relay setting attacks.</p>
</list-item>
<list-item>
<p>(2) Active and passive attacks have significantly different impacts on relays, especially in scenarios where multiple relays are simultaneously attacked, with PRSA being more destructive.</p>
</list-item>
<list-item>
<p>(3) Experiments show that in low-budget situations, device-specific defense measures contribute more to system security, while in high-budget situations, system-wide defense measures become more important.</p>
</list-item>
</list>
</p>
<p>This research primarily focuses on defending against relay setting attacks, specifically ARSA and PRSA. However, other types of cyberattacks, such as FDIA and DoS attacks, are also prevalent in power systems. The current model does not directly address these attack vectors. Future extensions of this work could adapt the three-layer optimization model to cover a broader range of cyber threats by integrating defense mechanisms against FDIA and DoS attacks, which target different system vulnerabilities such as data integrity and network availability.</p>
</sec>
</body>
<back>
<sec sec-type="data-availability" id="s6">
<title>Data availability statement</title>
<p>The original contributions presented in the study are included in the article/supplementary material, further inquiries can be directed to the corresponding author.</p>
</sec>
<sec sec-type="author-contributions" id="s7">
<title>Author contributions</title>
<p>LR: Writing&#x2013;review and editing, Writing&#x2013;original draft, Supervision, Methodology, Conceptualization. YB: Writing&#x2013;review and editing, Funding acquisition, Data curation. GH: Writing&#x2013;review and editing, Project administration, Methodology. LJ: Writing&#x2013;review and editing, Visualization, Formal Analysis. ZY: Writing&#x2013;review and editing, Formal Analysis, Data curation. FY: Writing&#x2013;review and editing, Resources, Investigation. TL: Writing&#x2013;review and editing, Visualization, Resources. ZZ: Writing&#x2013;review and editing, Validation, Resources.</p>
</sec>
<sec sec-type="funding-information" id="s8">
<title>Funding</title>
<p>The author(s) declare that financial support was received for the research, authorship, and/or publication of this article. Research supported by the science and technology project of Guizhou Power Grid Company (GZKJXM20222346).</p>
</sec>
<sec sec-type="COI-statement" id="s9">
<title>Conflict of interest</title>
<p>Authors YB, LJ, FY, and ZZ were employed by Information Centre of Guizhou Power Grid Co. Authors LR, GH, ZY, and TL Were employed by China Southern Power Grid. Authors LR, GH, ZY, and TL Were employed by China Southern Power Grid.</p>
<p>The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
<p>The authors declare that this study received funding from Guizhou Power Grid Company. The funder had the following involvement in the study: Data curation, Formal analysis, Visualization, Resources, Investigation, Validation, and Writingâreview and editing.</p>
</sec>
<sec sec-type="ai-statement" id="s11">
<title>Generative AI statement</title>
<p>The author(s) declare that no Generative AI was used in the creation of this manuscript.</p>
</sec>
<sec sec-type="disclaimer" id="s10">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Abdelkader</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Amissah</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Kinga</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Mugerwa</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Emmanuel</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Mansour</surname>
<given-names>D.-E. A.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Securing modern power systems: implementing comprehensive strategies to enhance resilience and reliability against cyber-attacks</article-title>. <source>Results Eng.</source> <volume>23</volume>, <fpage>102647</fpage>. <pub-id pub-id-type="doi">10.1016/j.rineng.2024.102647</pub-id>
</citation>
</ref>
<ref id="B2">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Abraham</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Toftegaard</surname>
<given-names>&#xd8;.</given-names>
</name>
<name>
<surname>Dr</surname>
<given-names>B. B. J.</given-names>
</name>
<name>
<surname>Gebremedhin</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Yayilgan</surname>
<given-names>S. Y.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Consequence simulation of cyber attacks on key smart grid business cases</article-title>. <source>Front. Energy Res.</source> <volume>12</volume>, <fpage>1395954</fpage>. <pub-id pub-id-type="doi">10.3389/fenrg.2024.1395954</pub-id>
</citation>
</ref>
<ref id="B3">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Altaf</surname>
<given-names>M. W.</given-names>
</name>
<name>
<surname>Arif</surname>
<given-names>M. T.</given-names>
</name>
<name>
<surname>Islam</surname>
<given-names>S. N.</given-names>
</name>
<name>
<surname>Haque</surname>
<given-names>Md E.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Microgrid protection challenges and mitigation approaches&#x2013;A comprehensive review</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>38895</fpage>&#x2013;<lpage>38922</lpage>. <pub-id pub-id-type="doi">10.1109/access.2022.3165011</pub-id>
</citation>
</ref>
<ref id="B4">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ameli</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Ali</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>El-Saadany</surname>
<given-names>E. F.</given-names>
</name>
<name>
<surname>Youssef</surname>
<given-names>A. M.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>An intrusion detection method for line current differential relays</article-title>. <source>IEEE Trans. Inf. Forensics Secur.</source> <volume>15</volume>, <fpage>329</fpage>&#x2013;<lpage>344</lpage>. <pub-id pub-id-type="doi">10.1109/TIFS.2019.2916331</pub-id>
</citation>
</ref>
<ref id="B5">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Amin</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>El-Sousy</surname>
<given-names>F. F. M.</given-names>
</name>
<name>
<surname>Aziz</surname>
<given-names>G. A. A.</given-names>
</name>
<name>
<surname>Gaber</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Mohammed</surname>
<given-names>O. A.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>CPS attacks mitigation approaches on power electronic systems with security challenges for smart grid applications: a review</article-title>. <source>Ieee Access</source> <volume>9</volume>, <fpage>38571</fpage>&#x2013;<lpage>38601</lpage>. <pub-id pub-id-type="doi">10.1109/access.2021.3063229</pub-id>
</citation>
</ref>
<ref id="B6">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Elgazzar</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Khalil</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Alghamdi</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Ahmed</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Abdelkader</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Elewah</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2022</year>). <article-title>Revisiting the internet of things: new trends, opportunities and grand challenges</article-title>. <source>Front. Media SA</source> <volume>1</volume>. <pub-id pub-id-type="doi">10.3389/friot.2022.1073780</pub-id>
</citation>
</ref>
<ref id="B7">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ganjkhani</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Mehdi Hosseini</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Parvania</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Optimal defensive strategy for power distribution systems against relay setting attacks</article-title>. <source>IEEE Trans. Power Deliv.</source> <volume>38</volume> (<issue>3</issue>), <fpage>1499</fpage>&#x2013;<lpage>1509</lpage>. <pub-id pub-id-type="doi">10.1109/tpwrd.2022.3230946</pub-id>
</citation>
</ref>
<ref id="B8">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ghiasi</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Niknam</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Mehrandezh</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Dehghani</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Ghadimi</surname>
<given-names>N.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>A comprehensive review of cyber-attacks and defense mechanisms for improving security in smart grid energy systems: past, present and future</article-title>. <source>Electr. Power Syst. Res.</source> <volume>215</volume>, <fpage>108975</fpage>. <pub-id pub-id-type="doi">10.1016/j.epsr.2022.108975</pub-id>
</citation>
</ref>
<ref id="B9">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hasan</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Dubey</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Karsai</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Koutsoukos</surname>
<given-names>X.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A game-theoretic approach for power systems defense against dynamic cyber-attacks</article-title>. <source>Int. J. Electr. Power and Energy Syst.</source> <volume>115</volume>, <fpage>105432</fpage>. <pub-id pub-id-type="doi">10.1016/j.ijepes.2019.105432</pub-id>
</citation>
</ref>
<ref id="B10">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kabeyi</surname>
<given-names>M. J. B.</given-names>
</name>
<name>
<surname>Olanrewaju</surname>
<given-names>O. A.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Sustainable energy transition for renewable and low carbon grid electricity generation and supply</article-title>. <source>Front. Energy Res.</source> <volume>9</volume>, <fpage>743114</fpage>. <pub-id pub-id-type="doi">10.3389/fenrg.2021.743114</pub-id>
</citation>
</ref>
<ref id="B11">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kampourakis</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Gkioulos</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Katsikas</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>A systematic literature review on wireless security testbeds in the cyber-physical realm</article-title>. <source>Comput. and Secur.</source> <volume>133</volume>, <fpage>103383</fpage>. <pub-id pub-id-type="doi">10.1016/j.cose.2023.103383</pub-id>
</citation>
</ref>
<ref id="B12">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Khaw</surname>
<given-names>Y. M.</given-names>
</name>
<name>
<surname>Abiri Jahromi</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Arani</surname>
<given-names>M. F. M.</given-names>
</name>
<name>
<surname>Sanner</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Kundur</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Kassouf</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A deep learning-based cyberattack detection system for transmission protective relays</article-title>. <source>IEEE Trans. Smart Grid</source> <volume>12</volume> (<issue>3</issue>), <fpage>2554</fpage>&#x2013;<lpage>2565</lpage>. <pub-id pub-id-type="doi">10.1109/tsg.2020.3040361</pub-id>
</citation>
</ref>
<ref id="B13">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lau</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Wei</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Ten</surname>
<given-names>C.-W.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A cybersecurity insurance model for power system reliability considering optimal defense resource allocation</article-title>. <source>IEEE Trans. Smart Grid</source> <volume>11</volume> (<issue>5</issue>), <fpage>4403</fpage>&#x2013;<lpage>4414</lpage>. <pub-id pub-id-type="doi">10.1109/tsg.2020.2992782</pub-id>
</citation>
</ref>
<ref id="B14">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Li</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Zhao</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Chang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Yang</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>A dual-head output network attack detection and classification approach for multi-energy systems</article-title>. <source>Front. Energy Res.</source> <volume>12</volume>, <fpage>1367199</fpage>. <pub-id pub-id-type="doi">10.3389/fenrg.2024.1367199</pub-id>
</citation>
</ref>
<ref id="B15">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Macwan</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Drew</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Panumpabi</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Valdes</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Vaidya</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Sauer</surname>
<given-names>P.</given-names>
</name>
<etal/>
</person-group> (<year>2016</year>). <article-title>Collaborative defense against data injection attack in IEC61850 based smart substations</article-title>. <source>IEEE Power Energy Soc. General Meet. (PESGM)</source>, <fpage>1</fpage>&#x2013;<lpage>5</lpage>. <pub-id pub-id-type="doi">10.1109/pesgm.2016.7741376</pub-id>
</citation>
</ref>
<ref id="B16">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Mohamed</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Magdy</surname>
<given-names>M. A. S.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Data mining-based cyber-physical attack detection tool for attack-resilient adaptive protective relays</article-title>. <source>Energies</source> <volume>15</volume> (<issue>12</issue>), <fpage>4328</fpage>. <pub-id pub-id-type="doi">10.3390/en15124328</pub-id>
</citation>
</ref>
<ref id="B17">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Rajkumar</surname>
<given-names>V. S.</given-names>
</name>
<name>
<surname>Tealane</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>&#x15e;tefanov</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Palensky</surname>
<given-names>P.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Cyber attacks on protective relays in digital substations and impact analysis</article-title>. <source>2020 8th Workshop Model. Simul. Cyber-Physical Energy Syst.</source>, <fpage>1</fpage>&#x2013;<lpage>6</lpage>. <pub-id pub-id-type="doi">10.1109/mscpes49613.2020.9133698</pub-id>
</citation>
</ref>
<ref id="B18">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Reda</surname>
<given-names>H. T.</given-names>
</name>
<name>
<surname>Anwar</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Mahmood</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Comprehensive survey and taxonomies of false data injection attacks in smart grids: attack models, targets, and impacts</article-title>. <source>Renew. Sustain. Energy Rev.</source> <volume>163</volume>, <fpage>112423</fpage>. <pub-id pub-id-type="doi">10.1016/j.rser.2022.112423</pub-id>
</citation>
</ref>
<ref id="B19">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Shan</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Gene</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Zhuang</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A game-theoretic approach to modeling attacks and defenses of smart grids at three levels</article-title>. <source>Reliab. Eng. and Syst. Saf.</source> <volume>195</volume>, <fpage>106683</fpage>. <pub-id pub-id-type="doi">10.1016/j.ress.2019.106683</pub-id>
</citation>
</ref>
<ref id="B20">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Trevizan</surname>
<given-names>R. D.</given-names>
</name>
<name>
<surname>Obert</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>De Angelis</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>Nguyen</surname>
<given-names>Tu A.</given-names>
</name>
<name>
<surname>Rao</surname>
<given-names>V. S.</given-names>
</name>
<name>
<surname>Chalamala</surname>
<given-names>B. R.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Cyberphysical security of grid battery energy storage systems</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>59675</fpage>&#x2013;<lpage>59722</lpage>. <pub-id pub-id-type="doi">10.1109/access.2022.3178987</pub-id>
</citation>
</ref>
<ref id="B21">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Vahidi</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Ghafouri</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Au</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Kassouf</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Mohammadi</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Debbabi</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Security of wide-area monitoring, protection, and control (WAMPAC) systems of the smart grid: a survey on challenges and opportunities</article-title>. <source>IEEE Commun. Surv. and Tutorials</source> <volume>25</volume> (<issue>2</issue>), <fpage>1294</fpage>&#x2013;<lpage>1335</lpage>. <pub-id pub-id-type="doi">10.1109/comst.2023.3251899</pub-id>
</citation>
</ref>
<ref id="B22">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Bi</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Mao</surname>
<given-names>W.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Indirect coordinated attack against relay via load-side power electronics and its defense strategy</article-title>. <source>IEEE Trans. Industrial Inf.</source> <volume>20</volume>, <fpage>5112</fpage>&#x2013;<lpage>5124</lpage>. <pub-id pub-id-type="doi">10.1109/tii.2023.3330307</pub-id>
</citation>
</ref>
<ref id="B23">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>Qi</given-names>
</name>
<name>
<surname>Cai</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Tang</surname>
<given-names>Yi</given-names>
</name>
<name>
<surname>Ni</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Methods of cyber-attack identification for power systems based on bilateral cyber-physical information</article-title>. <source>Int. J. Electr. Power and Energy Syst.</source> <volume>125</volume>, <fpage>106515</fpage>. <pub-id pub-id-type="doi">10.1016/j.ijepes.2020.106515</pub-id>
</citation>
</ref>
<ref id="B24">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>X.</given-names>
</name>
<name>
<surname>Ji</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Sun</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Jing</surname>
<given-names>Z.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Improving cyber-physical-power system stability through hardware-in-loop co-simulation platform for real-time cyber attack analysis</article-title>. <source>Front. Energy Res.</source> <volume>12</volume>, <fpage>1402566</fpage>. <pub-id pub-id-type="doi">10.3389/fenrg.2024.1402566</pub-id>
</citation>
</ref>
<ref id="B25">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wlazlo</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Sahu</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Mao</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Goulart</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Davis</surname>
<given-names>K.</given-names>
</name>
<etal/>
</person-group> (<year>2021</year>). <article-title>Man-in-the-middle attacks and defence in a power system cyber-physical testbed</article-title>. <source>IET Cyber-Physical Syst. Theory and Appl.</source> <volume>6</volume> (<issue>3</issue>), <fpage>164</fpage>&#x2013;<lpage>177</lpage>. <pub-id pub-id-type="doi">10.1049/cps2.12014</pub-id>
</citation>
</ref>
<ref id="B26">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Yohanandhan</surname>
<given-names>R. V.</given-names>
</name>
<name>
<surname>Madurai Elavarasan</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Manoharan</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Mihet-Popa</surname>
<given-names>L.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Cyber-physical power system (CPPS): a review on modeling, simulation, and analysis with cyber security applications</article-title>. <source>IEEE Access</source> <volume>8</volume>, <fpage>151019</fpage>&#x2013;<lpage>151064</lpage>. <pub-id pub-id-type="doi">10.1109/access.2020.3016826</pub-id>
</citation>
</ref>
<ref id="B27">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Yu</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Wen</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Ding</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Zhou</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Reinforcement learning solution for cyber-physical systems security against replay attacks</article-title>. <source>IEEE Trans. Inf. Forensics Secur.</source> <volume>18</volume>, <fpage>2583</fpage>&#x2013;<lpage>2595</lpage>. <pub-id pub-id-type="doi">10.1109/tifs.2023.3268532</pub-id>
</citation>
</ref>
<ref id="B28">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Dong</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>Cyber attacks on remote relays in smart grid</article-title>. <source>2017 IEEE Conf. Commun. Netw. Secur. (CNS)</source>. <pub-id pub-id-type="doi">10.1109/CNS.2017.8228637</pub-id>
</citation>
</ref>
<ref id="B29">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhou</surname>
<given-names>T. L.</given-names>
</name>
<name>
<surname>Xiahou</surname>
<given-names>K. S.</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>L. L.</given-names>
</name>
<name>
<surname>Wu</surname>
<given-names>Q. H.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Multi-agent-based hierarchical detection and mitigation of cyber attacks in power systems</article-title>. <source>Int. J. Electr. Power and Energy Syst.</source> <volume>125</volume>, <fpage>106516</fpage>. <pub-id pub-id-type="doi">10.1016/j.ijepes.2020.106516</pub-id>
</citation>
</ref>
</ref-list>
</back>
</article>