Distributed attack detection method for interconnected cyber-physical systems based on equivalent space method

By constructing an interconnected cyber-physical system model based on the equivalence space method, splitting the overall residual into distributed residuals, analyzing the impact of network attacks on neighboring subsystems, and selecting appropriate detection statistics and thresholds, the complexity of distributed attack detection in interconnected cyber-physical control systems is solved, achieving efficient attack detection.

CN119835064BActive Publication Date: 2025-11-04BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510021998.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-11-04
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

Interconnected cyber-physical control systems present complex challenges in detecting and isolating network attacks, especially distributed attacks. Existing observer-based detection schemes are complex to design and difficult to implement efficiently.

Method used

An interconnected cyber-physical system model is constructed using the equivalence space method. By building a distributed system model and a global system model, overlay attack and replay attack models are defined. The global residual is split into distributed residuals using the equivalence space method. The impact of network attacks on the residuals of neighboring subsystems is analyzed. Appropriate detection statistics and thresholds are selected to achieve distributed attack detection.

Benefits of technology

It achieves efficient distributed attack detection for interconnected cyber-physical control systems, simplifies the detection process, avoids complex observer design, and can effectively detect localized, stealthy network attacks while ensuring system control performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835064B_ABST
    Figure CN119835064B_ABST
Patent Text Reader

Abstract

The application discloses an interconnection information physical system distributed attack detection method based on an equivalent space method, and comprises the following steps: step 1, establishing a distributed model and an overall model of the interconnection information physical system; step 2, constructing a cover attack model and a replay attack model in the interconnection information physical system; step 3, constructing overall residual errors and distributed residual errors of the interconnection information physical system based on the equivalent space method; step 4, based on the distributed residual errors in step 3, analyzing residual error changes of neighbor subsystems when a single subsystem in the interconnection information physical system suffers from a network attack; and step 5, using the residual error changes caused by the attack, selecting a suitable detection statistic, formulating a detection strategy and selecting a detection threshold, and completing the attack detection. The application realizes the distributed attack detection of the interconnection information physical system by constructing the distributed residual errors of the interconnection information physical control system based on the equivalent space method.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security of interconnected information physical control system, and particularly relates to an interconnected information physical system distributed attack detection method based on an equivalent space method. BACKGROUND

[0002] An interconnected information physical control system is composed of multiple information physical control systems which are coupled on physical devices and have information transmission between communication networks. In addition, traditional infrastructures such as power systems and transportation systems are now large-scale interconnected systems. The design and construction cost of the interconnected information physical control system is often high, and the system can cause huge social and economic losses after being attacked by a network. Due to the more complex structure and composition of the interconnected information physical control system compared with a single system, the mutual influence and coupling between systems greatly increase the difficulty of attack detection and isolation. The interconnected information physical control system is interconnected on physical devices and communication networks, and the mutual influence between the systems makes the interconnected information physical control system more sensitive to network attacks and more vulnerable to attacks.

[0003] Most of the current methods for detecting distributed attacks on interconnected systems are based on observer detection schemes, and the design of the detector is complex. In a large-scale interconnected information physical control system, dynamic control processes often interact with each other, which makes it very complex to detect and isolate attacks from the perspective of dynamic feedback. SUMMARY

[0004] To solve the above problems, the application provides an interconnected information physical system distributed attack detection method based on an equivalent space method, which realizes distributed attack detection on the interconnected information physical system by constructing distributed residuals of the interconnected information physical control system based on the equivalent space method, and can simply and efficiently realize attack detection under the premise of ensuring control performance.

[0005] To achieve the above purpose, the technical scheme adopted by the application is as follows: an interconnected information physical system distributed attack detection method based on an equivalent space method, comprising the following steps:

[0006] Step 1: constructing an interconnected information physical system model, including a distributed system model and an overall system model;

[0007] Step 2: constructing a network attack model with concealment on the basis of the interconnected information physical system model, including a cover attack model and a replay attack model;

[0008] Step 3: constructing an overall residual of the interconnected information physical system based on the equivalent space method for the network attack model with concealment, and then splitting the overall residual into distributed residuals according to the dimension relationship of the system;

[0009] Step 4: Based on the obtained distributed residual, analyze the influence of network attack with local concealment on the residual of neighbor subsystem, analyze the change of residual when attack occurs;

[0010] Step 5: According to the change of residual, select appropriate detection statistics, formulate corresponding detection strategy and select appropriate detection threshold, complete attack detection.

[0011] Further, the distributed system model is:

[0012]

[0013] Wherein, k represents time, χ i is the state vector of the current subsystem, χ j is the state vector of other subsystems, u i is the input vector, y i is the output vector, w i , q i are independent and identically distributed Gaussian random vectors with mean 0 and covariance matrix Q and W respectively, Q and W are positive definite diagonal matrices, A ii , A ij , B i , C i are constant matrices, N represents the number of subsystems in the whole interconnected information physical system, and subscripts i and j represent the i th subsystem and the j th subsystem respectively.

[0014] Further, the whole system model is:

[0015]

[0016] Wherein, x is the state vector containing all subsystems, u is the input vector containing all subsystems, y is the output vector containing all subsystems, w and q are Gaussian random vectors containing all subsystems, A, B and C are constant matrices;

[0017] C = diag{C1, C2, … C N}, A = [A ij ] N×N , B is obtained by replacing C i in C with B i .

[0018] Further, the overlay attack model is:

[0019]

[0020] Wherein, k represents time, u(k) represents normal control input signal, y(k) represents normal measurement output signal, This indicates that the physical control object has received a control input signal that has been injected with an attack signal. The output measurement signal represents the injected attack signal received by the detector, and η(k) and γ(k) represent the attack signal injected by the overlay attack through the communication link;

[0021] When establishing attack signals η(k) and γ(k), the detector is made unable to distinguish between the attacked output signal and the normal output signal:

[0022]

[0023] in, This represents the matrix of system knowledge possessed by the attacker. This represents the state vector that represents the attacker's design of the attack signal;

[0024] Assuming the attacker has complete knowledge of the system, that is And in If the attack begins at a certain time, the overlay attack is completely covert.

[0025] Furthermore, the replay attack model is as follows:

[0026] The replay attack is carried out in two phases: Phase 1 is the eavesdropping phase, in which the attacker eavesdrops and records the output and input signals for a sufficiently long time; Phase 2 is the replay phase, in which the attacker replays the past output signal at the detector end, thereby masking the impact of the injection attack on the input signal on the output.

[0027]

[0028] Where, τ k >0 indicates replaying a past moment, and a(k) represents the attack signal injected by the attacker. This represents the control input signal received by the physically controlled object from the injected attack signal. This indicates that the detector received the replayed data from the past τ. k The output measurement signal at any given time.

[0029] Furthermore, for network attack models with stealth capabilities, the overall residual of the interconnected cyber-physical system is constructed based on the equivalence space method. Then, according to the system dimensionality relationship, the overall residual is decomposed into distributed residuals, including the following steps:

[0030] First, based on the overall model of the interconnected system, assuming q(k) = 0 and w(k) = 0; define the matrix:

[0031] y s (k)=H o,s x(ks)+H u,s u s (k);

[0032] where s denotes the window length, y s (k), x(k-s), u s (k) is a matrix composed of the measurement output vector, state vector and control input vector of the past time of the system, H o,s , H u,s is a matrix composed of system matrices A, B, C; according to the rank relationship of the system matrix, there exists at least one nonzero vector v s such that v s H o,s = 0;

[0033] Therefore, the residual r s (k) generated based on the equivalent space method with the window length s is:

[0034] r s (k) = v s (y s (k) - H u,s u s (k));

[0035] Reconsidering the influence of w(k), q(k) on the residual generator, the above steps are repeated to obtain

[0036] y s (k) = H o,s χ(k-s) + H u,s u s (k) + H e,s e s (k);

[0037] where e s (k) is a matrix composed of the process noise and measurement noise of the past time of the system, H e,s is a matrix composed of system matrices C, A;

[0038] Finally, the overall residual generated is:

[0039] r s (k) = v s (y s (k) - H u,s u s (k)) = v s H e,s e s (k);

[0040] Then, the overall residual is split into distributed residuals by row:

[0041]

[0042] where rs,i denotes the distributed residual corresponding to the i-th subsystem, v s,i is a non-zero vector, is H o,s , H u,s is a matrix composed of the i-th row in H o,s and H u,s , and the dimension of H m×N×(s+1) is l i , then the row number of the row corresponding to the i-th subsystem row i should be composed of m arithmetic sequences; and the common difference of the m arithmetic sequences is s+1, and the first term is all elements in {m×(i-1)+1, m×(i-1)+2, …, m×i} respectively.

[0043] Thus:

[0044] where, Θ i is the covariance matrix of r s,i (k), is a matrix composed of the i-th row in H e,s .

[0045] Further, based on the obtained distributed residual, the influence of a network attack with local concealment on the residual of the neighbor subsystem is analyzed, and the change of the residual when the attack occurs is analyzed, including the steps of:

[0046] Assuming that only the j-th subsystem is attacked, according to the distributed system model, the physical dynamics model of the j-th subsystem under attack is represented as:

[0047]

[0048] where, A ii , A ij , A jj , B i , C i are constant matrices, u j,a (k) represents the control input signal received by the j-th subsystem physical control object under attack, which is represented as u j,a (k) = u j (k) + a j (k), a j (k) represents the malicious signal injected by the attacker of the j-th subsystem, u j (k) represents the input vector of the j-th subsystem, x j represents the state vector of the j-th subsystem, y j represents the output vector of the j-th subsystem, w j is a Gaussian random vector; q j(k) is a Gaussian random vector, γ j (k) is an attack vector injected by the sensor output channel;

[0049] x j is the physical dynamic model of the ith subsystem, and

[0050]

[0051] q i (k) is a Gaussian random vector, then we have

[0052]

[0053] where, are the H o,s , H u,s , H e,s matrices composed of the row vectors corresponding to the ith subsystem in H s,i (k) is the matrix composed of the attack signal of the ith subsystem, y s,i (k), x i (k-s), u s,i (k) are the matrices composed of the measurement output vector, state vector and control input vector of the ith subsystem at past time of the system, e s,i (k) is the matrix composed of the process noise and measurement noise of the ith subsystem at past time of the system;

[0054] The distributed residual of the ith subsystem is:

[0055] denotes the residual of the ith subsystem when the system is attacked, assuming that the attack starts from k a =k-s, a s (k)≠0, and the kernel space of

[0056]

[0057] denotes that the covert attack implemented on the jth subsystem will cause the covariance of the residual of its neighbor subsystem to change;

[0058] When the jth subsystem is attacked by the replay attack model, the same conclusion is obtained.

[0059] Further, according to the change of the residual, a suitable detection statistic is selected, a corresponding detection strategy is formulated, and a suitable detection threshold is selected to complete attack detection, including:

[0060] χ 2The method of inspection carries out residual evaluation and threshold design, and defines statistics:

[0061]

[0062] wherein, represents the detection statistics of the i th subsystem at k time, r s,i (k) represents the distributed residual of the i th subsystem, Θ i represents the covariance matrix of the distributed residual of the i th subsystem under normal condition.

[0063] When the attack occurs, r s,i is replaced by χ 2 The criterion of the inspection is:

[0064]

[0065] wherein, obeys χ 2 distribution with degree of freedom l, is a detection threshold; in the case of selecting false alarm rate α, the detection threshold is obtained by looking up χ 2 critical table.

[0066] The beneficial effects of the technical solution are:

[0067] The application relates to a kind of interconnection information physical system distributed attack detection methods based on equivalent space method, constructs interconnection information physical control system distribution and overall model, establishes two network attack models with concealment and defines local concealment in interconnection system;Distributed residual is constructed based on equivalent space method;And the influence of network attack on residual characteristics is analyzed, detection statistics is selected, detection mechanism and appropriate detection threshold are formulated, and the distributed detection of network attack with local concealment in interconnection system is completed.The proposed interconnection information physical control system distributed attack detection scheme based on equivalent space method can realize the detection of network attack with local concealment, meanwhile, the scheme does not need to involve complex structure observer, can simply and efficiently realize distributed network attack detection in interconnection system under the condition of guaranteeing system control system, effectively solves the limitations of existing interconnection information physical control system distributed attack detection method and other problems.

[0068] This invention proposes a distributed attack detection method for interconnected cyber-physical systems (CPSS) based on the equivalence space method, achieving efficient distributed attack detection on CPSS control systems. Utilizing the system's input-output relationships, residuals are constructed using the equivalence space method, and the overall residuals are decomposed into distributed residuals. When a subsystem of the CPSS is subjected to a stealthy network attack, it does not affect the residuals of the current subsystem, but it does affect the changes in the residual statistics of its neighboring subsystems. Therefore, the network attack is detected by utilizing these changes in residual statistics. This scheme only utilizes local system knowledge and input-output data, avoiding complex observer design and eliminating the need for active mechanism signals. Compared with existing detection schemes, the proposed equivalence space-based distributed attack detection scheme can achieve attack detection simply and efficiently, while ensuring the system control system's stability, and without requiring subsystems to possess global information. Attached Figure Description

[0069] Figure 1 This is a schematic diagram of a distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to the present invention.

[0070] Figure 2 This is a schematic diagram of the overlay attack model in an embodiment of the present invention;

[0071] Figure 3 This is a schematic diagram of a replay attack model in an embodiment of the present invention;

[0072] Figure 4 This is a topology diagram of an interconnected cyber-physical system in an embodiment of the present invention;

[0073] Figure 5 This is the result of overlay attack detection in an embodiment of the present invention;

[0074] Figure 6 This is a graph showing the detection rate of coverage attacks in an embodiment of the present invention;

[0075] Figure 7 This is the result of replay attack detection in an embodiment of the present invention;

[0076] Figure 8 This is a graph showing the replay attack detection rate in an embodiment of the present invention. Detailed Implementation

[0077] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described below with reference to the accompanying drawings.

[0078] In this embodiment, see Figure 1 As shown, this invention proposes a distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method, comprising the following steps:

[0079] Step 1: constructing an interconnected information physical system model, including a distributed system model and an overall system model;

[0080] Step 2: constructing a network attack model with concealment on the basis of the interconnected information physical system model, including a cover attack model and a replay attack model;

[0081] Step 3: for the network attack model with concealment, constructing an overall residual of the interconnected information physical system based on an equivalent space method, and then splitting the overall residual into distributed residuals according to a system dimension relationship;

[0082] Step 4: based on the obtained distributed residuals, analyzing the influence of a network attack with local concealment on a neighbor subsystem residual, and analyzing the change of the residual when the attack occurs;

[0083] Step 5: selecting a suitable detection statistic according to the change of the residual, formulating a corresponding detection strategy and selecting a suitable detection threshold, and completing attack detection.

[0084] As an optimization scheme of the above embodiment, in the step 1, the distributed model and the overall system model of the interconnected information physical control system are respectively constructed, and the distributed system model is:

[0085]

[0086] wherein k represents a time, x i is a state vector of a current subsystem, x j is a state vector of other subsystems, u i is an input vector, y i is an output vector, w i and q i are independent and identically distributed Gaussian random vectors with mean values of 0 and covariance matrices of Q and W respectively, Q and W are positive definite diagonal matrices, A ii , A ij , B i , C i are constant matrices, N represents the number of subsystems in the entire interconnected information physical system, and subscripts i and j represent the i th subsystem and the j th subsystem respectively. Define as a set of all subsystems directly connected to the i th subsystem in the physical layer, when , A ij = 0.

[0087] The overall system model of the interconnected information physical system is:

[0088]

[0089] Where χ is the state vector containing all subsystems, u is the input vector containing all subsystems, y is the output vector containing all subsystems, w and q are Gaussian random vectors containing all subsystems, and A, B and C are constant matrices.

[0090] C = diag{C1,C2,…C} N}, A = [A ij ] N×N B through C in C i Replace with B i get.

[0091] As an optimized implementation of the above embodiments, in step 2, a network attack model with stealth is constructed, namely, overlay attack and replay attack;

[0092] like Figure 2 As shown, the coverage attack model is as follows:

[0093]

[0094] Where k represents time, u(k) represents the normal control input signal, and y(k) represents the normal measurement output signal. This indicates that the physical control object has received a control input signal that has been injected with an attack signal. The output measurement signal represents the injected attack signal received by the detector, and η(k) and γ(k) represent the attack signal injected by the overlay attack through the communication link;

[0095] When establishing attack signals η(k) and γ(k), the detector is made unable to distinguish between the attacked output signal and the normal output signal:

[0096]

[0097] in, This represents the system knowledge matrix possessed by the attacker. This represents the state vector that represents the attacker's design of the attack signal;

[0098] Assuming the attacker has complete knowledge of the system, that is And in If the attack begins at a certain time, the overlay attack is completely covert.

[0099] like Figure 3 As shown, the replay attack model is as follows:

[0100] The replay attack is divided into two stages: stage one is the eavesdropping stage, the attacker records the output signal and the input signal for a long enough time by eavesdropping; stage two is the replay stage, the attacker replays the past output signal at the detector end to cover the influence of the injection attack on the input signal on the output;

[0101]

[0102] wherein, τ k >0 represents replaying the past time, a(k) represents the attack signal injected by the attacker, represents the control input signal of the physical control object received by the injected attack signal, represents the output measurement signal received by the detector at the past τ k time.

[0103] As an optimized implementation of the above embodiment, in step 3, for a network attack model with concealment, the overall residual error of the interconnected information physical system is constructed based on the equivalent space method, and the overall residual error is split into distributed residual errors according to the dimension relationship of the system, including the steps of:

[0104] Firstly, based on the overall model of the interconnected system, it is assumed that q(k) = 0 and w(k) = 0; the matrix is defined as:

[0105] y s (k) = H o,s x(k-s) + H u,s u s (k);

[0106] wherein, s represents the window length, y s (k), x(k-s), and u s (k) are matrices composed of the measurement output vector, the state vector, and the control input vector of the system at the past time, H o,s , and H u,s are matrices composed of the system matrices A, B, and C; according to the rank relationship of the system matrix, there is at least one non-zero vector v s such that v s H o,s = 0;

[0107] Therefore, the residual error r s (k) with the window length s generated based on the equivalent space method is:

[0108] r s (k) = v s (y s (k) - H u,s u s (k));

[0109] Reconsidering the influence of w(k), q(k) on the residual generator, repeat the above steps to obtain:

[0110] y s (k)=H o,s x(k-s)+H u,s u s (k)+H e,s e s (k);

[0111] where e s (k) is a matrix composed of process noise and measurement noise of past time of the system, H e,s is a matrix composed of system matrix C, A;

[0112] Finally, the overall residual generated is:

[0113] r s (k)=v s (y s (k)-H u,s u s (k))=v s H e,s e s (k);

[0114] Then, the overall residual is split into distributed residuals by row:

[0115]

[0116] where r s,i represents the distributed residual corresponding to the i-th subsystem, v s,i is a non-zero vector, is a matrix composed of the i-th subsystem corresponding row in H o,s , H u,s ; Since the dimensions of H o,s and H u,s are l m×N×(s+1) , the number of rows row i corresponding to the i-th subsystem should be composed of m arithmetic sequences; And the common difference of the m arithmetic sequences is s+1, and the first term is {m×(i-1)+1, m×(i-1)+2, …, m×i} respectively;

[0117] Thus:

[0118] where Θ i is the covariance matrix of r s,i (k), is a matrix composed of the i-th subsystem corresponding row in H e,s .

[0119] As an optimized implementation of the above embodiment, in step 4, based on the obtained distributed residual, the influence of the network attack with local concealment on the neighbor subsystem residual is analyzed, and the change of the residual when the attack occurs is analyzed, including the steps of:

[0120] Assuming that only the jth subsystem is attacked, according to the distributed system model, the physical dynamics model of the jth subsystem under attack is represented as:

[0121]

[0122] where A ii , A ij , A jj , B i , C i are constant matrices, u j,a (k) represents the control input signal received by the jth subsystem physical control object under attack, which is represented as u j,a (k) = u j (k) + a j (k), a j (k) represents the malicious signal injected by the attacker of the jth subsystem, u j (k) represents the input vector of the jth subsystem, x j represents the state vector of the jth subsystem, y j represents the output vector of the jth subsystem, w j is a Gaussian random vector; q j (k) is a Gaussian random vector, and γ j (k) is an attack vector injected by the sensor output channel.

[0123] Then, the x j of the physical dynamics model of the ith subsystem is:

[0124]

[0125] q i (k) is a Gaussian random vector, and the following is obtained by derivation:

[0126]

[0127] wherein, are matrices composed of the row vectors corresponding to the ith subsystem in H o,s , H u,s , H e,s , a s,i (k) is a matrix composed of attack signals of the ith subsystem, y s,i (k), x i(k-s), u s,i (k) is the matrix composed of the measurement output vector, state vector and control input vector of the ith subsystem at the past time of the system, e s,i (k) is the matrix composed of the process noise and measurement noise of the ith subsystem at the past time of the system;

[0128] The distributed residual of the ith subsystem is:

[0129] represents the residual of the ith subsystem when the system is attacked, assuming that the attack starts from k a = k-s, a s (k)≠0, and The kernel space of is, then

[0130]

[0131] represents that the covert attack implemented on the jth subsystem will cause the covariance of the residual of its neighbor subsystem to change;

[0132] When the jth subsystem is attacked to meet the replay attack model, the same conclusion is obtained.

[0133] As an optimized implementation of the above embodiment, in step 5, according to the change of the residual, a suitable detection statistic is selected, a corresponding detection strategy is formulated, and a suitable detection threshold is selected to complete attack detection, including:

[0134] The residual evaluation and threshold design are performed by a method based on χ 2 test, and the statistical quantity is defined as:

[0135]

[0136] wherein, represents the detection statistic of the ith subsystem at k, r s,i (k represents the distributed residual of the ith subsystem, Θ i represents the covariance matrix of the distributed residual of the ith subsystem under normal conditions;

[0137] When the attack occurs, r s,i is replaced by χ 2 test criterion is:

[0138]

[0139] wherein, obeys χ 2 distribution with degree of freedom l, to detect the threshold value; by looking up χ 2 Critical table is obtained.

[0140] Examples:

[0141] Consider the cyber-physical system with parameters as follows, the topological structure is as shown in Figure 4

[0142] B1=B2=B3=B4=[1 1 1 1] T ;

[0143]

[0144] s=9; k=800; W=I4; Q=I2;

[0145] Suppose that the cover attack is implemented on the first subsystem between k=400 and k=600, and let a1=10. The χ 2 The change of detection statistics is as shown in Figure 5 , and the detection rate result is as shown in Figure 6 . It can be seen from Figure 5 that after the attack starts, the statistics of the first subsystem do not change much, but the residual statistics of its neighbor subsystems exceed the threshold value, and the cover attack detection is realized.

[0146] Suppose that the replay attack is implemented on the first subsystem between k=400 and k=800, the output data of τ k =200 is replayed, and the attack signal a1=10 is applied between k=400 and k=600. The χ 2 The change of detection statistics is as shown in Figure 7 , and the detection rate result is as shown in Figure 8 . It can be seen from Figure 7 that after the attack starts, the statistics of the first subsystem do not change much, but the residual statistics of its neighbor subsystems exceed the threshold value, and the replay attack detection is realized.

[0147] The basic principles and main features of the present application and the advantages of the present application are shown and described above. It should be understood by those skilled in the art that the present application is not limited by the above examples, and the above examples and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.​

Claims

1. A distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method, characterized in that, Including the following steps: Step 1: Construct an interconnected cyber-physical system model, including a distributed system model and an overall system model; Step 2: Construct a stealthy network attack model based on the interconnected cyber-physical system model, including an overlay attack model and a replay attack model; Step 3: For network attack models with stealth, construct the overall residual of the interconnected cyber-physical system based on the equivalence space method, and then decompose the overall residual into distributed residuals according to the system dimension relationship; Step 4: Based on the obtained distributed residuals, analyze the impact of network attacks with local concealment on the residuals of neighboring subsystems, and analyze the changes in residuals when the attack occurs; Step 5: Select appropriate detection statistics based on the changes in residuals, formulate corresponding detection strategies and select appropriate detection thresholds to complete attack detection.

2. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 1, characterized in that, The distributed system model is as follows: Where k represents time, x i x is the state vector of the current subsystem. j It is the state vector of other subsystems, u i It is the input vector, y i It is the output vector, w i q i Let A be an independent and identically distributed Gaussian random vector with mean 0 and covariance matrices Q and W, respectively, where Q and W are positive definite diagonal matrices. ii A ij B i C i It is a constant matrix, where N represents the number of subsystems in the entire interconnected cyber-physical system, and the subscripts i and j represent the i-th subsystem and the j-th subsystem, respectively.

3. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 2, characterized in that, The overall system model is as follows: Where x is the state vector containing all subsystems, u is the input vector containing all subsystems, y is the output vector containing all subsystems, w and q are Gaussian random vectors containing all subsystems, and A, B and C are constant matrices. C = diag{C1,C2,…C} N }, A = [A ij ] N×N B through C in C i Replace with B i get.

4. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 1, characterized in that, The overlay attack model is as follows: Where k represents time, u(k) represents the normal control input signal, and y(k) represents the normal measurement output signal. This indicates that the physical control object has received a control input signal that has been injected with an attack signal. The output measurement signal represents the injected attack signal received by the detector, and η(k) and γ(k) represent the attack signal injected by the overlay attack through the communication link; When establishing attack signals η(k) and γ(k), the detector is made unable to distinguish between the attacked output signal and the normal output signal: in, This represents the matrix of system knowledge possessed by the attacker. This represents the state vector that represents the attacker's design of the attack signal; Assuming the attacker has complete knowledge of the system, that is And in If the attack begins at a certain time, the overlay attack is completely covert.

5. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 4, characterized in that, The replay attack model is as follows: The replay attack is carried out in two phases: Phase 1 is the eavesdropping phase, in which the attacker eavesdrops and records the output and input signals for a sufficiently long time; Phase 2 is the replay phase, in which the attacker replays the past output signal at the detector end, thereby masking the impact of the injection attack on the input signal on the output. Where, τ k >0 indicates replaying a past moment, and a(k) represents the attack signal injected by the attacker. This represents the control input signal received by the physically controlled object from the injected attack signal. This indicates that the detector received the replayed data from the past τ. k The output measurement signal at any given time.

6. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 3, characterized in that, For stealthy network attack models, the overall residual of an interconnected cyber-physical system is constructed based on the equivalence space method. Then, the overall residual is decomposed into distributed residuals according to the system dimensionality relationship. The steps include: First, based on the overall model of the interconnected system, assuming q(k) = 0 and w(k) = 0; define the matrix: y s (k)=H o,s x(k-s)+H u,s u s (k); Where s represents the window length, y s (k), x(ks), u s (k) is a matrix composed of the system's past measurement output vector, state vector, and control input vector, H o,s H u,s It is a matrix composed of system matrices A, B, and C; according to the relationship of the rank of the system matrices, there exists at least one non-zero vector v. s , making v s H o,s =0; Therefore, the residual r with a window length of s generated based on the equivalent space method s (k) is: r s (k)=v s (y s (k)-H u,s u s (k)); Reconsider the effects of w(k) and q(k) on the residual generator, and repeat the above steps to obtain... y s (k)=H o,s x(k-s)+H u,s u s (k)+H e,s e s (k); Among them, e s (k) is a matrix composed of the process noise and measurement noise of the system at past time points, H e,s It is a matrix composed of system matrices C and A; Finally, the generated global residual is: r s (k)=v s (y s (k)-H u,s u s (k))=v s H e,s e s (k); Then, the overall residual is split into distributed residuals by row: Where r s,i This represents the distributed residual corresponding to the i-th subsystem. It is a non-zero vector. It is H o,s H u,s The matrix formed by the rows corresponding to the i-th subsystem; since H o,s and H u,s The dimensions are all l m×N×(s+1) Then the row number corresponding to the i-th subsystem is row i It should consist of m arithmetic sequences; and the common difference of these m arithmetic sequences is s+1, and the first term is all the elements in {m×(i-1)+1,m×(i-1)+2,…,m×i}; thereby: Where, Θ i For r s,i The covariance matrix of (k), It is H e,s The matrix formed by the rows corresponding to the i-th subsystem.

7. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 1, characterized in that, Based on the obtained distributed residuals, the impact of network attacks with local anonymity on the residuals of neighboring subsystems is analyzed, including the following steps: Assuming only the j-th subsystem is attacked, according to the distributed system model, the physical dynamics model of the attacked j-th subsystem is expressed as: Among them, A jj B j C j It is a constant matrix, u j,a (k) represents the attacked control input signal received by the physical control object of the j-th subsystem, denoted as u. j,a (k)=u j (k)+a j (k), a j (k) represents the malicious signal injected by the attacker in the j-th subsystem, u j (k) represents the input vector of the j-th subsystem, x j (k) represents the state vector of the j-th subsystem, y j (k) represents the output vector of the j-th subsystem, w j (k) is a Gaussian random vector; q j (k) is a Gaussian random vector, γ j (k) is the attack vector injected into the sensor output channel; Then the physical dynamics model of the i-th subsystem has x j for: q i (k) is a Gaussian random vector, A ii A ij B i C i It is a constant matrix; Then, through derivation, we obtain: in, H respectively o,s H u,s H e,s The matrix formed by the row vectors corresponding to the i-th subsystem, a s,i (k) is the matrix composed of attack signals of the i-th subsystem, y s,i (k), x i (ks), u s,i (k) are matrices representing the measurement output vector, state vector, and control input vector of the i-th subsystem at past time points, respectively. s,i (k is the matrix of the i-th subsystem composed of the process noise and measurement noise at past moments; then the distributed residual of the i-th subsystem is: This represents the residual of the i-th subsystem when the system is attacked, assuming the attack originates from k. a =Starting from time ks, we have a s,i (k)≠0, and The core space then has This indicates that a covert attack on the j-th subsystem will cause a change in the covariance of the residuals of its neighboring subsystems; The same conclusion is reached when the j-th subsystem satisfies the replay attack model.

8. The distributed attack detection method for interconnected cyber-physical systems based on the equivalence space method according to claim 1, characterized in that, Based on the changes in residuals, select appropriate detection statistics, formulate corresponding detection strategies, and choose suitable detection thresholds to complete attack detection, including: Using χ 2 The test method involves residual evaluation and threshold design, and the statistic is defined as follows: in, Let r represent the detection statistics of the i-th subsystem at time k. s,i (k) represents the distributed residual of the i-th subsystem, Θ i This represents the covariance matrix of the distributed residuals of the i-th subsystem under normal conditions. When the attack occurs, r s,i Replace with χ 2 The criteria for the test are: in, Obeying the x-axis with l degrees of freedom 2 distributed, To determine the detection threshold, given a false alarm rate α, X is searched. 2 Critical list obtained.

Citation Information

Patent Citations

  • Replay attack detection method for cyber-physical industrial control system

    CN116820071A

  • False data injection and concealment test method, system and equipment for safety test of process industry system

    CN119167255A