Abstract:Virtual power plants (VPPs) can participate in electricity market trading by aggregating distributed energy resources, thereby providing flexible regulation services to the power system. However, the interaction between VPPs and the power system involves high-frequency and multi-party data exchange, posing significant cybersecurity risks. To ensure the cybersecurity of VPPs throughout the entire interaction process, this paper first analyzes the intrinsic attributes of VPPs, identifying three key characteristics: aggregation, interaction, and regulation. Based on this, it integrates these attributes with confidentiality, integrity, and availability triad to construct a cybersecurity theoretical framework for VPPs. Second, this paper outlines the business processes, data interactions, and communication architecture of VPPs. Then, a risk analysis of potential cyberattacks is performed, detailing their injection points, propagation paths, and potential impacts of typical cyberattacks. Third, the core application mechanisms and use cases of key cybersecurity defense technologies are summarized. These technologies are applicable to interactions between VPP and power systems across different stages, including data anonymization, encryption, privacy-preserving computation, access control, and blockchain. Finally, an analysis of the current status, challenges, and prospects of artificial intelligence (AI)-based cybersecurity technologies is presented, which provides support for constructing a secure and reliable cybersecurity defense system for VPPs.