Cps adaptive network attack defense method and device based on symbiotic evolution strategy

By interacting with the Spear and Shield systems, potential attack vectors are generated and anomaly detectors are enhanced, solving the problem that existing systems cannot fully assess and adapt to changes, and achieving automated and effective anomaly detection.

CN118646567BActive Publication Date: 2025-11-04ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410714661.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2025-11-04
Estimated Expiration
2044-06-03

AI Technical Summary

Technical Problem

Existing physical information fusion system anomaly detection systems cannot fully acquire real attack methods for evaluation and cannot adapt to system changes, resulting in insufficient detection of new attack types.

Method used

A CPS adaptive network attack defense method based on a symbiotic evolution strategy is adopted. Potential attack vectors are generated by the Spear system and injected into the system for evaluation. The incremental learning of the Shield system is combined to strengthen the anomaly detector. Attack vectors are generated using a predictive model and fuzz testing, and the anomaly detector is optimized through incremental learning.

Benefits of technology

It has implemented an automated anomaly detection process that requires no manual intervention, enabling it to detect more attacks and enhance anomaly detection performance. It adapts to system changes and improves detection efficiency and applicability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118646567B_ABST
    Figure CN118646567B_ABST
Patent Text Reader

Abstract

The application discloses a CPS adaptive network attack defense method and device based on a symbiotic evolution strategy. The implementation of the method comprises two main components: a spear system and a shield system. The spear system predicts the behavior of a physical information fusion system by learning a model, and generates a potential effective attack vector. The shield system constructs an artificial intelligence-based anomaly detector for identifying abnormal data streams, and further enhances the performance of the anomaly detector through incremental learning. The method can automatically implement the process from data generation to anomaly detection without additional human intervention, without the need for additional professional knowledge of the physical information fusion system, and can explore more different attack methods, use the attack results as guidance, and further enhance the performance of the anomaly detection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information processing technology of physical information fusion system, in particular to a CPS adaptive network attack defense method and device based on symbiotic evolution strategy. BACKGROUND

[0002] Cyber-Physical Systems (CPS) are systems that tightly integrate algorithms and physical processes. Specifically, they are assumed to be composed of various computational elements, such as programmable logic controllers, which are distributed in a network and interact with physical processes through sensors and actuators. The operation of a CPS is controlled by programmable logic controllers, which take readings from sensors that observe the physical state, then calculate the corresponding instructions and send them to the relevant actuators in the network.

[0003] A Tennessee Eastman (TE) developed on Matlab was used as a test platform when designing the anomaly detection reinforcement system. This implementation is based on the mathematical model of the Tennessee Eastman process, which is used to provide a complex and practical environment. TE is a multivariable, nonlinear, and complex dynamic process that includes multiple operating units and reaction steps. During the entire control process, TE involves multiple key variables such as temperature, pressure, flow, and reactor level. The interaction between these variables and their dynamic characteristics make this platform meet the definition of a physical information fusion system and become an ideal test platform for anomaly detection reinforcement systems. The TE process on Matlab can be used to simulate and control the dynamic characteristics and nonlinear behavior of the process. Different variables such as temperature, pressure, and flow can be adjusted and detected to simulate different operating conditions and working conditions. And we can use the powerful functions of Matlab to improve the original system to meet different functional needs, such as modifying system variables in real time according to demand, which cannot be achieved in the original system, but relying on the powerful tool chain of Matlab, we can realize more complex functions.

[0004] Because physical information fusion systems tightly integrate computation, networks, and physical processes, as the number of software and physical devices increases, it brings more security risks. Network attacks on physical information fusion systems are mainly achieved through intelligent communication networks, data transmission protocols, and local control centers of the system. These network attacks can interfere with the normal operation of the system, cause data theft, damage system stability and security, and even cause catastrophic consequences. Therefore, it is very difficult to maintain complex physical information fusion systems.

[0005] Current anomaly detection systems for protecting physical information fusion systems use several types of solutions. First, anomaly detection-based systems monitor potential attack behavior by detecting anomalies in network traffic or device states. Second, fingerprinting-based systems monitor possible attacks by analyzing specific features in network packets, such as source addresses and ports. Another approach is to monitor system invariants to detect attacks. Additionally, real-time monitoring systems continuously monitor network traffic or device states to detect attacks in a timely manner. Furthermore, virtualization-based systems create virtualized environments to simulate network flows and device states to monitor and defend against attacks. Finally, machine learning-based systems use these advanced techniques to automatically detect and defend against various types of attacks. These different types of systems collectively form a multi-layered protection system for modern attack defense.

[0006] Current anomaly detection systems still have some drawbacks. First, these systems may not be able to detect attacks that only occur under specific strict conditions. Second, it is difficult to evaluate the reliability of an anomaly detection system because it requires deploying real attacks on a physical information fusion system. Moreover, current anomaly detection systems rely on system experts or white hats to manually construct a benchmark attack, which is time-consuming and difficult to comprehensively include potential attack points in the entire system. Furthermore, existing defense mechanisms cannot adapt to system changes and may not effectively detect new attack types, limiting the system's applicability. SUMMARY

[0007] The present invention provides a CPS adaptive network attack defense method and device based on a co-evolution strategy to alleviate the following shortcomings of existing anomaly detection systems for physical information fusion systems. First, existing systems cannot obtain comprehensive and realistic attack methods to comprehensively evaluate anomaly detection systems. Second, existing anomaly detection systems cannot adapt to system changes and cannot learn new defense strategies.

[0008] The technical solutions adopted by the present invention to solve the above technical problems are as follows:

[0009] The implementation of the CPS adaptive network attack defense method based on a co-evolution strategy proposed by the present invention includes two main components: the spear system (Spear) and the shield system (Shield), with the physical information fusion system (CPS) as the test object.

[0010] In the Spear system, a prediction model is learned to predict the behavior of a physical information fusion system. The dataset needed to learn the prediction model comes from the data generated by the physical information fusion system under various operations. The prediction model takes the current state of the physical information fusion system as input, including but not limited to the sensor values, actuator values, and controller configurations of the system, and then predicts the possible future states. Based on this prediction model and the attack target, the invention proposes a fuzzer that can analyze different operating modes of the system and generate potential effective attack vectors. Once a set of candidate attack vectors is generated, these vectors will be injected into the physical information fusion system one by one for security evaluation of the Shield system.

[0011] First, a prediction model that can reveal the relationship between actuator values, sensor values, controller configurations, and future physical states needs to be trained, and a comprehensive dataset that can reflect the behavior of the physical information fusion system is essential. In an ideal case, this dataset should contain time series of actuator values, sensor values, and controller configurations to reflect various operating scenarios of the target physical information fusion system. Data points should be recorded at consistent time intervals to improve the accuracy and applicability of the prediction model.

[0012] The method of the present application guides the fuzz testing to generate potential attack vectors through a prediction model. The core idea is that, in a complex physical information fusion system scenario, when an attacker makes changes to a specific actuator or configuration item, the evolution process of the target component can be understood in depth. For example, in the TE process, the potential attack target can be to make a certain specific container overflow, such as a reaction container. In order to achieve such a goal, the attacker must correspondingly operate the configuration in various systems. Based on this prediction model, the present application can generate a series of instructions to modify the system configuration, thereby forcing the system to increase the liquid level of the target container. First, the previously recorded data set can be preprocessed to convert it into a series of vectors with a fixed format. These vectors contain all sensor values, actuator values and controller configurations at each discrete time point. The data format can be specified as: <A, S, C>, where A, S and C represent the numerical records of the actuator, sensor and controller configuration from time point 0 to time point n. Since the data contained in these vectors is continuous and discrete values collected in different units and different scales, the data should be preprocessed after collection to standardize the data distribution. In addition, if the scale of the vector is too large to affect the training result, appropriate feature selection techniques should be used to reduce the input dimension of the model. In the training stage, since there are many different types of prediction models available on the market, a suitable prediction model should be selected according to the data set and the model target of the present application. For example, after obtaining a perfect data set, a deep learning model can be applied to predict the behavior of several components.

[0013] After a prediction model is obtained, the present application proposes a method to generate meaningful attack vectors. It is assumed that an attacker can modify the configuration of a controller in a physical information fusion system through a network attack (e.g. a man-in-the-middle attack), but randomly generated attack vectors do not do a good job of achieving a complex attack goal, such as overflowing a particular tank. To achieve a specific attack goal, a fitness function is needed to quantify how close the predicted properties are to the attack goal. For example, if the goal is to cause a reaction tank to overflow, the fitness function should take the reaction tank's level sensor reading as input and return a fitness value that increases as the input increases. Then, the fuzzer can use the fitness function to find the attack vector that maximizes the result, achieving the attack goal. The fitness function can be manually defined in different forms, for example, the fitness function can be defined as a quantitative way to describe the unsafe state of the relevant properties. Once the fitness function is formalized, each attack vector generated is assigned a fitness value. To make the attack vectors have some variation, for each set of attack vectors, the present application uses roulette wheel selection instead of simply selecting the attack vector with the maximum fitness value. Of course, the greater the fitness value of the attack vector corresponds, the higher the probability of being selected by the roulette wheel selection algorithm.

[0014] In the last phase of the inner loop of the Spear system, fuzzing, the present application injects the generated attack vectors into the target physical information fusion system for evaluating the current defense mechanisms. The present application records the data generated by the target system before and after the injection of the attack, if the current anomaly detector does not detect the injected attack after the attack is injected, and the attack eventually triggers a security alert of the target system for the key properties, this data will be saved for later improvement of the anomaly detector. Conversely, if the attack does not work, and the target system runs to a pre-defined time limit, this data will be discarded. After each round of fuzzing, the target system will be reset to a normal state.

[0015] In the Shield system, an anomaly detector, which can be an artificial intelligence-based binary classifier, is first constructed to determine whether the state of the physical information fusion system is safe. At the same time, the Spear system injects generated attacks into the physical information fusion system to generate abnormal data streams. The role of the anomaly detector in the Shield system is to identify abnormal data before the physical information fusion system triggers a safety alarm and shuts down the system. If the anomaly detector fails to identify the anomaly, it means that the attack vector designed by the present application bypasses the anomaly detector, and the data generated by the attacked physical information fusion system will be saved and marked accordingly, i.e., marked as abnormal. With the continuous accumulation of data, the Shield system further enhances the performance of the anomaly detector through incremental learning, triggering a continuous interaction cycle between the "Spear" and the "Shield".

[0016] Before formally implementing the fuzzing test, the anomaly detector needs to be initialized. In order to construct this detector, a data set with labels of whether it is abnormal is needed. Similar to the method in the Spear system, the data points of the actuator values, sensor values and controller configurations collected during the normal operation of the system are labeled as normal. In order to generate data representing abnormal behavior of the system, the controller configuration of the system can be modified during the normal operation of the system. For example, a certain system parameter can be selected and modified to be 4 times the original value, and the generated data is recorded. If the system runs safely to a time limit, the data is normal, otherwise if the system triggers a safety alarm within the time limit, the data is marked as abnormal. In actual situations, the present application uses a heuristic strategy to modify one controller configuration parameter in each round of operation, and the original value of the parameter is increased by an exponential factor in each round, for example, 1 times, 2 times, 4 times, etc., and the data generated in each round is given a corresponding label. Through this method, the distribution space of the attack vector is preliminarily explored, and an initial binary classifier is trained. The binary classifier will detect key variables in the target physical information fusion system, such as the pressure of the reaction vessel in the TE process. The main goal of the binary classifier is to detect in advance whether the system deviates from the expected normal behavior.

[0017] As the Spear system runs, fuzzing processes in Spear continuously generate attack vectors that potentially bypass the current anomaly detector and inject them into the target system to generate corresponding data records. These new data can be used to strengthen the current anomaly detector, so that the updated anomaly detector can timely detect similar attack methods. One intuitive method is to directly use the new data as a training set to fine-tune the parameters of the anomaly detector. However, such an approach can easily lead to the consequence of "catastrophic forgetting", that is, the model forgets the past training data, especially when a large amount of new data is used to fine-tune the model. In order to overcome "catastrophic forgetting", an intuitive solution is to save all historical data, and when updating the model, use the newly generated data and the historical data as training data to update the model, but this method has two major shortcomings, one is that it requires a large amount of storage space to save historical data, and the other is that as the data increases, the cost of training a model is rising. In summary, this scheme that relies on a large amount of additional storage and replays all data is not suitable for the actual physical information fusion system scenario. Therefore, in order to reduce the dependence on storage and the training cost of updating the model, the present application uses an incremental learning scheme, the main idea of which is to select a part of the data in the original data set, that is, the historical data set, as the exemplar set after the end of a round of training and add it to the next round of training. These selected data can ensure that after the model is updated in the next round of training, the parameters of the model will not deviate too much from the original basis, causing the model to "forget" the ability to detect old tasks. According to different selection strategies and the amount of selected data, different effects will be caused on the training results. Too large an exemplar set will increase the training pressure of the next stage, and too small an exemplar set will lead to "catastrophic forgetting" of the model, so an efficient screening algorithm needs to be selected and the trade-off between the amount of data retained and resource consumption needs to be balanced.

[0018] The process of training a neural network-based anomaly detector can be understood as observing the distribution of training data in its feature space to define a decision boundary, and the goal of training the model is to find a decision boundary that minimizes the misclassification probability between classes. When selecting training data as an exemplar set, the data selected is expected to best represent the current decision boundary. Usually, when constructing a neural network for a classification task, a feature vector can be obtained. It is the output vector of the last layer obtained after the input is obtained by the neural network and then propagated forward, and the calculation and transformation of multiple hidden layers. This feature vector contains high-level features that the neural network abstracts and represents the input data. Usually, the feature vector will go through a fully connected layer to get a classification label.

[0019] In screening data, for each data in each category (here, two categories of normal and abnormal), a feature vector value is calculated, and an average value, i.e., a category center, is calculated using the feature vector values. Then the following two operations can be adopted:

[0020] ① For each data in each category, the Euclidean distance between its feature value and the corresponding category center is calculated, and the data closest to the category center is selected as the initial value of the example set, and then new data is selected from the historical data set to join the example set, requiring that the newly added data can make the center of the feature vectors in the new example set closest to the category center. Repeat the process until the number of example set data reaches a preset upper limit, and the example set will be saved.

[0021] ② For each data in each category, the Euclidean distance between its feature value and the corresponding category center is calculated, and then the data is sorted according to the distance, and uniform sampling is performed on the sorted historical data set according to the preset example set size, that is, data points are selected at equal intervals in the historical data set, and the preset example set data quantity is met. This also means that the interval size depends on the number of historical data set data and the preset example set data quantity.

[0022] The example set obtained by data screening will be used together with newly generated data as the training set of the fine-tuning model. Compared with the method of saving and playing back all historical data, such a training set greatly reduces the storage consumption and the cost of training the model.

[0023] In summary, the Shield system plays a key role in protecting the target physical information fusion system from evolving attacks. It uses a binary classifier trained with labeled data to detect anomalies, and at the cost of smaller storage and training costs, it continuously improves detection performance through incremental learning techniques. This ensures that the anomaly detector remains effective and adaptable in the face of changing attack strategies.

[0024] The application also provides a CPS adaptive network attack defense device based on a symbiotic evolution strategy, comprising a memory and one or more processors, the memory storing executable code, and the processor executing the executable code to implement the CPS adaptive network attack defense method based on the symbiotic evolution strategy.

[0025] The method of the present application can automatically realize the process from data generation to anomaly detection without additional manual intervention. The method can not only effectively detect anomalies, but also does not require additional professional knowledge of a physical information fusion system, including its control program and physical process. In addition, the method can discover a larger number of attacks through two interactive systems, far exceeding the ability of manual work, and can further enhance the performance of anomaly detection through the attack data that has been discovered. BRIEF DESCRIPTION OF DRAWINGS

[0026] Figure 1 An interaction cycle diagram of Spear and Shield provided for an exemplary embodiment of the present application;

[0027] Figure 2 A fuzzy test flowchart provided for an exemplary embodiment of the present application;

[0028] Figure 3 A structure diagram of a CPS adaptive network attack defense device based on a symbiotic evolution strategy of the present application. DETAILED DESCRIPTION

[0029] In order to improve the performance of the anomaly detector for the physical information fusion system in the following two aspects, one is easy to deploy on various systems, and the other is to automatically generate meaningful attacks and enhance the anomaly detector, the embodiment of the present application proposes a CPS adaptive network attack defense method and device based on a symbiotic evolution strategy. The main implementation principles, specific implementation processes and corresponding beneficial effects that can be achieved of the embodiments of the present application are described in detail below in conjunction with the drawings of the specification.

[0030] The embodiment of the present application proposes a CPS adaptive network attack defense method based on a symbiotic evolution strategy, as shown in Figure 1 The implementation of the method includes two main components: Spear system and Shield system, and the physical information fusion system CPS as the test object.

[0031] The Spear system includes the following three main contents: building a prediction model, fuzzy testing, and implementing network attacks. The goal of the Spear system is to systematically generate attack vectors that cannot be captured by existing anomaly detectors. In order to achieve this purpose, a prediction model needs to be configured and trained according to the attack target and the sensors, actuators and controllers of the physical information fusion system. Then, fuzzy testing is performed, and this prediction model is used to systematically generate potential attack vectors according to the set attack target, and the flowchart is as shown in Figure 2As shown, the process begins with running a physical information fusion system to obtain current features as seeds for a fuzzing algorithm. Next, a set of attack vectors is generated based on a fitness function. The selected attack vectors are then applied to a real system, and the observed results are recorded. Subsequently, an anomaly detector checks the data; if an attack is detected, the detector issues an alert. These records are ultimately saved. Before each attack injection, the system is rebuilt and run under normal conditions. At the end of the process, a set of anomalous data can be constructed to enhance the anomaly detector. The implementation details will be further described below.

[0032] Collecting comprehensive data is a prerequisite for training a predictive model capable of revealing the relationships between sensor values, actuator values, controller configurations, and future physical states. Therefore, the dataset should contain time series data for actuator values, sensor values, and controller configurations. These data points are recorded at regular time intervals, reflecting the diverse operational scenarios of the target physical information fusion system. These datasets can be easily accessed from the historical database of the physical information fusion system. Even if a historical database is unavailable, obtaining the required data through a Supervisory Control and Data Acquisition (SCADA) system or network traffic is feasible. In the MATLAB version of the TE system, the "To File" data saving module in Simulink can be used to record system runtime data in real time. This ensures that the necessary data information is provided for training a powerful predictive model.

[0033] This method requires a predictive model to guide the search for potential attack vectors. The core idea is to gain a deep understanding of the evolution of target components within a system with complex physical processes. For example, a potential attack target might involve a specific container in a system that overflows physical information fusion. To achieve this, various configurations must be manipulated accordingly to force the system to increase the liquid level inside the target container. First, the previously collected dataset is converted into vectors with a fixed format. These vectors contain sensor values, actuator values, and controller configurations at each discrete time point. Before training, since the vectors contain values ​​in various units, the collected values ​​need to be preprocessed appropriately, such as normalized. During the training phase, since different types of predictive models are available, this embodiment uses the common LSTM model as the predictive model.

[0034] During fuzz testing, a predictive model generates a corresponding network attack based on a given attack target. The target system, TE, in this specific implementation has five observed variables. Each variable has a corresponding safety range; if a sensor reading exceeds this safety range, the system will crash. Anomaly detection aims to detect system anomalies before these variable results exceed their safety ranges. The specific descriptions of the observed variables are shown in the table below.

[0035] Observed variable Sensor number Safe range Reactor Pressure xmeas7 Less than 3000 Reactor Liquid Level xmeas8 57.94-834.86 Reactor Temperature xmeas9 Less than 175 Separator Liquid Level xmeas12 25.83-414.29 Stripper Liquid Level xmeas15 -14.69-232.52

[0036] Figure 2 A fuzzing method for generating meaningful attack vectors is presented. While it's assumed that an attacker can arbitrarily manipulate controller configurations via a network attack, randomly generated attack vectors cannot achieve complex attack targets, such as overflow containers. In a TE system, controller configurations include multiple sets of PI controller configurations, each set containing two floating-point parameters. These controller configurations can be encoded into a floating-point vector, for example...<c0,c1,...,cn> An attack vector can be encoded as a set of floating-point vectors. Each element in the vector corresponds to a controller parameter, and the value of the element represents the offset of the parameter. For example, an attack vector...<x0,x1,x2,...,xn> Corresponding controller configuration<c0,c1,...,cn> The new controller was then configured as follows:<c0+x0*c0,c1+x1*c1,...,cn+xn*cn> In the TE system, the fitness function can be defined as follows:

[0037]

[0038] Where d s The definition is as follows:

[0039]

[0040] Here v s L is the current value of sensor s. s This is the lower limit set by the sensor, H. s This is the upper limit set by the sensor.

[0041] like Figure 2 As shown, at the beginning of the fuzzing test, data generated by the target system under normal conditions is captured and combined with a previously randomly generated attack vector as input to the prediction model to calculate a prediction result. This process continues until the number of prediction results accumulates to a pre-set upper limit. Then, for each prediction result, the fitness function mentioned above is used to calculate its fitness. Finally, a roulette wheel selection algorithm is used to select a suitable result. The roulette wheel selection algorithm determines the probability of selection based on the fitness value. First, the fitness of each individual is standardized so that the sum of the fitness values ​​is 1. Then, each fitness value represents the probability of that data being selected, and a candidate attack vector is selected based on this probability. Furthermore, the higher the fitness, the more likely the attack vector is to cause system collapse, and the more likely it is to be selected. Compared to directly selecting the attack vector with the highest fitness, the roulette wheel selection method can provide data with more diverse distributions.

[0042] The last step of the Spear system injects the generated attack vectors into the physical information fusion system to evaluate the defense mechanisms, i.e., to push the system into an unsafe state by manipulating system properties without triggering the alarms of the anomaly detector. Thus, logs are only recorded when the attack successfully bypasses the anomaly detector and affects the system. It is worth noting that these attack vectors will be translated into a series of commands to manipulate system variables. For example, our attack vector contains an operation that changes the configuration of the controller. If the system remains normal within the manually set time limit, the attack is considered a failure, and the subsequent logs should be discarded. Otherwise, these data should be recorded for subsequent improvements to the anomaly detector. After that, the system should be reset to the normal state.

[0043] The Shield system maintains an anomaly detector. Before the formal implementation of fuzzing, the anomaly detector needs to be initialized. In order to build this detector, a dataset with labels of whether it is abnormal is needed. The collection of the dataset can use a similar strategy to the Spear system, and the data generated by the physical information fusion system under normal operation is labeled as normal. Subsequently, the labeled dataset is used to train a basic binary classifier. This binary classifier will serve as an anomaly detector to detect whether there is a scenario in the physical information fusion system that can cause the system to deviate from the normal state.

[0044] In the case of continuous operation of the Shield system, the fuzzing process in Spear will continuously generate attack vectors that can potentially bypass the current anomaly detector and inject them into the target system to generate corresponding data records. Over time, the system will accumulate new data that the current anomaly detector cannot normally judge. These additional data can be used to strengthen this anomaly detector. Here, the method of incremental learning is used to strengthen the current model. In order to reduce the storage space and computing resources overhead caused by strengthening the current model, and to overcome the problem of "catastrophic forgetting" when training neural networks, the invention selects a part of the data in the original dataset, i.e., the historical dataset, as an exemplar set after the end of a round of training, and adds it to the next round of training to meet the above several requirements.

[0045] Overall, the invention applies a data screening technique to the current training dataset, and then selects a plurality of data points as exemplar set samples (such as 200) from the dataset. In the next reinforcement training phase, the previously screened representative samples will be added to the latest training dataset for model updating.

[0046] To effectively solve catastrophic forgetting, during the training of the network, the example set samples are constructed and saved, so that the model can remember the distribution of old data, so as to still maintain the memory of the old data distribution when learning new distribution.

[0047] Because of the limitation of storage resources and computing resources, the model cannot use all the historical data to avoid catastrophic forgetting. The example set sample is a compact memory storage method, which can effectively save old information without saving all the old data.

[0048] During the training of the model, the training data defines the decision boundary through its distribution in the feature space, and the goal of the model is to find a decision boundary that can minimize the misclassification probability between classes. However, in the case of incremental learning, when new distribution data is added to the training data set, the decision boundary may change to adapt to the new data. This may cause the model to forget the old classes that have been learned, which is called catastrophic forgetting. Therefore, the purpose of the example set is to maintain the decision boundary of the old data when training new data, so as to maintain the decision boundary of the old model, so that the model can still have good performance on the old task.

[0049] When selecting training data as an example set, the data selected is expected to best represent the current decision boundary sample. Generally speaking, in a classification network, a neural network will usually use a feature vector before outputting a label. The present invention assumes that the model can be abstracted as a nonlinear function f, the input x of the network is input into the nonlinear function f to obtain the feature vector f(x), and then through a fully connected layer with a coefficient w to a classification label, that is, w*f(x).

[0050] When screening data, first, for the two categories of abnormal and normal, first calculate the average value of the feature vectors generated by the training data in the two categories, which is called the category center. Then the following two operations can be used:

[0051] ① For each data in each category, calculate the Euclidean distance between its feature value and the category center corresponding to it, select the data closest to the category center as the initial value of the example set, and then select new data from the historical data set to join the example set, requiring the newly added data to make the center of the feature vectors in the new example set after adding the data closest to the category center. Repeat the process until the number of example set data reaches a preset upper limit, and the example set will be saved.

[0052] ②For each piece of data in each category, calculate the Euclidean distance between its feature value and the center of the category corresponding to it, and then sort the data according to the distance, and uniformly sample the preset example set size in the sorted historical data set, that is, select data points at equal intervals in the historical data set and meet the preset example set data quantity. This also means that the interval size depends on both the number of data in the historical data set and the number of data in the preset example set.

[0053] The example set obtained through data screening will be used together with newly generated data as the training set for fine-tuning the model. Compared with the method of saving and replaying all historical data, such a training set greatly reduces the storage consumption and the cost of training the model.

[0054] The embodiment is implemented using Pytorch, Matlab2021b, Python3.9, and the symbiotic evolution strategy to strengthen the network physical system protection method against adaptive network attacks, and the number of code lines is about 10,000. The cuda version is 11.7. The server used includes an Intel(R) Core(TM) i7-12700 CPU, 32 GB of memory, and an RTX 3070 (8G) graphics card.

[0055] Referring to Figure 3 , the embodiment of the present application provides a CPS adaptive network attack defense device based on a symbiotic evolution strategy, comprising a memory and one or more processors, the memory storing executable code, and the processor executing the executable code to implement the CPS adaptive network attack defense method based on the symbiotic evolution strategy in the above embodiment.

[0056] The embodiment of the CPS adaptive network attack defense device based on the symbiotic evolution strategy of the present application can be applied to any device with data processing capability, which can be a device or apparatus such as a computer. The device embodiment can be realized by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logical device, it is formed by reading the corresponding computer program instructions in the non-volatile memory into the memory and running through the processor of the device with data processing capability where it is located. From the hardware level, as shown in Figure 3 , it is a hardware structure diagram of the device with data processing capability where the CPS adaptive network attack defense device based on the symbiotic evolution strategy of the present application is located. In addition to the processor, memory, network interface, and non-volatile memory shown in Figure 3 , the device with data processing capability where the device in the embodiment is located usually includes other hardware according to the actual functions of the device with data processing capability, and this will not be described again.

[0057] The implementation process of the functions and roles of each unit in the above device is specifically described in the implementation process of the corresponding steps in the above method, which will not be repeated here.

[0058] For the device embodiment, since it basically corresponds to the method embodiment, the relevant part can be referred to the part of the method embodiment. The above described device embodiment is only schematic, and the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or also distributed on multiple network units. According to the actual needs, part or all of the modules can be selected to achieve the purpose of the present application. Those skilled in the art can understand and implement it without creative labor.

[0059] The embodiment of the present application also provides a computer readable storage medium, which stores a program, and the program is executed by a processor to realize the CPS adaptive network attack defense method based on symbiotic evolution strategy in the above embodiment.

[0060] The above is only the preferred embodiment of one or more embodiments of the present application, and does not limit one or more embodiments of the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of one or more embodiments of the present application should be included in the protection scope of one or more embodiments of the present application.

Claims

1. A CPS adaptive network attack defense method based on symbiotic evolution strategy, characterized in that, The method includes a spear system and a shield system, and a CPS as a test object; the method includes the following steps: Step 1, in the spear system, a prediction model is learned to predict the behavior of the CPS, the prediction model takes the current state of the CPS as input to predict the future physical state; Step 2, based on the prediction model and the attack target, a fuzzer is designed to analyze different operation modes of the CPS and generate potential effective candidate attack vectors; Step 3, the generated candidate attack vectors are injected into the CPS in turn for security evaluation of the shield system; Step 4, in the shield system, an anomaly detector is constructed to determine whether the state of the CPS is safe; Step 5, the spear system injects the generated attack vectors into the CPS to generate abnormal data streams, and the anomaly detector in the spear system identifies abnormal data before the CPS issues a safety alarm and shuts down; Step 6, as the amount of data accumulates, the shield system enhances the performance of the anomaly detector through incremental learning, triggering continuous interaction between the spear system and the shield system.

2. The CPS adaptive network attack defense method based on the symbiotic evolution strategy according to claim 1, characterized in that, The spear system learns and constructs a prediction model through deep learning, and the data set required for learning the prediction model comes from the data generated by the target CPS under various operations, including time series of actuator values, sensor values and controller configurations, to reflect various operation scenarios of the target system, and data points are recorded at consistent time intervals.

3. The CPS adaptive network attack defense method based on the co-evolution strategy of claim 1, wherein, The prediction model is used to guide the fuzzer to generate potential effective attack vectors, which are specific to the attack target of the CPS, and the attack vectors may cause the state of the CPS to deviate from the normal state, but the current anomaly detector may not be able to capture it, because these attack vectors may not have appeared in the previous training data.

4. The CPS adaptive network attack defense method based on the co-evolution strategy of claim 1, wherein, Based on the prediction model, a series of instructions are generated to modify the system configuration, first, the previously recorded data set is preprocessed and converted into a series of vectors with fixed format, these vectors contain all sensor values, actuator values and controller configurations at each discrete time point; then data distribution standardization processing is performed; if the vector scale is too large to affect the training result, feature selection technology is used to reduce the input dimension of the model.

5. The CPS adaptive network attack defense method based on the symbiotic evolution strategy according to claim 1, characterized in that, In order to realize attack specific target, fitness function is designed to quantify the closeness of prediction attributes and attack target; the fitness function is defined as a quantitative description of the unsafe state of the relevant attributes; The fuzzer uses the fitness function to find attack vectors, each generated attack vector is assigned a fitness, and for each set of attack vectors, the attack vector is selected using roulette.

6. The method of claim 1, wherein, In the process of fuzzing, the generated attack vectors are injected into the target system for evaluation of the current defense mechanism; If the attack injection is not detected by the current anomaly detector after the injection, and the attack eventually triggers a security alert of the target system on the key attributes, the data generated before and after the attack is saved and labeled as an anomaly for improving the anomaly detector; On the contrary, if the attack does not take effect, and the target system runs to the predefined upper limit of time, the data is discarded; After each round of fuzzing test, the target system will be reset to the normal state.

7. The CPS adaptive network attack defense method based on the symbiotic evolution strategy according to claim 1, characterized in that, The initialization of the anomaly detector is specifically: constructing a labeled data set; the data points of the actuator value, the sensor value and the controller configuration collected during the normal operation of the system are labeled as normal; During the normal operation of the system, the controller configuration of the system is modified to construct abnormal data, and a heuristic strategy is used to modify one controller configuration parameter in each round of operation, and the original value of the parameter is increased by an exponential multiple in each round, and the data generated in each round is given a corresponding label; in this way, the distribution space of the attack vector is preliminarily explored, and an initial binary classifier is trained to detect whether the system deviates from the expected normal behavior in advance.

8. The CPS adaptive network attack defense method based on the co-evolution strategy of claim 1, wherein, The training of the anomaly detector is specifically: after the end of a round of training, a part of the data in the original data set, i.e., the historical data set, is selected as an example set through incremental learning, and the example set obtained through data screening and the newly generated data in this round are used as the training set of the fine-tuned anomaly detector, and the next round of training is performed.

9. The CPS adaptive network attack defense method based on the co-evolution strategy of claim 8, wherein, The construction of the example set is specifically: the average value of the feature vectors generated by the training data in different categories is calculated as the category center; For each data in each category, the Euclidean distance between its feature value and the corresponding category center is calculated, the nearest data to the category center is selected as the initial value of the example set, and then new data is selected from the historical data set to join the example set, and the newly added data is required to make the center of the feature vectors in the new example set after adding the data closest to the category center; Repeat the process until the number of example set data reaches the preset upper limit; Or, For each data in each category, the Euclidean distance between its feature value and the corresponding category center is calculated, and the data is sorted according to the distance, and the historical data set after sorting is uniformly sampled according to the preset size of the example set, that is, the data points are selected at equal intervals in the historical data set, and the preset number of example set data is met.

10. A CPS adaptive network attack defense device based on symbiotic evolution strategy, characterized in that, The memory and one or more processors, the memory stores executable code, and the processor executes the executable code to implement the CPS adaptive network attack defense method based on the symbiotic evolution strategy according to any one of claims 1-9.

Citation Information

Patent Citations

  • Low-cost detection and isolation method for spoofing attack in cyber-physical system

    CN115048625A

  • Attack detection method considering attack signal and unknown disturbance based on interconnected CPS

    CN115051872A