A distributed hybrid network attack detection method for interconnected nonlinear cyber-physical systems
By designing a hybrid network attack detection mechanism through distributed observers, the difficult problem of distributed hybrid network attack detection in interconnected cyber-physical systems is solved, the security and stability of the system are improved, and the comprehensive security assurance capability of the system is enhanced.
Patent Information
- Application Number
- CN202310417586.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-04-18
AI Technical Summary
Existing technologies make it difficult to effectively detect distributed hybrid network attacks in interconnected cyber-physical systems, threatening system security and stability.
A hybrid network attack detection mechanism is designed using a distributed observer. The interconnected nonlinear cyber-physical system model under external interference and hybrid network attacks is combined. The attack is determined by extending the state and residual signal, and the Lyapunov stability theory is used to analyze the stability of the closed-loop system.
It improves the security and reliability of interconnected nonlinear cyber-physical systems, enhances the system's comprehensive security assurance capabilities, and reduces performance losses and system failures.
Smart Images

Figure CN116668067B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to mixed network attack detection, in particular to a distributed mixed network attack detection method for interconnected nonlinear cyber-physical systems. BACKGROUND
[0002] With the fusion of Internet of Things and artificial intelligence, interconnected cyber-physical systems are widely used, such as smart grid systems, cross-domain unmanned systems, etc. However, various network attacks such as false data injection attacks, denial of service attacks, etc. are emerging in endlessly, which poses a great threat to the security and stability of interconnected information systems, causing huge economic losses.
[0003] In order to cope with the influence of network attacks on interconnected cyber-physical systems and improve the security of the system, many network attack detection methods have been studied. Literature [H. Sedjelmaci, S. M. Senouci and N. Ansari, "A Hierarchical Detection and Response System to Enhance Security Against Lethal Cyber-Attacks in UAV Networks," IEEE Transactions on Systems, Man, and Cybernetics: Systems, 48(9): 1594-1606.] studies the false data injection network attack method of interconnected unmanned aerial vehicle system.
[0004] The above-mentioned literature has made important contributions to the network attack detection of interconnected cyber-physical systems, and has proposed relatively effective network attack detection methods for specific attack types and attackers, but there are still deficiencies in the detection of distributed mixed network attacks, and there are certain limitations in practical application. It can be seen that it is of great significance to realize the distributed mixed network attack detection of interconnected cyber-physical systems by estimating the mixed network attack based on the actuator and sensor signal, so as to realize the stable operation of interconnected cyber-physical systems. SUMMARY
[0005] The present application aims to overcome the shortcomings of the prior art, and provides a distributed mixed network attack detection method suitable for interconnected nonlinear cyber-physical systems to solve the problem of external interference and mixed network attack based on actuators and sensors suffered by interconnected nonlinear cyber-physical systems, so as to improve the stable operation and control of the system.
[0006] To achieve the above objectives, the present invention is applicable to a distributed hybrid network attack detection method for interconnected nonlinear cyber-physical systems. The method is characterized by including a model of interconnected nonlinear cyber-physical systems under external interference and hybrid network attacks, a hybrid network attack detection mechanism based on a distributed observer, and closed-loop system stability analysis and proof. Specifically, the method comprises the following steps:
[0007] (1) Combining the characteristics of actuator false data injection network attacks, sensor false data injection network attacks and external interference functions, an interconnected nonlinear cyber-physical system model consisting of N interconnected cyber-physical subsystems is established;
[0008] (2) Based on the characteristics of the system model, the extended state is defined, the augmented system is established, the constant matrix is introduced, and then the distributed observer is designed. The obtained residual signal is then used to establish a hybrid network attack detection mechanism;
[0009] (3) Based on the estimation error dynamic equation and Lyapunov stability theory, the stability analysis and proof of the closed-loop system are realized.
[0010] The interconnected nonlinear cyber-physical system model under external interference and hybrid cyber attacks consists of N interconnected cyber-physical subsystems, where the state space model of the i-th cyber-physical subsystem subjected to the cyber attack of actuator false data injection, sensor false data injection and external interference at time t is expressed as where i = 1, 2, ... N; x i (t),u i (t), y i (t), a i (t) and d i (t) represents the state variables, control input signals, measurement output variables, false data injection network attacks and external interference of the cyber-physical subsystem respectively; f i (x i ,u i ,t) represents a known nonlinear function; h ij (x j ,u j ,t) represents the nonlinear coupling term between the ith cyber-physical subsystem and other neighboring subsystems; in represents the set of neighboring cyber-physical subsystems that have data interaction with the i-th cyber-physical subsystem; D ai is the sensor network attack parameter matrix; A i , B i , C i and D i are the known system parameter matrices, is the first-order derivative of ·; it should be noted that the state space models of the information-physical subsystem considered in this example are all controllable and objective; its nonlinear function f i (x i ,u i ,t) and h ij (x j ,u j ,t) satisfies the Lipschitz condition, that is, for f i (x i ,u i ,t), there is a constant L i > 0, so that for all (x i1 ,t) and (x i2 ,t), satisfying the following inequality:||f i (x i1 ,u i ,t)-f i (x i2 ,u i ,t)||≤L i ||x i1 -x i2 ||; for h ij (x j ,u j ,t), there is a constant So that for all (x0, t0) in a certain area j1 ,t) and (x j2 ,t), satisfies the following inequality The external interference considered in this example is energy-bounded and satisfies and The first-order derivative of the false injection network attack signal is bounded, that is, And ε i >0;
[0011] The hybrid network attack detection mechanism based on distributed observer is designed as follows: First, the augmented system is obtained based on the interconnected nonlinear cyber-physical system model under external interference and hybrid network attack, and its expression is: where z i (t) = [x i T (t) a i T (t)] T is the extended state of the system model; M i is a constant matrix; I is the identity matrix; secondly, according to the above augmented system design, the distributed observer is: in and They are the state variables z i (t) and the output variable y i The estimated value of (t), and is the nonlinear term and The estimate matrix is the parameter matrix; and the residual signal is I r =[0I]; Finally, the attack signal estimated by the distributed observer is used to design a hybrid network attack detection mechanism: if |r i (t)|>r th , define flag i =1, otherwise, flag i =0, where r th If the attack detection threshold is exceeded, it is determined that an attack has occurred and the system can issue an alarm to remind operators to conduct investigations and system maintenance to reduce system performance losses;
[0012] The stability analysis and proof of the closed-loop system are first designed to estimate the error dynamic equation The estimated error is Then analyze the dynamic equation of the estimation error and define the Lyapunov function Among them, P i is the designed positive definite symmetric matrix; define H ∞ Performance indicators Where γ is the designed positive scalar; Based on the above, we can get: for the control input signal u i (t) and the measured output signal y i (t) Simultaneously suffer from false data injection network attack a i (t) is an interconnected nonlinear cyber-physical system and the estimation error dynamic equation. For a given positive scalar γ, if there exists a positive definite symmetric matrix P i and the matrix π i , so that the following equation has a solution: in Then the system estimation error dynamic equation is asymptotically stable and satisfies H ∞ Performance indicators are Distributed observer parameter matrix Can be obtained by Solved.
[0013] The beneficial effect of the present invention is that it can effectively solve the problems of external interference suffered by interconnected nonlinear information-physical systems and hybrid network attack detection based on actuators and sensors, thereby improving the security and reliability of the system and enhancing the system's comprehensive security assurance capabilities.
[0014] The present application is further explained with regard to the accompanying drawings and detailed description below. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 is a structure schematic diagram of the interconnected nonlinear cyber-physical system of the present application;
[0016] Figure 2 is a distributed hybrid network attack detection structure diagram of the interconnected nonlinear cyber-physical system of the present application; DETAILED DESCRIPTION
[0017] The technical solutions of the present application are described in detail, clearly and completely below with regard to an interconnected nonlinear cyber-physical system under external disturbance and hybrid network attack, in combination with the accompanying drawings, to facilitate the professional technical personnel in the field to better understand the present application. It needs to be specially reminded that in the following description, when the detailed description of the known functions and designs may weaken the main content of the present application, these descriptions will be omitted here.
[0018] EMBODIMENT
[0019] Figure 1 is a structure schematic diagram of the interconnected nonlinear cyber-physical system of the present application, Figure 2 is a specific embodiment schematic diagram of the distributed hybrid network attack detection method of the interconnected nonlinear cyber-physical system of the present application. As shown in Figure 2 the specific steps of the distributed hybrid network attack detection method of the interconnected nonlinear cyber-physical system of the present application include: modeling of the interconnected nonlinear cyber-physical system under external disturbance and hybrid network attack, hybrid network attack detection mechanism design based on distributed observer, and closed-loop system stability analysis and proof.
[0020] The present application considers a kind of interconnected nonlinear cyber-physical system consisting of N interconnected information physical subsystems, and there can be certain information interaction between each subsystem, and control input signal and measurement output signal are transmitted between controller and physical device through communication network. In this information transmission process, the system is vulnerable to network attacks launched by malicious attackers. The present application studies the case where the system is subjected to false data injection attack, and the attacker intercepts the control input signal and measurement output signal transmitted in the network, injects attack signal into it, and sends the tampered signal back, to achieve the purpose of damaging system operation.
[0021] The model of the interconnected nonlinear cyber-physical system under external disturbance and hybrid network attack of the present application consists of N interconnected information physical subsystems, and the state space model of the information physical subsystem subjected to actuator false data injection network attack, sensor false data injection network attack and external disturbance at time t is expressed as
[0022]
[0023] where i = 1, 2,... N; x i (t), u i (t), y i (t), a i (t) and d i (t) represent state variables of cyber-physical systems, control input signals, measured output variables, false data injection cyber-attack signals and external disturbances, respectively; f i (x i , u i , t) represents a known nonlinear function; h ij (x j , u j , t) represents nonlinear coupling terms of the i-th cyber-physical system and other neighboring systems; denotes a set of neighboring cyber-physical systems that have data interactions with the i-th cyber-physical system; D ai is a sensor cyber-attack parameter matrix; A i , B i , C i and D i are known system parameter matrices, is the first order derivative of ·; it is noted that the cyber-physical system state space models considered in this example are controllable and objective; their nonlinear functions f i (x i , u i , t) and h ij (x j , u j , t) satisfy Lipschitz condition, i.e., for f i (x i , u i , t), there exists a constant L i > 0 such that for all (x i1 , t) and (x i2 , t) in some neighborhood of (x0, t0), the following inequality holds: ||f i (x i1 , u i , t) - f i (x i2 , u i , t)|| ≤ L i ||x i1 - x i2 ||; for h ij (x j , u j , t), there exists a constant So that for all (x0, t0) in a certain area j1 ,t) and (x j2 ,t), satisfies the following inequality The external interference considered in this example is energy-bounded and satisfies and The first-order derivative of the false injection network attack signal is bounded, that is, And ε i >0;
[0024] This example designs a hybrid network attack detection mechanism based on a distributed observer: First, an augmented system is obtained based on the interconnected nonlinear cyber-physical system model under external interference and hybrid network attacks, which is expressed as
[0025]
[0026] where z i (t) = [x i T (t) a i T (t)] T is the extended state of the system model; M i is a constant matrix; I is the identity matrix;
[0027] Secondly, according to the above augmented system design, the distributed observer is obtained as:
[0028]
[0029] in and They are the state variables z i (t) and the output variable y i The estimated value of (t), and is the nonlinear term and The estimate matrix is the parameter matrix; and the residual signal is I r =[0I]; Finally, the attack signal estimated by the distributed observer is used to design a hybrid network attack detection mechanism: if |r i (t)|>r th , define flag i =1, otherwise, flag i =0, where r thIf the attack detection threshold is exceeded, it is determined that an attack has occurred and the system can issue an alarm to remind operators to conduct investigations and system maintenance to reduce system performance losses.
[0030] In this example, the stability analysis and proof of the closed-loop system are first designed to estimate the error dynamic equation.
[0031]
[0032] The estimated error is
[0033] Then analyze the dynamic equation of the estimation error and obtain the nonlinear error and satisfy: Among them, L i and are known nonlinear functions f i (x i ,u i ,t) and h ij (x j ,u j ,t)’s Lipschitz constant.
[0034] Define the Lyapunov function Among them, P i is the designed positive definite symmetric matrix; according to the estimated error dynamic equation, we can get V i The derivative of (t) is of the form:
[0035]
[0036] Define H ∞ Performance indicators Where γ is a designed positive scalar; under zero initial conditions and Lyapunov function characteristics V i ≥0, we can get:
[0037]
[0038] From the above formula, we can get that the second term on the right side of the inequality sign in formula (5) satisfies:
[0039]
[0040] The third term on the right side of the inequality sign in formula (6) satisfies:
[0041]
[0042] Substituting equations (7) and (8) into (6), we can obtain
[0043]
[0044] right There is h ij (x j ,u j ,t)=0, then
[0045]
[0046] Therefore, formula (9) can be written as
[0047]
[0048] in If Σ i <0 holds, then J≤0. It can be concluded that the dynamic equation of the estimated error is asymptotically stable and satisfies H ∞ Performance indicators. Further, by robust H ∞ Stability control theory, we can get
[0049]
[0050] Based on the above analysis, we can get: i (t) and the measured output signal y i (t) Simultaneously suffer from false data injection network attack a i (t) is an interconnected nonlinear cyber-physical system and the estimation error dynamic equation. For a given positive scalar γ, if there exists a positive definite symmetric matrix P i and the matrix π i , so that the following equation has a solution: in Then the system estimation error dynamic equation is asymptotically stable and satisfies H ∞ Performance indicators are Distributed observer parameter matrix Can be obtained by Solved.
Claims
1. A distributed hybrid network attack detection method for interconnected nonlinear cyber-physical systems, including a model of interconnected nonlinear cyber-physical systems under external interference and hybrid network attacks, a hybrid network attack detection mechanism based on a distributed observer, and closed-loop system stability analysis and proof; characterized by: The steps include: Step 1: Combined with the characteristics of actuator false data injection network attack, sensor false data injection network attack and external interference function, an interconnected nonlinear cyber-physical system model consisting of N interconnected cyber-physical subsystems is established; Step 2: Based on the system model characteristics, define the extended state, establish the augmented system, introduce the constant matrix, and then design the distributed observer. Then, use the obtained residual signal to establish a hybrid network attack detection mechanism; Step 3: Based on the estimation error dynamic equation and Lyapunov stability theory, analyze and prove the stability of the closed-loop system; The interconnected nonlinear cyber-physical system model under external interference and hybrid cyber attacks is composed of N interconnected cyber-physical subsystems, where the state space model of the cyber-physical subsystem i that is subjected to the cyber attack of actuator false data injection, sensor false data injection and external interference at time t is expressed as where i = 1, 2, ... N; x i (t),u i (t), y i (t), a i (t) and d i (t) represents the state variables, control input signals, measurement output variables, false data injection network attacks and external interference of the cyber-physical subsystem respectively; f i (x i ,u i ,t) represents a known nonlinear function; h ij (x j ,u j ,t) represents the nonlinear coupling term between the ith cyber-physical subsystem and other neighboring subsystems; in represents the set of neighboring cyber-physical subsystems that have data interaction with the i-th cyber-physical subsystem; D ai is the sensor network attack parameter matrix; A i , B i , C i and D i are the known system parameter matrices, is the first derivative of ; The hybrid network attack detection mechanism based on distributed observers is as follows: First, based on the interconnected nonlinear cyber-physical system model under external interference and hybrid network attack, an augmented system is obtained, which is expressed as where z i (t) = [x i T (t) a i T (t)] T is the extended state of the system model; M i is a constant matrix; I is the identity matrix; secondly, according to the above augmented system design, the distributed observer is: in and They are the state variables z i (t) and the output variable y i The estimated value of (t), and is the nonlinear term and The estimate matrix is the parameter matrix; And the residual signal is I r =[0I]; Finally, the attack signal estimated by the distributed observer is used to design a hybrid network attack detection mechanism: if |r i (t)|>r th , define flag i =1, otherwise, flag i =0, where r th If the attack detection threshold is exceeded, it is determined that an attack has occurred and the system can issue an alarm to remind operators to conduct investigations and system maintenance to reduce system performance losses; The stability analysis and proof of the closed-loop system are first designed to estimate the error dynamic equation The estimated error is Then analyze the dynamic equation of the estimation error and define the Lyapunov function Among them, P i is the designed positive definite symmetric matrix; define H ∞ Performance indicators Where γ is the designed positive scalar; Based on the above, we can get: for the control input signal u i (t) and the measured output signal y i (t) Simultaneously suffer from false data injection network attack a i (t) is an interconnected nonlinear cyber-physical system and the estimation error dynamic equation. For a given positive scalar γ, if there exists a positive definite symmetric matrix P i and the matrix π i , so that the following equation has a solution: in Then the system estimation error dynamic equation is asymptotically stable and satisfies H ∞ Performance indicators are Simultaneous distributed observer parameter matrix Can be obtained by Solved.
2. The method according to claim 1, wherein the interconnected nonlinear cyber-physical system model under external interference and hybrid network attack is characterized by: This system consists of N interconnected, controllable, and observable nonlinear cyber-physical subsystems, with a multi-layered network structure consisting of physical layer, network layer, and control layer. The subsystems interact with each other and transmit control signals and measurement output signals between the controller and the physical devices through the communication network. Its multi-layer network structure makes its actuators and sensors vulnerable to false data injection network attacks, and its false data injection network attack signal a i The first-order derivative of (t) is bounded, that is, And ε i > 0; and the external interference suffered by the interconnected nonlinear cyber-physical system is energy-bounded, satisfying the condition and 3. The method according to claim 2, wherein the nonlinear cyber-physical subsystem is characterized in that Its nonlinear function f i (x i ,u i ,t) and h ij (x j ,u j ,t) satisfies the Lipschitz condition, that is, for f i (x i ,u i ,t), there is a constant L i > 0, so that for all (x i1 ,t) and (x i2 ,t), satisfying the following inequality:||f i (x i1 ,u i ,t)-f i (x i2 ,u i ,t)||≤L i ||x i1 -x i2 ||; for h ij (x j ,u j ,t), there is a constant So that for all (x0, t0) in a certain neighborhood j1 ,t) and (x j2 ,t), satisfying the following inequality:
4. The method according to claim 1, wherein the hybrid network attack detection mechanism based on distributed observers is characterized in that Through the state space model of the i-th nonlinear cyber-physical subsystem that is subjected to the cyber attack of actuator false data injection, sensor false data injection and external interference, the extended state is defined, and the augmented system is obtained based on the state space model. At the same time, the constant matrix is introduced to design a distributed observer, and the obtained residual signal is used to establish a hybrid network attack detection mechanism, thereby realizing the detection of hybrid network attacks; in addition, the distributed observer parameter matrix Can be obtained by Solved.
Citation Information
Patent Citations
Attack detection method considering attack signal and unknown disturbance based on interconnected CPS
CN115051872A
Fault detection method for multi-region photovoltaic power generation system under DoS attack
CN115459708A