1. Introduction
With the frequent occurrence of global extreme weather and natural disasters, enhancing the resilience of distribution networks has become a core issue in modern power system research [
1]. Under emergency conditions where the main grid experiences power outages due to disasters, temporary islanded microgrids constructed using emergency power vehicles (EPVs), i.e., truck-mounted mobile diesel generator units, together with distributed renewable energy sources, can serve as an effective means to ensure continuous power supply for regional critical loads [
2,
3]. In an islanded operation, the microgrid no longer receives frequency support from the main grid. Meanwhile, the high penetration of inverter-interfaced renewable generation further reduces the equivalent inertia of the system. As a result, the temporary islanded microgrid exhibits typical low-inertia characteristics [
4].
When facing sudden source-load changes caused by extreme disasters, low-inertia systems experience severe active power imbalances, which can trigger an excessive rate of change of frequency (RoCoF) and transient frequency nadir excursions, severely threatening the safety baseline and economic efficiency of the microgrid’s post-disaster emergency operation. Compared with large, interconnected power systems, temporary islanded microgrids are more vulnerable to frequency-security risks. Once disconnected from the main grid, the microgrid loses external frequency support, and its equivalent inertia is determined only by local synchronous and inverter-interfaced resources. Moreover, because the total capacity of an islanded microgrid is relatively small, the same MW-level source-load disturbance may correspond to a much larger per-unit power imbalance, resulting in a steeper RoCoF and a deeper transient frequency nadir. Therefore, RoCoF and frequency-nadir constraints are essential for ensuring secure operation in low-inertia islanded microgrids, especially when critical post-disaster loads must be continuously supplied [
5,
6]. From an operational perspective, these transient frequency–security issues also directly affect the economic performance of temporary islanded microgrids. Excessive RoCoF may trigger protection actions before slower reserves are fully activated, while a deep frequency nadir may require emergency physical load shedding to arrest the frequency decline. Since post-disaster islanded microgrids usually supply critical loads with limited local generation and reserve capacity, such emergency load shedding leads to high interruption penalties and reduces service restoration performance. Therefore, RoCoF and frequency-nadir constraints should be considered as key scheduling constraints rather than only as dynamic stability indices.
A grid-forming energy storage system (GFM-ESS) is widely regarded as an effective means of mitigating the inertia shortage in low-inertia islanded systems. References [
7,
8] conducted theoretical analyses on inertia support and frequency security in power system optimization problems, elucidating the necessity of considering frequency security constraints. Reference [
9] incorporated dynamic frequency security constraints into an economic scheduling model; by introducing RoCoF and frequency nadir constraints, it proposed a frequency-secure optimal scheduling scheme considering synchronous inertia demands. At the control level, references [
10,
11] enhanced the grid-connection stability of grid-forming devices from the perspectives of adaptive virtual synchronous machine control and cascaded controller parameter tuning, respectively. At the scheduling level, reference [
12] achieved the synchronous scheduling of multiple frequency response services within a stochastic unit commitment model. However, most of the aforementioned studies treat virtual inertia as a static parameter and rarely consider the coupling between the energy storage’s inertia support and its underlying state of charge (SoC) boundaries. In fact, the ability of GFM-ESS to release virtual inertia is constrained by its charging and discharging power as well as its remaining energy. If inertia control and energy boundary constraints are decoupled during scheduling, the system is highly prone to a collapse of the frequency defense line in extreme scenarios due to resource depletion [
13,
14]. Therefore, there is an urgent need to construct a multi-source collaborative scheduling framework that coordinates the physical inertia of EPVs, the virtual inertia of GFM-ESS, and flexible loads.
In terms of addressing source-load uncertainties, two-stage robust optimization has been widely applied in microgrid energy management [
15]. However, many robust scheduling models use traditional box or polyhedral uncertainty sets. These sets usually treat disturbances in different time periods as mutually independent and therefore ignore the temporal correlation and continuity of meteorological evolution. As a result, the subproblem may generate non-physical extreme trajectories with abrupt jumps between adjacent periods. Such trajectories are unlikely to occur in real meteorological processes and may make the scheduling results overly conservative [
16]. In addition, these unrealistic scenarios may reduce the efficiency of the column-and-constraint generation (C&CG) algorithm. The master problem has to add cuts generated from physically unlikely worst-case trajectories, which increases both the computational burden and the number of iterations. To address these issues, Reference [
17] constructed a state-dependent wind power uncertainty set, validating the positive role of characterizing temporal features in improving operational economy. Reference [
18] proposed a robust unit commitment model based on dynamic uncertainty sets. Reference [
19] further established a robust optimization model that accounts for the temporal correlation of wind power prediction errors. Therefore, accurately capturing the continuous temporal evolution patterns of meteorological disturbances to reduce conservatism while ensuring computational feasibility has become a critical issue in enhancing the practicality of day-ahead scheduling schemes.
In summary, this paper proposes a coordinated two-stage robust day-ahead scheduling model for temporary islanded microgrids under post-disaster operating conditions. It should be emphasized that the column-and-constraint generation framework is adopted as a standard solution technique, rather than being claimed as a methodological novelty. The main contributions of this paper are summarized as follows.
(1) A multi-source coordinated frequency-secure scheduling framework is developed for temporary islanded microgrids supplied by emergency power vehicles, grid-forming energy storage systems, distributed photovoltaic units, and contracted flexible loads. Different from conventional robust microgrid scheduling models that mainly focus on steady-state power balance, the proposed model explicitly incorporates RoCoF and frequency-nadir constraints into the day-ahead robust scheduling process, thereby establishing a dynamic frequency defense baseline before real-time disturbances occur.
(2) A virtual-inertia-aware GFM-ESS scheduling model is embedded into the robust optimization framework. Instead of treating virtual inertia as a fixed parameter, the proposed formulation links the frequency-support capability of the GFM-ESS with its charging/discharging power, reserve allocation, and energy boundary constraints. Therefore, the optimizer can coordinate the mechanical inertia of EPVs, the virtual inertia of GFM-ESSs, and fast demand-side response while ensuring that the storage SoC constraints are not violated in both the day-ahead and real-time stages.
(3) A time-correlated uncertainty set based on state-transition auxiliary variables is constructed to characterize the continuous evolution of severe weather-induced PV and load disturbances. Unlike simply adjusting the conventional spatial uncertainty budget, the proposed temporal budget restricts the number of adjacent-period state transitions and therefore controls the continuity of uncertainty trajectories. This makes it possible to preserve persistent severe-weather patterns while excluding non-physical high-frequency switching scenarios generated by traditional box uncertainty sets.
(4) Case studies on a modified IEEE 33-node islanded microgrid demonstrate that the proposed model can reduce emergency physical load shedding, maintain RoCoF and frequency nadir within safety limits, and improve the computational performance of the C&CG process by filtering out physically unlikely worst-case trajectories.
2. System Modeling
The islanded microgrid system investigated in this study primarily comprises EPVs, GFM-ESS, distributed photovoltaic (PV) units, and flexible loads. In the conventional grid-connected mode, the frequency and voltage of the microgrid are supported by the main grid; however, in the islanded mode, the system lacks such support and exhibits typical low-inertia characteristics. The system must not only address the steady-state energy balance issues caused by source-load fluctuations but also guard against transient frequency instability risks triggered by sudden power imbalances. The proposed model is formulated from the perspective of a microgrid operator responsible for post-disaster islanded operation. During the temporary islanded period, the operator is assumed to have dispatch authority over the deployed EPVs, GFM-ESS units, PV curtailment, and contracted flexible loads, including shiftable loads and interruptible loads. Ordinary non-contracted loads are treated as fixed demand, while critical loads are prioritized and are not voluntarily curtailed. Forced physical load shedding is only used as an emergency recourse action when the available dispatchable and contracted resources are insufficient to maintain power balance and frequency security. The operator does not directly control all end-user loads. Only contracted flexible loads participate in demand response according to pre-signed agreements.
2.1. EPV Model
In this study, an EPV refers to a truck-mounted emergency diesel generator unit with a grid-connection interface, which is deployed as a mobile dispatchable power source for post-disaster service restoration. As the primary support power source for the islanded microgrid, the operation of an EPV is restricted by its mechanical rotor inertia and governor response characteristics. Its operation must satisfy startup and shutdown logic, steady-state ramping, and transient reserve constraints. The operational status and start-stop logic of the units are expressed as
where
denotes the operational state of EPV during period
t, while
and
represent the startup and shutdown variables, respectively.
To ensure the safe operation of the units, the active power output must be restricted within the allowable physical range, and minimum startup and shutdown time requirements must be satisfied:
where
is the active power output of the EPV;
and
are the lower and upper output limits; and
and
are the minimum startup and shutdown time parameters.
The adjustment of unit output in adjacent periods is restricted by the steady-state ramp rate, and primary frequency regulation reserves must be pre-allocated to cope with transient frequency drops:
where
and
are the upper limits of the steady-state ramp rate;
represents the primary frequency regulation reserve capacity, the upper limit of which is constrained by the maximum transient physical ramping capability of the unit, denoted as
.
2.2. GFM-ESS Model
Unlike traditional grid-following storage, the GFM-ESS establishes and maintains the grid voltage and frequency through inverter control strategies. Its charging/discharging power and SoC must satisfy temporal energy continuity constraints:
where
is a mutual exclusivity variable to prevent simultaneous charging and discharging;
and
are the discharging and charging powers;
is the rated power of the inverter;
is the stored energy;
and
are the discharging and charging efficiencies;
and
are the allowable safety limits for the stored energy; and
and
represent the initial and final energy states within the scheduling cycle, ensuring intra-day energy conservation and availability for the following day.
It should be noted that the storage energy boundary in Equation (12) is enforced as a hard physical constraint in both the day-ahead pre-scheduling stage and the real-time re-scheduling stage. Real-time source-load fluctuations are not assumed to be absorbed solely by the GFM-ESS. Instead, they are jointly handled by GFM-ESS charging/discharging adjustment, pre-allocated frequency reserves, EPV primary frequency response, PV curtailment, contracted flexible loads, and emergency load shedding when necessary. Therefore, the GFM-ESS can only provide regulation and virtual inertia within its feasible power and energy ranges. If the available storage energy is insufficient, the model activates other recourse actions rather than relaxing or violating the SoC constraint.
When providing frequency support, the reserves pre-allocated by the storage are restricted not only by the power upper limit but also by the remaining energy [
20]:
where
and
are the upward and downward frequency regulation reserves;
is the short-term overload coefficient of the inverter; and
is the required sustained time.
The inertia support capability of the GFM-ESS stems from its power response capability [
21]. Let
be the equivalent inertia constant, which is proportional to the transmission power of the interface line. When the energy released by the storage is large, the inertia constant is large, and the RoCoF is relatively small, which is conducive to maintaining system power balance. Conversely, when the energy released is small, the inertia constant is small, and the RoCoF is larger, potentially causing frequency stability issues.
where
and
are the upper and lower virtual inertia limits.
It should be noted that Equation (18) assumes that the GFM-ESS remains electrically connected and operates in grid-forming mode during the islanded scheduling horizon. Therefore, even when and , the GFM-ESS can still provide the floor-level virtual inertia through its baseline voltage- and frequency-forming control. This standby grid-forming mode has a scheduling implication: the optimizer may keep a storage unit online to contribute minimum inertia support even when it does not exchange steady-state active power with the microgrid.
2.3. Flexible Load and PV Model
Flexible resources within the islanded microgrid primarily consist of demand-side shiftable loads (SLs) and interruptible loads (ILs). Rational deployment of these resources is crucial for maintaining power balance and coping with transient impacts.
SLs participate in scheduling by transferring power demand across periods. The shifted-in and shifted-out powers are restricted by the maximum participation ratio stipulated in user agreements and must satisfy total energy conservation throughout the scheduling cycle:
where
and
are the shifted-in and shifted-out powers;
is the forecasted baseline load; and
is the maximum allowable proportion of the SL.
ILs can be directly curtailed during emergencies such as power deficits. To protect the basic production benefits of industrial users, load shedding cannot be unlimited [
22]. The curtailed power must satisfy a single-period ratio upper limit, and the total energy called upon throughout the day must be constrained by the contract budget:
where
is the actual curtailed power;
is the maximum curtailment ratio; and
is the total energy budget limit.
For distributed PV, curtailment is permitted during extreme downward regulation or when the storage capacity reaches its limit. The curtailed amount is restricted by the current available generation capacity:
where
is the actual PV curtailment power and
is the actual available output of the distributed PV at period
t.
2.4. Network Power Flow Constraints
A linearized branch flow model (DistFlow) is employed to characterize the physical operational boundaries of the microgrid:
where
and
are the active and reactive power injected at node j;
and
are the branch active and reactive power flows;
is the square of the node voltage magnitude;
and
are the branch resistance and reactance parameters;
and
are the safety limits for the node voltage magnitude; and
and
denote the sets of branches with node j as the sending and receiving ends, respectively.
Regarding line capacity, the true physical feasible region is a non-linear quadratic circular domain. To overcome the pseudo-feasible region generated by traditional box relaxation and ensure the linearity of the two-stage RO subproblem, a regular octahedral polyhedral approximation is adopted for high-precision linear approximation:
where
is the apparent power capacity limit. Equations (29)–(32) transform the non-linear capacity boundary into purely linear inequalities through multiple linear hyperplanes with different slopes, ensuring power flow security under source-load disturbances.
2.5. Dynamic Frequency Security Constraints with Virtual Inertia
In the event of a sudden active-power deficit, the islanded microgrid faces the risks of excessive RoCoF and frequency nadir violations because it lacks voltage and frequency support from the main grid. The total equivalent inertia
of the system at period t is contributed by the physical mechanical inertia of the online EPVs and the virtual inertia of the GFM-ESSs. Following the standard per-unit swing-equation formulation, the aggregated system inertia is normalized by the system power base:
where
and
denote the total number of EPVs and GFM-ESS units, respectively;
and
represent the physical mechanical inertia constant and the rated capacity of EPV;
is the rated capacity of the inverter for GFM-ESS; and
is the system base power. With this normalization,
is expressed in seconds and the active-power imbalance terms used in the frequency-security constraints are expressed per unit.
The equivalent center-of-inertia swing equation for the low-inertia microgrid is written as follows:
where
is the system frequency deviation;
is the active power imbalance;
is the initial frequency.
Let
denote the PV-output shortfall caused by the uncertainty realization and let
denote the load-demand increase. The total active-power deficit caused by the source-load disturbance is defined as
The corresponding per-unit active-power deficit is
Similarly, the emergency physical load shedding used in the frequency-security constraints is also expressed per unit:
At the initial instant of the microgrid encountering a disturbance, no reserve resources are activated, and the system power deficit reaches its peak. To satisfy the maximum allowable RoCoF limit
, the initial net disturbance power
must be restricted by the current inertia boundary of the system. Since emergency physical load shedding acts as the last instantaneous defense measure to arrest the frequency drop, the net disturbance at this moment is
. Consequently, Equation (34) is transformed into the following linear inequality boundary:
Substituting Equations (18) and (33) into Equation (38) yields an affine inequality in the decision variables , , , and . This is because is an affine function of the charging and discharging powers, while , , , , and are constants. Therefore, the RoCoF constraint remains linear and does not require any additional linearization.
The nadir constraint aims to ensure that the minimum frequency of the system after a disturbance is not lower than the safety limit
. Integrating Equation (34) in the time domain from the occurrence of the disturbance to the time of the frequency nadir yields
where
is the initial net active power deficit of the system;
is the sum of the dynamic active power support responses provided by various reserve resources during the transient process; and
is the critical time window to reach the frequency nadir.
ILs possess fast frequency response capabilities and can complete shedding within an extremely short time [
23]. In this study, fast active-power support during the critical response window is provided by four resources: interruptible load, emergency physical load shedding, GFM-ESS upward reserve, and EPV primary frequency reserve. By approximating these fast responses as equivalent active-power support within τ, the integral term in Equation (39) can be converted into the following algebraic expression:
where
,
, and
.
By imposing the safety requirement
, the complex Nadir integral equation can be equivalently expressed as the following linear inequality:
Similar to the RoCoF constraint, substituting Equations (18) and (33) into Equation (41) does not introduce any bilinear product of decision variables. The right-hand side is affine in the dispatch variables because is affine after substitution, and all other coefficients are constants. Therefore, the proposed nadir-security constraint is also a linear inequality and can be directly embedded into the mixed-integer linear programming formulation.
4. Solution Procedure Based on Standard C&CG
To solve the min–max–min structure of the proposed two-stage robust optimization model, a standard C&CG framework is adopted. It should be noted that C&CG is used here as a solution technique rather than as a methodological contribution of this paper. The main modeling contributions lie in the coordinated frequency-security constraints and the time-correlated uncertainty set introduced in the previous sections. The algorithm decomposes the original problem into a master problem and a subproblem in MILP format. Through alternating iterations between the master problem and the subproblem, and by adding the identified worst-case scenarios as cutting planes, the robust scheduling scheme satisfying the worst-case boundaries is obtained.
The master problem aims to find the optimal baseline scheduling and reserve pre-allocation scheme under the set of identified worst-case scenarios, providing a lower bound (LB) for the objective function. In the
k-th iteration, the compact matrix form of the master problem is expressed as
where
is an auxiliary decision variable used to approximate the re-scheduling cost of the second-stage worst-case scenario;
l is the current iteration index;
is the extreme temporal disturbance scenario identified by the subproblem in the
l-th iteration; and
represents the re-scheduling decision variables newly generated for that specific scenario. After solving the master problem, the optimal day-ahead decision variables
are passed to the inner subproblem.
The subproblem receives the optimal day-ahead decisions
and identifies the worst-case scenario
within the uncertainty set U that maximizes the system’s re-scheduling cost, thereby providing an upper bound (UB) for the objective function. Given
, the subproblem presents a max–min bi-level structure:
where
is the objective value of the subproblem under the current iteration, and
is the column vector of non-positive dual variables corresponding to the second-stage operational constraints.
By utilizing strong duality theory, the inner minimization problem is transformed into its equivalent maximization dual problem, thus merging the bi-level subproblem into a single-level maximization model:
As shown in Equation (57), the objective function contains a linear term
and a bilinear non-convex term
, which involves the product of continuous dual variables
and uncertainty disturbance variables
. These bilinear terms represent the product of continuous and binary variables, which can be exactly linearized using the big-M method. Taking the dual product term related to PV disturbance as an example, a continuous auxiliary variable
is introduced, and the following linear inequality constraints are added for equivalent substitution:
where M denotes the upper bound used to linearize the product between the continuous dual expression and the binary uncertainty variable. In the numerical implementation, M is not selected as an arbitrarily large constant. Instead, it is determined according to the maximum marginal penalty coefficient in the second-stage re-scheduling problem.
An auxiliary emergency slack variable is introduced in the real-time re-scheduling model to guarantee complete recourse and prevent infeasibility under extreme uncertainty realizations. This slack variable is not regarded as a normal physical regulation resource; therefore, it is assigned the highest unit penalty coefficient, which is larger than the cost coefficients of all other second-stage recourse actions. The dual expressions associated with the PV and load uncertainty terms represent the marginal recourse costs caused by PV shortfall and load increase. Hence, their economically meaningful ranges are bounded by the maximum marginal penalty in the recourse problem. Accordingly, the Big-M value is set to be equal to the unit penalty coefficient of the auxiliary emergency slack variable in the numerical implementation.
Compared with using an excessively large big-M value, this cost-coefficient-based bound is consistent with the scale of the optimization model and helps avoid unnecessary numerical deterioration in Gurobi while preserving the exactness of the binary-continuous linearization.
When an extreme disturbance occurs (
),
is strictly equal to
; when there is no disturbance (
),
is strictly equal to 0. Similar linearization is applied to the bilinear terms involving load disturbances. After big-M linearization, the subproblem is thoroughly converted into a standard single-level MILP model, which can be efficiently solved by commercial solvers. The iterative C&CG solution process for the coordinated RO model is illustrated in
Figure 1.