Resilient Event-Triggered Control for LFC-VSG Scheme of Uncertain Discrete-Time Power System under DoS Attacks †

: This paper is concerned with resilient triggered control problem for load frequency control and virtual synchronous generation (LFC-VSG) scheme of discrete-time multi-area power system with parameter uncertainty, governor dead band (GDB), and low inertia under time delay and aperiodic Denial-of-Service (DoS) attacks. To reduce communication load of sleep intervals, event triggered mechanism (ETM) is introduced. A discrete-time switched delay system model is established to describe the dynamic of multi-area power system under resilient static output feedback control law. Combining piecewise Lyapunov–Krasovskii functional (LKF) method with switched system theory, a criterion is derived that the tolerant bound of attack duration and attack frequency can be estimated explicitly. Meanwhile, some sufﬁcient conditions are obtained which can preserve weighted H ∞ performance. By using linear matrix inequalities (LMIs) techniques, a co-design method is proposed to solve the control gains and trigger parameters. A simulation example of a two-area power system was carried out to verify the efﬁciency of our proposed resilient event based LFC-VSG scheme.

components, leading to the missing of transmission packets in times [12], even driving system operation out of stable region. False data injection attacks inject illegal error data into communication network to pollute measurements and demands [13]. In other words, the damage on availability and integrity of information caused by network attack leads to the performance degradation of networked power system [14][15][16][17]. Thus, it is urgent to study secure control scheme to keep frequency performance resilience against DoS attacks or false data injection attacks.

Related Work
Recently, many interesting works have researched secure control problem of networked system under DoS attacks. On the one hand, for continuous-time system, a communication regulation strategy has been presented to obtain input-to-state stability (ISS) under DoS attacks modeled by average dwell time concept [18]. However, this study, based on the Lyapunov function method, cannot provide the design method of resilient control gain. By using LKF method, a resilient event-triggered mechanism and PI based control scheme were jointly designed for LFC system under DoS attacks modeled by maximum number of successive packet loss [19]. Compared with average dwell time (ADT) model [18], the attack characteristics studied in [19] have not been fully explored. For periodic DoS jamming attacks, a resilient synthesis method of event-based feedback control has been presented; a joint design method to solve parameters of event trigger and controller has been proposed by employing piecewise Lyapunov-Krasovskii functional method and switched system method [20,21]. Further, motivated by the above method, delay bound based attack detection and resilient LFC scheme have been proposed for multi-area power system under ADT model based DoS attacks [22]. On the other hand, for discrete-time stochastic system, the event-based security control problem has been studied by using stochastic analysis method to achieve mean-square security under random DoS attacks [23]. To defend against the DoS attack, a compensation mechanism cooperating with attack detection has been proposed to preserve system stochastically stable [24]. Besides, stability analysis and resilient control design under DoS attacks modeled by Markov process has been investigated using Lyapunov theory [25]. For discrete-time deterministic system, the maximum tolerable number of DoS attacks has been obtained by using Lyapunov functional method [26]. However, this paper is only concerned with the duration of DoS attack but neglects the attack frequency. It is well known that high attack frequency would also cause system instability.

Our Contributions
To the best of our knowledge, secure control design for discrete-time deterministic power system under DoS attacks has never been considered. Thus, to fill this research gap, our published work studies resilient event triggered control of uncertain discrete-time system under DoS attacks [27]. In this paper, we apply the earlier work [27] to the design of resilient LFC-VSG scheme of multi-area power system under DoS attacks. First, a discrete-time power system model is established with nonlinear dynamic governor dead band (GDB), low inertia, and parameter uncertainty under RESs disturbances. The combined control scheme consisting of load frequency control and virtual synchronous generation (LFC-VSG) is adopted and formulated as static feedback control law. Second, a DoS attack model is represented by an average dwell time (ADT) model to constrain the attack frequency and duration. Considered the mixed communication influence of DoS attacks, time delay, and event-triggered mechanism, a discrete-time switched delay system is established to describe the dynamic of power system and a weighted H ∞ control problem is formulated for the frequency control of the considered power system. Piecewise Lyapunov-Krasovskii functional method and switched system method are employed to analyze the weighted H ∞ performance. A criterion about the tolerable delay bound and attack frequency and duration is obtained. Then, a co-design method for event triggered mechanism and resilient control gain is presented based on linear matrix inequalities techniques. In this paper, the main contributions can be summarized as followings: (1) Compared with our early work [27] considering resilient LFC design of discrete-time power system as a simulation example, this paper proposes a design method for resilient LFC-VSG scheme of discrete-time power system with more situations including GDB, low inertia, and uncertainty.
(2) A discrete-time switched delay system model is established to describe the frequency dynamic of multi-area power system with LFC-VSG scheme under DoS attacks.
(3) A new criterion of tolerable delay and DoS attacks in discrete-time form is derived, which is different from the one in continuous-time form.
(4) A co-design method for event-based LFC-VSG scheme is presented by employing piecewise Lyapunov-Krasovskii functional method and average dwell time approach to achieve weighted H ∞ performance.

Discrete-Time Model of Multi-Area Power System with GDB and Uncertainty under LFC-VSG Scheme
To illustrate interconnected multi-area power system with the uniform structure, Figure 1 shows the diagram of the ith area power system with RESs disturbances under LFC-VSG scheme [28] as shown in Figure 2. With Table 1, the system dynamic of the ith area power system is represented by  Figure 1. The ith area power system with event-triggered mechanism based LFC-VSG scheme.  Governor dead band (GDB) [29]: The governor dead-band nonlinearity leads to sustained sinusoidal oscillation of natural period of about T 0 = 2s, namely asin(2π f 0 t). By Fourier transformation with neglecting higher order term, the transfer function of governor with nonlinearity is represented by 0.8 − 0.2/πs 1 + sT gi .

Speed Droop Coefficient Uncertainty [30]:
The parameter uncertainty of power system referring to the speed droop coefficient R i is considered here. The uncertainty of speed droop coefficient is represented by (1 + (t))R i , where 0 ≤ (t) ≤ 1.
Then, the ith area power system can be formed by a continuous-time system model where Combining load frequency control (LFC) scheme and virtual synchronous generation (VSG) scheme ( Figure 2), a static output feedback control law is adopted for the ith area power system where The ith area power system can be represented by a discrete-time system model where Based on the ith area power system model in Equation (4), a linear discrete-time model is established for a n-area power system with parameter uncertainty. where The argument form of control law can be rewritten as where

Discrete-Time Power System under DoS Attacks and Event-Triggered Mechanism
DoS attacks launch in feedback channel to prevent measurements y(k) arriving at control center. Here, a class of aperiodic DoS attacks is considered. Define sleep intervals I 1,n = [g n , g n + b n [ and attack intervals I 2,n = [g n + b n , g n+1 [. Then, DoS attacks can be represented by a switched signal.
where the on/off instant g n , n ∈ N represents the (n − 1)th ending time of DoS attacks with g 0 = 0, while the off/on instant g n + b n ∈ N represents the nth beginning time of DoS attacks.
Denote the sum number of off/on instants as attack frequency N(k, k 0 ) during [k 0 , k] and attack duration Ξ(k, k 0 ) during [k 0 , k]. Then, the upper bound of attack frequency and duration is constrained by where κ ∈ R ≥0 , τ D ∈ R >0 and η ∈ R ≥0 , T α ∈ R >1 During sleep intervals I 1,n , the feedback channel recovers normal communication. Besides of network induced delay, the processing of the composite feedback signal y(k) consisting of ∆ f ,∆ f , ACE, and ACE would increase the computation load and waste much time to influence the real time control. To reduce the computation and communication load, event triggered mechanism is embedded in PMU nodes, which decides whether to send the measurements y(k). where , Ω c2 , · · · , Ω cn ] > 0. Note that, for discrete-time system, the minimum triggered interval is sample periodic h so that it avoids Zeno behavior. Introduce the transmission delay d(k n,m ) for the triggered signal Further, the sleep interval can be divided by where the triggered interval Φ n,m is specified by with k n,0 + d(k n,0 ) = g n and k n,m(n) + d(k n,m(n) ) = g n + b n .
Further, the triggered interval can be divided by Then, introduce a virtual delay d(k) Further, we introduce trigger error Thus, the resilient triggering control inputs are generated by On the basis of above analysis, a discrete-time switched delay system ∑ s(t) is established as and, according to Equation (9), by denoting Ω = C T Ω c C, the trigger condition is rewritten as For the established power system in Equation (11), the research objective of this study is to analyze the resilience performance and provide the design method for the resilient static feedback control in Equation (10) to preserve weighted H ∞ performance: (1) The power system in Equation (11) is exponentially stable when w = 0.

Analysis of Weighted H ∞ Performance
In this section, the weighted H ∞ performance of the power system in Equation (11) is analyzed by combining delay system method and switched system method. Theorem 1. Given positive scalars d M , λ i , µ i (i = 0, 1), γ, σ, the switched time delay system in Equation (11) is exponentially stable with weighted L 2 -gainγ under DoS attacks (τ D , T α ), if there exist positive definite matrices P i , Q i , R i , M i (i = 0, 1), Ω and appropriate dimension matrices X i , Y i (i = 0, 1), K satisfying where Proof. Please see Appendix A.1. in the Appendix A. (14) is the main contribution of this paper. The comprehensive influence of DoS attacks and time delay is bounded by the indices d M , τ D , and T α . The satisfaction of this criterion can guarantee the frequency stability of the considered multi-area power system. Considering the positive term ln(µ 0 µ 1 ), ln(λ 0 /λ 1 ) and the negative term ln(λ 1 ), it requires a small d M and large τ D and T a . It is reasonable that the frequency stability of power system can be preserved with small delay margin, low attack frequency 1/τ D , and small attack duration ratio 1/T α .

Design of Resilient Triggering Control
According to the resulting sufficient conditions in Theorem 1, this section provides a design method of resilient event-based LFC-VSG scheme on the basis of linear matrix inequalities techniques (LMIs).

Proof. Please see Appendix A.2 in the Appendix A.
Remark 2. Theorem 2 relies nonlinearly on the parameters ε, d M , λ i , µ i , (i = 0, 1) γ, ζ, σ, and δ. Once these parameters are given, the matrix inequalities in Equations (20)-(25) would become LMIs, by solving which LFC-VSG gain K and trigger parameter Ω can be further obtained by using MATLAB Toolbox YALMIP with solver MOSEK. Furthermore, the proposed design method allows for a trade-off: performance index γ, λ i versus delay margin d M and DoS attacks τ D , T α .

Simulation
To study the performance of the proposed event-based LFC-VSG scheme, a two-area power system with physical constraints (uncertainty, low inertia and GDB) and cyber disturbance (time delay and DoS attacks) was simulated using MATLAB. The nominal available parameters of the considered two-area power system were borrowed from [4,28], as listed in Table 2. The thermal power plants with various capacities in each area are equivalent to a single synchronous generator. The time constants of the disturbances terms of solar plant and farm plant for two-area power system are simply assumed to be same due to the used uniform inverters in engineering. From another aspect, the disturbance of RESs is not the key factor affecting the stability of power system in this study. The parameters of virtual synchronous generations selected by PSO algorithm [28] are larger than the inertia and damping coefficients of the equivalent SG to enhance system inertia.  Set h = 0.01s, γ = 120, d M = 10, λ 0 = 1.2, λ 1 = 0.4, µ 0 = 1.01, µ 1 = 1.01, σ = 0.1, δ = 0.01, ε = 10 −12 , and ζ = 10 −6 . The inertia of power system reduces 5%. According to Theorem 2, the control gain K and the trigger parameters Ω c = (C + ) T ΩC + were obtained using MATLAB Toolbox YALMIP with solver MOSEK. With the solved triggered control parameters, the frequency derivation ∆ f and the tie-line power exchange ∆P tie of the two-area power system in Equation (5) are depicted in Figures 3 and 4, where the time intervals with grey background represent DoS attacks. Multi-disturbances such as load change, wind farm disturbance and solar farm disturbance are depicted in Figures 5 and 6. It can be observed that the trajectories of frequency derivation and tie-line power exchange approach to zeros after oscillation. By calculation, the decay rate is λ = 0.6819, which verifies the achievement of exponential stability under our method. The oscillation in the time interval [0, 10s] is more serious than that in the time interval [40s, 50s] even though the former disturbances is less than the latter because DoS attacks frequently occur in the beginning time interval [0, 10s] to prevent the implementation of LFC-VSG control signals while the sleep interval [40s, 45s] guarantees power system restoring much resilient performance against DoS attack in the time interval [45s, 50s]. Thus, it is necessary to constrain attack frequency, which verifies the reasonableness of our research motivation. On the other hand, the theory value of H ∞ performance level isγ = 159.8680. By calculation, the actual H ∞ performance level y / w is γ * = 2.0966, which is less thanγ = 159.8680. Thus, the power system is exponentially stable with the desired H ∞ performance level, which verifies the efficiency of our design method.  The triggered instants and triggered intervals are depicted in Figure 7. The event-triggered mechanism is operated during sleep intervals while it stops working to save much energy during attack intervals. It can be observed that the average of release time intervals during [0, 30s] is larger than that during [70s, 100s] because the power system with the worse system performance requires many real-time control updates while power system operation in steady state needs low frequency of control update. Thus, the designed ETM can provide an automatic regulation of communication according to the operation state of power system. Compared with the sample time h = 0.01s, the transmission rate T rate during sleep intervals was calculated as 7.11%, which is efficient to reduce the communication load while preserving system performance.  In the next simulation, the influence of communication factors including delay and DoS attacks on power system resilient performance was studied. According to the resilient condition in Equation (14) in Theorem 1, the quantified results show the relationships among exponential decay rate λ, weight H ∞ levelγ, DoS attacks parameters T α and τ D , and delay bound d M . Note that 1 T α represents the total duty cycle of attack duration while 1 τ D represents attack frequency. For fixed τ D , other parameters being same as before, the H ∞ performance indices λ andγ are decreased with the increasing of T α , as shown in Table 3. It indicates that the H ∞ performance of power system would be seriously deteriorated with the large attack duration 1 T α . In Table 4, for fixed T α , the H ∞ performance level λ andγ are increased with the decrease of τ D . It indicates that the high attack frequency 1 τ D would brings damage on the frequency performance of power system. The resulting conclusions are reasonable to meet common sense. On the other hand, although both attack frequency and duration could lead to the performance deterioration of power system, the influence of attack duration is more serious than attack frequency. Transmission delay and DoS attacks would bring comprehensive influence on frequency stability of power system. Hence, it is interesting to study the relationship of delay bound and DoS attacks duration. For a given average dwell time τ D = 333, the attack duration ratio 1 T α is decreased with the increase of d M in Table 5. It indicates that the influence of delay and DoS attacks are additive because, when there is a large communication delay, the power system would only tolerate weak DoS attacks to preserve the desired performance. Remark 3. Indeed, the numerical evaluation can verify the usefulness of our proposed theory in a limited level. The practicality should be verified by using real time laboratory experiment, such as Analog Power System Simulation (APSS) implemented by operational amplifiers and electronic circuits, which is closer to the real-world power system. However, our study platform at present lacks this kind of experiment environment. Hence, we only performed numerical simulation experiment to verify the validity of our method using MATLAB ToolBox. In the study of LFC system, many researchers also use numerical simulation to verify their theories. In our future work, we will build a physical power system platform or real time semi-physical simulation platform to support our theory study.

Conclusions
The resilient control problem of event-based load frequency control and virtual synchronous generation (LFC-VSG) scheme of discrete-time multi-area power system with uncertainty, low inertia, and GDB under time delay and DoS attacks is studied. Considering the average dwell time (ADT) model-based DoS attacks influencing on the remote communication network of LFC-VSG scheme, a discrete-time switched delay system is established to describe multi-area power system dynamic. Even-triggered mechanism (ETM) is introduced to reduce the communication load of LFC-VSG control loop. By using piecewise Lyapunov-Krasovskii functional method and switched system method, a criterion quantifying the tolerant DoS attack (ADT and duty cycle) and delay bound is proposed. Meanwhile, some sufficient conditions are derived to preserve weighted H ∞ performance. Accordingly, a co-design method for ETM and LFC-VSG scheme is given in terms of LMIs. Aa simulation of two-area power system with the designed resilient event-based LFC-VSG scheme was carried out to illustrate the validity of our theory. In the future, renewable energy resources participating in remote frequency regulation will be considered and another network attack, namely false data injection attack, will be studied. The proposed method combining piecewise LFK and switched system method provides a flexible way for the system synthesis when countering complex cyber-physical factors. For improvement, advanced Lyapunov functional and integral inequality technique can be employed to reduce the conservatism of this conclusion.