GNSS deception jamming detection method and system based on random forest
Through the GNSS spoofing interference detection method based on random forests, using parameters at different processing stages as features, the problems of high complexity of existing methods and failure of physical characteristics are solved, efficient and accurate GNSS spoofing interference detection is achieved, and a reference is provided for anti-spoofing strategies.
Patent Information
- Application Number
- CN202510175148.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-06
AI Technical Summary
The existing GNSS spoofing interference detection methods have problems such as high complexity, failure of physical meaning of sample characteristics, and poor interpretability of the model. It is difficult to achieve accurate GNSS spoofing interference detection without increasing costs.
The GNSS spoof interference detection method based on random forest is used, and the parameters of different processing stages are selected as features and a random forest model is established to detect GNSS spoof interference. This method does not require dimensionality reduction, the feature parameters maintain physical significance, and intuitively analyze the importance of each feature.
It realizes efficient and accurate detection of GNSS fraud interference without increasing equipment costs, has good generalization capabilities, and provides reference for in-depth understanding of fraud behavior and reasonable formulation of anti-spoofing strategies.
Smart Images

Figure CN120103374A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of GNSS spoofing interference detection, and in particular to a GNSS spoofing interference detection method and system based on random forest. Background Art
[0002] The Global Navigation Satellite System (GNSS) is an important national space infrastructure that can provide users with real-time spatiotemporal information and play an important role in many fields such as national defense security, social production, and residents' lives. With its advantages of all-weather and high precision, it has become an important guarantee for the development of modern society. However, GNSS signals have low transmission power, large propagation loss, and are easily interfered by other electromagnetic signals. There are certain vulnerabilities, which restrict its in-depth application in some key fields. Existing satellite navigation interference is divided into two categories: suppression interference and deception interference. Among them, deception interference is achieved by generating signals that are highly similar to real signals, or forwarding real signals to achieve deception, which is more concealed and more harmful. Most of the existing satellite navigation receiving terminals fully trust the received GNSS signals. If there are deception signals similar to real signals in space, the terminal will provide users with wrong positioning and timing information, which may cause serious consequences such as paralysis of social infrastructure and change of navigation carrier trajectory.
[0003] In recent years, the potential safety hazards caused by deception interference have become increasingly prominent. GNSS protection research has received much attention, and deception detection has become a key technology. Satellite signal encryption and authentication technology has a good effect in detecting civilian signal deception, but it requires overall modification and adjustment of the satellite navigation system, which is difficult to implement and has high implementation costs. When the receiver terminal is subjected to deception interference, signal characteristics such as absolute power, carrier-to-noise ratio, and automatic gain control (AGC) will change. Deception detection methods based on signal characteristics are more flexible, but are only applicable to scenarios where deception signals are significantly stronger than real signals. When the power of deception signals is similar to that of real signals, the accuracy of the detection results is not high. Signal Quality Monitoring (SQM) technology uses the output of the correlator to construct the detection quantity and detects deception by judging whether the correlation peak is distorted. This type of method is relatively simple and direct, easy to implement, but it is difficult to distinguish between multipath and deception interference. In order to finely classify the signal, some scholars have constructed and improved the detector, but it also increases the computational complexity. Satellite navigation signals contain multiple types of information, and the consistency between the information can be used to detect GNSS spoofing interference, such as the consistency between Doppler frequency and code delay rate, ephemeris consistency, navigation message consistency, etc. Under normal circumstances, the directions of satellite signals come from different sources, while spoofing signals are emitted from the same interference source. The spatial structure of the signal can be used as an effective basis for detecting spoofing interference, but it has high requirements for receivers, antennas, etc., which will increase hardware costs. For forwarding spoofing, the real signal and the spoofing signal can be distinguished by the signal arrival time (TOA), but there is a risk when the spoofing interference method is unknown. Inertial Navigation System (INS), accelerometers, visual cameras, altimeters and other autonomous navigation sensors can be immune to electromagnetic interference and provide auxiliary information when GNSS signals are spoofed. Based on auxiliary information, spoofing interference can be effectively detected, but it usually increases equipment costs, is difficult to promote in the civilian field, and has a limited scope of application. Multi-frequency and multi-system receivers can provide redundant observations, which can be used to cross-validate the detection of GNSS spoofing interference, but it will also increase user costs and is only applicable to situations where there are fewer spoofing signals, otherwise misjudgment will occur.
[0004] Artificial intelligence technology has developed rapidly and has gradually become a research hotspot in various disciplines and fields. Some scholars have introduced machine learning methods into GNSS spoofing detection. Ebrahim et al. proposed a multi-layer neural network GPS spoofing detection method and proved the superiority of the method through simulation experiments. Li et al. introduced the KNN classification algorithm to detect short-delay spoofing. Silvio et al. introduced the supervised machine learning method to detect GNSS spoofing interference, and verified the detection performance of the support vector machine (SVM) using simulation data and measured data. Zhu et al. used SVM to detect spoofing based on improved SQM-MV, SQM-MA, early and late code phase, carrier-to-noise ratio moving variance, and receiver clock drift. Chen et al. used the SQM method to detect spoofing in combination with multiple parameters, and achieved better results than the traditional single parameter detection method in complex spoofing scenarios. Zuo et al. used the Isolation Forest algorithm to analyze the aggregation of data in satellite observation files to detect spoofing interference, achieving an accuracy rate of up to 95%. Fargana et al. developed a GPS spoofing jamming detection method for unmanned aerial vehicles (UAVs) based on convolutional neural networks (CNN), and applied it to two different types of UAVs to achieve high-precision detection. To overcome the shortcomings of a single classifier, Sun et al. proposed a GPS spoofing jamming detection method with decision fusion, which achieved a single detection effect that was superior to that of SVM, probabilistic neural networks (PNN) and decision trees. As a data-driven method, machine learning has the ability to automatically learn rules from data. Machine learning modeling can establish the intrinsic relationship between feature parameters and whether there is deception. Large numbers of high-quality data sets can usually improve the performance of the model, but they will also increase complexity and reduce practicality. Some GNSS spoofing jamming detection studies based on machine learning reduce the dimensionality of the data through preprocessing. PCA is a commonly used dimensionality reduction method that can transform the feature projection to a new space to reduce data redundancy, but the features will lose their physical meaning after the transformation. In addition, the intrinsic relationship between the data established by machine learning is usually not directly displayed, and this information is of reference value for deception impact analysis and anti-deception strategy formulation. Summary of the invention
[0005] To this end, the present invention provides a GNSS spoofing interference detection method and system based on random forest, which effectively improves the existing GNSS spoofing interference detection based on machine learning, such as high complexity, failure of physical meaning of sample features, and weak model interpretability. By selecting parameters at different processing stages as features and establishing a random forest model to detect GNSS spoofing interference, a reference is provided for in-depth understanding of deception behavior and reasonable formulation of anti-spoofing strategies.
[0006] According to the design scheme provided by the present invention, on the one hand, a GNSS spoofing interference detection method based on random forest is provided, comprising:
[0007] The data of three different deception scenarios in the OAKBAT deception dataset were selected, and the original high-fidelity intermediate frequency signal files were processed by a GNSS software receiver to extract the parameters of different processing stages as features. Sample labels were added according to the time when the deception occurred in each scenario, and the labeled sample data were divided into a training set for modeling training and a test set for test verification according to a preset ratio. The features of different processing stages include: signal processing stage features, original observation features, and PVT solution result features;
[0008] The GNSS spoofing interference detection is regarded as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals. The training set is used to model and train the random forest classifier, and the test set is used to test and verify the trained random forest classifier.
[0009] The constructed random forest classifier is used to detect the GNSS signal to be detected to determine whether there is a deception interference signal in the GNSS signal to be detected.
[0010] As a GNSS spoofing interference detection method based on random forest in the present invention, further, OAKBAT spoofing datasets of different scenarios are selected and the original data are processed, including:
[0011] The datasets of three timing spoofing scenarios, os2, os3 and os5, were used to model and verify GNSS spoofing detection.
[0012] Process the raw high-fidelity IF signal files using GNSS receiver software.
[0013] As the GNSS spoofing interference detection method based on random forest of the present invention, further, parameters of different processing stages are extracted as sample features, including:
[0014] The SQM-ELP index is calculated according to the leading and lagging output phase differences of the in-phase branch and the quadrature branch, and the SQM-ELP index is used as a feature of the signal processing stage;
[0015] Extracting three parameters, namely, carrier-to-noise ratio, pseudorange and Doppler frequency shift, as original observation features, wherein the carrier-to-noise ratio is used to represent the channel tracking signal strength;
[0016] The clock error and clock drift parameters are extracted as the characteristics of the PVT solution results.
[0017] The signal processing stage characteristics and the original observation quantity characteristics are single-channel processing parameters, which only reflect the characteristics of a single channel; the PVT solution result characteristics are overall solution parameters, which reflect the overall characteristics.
[0018] As a GNSS spoofing interference detection method based on random forest of the present invention, further, a random forest classifier is modeled and trained using a training set, including:
[0019] Assume that the training set contains N samples, each sample contains M features, and perform replacement sampling on the sample data in the training set to obtain multiple training subsets;
[0020] A corresponding decision tree is constructed for each training subset. When a tree node needs to be split, m features are randomly selected, and all decision trees together form a random forest.
[0021] As the GNSS spoofing interference detection method based on random forest of the present invention, further, the random forest classifier after modeling training is tested and verified using a test set, including:
[0022] The samples in the test set are input into the trained random forest classifier. The decision trees in the random forest independently judge and vote on whether the GNSS signal is subject to spoofing interference. The category with the most votes is taken as the final category and output.
[0023] Compare the true labels of the samples in the test set with the predicted labels output by the random forest classifier, and divide the test set detection results into true positive, false negative, false positive, and true negative.
[0024] Construct a confusion matrix based on the segmentation results, evaluate and visualize the classification results, and further evaluate the importance of each feature in deception detection;
[0025] Evaluate the importance of features in GNSS spoofing detection modeling based on the Gini index;
[0026] As the GNSS spoofing interference detection method based on random forest of the present invention, further, the classification result of the random forest classifier is evaluated according to the confusion matrix, including:
[0027] Calculate the model evaluation index of the random classifier according to the confusion matrix, wherein the model evaluation index includes accuracy, precision, recall rate and F1 score;
[0028] As a GNSS spoofing interference detection method based on random forests of the present invention, further, the importance of features in GNSS spoofing detection modeling is evaluated according to the Gini index, including:
[0029] The Gini index of the node is obtained based on the probability of the category to which the sample data belongs in the corresponding node, and the change in the Gini index before and after the node branching is calculated based on the Gini index of the node and the Gini index of the new node after the node splits;
[0030] The importance of the feature in the decision tree is calculated based on the number of times the feature appears in the decision tree and the change in the Gini index before and after the node branching, and the importance of the feature in the random forest is obtained based on the importance of the feature in the decision tree.
[0031] On the other hand, the present invention also provides a GNSS spoofing interference detection system based on random forest, comprising: a sample construction module, a classifier modeling module and a target detection module, wherein:
[0032] The sample construction module selects data from three different deception scenarios in the OAKBAT deception dataset, uses a GNSS software receiver to process the original high-fidelity intermediate frequency signal file, extracts parameters at different processing stages as sample features, adds sample labels according to the time when the deception occurs in each scenario, and divides the labeled sample data into a training set for modeling training and a test set for test verification according to a preset ratio. The features of the different processing stages include: signal processing stage features, original observation features, and PVT solution result features;
[0033] The classifier modeling module is used to classify GNSS spoofing interference detection as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals, and use the training set to model and train the random forest classifier, and use the test set to test and verify the trained random forest classifier;
[0034] The target detection module is used to detect the GNSS signal to be detected using the constructed random forest classifier to determine whether there is a deception interference signal in the GNSS signal to be detected.
[0035] Beneficial effects of the present invention:
[0036] The present invention uses a software-defined radio receiver to process intermediate frequency data, selects parameters at different data processing stages as input features, constructs a random forest classifier, and realizes accurate and effective detection of GNSS deception interference. Experiments have proved that the scheme of this case has high efficiency and good generalization ability. No preprocessing such as dimensionality reduction is required during data processing, and the feature parameters can maintain their own physical meaning, and then intuitively analyze the importance of each feature in the modeling process, providing a reference for in-depth understanding of deception behavior and rational formulation of anti-deception strategies, and has good application prospects in the field of GNSS deception interference detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 This is a schematic diagram of a GNSS spoofing interference detection process based on random forest in an embodiment;
[0038] Figure 2 It is a schematic diagram of the confusion matrix in the embodiment;
[0039] Figure 3 This is a schematic diagram of the importance ratio of the os2 scene features in the embodiment;
[0040] Figure 4 This is a schematic diagram of the importance ratio of os3 scene features in the embodiment;
[0041] Figure 5 The figure is a schematic diagram of the importance ratio of the os5 scene features in the embodiment. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and technical solutions.
[0043] The GNSS spoofing interference detection method based on signal encryption and authentication technology requires overall modification and adjustment of the satellite navigation system system, which is difficult to implement and has high implementation costs. The GNSS spoofing interference detection method based on signal characteristics is more flexible, but it is only applicable to scenarios where the spoofing signal is significantly stronger than the real signal. The GNSS spoofing interference detection method based on the signal spatial structure has high requirements for receivers, antennas, etc., which will increase hardware costs. The GNSS spoofing interference detection method based on external equipment assistance will usually also increase costs. Most existing methods use a single parameter to detect spoofing interference.
[0044] Machine learning has the ability to automatically learn patterns from data and can combine multiple parameters to implement GNSS spoofing interference detection without increasing costs. In existing studies, when using machine learning to detect spoofing interference, most of them require preprocessing such as normalization and dimensionality reduction of features. PCA is a commonly used dimensionality reduction method that can project feature parameters into a new space to reduce data redundancy, but it will cause the features to lose their original physical meaning, making it impossible to intuitively express the relationship between feature parameters and GNSS spoofing interference.
[0045] An embodiment of the present invention provides a GNSS spoofing interference detection method based on random forest, comprising:
[0046] S101. Select data from three different deception scenarios in the OAKBAT deception dataset, use a GNSS software receiver to process the original high-fidelity intermediate frequency signal file, extract parameters at different processing stages as sample features, add sample labels according to the time when deception occurs in each scenario, and divide the labeled sample data into a training set for modeling training and a test set for test verification according to a preset ratio. The characteristics of the different processing stages include: signal processing stage characteristics, original observation quantity characteristics, and PVT solution result characteristics.
[0047] Among them, processing public deception datasets may include:
[0048] A GNSS software-defined radio (SDR) receiver is used to process the original high-fidelity digital real-time intermediate frequency signal files of the OAKBAT dataset, capture and track the intermediate frequency signals, obtain the original observations, and solve the PVT information.
[0049] Among them, the parameters of different processing stages are taken as sample features, which can be designed to include:
[0050] The SQM-ELP index is extracted according to the phase difference between the leading and lagging outputs of the in-phase branch and the quadrature branch, and the SQM-ELP parameter is used as the signal processing stage feature;
[0051] Extracting the carrier-to-noise ratio, pseudorange and Doppler shift, and using the three parameters of carrier-to-noise ratio, pseudorange and Doppler shift as original observation features, wherein the carrier-to-noise ratio is used to represent the channel tracking signal strength;
[0052] Based on the GNSS spoofing signal and the specified positioning equation, PVT solution is performed to obtain the corresponding clock error and clock drift, and the clock error and clock drift are used as the characteristics of the PVT solution result.
[0053] S102. GNSS spoofing interference detection is regarded as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals, and a random forest classifier is modeled and trained using a training set, and the random forest classifier after modeling and training is tested and optimized using a test set.
[0054] GNSS spoofing interference detection can be regarded as a binary classification problem. When there is no spoofing interference, there are only real signals, which are defined as the positive class "0". When there is spoofing interference, there are spoofing signals mixed in, which are defined as the negative class "1".
[0055]
[0056] like Figure 1 As shown in the figure, the parameters of different data processing stages are extracted as input features, and a random forest classification detector is constructed to determine whether the GNSS signal is subject to deception interference.
[0057] Random forest is composed of multiple decision trees. It is an ensemble learning algorithm that can overcome the instability of a single estimator and achieve parallel operation. Random forest generates training data and builds trees through random sampling with replacement. There is no correlation between different decision trees, and each tree randomly selects attributes for splitting.
[0058] Specifically, the training set is used to model and train the random forest classifier, which can be designed to include:
[0059] Assume that the training set contains N samples, each sample contains M features, and perform replacement sampling on the sample data in the training set to obtain multiple training subsets;
[0060] A corresponding decision tree is constructed for each training subset. When a tree node needs to be split, m features are randomly selected, and all decision trees together form a random forest.
[0061] The decision trees in the random forest make judgments and vote, and the category with the most votes is used as the final output. The implementation process of the random forest classification algorithm can be summarized as follows:
[0062] Step 1: Suppose there is a sample data set X=[x 1 ,x 2 ,x 3 ,…,x N ] T , each sample x i There are M features. Sample X is sampled N times with replacement, and 1 sample is drawn each time to obtain a training subset A of size N, which may contain repeated samples.
[0063] Step 2: Use training subset A to build decision tree f A(x), when the tree node needs to be split, m features are randomly selected, m<M. The decision tree outputs the judgment category y=f A (x),y∈{1,2,…,C}, where C is the total number of possible categories.
[0064] Step 3: Repeat Step 1 and Step 2 to build K decision trees {f A1 (x),f A2 (x),…f AK (x)}, forming a random forest of size K.
[0065] Step 4: Random forest classification results of all decision trees {y 1 ,y 2 ,…,y K} Perform majority voting and take the category with the most votes as the final output Y.
[0066] S103: Use the constructed random forest classifier to detect the GNSS signal to be detected to determine whether there is a deception interference signal in the GNSS signal to be detected.
[0067] GNSS signal data collected in real scenarios are costly and prone to errors. To facilitate the development of various scientific research, many organizations have created standard datasets for GNSS spoofing signals and made them publicly available to users. The TEXBAT dataset is currently widely used, which contains GPS L1 data for 8 different spoofing scenarios and 2 non-spoofing scenarios, providing important support for related research on GNSS spoofing. Afterwards, the OAKBAT dataset reproduced the first 6 spoofing scenarios of TEXBAT, and added data from Galileo E1 in the corresponding scenarios, recording more detailed and accurate data information, which is a further enrichment and supplement to the TEXBAT dataset. In the present embodiment, the OAKBAT dataset can be used for GNSS spoofing detection experiments, and its high-fidelity data files can be obtained through the open source website.
[0068] The sampling rate of the OAKBAT data set is 5MHz, os1a, os2-os6 are the GPS L1 signal data corresponding to the first 6 scenarios of TEXBAT, and os9a, os10-os14 are the corresponding Galileo E1 signal data. Among them, the first 4 deception scenarios are static, and the 5th and 6th deception scenarios are static. In addition, the 2nd, 3rd, and 5th scenarios are timing deception, and the 4th and 6th scenarios are location deception. In this embodiment, the GPS L1 signal data of the three timing deception scenarios os2, os3 and os5 are selected to carry out experiments. The specific description of each scenario is shown in Table 1 below:
[0069] Table 1. Description of the dataset deception scenarios
[0070]
[0071]
[0072] The GNSSSDR receiver developed by the GNSS laboratory is publicly available to users and has been widely used in many research works. In this embodiment, the publicly available receiver can be used as the basis for processing the spoofing data set, and the six parameters of signal quality monitoring (SQM) index ELP, carrier-to-noise ratio C / N0, original observation pseudorange, Doppler frequency shift, PVT solution clock error, and clock drift are extracted as features of random forest modeling.
[0073] SQM detects anomalies in GNSS signals by identifying the distortion of correlation peaks. Ratio, Delta, and ELP are commonly used metrics, which are defined as:
[0074]
[0075]
[0076]
[0077] Where I E,k (n), I P,k (n) and I L,k (n) are the leading, immediate and lagging outputs of the in-phase branch at discrete time n, respectively; Q E,k (n), Q P,k (n) and Q L,k (n) are the leading, immediate and delayed outputs of the orthogonal branch at discrete time n, respectively. k is the correlator interval in chips.
[0078] The Delta indicator determines the symmetry of the correlation peak by comparing whether the leading and lagging outputs of the in-phase branch are equal. Under normal circumstances, the Delta mean is 0. The Ratio indicator determines whether the correlation peak is distorted by comparing the ratio of the leading and lagging outputs of the in-phase branch to the instantaneous output. Under normal circumstances, the value of Ratio is around 0.5. Both the Delta and Ratio metrics only use the output of the in-phase branch, and do not use the output of the quadrature branch. The ELP metric uses the indicators of both the in-phase and quadrature branches to detect deception based on the phase difference between the leading and lagging outputs. In this embodiment of the case, the ELP indicator is selected as one of the features of random forest modeling.
[0079] Carrier-to-noise ratio C / N 0It can reflect the strength of the channel tracking signal and can be estimated by calculating the accumulated value of the I and Q branches after despreading. It is an important indicator for GNSS signal deception detection. In this embodiment, the variance summing method (VSM) is used to calculate C / N 0 , and used it as one of the features for random forest modeling.
[0080] Pseudorange and Doppler frequency shift are the original observations of positioning and velocity measurement respectively. These two parameters are added to the indicators of random forest modeling. GNSS receiver deception will directly affect the PVT solution results. The clock error and clock drift are also used as the indicators of random forest modeling. Among the six selected indicators, SQM-ELP, C / N 0 , pseudorange, and Doppler shift can be considered as individual channel parameters, while clock error and clock drift are the overall solution results. The characteristic parameters selected for GNSS deception interference modeling are summarized in Table 2:
[0081] Table 2 Summary of selected characteristic parameters
[0082]
[0083] The sampling time of each scene in the OAKBAT dataset is 480s, and the deception starts at 121s. After being processed by the GNSS software receiver, a sample is extracted every 1ms from 11s to 475s, all feature values are calculated, and a label is added based on whether it is deceptive at that moment. Each deception scene generates 465,000 samples. Random forest modeling does not require data dimensionality reduction, and all samples are divided into 70% training set and 30% test set. The training set samples are used for random forest modeling. After the model is established, the test set features are used as input to determine whether deception occurs.
[0084] Among them, the test set is used to test and verify the random forest classifier after modeling and training, which can be designed to include:
[0085] The samples in the test set are input into the trained random forest classifier, and the decision tree in the random forest classifier is used to judge and vote on the binary classification problem of GNSS spoofing interference detection. The category with the most votes is taken as the final category and output;
[0086] The non-deceived GNSS signal data is taken as the positive class, and the deceiving GNSS signal data is taken as the negative class. The test set detection results are divided into true positive class, false negative class, false positive class, and true negative class by comparing the true labels of the samples in the test set and the predicted labels output by the random forest classifier.
[0087] Construct a confusion matrix based on the segmentation results, and use the confusion matrix to evaluate and visualize the classification results;
[0088] The importance of features in GNSS spoofing detection modeling is evaluated based on the Gini index.
[0089] Specifically, the confusion matrix is used to evaluate the classification results, which may include:
[0090] Calculate the model evaluation index of the random forest classifier according to the confusion matrix, wherein the model evaluation index includes accuracy, precision, recall rate and F1 score;
[0091] Confusion matrix is often used to evaluate classification models and can visualize the classification results. For a binary classification problem, the confusion matrix can be expressed as follows: Figure 2 As shown. The satellite signal data that has not been deceived is used as the positive class, and the satellite signal data that has been deceived is used as the negative class. Based on the confusion matrix, a variety of model evaluation indicators can be calculated. Accuracy, precision, recall and F1 score are commonly used indicators, which are defined as:
[0092]
[0093]
[0094]
[0095]
[0096] Accuracy is the ratio of samples correctly classified by the model to the total number of samples. The higher the accuracy, the better the model performance. Precision is the ratio of samples that are actually positive among the samples judged as positive by the model. Generally, the higher the accuracy, the better the model performance. Recall is the ratio of the number of positive samples identified by the model to the total number of positive samples. The higher the recall, the better the model performance. The F1 score is the harmonic mean of precision and recall. The closer its value is to 1, the better the model performance.
[0097] The importance scores of sample features are calculated based on the random forest classifier and the Gini index.
[0098] The Gini index of the node is obtained based on the probability of the category to which the sample data belongs in the corresponding node, and the change in the Gini index before and after the node branching is calculated based on the Gini index of the node and the Gini index of the new node after the node splits;
[0099] The importance of the feature in the decision tree is calculated based on the number of times the feature appears in the decision tree and the change in the Gini index before and after the node branching, and the importance of the feature in the random forest is obtained based on the importance of the feature in the decision tree.
[0100] In the random forest algorithm, feature importance can be evaluated, and variable importance measures (VIM) can be given while analyzing data. In this embodiment, the Gini index is used to calculate VIM.
[0101] Statistics It represents the average change in node split impurity of the jth variable in all trees of the random forest. The calculation formula of the Gini index is:
[0102]
[0103] Among them, K is the number of categories in the self-service sample set, is the estimated probability that the sample at node m belongs to the kth class. When the sample is binary data (K=2), the Gini index of node m is:
[0104]
[0105] is the probability estimate of the sample belonging to any class at node m. j The importance of node m, that is, the change in Gini index before and after node m branching is:
[0106]
[0107] GI l and GI r They represent the Gini index of the two new nodes split by node m. j appears M times in the i-th tree, then the variable X j The importance of the i-th tree is:
[0108]
[0109] VARIABLE X j The Gini importance in random forest is defined as:
[0110]
[0111] Here, n is the number of classification trees in the random forest.
[0112] The classification model established by random forest is used to evaluate the characteristic parameters of each input, and the importance of each feature in the GNSS spoofing interference detection modeling process is intuitively given, providing a reference for in-depth understanding of deception behavior and reasonable formulation of anti-spoofing strategies.
[0113] Furthermore, based on the above method, an embodiment of the present invention also provides a GNSS spoofing interference detection system based on random forest, comprising: a sample construction module, a classifier modeling module and a target detection module, wherein:
[0114] The sample construction module selects data from three different deception scenarios in the OAKBAT deception dataset, uses a GNSS software receiver to process the original high-fidelity intermediate frequency signal file, extracts parameters at different processing stages as sample features, adds sample labels according to the time when the deception occurs in each scenario, and divides the labeled sample data into a training set for modeling training and a test set for test verification according to a preset ratio. The features of the different processing stages include: signal processing stage features, original observation features, and PVT solution result features;
[0115] The classifier modeling module is used to classify GNSS spoofing interference detection as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals, and use the training set to model and train the random forest classifier, and use the test set to test and verify the trained random forest classifier;
[0116] The target detection module is used to detect the GNSS signal to be detected using the constructed random forest classifier to determine whether there is a deception interference signal in the GNSS signal to be detected.
[0117] In order to verify the effectiveness of this solution, the following is a further explanation based on experimental data:
[0118] Without increasing the cost of equipment, we fully utilized the existing information, deeply explored the intrinsic relationship between the data, and used random forest to build a classifier. In the three deception scenarios of os2, os3, and os5, we achieved high-accuracy and high-efficiency GNSS deception interference detection. The detection results of each scenario are shown in Tables 3 to 5, and the corresponding feature importance evaluation results are shown in Tables 3 to 5. Figure 3-Figure 5 .
[0119] Table 3. Random forest modeling deception detection results for os2 scenarios
[0120]
[0121]
[0122] The os2 scenario is static time deception, the deviation time is 2ms, and the power advantage of the deception signal is 10dB. Table 3 shows the evaluation results of random forest modeling for deception detection in this scenario. The accuracy, precision, recall and F1 score in the table are all above 99%, indicating that the results of random forest modeling for deception detection in this scenario are highly reliable. Figure 3It is the feature importance of the model corresponding to Table 3. As can be seen from the figure, the feature importance of different channels is different, but overall, the importance of pseudorange (PreR), carrier-to-noise ratio (C / N0), and clock difference (Dt) accounts for the highest proportion, and the cumulative importance of the three can reach more than 90%.
[0123] Table 4. Random forest modeling deception detection results for os3 scenarios
[0124]
[0125] The os3 scenario is also a static time deception with a deviation time of 2ms, but the power advantage of the deception signal is only 1.3dB. Table 4 shows the model evaluation results for this scenario. The accuracy, precision, recall and F1 score of the model in detecting deception are all above 99%. Figure 4 is the feature importance corresponding to Table 4. The importance of modeling pseudorange in this deception scenario is the highest, about 70% to 80%. The importance of clock difference ranks second, about 20%. The power advantage of the deception signal in this scenario is not obvious, and the importance of carrier-to-noise ratio is less than 10%.
[0126] Table 5. Random forest modeling deception detection results for os5 scenarios
[0127]
[0128] The os5 scenario is dynamic time deception, the deviation time is 2ms, and the power advantage of the deception signal is 9.9dB. Table 5 shows the evaluation results of the three models for deception detection in this scenario. The accuracy, precision, recall and F1 score in the table are all higher than 99%. Figure 5 It is the feature importance of the model corresponding to Table 5. Overall, the importance of carrier-to-noise ratio, pseudorange and clock difference is relatively high, but there are differences in the ranking of the feature importance of each channel. GPS-14, GPS-25, and GPS-27 channels all have the highest importance of clock difference, carrier-to-noise ratio is the second, and pseudorange is the third. The importance of pseudorange and clock difference in GPS-11 and GPS-24 channels is similar, and the carrier-to-noise ratio is slightly lower than pseudorange and clock difference. The importance of these three special types ranks in the top three. The importance of pseudorange in GPS-20 channel is the highest, the importance of clock difference is the second, and the carrier-to-noise ratio is the third.
[0129] The above results show that the accuracy, precision, recall and F1 score of random forest modeling for detecting GNSS spoofing interference are all above 99%. The sample data volume used for modeling of the three spoofing scenarios is 465000 (ms) × 6 (features), and the time to complete modeling and classification detection is 46.11s, 51.43s, and 42.67s. The GNSS spoofing interference detection method based on random forest achieves high reliability while also ensuring high efficiency. There are differences in the importance of features obtained from modeling different scenarios, which can provide an important reference for understanding different deception behaviors and formulating corresponding reasonable countermeasure strategies.
[0130] To further verify the performance of the random forest method in GNSS spoofing interference detection, the experiment merged the three single-scenario data sets mentioned above and conducted a multi-scenario spoofing detection experiment. The detection results are shown in Table 6.
[0131] Table 6 Multi-scenario random forest modeling deception detection results
[0132]
[0133] As can be seen from Table 6, the spoofing detection accuracy, precision, recall rate and F1 score of multi-scenario modeling are all above 99%. This shows that the GNSS spoofing interference detection method based on random forest has good effectiveness, efficiency and generalization ability. In addition, the feature importance evaluation results directly provided by the random forest method have important reference value for related research on spoofing and anti-spoofing.
[0134] Unless otherwise specifically stated, the relative steps, numerical expressions and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0135] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0136] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.
[0137] Those skilled in the art will appreciate that all or part of the steps in the above method can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk or an optical disk. Optionally, all or part of the steps in the above embodiment can also be implemented using one or more integrated circuits, and accordingly, each module / unit in the above embodiment can be implemented in the form of hardware or in the form of software function modules. The present invention is not limited to any specific form of combination of hardware and software.
[0138] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A GNSS spoofing interference detection method based on random forest, characterized in that: Include: The OAKBAT spoofing datasets of three different scenarios were selected, and the high-fidelity data files were processed by GNSS software receivers. The parameters of different processing stages were extracted as sample features. Sample labels were added according to the time when the spoofing occurred in each scenario, and the labeled sample data were divided into a training set for modeling training and a test set for test verification according to a preset ratio. The features of different processing stages include: signal processing stage features, original observation features, and PVT solution result features. The GNSS spoofing interference detection is regarded as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals. The training set is used to model and train the random forest classifier, and the test set is used to test and verify the trained random forest classifier. The random forest classifier verified by the test is used to detect the GNSS signal to be detected to determine whether there is a deception interference signal in the GNSS signal to be detected.
2. The GNSS spoofing interference detection method based on random forest according to claim 1, characterized in that: Use GNSS software receiver to process high-fidelity data files, including: The original high-fidelity data files of the OAKBAT dataset are processed using GNSS receiver software to capture and track the intermediate frequency signals, obtain the original observations, and solve the PVT information.
3. The GNSS spoofing interference detection method based on random forest according to claim 1, characterized in that: Extract parameters at different processing stages as sample features, including: The SQM index ELP is extracted according to the phase difference between the leading and lagging outputs of the in-phase branch and the quadrature branch, and the SQM-ELP parameter is used as the signal processing stage feature; Extracting three parameters, namely, carrier-to-noise ratio, pseudorange and Doppler frequency shift, as original observation features, wherein the carrier-to-noise ratio is used to represent the channel tracking signal strength; Extract the clock error and clock drift parameters as the characteristics of PVT solution results; Among them, the signal processing stage characteristics and the original observation quantity characteristics are both single-channel processing parameters, and the single-channel processing parameters are used to reflect the characteristics of a single channel; the PVT solution result characteristics are the overall solution parameters of the GNSS signal, and the overall solution parameters are used to reflect the overall characteristics of the GNSS signal.
4. The GNSS spoofing interference detection method based on random forest according to claim 1, characterized in that: Use the training set to model and train the random forest classifier, including: Assume that the training set contains N samples, each sample contains M features, and perform replacement sampling on the sample data in the training set to obtain multiple training subsets; A corresponding decision tree is constructed for each training subset. When a tree node needs to be split, m features are randomly selected, and all decision trees together form a random forest.
5. The GNSS spoofing interference detection method based on random forest according to claim 1, characterized in that: Use the test set to test and verify the random forest classifier after modeling training, and evaluate the importance of each feature in the modeling process, including: The samples in the test set are input into the trained random forest classifier. The decision trees in the random forest independently judge and vote on whether the GNSS signal is subject to spoofing interference. The category with the most votes is taken as the final category and output. By comparing the true labels of the samples in the test set and the predicted labels output by the random forest classifier, the test set detection results are divided into true positive, false negative, false positive, and true negative. Construct a confusion matrix based on the segmentation results, and use the confusion matrix to evaluate and visualize the classification results; The importance of features in GNSS spoofing detection modeling is evaluated based on the Gini index.
6. The random forest-based GNSS spoofing interference detection method according to claim 5, characterized in that: The classification results of the random forest classifier are evaluated based on the confusion matrix, including: The model evaluation indicators of the random classifier are calculated based on the confusion matrix, and the model evaluation indicators include accuracy, precision, recall rate and F1 score.
7. The random forest-based GNSS spoofing interference detection method according to claim 5, characterized in that: The Gini index is used to evaluate the importance of features in GNSS spoofing detection modeling, including: The Gini index of the node is obtained based on the probability of the category to which the sample data belongs in the corresponding node, and the change in the Gini index before and after the node branching is calculated based on the Gini index of the node and the Gini index of the new node after the node splits; The importance of the feature in the decision tree is calculated based on the number of times the feature appears in the decision tree and the change in the Gini index before and after the node branching, and the importance of the feature in the random forest is obtained based on the importance of the feature in the decision tree.
8. A GNSS spoofing interference detection system based on random forest, characterized in that: Contains: sample construction module, classifier modeling module and target detection module, among which, The sample construction module selects data from three different deception scenarios in the OAKBAT deception dataset, uses a GNSS software receiver to process the original high-fidelity intermediate frequency signal file, extracts parameters at different processing stages as sample features, adds sample labels according to the time when the deception occurs in each scenario, and divides the labeled sample data into a training set for modeling training and a test set for test verification according to a preset ratio. The features of the different processing stages include: signal processing stage features, original observation features, and PVT solution result features; The classifier modeling module is used to classify GNSS spoofing interference detection as a binary classification problem of non-spoofed interference signals and mixed spoofing interference signals, and use the training set to model and train the random forest classifier, and use the test set to test and verify the trained random forest classifier; The target detection module is used to detect the GNSS signal to be detected using the constructed random forest classifier to determine whether there is a deceptive interference signal in the GNSS signal to be detected.
9. An electronic device, characterized in that: include: at least one processor, and a memory coupled to the at least one processor; The memory stores a computer program, and the computer program can be executed by the at least one processor to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 can be implemented.
Citation Information
Cited By
Anti-deception and anti-interference satellite positioning safety protection method
CN121956047A
Navigation satellite positioning result identification method and device, equipment and storage medium
CN122151127A