Fault and attack detection methods, systems, media, and programs based on KL divergence
By adopting a fault and attack detection method based on KL divergence, the problems of system faults and data attacks in the permanent magnet synchronous motor test system are solved, enabling timely detection and processing and improving system operating efficiency.
Patent Information
- Application Number
- CN202110369945.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-07
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2041-04-07
AI Technical Summary
In permanent magnet synchronous motor testing systems, system failures and data attacks can affect the server's decision-making process, and existing technologies lack effective detection methods.
A fault and attack detection method based on KL divergence is adopted. The system state is predicted by state space modeling and Kalman estimator, and the KL divergence value is used to determine whether the system has a fault or has been attacked.
It enables timely detection of system faults and attacks, improves system operating efficiency, and reduces the impact on server decision-making processes.
Smart Images

Figure CN115186690B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communications, and more specifically, to fault and attack detection methods, systems, media, and programs based on KL divergence. Background Technology
[0002] In systems such as permanent magnet synchronous motor testing, system failures can occur due to wear of mechanical components, failure of system parts, or malfunctions. These failures will be reflected in the system's measurement data.
[0003] Furthermore, during data transmission, there is also the risk of data interception and tampering. Events where data is intercepted and tampered with during transmission are generally referred to as a system attack.
[0004] System malfunctions and attacks can both affect the server's decision-making process.
[0005] Therefore, there is a need for a method and system that can detect in a timely manner whether the system is malfunctioning or under attack, so that the server can take timely countermeasures. Summary of the Invention
[0006] In view of the above technical problems, the present invention proposes a fault and attack detection method, system, medium and program based on KL divergence.
[0007] According to one aspect of this disclosure, a fault and attack detection method based on KL divergence is provided, comprising: establishing a spatial state model for a local system: x k+1 =Ax k +Bu k +w k ,y k =Cx k +v k , where x k ∈R m For the local system status, y k ∈R n For local system output, u k ∈R p To control the input, w k ∈R m For process noise, v k ∈R n To measure the output noise, A∈R m ×m Let B be the local system matrix, and B ∈ R. m×p Let C ∈ R be the input matrix. n×m The output matrix is generated; the output data of the local system is received; the state of the local system is estimated using the received data and the Kalman estimator, where the Kalman estimator model is: in This is a one-step prediction of the state of the local system. K is the updated measurement value for the state of the local system. k For Kalman gain, and For Kalman information; during the local system debugging and operation phase, identify w while ensuring that the local system is free from faults and attacks. k and v k The covariances Q and R are calculated, and the Kalman innovation z is calculated at this time. k The covariance ∑; after the local system is put into operation, w is identified in real time. k and v k covariance and And calculate the Kalman information at this time. covariance And through formula or Calculate the KL divergence and determine if the local system is faulty or under attack when the KL divergence value is greater than a threshold.
[0008] According to another aspect of this disclosure, a fault and attack detection system based on KL divergence is provided, comprising: one or more processors; and a memory coupled to the one or more processors, the memory storing computer-readable program instructions that, when executed by the one or more processors, perform the fault and attack detection method based on KL divergence according to the present invention.
[0009] According to another aspect of this disclosure, a non-transitory computer-readable medium is provided having instructions stored thereon for execution by a processor to perform a fault and attack detection method based on KL divergence according to the present invention.
[0010] According to another aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, performs steps for fault and attack detection based on KL divergence according to the present invention.
[0011] Other features and advantages of the invention will become clearer from the following detailed description of exemplary embodiments of the invention with reference to the accompanying drawings. Attached Figure Description
[0012] The accompanying drawings, which form part of this specification, illustrate embodiments of this disclosure and, together with the specification, serve to explain the principles of this disclosure.
[0013] This disclosure will become clearer with reference to the accompanying drawings and the following detailed description, wherein:
[0014] Figure 1 A block diagram of an exemplary computer system / server 12 suitable for implementing embodiments of the present invention is shown.
[0015] Figure 2 A fault and attack detection method based on KL divergence according to an exemplary embodiment of the present invention is shown.
[0016] Figure 3 A schematic diagram of a local system according to an exemplary embodiment of the present invention is shown. Detailed Implementation
[0017] The following description is provided to enable those skilled in the art to implement and use the embodiments, and is provided in the context of a particular system and its requirements. Various modifications will be apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and systems without departing from the spirit and scope of the embodiments. Therefore, the embodiments are not limited to those shown, but are to be given the widest scope consistent with the principles and features disclosed herein.
[0018] Figure 1 A block diagram of an exemplary computer system / server 12 suitable for implementing embodiments of the present invention is shown. Figure 1 The computer system / server 12 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0019] like Figure 1 As shown, the computer system / server 12 is represented in the form of a general-purpose computing device. The components of the computer system / server 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and a bus 18 connecting different system components (including system memory 28 and processing units 16).
[0020] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer system / server 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media. Although... Figure 1 Not shown, a disk drive and an optical disk drive may also be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0021] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of the present invention.
[0022] The computer system / server 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, etc.) and a display 24, as well as with one or more devices that enable a user to interact with the computer system / server 12, and / or with any device that enables the computer system / server 12 to communicate with one or more other computing devices (e.g., network interface card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, the computer system / server 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of the computer system / server 12 via bus 18. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with the computer system / server 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0023] To distinguish it from the fault and attack detection system based on KL divergence that is to be protected by this invention, the system that needs to perform fault or attack detection is referred to as the local system in this document.
[0024] The fault and attack detection method based on KL divergence proposed in this invention requires first performing state-space modeling of the local system to obtain various parameters of the local system, and then using a Kalman estimator to predict the state of the local system to obtain the Kalman innovation and its covariance. (See below for reference.) Figure 2 A detailed description of fault and attack detection methods based on KL divergence is provided.
[0025] Figure 2 A fault and attack detection method 200 based on KL divergence according to an exemplary embodiment of the present invention is illustrated. This method 200 can, for example, be derived from... Figure 1 The computer system / server 12 performs the operation.
[0026] like Figure 2 As shown, in step 201, a state-space model is established for the local system.
[0027] According to an embodiment of the present invention, the state-space model is as follows:
[0028] x k+1 =Ax k +Bu k +w k ,
[0029] y k =Cx k +v k .
[0030] Where x k ∈R m For the local system status, y k ∈R n For local system output, u k ∈R p To control the input, w k ∈R m For process noise, v k ∈R n To measure the output noise, A∈R m×m Let B be the local system matrix, and B ∈ R. m×p Let C ∈ R be the input matrix. n×m This is the output matrix.
[0031] According to an embodiment of the present invention, {w k} and {v k The processes are modeled as independent zero-mean Gaussian processes with covariances Q and R, and (A, C) are observable. It is stable, and (A, B) is controllable.
[0032] In step 202, output data from the local system is received. For example, the output data includes A, B, C, and y. k .
[0033] In step 203, the state of the local system is predicted using the received output data of the local system and the Kalman estimator.
[0034] The Kalman estimator model is as follows:
[0035]
[0036]
[0037]
[0038]
[0039]
[0040] in This is a one-step prediction of the state of the local system. K is the updated measurement value for the state of the local system. k For Kalman gain, For the one-step prediction error covariance, This is used to update the measurement error covariance.
[0041] By solving the algebraic Riccati equation The steady-state value of the one-step prediction error covariance can be obtained.
[0042] This represents the steady-state Kalman gain.
[0043] The Kalman innovation follows a Gaussian distribution. And the covariance is
[0044] In step 204, during the local system debugging and operation phase, w is identified while ensuring that the local system is free from faults and attacks. k and v k The covariances Q and R are calculated, and the Kalman innovation z is calculated at this time. k The covariance ∑.
[0045] Here, for w k and v k The algorithms for identifying the covariances Q and R are detailed in "A new autocovariance least-squares method for estimating noise covariances" by Brian J. Odelson et al., published in Automatica, Vol. 42, 2006, pp. 303-308. They will not be repeated here, but their entire content is incorporated herein by reference. The content can also be found through [link to Automatica]. www.sciencedirect.com get.
[0046] In step 205, after the local system is put into operation, w is identified in real time. k and v k covariance and And calculate the Kalman information at this time. covariance
[0047] here, They respectively refer to the w identified in real time k and v kThe covariance, the corresponding Kalman innovation, and its covariance are used to distinguish them from the corresponding parameters during the system debugging and operation phase under fault-free and attack-free conditions.
[0048] It should be understood that With z k The same, that is, It also follows a Gaussian distribution.
[0049] In step 206, the KL divergence is calculated, and if the KL divergence value is greater than a threshold, it is determined that the local system has failed or been attacked.
[0050] According to an embodiment of the present invention, by formula or To calculate the KL divergence.
[0051] According to embodiments of the present invention, when a system malfunction or attack is detected, an alarm message is triggered to remind the user to handle the malfunction or attack promptly. This alarm message can be given visually, such as by displaying a pop-up notification or by setting an alarm light to flash, or it can be given audibly, or both visual and audible alarms can be used simultaneously.
[0052] According to embodiments of the present invention, the above-mentioned threshold can be set and modified as needed. For example, when setting... The corresponding threshold is set to ε, and... When the corresponding threshold is set to δ, in or This allows for timely identification of local system malfunctions or attacks.
[0053] The above The reasoning formula is as follows:
[0054]
[0055] By using the fault and attack detection method based on KL divergence according to the present invention, faults or attacks occurring in real-time dynamic systems can be detected in a timely manner, thereby enabling timely remedial measures to be taken, improving system operating efficiency and reducing the impact on the server's decision-making process.
[0056] This invention can be implemented by a system, method, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of the invention.
[0057] According to one embodiment of the present invention, a fault and attack detection system based on KL divergence is provided. The system includes one or more processors and a memory coupled to the one or more processors. The memory stores computer-readable program instructions that, when executed by the one or more processors, perform the fault and attack detection method based on KL divergence according to the present invention.
[0058] The fault and attack detection system based on KL divergence of the present invention can be implemented in software, hardware, or a combination of both.
[0059] The fault and attack detection system based on KL divergence of this invention can be applied to various real-time dynamic systems. For example, it can be applied to systems such as... Figure 3 The permanent magnet synchronous motor test system shown is shown.
[0060] According to another embodiment of the present invention, a non-transitory computer-readable medium is provided having instructions stored thereon for execution by a processor to perform a fault and attack detection method based on KL divergence according to the present invention.
[0061] According to another embodiment of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, performs the steps of the fault and attack detection method based on KL divergence according to the present invention.
[0062] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination thereof. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0063] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0064] The computer program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing state information from the computer-readable program instructions. This electronic circuitry can execute the computer-readable program instructions to implement various aspects of the invention.
[0065] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0066] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0067] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0068] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0069] The various embodiments of the present invention have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical applications, or technical improvements to the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A fault and attack detection method based on KL divergence, comprising: Establish a state-space model for the local system: x k+1 =Ax k +Bu k +w k ,y k =Cx k +v k , where x k ∈R m For the local system status, y k ∈R n For local system output, u k ∈R p To control the input, w k ∈R m For process noise, v k ∈R n To measure the output noise, A∈R m×W Let B be the local system matrix, and B ∈ R. m×p Given the input matrix, 6∈R n×W This is the output matrix; Receive output data from the local system; Predict the state of the local system using the received data and a Kalman estimator, where the Kalman estimator model is: in This is a one-step prediction of the state of the local system. K is the updated measurement value for the state of the local system. k For Kalman gain, and For Kalman's new information; During the local system debugging and operation phase, identify w while ensuring that the local system is free from faults and attacks. k and v k The covariances Q and R are calculated, and the Kalman innovation z is calculated at this time. k The covariance ∑; After the local system is put into operation, real-time identification of w k and v k covariance and And calculate the Kalman innovation at this time. covariance as well as Through formula or Calculate the KL divergence and determine if the local system is faulty or under attack when the KL divergence value is greater than a threshold.
2. The fault and attack detection method based on KL divergence according to claim 1, wherein {w k } and {v k They are each modeled as independent zero-mean Gaussian processes.
3. The fault and attack detection method based on KL divergence according to claim 1, wherein the Kalman estimator model further includes: in For one-step prediction error covariance and Where P k For measurement update error covariance 4. The fault and attack detection method based on KL divergence according to claim 3, wherein the Kalman gain...
5. The fault and attack detection method based on KL divergence according to claim 3 further includes solving the algebraic Riccati equation. Obtain the steady-state value of the one-step prediction error covariance 6. The fault and attack detection method based on KL divergence according to claim 5, wherein the Kalman innovation z k It follows a zero-mean Gaussian distribution, and its covariance is...
7. The fault and attack detection method based on KL divergence according to claim 1 further includes triggering alarm information when it is determined that the system has failed or been attacked.
8. A fault and attack detection system based on KL divergence, comprising: One or more processors; and A memory coupled to the one or more processors, the memory storing computer-readable program instructions that, when executed by the one or more processors, perform the method as described in any one of claims 1-7.
9. A non-transitory computer-readable medium having instructions stored thereon for execution by a processor to perform the method according to any one of claims 1-7.
10. A computer program product comprising a computer program that, when executed by a processor, performs the steps of the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Diagnosis method for initial failure of gearbox of wind generating set based on vibration monitoring
CN104392082A
Nonparametric tracking and forecasting of multivariate data
US20160071211A1