An unmanned system network attack detection method based on a recursive watermarking mechanism

By introducing a recursive watermarking mechanism into the unmanned system and optimizing the watermark triggering mode, the problem of balancing efficiency and performance loss in network attack detection in the unmanned system is solved, and efficient network attack detection is achieved.

CN115834222BActive Publication Date: 2026-03-27CHINA UNIV OF MINING & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively detect cyberattacks in unmanned systems, especially highly covert attacks, and existing detection methods struggle to balance detection rates with system performance degradation.

Method used

A network attack detection method based on recursive watermarking mechanism is adopted. By establishing an unmanned system, controller and detector model, a recursive watermarking mechanism with event triggering mechanism is introduced. It is divided into three watermark triggering modes: low probability, high probability and forced triggering. The use of watermark is optimized to reduce system performance loss.

Benefits of technology

While ensuring the detection rate, it significantly reduces system performance loss, is more efficient than the periodic watermarking method, and achieves a higher detection rate and less controller control performance loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834222B_ABST
    Figure CN115834222B_ABST
Patent Text Reader

Abstract

The application discloses an unmanned system network attack detection method based on a recursive watermark mechanism, first, an unmanned system model, a controller model and a detector model under network attack are established, second, a network attack model with non-continuous characteristics is established according to the unmanned system model, then, a recursive watermark mechanism based on an event trigger mechanism of a detector alarm is introduced, finally, the detection effect of the detector and the system performance loss are calculated according to the unmanned system model and the recursive watermark parameters proposed in the application. Compared with the traditional periodic watermark method, the detection rate of the recursive watermark algorithm is higher under the same performance loss, which is of great significance for guiding the deployment of unmanned system security defense measures and saving system performance loss, thereby realizing the guarantee of defense effect and the reduction of performance system loss.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of unmanned system network security, and particularly relates to an unmanned system network attack detection method based on a recursive watermark mechanism. BACKGROUND

[0002] Unmanned systems involve large-scale distributed communication, contain multiple communication networks and communication protocols, and different network channels are vulnerable to different types of network attacks. How to quickly detect network attacks online is an important prerequisite for unmanned system defense against network attacks, and has far-reaching significance for maintaining the safe operation of unmanned systems. Due to the concealment of attacks, existing fault diagnosis detection methods use the state information of the system, the historical information of the actuators and sensors to construct a class of dynamic detectors to detect whether an attack occurs within a certain time window, which is difficult to effectively detect whether the system is attacked.

[0003] In view of the problem that attacks in unmanned systems are highly concealed and difficult to detect, many scholars actively explore network attack detection methods. Among them, Mo Yilin, Du Dajun and others proposed an active detection method based on dynamic watermarking. This method improves the detection rate of the detector by adding a watermark at the input end of the controller, and analyzes the performance loss of the controller caused by the watermark. However, if the attack is discontinuous, continuous injection of watermarks may result in waste of control cost, especially when the attacker is in a silent state most of the time. Fang Chongrong et al. introduced a method using periodic watermark sequences. This method uses non-continuous periodic watermarks to reduce system performance loss, thereby achieving effective detection of network attacks while significantly reducing system performance loss. However, this method only injects fixed watermarks during the trigger period, sacrificing the detection rate of many detectors. SUMMARY

[0004] The present application aims to provide an unmanned system network attack detection method based on a recursive watermark mechanism, which can effectively detect network attacks and minimize system performance loss.

[0005] To achieve the above-mentioned purpose, the present application protects an unmanned system network attack detection method based on a recursive watermark mechanism, comprising the following steps:

[0006] Step 1, establishing an unmanned system model, a controller model and a detector model under network attacks;

[0007] Step 2, establishing a network attack model with non-continuous characteristics;

[0008] Step 3, introducing a recursive watermark mechanism based on an event-triggered mechanism of "detector alarm";

[0009] Step 4, Calculate the ability of detecting cyber-attacks under the recursive watermarking mechanism, and quantitatively give the system performance loss caused by the recursive watermarking.

[0010] Further, in step 1, the unmanned system and the controller are modeled first, and then the detector is designed, and the specific steps include:

[0011] Step 1-1, Establish the unmanned system, whose equation is

[0012] x(k+1)=Ax(k)+Bu(k)+w(k)

[0013] y(k)=Cx(k)+v(k)

[0014] Wherein, A is the system transition matrix, B is the system input matrix, C is the output sensor matrix; x(k)∈R n , y(k)∈R m are state variables and output variables of the unmanned system respectively. u(k)∈R p is the control input and is generated by the controller, w(k)~N(0,Q), v(k)~N(0,R) are independent of the system and are process noise and measurement noise respectively following Gaussian distribution.

[0015] Step 1-2, according to the system model of step 1-1, the given value of the unmanned system tracking is given, and the controller is designed to make the unmanned system track the given value, and the formula used is

[0016]

[0017] L=-(B T SB+U) -1 B T SAS

[0018] Wherein S=A T SA+W-A T SB(B T SBU) -1 B T SA, the algebraic Riccati equation; U is the optimization objective weight matrix, W is the optimization objective state weight matrix; is the state estimation value at time k.

[0019] Step 1-3, according to the system model of step 1-1, the threshold value α is given to make the false positive rate of the detector a fixed value, and finally the detector is designed, and the formula used is

[0020]

[0021] Wherein ρ=CPC T +R, T is the detection window; Zi is the residual error vector at the i-th time.

[0022] Further, for the random noise in the unmanned system obeying Gaussian distribution, a Kalman filter is established as the state observer of the unmanned system, and the formula used is

[0023]

[0024] K = PC T [CPC T +R] -1 ,

[0025] P = APA T +Q-APC T [CPC T +R] -1 CPA T ,

[0026] wherein is a residual variable; the initial value of the Kalman filter is is the state posterior estimation value at time k; is the optimal state estimation value at time k-1; is the sensor measurement data estimation value at time k; K is the Kalman gain matrix, and P is the covariance of the system state prediction estimation.

[0027] Further, in step 2, a network attack model with discontinuous characteristics is established, and the specific steps include:

[0028] Step 2-1, for the unmanned system model, controller model and detector model obtained in step 1, a virtual system is constructed to simulate the false data source in the network attack, and the formula used is

[0029] x'(k+1) = Ax'(k) + Bu'(k) + w'(k)

[0030] y'(k) = Cx'(k) + v'(k)

[0031]

[0032] Step 2-2, according to the attack virtual system model of step 2-1, an attack strategy is designed to tamper y(k) as y'(k), and the detector residual becomes:

[0033] Step 2-3, the attack duration is recorded as T s , and the formula used is

[0034] T s = T0+X

[0035] wherein T0 represents the shortest duration required for an attacker to cause malicious influence on the system, and X represents the additional duration controllable by the attacker, X ~ Pission(λ), λ is an attack duration parameter;

[0036] Step 2-4, define the attack frequency as: from 0 time, every NT0 time period occurs once, in the Mth attack sub-task, the initial time t0 of the attack obeys uniform distribution in time (MNT0-NT0, MNT0);

[0037] Step 2-5, define the initial time of the Mth sub-task attack as t0, and the formula used is

[0038] t0 ~ U (MNT0-NT0, MNT0).

[0039] Further, in step 3, the attack parameters obtained in step 2 are designed and calculated to obtain recursive watermark parameters, and the specific steps include:

[0040] Select the watermark as Δu(i) ~ N(0, J), divide the trigger period of the watermark based on the detection window T of step 1-2, and number each trigger period in a certain order as 1, 2, 3…, K…

[0041] Step 3-1, calculate the probability P0 of triggering the watermark at a low probability in the ith watermark trigger period, and the formula used is

[0042] P0 = 1 / N

[0043] Step 3-2, calculate the probability P of the next period without attack when the last period does not trigger the watermark and exactly has an attack, and the formula used is

[0044] P{X = 0} = λ 0 e -λ / 0!

[0045] Step 3-3, calculate the probability P1 of triggering the watermark at a high probability in the ith watermark trigger period, and the formula used is

[0046] P1 = 1-P{X = 0}

[0047] Step 3-4, calculate the probability β of forcibly triggering the watermark in the ith watermark trigger period, and the formula used is

[0048]

[0049] Further, according to the parameters of step 3-1, step 3-3 and step 3-4, the principle of triggering the watermark in the ith watermark trigger period is designed as:

[0050] (1) If the watermark is not triggered successfully in the i-1th trigger period, the watermark is triggered with a probability of P1 in the ith trigger period;

[0051] (2) If the watermark is triggered successfully in the i-1th trigger period and the detector alarms, the watermark is triggered with a probability of β in the ith trigger period;

[0052] (3) If the watermark is triggered successfully in the i-1th trigger period but the detector does not alarm, the watermark is triggered with a probability of P0 in the ith trigger period.

[0053] Further, according to the obtained recursive watermark parameters and the watermark trigger principle, the effect of the detector detecting the attack is calculated according to the attack parameters and the recursive watermark trigger principle, and the specific steps include:

[0054] Step 4-1, record event Ω as triggering the watermark in the first watermark trigger period when the attack occurs, and the probability is calculated by the formula

[0055] P{Ω} = P(1-β)P c / 3+(1-e -λ )P d / 3+βP c / 3;

[0056] Step 4-2, according to the recursive watermark parameters obtained in steps 2-3, 3-1, 3-2 and 3-3, the detection effect of the detector in the first trigger period after the attack is calculated, and the formula used is

[0057]

[0058] wherein P B represents the probability of triggering the watermark in the high probability mode; H = (A-BL)(I-KC);

[0059] Step 4-3, according to the detection effect of the detector detecting the attack obtained in step 4-2, the probability of triggering the watermark in the second watermark trigger period when the attack occurs is calculated, and the formula used is

[0060] β1 = P{mT0 / 2+trace(C T ρ -1 CΥ1)>α}

[0061] Step 4-4, according to the recursive watermark parameters obtained in step 4-2, the detection effect of the detector in the second trigger period after the attack is calculated, and the formula used is

[0062]

[0063] wherein, P B1is the probability of triggering the watermark in the first period;

[0064] Step 4-5, according to the effect of the detector obtained in step 4-3, the probability of forcibly triggering the watermark in the third watermark triggering period when the attack occurs is calculated, and the formula used is

[0065] β2=P{mT0+trace(C T ρ -1 CΥ2)>α}

[0066] Step 4-6, according to the effect of the detector obtained in step 4-4, the detection effect of the detector in the third triggering period after the attack occurs is calculated, and the formula used is

[0067]

[0068] Wherein Δu(i) is the watermark at the i-th moment; P B2 is the probability of triggering the watermark in the second period.

[0069] Further, the system performance loss caused by the recursive watermark is calculated, and the formula used is

[0070] J1=J * +P B trace[(B T SB+U)J]

[0071] Wherein, J * =trace(SQ)+trace[(A T SA+W-S)(P-KCP)].

[0072] The beneficial effects of the present application are: compared with the prior art, the recursive watermark network attack detection method proposed in the present application, the triggering mode of the watermark in the recursive watermark algorithm is divided into low probability triggering, high probability triggering and forced triggering, which can more reasonably utilize the watermark, while greatly reducing the control performance loss of the controller on the basis of ensuring the detection rate. Under the same performance loss, compared with the periodic watermark method, the detection rate of the recursive watermark algorithm will be higher. Similarly, if the same detection effect is wanted, the system performance loss caused by the periodic watermark will be more than that caused by the recursive watermark. BRIEF DESCRIPTION OF DRAWINGS

[0073] Figure 1 The schematic diagram of the closed loop of the unmanned system configured with the recursive watermark of the present application;

[0074] Figure 2 The flow chart of the online detection network attack method of the unmanned system of the present application;

[0075] Figure 3 Three state transition diagrams for recursive watermarking of the present application;

[0076] Figure 4 For an embodiment of the present application, the same performance loss under recursive watermarking detection and periodic watermarking detection effect comparison diagram;

[0077] Figure 5 For an embodiment of the present application, the performance loss comparison diagram of recursive watermarking and continuous watermarking; DETAILED DESCRIPTION

[0078] The present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0079] As Figure 2 shown, a method for unmanned system network attack detection based on recursive watermarking mechanism, the method comprising the following steps:

[0080] Step 1, establish the unmanned system model under network attack, detector model and controller model. In step 1, first model the unmanned system and the controller, and then design the detector, the specific steps comprising: step 1-1, establish the unmanned system closed loop model, the equation is

[0081] x(k+1)=Ax(k)+Bu(k)+w(k)

[0082] y(k)=Cx(k)+v(k)

[0083] Where x(k)∈R n , y(k)∈R m are the state variable and output variable of the unmanned system respectively. u(k)∈R p is the control input and is generated by the controller, w(k) ~ N(0, Q), v(k) ~ N(0, R) are independent of the system and are process noise, measurement noise respectively obeying Gaussian distribution.

[0084] Step 1-2, for the random noise obeying Gaussian distribution existing in the unmanned system, establish Kalman filter as the state observer of the unmanned system, the formula used is

[0085]

[0086] K=PC T [CPC T +R] -1 ,

[0087] P=APA T +Q-APC T [CPC T +R] -1 CPA T ,

[0088] where is the residual variable; the initial value of Kalman filter is is the state posteriori estimation value at time k; is the optimal state estimation value at time k-1; is the sensor measurement data estimation value at time k; K is the Kalman gain matrix, and P is the covariance of the system state prediction estimation.

[0089] Step 1-3, according to the system model of step 1-1, given the value of the unmanned system tracking, design the controller to make the unmanned system track the given value, and the formula used is

[0090]

[0091] L = -(B T SB+U) -1 B T SAS

[0092] where S = A T SA+W-A T SB(B T SBU) -1 B T SA, is the algebraic Riccati equation.

[0093] Step 1-4, according to the system model of step 1-1, given the threshold value α to make the false alarm rate of the detector a fixed value, finally design the detector, and the formula used is

[0094]

[0095] where ρ = CPC T +R, T is the detection window;

[0096] Step 2, establish a network attack model with discontinuous characteristics, the specific steps include:

[0097] Step 2-1, for the unmanned system model, detector model and controller model obtained in step 1, a virtual system is constructed to simulate the false data source in network attack, and the formula used is

[0098] x'(k+1) = Ax'(k) + Bu'(k) + w'(k)

[0099] y'(k) = Cx'(k) + v'(k)

[0100]

[0101] where, A is the system transition matrix, B is the system input matrix, C is the output sensor matrix; x'(k) ∈ Rn , y'(k) e R m , y'(k) e R p , y'(k) e R s , y'(k) e R s , y'(k) e R , y'(k) e R , y'(k) e R , y'(k) e R , y'(k) e R

[0102] , y'(k) e R , y'(k) e R , y'(k) e R

[0103] , y'(k) e R , y'(k) e R

[0104] , y'(k) e R , y'(k) e R

[0105] , y'(k) e R , y'(k) e R , y'(k) e R

[0106] , y'(k) e R , y'(k) e R

[0107] , y'(k) e R , y'(k) e R

[0108] , y'(k) e R , y'(k) e R

[0109] , y'(k) e R , y'(k) e R

[0110] , y'(k) e R , y'(k) e R

[0111] Step 3-1, calculate the probability P0 of triggering the watermark with low probability in the i-th watermark triggering period, using the formula

[0112] P0 = 1 / N

[0113] Step 3-2, calculate the probability P of the last period not triggering the watermark and exactly having an attack, and the next period having no attack, using the formula

[0114] P{X = 0} = λ 0 e -λ / 0!

[0115] Step 3-3, calculate the probability P1 of triggering the watermark with high probability in the i-th watermark triggering period, using the formula

[0116] P1 = 1 - P{X = 0}

[0117] Step 3-4, calculate the probability β of forcibly triggering the watermark in the i-th watermark triggering period, using the formula

[0118]

[0119] Step 3-5, according to the parameters of step 3-1, step 3-3 and step 3-4, the principle of triggering the watermark in the i-th watermark triggering period is:

[0120] (1) If the i-1 triggering period is not successful in triggering the watermark, then the i-th triggering period triggers the watermark with a probability of P1;

[0121] (2) If the i-1 period successfully triggers the watermark and the detector alarms, then the i-th period forcibly triggers the watermark with a probability of β; (3) If the i-1 period successfully triggers the watermark but the detector does not alarm, then the i-th period triggers the watermark with a probability of P0.

[0122] Figure 3 The three kinds of triggering state transition diagrams are shown in the figure. When there is no attack, the false alarm rate is low, and the triggering state is mostly converted between low probability triggering and high probability triggering. When an attack occurs, the alarm rate will be higher due to the existence of the watermark, and the triggering state will be converted to forced triggering, which has a greater probability.

[0123] Step 4, calculate the ability of detecting network attacks under the recursive watermark mechanism, and quantitatively give the system performance loss caused by the recursive watermark.

[0124] According to the obtained recursive watermark parameters and the watermark triggering principle, the effect of the detector detecting attacks is calculated according to the attack parameters and the recursive watermark triggering principle. The specific steps include:

[0125] Step 4-1, record event Ω as the probability of triggering the watermark in the first watermark triggering period when the attack occurs, and the formula used is

[0126] P{Ω} = P(1 - β)P c / 3 + (1 - e -λ )P d / 3 + βP c / 3;

[0127] Wherein, Pc is the triggering probability of the low probability triggering watermark. Pd is the triggering probability in the forced triggering watermark mode;

[0128] Step 4-2, according to the recursive watermark parameters obtained in steps 2-3, 3-1, 3-2 and 3-3, calculate the detection effect of the detector in the first triggering period after the attack, and the formula used is

[0129]

[0130] Wherein, P B represents the probability of the triggering watermark in the high probability mode; H = (A - BL) (I - KC);

[0131] Step 4-3, according to the detection effect of the detector obtained in step 4-2, calculate the probability of forced triggering watermark in the second watermark triggering period when the attack occurs, and the formula used is

[0132] β1 = P{mT0 / 2 + trace(C T ρ -1 CΥ1)>α}

[0133] Step 4-4, according to the recursive watermark parameters obtained in step 4-2, calculate the detection effect of the detector in the second triggering period after the attack, and the formula used is

[0134]

[0135] Wherein, P B1 is the probability of triggering the watermark in the first period;

[0136] Step 4-5, according to the detection effect of the detector obtained in step 4-3, calculate the probability of forced triggering watermark in the third watermark triggering period when the attack occurs, and the formula used is

[0137] β2 = P{mT0 + trace(C T ρ -1 CΥ2)>α}

[0138] Wherein, m is the output dimension.

[0139] Step 4-6, the detector obtained according to step 4-4 detects the effect of the attack, and the detection effect of the detector in the third trigger period after the attack is calculated, and the formula is

[0140]

[0141] Wherein, Delta u (i) is the watermark at the i time; P B2 Is the probability of triggering the watermark in the second period.

[0142] The system performance loss caused by the recursive watermark is calculated, and the formula is

[0143] J1=J * +P B trace[(B T SB+U)J]

[0144] Wherein, J * = trace (SQ) + trace [(A T SA+W-S) (P-KCP) ].

[0145] In summary, the present application introduces the detector alarm as the event triggered mechanism of the event, and by dividing the watermark trigger into low probability trigger, high probability trigger and forced trigger, the higher detection rate is realized on the basis of greatly reducing the system performance loss.

[0146] The detection method of the present application will be described in detail below with a specific embodiment, as Figure 1 shown, the unmanned system data is transmitted to the Kalman filter through the network, the Kalman filter completes the state estimation of the unmanned system, and then transmits the estimated system state to the LQG controller, and the LQG controller generates control input and transmits it to the unmanned system. The malicious attacker tampers with the transmission data of the unmanned system to achieve the purpose of disturbing the unmanned system and keeping hidden. The calculation process and results of the detection method of the embodiment are as follows:

[0147] (1) According to step 1-1, the unmanned system model is established, and the processing result is

[0148]

[0149] Q=0.1I4, R=0.25I2

[0150] (2) According to the unmanned system model obtained in (1), the LQG controller is calculated, and the processing result is

[0151]

[0152] (3) According to the unmanned system model and the LQG controller model obtained in (1) and (2), attack parameter selection is performed, and the processing result is: initial time t0~200+10*U(0,100), attack duration: T s ~100+Pission(60);

[0153] (4) According to the attack parameters obtained in (3), the detector time window is selected to be 100, and the threshold is selected by table lookup so that the detector false alarm rate is 2.5%;

[0154] (5) According to the unmanned system model obtained in (1), watermark parameter selection is performed, and the processing result is: Gaussian distributed watermark Δu(k)~N(0,1.8) is selected;

[0155] (6) According to the attack parameters obtained in (3), recursive watermark parameter calculation is performed, and the calculation result is: the trigger probability in the recursive watermark parameter is: P0=1 / 10, P1=0.6, and when no attack occurs, the alarm rate β is: 2.5%;

[0156] (7) According to the recursive watermark parameters obtained in (5) and (6), periodic watermark parameter calculation under the same performance loss is performed, and the calculation result is p / q=0.3;

[0157] (8) According to the watermark parameters obtained in (5) and (6), detector detection effect calculation under watermark is performed, and the calculation result is P B trace(C T ρ -1 Cy1)=47.9, P B1 trace(C T ρ -1 Cy2)=59.9, P B2 trace(C T ρ -1 Cy3)=33.5;

[0158] (9) According to the recursive watermark and periodic parameters obtained in (7) and (8), detector detection effect calculation under periodic / recursive watermark is performed, and the calculation result is that the detection rate of the recursive watermark is about 50%, and the detection rate of the periodic watermark is about 33%.

[0159] Figure 4 The comparison chart of recursive watermark detection and periodic watermark detection effect under the same performance loss of the present embodiment can be seen that, under the same performance loss, compared with the periodic watermark of p / q=0.3, the recursive watermark method more reasonably schedules the watermark, and through the event trigger mechanism, the detection rate is higher than that of the periodic watermark. Similarly, if the same detection rate is wanted to be obtained, the performance loss caused by the periodic watermark will be higher than that of the recursive watermark.

[0160] (10) According to the recursive watermark parameters obtained in (5) and (6), the system performance loss under recursive watermarking and continuous watermarking is calculated, and the calculation results are: recursive watermark 5500000, continuous watermark 7700000, and no watermark 3100000.

[0161] Figure 5 For the performance loss comparison chart of recursive watermarking and continuous watermarking, it can be seen that, compared with the performance loss of no watermarking and continuous watermarking, the recursive watermarking can greatly reduce the performance loss of system operation on the basis of ensuring safety.

[0162] According to the system loss obtained in (10), the upper limit of the watermark parameter is set according to the actual unmanned system performance loss requirement standard to give a reasonable selection range of the watermark parameter, and the watermark parameter is adjusted to promote the reduction of the performance loss of the unmanned system.

[0163] The embodiments of the present application are described in detail above in combination with the drawings, but the present application is not limited thereto, and various changes can be made within the knowledge range of those skilled in the art without departing from the purpose of the present application, which are all within the protection scope of the claims of the present application.

Claims

1. A method for detecting network attacks on unmanned systems based on a recursive watermarking mechanism, characterized in that, The method includes the following steps: Step 1: Establish unmanned system models, controller models, and detector models under network attacks; In step 1, the unmanned system and controller are modeled first, and then the detector is designed. The specific steps include: Step 1-1: Establish the unmanned system, whose equations are as follows: Where A is the system transition matrix, B is the system input matrix, and C is the output sensor matrix; , These are the state variables and output variables of the unmanned system, respectively. The control input is generated by the controller. , Independent of the system, and respectively following a Gaussian distribution: process noise and measurement noise; Step 1-2: Based on the system model in Step 1-1, given the setpoint for the unmanned system's tracking, design a controller to ensure the unmanned system tracks the setpoint. The formula used is: in, , which is the algebraic Riccati equation; U and W are weight matrices; yes State estimate at time 1; Steps 1-3: Based on the system model in Step 1-1, a threshold is given. To ensure a fixed false alarm rate for the detector, the final detector design uses the following formula: in, , here The covariance of the system state prediction estimate. Let z be the detection window; z(i) is the residual vector at time i. Step 2: Establish a network attack model with discontinuous characteristics; specific steps include: Step 2-1: For the unmanned system model, controller model, and detector model obtained in Step 1, a virtual system is constructed to simulate the source of false data in network attacks. The formula used is... ; Where A is the system transfer matrix, B is the system input matrix, and C is the output sensor matrix; , These are the system's state variables and output variables in the attack signal, respectively; The attack signal is a control input generated by the controller. , Independent of the system, and respectively, process noise and measurement noise in the attack signal following a Gaussian distribution; correspondingly, The residual variable is in the attack signal; the initial value of the Kalman filter in the attack signal is... , yes The posterior estimate of the state at time 1; yes The optimal state estimate at time t; Here is the Kalman gain matrix. The covariance of the system state prediction estimate; yes The optimal state estimate at time t; Step 2-2: Based on the attack virtual system model in Step 2-1, design an attack strategy. altered The detector residual becomes: ; Steps 2-3, the attack duration is recorded as follows: The formula used is in This indicates the minimum duration required for an attacker to cause malicious damage to the system. This represents an additional duration that the attacker can control. , , This is the attack duration parameter; Steps 2-4: Define the attack frequency as follows: starting from time 0, every... An attack occurs within a time period. In the Mth attack subtask, the initial moment of the attack... Within a time It follows a uniform distribution; Steps 2-5: Define the initial time of the Mth sub-task attack as (the time is not specified in the original text). The formula used is: Step 3: Introduce a recursive watermarking mechanism based on the event triggering mechanism of "detector alarm"; In step 3, the attack parameters obtained in step 2 are used to design and calculate the recursive watermark parameters. The specific steps include: The watermark is selected as Δu(i)~N(0,J), where J is the watermark covariance matrix; based on the detection window in steps 1-2... The watermark triggering cycle is defined, and each triggering cycle is numbered in a certain order as 1, 2, 3..., K...; Step 3-1: Calculate the probability P0 of triggering the watermark with low probability within the i-th watermark triggering period. The formula used is: Step 3-2: Calculate the probability P that the watermark was not triggered in the previous cycle and an attack occurred, and there is no attack in the next cycle. The formula used is: Step 3-3: Calculate the probability P1 of triggering the watermark with a high probability within the i-th watermark triggering period. The formula used is: Steps 3-4: Calculate the probability β of forcibly triggering the watermark within the i-th watermark triggering period, using the following formula: Where z(i) is the residual vector at time i; T0 represents the shortest duration required for an attacker to cause malicious impact on the system; Step 4: Calculate the ability to detect network attacks under the recursive watermarking mechanism, and quantitatively give the system performance loss caused by the recursive watermarking. Based on the obtained recursive watermark parameters and watermark triggering principles, the effectiveness of the detector in detecting attacks is calculated according to the attack parameters and recursive watermark triggering principles. Specific steps include: Step 4-1: Record the event The probability of triggering the watermark within the first watermark triggering cycle when the attack occurs is calculated using the following formula: ; Among them, P c This is the probability of triggering the watermark mode in a low-probability scenario; P d It is the trigger probability in the forced watermarking mode; Step 4-2: Based on the recursive watermark parameters obtained in steps 2-3, 3-1, 3-2, and 3-3, calculate the detection effect of the detector in the first trigger cycle after the attack occurs. The formula used is: in, ;P B This represents the probability of triggering the watermark in high-probability modes. ; Step 4-3: Based on the detector's effectiveness in detecting the attack obtained in Step 4-2, calculate the probability of forcibly triggering the watermark within the second watermark triggering cycle when the attack occurs. The formula used is: Step 4-4: Based on the recursive watermark parameters obtained in Step 4-2, calculate the detection effect of the detector in the second trigger cycle after the attack occurs. The formula used is: in ;P B1 It is the probability of triggering the watermark within the first cycle; Step 4-5: Based on the detector's effectiveness in detecting the attack obtained in Step 4-3, calculate the probability of forcibly triggering the watermark within the third watermark triggering cycle when the attack occurs. The formula used is: Where m is the output dimension; Step 4-6: Based on the detector's detection effect obtained in Step 4-4, calculate the detector's detection effect in the third trigger cycle after the attack occurs. The formula used is: in, ; It is the watermark at time i; P B2 It is the probability of triggering the watermark within the second cycle.

2. The method for detecting network attacks on unmanned systems based on a recursive watermarking mechanism according to claim 1, characterized in that, For unmanned systems containing random noise following a Gaussian distribution, a Kalman filter is established as the state observer of the unmanned system. The formula used is: in, The residual variable is used; the initial value of the Kalman filter is... , yes The posterior estimate of the state at time 1; yes The optimal state estimate at time t; yes Estimated values ​​of time sensor measurement data; Here is the Kalman gain matrix. This is the covariance estimated for system state prediction.

3. The method for detecting network attacks on unmanned systems based on a recursive watermarking mechanism according to claim 1, characterized in that, Based on the parameters in steps 3-1, 3-3, and 3-4, the principle for designing the watermark triggering cycle for the i-th watermark is as follows: (1) If the watermark is not successfully triggered in the (i-1)th trigger cycle, then the i-th trigger cycle will be... The probability of triggering the watermark; (2) If the watermark is successfully triggered in the (i-1)th cycle and the detector alarms, then the watermark is forcibly triggered in the i-th cycle with a probability of β. (3) If the watermark is successfully triggered in the (i-1)th cycle but the detector does not trigger an alarm, then the i-th cycle will use The probability of triggering the watermark.

4. The method for detecting network attacks on unmanned systems based on a recursive watermarking mechanism according to claim 1, characterized in that, The formula used to calculate the system performance loss caused by recursive watermarking is: in, .