Machine learning based quantum cryptography system integration anomaly detection method

By using Gaussian Mixture Model (GMM) and sliding window technology based on machine learning, efficient and accurate anomaly detection of quantum cryptography systems was achieved, solving the problems of device imperfection and eavesdropper attacks, and improving system security and transmission efficiency.

CN119921948BActive Publication Date: 2026-01-20NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510082037.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2026-01-20
Estimated Expiration
2045-01-20

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) systems suffer from device imperfections and eavesdropper attack vulnerabilities in practical applications, leading to security threats. Furthermore, existing security assessment methods require significant resources and reduce transmission efficiency.

Method used

An integrated anomaly detection method for quantum cryptosystems based on machine learning is adopted. By utilizing Gaussian mixture model (GMM) and sliding window technology, and through simulation data training and experimental data testing, the method identifies device modulation errors and eavesdropper attacks, providing efficient and accurate security assessment.

Benefits of technology

Without interrupting key transmission, it significantly reduces the cost and time required for security assessment, improves efficiency, and can identify unknown anomaly types, providing additional security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921948B_ABST
    Figure CN119921948B_ABST
Patent Text Reader

Abstract

The application discloses a quantum cryptography system integration anomaly detection method based on machine learning, which can not only identify the modulation error of various devices in the quantum cryptography system, but also detect common eavesdropper attacks. The application proposes and proves a kind of integrated detection method based on time series Gaussian mixture model, which uses simulation data for training and experimental data for testing, while maintaining high accuracy, it provides a more convenient solution for users. In addition, this method does not require additional equipment or interrupt key transmission, thereby reducing costs and improving efficiency. At the same time, this method can identify unknown anomalies and provide additional security for system security. Therefore, this work not only provides a new solution for the security evaluation of quantum cryptography system, but also provides a new perspective for the development of large-scale quantum security network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum cryptography, and particularly relates to a quantum cryptography system integrated anomaly detection method based on machine learning. BACKGROUND

[0002] Quantum key distribution (QKD) utilizes the basic principles of quantum mechanics to enable two communicating parties, Alice and Bob, to generate keys for encryption or authentication even in the presence of an eavesdropper. When combined with a "one-time pad" encryption method, QKD theoretically ensures unconditional security. However, achieving unconditional security requires idealized conditions, such as ideal quantum state preparation and perfect single-photon detection. In practical applications, factors such as limited extinction ratio in quantum state preparation, fluctuations and correlations in actual light source intensity, and imperfections in detectors can introduce potential security vulnerabilities.

[0003] At the transmitting end, imperfections in quantum fluctuation and modulation devices introduce random fluctuations in light source intensity, causing the intensity values of signal states and decoy states to deviate from expected values. In addition, phase modulators are mainly used for phase randomization of weak coherent states in decoy state schemes and for phase modulation and demodulation in phase encoding schemes. Currently, a "sweep-transmit" procedure is commonly used for phase calibration, and additional monitoring and measurement are required to evaluate the intensity and phase deviations of the modulation. At the receiving end, quantum key distribution (QKD) systems typically rely on multiple detectors. In security analysis and theoretical models, it is generally assumed that the performance parameters of these detectors are identical. However, in practical applications, the detection efficiency of each detector varies over time. Due to imperfections or errors present in actual quantum key distribution (QKD) devices, an eavesdropper may exploit these vulnerabilities to launch hacking attacks, which threatens the practical security of quantum cryptography systems. In addition, some modulation errors may be actively introduced by an eavesdropper, such as induced optical refraction attacks, laser damage attacks, and laser injection attacks. These attacks can cause damage to various devices, resulting in changes in the light intensity of prepared quantum states. One possible solution is to use additional incident light monitors to detect injected light, however, the classical monitors themselves can be damaged by high-intensity light introduced by an eavesdropper. Currently, most existing quantum key distribution (QKD) system evaluation schemes require calibration and detection of all components before and after key transmission. These processes not only require a large amount of human and material resources, but also reduce the transmission efficiency and practicality of quantum key distribution (QKD). SUMMARY

[0004] The present application aims at the deficiencies of the prior art, and provides a quantum cryptography system integrated abnormality detection method based on machine learning, which can be applied to a quantum cryptography system, can identify modulation errors of various devices in the quantum cryptography system and common eavesdropper attacks. The simulation data is used for training, and the experimental data is used for testing, so that a more convenient solution is provided for users while maintaining high accuracy. The present application greatly reduces the cost and improves the efficiency without the need for additional equipment and interrupting key transmission.

[0005] The present application discloses a quantum cryptography system abnormality detection method based on machine learning, which adopts a sliding window mode, inputs unmatched base data x in a continuous time sequence to a Gaussian mixture model GMM, and outputs abnormality type Y label The Gaussian mixture model GMM is trained as an output label of the Gaussian mixture model GMM;

[0006] The trained Gaussian mixture model GMM is obtained, and the number of the trained Gaussian mixture model GMM is the same as that of the abnormality type Y label That is, a single Gaussian mixture model GMM is trained for each abnormality type, and each abnormality type Y label Corresponds to a trained Gaussian mixture model GMM.

[0007] The abnormal unmatched base data x is input to all trained Gaussian mixture models GMM in a sliding window mode, the posterior probability of each group of sliding window sequence data for each abnormality type is calculated, and the abnormality type Y label as the abnormality type of the unmatched base data x, that is, the abnormality type of the quantum cryptography system.

[0008] Further, the size of the sliding window is greater than or equal to 3, and the step is 1.

[0009] Therefore, the unmatched base data x is written in the form of a continuous time sequence as follows: t , t+1 , t+2 , t+3 , …X t+N-1 ;X t represents the unmatched base data at time t.

[0010] Further, the unmatched base data includes eight counts of unmatched bases, which are represented as: MZ0X0, MZ0X1, MZ1X0, MZ1X1, MX0Z0, MX0Z1, MX1Z0, MX1Z1.

[0011] Wherein, MZ0X0 represents the count of Alice selecting Z-base encoding bit 0 and Bob selecting X-base encoding bit 0; MZ0X1 represents the count of Alice selecting Z-base encoding bit 0 and Bob selecting X-base encoding bit 1; MZ1X0 represents the count of Alice selecting Z-base encoding bit 1 and Bob selecting X-base encoding bit 0; MZ1X1 represents the count of Alice selecting Z-base encoding bit 1 and Bob selecting X-base encoding bit 1; MX0Z0 represents the count of Alice selecting X-base encoding bit 0 and Bob selecting Z-base encoding bit 0; MX0Z1 represents the count of Alice selecting X-base encoding bit 0 and Bob selecting Z-base encoding bit 1; MX1Z0 represents the count of Alice selecting X-base encoding bit 1 and Bob selecting Z-base encoding bit 0; MX1Z1 represents the count of Alice selecting X-base encoding bit 1 and Bob selecting Z-base encoding bit 1.

[0012] Further, the abnormal type Y label including phase error, efficiency mismatch, intensity fluctuation, phase error + efficiency mismatch, efficiency mismatch + intensity fluctuation, phase error + intensity fluctuation, phase error + efficiency mismatch + intensity fluctuation and attack.

[0013] Further, the abnormal mismatch base data refers to that the abnormal score S(x) of the mismatch base data x is located outside the normal fluctuation range; the calculation process of the abnormal score S(x) is as follows:

[0014] In the actual quantum cryptography system, the mismatch base data is obtained, and the probability density function p(x) of multiple Gaussian distributions is obtained by taking the logarithm of the probability density function p(x) and then taking the inverse, to obtain the abnormal score S(x) of the mismatch base data.

[0015] Further, the acquisition method of the normal fluctuation range is as follows:

[0016] In the normally operating quantum cryptography system, the probability density function p(x) of multiple Gaussian distributions is fitted, and the abnormal score S(x 正常 ) of the normal mismatch base data is obtained by taking the logarithm of the probability density function p(x) and then taking the inverse, and the distribution range of the abnormal score S(x 正常 ) of the normal mismatch base data is the normal fluctuation range.

[0017] Further, the single Gaussian distribution of the mismatch base data x is as follows:

[0018]

[0019] ​d denotes the vector dimension of the mismatched base data point, μ is the mean vector of the Gaussian component, Σ is the covariance matrix of the Gaussian component, |Σ| is the determinant of the covariance matrix, Σ -1 is the inverse of the covariance matrix.

[0020] The Gaussian Mixture Model (GMM) is a weighted sum of multiple Gaussian distributions, and its probability density function p(x) is:

[0021]

[0022] K is the number of Gaussian components, ω k is the weight of the k-th Gaussian component, satisfying μ k and Σ k are the mean vector and covariance matrix of the k-th Gaussian component, respectively;

[0023] The anomaly score S(x) is represented as:

[0024] S(x) = -log(p(x)).

[0025] Further, the Expectation Maximization (EM) algorithm is used to estimate the parameters of the Gaussian Mixture Model (GMM);

[0026] The Expectation Maximization (EM) algorithm includes two steps: the Expectation step (E-step) and the Maximization step (M-step);

[0027] E-step: Calculate the posterior probability γ i of the i-th input to the Gaussian Mixture Model (GMM) x ik .

[0028]

[0029] x is an N x 8 data set, where i ∈ [1, N], μ j and Σ j are the mean vector and covariance matrix of the j-th Gaussian component, respectively, μ k and Σ k are the mean vector and covariance matrix of the k-th Gaussian component, respectively;

[0030] M-step: Update the Gaussian Mixture Model (GMM) parameters according to the posterior probability calculated in the E-step.

[0031]

[0032] Repeat the E-step and M-step steps until the Gaussian Mixture Model (GMM) parameters ω k , μ k and Σ kThe change value of the Gaussian mixture model is less than the set threshold value or reaches the maximum number of iterations.

[0033] Further, the posterior probability of each group of sliding window sequence data for each abnormal type is less than 10 -500 If so, it is considered that the quantum cryptography system has unknown abnormalities. Unknown abnormal types can be identified in the test phase, providing additional security for system security, which do not require prior training to handle abnormal situations in the system.

[0034] Further, in the process of training the Gaussian mixture model GMM, the mismatched base data is simulation data, and experimental data is used for testing.

[0035] Further, the method is not only applicable to the phase-encoding BB84 protocol quantum key distribution QKD system, but also can be applied to other various quantum cryptography protocols, including but not limited to measurement device-independent quantum key distribution MDI-QKD protocol, quantum secret sharing QSS protocol, two-field quantum key distribution TF-QKD protocol, quantum identity authentication QIA protocol and quantum privacy amplification QPQ protocol; The method supports multiple encoding methods, including polarization encoding, timestamp-phase, etc., and can adapt to different quantum communication channels and light source characteristics.

[0036] The beneficial effects of the method are: compared with the traditional method, the abnormality detection method based on time series Gaussian mixture model (GMM) of the present application greatly reduces the time required for security evaluation of quantum cryptography system. The time requirement for security evaluation of quantum cryptography system is significantly reduced. At the same time, the method uses simulation data for model training and experimental data for testing, providing a convenient and high-accuracy solution for users; without additional equipment and without interrupting the key transmission process, thereby reducing the cost and improving the efficiency. In addition, the method can identify unknown abnormal types, providing additional security for the security of quantum cryptography system, so that the system can cope with unknown security threats. BRIEF DESCRIPTION OF DRAWINGS

[0037] Figure 1 is an experimental device diagram for verifying the method of the present application.

[0038] Figure 2 is an abnormal score graph of the present application under 100km of four different types of abnormalities.

[0039] Figure 3 is a confusion matrix result graph of the present application at 100km and 150km.

[0040] Figure 4 is a ROC curve comparison graph of the present application and other schemes.

[0041] Figure 5 is a process schematic diagram of the method of the present application. DETAILED DESCRIPTION

[0042] The technical solutions in the embodiments of the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0043] The present application proposes a machine learning-based quantum cryptography system integrated anomaly detection method, which can be applied to a quantum cryptography system and can identify modulation errors of various devices in the quantum cryptography system and common eavesdropper attacks. In this embodiment, a BB84 quantum key distribution QKD system using phase encoding is taken as an example for introduction, and the quantum key distribution QKD system includes a sending end Alice, a receiving end Bob and an eavesdropper Eve. Figure 5 is a process schematic diagram of the machine learning-based quantum cryptography system integrated anomaly detection method. The whole process is divided into two parts: a training stage and a testing stage, wherein simulation data is used for the training stage and actual experimental data is used for the testing stage:

[0044] Training stage:

[0045] Considering that it is impractical to collect experimental data in different environments and parameters in advance, the present application scheme uses simulation data for model training and experimental data for testing.

[0046] In the training part, the present application method uses a sliding window to input simulation data into a Gaussian mixture model GMM, as shown in Figure 5 The size of the sliding window is four continuous time series [X t ,X t+1 ,X t+2 ,X t+3 ] simulation data, which are used as input features of the Gaussian mixture model GMM, and each time simulation data X t contains the counts of eight unmatched bases, respectively MZ0X0, MZ0X1, MZ1X0, MZ1X1, MX0Z0, MX0Z1, MX1Z0, MX1Z1;

[0047] Wherein, MZ0X0 represents the count of Alice selecting Z-base encoding bit 0 and Bob selecting X-base encoding bit 0; MZ0X1 represents the count of Alice selecting Z-base encoding bit 0 and Bob selecting X-base encoding bit 1; MZ1X0 represents the count of Alice selecting Z-base encoding bit 1 and Bob selecting X-base encoding bit 0; MZ1X1 represents the count of Alice selecting Z-base encoding bit 1 and Bob selecting X-base encoding bit 1; MX0Z0 represents the count of Alice selecting X-base encoding bit 0 and Bob selecting Z-base encoding bit 0; MX0Z1 represents the count of Alice selecting X-base encoding bit 0 and Bob selecting Z-base encoding bit 1; MX1Z0 represents the count of Alice selecting X-base encoding bit 1 and Bob selecting Z-base encoding bit 0; MX1Z1 represents the count of Alice selecting X-base encoding bit 1 and Bob selecting Z-base encoding bit 1.

[0048] Anomaly type Y label As the output label of the Gaussian mixture model GMM, the anomaly type includes phase error, efficiency mismatch, intensity fluctuation, phase error+efficiency mismatch, efficiency mismatch+intensity fluctuation, phase error+intensity fluctuation, phase error+efficiency mismatch+intensity fluctuation and attack, a total of 8 anomaly types. The present scheme only uses 50 groups of simulation data of four consecutive time points to train the Gaussian mixture model GMM of each anomaly type, and a total of 8 trained Gaussian mixture models GMM are obtained, which enables the Gaussian mixture model GMM to learn the unique features of each anomaly type;

[0049] The 8 trained Gaussian mixture models GMM are used for subsequent testing stages.

[0050] Testing stage:

[0051] Actual quantum cryptography system experimental data is used for anomaly detection; during the operation of the quantum key distribution QKD system, the mismatched base data of the Alice end (the sending end) and the Bob end (the receiving end) is collected in real time, and Alice and Bob announce their base selection information through a classical public channel, when they select different bases, the mismatched base measurement data is used for integrated anomaly detection of the QKD system, which allows anomaly detection without interrupting key transmission. By calculating the anomaly score S(x) of each group of mismatched base data, it is determined whether the mismatched base data is normal;

[0052] The anomaly score S(x) of the mismatched base data point is calculated as follows:

[0053] Firstly, the present scheme needs to evaluate whether there is an anomaly in the quantum key distribution QKD system. Due to the inevitable statistical fluctuations in the quantum key distribution QKD system, small errors within the range of these fluctuations can be difficult to distinguish from normal fluctuations, so these small errors are classified as normal fluctuations, and it is considered that the quantum key distribution QKD system is running normally; the probability density function p(x) obtained by fitting a plurality of Gaussian distributions from the mismatched base data obtained under the normally running quantum key distribution QKD system is first taken logarithm and then taken inverse, to obtain the anomaly score S(x 正常 ) of the normal mismatched base data, and according to the distribution range of the anomaly score S(x 正常 ) of the normal mismatched base data, the normal fluctuation range of S(x) is obtained.

[0054] A single Gaussian distribution in d-dimensional space is as follows:

[0055]

[0056] x is a vector of d-dimensional mismatched base data points, μ is a mean vector of the Gaussian component, Σ is a covariance matrix of the Gaussian component, |Σ| is a determinant of the covariance matrix, and Σ -1 is the inverse of the covariance matrix. Wherein, d = 8, x is an N x 8 data set, corresponding to 8 groups of mismatched base measurement counts detected in the quantum key distribution QKD system, x can be written in the form of continuous time series: X t , X t+1 , X t+2 , X t+3 , X t+4 … X t+N-1 ;

[0057] The Gaussian mixture model GMM is a weighted sum of a plurality of Gaussian distributions, used to represent more complex data distribution, and its probability density function (PDF) is:

[0058]

[0059] K is the number of Gaussian components, ω k is the weight of the kth Gaussian component, satisfying μ k and Σ k are the mean vector and covariance matrix of the kth Gaussian component, respectively. In addition, in order to estimate the parameters of the Gaussian mixture model GMM, the present scheme uses the expectation maximization EM algorithm. The expectation maximization EM algorithm includes two steps: the expectation step (E-step) and the maximization step (M-step).

[0060] E-step: Calculate the posterior probability γ i of the ith input mismatched base data x to the kth Gaussian component in the Gaussian mixture model GMM.ik .

[0061]

[0062] x is an N x 8 data set, where i ∈ [1, N], μ j and Σ j are the mean vector and covariance matrix of the jth Gaussian component, μ k and Σ k are the mean vector and covariance matrix of the kth Gaussian component;

[0063] M-step: update the model parameters according to the posterior probability calculated in the E-step.

[0064]

[0065] Repeat the E-step and M-step steps until the change values of the above model parameters ω k , μ k and Σ k are less than a set threshold or reach a maximum number of iterations. In this scheme, the maximum number of iterations is 100. In addition, if the change values of all model parameters ω k , μ k and Σ k in each iteration are less than a set tolerance possibility threshold (10 -8 ), that is, the change is very small, it means that the model parameters have converged, and the algorithm terminates.

[0066] The anomaly score S(x) is represented as:

[0067] S(x) = -log(p(x)).

[0068] The method defines the anomaly score S(x). When the anomaly score S(x) is within the normal fluctuation range, the mismatched base data corresponding to the experimental measurement is normal, indicating that the quantum key distribution (QKD) system is normal. When the anomaly score S(x) is outside the normal fluctuation range, the mismatched base data corresponding to the experimental measurement is abnormal, indicating that the QKD system has an anomaly.

[0069] For the mismatched base data points identified as abnormal, the mismatched base data [X t , X t+1 , X t+2 , X t+3 ], [X t+1 , X t+2 , X t+3 , X t+4The sliding window sequences are input into 8 trained Gaussian mixture models (GMMs) as features, and the data contained in one sliding window input into a trained GMM is a group of sequence data. The posterior probability γ of each group of sliding window sequence data for each type of anomaly is calculated ik , and the class with the highest posterior probability is selected as the final type of system anomaly.

[0070] Figure 1 is an experimental device diagram for verifying the machine learning-based quantum cryptography system integrated anomaly detection method of the present application. At the Alice end, a 20MHz frequency laser emits light pulses with a central wavelength of 1550.6nm. The encoded information is encoded on the optical phase through a self-made asymmetric Mach-Zehnder interferometer (AMZI) with an arm length difference of 6.3ns. A phase modulator (PM) is placed on the long arm of the asymmetric Mach-Zehnder interferometer (AMZI), and the phase modulator (PM) at the Alice end realizes phase modulation. After interference at the polarization beam splitter (PBS), the intensity modulator (IM) is reached. An intensity modulator (IM) is used to realize different intensity modulation. The intensity of the laser pulse is attenuated to the single photon level by an attenuator (ATT), and then transmitted to the quantum channel;

[0071] After the pulse reaches the Bob end, the phase modulator (PM) at the Bob end realizes phase demodulation. The modulated pulse interferes at the beam splitter (BS), and the interference result is detected by two different channel superconducting nanowire single photon detectors (SNSPD). The SNSPD works at a temperature of 2.2K, providing a detection efficiency of 67% and an average dark count of 10Hz. At the same time, a ultraviolet laser diode is injected into the output end of the intensity modulator (IM) of Alice through a 1:99 beam splitter, and the pulse of Eve is injected into the intensity modulator (IM) of Alice in the opposite direction to realize the attack.

[0072] To verify the effectiveness of the integrated real-time detection method of this invention, the verification was mainly conducted from two perspectives: passive modulation error and active modulation error. Passive modulation error may originate from inherent defects in the actual equipment, environmental changes, or imperfect regulators. For passive modulation error, this scheme uses intensity fluctuations caused by the intensity modulator (IM), phase errors caused by the phase modulator (PM), and detector efficiency mismatch as examples, but it is not limited to these defects and can be adjusted according to the actual situation of the quantum cryptography system. This invention designs a method to simulate modulation error by artificially shifting the original operating voltage of the phase modulator (PM) to a certain extent, thereby changing the modulation points of all phases to achieve the effect of phase modulation error. Similarly, detector efficiency mismatch is simulated by adjusting the bias current of detectors in different channels, as the bias current directly affects the efficiency of the superconducting nanowire single-photon detector (SNSPD). To simulate intensity fluctuations, this scheme first measures the statistical fluctuations of the quantum key distribution (QKD) system under normal operating conditions, which are 0.57% at a distance of 100 km. To make the intensity fluctuations more apparent in the experiment, the attenuation value is adjusted using a sequence designed based on a Gaussian distribution, and the final simulated intensity fluctuation is 3.52%.

[0073] Furthermore, this scheme also considers the active modulation error introduced by Eve. This embodiment demonstrates an induced optical refraction attack, where the DC bias of the LiNbO3 modulator drifts over time due to the photorefractive effect. The integrated anomaly detection method for quantum cryptography systems based on machine learning is also applicable to other attacks, such as laser damage attacks and laser seeding attacks. These attacks can cause damage to various devices, resulting in changes in the light intensity of the prepared quantum state. Figure 1 As shown, this scheme uses a 445nm ultraviolet laser diode (UVLD) to generate pulses. These ultraviolet pulses are then reverse-biased through a 1:99 beam splitter (BS) and enter the intensity modulator (IM) at the Alice end, inducing a photorefractive effect. Before launching the attack, the DC bias of the intensity modulator (IM) is first calibrated to the correct voltage, and then the ultraviolet laser is turned on. In the experiment, Eve modulates the pulse with a power of 0.7mW, resulting in a power of 0.2μW reaching the intensity modulator (IM), ultimately causing a shift in the DC bias of the IM and successfully launching the attack.

[0074] Figure 2 These are the anomaly scores for four different types of anomalies over a transmission distance of 100km: Figure 2 In the diagram, (a) represents the phase error. Figure 2 (b) in the text represents an efficiency mismatch. Figure 2 (c) in the figure represents intensity fluctuations. Figure 2(d) is an attack. Each point in the figure represents the anomaly score calculated based on the measurement data of a set of mismatch bases, and the data is collected at an interval of 0.5 seconds. The shaded area represents the anomaly score calculated from the simulation data, in which the signal state intensity is 0.5, the phase error is 0, and the detection efficiency is 67%. Considering the statistical fluctuation of 0.57%, the maximum and minimum anomaly scores of the simulation data are 71.8928 and 71.8446, respectively. Figure 2 (a) in FIG. 7 shows the case when the voltage deviation is 0.1V and 0.2V, and in the embodiment of the present application, the half-wave voltage of the phase modulator PM at Bob's end is 7.3V, and the voltage deviations of 0.1V and 0.2V correspond to phase deviations of 0.043° and 0.086°, respectively, all data points fall outside the shaded area, indicating that the data points are considered abnormal; Figure 2 (b) in FIG. 7 shows the case when the detection efficiency changes from 67% to 65% and 63%, when the detection efficiency is 65%, most of the data is outside the shaded area, only a few data is considered normal. When the efficiency is 65%, all data falls outside this range and is considered abnormal; intensity fluctuations and attacks will cause changes in intensity, however, intensity fluctuations alternate between increasing and decreasing, while attacks will cause a sudden and one-way change in intensity. Figure 2 (c) in FIG. 7 shows the anomaly score of the intensity fluctuation. Since the intensity fluctuation follows a Gaussian distribution, most intensity values are concentrated around 0.5, the shaded area in the figure represents the anomaly score corresponding to the normal simulation data, and the circular points represent the measured data falling within the expected range of the normal simulation data and can be considered normal. In contrast, the triangular points represent measured data that is outside this range, indicating that it is abnormal; Figure 3 (d) in FIG. 7 shows the anomaly scores of 8 different induced photorefractive attacks by Eve, each attack is represented by a different style of point. It can be clearly seen that at the moment of each attack, the anomaly score suddenly increases, indicating that the intensity deviates sharply from the normal range.

[0075] After identifying the abnormal data, the sliding window sequence corresponding to the mismatch base is extracted as a feature, and these sequences are input into 8 pre-trained Gaussian mixture models GMM. Then the posterior probability of these data in each category is calculated, and the category with the highest posterior probability is selected as the final type of system anomaly. If the posterior probability is less than 10 -500 , the QKD system is considered to be an unknown anomaly. Figure 3 FIG. 8 is a confusion matrix result diagram of the present application based on the time series Gaussian mixture model GMM algorithm at 100km and 150km, wherein, Figure 3 (a) in FIG. 8 is a confusion matrix result diagram of the present application method at 100km, Figure 4The confusion matrix result figure of the method of the application in (b) at 150km, the vertical coordinate is the label corresponding to the actual system anomaly type, and the horizontal coordinate is the label corresponding to the anomaly type predicted by the Gaussian mixture model (GMM) algorithm. There are 1084 groups of abnormal data at 100km, and 933 groups of abnormal data at 150km. Labels 1-9 represent: 1) unknown anomaly, 2) phase error, 3) efficiency mismatch, 4) intensity fluctuation, 5) phase error + efficiency mismatch, 6) efficiency mismatch + intensity fluctuation, 7) phase error + intensity fluctuation, 8) phase error + efficiency mismatch + intensity fluctuation, and 9) attack. The application scheme is outstanding in detecting unknown anomalies due to its soft classification method, and also shows higher accuracy in identifying known types, with an accuracy rate of 98.7% at a distance of 100km, which is significantly higher than the 84.1% of the RF algorithm and the 57.7% of the SVM algorithm. At the same time, the application method is further verified at a distance of 150km, and the accuracy rate of the application scheme is the highest, reaching 98.8%, while the accuracy rates of the RF and SVM algorithms are 62.1% and 80.2%, respectively.

[0076] Figure 4 The ROC curve comparison figure of the application and other schemes is shown in (b). Figure 4 (a) in (b) is the ROC curve comparison figure of the application scheme at 100km and other schemes, ​ (b) in (b) is the ROC curve comparison figure of the application scheme at 150km and other schemes, and the ROC curve shows the trade-off between true positive rate (TPR) and false positive rate (FPR) at different decision thresholds. A key indicator derived from the ROC curve is the area under the curve (AUC), which quantifies the overall ability of the classifier to distinguish between classes. AUC of 1 indicates perfect classification, and 0.5 indicates random guessing. As can be seen from the results, the performance of the application scheme is the best, with an AUC of 0.999 at distances of 100km and 150km, which is significantly better than RF and SVM.

[0077] The method can be applied to various quantum cryptography protocols, including measurement device independent (MDI) QKD protocol, quantum secret sharing (QSS) protocol, two-field (TF) QKD protocol, quantum identity authentication (QIA) protocol and quantum privacy amplification (QPQ) protocol; the method supports various encoding modes, including polarization encoding, timestamp-phase, etc., and can adapt to different quantum communication channels and light source characteristics.

[0078] The above only describes the preferred embodiments of the application, and the protection scope of the application is not limited to the above embodiments, but any equivalent modifications or changes made by those skilled in the art according to the disclosed content of the application shall be included in the protection scope recited in the claims.

Claims

1. An anomaly detection method for a quantum cryptosystem based on machine learning, characterized in that, Using a sliding window approach, mismatched basis data x are input as continuous time series into a Gaussian mixture model (GMM), with anomaly type Y. label The Gaussian Mixture Model (GMM) is trained using the output labels as the output labels. We obtain a well-trained Gaussian Mixture Model (GMM), and the number of well-trained GMMs and the anomaly types Y. label The number is the same, that is, each exception type Y label This corresponds to a pre-trained Gaussian Mixture Model (GMM). The anomalous mismatch basis data is input into all trained Gaussian Mixture Models (GMMs) in a sliding window manner. The posterior probability of each sliding window sequence for each anomalous type is calculated, and the anomalous type Y corresponding to the maximum posterior probability is selected. label As an anomaly type of mismatched base data x; The anomalous mismatched base data refers to the anomalous score S(x) of the mismatched base data x that is outside the normal fluctuation range; The calculation process for the anomaly score S(x) is as follows: In a real-world quantum cryptography system, mismatched basis data is obtained. The probability density function p(x) is obtained from multiple Gaussian distributions in the quantum key distribution system. The logarithm of the probability density function p(x) is taken first and then inverted to obtain the anomaly score S(x) of the mismatched basis data. The method for obtaining the normal fluctuation range is as follows: In a normally functioning quantum cryptography system, mismatched basis data is acquired, and the probability density function p(x) obtained by fitting multiple Gaussian distributions is calculated. The logarithm of the probability density function p(x) is then inverted to obtain the anomaly score S(x) of the normal mismatched basis data. 正常 The abnormal score S(x) of the normal mismatched base data 正常 The distribution range of ) is the normal fluctuation range.

2. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 1, characterized in that, The sliding window has a size of 3 or greater and a step size of 1. Therefore, the mismatched base data x can be written in continuous time series form as: X t ,X t+1 ,X t+2 ,X t+3 …X t+N-1 ;X t This represents the mismatched base data at time t.

3. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 1, characterized in that, The mismatched basis data includes the counts of eight mismatched bases, represented as: MZ0X0, MZ0X1, MZ1X0, MZ1X1, MX0Z0, MX0Z1, MX1Z0, MX1Z1; Where MZ0X0 represents the count of Alice choosing Z-based coded bit 0 and Bob choosing X-based coded bit 0; MZ0X1 represents the count of Alice choosing Z-based encoding bit 0 and Bob choosing X-based encoding bit 1; MZ1X0 represents the count of Alice choosing Z-based encoding bit 1 and Bob choosing X-based encoding bit 0; MZ1X1 represents the count of Alice choosing Z-based encoding bit 1 and Bob choosing X-based encoding bit 1; MX0Z0 indicates the count of Alice selecting X-based coded bit 0 and Bob selecting Z-based coded bit 0; MX0Z1 indicates the count of Alice selecting X-based encoding bit 0 and Bob selecting Z-based encoding bit 1; MX1Z0 indicates the count of Alice selecting X-based encoding bit 1 and Bob selecting Z-based encoding bit 0; MX1Z1 indicates the count of Alice selecting X-based encoding bit 1 and Bob selecting Z-based encoding bit 1.

4. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 1, characterized in that, Exception type Y label This includes phase error, efficiency mismatch, intensity fluctuation, phase error + efficiency mismatch, efficiency mismatch + intensity fluctuation, phase error + intensity fluctuation, phase error + efficiency mismatch + intensity fluctuation, and attack.

5. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 1, characterized in that, Mismatched base data x Single Gaussian distribution as follows: d represents the vector dimension of the mismatched base data points, μ is the mean vector of the Gaussian components, Σ is the covariance matrix of the Gaussian components, and |Σ| is the determinant of the covariance matrix. -1 It is the inverse of the covariance matrix; A Gaussian Mixture Model (GMM) is a weighted sum of multiple Gaussian distributions, and its probability density function p(x) is: K is the number of Gaussian components, ω k Let the weight of the k-th Gaussian component satisfy the following condition: μ k and Σ k These are the mean vector and covariance matrix of the k-th Gaussian component, respectively; The abnormal score S(x) is represented as: S(x) = -log(p(x)).

6. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 5, characterized in that, The Expectation-Maximization (EM) algorithm is used to estimate the parameters of the Gaussian Mixture Model (GMM).

7. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 6, characterized in that, The Expectation Maximization (EM) algorithm comprises two steps: the expectation step (E-step) and the maximization step (M-step). E-step: Calculate the mismatched basis data x of the i-th input to the Gaussian Mixture Model (GMM). i The posterior probability γ of belonging to the k-th Gaussian component ik ; x is an N×8 dataset, where i∈[1,N], μ j and Σ j Let μ be the mean vector and covariance matrix of the j-th Gaussian component, respectively. k and Σ k These are the mean vector and covariance matrix of the k-th Gaussian component, respectively; M-step: Updates the parameters of the Gaussian Mixture Model (GMM) based on the posterior probabilities calculated by the E-step; Repeat the E-step and M-step steps until the Gaussian Mixture Model (GMM) parameter ω is reached. k μ k and Σ k The change value is less than the set threshold or the maximum number of iterations is reached.

8. The anomaly detection method for a quantum cryptosystem based on machine learning according to claim 1, characterized in that, The posterior probability of each sliding window sequence for each anomaly type is less than 10. -500 At that time, it is believed that the quantum cryptography system has unknown anomalies.

Citation Information

Patent Citations

  • Attack detection method for continuous variable quantum key distribution system

    CN113037778A

  • Detection method for QKD system defect and hacker attack based on machine learning

    CN116319010A