Trust evaluation method for human-computer interaction in intelligent navigation of inland ship controlled by shore-based control

By establishing a multi-dimensional trust index system and real-time dynamic trust calculation method, the problem that traditional trust evaluation methods fail to consider changes in dynamic environment and system state is solved, and the safety and stability of ship navigation are improved.

CN119578903BActive Publication Date: 2025-05-23ANHUI UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510131568.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-23
Estimated Expiration
2045-02-06

AI Technical Summary

Technical Problem

In traditional ship control systems, the communication security between the ship and the shore base is relatively weak, with potential trust loopholes, and the existing trust evaluation methods fail to fully consider changes in the dynamic environment and system state, resulting in the failure or inaccuracy of trust evaluation.

Method used

A human-computer interactive trust assessment method for intelligent navigation of inland ships based on shore-based driving is proposed. By establishing a multi-dimensional trust index system, including behavioral credibility, identity credibility, environmental credibility and historical credibility, the fuzzy comprehensive evaluation method is used to determine the weight of each indicator. This method calculates the trust value of the interactive node through multi-source fusion data, introduces a time decay factor, and dynamically updates the trust value in real time to reflect the changes in interaction behavior.

Benefits of technology

It improves the safety and stability of the ship's navigation process, especially in a complex and dynamic navigation environment, it can effectively respond to the dynamic changing environment and ship status during inland navigation, eliminate safety hazards in communication and operation between the ship and the shore base, and provide timely response and correction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119578903B_ABST
    Figure CN119578903B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of ship automation control and intelligent transportation system, and solves the technical problem that traditional trust assessment methods fail to fully consider the changes in dynamic environment and system status, resulting in invalid or inaccurate trust assessment. In particular, it relates to a human-computer interaction trust assessment method for intelligent navigation of shore-based inland ship control, which aims to improve the interaction security and system stability between the ship and the shore-based control center through dynamic trust calculation and risk assessment mechanism. It is specifically divided into four parts: trust indicator system construction, data collection and preprocessing, dynamic trust calculation, and risk assessment and response. The present invention dynamically evaluates and manages the trust of human-computer interaction in the intelligent navigation of inland ships through a zero-trust framework, aiming to improve the safety and stability of the ship during navigation, especially in a complex and dynamic navigation environment, to conduct a trust evaluation on the interaction between the shore and the ship, thereby ensuring the safety and reliability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of ship automation control technology, intelligent transportation system and information security technology, and in particular to a human-computer interaction trust assessment method for intelligent navigation of a shore-based inland ship. Background Art

[0002] With the rapid development of information technology and automation technology, ship navigation control systems are gradually developing towards intelligence and automation, especially in inland navigation, where intelligent navigation technology has begun to be widely used. Modern inland ships usually rely on shore-based control systems for remote operation and control to improve navigation efficiency and safety. Intelligent navigation systems integrate sensors, automatic control technology, data communication, and artificial intelligence to achieve autonomous navigation and obstacle avoidance decisions for ships, thereby reducing human operational errors and improving navigation safety. However, the safety and reliability of such systems and the interactive trust between ships and shore-based control centers are still technical problems that need to be solved urgently.

[0003] In traditional ship control systems, the communication security between ships and shore-based systems is relatively weak, with potential trust loopholes, and is vulnerable to cyber attacks or changes in the external environment. In the remote collaboration between ships and shore-based systems, if the trust assessment mechanism is not perfect, it may lead to the issuance or response of incorrect instructions, thus affecting navigation safety. In addition, the level of intelligence of ship operations and the requirements for environmental adaptability are increasing. Most of the existing trust assessment methods are based on static trust models, which fail to fully consider the changes in dynamic environment and system status, resulting in invalid or inaccurate trust assessment. Summary of the invention

[0004] In view of the shortcomings of the prior art, the present invention provides a human-computer interaction trust assessment method for intelligent navigation of inland vessels controlled by shore-based control, which solves the technical problem that traditional trust assessment methods fail to fully consider changes in dynamic environment and system status, resulting in invalid or inaccurate trust assessment.

[0005] In order to solve the above technical problems, the present invention provides the following technical solutions: a human-computer interaction trust evaluation method for intelligent navigation of shore-based inland ship control, the method comprising the following steps:

[0006] Establish a multi-dimensional trust index system for ships' intelligent navigation in inland waterway environments. The trust index system includes behavioral credibility, identity credibility, environmental credibility, and historical credibility. The weight of each indicator in the trust index system is determined by fuzzy comprehensive evaluation method.

[0007] Acquire raw data of intelligent navigation of ships in inland waterway environments, and pre-process the raw data to obtain multi-source fusion data with the same scale, wherein the raw data includes inland ship sensor data, driver behavior data, and shore-based control center data;

[0008] Under the trust index system, the trust value of each interactive node is calculated based on multi-source fusion data, and the time decay factor is introduced to dynamically update the trust value in real time to reflect the changes in the interactive behavior between each interactive node;

[0009] Conduct risk assessment on each interactive node based on the trust value, predict potential risks based on the equilibrium solution of the attack and defense game model, and provide an automated response strategy based on the assessment results.

[0010] Furthermore, the credibility of the behavior Used to evaluate whether the behavior of subject j at time t is in line with expectations and the credibility of the behavior The calculation formula is:

[0011] ;

[0012] in, is the penalty coefficient for the violation; The degree of behavioral matching; is the frequency of violations;

[0013] The identity is trustworthy It is used to reflect the credibility of the subject j’s identity in the current interaction. The expression is:

[0014] ;

[0015] in, is the historical identity verification reliability of subject j; is the weight coefficient, ; is the authentication model of subject j at time t ;

[0016] The credibility of the environment Used to measure the adaptability of ship and shore-based operating environments. The calculation formula of environmental credibility is:

[0017] ;

[0018] ;

[0019] in, is the weight of environmental factors; is the fuzzy membership function; is the ideal value of the environmental factor k; is the standard deviation; is the number of environmental factors k;

[0020] The historical credibility Used to measure the trust accumulation and historical credibility between subject j and subject i The calculation formula is:

[0021] ;

[0022] in, For the moment Trust value; is the attenuation factor, ; is the upper limit of the time span of historical interactions considered when calculating historical credibility, i.e., the number of time periods looking back into the past; It is a time index variable used to traverse from 1 to The time step;

[0023] Define the fuzzy evaluation matrix , and the fuzzy comprehensive evaluation method is used to determine the weight of each indicator, the fuzzy evaluation matrix The expression is:

[0024] ;

[0025] In the formula, They are the weight coefficients of behavioral credibility, identity credibility, environmental credibility, and historical credibility respectively.

[0026] Furthermore, the credibility of the behavior It includes the behavior matching degree used to measure the degree to which the subject j's current behavior matches the expected behavior , and the frequency of violations used to count whether subject j has violated regulations or abnormal behaviors , where the behavior matching degree The calculation formula is:

[0027] ;

[0028] in, is the cosine similarity, which indicates the similarity between the current behavior and the expected behavior; is the feature vector of the kth behavior; is the expected behavior feature vector; is the number of behaviors of subject j;

[0029] Frequency of violations The calculation formula is:

[0030] ;

[0031] in, Expressing behavior It is against the rules; For violations The penalty weight of is the number of violations or abnormal behaviors of subject j.

[0032] Furthermore, the preprocessing of the original data to obtain multi-source fusion data with the same scale specifically includes:

[0033] The original data is denoised and the denoised original data is standardized to a uniform scale. The denoising process includes weighted moving average denoising and low-pass filtering, wherein:

[0034] The expression of weighted moving average denoising is:

[0035] ;

[0036] in, is the original data after denoising; is the weight coefficient; m is the window size; Indicates at time The original data collected;

[0037] The expression of low-pass filtering is:

[0038] ;

[0039] in, is the original data after filtering; is the time constant of the filter; is the original data of the input filter;

[0040] Anomaly detection is performed on raw data with a uniform scale, and the weighted average of adjacent data points is used to fill in missing or abnormal data;

[0041] Fusion of the original data after anomaly detection to obtain multi-source fusion data , the expression is:

[0042] ;

[0043] in, For data source The weight of For data source number; For the A signal from a data source.

[0044] Furthermore, the trust value of each interactive node is calculated based on the multi-source fusion data, and a time decay factor is introduced to dynamically update the trust value in real time. The specific process includes:

[0045] Construct a Bayesian network consisting of N interactive nodes, where the interactive nodes are connected by conditional dependencies. Each interactive node represents an interactive entity, including a ship, a driver, and a shore-based control center, and the edge represents the trust dependency between the interactive nodes.

[0046] The graph structure of the Bayesian network is:

[0047] ;

[0048] in, represents all interaction nodes; E represents the edge between interaction nodes, i.e., trust dependency relationship;

[0049] The conditional dependency between interaction nodes is expressed as:

[0050] ;

[0051] in, It is an interactive node Conditional probability distribution given the parent node; It is an interactive node The parent node set of

[0052] According to the interaction node Behavioral credibility , Identity Credibility , historical credibility , Environmental Credibility , calculate the interaction nodes At the moment Trust value ,Right now:

[0053] ;

[0054] in, is the weight coefficient, and ;

[0055] Introducing a time decay factor to determine the trust value of time The influence of is expressed as:

[0056] ;

[0057] in, is the time decay factor, indicating the degree of decay of the trust value over time; represents the exponential weight of the time decay factor;

[0058] Dynamically update trust value .

[0059] Furthermore, the dynamically updated trust value The specific process includes:

[0060] Initial trust value calculation: based on the initial behavior credibility , Identity Credibility , historical credibility , Environmental Credibility Calculate the initial trust value of each interaction node;

[0061] Real-time trust value update: As the interaction between the ship and the shore changes, new interaction data will be collected in real time, including new behavior logs, environmental data, and control instructions, and the initial trust value will be updated in real time based on the Bayesian network structure and time decay factor;

[0062] Trust value correction: When the trust value of any interactive node changes abnormally and the behavior does not meet expectations, the trust value will be corrected, and the corresponding conditional probability distribution in the Bayesian network will be updated to ensure that the calculation of the trust value accurately reflects the actual behavior of the interactive node;

[0063] Adaptive weight adjustment: Based on real-time interaction data, the weight of the trust value is adjusted according to different scenarios.

[0064] Furthermore, the risk assessment of each interactive node is performed based on the trust value, the potential risk is predicted in combination with the equilibrium solution of the attack and defense game model, and an automated response strategy is provided based on the assessment results. The specific process includes:

[0065] Calculate the abnormality of the interaction node behavior , the calculation formula is:

[0066] ;

[0067] in, For interactive nodes Historical Behavior The mean of For interactive nodes Historical Behavior The standard deviation of For current behavior;

[0068] According to abnormality A risk assessment model is established to assess the risk value of interactive nodes. The expression is:

[0069] ;

[0070] in, For interactive nodes Value at risk at time t; For interactive nodes Trust value; is the abnormality of the interaction node behavior, indicating the degree to which the behavior of the interaction node deviates from expectations; is the weight of the interaction node;

[0071] Value at Risk Standardization is performed to obtain a risk assessment value between 0 and 1 , the standardized formula is:

[0072] ;

[0073] in, , are the maximum risk value and the minimum risk value respectively;

[0074] Risk Assessment Value Minimization is the goal to establish the equilibrium solution of the attack and defense game model, the expression is:

[0075] ;

[0076] ;

[0077] in, , They are respectively the attacker strategy and defender strategy in the attack and defense game model; , are the payoff functions of the attacker strategy and the defender strategy respectively; is the attacker's profit function, which represents the attacker's profit from executing a certain attack strategy; is the defender’s profit function, which represents the defender’s profit from executing a certain defense strategy;

[0078] The best defense strategy is identified by solving the equilibrium solution of the attack and defense game model, and risk responses are made accordingly, including restricting permissions, isolating risk nodes, and triggering manual review, namely:

[0079] The expression for restricting permissions is:

[0080] ;

[0081] Among them, θ is the threshold;

[0082] The expression for isolating risk nodes is:

[0083] ;

[0084] in, Risk threshold for quarantine;

[0085] The expression triggered by manual review is:

[0086] ;

[0087] in, The threshold range for manual review.

[0088] By means of the above technical solution, the present invention provides a human-computer interaction trust assessment method for intelligent navigation of shore-based inland ship control, which has at least the following beneficial effects:

[0089] 1. The present invention dynamically evaluates and manages the trust of human-computer interaction in the intelligent navigation of inland vessels through a zero-trust framework, aiming to improve the safety and stability of ships during navigation, especially in complex and dynamic navigation environments, to evaluate the trust of the interaction between shore-based and ships, thereby ensuring the safety and reliability of the system.

[0090] 2. The present invention can effectively cope with the dynamically changing environment and ship status during inland navigation, and update the trust evaluation in real time, enhancing the comprehensive consideration of the complex and dynamic navigation environment and ship behavior. At the same time, the trust value is dynamically adjusted according to the real-time interaction between the ship and the shore-based control center, eliminating the potential safety hazards in the communication and operation between the ship and the shore, and providing timely response and correction when facing malicious attacks or inconsistent data.

[0091] 3. The present invention can add effective trust verification and security control mechanisms during the communication process between the ship and the shore-based control system, thereby eliminating the impact of external attacks, data tampering or misoperation, and improving the stability of the system and navigation safety. At the same time, multi-source data is fully integrated in the trust evaluation process, so as to accurately reflect the real situation of the interaction between the ship and the shore, and effectively identify and handle abnormal behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0092] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0093] Figure 1 It is a principle block diagram of the human-computer interaction trust evaluation method in the present invention;

[0094] Figure 2 It is a principle block diagram of the shore-based driving control system in the present invention;

[0095] Figure 3This is a principle block diagram of the inland river vessel intelligent navigation system of the present invention;

[0096] Figure 4 This is a principle block diagram of the zero-trust architecture in the present invention. DETAILED DESCRIPTION

[0097] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific implementation methods, so that the implementation process of how the present application uses technical means to solve technical problems and achieve technical effects can be fully understood and implemented accordingly.

[0098] With the support of zero-trust architecture, the interactive trust between ships and shore-based systems can be based on dynamic evaluation rather than static trust models. Zero-trust architecture emphasizes the principle of "never trust, always verify", and all communications and interactions must be continuously verified even in internal networks. This trust calculation method is suitable for modern intelligent systems, especially in distributed and dynamic environments, and can effectively prevent system security issues caused by trust defects. However, in actual application, there are still the following shortcomings:

[0099] 1. Static problem of trust assessment model: Most existing trust assessment methods rely on static trust models and cannot effectively cope with the dynamically changing environment and ship status during inland navigation. Trust assessment in existing technologies fails to update in real time and lacks comprehensive consideration of complex and dynamic navigation environments (such as water flow, weather changes, network delays, etc.) and ship behavior.

[0100] 2. Lack of real-time and dynamic trust calculation: Existing technologies cannot dynamically adjust the trust value based on the real-time interaction between the ship and the shore-based control center. There are security risks in the communication and operation between the ship and the shore. When faced with malicious attacks or inconsistent data, the existing trust evaluation mechanism is difficult to provide timely response and correction.

[0101] 3. Insufficient information security: The existing intelligent navigation system lacks effective trust verification and security control mechanisms during the communication process between ships and shore-based systems. It is vulnerable to external attacks, data tampering or misoperation, affecting the stability of the system and navigation safety.

[0102] 4. Insufficient comprehensive analysis of multi-source data: Existing technologies fail to fully integrate multi-source data, such as sensor data, environmental factors, historical behavior records, etc., during the trust assessment process, resulting in the inability of trust assessment to accurately reflect the actual interaction between ships and shore-based systems, and the lack of effective identification and processing of abnormal behaviors.

[0103] Therefore, this embodiment proposes a solution to the defects and deficiencies in the prior art. Figure 1This embodiment proposes a trust evaluation method for human-machine interaction of shore-based inland ship intelligent navigation, which aims to improve the interaction security and system stability between the ship and the shore-based control center through dynamic trust calculation and risk assessment mechanism. It is specifically divided into four parts: trust indicator system construction, data collection and preprocessing, dynamic trust calculation and risk assessment and response. The method includes the following steps:

[0104] S1. Establish a multi-dimensional trust index system for intelligent navigation of ships in inland waterway environments. The trust index system includes behavioral credibility, identity credibility, environmental credibility and historical credibility, and the weight of each indicator in the trust index system is determined by fuzzy comprehensive evaluation method.

[0105] In this embodiment, the behavior credibility It is used to evaluate whether the behavior of subject j at time t is in line with expectations, where the behavior credibility Whether the behavior of subject j at time t is in line with expectations is an important dimension of trust assessment. Behavioral credibility mainly consists of the following two parts:

[0106] 1. Behavior matching: measures the matching degree between the current behavior of subject j and the expected behavior. Assume that the behavior dataset is ,in is the feature vector of the kth behavior, and is the expected behavior feature vector.

[0107] The calculation formula for behavior matching is:

[0108] ;

[0109] in, is the cosine similarity, which indicates the similarity between the current behavior and the expected behavior.

[0110] Frequency of Illegal Behavior: Count whether subject j has violated regulations or abnormal behavior. Set up abnormal behavior detection model , detect each behavior and output whether it is a violation. If a violation is detected, a weighted penalty is imposed on it.

[0111] Violation frequency calculation formula:

[0112] ;

[0113] in, Expressing behavior It is against the rules; For violations The penalty weight.

[0114] Specifically, combined with behavioral matching and frequency of violations , then the behavior credibility The calculation formula is:

[0115] ;

[0116] in, is the penalty coefficient for violations.

[0117] In this embodiment, the identity credibility It is used to reflect the trustworthiness of the subject j’s identity in the current interaction. Identity trustworthiness is usually calculated based on the subject’s authentication information, authorization status, and historical authentication records. Assume there is an authentication model , it can be evaluated whether subject j has a legal identity.

[0118] The formula for calculating identity credibility is:

[0119] ;

[0120] If the authentication is successful, ,otherwise In addition, corrections can be made based on historical authentication records, taking into account the stability of identity authentication:

[0121] ;

[0122] in, is the historical identity verification reliability of subject j; is the weight coefficient, ; is the authentication model of subject j at time t .

[0123] In this embodiment, the environmental credibility Used to measure the adaptability of the ship and shore-based operating environment. In intelligent navigation, environmental factors (such as water current, weather, channel congestion, sensor errors, etc.) will affect the stability and safety of the system.

[0124] Assuming environmental factors is a multidimensional environmental vector, representing multiple environmental parameters (water flow rate, wind speed, weather conditions, etc.). Fuzzy logic method is used to evaluate the adaptability of the environment, through the membership function To represent the impact of each environmental factor on trust.

[0125] The calculation formula of environmental credibility is:

[0126] ;

[0127] in, is the weight of environmental factors; is the fuzzy membership function, defined as:

[0128] ;

[0129] in, is the ideal value of the environmental factor k; is the standard deviation.

[0130] In this embodiment, historical credibility It is used to measure the trust accumulation of historical interactions between subject j and subject i. This indicator is based on the past trust records between subjects and combines the time decay model to calculate the historical trust. The calculation formula is:

[0131] ;

[0132] in, For the moment Trust value; is the attenuation factor, , which determines the extent to which historical trust affects current trust; is the upper limit of the time span of historical interactions considered when calculating historical credibility, i.e., the number of time periods looking back into the past; It is a time index variable used to traverse from 1 to time step.

[0133] In the multi-dimensional trust index system, each index (behavior credibility, identity credibility, environmental credibility, and historical credibility) contributes differently to the overall trust value. Assume that the weight coefficients of behavior credibility, identity credibility, environmental credibility, and historical credibility are ,and .

[0134] In order to comprehensively consider the impact of these indicators, we first define the fuzzy evaluation matrix , and the fuzzy comprehensive evaluation method is used to determine the weight of each indicator, the fuzzy evaluation matrix The expression is:

[0135] ;

[0136] In practical applications, the weight coefficient can be determined according to the specific situation through fuzzy comprehensive evaluation method or other appropriate methods. In some scenarios where the safety requirements of behavior are extremely high, the weight of behavior credibility will be appropriately increased. ; When focusing on the stability of long-term cooperation, the weight of historical credibility These weight coefficients will be used in subsequent trust calculations to ensure the balance of each trust dimension in the final evaluation.

[0137] S2. Obtain the raw data of the ship's intelligent navigation in the inland waterway environment, and pre-process the raw data to obtain multi-source fusion data with the same scale. The goal of this step is to collect relevant data from multiple data sources such as inland ship sensors, driver behavior records, and shore-based control centers, and ensure the high quality of input data through data preprocessing (including denoising, standardization, and anomaly detection), providing an accurate basis for subsequent trust assessment and decision-making.

[0138] In this embodiment, data is collected from various sensors of inland vessels (such as GPS, radar, gyroscope, wind speed sensor, etc.), driver's behavior records (such as operation logs, manual instructions, etc.), and communication and control information of the shore-based control center (such as navigation instructions, real-time monitoring data, etc.). Specifically, the original data includes inland vessel sensor data, driver behavior data, and shore-based control center data.

[0139] Inland ship sensor data: including the ship's heading, speed, acceleration, sensor status, environmental data (such as water flow, weather, etc.). The data format is: timestamp t, location ,speed , acceleration , heading angle , Environmental factors .

[0140] Driver behavior data: including driver manual intervention records, operating habits, instruction history, decision-making process, etc. The data format is: timestamp t, instruction type , Operation behavior mark , intervention records .

[0141] Data from the shore-based control center: including remote control commands issued by the shore-based center, environmental monitoring data, real-time communication logs, etc. The data format is: timestamp t, command type , control instruction parameters , Network communication status .

[0142] These data are uploaded to the data processing system in real time via wireless network, satellite communication or other appropriate transmission methods.

[0143] After data collection, the raw data may contain noise, missing values ​​or outliers, and data preprocessing is required to ensure data quality. The preprocessing process includes denoising, standardization and anomaly detection.

[0144] First, denoising is performed. Due to the complex inland navigation environment, sensor data (such as GPS position, acceleration, environmental data, etc.) are often interfered by noise. In order to improve the accuracy and stability of the data, the following denoising method is needed.

[0145] 1. Weighted moving average method: Use the weighted moving average method to smooth the sensor data and remove high-frequency noise. Assume that the data collected at time t is , through the sliding window W rows weighted average, get the denoised data :

[0146] ;

[0147] in, is the weight coefficient, usually a symmetric Gaussian function (or other suitable weighting function), and m is the window size.

[0148] 2. Low-pass filtering: For higher frequency noise, a low-pass filter can be used to remove noise. The filtered signal It is given by the following formula:

[0149] The expression of low-pass filtering is:

[0150] ;

[0151] in, is the time constant of the filter.

[0152] Then the data is standardized. The purpose of standardization is to convert data from different sources into a unified scale to make them comparable. For example, the dimensions of ship speed, acceleration, environmental factors, etc. are different. Standardization can eliminate such differences. The specific methods include the following:

[0153] 1. Z-score standardization: for each data point Standardize and get the standardized original data , the standardized formula is as follows:

[0154] ;

[0155] in, is the mean of the original data x, is the standard deviation. The original data after standardization It will have a mean of 0 and a standard deviation of 1, which is suitable for data fusion and subsequent analysis of different dimensions.

[0156] 2. Min-Max normalization: Scale the original data to the [0, 1] interval. You can use the following formula:

[0157] ;

[0158] This normalization approach is particularly suitable for application scenarios where you need to ensure that data is within a fixed range.

[0159] Next, anomaly detection is performed. In practical applications, factors such as sensor failure and environmental interference may cause abnormal values ​​in the data. The purpose of anomaly detection is to automatically identify and mark these abnormal data for subsequent processing.

[0160] Detect outliers by using statistical methods such as mean and standard deviation. If the value is too different from the surrounding data points, it is considered an outlier. , the standard deviation is , if a data point meets the following conditions, it is an outlier, that is:

[0161] ;

[0162] in, is a constant representing the abnormal threshold.

[0163] For detected outliers, they can be replaced using interpolation or sliding window methods, using the weighted average of adjacent data points to fill in missing or abnormal data.

[0164] After denoising, standardization and anomaly detection, data from different data sources need to be fused and integrated. Data fusion can be done by weighted averaging or Bayesian inference.

[0165] Assume there are signals from multiple data sources ,in is the signal from the i-th data source (such as sensor, driver behavior, shore-based control, etc.). The fused signal can be obtained by weighted average method:

[0166] ;

[0167] in, For data source The weight can be determined based on factors such as the reliability of the signal and the importance of the source.

[0168] The preprocessed data will include the following aspects:

[0169] 1. Denoised data: Sensor data, driver behavior records, environmental monitoring data, etc. are denoised to obtain smooth time series data.

[0170] 2. Standardized data: All data are standardized to the same scale for further analysis and trust assessment.

[0171] 3. Data after outlier processing: Mark, replace or remove abnormal data to ensure the quality and stability of the data set.

[0172] 4. Fusion of multi-source data: Various data sources are fused to form a unified data set, providing accurate and reliable data support for subsequent modules.

[0173] S3. Under the trust indicator system, the trust value of each interactive node is calculated based on multi-source fusion data, and a time decay factor is introduced to dynamically update the trust value in real time to reflect the changes in the interactive behavior between each interactive node.

[0174] Bayesian network is a graphical model that can effectively represent and calculate uncertainty. In the present invention, Bayesian network is used to represent the trust relationship between interactive nodes and calculate the trust value of each node. Each interactive node represents an interactive entity (such as a ship, a driver, a shore-based control center, etc.), and the edge represents the trust dependency relationship between the interactive nodes.

[0175] Assuming that there are N interactive nodes in the system, the trust value of each interactive node can be determined by multiple influencing factors such as behavior credibility, identity credibility, historical credibility, etc. This embodiment constructs a Bayesian network composed of N interactive nodes, in which the interactive nodes are connected through conditional dependencies.

[0176] The graph structure of the Bayesian network is:

[0177] ;

[0178] in, represents all interaction nodes; E represents the edges between interaction nodes, that is, the trust dependency relationship.

[0179] Each interactive node With a conditional probability distribution ,in It is an interactive node The parent node set of represents its influencing factors. The conditional dependency relationship between the interaction nodes is expressed as:

[0180] ;

[0181] in, It is an interactive node Conditional probability given the parent node.

[0182] Trust value calculation depends on the state of the interaction nodes in the Bayesian network and their interdependencies. At each time t, the trust value of each interaction node is Determined by its dependent factors (such as behavior credibility, identity credibility, historical credibility, etc.). Assuming the trust value The calculation of depends on the following main factors: Behavior credibility , Identity Credibility , historical credibility , Environmental Credibility ;

[0183] Then the trust value of each interaction node It can be expressed as a weighted sum of these factors:

[0184] ;

[0185] in, is the weight coefficient, satisfying:

[0186] ;

[0187] These weights can be dynamically adjusted according to specific circumstances through fuzzy comprehensive evaluation or other methods.

[0188] To make the trust value The calculation of can reflect the changes of interactive behavior in real time, and it is necessary to introduce a time decay factor to consider the effect of time on trust value. As time goes by, the old interaction information has an impact on the trust value. The influence of will gradually weaken. The introduction of time decay factor can be achieved through the following formula, namely:

[0189] Introducing a time decay factor to determine the trust value of time The influence of is expressed as:

[0190] ;

[0191] in, is the time decay factor, indicating the degree of decay of the trust value over time; An exponential weight representing the time decay factor.

[0192] By introducing the time decay factor, we can ensure that the trust value reflects new interactive behaviors and environmental changes in a timely manner during real-time changes.

[0193] Dynamically update trust value It is one of the cores of this embodiment. The dynamic update of the trust value is mainly achieved through the following steps:

[0194] Initial trust value calculation: based on the initial behavior credibility , Identity Credibility , historical credibility , Environmental Credibility Calculate the initial trust value of each interactive node. That is, when the system is initialized, the initial trust value of each interactive node is calculated through the Bayesian network structure and the initial trust indicators of each interactive node (such as initial behavior credibility, identity credibility, etc.).

[0195] Real-time trust value update: As the interaction between the ship and the shore changes, new interaction data (such as new behavior logs, environmental data, control instructions, etc.) will be collected in real time, and the initial trust value will be updated in real time based on the Bayesian network structure and time decay factor.

[0196] Trust value correction: When the trust value of any interactive node changes abnormally and the behavior does not meet expectations, the trust value will be corrected, and the corresponding conditional probability distribution in the Bayesian network will be updated to ensure that the calculation of the trust value accurately reflects the actual behavior of the interactive node.

[0197] Adaptive weight adjustment: Based on real-time interaction data, the weight of the trust value is adjusted according to different situations. At certain critical moments (such as when a ship is in emergency shelter), the credibility of the behavior may be more important than other indicators, so the weight can be adjusted dynamically.

[0198] S4. Conduct risk assessment on each interactive node based on the trust value, predict potential risks based on the equilibrium solution of the attack and defense game model, and provide an automated response strategy based on the assessment results. The goal of this step is to conduct risk assessment on interactive nodes with low trust values, predict potential risks based on the attack and defense game model, and provide an automated response strategy based on the assessment results, such as restricting permissions, isolating risky nodes, or triggering manual review. Through dynamic assessment and response mechanisms, ensure that the system can effectively prevent potential security risks and enhance the system's anti-attack and adaptive capabilities.

[0199] The purpose of risk assessment is to identify potential risk nodes in the system through trust value analysis and assess the risk they may bring. Risk identification based on low trust value nodes can help the system respond in a timely manner. To this end, this embodiment will combine the following key factors to conduct risk assessment:

[0200] Node trust value: the trust value of each interactive node .

[0201] Node importance: Different weights are assigned to interaction nodes according to their importance and role in the system.

[0202] Node behavior abnormality: Calculates whether the behavior of the interactive node deviates from the normal mode. The greater the deviation, the higher the risk.

[0203] Assume that each interacting node in the system Trust value It has been obtained through step S3. According to the trust and abnormality of the low trust value node, the risk assessment formula is defined as follows:

[0204] ;

[0205] in, For interactive nodes Value at risk at time t; For interactive nodes Trust value; is the abnormality of the interaction node behavior, indicating the degree to which the behavior of the interaction node deviates from expectations; is the weight of the interaction node, indicating the importance of the interaction node in the system. For example, the importance of a ship may be higher than that of a shore-based control center.

[0206] Abnormality of interaction node behavior It can be calculated by comparing the current behavior of the node with its historical behavior pattern. Assume that the historical behavior pattern is , the current behavior is , we can calculate the deviation of the behavior (such as standard deviation or mean square error) to measure the degree of abnormality:

[0207] ;

[0208] in, For interactive nodes The mean of historical behavior; For interactive nodes The standard deviation of historical behavior. The greater the abnormality, the more the node's behavior deviates from the normal mode, and the higher the risk value.

[0209] To facilitate comparison and decision making, the risk value Should be standardized. Assuming the maximum risk value and minimum risk value If it is known, the risk value can be standardized as:

[0210] ;

[0211] Standardized risk assessment value Between 0 and 1, it is convenient for the subsequent response strategy application.

[0212] In order to more accurately assess potential risks and attack paths, the attack-defense game model can be combined to predict risks. The attack-defense game model can identify potential attacks and defense strategies in a dynamic environment by simulating the game between attackers and defenders.

[0213] In the attack-defense game model, the defender of the system attempts to resist attackers by adjusting node trust, authority control, etc., while the attacker attacks the system by reducing node trust or performing malicious actions.

[0214] Defender strategies include controlling permissions, isolating risky nodes, strengthening identity verification, triggering manual review, etc. Attacker strategies include reducing trust values, forging identities, tampering with data, simulating normal behavior, etc. The goal of the game is to find an optimal strategy combination to minimize the risk of the system.

[0215] Assume that the attacker's strategy and the defender's strategy are and , and their revenue functions are and .

[0216] In this embodiment, the risk assessment value Minimization is the goal to establish the equilibrium solution of the attack and defense game model, the expression is:

[0217] ;

[0218] ;

[0219] in, is the attacker's profit function, which represents the attacker's profit from executing a certain attack strategy; is the defender’s profit function, which represents the defender’s profit from executing a certain defense strategy.

[0220] The best defense strategy is identified by solving the equilibrium solution of the attack and defense game model, and risk responses are made accordingly, including restricting permissions, isolating risk nodes, and triggering manual review, namely:

[0221] When the risk assessment value of a certain interaction node When the trust value is greater than the set threshold, the system can automatically limit the node's permissions and reduce its access to key resources or decisions. If the trust value of a ship is too low, its communication or control authority with the shore-based control center can be restricted.

[0222] The expression for restricting permissions is:

[0223] ;

[0224] Among them, θ is the threshold.

[0225] For high-risk interaction nodes, isolation measures can be taken to physically or logically isolate them from other critical parts of the system to prevent the spread of potential risks.

[0226] The expression for isolating risk nodes is:

[0227] ;

[0228] in, The risk threshold for quarantine.

[0229] When the risk assessment value approaches a certain critical value, the system can trigger a manual review to further confirm whether the risk actually exists.

[0230] The expression triggered by manual review is:

[0231] ;

[0232] in, The threshold range for manual review.

[0233] This embodiment uses a zero-trust framework to dynamically evaluate and manage the trust of human-computer interaction in the intelligent navigation of inland vessels, aiming to improve the safety and stability of ships during navigation, especially in complex and dynamic navigation environments, to conduct trust evaluation on the interaction between shore-based and ships, thereby ensuring the safety and reliability of the system.

[0234] Please refer to Figure 2-Figure 4 This embodiment also provides a human-computer interaction trust evaluation system, which consists of a shore-based driving control system, an inland ship intelligent navigation system, and a zero-trust architecture. The shore-based driving control system realizes the linkage between the shore-based driving control center and the ships in the inland waterway, and is used for command, monitoring, calculation and decision support in the autonomous navigation of ships; the inland ship intelligent navigation system is used to realize autonomous navigation, real-time monitoring and remote interactive control of ships in inland waterways; the zero-trust architecture is a trust mechanism between the inland ship intelligent navigation system and the shore-based driving control system, which ensures the security and reliability of the interaction between the entities through dynamic trust evaluation and continuous verification mechanism.

[0235] Figure 2 The figure shows the principle block diagram of the shore-based control system. As an important part of the intelligent navigation system of inland vessels, the shore-based control system mainly undertakes the functions of command, monitoring, calculation, and decision support. The core of the shore-based control system includes data acquisition unit, data processing unit, information interaction unit, decision support unit, and human-computer interaction terminal. These modules work together to achieve efficient linkage between the shore and inland vessels.

[0236] First, the data acquisition unit is the front-end perception layer of the entire system, responsible for acquiring multi-source data from the distributed sensor network, including environmental data (such as water flow, wind speed, weather), ship operation data (such as speed, position, heading) and communication status data. These data are transmitted to the shore-based system through wireless communication links to provide basic data support for subsequent processing. In order to ensure the accuracy and real-time performance of data acquisition, the system needs to deploy high-precision sensors and adopt fault-tolerant design to deal with possible hardware failures.

[0237] The data processing unit is located at the core of the system, receiving the raw data from the data acquisition unit and performing preprocessing. The preprocessing process includes denoising, formatting, standardization, and anomaly detection to ensure that the data quality meets the analysis requirements. The preprocessed data enters the data fusion stage, and multi-source data is integrated through weighted averaging or Bayesian inference models. The data processing unit also needs to have efficient data storage and query capabilities, and can use a distributed database system to support real-time processing of large-scale data.

[0238] As the communication hub of the system, the information exchange unit is responsible for data exchange and status synchronization between the shore-based control center and the inland vessels. It uses encrypted communication protocols (such as TLS) to ensure the security of transmitted data and supports two-way communication. The information exchange unit is embedded with a zero-trust verification mechanism to verify the identity and communication content at each data interaction to prevent unauthorized access or data tampering. In addition, the unit also has a certain network dynamic routing function to ensure that it can automatically switch to the backup link when the communication link is interrupted.

[0239] The decision support unit is the intelligent analysis core of the system. It analyzes and predicts the input provided by the data processing unit through embedded algorithm models such as improved Bayesian networks. After receiving the real-time status and environmental data of the ship, the decision support unit can perform risk assessment, path optimization, navigation instruction generation and other operations. The system should support online learning and model updating capabilities to continuously improve decision accuracy. In addition, the unit will output specific suggestions or instructions, which will be transmitted back to the ship for execution through the information interaction unit.

[0240] The human-machine interactive terminal provides an intuitive interface for operators to monitor, command and adjust system operation. The terminal interface includes multiple modules such as the ship's real-time position, environmental parameters, historical data trend charts, and alarm information. Through touch screen or voice interaction, operators can quickly issue instructions, adjust parameters or respond to emergencies. In addition, the interactive terminal integrates an intelligent assistance system that can provide operational suggestions based on real-time data and preset rules, thereby reducing the burden on operators.

[0241] Figure 3The principle block diagram of the inland ship intelligent navigation system shown in the figure describes the core structure and technical implementation framework of the intelligent navigation ship. The system aims to achieve autonomous navigation, real-time monitoring and remote interactive control of the ship through the coordinated operation of various sub-modules, thereby ensuring the safety and efficiency of navigation.

[0242] The core of the system is composed of sensor networks, shipboard computing units, communication modules, control execution systems and human-computer interaction terminals. These parts work closely together to complete the ship's state perception, data processing, command generation and action execution functions.

[0243] First, the sensor network, as the perception layer of the system, is deployed at various key locations on the ship to collect multi-source data including the environment and operating status, including GPS position, speed, acceleration, ship attitude, water depth, radar images and other information. The sensors use high-precision equipment and are combined with redundant design to improve reliability. The sensor network also needs to achieve high-speed data transmission with the shipboard computing unit, which can use a bus structure or wireless communication method.

[0244] The onboard computing unit is the core processor of the entire system, and its functions include data fusion, signal analysis, path planning, and dynamic decision support. After the multi-source data from the sensors are transmitted to the onboard computing unit, they first go through a data preprocessing process, including denoising, formatting, and outlier detection, to ensure the integrity and reliability of the data. Subsequently, multi-source data fusion is achieved through the Bayesian inference method to obtain a real-time state estimate of the ship. The computing unit is also embedded with a risk assessment module that can identify potential navigation risks and recommend avoidance strategies.

[0245] The communication module is responsible for data exchange between inland vessels and shore-based control centers, while supporting interconnection with other ships or surrounding infrastructure. The communication module uses two-way encrypted wireless communication protocols such as 4G / 5G or satellite communications to achieve real-time data transmission. A zero-trust verification mechanism is introduced in the design to dynamically authenticate the identity during each communication and perform integrity checks on the transmitted data packets to prevent potential network attacks or data tampering. The communication module also includes a breakpoint resume function. When the communication link is interrupted by the environment, it can automatically save the data and retransmit it after recovery to ensure the integrity of the information.

[0246] The control execution system is an execution unit that converts decisions into physical actions. It consists of the ship's power system, rudder system, and auxiliary equipment (such as anchor winch and obstacle avoidance devices). The navigation and control instructions generated by the shipboard computing unit are transmitted to the control execution system through a real-time bus. In order to ensure the accuracy of execution, a closed-loop feedback control mechanism is designed inside the control execution system, which uses sensors to monitor the execution results in real time and feeds back the deviation information to the computing unit for correction. In addition, in order to deal with emergencies, the control execution system has a manual intervention mode, and the operator can directly control key components through the human-computer interaction terminal.

[0247] The human-machine interaction terminal provides a real-time monitoring and operation interface for ship operators. The terminal display integrates navigation maps, environmental data, ship status and alarm information modules. Operators can adjust system parameters, switch modes and set tasks through the touch screen or physical controller. In order to improve the convenience and intelligence level of interaction, the terminal also supports voice commands and gesture recognition functions. In terms of security design, the interactive terminal has a built-in access control mechanism, and only authorized users can perform key operations. In addition, the terminal maintains efficient synchronization with the shipboard computing unit to ensure the real-time nature of the interactive information.

[0248] In order to ensure the overall reliability of the system, redundant design and fault tolerance are fully considered during the design of the inland river vessel framework. Key sensors and onboard computing modules use dual-machine backup, the communication module supports multi-link switching, and the control execution system is equipped with mechanical and electronic dual protection mechanisms. In terms of energy management, the system is equipped with a main battery and backup battery pack switching function to ensure that the system can continue to operate even when the main power fails.

[0249] Figure 4 The zero-trust architecture shown is the core framework of the trust mechanism of the inland ship intelligent navigation system and the shore-based control system. Its implementation plan aims to ensure the security and reliability of the interaction between entities in the system through dynamic trust evaluation and continuous verification mechanisms. The architecture is based on the principle of "never trust, always verify", combined with multi-level security control and trust management strategies, to build a comprehensive security system.

[0250] The core of the zero-trust architecture is an identity-based dynamic verification mechanism that combines behavioral analysis, environmental perception, and historical interaction records to dynamically calculate trust values ​​to determine whether to authorize access or interaction. Each interactive node in the architecture (including ships, shore-based systems, and intermediate communication equipment) must undergo strict identity authentication and trust verification when interacting. First, during the system initialization phase, all interactive nodes must register their unique identity information, including hardware features, digital certificates, and access permission policies. This identity information is stored in a distributed authentication server and encrypted and protected by a public key infrastructure (PKI).

[0251] In actual operation, the zero-trust architecture adopts a distributed trust management model. Each interactive node needs to submit identity credentials and current context information (such as location, behavior pattern, environmental status, etc.) when initiating an interaction request. The authentication server generates a dynamic trust value based on this information. The trust value calculation is based on an improved Bayesian model, which comprehensively considers the identity credibility, behavior credibility, environmental credibility, and historical credibility of the node. The dynamic nature of the trust value is controlled by the time decay factor, ensuring that the system gives higher weight to the latest interactive behavior, while the influence of historical records gradually weakens.

[0252] The communication control layer in the architecture is responsible for encrypting and verifying all data transmission. Before data transmission, both parties in communication need to complete two-way identity authentication to ensure that the sender and receiver of the data are both trusted entities. End-to-end encryption technology (such as TLS 1.3) is used during the communication process to encrypt the transmitted data, generate a message digest and attach a digital signature to prevent tampering and forgery. The zero-trust architecture supports distributed key management and regularly updates encryption keys through an automatic key rotation mechanism to reduce the risk of key leakage.

[0253] To prevent potential attacks and abnormal behaviors, a real-time monitoring and behavior analysis module is embedded in the zero-trust architecture. This module identifies potential abnormal or malicious behaviors by analyzing sensor data, operation logs, and network traffic. For example, when the operation mode of a node deviates significantly from the normal behavior mode, the system triggers a risk assessment, recalculates the trust value, and adjusts permissions based on the results. The real-time monitoring and behavior analysis module uses machine learning algorithms such as anomaly detection models to identify a variety of complex attack patterns in dynamic environments, such as replay attacks, identity forgery, or command tampering.

[0254] The zero-trust architecture also introduces a dynamic permission management mechanism to adjust node permissions in real time based on changes in trust values. Nodes with high trust values ​​are granted higher access rights, while nodes with low trust values ​​have their permissions restricted or revoked. When a ship's trust value is reduced due to abnormal behavior, its permission to access critical data or send important instructions will be temporarily revoked until trust is restored through manual review or re-verification. Permission management is based on the principle of least privilege, ensuring that each node can only access the minimum resources required for its operation, thereby reducing potential security risks.

[0255] In addition, the zero-trust architecture has a strong emergency response capability. When an abnormal trust assessment value or a potential attack is detected, the system automatically triggers a preset response mechanism, including isolating risk nodes, sending alerts to administrators, or switching to backup communication links. To improve overall security, the architecture supports the coordinated operation of multi-level security strategies, such as combining physical isolation measures, software sandbox technology, and regular security audits.

[0256] Those skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a program, so the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0257] The above implementation methods have been described in detail. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A human-computer interaction trust assessment method for intelligent navigation of shore-based inland ship control, characterized in that: The method comprises the following steps: Establish a multi-dimensional trust index system for intelligent navigation of ships in inland waterway environments. The trust index system includes behavior credibility, identity credibility, environmental credibility and historical credibility. The weight of each indicator in the trust index system is determined by fuzzy comprehensive evaluation method. The environmental credibility is used to measure the adaptability of the ship and shore-based operating environment. Obtain the original data of the ship's intelligent navigation in the inland waterway environment, and pre-process the original data to obtain multi-source fusion data with the same scale; Under the trust index system, the trust value of each interaction node is calculated based on multi-source fusion data, and the time decay factor is introduced to dynamically update the trust value in real time to reflect the changes in the interaction behavior between each interaction node; a Bayesian network consisting of N interaction nodes is constructed, in which the interaction nodes are connected by conditional dependencies. Each interaction node represents an interaction entity, including ships, drivers, and shore-based control centers, and the edges represent the trust dependency relationships between interaction nodes; Perform risk assessment on each interactive node based on the trust value, predict potential risks based on the equilibrium solution of the attack and defense game model, and provide an automated response strategy based on the assessment results. The specific process includes: Calculate the abnormality of the interaction node behavior , the calculation formula is: ; in, For interactive nodes Historical Behavior The mean of For interactive nodes Historical Behavior The standard deviation of For current behavior; According to abnormality A risk assessment model is established to assess the risk value of interactive nodes. The expression is: ; in, For interactive nodes Value at risk at time t; For interactive nodes Trust value; is the abnormality of the interaction node behavior, indicating the degree to which the behavior of the interaction node deviates from expectations; is the weight of the interaction node; Value at Risk Standardization is performed to obtain a risk assessment value between 0 and 1 , the standardized formula is: ; in, , are the maximum risk value and the minimum risk value respectively; Risk Assessment Value Minimization is the goal to establish the equilibrium solution of the attack and defense game model, the expression is: ; ; in, , They are respectively the attacker strategy and defender strategy in the attack and defense game model; , are the payoff functions of the attacker strategy and the defender strategy respectively; is the attacker's profit function, which represents the attacker's profit from executing a certain attack strategy; is the defender’s profit function, which represents the defender’s profit from executing a certain defense strategy; The best defense strategy is identified by solving the equilibrium solution of the attack and defense game model, and risk responses are made accordingly, including restricting permissions, isolating risk nodes, and triggering manual review, namely: The expression for restricting permissions is: ; Among them, θ is the threshold; The expression for isolating risk nodes is: ; in, Risk threshold for quarantine; The expression triggered by manual review is: ; in, The threshold range for manual review.

2. The human-computer interaction trust evaluation method according to claim 1, characterized in that: Credibility of the behavior Used to evaluate whether the behavior of subject j at time t is in line with expectations and the credibility of the behavior The calculation formula is: ; in, is the penalty coefficient for the violation; The degree of behavioral matching; is the frequency of violations; The identity is trustworthy It is used to reflect the credibility of the subject j’s identity in the current interaction. The expression is: ; in, is the historical identity verification reliability of subject j; is the weight coefficient, ; is the authentication model of subject j at time t ; Environmental credibility The calculation formula is: ; ; in, is the weight of environmental factors; is the fuzzy membership function; is the ideal value of the environmental factor k; is the standard deviation; is the number of environmental factors k; The historical credibility Used to measure the trust accumulation and historical credibility between subject j and subject i The calculation formula is: ; in, For the moment Trust value; is the attenuation factor, ; is the upper limit of the time span of historical interactions considered when calculating historical credibility, i.e., the number of time periods looking back into the past; It is a time index variable used to traverse from 1 to The time step; Define the fuzzy evaluation matrix , and the fuzzy comprehensive evaluation method is used to determine the weight of each indicator, the fuzzy evaluation matrix The expression is: ; In the formula, They are the weight coefficients of behavioral credibility, identity credibility, environmental credibility, and historical credibility respectively.

3. The human-computer interaction trust evaluation method according to claim 2, characterized in that: Credibility of the behavior It includes the behavior matching degree used to measure the degree to which the subject j's current behavior matches the expected behavior , and the frequency of violations used to count whether subject j has violated regulations or abnormal behaviors , where the behavior matching The calculation formula is: ; in, is the cosine similarity, which indicates the similarity between the current behavior and the expected behavior; is the feature vector of the kth behavior; is the expected behavior feature vector; is the number of behaviors of subject j; Frequency of violations The calculation formula is: ; in, Expressing behavior It is against the rules; For violations The penalty weight of is the number of violations or abnormal behaviors of subject j.

4. The human-computer interaction trust evaluation method according to claim 1, characterized in that: The preprocessing of the original data to obtain multi-source fusion data with the same scale specifically includes: The original data is denoised and the denoised original data is standardized to a uniform scale. The denoising process includes weighted moving average denoising and low-pass filtering, wherein: The expression of weighted moving average denoising is: ; in, is the original data after denoising; is the weight coefficient; m is the window size; Indicates at time The original data collected; The expression of low-pass filtering is: ; in, is the original data after filtering; is the time constant of the filter; is the original data of the input filter; Anomaly detection is performed on raw data with a uniform scale, and the weighted average of adjacent data points is used to fill in missing or abnormal data; Fusion of the original data after anomaly detection to obtain multi-source fusion data , the expression is: ; in, For data source The weight of For data source number; For the A signal from a data source.

5. The human-computer interaction trust evaluation method according to claim 1, characterized in that: The trust value of each interactive node is calculated based on multi-source fusion data, and a time decay factor is introduced to dynamically update the trust value in real time. The specific process includes: Construct a Bayesian network consisting of N interactive nodes, where the interactive nodes are connected by conditional dependencies. Each interactive node represents an interactive entity, including a ship, a driver, and a shore-based control center, and the edges represent the trust dependencies between the interactive nodes. The graph structure of the Bayesian network is: ; in, represents all interaction nodes; E represents the edge between interaction nodes, i.e., trust dependency relationship; The conditional dependency between interaction nodes is expressed as: ; in, It is an interactive node Conditional probability distribution given the parent node; It is an interactive node The parent node set of According to the interaction node Behavioral credibility , Identity Credibility , historical credibility , Environmental Credibility , calculate the interaction nodes At the moment Trust value ,Right now: ; in, is the weight coefficient, and ; Introducing a time decay factor to determine the trust value of time The influence of is expressed as: ; in, is the time decay factor, indicating the degree of decay of the trust value over time; represents the exponential weight of the time decay factor; Dynamically update trust value .

6. The human-computer interaction trust evaluation method according to claim 5, characterized in that: The dynamically updated trust value The specific process includes: Initial trust value calculation: based on the initial behavior credibility , Identity Credibility , historical credibility , Environmental Credibility Calculate the initial trust value of each interaction node; Real-time trust value update: As the interaction between the ship and the shore changes, new interaction data will be collected in real time, including new behavior logs, environmental data, and control instructions, and the initial trust value will be updated in real time based on the Bayesian network structure and time decay factor; Trust value correction: When the trust value of any interactive node changes abnormally and the behavior does not meet expectations, the trust value will be corrected, and the corresponding conditional probability distribution in the Bayesian network will be updated to ensure that the calculation of the trust value accurately reflects the actual behavior of the interactive node; Adaptive weight adjustment: Based on real-time interaction data, the weight of the trust value is adjusted according to different scenarios.

7. A human-computer interaction trust evaluation system for implementing the human-computer interaction trust evaluation method according to any one of claims 1 to 6, characterized in that: include: A shore-based control system, which realizes the linkage between the shore-based control center and the ships in the inland waterway, and is used for command, monitoring, calculation and decision support during the autonomous navigation of the ships; An intelligent navigation system for inland river vessels, which is used to realize autonomous navigation, real-time monitoring and remote interactive control of ships navigating in inland waterways; Zero trust architecture, which is a trust mechanism between the inland vessel intelligent navigation system and the shore-based driving and control system. It ensures the security and reliability of the interaction between entities through dynamic trust evaluation and continuous verification mechanism.

8. The human-computer interaction trust evaluation system according to claim 7, characterized in that: The shore-based driving control system comprises: A data acquisition unit, the data acquisition unit is used to acquire multi-source data from a distributed sensor network, including environmental data, ship operation data, and communication status data; A data processing unit, the data processing unit is used to receive the raw data from the data acquisition unit and perform preprocessing, the preprocessing process includes denoising, formatting, standardization, anomaly detection and data fusion; An information interaction unit, which is used for data exchange and status synchronization between the shore-based control center and the inland vessel, and a zero-trust verification mechanism is embedded in the information interaction unit to verify the identity and communication content at each data interaction; A decision support unit, which is used to analyze and predict the input provided by the data processing unit, and perform risk assessment, route optimization, and navigation instruction generation after receiving the real-time status and environmental data of the ship; The first human-machine interaction terminal provides an intuitive interface for operators to monitor, direct and adjust system operation.

9. The human-computer interaction trust evaluation system according to claim 7, characterized in that: The inland river vessel intelligent navigation system comprises: A sensor network is arranged at various key positions of the ship to collect multi-source data including environment and operation status; A shipboard computing unit receives multi-source data from a sensor network, fuses the multi-source data through a Bayesian inference method, obtains a real-time state estimate of the ship, identifies potential navigation risks, and recommends avoidance strategies; A communication module, which is used for data exchange between inland waterway vessels and shore-based control centers, and supports interconnection with other vessels or surrounding infrastructure; A control execution system, which is used to convert navigation and control instructions generated by the ship's onboard computing unit into physical actions and is composed of the ship's power system, rudder system and auxiliary equipment; The second human-machine interaction terminal provides a real-time monitoring and operation interface for the ship operator.

Citation Information

Patent Citations

  • A method for establishing a trust model in an underwater sensor network

    CN103619009A

  • Cloud master station access control method and device based on zero trust

    CN116208401A