Unmanned aerial vehicle injection attack detection method and system based on edge-cloud collaborative double-layer model

By using a dual-layer edge-cloud collaborative model to perform joint detection on the edge and cloud sides of the UAV, the problems of low detection efficiency and limited resources for data injection attacks in UAV systems are solved, and efficient and accurate data injection attack detection is achieved.

CN118714570BActive Publication Date: 2025-11-18NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410611143.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-16
Publication Date
2025-11-18
Estimated Expiration
2044-05-16

AI Technical Summary

Technical Problem

Existing technologies struggle to efficiently detect data injection attacks in unmanned aerial vehicle (UAV) systems, especially under edge-cloud collaborative control architectures. Traditional detection models cannot meet the specific needs of UAV systems, which are characterized by limited resources and unstable wireless networks, resulting in low detection efficiency and extended detection time.

Method used

A detection method based on a two-layer edge-cloud collaborative model is adopted. A lightweight detection model is used to perform preliminary detection at the edge of the UAV, and a complete detection model in the cloud is combined to aggregate and analyze sensor data to build a lightweight LOF detection model and a SAX-VSM detection model, so as to achieve efficient and accurate detection of data injection attacks.

Benefits of technology

It improves the detection accuracy of drone data injection attacks, alleviates the detection latency problem caused by resource constraints and wireless network instability, and enhances the timeliness of detection and resource utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118714570B_ABST
    Figure CN118714570B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on edge cloud collaborative double-layer model's unmanned plane injection attack detection method and system, the application includes through the lightweight detection model in edge cloud collaborative double-layer model on unmanned plane on the sensor data of this unmanned plane injection attack detection, if injection attack is detected, alarm and exit;Otherwise, through the complete detection model in edge cloud collaborative double-layer model in cloud end, the sensor data uploaded by this unmanned plane is combined with the sensor data uploaded by other unmanned plane and is gathered to form time series data, and injection attack detection is carried out to the time series data formed, if injection attack is detected, alarm and exit.The application aims to enhance the detection capability of attack data through the complete detection model in cloud end, compensate the influence of wireless network efficiency on detection delay through edge side detection capability, improve the data injection attack detection capability for unmanned plane in timeliness, resource consumption and accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned system security, specifically to a method and system for detecting UAV injection attacks based on an edge-cloud collaborative two-layer model. Background Technology

[0002] With the widespread application of drones in both military and civilian fields, their security has become a major concern. False Data Injection (FDI) attacks, which manipulate drone sensor data or control commands to cause drones to deviate from normal behavior, are a significant threat currently facing drones. Attackers compromise communication channels to tamper with sensor data or control commands exchanged between the ground control station and the drone, leading to injected control or malfunctions. In particular, as attack intensity increases, attackers can simultaneously tamper with multiple types of data, causing greater attack effects and even disrupting cascaded drone control systems. Therefore, efficient detection of drone data injection attacks is crucial.

[0003] Based on the type of data tampering, data injection attacks can be divided into three categories: perception data injection attacks, control signal data injection attacks, and coordinated attacks. Coordinated attacks mainly refer to attacks in which attackers simultaneously tamper with control signals and perception data. Generally speaking, the more targets an attacker targets, the stronger the harm and the greater the concealment; however, the higher the requirements for their attack capabilities. In particular, with the rise of large-scale swarm operations of unmanned systems, the control architecture of unmanned systems such as UAV swarms has gradually evolved from the traditional ground control station-UAV single control architecture to an edge-cloud coordinated control architecture. The cloud connects to the ground control station, acquires a large amount of UAV data, generates decisions, and then the ground control station sends control commands to the UAVs. On the other hand, because UAVs have certain computing capabilities, and considering the need for many real-time execution tasks, UAVs have the need for onboard decision-making for some special tasks. Based on the above, the current task control of UAVs has given rise to an edge-cloud coordinated control architecture.

[0004] There is currently a large number of research on data injection attack detection schemes. For example, for smart grid data injection attacks, researchers have proposed data injection attack detection methods based on state estimation and data injection attack detection methods based on command signal sequence correlation. However, since the above methods are mainly aimed at the smart grid field, although they have good detection capabilities, they face the following problems when directly applied to UAV systems: (1) The special characteristics of UAV systems reduce the accuracy of traditional attack detection algorithms. Unlike traditional smart grids, the UAV's operating trajectory and task execution are variable and special. In particular, UAVs exhibit different characteristics in physical structure and control theory. Therefore, it is difficult to achieve efficient detection by directly applying the detection models applied to smart grid fields to UAV data injection attack scenarios. On the other hand, the multi-UAV collaboration makes the detection problem more complex. Unlike the traditional single-system single-function detection modeling, the heterogeneity of sensor data and control command data and the large-scale variable time series data make it difficult to construct an accurate detection mechanism using traditional models, i.e., the detection efficiency is low. (2) Limited UAV resources make it difficult to deploy and apply traditional detection algorithms. Traditional cyber-physical systems do not have resource constraints. Therefore, the design of detection schemes often adopts the method of aggregating and detecting collected data. This scheme requires the system to be unrestricted in terms of network bandwidth and computing resources. In particular, as the network scale continues to increase and the detection model becomes more and more complex, its demand for computing resources increases dramatically. That is, the existing detection schemes are difficult to meet the actual situation of limited network resources of UAVs. (3) Wireless networks are difficult to support real-time detection-control closed loop and cannot meet the real-time detection requirements. During the execution of the mission, multiple UAVs and the UAV and the ground control station realize data transmission through wireless networks to achieve detection effects. However, wireless networks are unstable and have slow transmission rates. For the traditional detection framework, the data first needs to be aggregated and then analyzed. After obtaining the detection results and forming control commands, the data is transmitted to the UAV through the wireless network. The above process requires two passes through the wireless network. This method will seriously affect the safety protection efficiency of the unmanned system. Summary of the Invention

[0005] The technical problem to be solved by this invention is to provide a method and system for detecting UAV injection attacks based on an edge-cloud collaborative dual-layer model, which addresses the above-mentioned problems in the prior art. This invention aims to enhance the detection capability of attack data through a complete detection model in the cloud and to compensate for the impact of wireless network performance on detection latency through edge detection capability, thereby improving the detection capability of UAV data injection attacks in terms of timeliness, resource consumption, and accuracy.

[0006] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0007] A method for detecting drone injection attacks based on an edge-cloud collaborative two-layer model includes:

[0008] Step S101: The lightweight detection model located on the UAV in the edge-cloud collaborative dual-layer model is used to detect injection attacks on the UAV's sensor data. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the UAV's sensor data is uploaded to the cloud and the process proceeds to step S102.

[0009] Step S102: The sensor data uploaded by the UAV is combined with the sensor data uploaded by other UAVs to form time series data through the complete detection model in the cloud in the edge-cloud collaborative dual-layer model. The time series data is then subjected to injection attack detection. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the detection ends and the process exits.

[0010] Optionally, the lightweight detection model in step S101 is a LOF detection model, and the injection attack detection of the UAV's sensor data using the LOF detection model includes:

[0011] Step S201, for the data points corresponding to the current drone sensor data ={ } T Calculate the current data point With existing data point set any point in} The distance to the neighbors, among which The current flight speed of the drone, The current three-dimensional position coordinates of the drone. ~ These represent the data points from the 1st to the (k-1)th data points;

[0012] Step S202: Calculate the existing data point set. In and the current data points The nearest neighbor is a specified number of K points With the current data points average distance between As the current data point K-nearest neighbor distance Determine the current data point. For data points whose neighbor distance is less than or equal to the constant parameter 10 within the neighborhood, obtain the current data point. 10th distance neighborhood And calculate the current data point. Locally achievable density ;

[0013] Step S203, based on the current data points K-nearest neighbor distance Locally achievable density Calculate the current data point The Local Injection Attack Factor (LOF) is used to determine whether an injection attack has been detected. If the LOF is greater than a preset threshold, the attack is considered to have been detected; otherwise, it is considered that no attack has been detected, and the current data point is set to [a new threshold]. Add to existing data point set .

[0014] Optionally, in step S202, the current data point is calculated. Locally achievable density The expression for the computation function is:

[0015] ,

[0016] In the above formula, For the current data point The 10th distance neighborhood, For the current data point For any data point in the 10th distance neighborhood, The expression for the computation function is:

[0017] ,

[0018] In the above formula, To obtain the maximum value, For data points 10-nearest distance, For data points With data points The proximity.

[0019] Optionally, the current data point in step S203 The expression for calculating the Local Injection Attack Factor (LOF) is as follows:

[0020] ,

[0021] In the above formula, For data points with a threshold of 10 Locally achievable density, For the current data point Any data point in the 10th distance neighborhood.

[0022] Optionally, step S102, which involves combining the sensor data uploaded by the drone with sensor data uploaded by other drones to form time-series data, includes:

[0023] Step S301: Combine the sensor data uploaded by the drone with each of the r data points in the sensor data uploaded by other drones to convert the multidimensional data into 1-dimensional data and arrange them in time.

[0024] Step S302: The 1-dimensional data arranged by time is divided into groups, and each group forms a multi-dimensional vector.

[0025] Step S303: Divide the numerical domain of the 1D data of r data points into multiple sub-regions with equal probability;

[0026] Step S304: For each multidimensional vector, construct a sequence list with a specified window size using a sliding window method, and convert the sequence list into characters. The conversion rule is to check which sub-region each element in the sequence list belongs to, and determine the preset string corresponding to the sub-region by looking up a table, thereby obtaining a character sequence with a specified window size as its length, which is used as the temporal data for injection attack detection by the complete detection model.

[0027] Optionally, the function expression for converting multidimensional data to 1-dimensional data in step S301 is:

[0028] ,

[0029] In the above formula, Let n represent the i-th 1-dimensional data. Dimensions This represents the data in the j-th dimension of the i-th data point.

[0030] Optionally, the complete detection model in step S102 is the SAX-VSM detection model. When performing injection attack detection on the formed time series data using the SAX-VSM detection model, each character of the character sequence with the specified window size as the length corresponds to one bit of the output of the SAX-VSM detection model, and the output is 1 or 0. If the output of the SAX-VSM detection model for all characters is 0, it is determined that no injection attack has been detected; otherwise, it is determined that an injection attack has been detected.

[0031] Furthermore, the present invention also provides a drone injection attack detection system based on an edge-cloud collaborative two-layer model, comprising interconnected drones and cloud computing devices, wherein the drones and cloud computing devices are programmed or configured to execute the drone injection attack detection method based on the edge-cloud collaborative two-layer model.

[0032] Furthermore, the present invention also provides a computer-readable storage medium storing a computer program, the computer program being programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model.

[0033] In addition, the present invention also provides a computer program product, wherein the computer program product stores computer program instructions, which are used to be programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model.

[0034] Compared with the prior art, the present invention has the following main advantages:

[0035] (1) Provides highly accurate detection of UAV data injection attacks. Traditional cyber-physical system data injection attacks focus more on power grids and water networks, and do not focus on the system characteristics of UAVs themselves, so they cannot be effectively applied to the detection of UAV data injection attacks. The edge-cloud collaborative dual-layer model of this invention consists of a complete detection model located in the cloud and lightweight detection models located on each UAV. By using the dual-layer detection model in combination, it can efficiently detect data injection attacks against UAVs and achieve efficient protection against data injection attacks.

[0036] (2) Solving the resource bottleneck of UAVs. If traditional detection mechanisms are directly applied to UAVs, they will seriously consume the UAVs' computing resources. However, the UAVs' computing resources are limited. Therefore, the method in this embodiment introduces an edge-cloud collaborative dual-layer detection architecture, which enables simple detection algorithms to run on the edge side and complex and efficient algorithms to run on the cloud side, thus solving the problem of limited computing resources.

[0037] (3) The high dynamism of UAVs during flight further exposes the instability of wireless networks, namely, the problem of long detection time. The method of this invention introduces an edge-cloud collaborative detection architecture to detect some data at the edge, which can alleviate the problem of long detection time for some attacks to a certain extent. Attached Figure Description

[0038] Figure 1 This is a schematic diagram of the basic process of the method in an embodiment of the present invention.

[0039] Figure 2 This is a schematic diagram of the edge-cloud collaborative two-layer model in an embodiment of the present invention.

[0040] Figure 3 This is a detailed flowchart illustrating the method of an embodiment of the present invention. Detailed Implementation

[0041] like Figure 1 As shown, the UAV injection attack detection method based on the edge-cloud collaborative two-layer model in this embodiment includes:

[0042] Step S101: The lightweight detection model located on the UAV in the edge-cloud collaborative dual-layer model is used to detect injection attacks on the UAV's sensor data. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the UAV's sensor data is uploaded to the cloud and the process proceeds to step S102.

[0043] Step S102: The sensor data uploaded by the UAV is combined with the sensor data uploaded by other UAVs to form time series data through the complete detection model in the cloud in the edge-cloud collaborative dual-layer model. The time series data is then subjected to injection attack detection. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the detection ends and the process exits.

[0044] like Figure 2 As shown, the edge-cloud collaborative two-layer model in this embodiment consists of a complete detection model located in the cloud and lightweight detection models located on each drone. In this embodiment, the two-layer structure includes each drone and a cloud command center. Each drone runs a lightweight detection model for efficient real-time detection; furthermore, this mode reduces resource consumption during model training. The cloud command center runs a model based on the complete detection model to achieve further accurate detection, thus realizing a two-stage detection of injection attacks. This embodiment includes using a lightweight detection model located on the UAV within an edge-cloud collaborative dual-layer model to detect injection attacks on the UAV's sensor data. If an injection attack is detected, an alarm is triggered and the process exits. Otherwise, the complete detection model located in the cloud within the edge-cloud collaborative dual-layer model aggregates the sensor data uploaded by the UAV with sensor data uploaded by other UAVs to form time-series data. Injection attack detection is then performed on the formed time-series data. If an injection attack is detected, an alarm is triggered and the process exits. Injection attacks cause abnormal UAV control by tampering with sensor perception data and control signals. This embodiment uses an edge-cloud collaborative dual-layer model at both the edge and cloud sides to collect and analyze sensor and control signals to detect the presence of injection attacks. This embodiment enhances the detection capability of attack data through the complete detection model in the cloud and compensates for the impact of wireless network performance on detection latency through edge-side detection capabilities, improving the data injection attack detection capability for UAVs in terms of timeliness, resource consumption, and accuracy.

[0045] like Figure 3As shown, the lightweight detection model in step S101 of this embodiment is the LOF detection model, and the complete detection model in step S102 is the SAX-VSM detection model (see reference: P. Senin and S. Malinchik, "SAX-VSM: Interpretable Time Series Classification Using SAX and Vector Space Model," 2013 IEEE 13th International Conference on Data Mining, Dallas, TX, USA, 2013, pp. 1175-1180, doi: 10.1109 / ICDM.2013.52.). After an injection attack occurs, the data is first collected by the edge-side LOF detection model. The LOF detection model inputs the data and analyzes whether there is any injection tampering behavior. If no tampering anomaly is found, it is transmitted to the cloud-based SAX-VSM detection model. The cloud-based SAX-VSM detection model combines the data transmitted by other UAVs to reduce the dimensionality of the data and inputs it into the SAX-VSM detection model to determine whether an injection attack exists. To address the shortcomings of existing data injection attack detection methods, this embodiment integrates the detection algorithm with an edge-cloud collaborative control architecture. Considering the limited detection capabilities at the edge but the availability of real-time control, a lightweight detection model based on LOF (Local Outer Factor) is designed at the edge, namely the LOF detection model. To address the complex and variable situations caused by multi-device collaboration, a SAX-VSM (Symbolic Aggregate Approximation Vector Space Model) detection model that integrates heterogeneous time-series data from multiple domains is designed in the cloud to enhance the detection capability of attack data. The edge-side detection capability compensates for the impact of wireless network performance on detection latency. Therefore, the detection device designed based on the method of this embodiment can improve the detection capability against UAV data injection attacks in terms of timeliness, resource consumption, and accuracy.

[0046] The basic idea of ​​LOF detection is to first calculate a local reachability density for each data point based on the data density around it. Then, it further calculates an outlier factor for each data point based on the local reachability density. This outlier factor indicates the degree of outlier for a data point; a larger factor value indicates a higher degree of outlierness, and a smaller factor value indicates a lower degree of outlierness. The model uses the Euclid norm to calculate neighbor distances, which can be specifically expressed as:

[0047] ,

[0048] In the above formula, express Neighbor distance, ={ } T Let represent the i-th data point, which is a vector composed of n-dimensional attributes. Each attribute represents a value from a specific sensor in the UAV system, and n is the number of sensors in the UAV. This represents the value of the j-th sensor on the drone. Similarly, This represents the j-th data point. Specifically, in this embodiment, the injection attack detection of the UAV's sensor data using the LOF detection model includes:

[0049] Step S201, for the data points corresponding to the current drone sensor data ={ } T Calculate the current data point With existing data point set any point in} The distance to the neighbors, among which The current flight speed of the drone, The current three-dimensional position coordinates of the drone. ~ These represent the 1st to k-1th data points; in this embodiment, n=4, and the Euclid norm is used to calculate the neighbor distance for any two data points. ={ } T and ={ } T Its neighbor distance can be expressed as:

[0050] ;

[0051] Step S202: Calculate the existing data point set. In and the current data points The nearest neighbor is a specified number of K points With the current data points average distance between As the current data point K-nearest neighbor distance Determine the current data point. For data points whose neighbor distance is less than or equal to the constant parameter 10 within the neighborhood, obtain the current data point. 10th distance neighborhood And calculate the current data point. Locally achievable density ;

[0052] For each data point, define a neighborhood radius p, and calculate the number of other data points within its neighborhood whose distance is less than or equal to p. These points constitute the p-th distance neighborhood of that point. , can be represented as:

[0053] ,

[0054] Where j <= k-1, when p = 10, the 10th distance neighborhood can be obtained. ;

[0055] Step S203, based on the current data points K-nearest neighbor distance Locally achievable density Calculate the current data point The Local Injection Attack Factor (LOF) is used to determine whether an injection attack has been detected. If the LOF is greater than a preset threshold, the attack is considered to have been detected; otherwise, it is considered that no attack has been detected, and the current data point is set to [a new threshold]. Add to existing data point set .

[0056] Calculate data points Locally achievable density The calculation process method is based on The reciprocal of the average reachability distance of the nearest neighbor is expressed as:

[0057] ,

[0058] Therefore, in step S202, the current data point is calculated. Locally achievable density The expression for the computation function is:

[0059] ,

[0060] In the above formula, For the current data point The 10th distance neighborhood, For the current data point For any data point in the 10th distance neighborhood, The expression for the computation function is:

[0061] ,

[0062] In the above formula, To obtain the maximum value, For data points 10-nearest distance, For data points With data points The proximity.

[0063] Calculation points Average local reachability density of points within the neighborhood and data points The ratio of locally accessible densities is the data point. The Local Outlier Factor (LOF value), the current data point in step S203 of this embodiment. The expression for calculating the Local Injection Attack Factor (LOF) is as follows:

[0064] ,

[0065] In the above formula, For data points with a threshold of 10 Locally achievable density, For the current data point Any data point in the 10th distance neighborhood. The data is compared to an anomaly threshold θ. If the value is greater than θ, it indicates that the current data is abnormal (an injection attack has been detected), and the detection model issues a warning signal and stops the detection process. If the value is less than or equal to θ, the data is considered normal (no injection attack was detected). Add the data to set M, and simultaneously transmit the data points to the cloud-based command and control center. As an optional implementation, the anomaly threshold θ in the above formula is set to 0.2. Compared with the anomaly threshold of 0.2, if it is greater than 0.2, it indicates that the current data is abnormal, the detection model will issue a warning signal and stop the detection process; if it is less than or equal to 0.2, the data is considered to be normal.

[0066] Considering the resource constraints of drones, they suffer from serious missed detection problems when facing multidimensional data and complex attacks. Therefore, we established a cloud-based SAX-VSM detection model. The basic idea is to convert continuous multidimensional data points into symbol sequences using the SAX algorithm to achieve data dimensionality reduction. Then, the VSM algorithm is used to treat the SAX symbol sequences as "text documents" and perform TF-IDF (Term Frequency-Inverse Document Frequency) transformation. Finally, the obtained vectors are compared with data from "normal" and "abnormal" classes. The vector is assigned to the class it is closest to. In this embodiment, step S102, which combines the sensor data uploaded by the drone with sensor data uploaded by other drones to form time-series data, includes:

[0067] Step S301: Combine the sensor data uploaded by the drone with each of the r data points in the sensor data uploaded by other drones to convert the multidimensional data into 1-dimensional data and arrange them in time.

[0068] Step S302: The 1-dimensional data arranged by time is divided into groups, and each group forms a multi-dimensional vector.

[0069] Step S303: Divide the numerical domain of the 1D data of r data points into multiple sub-regions with equal probability;

[0070] Step S304: For each multidimensional vector, construct a sequence list with a specified window size using a sliding window method, and convert the sequence list into characters. The conversion rule is to check which sub-region each element in the sequence list belongs to, and determine the preset string corresponding to the sub-region by looking up a table, thereby obtaining a character sequence with a specified window size as its length, which is used as the temporal data for injection attack detection by the complete detection model.

[0071] In this embodiment, step S301 specifically involves collecting m historical data points, arranging the historical data in chronological order of their generation, and converting each data point (multidimensional attribute) into 1-dimensional data. Specifically, this embodiment collects m historical data points, and when training the SAX-VSM detection model, it requires a majority of normal data and a small portion of abnormal data. For example, in this embodiment, m = 1500 historical data points are collected, including 1400 normal data points and 100 abnormal data points. The historical data are then arranged in chronological order of their generation, and each data point (4-dimensional attribute, including v, x, y, z) is converted into 1-dimensional data. In this embodiment, the function expression for converting multidimensional data into 1-dimensional data in step S301 is:

[0072] ,

[0073] In the above formula, Let n represent the i-th 1-dimensional data. Dimensions Let represent the data in the j-th dimension of the i-th data point. Replacing it with specific velocity and coordinate data, it can be represented as:

[0074] ,

[0075] in, For speed, It represents three-dimensional coordinates.

[0076] In step S302 of this embodiment, the converted historical data is arranged according to the time series and divided into q groups. Each group forms an r-dimensional vector, that is, the vector of the i-th group can be expressed as:

[0077] ,

[0078] During training, each generated vector is simultaneously labeled with its category (denoted as 0 / 1). That is, if a vector contains data transformed from the modified data, it is labeled as an anomaly; otherwise, it is classified as normal data. For example, in this embodiment, the transformed historical data is arranged according to time series and divided into 150 groups, each group forming a 10-dimensional vector. The vector in the i-th group can be expressed as:

[0079] .

[0080] In step S303 of this embodiment, when dividing the numerical domain of the 1D data of r data points into multiple sub-regions with equal probability, it includes dividing the time series numerical domain [Min{ ,..., }, Max{ ,..., Divide the region into 26 sub-regions with equal probability, forming 26 intervals [Min{ ,..., }, ),[ , ), ...,[ Max{ ,..., }].in, ~ The values ​​represent the boundary values ​​between adjacent sub-regions in the 26 sub-regions.

[0081] In step S3034 of this embodiment, when constructing a sequence list of a specified window size for each multidimensional vector using a sliding window method, for any i-th group of vectors:

[0082] ,

[0083] The sequence list with window size d is constructed using a sliding window approach as follows:

[0084] [ , ,..., ],

[0085] The sequence list is then converted into characters. The conversion rule is to check which sub-region an element belongs to. The 26 regions correspond to a, b, c, d, e, f, g, h, i, j, k, l, m, n, o, p, q, r, s, t, u, v, w, x, y, z in sequence. Each resulting character sequence is of length d. In this embodiment, d=3, then:

[0086] For any T

[0087] Construct a list of sequences with a window size of 3 using a sliding window approach:

[0088] [ , , , , , , , ].

[0089] Ultimately, the large number of character sequence groups obtained constitutes the time-series data.

[0090] In this embodiment, the generated time-series data is input into the SAX-VSM detection model for training, resulting in a binary classification detection model. When used, the generated time-series data is input into the trained SAX-VSM detection model to obtain the detection results. In this embodiment, when detecting injection attacks on the generated time-series data using the SAX-VSM detection model, each character in the input character sequence (with a specified window size as its length) corresponds to one bit of the SAX-VSM detection model's output, and this output is either 1 or 0. If all characters correspond to a 0 in the output of the SAX-VSM detection model, it is determined that no injection attack has been detected; otherwise, it is determined that an injection attack has been detected. In this embodiment, the data to be detected is sorted by time. When there are r data points, each data point is dimensionality reduced, and then the data is converted into r-d+1 string groups, which are input into the trained SAX-VSM detection model. The detection model outputs a 0 / 1 value for each string group. If all r-d+1 string arrays output 0, the data is considered normal. If a string input outputs 1, an anomaly is considered to exist in the sequence, and an alarm is sent to the cloud controller. Specifically, in this embodiment, the data to be detected is sorted according to time. When there are 10 data points, the dimensionality of each data point is reduced, and then the data is converted into 8 string groups. These are then input into the trained SAX-VSM model. The detection model will output 0 / 1 values ​​for each string group. If all 8 string arrays output 0, the data is considered to be normal. If there is a string input and output of 1, the sequence is considered to be abnormal, and an alarm is sent to the cloud controller.

[0091] To verify the UAV injection attack detection method based on the edge-cloud collaborative two-layer model, this embodiment conducted attack detection in a scenario of 15 UAV sorties, as shown in Table 1. 150,000 historical data entries (per UAV), 10,000 abnormal data entries (per UAV), and 2,000 data entries of attacks on multiple UAVs (greater than or equal to 2) were collected. The data were used with the principle of 80% training and 20% detection.

[0092] Table 1. Detection Results of Single / Multiple Drone Attacks

[0093]

[0094] As shown in Table 1, the method in this embodiment achieves excellent detection results in both accuracy and average latency for both single-aircraft and multi-aircraft drone attacks. Average latency is the average response time to abnormal data.

[0095] In addition, for comparison, Table 2 in this embodiment shows the detection performance of a single UAV using the LOF detection model and the SAX-VSM detection model alone.

[0096] Table 2 shows the attack detection performance using the LOF detection model and the SAX-VSM detection model alone.

[0097]

[0098] As shown in Table 2, the accuracy of detection is significantly insufficient when using the LOF detection model and the SAX-VSM detection model alone. This indicates that the combination of the LOF detection model and the SAX-VSM detection model in this embodiment achieves a significant improvement in accuracy compared to using the LOF detection model and the SAX-VSM detection model alone.

[0099] In summary, complex data injection attacks targeting a single drone focus more on concealing the abnormal behavior of that individual drone, while attacks targeting multiple drones focus more on disrupting their collaboration. Therefore, their anomalous characteristics differ significantly, and a single detection model cannot meet the detection requirements. Different detection models are needed for these two scenarios. This embodiment combines a complete detection model located in the cloud with lightweight detection models located on each drone to achieve joint detection in a cloud-edge collaborative two-layer model. Considering the large number of attack entry points faced by a single drone, making it difficult to construct an anomaly detection model using limited data labeling, this invention employs a lightweight detection model implemented with unsupervised detection technology to detect single drone attacks at the edge. Considering the high concealment of attacks from multiple drones, this embodiment aggregates sensor data from multiple drones to form time-series data. Anomaly detection is achieved by discovering potential correlations between time-series data. Considering the rapid increase in data dimensionality in the context of a large number of drones, which would lead to inaccurate detection model construction and high resource consumption, a dimensionality reduction strategy is implemented to reduce the data dimensionality. Simultaneously, a semantic analysis model is used to discover potential correlations between discrete data, constructing an efficient detection model. Traditional drone attack detection primarily focuses on DDoS and malicious identity access attacks, exhibiting weak and ineffective detection capabilities for data injection attacks. This invention focuses on drone data injection attacks, particularly providing robust detection capabilities when multiple drones simultaneously encounter such attacks. Unlike traditional detection mechanisms, this invention employs an edge-cloud collaborative detection mechanism, utilizing drone computing power for low-cost detection. Simultaneously, by leveraging the drone's edge detection capabilities, it reduces data transmission volume and saves bandwidth resources. Addressing the challenges of multi-drone scenario detection, such as complex data dimensions and poor data correlation leading to difficult detection model construction and low accuracy, this embodiment utilizes the SAX-VSM mechanism to first reduce the dimensionality of multi-dimensional data and then construct a high-precision detection model using a semantic model. This effectively avoids the difficulty of constructing models from multi-dimensional data. Furthermore, the semantic analysis model effectively discovers correlations between discrete data, improving detection accuracy.

[0100] Furthermore, this embodiment also provides a drone injection attack detection system based on an edge-cloud collaborative two-layer model, including interconnected drones and cloud computing devices, wherein the drones and cloud computing devices are programmed or configured to execute the drone injection attack detection method based on the edge-cloud collaborative two-layer model.

[0101] In addition, this embodiment also provides a computer-readable storage medium storing a computer program, which is used to be programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model.

[0102] In addition, this embodiment also provides a computer program product, which stores computer program instructions for being programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model.

[0103] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable apparatus for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0104] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A method for detecting UAV injection attacks based on an edge-cloud collaborative two-layer model, characterized in that, include: Step S101: The lightweight detection model located on the UAV in the edge-cloud collaborative dual-layer model is used to detect injection attacks on the UAV's sensor data. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the UAV's sensor data is uploaded to the cloud and the process proceeds to step S102. Step S102: The sensor data uploaded by the UAV is combined with the sensor data uploaded by other UAVs to form time series data through the complete detection model in the cloud in the edge-cloud collaborative dual-layer model. The time series data is then subjected to injection attack detection. If an injection attack is detected, an alarm is triggered and the process exits; otherwise, the detection ends and the process exits. Step S102, which involves combining the sensor data uploaded by the drone with sensor data uploaded by other drones to form time-series data, includes: Step S301: Combine the sensor data uploaded by the drone with each of the r data points in the sensor data uploaded by other drones to convert the multidimensional data into 1-dimensional data and arrange them in time. Step S302: The 1-dimensional data arranged by time is divided into groups, and each group forms a multi-dimensional vector. Step S303: Divide the numerical domain of the 1D data of r data points into multiple sub-regions with equal probability; Step S304: For each multidimensional vector, construct a sequence list with a specified window size using a sliding window method, and convert the sequence list into characters. The conversion rule is to check which sub-region each element in the sequence list belongs to, and determine the preset string corresponding to the sub-region by looking up a table, thereby obtaining a character sequence with a specified window size as its length, which is used as the temporal data for injection attack detection by the complete detection model.

2. The UAV injection attack detection method based on an edge-cloud collaborative two-layer model according to claim 1, characterized in that, The lightweight detection model in step S101 is the LOF detection model, and the injection attack detection of the drone's sensor data using the LOF detection model includes: Step S201, for the data points corresponding to the current drone sensor data ={ } T Calculate the current data point With existing data point set any point in} The distance to the neighbors, among which The current flight speed of the drone, The current three-dimensional position coordinates of the drone. ~ These represent the data points from the 1st to the (k-1)th data points; Step S202: Calculate the existing data point set. In and the current data points The nearest neighbor is a specified number of K points With the current data points average distance between As the current data point K-nearest neighbor distance Determine the current data point. For data points whose neighbor distance is less than or equal to the constant parameter 10 within the neighborhood, obtain the current data point. 10th distance neighborhood And calculate the current data point. Locally achievable density ; Step S203, based on the current data points K-nearest neighbor distance Locally achievable density Calculate the current data point The Local Injection Attack Factor (LOF) is used to determine whether an injection attack has been detected. If the LOF is greater than a preset threshold, the attack is considered to have been detected; otherwise, it is considered that no attack has been detected, and the current data point is set to [a new threshold]. Add to existing data point set .

3. The UAV injection attack detection method based on an edge-cloud collaborative two-layer model according to claim 2, characterized in that, In step S202, the current data point is calculated. Locally achievable density The expression for the computation function is: , In the above formula, For the current data point The 10th distance neighborhood, For the current data point For any data point in the 10th distance neighborhood, The expression for the computation function is: , In the above formula, To obtain the maximum value, For data points 10-nearest distance, For data points With data points The proximity.

4. The UAV injection attack detection method based on an edge-cloud collaborative two-layer model according to claim 2, characterized in that, The current data point in step S203 The expression for the calculation function of the Local Injection Attack Factor (LOF) is: , In the above formula, For data points with a threshold of 10 Locally achievable density, For the current data point Any data point in the 10th distance neighborhood.

5. The UAV injection attack detection method based on an edge-cloud collaborative two-layer model according to claim 1, characterized in that, The function expression for converting multidimensional data to 1-dimensional data in step S301 is: , In the above formula, For the first i A 1-dimensional data point, n represents... Dimensions Indicates the first i The data point of the th data point j Data in multiple dimensions.

6. The UAV injection attack detection method based on an edge-cloud collaborative two-layer model according to claim 1, characterized in that, The complete detection model in step S102 is the SAX-VSM detection model. When performing injection attack detection on the formed time series data using the SAX-VSM detection model, each character of the character sequence with the specified window size as the length corresponds to one bit of the output of the SAX-VSM detection model, and the output is 1 or 0. If the output of the SAX-VSM detection model for all characters is 0, it is determined that no injection attack has been detected; otherwise, it is determined that an injection attack has been detected.

7. A UAV injection attack detection system based on an edge-cloud collaborative two-layer model, comprising interconnected UAVs and cloud computing devices, characterized in that, The drone and cloud computing device are programmed or configured to execute the drone injection attack detection method based on the edge-cloud collaborative two-layer model as described in any one of claims 1 to 6.

8. A computer-readable storage medium storing a computer program, characterized in that, The computer program is used to be programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model as described in any one of claims 1 to 6.

9. A computer program product, wherein the computer program product stores computer program instructions, characterized in that, The computer program instructions are used to be programmed or configured by a microprocessor to execute the UAV injection attack detection method based on the edge-cloud collaborative two-layer model as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Threat monitoring method of swarm intelligence system suitable for small unmanned aerial vehicle cluster

    CN111050302A

  • High-dimensional data anomaly detection method based on hierarchical processing in industrial Internet of Things

    CN112004204A