A method for detecting deception attacks in industrial cyber-physical systems
By establishing a multi-channel data correlation model in a cyber-physical system, constructing detection residuals, and designing an optimal weight matrix, the problem of insufficient performance in deception attack detection is solved, and efficient and accurate deception attack detection is achieved.
Patent Information
- Application Number
- CN202411368959.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2044-09-29
AI Technical Summary
Existing deception attack detection methods suffer from limited detection performance and poor applicability in cyber-physical systems, especially in multi-channel scenarios where the correlation of multi-channel data at different security levels has not been fully studied and utilized.
By establishing data transmission channel models with different security levels, generating innovation using sequential Kalman filters, constructing detection residuals, quantifying data correlation changes caused by spoofing attacks, designing the optimal weight matrix, and setting detection strategies and thresholds, high-performance detection of spoofing attacks is achieved.
It achieves timely and accurate detection of deception attacks without affecting system state estimation and control performance, thus solving the limitations and poor applicability of existing methods.
Smart Images

Figure CN119363390B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of security technology for industrial cyber-physical systems, and in particular relates to a method for detecting deception attacks on industrial cyber-physical systems. Background Technology
[0002] Cyber-physical systems (CPS) integrate computers, communication networks, and physical devices, utilizing feedback loops to monitor and control physical processes. They support the control and monitoring of complex systems and are widely used in critical sectors such as energy and water resources. However, with the introduction of communication networks and wireless sensors, CPS face the risk of cyberattacks, including eavesdropping, spoofing, and sabotage attacks. Spoofing attacks use acquired system dynamics and defense information to construct attacks and inject attack signals into measurement or control signals to disrupt the state estimation of the CPS. Attackers, through sophisticated design, can bypass attack detectors, causing fatal damage to the system while maintaining stealth. Therefore, spoofing attack detection and defense are crucial for the secure and reliable operation of CPS.
[0003] Deception attack detection can be categorized into statistical characteristic-based detection, machine learning-based detection, and active detection based on encryption and encoding. Statistical characteristic-based detection has limited performance, while machine learning requires complex model training and is not effective in practical applications. Active detection methods, such as watermarking and moving target detection, often impact system control performance and require additional system architecture modifications, making them difficult to deploy in complex industrial scenarios.
[0004] Furthermore, most deception attack detection methods do not consider multi-channel scenarios. With the increasing scale of cyber-physical systems, multi-channel transmission has been widely applied in industrial settings. In a multi-channel framework, more information can be utilized for attack and detection, potentially increasing the complexity and effectiveness of attack and defense strategies. However, current research on multi-channel scenarios remains limited, and the correlation between multi-channel data at different security levels has not been fully studied and utilized. Summary of the Invention
[0005] To address the aforementioned issues, this invention proposes a deception attack detection method for industrial cyber-physical systems. This method is based on multi-channel data correlation and achieves deception attack detection by quantifying changes in data correlation caused by the attack. It effectively solves the limitations of existing deception attack detection methods and their application problems in multi-channel cyber-physical systems.
[0006] To achieve the above objectives, the technical solution adopted by this invention is: a method for detecting deception attacks in industrial cyber-physical systems, comprising the following steps:
[0007] Step 1: Establish cyber-physical system models with data transmission channels of different security levels, establish a discrete linear time-invariant state-space model, and establish a description of the deception attack process under this model;
[0008] Step 2: Establish a set of sparsely sampled secure data transmission channels and encrypt the data in the unreliable channels;
[0009] Step 3: Collect input and output data of the cyber-physical control system, and construct detection residuals based on the data correlation between different channels;
[0010] Step 4: Quantify the residual changes caused by the deception attack, and establish the optimal weight matrix based on the residual changes to improve detection performance;
[0011] Step 5: Set the detection strategy and detection threshold, calculate the detection statistics, and complete the deception attack detection.
[0012] Furthermore, in step 1, the cyber-physical system model establishing data transmission channels with different security levels is as follows:
[0013]
[0014] Where k is time, x represents the system state, and y i The system measurement output is represented by the subscript i∈{a,b}, which indicates data transmission channels with different security levels. 'a' represents an unreliable channel that can be eavesdropped on and tampered with, and 'b' represents a reliable channel that can be eavesdropped on but cannot be tampered with. w(k) and v i (k) represent process noise and measurement noise, respectively; A and C i Given a matrix of a specified dimension, satisfying (A, C) i ) is detectable.
[0015] Generate new information for transmission
[0016] Where i∈{a,b}, The prior minimum variance error state estimate is generated by a sequential Kalman filter.
[0017] Furthermore, in step 1, establishing the deception attack description includes:
[0018] In cyber-physical control systems, attackers can construct attack vectors by eavesdropping on data transmitted through reliable and unreliable channels and inject them into the unreliable channels to disrupt system state estimation.
[0019] Malicious vectors constructed by the attacker:
[0020]
[0021] Where S(k) and T(k) are attack matrices with specified dimensions, and b(k) are independent and identically distributed Gaussian random vectors; the deception attack satisfies and They are respectively and z a The covariance.
[0022] Furthermore, in step 2, a set of sparsely sampled secure data transmission channels is established to encrypt data in unreliable channels, including:
[0023] To achieve deception attack detection, a set of secure transmission channels with sparse sampling periods is set up:
[0024] y s (k i ) = C s χ(k i )+v s (k i );
[0025]
[0026] Among them, y s and C s These are the measurement output and measurement matrix of the secure channel, respectively. s For new information, χ represents the system state. For prior minimum variance error state estimation; k i (i = 0, 1, 2, ...) represents the time when data is transmitted via the secure channel, satisfying k i+1 =k i +τ, where τ is the sampling period; at each time point k = k i Data is transmitted through a secure channel s, and the data in the channel cannot be eavesdropped on or tampered with by attackers;
[0027] The information acquired at each time point at both ends of the channel is defined as follows:
[0028]
[0029] Using secure channel data, data in unreliable channels is encrypted, making... z a This refers to information delivered through unreliable channels that can be eavesdropped on and tampered with.
[0030] The covariance is:
[0031]
[0032] in, For new information za covariance, For new information z s covariance, For new information z a With z s Covariance between For new information z s With z a The covariance between them.
[0033] Furthermore, in step 3, the input and output data of the cyber-physical control system are collected, and the detection residual is constructed based on the data correlation between different channels as follows:
[0034]
[0035] Where W(k) represents the weight matrix, r(k) is the detection residual, and z e Encrypted data transmitted over the channel. For the new information acquired at each moment at both ends of the secure channel;
[0036] The covariance matrix of the residuals is:
[0037]
[0038] in
[0039]
[0040] in, For new information z s covariance, To encrypt data z e covariance, For new information z a With z s Covariance between For new information z s With z a Covariance between For new information z s The covariance.
[0041] Furthermore, in step 4, the residual change caused by the deception attack is quantified, including the following steps:
[0042] Based on the detection mechanisms in steps 2 and 3, the data and residuals under a deception attack are respectively represented as:
[0043]
[0044] in, For, r a (k) is an attack matrix with specified dimensions, and S(k) and T(k) are attack matrices with specified dimensions.a z represents information from an unreliable channel that can be eavesdropped on and tampered with. b Let b(k) represent the information of a reliable channel that can be eavesdropped on but cannot be tampered with, and let b(k) be an independent and identically distributed Gaussian random vector. This refers to the data acquired at each time point at both ends of the channel;
[0045] The covariance matrix of the residuals after the attack is:
[0046]
[0047] in
[0048]
[0049] in, For new information z s covariance, Data under attack covariance, For new information z a With z s Covariance between For new information z b With z s Covariance between them;
[0050] The change in covariance caused by a deception attack is:
[0051]
[0052] in
[0053]
[0054] Where I is the identity matrix.
[0055] Furthermore, based on residual variation analysis, an optimal weight matrix is designed to improve detection performance. A unified solution form is given based on two optimization indices, including the following steps:
[0056] Let Π = WΣ r W T , Δ=Π-Π a =WΣ Δ W T ;
[0057] Π is the covariance matrix of the residuals. a Let Σ be the covariance matrix of the residuals under attack. r for The covariance matrix, for The covariance matrix,
[0058] Define the norm optimization metric:
[0059] in, Covariance matrix The square root of;
[0060] right Perform SVD decomposition to obtain:
[0061] Where U and V are orthogonal matrices obtained from SVD decomposition, we have UU T =I and VV T =I, Λ is a diagonal matrix composed of singular values; U is The left singular vector matrix, V is The right singular vector matrix;
[0062] Optimization problem The solutions and their maximum values are:
[0063] W = Λ -1 U T ;
[0064]
[0065] in, for;
[0066] Set trace optimization metrics:
[0067] in, The maximum value of J1 corresponding to the optimal point W;
[0068] Optimization problem The solutions and their maximum values are:
[0069]
[0070] in, W is the maximum value of J2 corresponding to the optimal point W. i Yes (Σ) Δ ,Σ r The i-th largest generalized eigenvector of ) is λ. i Yes (Σ) Δ ,Σ r The i-th largest eigenvalue of ).
[0071] Based on the two optimization schemes described above, the optimization problem is... and The solution has a unified form W = Λ - 1 U T, which serves as the optimal weight matrix.
[0072] Furthermore, in step 5, selecting the detection quantity and detection threshold, calculating the detection quantity and comparing it with the threshold to complete the deception attack detection includes:
[0073] Define χ 2 Statistic:
[0074]
[0075] Where j is the detector window size, k is time, r(i) is the residual at time i, and χ 2 (l) represents the chi-square distribution with l degrees of freedom, and Π is the covariance matrix of the residuals;
[0076] Select the threshold based on the chi-square distribution table. When the statistic is greater than the threshold, it means that an attack has been detected; when the statistic is less than the threshold, it means that no attack has been detected.
[0077] The beneficial effects of adopting this technical solution are:
[0078] The purpose of this invention is to provide a cyber-physical system (CPS) deception attack detection method based on multi-channel data correlation. The method includes: establishing a CPS model with data transmission channels of different security levels and sequential Kalman filters; introducing a deception attack; establishing a discrete linear time-invariant state-space model; establishing a sparsely sampled secure data transmission channel model; designing an attack detection mechanism; collecting input and output data of the CPS control system; constructing detection residuals based on the correlation of data from different channels; analyzing the changes in the statistical characteristics of the residuals caused by the attack; designing an optimal weight matrix based on the residual changes to improve detection performance; further setting detection strategies and detection thresholds; calculating detection statistics; and completing the deception attack detection. This method, based on data correlation design, can achieve timely and accurate detection of deception attacks. Furthermore, when no attack occurs, this detection method does not affect the system's state estimation and control, effectively solving the limitations and poor applicability of existing deception attack detection methods.
[0079] This invention proposes a cyber-physical system spoofing attack detection method based on multi-channel data correlation, achieving high-performance detection of spoofing attacks within a multi-channel framework. By quantitatively analyzing the residual characteristic changes caused by spoofing attacks, an optimal weight matrix is designed to further improve detection performance. Time-varying data correlation makes it difficult for attackers to design stealthy attacks. Since the time-varying data correlation between channels is caused by the intrinsic characteristics of the Kalman filter, this characteristic does not require modification of the system structure to be activated. Compared to existing detection schemes, the above scheme can efficiently detect spoofing attacks, maintain control performance, and is simple and convenient to implement. Attached Figure Description
[0080] Figure 1 This is a schematic diagram of a deception attack detection method for an industrial cyber-physical system according to the present invention;
[0081] Figure 2 This is a model diagram of a cyber-physical system in an embodiment of the present invention;
[0082] Figure 3 This is a system model diagram of the deception attack detection mechanism in an embodiment of the present invention;
[0083] Figure 4 This is a simulation result of deception attack detection in an embodiment of the present invention;
[0084] Figure 5 This is a simulation result of the attack detection rate using the optimal weight matrix in an embodiment of the present invention. Detailed Implementation
[0085] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described below with reference to the accompanying drawings.
[0086] In this embodiment, see Figure 1 As shown, this invention proposes a method for detecting deception attacks in industrial cyber-physical systems, including the following steps:
[0087] Step 1: Establish cyber-physical system models with data transmission channels of different security levels, establish a discrete linear time-invariant state-space model, and establish a description of the deception attack process under this model;
[0088] Step 2: Establish a set of sparsely sampled secure data transmission channels and encrypt the data in the unreliable channels;
[0089] Step 3: Collect input and output data of the cyber-physical control system, and construct detection residuals based on the data correlation between different channels;
[0090] Step 4: Quantify the residual changes caused by the deception attack, and establish the optimal weight matrix based on the residual changes to improve detection performance;
[0091] Step 5: Set the detection strategy and detection threshold, calculate the detection statistics, and complete the deception attack detection.
[0092] As an optimization of the above embodiment, in step 1:
[0093] Establish cyber-physical system models with data transmission channels of different security levels, such as... Figure 2 As shown.
[0094] The cyber-physical system model with data transmission channels of different security levels is as follows:
[0095]
[0096] Where k is time, x represents the system state, and y i The system measurement output is represented by the subscript i∈{a,b}, which indicates data transmission channels with different security levels. 'a' represents an unreliable channel that can be eavesdropped on and tampered with, and 'b' represents a reliable channel that can be eavesdropped on but cannot be tampered with. w(k) and v i (k) represent process noise and measurement noise, respectively. They are independent of each other and follow a zero-mean Gaussian distribution, with covariance matrices Q>O and R0, respectively. i >O; A and C i Given a matrix of a specified dimension, satisfying (A, C) i ) is detectable.
[0097] Generate new information for transmission
[0098] Where i∈{a,b}, The prior minimum variance error state estimate is generated by a sequential Kalman filter.
[0099] Sequential Kalman Filter:
[0100]
[0101] P - (k)=AP(k-1)A T +Q
[0102]
[0103] {P b (k)=(IK b (k)C b )P - (k)
[0104]
[0105] P(k=(IK) a (k)C a )P b (k)
[0106] in, For the minimum variance error state estimation, P - P(k) and P(k) represent the prior and posterior estimation errors, respectively. (New information z) i The covariance of (k) is
[0107] In step 1, establishing the deception attack description includes:
[0108] In cyber-physical control systems, attackers can construct attack vectors by eavesdropping on data transmitted through reliable and unreliable channels and inject them into the unreliable channels to disrupt system state estimation.
[0109] Malicious vectors constructed by the attacker:
[0110]
[0111] Where S(k) and T(k) are attack matrices with specified dimensions, and b(k) are independent and identically distributed Gaussian random vectors; the deception attack satisfies and They are respectively and z a The covariance.
[0112] As an optimization of the above embodiment, in step 2, a set of sparsely sampled secure data transmission channels is established to encrypt data in unreliable channels.
[0113] Specifically, such as Figure 3 As shown. Data in the secure channel cannot be eavesdropped on or tampered with by attackers. To conserve communication resources, a sparse sampling frequency is set. Data is transmitted once every τ seconds in the secure channel. The measurement data and information of the secure channel are as follows:
[0114] To achieve deception attack detection, a set of secure transmission channels with sparse sampling periods is set up:
[0115] y s (k i ) = C s χ(k i )+v s (k i );
[0116]
[0117] Among them, y s and C s These are the measurement output and measurement matrix of the secure channel, respectively. s For new information, χ represents the system state. For prior minimum variance error state estimation; k i (i = 0, 1, 2, ...) represents the time when data is transmitted via the secure channel, satisfying k i+1 =k i +τ, where τ is the sampling period; at each time point k = k i Data is transmitted through a secure channel s, and the data in the channel cannot be eavesdropped on or tampered with by attackers;
[0118] The information acquired at each time point at both ends of the channel is defined as follows:
[0119]
[0120] Using secure channel data, data in unreliable channels is encrypted, making... z a This refers to information delivered through unreliable channels that can be eavesdropped on and tampered with.
[0121] The covariance is:
[0122]
[0123] in, For new information z a covariance, For new information z s covariance, For new information z a With z s Covariance between For new information z s With z a The covariance between them.
[0124] As an optimization of the above embodiment, in step 3, the input and output data of the cyber-physical control system are collected, and the detection residual is constructed based on the data correlation between different channels as follows:
[0125]
[0126] Where W(k) represents the weight matrix, r(k) is the detection residual, and z e Encrypted data transmitted over the channel. For the new information acquired at each moment at both ends of the secure channel;
[0127] The covariance matrix of the residuals is:
[0128]
[0129] in
[0130]
[0131] in, For new information z s covariance, To encrypt data z e covariance, For new information z a With z s Covariance between For new information z s With za Covariance between For new information z s The covariance.
[0132] As an optimization of the above embodiment, step 4, quantifying the residual change caused by the deception attack, includes the following steps:
[0133] Based on the detection mechanisms in steps 2 and 3, the data and residuals under a deception attack are respectively represented as:
[0134]
[0135] in, For, r a (k) is an attack matrix with specified dimensions, and S(k) and T(k) are attack matrices with specified dimensions. a z represents information from an unreliable channel that can be eavesdropped on and tampered with. b Let b(k) represent the information of a reliable channel that can be eavesdropped on but cannot be tampered with, and let b(k) be an independent and identically distributed Gaussian random vector. This refers to the data acquired at each time point at both ends of the channel;
[0136] The covariance matrix of the residuals after the attack is:
[0137]
[0138] in
[0139]
[0140] in, For new information z s covariance, Encrypted data under attack covariance, For new information z a With z s Covariance between For new information z b With z s Covariance between them;
[0141] The change in covariance caused by a deception attack is:
[0142]
[0143] in
[0144]
[0145] Where I is the identity matrix.
[0146] Based on residual change analysis, an optimal weight matrix is designed to improve detection performance. A unified solution form is given based on two optimization indices, including the following steps:
[0147] Let Π = WΣ r W T , Δ=Π-Π a =WΣ Δ W T ;
[0148] Π is the covariance matrix of the residuals. a Let Σ be the covariance matrix of the residuals under attack. r for The covariance matrix, for The covariance matrix,
[0149] Define the norm optimization metric:
[0150] in, Covariance matrix The square root of;
[0151] right Perform SVD decomposition to obtain:
[0152] Where U and V are orthogonal matrices obtained from SVD decomposition, we have UU T =I and VV T =I, Λ is a diagonal matrix composed of singular values; U is The left singular vector matrix, V is The right singular vector matrix;
[0153] Optimization problem The solutions and their maximum values are:
[0154] W = Λ -1 U T ;
[0155]
[0156] in, The maximum value of J1 corresponding to the optimal point W;
[0157] Set trace optimization metrics:
[0158] Where tr represents finding the trace of a matrix;
[0159] Optimization problem The solutions and their maximum values are:
[0160]
[0161] in, W is the maximum value of J2 corresponding to the optimal point W. i Yes (Σ) Δ ,Σ r The i-th largest generalized eigenvector of ) is λ. i Yes (Σ) Δ ,Σr ) The i-th largest eigenvalue;
[0162] Based on the two optimization schemes described above, the optimization problem is... and The solution has a unified form W = Λ - 1 U T , which serves as the optimal weight matrix.
[0163] As an optimization of the above embodiment, step 5 involves selecting a detection quantity and a detection threshold, calculating the detection quantity and comparing them to complete the deception attack detection, including:
[0164] Define χ 2 Statistic:
[0165]
[0166] Where j is the detector window size, k is time, r(i) is the residual at time i, and χ is the value of the detector window. 2 (l) represents the chi-square distribution with l degrees of freedom, and Π is the covariance matrix of the residuals;
[0167] Select the threshold based on the chi-square distribution table. When the statistic is greater than the threshold, it means that an attack has been detected; when the statistic is less than the threshold, it means that no attack has been detected.
[0168] The expression is:
[0169]
[0170] Define the likelihood ratio detection quantity:
[0171]
[0172] Where, n r For the number of observations, For Π a The maximum likelihood estimate.
[0173]
[0174] Given a false alarm rate α, the detection threshold for likelihood ratio detection is calculated by a threshold learning algorithm, and the detection strategy is related to χ². 2 The detection is consistent, thus completing the detection of deception attacks.
[0175] The specific implementation method is as follows:
[0176] Consider a cyber-physical system with the following parameters:
[0177]
[0178] C a =C b =C s =I 3×3 ;
[0179] τ = 5, j = 3;
[0180] Q = R i =I 3×3 ,i∈{a,b,s};
[0181] When k∈[50,100], a deception attack is performed, χ 2 Changes in detection statistics, such as Figure 4 As shown, the simulation results of the detection rate are as follows: Figure 5 As shown in the figure, the proposed detection method based on multi-channel data correlation can achieve high-performance detection of deception attacks. Once the attack begins, the detection statistics rapidly increase to exceed the threshold, thus detecting the deception attack. Figure 5 As shown, the detection rate is significantly improved when the optimal matrix is set, which verifies the effectiveness of the optimal matrix design.
[0182] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A method for detecting deception attacks in an industrial cyber-physical system, characterized in that, Including the following steps: Step 1: Establish cyber-physical system models with data transmission channels of different security levels, establish a discrete linear time-invariant state-space model, and establish a description of the deception attack process under this model; Step 2: Establish a set of sparsely sampled secure data transmission channels and encrypt data in unreliable channels; including: To achieve deception attack detection, a set of secure transmission channels with sparse sampling periods is set up: y s (k i )=C s x(k i )+v s (k i ); Among them, y s and C s These are the measurement output and measurement matrix of the secure channel, respectively. s Here, x represents the system state, which is the new information. For the prior minimum variance error state estimate; k i (i = 0, 1, 2, ...) represents the time when data is transmitted via the secure channel, satisfying k i+1 =k i +τ, where τ is the sampling period; at each time point k = k i Data is transmitted through a secure channel s, and the data in the channel cannot be eavesdropped on or tampered with by attackers; The information acquired at each time point at both ends of the channel is defined as follows: Using secure channel data, data in unreliable channels is encrypted, making... z a This refers to information delivered through unreliable channels that can be eavesdropped on and tampered with. The covariance is: in, For new information z a covariance, For new information z s covariance, For new information z a With z s Covariance between For new information z s With z a Covariance between them; Step 3: Collect input and output data of the cyber-physical control system, and construct detection residuals based on the data correlation between different channels; Step 4: Quantify the residual changes caused by the deception attack, and establish the optimal weight matrix based on the residual changes to improve detection performance; Step 5: Set the detection strategy and detection threshold, calculate the detection statistics, and complete the deception attack detection.
2. The method for detecting deception attacks in an industrial cyber-physical system according to claim 1, characterized in that, In step 1, the cyber-physical system model with data transmission channels of different security levels is established as follows: Where k is time, x represents the system state, and y i The system measurement output is represented by the subscript i∈{a,b}, which indicates data transmission channels with different security levels. 'a' represents an unreliable channel that can be eavesdropped on and tampered with, and 'b' represents a reliable channel that can be eavesdropped on but cannot be tampered with. w(k) and v i (k) represent process noise and measurement noise, respectively; A and C i Given a matrix of a specified dimension, satisfying (A, C) i ) is detectable; Generate new information data for transmission Where i∈{a,b}, The prior minimum variance error state estimate is generated by a sequential Kalman filter.
3. The method for detecting deception attacks in an industrial cyber-physical system according to claim 2, characterized in that, In step 1, establishing the deception attack description includes: In cyber-physical control systems, attackers can construct attack vectors and inject them into unreliable channels by eavesdropping on data transmitted through both reliable and unreliable channels, thereby disrupting system state estimation. Malicious vectors constructed by the attacker: Where S(k) and T(k) are attack matrices with specified dimensions, and b(k) are independent and identically distributed Gaussian random vectors; the deception attack satisfies and They are respectively and z a The covariance.
4. The method for detecting deception attacks in an industrial cyber-physical system according to claim 1, characterized in that, In step 3, the input and output data of the cyber-physical control system are collected, and the detection residual is constructed based on the data correlation between different channels: Where W(k) represents the weight matrix, r(k) is the detection residual, and z e Encryption for transmission over the channel, For the new information acquired at each moment at both ends of the secure channel; The covariance matrix of the residuals is: in in, For new information z s covariance, To encrypt data z e covariance, For new information z a With z s Covariance between For new information z s With z a Covariance between For new information z s The covariance.
5. The method for detecting deception attacks in an industrial cyber-physical system according to claim 1, characterized in that, In step 4, the residual change caused by the spoofing attack is quantified, including the following steps: Based on the detection mechanisms in steps 2 and 3, the data and residuals under a deception attack are respectively represented as: in, For, r a (k) is an attack matrix with specified dimensions, and S(k) and T(k) are attack matrices with specified dimensions. a z represents information from an unreliable channel that can be eavesdropped on and tampered with. b Let b(k) represent the information of a reliable channel that can be eavesdropped on but cannot be tampered with, and let b(k) be an independent and identically distributed Gaussian random vector. This refers to the data acquired at each time point at both ends of the channel; The covariance matrix of the residuals after the attack is: in, in, For new information z s covariance, Encrypted data under attack covariance, For z a With z s Covariance between For new information z b With z s Covariance between them; The change in covariance caused by a deception attack is as follows: in Where I is the identity matrix.
6. The method for detecting deception attacks in an industrial cyber-physical system according to claim 5, characterized in that, Based on residual change analysis, an optimal weight matrix is designed to improve detection performance. A unified solution form is given based on two optimization indices, including the following steps: Let Π = WΣ r W T , Δ = Π - Π a = WΣ Δ W T ; Π is the covariance matrix of the residuals. a Let Σ be the covariance matrix of the residuals under attack. r for The covariance matrix, for The covariance matrix, Define the norm optimization metric: in, Covariance matrix The square root of; right Perform SVD decomposition to obtain: Where U and V are orthogonal matrices obtained from SVD decomposition, we have UU T =I and VV T =I, Λ is a diagonal matrix composed of singular values; U is The left singular vector matrix, V is The right singular vector matrix; Optimization problem The solutions and their maximum values are: W=Λ -1 U T ; in, The maximum value of J1 corresponding to the optimal point W; Set trace optimization metrics: Where tr represents finding the trace of a matrix; Optimization problem The solutions and their maximum values are: in, W is the maximum value of J2 corresponding to the optimal point W. i Yes (Σ) Δ ,Σ r The i-th largest generalized eigenvector of ) , λ i Yes (Σ) Δ ,Σ r The i-th largest eigenvalue of ). Based on the two optimization schemes described above, the optimization problem is... and The solution has a unified form W = Λ -1 U T , which serves as the optimal weight matrix.
7. The method for detecting deception attacks in an industrial cyber-physical system according to claim 1, characterized in that, In step 5, a detection quantity and a detection threshold are selected, and the detection quantity and threshold are compared to complete the deception attack detection, including: Define χ 2 Statistic: Where j is the detector window size, k is time, r(i) is the residual at time i, and χ 2 (l) represents the chi-square distribution with l degrees of freedom, and Π is the covariance matrix of the residuals; Select the threshold based on the chi-square distribution table. When the statistic is greater than the threshold, it means that an attack has been detected; when the statistic is less than the threshold, it means that no attack has been detected.