arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.10645eess.SYcs.SY

算力-电力协同攻击下的AI数据中心(AIDC)微电网脆弱性评估

AIDC Microgrid Vulnerability Assessment Under Computing-Power Coordinated Attacks

Ze Yu, Hongwei Zhen, Chao Shen, Mingyang Sun

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对低碳AI数据中心(AIDC)微电网的算力-电力协同攻击问题,提出不确定性感知脆弱性评估框架,经案例验证可识别脆弱时段,协同攻击危害大于单一攻击。

中文摘要 AI 辅助

大型语言模型(LLM)服务的快速增长正推动AI数据中心(AIDC)的扩张,加剧了对电力系统资源充足性和碳排放上升的担忧。可再生能源的整合为应对这些压力提供了途径,但也给低碳AIDC带来了新的跨域稳定性挑战。例如,可再生能源发电的波动性影响供应侧可靠性,而AIDC工作负载的波动影响需求侧可靠性,共同在AIDC微电网中形成相互关联的稳定性风险。为解决这一问题,本文首次探索针对低碳AIDC的算力-电力协同攻击。首先,提出一种不确定性感知的AIDC微电网脆弱性评估框架,以捕捉两个相互作用的攻击面:逆变器控制参数篡改攻击和AI诱导的需求操纵攻击。随后,考虑可再生能源侧的预测不确定性和AIDC侧的需求响应不确定性,引入置信加权实现并构建长期攻击可达域分析。此外,采用基于阻抗的筛选方法将发电和负荷变化映射到稳定裕度的侵蚀,从而识别脆弱的攻击时间窗口和攻击向量。案例研究表明,算力-电力协同攻击会导致逆变器频率持续偏移超过额定值的20%,并达到单一攻击无法实现的不稳定状态。结果还表明,所提出的框架可从长期运行轨迹中提取稀疏、高置信度的脆弱时段。

英文摘要

The rapid growth of large language model (LLM) services is expanding AI data centers (AIDCs), increasing electricity demand and associated carbon emissions. Renewable energy integration can mitigate these impacts but also strengthens the coupling between AIDC loads and inverter-interfaced generation, creating cross-domain cyber-physical vulnerabilities. Specifically, adversarial AI requests alter AIDC power demand, whereas inverter control tampering modifies source-side dynamics, and their combined impact on system stability varies with generation forecast and demand response uncertainties. To this end, we propose an uncertainty-aware AIDC microgrid vulnerability assessment framework under computing-power coordinated attacks. First, the framework maps adversarial AI requests to AIDC power variations and represents uncertainties in attack-induced demand responses and photovoltaic (PV) forecasts through confidence-weighted realizations. Then, impedance based stability analysis combines these realizations with bounded inverter parameter tampering to construct attack reachable domains and identify critical attack time windows. Furthermore, a separate criterion identifies fixed coordinated attack vectors that retain destabilizing capability throughout each selected window. Case studies demonstrate that, unlike either attack component applied alone, coordinated attacks within identified critical windows induce sustained inverter frequency oscillations with peak absolute deviations exceeding 20% of nominal frequency, whereas the evaluated out-of-window response remains bounded. The proposed method further identifies critical attack windows and the associated coordinated attack vectors.

↑