SVM (Support Vector Machine) induced deception detection algorithm based on related domain information

Through feature correlation analysis and automatic selection of feature combinations of mutual information calculations, an SVM-induced spoof detection algorithm based on related domain information is constructed, which solves the problem of misjudgment in a multipath interference environment in traditional technology, realizes efficient spoof detection and multipath interference distinction, and improves detection performance and model migration capabilities.

CN119936922AActive Publication Date: 2025-05-06NAT UNIV OF DEFENSE TECH

Patent Information

Application Number
CN202510103341.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-06
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

When the prior art deals with multipath interference, traditional related domain signal quality monitoring technology is prone to misjudging multipath interference as a spoofed signal, resulting in high false alarm rates, lack of system analysis of feature selection, insufficient model generalization capabilities, and poor fraud detection performance.

Method used

Through feature correlation analysis and mutual information calculation, the feature combination of automatically selected targets is learned, the timing laws of related peak distortion and the joint relationship between multiple features are constructed, and the SVM-induced spoof detection algorithm based on related domain information is constructed to distinguish multipath interference from spoof signals.

Benefits of technology

It significantly improves the accuracy of fraud detection and the migration ability of the model, reduces false alarms, improves detection performance in multipath environments, and does not require retraining in various scenarios, improving the practicality and wide adaptability of the algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119936922A_ABST
    Figure CN119936922A_ABST
Patent Text Reader

Abstract

The invention relates to an SVM (Support Vector Machine) induced deception detection algorithm based on related domain information. The method comprises the following steps: acquiring a signal source generation signal in an interference scene, and capturing and resolving the signal source generation signal to obtain output data; the output data comprises a moving mean value output by an IQ branch of the ELP correlator and related detection index data; carrying out correlation analysis on the output data and carrying out feature screening on contribution degrees of features to tags to obtain input feature combinations of different feature numbers; part of data is randomly selected from the input feature combinations with different feature numbers to serve as a training set, the other data serves as a test set, and SVM model parameters are solved through the training set to construct a classifier for detecting GNSS deception and multipath interference; and the classifier is classified and predicted by using the test set, the detection performance of the SVM model is evaluated, and deception detection is performed according to the trained SVM model. By adopting the method, the spoofing detection performance can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of satellite navigation technology, and in particular to an SVM induced deception detection algorithm based on relevant domain information. Background Art

[0002] Satellite navigation technology has been widely used around the world, and most devices rely on this technology for accurate positioning and navigation. However, with the popularization of technology, spoofing attacks on satellite navigation systems have increased and have become an important issue that needs urgent attention. In civil emergency services, ensuring the authenticity and accuracy of navigation signals is crucial to the effectiveness of equipment and the safety of operations. Therefore, it is necessary to research and develop effective satellite navigation spoofing detection technology to cope with evolving security threats in order to ensure the safety and reliability of navigation systems.

[0003] Traditional satellite navigation deception techniques can be divided into three types: simple, intermediate and complex. Simple deception confuses the receiver by sending false signals similar to real signals; complex deception completely simulates real navigation signals and has more sophisticated technology. Among them, intermediate induced deception has become a research hotspot due to its excellent deception effect and easy implementation. This technology gradually adjusts the power and code rate of the signal to make the receiver deviate from the real signal and eventually lock on the deception signal. Its strong concealment and high success rate make it more operational than complex methods, and it is also better than simple methods. Therefore, induced deception has been widely used in the civilian field. Its concealment and effectiveness make it an important field in navigation deception research, and gradually become a mainstream deception technology, and therefore an important target field for deception detection research.

[0004] Induced deception attacks mainly manipulate the receiver by slowly shifting the loop tracking point, thereby achieving control over the loop. In order to deal with this attack, many scholars have constructed various detection quantities in the correlation domain to detect deception. Some people have proposed classic detection quantities such as Delta, Ratio and ELP, which can accurately detect induced deception after it enters the loop correlator spacing. Another group of people proposed the use of a new SQM (Signal Quality Monitoring, SQM) detection quantity, which has greatly improved the deception detection performance on public data sets compared to traditional Delta, Ratio and ELP detection quantities. However, because the distortion effect of induced deception on the loop correlation peak is very similar to multipath interference, these traditional detection quantities are prone to detect multipath as deception in a multipath environment, resulting in a large number of false alarms. In order to solve the problem that traditional correlation domain signal quality monitoring technology is still faced with high false alarm rate when used for deception detection when dealing with multipath interference. Others have introduced wavelet transforms to extract features from correlation peaks and combined them with fuzzy classifiers to distinguish multipath from deception signals. Some have also proposed using the SVM algorithm combined with multi-domain information to directly detect deception. The deception detection accuracy and AUC value indicators on public data sets such as TEXBAT have increased by 30.82% and 0.24 respectively compared to the Delta algorithm, showing better performance than the traditional SQM method. On this basis, some people evaluated the impact of the number of input features on the SVM algorithm and added tests on the OAKBAT data set to evaluate the deception detection performance in all data scenarios. The best performance was achieved in scenario 7, with a deception detection accuracy of 97.02% and an AUC of 0.99.

[0005] However, existing studies have all used manual selection when selecting features, lacking a systematic analysis of feature contribution and correlation, and insufficient evaluation of the generalization ability of the model, resulting in poor deception detection performance. Summary of the invention

[0006] Based on this, it is necessary to provide an SVM induced deception detection algorithm based on relevant domain information that can improve the deception detection performance in response to the above technical problems.

[0007] An SVM inductive deception detection algorithm based on relevant domain information, the method comprising: Obtain the signal generated by the signal source in the interference scenario and capture and solve the signal generated by the signal source to obtain output data; the output data includes the moving average output of the IQ branch of the ELP correlator and related detection index data; Perform correlation analysis on the output data and feature screening based on the contribution of features to the label to obtain input feature combinations with different numbers of features; Part of the data is randomly selected from the input feature combinations with different numbers of features as the training set, and the rest of the data is used as the test set. The training set is used to solve the SVM model parameters and build a classifier for detecting GNSS spoofing and multipath interference. The test set is used to classify and predict the classifier, evaluate the detection performance of the SVM model, and perform spoofing detection based on the trained SVM model.

[0008] The above-mentioned SVM-induced deception detection algorithm based on relevant domain information, this application automatically selects the feature combination of the target quantity through feature correlation analysis and mutual information calculation, so as to learn the temporal law of correlation peak distortion and the joint relationship between multiple features, fully mine the relevant domain information, and through training on synchronous, asynchronous and multipath interference data sets, deeply learn the joint relationship between multiple features and their temporal evolution. Using the training set to solve the SVM model parameters to build a classifier for detecting GNSS deception and multipath interference can effectively distinguish multipath interference from deception signals, and performs well in the simultaneous deception detection effect. The model also shows a certain migration ability, and there is no need to retrain in each scenario, which significantly improves its practicality and wide adaptability. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 A schematic diagram of a flow chart of an SVM inductive deception detection algorithm based on relevant domain information in one embodiment; Figure 2 is a flowchart of a SVM classification algorithm based on related domain features in one embodiment; Figure 3 A schematic diagram of the working principle of a support vector machine in one embodiment; Figure 4 Schematic diagram of the change process of the feature Delta-avg in two scenarios in another embodiment; Figure 5 is a diagram showing the change process of the feature iE-avg in two scenarios in one embodiment; Figure 6 is a graph showing the analysis results of feature correlation and contribution to tags in one embodiment; Figure 7 A graph showing a change in the Ratio detection amount in a Spoofing1 deception scenario in an embodiment; Figure 8 A graph showing the change in Delta detection amount for a Spoofing1 deception scenario in an embodiment; Fig. 9 This is a result of Spoofing1 traditional induced deception detection in an embodiment; Fig.10 This is a graph showing the change in Delta detection amount in a Multipath1 multipath interference scenario in an embodiment; Fig.11 This is a graph showing a change in the Ratio detection amount in a Multipath1 multipath interference scenario in an embodiment; Fig.12 is a ROC curve diagram of the CD-SVM algorithm under different feature numbers in one embodiment; Fig.13 is a ROC curve diagram of a traditional SVM algorithm under different feature numbers in one embodiment; Fig.14 A ROC curve diagram of a traditional SQM algorithm in one embodiment; Fig.15 The following is a detection result of the SVM algorithm under an evaluation data set in one embodiment. DETAILED DESCRIPTION

[0010] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0011] In one embodiment, Figure 1 and Figure 2 As shown, a SVM inductive deception detection algorithm based on relevant domain information is provided, including the following steps: Step 102, obtaining a signal generated by a signal source in an interference scenario and capturing and solving the signal generated by the signal source to obtain output data; the output data includes a moving average of the IQ branch output of the ELP correlator and related detection index data.

[0012] In the GNSS spoofing and multipath interference scenarios, read the signal generated by the signal source, configure the parameters of each stage of the software receiver, run the signal capture, signal tracking and position, velocity, time (PVT) solution functions, and output the original data, including the IQ branch output of the ELP correlator, Ratio, Delta, ELP and other detection indicators. The input features of the model are the moving mean of the IQ branch output of the ELP correlator in the correlation domain, the moving mean and moving difference of Ratio, Delta and ELP, and 12 features. The specific features are shown in Table 1.

[0013] Table 1

[0014] The signal generated by the signal source in the interference scenario is obtained and captured and solved to obtain output data including the moving average of the IQ branch output of the ELP correlator and related detection index data. These data are directly related to the actual processing of the signal. The output data of the ELP correlator can reflect some key characteristics of the signal, such as signal strength, phase and other aspects. By performing correlation analysis and feature screening on these data, more targeted input feature combinations with different feature quantities can be obtained, which are closer to the actual needs of deception detection and multipath interference differentiation.

[0015] Step 104 , performing correlation analysis on the output data and feature screening based on the contribution of the features to the labels, to obtain input feature combinations with different numbers of features.

[0016] The original 12 features are analyzed for correlation and contribution to the label to determine the input features selected by the final model. Based on the ranking of feature contribution, the correlation between different features and the amount of original information they contain are considered as the selection principle for feature combinations under different numbers of features. Feature combinations of the target number are automatically selected through feature correlation analysis and mutual information calculation. This is different from the previous method of manually selecting features. Automatic selection can mine relevant domain information more comprehensively and systematically. In a complex satellite navigation signal environment, there may be a variety of potential features related to deception signals and multipath interference. Manual selection is prone to miss some important features or select some features with weak correlation. Automatic selection can comprehensively consider multiple factors, learn the temporal law of correlation peak distortion and the joint relationship between multiple features, so as to accurately select the most representative and distinguishing feature combination for deception detection. At the same time, relevant domain information can be fully mined. In satellite navigation signal processing, the relevant domain contains rich signal features, such as signal correlation, phase and other information. Through the automatic selection process, we can deeply learn the joint relationship between these information and their time-series evolution, so that the selected features can better reflect the true state of the signal, including the differences between spoofed signals and normal signals and multipath interference, thereby providing stronger support for subsequent spoofing detection.

[0017] Step 106, randomly select part of the data from the input feature combinations with different feature numbers as the training set, and the rest of the data as the test set, use the training set to solve the SVM model parameters to build a classifier for detecting GNSS spoofing and multipath interference; use the test set to classify and predict the classifier, evaluate the detection performance of the SVM model, and perform spoofing detection based on the trained SVM model.

[0018] The training set and test set are reasonably divided from the input feature combinations with different feature numbers. 80% are randomly selected as the training set and 20% as the test set. The training set is used to solve the SVM model parameters to build a classifier for detecting GNSS spoofing and multipath interference. Through reasonable data division, the model can better learn the relationship between features and labels (spoofing signals or normal signals). Moreover, using the test set to classify and predict the classifier to evaluate the detection performance of the SVM model can continuously optimize the model so that the model can make more accurate judgments when facing actual spoofing detection tasks, thereby reducing false alarms and improving the accuracy of spoofing detection.

[0019] The above-mentioned SVM-induced deception detection algorithm based on relevant domain information, this application automatically selects the feature combination of the target quantity through feature correlation analysis and mutual information calculation, so as to learn the temporal law of correlation peak distortion and the joint relationship between multiple features, fully mine the relevant domain information, and through training on synchronous, asynchronous and multipath interference data sets, deeply learn the joint relationship between multiple features and their temporal evolution. Using the training set to solve the SVM model parameters to build a classifier for detecting GNSS deception and multipath interference can effectively distinguish multipath interference from deception signals, and performs well in the simultaneous deception detection effect. The model also shows a certain migration ability, and there is no need to retrain in each scenario, which significantly improves its practicality and wide adaptability.

[0020] In one embodiment, the relevant detection index data includes the moving average and moving difference of Ratio, Delta and ELP.

[0021] In one embodiment, performing correlation analysis on the output data includes: The Pearson coefficient was used to perform correlation analysis on the output data. The formula is as follows:

[0022] In the formula, Represents the Pearson correlation coefficient, which is used to measure the variables and The linear correlation between them, that is, analyzing the correlation between the 12 features in Table 1, and Representation variables and No. Observations, variable The average value of , It represents the time from the first observation to the The cumulative sum of observations.

[0023] In one embodiment, the process of calculating the contribution of a feature to a tag includes: The contribution between the feature value and the category label in the calculated output data is

[0024] in, Represents the characteristic variable, that is, the characteristic value in the output data, Indicates the classification result of the category label, i.e., whether it is deceived and whether it contains multipath. represents the joint probability distribution, express The marginal probability distribution of .

[0025] In a specific embodiment, by calculating the contribution between the feature value and the category label in the output data, a higher mutual information value indicates that the correlation between the feature and the target variable is stronger, so these features are more helpful for the classification task.

[0026] In one embodiment, the sample sets of the training set and the test set are

[0027] in, Indicates the mixed signal after being processed by the receiver. Time-dependent domain output dimensional feature vector, where , A feature selected from a combination of input features with different feature numbers, i.e., the input obtained after processing the received mixed signal, Represents the output result, that is, the category of the signal at the current moment, m represents the number of training set data, n Indicates the number of test set data.

[0028] In one embodiment, using a training set to solve SVM model parameters to construct a classifier for detecting GNSS spoofing and multipath interference includes: The kernel function is used to map the features in the training set from the original feature space to a higher-dimensional space, and the optimal separating hyperplane corresponding to the SVM model is found. A classifier for detecting GNSS spoofing and multipath interference is constructed based on the optimal separating hyperplane. The classifier divides samples of different categories into maximum intervals in the high-dimensional feature space.

[0029] In one embodiment, the kernel function is

[0030] in, Represents the original feature space The mapping function to the high-dimensional feature space, Represents the inner product operation.

[0031] In one embodiment, a classifier for detecting GNSS spoofing and multipath interference is constructed based on the optimal separating hyperplane:

[0032]

[0033] in, is the normal vector of the hyperplane, representing the mean vector of the hyperplane, is the offset, which represents the distance between the hyperplane and the origin, Represents input feature combinations with different numbers of features in a high-dimensional feature space, Represents the output result, that is, the category of the signal at the current moment, m Indicates the number of training set data.

[0034] In a specific embodiment, the hyperplane can correctly divide the training data set and maximize the geometric margin. Figure 3 As shown, the green and orange points represent positive and negative classes respectively, and the points with red borders represent support vectors. The support vectors are the sample points closest to the hyperplane and determine the position and direction of the hyperplane.

[0035] In one embodiment, a simulation experiment was conducted. The existing public deception dataset is a synchronous induced deception scenario, while the deception dataset built by this application includes both synchronous induced deception and asynchronous induced deception. In addition, the simulated dataset is intended to provide a more comprehensive testing platform to ensure that the algorithm can perform well in a variety of deception scenarios. By not relying on existing public datasets, the experiment maintains a higher degree of independence and innovation, allowing new signal processing technologies and algorithms to be explored without restrictions.

[0036] The real dynamic scenarios of the simulation experiment users in this application are static position and dynamic motion. The static user position is (-2836275, 3333782, 4623813) in the Earth-Centered, Earth-Fixed (ECEF) coordinate system, and the dynamic user starts from (-2836275, 3333782, 4623813) and moves at a uniform speed of 10m / s along the y-axis. For static users, the initial pseudo-code phase deviation of -0.75chips and -0.25chips is set, and then the code phase deviation speed is 0.1chips / s and 0.5chips / s for induced deception; for dynamic users, the pseudo-code phase offset of -10chips is set, and then gradually approaches the real target at 0.5chips / s, and finally implements the deviation. Multipath interference simulates multipath interference by adding code phase delay and Doppler to the same signal on the original signal. The scenario parameter configuration of the experimental data set is shown in Table 2. The training set includes Spoofing1, Spoofing2, Multipath1 and Multipath2, and the model evaluation set is Spoofing3 and Multipath3. Spoofing1 is to spoof dynamic users. Since the start code phase is greater than the correlator spacing (1chips), it is an asynchronous induced spoofing data set. Spoofing2 and Spoofing3 are to spoof static users, and the start code phase is less than the correlator spacing, so they are synchronous induced spoofing data sets. Multipath1, Multipath2 and Multipath3 all implement multipath interference on static users.

[0037] For the scenario data set used in the simulation experiment of this application, Table 2 lists in detail the duration of the mixed signal, the carrier-to-noise ratio of the navigation signal, the cut-in time of the spoofing signal, the power gain, the initial pseudo code phase delay, the pseudo code deviation rate and the Doppler frequency deviation. For the multipath interference data set, the information such as the power attenuation, cut-in time, delay and Doppler frequency deviation of the multipath interference is provided.

[0038] Table 2

[0039] The input features of the model include the moving mean, Ratio, Delta of the IQ branch output of the correlation domain ELP correlator, and the moving mean and moving difference of ELP, totaling 12 features. For the same target, the impact of Spoofing2 deception and Multipath1 multipath interference on these features is shown in the figure below. Figure 4 and Figure 5 shown. Figure 4It shows the changing trend of the feature Delta-avg in the above two cases. Figure 5 The change pattern of the feature iE-avg in two situations is revealed. Specifically, before deception and multipath interference invade, the detection amount remains stable; once deception or multipath interference intervenes, the detection amount will immediately undergo a significant mutation. Especially after deception intervenes, the detection amount will stabilize again after a period of dynamic changes; and after multipath interference intervenes, the detection amount tends to be stable and maintains at a specific value.

[0040] In order to determine the input features that the model will eventually select, this application first conducts a detailed correlation analysis on the original 12 features, and evaluates their importance by their contribution to the label. The Pearson coefficient is used to conduct a correlation analysis on the original 12 features listed in Table 1, and the mutual information method is used to further analyze the actual contribution of the features to the result label. The detailed analysis results are as follows: Figure 6 As shown. Figure 6 The correlation analysis on the left shows that the moving average detection of Delta and Ratio shows a negative correlation, while their difference shows a positive correlation, and the correlation between the two is particularly prominent. Figure 6 The contribution bar graph on the right side is used for comprehensive evaluation, and it is found that although there is a strong negative correlation between Delta and Ratio, the contribution of these two detection quantities to the final result is still quite high. Further inspection of the characteristics of the IQ path output shows that there is a high positive correlation between the I path and Q path information, and the contribution of the I path information is significantly higher than the ELP detection quantity and the Q path detection quantity. This result is highly consistent with the physical principle that the I path is an effective energy channel and the Q path is a noise channel.

[0041] First, feature selection is performed by calculating the mutual information between features and labels and the correlation between features. This process determines the best combinations of features from 2 to 6, and these combinations are listed as shown in Table 3. Subsequently, these different numbers of feature combinations are used to train and test the model. Among them, although the I_P_Avg feature has a lower contribution than Delta_Diff, since Delta_Diff is the first-order difference component of the Delta_Avg feature, it has a lower priority in feature selection than the I_P_Avg feature.

[0042] Table 3

[0043] When using SQM technology for deception jamming detection, it is necessary to understand the statistical characteristics of the SQM index to obtain its probability density function and determine the decision threshold based on the set false alarm probability. Existing studies have shown that under high signal-to-noise ratio conditions, the SQM index approximately follows a normal distribution.

[0044] The simulation experiment of this application uses the Ratio index and Delta index after moving smoothing to detect deception and multipath interference. The false alarm probability is set to 5%, and the deception detection threshold is obtained. The detection accuracy is defined as the ratio of the number of samples exceeding the detection threshold to the total number of samples calculated every 100 milliseconds.

[0045] The first and fourth groups of signals in Table 2 are accurately detected using the traditional SQM deception detection algorithm. The first group of signals is the induced deception Spoofing1, which is implemented with an initial pseudo code phase difference of -0.25 chips and a pulling speed of 0.1 chips / s. The duration of the Spoofing1 mixed signal is 100 seconds, of which the first 30 seconds are pure navigation signals, and the mixed signal after the 30th second is composed of deception signals and navigation signals. The second group of signals is the multipath interference Multipath1 with a pseudo code delay difference of -0.5 chips. The Multipath1 mixed signal also lasts for 100 seconds, of which the first 30 seconds are pure navigation signals, and after the 30th second, multipath signals and navigation signals are mixed.

[0046] The changes in Ratio and Delta detection in the Spoofing1 deception scenario are as follows Figure 7 and Figure 8 As shown in the figure. It is clear from observing these graphs that in the pure navigation signal stage before the spoofing signal is involved, the detection volume always remains within the detection threshold; however, once the spoofing signal is involved, the detection volume quickly climbs and exceeds the detection threshold. Over time, when the spoofing signal completely controls the loop, the detection volume stabilizes again.

[0047] Test results such as Fig. 9As shown. At about 30 seconds, the deception detection accuracy rate quickly jumped from 0% to 100%, indicating that the algorithm successfully identified the deception signal at this stage, which is completely consistent with the setting of the actual deception scene, proving the excellent performance of the algorithm. However, at about 50 seconds, the deception detection accuracy rate dropped rapidly from 100% to 0%, indicating that the algorithm now believes that there is no deception in the signal, but the actual situation is that the deception signal continues to exist, resulting in errors in the algorithm detection. The reason for this phenomenon is that in the scene configuration, the intervention time of the deception signal is the 30th second. From the 30th second to the 50th second, the deception signal and the navigation signal compete fiercely for the control of the code loop, resulting in the distortion of the correlation peak. However, after the 50th second, the deception signal has completely controlled the loop, and the distortion of the correlation peak disappears. Therefore, the algorithm detection accuracy rate at 30 seconds quickly rose from 0% to 100%, but after the deception signal completely controlled the loop, the detection accuracy rate dropped to 0%. The traditional SQM deception detection algorithm is used to detect the Multipath1 multipath interference scene in Table 3 in the same way. The detection quantity change curve is shown in Fig.10 and Fig.11 As shown in the figure. In the pure navigation signal stage where multipath interference signals have not yet intervened, the detection amount always remains within the detection threshold; when multipath interference enters, the detection amount rises rapidly and exceeds the detection threshold, and persists. This will cause a large number of false alarms in the traditional SQM deception detection algorithm in multipath scenarios.

[0048] On the same dataset, the detection performance of the CD-SVM deception detection algorithm is compared with that of the traditional SVM deception detection algorithm and the traditional SQM deception detection algorithm. The traditional SVM algorithm uses artificial random feature selection [20, 21], while the traditional SQM algorithm uses the moving average detection volume deception detection algorithm proposed by Phelts et al.

[24] .

[0049] The experimental data set selected the progressive deception deviation scenarios (Spoofing1, Spoofing2) and multipath scenarios (Multipath1, Multipath2) in Table 2 as training sets, containing a total of 13 signals. The duration of each signal is 100 seconds, with 100ms as a data point. During the experiment, the signal is processed by the software receiver, and the data is extracted from the relevant domain features output by the tracking loop. The time unit of these features is milliseconds. Therefore, each millisecond of signal will correspond to multiple feature values. Subsequently, this application performed data preprocessing and feature engineering on these feature values, and finally generated a training data set. The signal label of the interference-free signal time period in the data set is set to 0, the signal label of the deception interference time period is set to 1, and the signal label of the multipath interference time period is set to 2. 80% of the data set is randomly selected for training, and the remaining 20% ​​of the data set is used for testing. Comparing the detection performance of the CD-SVM algorithm and the traditional SVM algorithm, the classification performance of each algorithm is intuitively displayed by using the ROC (Receiver Operating Characteristic Curve) curve and AUC (Area Under the Curve) value. The ROC curve is a commonly used performance evaluation tool that can reflect the relationship between the true positive rate (TPR) and the false positive rate (FPR) of the model under different thresholds. The closer the ROC curve of the model is to the upper left corner, the lower the FPR is while maintaining a high TPR, that is, the better the model performance is. AUC is an indicator to measure the performance of the classification model. The closer the value is to 1, the stronger the classification ability of the model is. The ROC curve of the CD-SVM (Correlation Domain Support Vector Machine) algorithm proposed in this application at different numbers of features is shown in Figure 12. The three sub-figures in Figure 12 are the ROC result diagrams of the SVM algorithm for pure navigation signals (Nav-only), spoofing signals and navigation signals (Nav+spoof), and multipath interference and navigation signals (Nav+Multipath) at different numbers of features. Through the analysis of the ROC curve, it is found that the ROC curve of the SVM algorithm gradually moves to the upper left corner with the increase of the number of features, especially in the classification task of multipath interference, the curve is almost optimal. This shows that SVM can more accurately distinguish positive and negative samples under high-dimensional feature combinations, especially in the identification of multipath interference.

[0050] Therefore, in practical applications, it is recommended to give priority to the combination with a feature number of 6 to maximize the classification performance of SVM, and to further optimize the features of the classification task of deception interference to improve the recognition accuracy.

[0051] Combined with the AUC results corresponding to the ROC curve in Table 5, it can be seen that the AUC values ​​of the SVM algorithm when the number of features ranges from 2 to 6 show that as the number of features increases, its AUC values ​​in various classification tasks show an overall upward trend. In particular, the AUC value of multipath interference (Nav+Multipath) increased from 0.9639 to 0.9971, indicating that SVM exhibits extremely strong classification capabilities under high-dimensional feature combinations. This phenomenon is also significant in Nav-only and Nav+Spoof, which increased from 0.9479 to 0.9939 and from 0.7291 to 0.9789, respectively. By randomly selecting different numbers of feature combinations from the existing 12 features, the features selected for the experiment are shown in Table 4 below. Observation Fig.13 The experimental results show that compared with Fig.12 In the ROC curve results of CD-SVM, the ROC curve of the CD-SVM algorithm is closer to the upper left corner, and the performance is better. According to the experimental results, randomly selecting feature combinations will cause the ROC curve performance to not increase with the increase in the number of features, increasing the complexity of manual traversal testing.

[0052] Table 4

[0053] From the data in Table 5, it can be concluded that CD-SVM generally outperforms traditional SVM under different numbers of features. Specifically, as the number of features increases, the accuracy of CD-SVM increases from 0.8813 to 0.9561, showing its strong generalization ability. Similarly, CD-SVM also shows significant improvements in precision, recall, and F1 score, especially when the number of features is 6, all indicators reach the highest value, which are 0.9561, 0.9561, and 0.9561, respectively, indicating that its performance in classification tasks is very stable and efficient.

[0054] Further observation of the AUC values ​​shows that CD-SVM also outperforms traditional SVM at different numbers of features. As the number of features increases, the AUC value of CD-SVM significantly increases from 0.9479 at 2 features to 0.9971 at 6 features, showing its high adaptability to feature combinations and strong generalization ability. In contrast, the AUC value of traditional SVM fluctuates greatly at different numbers of features, with the highest value being 0.9733 (with 4 features), but the lowest value being only 0.5955 (with 2 features), indicating that it is not as stable and efficient as CD-SVM in terms of feature selection and model performance.

[0055] It is worth noting that when the number of features of CD-SVM is 4 and 6, all indicators (including Nav-only_AUC and Nav+spoof_AUC) have reached a high level, especially when the number of features is 6, all indicators have performed well, 0.9939, 0.9789 and 0.9971 respectively. This further verifies the superior performance of CD-SVM under complex feature combinations. Although traditional SVM also performs well under certain feature combinations, overall, its stability and accuracy in processing high-dimensional feature data are still inferior to CD-SVM.

[0056] In summary, CD-SVM has obvious advantages in feature selection and model training, and can better utilize different numbers of feature combinations for classification tasks, thereby significantly improving the prediction performance and robustness of the model.

[0057] Table 5

[0058] The traditional signal quality measurement (SQM) method is used to perform deception detection in the dynamic target asynchronous deception dataset Spoofing1 scenario. This application uses the traditional Ratio detection quantity and sets the false alarm probability to 1%. The experimental results are shown in Fig.14 Observing these results, we can find that when dealing with the binary detection problem of only deception and non-deception, the AUC value of the traditional detection algorithm is 0.8750, while according to the data in Table 5, the AUC value of CD-SVM is 0.9789. This shows that even in the single deception scene detection task, the performance of the traditional SQM algorithm is still significantly lower than that of the CD-SVM algorithm.

[0059] This result further emphasizes the superiority of the CD-SVM algorithm in handling complex deception detection tasks, especially when considering the key performance indicator of AUC value, CD-SVM can more accurately distinguish between deception and non-deception states, showing its efficient and stable detection capabilities.

[0060] In order to further evaluate the performance of the trained SVM model, the CD-SVM model with 6 feature inputs was loaded, and the migration test was performed using the evaluation data set in the experimental scenario in Table 3. The experimental results are shown in Figure 15. The left vertical axis represents the true label of the manual annotation, the lower horizontal axis represents the model prediction label, and the diagonal line represents the accuracy of the three detection targets, namely, the detection accuracy of the three cases of no deception (Nav-only), deception (Nav+spoof), and multipath interference (Nav+Multipath).

[0061] According to Figure 15, the classification accuracy of the SVM algorithm for Nav+Multipath in the evaluation data set reached 99.0%, and the classification accuracy for Nav-only and Nav+spoof was 93.7% and 90.5%.

[27] The classification results were evaluated, and the evaluation results of Accuracy, Precision, Recall, and F1 were 0.9043, 0.9106, 0.9043, and 0.8939, respectively.

[0062] The CD-SVM model with 6 feature inputs is also used to test the TEXBAT dataset, using the ds2 scenario [5] The CD-SVM model is trained and used to test the ds3 scenario. The specific results are shown in Table 6 below.

[0063] Table 6

[0064] It can be found that in the training scenario of ds2, the 6-feature CD-SVM model is used for training and testing, and the accuracy, precision and other detection indicators all reach more than 99%. The detection indicators on the evaluation test set ds3 are also more than 98%.

[0065] The above results prove that the CD-SVM model proposed in the simulation experiment of this application not only has good performance in detecting induced deception in multipath scenarios, but also has certain migration capabilities.

[0066] It should be understood that although Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0067] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0068] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention. It should be pointed out that, for a person of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A SVM inductive deception detection algorithm based on relevant domain information, characterized in that: The method comprises: Acquire a signal generated by a signal source in an interference scenario and capture and solve the signal generated by the signal source to obtain output data; the output data includes a moving average output of an IQ branch of the ELP correlator and related detection index data; Performing correlation analysis on the output data and feature screening based on the contribution of the features to the labels to obtain input feature combinations with different numbers of features; A part of the data is randomly selected from the input feature combinations with different feature numbers as a training set, and the remaining data is used as a test set. The training set is used to solve the SVM model parameters to construct a classifier for detecting GNSS spoofing and multipath interference; the test set is used to classify and predict the classifier, evaluate the detection performance of the SVM model, and perform spoofing detection based on the trained SVM model.

2. The method according to claim 1, characterized in that The relevant detection index data include the moving average and moving difference of Ratio, Delta and ELP.

3. The method according to claim 1, characterized in that Performing correlation analysis on the output data, including: The Pearson coefficient was used to perform correlation analysis on the output data, and the formula is as follows: In the formula, Represents the Pearson correlation coefficient, which is used to measure the variables and The linear correlation between and Representation variables and No. Observations, variable The average value of , It represents the time from the first observation to the The cumulative sum of observations.

4. The method according to claim 1, characterized in that The calculation process of the contribution of the feature to the label includes: The contribution between the feature value and the category label in the output data is calculated as in, Represents the characteristic variable, that is, the characteristic value in the output data, Indicates the classification result of the category label, i.e., whether it is deceived and whether it contains multipath. represents the joint probability distribution, express The marginal probability distribution of .

5. The method according to claim 1, characterized in that The sample sets of the training set and the test set are in, Indicates the mixed signal after being processed by the receiver. Time-dependent domain output dimensional feature vector, where , A feature selected from a combination of input features with different feature numbers, i.e., the input obtained after processing the received mixed signal, Represents the output result, that is, the category of the signal at the current moment, m represents the number of training set data, n Indicates the number of test set data.

6. The method according to claim 1, characterized in that The training set is used to solve the SVM model parameters and build a classifier for detecting GNSS spoofing and multipath interference, including: The features in the training set are mapped from the original feature space to a higher-dimensional space using a kernel function, and the optimal separation hyperplane corresponding to the SVM model is found. A classifier for detecting GNSS spoofing and multipath interference is constructed based on the optimal separation hyperplane, and the classifier divides samples of different categories into maximized intervals in the high-dimensional feature space.

7. The method according to claim 6, characterized in that The kernel function is in, Represents the original feature space The mapping function to the high-dimensional feature space, Represents the inner product operation.

8. The method according to claim 6, characterized in that The classifier for detecting GNSS spoofing and multipath interference is constructed according to the optimal separation hyperplane: in, is the normal vector of the hyperplane, representing the mean vector of the hyperplane, is the offset, which represents the distance between the hyperplane and the origin, Represents input feature combinations with different numbers of features in a high-dimensional feature space, Represents the output result, that is, the category of the signal at the current moment, m Indicates the number of training set data.

Citation Information

Patent Citations

  • GNSS deception jamming detection method and device, electronic equipment and storage medium

    CN115494526A

  • GNSS deception detection method based on machine learning

    CN115932900A

  • GNSS (Global Navigation Satellite System) induced deception detection method based on RMS sliding envelope and SVM (Support Vector Machine)

    CN116719061A

Cited By

  • Intelligent tablet anti-intrusion system for field communication

    CN121284570A

  • An intelligent tablet anti-intrusion system for field communication

    CN121284570B