A method and related equipment for detecting abnormal signals of myoelectric control system under malicious attack
By calculating channel characteristics of standard sample data and interfering sample data in the electromyography control system and training the SVM classifier, the error classification problem of deep learning methods when maliciously attacked is solved, and the abnormal signals are identified and filtered, improving the security of the system.
Patent Information
- Application Number
- CN202210138472.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-15
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-02-15
AI Technical Summary
When the electromyography control system is maliciously attacked, deep learning methods, especially gesture recognition methods based on convolutional neural networks, are vulnerable to attacks, resulting in incorrect classification, and it is difficult to identify abnormal signals.
By obtaining standard sample data and interference sample data after the disturbance signal is applied, the channel characteristics of each channel are calculated and the Support Vector Machine (SVM) classifier is trained to enable it to filter interference sample data.
It realizes the identification of abnormal signals after malicious attacks in the electromyography control system, improves the security and reliability of the system, and prevents misclassification caused by malicious attacks.
Smart Images

Figure CN114492537B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of signal processing, and in particular to a method and related equipment for detecting abnormal signals of a myoelectric control system subjected to malicious attacks. Background Art
[0002] Electromyography (EMG) is a bioelectric signal accompanying muscle contraction, which can be used to characterize the user's movement state or movement intention. When the human body needs to perform muscle activity, the brain transmits the movement command to the central nervous system and controls the muscle tissue by activating the corresponding motor neurons to obtain the desired activity effect. Since surface electromyography (SEMG) can be obtained using surface electrodes, it reflects the intensity and flexion and extension of the movement joints, as well as the movement, shape, position and orientation of the hand during the gesture completion process, and has unique advantages in gesture recognition.
[0003] Myoelectric control is a technology that uses surface electromyographic signals to convert movements or intentions into commands for manipulating prostheses or other external robotic devices. Myoelectric pattern recognition is considered a milestone technological development that is capable of controlling multiple degrees of freedom. The methods for implementing myoelectric pattern recognition can be roughly divided into traditional methods and deep learning methods. In recent years, deep learning methods have been shown to be more accurate in recognizing gestures. However, deep learning methods, especially gesture recognition methods based on convolutional neural networks (CNNs), are vulnerable to attacks and produce incorrect classifications. Summary of the invention
[0004] In view of this, an embodiment of the present invention provides a method and related equipment for detecting abnormal signals of a myoelectric control system under malicious attack, so as to realize the recognition of abnormal signals.
[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:
[0006] A method for detecting abnormal signals of a myoelectric control system under malicious attack, comprising:
[0007] Acquire standard sample data, where the standard sample data is an electromyographic signal corresponding to a known gesture action;
[0008] A disturbance signal is applied to the standard sample data using a preset attack algorithm, which is recorded as interference sample data;
[0009] Calculating the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample;
[0010] The SVM classifier is trained using the channel features corresponding to the standard sample data and the interference sample data, so that the SVM classifier can filter the interference sample data.
[0011] Optionally, in the above-mentioned abnormal signal detection method for a myoelectric control system subjected to a malicious attack, the step of applying a disturbance signal to the standard sample data using a preset attack algorithm includes:
[0012] A disturbance signal is applied to the standard sample data by using a general adversarial perturbation attack algorithm based on DeepFool, a general adversarial perturbation attack algorithm based on a generative network, and / or a general adversarial perturbation attack algorithm based on total loss minimization.
[0013] Optionally, in the above-mentioned abnormal signal detection method for a myoelectric control system subjected to a malicious attack, calculating the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample includes:
[0014] The Chebyshev distances between each channel and other adjacent channels in the standard sample data and the interference sample data are calculated, and the sum of the Chebyshev distances between each channel and other adjacent channels is used as the channel feature of the channel.
[0015] Optionally, in the above-mentioned abnormal signal detection method for a myoelectric control system subjected to a malicious attack, obtaining standard sample data includes:
[0016] The electromyographic signals generated when M different subjects perform N different actions are collected as standard sample data, where M and N are positive integers not less than 1.
[0017] Optionally, in the above abnormal signal detection method for a myoelectric control system under malicious attack, the myoelectric signals generated when M different subjects perform N different actions are collected as standard sample data, including:
[0018] The continuous electromyographic signals of M subjects when they continuously perform N different actions and the electromyographic signals in a resting state are collected through the electrode devices at the sampling points of the subjects;
[0019] The continuous electromyographic signal is segmented using the electromyographic signal in a resting state to obtain segmented electromyographic sample data, and the segmented electromyographic sample data is used as the standard sample data.
[0020] Optionally, in the above-mentioned abnormal signal detection method for a maliciously attacked electromyographic control system, the electrode device is a flexible high-density electrode array with p row channels, q column channels, and a density of D, and the values of p and q are both greater than 1, and the value of D is greater than 0.
[0021] Optionally, in the above-mentioned abnormal signal detection method for a myoelectric control system subjected to a malicious attack, when a disturbance signal is applied to the standard sample data using a preset attack algorithm, the disturbance signal includes a disturbance signal and noise, and the disturbance amplitude of the disturbance signal ||v|| p ≤0.05.
[0022] An abnormal signal detection device for a myoelectric control system under malicious attack, comprising:
[0023] A standard sample acquisition unit, used to acquire standard sample data, wherein the standard sample data is an electromyographic signal corresponding to a known gesture action;
[0024] An abnormal sample generating unit, used for applying a disturbance signal to the standard sample data by using a preset attack algorithm, recorded as interference sample data;
[0025] A channel feature calculation unit, used to calculate the channel feature of each channel in the standard sample data and the channel feature of each channel in the interference sample;
[0026] The training unit is used to train the SVM classifier by using the channel features corresponding to the standard sample data and the interference sample data, so that the SVM classifier can filter the interference sample data.
[0027] An electronic device, comprising: a memory and a processor;
[0028] The memory is used to store programs;
[0029] The processor is used to execute the program to implement each step of the abnormal signal detection method for a myoelectric control system under malicious attack as described in any one of the above items.
[0030] A classifier is an SVM classifier trained by using any one of the above-mentioned abnormal signal detection methods for a myoelectric control system subjected to malicious attacks.
[0031] Based on the above technical scheme, the above scheme provided by the embodiment of the present invention configures the standard sample data of the electromyographic signal and the interference sample data after applying the disturbance signal, calculates the channel characteristics of the standard sample data and the interference sample data, and then trains the SVM classifier based on the channel characteristics, so that the classifier can recognize the electromyographic signal after the disturbance signal is applied, thereby realizing the detection of abnormal signals that are maliciously attacked in the electromyographic control system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0033] Figure 1 A flow chart of an abnormal signal detection method for a myoelectric control system subjected to a malicious attack disclosed in an embodiment of the present application;
[0034] Figure 2 is a schematic diagram of the structure of the electrode device;
[0035] Figure 3 This is a schematic diagram of the structure of the gesture classification network;
[0036] Figure 4 It is a schematic diagram of the structure of the abnormal signal detection device for the myoelectric control system under malicious attack disclosed in the embodiment of the present application;
[0037] Figure 5 A schematic diagram of the structure of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0039] The present application discloses a method of controlling a classifier to identify abnormal data of an electromyographic signal based on the channel characteristics of the electromyographic signal when predicting gestures based on the electromyographic signal through a deep learning network, and judging whether the electromyographic signal is a normal electromyographic signal or an interfered electromyographic signal based on the identification result, thereby realizing the detection of abnormal signals that are maliciously attacked during the gesture prediction process.
[0040] See also Figure 1 , this application discloses a method for detecting abnormal signals of a myoelectric control system under malicious attack, see Figure 1 , the method may include:
[0041] Step S101: Acquire standard sample data, where the standard sample data is an electromyographic signal corresponding to a known gesture action.
[0042] In the technical solution disclosed in the embodiment of the present application, the SVM classifier is mainly trained so that the SVM classifier can identify the interfered electromyographic signal.
[0043] In this step, the standard sample data refers to the electromyographic signals of the corresponding gesture actions that have been calibrated, and the number of standard sample data can be set according to user needs.
[0044] For example, the electromyographic signal set corresponding to action A, the electromyographic signal set corresponding to action B, and the electromyographic signal set corresponding to action C, the electromyographic signals in these electromyographic signal sets corresponding to actions can all be used as standard sample data, and these data are used as positive data to train the SVM classifier.
[0045] These data can be obtained by collecting data from multiple subjects. For example, the specific collection process of the standard sample data of this step can be: the electromyographic signals generated when M different subjects perform N different actions are collected as standard sample data, and N and N are positive integers not less than 1. For example, M can be 8, N can be 6, and the 6 actions can include index finger extension, middle finger extension, little finger extension, index finger and middle finger extension, three fingers extension and wrist extension. Each action is collected 10 times, and each time the isometric contraction of medium force is maintained for the first duration (which can be 5 seconds), and the subjects can be given sufficient rest time between the exercise processes. During the rest process, the electromyographic signals in the resting state of the first duration can be collected. In this process, the collection of electromyographic signals is realized by an electrode device, which is fixed at the sampling point of the subject (for example, it can be the forearm finger extensor muscle group), and the continuous electromyographic signals of M subjects when they continuously perform N different actions are collected. The continuous electromyographic signal refers to the uninterrupted electromyographic signal generated in the process when the subject completes the previous action and then performs the next action. After obtaining the continuous electromyographic signal, the electromyographic signals of M subjects in a resting state of a preset length are collected. The electromyographic signal in the resting state refers to the electromyographic signal collected by the electrode device when the user does not perform any gesture. The continuous electromyographic signal is segmented using the electromyographic signal in the resting state to obtain the segmented electromyographic sample data. At this time, the electromyographic sample data obtained after segmentation is the electromyographic signal corresponding to the user performing a certain gesture action, and the segmented electromyographic sample data is used as the standard sample data.
[0046] Wherein, the structure type of the electrode device is as follows Figure 2As shown, the electrode device is provided with electromyographic signal collection electrodes distributed in a square shape. When collecting electromyographic signals, the collection electrodes on the electrode device need to be in contact with the user's skin. The configuration of the electrode device can be configured according to user needs. The number of row channels is p, the number of column channels is q, and the density is D. The flexible high-density electrode array, the values of p and q are both greater than 1, and the value of D is greater than 0. Specifically, p=10, q=10, and D=7mm can be set.
[0047] In the specific process of obtaining standard sample data provided in the present application, after collecting a batch of electromyographic signals of gesture actions, the electromyographic signals are preprocessed (preprocessing may refer to difference processing, filtering processing, etc.), and then the active segment of the electromyographic signal is subjected to sliding window, and the electromyographic signal stream in the resting state is selected to form an analysis window for segmenting the electromyographic signal, and the resting state threshold is calculated as Th; the resting state threshold Th is used to determine whether all analysis windows are active segments of muscle contraction, and if so, the sliding window technology is used to segment the continuous electromyographic signal stream into a certain number of analysis windows, with a window length of N and a sliding increment of L; the corresponding action task label (such as handshake, clapping and other gesture actions) is marked and used as a standard electromyographic sample data, and any one of the electromyographic samples is recorded as X∈R N×C , where N represents the number of sampling points and C represents the number of electrode channels. In order to better reflect the spatial information of the muscle, the electromyographic samples are transformed into The form of electromyographic image, where C row and C col Respectively represent the height and width of the electromyographic image. In the above process, the resting state threshold Th can be obtained by adding three times the standard deviation of the average value of the electromyographic signals of all channels in the electromyographic sample data collected in the resting state, N = 256ms, L = 128ms, and in order to facilitate subsequent processing and calculation of general adversarial perturbations, the obtained electromyographic sample data can be normalized.
[0048] Step S102: using a preset attack algorithm to apply a disturbance signal to the standard sample data, which is recorded as interference sample data.
[0049] In this step, a pre-configured attack algorithm may be used to attack the standard sample data, thereby applying a disturbance signal to the standard sample data.
[0050] In this scheme, the type of attack algorithm can be configured according to user needs. For example, in this scheme, the attack algorithm may include but is not limited to DeepFool-based universal adversarial perturbation (DF-based UAP), generative model-based universal adversarial perturbation (GM-based UAP), and total loss minimization-based universal adversarial perturbation (TLM-based UAP). At this time, the use of a preset attack algorithm to apply a perturbation signal to the standard sample data includes: applying a perturbation signal to the standard sample data through a DeepFool-based universal adversarial perturbation attack algorithm, a generative network-based universal adversarial perturbation attack algorithm, and / or a universal adversarial perturbation attack algorithm based on total loss minimization.
[0051] When using the attack algorithm to apply interference signals, the general adversarial perturbation attack algorithm based on DeepFool is mainly based on calculating the minimum perturbation that changes the sample category. For the binary classification problem, the decision surface function is defined as f(x) = w T x+b, the minimum perturbation can be obtained by the formula For multi-classification problems, the distance from the sample point to each interface needs to be calculated, and then the minimum distance is compared, which is the interference value to be achieved. The general adversarial perturbation attack algorithm based on the generative network uses a generative adversarial network to learn the overall distribution of the perturbation, and outputs a general adversarial perturbation by inputting a random noise sampled from a normal distribution. The loss function of the network optimization is designed as where c 0 Represents the true category, and κ represents the confidence threshold. When the predicted category is the second possible category other than the true category, the total loss will be minimized. The general adversarial perturbation attack algorithm based on total loss minimization achieves the attack effect by increasing the network loss and causing the model to misclassify. The loss function of the network optimization is designed as Where l(x+v, y) represents the loss function, y represents the label of sample x, C(x, v) represents the restriction on perturbation v, and α is the regularization coefficient. l(x, y) is designed to be log(p y(x)), to minimize the possibility of the true category. When training the model, the adversarial model can be used to generate universal adversarial perturbations through three attack algorithms in advance, and then the standard electromyographic sample data is input into the adversarial model, so that the adversarial model generates three universal adversarial perturbations corresponding to the standard sample data: DF-based UAP, GM-based UAP, and TLM-based UAP.
[0052] Furthermore, in a specific implementation, in order to make the disturbance not easily discovered, the disturbance amplitude can be limited to ||v|| p ≤0.05, and the same size of random noise is added as a comparative experiment, because if random noise can greatly reduce the classification performance of the gesture classification network (the gesture classification network is a gesture classification network designed based on a convolutional neural network), there is no need to design disturbances. Noise and the above three disturbances v (DF-based UAP, GM-based UAP, TLM-based UAP) are added to the standard sample data respectively, and then input into the gesture classification network, the gesture classification network can output the prediction results of the electromyographic samples of the standard sample data (interference sample data) after the disturbance is added; it has been verified that before abnormal signal detection, the recognition accuracy of the gesture classification network for standard electromyographic data, standard electromyographic data after adding random noise, standard electromyographic data after adding DF-based UAP, standard electromyographic data after adding GM-based UAP, and standard electromyographic data after adding TLM-based UAP are 90.80%, 79.28%, 36.67%, 51.43% and 14.72% respectively. It can be seen that after adding universal adversarial perturbations, the classification ability of the network will drop significantly, while adding random noise will not. Therefore, a well-designed universal adversarial perturbation may cause the gesture classification network based on the convolutional neural network to lose its classification ability, which will bring huge safety risks to the electromyographic control system. Therefore, before inputting into the gesture classification network, enabling the electromyographic control system to recognize the electromyographic signal with the perturbation is one of the technical problems that must be solved at present.
[0053] Step S103: Calculate the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample data.
[0054] In order to enable the SVM classifier to accurately identify the interference sample data with the disturbance signal added, in this solution, it is necessary to train the SVM classifier based on the channel features of each channel in the standard sample data and the interference sample data.
[0055] The channel feature described in this scheme may refer to the sum of the Chebyshev distances corresponding to each channel, that is, when calculating the channel feature, the Chebyshev distances between each channel and other adjacent channels in the standard sample data and the interference sample data are calculated, and the sum of the Chebyshev distances between each channel and other adjacent channels is used as the channel feature of the channel.
[0056] Here, the data forms of the standard sample data and the interference sample data can be: For each channel's electromyographic signal, calculate the Chebyshev distance between the channel and each of its adjacent channels. For example, for channel x p,q (t), calculate max|x p,q (t)-x p-1,q-1 (t)|,max|x p,q (t)-x p-1,q (t)|,max|x p,q (t)-x p-1,q+1 (t)|,max|x p,q (t)-x p,q-1 (t)|,max|x p,q (t)-x p,q+1 (t)|,max|x p,q (t)-x p+1,q-1 (t)|,max|x p,q (t)-x p+1,q (t)|,max|x p,q (t)-x p+1,q+1 (t)|. Then the sum of all Chebyshev distances between each channel and its adjacent channels is taken as the channel feature of the channel.
[0057] In the above scheme, if the element whose channel features need to be calculated is located at a vertex position in the data matrix of the standard sample data and the interference sample data, it is necessary to calculate the Chebyshev distance between it and the three adjacent channels. If it is located at a non-vertex position on the edge of the data matrix, it is necessary to calculate the Chebyshev distance between it and the five adjacent channels. For channels at other positions, it is necessary to calculate the Chebyshev distance between it and the eight adjacent channels.
[0058] Step S104: using the interference sample data and the corresponding channel features to train the SVM classifier, so that the SVM classifier can filter the interference sample data.
[0059] In step S104, after calculating the channel features of each channel in the standard sample data and the interference sample data and the channel features of each channel in the interference sample, the SVM classifier is trained using the channel features corresponding to the standard sample data and the interference sample data, wherein the SVM classifier selects an SVM with an RBF kernel, and the standard sample data and the interference sample data contained in the training set can be in a ratio of 1:1, wherein the standard sample data is labeled as 0 and the interference sample data is labeled as 1. In this solution, in order to speed up the training process, the interference sample data can be generated by adding TLM-based UAP, because the generation speed of such interference is fast and the training time is short, and the test set contains standard sample data and interference sample data generated by three different universal adversarial perturbations. After training the SVM classifier with the channel features corresponding to the standard sample data and the interference sample data, the SVM classifier can accurately identify the interference sample data, and the trained SVM classifier can be used to classify the samples in the test set and detect the interference sample data. The detection method uses the detection rate as an indicator, which is defined as the number of samples correctly detected / the total number of samples.
[0060] In this solution, after configuring the standard sample data of the electromyographic signal and the interference sample data after applying the disturbance signal, the channel characteristics of the standard sample data and the interference sample data are calculated, and then the SVM classifier is trained based on the channel characteristics, so that the classifier can recognize the electromyographic signal after applying the disturbance signal, thereby realizing the detection of abnormal signals that are maliciously attacked in the electromyographic control system.
[0061] When training the SVM classifier, the channel features of each channel in the standard sample data and the interference sample data can be used as the input data of the SVM classifier. After analyzing the channel features of each channel in the standard sample data and the interference sample data, the SVM classifier outputs the corresponding labels 0 and 1. By continuously inputting the standard sample data and the interference sample data into the SVM classifier, the SVM classifier is controlled to continuously adjust the internal recognition algorithm, so that the SVM classifier can accurately identify which are the interference sample data and which are the standard sample data. If the SVM classifier does not perform gesture recognition on the interference sample data after identifying it, it can be directly abandoned. After the SVM classifier recognizes the standard sample data, it inputs it into the gesture classification network to perform gesture recognition on it.
[0062] In a technical solution disclosed in another embodiment of the present application, the action of calculating the channel features of each channel in the standard sample data and the channel features of each channel in the interference sample can also be performed inside the classifier.
[0063] In this application, after the abnormal signal detection is completed, the gesture prediction can be performed on the acquired electromyographic sample data through the gesture classification network, and the input of the gesture classification network is the electromyographic data collected by the motor device, see Figure 3 The gesture classification network consists of two convolution blocks Block 1 and Block 2, an expansion layer, and three fully connected layers. The gesture classification network passes the electromyographic data through two convolution blocks, each of which contains a convolution layer, a batch normalization layer, and a maximum pooling layer. The convolution layer is used to extract the spatial features of the electromyographic signal, the batch normalization layer is used to accelerate the training and convergence speed of the network and prevent the network from overfitting, and the maximum pooling layer is used to reduce the dimension of the features. Then, after three fully connected layers, the activation functions of the two fully connected layers are ReLU functions, and the activation function of the last fully connected layer is SoftMax function, the probability value of the gesture corresponding to the electromyographic data is obtained, wherein the fully connected layer mainly plays the role of transforming the dimension, and the SoftMax function can adjust the output of the network to probability so that the sum is 1, which is convenient for classification; finally, the network outputs the gesture prediction result for the sample.
[0064] Corresponding to the abnormal signal detection method for a myoelectric control system under malicious attack in the above-mentioned embodiment, this embodiment discloses an abnormal signal detection device for a myoelectric control system under malicious attack. For the specific working content of each unit in the device, please refer to the content of the above-mentioned method embodiment.
[0065] The following is a description of an abnormal signal detection device for a myoelectric control system under malicious attack provided by an embodiment of the present invention. The abnormal signal detection device for a myoelectric control system under malicious attack described below and the abnormal signal detection method for a myoelectric control system under malicious attack described above can refer to each other.
[0066] See also Figure 4 The abnormal signal detection device for a myoelectric control system under malicious attack disclosed in an embodiment of the present application may include: a standard sample acquisition unit A, an abnormal sample generation unit B, a channel feature calculation unit C and a training unit D.
[0067] The standard sample acquisition unit A corresponds to step S101 in the above method and is used to obtain standard sample data, where the standard sample data is an electromyographic signal corresponding to a known gesture action;
[0068] The abnormal sample generating unit B corresponds to step S102 in the above method, and is used to apply a disturbance signal to the standard sample data using a preset attack algorithm, which is recorded as interference sample data;
[0069] A channel feature calculation unit C, corresponding to step S103 in the above method, is used to calculate the channel features of each channel of the standard sample data and the channel features of each channel in the interference sample;
[0070] The training unit D corresponds to step S104 in the above method, and is used to train the SVM classifier using the interference sample data and the corresponding channel features, so that the SVM classifier can filter the interference sample data.
[0071] Corresponding to the above method, the present application also discloses an electronic device, see Figure 5 , the electronic device may include: at least one processor 100, at least one communication interface 200, at least one memory 300 and at least one communication bus 400;
[0072] In the embodiment of the present invention, the number of the processor 100, the communication interface 200, the memory 300, and the communication bus 400 is at least one, and the processor 100, the communication interface 200, and the memory 300 communicate with each other through the communication bus 400; obviously, Figure 5 The communication connections shown for the processor 100, the communication interface 200, the memory 300, and the communication bus 400 are merely optional;
[0073] Optionally, the communication interface 200 may be an interface of a communication module, such as an interface of a GSM module;
[0074] The processor 100 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.
[0075] The memory 300 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0076] The processor 100 is specifically configured to:
[0077] Acquire standard sample data, where the standard sample data is an electromyographic signal corresponding to a known gesture action;
[0078] A disturbance signal is applied to the standard sample data using a preset attack algorithm, which is recorded as interference sample data;
[0079] Calculating the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample;
[0080] The standard sample data, the interference sample data and the corresponding channel features are used to train the SVM classifier, so that the SVM classifier can filter the interference sample data.
[0081] A classifier and an electromyographic control system using the classifier, wherein the classifier is an SVM classifier trained by any of the above-mentioned abnormal signal detection methods for a myoelectric control system subjected to malicious attacks.
[0082] For the convenience of description, the above system is described as being divided into various modules according to their functions. Of course, when implementing the present invention, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0083] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can refer to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without creative work.
[0084] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0085] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0086] It should also be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0087] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for detecting abnormal signals of a myoelectric control system under malicious attack. It is characterized in that include: Acquire standard sample data, where the standard sample data is an electromyographic signal corresponding to a known gesture action; A disturbance signal is applied to the standard sample data using a preset attack algorithm, which is recorded as interference sample data; Calculating the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample; The SVM classifier is trained using the channel features corresponding to the standard sample data and the interference sample data, so that the SVM classifier can filter the interference sample data; The calculation of the channel characteristics of each channel in the standard sample data and the channel characteristics of each channel in the interference sample includes: The Chebyshev distances between each channel and other adjacent channels in the standard sample data and the interference sample data are calculated, and the sum of the Chebyshev distances between each channel and other adjacent channels is used as the channel feature of the channel.
2. The method for detecting abnormal signals of a myoelectric control system under malicious attack according to claim 1, It is characterized in that The using a preset attack algorithm to apply a disturbance signal to the standard sample data includes: A disturbance signal is applied to the standard sample data by using a general adversarial perturbation attack algorithm based on DeepFool, a general adversarial perturbation attack algorithm based on a generative network, and / or a general adversarial perturbation attack algorithm based on total loss minimization.
3. The abnormal signal detection method for a myoelectric control system subjected to malicious attack according to claim 1, It is characterized in that Obtaining standard sample data includes: The electromyographic signals generated when M different subjects perform N different actions are collected as standard sample data, where M and N are positive integers not less than 1.
4. The abnormal signal detection method for a myoelectric control system subjected to malicious attack according to claim 1, It is characterized in that The electromyographic signals generated by M different subjects performing N different actions are collected as standard sample data, including: The continuous electromyographic signals of M subjects when they continuously perform N different actions and the electromyographic signals in a resting state are collected through the electrode devices at the sampling points of the subjects; The continuous electromyographic signal is segmented using the electromyographic signal in a resting state to obtain segmented electromyographic sample data, and the segmented electromyographic sample data is used as the standard sample data.
5. The abnormal signal detection method for a myoelectric control system subjected to malicious attack according to claim 4, It is characterized in that The electrode device has a row channel number of p, a column channel number of q, and a flexible high-density electrode array with a density of D. The values of p and q are both greater than 1, and the value of D is greater than 0.
6. The abnormal signal detection method for a myoelectric control system subjected to malicious attack according to claim 4, It is characterized in that When a disturbance signal is applied to the standard sample data using a preset attack algorithm, the disturbance signal includes a disturbance signal and noise, and the disturbance amplitude of the disturbance signal ||v|| p ≤0.
05.
7. An abnormal signal detection device for a myoelectric control system under malicious attack, It is characterized in that include: A standard sample acquisition unit, used to acquire standard sample data, wherein the standard sample data is an electromyographic signal corresponding to a known gesture action; An abnormal sample generating unit, used for applying a disturbance signal to the standard sample data by using a preset attack algorithm, recorded as interference sample data; A channel feature calculation unit, used to calculate the channel feature of each channel in the standard sample data and the channel feature of each channel in the interference sample; A training unit, used to train the SVM classifier using the channel features corresponding to the standard sample data and the interference sample data, so that the SVM classifier can filter the interference sample data; The channel feature calculation unit calculates the channel features of each channel in the standard sample data and the channel features of each channel in the interference sample, specifically for: The Chebyshev distances between each channel and other adjacent channels in the standard sample data and the interference sample data are calculated, and the sum of the Chebyshev distances between each channel and other adjacent channels is used as the channel feature of the channel.
8. An electronic device, It is characterized in that include: including memory and processor; The memory is used to store programs; The processor is used to execute the program to implement each step of the abnormal signal detection method for a myoelectric control system under malicious attack as described in any one of claims 1-6.
9. A myoelectric control system using a classifier, It is characterized in that The classifier is an SVM classifier trained by using the abnormal signal detection method for a myoelectric control system subjected to malicious attacks as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Human-computer interaction method and system based on dynamic gesture recognition
AU2021101815A4
Myoelectricity control method and device
CN111783719A