A game information intrusion detection system based on state interval estimation

CN116170178BActive Publication Date: 2026-09-22ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211649984.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-21
Publication Date
2026-09-22
Estimated Expiration
2042-12-21

AI Technical Summary

Technical Problem

[0004]为了克服目前基于传统点估计方法在检测复杂系统信息入侵时精度差且易误报的不足,本发明的目的在于提供一种高准确性、强泛化性的信息入侵检测系统

Benefits of technology

[0049]本发明的有益效果主要表现在:1、可靠的信息入侵检测准则,超过估计区间即代表有信息入侵;2、高精度的系统状态估计新方法,所得到的状态估计区间的宽度很窄,估计准确性高,而且没有增加任何的前提假设条件,在广泛的复杂系统中都能应用。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116170178B_ABST
    Figure CN116170178B_ABST
Patent Text Reader

Abstract

The application discloses a game information intrusion detection system based on state interval estimation, which is composed of a robust point estimation module, an augmented state construction module, a state interval estimation module and an information intrusion alarm module. The robust point estimation module obtains point estimation information of the system state by reconstructing the state of the system. The augmented state construction module forms a new system state by combining the system error with the original system state. On this basis, the state interval estimation module performs interval estimation on the new system state to obtain boundary information of the error, and combines the point estimation information of the state point estimation module to obtain interval information of the original system state. When the system is subjected to information intrusion, the system state exceeds the normal interval given by the state interval estimation module, and the information intrusion alarm module will immediately issue an alarm. The application provides a game information intrusion detection system with strong reliability, high accuracy and generalization, which can be applied to various devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information intrusion detection, and in particular, to a game-theoretic information intrusion detection system based on state interval estimation. Background Technology

[0002] In modern systems, information network systems, such as communication and control systems characterized by information technology, have been integrated into physical infrastructure. These systems, which combine physical and information networks, are called cyber-physical systems (CPS) and are widely used in transportation, power, industrial automation, and wireless systems. However, due to the inherent complexity of CPS and the openness of information networks, they are highly vulnerable to information intrusion, which can damage physical infrastructure. In battlefield environments, information intrusion is even more prevalent and intense, making timely and accurate detection crucial for maximizing strategic gains.

[0003] Information intrusion, also known as information attack, can be divided into infrastructure attacks and network attacks. Currently, practical systems have established multiple robust protection mechanisms against information intrusion at the physical and network layers. However, the diverse types of sensing devices located between the physical and network layers make them more vulnerable to attack, thus affecting the security and stability of the entire system. Therefore, detecting system state information provided by sensing devices is of great significance. Current information intrusion detection targeting sensing devices mainly relies on traditional point estimation methods, including Kalman filters and sliding mode observers. However, these methods can only provide a rough estimate of the system state and depend on experience to judge the extent of information intrusion, making it difficult to meet the requirements of high accuracy and low false alarms in information intrusion detection for complex systems in complex environments. Summary of the Invention

[0004] To overcome the shortcomings of current traditional point estimation methods in detecting information intrusion in complex systems, which suffer from poor accuracy and are prone to false alarms, the present invention aims to provide an information intrusion detection system with high accuracy and strong generalization.

[0005] The technical solution adopted by this invention to solve its technical problem is:

[0006] An information intrusion detection system based on a state interval estimation method is characterized by comprising a robust point estimation module, an augmented state construction module, a state interval estimation module, and an information intrusion alarm module, with the four modules connected sequentially. The system's operating steps include:

[0007] The robust point estimation module is used to make a preliminary estimate of the system state, which is accomplished through the following process:

[0008] Step A1: Obtain the system's mechanistic model:

[0009]

[0010] Where x(k) and x(k+1) are the states of the system at time k and time k+1, respectively, y(k) is the output of the system at time k, w(k)|≤w and |v(k)|≤v are the process noise and measurement noise of the system at time k, w and v are known constant vectors, and A, C, E, and F are known constant matrices.

[0011] Step A2: Based on the obtained system model, design the corresponding robust observer:

[0012]

[0013] in, and These are the estimates of the system state at time k and time k+1, respectively. It is the estimated value of the system output at time k, and L is the gain matrix of the observer.

[0014] This invention employs a novel augmented state construction module to reconstruct the system state, resulting in a narrow state estimation interval with high accuracy, without adding any preconditions or assumptions. The process is as follows:

[0015] Step B1: Subtract the state equation of the original system from the designed robust observer to obtain the error system:

[0016] e(k+1)=(A-LC)e(k)+Ew(k)-LFv(k) (15)

[0017] in, e is the error at time k, and e(k+1) is the error at time k+1.

[0018] Step B2: Combine the original system and the error system to obtain the augmented system:

[0019]

[0020] Where ξ(k)=[x T (k)e T (k)] T Let ξ(k+1) be the state of the augmented system at time k, and ξ(k+1) be the state of the augmented system at time k+1. It is the process noise of the augmented system. The state matrix of the augmented system has the following form:

[0021]

[0022] The state interval estimation module is used to perform interval estimation of the original system state, which is accomplished through the following process:

[0023] Step C1: Assume the set of systematic errors e(k) is contained within a centrally symmetric polyhedron:

[0024] Z e (k)= <p e (k),H e (k)> (17)

[0025] Among them, Z e (k) is a centrally symmetric polyhedron containing the error at time k, p e (k) is Z e The center vector of (k), H e (k) is Z e The generating matrix of (k), where <·,·> represents a centrally symmetric polyhedron.

[0026] Step C2: Because and These are the state estimates obtained from the robust point estimation module, therefore we obtain:

[0027]

[0028] Among them, Z x (k) is a centrosymmetric polyhedron containing the original system state at time k. It is Z x The center vector of (k), H e (k) is also Z x The generating matrix of (k), 0 n×n It is an n×n dimensional zero matrix. It is Minkowski and...

[0029] Step C3: Based on the augmented system obtained from the augmented state construction module, we have:

[0030] Z ξ (k)= <p ξ (k),H ξ (k)> (19)

[0031] Among them, Z ξ (k) is a centrally symmetric polyhedron containing the state of the augmented system at time k, p ξ (k)=[(p x (k)) T (p e (k)) T ] T It is Z ξ The center vector of (k), H ξ (k)=diag{H e (k),H e (k)} is Zξ The generating matrix of (k), where diag{·} is the function that constructs the diagonal matrix.

[0032] Step C4: Assume the process noise of the augmented system The set to which it belongs is contained by the following centrally symmetric polyhedra:

[0033]

[0034] in, It is a centrosymmetric polyhedron containing augmented system process noise, 0 n×1 It is the zero vector of n dimensions. yes The generating matrix.

[0035] Step C5: Substituting equations (19) and (20) into equation (16), we get the following equation:

[0036]

[0037] Among them, Z ξ (k+1) is a centrally symmetric polyhedron containing the augmented system state at time k+1. This new method for obtaining the system state estimation interval has the following advantages: 1. It does not introduce any additional preconditions and is applicable to a wide range of complex systems; 2. The obtained state estimation interval is very narrow and has high estimation accuracy. According to equation (21), the iterative formula can be obtained:

[0038]

[0039] Step C6: As equation (22) iterates continuously, H ξ The dimension of (k) also continues to grow. Therefore, by performing a dimension reduction operation on equation (22), we obtain:

[0040]

[0041] Among them, H ξ (k) is H ξ The matrix obtained by transforming the matrix whose columns of (k) are arranged in descending order according to the Euclidean norm.

[0042] Step C7: Based on the iterative results of equation (23), the interval estimation boundaries of the original system state are:

[0043]

[0044] Where i is the row number, i is the column number, and length(H) ξ (k) represents H ξ The length of (k), They represent The element in the i-th row, These are the upper and lower bounds of the system state x(k). p ξ The element in the i-th row of (k), H represents ξ The element in the i-th row and j-th column of (k), |·| is a function that takes the absolute value.

[0045] The information intrusion alarm module is used to detect information intrusion situations, and it is completed through the following process:

[0046] Step D1: Obtain the real-time state x(k) of the system through the sensing device;

[0047] Step D2: Compare x(k) with the estimated interval obtained from the state interval estimation module. For comparison, when x(k) falls within the interval When x(k) is within the specified range, the system is operating normally; when x(k) exceeds the specified range... When the system is within the specified range, it indicates that the system has been compromised and issues an alarm.

[0048] The technical concept of this invention is as follows: For systems unaffected by information intrusion, this invention performs point estimation of the system state and combines this estimation with the error of the original system state to construct an augmented system. Based on this, interval estimation is performed on the new augmented system state to obtain boundary information of the error, and combined with the point estimation information, the interval information of the original system state is obtained. When the system is subjected to information intrusion, the system state exceeds the normal interval given by the state interval estimation module, and the information intrusion alarm module immediately issues an alarm, thus realizing the detection of information intrusion.

[0049] The beneficial effects of this invention are mainly reflected in: 1. A reliable information intrusion detection criterion, where exceeding the estimation interval indicates information intrusion; 2. A new method for high-precision system state estimation, which obtains a narrow state estimation interval with high estimation accuracy, and does not add any preconditions or assumptions, making it applicable to a wide range of complex systems. Attached Figure Description

[0050] Figure 1 This is a functional block diagram of the system proposed in this invention. Detailed Implementation

[0051] The present invention will now be described in detail with reference to the accompanying drawings. The embodiments of the present invention are used to explain and illustrate the invention, but not to limit it. Any modifications and alterations made to the present invention within the spirit and scope of the claims fall within the protection scope of the present invention.

[0052] Example 1

[0053] Reference Figure 1 A game-theoretic information intrusion detection system based on state interval estimation includes a robust point estimation module 1, an augmented state construction module 2, a state interval estimation module 3, and an information intrusion alarm module 4, which are sequentially connected. The system's operating steps include:

[0054] Robust point estimation module 1 is used to make a preliminary estimate of the system state, which is accomplished through the following process:

[0055] Step A1: Obtain the system's mechanistic model:

[0056]

[0057] Where x(k) and x(k+1) are the states of the system at time k and time k+1, respectively, y(k) is the output of the system at time k, w(k)|≤w and |v(k)|≤v are the process noise and measurement noise of the system at time k, w and v are known constant vectors, and A, C, E, and F are known constant matrices.

[0058] Step A2: Based on the obtained system model, design the corresponding robust observer:

[0059]

[0060] in, and These are the estimates of the system state at time k and time k+1, respectively. It is the estimated value of the system output at time k, and L is the gain matrix of the observer.

[0061] This invention employs a novel augmented state construction module 2 to reconstruct the system state. The resulting state estimation interval has a very narrow width and high estimation accuracy, without adding any preconditions or assumptions. The process is as follows:

[0062] Step B1: Subtract the state equation of the original system from the designed robust observer to obtain the error system:

[0063] e(k+1)=(A-LC)e(k)+Ew(k)-LFv(k) (27)

[0064] in, e is the error at time k, and e(k+1) is the error at time k+1.

[0065] Step B2: Combine the original system and the error system to obtain the augmented system:

[0066]

[0067] Where ξ(k)=[x T (k)e T (k)] T Let ξ(k+1) be the state of the augmented system at time k, and ξ(k+1) be the state of the augmented system at time k+1. It is the process noise of the augmented system. The state matrix of the augmented system has the following form:

[0068]

[0069] State interval estimation module 3 is used to perform interval estimation of the original system state, which is accomplished through the following process:

[0070] Step C1: Assume the set of systematic errors e(k) is contained within a centrally symmetric polyhedron:

[0071] Z e (k)= <p e (k),H e (k)> (29)

[0072] Among them, Z e (k) is a centrally symmetric polyhedron containing the error at time k, p e (k) is Z e The center vector of (k), H e (k) is Z e The generating matrix of (k), where <·,·> represents a centrally symmetric polyhedron.

[0073] Step C2: Because and The state estimate is obtained from robust point estimation module 1, therefore we get:

[0074]

[0075] Among them, Z x (k) is a centrosymmetric polyhedron containing the original system state at time k. It is Z x The center vector of (k), H e (k) is also Z x The generating matrix of (k), 0 n×n It is an n×n dimensional zero matrix. It is Minkowski and...

[0076] Step C3: Based on the augmented system obtained in module 2, we have:

[0077] Z ξ (k)= <p ξ(k),H ξ (k)> (31)

[0078] Among them, Z ξ (k) is a centrally symmetric polyhedron containing the state of the augmented system at time k, p ξ (k)=[(p x (k)) T (p e (k)) T ] T It is Z ξ The center vector of (k), H ξ (k)=diag{H e (k),H e (k)} is Z ξ The generating matrix of (k), where diag{·} is the function that constructs the diagonal matrix.

[0079] Step C4: Assume the process noise of the augmented system The set to which it belongs is contained by the following centrally symmetric polyhedra:

[0080]

[0081] in, It is a centrosymmetric polyhedron containing augmented system process noise, 0 n×1 It is the zero vector of n dimensions. yes The generating matrix.

[0082] Step C5: Substituting equations (31) and (32) into equation (28), we get the equation:

[0083]

[0084] Among them, Z ξ (k+1) is a centrally symmetric polyhedron containing the augmented system state at time k+1. This new method for obtaining the system state estimation interval has the following advantages: 1. It does not introduce any additional preconditions and is applicable to a wide range of complex systems; 2. The obtained state estimation interval is very narrow and has high estimation accuracy. According to equation (33), the iterative formula can be obtained:

[0085]

[0086] Step C6: As equation (34) iterates continuously, H ξ The dimension of (k) also continues to grow. Therefore, by performing a dimension reduction operation on equation (34), we obtain:

[0087]

[0088] in, It is H ξ The matrix obtained by transforming the matrix whose columns of (k) are arranged in descending order according to the Euclidean norm.

[0089] Step C7: Based on the iterative results of equation (35), the interval estimation boundaries of the original system state are:

[0090]

[0091] Where i is the row number, i is the column number, and length(H) ξ (k) represents H ξ The length of (k), They represent The element in the i-th row, These are the upper and lower bounds of the system state x(k). p ξ The element in the i-th row of (k), H represents ξ The element in the i-th row and j-th column of (k), |·| is a function that takes the absolute value.

[0092] The information intrusion alarm module 4 is used to detect information intrusion situations, and it is accomplished through the following process:

[0093] Step D1: Obtain the real-time state x(k) of the system through the sensing device;

[0094] Step D2: Compare x(k) with the estimated interval obtained in state interval estimation module 3. For comparison, when x(k) falls within the interval When x(k) is within the specified range, the system is operating normally; when x(k) exceeds the specified range... When the system is within the specified range, it indicates that the system has been compromised and issues an alarm.

Claims

1. A game information intrusion detection system based on state interval estimation, characterized in that: It consists of a robust point estimation module, an augmented state construction module, a state interval estimation module, and an information intrusion alarm module connected in sequence. The robust point estimation module is used to make a preliminary estimate of the system state and obtain a robust observer; The augmented state building module, used to rebuild the system state, includes the following steps: Step B2: Combine the original system state with the error system to obtain the augmented system: ; Where ξ(k)=[x T (k) e T (k)] T Let ξ(k+1) be the state of the augmented system at time k, and ξ(k+1) be the state of the augmented system at time k+1. It is the process noise of the augmented system. Is the system in The state at time t is e(k). Time error, It is a state estimate; and Is the system in Time-based process noise and measurement noise, It is a known constant vector. The state matrix of the augmented system has the following form: ; It is a known constant matrix. It is the gain matrix of the robust observer; The state interval estimation module is used to perform interval estimation of the original system state, including the following steps: Step C1: Assume the set of systematic errors e(k) is contained within a centrally symmetric polyhedron: Z e (k)=<p e (k),H e (k)> (5) Among them, Z e (k) is a centrally symmetric polyhedron containing the error at time k, p e (k) is Z e The center vector of (k), H e (k) is Z e The generating matrix of (k), where <·,·> represents a centrally symmetric polyhedron; Step C2: Because ,and These are the state estimates obtained from the robust point estimation module, therefore we get: ; Among them, Z x (k) is a centrosymmetric polyhedron containing the original system state at time k. It is Z x The center vector of (k), 0 n×n It is an n×n dimensional zero matrix. It is Minkowski and; Step C3: Based on the augmented system obtained from the augmented state construction module, we have: Z ξ (k)=<p ξ (k),H ξ (k)> (7) Among them, Z ξ (k) is a centrally symmetric polyhedron containing the state of the augmented system at time k, p ξ (k)=[(p x (k)) T (p e (k)) T ] T It is Z ξ The center vector of (k), H ξ (k)=diag{H e (k),H e (k)} is Z ξ The generating matrix of (k), where diag{·} is the function that constructs the diagonal matrix; Step C4: Assume the process noise of the augmented system The set to which it belongs is contained by the following centrally symmetric polyhedra: ; in, It is a centrosymmetric polyhedron containing augmented system process noise, 0 n×1 It is the zero vector of n dimensions. yes The generating matrix; Step C5: Substituting equations (7) and (8) into equation (4), we get the equation: ; Among them, Z ξ (k+1) is a centrally symmetric polyhedron containing the state of the augmented system at time k+1; According to equation (9), the iterative formula can be obtained: ; Step C6: As equation (10) iterates continuously, H ξ The dimension of (k) also continues to grow. Therefore, by performing a dimension reduction operation on equation (10), we obtain: ; in, It is H ξ The matrix obtained by transforming the matrix whose columns of (k) are arranged in descending order according to the Euclidean norm; Step C7: Based on the iterative results of equation (11), the interval estimation boundaries of the original system state are: ; Where i is the row number, j is the column number, and length(H) ξ (k) represents H ξ The length of (k), They represent The element in the i-th row, These are the upper and lower bounds of the system state x(k). p ξ The element in the i-th row of (k), H represents ξ The element in the i-th row and j-th column of (k), |·| is a function that takes the absolute value; The information intrusion alarm module is used for intrusion detection based on the interval estimation of the original system state.

2. According to the system of claim 1, the robust point estimation module is used to make a preliminary estimate of the system state, specifically including the following steps: Step A1: Obtain the system's mechanistic model: (1); in, Is the system in The state at any given moment, Is the system in Output at any moment; Step A2: Based on the obtained system model, design the corresponding robust observer: (2); in, and They are in Time and The estimated value of the system state at any given time. Is The estimated value of the system output at any given time.

3. The system according to claim 2, wherein the augmented state construction module, used to reconstruct the system state, further includes the following steps: Step B1: Subtract the state equation of the original system from the designed robust observer to obtain the error system: (3) in, yes Time error, That is Error in time.

4. According to the system as described in claim 3, the information intrusion alarm module is used to perform intrusion detection based on the interval estimation of the original system state, and completes this process as follows: Step D1: Obtain the real-time state x(k) of the system through the sensing device; Step D2: Compare x(k) with the estimated interval obtained from the state interval estimation module. For comparison, when x(k) falls within the interval When x(k) is within the specified range, the system is operating normally; when x(k) exceeds the specified range... When the system is within the specified range, it indicates that the system has been compromised and issues an alarm.

Citation Information

Patent Citations

  • Robust fault estimation method for discrete switching system based on unknown input observer

    CN111812980A

  • Joint interval estimation method for state and fault of networked control system under FDI attack

    CN114019944A