A dynamic event-triggered fault detection method for networked control systems
By introducing a dynamic event triggering mechanism and fault detection method into the network control system, the problems of fault detection and communication resources under mixed network attacks are solved, thereby improving the system's stability and resource utilization.
Patent Information
- Application Number
- CN202411626562.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2044-11-13
AI Technical Summary
Existing technologies struggle to effectively integrate dynamic event triggering mechanisms into network control systems to address issues related to fault detection, network security, and communication resources, especially lacking effective solutions when facing promiscuous network attacks.
A dynamic event-triggered fault detection method for networked control systems is designed. This method involves establishing a linear system model, a fault detection filtering model, characterizing attack signals, constructing a dynamic event triggering scheme, and designing a fault detection evaluation function. Fault detection is performed using a time-delay residual system model, and the event triggering mechanism is combined to reduce communication frequency and improve system stability.
It improves the system's fault tolerance and maintainability under promiscuous network attacks, reduces communication resource waste, maintains system stability, enhances channel utilization, and prevents performance degradation.
Smart Images

Figure CN119696822B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network security, and particularly relates to a dynamic event-triggered fault detection method for a networked control system. BACKGROUND
[0002] With the rapid development of network technology and control systems, the combination between the two is becoming closer and closer, and network control systems are thus born. Network control systems are a class of control systems that realize information transmission and interaction between sensors, controllers and actuators through network communication. Unlike the control systems before the development, the various components of the network control system are connected through computer networks (such as Ethernet, wireless networks, etc.), and data is transmitted through the network, and the information of the system realizes interconnection and sharing. Since the system needs to rely on the network, it is easy to be subjected to scanning, detection and intrusion by network attackers in the communication process. The vulnerabilities of the communication protocols used by the network control system also provide opportunities for attackers, making it easy for them to disrupt the normal operation of the system by sending malicious commands or tampering with data. In addition to network security problems, network control systems also face challenges of fault and communication resource problems.
[0003] Equipment in long-term use without regular maintenance, internal components may accumulate dust or parts loose, materials may age or wear, these problems may gradually accumulate, leading to system performance degradation or failure. Fault detection plays a crucial role in any complex system, especially in industrial control systems, mechanical systems, aerospace systems, and medical devices. Its main role is to discover potential problems or already occurred faults in the system in a timely manner, prevent fault propagation, reduce losses, and improve the safety, reliability and maintainability of the system. Therefore, when designing and managing complex systems, fault detection, diagnosis and fault tolerance measures need to be taken to reduce the frequency of faults and reduce the impact of faults.
[0004] Due to physical and technical constraints, economic costs, user demand growth, and the scarcity of spectrum and bandwidth, the resources of communication networks are limited. The introduction of event-triggered mechanism in network control systems is an effective method to reduce the occupation of communication resources. Event triggering is a mechanism that reduces the frequency of information transmission in the network by setting specific trigger conditions, and the system performs corresponding operations when specific events occur, greatly improving the responsiveness and flexibility of the system. Through the event-triggered mechanism, the system can accurately operate when specific conditions are met, reducing the probability of false triggering or invalid operations.
[0005] Most existing methods focus solely on fault detection in network control systems, rarely considering dynamic event triggering mechanisms to reduce transmission frequency, and even fewer address promiscuous network attacks. Therefore, considering systems vulnerable to promiscuous network attacks and simultaneously addressing system faults, network security, and communication resource issues presents a significant challenge. Such complex systems have not yet been addressed in previous inventions, representing a crucial problem that current research needs to solve. Summary of the Invention
[0006] In view of the above-mentioned deficiencies of the prior art, the present invention proposes a dynamic event-triggered fault detection method for a networked control system. The technical solution designed in this invention includes the following steps:
[0007] S10: Establish a linear system model for the network control system;
[0008] S20: Establish a fault detection filtering model;
[0009] S30: Describes and describes denial-of-service and spoofed data injection attack signals that affect the network control system;
[0010] S40: Construct a dynamic event triggering scheme;
[0011] S50: Design fault detection and evaluation functions;
[0012] S60: Establish a time-delay residual system model to perform fault detection on the network control system.
[0013] Preferably, the linear system model of the network control system in S10 is as follows:
[0014]
[0015] Where x(t)∈R m Represents the state of the network control system, ω(t)∈R p The external disturbance representing the network control system, f(t)∈R q Represents a fault signal in a networked control system, y(t)∈R l This represents the output vector of the networked control system, where m, p, q, and l are preset dimensions, and A, B... ω C and D are the preset matrices of the network control system.
[0016] Preferably, the fault detection filtering model in S20 has the following formula:
[0017]
[0018] Where, x f (t)∈Rr Indicates the state of the filter. Let r(t) ∈ R represent the input of the filter. d Represents the residual signal, where r, g, and d are preset dimensions, and A f B f C f D f These are the preset matrices of the filter.
[0019] Preferably, the denial-of-service attack signal received by the network control system in S30 is represented by the following formula:
[0020]
[0021] Among them, g n Let s represent the start time of the (n+1)th interval without denial-of-service attacks. n This represents the (n+1)th interval without a denial-of-service attack. This indicates the range during which the network control system has not been subjected to a denial-of-service attack. This indicates the range during which a network control system is subjected to a denial-of-service attack.
[0022] Preferably, S30 further includes:
[0023] Limiting the extent of denial-of-service attacks on network control systems and controlling attack frequency. Has an effect on the duration of the attack Where, v1∈R ≥0 It is a positive real scalar, Γ D ∈R >0 This is a parameter that limits the attack frequency, s min ,s max ,g max It is a positive scalar.
[0024] Preferably, after the network control system in S30 is subjected to a false data injection attack signal, the filtering input formula of the network control system is as follows:
[0025]
[0026] in, α(t)∈{0,1} is a Bernoulli variable with the expected value being... d(t) represents a fake data injection attack signal.
[0027] Preferably, S40 includes:
[0028] An event-triggered mechanism is introduced, and the sampled signals of the network control system are transmitted on demand based on conditional judgments. The triggering mechanism formula is as follows:
[0029]
[0030] Among them, conditions a for Let T be the transpose of the sample, jh be the j-th sampling interval, and t be the time interval following the last trigger. k h is the trigger time of the last triggering mechanism. It is the output error of the network control system, ε∈(0,1) is the set condition threshold, and the parameter δ>0;
[0031] When an event-triggered mechanism is introduced, the internal dynamic variables of the network control system satisfy the following formula:
[0032]
[0033] Wherein, the parameter μ is set to 0, and the given initial conditions are met.
[0034] Preferably, S50 includes:
[0035] A detection standard is designed within the filter to detect faults occurring in the network control system using the filter's residual signal r(t). The evaluation function is expressed as follows: r(v) represents the residual signal in the filter, and the standard threshold for evaluating whether a fault has occurred is... L2 indicates that the integral of the square of the function over [0, ∞) is finite;
[0036] The network control system detects the following conditions:
[0037]
[0038] Preferably, S60 includes:
[0039] The time delay function is obtained by triggering feedback using input time delay processing, as shown in the following formula:
[0040]
[0041] Among them, t k,n h is the last time the triggering mechanism was triggered, θ k,n It is the calculated value of the number of samples between two consecutive triggers. This represents the initial moment of the next trigger;
[0042] T k,n (t)∈[0, h), t∈V k,n ∩G n
[0043] Where h is the sensor sampling period, V k,nIt is the interval between two consecutive triggering times;
[0044] The error function is obtained, and the formula is as follows:
[0045]
[0046] The output of the network control system is further expressed by the following formula:
[0047] y(t k,n h)=y(t-τ k,n (t))+e k,n (t), t∈V k,n ∩G n
[0048] The input to the filter is determined by the triggering time, as shown in the following formula:
[0049]
[0050] in, d(y(t k,n h)) satisfies the condition ||d(y(t) k,n h))||2≤||Ey(t)||2, where E is a given parameter constraining a nonlinear function;
[0051] The fault detection filter model is updated as follows:
[0052]
[0053] The time-delay residual system model is obtained, and the formula is as follows:
[0054]
[0055] In the formula, w(t)=[ω T (t) f T (t) T r e (t)=r(t)-f(t), G = [I 0], D1 = [0 C] f ], E1 = D f C, E2 = D f H = [0, -1]
[0056] Beneficial effects:
[0057] 1. This invention uses a fault detection method and sets a fault evaluation and detection function to detect the faults that occur in the system from the residual signal of the filter, which has the advantages of improving the fault tolerance and maintainability of the system.
[0058] 2. This invention incorporates a dynamic event triggering mechanism, which effectively reduces the frequency of communication signal transmission, avoids unnecessary waste of communication resources, and prevents the risk of system performance degradation due to slow transmission rate, thus improving channel utilization.
[0059] 3. The present invention can maintain its stability under promiscuous attacks. Compared with some solutions that do not consider network attacks or only consider a single type of attack, the present invention is more effective. Attached Figure Description
[0060] Fig. 1 This is a flowchart illustrating a preferred embodiment of the present invention;
[0061] Fig. 2 This is a schematic diagram of the network control system structure of a preferred embodiment of the present invention. Detailed Implementation
[0062] The embodiments of the present invention will be described in detail below. The embodiments described below are implemented based on the technical solution of the present invention, and detailed implementation methods and specific operation processes are given. However, the protection scope of the present invention is not limited to the embodiments described below.
[0063] This invention designs a dynamic event-triggered fault detection method for networked control systems. For networked control systems affected by promiscuous network attacks and disturbances, it uses a residual signal to detect faults in the system through an internal detection and evaluation function of a filter, promptly identifying potential problems and reducing the impact of system damage. Utilizing a dynamic event triggering mechanism, it determines whether the sampled signal meets the triggering conditions, ensuring the system outputs at the trigger time, reducing the frequency of signal transmission and improving the effective utilization of network transmission. Furthermore, this invention can reduce the adverse effects of network attacks and disturbances on the system, aiming to maintain system stability in complex environments. Figs. 1-2 As shown, the technical solution includes the following steps, specifically:
[0064] S10: Establish a linear system model for the network control system;
[0065] S20: Establish a fault detection filtering model;
[0066] S30: Describes and describes denial-of-service and spoofed data injection attack signals that affect the network control system;
[0067] S40: Construct a dynamic event triggering scheme;
[0068] S50: Design fault detection and evaluation functions;
[0069] S60: Establish a time-delay residual system model to perform fault detection on the network control system.
[0070] Preferably, the linear system model of the network control system in S10 is as follows:
[0071]
[0072] Where x(t)∈R m Represents the state of the network control system, ω(t)∈R p The external disturbance representing the network control system, f(t)∈R q Represents a fault signal in a networked control system, y(t)∈R l This represents the output vector of the networked control system, where m, p, q, and l are preset dimensions, and A, B... ω C and D are the preset matrices of the network control system.
[0073] Preferably, the fault detection filtering model in S20 has the following formula:
[0074]
[0075] Where, x f (t)∈R r Indicates the state of the filter. Let r(t) ∈ R represent the input of the filter. d Represents the residual signal, where r, g, and d are preset dimensions, and A f B f C f D f These are the preset matrices of the filter.
[0076] Preferably, the denial-of-service attack signal received by the network control system in S30 is represented by the following formula:
[0077]
[0078] Among them, g n Let s represent the start time of the (n+1)th interval without denial-of-service attacks. n This represents the (n+1)th interval without a denial-of-service attack. This indicates the range during which the network control system has not been subjected to a denial-of-service attack. This indicates the range during which a network control system is subjected to a denial-of-service attack.
[0079] Preferably, S30 further includes:
[0080] Limiting the extent of denial-of-service attacks on network control systems and controlling attack frequency. Has an effect on the duration of the attack Where, v1∈R≥0 It is a positive real scalar, Γ D ∈R >0 This is a parameter that limits the attack frequency, s min ,s max ,g max It is a positive scalar.
[0081] Preferably, after the network control system in S30 is subjected to a false data injection attack signal, the filtering input formula of the network control system is as follows:
[0082]
[0083] in, α(t)∈{0,1} is a Bernoulli variable with the expected value being... d(t) represents a fake data injection attack signal.
[0084] Specifically, since this type of DoS attack is non-periodic, the system can transmit information through the network during periods without attacks; however, when a DoS attack occurs, the network channel is maliciously blocked, and information cannot be transmitted and shared between components. Therefore, the DoS attack signal is represented by the formula above.
[0085] Furthermore, limiting the extent of network attacks on the system is crucial to mitigating their adverse impact on system performance, ensuring the system remains under control even after an attack. This requires applying the aforementioned basic assumptions regarding attack frequency and duration.
[0086] Preferably, S40 includes:
[0087] An event-triggered mechanism is introduced, and the sampled signals of the network control system are transmitted on demand based on conditional judgments. The triggering mechanism formula is as follows:
[0088]
[0089] Where, condition a is Let T be the transpose of the sample, jh be the j-th sampling interval, and t be the time interval following the last trigger. k h is the trigger time of the last triggering mechanism. It is the output error of the network control system, ε∈(0,1) is the set condition threshold, and the parameter δ>0;
[0090] When an event-triggered mechanism is introduced, the internal dynamic variables of the network control system satisfy the following formula:
[0091]
[0092] Wherein, the parameter μ is set to 0, and the given initial conditions are met.
[0093] Preferably, S50 includes:
[0094] A detection standard is designed inside the filter to detect faults in the network control system using the filter's residual signal r(t). The evaluation function is expressed as follows: r(v) represents the residual signal in the filter, and the standard threshold for evaluating whether a fault has occurred is... L2 indicates that the integral of the square of the function over [0, ∞) is finite;
[0095] The network control system detects the following conditions:
[0096]
[0097] Preferably, S60 includes:
[0098] The time delay function is obtained by triggering feedback using input time delay processing, as shown in the following formula:
[0099]
[0100] Among them, t k,n h is the last time the triggering mechanism was triggered, θ k,n It is the calculated value of the number of samples between two consecutive triggers. This represents the initial moment of the next trigger;
[0101] τ k,n (t)∈[0,h), t∈V k,n ∩G n
[0102] Where h is the sensor sampling period, V k,n It is the interval between two consecutive triggering times;
[0103] The error function is obtained, and the formula is as follows:
[0104]
[0105] The output of the network control system is further expressed by the following formula:
[0106] y(t k,n h)=y(t-τ k,n (t))+e k,n (t), t∈V k,n ∩G n
[0107] The input to the filter is determined by the triggering time, as shown in the following formula:
[0108]
[0109] in, d(y(t k,n h)) satisfies the condition ||d(y(t) k,n h))||2≤||Ey(t)||2, where E is a given parameter constraining a nonlinear function;
[0110] The fault detection filter model is updated as follows:
[0111]
[0112] The time-delay residual system model is obtained, and the formula is as follows:
[0113]
[0114] In the formula, w(t)=[ω T (t) f T (t)] T r e (t)=r(t)-f(t), G[I 0], D1 = [0 C] f ], E1 = D f C, E2 = D f H = [0, -1]
[0115] Specifically, in step S60, an event triggering mechanism is introduced through step S40, and the transmission time is determined by t. k,n h determines the initial output of the network control system:
[0116] y(t k.n h)=Cx(t k.n h), t∈V k.n ∩G n
[0117] Among them, t k,n h is the last time the triggering mechanism was triggered. It is the interval between two consecutive triggering times, θ k,n =inf{c∈N|t k,n h+ch≥t k+1,n h}.
[0118] In addition, this application also provides stability analysis and H-level performance testing for network control systems. ∞ Performance analysis, including:
[0119] To analyze the stability of the system under this complex environment, two definitions are introduced;
[0120] Definition 1: Given constants ψ≥1 and ρ>0, if the system also satisfies the following:
[0121]
[0122] Therefore, the system is mean square exponentially stable.
[0123] Definition 2: Given constants γ>0, β>0, if the system satisfies the following:
[0124] (i) When there is no disturbance (w(t) = 0), the system has mean square exponential stability as defined in definition 1;
[0125] (ii) When a perturbation exists (w(t)∈L2[0,∞)), χ0=0, which satisfies the following condition.
[0126]
[0127] Then the system can be called having H ∞ The performance index γ and the mean square exponent are stable.
[0128] Based on the piecewise Lyapunov functionals V1(t) and V2(t), after differentiation and simplification, we have:
[0129]
[0130] When w(t) = 0, by the inequality P1 ≤ μ2P2, Q1≤μ2Q2, R1≤μ2R2, Q2≤μ1Q1, R2≤μ1R1, further expressing μ as We can obtain:
[0131]
[0132] Wherein, parameter x1 is x1=(ln(μ1μ2)+2(α1+α2)h-2α1s min +2α2g max v1, parameter x|h| is
[0133]
[0134] Furthermore, define the parameter w1 = min{λ} min (P1),λ min (P2)},w2=λ max (P1), According to the derivation, we can obtain:
[0135]
[0136] The converted result is as follows:
[0137]
[0138] The parameters are respectively It represents the convergence rate of a complex system.
[0139] Combining the above trajectory equation, let The following results were obtained:
[0140]
[0141] Further derivation yields:
[0142]
[0143] Organized when n→∞ , can be represented as:
[0144]
[0145] The result after conversion is:
[0146]
[0147] Wherein, parameter φ is
[0148] The preferred embodiments of the present invention have been described in detail above. It should be understood that those skilled in the art can make numerous modifications and variations based on the concept of the present invention without creative effort. Therefore, all technical solutions that can be obtained by those skilled in the art based on the concept of the present invention through logical analysis, reasoning, or limited experimentation on the basis of existing technology should be within the scope of protection defined by the claims.
Claims
1. A method for detecting dynamic event-triggered faults in a networked control system, characterized in that, Includes the following steps: S10: Establish a linear system model for the network control system; S20: Establish a fault detection filtering model; S30: Describes and describes denial-of-service and spoofed data injection attack signals that affect the network control system; S40: Construct a dynamic event triggering scheme; S50: Design fault detection and evaluation functions; S60: Establish a time-delay residual system model and perform fault detection on the network control system; The linear system model of the network control system in S10 is as follows: in, This represents the state of the network control system. This represents external disturbances to the network control system. This represents a fault signal in a network control system. This represents the output vector of the networked control system, where m, p, q, and l are preset dimensions. These are the preset matrices of the network control system; The fault detection filtering model in S20 is as follows: in, Indicates the state of the filter. Indicates the input of the filter. This represents the residual signal, where r, g, and d are preset dimensions. These are the preset matrices of the filter; The denial-of-service attack signal received by the network control system in S30 is given by the following formula: in, Indicates the first The start time of a no-denial-of-service attack range Indicates the first No denial-of-service attack interval This indicates the range during which the network control system has not been subjected to a denial-of-service attack. This indicates the range during which a network control system is subjected to a denial-of-service attack. The S30 further includes: Limiting the extent of denial-of-service attacks on network control systems and controlling attack frequency. The duration of the attack is affected. , , ,in, It is a positive real scalar. It is a parameter that limits the attack frequency. It is a positive scalar; After the network control system in S30 is subjected to a false data injection attack signal, the filtering input formula of the network control system is as follows: in, , It is a Bernoulli variable with the expected value being , This indicates a fake data injection attack signal; S40 includes: An event-triggered mechanism is introduced, and the sampled signals of the network control system are transmitted on demand based on conditional judgments. The triggering mechanism formula is as follows: Among them, conditions for , Let T represent the sampling time following the last trigger, where T is the transpose and jh is the j-th sampling interval. It is the trigger time of the last trigger mechanism. It is the output error of the network control system. It is a set conditional threshold, parameter ; When an event-triggered mechanism is introduced, the internal dynamic variables of the network control system satisfy the following formula: Among them, setting parameters The given initial conditions are satisfied ; The S50 includes: A detection standard is designed inside the filter, and the residual signal from the filter is used for detection. The evaluation function is expressed as follows: (This is a partial translation of the original text, which is not possible without further context.) , The residual signal in the filter represents the standard threshold for evaluating whether a fault has occurred. , Indicates in The integral of the square of the function above is finite; The network control system detects the following conditions: ; The S60 includes: The time delay function is obtained by triggering feedback using input time delay processing, as shown in the following formula: in, It is the last time the triggering mechanism was triggered. It is the calculated value of the number of samples between two consecutive triggers. This represents the initial moment of the next trigger; Where h is the sensor sampling period, It is the interval between two consecutive triggering times; The error function is obtained, and the formula is as follows: The output of the network control system is further expressed by the following formula: The input to the filter is determined by the triggering time, as shown in the following formula: in, , Meet the conditions E is a given parameter constrained by a nonlinear function; The fault detection filter model is updated as follows: The time-delay residual system model is obtained, and the formula is as follows: In the formula, , , , , , , , , , , , , .
Citation Information
Patent Citations
Collaborative design method of fault detection filter and controller under DoS attack
CN108629132A
Fault detection method of nonlinear network control system based on event triggering mechanism
CN108667673A