Robust unsupervised detection method for pilot pollution attacks in industrial IoT

By constructing a robust autoencoder network, optimizing it with the alternating direction multiplier algorithm, and combining it with discrete Fourier transform, the problem of poor robustness in pilot contamination attack detection is solved, and efficient detection and elimination in complex environments is achieved.

CN119011450BActive Publication Date: 2025-09-23XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410959016.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-17
Publication Date
2025-09-23
Estimated Expiration
2044-07-17

AI Technical Summary

Technical Problem

Existing pilot contamination attack detection methods lack robustness in complex, time-varying electromagnetic environments and cannot accurately detect them. In addition, deep learning-based methods have poor generalization capabilities for unknown patterns.

Method used

An industrial Internet of Things communication system is constructed. The robust autoencoder network is used to iteratively optimize the alternating direction multiplier algorithm, combined with discrete Fourier transform to extract the sparsity of the wireless channel and detect and eliminate pilot contamination attacks.

Benefits of technology

It effectively improves the ability to detect and eliminate pilot pollution attacks in industrial Internet of Things communication systems, and improves the detection accuracy and robustness in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011450B_ABST
    Figure CN119011450B_ABST
Patent Text Reader

Abstract

The present invention discloses a robust unsupervised detection method for pilot pollution attacks in the industrial Internet of Things (IIoT), which relates to the field of radio and is used to solve the problem of poor robustness in pilot pollution attack detection. The present invention comprises: constructing an IIoT communication system including a pilot pollution attack node, multiple legitimate transmitting nodes, and a receiving node; constructing a receiving signal model; obtaining an estimated channel from a legitimate transmitting node that is not attacked / affected by a pilot pollution attack to a receiving node based on the receiving signal model, and constructing a channel data set attacked by a pilot pollution attack; inputting the channel data set into a robust autoencoder network for unsupervised training, and iteratively optimizing the robust autoencoder network using an alternating direction multiplier algorithm; detecting pilot pollution attacks based on non-reconstructable estimated channel components, where the reconstructable estimated channel components are the estimated channels for eliminating pilot pollution attacks. The present invention significantly improves the ability to detect and eliminate pilot pollution attacks in IIoT communication systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of radio, and in particular to a robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things. Background Art

[0002] With the development of wireless communication technology, a large number of wireless devices have been connected to the network. However, due to the open nature of wireless communication systems, legitimate nodes in typical 5G communication scenarios, such as the Industrial Internet of Things, are extremely vulnerable to pilot pollution attacks. Pilot pollution attacks are active attacks that occur during the uplink channel training phase. Attackers eavesdrop on wireless communication channels to steal the pilot signals used by legitimate nodes for channel estimation. They then indirectly or continuously transmit the same pilot signals at varying power levels, thereby intercepting or tampering with the legitimate nodes' information, leading to confidential information leakage and data tampering. Pilot pollution attacks pose a serious threat to the security of wireless communication systems. Therefore, there is an urgent need to research pilot pollution attack detection methods to ensure communication security.

[0003] To protect communication security, existing research on pilot pollution attack detection in wireless communication systems can be roughly categorized into three categories: detection schemes based on channel estimation processes, detection schemes based on random pilots, and intelligent detection schemes based on deep learning. Furthermore, there are efforts to enhance the detection criteria for pilot pollution attacks, such as designing detectors based on energy ratios or random matrix theory. While these approaches have achieved some success, they lack robustness to environmental noise and cannot accurately detect pilot pollution attacks in complex, time-varying electromagnetic environments. Detection schemes based on channel estimation processes inevitably incur high communication overhead and computational complexity, making them unsuitable for industrial IoT nodes with limited communication and computing resources. While detection schemes based on random pilots reduce communication overhead, they are limited in emerging communication scenarios, such as unlicensed IoT networks, where pilot signals are pre-assigned. With the rapid development of artificial intelligence, intelligent detection schemes based on deep learning have gradually emerged. This approach focuses on exploring the data characteristics of the wireless channel itself, but often relies on learning known patterns from large amounts of labeled data, potentially resulting in poor generalization to unknown patterns. Summary of the Invention

[0004] The purpose of the present invention is to provide a robust unsupervised detection method for pilot pollution attacks in the industrial Internet of Things to address the above-mentioned problems, so as to solve the problem of poor robustness in pilot pollution attack detection.

[0005] The technical solution adopted in the present invention is as follows:

[0006] A robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things, characterized by comprising:

[0007] S1. Build an industrial Internet of Things communication system, which includes a pilot pollution attack node, multiple legitimate transmitting nodes, and a receiving node;

[0008] S2. Constructing a reception signal model from each of the legitimate transmitting nodes and the pilot pollution attack node to the receiving node respectively;

[0009] S3. Based on the received signal model, obtain estimated channels from the legitimate transmitting node that is not attacked by the pilot pollution attack and the legitimate transmitting node that is attacked by the pilot pollution attack to the receiving node, and construct a channel data set attacked by the pilot pollution attack according to the estimated channels;

[0010] S4. Inputting the channel data set attacked by the pilot contamination into a robust autoencoder network for unsupervised training, and iteratively optimizing the robust autoencoder network using an alternating direction multiplier algorithm to obtain a reconstructible estimated channel component and a non-reconstructible estimated channel component;

[0011] S5. Detecting a pilot pollution attack based on the non-reconstructable estimated channel component. The reconstructable estimated channel component is an estimated channel for eliminating the pilot pollution attack.

[0012] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0013] The present invention proposes a method for robust unsupervised detection of pilot contamination attacks. A robust autoencoder network based on the alternating direction multiplier algorithm is designed. The discrete Fourier transform is used to extract the inherent sparsity of the wireless channel. The alternating direction multiplier algorithm is used to iteratively optimize the robust autoencoder network, effectively eliminating channel data affected by pilot contamination attacks. This greatly improves the ability to detect and eliminate pilot contamination attacks in industrial Internet of Things communication systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The present invention will now be described by way of example with reference to the accompanying drawings, in which:

[0015] Figure 1 This is a flowchart of a robust unsupervised detection method for pilot pollution attacks in the industrial Internet of Things according to an embodiment of the present invention;

[0016] Figure 2 is a schematic diagram of the structure of a robust autoencoder network according to an embodiment of the present invention;

[0017] Figure 3 is a structural diagram of an sLSTM module of a robust autoencoder network according to an embodiment of the present invention;

[0018] Figure 4 is a schematic structural diagram of an mLSTM module of a robust autoencoder network according to an embodiment of the present invention;

[0019] Figure 5 is a schematic diagram of an sLSTM layer of a robust autoencoder network according to an embodiment of the present invention;

[0020] Figure 6 is a schematic diagram of an mLSTM layer of a robust autoencoder network according to an embodiment of the present invention;

[0021] Figure 7 is an estimated channel graph from a legitimate transmitting node that is not attacked / attacked by a pilot pollution and a pilot pollution attack node to a receiving node in an embodiment of the present invention;

[0022] Figure 8 This is a diagram showing the effect of a robust autoencoder network detecting and eliminating pilot contamination attacks according to an embodiment of the present invention;

[0023] Figure 9 4 is a pilot contamination attack detection rate diagram based on a robust autoencoder network according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] All features disclosed in this specification, or all steps in the disclosed methods or processes, except mutually exclusive features and / or steps, can be combined in any manner.

[0025] Any feature disclosed in this specification (including any appended claims and abstract), unless otherwise stated, may be replaced by other equivalent or similar features. That is, unless otherwise stated, each feature is only an example of a series of equivalent or similar features.

[0026] The embodiment of the present invention provides a robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things. Figure 1 As shown, the method comprises the following steps:

[0027] 101. Build an industrial Internet of Things communication system, which includes a pilot pollution attack node, multiple legitimate transmitting nodes, and a receiving node.

[0028] Specifically, an industrial Internet of Things communication system is constructed as follows: the base station BS is equipped with N r A uniform linear array composed of antennas is responsible for authenticating K legal transmitting nodes LN1, ..., LN k ,…,LN K , and detect potential pilot pollution attack node SN.

[0029] 102. Construct receiving signal models from each legitimate transmitting node and pilot pollution attack node to the receiving node respectively.

[0030] In a possible implementation, the constructed receiving signal models from the legitimate transmitting node and the pilot pollution attack node to the receiving node include:

[0031] a first receiving signal model from each legitimate transmitting node to the receiving node that is not attacked by the pilot pollution; and

[0032] The second receiving signal model from each legitimate transmitting node to the receiving node is attacked by the pilot pollution.

[0033] Specifically, according to the industrial Internet of Things communication system constructed in step 101, a received signal model for the received signal is constructed. The first received signal model from the kth legitimate transmitting node to the receiving node that is not attacked by the pilot pollution is as follows:

[0034]

[0035] Among them, Y k represents the received signal from the kth legal transmitting node to the receiving node, h k represents the channel from the kth legal transmitting node to the receiving node, x k represents the pilot signal from the kth legal transmitting node to the receiving node, (·) H represents the conjugate transpose, N represents the Gaussian noise from the legal transmitting node to the receiving node, and k ranges from 1 to K.

[0036] Specifically, the second receiving signal model from the kth legitimate transmitting node to the receiving node, which is attacked by the pilot contamination, is as follows:

[0037]

[0038] Among them, Y k represents the received signal from the kth legal transmitting node to the receiving node, h c represents the channel from the pilot contamination attack node to the receiving node, x c Represents the pilot signal from the pilot pollution attack node to the receiving node.

[0039] The above method can be used to construct the receiving signal model from the legitimate transmitting node and the pilot pollution attack node to the receiving node.

[0040] 103. Based on the received signal model, obtain estimated channels from the legitimate transmitting nodes that are not attacked by pilot pollution and those that are attacked by pilot pollution to the receiving node, and construct a channel data set attacked by pilot pollution according to the estimated channels.

[0041] In one possible implementation, this step includes:

[0042] According to the first received signal model and the second received signal model, respectively, a least squares method is used for fitting to obtain an estimated channel not attacked by the pilot contamination attack and an estimated channel attacked by the pilot contamination attack;

[0043] Discrete Fourier transform is performed on the estimated channel that is not attacked by pilot pollution and the estimated channel that is attacked by pilot pollution, and a channel data set attacked by pilot pollution is constructed.

[0044] Specifically, the estimated channel from the kth legitimate transmitting node to the receiving node that is not attacked by the pilot pollution is obtained based on the first receiving signal model as follows:

[0045]

[0046] Where, represents the estimated channel from the kth legal transmitting node to the receiving node, h k represents the channel from the kth legal transmitting node to the receiving node, Represents the pseudo-inverse of the conjugate transpose of the pilot signal from the kth legal transmitting node to the receiving node.

[0047] In one possible implementation, the pilot pollution attack includes:

[0048] A first pilot pollution attack in which the pilot pollution attack node continuously sends the same low-power pilot signal as the legitimate transmitting node; and

[0049] The pilot pollution attack node intermittently sends the same high-power pilot signal as the legitimate transmitting node.

[0050] Specifically, the pilot signal x under the first pilot pollution attack c as follows:

[0051]

[0052] Where x c represents the pilot signal from the pilot pollution attack node to the receiving node, 0<p1<1 represents the normalized power attenuation coefficient, ω k Represents a random phase offset. Specifically, the estimated channel from the kth legitimate transmitting node to the receiving node under the first pilot contamination attack obtained based on the second received signal model is as follows:

[0053]

[0054] Where, It represents the estimated channel from the kth legitimate transmitting node to the receiving node under the first pilot pollution attack.

[0055] Specifically, the pilot signal x under the second pilot pollution attack c as follows:

[0056]

[0057] Where x c represents the pilot signal from the pilot pollution attack node to the receiving node, ⊙ represents the element-wise multiplication operation of the matrix, p2≥1 represents the normalized power amplification factor,

[0058] Represents the indicator function, and p represents the probability of the pilot pollution attack node launching an attack. Specifically, the estimated channel from the kth legitimate transmitting node to the receiving node under the second pilot pollution attack obtained based on the second received signal model is as follows:

[0059]

[0060] Where, It represents the estimated channel from the kth legitimate transmitting node to the receiving node under the second pilot pollution attack.

[0061] Specifically, the channel is estimated using discrete Fourier transform processing, and the estimated channel of the kth legal transmitting node is used as an example for explanation, as follows:

[0062]

[0063] Where, Represents the discrete Fourier transform result, U r represents the unitary discrete Fourier transform matrix. The nth term of is as follows:

[0064]

[0065] Where, express The nth item of express The qth term, N r Indicates the number of base station antennas.

[0066] The final estimated channel can be obtained through the above method, and then the channel data set attacked by pilot contamination can be constructed.

[0067] The channel data set attacked by pilot contamination is input into the robust autoencoder network for unsupervised training, and the alternating direction multiplier algorithm is used to iteratively optimize the robust autoencoder network to obtain reconstructible estimated channel components and non-reconstructible estimated channel components.

[0068] In one possible implementation, the robust autoencoder network includes an encoder module and a decoder module. Step 104 includes:

[0069] A multi-objective optimization problem is constructed: the objective function includes a reconstruction error function for obtaining reconstructable estimated channel components and a penalty function for obtaining non-reconstructable estimated channel components; the constraint function includes that the channel data set attacked by pilot contamination is equal to the sum of the reconstructable estimated channel components and the non-reconstructable estimated channel components;

[0070] The alternating direction multiplier algorithm is used to iteratively optimize the multi-objective optimization problem and output reconstructable estimated channel components and non-reconstructable estimated channel components.

[0071] In one possible implementation, an alternating direction multiplier algorithm is used to iteratively optimize a multi-objective optimization problem, and output a reconstructible estimated channel component and a non-reconstructible estimated channel component, including:

[0072] Fixing the non-reconstructable estimated channel component, optimizing the reconstruction error function for obtaining the reconstructable estimated channel component according to the back propagation algorithm, and outputting the updated reconstructable estimated channel component;

[0073] Fixing the reconstructable estimated channel component, optimizing the penalty function for obtaining the non-reconstructable estimated channel component according to the proximal gradient algorithm, and outputting the updated non-reconstructable estimated channel component;

[0074] A relative error is calculated based on the updated reconstructable estimated channel components and the non-reconstructable estimated channel components; whether the iteration converges is determined based on the relative error and a preset threshold; if the iteration converges, the reconstructable estimated channel components and the non-reconstructable estimated channel components are output; if the iteration does not converge, the robust autoencoder network is iteratively optimized based on the channel data set attacked by pilot contamination and the updated reconstructable estimated channel components and the non-reconstructable estimated channel components.

[0075] In one possible implementation, the relative error includes:

[0076] a first relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the channel data set attacked by pilot contamination;

[0077] a second relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the sum of the reconstructable estimated channel component and the non-reconstructable estimated channel component in the previous iteration.

[0078] In one possible implementation, determining whether the iteration has converged based on the relative error and a preset threshold includes:

[0079] If the first relative error or the second relative error is less than a preset threshold, the iteration converges; otherwise, the iteration does not converge.

[0080] Specifically, the channel data set attacked by pilot pollution is as follows:

[0081] X=L+S,

[0082] Where, represents the channel data set attacked by pilot pollution, represents the M samples in the channel data set, M represents the total number of samples in the channel data set, L represents the reconstructible estimated channel component, and S represents the non-reconstructible estimated channel component.

[0083] Specifically, the multi-objective optimization problem is as follows:

[0084]

[0085] stX-L AE -S=0,

[0086] In the formula, ||·||2 represents the l2 norm of the matrix, ||·|| 2,1 l represents the matrix 2,1 Norm, L AE represents part of the input of the robust autoencoder network, D θ represents the decoder module of the robust autoencoder network, E φ represents the encoder module of the robust autoencoder network, and λ1 represents the parameter that adjusts the sparsity of the non-reconstructible estimated channel component.

[0087] The optimization iteration process is explained by taking the i-th round of iterative optimization of the robust autoencoder network using the alternating direction multiplier algorithm as an example:

[0088] The channel dataset X attacked by pilot pollution is taken as input, the non-reconstructible estimated channel component S is fixed, and the input L of the robust autoencoder network is obtained. AE =XS; use backpropagation algorithm to optimize ||L AE -D θ (E φ (L AE ))||2, obtain the trained robust autoencoder network Get the updated reconstructible estimated channel components output by the network

[0089] Where, L AE represents the reconstructible estimated channel component, E φ (L AE ) represents the output of the encoder after the reconstructible estimated channel component is input into the robust autoencoder network, Dθ (E φ (L AE )) represents the reconstructable estimated channel component L AE The output of the decoder after inputting the robust autoencoder network.

[0090] Fixed reconfigurable estimated channel component L AE , obtain the non-reconstructible estimated channel component S = XL AE ; Use the proximal gradient algorithm to optimize λ1||S|| 2,1 , the calculation method is as follows:

[0091]

[0092] Where s i,j represents the (i, j)th element of S, ||s j ||2 represents the l2 norm of the j-th column of S.

[0093] The updated reconstructable estimated channel component L can be obtained by the above method AE And the non-reconstructible estimated channel component S, calculate the relative error based on the two, and judge whether the relative error meets the convergence condition, as follows:

[0094] If condition 1 or condition 2 is met, the convergence condition is met:

[0095] Condition 1 is:

[0096] τ1=‖XL AE -S‖2 / ‖X‖2<ε,

[0097] Condition 2 is:

[0098] τ2=‖X f -L AE -S‖2 / ‖X‖2<ε,

[0099] Wherein, τ1 represents the relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the channel data set attacked by the pilot contamination, i.e., the first relative error; τ2 represents the relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the sum of the reconstructable estimated channel component and the non-reconstructable estimated channel component in the i-1th iteration, i.e., the second relative error; ε is the threshold value preset for judging whether the two relative errors meet conditions 1 and 2; X, as mentioned above, is the channel data set attacked by the pilot contamination, X f =L AE +S is the sum of the reconstructable estimated channel components and the non-reconstructable estimated channel components in the i-1th iteration.

[0100] Obtain the reconstructable estimated channel component L in the i-th iteration AE After the non-reconstructible estimated channel component S is obtained, it is determined whether the convergence condition is met, that is, whether condition 1 or condition 2 is met. If the convergence condition is met, the iteration is stopped and L is saved. AE and S, otherwise update X f =L AE +S and continue to iterate using S to determine whether the convergence condition is met, and then determine whether to stop the iteration based on whether the convergence condition is met.

[0101] Through the above process, the optimized robust autoencoder network and the final updated reconstructable estimated channel component L can be obtained. AE and the non-reconstructible estimated channel component S.

[0102] In one possible implementation, the encoder module includes, in sequence, a first sLSTM module, a first mLSTM module, and a first fully connected layer;

[0103] The decoder module includes a second fully connected layer, a second mLSTM module, and a second sLSTM module in sequence.

[0104] Specifically, if Figure 2 As shown, Figure 2 This is a structural diagram of the robust autoencoder network. The encoder module is composed of the first sLSTM module, the first mLSTM module, and the first fully connected layer in sequence. The decoder module is composed of the second fully connected layer, the second mLSTM module, and the second sLSTM module in sequence.

[0105] In one possible implementation, the first sLSTM module and the second sLSTM module each include a first hierarchical normalization layer, a first convolutional layer, a first sLSTM layer, a first group normalization layer, a first upper projection layer, and a first lower projection layer;

[0106] The first mLSTM module and the second mLSTM module both include a second hierarchical normalization layer, a second upper projection layer, a second convolutional layer, a first mLSTM layer, a second group normalization layer, and a second lower projection layer.

[0107] Specifically, if Figure 3 As shown, Figure 3 Schematic diagram of the sLSTM module of the robust autoencoder network. The input first passes through the first level normalization layer;

[0108] In the first convolutional layer, the output results of the previous layer enter the first channel and the second channel of the first convolutional layer respectively. In the first channel, the input first passes through a convolutional layer with a window size of 4 and an activation function of the Swish function, and then is fed through a block diagonal linear layer with 4 heads. In the second channel, the input is directly fed through a block diagonal linear layer with 4 heads.

[0109] The output results of the first and second channels pass through the first sLSTM layer;

[0110] The output of the first sLSTM layer passes through the first group normalization layer;

[0111] In the first projection layer, the projection factor The output results of the previous layer enter the third and fourth channels respectively. The input in the third channel is only projected upward, while the input in the fourth channel is first projected upward and then passes through the GeLu activation function. The output results of the third and fourth channels are multiplied element by element to obtain the output result of the first upward projection layer.

[0112] Finally, the output of the first upper projection layer is input into the first lower projection layer to obtain the final result. In the first lower projection layer, the projection factor

[0113] Specifically, if Figure 4 As shown, Figure 4 Schematic diagram of the mLSTM module of the robust autoencoder network. The input first passes through the second level normalization layer;

[0114] In the second up-projection layer, the projection factor PF=2, and the output of the previous layer enters the fifth and sixth channels respectively after up-projection;

[0115] In the fifth channel, the input enters the seventh and eighth channels of the second convolutional layer respectively. In the seventh channel, the input first passes through the convolution layer with a window size of 4 and an activation function of the Swish function, and then obtains the output result through the block diagonal projection matrix with a block size of 4. The input in the eighth channel obtains the output result through the block diagonal projection matrix with a block size of 4;

[0116] The output results of the seventh and eighth channels pass through the first mLSTM layer;

[0117] The output of the first mLSTM layer passes through the second group normalization layer, and after adding a residual connection, the output of the fifth channel is obtained. The input of the sixth channel passes through the Swish activation function and is multiplied element-wise with the output of the fifth channel.

[0118] Finally, the output results of the fifth and sixth channels are multiplied element by element and then pass through the second projection layer to obtain the final result. The projection factor in the second projection layer is

[0119] In one possible implementation, the first sLSTM layer includes, in sequence, an input gate, a forget gate, an output gate, a candidate memory unit, a memory unit, a hidden state, and a normalized state; the first mLSTM layer includes an input gate, a forget gate, an output gate, a query input, a key input, a value input, a memory unit, a hidden state, and a normalized state.

[0120] Specifically, the first sLSTM layer is used to retain the core information in the channel data set attacked by pilot contamination and eliminate redundant information within T time moments 1,…,t,…,T. It consists of an input gate i, a forget gate f, an output gate o, a candidate memory unit z, a memory unit c, a hidden state h, and a normalized state n. Figure 5 is a schematic diagram of the first sLSTM layer, as shown Figure 5 As shown, x t As the input of the first sLSTM layer, t increases from 1 to T through the following calculation, and finally the hidden state h at time T is T As the output of the first sLSTM layer.

[0121] The calculation method of input gate i at time t is as follows:

[0122]

[0123] Where i t represents the calculation result of the input gate at time t, exp(·) represents the exponential activation function, x t represents the input at time t, w i Represents the weight parameter of the input gate, h t-1 represents the hidden state at time t-1, r i represents the recurrent weight parameter of the input gate, b i Represents the bias parameter of the input gate.

[0124] The calculation method of the forget gate f at time t is as follows:

[0125]

[0126] Where, f t represents the calculation result of the forget gate at time t, σ(·) represents the sigmoid activation function, exp(·) represents the exponential activation function, OR represents the bitwise OR operation, x t represents the input at time t, w f Represents the weight parameter of the forget gate, h t-1 represents the hidden state at time t-1, r f represents the cyclic weight parameter of the forget gate, b f Represents the bias parameter of the forget gate.

[0127] The calculation method of the output gate o at time t is as follows:

[0128]

[0129] In the formula, o t represents the calculation result of the output gate at time t, σ(·) represents the sigmoid activation function, x t represents the input at time t, w o Represents the weight parameter of the output gate, h t-1 represents the hidden state at time t-1, r o represents the recurrent weight parameter of the output gate, b o Represents the bias parameter of the output gate.

[0130] The calculation method of candidate memory unit z at time t is as follows:

[0131]

[0132] Where z t represents the calculation result of the candidate memory unit at time t, represents the activation function, x t represents the input at time t, w z Represents the weight parameter of the candidate memory unit, h t-1 represents the hidden state at time t-1, r z represents the recurrent weight parameter of the candidate memory unit, b z Represents the bias parameters of the candidate memory unit.

[0133] The calculation method of memory unit c at time t is as follows:

[0134] c t =f t c t-1 +i t z t

[0135] Where c t represents the calculation result of the memory unit at time t, f t represents the calculation result of the forget gate at time t, c t-1 Represents the calculation result of the memory unit at time t-1, i t Represents the calculation result of the input gate at time t, z t Represents the calculation result of the candidate memory unit at time t.

[0136] The hidden state h at time t is calculated as follows:

[0137]

[0138] Where h t Represents the calculation result of the hidden state at time t, o t represents the calculation result of the output gate at time t, c t Represents the calculation result of the memory unit at time t, n t Represents the calculation result of the normalized state at time t.

[0139] The normalized state n at time t is calculated as follows:

[0140] n t =f t n t-1 +i t ,

[0141] Where n t represents the calculation result of the normalized state at time t, f t Represents the calculation result of the forget gate at time t, n t-1 represents the calculation result of the normalized state at time t-1, i t Represents the calculation result of the input gate at time t.

[0142] Specifically, the first mLSTM layer is used to retain the core information of the input and eliminate redundant information within T time moments 1,…,t,…,T. It consists of an input gate i, a forget gate f, an output gate o, a query input q, a key input k, a value input v, a memory unit C, a hidden state h, and a normalized state n. Figure 6 is a schematic diagram of the first mLSTM layer, as shown Figure 6 As shown, x t As the input of the first mLSTM layer, t increases from 1 to T through the following calculation, and finally the hidden state h at time T is T As the output result of the first mLSTM layer.

[0143] The calculation method of input gate i at time t is as follows:

[0144]

[0145] Where i t represents the calculation result of the input gate at time t, exp(·) represents the exponential activation function, x t represents the input at time t, w i represents the weight parameter of the input gate, b i Represents the bias parameter of the input gate.

[0146] The calculation method of the forget gate f at time t is as follows:

[0147]

[0148] Where, f t represents the calculation result of the forget gate at time t, σ(·) represents the sigmoid activation function, exp(·) represents the exponential activation function, OR represents the bitwise OR operation, x t represents the input at time t, w f represents the weight parameter of the forget gate, b f Represents the bias parameter of the forget gate.

[0149] The calculation method of the output gate o at time t is as follows:

[0150]

[0151] In the formula, o t represents the calculation result of the output gate at time t, σ(·) represents the sigmoid activation function, x t represents the input at time t, W o represents the weight parameter of the output gate, b o Represents the bias parameter of the output gate.

[0152] The calculation method for query input q at time t is as follows:

[0153] q t =W q x t +b q ,

[0154] Where q t represents the calculation result of the query input at time t, W q Represents the weight parameter of the query input, x t represents the input at time t, b q Indicates the bias parameter of the query input.

[0155] The calculation method of key input k at time t is as follows:

[0156]

[0157] Where k t represents the calculation result of the key input at time t, d represents the dimension of the key input, W k Represents the weight parameter of the key input, x t represents the input at time t, b k Indicates the offset parameter of the key input.

[0158] The value input v at time t is calculated as follows:

[0159] v t =W v x t +bv ,

[0160] Where, v t Indicates the calculation result of the value input at time t, W v Represents the weight parameter of the value input, x t represents the input at time t, b v Indicates the bias parameter for the value input.

[0161] The calculation method of memory unit C at time t is as follows:

[0162]

[0163] Where C t represents the calculation result of the memory unit at time t, f t Represents the calculation result of the forget gate at time t, C t-1 Represents the calculation result of the memory unit at time t-1, i t Represents the calculation result of the input gate at time t, v t Indicates the calculation result of the value input at time t, k t Indicates the calculation result of the key input at time t.

[0164] The hidden state h at time t is calculated as follows:

[0165]

[0166] Where h t Represents the calculation result of the hidden state at time t, o t represents the calculation result of the output gate at time t, ⊙ represents the element-wise multiplication operation of the matrix, C t Represents the calculation result of the memory unit at time t, q t represents the calculation result of the query input at time t, max{·,·} represents the maximum value function, n t Represents the calculation result of the normalized state at time t.

[0167] The normalized state n at time t is calculated as follows:

[0168] n t =f t n t-1 +i t k t ,

[0169] Where n t represents the calculation result of the normalized state at time t, f t Represents the calculation result of the forget gate at time t, n t-1represents the calculation result of the normalized state at time t-1, i t Represents the calculation result of the input gate at time t, k t Indicates the calculation result of the key input at time t.

[0170] 105. Detecting a pilot contamination attack based on a non-reconstructable estimated channel component. The reconstructable estimated channel component is an estimated channel for eliminating the pilot contamination attack.

[0171] In one possible implementation, detecting a pilot pollution attack based on a non-reconstructable estimated channel component, where the reconstructable estimated channel component is an estimated channel for eliminating the pilot pollution attack, includes:

[0172] Obtaining a Euclidean norm based on the non-reconstructable estimated channel components;

[0173] Determine whether it is a pilot pollution attack based on the Euclidean norm and the preset detection threshold;

[0174] If the Euclidean norm is not greater than the preset detection threshold, it is not a pilot contamination attack, and the output reconstructible estimated channel component is the estimated channel that eliminates the pilot contamination attack;

[0175] If the Euclidean norm is greater than the preset detection threshold, it is a pilot contamination attack.

[0176] Specifically, the following binary assumptions are introduced:

[0177]

[0178] Where ||·||2 represents the l2 norm of the matrix, η1 represents the threshold for detecting pilot pollution attacks, Denotes the unreconstructable estimated channel component of the mth instance. If the hypothesis H1 holds, a pilot pollution attack is detected, otherwise, a legitimate transmitting node is detected.

[0179] If a legitimate transmitting node is detected, the output reconstructable estimated channel component is the estimated channel that eliminates the pilot pollution attack.

[0180] The effect of the embodiment can be further illustrated by the following simulation experiment, which designs a robust unsupervised detection method experiment for the pilot pollution attack of the industrial Internet of Things. r A uniform linear array consisting of 64 antennas is used to authenticate K = 9 legitimate transmitting nodes, LN1, LN2, LN3, LN4, LN5, LN6, LN7, LN8, and LN9, and detect potential pilot pollution attack nodes, SN. The base station, pilot pollution attack nodes, and legitimate transmitting nodes are all located in an area of ​​[0, 100 m] × [0, 200 m].

[0181] After receiving the signal, the receiving node uses the least squares method to obtain the estimated channels that are not attacked / affected by pilot contamination according to the first received signal model and the second received signal model, and uses discrete Fourier transform to process the estimated channels that are not attacked / affected by pilot contamination, thereby constructing a channel data set that is attacked by pilot contamination.

[0182] The channel dataset affected by pilot contamination attack is constructed as follows: the ratio of the number of samples in the training set and the validation set is 8:2. The training phase only contains K = 9 legitimate transmitting nodes and 14,000 samples. The number of samples in the training set of the robust autoencoder network is 11,200, and the number of samples in the validation set is 2,800. The test set in the testing phase contains K = 9 legitimate transmitting nodes and 1 pilot contamination attack node, for a total of 3,000 samples, of which each legitimate transmitting node has 375 samples and the pilot contamination attack node has 1,500 samples.

[0183] In the simulation of pilot contamination attack detection and elimination based on the robust autoencoder network, the parameters of the robust autoencoder network are shown in Table 1. The Euclidean norm of the non-reconstructible estimated channel component of the channel data set attacked by the pilot contamination is calculated and compared with the detection threshold of the pilot contamination attack to detect whether the pilot contamination attack exists.

[0184] Table 1

[0185]

[0186]

[0187] Based on the above experimental settings and parameter settings, two experiments are conducted using a robust autoencoder network to test the performance of pilot contamination attack detection and the impact of different attack probabilities and false alarm rate constraints on pilot contamination attack detection.

[0188] Figure 7 It is the estimated channel graph from the legitimate transmitting node that is not / affected by the pilot pollution attack and the pilot pollution attack node to the receiving node. Figure 7 (a) and Figure 7 (d) describes the estimated channel from two legal transmitting nodes at different locations to the receiving node, whose peaks appear in different feature dimensions. Figure 7 (b) and Figure 7 (e) describes the estimated channel from the same pilot pollution attack node to the receiving node, Figure 7 (c) and Figure 7 (f) describes the estimated channel from two legitimate transmitting nodes to the receiving node under the pilot pollution attack, Figure 7 (c) Yes Figure 7 (a) with Figure 7 (b) is a linear combination of Figure 7 (f) Yes Figure 7 (d) with Figure 7 (e) The linear combination of the two channels. It can be seen that the essence of the pilot pollution attack lies in the linear combination of the legitimate channel and the attacker's channel.

[0189] Figure 8 The effect diagram of detecting and eliminating pilot pollution attacks for robust autoencoder networks. Figure 8 (a) depicts 10 channel instances under the first pilot pollution attack, where the sixth feature of each channel instance is lightly polluted. Figure 8 (c) describes 15 channel instances under the second pilot pollution attack, where the sixth feature of the eighth and fourteenth instances is heavily polluted. Figure 8 (b) and Figure 8 (d) depicts an example of a channel after elimination by the robust autoencoder network. This shows that the robust autoencoder network has a good ability to detect and eliminate pilot contamination attacks.

[0190] Figure 9 is the pilot pollution attack detection rate diagram under the second pilot pollution attack, Figure 9 The horizontal axis represents the probability of a pilot pollution attack node launching a pilot pollution attack, and the vertical axis represents the detection rate. Figure 9 It can be concluded that, given a fixed number of legitimate transmitting nodes, the pilot pollution attack detection rate gradually decreases as the attack probability p increases. This is because as the attack probability p increases, the number of channel instances affected by pilot pollution in the channel dataset increases, making it more difficult for the robust autoencoder network to detect pilot pollution attacks. When there are nine legitimate transmitting nodes and the probability p = 0.3 that a pilot pollution attacking node launches a pilot pollution attack, the detection rate is 71.18%. On the other hand, when the attack probability p is fixed, the pilot pollution attack detection rate gradually decreases as the number of legitimate transmitting nodes increases. This is because as the number of legitimate transmitting nodes increases, the channel instances for each legitimate transmitting node in the channel dataset become more dispersed, indirectly increasing the proportion of channel instances affected by pilot pollution. When there are nine legitimate transmitting nodes and the probability p = 0.033 that a pilot pollution attacking node launches a pilot pollution attack, the detection rate is 98.4%. This shows that the robust autoencoder network of this embodiment of the present invention has strong pilot pollution attack detection capabilities under different communication environments.

[0191] Table 2 shows the results of the test on the impact of different attack probabilities and false alarm rate constraints on pilot contamination attack detection. FArepresents the false alarm rate, p represents the probability of the pilot pollution attack node launching a pilot pollution attack. For each attack probability p, the channel data set attacked by the pilot pollution attack contains 1500 instances. From Table 2, we can conclude that when the false alarm rate constraint is fixed, as the attack probability p increases, the pilot pollution attack detection rate gradually decreases; when the attack probability p is fixed, as the false alarm rate constraint increases, the pilot pollution attack detection rate gradually increases. For example, at P FA = 0.1%, the robust autoencoder network only detects 493 contaminated instances with a detection rate of 72.5%, while under the constraint of P FA =2%, the robust autoencoder network detected 613 contaminated instances, with a detection rate of 90.14%, an improvement of 17.64%. This shows that the robust autoencoder network of the embodiment of the present invention significantly improves the detection performance of pilot contamination attacks as the false alarm rate constraint is relaxed.

[0192] Table 2

[0193]

[0194] The present invention is not limited to the aforementioned specific embodiments, but extends to any new features or any new combination disclosed in this specification, as well as any new method or process steps or any new combination disclosed.

Claims

1. A robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things, characterized by: include: S1. Build an industrial Internet of Things communication system, which includes a pilot pollution attack node, multiple legitimate transmitting nodes, and a receiving node; S2. Constructing a reception signal model from each of the legitimate transmitting nodes and the pilot pollution attack node to the receiving node respectively; S3. Based on the received signal model, obtain estimated channels from the legitimate transmitting node that is not attacked by the pilot pollution attack and the legitimate transmitting node that is attacked by the pilot pollution attack to the receiving node, and construct a channel data set attacked by the pilot pollution attack according to the estimated channels; S4. Inputting the channel data set attacked by the pilot contamination into a robust autoencoder network for unsupervised training, and iteratively optimizing the robust autoencoder network using an alternating direction multiplier algorithm to obtain a reconstructible estimated channel component and a non-reconstructible estimated channel component; S5. Detecting a pilot pollution attack based on the non-reconstructable estimated channel component. The reconstructable estimated channel component is an estimated channel for eliminating the pilot pollution attack.

2. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 1, characterized in that: The received signal model constructed in step S2 includes: a first receiving signal model from each of the legal transmitting nodes to the receiving node that is not attacked by pilot pollution; and A second receiving signal model from each of the legal transmitting nodes to the receiving node that is attacked by pilot pollution.

3. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 2, characterized in that: The step S3 comprises: According to the first received signal model and the second received signal model, respectively, a least squares method is used for fitting to obtain an estimated channel not attacked by the pilot contamination attack and an estimated channel attacked by the pilot contamination attack; Discrete Fourier transform is performed on the estimated channel that is not attacked by the pilot pollution and the estimated channel that is attacked by the pilot pollution to construct a channel data set that is attacked by the pilot pollution.

4. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 2, characterized in that: The pilot pollution attack includes: The pilot pollution attack node continuously sends a first pilot pollution attack with the same low-power pilot signal as the legitimate transmitting node; and The pilot pollution attack node intermittently sends a second pilot pollution attack with the same high-power pilot signal as the legitimate transmitting node.

5. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 1, characterized in that: The robust autoencoder network includes an encoder module and a decoder module; step S4 includes: Constructing a multi-objective optimization problem: the objective function includes a reconstruction error function for obtaining a reconstructable estimated channel component and a penalty function for obtaining a non-reconstructable estimated channel component; the constraint function includes that the channel data set attacked by the pilot contamination is equal to the sum of the reconstructable estimated channel component and the non-reconstructable estimated channel component; The multi-objective optimization problem is iteratively optimized using an alternating direction multiplier algorithm, and a reconstructable estimated channel component and a non-reconstructable estimated channel component are output.

6. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 5, characterized in that: The encoder module includes a first sLSTM module, a first mLSTM module, and a first fully connected layer in sequence; The decoder module includes a second fully connected layer, a second mLSTM module and a second sLSTM module in sequence; The first sLSTM module and the second sLSTM module each include, in sequence, a first hierarchical normalization layer, a first convolutional layer, a first sLSTM layer, a first group normalization layer, a first upper projection layer, and a first lower projection layer; The first mLSTM module and the second mLSTM module each include, in sequence, a second hierarchical normalization layer, a second upper projection layer, a second convolutional layer, a first mLSTM layer, a second group normalization layer, and a second lower projection layer.

7. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 5, characterized in that: The iterative optimization of the multi-objective optimization problem using an alternating direction multiplier algorithm to output a reconstructable estimated channel component and a non-reconstructable estimated channel component includes: Fixing the non-reconstructable estimated channel component, optimizing the reconstruction error function for obtaining the reconstructable estimated channel component according to a back propagation algorithm, and outputting an updated reconstructable estimated channel component; Fixing the reconstructable estimated channel component, optimizing the penalty function for obtaining the non-reconstructable estimated channel component according to a proximal gradient algorithm, and outputting an updated non-reconstructable estimated channel component; A relative error is calculated based on the updated reconstructable estimated channel component and the non-reconstructable estimated channel component; whether the iteration converges is determined based on the relative error and a preset threshold; if the iteration converges, the reconstructable estimated channel component and the non-reconstructable estimated channel component are output; if the iteration does not converge, a robust autoencoder network is iteratively optimized based on the channel data set attacked by pilot contamination, the updated reconstructable estimated channel component, and the non-reconstructable estimated channel component.

8. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 7, characterized in that: The relative error includes: a first relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the channel data set attacked by pilot contamination; and a second relative error between the sum of the updated reconstructable estimated channel component and the non-reconstructable estimated channel component and the sum of the reconstructable estimated channel component and the non-reconstructable estimated channel component in the previous iteration; and 9. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 8, characterized in that: The step of judging whether the iteration has converged based on the relative error and the preset threshold comprises: If the first relative error or the second relative error is less than a preset threshold, the iteration converges; otherwise, the iteration does not converge.

10. The robust unsupervised detection method for pilot pollution attacks in industrial Internet of Things according to claim 1, characterized in that: The step S5 comprises: Obtaining a Euclidean norm according to the non-reconstructable estimated channel component; Determine whether it is a pilot pollution attack based on the Euclidean norm and the preset detection threshold: If the Euclidean norm is not greater than a preset detection threshold, it is not a pilot contamination attack, and the reconfigurable estimated channel component is output as the estimated channel that eliminates the pilot contamination attack; If the Euclidean norm is greater than a preset detection threshold, it is a pilot contamination attack.

Citation Information

Patent Citations

  • Secure paring method for MIMO systems

    CN109417469A

  • Pilot pollution attack channel decontamination method in NOMA scene

    CN113507710A