Distributed safety estimation method for kettle reactor system based on rolling time domain

By introducing Bernoulli random variables and a distributed rolling time-domain estimator into a batch reactor system, the problem of multiple attacks coexisting in wireless sensor networks is solved, achieving high-precision and robust state estimation and ensuring the safe and stable operation of the system under mixed attacks.

CN121690680APending Publication Date: 2026-03-17ZHEJIANG UNIV OF FINANCE & ECONOMICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511755931.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing distributed state estimation methods have failed to effectively handle complex hybrid attack scenarios in wireless sensor networks where multiple attacks (such as denial-of-service and fake data injection) coexist, leading to degraded state estimation performance or even system instability, threatening the secure and reliable operation of cyber-physical systems.

Method used

A distributed security estimation method for a batch reactor system based on rolling time domain is constructed. By introducing two interrelated Bernoulli random variables to characterize mixed attacks, a distributed rolling time domain estimator is designed. Combining the zero-order preservation mechanism and the neighbor consistency term, the objective function is optimized to handle local and global information. The boundedness of the estimation error is proved using linear matrix inequality analysis.

Benefits of technology

It achieves high-precision and high-reliability online estimation of critical states under hybrid attacks, ensuring the safe and stable operation of the system and enhancing its robustness and practicality in complex attack environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690680A_ABST
    Figure CN121690680A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed safety estimation method for a tank reactor system based on a rolling time domain, and belongs to the technical field of information physical system safety, and the method comprises the steps: building a discretization linear state space model of a continuous stirred tank reactor through building a multi-sensor network topology; two associated Bernoulli variables are introduced to describe a hybrid attack model in which denial of service attack and false data injection attack coexist, and zero-order retention compensation is adopted when DoS occurs; designing a distributed rolling time domain estimator for each node, and locally optimizing target function fusion measurement fitting degree, prior deviation and neighbor consistency; solving to output the current state estimation under the condition of meeting the dynamic constraint of the system; and a linear matrix inequality proves that the estimation error is consistent and finally bounded under the mean square meaning. According to the method, Gaussian noise hypothesis is not needed, bounded non-Gaussian disturbance is effectively dealt with, online, real-time and high-robustness state estimation is achieved, and safe operation of the reactor in an information physical environment is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information physical system security, and particularly relates to a rolling time domain-based distributed security estimation method for a tank reactor system. BACKGROUND

[0002] An information physical system realizes close integration of computing resources and physical resources, wherein distributed state estimation based on a wireless sensor network (WSN) is one of core functions thereof and is widely applied to industrial automation, intelligent transportation and the like.

[0003] In the distributed estimation, a rolling time domain estimation (MHE) method has become a research hotspot due to its ability to process unknown or non-Gaussian noise and to have limited time domain optimization and explicit processing of constraints. However, existing distributed MHE researches are mostly based on ideal assumptions of communication channel security and complete data transmission.

[0004] In fact, due to the broadcast nature of wireless communication, a sensor network is vulnerable to malicious attacks. Among them, a denial of service (DoS) attack will block the communication channel, resulting in data packet loss; a false data injection (FDI) attack will tamper with the transmission data, misleading the estimator to produce an incorrect result. At present, researches on secure state estimation mostly only consider a single type of attack (such as only considering DoS attack or only considering FDI attack), and fail to fully reflect the complex mixed attack scene where multiple attacks coexist in reality. This will lead to a significant decline in state estimation performance in the mixed attack scene where DoS attack and FDI attack coexist, and even cause system instability, seriously threatening the safe and reliable operation of the information physical system. SUMMARY

[0005] The application aims to provide a rolling time domain-based distributed security estimation method for a tank reactor system to solve the problems in the background art.

[0006] To achieve the above-mentioned purpose, the application provides the following technical scheme: a rolling time domain-based distributed security estimation method for a tank reactor system, comprising the following steps: S1: constructing a multi-sensor network topology structure for a continuous stirred tank reactor device; S2: based on the network topology structure, establishing a discretized linear state space model of the continuous stirred tank reactor system to describe the dynamic relationship between the internal state variables of the reactor and the sensor measurement output; S3: introducing two interrelated Bernoulli random variables to represent whether each sensor is subjected to a denial of service attack and whether each sensor is subjected to a false data injection attack at each sampling time, thereby constructing a mixed attack model capable of simultaneously depicting denial of service attack, false data injection attack and normal communication. wherein, when a denial-of-service attack occurs, the measurement value received at the last time is used for zero-order hold compensation, and when a false data injection attack occurs but a denial-of-service attack does not occur, the received measurement data contains malicious tampering noise within a bounded range; S4: for each sensor node, a distributed rolling horizon estimator is designed, and at each sampling time, a local optimization objective function is constructed based on a fixed-length finite time window; the objective function comprehensively considers three aspects of information: the fitting degree between the actual received local measurement data in the window and the model prediction value, the deviation between the current estimation of the state at the start time of the window and the prior estimation at the last time, and the consistency with the state estimation of adjacent sensor nodes at the start time of the window; S5: under the premise of meeting the system dynamic evolution constraint, the local optimization objective function is solved to obtain an optimal state estimation sequence in the time window, and a system state estimation value at the current time is output; S6: using a linear matrix inequality analysis tool, the estimation error dynamics of the designed distributed rolling horizon estimator are theoretically analyzed, and it is proved that under the joint action of mixed attacks and bounded system disturbances, the state estimation error of each sensor node is uniformly ultimately bounded in the mean square sense.

[0007] Preferably, the state variables of the continuous stirred tank reactor system include the concentration of reactant A, the concentration of product B, and the temperature in the reactor, and the system model parameters include initial concentration, steady-state operating point, coolant temperature, dilution rate, volume flow rate, heat capacity, heat transfer coefficient, density, reaction rate constant, and corresponding activation energy and frequency factor.

[0008] Preferably, the two Bernoulli random variables have known statistical probability characteristics, one of which represents the probability of a denial-of-service attack, and the other represents the conditional probability of a false data injection attack under the condition that communication is not blocked, and both reflect the randomness and coupling relationship of mixed attacks.

[0009] Preferably, when a sensor node determines at a certain time that it is subjected to a denial-of-service attack and cannot receive new measurement data, a zero-order hold mechanism is automatically enabled, and the measurement value successfully received by the node at the last time is used as the substitute input at the current time to maintain the continuous operation of the estimator.

[0010] Preferably, the local optimization objective function contains a neighbor consistency term, which integrates the state estimation information of adjacent sensor nodes at the start time of the same time window through a weighted manner to enhance the overall collaboration and robustness of distributed estimation.

[0011] In this preferred embodiment, the solution result of the distributed rolling time-domain estimator can be expressed as a modified form of the prior estimate of the initial state of the window. The modification amount is jointly determined by the actual measurement sequence received within the window, the known control input sequence, and the system model parameters.

[0012] In this preferred embodiment, the estimation error is defined as the difference between the actual system state and the estimated current state of the sensor node. Its dynamic evolution is affected by a combination of hybrid attack behaviors, system process noise, measurement noise, and estimation bias of neighboring nodes.

[0013] In this preferred embodiment, by constructing a Lyapunov function and combining it with the stability theory of stochastic systems, if there exist positive definite matrices and positive scalars that satisfy specific conditions, it can be rigorously proven that the estimation error has final boundedness in the mean square sense, and its asymptotic upper bound can be explicitly determined.

[0014] In this preferred embodiment, the specific conditions are given in the form of linear matrix inequalities. These inequalities involve the system dynamic matrix, observation structure, attack probability parameters, noise bound, optimization weight matrix, and sensor network topology information, and can be solved and verified using standard convex optimization tools.

[0015] The preferred embodiment of this solution is applicable to complex security threat scenarios in wireless sensor networks where denial-of-service attacks and spoofing attacks coexist. It does not rely on the assumption that noise follows a Gaussian distribution, can effectively handle bounded non-Gaussian disturbances, and achieves online, real-time, and highly robust state estimation through a rolling optimization mechanism, ensuring the safe and stable operation of the continuous stirred tank reactor in a cyber-physical fusion environment.

[0016] Compared with the prior art, the technical effects and advantages of the present invention are as follows: This distributed security estimation method for continuous stirred-tank reactor (CSTR) systems, based on rolling time domain, constructs a multi-sensor network topology for CSTR systems and establishes a discretized linear state-space model on this basis. This allows for accurate characterization of the system's dynamic behavior, providing a reliable physical foundation for subsequent distributed state estimation. More importantly, by introducing two interrelated Bernoulli random variables to represent the occurrence states of denial-of-service (DoS) attacks and fictitious data injection (FDI) attacks, this scheme is the first to explicitly model a hybrid attack scenario in which these two mainstream network attacks coexist within the estimation framework, accurately reflecting the logical coupling relationship between them (i.e., FDI attacks can only occur when communication is not blocked by DoS). This design makes the attack model closer to the actual security threat environment of industrial wireless sensor networks, overcoming the limitations of existing studies that mostly consider only a single attack type and ignore the dependencies between attacks.

[0017] Based on this hybrid attack model, a distributed rolling time-domain estimator is designed for each sensor node. This estimator integrates three pieces of information into the local optimization objective function: the fit between the actual (potentially attacked) measurement data received within the window and the model's predicted values; the deviation between the current estimate and the prior estimate; and the consistency with the state estimates of neighboring nodes at the window's starting point. This ensures that the estimator not only possesses robustness against local anomalous data but also effectively suppresses estimation biases caused by strong FDI attacks on individual nodes through a neighbor consensus mechanism. Particularly during DoS attacks, the automatic activation of the zero-order hold mechanism, using the previous valid measurement value for compensation, guarantees the continuity and stability of the estimation process. During FDI attacks, the rolling time-domain estimation itself does not rely on the Gaussian statistical assumption of noise, and the optimization objective includes state evolution constraints and neighbor cooperation terms, effectively "filtering" or weakening the impact of bounded malicious noise. This design principle, which integrates local robustness and global cooperation, achieves high-precision and high-reliability online estimation of critical states (such as reactant concentration and temperature) of CSTRs in complex hybrid attack environments. By employing the Linear Matrix Inequality (LMI) tool to rigorously analyze the dynamics of the estimation error, this study proves that the estimation errors of each node are uniformly and ultimately bounded in the mean-square sense under the combined effects of mixed attacks and bounded perturbations. This theoretical result not only provides a mathematical guarantee for the effectiveness of the method but also gives computable sufficient conditions for estimator parameter design in LMI form, facilitating engineering implementation. Compared to existing techniques that lack quantitative analysis of estimation performance under mixed attacks or rely solely on simulation verification, this approach achieves a closed-loop "design-verification" process, significantly improving the reliability and practicality of the method. Attached Figure Description

[0018] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0019] Fig. 1 This is a flowchart of a distributed security estimation method for a batch reactor system based on rolling time domain according to the present invention; Fig. 2 This is a detailed flowchart of the method of the present invention; Fig. 3 This is a schematic diagram showing the state estimation results of a continuous stirred tank reactor system under a mixing attack in an embodiment of the present invention. Detailed Implementation

[0020] In the following description, numerous specific details are set forth in order to provide a more thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention can be practiced without one or more of these details. In other instances, certain technical features well-known in the art have not been described in order to avoid obscuring the invention.

[0021] Unless otherwise defined, the directions mentioned herein, such as up, down, left, right, front, back, inside, and outside, are based on the directions shown in the figures of this invention, and are explained here together.

[0022] This embodiment provides, for example Figs. 1 to 3 The distributed safety estimation method for a batch reactor system based on rolling time domain, as shown, includes the following steps: S1: Construct a sensor network topology for a continuous stirred tank reactor (CSTR) device; In this embodiment, a distributed sensor network consisting of multiple wireless sensor nodes is considered. Each node is deployed at a different location on the CSTR device to collect key process variables (such as concentration, temperature, etc.). The sensor nodes exchange information within a limited range via wireless links, forming an undirected or directed communication topology. ,in Represents a set of sensor nodes. Let represent the set of communication edges. If node j can send information to node i, then .remember Let i be the set of neighbors of node i.

[0023] S2: Based on the sensor network topology, establish a system state-space model based on the distributed rolling time-domain estimation problem.

[0024] First, a physical model of the CSTR device is performed. The following two parallel reactions occur in the CSTR: ; In this study, substance A is a reactant, and substances B and C are products. Let... The concentration of substance A (unit: ), The concentration of substance B (unit: ), Temperature inside the reactor (unit: K). q is the coolant temperature (in K), and q is the volumetric flow rate (in K). V is the volume of the reactor (unit: ), Dilution rate (unit: 1 / s). Heat transfer area of ​​the reactor (unit: ), Fluid density (unit: ), Heat capacity (unit: U is the heat transfer coefficient (unit: ), These are the heats of reaction for the two reactions (unit: J / mol). Activation energy (unit: J / mol) R is the frequency factor (unit: 1 / s), and R is the ideal gas constant ( ).

[0025] The reaction rate coefficient is given by the Arrhenius equation: ; in, This represents the initial concentration (feed concentration) of substance A. This refers to the initial temperature of the reactor (feed temperature). The steady-state operating point is selected. (See Table 1) The above nonlinear model is linearized near this point to obtain a continuous-time linear state-space model: ; Where the state vector Control input V is the continuous-time process noise, and v(t) is the measurement noise.

[0026] Set standard sampling period Discretizing the continuous model yields a discrete-time state-space model: ; in: (Here, n=3) represents the system state vector at time k; This represents the control input (coolant temperature deviation) at time k. Describes the process noise of a bounded system at time k, satisfying ; This represents the actual measurement output vector at time k; Describes the bounded measurement noise at time k, satisfying ; The system matrix is ​​known.

[0027] In a distributed setup, the total measurement output is divided into Local observation: ; in: This represents the actual measurement output of the i-th sensor at time k; Let be the local observation matrix of the i-th sensor; To correspond to the measured noise; satisfy .

[0028] This section clarifies the physical meaning and dimensions of all states, inputs, outputs, and noise. For example, n=3 corresponds to three state variables. It is the output dimension of the i-th sensor; express A dimensional real vector space.

[0029] This technical solution explicitly defines the state variables of a continuous stirred tank reactor (CSTR) system as the concentrations of reactant A, product B, and the reactor temperature. It also fully incorporates key physical parameters such as initial concentration, steady-state operating point, coolant temperature, dilution rate, volumetric flow rate, heat capacity, heat transfer coefficient, density, reaction rate constant, and their corresponding activation energy and frequency factor. This allows the established state-space model to accurately reflect the complex chemical and thermodynamic coupling dynamics within the CSTR. Linearization modeling based on the Arrhenius equation and the law of conservation of mass and energy ensures high fidelity near the steady-state operating point. The resulting state estimation not only covers the core variables affecting reaction efficiency and safety but also accurately captures changes in system behavior caused by parameter disturbances (such as feed concentration fluctuations or cooling failures). Compared to existing general industrial estimation methods that ignore the unique nonlinear mechanisms of CSTRs and rely solely on black-box models, this approach improves the physical interpretability and process adaptability of the state estimation, providing a reliable foundation for subsequent safety control and fault diagnosis.

[0030] S3: Using Bernoulli random variables, establish a hybrid attack model that simultaneously considers denial-of-service attacks and spoofing attacks. Two Bernoulli random variables are introduced. and To characterize the attack scenario suffered by the i-th sensor at time k: : Indicates whether the i-th sensor at time k is under a denial-of-service (DoS) attack.

[0031] like =0 indicates that a DoS attack has occurred, the communication channel is blocked, and new data cannot be received; like =1 indicates that communication is normal or that it is only under FDI attack.

[0032] This indicates that the attack occurred without a DoS attack (i.e., ...). =1), whether it has been subjected to a Fake Data Injection (FDI) attack.

[0033] like =1 indicates that an FDI attack has occurred and the measurement data has been tampered with; like =0 indicates no FDI attack.

[0034] The two satisfy a probability relationship: ; in Let be known constants, representing the probability that a DoS attack does not occur and the conditional probability of an FDI attack, respectively. The information actually received by the i-th sensor node at time k is... The definition is as follows: Scenario 1: DoS attack ( =0); Since the current measurement value cannot be obtained at this time, a zero-order hold is used to take the measurement value received at the previous time step as the current replacement value: ; in This represents the actual (potentially attacked) measurement value received at time k-1.

[0035] Scenario 2: FDI attack ( =1 and =1); The measured value was then tampered with, and the received data is: ; in Fake data injected by attackers (attack noise). It is a known set of bounded polyhedra, meaning that there exist known positive constants. >0, making .

[0036] Scenario 3: Secure Communication =1 and =0); Accurate transmission of measured values: ; In summary, the unified expression is: ; in, It is the Bernoulli variable of the DoS attack suffered by the sensor at time k; It is the Bernoulli variable of the sensor subjected to the FDI attack at time k; " "This should be understood as the upper bound of the attack noise amplitude, used here..." It indicates that it belongs to a bounded set. ; express The dimensional real vector space, i.e., the output of the i-th sensor is Dimensional vector.

[0037] This technical solution endows two Bernoulli random variables with explicit statistical probability characteristics—one variable representing the prior probability of a denial-of-service attack occurring, and the other representing the conditional probability of a spoofed data injection attack under conditions where communication is not blocked—enabling the hybrid attack model not only to describe whether an attack occurs but also to quantitatively characterize the dependency relationship and joint occurrence pattern between the two types of attacks. Based on conditional probability theory, this design realistically reflects the tactical coupling phenomenon in real-world networks where DoS attacks are often used as a prelude to FDI attacks (e.g., attackers first block normal communication and then inject forged data). The resulting stochastic attack model provides accurate prior attack information for the rolling time-domain estimator, allowing the robustness term in the optimization objective to specifically weight and process measurement reliability under different attack combinations. Compared to the simplistic assumptions in existing technologies that treat DoS and FDI as independent events or completely ignore their correlation, this enhances the estimator's ability to identify and defend against complex coordinated attacks, improving estimation robustness in highly adversarial network environments. In this embodiment, a zero-order hold mechanism is automatically activated upon detecting a denial-of-service attack. The valid measurement value successfully received in the previous time step is used as the substitute input for the current time step, enabling the estimator to maintain basic state prediction and update capabilities during communication interruptions. This avoids estimation divergence or system instability due to data loss. The mechanism operates by utilizing the assumption of short-term continuity in process dynamics, approximating the current state output with historical valid data within a finite time, thus maintaining a smooth transition of the estimated trajectory. This design effectively solves the problem of covariance inflation and a sharp decline in estimation performance caused by the lack of new observations in traditional filters (such as Kalman filters) under DoS attacks. Compared to existing security estimation methods that only employ discarding or simple interpolation strategies for DoS attacks, this scheme improves the system's continuous operation capability and state observability in intermittent communication interruption scenarios without increasing additional communication overhead. Furthermore, by coupling denial-of-service (DoS) attacks and fictitious data injection (FDI) attacks through two associated Bernoulli variables in the hybrid attack model, the attack identification logic is naturally embedded in the estimator design. This design not only characterizes the randomness of attack occurrences but also indirectly provides a basis for weighting measurement confidence in rolling time-domain optimization—when the probability of a DoS attack is high, the weight of the prior term is automatically enhanced; when the conditional probability of FDI is high, the role of the neighbor consistency term is strengthened to suppress local spoofing. This mechanism makes attack statistics no longer just modeling parameters but an "implicit scheduling signal" that dynamically adjusts the estimation strategy, achieving the integration of attack perception and adaptive adjustment of the estimation structure, and achieving an intelligent anti-interference effect far exceeding that of simple robust filtering.

[0038] S4: Based on the system model and attack model, a distributed rolling temporal estimator is designed for each sensor node. At each sampling time k, each sensor node constructs a local optimization objective function based on an estimation window of fixed length N [kN, k]. ; in: : Represents the state estimate of node i at time k with respect to time d; : Represents the prior state estimate of a node at time k-1 relative to the window start time kN; : Represents the measurement value (potentially under attack) actually received by node i at time d; : Positive definite weighting matrix, used to penalize the deviation between the current estimate and the prior estimate; Positive definite weighted matrix, used to measure the goodness of fit of a measurement; : A positive semidefinite weighted matrix, representing the trust weight of node i for information about neighbor j; This represents the weighted norm.

[0039] The objective function consists of three parts: Prior terms: ensure the smoothness of the estimate; Measurement fitting term: Makes the estimated state match the actual received measurement data as closely as possible; Neighbor consensus term: Promotes consensus among neighboring nodes on the state estimation at the window start point.

[0040] The optimization problem must satisfy the system's dynamic constraints: ; in: The actual value received at time d; Predicted measurement value at time d; Current estimates for time steps k-N; The prior estimate of time k-N from the previous time step; All subscripts "Indicates "the estimate of node i at time k".

[0041] In this embodiment, a neighbor consensus term is introduced into the local optimization objective function, and the state estimation information of adjacent sensor nodes at the same starting point of the same time window is fused in a weighted manner. This allows each node to not only rely on its own measurements during the optimization process but also actively refer to the consensus of its neighborhood, thus forming a distributed collaborative estimation mechanism. The principle of this design lies in utilizing the spatial redundancy of the sensor network: even if individual nodes suffer a strong FDI attack that causes a local estimation shift, the true estimates of their neighboring nodes can be "pulled back" by the consensus term, suppressing the propagation of anomalies. (Weight matrix) The introduction of this feature further allows for dynamic adjustment of the fusion strength based on the communication quality or trust level between nodes. Compared to existing distributed estimation methods that simply average or ignore neighbor information, this enhances the fault tolerance and anti-spoofing capabilities of the overall estimation system, maintaining global estimation accuracy even in extreme scenarios where some nodes are maliciously controlled. By simultaneously introducing prior bias, measurement fitting, and neighbor consensus terms into the local optimization objective function, a closed-loop linkage mechanism for error compensation is formed among them: when a node suffers a strong FDI attack that distorts the measurement fitting term, the neighbor consensus term provides correction from the spatial dimension; if multiple neighboring nodes are simultaneously subjected to a DoS attack that weakens consensus information, the prior term maintains estimation stability through the historical smoothness of the time dimension. This coupled design of the "time-space-model" triple constraints enables the system to maintain overall observability even in extreme cases where some sensors completely fail or are maliciously manipulated, achieving the elastic recovery capability of the distributed system under partial collapse, an effect that cannot be achieved by a single-dimensional robust design.

[0042] S5: Solve the local rolling time-domain optimization problem and output the current state estimate.

[0043] For each node i, solve the following optimization problem at time k: ; in: Given a known control input sequence; It is a block matrix composed of A and B (the specific form is omitted, which belongs to the conventional MHE construction).

[0044] Substituting the constraints into the objective function and taking the derivative, we obtain the optimal solution that satisfies: ; The optimal estimate can then be explicitly expressed as: ; in For the reason The gain matrix is ​​determined by the given information.

[0045] Finally, the latest state estimate is taken as the output: ; In this embodiment, the solution of the distributed rolling time-domain estimator is expressed as a correction to the prior estimate of the initial state of the window. The correction amount is jointly determined by the actual received measurement sequence within the window, the known control input sequence, and the system model parameters, giving the estimation process a clear recursive structure and physical interpretability. This design, based on the standard optimization framework of rolling time-domain estimation, transforms the accumulation of multi-step prediction errors into incremental correction of the initial state, preserving the stability of historical information while fully utilizing the timeliness of the latest observations. This structure is easy to implement online, and the explicit dependency of the correction amount helps analyze the impact path of attacks on estimation bias. Compared to existing methods that directly output the entire window state sequence without clear update logic, this approach is easier to embed into real-time control systems and provides traceable error source clues for subsequent attack detection and isolation.

[0046] In this embodiment, by combining the zero-order hold mechanism with the finite window structure of rolling temporal estimation, the data loss under a DoS attack does not accumulate errors indefinitely. Since rolling temporal estimation only relies on data within a fixed-length window, historical old data (including multiple DoS compensation values) is naturally eliminated during window sliding, avoiding the estimation drift problem caused by the continuous use of outdated compensation values ​​in traditional recursive filtering. This design transforms the originally passive fault-tolerance strategy into an active error self-cleaning mechanism, not only maintaining continuous operation but also limiting the impact of DoS attacks on long-term estimation accuracy, achieving a "limited damage, rapid recovery" safety effect.

[0047] S6: Using the Linear Matrix Inequality (LMI) tool, analyze the dynamics of the estimation error and prove that the estimation error is uniformly and eventually bounded in the mean square sense.

[0048] Define the estimation error: ; Error propagation analysis reveals that the error dynamics are affected by attacks, noise, and neighbor bias. To analyze its stability, a Lyapunov-like function is constructed: ; in For the matrix to be designed, Represent the mathematical expectation. Calculate along the error locus. If a positive scalar exists and positive definite matrix This makes the following linear matrix inequality hold: ; Each sub-block Depend on The weight matrix and network topology determine the structure (the specific form is a conventional LMI construction, which will be omitted here). Then, according to Lemma 1 (the ultimate boundedness criterion for the exponential nature of stochastic systems), it can be proved that: ; That is, the estimation error is uniformly bounded in the mean square sense.

[0049] In this embodiment, the estimation error is explicitly defined as the difference between the actual system state and the estimated current state of the sensor nodes. Its dynamic evolution is revealed to be influenced by a combination of hybrid attack behaviors, system process noise, measurement noise, and estimation biases of neighboring nodes, thus providing a complete causal chain for error analysis. This definition provides a clear analytical object for subsequent stability proofs, enabling theoretical derivations to accurately capture the coupling effect of various disturbance sources on estimation performance. Especially under hybrid attacks, the error dynamics simultaneously include the data loss effect caused by DoS and the bias injection effect introduced by FDI. This scheme incorporates these into the same analytical framework through a unified error model. Compared to the simplified analysis in existing studies that only considers a single noise source or ignores the damage to the error structure caused by attacks, this provides a more realistic theoretical basis for designing truly robust estimators.

[0050] S6 provides the theoretical guarantee for the integrity of the method and is used to prove the robustness of the proposed estimator under mixed attacks. It is a necessary technical effect verification and forms a "design-verification" closed loop with S5. Fig. 3 This diagram illustrates the state estimation results of a continuous stirred tank reactor system under a mixed attack in an embodiment of the present invention. (a) shows the comparison curve between the actual and estimated concentrations of reactant A, (b) shows the comparison curve between the actual and estimated concentrations of product B, and (c) shows the comparison curve between the actual and estimated reactor temperature. The solid blue line represents the actual system state, and the dashed red line represents the state estimate obtained using the distributed rolling time-domain estimation method described in this invention. This verifies the method's high-precision and robust online estimation capability for key state variables in scenarios where denial-of-service attacks and spoofed data injection attacks coexist.

[0051] Implementation effect verification: The simulation was performed on the CSTR system according to the above method. The system parameters and steady-state operating point are shown in Table 1: Table 1 It should be noted that, in this document, relational terms such as "one" and "two" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, the phrase "comprising an element defined as..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0052] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A rolling horizon based distributed safety estimation method for a CSTR reactor system, characterized in that, The method comprises the following steps: S1: constructing a multi-sensor network topology for a continuous stirred tank reactor device; S2: based on the network topology, establishing a discretized linear state space model of the continuous stirred tank reactor system to describe the dynamic relationship between the internal state variables of the reactor and the sensor measurement outputs; S3: introducing two interrelated Bernoulli random variables to represent whether each sensor is subjected to a denial of service attack and whether it is subjected to a false data injection attack at each sampling time, thereby constructing a hybrid attack model that can depict denial of service attacks, false data injection attacks and normal communication; Wherein, when a denial of service attack occurs, the measurement value received at the last time is used for zero-order hold compensation, and when a false data injection attack occurs but a denial of service attack does not occur, the received measurement data contains malicious tampering noise within a bounded range; S4: for each sensor node, a distributed rolling horizon estimator is designed to construct a local optimization objective function based on a fixed length finite time window at each sampling time; S5: under the premise of satisfying the system dynamic evolution constraint, the local optimization objective function is solved to obtain the optimal state estimation sequence within the time window, and the system state estimation value at the current time is output; S6: using a linear matrix inequality analysis tool, the estimation error dynamics of the designed distributed rolling horizon estimator are theoretically analyzed, and it is proved that under the combined action of hybrid attacks and bounded system disturbances, the state estimation error of each sensor node is uniformly ultimately bounded in the mean square sense.

2. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The state variables of the continuous stirred tank reactor system include the concentration of reactant A, the concentration of product B and the temperature in the reactor, and the system model parameters include initial concentration, steady-state operating point, coolant temperature, dilution rate, volume flow, heat capacity, heat transfer coefficient, density, reaction rate constant and its corresponding activation energy and frequency factor.

3. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The two Bernoulli random variables have known statistical probability characteristics, one of which represents the probability of denial of service attack, and the other represents the conditional probability of false data injection attack under the condition that communication is not blocked, both of which reflect the randomness and coupling relationship of hybrid attacks.

4. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: When a sensor node determines at a certain time that it is subjected to a denial of service attack and cannot receive new measurement data, a zero-order hold mechanism is automatically enabled, and the measurement value successfully received at the last time of the node is used as the substitute input at the current time to maintain the continuous operation of the estimator.

5. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The local optimization objective function contains a neighbor consistency term, which integrates the state estimation information of adjacent sensor nodes at the start of the same time window through a weighted manner to enhance the overall collaboration and robustness of distributed estimation.

6. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The solution of the distributed rolling horizon estimator can be expressed as a modified form of the prior estimation of the window start state, and the modification amount is determined by the actual received measurement sequence, the known control input sequence and the system model parameters within the window.

7. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The estimation error is defined as the difference between the true system state and the current state estimation of the sensor node, and its dynamic evolution is influenced by the mixed attack behavior, system process noise, measurement noise and neighbor node estimation bias.

8. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: By constructing a Lyapunov-like function and combining the stability theory of stochastic systems, if there exist a positive definite matrix and a positive scalar satisfying certain conditions, it can be strictly proved that the estimation error is ultimately bounded in the mean square sense, and its asymptotic upper bound can be explicitly determined.

9. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The specific conditions are given in the form of linear matrix inequalities, which involve system dynamic matrices, observation structure, attack probability parameters, noise bounds, optimization weight matrices and sensor network topology information, and can be solved and verified by standard convex optimization tools.

10. The distributed safety estimation method for a rolling horizon based tank reactor system according to claim 1, wherein: The method is also applicable to the complex security threat scenario of denial of service attacks and false data injection attacks coexisting in wireless sensor networks, does not rely on the assumption that noise is subject to Gaussian distribution, can effectively handle bounded non-Gaussian disturbances, and realizes online, real-time and high-robust state estimation through a rolling optimization mechanism, ensuring the safe and stable operation of the continuous stirred tank reactor in the information-physical fusion environment.