An event-triggered data privacy protection method
By adopting event-triggered data privacy protection methods in the information physics system, trigger threshold conditions are derived, and combined with distributed matrix weighted fusion filters, the data privacy leakage problem caused by eavesdropping attacks under limited sensor energy is solved, and energy-saving and effective data privacy protection is achieved.
Patent Information
- Application Number
- CN202410083710.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2044-01-19
AI Technical Summary
In information physics systems (CPSs), data privacy leakage caused by eavesdropping attacks is difficult to effectively solve, especially when sensor energy is limited, existing encryption algorithms consume too much energy and are difficult to implement.
The data privacy protection method based on event triggering is adopted, and the trigger threshold conditions are derived by designing event triggered data scheduling strategies on the sensor, so that the eavesdropper estimation error is unbounded, while the error covariance of legitimate users remains bounded, and state fusion estimation is achieved using a distributed matrix weighted fusion filter.
While saving sensor energy, it achieves perfect data privacy protection. The error covariance of legitimate users is bounded and the error error of eavesdroppers is unbounded, ensuring that the system status privacy is not leaked.
Smart Images

Figure CN118233140B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data privacy protection, and particularly relates to a data privacy protection method based on event triggering. Background Art
[0002] Cyber-physical systems (CPSs) have been widely integrated in many application fields, such as intelligent transportation, power systems, and medical device systems. Multi-sensor fusion estimation is an information processing process that uses the observations of multiple sensors to complete system state estimation under certain conditions. Due to its high reliability and strong robustness, it is widely used in CPSs. However, due to the openness of the network, CPSs have become targets for malicious attackers. Among them, eavesdropping attacks are one of the typical network attacks. Therefore, the security of CPSs has received extensive attention, and confidentiality is a basic security issue. The data transmitted in the channel can easily be intercepted by eavesdroppers through another channel. After analyzing a large amount of intercepted data, they can launch complex attacks, such as false data injection attacks. Therefore, it is of great theoretical and practical significance to study secure fusion estimation in the presence of eavesdroppers.
[0003] Encrypting messages to prevent privacy leakage has been studied from the perspective of information theory. The energy of sensors usually comes from batteries, and their energy is often limited. Therefore, due to the large energy requirements of strong encryption algorithms, it is difficult to apply and implement them in CPSs. In recent years, the use of physical layer information and artificial noise to study security communication problems has been carried out. From the perspective of control theory, the concept of perfect encryption has been proposed. Some scholars have given the definition of perfect encryption, requiring that the state estimation error of users is bounded, while the estimation error of eavesdroppers is unbounded over time. Furthermore, an optimal data privacy protection strategy for non-feedback eavesdroppers has been given to obtain perfect confidentiality. At the same time, similar results have been obtained through feedback. Subsequent researchers have designed an event-triggered sensor data scheduling strategy to prevent eavesdropping on recursive Markov chains. In addition, considering the dynamic characteristics and physical layer information of CPSs, state-preserving ciphers have been introduced to achieve the goal of perfect encryption for stable, unstable, and arbitrary systems. Considering the encryption cost, some scholars have proposed an optimized encryption schedule to improve the confidentiality of system states. In a distributed framework, for secure fusion estimation with state privacy protection, complete confidentiality is achieved by injecting artificial noise. In the framework of state component transmission, researchers have developed an artificial noise design strategy based on system parameters, which makes the fusion error covariance of eavesdroppers worse. Some scholars have proposed a strategy of actively contaminating local estimation components to improve the privacy protection level of local estimation. Recently, under the constraint of sensor energy, artificial noise based on the channel gain matrix has been injected into the transmitted signal to maintain confidentiality. However, the injected artificial noise consumes more sensor energy, which increases the challenges in the design of privacy protection strategies. Summary of the Invention
[0004] To avoid the deficiencies in the background art, a data privacy protection method based on event triggering is designed, including the following steps:
[0005] Step 1, input parameters: P δ , σ , system initial parameters A, C i ,Q, R i ,P i (0), P ij (0), λ i ,ρ i (i = 1, 2,..., L);
[0006] Step 2, calculate the steady-state error covariance of each local estimation system
[0007]
[0008] Step 4, select the event-triggering threshold according to conditions (14)-(15) and feedback it to each local sensor;
[0009] Step 5, the user's FC processes the received signal according to (4) and performs state fusion estimation according to formulas (5)-(9);
[0010] Step 6, go to Step 5 and continue to calculate the fusion estimation value next time.
[0011] Preferably, according to the standard Kalman filter, and P i (t) can be obtained from the local estimator (LE) of the i-th sensor:
[0012]
[0013] P i (t) can exponentially converge to the steady-state value through several iterations, and this steady-state value is the steady-state error covariance in Step 2
[0014] Preferably, in the usage scenario, all sensors are intelligent sensors with computing capabilities. At time t, the i-th sensor observes the physical process to obtain the observation result y i (t). After collecting the observations up to time t, the information set of the i-th local estimator is given as Y i (t) = {y i (1),..., y i (t)}, and it is defined as:
[0015]
[0016] where and are the a priori and a posteriori MMSE estimates, and P i - (t) and P i (t) are the estimation error covariance.
[0017] Preferably, the event-triggering threshold is selected according to conditions (14)-(15) in step 4, specifically as follows. For the unstable system (1) with the channel model (11), under the encryption mechanism (10), if the triggering thresholds of all sensors satisfy:
[0018] (i) There exists a positive integer i such that
[0019]
[0020] (ii) For any positive integer i, the following inequality holds
[0021]
[0022] then perfect expected confidentiality can be obtained.
[0023] Preferably, the encryption mechanism is such that the processor of the i-th sensor can generate a random variable ζ at each time instant t i , specifically as follows,
[0024]
[0025] Preferably, the channel model is given as follows:
[0026]
[0027] where ρ i represents the probability that the i-th local estimate is intercepted by the eavesdropper, and λ i represents the probability that the user receives the i-th local estimate.
[0028] Preferably, the definition of perfect expected confidentiality is as follows. For any initial condition P(0), the secrecy mechanism can achieve perfect expected confidentiality if and only if the following two conditions are both satisfied:
[0029]
[0030] where the covariance of the state estimation error of the eavesdropper is represented by P e (t), Sup represents the upper bound, and Tr represents the trace operator.
[0031] Preferably, the system is described by the following physical model:
[0032]
[0033] where x(t) ∈ R n is the state vector with dimension n, is the sensor observation value of the i-th sensor with dimension q i and w(t) and v i (t) are Gaussian white noises with zero mean and variances Q and R respectively i , L represents that there are L sensors to observe the system state. Additionally, the matrix pair (C i , A) is detectable and (A, Q 1 / 2 ) is controllable.
[0034] Preferably, the FC of the user in step five processes the received signal according to (4), where (4) is calculated by and covariance as:
[0035]
[0036] Preferably, the state fusion estimation is performed according to formulas (5)-(9) as follows. The distributed matrix weighted fusion filter is obtained by the following method:
[0037]
[0038] where
[0039]
[0040] Then, define where is the cross-covariance matrix between any two LEs and is calculated by the following formula:
[0041]
[0042] It can exponentially converge to the steady-state value through several iterations;
[0043] Under the linear minimum variance criterion, the optimal values of W1(t), W2(t), …, W L (t) in formula (6) are:
[0044] [W1(t),...,W L (t)] = ((Υ s ) T Ξ -1 (t)Υ s) -1 (Υ s ) T Ξ -1 (t) (8)
[0045] where Υ s =[I n ,I n ,...,I n T , in addition, the fusion error covariance can be calculated by the following formula as:
[0046] P u (t)=((Υ s ) T Ξ -1 (t)Υ s ) -1 (9).
[0047] The present invention has the following advantages compared with the background art:
[0048] First, in the present invention, each local sensor sends local state data to the remote fusion center through the network. In order to protect the privacy of the system state data, an event-triggered data scheduling strategy is adopted on each sensor, and some sufficient conditions on the trigger threshold are derived, so that the estimation error covariance of the eavesdropper to the state is unbounded, while the error covariance of the legitimate user remains bounded, so as to achieve perfect data privacy protection;
[0049] Second, the present invention utilizes the problem of event-based confidentiality fusion estimation of CPSs under the condition of limited sensor energy. For this reason, the present invention does not encrypt the data, but arranges the transmission of data according to the event trigger, which greatly saves the power consumption of the sensor. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 is a system model block diagram in an event-triggered data privacy protection method.
[0051] Figure 2 is the final LE error covariance curve of the eavesdropper.
[0052] Figure 3 is the final LE error covariance curve of the user FC.
[0053] Figure 4 is the tracking curve of the fusion estimation error covariance of the eavesdropper and the user.
[0054] Figure 5 is the final local estimation curve of sensor 1 Figure 1 .
[0055] Figure 6 Is the final local estimation curve of sensor 2 Figure 2 .
[0056] Figure 7 Is the fusion estimation performance (eavesdropper) graph of two sensors under different event trigger threshold combinations.
[0057] Figure 8 Is the fusion estimation performance (user) graph of two sensors under different event trigger threshold combinations. Detailed implementation method
[0058] Example 1: Refer to the appendix Figures 1 - 8 . A data privacy protection method based on event triggering includes the following steps:
[0059] Step 1, input parameters: P δ , σ , System initial parameters A, C i , Q, R i , P i (0), P ij (0), λ i , ρ i (i = 1, 2,..., L);
[0060] Step 2, calculate the steady-state error covariance of each local estimation system
[0061] Step 3, calculate
[0062] Step 4, select the event trigger threshold according to conditions (14)-(15) and feedback it to each local sensor;
[0063] Step 5, the FC of the user processes the received signal according to (4) and performs state fusion estimation according to formulas (5)-(9);
[0064] Step 6, go to Step 5 and continue to calculate the fusion estimation value next time.
[0065] Preferably, according to the standard Kalman filter, and P i (t) can be obtained from the local estimator (LE) of the i-th sensor:
[0066]
[0067] P i (t) can exponentially converge to the steady-state value through several iterations, and this steady-state value is the steady-state error covariance in Step 2
[0068] Preferably, in the usage scenario, all sensors are intelligent sensors with computing capabilities. At time t, the i-th sensor observes the physical process to obtain the observation result y i (t). After collecting the observations up to time t, the information set of the i-th local estimator is given as Y i (t) = {y i (1),..., y i (t)}, and it is defined that:
[0069]
[0070] where and are the prior and posterior MMSE estimates, and P i - (t) and P i (t) are the estimation error covariances.
[0071] Preferably, for selecting the event trigger threshold according to conditions (14)-(15) in step four, specifically as follows, for the unstable system (1) with the channel model (11), under the encryption mechanism (10), if the trigger thresholds of all sensors satisfy:
[0072] (iii) There exists a positive integer i such that
[0073]
[0074] (iv) For any positive integer i, the following inequality holds
[0075]
[0076] Then perfect expected confidentiality can be obtained.
[0077] Preferably, the encryption mechanism is that the processor of the i-th sensor can generate a random variable ζ i at each moment t, specifically as follows,
[0078]
[0079] Preferably, the channel model is given as follows:
[0080]
[0081] where ρ i represents the probability that the i-th local estimate is intercepted by the eavesdropper, and λ i represents the probability that the user receives the i-th local estimate.
[0082] Preferably, the definition of perfect expected confidentiality is as follows. For any initial condition P(0), a confidentiality mechanism achieves perfect expected confidentiality if and only if the following two conditions are both satisfied:
[0083]
[0084] where the covariance of the state estimation error of the eavesdropper is represented by P e (t), Sup represents the upper bound, and Tr represents the trace operator.
[0085] Preferably, the system is described by the following physical model:
[0086]
[0087] where x(t) ∈ R n is the state vector with dimension n, y i (t) ∈ R qi is the sensor observation of the i-th sensor with dimension q i , w(t) and v i (t) are Gaussian white noises with zero mean and variances Q and R i respectively, L represents that there are L sensors to observe the system state. Additionally, the matrix pair (C i , A) is detectable and (A, Q 1 / 2 ) is controllable.
[0088] Preferably, the FC of the user in step five processes the received signal according to (4), where (4) is calculated from and covariance as:
[0089]
[0090] Preferably, the state fusion estimation is performed according to formulas (5)-(9) in step five. Specifically, the distributed matrix weighted fusion filter is obtained as follows:
[0091]
[0092] where
[0093]
[0094] Then, define where is the cross-covariance matrix between any two LEs and is calculated by the following formula:
[0095]
[0096] It can exponentially converge to the steady-state value through several iterations;
[0097] Under the linear minimum variance criterion, according to W1(t), W2(t), …, W L (t) in formula (6), the optimal values are:
[0098] [W1(t),...,W L (t)] = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (Υ s ) T Ξ -1 (t) (8)
[0099] where Υ s = [I n ,I n ,...,I n ) T , in addition, the fusion error covariance can be calculated by the following formula as:
[0100] P u (t) = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (9).
[0101] The following is a further description of an event-triggered data privacy protection method:
[0102] The system model structure is as Figure 1 shown and is described by the following physical model:
[0103]
[0104] where, x(t) ∈ R n is the state vector with dimension n, and is the sensor observation value of the i-th sensor with dimension q i . w(t) and v i (t) are Gaussian white noises with zero mean and variances Q and R i respectively. L represents that there are L sensors to observe the system state. It is assumed that the matrix pair (C i , A) is detectable and (A, Q 1 / 2 ) is controllable.
[0105] In our system scenario, all sensors are intelligent sensors with computing capabilities. At time t, the i-th sensor observes the physical process to obtain the observation result y i (t). After collecting the observations up to time t, the information set of the i-th local estimator is given as
[0106] Y i (t) = {y i (1),..., y i (t)}. Additionally, define:
[0107]
[0108] where and are the prior and posterior MMSE estimates, and P i - (t) and P i (t) are the estimation error covariances. Recall the standard Kalman filter, and P i (t) can be obtained according to the local estimator (LE) of the i-th sensor:
[0109]
[0110] Typically, P i (t) can exponentially converge to the steady-state value with only a few iterations. For simplicity, let P i (0) be the initial error covariance of the i-th sensor, which is equal to Additionally, we know that for all times t.
[0111] After obtaining , the i-th sensor decides whether to send it to the fusion center (FC). We introduce the binary variable α i (t) to model the decision-making process. α i (t) = 1 indicates that is sent by the i-th sensor; otherwise, it is not sent (to avoid packet loss due to unreliable channels between the sensor and the FC). Additionally, the data packet transmitted on this channel can be intercepted by an eavesdropper on another channel. Thus, let the binary variable β i (t) = 1 and 0 indicate whether the i-th LE is intercepted by the eavesdropper, and let the binary variable γ i (t) = 1 and 0 indicate whether the user successfully receives the i-th LE.
[0112] In the FC, to obtain an accurate state estimate, the user and the eavesdropper use the weighted matrix fusion method to obtain the final state estimate based on the received LEs. To avoid symbol misuse, the fusion estimate of the user's FC is taken as an example to illustrate how to implement the weighted matrix fusion algorithm. Let h and h k be functions. Specifically, h(X) = AXA T +Q and If, k1 ≤ k2, k1,k2 ∈ Z + Then in the user's FC, the LE of the i-th sensor cannot be successfully received in both cases.
[0113] The first case is that the i-th sensor does not send the LE to the FC. In this case, α i (t) = 0;
[0114] The second case is that the i-th LE is sent, but packet loss occurs in the channel. In this case, γ i (t) = 0, and it needs to perform a one-step prediction compensation on the local estimate;
[0115] Therefore, the final and covariance are calculated as
[0116]
[0117] Furthermore, the distributed matrix weighted fusion filter can be obtained in the following way:
[0118]
[0119] where
[0120]
[0121] Then, define where is the cross-covariance matrix between any two LEs and is calculated by the following formula:
[0122]
[0123] Generally it only takes a few iterations to converge exponentially to the steady-state value. For simplicity, we denote the initial error cross-covariance matrix of the i-th sensor, which is equal to P ij (0). Then, it can be concluded that For all times t, the initial Ξ(0) is
[0124] Under the linear minimum variance criterion, W1(t), W2(t), …, W in formula (6)L The optimal value of (t) is:
[0125] [W1(t),...,W L (t)] = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (Υ s ) T Ξ -1 (t) (8)
[0126] where Υ s = [I n ,I n ,…,I n T , in addition, the fusion error covariance can be calculated by the following formula as:
[0127] P u (t) = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (9)
[0128] For an eavesdropper, if he is powerful enough to eavesdrop on the transmission data of multiple sensors simultaneously, he can use the intercepted LEs to obtain a more accurate state estimate through a fusion estimation method, which poses a challenge to distributed secure fusion estimation. To solve this problem:
[0129] First, we use p i to represent the probability that the i-th sensor decides to send the LE to the FC; to prevent the leakage of state privacy, all sensors adopt a random event-triggering strategy; specifically, the processor of the i-th sensor can generate a random variable ζ i at each time t; these variables follow a uniform distribution on (0, 1), that is, ζ i ~U(0,1). The random event trigger is composed of
[0130]
[0131] In addition, assume that each sensor always decides to send the LE to the FC, that is, at all times t; we model packet dropping and packet interception as independent and identically distributed over time; we let ρ i represent the probability that the i-th local estimate is intercepted by the eavesdropper, and λ i represent the probability that the user receives the i-th local estimate; therefore, the channel model can be given as follows:
[0132]
[0133] When describing physical layer security issues, it is a common assumption to accurately understand the channel model of the eavesdropper with respect to the user; the channel gain can be obtained by using blind estimation, pilot-based estimation, etc.; in this case, knowing the probability is less restrictive than knowing the exact channel model of the eavesdropper. In fact, it can be considered as the confidence level of the system designer in the ability of the eavesdropper to successfully eavesdrop on data packets.
[0134] Next, define perfect expected secrecy: For any initial condition P(0), the secrecy mechanism can achieve perfect expected secrecy if and only if the following two conditions are both satisfied:
[0135]
[0136] where the covariance of the state estimation error of the eavesdropper is denoted by P e (t), Sup represents the upper bound, and Tr represents the trace operator.
[0137] For any initial system estimation error covariance, when the transmitted data is encrypted according to the privacy data encryption mechanism, over time, the trace of the legitimate user's covariance tends to be bounded in the expected sense, while the trace of the estimation error covariance of the eavesdropper's state privacy tends to be unbounded. In this case, the state estimation error of the eavesdropper is infinite, and accurate information about the system state privacy cannot be obtained. Therefore, perfect expected encryption is achieved under this encryption mechanism.
[0138] Furthermore, we need to further describe the problem to be solved as follows:
[0139] (1) For distributed fusion estimation, the first goal is to solve "how to design an event-triggered data scheduler for sensors such that the estimation error of the legitimate user is convergent, but the estimation error of the eavesdropper will be infinite".
[0140] (2) From the perspective of the defender, another goal is to design an event-triggered confidentiality fusion estimation algorithm to ensure the effectiveness of our data privacy protection method.
[0141] For a stable system, as long as the eavesdropper has the system model parameters, it can predict the system state data in real time without eavesdropping, and the prediction error is always bounded. Therefore, what we need to study is the confidentiality fusion estimation problem of unstable systems.
[0142] For an unstable system, we assume that the spectral radius of A in the unstable system (1) satisfies some sufficient conditions. Under these conditions, we can obtain a distributed secure fusion estimation algorithm to protect the state data privacy, as follows:
[0143] Theorem 1: For the unstable system (1) with the channel model (11), under the encryption mechanism (10), if the triggering thresholds of all sensors satisfy:
[0144] (v) There exists a positive integer i such that
[0145]
[0146] (vi) For any positive integer i, the following inequality holds
[0147]
[0148] Then perfect expected confidentiality can be obtained.
[0149] Next is the proof process, which is as follows:
[0150] Proof: According to the definition of perfect expected confidentiality, we need to prove that equations (12) and (13) hold simultaneously under conditions (14) and (15); we first prove that the complete expected confidentiality condition (12) is satisfied under condition (14); assume that the event triggering threshold η of the s0 - th sensor i satisfies Then we have
[0151]
[0152] In this case, the probability that the FC of the legitimate user can successfully receive the LE of the s0 - th sensor always satisfies Then, the state - estimation error covariance of the s0 - th sensor is bounded, that is where the i - th block position is the identity matrix I n . 0 represents the zero matrix of dimension n. Furthermore, we have
[0153]
[0154] This means that as long as the LE error covariance of one sensor is bounded, the state error covariance obtained by the FC after fusing all local estimates must be bounded; thus, condition (12) is satisfied.
[0155] Furthermore, we prove that under condition (15), the complete expected confidentiality condition (13) holds; let Ω be the event that when the LE is sent, the event triggers of all sensors are not triggered and all LEs are not successfully intercepted; Ω ⊥ represents its complementarity; in addition, we consider the probability of the event Ω over a finite time N and obtain:
[0156]
[0157] Among them,
[0158] Taking the trace P e (N) of the terminal estimation error covariance, we can obtain:
[0159]
[0160] Then, there is a positive integer i that makes the following equation hold:
[0161]
[0162] In addition, according to condition (15), we can obtain Combining (21), the following inequality can be obtained:
[0163]
[0164] Therefore, it can be concluded that when N reaches infinity, Tr{E{P e (N)}} → ∞, that is
[0165] The above proof process shows that as long as the event trigger threshold of one sensor is greater than it can ensure that the user's fusion estimation error is bounded; on this basis, if the event trigger thresholds of all sensors are controlled to meet condition (15), the state estimation error of the eavesdropper will tend to be unlimited; from the user's perspective, in order to protect the privacy of the state data from being leaked, when condition (14) is satisfied, the event trigger threshold should be reduced as much as possible; in this case, the probability that the eavesdropper successfully intercepts each local estimate is very small, which makes the fusion estimation performance worse; in addition, the larger the number L of sensors, the more local estimates the eavesdropper may intercept; the user needs to reduce the event trigger threshold to a greater extent to ensure confidentiality. In the special case of a single sensor with only L = 1, the result will degenerate to
[0166] The following is a scenario where two sensors observe a dynamic system; the model parameters are as follows:
[0167]
[0168] Through multiple iterations, the steady-state covariance matrix can be obtained:
[0169]
[0170] Assume that the probabilities of successful data reception between the user's FC and two local sensors are 0.7 and 0.9 respectively; both channels are eavesdropped, and the data interception probabilities are both 0.4; we can calculate the values of 0.5080 and 0.3951 respectively, and both of these values are 0.4932; all results are from 1000 Monte Carlo simulations; to better explain the simulation results, we define the following abbreviations: Tracking Error Covariance (TEC) and Tracking Fusion Error Covariance (TFEC).
[0171] The event-triggering thresholds of two local sensors; the specific simulation results are as Figures 2 - 4 shown.
[0172] where Figure 2 shows the final LE error covariance curve of the eavesdropper, Figure 3 shows the final LE error covariance curve of the user's FC, Figure 4 shows the tracking curve of their fusion estimation error covariance. It can be seen from the simulation result graph that the final LE error of the eavesdropper is much larger than that of the user, because the successful reception rate of the user's FC is higher than that of the eavesdropper. However, it should be noted that both the eavesdropper and the user can obtain much smaller estimation errors than the final local estimation through the fusion estimation method; therefore, the fusion estimation can greatly reduce the state estimation error of the user, but at the same time it may also lead to more state privacy leakage.
[0173] Design random event triggers for two local sensors according to (10); let the combination of triggering thresholds of two local sensors be (0.4, 0.4), (0.45, 0.9), (0.9, 0.9). The specific simulation results are as Figures 5 - 8 shown.
[0174] where Figure 5 shows the final local estimation curve of the eavesdropper's FC Figure 1 , Figure 6 shows the final local estimation curve of the eavesdropper's FC Figure 2 , Figure 7 reflects the fusion estimation performance (eavesdropper) of two sensors under different combinations of event-triggering thresholds, Figure 8 reflects the fusion estimation performance (user) of two sensors under different combinations of event-triggering thresholds. It can be seen from Figure 4 that when the communication rate between the sensor and the FC is low, the TEC of the eavesdropper will grow infinitely. It can be seen from Figure 7It can be seen that when the triggering threshold is selected as (0.4, 0.4), the estimation performance of the eavesdropper is poor, and its TFEC grows infinitely over time; this is because the sufficiency condition (15) is satisfied under this communication rate combination, making it impossible for the eavesdropper to obtain the true state information. At the same time, in this case, the user's TFEC is bounded, because the user's FC has a high success rate of receiving data from local sensors, which makes the sufficiency condition (14) satisfied. For other combinations, conditions (14) and (15) are not satisfied simultaneously. The eavesdropper can always obtain a bounded estimation error, which makes the event trigger ineffective. Therefore, in order to prevent the leakage of national privacy, the user must design a smaller triggering threshold to meet the sufficiency condition of Theorem 1.
[0175] This application researches and develops the state privacy protection problem of CPSs distributed fusion estimation; the goal is to make the TFEC matrix of the eavesdropper become unbounded over time while the expected error covariance of the user remains bounded, adopts a random event-triggering strategy to maintain confidentiality, establishes the relationship between the event-triggering threshold and the estimation performance in the FC; derives some sufficient conditions for the triggering threshold to ensure complete expected confidentiality; finally, verifies the effectiveness of the method through simulation examples.
[0176] It should be understood that although the above embodiments have made a relatively detailed written description of the design concept of the present invention, these written descriptions are only simple written descriptions of the design concept of the present invention, rather than limitations on the design concept of the present invention. Any combination, addition, or modification that does not exceed the design concept of the present invention falls within the protection scope of the present invention.
Claims
1. An event-triggered data privacy protection method, applied to Cyber-Physical Systems (CPSs), Its features include the following steps: Step 1, input parameters: P δ , σ , system initial parameters A, C i ,Q, R i ,P i (0), P ij (0), λ i ,ρ i (i = 1, 2,..., L); Q, R i are the variances of the Gaussian white noises w(t) and v i (t) with zero means respectively, and P i (0) is the initial error covariance of the i-th sensor, and P ij (0) represents the initial error cross-covariance matrix of the i-th sensor, and λ i represents the probability that the user receives the i-th local estimate, and ρ i (i = 1, 2,..., L) represents the probability that the i-th local estimate is intercepted by the eavesdropper, and L represents L sensors; Step 2, calculate the stable error covariance of each local estimation system Step 3, calculate Step 4: Select the event trigger threshold according to conditions (14)-(15) and feedback it to each local sensor; The selection of the event trigger threshold according to conditions (14)-(15) in Step 4 is as follows. For an unstable system with a channel model, under the encryption mechanism, if the trigger thresholds of all sensors satisfy: (i) There exists a positive integer i such that η i represents the event trigger threshold of the i-th sensor; (ii) For any positive integer i, the following inequality holds Then perfect expected confidentiality can be obtained; The unstable system is described by the following physical model: where \(x(t)\in\mathbb{R}\) n is the state vector of dimension \(n\), is the sensor observation of the \(i\)-th sensor of dimension \(q\) i , and the matrix pair \((C i , A)\) is detectable and \((A, Q 1 / 2 )\) is controllable; Step 5: The user's fusion center FC processes the received signal according to formula (4) and performs state fusion estimation according to formulas (5)-(9); In step 5, the user's fusion center FC processes the received signal according to formula (4), where formula (4) is calculated by the local estimator and covariance as follows: denotes the posterior MMSE estimate, α i (t) denotes a binary variable, γ i (t) is a binary variable, γ i (t) = 1 indicates that the user successfully receives the i-th LE, γ i (t) = 0 indicates that the user does not successfully receive the i-th LE; The state fusion estimation in step five is performed according to formulas (5)-(9), specifically as follows, the distributed matrix weighted fusion filter is obtained by the following method: Among which W i (t) represents the weighted weight of the distributed matrix; Then, define where is the cross-covariance matrix between any two LEs, calculated by the following formula: It can converge exponentially to the steady-state value through several iterations; Under the linear minimum variance criterion, according to the optimal values of W1(t), W2(t), …, W L (t) in formula (6) are as follows: [W1(t),...,W L (t)] = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (Υ s ) T Ξ -1 (t) (8) where Υ s = [I n , I n ,..., I n T , and the fusion error covariance can be calculated by the following formula as: P u (t) = ((Υ s ) T Ξ -1 (t)Υ s ) -1 (9); Step 6: Go to Step 5 and continue to calculate the fusion estimation value next time.
2. The data privacy protection method based on event triggering according to claim 1, characterized in that: According to the standard Kalman filter, and P i (t) can be obtained from the local estimator (LE) of the i-th sensor: P i (t) can exponentially converge to the steady-state value through several iterations, and this steady-state value is the stable error covariance in Step 2 where represents the prior MMSE estimate represents the prior estimate error covariance, P i (t) represents the posterior estimate error covariance 3. The data privacy protection method based on event triggering according to claim 2 is characterized in that: in In the usage scenario, all sensors are intelligent sensors with computing capabilities. At time t, the i-th sensor observes the physical process to obtain the observation result y i (t). After collecting the observations up to time t, the information set of the i-th local estimator is given as Y i (t) = {y i (1),..., y i (t)}, and it is defined that:
4. A data privacy protection method based on event triggering according to claim 1, characterized in that: The encryption mechanism is that the processor of the $i$-th sensor can generate a random variable $\zeta$ at each moment $t$, i as follows:
5. A data privacy protection method based on event triggering according to claim 1, characterized in that: The channel model is given as follows: where β i (t) represents a binary variable, and β i (t) = 1 means that the eavesdropper successfully intercepts the i-th LE, and β i (t) = 0 means that the eavesdropper does not successfully intercept the i-th LE.
6. The data privacy protection method based on event triggering according to claim 1, characterized in that: The definition of perfect expected confidentiality is as follows. For any initial condition P(0), the confidentiality mechanism can achieve perfect expected confidentiality if and only if the following two conditions are both satisfied: where the covariance of the state estimation error of the eavesdropper is represented by P e (t), Sup represents the upper bound, and Tr represents the tracking operator.