A method and device for unmanned aerial vehicle safety detection
By grouping and feature screening of drone real-time status information and combining with hybrid deep recognition models, the problem of excessive computing resources consumption and inconsistent detection of drone attack detection is solved, and efficient and accurate drone attack recognition is achieved.
Patent Information
- Application Number
- CN202210361714.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-07
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-04-07
AI Technical Summary
The existing drone attack detection methods lack a unified detection and processing process, cannot effectively identify different types of attacks, and the computing resources are consumed too much, making it difficult to adapt to the computing capacity limitations of small and medium-sized commercial and civilian drones.
The hybrid depth recognition model is used to group the real-time state information of the drone, filter out the most suitable sensor features, and identify them through the convolutional layer, the bidirectional LSTM layer and the attention mechanism layer to reduce computing resource consumption and improve detection efficiency and accuracy.
It realizes efficient and accurate identification of drone attacks when small and medium-sized drones have limited computing resources, providing a unified detection and processing process, improving detection efficiency and accuracy.
Smart Images

Figure CN114997258B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of UAV security, and particularly relates to a UAV security detection method and device. Background Art
[0002] With the rapid development of electronic information and unmanned driving technologies, the application scale of UAVs in military, civilian, industrial, and consumer fields has been continuously expanding. UAVs are widely used in many fields such as aerial photography, agricultural plant protection, express delivery, and data collection, and their application value and market prospects have been further released. It is estimated that the global UAV sales reached 4.33 million units in 2020, and the global UAV output value reached $25.9 billion in 2020.
[0003] In 2011, a virus named "keylogger" was spread to steal a large amount of telemetry and real-time reconnaissance intelligence data of UAVs. Since then, many cases of UAV attacks have started to appear in people's sight, and the security problems of UAVs have become increasingly prominent. After a UAV is attacked, not only is the system itself damaged, causing losses of data and equipment to users, but also accidents such as collisions and crashes may occur, posing a threat to the life and property safety of ground personnel.
[0004] The information security problem of UAV systems is related to their limited wireless communication, infrastructure, storage, and computing resources. Currently, most UAV devices are designed and developed based on general-purpose chips, operating systems, and general protocols. Product manufacturers mostly focus on the functions, performance, and usability of UAV devices, and their security designs are often ignored. As the security risks of UAV systems continue to emerge, system vulnerabilities are also continuously discovered, which will inevitably pose a major threat to the security of UAV systems and seriously hinder the healthy development of the UAV industry.
[0005] The high-precision position information provided by GPS helps to reduce or even eliminate the cumulative error of the inertial measurement unit (IMU). In the case of GPS and IMU integrated navigation, the navigation accuracy, reliability, and anti-interference ability of UAVs have all been improved. However, since the frequency band and data format used by civilian GPS are publicly available, this makes GPS signals vulnerable to interception and tampering. GPS spoofing attacks, that is, by forging or replaying GPS signals, cause GPS receivers to receive forged or replayed GPS signals, so that GPS receivers calculate incorrect position and time information. Such attacks may hijack or crash UAVs, resulting in inestimable consequences.
[0006] Due to the limitations of energy consumption and payload capacity, the computing power of the on-board processors used in drones is weak, making them vulnerable to Denial of Service (DoS) attacks. Therefore, frames can be sent to the drones via a wireless network, significantly reducing the computing speed of the processors. For example, an attacker uses a flood network card to attack the network port of the drone, causing the drone to lose control and crash.
[0007] GPS spoofing attacks and DoS attacks are the most common ways to attack drones. These attacks may control or destroy the drones, and even cause harm to people within the flight area of the drones or damage other aircraft. Therefore, it is urgent to detect drone attacks to resist security issues.
[0008] Existing drone attack detection methods generally do not have a unified detection and processing process. For example, most GPS spoofing attack detection methods are based on the differences between normal GPS signals and false GPS signals, which are not applicable to the detection of other types of attacks (such as DoS attacks). It is also unclear which sensor features are most suitable for drone attack detection, as well as the minimum number of required features, and the data sources of the sensor features used are not comprehensive enough. Moreover, most existing methods with high detection rates are based on models that consume a large amount of computing resources, without considering the limited computing resources of small and medium-sized commercial and civilian drones. Summary of the Invention
[0009] The purpose of the present invention is to provide a drone security detection method and device, which screen the sensor features of the drone and then detect whether an attack occurs, so as to reduce the resource consumption in the detection process.
[0010] The present invention adopts the following technical solutions: A drone security detection method, comprising the following steps:
[0011] Obtain the real-time status information of the drone;
[0012] Based on the real-time status information grouping strategy, generate a number of sub-datasets according to the real-time status information; wherein, each sub-dataset corresponds to a type of drone attack.
[0013] Using the sub-datasets as input information, adopt a hybrid depth recognition model to determine the security status information of the drone; wherein, the security status information is the probability value corresponding to each type of drone attack; the hybrid depth recognition model includes an input layer, a convolutional layer, a bidirectional LSTM layer, an attention mechanism layer, and a direct multiplication layer connected in sequence.
[0014] Preferably, the hybrid depth recognition model optimizes the data parameters through the following method:
[0015] Obtain a training data set; wherein, the training data set is several groups of UAV state information within a training period, and the UAV state information is of the same category as the real-time state information;
[0016] Identify each group of UAV state information;
[0017] Perform normalization processing on each group of identified UAV state information;
[0018] Generate a data group corresponding to each UAV attack type according to each group of UAV state information after normalization processing;
[0019] Train the hybrid depth recognition model using the data groups.
[0020] Preferably, identifying each group of UAV state information includes:
[0021] Determine the first time interval in each group of UAV state information;
[0022] Determine the second time interval according to multiple first time intervals; wherein, the second time interval is the intersection of the first time intervals;
[0023] Identify each group of UAV state information according to the second time interval.
[0024] Preferably, determining the first time interval in each sub-state information includes:
[0025] Determine the first time interval in each group of UAV state information by using the outlier analysis method.
[0026] Preferably, determining the second time interval according to multiple first time intervals includes:
[0027] Select the time interval with the most overlapping times among multiple first time intervals as the second time interval.
[0028] Preferably, generating a data group corresponding to each UAV attack type according to each group of UAV state information after normalization processing includes:
[0029] Generate a data group corresponding to each UAV attack type in each group of UAV state information after normalization processing by using the joint hypothesis testing method.
[0030] Preferably, before training the hybrid depth recognition model using the data groups, it further includes:
[0031] Perform interpolation processing on the data group corresponding to the second time interval;
[0032] Perform downsampling processing on the data group corresponding to the non-second time interval.
[0033] Preferably, the normalization processing is carried out by Implementation;
[0034] Wherein, X norm is the data value after normalization processing, X is the original data in the UAV state information, and X min is the minimum value of the original data in the group where X is located, and X max is the maximum value of the original data in the group where X is located.
[0035] Preferably, the real-time status information grouping strategy is implemented based on the joint hypothesis testing method.
[0036] Another technical solution of the present invention: A UAV safety detection device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned UAV safety detection method is implemented.
[0037] The beneficial effects of the present invention are as follows: By grouping the real-time status information of the UAV, the present invention reduces the amount of data used in the process of identifying the safety status of the UAV, improves the processing efficiency, and at the same time uses each sub-data set after grouping as the input information, and adopts a hybrid depth recognition model to identify and determine the safety status of the UAV at the current moment, which can ensure the accuracy of identifying the safety status of the UAV. Brief Description of the Drawings
[0038] Figure 1 is a flowchart of a UAV safety detection method according to an embodiment of the present invention;
[0039] Figure 2 is a flowchart of a UAV safety detection method according to another embodiment of the present invention;
[0040] Figure 3 is a visualization result diagram when screening features by F-test in an embodiment of the present invention;
[0041] Figure 4 is a schematic architecture diagram of a hybrid depth model in an embodiment of the present invention;
[0042] Figure 5 is a comparison diagram of the training convergence effects of each model for DoS attacks in a verification embodiment of the present invention;
[0043] Figure 6 is a comparison diagram of the training convergence effects of each model for GPS attacks in a verification embodiment of the present invention. Detailed Embodiments
[0044] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0045] Most of the existing UAV attack detection technologies are only applicable to specific types of UAV attacks and do not have a unified detection and processing process. For example, most of the GPS spoofing attack detection methods are based on the differences between normal GPS signals and false GPS signals, which are not applicable to other types of attacks (such as DoS attacks). The existing UAV attack detection technologies do not know which sensor features are most suitable for UAV attack detection and the minimum number of required features, and the data sources of the used sensor features are not comprehensive enough. Most of the existing methods with high detection rates are based on models that consume a large amount of computing resources and do not consider the detection cost. For small and medium-sized commercial and civilian UAVs, the computing resources are limited. To avoid affecting other important components that also require computing resources, the attack detection module should minimize the consumption of computing resources on the basis of ensuring the detection rate.
[0046] The present invention discloses a UAV security detection method, as Figure 1 shown, including the following steps: Step S110, obtaining the real-time status information of the UAV; Step S120, based on the real-time status information grouping strategy (the real-time status information grouping strategy in the embodiment of the present invention is implemented based on the joint hypothesis testing method), generating a plurality of sub-datasets according to the real-time status information; wherein, each sub-dataset corresponds to a type of UAV attack; Step S130, using the sub-dataset as input information and adopting a hybrid depth recognition model to determine the security status information of the UAV; wherein, the security status information is the probability value corresponding to each type of UAV attack; the hybrid depth recognition model includes an input layer, a convolutional layer, a bidirectional LSTM layer, an attention mechanism layer, and a direct connection multiplication layer connected in sequence.
[0047] The present invention groups the real-time status information of the UAV, reduces the amount of data used in the UAV security status recognition process, can improve the processing efficiency, and at the same time uses each sub-dataset after grouping as input information and adopts a hybrid depth recognition model to identify and determine the security status of the UAV at the current moment, which can ensure the accuracy of the UAV security status recognition.
[0048] In one embodiment, as Figure 2 shown, the hybrid depth recognition model optimizes the data parameters through the following method: obtaining a training dataset; wherein, the training dataset is a plurality of groups of UAV status information within the training period, and the UAV status information is of the same type as the real-time status information; identifying each group of UAV status information; performing normalization processing on each group of identified UAV status information; generating a data group corresponding to each type of UAV attack according to each group of UAV status information after normalization processing; and training the hybrid depth recognition model with the data group.
[0049] Specifically, the training dataset can be experimentally collected as needed or obtained through other means. The training dataset should contain all the state information during the flight of the drone. For example, first, install the pyulog module (i.e., a Python module) in the drone system. Then, in the.ulog file directory, the ulog2csv command can be used to convert the drone's ulog file into a csv file required for data preprocessing. The names of these csv files correspond to different data recorded during the drone's flight (there is also a lot of other data in addition to sensor data). Then, visualize the data in each csv file. The purpose of visualization is to determine that the data of each sensor of the drone will change significantly when the drone is attacked, so as to verify the correctness of the method of the embodiment of the present invention.
[0050] In one embodiment, identifying each group of drone state information includes: determining the first time interval in each group of drone state information; determining the second time interval according to multiple first time intervals; wherein, the second time interval is the intersection of the first time intervals; and identifying each group of drone state information according to the second time interval.
[0051] Preferably, determining the first time interval in each sub-state information includes: determining the first time interval in each group of drone state information by using the outlier analysis method. Specifically, the outlier analysis can be used through Python statements to determine the time when each sensor changes most violently. In detail, each csv file is analyzed to determine multiple time intervals, and each time interval is selected from the csv file corresponding to different data. Since the change trend of each type of data is not significant during the normal flight of the drone, then, when the change trend of a certain type of data suddenly becomes very obvious, it can be determined that the time period corresponding to the change interval may be the process when the drone is attacked. Therefore, the time when each sensor changes most violently is selected as the time when the drone is attacked.
[0052] Next, select the time interval with the most overlapping times among the multiple first time intervals as the second time interval. If the time period when a single sensor data changes most violently (i.e., the first time interval) is directly used as the time period when the drone is attacked, it may cause a large problem of discrimination error. Therefore, in the embodiment of the present invention, in order to make the selected time interval more accurate, the first time intervals corresponding to each sensor are selected. If the drone is attacked, there must be a common overlapping sub-time interval among these first time intervals. Finally, the sub-time interval with the most overlapping times is taken as the time interval when the drone is attacked, which can improve the robustness of the time interval selection.
[0053] Then, because each csv file has a timestamp, use python statements to match the timestamp sub-time interval to match and merge all the feature data from different csv files into one csv file, which is convenient for subsequent one-time reading. In this way, the required features after the first round of screening are obtained.
[0054] After the matched and merged data is read in, the data in the aforementioned second sub-time interval and the data in other time intervals are labeled differently. For example, the data in the attacked sub-time interval (second time interval) is labeled as 1, and the data in other time intervals is labeled as 0.
[0055] In order to achieve a high detection rate at the lowest possible cost, a second round of feature screening is performed in the embodiment of the present invention. In this process, the F-test (joint hypothesis test) is first used to screen features, and then based on this, feature screening is performed according to the physical meaning of the sensor data and the effects of GPS spoofing attacks and DoS attacks on drones, so as to reduce the amount of feature data and perform normalization processing.
[0056] Because the computing power of drones is limited, the existing deep models do not consider the detection cost at all but only the accuracy. In order to reduce the computing cost, the present invention must start from two points. The first point is that the designed model needs to be simplified (this point has been met in the model designed later. The parameters of the model are only slightly improved compared to the baseline model, but the accuracy has been greatly improved); the second point is to screen again based on the features screened out in the first round, and the performance of the baseline model will inevitably decrease after feature screening (this is also the reason why the model needs to be redesigned).
[0057] Therefore, the second round of screening needs to eliminate the decrease in accuracy caused by the reduction of feature data as much as possible. First, the features screened in the first round need to be screened according to the F-test (joint hypothesis test), because different types of drone attacks have different effects on drone sensors. For example, GPS spoofing attacks often affect the flight trajectory of drones without causing significant changes in data such as rotor angular velocity and speed; DoS attacks often cause drones to be grounded directly, which will cause significant changes in data such as rotor angular velocity and speed (based on physical meaning and the effect of drone attacks on drones).
[0058] Next, based on the features preliminarily screened by the F-test, the sensor data needs to be grouped according to physical meaning, so that for different types of UAV attacks, the characteristic data suitable for detecting these attacks can be selected respectively (for example, in the DoS attack, the finally selected characteristic data attitude data is mainly divided into sensor data, attitude data, and gyroscope data; in the GPS spoofing attack, the selected characteristic data attitude data is mainly divided into sensor data and coordinate data). As Figure 3 shown, this figure is the visualization of the features screened by the F-test. The abscissa represents the features screened in the first round under different attack types, and the ordinate represents the correlation significance between the features and the labels obtained after calculating the feature P-value (P-value, a criterion in hypothesis testing, used to compare with the significance level) through the F-test. After setting the threshold, the written program will automatically select the most suitable features by judging the size of the ordinate.
[0059] Furthermore, the specific characteristic data selected is shown in Table 1 and Table 2 below.
[0060] Table 1
[0061]
[0062] Table 2
[0063]
[0064]
[0065] Finally, the most effective sensor features for detecting attacks in the shortest time are explored, and the minimum number of required features is verified, which well takes into account the limited computing resources of small and medium-sized UAVs. Since the purpose of this technical solution is to obtain a unified detection and processing flow, but different attack methods have different impacts on UAV sensors, the data features screened according to the processing flow in this technical solution are not fixed and will vary with different attack methods. The two are causal relationships, but the detection and processing flows for different attack methods are completely unified.
[0066] In summary, the joint hypothesis testing method is used to generate data groups corresponding to each UAV attack type in each group of UAV state information after normalization processing.
[0067] As a specific implementation method, Min-max normalization is adopted, and the normalization processing is achieved through ; where X norm is the data value after normalization processing, X is the original data in the UAV state information, X min is the minimum value of the original data in the group where X is located, X maxis the maximum value of the original data in the group where X is located. Normalizing the original data allows the features of different dimensions to be numerically comparable, ensuring the reliability of the results and greatly improving the accuracy of the model.
[0068] Because the time when the drone is attacked is very short compared to the normal flight time of the drone, the amount of drone sensor data when it is attacked is also much less than the amount of data during normal flight. In order to ensure the detection rate of the model, in one embodiment, the data group corresponding to the second time interval is interpolated, that is, the average of every two adjacent data in the attacked data with less data volume is taken to create a new data and insert it between the adjacent data. However, during the detection process of the model, we will delete these generated data in the test set to ensure that all real data are used. Downsampling is performed on the data group corresponding to the non-second time interval.
[0069] Through the above steps, the feature data to be used in the end has been obtained and processed, but before using the model for detection, the data needs to be divided into training sets and test sets (the prerequisite for data set division is the consistency of data distribution, and the role of the above steps has met the data distribution consistency requirements here).
[0070] In one embodiment, the specific steps are to first divide the data set into a training set and a test set in a ratio of 4:1. In the training set, because the duration of the drone being attacked is relatively short compared to the normal flight time, this will cause the aforementioned sub-time interval to account for a relatively small proportion of the entire time interval, which also makes the proportion of data with different labels seriously unbalanced. This problem will cause poor model accuracy in the training set, so we need to perform data balancing processing on the data.
[0071] Specifically, first determine the ratio of unbalanced data, then downsample the majority sample data according to the determined ratio, and interpolate the minority samples (for example, if the majority sample is 10,000 and the minority sample is 1,000, then interpolate the minority samples to generate 999 data, and the number of minority samples will eventually become 1,999. Then, the majority sample is sampled every five, and the number of majority samples will eventually become 2,000, thus achieving data balance). At this point, data balancing is complete. In the test set, all real data is used to ensure the authenticity and effectiveness of the detection effect.
[0072] In the embodiment of the present invention, Figure 4As shown in the figure, the hybrid depth recognition model is mainly divided into: input layer (Inputlayer), convolutional layer (CNN), bidirectional LSTM layer (BiLSTM), attention mechanism layer (Attention layer), and direct multiplication layer (Multiply layer). The design improvement idea of the model is determined according to the characteristics of the UAV sensor data and the feature screening process in this solution, which is fully matched with the aforementioned data preprocessing process and can very well detect UAV attacks (i.e., improvement and enhancement).
[0073] First, the preprocessed feature data is transmitted to the convolutional layer through the input layer (Input layer). Since the one-dimensional time series data is extracted from the UAV sensor, the convolutional layer uses Conv1D (one-dimensional convolution) to extract the features of the UAV sensor time series data, and then a max pooling layer (MaxPooling1D) is connected to speed up the calculation and prevent overfitting. After the convolutional layer extracts the features, the obtained data will be transmitted to the bidirectional LSTM (BiLSTM) layer, which is composed of a forward LSTM and a backward LSTM. The LSTM can very well extract the features of the time series data, and the UAV sensor time series data is closely related before and after, so it is more suitable to use the bidirectional LSTM (BiLSTM) layer to extract the features. After passing through the bidirectional LSTM (BiLSTM) layer, in order to eliminate the impact brought by the data screening and reduction when considering the detection cost issue, an attention mechanism layer (Attention layer) is introduced for the extracted sensor data, hoping to improve the model accuracy by performing weighted transformation on the sensor data. In the direct multiplication layer (Multiply layer), the attention mechanism layer (Attention layer) first performs weighted transformation on the features extracted by the bidirectional LSTM (BiLSTM) layer, and then directly performs multiplication operation on the data after passing through the max pooling layer (MaxPooling1D) and the Dropout layer (which can reduce model overfitting). This can bring an effect similar to residual stacking (skip connect), expressing the output as a linear superposition of the input and a non-linear transformation of the input, preventing gradient disappearance, and being more conducive to improving the model accuracy. After that, the data passes through a fully connected (Dense) layer in the model and outputs the classification probability through the sigmoid function to obtain the final classification judgment (whether the UAV is attacked).
[0074] In the embodiments of the present invention, to demonstrate the more stable and excellent detection effect of the model, the well-known SVM (Supported Vector Machine), BP (Back Propagation Neural Network), CNN (Convolutional Neural Networks), and LSTM (Long Short-Term Memory Networks) are selected as baseline models to be compared with the model (i.e., the hybrid depth recognition model) of the embodiments of the present invention. At the same time, each part of the CNN-BiLSTM-Attention hybrid depth model is also separately compared. The results are as follows:
[0075] (1) Results of the baseline models:
[0076] As Figure 5 shown, it is the detection result of the baseline model for GPS spoofing attacks. The CBA model proposed in the embodiments of the present invention uses a dotted line. The abscissa is the number of epochs of model training, and the ordinate is the loss value of model training. This figure corresponds to the model training process of DoS attack detection, so it is named "Model loss-DoS attack". It can be seen that the model proposed in the embodiments of the present invention can converge faster while improving the accuracy, which helps to improve the timeliness and accuracy of UAV attacks. In addition, the model proposed in the embodiments of the present invention has almost no difference in the convergence speed with other models when dealing with GPS spoofing attacks, and can greatly improve the accuracy, which can improve the accuracy of UAV attack detection while ensuring the timeliness of UAV attack detection. (The convergence speed is visible in the model convergence graph, and the accuracy improvement can be seen in the table)
[0077] The detection results of the baseline models for Dos attacks and GPS spoofing attacks are shown in Table 3 below.
[0078] Table 3
[0079] Model CNN LSTM BP SVM GPS spoofing attack 85.4% 84.2% 86.1% 82.2% DoS attack 96.4% 94.7% 91.2% 94.7%
[0080] (2) Results of the CNN+BiLSTM+Attention model and comparison with different combinations:
[0081] As Figure 6As shown, this figure corresponds to the model training process for GPS spoofing attack detection, so it is named "Modelloss - GPS Spoofing attack". It can be seen that the model proposed in the embodiment of the present invention has almost no difference in the convergence speed compared with other models, and can significantly improve the accuracy, being able to improve the accuracy of UAV attack detection while ensuring the timeliness of UAV attack detection. The present invention lists the comparison results of different combinations of this model and its components, as well as the data features adopted after the second - round reduction and screening according to the actual physical meaning.
[0082] The detection results for GPS spoofing attack are shown in Table 4 as follows:
[0083] Table 4
[0084]
[0085] The detection results for DoS attack are shown in Table 5 as follows.
[0086] Table 5
[0087]
[0088]
[0089] According to the experimental results, it can be seen that the CNN + BiLSTM + Attention hybrid deep model significantly improves the attack detection rate after feature reduction, meets the requirements of limited computing power of commercial and civilian small UAVs, and in the actual experiment, the parameters of the model are controlled within one order of magnitude, obtaining a higher detection rate at a very small time cost and ensuring the timeliness.
[0090] In summary, for the problem of UAV attack detection, the present invention proposes a unified detection and processing flow for different types of attack methods. It explores the most effective sensor features for detecting attacks in the shortest time and verifies the minimum number of required features. It proposes that the CNN - BiLSTM - Attention hybrid deep model achieves excellent and stable detection results at low cost.
[0091] Regarding the problem that the existing UAV attack detection technology is not clear about which sensor features are most suitable for UAV attack detection, the minimum number of required features, and the source of sensor feature data used is not comprehensive enough, this technical solution explores the most effective sensor features for detecting attacks in the shortest time and verifies the minimum number of required features.
[0092] Most existing methods with high detection rates are based on models that consume a large amount of computing resources, without considering the limited computing resources of small and medium-sized commercial and civilian drones. To address this issue, based on reducing the features used according to the actual physical meaning, this technical solution proposes a hybrid model CNN-BiLSTM-Attention to detect attacks and achieves more excellent and stable detection results.
[0093] The present invention also discloses a drone security detection device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the above-mentioned drone security detection method.
[0094] It should be noted that for the information interaction, execution process, etc. between the modules of the above device, since they are based on the same concept as the method embodiment of the present invention, their specific functions and the technical effects brought can be specifically referred to in the method embodiment part, and will not be elaborated here.
[0095] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. Each functional module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiment and will not be elaborated here.
[0096] The device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The device can include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the device can include more or fewer components, or combine certain components, or different components. For example, it can also include input and output devices, network access devices, etc.
[0097] The processor can be a Central Processing Unit (CPU), and it can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0098] In some embodiments, the memory can be an internal storage unit of the device, such as the hard disk or memory of the device. In other embodiments, the memory can also be an external storage device of the device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the device. Further, the memory can also include both the internal storage unit and the external storage device of the device. The memory is used to store the operating system, application programs, BootLoader, data, and other programs, such as the program code of the computer program, etc. The memory can also be used to temporarily store the data that has been output or will be output.
[0099] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments. Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
Claims
1. A method for safety detection of an unmanned aerial vehicle, characterized in that, Including the following steps: Obtain the real-time status information of the drone; the real-time status information includes the position data, speed data, acceleration data, and attitude data of the drone; Based on the real-time status information grouping strategy, generate a number of sub-datasets according to the real-time status information; wherein, each sub-dataset corresponds to a type of drone attack; Using the sub-datasets as input information, adopt a hybrid depth recognition model to determine the security status information of the drone; wherein, the security status information is the probability value corresponding to each type of drone attack; the hybrid depth recognition model includes an input layer, a convolutional layer, a bidirectional LSTM layer, an attention mechanism layer, and a direct multiplication layer connected in sequence; the direct multiplication layer is used to perform multiplication operations on the data.
2. The drone safety detection method according to claim 1, characterized in that The data parameters of the hybrid depth recognition model are optimized by the following method: Obtain the training dataset; wherein, the training dataset is a number of groups of drone status information within the training period, and the drone status information is of the same category as the real-time status information; Label each group of the drone status information; Perform normalization processing on each labeled group of the drone status information; Generate a data group corresponding to each type of drone attack according to each group of normalized drone status information; Use the data groups to train the hybrid depth recognition model.
3. The method for drone safety detection according to claim 2, characterized in that, Labeling each group of the drone status information includes: Determine the first time interval in each group of the drone status information; Determine the second time interval according to multiple first time intervals; wherein, the second time interval is the intersection of the first time intervals; Label each group of the drone status information according to the second time interval.
4. The drone safety detection method according to claim 2, characterized in that, Determining the first time interval in each of the drone status information includes: Determine the first time interval in each group of the drone status information by the outlier analysis method.
5. A method for detecting the safety of a drone according to claim 3 or 4, characterized in that, Determining the second time interval according to multiple first time intervals includes: Select the time interval with the most overlapping times among the multiple first time intervals as the second time interval.
6. The method for drone safety detection according to claim 2, characterized in that, Generating a data group corresponding to each type of drone attack according to each group of normalized drone status information includes: Generate a data group corresponding to each type of drone attack in each group of normalized drone status information by the joint hypothesis testing method.
7. The method for detecting the safety of an unmanned aerial vehicle according to claim 3, characterized in that, Before using the data groups to train the hybrid depth recognition model, it further includes: Perform interpolation processing on the data groups corresponding to the second time interval; Perform downsampling processing on the data groups not corresponding to the second time interval.
8. The method for drone safety detection according to claim 7, characterized in that, The normalization process is achieved by ; Among them, is the data value after normalization processing, X is the original data in the UAV state information, is the minimum value of the original data in the group where it is located, is the maximum value of the original data in the group where it is located.
9. The method for detecting the safety of an unmanned aerial vehicle according to claim 6, wherein, The real-time status information grouping strategy is implemented based on the joint hypothesis testing method.
10. A drone safety detection device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a drone security detection method according to any one of claims 1-9.
Citation Information
Patent Citations
A system for detecting concept deviations and network-based attacks in network traffic
DE202022100122U1