Centralized trust evaluation method and device based on cloud theory and storage medium
By adopting a centralized trust assessment method based on cloud theory and combining VAE and SVM models, the fuzziness and uncertainty of trust models in underwater wireless sensor networks are solved, achieving efficient identification of malicious nodes and improved security of cluster head election, thus extending network lifetime.
Patent Information
- Application Number
- CN202510013784.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-01-06
AI Technical Summary
Existing trust models in underwater wireless sensor networks neglect the ambiguity and uncertainty of trust in clustered topologies, rely on manually set thresholds and standard trust clouds, and fail to effectively identify malicious nodes, resulting in network security and insecurity in the cluster head election process.
A centralized trust evaluation method based on cloud theory is adopted. Trust evidence is collected by member nodes in the cluster. The cluster head node calculates the trust value, and the sink node updates the trust model of the entire network. The VAE and SVM models are combined to identify malicious nodes, and the LEACH algorithm is improved to improve the security of cluster head election.
It achieves a high recognition rate of malicious nodes (above 99.3%) and a low false detection rate (below 0.24%), improves the security of the cluster head election process, reduces the proportion of malicious nodes, and extends the network life.
Smart Images

Figure CN119835647B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of trust model of underwater wireless sensor networks, and particularly relates to a trust evaluation method of underwater wireless sensor networks. BACKGROUND
[0002] Underwater wireless sensor networks (UWSNs) as an important part of underwater information networks, have important significance for expanding the monitoring range of underwater information networks and perfecting the three-dimensional information network of sea, land, air and sky, and have been widely applied in the fields of pollution monitoring, oil and gas exploration, navigation control, tsunami warning and military and security.
[0003] UWSNs is a distributed wireless communication network formed by self-organizing using underwater acoustic wireless communication mode by deploying a large number of communication nodes formed by low-cost, carrying micro-sized acoustic, magnetic, marine biochemical and other sensors to the designated sea area. The nodes in the network cooperate with each other to complete the work of environmental monitoring, data collection, etc. The collected data is transmitted to the underwater sink node or the water surface base station through hop-by-hop forwarding, and then transmitted to the user through radio frequency communication mode or wired communication mode.
[0004] Security problem is an important problem in the field of UWSNs. The security requirements of UWSNs include node authentication, data confidentiality, data integrity, etc. Many researchers use cryptographic methods to ensure the above security requirements.
[0005] However, sensor nodes are disposable and low-cost, so most of these nodes are not implemented with tamper-proofing technology, and at the same time, sensor nodes are often deployed in unattended or even hostile areas, so it is possible for a malicious attacker to make a compromised node by physically invading and redeploying the sensor node, so that it can be integrated into the network to launch malicious attacks (such as tampering attacks, Sybil attacks and selfish attacks, etc.). Since the compromised node is physically attacked, its memory is parsed and rewritten, and it already has the encryption information required by the legitimate node, so the cryptographic technology cannot provide sufficient protection for the network in the presence of compromised nodes in the network.
[0006] The existence of compromised nodes in the network will cause new security risks. A node may pass the traditional encryption hard security check (authorization and access), but still report false measurement results to gain an advantage over other nodes. This security risk is called "soft security threat".
[0007] Trust management mechanism is considered as an effective complement to traditional cryptographic mechanism, which is composed of a series of trust-based security technologies to protect the network from compromised nodes (i.e. to deal with soft security threats). Since Marsh introduced the trust research into the field of computer, many trust models have been proposed in distributed networks, ubiquitous computing, peer-to-peer computing, self-organizing networks and other aspects to improve the security, reliability and fairness of the system.
[0008] There are mainly three topologies in UWSNs: centralized, distributed and clustered. The existing trust models for clustered network topology have the following problems:
[0009] (1) The traditional trust model ignores the fuzziness and uncertainty of trust when using precise values to represent trust, which will affect the trust evaluation effect.
[0010] (2) The method of identifying malicious nodes in traditional trust model relies on the threshold and standard trust cloud set by human, and the strong subjectivity will limit the detection rate of malicious nodes.
[0011] (3) Due to the lack of relevant field data and simulation data sets, it is difficult to apply machine learning methods in trust models.
[0012] In addition, in the clustered network topology, underwater nodes are dynamically clustered, each cluster has a cluster head node and multiple intra-cluster member nodes, intra-cluster member nodes send data packets to cluster head nodes, and cluster head nodes forward to surface sink nodes after performing data processing functions. UWSNs nodes are energy-constrained, and cluster-based routing protocols can balance node energy consumption and prolong network lifetime by designing cluster head selection methods, which are common routing protocols in UWSNs clustered network topology.
[0013] However, the existing cluster-based routing protocols mainly consider the factors such as the distance of nodes from the surface sink node, residual energy, node density, etc. in the cluster head selection process, while ignoring security issues. When malicious nodes in the network act as intra-cluster member nodes, selfish attacks will reduce their own energy consumption, which will destroy the energy balance between nodes and lead to unfair cluster head election; when launching tampering attacks, it will tamper with its own sensor data, which will damage the authenticity of data; when launching the Sybil attack, it will increase the possibility of malicious nodes becoming cluster head nodes by forging identity. In addition, the clustered network topology of UWSNs determines that once the cluster head node is compromised, the communication security of the entire network cannot be guaranteed, and when malicious nodes become cluster head nodes, the harm of malicious attacks launched by them will be greater.
[0014] In summary, there is an urgent need for a trust evaluation method (or trust model) that can describe the fuzziness and uncertainty of trust and avoid the limitations of artificially setting parameters on model trust evaluation, and a secure security mechanism to ensure the security of the cluster head election process in the cluster-based routing protocol. SUMMARY
[0015] The application provides a centralized trust evaluation method based on cloud theory, which solves the problems of ignoring the fuzziness and uncertainty of trust and relying on artificially set threshold and standard trust cloud in the existing trust model for a clustered network topology.
[0016] The centralized trust evaluation method based on cloud theory provided by the application is applied to an underwater wireless sensor network with a clustered network topology, and the method comprises the following steps:
[0017] The trust evidence collection step: the member nodes in the cluster collect packet trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to the cluster head node;
[0018] The trust calculation step: the cluster head node calculates the packet trust value, data trust value and energy trust value of the member nodes in the cluster based on the three types of trust evidence collected by the member nodes in the cluster, and sends the three types of trust values to the sink node;
[0019] The trust updating step: the sink node calculates and updates the packet cloud model, data cloud model and energy cloud model of all nodes in the network using the reverse cloud algorithm according to the trust values of all nodes in the network;
[0020] The malicious node step: the sink node combines the three types of cloud models of the node to be evaluated into a 1*9 tensor as an output sample input into the VAE model, and obtains the output of the VAE model as an output sample; calculates the mean square error between the input sample and the output sample as the reconstruction error; inputs the reconstruction error into the SVM model for node binary classification to realize malicious node identification.
[0021] Further, a preferred embodiment is provided, in which the cluster head node calculates the packet trust value of the member nodes in the cluster based on the packet trust evidence collected by the member nodes in the cluster:
[0022]
[0023] wherein T packet is the packet trust value; PN is the packet trust evidence; PN average is the average number of packets sent by the member nodes in the cluster within a given time period counted by the cluster head node.
[0024] Further, a preferred embodiment is provided, in which the cluster head node calculates the data trust value of the member nodes in the cluster based on the data trust evidence collected by the member nodes in the cluster:
[0025] The data trust evidence of each member node in the cluster is converted into a cloud vector using a reverse cloud algorithm; the cloud vector includes three parameters: expectation ex, entropy en, and hyper entropy he;
[0026] The estimated values of the three parameters are obtained, and the estimated values of the three parameters are:
[0027]
[0028] wherein the mean value is and the variance S 2 is expressed as:
[0029]
[0030] wherein x q represents the data trust evidence of the member node q in the cluster, q = 1, 2,..., M-1;
[0031] The cluster head node uses a cloud similarity algorithm to quantify the similarity between the cloud vector of each member node in the cluster and the cloud vector of any other member node in the cluster;
[0032] The similarity between the two cloud vectors is represented by the cosine value of the angle between the two cloud vectors, and the similarity between the two cloud vectors is:
[0033]
[0034] wherein and represent the vectors composed of the numerical features of the two cloud vectors C i and C j , and i and j represent the cloud vectors C i and C j The corresponding member nodes before conversion using the reverse cloud algorithm; wherein C i = (ex i , en i , he i ), C j = (ex j , en j , he j );
[0035] The relative trust RT ij of the member node i and the member node j in the cluster in the data of this period is expressed as:
[0036]
[0037] The cluster head node calculates the data trust value of each member node in the cluster:
[0038] The data trust value T data The average value of the relative trust of member node i by all other member nodes in the cluster except member node i:
[0039]
[0040] Wherein, M is the total number of member nodes in the cluster; k is any other member node in the cluster except member node i, k = 1, 2, …, M, k ≠ i; T data ∈ [0, 1].
[0041] Further, a preferred embodiment is provided, in which the cluster head node calculates the energy trust value of the member nodes in the cluster based on the energy trust evidence collected by the member nodes in the cluster:
[0042] The energy trust evidence is modified:
[0043]
[0044] Wherein, E original is the energy consumption of the member node in the cluster in a given time period, as the energy trust evidence; E consume is the modified energy consumption, as the modified energy trust evidence; d is the straight-line distance between the member node in the cluster and the cluster head node; f is the center frequency used in acoustic communication; A(d, f) is the attenuation function;
[0045] Based on the modified energy consumption E consume , the energy trust value T energy is calculated using the normal distribution probability density function:
[0046]
[0047] Wherein, f(x) is the normal distribution probability density function of the modified energy consumption E consume ; x is a random variable subject to normal distribution; E average is the mean value of the normal distribution, which is the mean value of the modified energy consumption of all member nodes in the cluster calculated by the cluster head node; σ is the standard deviation of the normal distribution; e evaluated = E consume .
[0048] Further, a preferred embodiment is provided, in which the VAE model is obtained after training the initial VAE model using the VAE dataset;
[0049] The VAE dataset is cloud model data generated by nodes with attack node sample existing, which is collected by network simulation technology.
[0050] The application further provides a centralized trust evaluation device based on a cloud theory, which is applied to an underwater wireless sensor network in a clustered network topology, and comprises the following modules:
[0051] A trust evidence collection module: member nodes in a cluster collect packet trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to a cluster head node;
[0052] A trust calculation module: the cluster head node calculates packet trust values, data trust values and energy trust values of the member nodes in the cluster based on the three types of trust evidence collected by the member nodes, and sends the three types of trust values to a sink node;
[0053] A trust updating module: the sink node calculates and updates packet cloud models, data cloud models and energy cloud models of all nodes in the network by using a reverse cloud algorithm according to the trust values of the nodes in the network;
[0054] A malicious node module: the sink node combines the three types of cloud models of an evaluated node into a 1*9 tensor as an input sample of a VAE model, obtains an output of the VAE model as an output sample, calculates a mean square error between the input sample and the output sample as a reconstruction error, inputs the reconstruction error into an SVM model for node binary classification, and realizes malicious node identification.
[0055] The application further provides a computer device, which comprises a processor and a memory, the memory is used for storing executable instructions of the processor, and the processor is configured to execute the centralized trust evaluation method based on the cloud theory by executing the executable instructions.
[0056] The application further provides a computer storage medium, wherein the computer storage medium stores a computer program, and the computer program is used for executing the centralized trust evaluation method based on the cloud theory.
[0057] The application further provides a computer program product, which comprises computer programs / instructions, and the computer programs / instructions are used for realizing the steps of the centralized trust evaluation method based on the cloud theory when executed by a processor.
[0058] The application further provides a cluster head election method for improving the LEACH algorithm, and the method comprises the following steps:
[0059] Each node obtains an updated mean square error mse of itself by using the centralized trust evaluation method based on the cloud theory.
[0060] Each node uses an improved cluster head election threshold function T based on the number of times it has served as a cluster head node, a priori determined proportion of cluster head nodes and mse imp (n) calculating a cluster head election threshold;
[0061] Each node generates a random number itself; the random number is generated by a random variable within [0, 1]; the random number is subject to uniform distribution;
[0062] Each node compares the random number generated by itself with the cluster head election threshold:
[0063] If less than the cluster head election threshold, the node becomes a cluster head node in the current large period;
[0064] Otherwise, the node does not become a cluster head node;
[0065] Improved cluster head election threshold function T imp (n) as follows:
[0066]
[0067] F(mse)=1.02^(24^(10*mse));
[0068] Wherein, mse [0, +∞);P is a priori determined proportion of cluster head nodes in the network;R is the current round;G is the set of nodes that have not become cluster head nodes in the last 1 / P rounds.
[0069] The application has the following beneficial effects:
[0070] 1. The centralized trust evaluation method based on cloud theory, by considering the characteristics of selfish attacks, tampering attacks and Sybil attacks, designs multi-dimensional trust evidence and trust value algorithm; by using the advantages of cloud model to describe trust fuzziness and uncertainty, the node credibility is qualitatively evaluated.
[0071] 2. The centralized trust evaluation method based on cloud theory, by collecting data based on network simulation technology (NS-3 software) and training machine learning method model, the limitation of artificial parameter setting on model trust evaluation is avoided.
[0072] 3. The centralized trust evaluation method based on cloud theory, the identification rate of malicious nodes is finally maintained above 99.3%, the false detection rate is maintained below 0.24%, and the malicious nodes can be effectively and accurately identified.
[0073] 4. The cluster head election method for improving the LEACH algorithm, the soft security mechanism for routing based on the trust model effectively reduces the proportion of malicious nodes in the cluster head node in the improved LEACH protocol, and the proportion is finally basically stabilized below 1.4%, thereby improving the security of the cluster head election process.
[0074] The centralized trust evaluation method and device based on the cloud theory and the storage medium are suitable for trust evaluation of nodes in a clustered network topology. BRIEF DESCRIPTION OF DRAWINGS
[0075] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.
[0076] Figure 1 For an embodiment of the present application, a flowchart of the centralized trust evaluation method based on the cloud theory;
[0077] Figure 2 For an embodiment of the present application, a flowchart of the cluster head election method for improving the LEACH algorithm;
[0078] Figure 3 For an embodiment of the present application, a structure diagram of the VAE model;
[0079] Figure 4 For an embodiment of the present application, a cloud model vector diagram of various attack nodes; wherein, Figure 4 (a) is a vector diagram of a selfish attack node cloud model; Figure 4 (b) is a vector diagram of a tampering attack node cloud model; Figure 4 (c) is a vector diagram of a witch attack node cloud model;
[0080] Figure 5 For an embodiment of the present application, a result diagram of grid optimization of SVM model parameters;
[0081] Figure 6 For an embodiment of the present application, a F(mse) function curve diagram; it can be seen that when mse∈[0, 0.15], F(mse) increases with the increase of mse, and the increasing amplitude gradually increases. In fact, when mse∈[0, +∞), F(mse) monotonically increases, and F(mse)∈[1, +∞);
[0082] Figure 7 For an embodiment of the present application, a diagram of change of detection rate and false detection rate of the trust evaluation method with simulation time;
[0083] Figure 8 Figure 4 is a plot of the node cloud model mean square error (MSE) as a function of simulation time for an embodiment of the present application;
[0084] Figure 9 Figure 5 is a plot of the proportion of malicious nodes in the cluster head nodes as a function of simulation time for an embodiment of the present application;
[0085] Figure 10 Figure 6 is a plot of the UWSNs network topology for an embodiment of the present application;
[0086] Figure 11 Figure 7 is a plot of the classification of underwater routing protocols for an embodiment of the present application
[0087] Figure 12 Figure 8 is a plot of the general framework of a centralized reputation system for an embodiment of the present application; wherein, Figure 12 (a) shows the interactions that have taken place between the agents, after each interaction, both agents provide an evaluation of each other's performance, these evaluations are uploaded to the reputation center; the reputation center collects all evaluations and continuously updates the reputation score of each agent based on the received evaluations; Figure 12 (b) shows that agents A and B are currently considering the upcoming interaction between them, the updated reputation score will be provided to all agents for viewing and can be used by the agents to decide whether to interact with a particular agent. DETAILED DESCRIPTION
[0088] In order to make the technical solutions and advantages of the present application clearer, the specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings. The various embodiments described below are only some preferred solutions of the present application, rather than all embodiments; the various embodiments described below are intended to explain the present application, and cannot be understood as limiting the present application; the reasonable combinations of the technical features defined in the various embodiments of the present application, and all other embodiments obtained by those skilled in the art without making creative efforts based on the embodiments of the present application, all belong to the scope of protection of the present application.
[0089] In order to better parameterize the specific embodiments, some concepts of the design are described as follows:
[0090] Regarding the topology of UWSNs:
[0091] It should be noted that there are mainly three topologies for communication between UWSNs nodes: centralized, distributed and clustered. Among them, the coverage range of the centralized network topology is generally small, so from the perspective of expanding the network monitoring range, the commonly used are the distributed network topology and the clustered network topology.
[0092] In the UWSNs network of the cluster network topology, the identities of the underwater nodes are divided into cluster member (CM) nodes and cluster header (CH) nodes, data is aggregated from the cluster member nodes to the cluster header nodes, and then sent to the sink node on the water surface by the cluster header nodes.
[0093] The cluster network has good expansibility, and the network size is not limited, which is suitable for the UWSNs with large deployment range, sparse nodes and requirement for scalability.
[0094] However, compared with the cluster member nodes, the cluster header nodes usually consume energy faster because they perform high-energy-consuming tasks such as data processing and forwarding. At the same time, because of the special role of the cluster header nodes, malicious nodes may compete to become cluster header nodes by improper means and further perform more effective attacks, which makes this type of network face serious single-point failure risk.
[0095] In the embodiment, the trust evaluation method (or called trust model) is applied to the cluster network topology.
[0096] In the cluster network topology:
[0097] The underwater nodes are homogeneous and uniformly distributed in the cubic water area, and a sink node is located at the center of the water surface;
[0098] All nodes have no mobility, and each has a unique node ID in the network to determine the identity;
[0099] The number of data packets generated by the underwater nodes per second as a random variable follows a Poisson distribution;
[0100] The cluster member nodes send packets to the cluster header nodes as source nodes;
[0101] The cluster header nodes collect cluster data packets and perform information processing, and send the data packets to the sink node on the water surface;
[0102] The data packets are considered to be successfully delivered after reaching the sink node.
[0103] Regarding the routing protocol of UWSNs:
[0104] It should be noted that the routing protocol design is an important research content in UWSNs. The role of the routing protocol is to find a path from the source node to the destination node and correctly forward the data packets along the path. The main goal of the routing protocol design in UWSNs is to establish an efficient energy path, prolong the life of the network as much as possible, improve the fault tolerance of the routing, and form a reliable data forwarding mechanism.
[0105] According to the characteristics of underwater routing protocols, the protocols can be divided into three categories: energy-based routing protocols, data-based routing protocols, and geographic information-based routing protocols.
[0106] The nodes of UWSNs are powered by batteries and it is difficult to replenish the power, so the energy of the nodes is limited. Energy-based routing protocols can improve the energy efficiency of the network, which is important to prolong the life of the network. Energy-based routing protocols select the most suitable path from the source node to the destination node based on the residual energy of the sensor nodes to forward data packets. Energy-based routing protocols can be further divided into energy-aware routing protocols and cluster-based routing protocols. Among them, the cluster-based routing protocol divides the entire network into dynamic clusters, each cluster has a cluster head node and multiple intra-cluster member nodes. Intra-cluster member nodes transmit data to cluster head nodes, and cluster head nodes perform data processing tasks and transmit processed data to surface sink nodes. Since the energy consumption of cluster head nodes is large, cluster-based underwater routing protocols balance the energy consumption between nodes in the network by designing methods to select cluster heads, thereby prolonging the life of the network.
[0107] It should be noted that the clustering routing protocol in traditional wireless sensor networks clusters the network, which can balance the energy consumption of the network and prolong the life cycle of the network. However, in traditional clustering algorithms, cluster heads are pre-selected and remain fixed throughout the system's operation period, which can quickly cause the selected cluster heads to lose working ability due to energy depletion, resulting in all nodes belonging to these clusters being unable to work normally. To solve this problem, the skilled person in the art proposes the LEACH protocol.
[0108] LEACH is a self-organizing and adaptive clustering protocol that uses randomization to evenly distribute the energy load of sensors in the network. In LEACH, sensor nodes self-organize into local clusters, with one node acting as a cluster head node and other nodes becoming intra-cluster member nodes. The location of the cluster head node is randomly rotated among sensor nodes to avoid rapid depletion of the energy of a single sensor node.
[0109] The LEACH protocol is divided into four phases: the advertisement phase, the cluster set-up phase, the schedule creation phase, and the data transmission phase. The protocol content of each phase is as follows:
[0110] In the advertisement phase, each node decides whether to become the cluster head of the current round based on the number of times it has served as a cluster head and the cluster head node ratio determined in advance.
[0111]
[0112] where P is a priori determined proportion of cluster head nodes in the network, r is the current round, and G is the set of nodes that have not been cluster heads in the last 1 / P rounds. Through simple calculation, it can be known that the design of the cluster head election probability formula T(n) aims to maintain the proportion of the cluster head nodes selected in each round in the total number of nodes in the network, and prevent the nodes that have recently become cluster heads from being re-elected as cluster heads in the short term.
[0113] Each node that elects itself as a cluster head will consume the same transmission energy to broadcast advertisement information to the remaining non-cluster head nodes, and the non-cluster head nodes remain in a listening state and decide the cluster head to which they belong in the current round based on the received signal strength. In order to enter a cluster, the non-cluster head nodes will select the cluster head corresponding to the packet with the maximum signal strength that they have listened to and enter the cluster.
[0114] In the clustering phase, after each non-cluster head node decides which cluster it belongs to, it must notify the cluster head node that it will become a member node of the cluster.
[0115] In the scheduling phase, based on the cluster entry information of the non-cluster head nodes, the cluster head node creates a TDMA scheduling table according to the number of nodes in the cluster, and arranges the data transmission time of each member node in the cluster.
[0116] In the data transmission phase, the nodes in the cluster transmit data to the cluster head node using as little energy as possible according to the needs and arrangements, and the cluster head node first organizes and fuses the data packets after collecting the data transmitted by the nodes in the cluster, and then transmits the fused data packets to the sink node.
[0117] The existing LEACH algorithm does not consider the security problem when there are malicious nodes in the network, and how to appropriately elect a cluster head (i.e., a cluster head) is an important problem to be solved when researching such a clustering routing protocol.
[0118] In the embodiment, the LEACH, a cluster-based routing protocol, is selected in the network scenario.
[0119] In the simulation, a normal propagation model is used, and the nodes are variable in distance, and the signal transmission power is adaptively controlled under the condition that the signal-to-noise ratio at the receiving node is ensured. When calculating the signal transmission power, the distance between nodes, signal frequency, receiver noise bandwidth, noise intensity, etc. are taken as parameters, and the minimum power available can be calculated while ensuring that the signal-to-noise ratio at the receiver is higher than a certain threshold.
[0120] For two nodes that are far apart, due to the serious acoustic signal attenuation in water, the source node will use a larger transmission power to ensure that the acoustic signal received by the destination node has a higher signal-to-noise ratio. Conversely, for two nodes that are close together, the source node will choose a smaller transmission power.
[0121] Regarding the security issues of UWSNs, i.e., common malicious attacks:
[0122] It should be noted that security issues are important issues in the field of UWSNs, and UWSNs pose many requirements in security aspects, including data confidentiality, data integrity, data freshness, and network availability. Malicious attacks launched by internal nodes of the network will destroy these security requirements.
[0123] Common malicious attacks can be divided into active attacks and passive attacks according to the interaction mode between the malicious node and the attacked node. Passive attacks refer to the affected device attempting to detect activities and collect data transmitted in the network without interfering with network functions. Active attacks aim to inject, alter, destroy, or delete data carried on the network, and may capture network data and attempt to alter or destroy data packets to interfere with network communication and operation. Both internal attackers and external attackers can launch active attacks. If the attack is made through a node that does not belong to the network, it is an external attack. If the attack comes from an internal node of the network, it is classified as an internal attack.
[0124] Although passive attacks pose a non-negligible threat to the network, it is difficult to determine passive attackers based on trust model methods because network functions are not affected. Therefore, the present embodiment does not consider passive attacks. In addition, according to previous research results, internal attacks are more difficult to trace than external attacks and can cause greater danger, so the malicious attacks considered in the present embodiment are all internal attacks.
[0125] It should be noted that in the cluster network topology, three common malicious attacks are tampering attacks, Sybil attacks, and selfish attacks, whose principles and effects are as follows:
[0126] Tampering attack: A node launching a tampering attack will maliciously tamper with data in its own sensor or in a data packet to be forwarded, and then re-inject the network, aiming to destroy the integrity and correctness (authenticity) of the data.
[0127] Sybil attack: Sybil attack is a network layer malicious attack. Sybil nodes pretend to be in multiple locations at the same time and have multiple identities (i.e., fake identities), thereby misleading the routing protocol, increasing the likelihood of becoming a hotspot node and further launching other attacks.
[0128] Selfish attack: A selfish attack node will reduce the frequency of data packet transmission with the goal of prolonging its own life, which will destroy the energy balance between nodes in a cluster-based routing protocol and may lead to unfair cluster head election.
[0129] In view of the damage caused by tampering attacks, witch attacks, and selfish attacks to the network and routing protocols, the embodiment aims at these malicious attacks, studies the design problem of a trust model (a trust evaluation method), and can be used to design a routing soft security mechanism based on the trust model.
[0130] Regarding the trust model (or the trust evaluation method), the trust system, and the reputation system:
[0131] It should be noted that the trust model is an abstract model for describing the trust relationship between individuals, and is used to describe the trust relationship between individuals based on some trust indicators or trust metrics, while the trust system is a software tool or system that specifically implements and supports the trust model, and the main goal is to create a trusted environment. The trust system is an important part of the soft security mechanism, and the trust model is the core content of the trust system.
[0132] It should be noted that the traditional mechanisms such as identity verification and access control based on cryptographic technology belong to hard security mechanisms, while the trust and reputation systems belong to soft security mechanisms. On the one hand, encryption and identity verification mechanisms provide identity trust, which is a measure of identity correctness. However, hard security mechanisms lack robustness and cannot protect the network from internal attacks after password leakage. On the other hand, users are also interested in the reliability of the authentication party or the quality of the goods and services provided by it. This type of trust is called provision trust, and only trust and reputation systems (i.e., soft security mechanisms) are useful tools to obtain provision trust. Therefore, in the face of internal attacks on the network, the trust model has irreplaceable advantages over traditional cryptographic technology.
[0133] It should be noted that the trust system and the reputation system are different but closely related.
[0134] The main differences between trust systems and reputation systems in the context of UWSNs are described as follows: a trust system of node A produces a score reflecting node A's subjective opinion of the trustworthiness of node B, while a reputation system of node B produces a reputation score that can be seen by all nodes in the network. Second, the transitivity of trust paths and networks is an explicit component of trust systems, which often appear in the form of referral trust in UWSNs, while reputation systems usually do not consider transitivity or only consider it in an implicit way. Finally, the input to a trust system is a subjective expression of trust in other nodes, while the input to a reputation system is an evaluation of an objective event. A trust system can contain elements of a reputation system, and vice versa, so it is not always clear how to classify a given system. Due to the mutual inclusion of trust systems and reputation systems and the unclear classification boundary, it is feasible to study and distinguish centralized and distributed trust systems in UWSNs based on the classification of reputation system architectures by previous researchers.
[0135] The network architecture determines how evaluations and reputation scores are passed between agents in a reputation system. There are two main architectures of reputation models, namely centralized reputation systems and distributed reputation systems.
[0136] In a centralized reputation system, information about a particular agent's performance is collected from the evaluations of other agents in the system who have direct experience with the particular agent. The collected evaluations are centralized at a reputation center, which determines a reputation score for each agent in the system based on this information and makes all scores public. Agents in the system can use these scores to make judgments and decisions before interacting with other agents.
[0137] The two basic aspects of a centralized reputation system are:
[0138] a. A centralized communication protocol that allows agents to submit their evaluations of other agents to the reputation center and to obtain the reputation scores of other agents from the reputation center.
[0139] b. The reputation center is responsible for reputation computation, which computes a reputation score for each agent in the system based on the received evaluations and other information.
[0140] Distributed reputation systems: In some environments, distributed reputation systems are more suitable than centralized systems. In a distributed system, there is no reputation center designed to collect information and centralized computation, instead, the storage and computation of agents are distributed locally, and relevant evaluations and information can be recommended to other agents for evaluation of a particular agent.
[0141] The two basic aspects of a distributed reputation system are:
[0142] a. A distributed communication protocol that allows agents to obtain evaluations from other agents in the system.
[0143] b. Each agent computes a reputation score for the target agent based on the received evaluations and possibly other information.
[0144] In this embodiment, the trust evaluation method (or called trust model) is similar to a centralized reputation system, so it can be called a centralized trust evaluation method (or called a centralized trust model).
[0145] The centralized trust model is suitable for use in a clustered network. In the centralized trust model, the member nodes in the cluster, the cluster head nodes, and the surface sink nodes undertake relevant work, and the information related to trust is sent to the surface sink nodes for processing, and the trust evaluation results are visible throughout the network. Since the surface sink nodes usually have stronger computing power and larger storage space, and the batteries are easy to replace or charge, most of the trust calculation work and storage requirements in the model are implemented on the surface sink nodes, which reduces the occupation of the trust evaluation work on the underwater node computing and storage resources. Since the complete trust information of the entire network can be continuously obtained, the centralized trust model is more accurate in evaluating the trustworthiness of nodes. In addition, the cluster-based routing protocol can also alleviate the excessive occupation of energy resources when nodes transmit information related to trust.
[0146] It should be noted that there are many existing trust models for TWSNs (TWSNs) in the prior art, but the environmental characteristics of TWSNs and UWSNs are different, and the existing TWSNs trust model cannot be directly applied to UWSNs. In TWSNs, nodes are densely deployed on a two-dimensional plane, while in UWSNs, nodes are located in a three-dimensional underwater environment considering depth. Unlike the radio frequency radio signals used for communication by land-based sensor nodes, underwater nodes usually use acoustic signals for communication. The transmission rate of underwater acoustic signals is five orders of magnitude lower than that of radio signals, resulting in serious time and space uncertainty of underwater acoustic communication. Complex underwater environmental noise can increase the bit error rate and packet loss rate, and wind and ocean currents can cause the node position to change dramatically, also increasing the probability of packet loss due to data packet collision, which makes the underwater link very fragile. At the same time, the serious Doppler effect and multipath effect of the underwater acoustic channel result in high transmission loss.
[0147] Regarding the cloud model and the reverse cloud algorithm:
[0148] It should be noted that the cloud model is a model used to describe concepts in nature. Its three parameters reflect the uncertainty in natural language and enable conversion between qualitative and quantitative concepts. The three parameters of cloud theory are expectation (ex), entropy (en), and hyperentropy (he). ex is the expectation of an attribute, reflecting the central trust value. en is the entropy of the attribute, reflecting the trust ambiguity of ex. He is the hyperentropy of the attribute, reflecting the uncertainty of en. The forward cloud algorithm can transform the overall characteristics of a qualitative concept into a quantitative numerical representation, achieving the conversion from conceptual space to numerical space. The reverse cloud algorithm can achieve the conversion from quantitative values to qualitative concepts, converting a set of quantitative data into qualitative concepts represented by numerical features.
[0149] For any trust attribute x, x∈X, where X is the trust evaluation domain, denoted as the exact value, if There always exists a mapping μ that satisfies
[0150] μ:X→[0,1],x→μ(x)∈[0,1];
[0151] Then, the distribution of x in domain X is called the trust cloud. μ(x) is called the membership function, and its formula is as follows.
[0152]
[0153] The node selects the N most recent data collected by its own sensors as cloud droplets and uses the reverse cloud algorithm to locally calculate the cloud model related to its own sensor data;
[0154] When building a cloud model, it is necessary to calculate the estimated values of the three digital eigenvalues (i.e., the three parameters of cloud theory) ex, en, and he that characterize the cloud based on the inverse cloud algorithm to achieve a qualitative analysis of the node's credibility.
[0155] Assume that the qth data among the N data collected by the node’s own sensor is x q ,The steps of the reverse cloud algorithm are as follows:
[0156] Step 1: Calculate x q The mean and variance S 2 :
[0157]
[0158] Step 2: Calculate an estimate of ex
[0159]
[0160] Step 3: Calculate an estimate of en
[0161]
[0162] Step 4: Calculate the estimated value of he
[0163]
[0164] In an embodiment, a centralized trust evaluation method based on cloud theory is provided, which is applied to an underwater wireless sensor network with a clustered network topology, and the method comprises the following steps:
[0165] Trust evidence collection step: the in-cluster member nodes collect packet sending trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to the cluster head node;
[0166] Trust calculation step: the cluster head node calculates the packet sending trust value, data trust value and energy trust value of the in-cluster member nodes based on the three types of trust evidence collected by the in-cluster member nodes, and sends the three types of trust values to the sink node;
[0167] Trust updating step: the sink node calculates and updates the packet sending cloud model, data cloud model and energy cloud model of all network nodes using the reverse cloud algorithm according to the trust values of all network nodes;
[0168] Malicious node step: the sink node combines the three types of cloud models of the node to be evaluated into a 1*9 tensor as an output sample input into the VAE model, and obtains the output of the VAE model as an output sample; calculates the mean square error between the input sample and the output sample as the reconstruction error; inputs the reconstruction error into the SVM model for node binary classification to realize malicious node identification.
[0169] In the embodiment, the trust evaluation method (or trust model) is periodically repeated. In order to realize the trust evaluation of the centralized trust evaluation method for the nodes in the network, the in-cluster member nodes, the cluster head node and the surface sink node (i.e. the sink node, because the sink node is located on the surface, it is also called the surface sink node) undertake the tasks in the trust evaluation method.
[0170] Specifically:
[0171] According to the attack characteristics of selfish attack, tampering attack and Sybil attack, the in-cluster member nodes collect trust evidence related to the number of node packet sending, sensor data and energy consumption of themselves (i.e. packet sending trust evidence, data trust evidence and energy trust evidence), to reflect abnormal conditions of packet sending frequency, sensor data and energy consumption, and report the above information to the cluster head node.
[0172] The cluster head node calculates the packet sending trust value, data trust value and energy trust value of the member nodes in the cluster based on three types of trust evidence of the member nodes in the cluster, and reports the three types of trust value information to the surface sink node.
[0173] After the sink node obtains the trust values of all nodes in the network, the sink node calculates and updates the packet sending cloud model, data cloud model and energy cloud model of all nodes in the network using a reverse cloud algorithm.
[0174] Then, the sink node combines the three types of cloud models of the evaluated nodes into a 1*9 (i.e., 1 times 9) tensor as an input sample and inputs the input sample into a VAE model (Variational Autoencoder), calculates the Mean Squared Error (MSE) between the input sample and the output sample as a reconstruction error, inputs the reconstruction error into an SVM model for node binary classification, and realizes malicious node identification.
[0175] Finally, the sink node notifies all nodes in the network of the malicious node identification result and related information in the form of a broadcast.
[0176] The malicious node identification result and related information can be used to guide routing decisions, realize logical isolation of the network from malicious nodes, and further realize physical isolation of the network from malicious nodes.
[0177] In addition, in an embodiment, the cluster head node calculates the packet sending trust value of the member nodes in the cluster based on the packet sending trust evidence collected by the member nodes in the cluster:
[0178]
[0179] wherein T packet is the packet sending trust value; PN is the packet sending trust evidence; PN average is the average number of packet sending of the member nodes in the cluster within a given time period counted by the cluster head node.
[0180] It should be noted that, compared with the radio frequency communication mode in the land-based wireless sensor network, the underwater acoustic communication of the nodes in the UWSN consumes more energy, and therefore most of the energy of the nodes is used for communication, especially for sending data packets. In order to protect the energy consumption of the malicious nodes, the malicious nodes will adopt the hidden attack strategy of selfish attack, and the nodes launching the selfish attack will refuse to comply with the arrangement of the protocol and refuse to generate and send data packets, so as to avoid energy consumption caused by sending data packets, which will destroy data integrity.
[0181] In this embodiment, the number of data packets generated and sent by a node in a period of time PN is selected as the packet sending trust evidence when the node launches a selfish attack. The number of data packets generated and sent by each member node in a period of time is recorded as the packet sending trust evidence, and the packet sending trust evidence is sent to the cluster head node with a packet.
[0182] In this embodiment, the packet sending trust values of the member nodes and the cluster head node are sent to the water surface sink node with a packet by the cluster head node.
[0183] In this embodiment, the packet sending trust value is used to quantify the normality of the number of data packets generated and sent by a node.
[0184] In addition, in an embodiment, the cluster head node calculates the data trust value of each member node based on the data trust evidence collected by the member nodes:
[0185] The data trust evidence of each member node is converted into a cloud vector using a reverse cloud algorithm; the cloud vector includes three parameters: expectation ex, entropy en, and hyper entropy he;
[0186] The estimated values of the three parameters are:
[0187]
[0188] wherein the mean value is and the variance S 2 is represented as:
[0189]
[0190] wherein x q represents the data trust evidence of the member node q, q = 1, 2,..., M-1;
[0191] The cluster head node quantifies the similarity between the cloud vectors of each member node and any other member node using a cloud similarity algorithm.
[0192] The similarity between the two cloud vectors is represented by the cosine value of the angle between the two cloud vectors, and the similarity between the two cloud vectors is:
[0193]
[0194] wherein and represent the vectors composed of the numerical features of the two cloud vectors C i and C j , and i and j represent the numerical features of the cloud vectors C i and C jThe corresponding in-cluster member node before conversion using the reverse cloud algorithm; wherein, C i =(ex i ,en i ,he i ), C j =(ex j ,en j ,he j );
[0195] The relative trust RT ij of the data of the in-cluster member node i and the in-cluster member node j in the period is expressed as:
[0196]
[0197] The cluster head node calculates the data trust value of each in-cluster member node:
[0198] The data trust value T data of the in-cluster member node i is the average value of the relative trust of the in-cluster member node i by all other in-cluster member nodes except the in-cluster member node i:
[0199]
[0200] Wherein, M is the total number of in-cluster member nodes; k is any other in-cluster member node except the in-cluster member node i, k = 1, 2,..., M, k ≠ i; T data ∈ [0, 1].
[0201] In the embodiment, the data trust value is calculated by collecting the data trust evidence related to the sensor data according to the characteristics that the node will tamper with the data collected by the sensor when launching tampering attack.
[0202] For simplicity, it is assumed that the sensing data is digital information, on the basis of which, the data trust value T data ∈ [0, 1] is calculated using the group trust algorithm based on the cloud model.
[0203] The node selects the N data newly collected by the sensor as the data trust evidence {u1, u2,..., u N};
[0204] The data trust evidence is taken as a cloud drop, and the cloud vector of the data trust evidence related to the sensor data is calculated locally using the reverse cloud algorithm, that is, the data trust evidence of each in-cluster member node is converted into a cloud vector using the reverse cloud algorithm.
[0205] The in-cluster member node sends the calculated cloud vector to the cluster head node with a package.
[0206] The cluster head node quantifies the similarity degree between the cloud vector of each cluster member node and that of any other cluster member node using a cloud similarity algorithm, and then uses relative trust to describe the relative trust degree of the data of two nodes in the same period (i.e., relative trust) on the basis of the cloud similarity, and then obtains the data trust value of each cluster member node according to the average value of the relative trust.
[0207] Finally, the data trust values of the cluster member nodes and the cluster head node are sent to the surface sink node by the cluster head node.
[0208] In addition, in an embodiment, the cluster head node calculates the energy trust value of the cluster member node based on the energy trust evidence collected by the cluster member node:
[0209] The energy trust evidence is modified as follows:
[0210]
[0211] wherein E original is the energy consumption of the cluster member node in a given time period, serving as the energy trust evidence; E consume is the modified energy consumption, serving as the modified energy trust evidence; d is the straight-line distance between the cluster member node and the cluster head node; f is the center frequency used in acoustic communication (i.e., underwater acoustic communication mode); and A(d, f) is an attenuation function.
[0212] Based on the modified energy consumption E consume , the energy trust value T energy is calculated using a normal distribution probability density function.
[0213]
[0214] wherein f(x) is the normal distribution probability density function of the modified energy consumption E consume ; x is a random variable subject to normal distribution; E average is the mean value of the normal distribution, which is the mean value of the modified energy consumptions of all cluster member nodes calculated by the cluster head node; and σ is the standard deviation of the normal distribution. evaluated consume
[0215] It should be noted that the present embodiment studies underwater communication-related problems. In underwater communication, the radio propagation distance is limited, so acoustic communication is used, i.e., acoustic communication.
[0216] In this embodiment, by analyzing the characteristics of the witch attack with multiple identities, it is found that the node launching the witch attack will mimic the behavior of normal nodes in order to hide the false identity in normal nodes, such as cooperating with the clustering protocol and generating and sending data packets at a similar frequency, which will inevitably lead to additional energy consumption. Therefore, in the case that other characteristics of the node are normal, the potential witch node can be identified by the abnormal energy consumption of the node.
[0217] In this embodiment, the energy consumption E original as the energy trust evidence.
[0218] In this embodiment, since the cluster head node undertakes high-energy-consuming tasks such as receiving data packets of cluster member nodes, information processing, and packet sending to the surface sink node, the calculation and evaluation of the energy trust value only include the cluster member nodes, but not the cluster head node in this round.
[0219] In this embodiment, when the energy trust evidence is counted, although the number of packet sending per second of the cluster member node as a random variable follows the Poisson distribution with the same parameter, unlike the land-based wireless sensor network, the underwater acoustic signal in the UWSNs decays seriously, and the energy consumption of the communication between nodes at different distances differs greatly, so it is difficult to directly identify the abnormal energy consumption.
[0220] To solve this problem, the energy trust evidence is modified with distance as a parameter, by reducing the influence of distance on the communication energy consumption of underwater nodes, a more accurate trust evaluation result is obtained:
[0221] By analyzing the formula of the underwater acoustic signal attenuation function, the modification of the energy trust evidence is as follows:
[0222]
[0223] wherein, E original is the energy consumption of the cluster member node in a given time period, i.e. the energy trust evidence; E consume is the modified energy consumption, which is the modified energy trust evidence; d (unit: m) is the straight-line distance between the cluster member node and the cluster head node; f (unit: Hz) is the center frequency of the acoustic communication; A (d, f) is the attenuation function.
[0224] The cluster member node periodically records its own energy consumption, and sends the modified energy trust evidence with the packet to the cluster head node.
[0225] In this embodiment, the cluster head node calculates the energy trust value based on the modified energy trust evidence, and the energy trust value is used to quantify the normal degree of energy consumption of the node in a given time period.
[0226] In this embodiment, the energy trust value of the member node in the cluster is sent to the water surface sink node by the cluster head node.
[0227] In this embodiment, the standard deviation σ of the normal distribution can be set according to the specific scene.
[0228] In addition, in an embodiment, the sink node calculates and updates the packet sending cloud model, data cloud model and energy cloud model of all network nodes using the reverse cloud algorithm according to the trust values of all network nodes, including:
[0229] Let the packet sending trust value of any node be {T packet1 ,T packet2 ,......,T packetn}, where n is the number of packet sending trust value data of any node saved at the sink node; using the packet sending trust value of any node as a cloud drop, the packet sending cloud model is calculated using the reverse cloud algorithm as (Ex packet ,En packet ,He packet );
[0230] Based on the data trust value, the data cloud model (Ex data ,En data ,He data ) is obtained;
[0231] Based on the energy trust value, the energy cloud model (Ex energy ,En energy ,He energy ) is obtained;
[0232] The three types of cloud models, packet sending cloud model, data cloud model and energy cloud model, are periodically calculated and updated with the accumulation of the three types of trust values, packet sending trust value, data trust value and energy trust value.
[0233] In this embodiment, the cloud model refers to the cloud model related to the node trust value, that is, the trust cloud. After the sink node completes the collection of the trust values of all network nodes, these trust values are sorted and saved locally to calculate and update the trust cloud (cloud model) related to the trust value.
[0234] In this embodiment, Ex packet is the expectation of the packet sending cloud model; En packet is the entropy of the packet sending cloud model; and He packet is the hyper entropy of the packet sending cloud model.
[0235] In this embodiment, Ex data is the expectation of the data cloud model; En data is the entropy of the data cloud model; and He data is the hyper entropy of the data cloud model.
[0236] In this embodiment, Ex energy is the expectation of the energy cloud model; En energy is the entropy of the energy cloud model; He energy is the hyper-entropy of the energy cloud model.
[0237] In this embodiment, the three types of trust clouds (cloud models) constructed can qualitatively represent the trustworthiness of the evaluated node in terms of packet, data and energy,
[0238] In addition, in an embodiment, the VAE model is obtained after training an initial VAE model using a VAE data set;
[0239] The VAE data set is cloud model data generated by nodes with the presence of attack node samples collected using network simulation and emulation technology.
[0240] In this embodiment, the network simulation and emulation technology refers to simulation based on NS-3 software to collect cloud model data generated by nodes with the presence of attack node samples.
[0241] It should be noted that NS-3 software is an open source project written in C++ language, and the main operating platform is GNU / Linux, such as CentOS, Ubuntu, Fedora, etc. Although Windows users can also use Cygwin or Visual Studio to run NS-3, some functions may not be available, such as interaction with physical networks. The functions and features of NS-3 software mainly include:
[0242] Network simulation: NS-3 is mainly used for simulating computer networks, which can simulate various types and sizes of network structures in the physical world on a computer.
[0243] Discrete event driven: NS-3 uses discrete event simulation technology to abstract a continuous process in the physical world into a series of discrete events in the virtual world, which can very realistically simulate various network protocols in the physical world.
[0244] Script support: The simulation script of NS-3 can support two program languages, C++ and Python, and users can call various application program interfaces (APIs) provided by NS-3 for network simulation in the simulation script to construct their own virtual network structure.
[0245] NS-3 also has the following auxiliary functions:
[0246] trace generation: allows users to directly analyze the data generated by NS-3 through third-party software (such as Wireshark, tcpdump).
[0247] Mobile module: the starting position and moving trajectory can be automatically assigned for the node.
[0248] Interaction with physical network: the virtual network built by NS-3 can be highly integrated with the physical network environment, and the virtual node can transmit data by using the physical network, and the physical node can also transmit data packets by using the virtual channel built by NS-3.
[0249] As an alternative software to NS-3, NS-2 is undoubtedly a choice. NS-2 is also a mainstream software in the field of network simulation, but it is the predecessor of NS-3, part of which is written in C++ and the other part is written in OTcl. Compared with NS-3, NS-2 has stopped updating, but it may still have advantages in some specific fields, such as the simulation of Reina D.G. network's probabilistic broadcast scheme, the simulation of routing protocols of FANETs (FANETs) intelligent routing protocols of wireless sensor networks, etc.
[0250] In this embodiment, the simulation parameters based on NS-3 software are set as shown in the following table:
[0251] Parameter name Parameter setting Deployment range 5000m*5000m*5000m Number of packet sending nodes 100 Data packet size 400Bytes Total number of malicious nodes 15 Number of selfish attack nodes 5 Number of tampering attack nodes 5 Number of Sybil attack nodes 5 Movement model Fixed Simulation time 3000s Attack start time 1000s Data collection time 2000s
[0252] In this embodiment, the process of simulation based on NS-3 software is as follows:
[0253] The cluster member node collects and reports its own trust evidence to the cluster head node, and the cluster head node calculates the trust value and reports it to the water surface sink node;
[0254] In the case of attack by malicious nodes, change the random seed and run the simulation multiple times, collect 2100 pieces of three types of trust cloud data of normal nodes for modeling normal node cloud model;
[0255] At the same time, 300 pieces of three types of trust cloud data of malicious nodes are collected for testing the model training effect.
[0256] In this embodiment, the essence of VAE model (Variational Autoencoder) is to extract the hidden features of data and build a neural network model from hidden features to generate target. It has two structures of encoder (Encoder) and decoder (Decoder) in the design architecture, wherein the encoder converts the input data into a smaller and more compact encoding expression in the hidden space, and the decoder restores the encoding to the original input data.
[0257] In this embodiment, the VAE model can fit the prior distribution of the hidden variables of the existing samples and then sample new samples. Therefore, the VAE can be used to extract the features of the normal node cloud model and realize the modeling of the normal node cloud model by virtue of the excellent generation and reconstruction capabilities of the VAE. Then, according to the feature that the corresponding cloud model of the malicious node will change after launching an attack, the abnormal cloud model can be detected by identifying the large fluctuation of the abnormal cloud model when passing through the VAE model.
[0258] In this embodiment, the network structure of the VAE model is as follows:
[0259] The VAE model includes an encoder and a decoder.
[0260] The encoder includes, in sequence:
[0261] An input layer with an input size of 9;
[0262] A self-attention layer with an input size of 9 and an output size of 9;
[0263] A fully connected layer 1 with an input size of 9 and an output size of 128;
[0264] A mean layer with an input size of 128 and an output size of 2;
[0265] A variance layer with an input size of 128 and an output size of 2;
[0266] The hidden variables are obtained according to the variance layer and the mean layer.
[0267] The decoder includes, in sequence:
[0268] A fully connected layer 2 with an input size of 2 and an output size of 128; the hidden variables are input into the fully connected layer 2;
[0269] An output layer with an input size of 128 and an output size of 9.
[0270] In order to enable the encoder to adaptively focus on the importance of different parts in the input when extracting features and improve the expression ability and feature extraction ability of the encoder, an attention mechanism is introduced into the VAE model. That is, a self-attention layer with an input size of 9 and an output size of 9 is added to the structure of the VAE model.
[0271] In this embodiment, as described above, the training effect of the VAE model is tested. Figure 4
[0272] A 1*3 vector (Ex, En, He) composed of the expectation, the entropy and the hyper entropy of the cloud model is named as a feature vector of the cloud model.
[0273] First, we show the changes of three types of cloud models of normal nodes and malicious nodes in the VAE dataset as vectors in three-dimensional space before and after passing through the VAE model.
[0274] Among them, the three-dimensional coordinates are the expectation, entropy and super entropy of the cloud model. In the three-dimensional graph, arrows of different colors are used to represent the eigenvectors corresponding to the cloud model. From left to right, the three graphs represent the situations when launching selective forwarding attacks, tampering attacks, and witch attack nodes respectively.
[0275] Among them, the light red arrow represents the feature vector of the cloud model after the malicious node launches an attack, the dark red represents the feature vector of the output cloud model after the malicious node launches an attack and the cloud model is input into the VAE model, the light green represents the feature vector of the cloud model of the normal node, and the dark green represents the feature vector of the output cloud model after the normal node cloud model is input into the VAE model.
[0276] like Figure 4 As shown, Figure 4 (a) Figure 4 (b) Figure 4 (c) Vector diagrams of the node cloud model for selfish attack, tampering attack, and Sybil attack, respectively.
[0277] In the figure, the light red arrows all deviate significantly from the light green arrows, indicating that the attacking node's behavior has caused its own cloud model to become abnormal, significantly different from the cloud model of a normal node. Furthermore, the dark red and dark green arrows differ, indicating that when the input data is abnormal, the error generated by the VAE model fluctuates compared to the normal error.
[0278] The following uses the mean square error (MSE) of the generated vector and the input vector as an indicator, and inputs the training set, test set, and malicious node data set from the normal node data set to test the training effect. The results are as follows:
[0279]
[0280]
[0281] It can be seen that the MSE obtained by inputting the malicious node dataset is about 15 times that of the normal node dataset, and the difference is obvious. This shows that the VAE model can effectively extract the data features of the normal node cloud model in the network, and reconstruct and generate it on this basis. In addition, when the malicious node cloud model data passes through the VAE model, the MSE result has obvious fluctuations.
[0282] In addition, in one embodiment, the SVM model is obtained by training an initial SVM model using an SVM dataset;
[0283] The SVM data set is obtained by using network simulation technology (i.e., simulation based on NS-3 software) on the basis of completing initial VAE model training. The simulation parameters are the same as above.
[0284] In this embodiment, the SVM data set includes three types of cloud vectors (i.e., cloud models) of normal nodes and malicious nodes, and the MSE calculated by the VAE model at the time of 2000s.
[0285] In this embodiment, the SVM data set is labeled, and label 1 represents a normal node and label -1 represents a malicious node.
[0286] In this embodiment, in the process of simulation based on NS-3 software, the random seed is changed multiple times in the presence of malicious nodes launching attacks, and the simulation is run multiple times, and 3240 data are collected, of which 2000 are used as a training set and 1240 are used as a test set. In the SVM data set, the number of malicious node data accounts for 15% of the total number of data.
[0287] In this embodiment, the SVM model (i.e., support vector machine) has higher accuracy in small sample and nonlinear classification than other models based on artificial intelligence technology.
[0288] Due to the sparse deployment of underwater network nodes, the trust evidence collected by the nodes is less, and compared with other supervised learning algorithms, SVM can effectively solve the learning problem of relatively small samples, so SVM method is used to realize node classification.
[0289] It should be noted that the SVM model requires a large amount of training resources; in traditional trust evaluation methods, it is difficult to apply the SVM model due to the lack of data sets in related scenarios, and the present embodiment solves this technical problem by using network simulation technology (i.e., simulation based on NS-3 software).
[0290] In this embodiment, before training the initial SVM model, the type and parameters of the SVM model need to be determined.
[0291] The type of SVM model is selected as C-SVM type;
[0292] Due to the small number of sample features, a radial basis kernel function is used;
[0293] The grid traversal method is used to find the optimal parameters c and γ with the smallest error, and then the optimal parameters are used to train the initial SVM model.
[0294] In this embodiment, in order to determine the optimal parameters, the parameters c and γ of C-SVC are first optimized based on the grid traversal principle; the grid optimization results of the parameters c and γ of C-SVM are as follows Figure 5As shown, since the model reaches 100% classification accuracy on the training set at c=8.0, γ=0.5, it is selected as the optimal parameter.
[0295] In this embodiment, the hyperparameters set when training the initial SVM model are as shown in the following table:
[0296] Attribute name Attribute value SVM type C-SVM Kernel function type RBF kernel Set the order of kernel function 3 Gamma parameter in kernel function 0.5 Coef0 parameter in kernel function 0 Penalty coefficient C 8 Cache memory size 40MB Tolerable deviation in termination principle 0.001 Whether to use heuristic Yes Penalty coefficient C weighting for each type of sample 1
[0297] After the initial SVM model is trained, the parameters of the obtained SVM model are as shown in the following table:
[0298]
[0299] In addition, in an embodiment, the aggregation node combines the three types of cloud models of the evaluated node into a 1*9 tensor as an output sample and inputs the VAE model, and obtains the output of the VAE model as an output sample; the mean square error between the input sample and the output sample is calculated as the reconstruction error, which is:
[0300] Let the input sample be X=(X1, X2, X3, L X9);
[0301] The reconstruction result output by the VAE model, i.e., the output sample, is
[0302] The reconstruction error MSE is:
[0303]
[0304] In addition, in an embodiment, the reconstruction error is input into the SVM model for node binary classification to realize malicious node identification, which is:
[0305] The reconstruction error is input into the SVM model for node binary classification:
[0306] If the classification result is -1, it indicates that the reconstruction error of the cloud model of the evaluated node exceeds the given threshold, the cloud model is abnormal, and the evaluated node is identified as a malicious node;
[0307] On the contrary, if the classification result is 1, the evaluated node is identified as a normal node.
[0308] In this embodiment, in the process of malicious node identification, the VAE model will generate a certain error when decoding the data after the encoder. If there is an anomaly in the original input data, the generated error will have a larger fluctuation compared to the conventional error. Based on the SVM model classification of the errors generated by different nodes, normal nodes and malicious nodes can be distinguished, and the trust evaluation of the evaluated node is completed.
[0309] In an embodiment, a centralized trust evaluation device based on cloud theory is provided, which is applied to an underwater wireless sensor network of a clustered network topology, and the device comprises the following modules:
[0310] A trust evidence collection module: the member nodes in a cluster collect packet trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to the cluster head node;
[0311] A trust calculation module: the cluster head node calculates the packet trust value, data trust value and energy trust value of the member nodes in the cluster based on the three types of trust evidence collected by the member nodes, and sends the three types of trust values to the sink node;
[0312] A trust updating module: the sink node calculates and updates the packet cloud model, data cloud model and energy cloud model of all nodes in the network using the reverse cloud algorithm according to the trust values of the nodes in the network;
[0313] A malicious node module: the sink node combines the three types of cloud models of the node to be evaluated into a 1*9 tensor as an input sample of the VAE model, and obtains the output of the VAE model as an output sample; calculates the mean square error between the input sample and the output sample as a reconstruction error; inputs the reconstruction error into the SVM model for node binary classification to realize malicious node identification.
[0314] In an embodiment, a cluster head election method improved from the LEACH algorithm is provided, and the method comprises the following steps:
[0315] Each node obtains its updated mean square error mse by using any one of the centralized trust evaluation methods based on cloud theory described above;
[0316] Each node uses the improved cluster head election threshold function T imp (n) to calculate the cluster head election threshold based on the number of times it serves as a cluster head node, the cluster head node proportion determined in advance and the mse;
[0317] Each node generates a random number by itself; the random number is generated by a random variable in [0, 1]; the random number is subject to a uniform distribution;
[0318] Each node compares the random number generated by itself with the cluster head election threshold:
[0319] If it is less than the cluster head election threshold, the node becomes a cluster head node in the current large period;
[0320] Otherwise, the node does not become a cluster head node;
[0321] The improved cluster head election threshold function T imp (n) is as follows:
[0322]
[0323] F(mse) = 1.02^(24^(10*mse));
[0324] wherein, mse∈[0, +∞); P is a priori determined proportion of cluster head nodes in the network; r is the current round; G is a set of nodes that have not become cluster head nodes in the last 1 / P rounds.
[0325] In the embodiment, each node obtains its updated mean square error mse by using the centralized trust evaluation method based on the cloud theory in any one of the above embodiments:
[0326] In the centralized trust evaluation method based on the cloud theory in any one of the above embodiments, each node is taken as an evaluated node; the three types of cloud models of the evaluated node (i.e., each node) are combined into a 1*9 tensor as an output sample input into the VAE model by the sink node, and the output of the VAE model is obtained as an output sample; and the mean square error between the input sample and the output sample is calculated as the updated mean square error mse of each node itself.
[0327] It should be noted that the traditional LEACH algorithm does not consider the security problem when there are malicious nodes in the network, and how to appropriately elect a cluster head is an important problem to be solved in the research of such a clustering routing protocol. Therefore, the routing soft security mechanism is designed based on the trust model in the embodiment to obtain a cluster head election method of the improved LEACH algorithm.
[0328] In the embodiment, the F(mse) function curve is as shown in Figure 6 .
[0329] It can be seen that when mse∈[0, 0.15], F(mse) increases with the increase of mse, and the increasing amplitude gradually increases; in fact, when mse∈[0, +∞), F(mse) is monotonically increasing, and F(mse)∈[1, +∞). In the improved LEACH algorithm, the larger the mse of a node is, the larger the F(mse) of the node is, and the smaller T imp (n) is, and when T imp (n) decreases, the probability of the node becoming a cluster head node also decreases. Therefore, the design of the cluster head election threshold function in the improved LEACH protocol can reduce the possibility of a node with a higher mse being elected as a cluster head node, while the cluster head election process has little effect on a node with a lower mse.
[0330] In an embodiment, an improved LEACH routing protocol method is provided, which comprises a clustering step and a data transmission step.
[0331] Cluster building step: the nodes periodically re-elect cluster head nodes to build clusters, and this period is called a large period, denoted as T1; wherein the cluster head nodes are elected by using the cluster head election method of the improved LEACH algorithm.
[0332] Data transmission step: the cluster head nodes periodically transmit the integrated data packets of the in-cluster member nodes to the sink node, and this period is called a small period, denoted as T2.
[0333] In the data transmission step, the number of packets transmitted by the in-cluster member nodes per second is a random variable following a Poisson distribution, and the in-cluster member nodes immediately attempt to send data packets to the cluster head node whenever data is generated.
[0334] In the data transmission step, the in-cluster member nodes also send their packet transmission trust evidence, energy trust evidence, and energy trust evidence to the cluster head node with the data packets.
[0335] In the data transmission step, the cluster head node first stores and integrates the data packets received from the in-cluster member nodes; then periodically transmits the integrated data packets to the surface sink node with T2 as the period.
[0336] In the data transmission step, the cluster head node periodically calculates the trust values of the in-cluster member nodes based on the collected trust evidence with T2 as the period, and transmits the trust value calculation results to the surface sink node with the integrated data packets.
[0337] In addition, in an embodiment, a simulation experiment is provided to verify the performance of the centralized trust evaluation method based on the cloud theory and the cluster head election method of the improved LEACH algorithm.
[0338] Simulation environment setting:
[0339] The simulation is performed based on the NS-3 network simulation software and the Aqua-Sim-NG underwater acoustic communication simulation module.
[0340] The simulation includes a simulation experiment related to the trust evaluation method and a simulation experiment related to the improved LEACH algorithm, the former mainly considers the ability of the trust evaluation method to accurately identify malicious nodes, and the latter mainly considers the security of the cluster head election process in the improved routing protocol.
[0341] Simulation parameter setting:
[0342] The underwater nodes are randomly deployed in a 5000m*5000m*5000m cubic water area, and the surface sink node is located at the center of the water surface. In the simulation, it is assumed that there is no malicious attack during the initial deployment of the network, and the malicious attack starts from the middle and lasts until the end of the simulation. The signal transmission power of the nodes is adaptively adjusted according to the distance, and the minimum power is selected to transmit the signal under the premise of ensuring the signal-to-noise ratio at the receiving end. In order to facilitate the collection of energy trust evidence, the lower limit of the transmission power is additionally specified in the simulation.
[0343] In addition, the medium access control (MAC) protocol used in the simulation is a modified version of the broadcast MAC protocol used by researchers in the field. In the broadcast MAC protocol, nodes first sense the channel before sending data packets. If the channel is idle, the packet is sent, otherwise the backoff operation is performed, the backoff interval is randomly determined and the attempt is made again until the data packet is successfully sent or the number of attempts reaches the upper limit, at which time the data packet will be discarded. The MAC protocol used in the simulation is modified based on the broadcast MAC protocol. In order to facilitate the collection of trust evidence, an ACK confirmation mechanism is additionally added, in which when a node receives a data packet sent to itself, it will immediately return an ACK frame to notify the previous hop node that it has successfully received the data packet.
[0344] In the simulation, the detection rate and false detection rate are mainly used as indicators to test the effectiveness of the designed trust model (i.e. centralized trust evaluation method based on cloud theory). When testing the security of the improved routing protocol (i.e. improved LEACH algorithm), the proportion of malicious nodes in the current cluster head node after each clustering stage is mainly concerned.
[0345] The detailed simulation parameters are shown in the following table:
[0346]
[0347]
[0348] Trust model (trust evaluation method) simulation experiment:
[0349] In order to study the effectiveness of the trust evaluation method in identifying malicious nodes, Figure 7 The detection rate and false detection rate of the trust evaluation method with respect to simulation time are shown.
[0350] As Figure 7To avoid the problem that the cloud model is inaccurate due to too few cloud droplets, the condition for calculating the cloud model is set in the simulation, i.e., the cloud model is not calculated and the trust evaluation is not performed when the number of cloud droplets is too small, so the data from 0s to 400s is meaningless. Between 500s and 600s, the malicious node does not launch an attack, and the detection rate and false detection rate of the trust evaluation method first increase and then gradually decrease, because the trust evaluation method has fewer cloud droplets in the early stage of the network, and the cloud model calculated each time changes greatly, resulting in a high false detection rate, and the detection rate also increases. Between 700s and 1000s, the detection rate and false detection rate gradually decrease, because as the number of cloud droplets increases, the calculated cloud model can more accurately describe the trust degree of the node, which reduces the false detection rate. After 1000s, the malicious node starts to launch an attack, and the malicious node detection rate first increases slowly with time, and then rises rapidly, and the simulation data shows that the detection rate eventually gradually stabilizes at a high level of more than 99.3%. This trend is because it takes a process for the malicious node to launch an attack to be recognized by the trust evaluation method, during which the trust evidence of the malicious node first appears abnormal, and the trust value also decreases, and as the low trust value accumulates as cloud droplets, the cloud model gradually becomes abnormal. After a period of time, the abnormal cloud model will cause the calculated MSE to fluctuate greatly when passing through the VAE, and the SVM will only recognize the corresponding node as a malicious node after detecting such fluctuations. After 1000s, it is noted that the false detection rate gradually decreases with time and stabilizes at a low level of less than 0.24%, because as the number of cloud droplets increases, the cloud model calculation result of the normal node gradually stabilizes, which reduces the possibility of the trust model detecting the normal node as a malicious node.
[0351] In the trust evaluation method, MSE (Mean Square Error) as an important indicator can quantitatively evaluate the degree of deviation of the node cloud model from the normal cloud model, the higher the MSE, the farther the deviation from the normal cloud model, the cloud model is abnormal, and vice versa, the lower the MSE, the closer to the normal cloud model. The following studies the change of the MSE of the cloud model of the attack node and the normal node with the simulation time.
[0352] As shown in Figure 8 , the MSE of the normal node cloud model is always in a low area of about 0.02, while the MSE of the attack node cloud model gradually increases after the attack at 1000s and rises to about 0.15 at 1900s, which is obviously different from the MSE of the normal node cloud model. This is because after the malicious node launches an attack, the attack behavior is reflected in the trust evidence, resulting in a decrease in the trust value and an abnormal cloud model, and when the abnormal cloud model passes through the VAE, the MSE will fluctuate, while the normal node does not have obvious changes in behavior, and the trust evidence, trust value and cloud model are normal, and the MSE of the normal node cloud model does not change much when it passes through the VAE.
[0353] The MSE corresponding to different attack types in the figure is not strictly monotonically increasing with simulation time, and the fluctuations can be explained by the randomness in the simulation. The packet sending frequency of the node obeys the Poisson distribution as a random variable, so the number of packets sent by the node in a period of time is not fixed, which also causes the energy consumption level of the node in different time periods to be different. In addition, the malicious tampering of data by the node is also affected by the random number. The above reasons will cause the fluctuation of the trust value, and then affect the updating result of the cloud model and the calculation result of the MSE.
[0354] Improved LEACH protocol simulation experiment:
[0355] In order to study the security of the cluster head election link in the improved LEACH protocol, the proportion of malicious nodes in the cluster head nodes in each round of the LEACH protocol and the improved LEACH protocol (algorithm) is tested. A high proportion means that more malicious nodes are selected as cluster heads, and vice versa means that the proportion of malicious nodes selected as cluster heads is smaller.
[0356] Figure 9 The proportion of malicious nodes in the cluster head nodes is shown as a function of simulation time, where the malicious nodes start attacking at 1000s. The red circle line represents the performance of the original LEACH protocol. Since the original LEACH protocol does not consider security in the cluster head election process, when there are malicious nodes in the network, it is possible to select malicious nodes as cluster head nodes. After 1000s, the proportion of malicious nodes in the cluster head nodes fluctuates around 15%, which is consistent with the 15% malicious node proportion in the simulation conditions. The blue triangular line represents the performance of the improved LEACH protocol (i.e. the improved LEACH routing protocol method). Since the improved LEACH protocol adds a soft security mechanism based on the trust model, the model's evaluation of the node's trustworthiness affects the cluster head election process (i.e. the cluster head election method of the improved LEACH algorithm), reducing the likelihood of malicious nodes being elected as cluster heads. After 1000s, the proportion of malicious nodes first increases and then gradually decreases, eventually stabilizing below 1.4%. The performance of the improved LEACH protocol can be explained by the running characteristics of the trust model. The identification of malicious nodes by the centralized trust model based on cloud theory (i.e. the centralized trust evaluation method based on cloud theory) is a process. After the attack starts, with the accumulation of trust evidence, the abnormal situation of the cloud model of the malicious node becomes more and more serious, the reconstruction error gradually increases, and the threshold value generated by the threshold function of the malicious node in the cluster head election process becomes smaller and smaller, which greatly reduces the possibility of the malicious node becoming a cluster head. Compared with the original LEACH protocol, the improved LEACH protocol is less likely to elect malicious nodes as cluster head nodes in the cluster head election process, which demonstrates the ability of the routing soft security mechanism based on the trust model to improve the security of the cluster head election process in the clustering routing protocol.
[0357] The malicious node ratio of the two protocol cluster head nodes fluctuates with the change of simulation time, because the original LEACH protocol and the improved LEACH protocol both use the cluster head election method based on probability, and the statistical results in each round will have normal fluctuation phenomenon under the limited simulation times. The fluctuation of the improved LEACH protocol between 3500 seconds and 4000 seconds can also be explained by the characteristics of the cluster head election process. Although the improved LEACH protocol can effectively reduce the possibility of malicious nodes becoming cluster heads, it is not absolute, and the cluster head election threshold function of the nodes that have never been selected as cluster heads will tend to give a higher threshold in the next cluster head election process, which will increase the possibility of the nodes being selected as cluster heads. Therefore, the malicious nodes that have never been selected as cluster heads still have a small possibility of becoming cluster head nodes, but compared with the original LEACH protocol, the possibility of malicious nodes becoming cluster head nodes has been significantly reduced as a whole.
[0358] The above further describes the technical solutions provided by the present application through several specific embodiments, in order to highlight the advantages and benefits of the technical solutions provided by the present application. However, the above several specific embodiments are not used as a limitation of the present application, and any reasonable changes and improvements, reasonable combinations and equivalent replacements of the embodiments, etc. based on the spirit and principles of the present application should be included in the protection scope of the present application.
Claims
1. A centralized trust evaluation method based on cloud theory, the method being applied to an underwater wireless sensor network of a clustered network topology, characterized in that, The method comprises the following steps: Trust evidence collection step: the in-cluster member nodes collect packet sending trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to the cluster head node; Trust calculation step: the cluster head node calculates the packet sending trust value, data trust value and energy trust value of the in-cluster member nodes based on the three types of trust evidence collected by the in-cluster member nodes, and sends the three types of trust values to the sink node; Trust updating step: the sink node calculates and updates the packet sending cloud model, data cloud model and energy cloud model of all network nodes using the reverse cloud algorithm according to the trust values of all network nodes; Malicious node step: the sink node combines the three types of cloud models of the evaluated node into a 1*9 tensor as an input sample to input into the VAE model, and obtains the output of the VAE model as an output sample; the mean square error between the input sample and the output sample is calculated as a reconstruction error; the reconstruction error is input into the SVM model for node binary classification to realize malicious node identification; The cluster head node calculates the packet sending trust value of the member node in the cluster based on the packet sending trust evidence collected by the member node in the cluster: T packet ∈[0,1]; Wherein, T packet is the packet sending trust value; PN is the packet sending trust evidence; P Naverage is the average number of packets sent by the cluster head node within a given time period.
2. The cloud theory based centralized trust assessment method according to claim 1, wherein, The cluster head node calculates the data trust value of the in-cluster member nodes based on the data trust evidence collected by the in-cluster member nodes: The data trust evidence of each in-cluster member node is converted into a cloud vector using the reverse cloud algorithm; the cloud vector includes three parameters: expectation ex, entropy en and hyper entropy he; The estimated values of the three parameters are: wherein the mean and the variance S 2 is expressed as: where x q represents the data trust evidence of the member node q in the cluster, q = 1, 2, …, M-1; The cluster head node quantifies the similarity between the cloud vectors of each in-cluster member node and any other in-cluster member node using a cloud similarity algorithm; The similarity between the two cloud vectors is represented by the cosine value of the two cloud vectors, and the similarity between the two cloud vectors is: wherein, and denote the vector of the numerical features of the two cloud vectors C i and C j , i and j denote the cloud vectors C i and C j , and the corresponding intra-cluster member nodes before conversion using the reverse cloud algorithm; wherein C i = (ex i , en i , he i ), C j = (ex j , en j , he j ). The relative trust RT of the data of the member node i and the member node j in the cluster in the period ij is represented as: The cluster head node calculates the data trust value of each in-cluster member node: Data trust value T for an in-cluster member node i data Average of relative trust of in-cluster member node i by all other in-cluster member nodes except in-cluster member node i: Wherein, M is the total number of member nodes in the cluster; k is any other member node in the cluster except the member node i, k = 1, 2,... M, k ≠ i; T data ∈ [0, 1].
3. The cloud theory based centralized trust assessment method according to claim 1, wherein, The cluster head node calculates the energy trust value of the in-cluster member nodes based on the energy trust evidence collected by the in-cluster member nodes: The energy trust evidence is corrected: wherein E original is the energy consumption of the in-cluster member node within a given time period as an energy trust evidence; E consume is the corrected energy consumption as a corrected energy trust evidence; d is the straight-line distance between the in-cluster member node and the cluster head node; f is the center frequency used for acoustic communication; and A(d, f) is an attenuation function. Based on the corrected energy consumption E consume , the energy trust value T is calculated using a normal distribution probability density function energy : T energy ∈[0,1]; Among them, f(x) is the corrected energy consumption E cossume The probability density function of the normal distribution; x is a random variable that obeys the normal distribution; E average is the mean of the normal distribution, which is the mean of the corrected energy consumption of all member nodes in the cluster calculated by the cluster head node; σ is the standard deviation of the normal distribution; e evaluated =E consume .
4. The centralized trust evaluation method based on cloud theory according to claim 1, characterized in that: The VAE model is obtained after training the initial VAE model using the VAE data set; The VAE data set is cloud model data generated by the node when the attack node sample exists, which is collected using network simulation technology.
5. A centralized trust evaluation apparatus based on cloud theory, which is applied to an underwater wireless sensor network with a clustered network topology, characterized in that, The device comprises the following modules: Trust evidence collection module: the in-cluster member nodes collect packet sending trust evidence, data trust evidence and energy trust evidence, and send the three types of trust evidence to the cluster head node; Trust calculation module: the cluster head node calculates the packet sending trust value, data trust value and energy trust value of the in-cluster member nodes based on the three types of trust evidence collected by the in-cluster member nodes, and sends the three types of trust values to the sink node; Trust updating module: the sink node calculates and updates the packet sending cloud model, data cloud model and energy cloud model of all network nodes using the reverse cloud algorithm according to the trust values of all network nodes; Malicious node module: the sink node combines the three types of cloud models of the evaluated node into a 1*9 tensor as an input sample to input into the VAE model, and obtains the output of the VAE model as an output sample; the mean square error between the input sample and the output sample is calculated as a reconstruction error; the reconstruction error is input into the SVM model for node binary classification to realize malicious node identification; The cluster head node calculates the packet sending trust value of the member node in the cluster based on the packet sending trust evidence collected by the member node in the cluster: T packet ∈[0,1]; Wherein, T packet is the packet sending trust value; PN is the packet sending trust evidence; P Naverage is the average number of packets sent by the cluster head node within a given time period.
6. A computer device comprising: A processor and a memory, characterized in that the memory is configured to store executable instructions of the processor, and the processor is configured to execute the cloud theory based centralized trust evaluation method according to any one of claims 1-4 by executing the executable instructions.
7. A computer storage medium, characterized in that The storage medium stores a computer program, and the computer program executes the cloud theory based centralized trust evaluation method according to any one of claims 1-4 when running.
8. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the cloud theory based centralized trust evaluation method according to any one of claims 1-4.
9. A cluster head election method for improving LEACH algorithm, characterized in that, The method comprises the following steps: Each node obtains its updated mean square error (MSE) by using the cloud theory based centralized trust evaluation method according to any one of claims 1-4. Each node uses an improved cluster head election threshold function T based on the number of times it has served as a cluster head node, a priori determined cluster head node proportion, and mse imp (n) calculating a cluster head election threshold; Each node generates a random number by itself; the random number is generated by a random variable in [0, 1]; and the random number is subject to a uniform distribution. Each node compares the random number generated by itself with a cluster head election threshold value: If the random number is less than the cluster head election threshold value, the node becomes a cluster head node in the current large period; Otherwise, the node does not become a cluster head node. Improved cluster head election threshold function T imp (n) as follows: F(mse) = 1.02^(24^(10*mse)); Wherein, mse∈[0, +∞); P is a priori determined proportion of cluster head nodes in the network; r is the current round; and G is a set of nodes that have not become cluster head nodes in the last 1 / P rounds.
Citation Information
Patent Citations
Cluster head election method for improving LEACH algorithm and method for improving LEACH routing protocol
CN119835726A