A physical layer interference attack recovery method for a software-defined optical network

By employing a machine learning-based end-to-end attack recovery system in optical networks, and training models for different attack types, the problem of communication interruption caused by optical network signal interference attacks was solved, achieving efficient signal recovery and stable communication.

CN116743268BActive Publication Date: 2026-05-29CHONGQING UNIV OF POSTS & TELECOMM

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHONGQING UNIV OF POSTS & TELECOMM
Filing Date
2023-06-20
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies require additional optical path resources and cannot guarantee real-time communication when facing signal interference attacks on optical networks, leading to communication service interruptions.

Method used

An end-to-end attack recovery system based on machine learning is adopted. By collecting signal bit sequences under different attack conditions and training machine learning models, the system can recover from signal interference attacks and avoid the consumption of additional optical path resources.

Benefits of technology

It achieves high recovery rate and high recovery speed under different attack intensities and types, and does not require additional optical path resources, thus ensuring the real-time performance and stability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743268B_ABST
    Figure CN116743268B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of physical layer interference attack recovery methods for software-defined optical network, belong to optical fiber communication security technical field, including the following steps: S1: define macroscopic optical network physical layer signal interference attack recovery framework;S2: build in-band, out-of-band interference attack implementation 16QAM dual polarization wavelength division multiplexing coherent communication system;S3: construct and train the end-to-end attack recovery model based on machine learning;S4: define mild, intensity in-band interference attack;S5: define mild, intensity out-of-band interference attack;S6: by the end-to-end attack recovery model based on machine learning of well-trained different attack intensity, different attack type interference attack recovery is realized.The present application realizes the recovery of attack without additional optical path resources and high recovery rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of optical fiber communication security technology and relates to a method for recovering from physical layer interference attacks in software-defined optical networks. Background Technology

[0002] As a carrier of communication traffic generated in important national sectors such as communication, transportation, aviation, aerospace, finance, healthcare, energy, education, and national defense, optical networks are vulnerable to physical layer attacks from various attackers due to their transparent structure and the complex environment in which optical fibers are deployed. Among the more destructive physical layer attacks are signal jamming attacks, which are divided into two types. One type involves injecting an interference signal with a transmission bandwidth within the legitimate signal's transmission bandwidth into the legitimate signal's transmission channel during legitimate signal transmission. When the legitimate signal is demodulated at the receiving end, the interference introduces unfilterable noise into the legitimate signal, thus degrading the communication quality between the two parties. This type of attack is called an in-band jamming attack. The other type involves injecting a high-power interference signal with a transmission bandwidth outside the legitimate signal's transmission bandwidth into the legitimate signal's transmission channel during legitimate signal transmission. When the legitimate signal is transmitted in the channel, the high-power interference signal, through gain competition in the EDFA (Erbium Doped Fiber Amplifier) ​​and the nonlinear effects of the fiber, causes power attenuation and phase changes in the legitimate signal, degrading the signal transmission quality and ultimately reducing or even interrupting the communication service between the two parties. This type of attack is called an out-of-band jamming attack.

[0003] Currently, the effective recovery mechanism against such signal interference attacks is to use optical path resource reallocation technology, that is, to re-establish an optical path to retransmit the legitimate signal, thereby avoiding the legitimate signal from being continuously affected by the interference signal. However, such an attack recovery mechanism requires additional optical path resources, and retransmitting the legitimate signal will interrupt the communication service of the original two parties, making it impossible to guarantee the real-time performance of the user's communication. Summary of the Invention

[0004] In view of this, considering the advantages of machine learning in big data processing tasks, and the fact that a signal will change a large number of bit sequences after being attacked, the purpose of this invention is to provide an end-to-end attack recovery system based on machine learning. By collecting the bit sequences of the signal before and after the attack at the receiving end under different attack conditions, the attack recovery system is used to train machine learning attack recovery models with different attack intensities and attack types. Then, the trained machine learning attack recovery models are used to directly recover the attacked bit sequences. This not only ensures the real-time nature of attack recovery and improves the attack recovery rate, but also does not require additional optical path resources.

[0005] To achieve the above objectives, the present invention provides the following technical solution:

[0006] A method for recovering from physical layer interference attacks in software-defined optical networks includes the following steps:

[0007] S1: Defines a macroscopic framework for recovering from signal interference attacks at the physical layer of optical networks;

[0008] S2: Construct a 16QAM dual-polarization wavelength division multiplexing coherent communication system that achieves in-band and out-of-band interference attacks;

[0009] S3: Build and train an end-to-end attack recovery model based on machine learning;

[0010] S4: Under the condition of no injected interference signal, the signal transmission in the coherent communication system is marked as normal signal transmission. The 16QAM signal transmission power is kept constant. The power of the injected interference signal is changed. While keeping the power constant, the transmission frequency of the interference signal is changed. The range of the transmission frequency change is within the transmission window of the 16QAM signal. After N attacks, the distribution of BER at the receiver is statistically analyzed. Based on the BER distribution, the interference attack at this power is defined as a mild in-band interference attack or a strong in-band interference attack. The signal bit sequence of the 16QAM signal obtained at the receiver under mild, strong in-band interference attacks and normal transmission conditions is collected.

[0011] S5: Define mild and strong out-of-band interference attacks. With the 16QAM signal transmission power unchanged, change the transmission frequency of the interference signal under different injected interference signal powers. The frequency range is outside the transmission window of the legitimate signal. After N attacks under a specific power interference signal attack, statistically analyze the distribution of BER at the receiver. Based on the BER distribution, define whether the interference attack under this power is a mild out-of-band interference attack or a strong out-of-band interference attack. Collect the signal bit sequence of the 16QAM signal at the receiver under mild, strong out-of-band interference attacks and normal transmission conditions.

[0012] S6: Achieve recovery from interference attacks of different intensities and types by using a trained machine learning-based attack recovery model.

[0013] Furthermore, the workflow of the macroscopic optical network physical layer signal interference attack recovery framework defined in step S1 is as follows:

[0014] After the wavelength division multiplexed optical signal at the transmitting end enters the optical network through the coupling device OXC, it is then demultiplexed through the OXC and reaches the receiving end for demultiplexing. Finally, each optical signal is coherently demodulated and processed by DSP (Digital Signal Processing).

[0015] The attack model in the framework considers that an attacker injects interference signals into network nodes through some coupling devices OXC, and the interference signals are transmitted through the optical network together with the normal signals;

[0016] The attack detection, identification, and recovery process is as follows: First, the optical network controller periodically retrieves, stores, and preprocesses the spectral data collected by the receiver after dimensionality reduction via Principal Component Analysis (PCA). Then, it uses an offline-trained attack detection model to detect and identify attacks, determining whether the optical signal has been attacked. If not, it performs normal demodulation and DSP processing. If attacked, it sends attack strength and type information to the DSP controller at the receiver. The DSP can then activate the corresponding attack recovery module based on the attack information provided by the DSP controller.

[0017] Furthermore, step S2, which describes the construction of a 16QAM dual-polarization wavelength division multiplexing coherent communication system implemented through in-band and out-of-band interference attacks, specifically includes:

[0018] The transmitter generates eight sub-channel wavelength division multiplexed signals with a bandwidth of 50 GHz, including one dual-polarization 16QAM coherent optical signal with frequency f0 and seven empty carriers with frequencies f1 to f7. ja The interference signal is injected into an optical fiber with N loops through a coupler with a split ratio of 50:50 and the wavelength division multiplexed signal. Each loop consists of a standard single-mode fiber (SSMF) and an EDFA.

[0019] At the receiving end, a 16QAM optical signal affected by interference attack signals is obtained through an OBPF with a center frequency of f0 and a bandwidth of 50GHz. Then, it is received by a coherent receiver and processed by DSP. The bit sequence carried by the signal is collected for training an end-to-end attack recovery model based on machine learning.

[0020] Furthermore, the training process of the machine learning-based end-to-end attack recovery model is viewed as a machine learning-based multi-output regression problem;

[0021] When not under attack, the signal sent by the transmitter is transmitted normally, and after demodulation and digital signal processing at the receiver, the bit sequence of the signal is obtained as the label of the collected dataset and used as feedback for the machine learning-based attack recovery model.

[0022] After the transmitter sends the same signal and it is attacked by interference during transmission, the receiver demodulates and processes the signal digitally to obtain the bit sequence of the signal. This bit sequence is used as the feature of the collected dataset and as the input of the machine learning-based attack recovery model. Data is collected under different in-band and out-of-band interference attacks of different intensities to train the in-band and out-of-band interference attack recovery models of different intensities.

[0023] Finally, after detecting the type and intensity of the attack on the system, the attacked signal bit sequence is directly used as the input to the corresponding trained machine learning-based attack recovery model, and the model output is the recovered signal bit sequence.

[0024] Furthermore, the distribution of BER at the statistical receiver is used to define whether an interference attack at this power level is a mild in-band interference attack or a strong in-band interference attack, specifically including:

[0025] If the number of samples with BER < 0.02 accounts for 50% or more of the total number of samples, it is considered that there is a 50% or more probability of strong error correction or bit error correction under the power of the in-band interference attack, so as to eliminate the impact of the attack. This type of attack is called mild in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0026] If the number of samples with BER < 0.02 accounts for 5% or less of the total number of samples, it is considered that the probability of eliminating the impact of the attack and achieving normal transmission under this attack is less than or equal to 5%. This type of attack is defined as an in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0027] Furthermore, the machine learning-based attack recovery model is a model based on Bidirectional Long Short-Term Memory-Bidirectional Gated Recurrent Unit (BiLSTM-BiGRU), consisting of an input layer, an LSTM layer, a GRU layer, and an output layer. The LSTM layer comprises forward LSTM blocks and backward LSTM blocks, and the GRU layer comprises forward GRU blocks and backward GRU blocks. GRU is a homologous variant of LSTM. When the input X represents the bit sequence of the signal after an attack, X enters the input layer and then the LSTM layer. The forward and backward LSTM blocks of the LSTM layer first perform feature mining and calculation on X, then transmit the results to the GRU layer. The forward and backward GRU blocks of the GRU layer extract features from the output of the LSTM layer and perform calculations, finally outputting the results to the output layer to obtain the recovered signal bit sequence Y.

[0028] The training process of the BiLSTM-BiGRU model uses the RMSprop optimizer and employs the Mean Squared Error (MSE) function as the loss function.

[0029]

[0030] Among them, y i Represents the true value, y i This represents the model's predicted value, or output value.

[0031] The Mean Absolute Error (MAE) function is used as the evaluation function.

[0032]

[0033] The output layer uses the sigmoid activation function:

[0034]

[0035] The beneficial effects of this invention are as follows: This invention achieves high recovery rate, high recovery speed, and low training time cost recovery of signal interference attacks of different attack intensities and types without consuming additional optical path resources.

[0036] Other advantages, objectives, and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination, or may be learned from practice of the invention. The objectives and other advantages of the invention can be realized and obtained through the following description. Attached Figure Description

[0037] To make the objectives, technical solutions, and advantages of the present invention clearer, the preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, wherein:

[0038] Figure 1 A network framework for attack detection and identification, and a framework for recovering from physical layer signal interference attacks in optical networks;

[0039] Figure 2 This is a 16QAM dual-polarization wavelength division multiplexing coherent communication system.

[0040] Figure 3 An end-to-end attack recovery system based on machine learning;

[0041] Figure 4 Loss curves for BP-LIB, BiLSTM-LIB, and BiLSTM-BiGRU-LIB;

[0042] Figure 5 The attack recovery effect of BiLSTM-BiGRU-LIB is shown in (a) and (b) respectively.

[0043] Figure 6 The loss curves are for BP-SIB, BiLSTM-SIB, and BiLSTM-BiGRU-SIB.

[0044] Figure 7 The attack recovery effect of BiLSTM-BiGRU-SIB is shown in (a) and (b) respectively.

[0045] Figure 8 The loss curves for BP-LOOB, BiLSTM-LOOB, and BiLSTM-BiGRU-LOOB are shown.

[0046] Figure 9 The attack recovery effect of BiLSTM-BiGRU-LOOB is shown in (a) and (b) respectively.

[0047] Figure 10 The loss curves are for BP-SOOB, BiLSTM-SOOB, and BiLSTM-BiGRU-SOOB.

[0048] Figure 11 The loss curves are for BP-SOOB, BiLSTM-SOOB, and BiLSTM-BiGRU-SOOB.

[0049] Figure 12 This is a diagram of the BiLSTM-BiGRU network structure. Detailed Implementation

[0050] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0051] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual pictures. They should not be construed as limiting the invention. To better illustrate the embodiments of the invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.

[0052] In the accompanying drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components. In the description of the present invention, it should be understood that if terms such as "upper," "lower," "left," "right," "front," and "rear" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting the present invention. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.

[0053] Considering the advantages of machine learning in big data processing tasks, and that a signal being attacked can alter a large number of bit sequences it carries.

[0054] Therefore, this invention proposes a high-attack recovery rate, high-attack recovery speed, and low-cost interference attack recovery method using signal bit sequences: a physical layer interference attack recovery method for software-defined optical networks. Under different attack conditions, the bit sequences of the signal before and after the attack are collected at the receiving end. The attack recovery system proposed in this invention is used to train machine learning attack recovery models with different attack intensities and attack types. Then, the trained machine learning attack recovery models are used to directly recover the attacked bit sequences. This not only ensures the real-time performance of attack recovery and improves the attack recovery rate, but also does not require additional optical path resources.

[0055] Includes the following:

[0056] Step 1: Define a macroscopic framework for recovering from optical network physical layer signal interference attacks, such as... Figure 1 As shown, an attack detection and identification function has been added to the optical network controller. The workflow of the proposed optical network physical layer signal interference attack recovery framework is as follows: The wavelength division multiplexed optical signal at the transmitting end enters the optical network through a coupling device such as an OXC (Optical Cross Connection), then goes through the OXC again for demultiplexing, and finally reaches the receiving end for demultiplexing. Finally, each optical signal undergoes coherent demodulation and DSP (Digital Signal Processing). The attack model in the framework considers that attackers inject interference signals at network nodes through some coupling devices (OXCs), and the interference signals are transmitted through the optical network along with the normal signals. The attack detection, identification, and recovery process is as follows. First, the optical network controller periodically retrieves, stores, and preprocesses the spectral data acquired by the receiver after PCA (Principal Component Analysis) dimensionality reduction. Then, it uses an offline-trained attack detection model to detect and identify attacks, determining whether the optical signal is under attack. If not, it performs normal demodulation and DSP processing. If attacked, it sends attack strength and type information to the receiver's DSP controller. The DSP can then activate the corresponding attack recovery module based on the attack information provided by the DSP controller. Figure 1 As shown, if the optical network controller detects an attack on user 1's optical path, it will send out user 1's signal security status information, notifying user 1 of the attack strength and type. Next, user 1's coherent receiver demodulates the signal, performs DSP processing to obtain user 1's bit sequence, recovers the attacked bit sequence through the attack recovery module, and then sends the recovered bit sequence back to user 1. This achieves the mitigation of the attack's impact without additional optical path resource reallocation, thus achieving attack recovery. It is worth noting that the attack recovery module in the framework integrates offline-trained attack recovery models with different attack strengths and types, allowing the selection of the appropriate attack recovery model based on the attack information received by the signal.

[0057] Step 2: Construct a 16QAM dual-polarization wavelength division multiplexing coherent communication system implemented with in-band and out-of-band interference attacks, such as... Figure 2 As shown, to simulate a real optical communication system, the transmitting end generates eight wavelength division multiplexed signals with a sub-channel bandwidth of 50 GHz, including one dual-polarization 16QAM coherent optical signal with frequency f0 and seven empty carriers with frequencies f1 to f7. jaInterference signals (including mild and strong in-band and out-of-band interference signals) are injected into an optical fiber with N loops along with a wavelength division multiplexed signal via a 50:50 splitter coupler. Each loop consists of SSMF (Standard Single Mode Fiber) and EDFA. At the receiving end, a 16QAM optical signal affected by the interference attack signal is obtained through an OBPF with a center frequency of f0 and a bandwidth of 50 GHz. This signal is then received by a coherent receiver and subjected to DSP processes such as resampling, dispersion compensation, channel equalization, carrier recovery, and phase recovery. The bit sequence carried by the acquired signal is used to train a machine learning-based attack recovery model.

[0058] Step 3: The end-to-end attack recovery system based on machine learning proposed in this invention is as follows: Figure 3 As shown in the diagram, the attack recovery model training process is illustrated. The upper branch represents the normal signal transmission scenario, while the lower branch represents the scenario where the signal is affected by interference injected into the optical fiber by an attacker via OXC during transmission. The training process of the attack recovery model can be viewed as a multi-output regression problem based on machine learning. First, after the signal transmitted by the transmitter in the upper branch is transmitted normally, it is demodulated and digitally processed at the receiver to obtain the bit sequence of the signal, which is used as the label of the collected dataset and as feedback for the machine learning model. The lower branch represents the transmission scenario after the signal transmitted by the transmitter is attacked.

[0059] After the same signal transmitted by transmitter 1 in the lower branch is subjected to interference during transmission, it undergoes demodulation and digital signal processing at receiver 1. The resulting bit sequence is used as a feature of the collected dataset and as input to a machine learning model. Data is collected under in-band and out-of-band interference attacks of varying intensities to train recovery models for different in-band and out-of-band interference attacks. The trained attack recovery model neutralizes the interference from in-band and out-of-band interference attacks, compensating for the interference caused by their mechanisms. Finally, after detecting the type and intensity of the attack, the bit sequence of the attacked signal is directly used as input to the corresponding trained attack recovery model, and the model output is the recovered bit sequence of the signal.

[0060] Step 4: Ensure the 16QAM signal transmit power remains constant, change the power of the interference signal, and while keeping the power constant, change the transmission frequency of the interference signal. The frequency variation should be within the transmission window of the 16QAM signal, i.e., f0-25GHz ≤ f ja ≤f0+25GHz, where f0 is the carrier frequency of the transmitted signal, f jaAfter 101 attacks on the frequency of the interference signal, the distribution of BER at the receiver is statistically analyzed. If, under a certain power, the number of samples with BER < 0.02 accounts for 50% or more of the total number of samples in 101 attacks by changing the frequency of the interference signal, it is considered that the in-band interference attack at that power has a 50% or more probability of incurring some high costs, such as strong error correction, bit error correction, so as to eliminate the impact of the attack. This type of attack is called a mild in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0061] If the number of samples with BER < 0.02 accounts for 5% or less of the total number of samples, it is considered that the probability of eliminating the impact of the attack and achieving normal transmission under this attack is less than or equal to 5%. This type of attack is defined as an in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0062] Step 5: Define mild and strong out-of-band interference attacks. Similar to mild in-band interference attacks, the definition of strong in-band interference attacks is as follows: with the 16QAM signal transmission power unchanged, change the transmission frequency of the interference signal under different interference signal powers. The frequency range is outside the transmission window of the legitimate signal. Under a specific power interference attack, conduct 101 experiments. If the number of samples with BER < 0.02 at the receiver accounts for 50% or more of the total number of samples, this type of attack is considered to be a mild out-of-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0063] If the number of samples with BER < 0.02 accounts for 5% or less of the total number of samples, this type of attack is defined as an out-of-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

[0064] Step 6: Build BiLSTM-BiGRU, BiLSTM, and BP regression models. Validate the advantages of BiLSTM-BiGRU over the other two models in recovering from interference attacks of different attack intensities and types using three metrics: attack recovery rate, attack recovery speed, and training time cost of the attack recovery model. Ultimately, achieve high recovery rate, high recovery speed, and low training time cost for recovering signal interference attacks.

[0065] In this embodiment, VPI Transmission Maker 9.5 is used as the simulation software to verify the performance of the proposed scheme. The transmission system is as follows: Figure 2 As shown in Table 1, some of the simulation parameters in VPI are as follows:

[0066] Table 1

[0067]

[0068] For the 16QAM optical signal transmitter, the baud rate is set to 25 GBaud, the frequency f0 = 193.1 THz, and the transmit optical power is 5 dBm. For the fiber optic link, the number of loops N = 4, the standard single-mode fiber length in each loop is set to 100 km, the fiber attenuation is set to 0.2 dB / km, the dispersion is 16 ps / (nm·km), and the dispersion slope is set to 0.08 × 10⁻⁶. 3 s / m 3 The group refractive index is set to 1.47, and the polarization mode dispersion is set to... The nonlinear coefficient is set to 2.6 × 10⁻⁶. -20 m 2 / W, EDFA power is set to 20dBm.

[0069] 1. Data Collection under Mild In-Band Interference Attacks

[0070] The transmission power of the interference signal was set to -15.38dBm, -15.23dBm, -15.09dBm, -14.95dBm, -14.82dBm, -14.69dBm, -14.56dBm, -14.44dBm, -14.32dBm, and -14.20dBm using a continuous wave laser. At different transmission powers, the frequency f of the interference signal was... ja The range of variation is set to f0-25GHz≤f ja ≤f0+25GHz, where f0 represents the center frequency of the dual-polarization 16QAM optical signal. 101 in-band interference attack experiments were conducted, and 101 bit sequence samples were collected at the receiver. The feature in a bit sequence sample represents the bit sequence sample at the receiver after a slight in-band interference attack, while the label represents the bit sequence sample at the receiver during normal signal transmission. A total of 101 × 10 = 1010 bit sequence samples were collected. When the collected bit sequence samples were used to train the attack recovery model, the model could learn the correlation between the transformation of the Feature bit sequence and the Label bit sequence, thereby compensating for the impact of the attack. Table 2 reflects the detailed information on the bit sequence sample collection.

[0071] Table 2

[0072]

[0073] 2. Data Collection under In-Band Interference Attacks

[0074] Table 3

[0075]

[0076]

[0077] The transmission power of the interference signal was set to -10.71dBm, -10.46dBm, -10.22dBm, -10.00dBm, -9.79dBm, -9.59dBm, -9.39dBm, -9.21dBm, -9.03dBm, and -8.86dBm using a continuous wave laser. At different transmission powers, the frequency f of the interference signal was... ja The range of variation is set to f0-25GHz≤f ja ≤f0+25GHz, where f0 represents the center frequency of the dual-polarization 16QAM optical signal. 101 in-band interference attack experiments were conducted, and 101 bit sequence samples were collected at the receiver. The feature of a bit sequence sample represents the bit sequence sample at the receiver after the signal has been subjected to strong in-band interference, while the label represents the bit sequence sample at the receiver during normal signal transmission. A total of 101 × 10 = 10¹⁰ bit sequence samples were collected. Table 3 reflects the detailed information on the bit sequence sample collection.

[0078] 3. Data Collection under Mild Out-of-Band Interference Attacks

[0079] Table 4

[0080]

[0081] The transmission power of the interference signal was set to 14.23dBm, 14.31dBm, 14.39dBm, 14.47dBm, 14.55dBm, 14.62dBm, 14.70dBm, 14.78dBm, 14.84dBm, and 14.91dBm using a continuous wave laser. At different transmission powers, the frequency f of the interference signal was... ja The range of variation is set to f0 + 200GHz ≤ f ja ≤f0+400GHz, where f0 represents the center frequency of the dual-polarization 16QAM optical signal. 101 out-of-band interference attack experiments were conducted, and 101 bit sequence samples were collected at the receiver. The feature of a bit sequence sample represents the bit sequence sample at the receiver after a slight out-of-band interference attack, while the label represents the bit sequence sample at the receiver during normal signal transmission. A total of 101 × 10 = 10¹⁰ bit sequence samples were collected. Table 4 reflects the detailed information on the bit sequence sample collection.

[0082] 4. Data Collection under Intensity Out-of-Band Interference Attacks

[0083] The transmission power of the interference signal was set to 16.13dBm, 16.23dBm, 16.34dBm, 16.44dBm, 16.53dBm, 16.63dBm, 16.72dBm, 16.81dBm, 16.90dBm, and 16.99dBm using a continuous wave laser. At different transmission powers, the frequency f of the interference signal was... ja The range of variation is set to f0 + 200GHz ≤ f ja ≤f0+400GHz, where f0 represents the center frequency of the dual-polarization 16QAM optical signal. 101 out-of-band interference attack experiments were conducted, and 101 bit sequence samples were collected at the receiver. The feature of a bit sequence sample represents the bit sequence sample at the receiver after the signal has been subjected to strong out-of-band interference, while the label represents the bit sequence sample at the receiver during normal signal transmission. A total of 101 × 10 = 10¹⁰ bit sequence samples were collected. Table 5 reflects the detailed information on the bit sequence sample collection.

[0084] Table 5

[0085]

[0086] 5. Machine Learning Attack Recovery Model Parameter Configuration

[0087] The training environment configuration for BiLSTM-BiGRU, BiLSTM, and BP used in this invention is as follows: TensorFlow version 2.4.0, GPU: NVIDIA GeForce GTX 1060 6GB, CPU: Intel(R) Core(TM) i7-8700 CPU@3.20GHz (12 CPUs)~3.2GHz, and programming language: Python 3.7.

[0088] Among them, BP, BiLSTM, and BiLSTM-BiGRU, respectively, use the RMSprop optimizer during the recovery process from mild in-band interference attacks, strong in-band interference attacks, mild out-of-band interference attacks, and strong out-of-band interference attacks. MSE (Mean Squared Error) is used as the loss function, and MAE (Mean Absolute Error) is used as the evaluation function, as shown in equations (1-1) and (1-2), respectively. i Represents the true value, y i This represents the model's predicted value, i.e., the output value. During training, the batch_size is set to 128, the epochs are set to 100, and the output layer uses the sigmoid activation function, as shown in equation (1-3).

[0089]

[0090]

[0091]

[0092] Tables 6, 7, 8, and 9 present the network structures proposed in this invention for recovering from mild in-band interference attacks, strong in-band interference attacks, mild out-of-band interference attacks, and strong out-of-band interference attacks, respectively: BiLSTM-BiGRU-LIB (Light-In-Band), BiLSTM-BiGRU-SIB (Strong-In-Band), BiLSTM-BiGRU-LOOB (Light-Out-Of-Band), and BiLSTM-BiGRU-SOOB (Strong-Out-Of-Band). The BatchNormalization layer uses the default parameters of the corresponding neural network layer interface in the Keras module within TensorFlow.

[0093] Table 6

[0094]

[0095] Table 7

[0096]

[0097] Table 8

[0098]

[0099] Table 9

[0100]

[0101]

[0102] 6. Results Display

[0103] This invention evaluates the performance of BP, BiLSTM, and BiLSTM-BiGRU attack recovery models in recovering from mild in-band interference attacks, strong in-band interference attacks, mild out-of-band interference attacks, and strong out-of-band interference attacks from multiple dimensions, including attack recovery rate, attack recovery speed, and training time cost of the attack recovery model.

[0104] This invention uses the Jaccard similarity coefficient as an indicator to evaluate the attack recovery rate of the model on the test set. The Jaccard coefficient is shown in equation (1-4). It is calculated by comparing the bit sequence obtained after the attacked bit sequence on the test set is recovered by the model with the bit sequence before the attack. The larger the Jaccard similarity coefficient, the more similar the bit sequence obtained after the attacked bit sequence is to the bit sequence before the attack, and the better the attack recovery effect of the model. When the Jaccard similarity coefficient is greater than or equal to 0.99, it is considered that the model can completely eliminate the impact of the attack and can completely recover the attack. The Jaccard coefficient is defined as follows: given two sets P and Q, the Jaccard coefficient J(P,Q) is defined as the ratio of the size of the intersection of P and Q to the size of the size of the union of P and Q. The larger the Jaccard similarity coefficient, the more similar the two sets are, and the more identical the elements in the two sets are.

[0105]

[0106] A. Mild in-band interference attack recovery

[0107] First, 1010 labeled bit sequence samples collected under a light-in-band (LIB) interference attack were divided into a training set, a validation set, and a test set in a ratio of 3:1:1. After standardizing the divided dataset, the performance of BP-LIB, BiLSTM-LIB, and BiLSTM-BiGRU-LIB in recovering from a light-in-band interference attack was evaluated.

[0108] Figure 4 The graph shows the changes in the loss curves on the training set during the training of these three models. As can be seen from the graph, after approximately 100 training iterations, the loss curve on the training set gradually stabilizes and approaches convergence. Therefore, setting epochs to 100 can prevent underfitting and reduce training time.

[0109] Figure 5 The recovery results of the BiLSTM-BiGRU-LIB model for 202 attacked bit sequence samples on the test set are presented. Figure 5 As shown, Figure 5(a) represents the Jaccard similarity coefficient between 202 bit sequence samples (Feature) subjected to a mild in-band interference attack and 202 bit sequence samples (Label) collected at the receiving end before the attack, i.e. during normal transmission. Due to the influence of the mild in-band interference attack, the bit sequence carried by the signal will change, so the Jaccard similarity coefficient will be less than 1 and will decrease as the attack intensity increases. Figure 5 (b) represents the Jaccard similarity coefficient between the recovered 202 bit sequence samples after the BiLSTM-BiGRU-LIB attack recovery model and the bit sequence samples (Labels) obtained during normal transmission. Figure 5 As shown in (b), among the 202 test samples, the Jaccard similarity coefficient of 192 samples was restored to above 0.99, meaning that BiLSTM-BiGRU-LIB achieved a recovery rate of 95.05% for mild in-band interference attacks. Similarly, BiLSTM-LIB and BP-LIB restored the Jaccard similarity coefficients of 180 and 179 samples out of the 202 test samples to above 0.99, respectively, achieving recovery rates of 89.11% and 88.61% for mild in-band interference attacks. It is evident that BiLSTM-BiGRU-LIB has the highest recovery rate for mild in-band interference attacks.

[0110] Table 10 shows the time required for 100 iterations of training for BP-LIB, BiLSTM-LIB, and BiLSTM-BiGRU-LIB, as well as the attack recovery time for the model on 202 test samples. As can be seen from the table, BiLSTM-BiGRU-LIB can recover 202 × 8192 = 1,654,784 bits within 0.634 seconds, achieving an attack recovery rate of 2.61 Mbit / s. The model training time is 42.285 seconds, meaning training can be completed within one minute.

[0111] Table 10

[0112]

[0113] B. In-band interference attack recovery

[0114] The dataset, consisting of 1010 labeled bit sequence samples collected under a strong-in-band (SIB) jamming attack, was divided into a training set, a validation set, and a test set in a ratio of 3:1:1. After standardizing the divided dataset, the performance of BP-SIB, BiLSTM-SIB, and BiLSTM-BiGRU-SIB in recovering from strong-in-band jamming attacks was evaluated.

[0115] Figure 6 The graph shows the changes in the loss curves on the training set during the training process of these three models. As can be seen from the graph, after about 100 iterations of training, the loss curves on the training set gradually stabilize and approach convergence.

[0116] Figure 7 The recovery results of the BiLSTM-BiGRU-SIB model for 202 attacked bit sequence samples on the test set are presented. Figure 7 As shown, from Figure 7 As shown in (b), among the 202 test samples, the Jaccard similarity coefficient of 196 samples was recovered to above 0.99, meaning that the recovery rate of BiLSTM-BiGRU-SIB against in-band interference attacks reached 97.03%. Similarly, the recovery rates of BiLSTM-SIB and BP-SIB against in-band interference attacks reached 92.57% and 91.09%, respectively. It is evident that BiLSTM-BiGRU-SIB has the highest recovery rate against in-band interference attacks.

[0117] Table 11 shows the time required for 100 iterations of training for BP-SIB, BiLSTM-SIB, and BiLSTM-BiGRU-SIB, as well as the attack recovery time for the model on 202 test samples. As can be seen from the table, BiLSTM-BiGRU-SIB can recover 202 × 8192 = 1,654,784 bits within 0.792 seconds, achieving an attack recovery rate of 2.09 Mbit / s. The model training time is 47.981 seconds, meaning training can be completed within one minute.

[0118] Table 11

[0119]

[0120] C. Mild out-of-band interference attack recovery

[0121] A sample of 1010 labeled bit sequences collected under a light-out-of-band (LOOB) interference attack was divided into a training set, a validation set, and a test set in a 3:1:1 ratio. After standardizing the partitioned datasets, the performance of BP-LOOB, BiLSTM-LOOB, and BiLSTM-BiGRU-LOOB on light-out-of-band interference attack recovery was evaluated. Figure 8 As can be seen, after about 100 iterations of model training, the loss curve on the training set gradually stabilizes and approaches convergence.

[0122] Figure 9The recovery results of the BiLSTM-BiGRU-LOOB model for 202 attacked bit sequence samples on the test set are presented. From... Figure 9 As shown in (b), among the 202 test samples, 190 samples had Jaccard similarity coefficients recovered to above 0.99, meaning that BiLSTM-BiGRU-LOOB achieved a recovery rate of 94.06% for mild out-of-band interference attacks. Similarly, BiLSTM-LOOB and BP-LOOB achieved recovery rates of 91.58% and 91.09% respectively for mild out-of-band interference attacks. It is evident that BiLSTM-BiGRU-LOOB has the highest recovery rate for mild out-of-band interference attacks.

[0123] Table 12 shows the time required for 100 iterations of training for BP-LOOB, BiLSTM-LOOB, and BiLSTM-BiGRU-LOOB, as well as the attack recovery time for the model on 202 test samples. The table shows that BiLSTM-BiGRU-LOOB can recover 202 × 8192 = 1,654,784 bits within 0.648 seconds, achieving an attack recovery rate of 2.55 Mbit / s. The model training time is 46.643 seconds, meaning training can be completed within one minute.

[0124] Table 12

[0125]

[0126] D. Strength out-of-band interference attack recovery

[0127] A 1010-bit sequence sample with labels collected under a strong-out-of-band (SOOB) interference attack was divided into a training set, a validation set, and a test set in a ratio of 3:1:1. After standardizing the divided datasets, the performance of BP-SOOB, BiLSTM-SOOB, and BiLSTM-BiGRU-SOOB in recovering from strong-out-of-band interference attacks was evaluated. Figure 10 The graph shows the changes in the loss curves on the training set during the training process of these three models. As can be seen from the graph, after approximately 100 training iterations, the loss curves on the training set gradually stabilize and approach convergence.

[0128] Figure 11 The recovery results of the BiLSTM-BiGRU-SOOB model for 202 attacked bit sequence samples on the test set are presented. Figure 11As shown in (b), among the 202 test samples, 125 samples had Jaccard similarity coefficients recovered to above 0.99, meaning that BiLSTM-BiGRU-SOOB achieved a recovery rate of 61.88% against out-of-band interference attacks. Similarly, BiLSTM-SOOB and BP-SOOB achieved recovery rates of 52.48% and 49.01% respectively against out-of-band interference attacks. It is evident that BiLSTM-BiGRU-SOOB has the highest recovery rate against out-of-band interference attacks.

[0129] Table 13 shows the time required for 100 iterations of training for BP-SOOB, BiLSTM-SOOB, and BiLSTM-BiGRU-SOOB, as well as the attack recovery time for the model on 202 test samples. As can be seen from the table, BiLSTM-BiGRU-SOOB can recover 202 × 8192 = 1,654,784 bits within 0.65 seconds, achieving an attack recovery rate of 2.55 Mbit / s. The model training time is 42.219 seconds, meaning training can be completed within one minute.

[0130] Table 13

[0131]

[0132] In this system, the machine learning attack recovery model learns the correlation between the normal transmission of legitimate signals and the signal bit sequences obtained after demodulation at the receiving end after interference attacks. This allows the model to neutralize or mitigate the attack source, achieving a high recovery rate in attack recovery without consuming additional optical path resources or interrupting the real-time communication of users. BiGRU is a homologous variant of BiLSTM, and its algorithm implementation complexity is lower than that of BiLSTM. Therefore, this invention proposes a BiLSTM-BiGRU attack recovery model that can prevent the gradient vanishing problem during long-term training and has low algorithm complexity. Furthermore, the performance of four attack recovery models based on BiLSTM-BiGRU in recovering in-band and out-of-band interference attacks of different intensities was evaluated. Numerical simulation results show that BiLSTM-BiGRU-LIB, BiLSTM-BiGRU-SIB, BiLSTM-BiGRU-LOOB, and BiLSTM-BiGRU-SOOB achieve recovery rates of 95.05%, 97.03%, 94.06%, and 61.88% for mild in-band interference attacks, strong in-band interference attacks, mild out-of-band interference attacks, and strong out-of-band interference attacks, respectively, achieving high recovery rates without consuming additional optical path resources.

[0133] Specifically, Figure 12 Network architecture diagram of BiLSTM-BiGRU. (See diagram below.) Figure 12 As shown, the BiLSTM-BiGRU proposed in this invention consists of an input layer, an LSTM layer, a GRU layer, and an output layer. The LSTM layer is composed of forward LSTM blocks and backward LSTM blocks, while the GRU layer is composed of forward GRU blocks and backward GRU blocks. GRU is a homologous variant of LSTM, and its algorithm implementation complexity is lower than that of LSTM. Therefore, the BiLSTM-BiGRU attack recovery model proposed in this invention can prevent the gradient vanishing problem during long-term training and has low algorithm complexity. When the input X represents the bit sequence of the signal after being attacked, X enters the input layer and then enters the LSTM layer. At this time, the forward and backward LSTM blocks of the LSTM layer first perform feature mining on X and perform calculations before sending it to the GRU layer. Similarly, the forward and backward GRU blocks of the GRU layer also extract features from the output of the LSTM layer and perform calculations. Finally, the calculation results are output to the output layer, and the recovered signal bit sequence Y is obtained.

[0134] Furthermore, the model training process uses the RMSprop optimizer, employing the mean squared error (MSE) function as the loss function.

[0135]

[0136] Among them, y i Represents the true value, y i This represents the model's predicted value, or output value.

[0137] The Mean Absolute Error (MAE) function is used as the evaluation function.

[0138]

[0139] The output layer uses the sigmoid activation function:

[0140]

[0141] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for recovering from physical layer interference attacks in software-defined optical networks, characterized in that: Includes the following steps: S1: Defines a macroscopic framework for recovering from signal interference attacks at the physical layer of optical networks; S2: Construct a 16QAM dual-polarization wavelength division multiplexing coherent communication system that achieves in-band and out-of-band interference attacks; S3: Build and train an end-to-end attack recovery model based on machine learning; S4: Under the condition of no injected interference signal, the signal transmission in the coherent communication system is marked as normal signal transmission. The 16QAM signal transmission power is kept constant. The power of the injected interference signal is changed. While keeping the power constant, the transmission frequency of the interference signal is changed. The range of the transmission frequency change is within the transmission window of the 16QAM signal. After N attacks, the distribution of BER at the receiver is statistically analyzed. Based on the BER distribution, the interference attack at this power is defined as a mild in-band interference attack or a strong in-band interference attack. The signal bit sequence of the 16QAM signal obtained at the receiver under mild, strong in-band interference attacks and normal transmission conditions is collected. S5: Define mild and strong out-of-band interference attacks. With the 16QAM signal transmission power unchanged, change the transmission frequency of the interference signal under different injected interference signal powers. The frequency range is outside the transmission window of the legitimate signal. After N attacks under a specific power interference signal attack, statistically analyze the distribution of BER at the receiver. Based on the BER distribution, define whether the interference attack under this power is a mild out-of-band interference attack or a strong out-of-band interference attack. Collect the signal bit sequence of the 16QAM signal at the receiver under mild, strong out-of-band interference attacks and normal transmission conditions. S6: Achieve recovery from interference attacks of different intensities and types by using a trained end-to-end attack recovery model based on machine learning.

2. The method for recovering from physical layer interference attacks in software-defined optical networks according to claim 1, characterized in that: The workflow of the macroscopic optical network physical layer signal interference attack recovery framework defined in step S1 is as follows: After the wavelength division multiplexed optical signal at the transmitting end enters the optical network through the coupling device OXC, it is then demultiplexed through the OXC and reaches the receiving end for demultiplexing. Finally, each optical signal is coherently demodulated and processed by digital signal processing (DSP). The attack model in the framework considers that an attacker injects interference signals into network nodes through some coupling devices OXC, and the interference signals are transmitted through the optical network together with the normal signals; The attack detection, identification, and recovery process is as follows: First, the optical network controller periodically retrieves, stores, and preprocesses the spectral data collected by the receiver after dimensionality reduction by principal component analysis (PCA). Then, it uses an offline-trained attack detection model to detect and identify attacks, determining whether the optical signal has been attacked. If it has not been attacked, it performs normal demodulation and DSP processing. If attacked, the attack strength and type information are sent to the DSP controller at the receiving end. Then, the DSP can activate the corresponding attack recovery module based on the attack information provided by the DSP controller.

3. The method for recovering from physical layer interference attacks in software-defined optical networks according to claim 1, characterized in that: Step S2, which describes the construction of a 16QAM dual-polarization wavelength division multiplexing coherent communication system implemented through in-band and out-of-band interference attacks, specifically includes: The transmitter generates eight sub-channel wavelength division multiplexed signals with a bandwidth of 50 GHz, including one channel with a frequency of... The dual-polarized 16QAM coherent optical signal and frequency are 7 empty carriers, frequency is The interference signal is split by a ratio of A 50:50 coupler and wavelength division multiplexed signal are injected together into a circuit with... N Transmitted in optical fibers in loops, each loop consisting of standard single-mode fiber SSMF and EDFA; At the receiving end, through a center frequency of An OBPF with a bandwidth of 50 GHz is used to obtain a 16QAM optical signal affected by interference attack signals. This signal is then received by a coherent receiver and processed by a DSP. The bit sequence carried by the signal is then collected for training an end-to-end attack recovery model based on machine learning.

4. The method for recovering from physical layer interference attacks in software-defined optical networks according to claim 1, characterized in that: The training process of the machine learning-based attack recovery model is viewed as a machine learning-based multi-output regression problem. When not under attack, the signal sent by the transmitter is transmitted normally, and after demodulation and digital signal processing at the receiver, the bit sequence of the signal is obtained as the label of the collected dataset and used as feedback for the machine learning-based attack recovery model. After the transmitter sends the same signal and it is attacked by interference during transmission, the receiver demodulates and processes the signal digitally to obtain the bit sequence of the signal. This bit sequence is used as the feature of the collected dataset and as the input of the machine learning-based attack recovery model. Data is collected under different in-band and out-of-band interference attacks of different intensities to train the in-band and out-of-band interference attack recovery models of different intensities. Finally, after detecting the type and intensity of the attack on the system, the attacked signal bit sequence is directly used as the input to the corresponding trained machine learning-based attack recovery model, and the model output is the recovered signal bit sequence.

5. The method for recovering from physical layer interference attacks in software-defined optical networks according to claim 1, characterized in that: The distribution of BER at the statistical receiver is used to define whether an interference attack at this power level is a mild in-band interference attack or a strong in-band interference attack, specifically including: If the number of samples with BER < 0.02 accounts for 50% or more of the total number of samples, it is considered that there is a 50% or more probability of strong error correction or bit error correction under the power of the in-band interference attack, so as to eliminate the impact of the attack. This type of attack is called mild in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected. If the number of samples with BER < 0.02 accounts for 5% or less of the total number of samples, it is considered that the probability of eliminating the impact of the attack and achieving normal transmission under this attack is less than or equal to 5%. This type of attack is defined as an in-band interference attack, and the signal bit sequence under the corresponding attack conditions is collected.

6. The method for recovering from physical layer interference attacks in software-defined optical networks according to claim 1, characterized in that: The machine learning-based attack recovery model is a model based on Bidirectional Long Short-Term Memory-Bidirectional Gated Recurrent Unit (BiLSTM-BiGRU), consisting of an input layer, an LSTM layer, a GRU layer, and an output layer. The LSTM layer comprises forward LSTM blocks and backward LSTM blocks, and the GRU layer comprises forward GRU blocks and backward GRU blocks. GRU is a homologous variant of LSTM. When representing the bit sequence after a signal has been attacked, After entering the input layer, it then enters the LSTM layer. At this point, the forward and backward LSTM blocks of the LSTM layer first... After feature mining and computation, the data is passed to the GRU layer. The forward and backward GRU blocks in the GRU layer extract and compute features from the output of the LSTM layer, and finally output the results to the output layer to obtain the recovered signal bit sequence. ; The training process of the BiLSTM-BiGRU model uses the RMSprop optimizer and the mean squared error function (MSE) as the loss function. in, Represents the actual value. This represents the model's predicted value, or output value. Use the mean absolute error (MAE) function as the evaluation function: The output layer uses sigmoid Activation function: 。