Multi-agent system security consistency control method and system for immediate attack detection

By adopting immediate attack detection method in multi-agent systems and using encoding and decoding for real-time verification, the problem of security consistency control of multi-agent systems under data injection attacks is solved, and efficient and real-time attack detection and consistency control are achieved.

CN119484160BActive Publication Date: 2025-05-06HANGZHOU NORMAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510046866.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-06
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

Security consistency control of multi-agent systems under data injection attacks is difficult to achieve. The lack of effective joint design of attack detection algorithms and consistency controllers in the existing methods, which makes the system unable to find a balance between real-time and security.

Method used

An immediate attack detection method is adopted, by encoding and decoding when sending and receiving data between agents, and using logical operations to perform real-time verification, we judge whether the data transmission is attacked. The encoding and decoding process has low computational complexity, and can quickly complete data transmission and avoid poor consistency control.

Benefits of technology

It realizes immediate and accurate attack detection, can eliminate data tampered with due to attack in consistency control, ensure stable and consistent control of multi-agent systems, and has low computational complexity, ensuring high real-timeness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484160B_ABST
    Figure CN119484160B_ABST
Patent Text Reader

Abstract

The present invention provides a multi-agent system security consistency control method and system for immediate attack detection; the method uses encoding parameters to encode data containing system status and sends the encoded data to the outside. The agent receiving the data decodes the received encoded data using decoding parameters. The encoding parameters match the decoding parameters, so that the decoded data contains system status information. The decoded data is subjected to a logical operation matching the encoding process; based on whether the logical operation result matches the decoding parameters, it is determined whether the transmission of the encoded data is under attack; the present invention performs encoding and decoding processes with logical operations on the system status information at the transmitting end and the receiving end respectively, so that any changes in the communication data caused by the attack can be discovered in the attack detection, and then an alarm is immediately triggered to prevent the attacked data from affecting the consistency control of the multi-agent system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of multi-agent system consistency control, and specifically relates to a multi-agent system security consistency control method and system for immediate attack detection. Background Art

[0002] A multi-agent system is a system composed of multiple agents with dynamic evolution characteristics. These agents can complete more complex tasks through mutual communication and coordination. The consistency control of a multi-agent system refers to the use of a certain control strategy to enable all agents in the system to reach the same state or behavior mode. Consistency is one of the key conditions for whether a multi-agent system can complete collaborative control tasks. In practical applications, consistency control is of great significance for realizing swarm intelligence, distributed decision-making and collaborative operations.

[0003] Due to the openness of the communication network, the system information transmitted in the communication network in the multi-agent system is extremely vulnerable to network attacks. When the system data transmitted between agents is subject to data injection attacks, the agents will receive false neighbor information, which will eventually lead to the inability of the multi-agent system to achieve consistency goals. Network attacks in industrial control systems first parse the data packet format in the communication network, and then only tamper with the data bits in the data packet to destroy the authenticity of the data, resulting in the failure of traditional attack detection methods based on data verification. The key to achieving the goal of secure consistency control under network attacks is: first, it is necessary to design an effective real-time attack detection algorithm to detect whether the communication data between different agents is attacked; second, the designed attack detection algorithm needs to meet the real-time requirements of consistency control. In particular, although the existing complex data encryption methods can ensure the security of data, the complex data encryption algorithms consume huge computing resources and computing time, resulting in the inability of multi-agent systems with limited computing power to achieve real-time consistency control goals.

[0004] In view of the above problems, from the perspective of the defender, in order to reduce the impact of network attacks on the consistency of multi-agents, it is necessary to first achieve effective attack detection and location, and further jointly design a security consistency controller to achieve the consistency goal of multi-agents. It should be pointed out that the existing methods rarely study the joint design of attack detection algorithms and consistency controllers. Summary of the invention

[0005] In order to solve the problem of security consistency control of multi-agent systems under data injection attacks, the present invention provides a multi-agent system security consistency control method and system for immediate attack detection to achieve the consistency goal of the multi-agent system under data injection attacks.

[0006] In a first aspect, the present invention provides a multi-agent system security consistency control method for immediate attack detection, which comprises the following steps:

[0007] The agent sending the data uses the encoding parameters Contains system status The encoding process includes encoding parameters. System status logical operations.

[0008] The receiving agent uses the decoded parameters The received coded data is decoded to obtain decoded data. Both the encoding and decoding strategies have the characteristics of low computational complexity, which helps to quickly complete data transmission and avoid the situation where the delay in communication and data processing leads to poor consistency control effect.

[0009] Encoding parameters With decoding parameters The encoding parameters are matched so that the decoded data contains system status information. and decoding parameters The values ​​are the same as the system status Random vectors of the same dimension .

[0010] After obtaining the decoded data, real-time verification is performed, and the decoded data is subjected to logical operations that match the encoding process; according to the logical operation results and the decoding parameters Whether the transmission of the coded data matches or not, it is judged whether the transmission of the coded data is attacked; preferably, the logic operation in the encoding and real-time verification link is an XOR operation; further preferably, based on the characteristic that two bitwise XOR operations can restore data, the result of the logic operation should be consistent with the decoding parameter Consistent.

[0011] If attacked, the decoded data is discarded; the decoded data that is not discarded is used to adjust the control input signal of the agent, so that the system state of each agent in the multi-agent system Preferably, the specific measure of discarding the decoded data is: in this round of iteration, the association weight between the two agents involved in the attacked communication is reset to 0; at this time, the decoded data will not be able to affect the output of the consistency control model in this round of iteration.

[0012] Since only simple algebraic and logical operations are required in the encoding and decoding process of the present invention, the required amount of calculation is very small, thereby achieving high real-time encoding and decoding; at the same time, after any part of the transmitted encoded data is tampered with, the corresponding decoded data will show the situation of "the logical operation result does not match the decoding parameter" after the specified logical operation; therefore, any part of the encoded data that has been tampered with can be quickly and accurately discovered, which greatly improves the effectiveness and reliability of attack detection.

[0013] In a second aspect, the present invention provides a multi-agent system safety consistency control system based on immediate attack detection, characterized in that: it is used for the aforementioned multi-agent system safety consistency control method. The multi-agent system safety consistency control system includes an encoding module, a decoding module, an attack detection module and a consistency control module. The encoding module is used to encode the system state sent out by the agent. The decoding module is used to decode the data received by the agent. The attack detection module is used to perform real-time verification of the decoded data to determine whether the communication has been attacked; the consistency control module is used to adjust the control input signal of the robot according to the decoded data that has not been attacked.

[0014] The present invention has the following beneficial effects.

[0015] 1. Realize immediate and accurate attack detection: The present invention performs real-time encoding, decoding and verification processes with logical operations on system status information at the transmitting end and the receiving end, respectively, so that any changes in the communication data caused by the attack can be discovered in the attack detection, and then the data tampered with due to the attack can be excluded in the consistency control. Even if the attacker is fully aware of the data composition of the communication data, it can still ensure that any data tampering can be discovered and excluded; in a complex attack environment, it is guaranteed that the multi-agent system maintains stable consistency control.

[0016] 2. Low computational complexity to ensure high real-time performance: The present invention only needs to perform simple algebraic and logical operations before and after data transmission; therefore, the required amount of computation is very small; therefore, the real-time performance of the consistency control algorithm can be ensured; therefore, while achieving the effectiveness of attack detection, the present invention can also maintain the real-time performance of the control algorithm and ensure the smooth execution of consistency control.

[0017] 3. Realize the safety consistency of multi-agent system: The present invention realizes the immediate attack location and isolation based on accurate and efficient immediate attack detection algorithm, and then designs a safety consistency controller; it dynamically adjusts the association weights between agents through attack detection results, thereby eliminating the impact of attacks on the consistency control of multi-agent system under data injection attacks, and achieving the consistency goal. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1It is a communication topology diagram of the multi-agent system in an embodiment of the present invention.

[0019] Figure 2 3 is an attack detection result diagram under a data injection attack in an embodiment of the present invention.

[0020] Figure 3 This is a diagram showing the security consistency control results of a multi-agent system under a data injection attack in an embodiment of the present invention. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention is further described below in conjunction with the accompanying drawings and engineering examples.

[0022] Example

[0023] like Figure 1 to Figure 3 As shown, a multi-agent system security consistency control method for immediate attack detection includes the following steps:

[0024] Step 1: Construct a discrete multi-agent system as follows:

[0025] Formula (1)

[0026] in, is the number of agents in the multi-agent system; For the Agents in System status at the moment; For the Agents in The control input signal at each moment; is the system step length, which is a constant greater than zero. The consensus goal of the multi-agent system is defined as accomplish In order to achieve the consensus goal of the multi-agent system, the agent sends its own status to its neighboring agents.

[0027] If The agent and There is information exchange between agents, so define The agent and The association weights between agents ; otherwise define The present invention adopts an undirected communication topology graph, that is, .definition , The communication topology diagram of the multi-agent system in this embodiment is as follows: Figure 1 shown.

[0028] In this embodiment, the multi-agent system includes a plurality of mobile robots that are independent of each other. The system state of the agent includes the displacement and speed of the mobile robot. In some other embodiments, the multi-agent system includes a plurality of aircrafts; the aircrafts may be multi-rotor aircrafts. In some other embodiments, the multi-agent system is a power supply system; the power supply system includes a plurality of power supply lines. The system state of the agent includes the voltage and frequency of the power supply lines.

[0029] In some other embodiments, the multi-agent system may also adopt other existing kinematic or dynamic models.

[0030] Step 2: In order to achieve immediate attack detection, this embodiment provides a transcoding communication solution between agents. All agents store the same encoding parameters and decoding parameters .

[0031] In this embodiment, the encoding parameters and decoding parameters The same, equal to a system state Random vectors of the same dimension .

[0032] This embodiment generates encoding parameters before the multi-agent system is put into use. and decoding parameters This problem is solved by storing it in the agent.

[0033] In some other embodiments, a set of pseudo-random numbers with a certain order may be generated in advance. The set of pseudo-random numbers is stored in different agents, and each agent sequentially calls the pseudo-random numbers as encoding parameters at a preset time interval. and decoding parameters , so as to realize the encoding parameters of different agents With decoding parameters While being consistent, the encoding parameters and decoding parameters Dynamic replacement improves communication security.

[0034] The transcoding communication scheme includes an encoding process and a decoding process.

[0035] The encoding process is: through the system status being sent With encoding parameters Calculate and get two coded data and as follows:

[0036] Formula (2)

[0037] in, is the encoding parameter; is the exclusive OR operator; , The two encoded data are obtained by encoding.

[0038] The decoding process is: using decoding parameters For the two received coded data , Decode and get two decoded data , as follows:

[0039] Formula (3)

[0040] in, is the encoding parameter; is the exclusive OR operator; , These are the two decoded data obtained by decoding.

[0041] Decoding the data System status Corresponding; in the case of no attack, decoded data System status Equal. Decoded data As attack identification information.

[0042] In some other embodiments, other logical operations besides XOR operation may be used in the encoding process and the decoding process, as long as it is possible to determine whether the communication process can be attacked through the logical operation after decoding.

[0043] In the encoding and decoding process of this embodiment, only simple addition, subtraction and bitwise XOR operations are performed, and the computational complexity is very low; therefore, the situation of not meeting the real-time requirements of the consistency control algorithm due to long computation time is effectively avoided. In addition, the two XOR operations on the complete data can make any changes in the communication data caused by the attack be discovered in the attack detection, and then exclude the data tampered by the attack in the consistency control. Even if the attacker is fully aware of the data composition of the communication data, it can still ensure that any data tampering can be discovered and excluded.

[0044] Step 3: Each agent encodes its own system state through the encoding process Transcode and get two encoded data and ; Each agent sends its own coded data to other agents according to the communication topology and .

[0045] Step 4: Each agent receives the coded data sent by other agents , After that, two decoded data are obtained through the decoding process , .

[0046] Each agent receives the decoded data , After that, communication attack detection is performed. The process of communication attack detection is as follows:

[0047] Calculate the detection identity vector .

[0048] For the detection identification vector P i (k) and decoding parameters Make a comparison.

[0049] Case 1: If , indicating the encoded data and The data transmission process is not attacked. The principle is that the target vector will restore the initial value after two XOR operations with the same vector.

[0050] Case 2: If , indicating the encoded data and The data transmission process is attacked and an alarm is triggered immediately.

[0051] Step 5. The above-mentioned transcoding-based attack detection method can realize immediate attack detection. In this case, in order to eliminate the impact of data injection attack on consistency control, the agent will determine whether to actively discard the attacked neighbor information based on the attack detection results.

[0052] Specifically, for the i-th agent sending data and the j-th agent receiving data; if the j-th agent receives the data from the i-th agent and triggers an alarm, the associated weight will be Set to 0 and restore the association weight in the next round of communication ;

[0053] At this point, the designed safety consistency controller is as follows:

[0054] Formula (4)

[0055] in, The decoded data obtained by the i-th agent decoding the data from the j-th agent.

[0056] If the system step size in the multi-agent system (1) satisfies , then the safety consistency controller (4) can achieve the consistency goal of the multi-agent system.

[0057] It is worth noting that the status of the multi-agent system is updated in real time, so it will not cause too much harm if some of its data is deciphered and read externally; and the loss of some communication data in some iteration rounds will not cause serious damage to the consistency control of the multi-agent system; therefore, this embodiment can effectively realize the security consistency control of the multi-agent system in a complex attack environment.

[0058] In some other embodiments, the safety consistency controller can also be designed based on other motion controllers, as long as the associated weights adjusted according to the attack detection results are introduced into the other motion controllers. That's it.

[0059] In this embodiment, the system step length of the multi-agent system is set ,The attack detection results under data injection attack are shown in the figure Figure 2 As shown in the figure, the safety consistency control results of the multi-agent system under data injection attack are shown in Figure 3 shown. Figure 2 In part (a), the solid red dots represent attacks, and the blue circles represent no attacks. Figure 2 The red cross in part (b) indicates data that is actively discarded; Figure 2 It can be seen from the figure that the proposed attack detection method can achieve immediate attack detection when an attack occurs. Figure 3 It has been verified that the security consistency controller provided in this embodiment can achieve the consistency goal of the multi-agent system when it is attacked by communication by detecting attacks in real time and discarding the attacked data.

[0060] The above describes the good effect of the present invention in the consistency control problem of multi-agent systems. It should be pointed out that the present invention is not limited to the above situation, and based on the method of the present invention, it can be applied to attack detection problems of other industrial control systems with slight improvements.

Claims

1. A multi-agent system security consistency control method with immediate attack detection, characterized by: The following steps are involved: The agent sending the data uses the encoding parameters Contains system status The data is encoded in real time to obtain encoded data, and the encoded data is sent out; The real-time encoding process includes encoding parameters System status Logical operations of The receiving agent uses the decoded parameters Decoding the received coded data in real time to obtain decoded data; The real-time encoding process is: through the system status being sent With encoding parameters Calculate and get two coded data , as follows: ; The real-time decoding process is: using decoding parameters For the two received coded data and Decode and get two decoded data , as follows: ; Decoding the data as the received system status; Encoding parameters With decoding parameters Matching, so that the decoded data contains the system status; Perform real-time verification on the decoded data; the real-time verification includes logical operations that match the real-time encoding process; based on the real-time verification results, determine whether the transmission of the encoded data is under attack; if under attack, discard the decoded data; use the decoded data that is not discarded to adjust the control input signal of the intelligent agent; The real-time verification process is as follows: Calculate the detection identification vector ;like , it is judged that the coded data has not been attacked during the data transmission process; otherwise, it is judged that the coded data has been attacked during the data transmission process; The multi-agent system communicates based on an undirected communication topology graph; Introducing correlated weights in a consensus control model for multi-agent systems to obtain agent input signals ; If there is communication between two agents and it is determined that the data transmission process is not attacked, the association weight between the two agents is set ; Otherwise, set the association weight between the two agents ; The discrete multi-agent system is constructed as follows: ; Where n is the number of agents; For the The system state of each agent at time k+1; For the Agents in System status at the moment; For the Agents in The control input signal at each moment; is the system step length; The expression of the consensus control model of the multi-agent system is as follows: ; in, For the The decoded data obtained by the agent decoding the data from the jth agent; For the The control input signal of each agent; The system step size in the multi-agent system satisfy conditions; ; ; The system state of the agent includes the displacement and velocity of the mobile robot.

2. The method for controlling the security consistency of a multi-agent system with immediate attack detection according to claim 1, characterized in that: The encoding parameters and decoding parameters The values ​​are the same as the system status Random vectors of the same dimension .

3. The method for controlling the security consistency of a multi-agent system with immediate attack detection according to claim 1, characterized in that: The logical operation in the real-time encoding and real-time verification process is an exclusive OR operation.

4. A multi-agent system security consistency control system with immediate attack detection, characterized by: Used to execute the multi-agent system security consistency control method as claimed in claim 1; the multi-agent system security consistency control system includes an encoding module, a decoding module, an attack detection module and a consistency control module; the encoding module is used to encode the system state sent out by the agent; the decoding module is used to decode the data received by the agent; the attack detection module is used to perform real-time verification of the decoded data to determine whether the communication is attacked; The consistency control module is used to adjust the control input signal of the robot according to the decoded data that has not been attacked.