UAV GPS spoofing attack detection method and equipment based on contrastive learning and Mamba
By using a dual-branch model based on contrastive learning and Mamba, and leveraging the shared weights of the dual-branch Mamba model to extract features from the time and frequency domains, this approach addresses the issues of strong dependence on labeled samples and low efficiency in long sequence modeling in UAV GPS spoofing attack detection, achieving efficient and robust detection in complex scenarios.
Patent Information
- Application Number
- CN202511062065.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-07-31
AI Technical Summary
Existing methods for detecting drone GPS spoofing attacks are highly dependent on labeled samples, have low efficiency in long sequence modeling, and lack robustness in complex scenarios.
A dual-branch model based on contrastive learning and Mamba is adopted. The UAV GPS navigation data is preprocessed and frequency domain transformed. The dual-branch Mamba model with shared weights is used to extract features from both time and frequency domain perspectives. Spoofing attacks are detected by spoofing scores. The self-supervised learning strategy is combined to reduce the dependence on labeled samples.
While reducing reliance on labeled samples, it improves the accuracy and robustness of detecting UAV GPS spoofing attacks and adapts to real-time detection capabilities in complex scenarios.
Smart Images

Figure CN120559680B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of unmanned aerial vehicle (UAV) navigation security monitoring technology, and in particular to a method and device for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba. Background Art
[0002] In recent years, drones have been widely used in environmental monitoring, logistics delivery, and emergency rescue, and the security of their navigation systems has increasingly attracted attention. While the Global Positioning System (GPS), upon which drones rely for flight, boasts advantages such as global coverage, low power consumption, and strong real-time performance, its weak signal strength and high vulnerability make it highly susceptible to human interference, particularly the threat of "GPS spoofing attacks." These attacks transmit forged GPS signals, inducing drones to misjudge their current position and flight direction, and even achieving complete control over their flight path. This can lead to mission failure, crashes, and even safety hazards, making it highly covert and dangerous.
[0003] While some current detection methods have achieved good results, they still have significant limitations when facing complex terrain environments and novel attack methods. On the one hand, many methods rely on manually designed rules or statistical features, which are insufficiently adaptable to attack patterns and prone to failure in unstructured or dynamically changing scenarios. On the other hand, detection models based on traditional supervised learning usually require a large number of labeled deception samples for training, but in practical applications, such samples are difficult to obtain, and attack methods are highly uncertain, resulting in limited model generalization ability. In addition, GPS navigation data is inherently a type of high-dimensional, multivariate, and long-term dependent time-series data. Conventional time-series modeling methods, such as Recurrent Neural Networks (RNNs), Long Short-Term Memory (LSTM) networks, and Convolutional Neural Networks (CNNs), struggle to balance modeling capability and computational efficiency, especially under high-frequency sampling conditions, which place significant pressure on real-time processing.
[0004] Therefore, existing technologies have not yet effectively solved the problems of strong dependence on labeled samples, low efficiency in long sequence modeling, and insufficient robustness in detection under complex scenarios. Summary of the Invention
[0005] This invention provides a method and device for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba, in order to solve the problems of existing UAV GPS spoofing attack detection schemes, such as strong dependence on labeled samples, low efficiency of long sequence modeling, and insufficient robustness in complex scenarios.
[0006] In a first aspect, embodiments of the present invention provide a method for detecting drone GPS spoofing attacks based on contrastive learning and Mamba, including:
[0007] The navigation data of the UAV's GPS is acquired, the navigation data is preprocessed to generate multiple trajectory subsequences with a fixed window length to obtain initial time domain data, and the navigation data is frequency domain transformed to obtain initial frequency domain data.
[0008] The initial time-domain data and the initial frequency-domain data are input into the trained dual-branch Mamba model for feature extraction, and the time-domain features and frequency-domain features are output respectively.
[0009] The deception score is calculated based on the time-domain features and the frequency-domain features, and the detection result of the deception attack behavior is determined based on the deception score.
[0010] In this dual-branch Mamba model, the two branches share weights; the dual-branch Mamba model is trained based on a contrastive learning strategy.
[0011] In one possible implementation, the dual-branch Mamba model includes a sequentially connected instance normalization module, a one-dimensional convolution module, and a Mamba module;
[0012] The instance normalization module takes the initial time-domain data and the initial frequency-domain data as inputs and outputs the normalized time-domain data and frequency-domain data as outputs.
[0013] The input to the one-dimensional convolution is normalized time-domain data and frequency-domain data, and the output is intermediate time-domain data and intermediate frequency-domain data mapped to the required feature dimensions inside the Mamba module.
[0014] The Mamba module includes a first branch and a second branch with shared weights; wherein, the input of the first branch is the intermediate time-domain data, and the output is a time-domain feature with the same feature dimension as the initial time-domain data; the input of the second branch is the intermediate frequency-domain data, and the output is a frequency-domain feature with the same feature dimension as the initial frequency-domain data.
[0015] In one possible implementation, both the first branch and the second branch include: a first RMS normalization module, a linear layer, SiLU activation, a one-dimensional convolutional layer, a selective state space model, a linear mapping layer, and a second RMS normalization module.
[0016] The first RMS normalization module outputs a normalized feature vector; the feature vector is divided into a first part and a second part according to the channel dimension.
[0017] The first part generates a gated signal through the linear layer and the SiLU activation function; the second part is processed by the linear layer, the one-dimensional convolutional layer and the SiLU activation function, and then input to the selective state-space model.
[0018] The output of the selective state-space model is multiplied element-wise with the gated signal to obtain the fused features, which are then input into the linear mapping layer.
[0019] The output of the linear mapping layer is the target feature after mapping processing; wherein, the target feature has the same feature dimension as the input feature of the first RMS normalization module;
[0020] The input to the second RMS normalization module is the sum of the target feature and the input feature of the first RMS normalization module.
[0021] In one possible implementation, the preprocessing of the navigation data to generate multiple trajectory subsequences with a fixed window length includes:
[0022] The navigation data is standardized to convert it into a standard normal distribution with a mean of 0 and a variance of 1.
[0023] A sliding window strategy is used to extract a fixed-length trajectory subsequence from the standardized navigation data according to a set length.
[0024] In one possible implementation, the step of performing frequency domain transformation on the navigation data to obtain initial frequency domain data includes:
[0025] The navigation data is converted from the time domain to the frequency domain using a fast Fourier transform, and amplitude and phase information are extracted.
[0026] The amplitude information and the phase information are concatenated along the channel dimension, and the concatenation result is mapped and converted to the same dimension as the navigation data to obtain the initial frequency domain data.
[0027] In one possible implementation, the formula for performing frequency domain transformation on the navigation data is as follows:
[0028]
[0029] in, and These represent amplitude characteristics and phase characteristics, respectively. This represents the characteristic representation after amplitude and phase mapping. This indicates a splicing operation along the channel dimension. and Here are the weight matrix and bias vector for the linear layer.
[0030] In one possible implementation, the training process of the deception attack detection model includes:
[0031] Acquire historical navigation data from the drone's GPS to obtain initial time-domain and initial frequency-domain data and construct training samples;
[0032] The initial time-domain data and initial frequency-domain data are input into the initial two-branch Mamba model for feature extraction, and the two branches of features, time-domain features and frequency-domain features, are output.
[0033] The two branch features are normalized using Softmax to convert them into probability distributions. The KL divergence loss function is then used to calculate the difference between the probability distributions of the normal navigation trajectory and the spoofing signal in the time and frequency domains. Specifically, when calculating the loss of the frequency domain branch using the KL divergence loss function, a gradient backpropagation halting operation is applied to the time domain features.
[0034] Based on the loss of the frequency domain branch and the loss of the time domain branch, the gradient of the total loss function with respect to each parameter of the model is passed to the initial two-branch Mamba model through the backpropagation algorithm, and the model parameters are updated using the Adam optimizer until the preset convergence criterion is reached, thus obtaining the trained two-branch Mamba model.
[0035] In one possible implementation, the KL divergence loss function is as follows:
[0036]
[0037]
[0038]
[0039] in, and Let these represent the probability distributions of the time-domain features and frequency-domain features after Softmax normalization, respectively. This operation is used to stop gradient backpropagation, ensuring that the two branches learn independently during training. The KL divergence metric. and These are the loss functions for the time-domain branch and the frequency-domain branch, respectively. This is the total loss function.
[0040] In one possible implementation, the step of reaching a preset convergence criterion includes:
[0041] Record the network loss value calculated using the total loss function for each training cycle;
[0042] The convergence condition is met when the network loss value for a consecutive training cycle is less than the minimum historical network loss value.
[0043] In one possible implementation, determining the deception attack behavior detection result based on the deception score includes:
[0044] If a deception score exceeds a set threshold, it is determined that the location corresponding to that deception score is at risk of a GPS spoofing attack.
[0045] In one possible implementation, the formula for calculating the cheat score is as follows:
[0046]
[0047] in, and These represent the output representations of the time-domain and frequency-domain branches, respectively. The operation is used to stop gradient backpropagation. The KL divergence metric. This is the deception score for the current sample point.
[0048] Secondly, embodiments of the present invention provide a drone GPS spoofing attack detection device based on contrastive learning and Mamba, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in the first aspect or any possible implementation of the first aspect.
[0049] In this embodiment of the invention, initial time-domain data is obtained by acquiring and preprocessing UAV GPS navigation data to generate trajectory subsequences within a fixed window. Simultaneously, frequency-domain transformation is performed to obtain initial frequency-domain data, thus preserving both the temporal continuity and frequency-domain feature information of the navigation data. The shared weight design of the dual-branch Mamba model ensures consistency in features learned from both the time and frequency domains, reducing model parameter redundancy while improving the stability of feature learning. The dual-branch Mamba model trained based on a contrastive learning strategy can learn discriminative features between normal and deceptive signals by mining the differences between time-domain and frequency-domain features without requiring a large number of labeled deception samples. Ultimately, it detects attack behavior through deception scores, thereby reducing reliance on manual labels while maintaining both modeling efficiency and detection accuracy for long-sequence navigation data. Attached Figure Description
[0050] Figure 1 This is an application scenario diagram of the UAV GPS spoofing attack detection method based on contrastive learning and Mamba provided in the embodiments of the present invention;
[0051] Figure 2 This is a flowchart illustrating the implementation of the UAV GPS spoofing attack detection method based on contrastive learning and Mamba provided in this embodiment of the invention.
[0052] Figure 3 This is a schematic diagram of the structure of the dual-branch Mamba model provided in an embodiment of the present invention;
[0053] Figure 4 This is a schematic diagram of the structure of the Mamba branch in the dual-branch Mamba model provided in this embodiment of the invention;
[0054] Figure 5 This is a schematic diagram of the process for frequency domain conversion of navigation data provided in an embodiment of the present invention;
[0055] Figure 6 This is a schematic diagram of the training process of the deception attack detection model provided in an embodiment of the present invention;
[0056] Figure 7 This is a schematic diagram of the structure of the drone GPS spoofing attack detection device based on contrastive learning and Mamba provided in an embodiment of the present invention. Detailed Implementation
[0057] Recently, self-supervised learning methods, represented by contrastive learning, have demonstrated excellent performance advantages in anomaly detection. They guide the model to learn discriminative latent features by constructing positive and negative samples, without relying on a large number of labels, making them suitable for scenarios with scarce data samples. Meanwhile, the Mamba model, as a novel state-space model (SSM), dynamically adjusts parameters through a selective state-space mechanism, enabling efficient modeling of long-sequence data with linear time complexity. This makes it suitable for time-series data with long-distance dependencies and dynamic evolutionary characteristics, such as navigation trajectories. The solution provided in this application aims to offer a novel method combining self-supervised contrastive learning strategies and efficient sequence modeling structures, based on contrastive learning and the Mamba structure, to improve the accuracy, robustness, and real-time performance of GPS spoofing attack detection while reducing label requirements.
[0058] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0059] Figure 1 This diagram illustrates an application scenario of the UAV GPS spoofing attack detection method based on contrastive learning and Mamba, as provided in this embodiment of the invention. Figure 1As shown, the drone interacts with the server via a wireless network to exchange GPS navigation data. During this interaction, the signal strength is weak and the network is highly vulnerable to human interference, particularly the threat of "GPS spoofing attacks." These attacks transmit forged GPS signals, inducing the drone to misjudge its current position and flight direction, and even achieving complete control over its flight path, potentially leading to mission failure, crashes, or even safety hazards. This application aims to provide a drone GPS spoofing attack detection method based on contrastive learning and Mamba, performing GPS spoofing attack detection on the drone and / or server side, thereby improving drone security.
[0060] In practice, detecting GPS spoofing attacks on drones increases computational load and energy consumption. Therefore, when drones have limited range or the workload is heavy but computing power is limited, GPS spoofing attack detection is primarily performed on the server side. In other possible implementations, when drones do not experience range anxiety and computing power allows, the drone itself can perform GPS spoofing attack detection to enable timely flight corrections.
[0061] See Figure 2 The document illustrates a flowchart of the implementation of a UAV GPS spoofing attack detection method based on contrastive learning and Mamba, as provided in an embodiment of the present invention, including the following steps:
[0062] S201: Acquire navigation data from the UAV's GPS, preprocess the navigation data to generate multiple trajectory subsequences with a fixed window length to obtain initial time-domain data, and perform frequency-domain transformation on the navigation data to obtain initial frequency-domain data.
[0063] The execution subject of each embodiment of this application can be a server, processor, microprocessor, or other device with data processing capabilities. In actual implementation, the specific implementation method of the execution subject can be selected according to actual needs. This embodiment does not impose any particular restrictions on this, as long as it is a device with data processing capabilities.
[0064] The navigation data from a UAV's GPS includes features such as position, speed, and heading. When preprocessing the navigation data to generate multiple trajectory subsequences with fixed window lengths, the features mentioned above are standardized to eliminate the influence of different data scales.
[0065] The navigation data is transformed into frequency domain data to obtain initial frequency domain data, which enhances the distinguishability between normal navigation trajectories and deceptive trajectories in the feature space.
[0066] S202, the initial time-domain data and initial frequency-domain data are input into the trained two-branch Mamba model for feature extraction, and the time-domain features and frequency-domain features are output respectively. The two branches of the two-branch Mamba model share weights; the two-branch Mamba model is trained based on a contrastive learning strategy.
[0067] The study combines the differences in representation between the time and frequency domains to further improve the detection performance of GPS spoofing attacks. The dual-branch Mamba structure, through its efficient state-space modeling mechanism and compact feature representation capabilities, significantly reduces computational complexity while maintaining model expressiveness, making it suitable for real-time modeling needs of long-term series in UAV navigation data.
[0068] In the two-branch Mamba model, the two branches share weights. The two-branch Mamba model aims to extract deep features from the input GPS navigation sub-sequences from both the time and frequency domains. The shared weight design ensures consistency in feature representation between the two branches, while simultaneously capturing feature patterns of trajectory signals from different perspectives. This allows the model to more comprehensively understand normal patterns and potential anomalies in navigation data, thereby improving the accuracy and robustness in identifying GPS spoofing attacks.
[0069] Contrastive learning, used to train a two-branch Mamba model for GPS spoofing attack detection, is a self-supervised learning strategy that can mine deep feature representations of data without relying on a large number of labels. Its core idea is to construct pairs of positive and negative samples from different perspectives, enabling the model to learn to identify potential anomalies in navigation trajectories.
[0070] Specifically, for normal UAV navigation trajectories, the physical motion process is consistent, resulting in similar feature representations extracted from both the time and frequency domains. However, for trajectory data subjected to GPS spoofing attacks, the time and frequency domain features often exhibit structural inconsistencies and significant differences. By employing a contrastive learning strategy for training, the model can effectively amplify these feature deviations, enabling it to more sensitively identify abnormal trajectory changes.
[0071] S203, calculate the deception score based on time domain features and frequency domain features, and determine the detection result of deception attack behavior based on the deception score.
[0072] In this embodiment, initial time-domain data is obtained by acquiring and preprocessing UAV GPS navigation data to generate trajectory subsequences within a fixed window. Simultaneously, frequency-domain transformation is performed to obtain initial frequency-domain data, thus preserving both the temporal continuity and frequency-domain feature information of the navigation data. The shared weight design of the dual-branch Mamba model ensures consistency in features learned from both the time and frequency domains, reducing model parameter redundancy while improving the stability of feature learning. The dual-branch Mamba model trained based on a contrastive learning strategy can learn discriminative features between normal and deceptive signals by mining the differences between time and frequency domain features without requiring a large number of labeled deception samples. Ultimately, it detects attack behavior through deception scores, thereby reducing reliance on manual labeling while maintaining both modeling efficiency and detection accuracy for long-sequence navigation data.
[0073] In one possible implementation, the two-branch Mamba model includes a sequentially connected instance normalization module, a one-dimensional convolution module, and a Mamba module, corresponding to... Figure 3 The examples shown are Instance Normalization, Convert1D, and MambaBlock.
[0074] The instance normalization module takes initial time-domain data and initial frequency-domain data as input and outputs normalized time-domain data and frequency-domain data as output.
[0075] The input to the one-dimensional convolution module is normalized time-domain data and frequency-domain data, and the output is intermediate time-domain data and intermediate frequency-domain data mapped to the required feature dimensions inside the Mamba module.
[0076] The Mamba module includes a first branch and a second branch with shared weights. The first branch takes intermediate time-domain data as input and outputs time-domain features with the same feature dimensions as the initial time-domain data. The second branch takes intermediate frequency-domain data as input and outputs frequency-domain features with the same feature dimensions as the initial frequency-domain data.
[0077] In the specific implementation process, firstly, the input time-domain and frequency-domain data are normalized using an instance normalization module. Then, a one-dimensional convolution module processes the normalized data, mapping it to the feature dimensions required within the Mamba module. Finally, the convolutionally processed features are fed into two parallel Mamba branches. These branches employ a shared weight design to learn representations of the input data from both time-domain and frequency-domain perspectives, ensuring consistent feature representations are generated under the same structure and parameters.
[0078] Specifically, instance normalization is used to normalize the input time-domain and frequency-domain data respectively, as defined below:
[0079] Assuming input data ,in, For batch size, The length of the sequence. For the characteristic number, its instantiation normalization formula is as follows:
[0080]
[0081]
[0082]
[0083] in, Indicates sample At time step and characteristics The value on, Indicates sample In features The mean of the above, Indicates sample In features The standard deviation on This represents the normalized value;
[0084] Optionally, the one-dimensional convolution module uses a kernel size of 3, a stride of 1, an output dimension of 256, and a padding size of 1, and employs cyclic padding to handle edge data. After convolving the input time-domain and frequency-domain data, the one-dimensional convolution module maps the output to intermediate time-domain and intermediate frequency-domain data of the required feature dimensions within the Mamba module, thus adapting the data to the Mamba model structure.
[0085] In the Mamba module, the first and second branches, which share weights, process the intermediate time-domain data and intermediate frequency-domain data respectively, capturing the deep features of the navigation data from different dimensions, and outputting frequency-domain features with the same feature dimensions as the initial frequency-domain data.
[0086] In this embodiment, the instance normalization module in the dual-branch Mamba model normalizes the initial time-domain and initial frequency-domain data, eliminating the interference of different data distributions on feature extraction. The one-dimensional convolution module maps the normalized data to the feature dimensions required by the Mamba module, achieving data-model structure adaptation. The first and second branches, sharing weights, process the intermediate time-domain and intermediate frequency-domain data respectively, ensuring that the two branches generate consistent feature representations under the same parameters, while also capturing deep features of navigation data from different dimensions. This reduces the number of model parameters while improving the robustness of feature extraction, providing a more reliable feature foundation for subsequent deception attack detection.
[0087] In one possible implementation, both the first branch and the second branch include: a first RMS normalization module, a linear layer, SiLU activation, a one-dimensional convolutional layer, a selective state-space model, a linear mapping layer, and a second RMS normalization module, corresponding sequentially. Figure 4 The layers distributed from left to right are RMSNorm, Linear, SiLU, Conv1D, SSSM (Selective StateSpace Model), Linear Projection Layer, and RMSNorm.
[0088] The first RMS normalization module outputs a normalized feature vector; the feature vector is divided into a first part and a second part according to the channel dimension.
[0089] The first part generates a gated signal through a linear layer and the SiLU activation function; the second part is processed by a linear layer, a one-dimensional convolutional layer, and the SiLU activation function, and then inputs a selective state-space model.
[0090] The output of the selective state-space model is multiplied element-wise with the gated signal to obtain the fused features, which are then input into the linear mapping layer.
[0091] The output of the linear mapping layer is the target feature after mapping; where the target feature has the same feature dimension as the input feature of the first RMS normalization module.
[0092] The input to the second RMS normalization module is the sum of the target feature and the input feature of the first RMS normalization module.
[0093] In the specific implementation process, the operation steps for each branch of the Mamba module are as follows:
[0094] For input features Perform root mean square (RMS) normalization:
[0095]
[0096] in, The number of channels for the input feature; To prevent the constant introduced by the division by zero operation, the value is generally set to 1e-5; For the first Input characteristics of each channel;
[0097] The normalized feature vector Divided into two parts along the channel dimension:
[0098]
[0099] in, Used to generate gating signals As input to the subsequent selective state-space model;
[0100] The first part of the features is used to generate a gated signal through a linear layer and the SiLU activation function:
[0101]
[0102] in, and These are the weight matrix and bias of the linear layer, respectively;
[0103] The second part of the features is processed by a linear layer, a one-dimensional convolutional layer, and the SiLU activation function, and then passed as input to the selective state-space model.
[0104]
[0105]
[0106]
[0107] in, and For linear layer parameters; The kernel size; Output for linear layers; for and One-dimensional convolution;
[0108] Output the selective state-space model With the generated gating signal Element-wise multiplication is performed to achieve selective fusion of information:
[0109]
[0110] The resulting fused features are processed through a linear mapping layer to map them to the same feature dimension as the input features:
[0111]
[0112] in, and These are the parameters for the linear mapping layer;
[0113] The processed features are added to the input features, and then the result is normalized again using RMS to obtain the final output.
[0114]
[0115] in, These are the fused features after mapping; For input features; The number of channels for the input feature; To prevent the constant introduced by the division by zero operation, the value is generally set to 1e-5; For the first Input characteristics of each channel; For the first The fusion features after mapping;
[0116] Both the time-domain branch and the frequency-domain branch follow the operation steps of the Mamba module described above, and ensure the consistency of feature representation through shared weights;
[0117] The selective state-space model is defined as follows:
[0118]
[0119]
[0120]
[0121]
[0122]
[0123] in, For time step, Here is the state transition matrix. For the input matrix, For the output matrix, It is a linear transformation layer used to transform the input. Dynamically adjust parameters. and These are the discretized state transition matrix and input matrix. It is the identity matrix; In hidden state, This is the output of the selective state-space model. The hidden state at the current time step. This is the hidden state of the previous time step.
[0124] In practice, the first and second branches of the Mamba module perform the aforementioned data processing procedures on the time-domain and frequency-domain data, respectively. These two branches can process the time-domain and frequency-domain data in parallel, improving data processing efficiency and accuracy.
[0125] In this embodiment, the first RMS normalization module within the first and second branches normalizes the input features, stabilizing the training process. The feature vector is divided into two parts for separate processing. The gating signal generated in the first part is multiplied element-wise with the output of the selective state-space model, enabling selective information fusion and highlighting key features. The second part, after processing through a linear layer, a one-dimensional convolutional layer, and the SiLU activation function, is input into the selective state-space model, efficiently modeling the temporal dependencies of long-sequence data. The linear mapping layer ensures that the output features have the same dimension as the input features, facilitating subsequent comparative learning. The second RMS normalization module further optimizes the feature distribution, ultimately enabling the two branches to accurately capture subtle feature differences in the time and frequency domains, improving the ability to identify complex spoofing attacks.
[0126] The preceding section primarily introduced the specific processing steps for inputting initial time-domain and initial frequency-domain data into a two-branch Mamba model for feature extraction, and outputting time-domain and frequency-domain features respectively. The following section elaborates on the preprocessing of navigation data from UAV GPS to obtain initial time-domain and initial frequency-domain data.
[0127] In one possible implementation, the navigation data is preprocessed to generate multiple trajectory subsequences with a fixed window length, including:
[0128] The navigation data is standardized by converting it into a standard normal distribution with a mean of 0 and a variance of 1.
[0129] A sliding window strategy is used to extract a fixed-length trajectory subsequence from the standardized navigation data according to a set length.
[0130] Among these measures, the navigation data is standardized by converting it into a standard normal distribution with a mean of 0 and a variance of 1, in order to eliminate the influence of different data scales.
[0131] Optionally, the fixed length for the sliding window strategy is 100, and the window sliding step is 1. The sliding window strategy extracts a fixed-length trajectory subsequence from the standardized navigation data according to the set length, ensuring the continuity of subsequent subsequence data and coverage of the entire sequence.
[0132] The process of extracting a fixed-length subsequence using the sliding window strategy is as follows:
[0133] Let the navigation sequence corresponding to the original navigation data be... If the window length is L and the sliding step size is s, then the sub-trajectory sequence data obtained at time t after segmentation is... Represented as:
[0134] .
[0135] In this embodiment, the navigation data is standardized to a standard normal distribution with a mean of 0 and a variance of 1. This eliminates scale differences across different feature dimensions and prevents a single feature from dominating model learning due to its excessively large numerical range. A sliding window strategy is used to extract fixed-length trajectory subsequences, ensuring the continuity of the subsequences and fully covering the original navigation sequence. This allows the model to learn the temporal correlation of the navigation data, providing consistent and continuous input data for subsequent time-frequency domain feature extraction and attack detection, thus improving the model's performance in modeling dynamic navigation processes.
[0136] Figure 5 This is a schematic diagram illustrating the process of frequency domain conversion of navigation data provided in an embodiment of the present invention. Figure 5 As shown, in one possible implementation, the navigation data undergoes frequency domain transformation to obtain initial frequency domain data, including:
[0137] The navigation data is converted from the time domain to the frequency domain using the Fast Fourier Transform, and the amplitude and phase information are extracted.
[0138] Amplitude and phase information are stitched together along the channel dimension, and the stitching result is mapped to the same dimension as the navigation data to obtain the initial frequency domain data.
[0139] The formula for the Fast Fourier Transform is as follows:
[0140]
[0141] in, This represents the nth sample value of the time-domain signal. This represents the corresponding frequency domain coefficients. This represents the total number of signal sampling points. It is the imaginary unit.
[0142] Since frequency domain data is represented in complex form, it cannot be directly used for neural network training. It is necessary to extract the amplitude and phase information of the frequency domain data. The formulas for calculating amplitude and phase are as follows:
[0143]
[0144]
[0145] in, For amplitude characteristics, This is a phase characteristic.
[0146] Use linear layers (such as) Figure 5 The linear array splices amplitude and phase information along the channel dimension, maps the splicing result to the same dimension as the navigation data, and converts it into real number form to adapt to the neural network input.
[0147] In one possible implementation, the formula for frequency domain transformation of navigation data is as follows:
[0148]
[0149] in, and These represent amplitude characteristics and phase characteristics, respectively. This represents the characteristic representation after amplitude and phase mapping. This indicates a splicing operation along the channel dimension. and Here are the weight matrix and bias vector for the linear layer.
[0150] This formula achieves the fusion of two key types of information in the frequency domain by concatenating amplitude and phase features along the channel dimension. The concatenated result is then mapped to the target feature representation using the weight matrix and bias vector of the linear layer, ensuring that the mapped frequency domain features are dimensionally consistent with the original navigation data and can directly adapt to the input requirements of subsequent two-branch Mamba structures. Simultaneously, this operation effectively preserves the inherent correlation between amplitude and phase features, enabling the frequency domain features to more accurately reflect the characteristics of the navigation data. This provides a reliable foundation for comparative learning with time domain features, further enhancing the model's sensitivity to identifying deception signals.
[0151] In this embodiment, the navigation data is transformed from the time domain to the frequency domain using Fast Fourier Transform (FFT), which can uncover frequency features that are difficult to reveal in the time domain, supplementing the feature dimensions of the navigation data. Extracting amplitude and phase information and concatenating them along the channel dimension can completely preserve the key information of the frequency domain features. Mapping the concatenated result to the same dimension as the navigation data ensures that the frequency domain features can be directly input into the two-branch Mamba model, and also achieves collaborative modeling of time and frequency domain features. Multi-view feature fusion enhances the distinction between normal navigation trajectories and deceptive trajectories, thereby improving detection accuracy.
[0152] The foregoing embodiments introduced the acquisition of initial time-domain data and initial frequency-domain data, as well as the extraction of time-domain features and frequency-domain features from the initial time-domain data and initial frequency-domain data. The following describes the training process of the two-branch Mamba model.
[0153] In one possible implementation, the training process of the two-branch Mamba model includes:
[0154] Acquire historical navigation data from the drone's GPS to obtain initial time-domain and initial frequency-domain data and construct training samples;
[0155] The initial time-domain data and initial frequency-domain data are input into the initial two-branch Mamba model for feature extraction, and the two branches of features, time-domain features and frequency-domain features, are output.
[0156] The two branch features are normalized using Softmax to convert them into probability distributions. The KL divergence loss function is then used to calculate the difference between the probability distributions of the normal navigation trajectory and the spoofing signal in the time and frequency domains. Specifically, when calculating the loss of the frequency domain branch using the KL divergence loss function, a gradient backpropagation halting operation is applied to the time domain features.
[0157] Based on the loss of the frequency domain branch and the loss of the time domain branch, the gradient of the total loss function with respect to each parameter of the model is passed to the initial two-branch Mamba model through the backpropagation algorithm, and the Adam optimizer is used to update the model parameters until the preset convergence criterion is reached, thus obtaining the trained two-branch Mamba model.
[0158] Combination Figure 6 The flowchart shown illustrates the specific implementation process as follows: First, historical UAV GPS navigation data is acquired. Data preprocessing is then performed to obtain training samples, avoiding excessive noise and improving model training accuracy. For each training sample, time-domain and frequency-domain data are first obtained through a frequency-domain feature extraction module and input into a dual-branch Mamba model. Corresponding feature representations are generated through the time-domain and frequency-domain branches, respectively. Subsequently, the features of these two branches are normalized using Softmax to convert them into probability distributions. The KL divergence loss function is then used to calculate the difference between the probability distributions of the normal navigation trajectory and the spoofing signal in the time-domain and frequency-domain branches. Specifically, when calculating the contrast loss, a stopping backpropagation operation is applied to the gradient of one branch (i.e.,...). Figure 6 The Stopgrad operation shown in the diagram ensures that the two branches can learn independently during training, thereby avoiding gradient interference. Finally, the gradient of the total loss function with respect to each parameter of the model is passed to the two-branch Mamba model through the backpropagation algorithm, and the Adam optimizer is used to update the model parameters until the preset convergence criterion is reached.
[0159] In this embodiment, training samples are constructed using historical navigation data to fully explore the characteristic patterns of normal and deceptive navigation modes. The time-domain and frequency-domain features extracted by the dual-branch Mamba structure are converted into probability distributions after Softmax normalization. The KL divergence loss function can accurately measure the difference between the two feature distributions. When calculating the loss, a gradient-stopping backpropagation operation is applied to one of the branches to avoid gradient interference between the two branches, ensuring that each branch independently learns its unique time-domain and frequency-domain features. Combining the total loss function with parameter updates via the Adam optimizer can efficiently adjust the model parameters until convergence, enabling the model to fully learn the discriminative features of normal and deceptive signals without requiring a large number of labeled samples, thus improving the generalization ability and convergence efficiency of the detection model.
[0160] In one possible implementation, the KL divergence loss function is as follows:
[0161]
[0162]
[0163]
[0164] in, and Let these represent the probability distributions of the time-domain features and frequency-domain features after Softmax normalization, respectively. This operation is used to stop gradient backpropagation, ensuring that the two branches learn independently during training. The KL divergence metric. and These are the loss functions for the time-domain branch and the frequency-domain branch, respectively. This is the total loss function.
[0165] In one possible implementation, the convergence continues until a preset criterion is met, including:
[0166] Record the network loss value calculated using the total loss function for each training cycle;
[0167] The convergence condition is met when the network loss value for a consecutive training cycle is less than the minimum historical network loss value.
[0168] Optionally, the number of consecutive training epochs can be set to 3 to 8. Optionally, when the network loss value corresponding to 5 consecutive training epochs is less than the minimum historical network loss value, the convergence condition is determined to be met, and training is stopped to avoid model overfitting and to determine the convergence state.
[0169] In this embodiment, the preset convergence criterion clarifies the termination condition of model training, avoiding poor model performance due to insufficient training or overfitting caused by overtraining. By setting criteria such as the loss function value stabilizing within a preset range or reaching the maximum number of iterations, it can be ensured that the model maintains good generalization ability under the premise of sufficient learning, enabling the trained model to be stably and reliably applied to actual UAV GPS spoofing attack detection scenarios, ensuring the consistency of detection performance.
[0170] In one possible implementation, determining the detection result of deception attack behavior based on the deception score includes:
[0171] If a spoofing score exceeds a set threshold, then the location corresponding to that spoofing score is identified as having a risk of GPS spoofing attack.
[0172] In this embodiment, the attack detection result is determined by comparing the deception score with a set threshold, making the deception attack determination process quantifiable and explicit. When the deception score is greater than the set threshold, a GPS deception attack risk is determined. This mechanism can intuitively reflect the degree of anomaly in the current navigation data based on the degree of difference in time-frequency branch features, avoiding ambiguous determinations, improving the reliability and interpretability of the detection results, and facilitating a rapid response from the UAV navigation system to potential attacks.
[0173] In one possible implementation, the formula for calculating the cheat score is as follows:
[0174]
[0175] in, and These represent the output representations of the time-domain and frequency-domain branches, respectively. The operation is used to stop gradient backpropagation. The KL divergence metric. This is the deception score for the current sample point.
[0176] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0177] The following are device embodiments of the present invention. For details not described in detail, please refer to the corresponding method embodiments described above.
[0178] Figure 7 The diagram shows a schematic of the UAV GPS spoofing attack detection device based on contrastive learning and Mamba provided in an embodiment of the present invention. For ease of explanation, only the parts relevant to the embodiment of the present invention are shown, and are described in detail below:
[0179] like Figure 7 As shown, the drone GPS spoofing attack detection device 7 based on contrastive learning and Mamba includes:
[0180] The data preprocessing module 701 is used to acquire navigation data from the UAV's GPS, preprocess the navigation data to generate multiple trajectory subsequences with a fixed window length to obtain initial time domain data, and perform frequency domain transformation on the navigation data to obtain initial frequency domain data.
[0181] The feature extraction module 702 is used to input the initial time-domain data and the initial frequency-domain data into the trained dual-branch Mamba model to extract features respectively, and output time-domain features and frequency-domain features.
[0182] The detection module 703 is used to calculate the deception score based on time-domain features and frequency-domain features, and to determine the detection result of the deception attack behavior based on the deception score;
[0183] In the two-branch Mamba model, the two branches share weights; the two-branch Mamba model is trained based on a contrastive learning strategy.
[0184] In one possible implementation, the data preprocessing module 701 is specifically used for:
[0185] The navigation data is standardized by converting it into a standard normal distribution with a mean of 0 and a variance of 1.
[0186] A sliding window strategy is used to extract a fixed-length trajectory subsequence from the standardized navigation data according to a set length.
[0187] In one possible implementation, the data preprocessing module 701 is specifically used for:
[0188] The navigation data is converted from the time domain to the frequency domain using the Fast Fourier Transform, and the amplitude and phase information are extracted.
[0189] Amplitude and phase information are stitched together along the channel dimension, and the stitching result is mapped to the same dimension as the navigation data to obtain the initial frequency domain data.
[0190] In one possible implementation, a training module is also included, used for:
[0191] Acquire historical navigation data from the drone's GPS to obtain initial time-domain and initial frequency-domain data and construct training samples;
[0192] The initial time-domain data and initial frequency-domain data are input into the initial two-branch Mamba model for feature extraction, and the two branches of features, time-domain features and frequency-domain features, are output.
[0193] The two branch features are normalized using Softmax to convert them into probability distributions. The KL divergence loss function is then used to calculate the difference between the probability distributions of the normal navigation trajectory and the spoofing signal in the time and frequency domains. Specifically, when calculating the loss of the frequency domain branch using the KL divergence loss function, a gradient backpropagation halting operation is applied to the time domain features.
[0194] Based on the loss of the frequency domain branch and the loss of the time domain branch, the gradient of the total loss function with respect to each parameter of the model is passed to the initial two-branch Mamba model through the backpropagation algorithm, and the Adam optimizer is used to update the model parameters until the preset convergence criterion is reached, thus obtaining the trained two-branch Mamba model.
[0195] This invention also provides a drone GPS spoofing attack detection device based on contrastive learning and Mamba, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in the above method embodiments. Exemplarily, the drone GPS spoofing attack detection device based on contrastive learning and Mamba can be a server, a laptop computer, etc., and is not limited thereto.
[0196] In the above embodiments, the descriptions of each embodiment have their own emphasis. Parts not detailed or described in a particular embodiment can be referred to in the relevant descriptions of other embodiments. Unless otherwise specified or in conflict with logic, the terminology and / or descriptions between different embodiments are consistent and can be referenced interchangeably. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0197] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba, characterized in that, include: The navigation data of the UAV's GPS is acquired, the navigation data is preprocessed to generate multiple trajectory subsequences with a fixed window length to obtain initial time domain data, and the navigation data is frequency domain transformed to obtain initial frequency domain data. The initial time-domain data and the initial frequency-domain data are input into the trained dual-branch Mamba model for feature extraction, and the time-domain features and frequency-domain features are output respectively. The deception score is calculated based on the time-domain features and the frequency-domain features, and the detection result of the deception attack behavior is determined based on the deception score. In the dual-branch Mamba model, the two branches share weights; the dual-branch Mamba model is trained based on a contrastive learning strategy. The specific formula for calculating the deception score is as follows: in, and These represent the output representations of the time-domain and frequency-domain branches, respectively. The operation is used to stop gradient backpropagation. The KL divergence metric. This is the deception score for the current sample point.
2. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 1, characterized in that, The dual-branch Mamba model includes a sequentially connected instance normalization module, a one-dimensional convolution module, and a Mamba module; The instance normalization module takes the initial time-domain data and the initial frequency-domain data as inputs and outputs the normalized time-domain data and frequency-domain data as outputs. The input to the one-dimensional convolution is normalized time-domain data and frequency-domain data, and the output is intermediate time-domain data and intermediate frequency-domain data mapped to the required feature dimensions inside the Mamba module. The Mamba module includes a first branch and a second branch with shared weights; wherein, the input of the first branch is the intermediate time-domain data, and the output is a time-domain feature with the same feature dimension as the initial time-domain data; the input of the second branch is the intermediate frequency-domain data, and the output is a frequency-domain feature with the same feature dimension as the initial frequency-domain data.
3. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 2, characterized in that, Both the first branch and the second branch include: a first RMS normalization module, a linear layer, SiLU activation, a one-dimensional convolutional layer, a selective state-space model, a linear mapping layer, and a second RMS normalization module. The first RMS normalization module outputs a normalized feature vector; the feature vector is divided into a first part and a second part according to the channel dimension. The first part generates a gated signal through the linear layer and the SiLU activation function; the second part is processed by the linear layer, the one-dimensional convolutional layer and the SiLU activation function, and then input to the selective state-space model. The output of the selective state-space model is multiplied element-wise with the gated signal to obtain the fused features, which are then input into the linear mapping layer. The output of the linear mapping layer is the target feature after mapping processing; wherein, the target feature has the same feature dimension as the input feature of the first RMS normalization module; The input to the second RMS normalization module is the sum of the target feature and the input feature of the first RMS normalization module.
4. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 1, characterized in that, The preprocessing of the navigation data to generate multiple trajectory subsequences with a fixed window length includes: The navigation data is standardized to convert it into a standard normal distribution with a mean of 0 and a variance of 1. A sliding window strategy is used to extract a fixed-length trajectory subsequence from the standardized navigation data according to a set length.
5. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 1, characterized in that, The step of performing frequency domain transformation on the navigation data to obtain initial frequency domain data includes: The navigation data is converted from the time domain to the frequency domain using a fast Fourier transform, and amplitude and phase information are extracted. The amplitude information and the phase information are concatenated along the channel dimension, and the concatenation result is mapped and converted to the same dimension as the navigation data to obtain the initial frequency domain data.
6. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 5, characterized in that, The formula for frequency domain conversion of the navigation data is as follows: in, and These represent amplitude characteristics and phase characteristics, respectively. This represents the characteristic representation after amplitude and phase mapping. This indicates a splicing operation along the channel dimension. and Here are the weight matrix and bias vector for the linear layer.
7. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 1, characterized in that, The determination of the deception attack behavior detection result based on the deception score includes: If a deception score exceeds a set threshold, it is determined that the location corresponding to that deception score is at risk of a GPS spoofing attack.
8. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 1, characterized in that, The training process of the two-branch Mamba model includes: Acquire historical navigation data from the drone's GPS to obtain initial time-domain and initial frequency-domain data and construct training samples; The initial time-domain data and initial frequency-domain data are input into the initial two-branch Mamba model for feature extraction, and the two branches of features, time-domain features and frequency-domain features, are output. The two branch features are normalized using Softmax to convert them into probability distributions. The KL divergence loss function is then used to calculate the difference between the probability distributions of the normal navigation trajectory and the spoofing signal in the time and frequency domains. Specifically, when calculating the loss of the frequency domain branch using the KL divergence loss function, a gradient backpropagation halting operation is applied to the time domain features. Based on the loss of the frequency domain branch and the loss of the time domain branch, the gradient of the total loss function with respect to each parameter of the model is passed to the initial two-branch Mamba model through the backpropagation algorithm, and the model parameters are updated using the Adam optimizer until the preset convergence criterion is reached, thus obtaining the trained two-branch Mamba model.
9. The method for detecting UAV GPS spoofing attacks based on contrastive learning and Mamba according to claim 8, characterized in that, The process of reaching the preset convergence criterion includes: Record the network loss value calculated using the total loss function for each training cycle; The convergence condition is met when the network loss value for a consecutive training cycle is less than the minimum historical network loss value.
10. A drone GPS spoofing attack detection device based on contrastive learning and Mamba, characterized in that, It includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method as described in any one of claims 1 to 9.
Citation Information
Patent Citations
ADS-B spoofing attack detection method based on discrete cosine patch attention mechanism
CN119598141A
Semi-supervised cardiac image segmentation method based on Mamba-Transform double structure and contrast learning
CN120147330A