Unmanned vehicle safety control method and system for resisting hidden false data injection attack

By modeling unmanned vehicles as information physics systems, building differential closed-loop system models and designing robust model prediction controllers, the threat of hidden and false data injection attacks to unmanned vehicle systems is solved, and the system's stability and security under attack is achieved.

CN119937635AActive Publication Date: 2025-05-06HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Patent Information

Application Number
CN202510112761.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

The prior art has limitations in dealing with hidden and false data injection attacks, and cannot effectively prevent attackers from affecting the decision-making process of unmanned vehicles by tampering with sensor data or controlling system instructions.

Method used

Model the unmanned vehicles as an information physics system, build a normal and attacked closed-loop system model, identify the state difference through the differential closed-loop system model, design a steady-state Kalman filtered gain and robust model prediction controller, and generate a differential input signal to resist attacks.

Benefits of technology

The unmanned vehicle system is stable and secure under hidden and false data injection attacks, ensuring that the system can still maintain stability and security when attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937635A_ABST
    Figure CN119937635A_ABST
Patent Text Reader

Abstract

The invention relates to an unmanned vehicle safety control method and system for resisting hidden false data injection attack. The method comprises the following steps: based on an unmanned vehicle information physical system, constructing a normal system which is not attacked and a system which is attacked by a hidden actuator, and constructing a difference system according to a state difference value of the two systems; solving the steady-state Kalman filtering gain of a normal system; constructing a linear matrix inequality condition for ensuring the stability of a normal system and the state of a differential system to be bounded based on the non-escapable set, and obtaining a controller gain meeting the condition; according to robust model predictive control, an augmentation vector and a prediction equation are constructed, a difference system bounded and stable minimum and maximum problem is given and converted into a linear matrix inequality to obtain an input signal of the difference system, and finally an input signal of an attacked system is obtained and applied to the attacked system, so that the difference system is bounded and stable, and the attacked system is more stable. And the system is stable and safe when being attacked. According to the invention, the state of the attacked system is stable and the system is safe.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an unmanned vehicle safety control method and system for resisting hidden false data injection attacks, and belongs to the field of safety control of information-physical systems. Background Art

[0002] Cyber-Physical Systems (CPS) refer to architectures that tightly integrate computing resources with the physical world. They play an indispensable role in many key areas such as energy, transportation, and manufacturing. CPS integrates sensors, actuators, communications, and control mechanisms to enable real-time monitoring, control, and response, thereby enhancing the efficiency, stability, and intelligence of the system. With the advancement and widespread application of IoT technology, CPS is facing increasingly complex and extensive security challenges. In particular, false data injection (FDI) attacks—a method by which attackers attempt to compromise the integrity, availability, and reliability of a CPS by modifying or introducing false data into the CPS—pose a major risk to important industries such as intelligent transportation and smart logistics, which are composed of intelligent unmanned systems such as driverless cars.

[0003] Although the traditional model predictive control (MPC) method can guarantee the stability of the system to a certain extent, it has limitations in dealing with covert FDI attacks. MPC usually assumes that all inputs are credible, and FDI attacks take advantage of this to influence the decision-making process by tampering with sensor data or control system instructions. In addition, most existing security measures focus on detecting abnormal behavior rather than active defense, and cannot provide sufficient protection to prevent the occurrence and development of attacks. Summary of the invention

[0004] The present invention provides an unmanned vehicle safety control method and system for resisting hidden false data injection attacks, aiming to solve at least one of the technical problems existing in the prior art.

[0005] The technical solution of the present invention relates to a safety control method for an unmanned vehicle, and the method according to the present invention comprises the following steps:

[0006] S100, modeling the unmanned vehicle as a cyber-physical system; based on the cyber-physical system, constructing a normal closed-loop system model that is not attacked, and constructing an attacked closed-loop system model that is attacked by a hidden actuator, so as to construct a differential closed-loop system model according to the state difference between the attacked closed-loop system and the normal closed-loop system; wherein the actuator attack refers to an attack in which an attacker injects false data into the communication channel between the remote controller and the actuator;

[0007] S200, according to a normal closed-loop system model that is not attacked, the steady-state Kalman filter gain of the system is obtained; based on the inescapable set, a linear matrix inequality condition is constructed to ensure that the normal system state is stable and the differential system state is bounded, and the controller gain that satisfies the condition is obtained;

[0008] S300, constructing an augmented vector and a prediction equation according to the framework of a robust model predictive control model, and providing a minimax problem to ensure that the state of the differential system is bounded and stable, converting the minimax problem into a linear matrix inequality and solving it to obtain a differential input signal of the differential system, and finally obtaining an input signal of the attacked system;

[0009] S400, applying the obtained input signal of the attacked system to the attacked system, so that the differential system is bounded and stable under the action of the inescapable set, and the system remains stable and safe when attacked.

[0010] Furthermore, in step S100: the normal cyber-physical system of the unmanned vehicle that is not attacked is constructed , represented by the following discrete-time system:

[0011]

[0012] In the formula, k represents the time, Indicates the system status. represents the control input, represents the measured output, where the initial state x0 has the mean and covariance Σ0; represents the process noise, represents the measurement noise; and are all known covariance matrices; A, B and C are all known real matrices;

[0013] The remote controller of the cyber-physical system includes a The state estimator ε is used to transform the state x k Feedback controller adjusted to the origin and a fault detector for detecting abnormal operation;

[0014] Among them, the state estimator ε and the feedback controller They are respectively expressed as follows:

[0015]

[0016] In the formula, represents the state estimate at time k; K and L represent the constant estimator gain and controller gain, respectively;

[0017] Among them, for χ 2 Fault detector detection value Set when g k >α, triggering an alarm, where α is the preset threshold, Σ k is the covariance of the state estimation error at time k, and the estimated residual And the estimation error is expressed as:

[0018]

[0019] e k+1 =(I-KC)(Ae k +ω k )-Kv k+1 .

[0020] Wherein, I represents the identity matrix and has a dimension of n×n.

[0021] Furthermore, in step S100: the constructed physical system dynamic representation under the actuator attack is It is expressed as follows:

[0022]

[0023] Among them, the state estimator ε′ and the feedback controller under the actuator attack It is expressed as follows:

[0024]

[0025] In the formula, represents the actuator attack sequence injected at time k; x′ k , u′ k , y′ k and Respectively represent the attacks k the affected system states, control commands implemented at the actuators, sensor measurements, and state estimates;

[0026] Among them, the estimated error e′ under the actuator attack k+1 and the residual z′ k+1 It is expressed as follows:

[0027]

[0028] System states of a normal cyber-physical system that is not attacked and a cyber-physical system under an actuator attack Estimation Error and the estimated residuals The differences between are shown below:

[0029]

[0030] in, and The dynamic equation is expressed as follows:

[0031]

[0032] In the formula, and represents the system state, estimated error and estimated residual of the differential closed-loop system at time k, the initial state

[0033] Further, in step S200: the state estimator is a Kalman filter, and the steady-state Kalman filter gain K is expressed as follows:

[0034]

[0035] Where P represents the state estimation error covariance matrix;

[0036] Among them, the hidden attack sequence a k It is expressed as follows:

[0037]

[0038] In the formula, the matrix CB is assumed to have full column rank, reversible, and is the left inverse of the matrix CB;

[0039] and then:

[0040]

[0041] Further, in step S200, the linear matrix inequality is expressed as follows:

[0042] P2≤δI,

[0043]

[0044] In the formula, and ; Wherein, the positive scalars α, β, γ, δ, λ are set, the positive definite matrices P1>0, P2>0 are set, and the matrix U of the set dimension is set, so that the linear matrix inequality holds;

[0045] Then set the controller gain So that under the hidden actuator attack, the closed-loop system state difference is limited to And get and Their respective inescapable sets are represented as and

[0046] Further, in step S300,

[0047] According to the obtained An inescapable set We can get:

[0048]

[0049] Then we can get the augmented vector and the prediction equation Φ are expressed as follows:

[0050]

[0051] In the formula,

[0052]

[0053] L p =[L0], L is the controller gain obtained in step S200,

[0054]

[0055] h k+j|k A new decision variable is introduced to adjust the control signal to achieve the desired effect.

[0056] Further, in step S300,

[0057] Assume positive scalar t,τ0,τ1,…,τ N+2 This makes the optimization problem satisfying the following constraints:

[0058]

[0059] Where, T N :=diag{τ1I,…,τ N I}, T Θ : = diag{τ N+1 I,τ N+2 I},

[0060] Further, in step S400,

[0061] The H obtained by solving step S300 and the feedback controller actually used Calculate the input signal u′ of the closed-loop system under attack at time k k .

[0062] The technical solution of the present invention also relates to a computer-readable storage medium on which program instructions are stored, and the above-mentioned method is implemented when the program instructions are executed by a processor.

[0063] The technical solution of the present invention also relates to an unmanned vehicle safety control system, the system comprising a computer device, and the computer device contains the above-mentioned computer-readable storage medium.

[0064] The beneficial effects of the present invention are as follows:

[0065] The present invention focuses on the safety control method and system of unmanned vehicles that resist hidden false data injection attacks. It is a safety control method and corresponding system for intelligent unmanned vehicles (UGVs) when they are attacked by false data injection (FDI) of hidden actuators. The present invention models the unmanned vehicle as a cyber-physical system, designs a safety controller based on the idea of ​​a non-escapable set, and the designed state feedback controller gain can not only make the state of the normal non-attacked system converge and stabilize, but also the control signal of the robust model predictive controller combined with feedback prediction can make the state of the attacked system stable and the system safe. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 The figure is a basic flow chart of the unmanned vehicle safety control method according to an embodiment of the present invention.

[0067] Figure 2 is a system block diagram of an unmanned ground vehicle (UGV) according to an embodiment of the present invention;

[0068] Figure 3 It is a schematic diagram of the open-loop state response result of the UGV system according to an embodiment of the present invention;

[0069] Figure 4 It is a schematic diagram of the closed-loop state response result of the UGV system that is not attacked according to an embodiment of the present invention;

[0070] Figure 5 It is a schematic diagram of the estimated residual difference results before and after the UGV system of an embodiment of the present invention is attacked;

[0071] Figure 6 It is a schematic diagram of the modulus change of the state difference before and after the UGV system of the embodiment of the present invention is attacked and its bounded limit result;

[0072] Figure 7 It is a schematic diagram of the square change result of the 2-norm of the state difference before and after the UGV system of an embodiment of the present invention is attacked;

[0073] Figure 8 It is a schematic diagram of the closed-loop state response results of the UGV system of an embodiment of the present invention using the model predictive control without considering the estimated residual difference of the differential system and comparing it with the method of the present invention. DETAILED DESCRIPTION

[0074] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in combination with the embodiments and drawings to fully understand the purpose, scheme and effect of the present invention.

[0075] It should be noted that, unless otherwise specified, when a feature is referred to as being "fixed" or "connected" to another feature, it may be directly fixed or connected to another feature, or it may be indirectly fixed or connected to another feature. The singular forms "a", "said" and "the" used herein are also intended to include the plural forms, unless the context clearly indicates otherwise. In addition, unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art. The terms used in this specification are intended only to describe specific embodiments and are not intended to limit the invention. The term "and / or" used herein includes any combination of one or more of the related listed items.

[0076] It should be understood that, although the term first, second, third etc. may be adopted to describe various elements in the present disclosure, these elements should not be limited to these terms. These terms are only used to distinguish the same type of elements from each other. For example, without departing from the scope of the present disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element. The use of any and all examples or exemplary language ("for example", "such as" etc.) provided herein is only intended to better illustrate embodiments of the present invention, and unless otherwise required, the scope of the present invention will not be limited.

[0077] Reference Figures 1 to 8 In some embodiments, a safety control method for an unmanned vehicle according to the present invention is applied to an unmanned vehicle system attacked by covert false data injection, and the method comprises at least the following steps:

[0078] S100, modeling the unmanned vehicle as a cyber-physical system; based on the cyber-physical system, constructing a normal closed-loop system model that is not attacked, and constructing an attacked closed-loop system model that is attacked by a hidden actuator, so as to construct a differential closed-loop system model according to the state difference between the attacked closed-loop system and the normal closed-loop system; wherein the actuator attack refers to an attack in which an attacker injects false data into the communication channel between the remote controller and the actuator;

[0079] S200, according to a normal closed-loop system model that is not attacked, the steady-state Kalman filter gain of the system is obtained; based on the inescapable set, a linear matrix inequality condition is constructed to ensure that the normal system state is stable and the differential system state is bounded, and the controller gain that satisfies the condition is obtained;

[0080] S300, constructing an augmented vector and a prediction equation according to the framework of a robust model predictive control model, and providing a minimax problem to ensure that the state of the differential system is bounded and stable, converting the minimax problem into a linear matrix inequality and solving it to obtain a differential input signal of the differential system, and finally obtaining an input signal of the attacked system;

[0081] S400, applying the obtained input signal of the attacked system to the attacked system, so that the differential system is bounded and stable under the action of the inescapable set, and the system remains stable and safe when attacked.

[0082] The unmanned vehicle safety control method and system of the present invention, which can resist covert false data injection attacks, models the unmanned vehicle as an information-physical system, designs a safety controller based on the idea of ​​a non-escapable set, and the designed state feedback controller gain can not only make the state of a normal system not under attack converge and stabilize, but also the control signal of the robust model predictive controller combined with feedback prediction can make the state of the attacked system stable and the system safe.

[0083] In some embodiments, the unmanned vehicle is constructed as a cyber-physical system, whose physical system is described by the following discrete-time system:

[0084]

[0085] In the formula, k represents the time, is the system status, is the control input, is the measured output, where the initial state x0 has the mean and covariance Σ0. Process noise and measurement noise are white noise, independent of each other, and zero mean, with known covariance matrices and A, B, and C are known real matrices with appropriate dimensions, and their specific parameters and dimension values ​​come from the actual system parameters of the unmanned vehicle.

[0086] Furthermore, a computer is used as the actual carrier of the remote control center to build a network layer to realize remote control of the physical system. In the remote control center (i.e., remote controller), the state estimation is calculated by the state estimator ε, and the feedback controller The state x k Adjust to the origin (i.e. x k =0):

[0087]

[0088] in, is the state estimate at time k; K and L are the constant estimator gain and controller gain, respectively.

[0089] Furthermore, the remote control center deploys a 2 Fault detector to detect abnormal operation. At each time instant k, 2 The fault detector first calculates Where Σ k is the covariance of the state estimation error at time k, and then g k is compared with the preset threshold α. k >α, an alarm is triggered. It should be noted that when the system is operating normally (i.e., there is no network attack), g k Satisfy χ 2 distribution, so we can get g k The larger one has a lower probability.

[0090] The estimation error is expressed as Then we have:

[0091] e k+1 =(I-KC)(Ae k +ω k )-Kv k+1

[0092] Wherein, I represents the identity matrix and has a dimension of n×n.

[0093] It should be noted that the symbol := indicates the definition.

[0094] The following settings are made for the designed cyber-physical system:

[0095] Setting 1: The matrix pair (A, C) is observable and the matrix pair (A, B) is controllable.

[0096] Setting 2: Rank(CB) = m, that is, the matrix CB has full column rank.

[0097] In some embodiments, the attacker injects false data into the communication channel between the remote controller and the actuator. Such attacks are referred to as "actuator attacks."

[0098] The dynamics of the physical system under actuator attack is expressed as It is expressed as follows:

[0099]

[0100] When attacked, the state estimator ε′ and the feedback controller as follows:

[0101]

[0102] in, represents the actuator attack injected at time k; x′ k , u′ k , y′ k and Respectively represent the attacks k The affected system states, control commands implemented at the actuators, sensor measurements, and state estimates. It should be noted that the attacked state estimator ε′ and the feedback controller With the ideal state estimator ε and feedback controller have the same gains K and L, but they use different signals. Without loss of generality, assume that the injected false data attack starts at time k = 1, and the initial system state and state estimate are x′0 = x0 and

[0103] The estimated error and residual under the actuator false data injection attack are shown below:

[0104]

[0105] Considering the impact of the actuator attack on the system dynamics, the difference between the system state, estimation error and estimation residual of the physical system in the non-attack case and the system under attack is defined, that is, the system state of the differential closed-loop system Estimation Error and the estimated residuals It is expressed as follows:

[0106]

[0107] and The dynamics can be derived as follows:

[0108]

[0109] Among them, the initial state

[0110] In some embodiments, in the covert actuator attack model, the attacker will initiate a "special" data injection sequence to reduce the system dynamic performance or even make it unstable, while not being affected by the x 2 The detector detects that when the estimated residual of the differential closed-loop system When it is very small, 2 The detector cannot distinguish z′ with high probability k and z k According to the above characteristics, in order to make the attack sequence concealed, the injection of false data should avoid causing the difference in estimated residuals. That is, the attacker can predetermine that his "special" sequence must satisfy should always hold, where ζ represents χ 2 The tolerance level of the detector, so the present invention sets The FDI attack sequence that always holds true k}It is concealed.

[0111] To this end, a similar security setting under covert executor attack is proposed:

[0112] Security Assumption 1: There exists at least one attack sequence {a k}, making the system state Differences meet:

[0113]

[0114] Then it is determined that under the hidden actuator attack, the state estimator ε′ and the feedback controller System is unsafe; otherwise, it is determined that the state estimator ε′ and the feedback controller System It is safe from covert actuator attacks.

[0115] It should be noted that when using χ 2 When the detector is used for attack detection, the Kalman filter is used as the state estimator, which can make χ 2 The test statistic has the best detection ability. It is understandable that only when the residual is white noise can it be regarded as an independent sample at different sampling time points, otherwise any correlation between the residuals at different time points will significantly reduce the detection performance.

[0116] In an application embodiment, according to a normal closed-loop system model that is not attacked, the steady-state Kalman filter gain of the system is obtained. Specifically, the Kalman filter is used as a state estimator, and the Kalman filter is applied from the observation values ​​y0,…,y k Obtain state estimates in

[0117]

[0118] In the formula, represents the state estimate before time 0, that is, the initial state estimate; K represents the state estimation before time k+1, that is, the prediction of the state at time k+1 based on the information at time k; k represents the Kalman filter gain at time k; P k represents the state estimation error covariance matrix at time k, that is, the uncertainty of the estimation.

[0119] Furthermore, although K k varies with time, but after a few steps K k will converge, so the present invention assumes that the Kalman filter is already in a steady state, so that the steady-state Kalman filter gain K is expressed as follows:

[0120]

[0121] According to the assumption that the matrix CB has full column rank, is reversible, and is the left inverse of the matrix CB, so we can get the hidden attack sequence a k It is expressed as follows:

[0122]

[0123] Then we can get:

[0124]

[0125] According to the above formula, we set positive scalars α, β, γ, δ, λ, positive definite matrices P1>0, P2>0, and matrix U of appropriate dimensions so that the following linear matrix inequalities are established:

[0126] P2≤δI,

[0127]

[0128] In the formula, and

[0129] Set the controller gain to Then under the hidden actuator attack, the closed-loop system state difference is limited to At the same time, you can get and Each of them has an inescapable set, namely and Therefore, based on the inescapable set, a linear matrix inequality condition is constructed to ensure the stability of the normal system state and the boundedness of the differential system state, and the controller gain that satisfies the conditions is obtained.

[0130] In some embodiments, the present invention constructs augmented vectors and prediction equations based on the framework of a robust model predictive control model, and simultaneously provides a minimax problem that ensures that the state of the differential system is bounded and stable, converts the minimax problem into a linear matrix inequality and solves it to obtain the differential input signal of the differential system, and finally obtains the input signal of the attacked system.

[0131] Specifically, according to and The dynamic equations of the closed-loop differential system are separated into control signals and We can get:

[0132]

[0133] Defining Estimates Then we have:

[0134]

[0135] in:

[0136]

[0137] Given the number of prediction steps N, the optimization problem to be solved is:

[0138]

[0139] Among them, the matrices Ξ>0 and Υ>0 are given as performance weights. And define:

[0140]

[0141] By introducing some conservatism to replace the original minimax problem, the problem can be effectively solved.

[0142] Specifically, the objective function can be expressed as:

[0143]

[0144] in,

[0145]

[0146] Next, the robust model predictive control (RMPC) considering the estimation error is applied and the design of RMPC is introduced using the feedback prediction method. In order to adjust the control signal to achieve the desired effect, a new decision variable h is introduced. k+j|k , feedback controller The design is as follows:

[0147]

[0148] in

[0149] L p =[L0]

[0150] L is the controller gain obtained in step S200. That is, the feedback controller actually used under the actuator FDI attack It is expressed as follows:

[0151]

[0152] Then, the augmented vector of the control signal is It is expressed as follows:

[0153]

[0154] In the formula,

[0155]

[0156] The prediction equation Φ can be expressed as:

[0157]

[0158] in

[0159]

[0160] According to the above formula, we can solve:

[0161]

[0162] For convenience, define:

[0163]

[0164] because And only estimated values ​​of state variables can be obtained and so pass Calculate, in addition, By definition There is an estimated value φ k =φ k|k +η k ,in is an estimate of time k. Therefore:

[0165]

[0166] In step S200, it is found An inescapable set definition:

[0167]

[0168] Substituting it into the prediction equation, we get:

[0169]

[0170] in

[0171] Based on the above derivation, solve H, positive scalar t, τ0, τ1, …, τ N+2 This makes the optimization problem satisfying the following constraints:

[0172]

[0173] Where, T N :=diag{τ1I,…,τ N I}, T Θ : = diag{τ N+1 I,τ n+2 I},

[0174] Then, the controlled system In the steady-state Kalman filter ε′ and the feedback controller Under the action of , it is stable and secure under the covert actuator FDI attack, and the state of the differential system satisfy

[0175] In some embodiments, the input signal of the attacked system is applied to the attacked system, so that the differential system is bounded and stable under the action of the inescapable set, and the system remains stable and safe when attacked. Specifically, the first m rows of H obtained in step S300 are taken to form a column vector, that is, h k|k , and substitute it into the feedback controller form u′ actually used k|k =Lx′ k|k +h k|k That is to say Calculate the input signal u′ of the attacked system at step k k .

[0176] Here, a specific embodiment is used to illustrate and verify the effectiveness of the intelligent unmanned vehicle information physical security control method and system for resisting hidden false data injection attacks of the embodiment of the present invention. Specifically, the present invention is further described by an example of an unmanned ground vehicle (UGV) system. The system block diagram of the UGV is shown in FIG. Figure 2 As shown, the network layer is implemented through a wireless network connection.

[0177] Specifically, the physical system modeling in this application example is as follows:

[0178] Assume that the UGV moves in a straight line and that the straight line motion stops completely before rotating. Under this assumption, the dynamic equations of the UGV's straight line motion and angular motion can be expressed as:

[0179]

[0180] Where: x is the position of the unmanned ground vehicle (m);

[0181] v——Linear speed of the UGV (m / s);

[0182] θ——angle of the UGV (rad);

[0183] ω——angular velocity of the unmanned ground vehicle (rad / s)

[0184] M——the mass of the unmanned ground vehicle (kg);

[0185] J——Moment of inertia of the unmanned ground vehicle (kg·m2);

[0186] B——Coefficient of translational friction;

[0187] B r ——coefficient of rotational friction;

[0188] F——input force (N);

[0189] T——Input torque (N·m).

[0190] Assuming that the encoder performs the necessary processing to directly provide a velocity measurement, the resulting output equation can be expressed as:

[0191]

[0192] Among them, ψ i is the measurement noise of the ith sensor, which is assumed to be a Gaussian white noise with zero mean and finite covariance. For the convenience of representation and consistency with the state vector of the output equation, let the new state variable be Then the state equation can be expressed as:

[0193]

[0194] Among them, the input signal .

[0195] In this application example, the sampling time is set to 0.1s to discretize the continuous system. At the same time, the process noise and measurement noise of the model are considered to obtain the discrete state equation, which is then organized into the form of the cyber-physical system in step S100, that is, the UGV system that needs to be safely controlled is obtained. The initial state value of the UGV system is taken as , from which we can get Figure 3 The open loop state response.

[0196] First, according to step S200, the steady-state Kalman filter gain of the system is calculated. Assume that the control signal of the UGV is attacked during the transmission to the actuator. In this experiment, the attack signal is in the form of a sinusoidal signal. Next, according to step S200, a set of feasible solutions for solving the controller gain is found to obtain the values ​​of parameters α, β, γ, λ, and δ.

[0197] In the controller Under the action of Figure 4 It can be found that the controller gain L can make the unattacked UGV system converge to zero faster. The control purpose of the present invention is to use the RMPC method to make the state of the attacked system track the state of the normal system on the basis of using the controller gain L for the normal system, that is, to obtain the state of the differential system between the two. It can also be stabilized at zero. In the following experimental process, the method of using MPC on a normal system and an attacked system will be compared with the method proposed in the present invention.

[0198] because Only with and a k Since the initial values ​​of the state estimates of the normal non-attacked system and the attacked system are the same and both are zero, the state errors of the two systems at time zero are also the same, that is, e k =e′ k ,So Therefore, during the calculation process, Only with a k Related, then Only with a k Under the condition that the FDI attack signal of the actuator is the same, the difference of the estimated residuals between the attacked system and the non-attacked system generated by the MPC method and the control method of the present invention is The same changes as Figure 5 As shown. Always satisfied That is, the introduced FDI attack sequence is covert.

[0199] On the basis of feedback control, by solving the optimization problem in step S300, the optimal robust model predictive controller signal can be obtained. Under the action of the RMPC controller signal, the differential state of the UGV system before and after the attack satisfies The limits of and the square of its 2-norm are Figure 6 and Figure 7 As shown. It can be seen that Changes over time always remain and Therefore, by using the proposed method, the security and stability of the closed-loop system can be ensured under covert FDI attacks.

[0200] The comparison diagram of the closed-loop state response of the UGV system generated by the method using MPC and the method used in the present invention is shown in FIG. Figure 8 It can be seen that both the MPC method and the method proposed in the present invention can make the UGV system converge to the origin after a certain period of time, but in terms of convergence speed, the linear feedback plus RMPC method proposed in the present invention can make the system converge to the origin faster and ensure the safety of the system, which highlights the effectiveness of the method proposed in the present invention to a certain extent.

[0201] It should be noted that, considering that the system is often very complex in the actual production process, it is almost impossible to accurately identify its system parameters, so it is very necessary to obtain a safety controller based on data calculation based on iterative optimization. The present invention proposes a safety control method and system for unmanned vehicles that resist hidden false data injection attacks, allowing the attacked system state to track the state of the normal system that is not attacked, and ensuring the boundedness of the differential system state by applying the relevant theorem of inescapable sets, and effectively processing the state error under the framework of robust model predictive control to ensure the accuracy of the prediction equation, while converting the uncertain matrix constraints into processable linear matrix inequalities, and finally obtaining the control signal of the system, which can ensure that the system can still have good performance when attacked, making the system not only safe but also stable.

[0202] It should be appreciated that the method steps in the embodiments of the present invention can be implemented or implemented by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer readable memory. The method can use standard programming techniques. Each program can be implemented in a high-level process or object-oriented programming language to communicate with a computer system. However, if necessary, the program can be implemented in an assembly or machine language. In any case, the language can be a compiled or interpreted language. In addition, the program can be run on a programmed ASIC for this purpose.

[0203] Furthermore, the operations of the processes described herein may be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. The processes described herein (or variations and / or combinations thereof) may be performed under the control of one or more computer systems configured with executable instructions, and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that is executed collectively on one or more processors, by hardware, or a combination thereof. The computer program includes a plurality of instructions that may be executed by one or more processors.

[0204] Further, the method can be implemented in any type of computing platform that is operably connected to a suitable computer, including but not limited to a personal computer, a minicomputer, a mainframe, a workstation, a network or distributed computing environment, a separate or integrated computer platform, or in communication with a charged particle tool or other imaging device, etc. Various aspects of the present invention can be implemented in machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, an optical read and / or write storage medium, an RSM, a ROM, etc., so that it can be read by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the process described herein. In addition, the machine-readable code, or portions thereof, can be transmitted via a wired or wireless network. When such media includes instructions or programs that implement the steps described above in conjunction with a microprocessor or other data processor, the invention described herein includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention can also include the computer itself.

[0205] The computer program can be applied to input data to perform the functions described herein, thereby converting the input data to generate output data stored in a non-volatile memory. The output information can also be applied to one or more output devices such as a display. In a preferred embodiment of the present invention, the converted data represents physical and tangible objects, including specific visual depictions of physical and tangible objects produced on the display.

[0206] The above is only a preferred embodiment of the present invention. The present invention is not limited to the above implementation. As long as the technical effect of the present invention is achieved by the same means, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the scope of protection of the present invention. Within the scope of protection of the present invention, its technical scheme and / or implementation method may have various modifications and changes.

Claims

1. A safety control method for an unmanned vehicle, characterized in that: The method comprises the following steps: S100, modeling the unmanned vehicle as a cyber-physical system; based on the cyber-physical system, constructing a normal closed-loop system model that is not attacked, and constructing an attacked closed-loop system model that is attacked by a hidden actuator, so as to construct a differential closed-loop system model according to the state difference between the attacked closed-loop system and the normal closed-loop system; wherein the actuator attack refers to an attack in which an attacker injects false data into the communication channel between the remote controller and the actuator; S200, according to a normal closed-loop system model that is not attacked, the steady-state Kalman filter gain of the system is obtained; based on the inescapable set, a linear matrix inequality condition is constructed to ensure that the normal system state is stable and the differential system state is bounded, and the controller gain that satisfies the condition is obtained; S300, constructing an augmented vector and a prediction equation according to the framework of a robust model predictive control model, and providing a minimax problem to ensure that the state of the differential system is bounded and stable, converting the minimax problem into a linear matrix inequality and solving it to obtain a differential input signal of the differential system, and finally obtaining an input signal of the attacked system; S400, applying the obtained input signal of the attacked system to the attacked system, so that the differential system is bounded and stable under the action of the inescapable set, and the system remains stable and safe when attacked.

2. The method according to claim 1, characterized in that In step S100: Building a cyber-physical system for unmanned vehicles that is safe from attack is represented by the following discrete-time system: In the formula, k represents the time, Indicates the system status. represents the control input, represents the measured output, where the initial state x0 has the mean and covariance Σ0; represents the process noise, represents the measurement noise; and are all known covariance matrices; A, B and C are all known real matrices; The remote controller of the cyber-physical system includes a The state estimator ε is used to transform the state x k Feedback controller adjusted to the origin and a fault detector for detecting abnormal operation; Among them, the state estimator ε and the feedback controller They are respectively expressed as follows: In the formula, represents the state estimate at time k; K and L represent the constant estimator gain and controller gain, respectively; Among them, for χ 2 Fault detector detection value Set when g k >α, triggering an alarm, where α is the preset threshold, Σ k is the covariance of the state estimation error at time k, and the estimated residual And the estimation error is expressed as: have been k+1 =(I-KC)(Yes k +ω k )-Kv k+1 . Wherein, I represents the identity matrix and has a dimension of n×n.

3. The method according to claim 2, characterized in that In step S100: The constructed physical system dynamic representation under actuator attack is It is expressed as follows: Among them, the state estimator ε′ and the feedback controller under the actuator attack It is expressed as follows: In the formula, represents the actuator attack sequence injected at time k; x′ k , u′ k , y′ k and Respectively represent the attacks k the affected system states, control commands implemented at the actuators, sensor measurements, and state estimates; Among them, the estimated error e′ under the actuator attack k+1 and the residual z′ k+1 It is expressed as follows: System states of a normal cyber-physical system that is not attacked and a cyber-physical system under an actuator attack Estimation Error and the estimated residuals The differences between are shown below: in, and The dynamic equation is expressed as follows: In the formula, and represents the system state, estimated error and estimated residual of the differential closed-loop system at time k, the initial state 4. The method according to claim 3, characterized in that In step S200: The state estimator is a Kalman filter, and the steady-state Kalman filter gain K is expressed as follows: Where P represents the state estimation error covariance matrix; Among them, the hidden attack sequence a k It is expressed as follows: In the formula, the matrix CB is assumed to have full column rank, reversible, and is the left inverse of the matrix CB; and then:

5. The method according to claim 4, characterized in that In the step S200, The linear matrix inequality is expressed as follows: P2≤δI, In the formula, and Wherein, the positive scalars α, β, γ, δ, λ are set, the positive definite matrices P1>0, P2>0 are set, and the matrix U of the dimension is set, so that the linear matrix inequality holds; Then set the controller gain So that under the hidden actuator attack, the closed-loop system state difference is limited to And get and Their respective inescapable sets are represented as and 6. The method according to claim 5, characterized in that In the step S300, According to the obtained An inescapable set We can get: Then we can get the augmented vector and the prediction equation Φ are expressed as follows: In the formula, L p =[L 0], L is the controller gain obtained in step S200, h k+j|k A new decision variable is introduced to adjust the control signal to achieve the desired effect.

7. The method according to claim 6, characterized in that In the step S300, Assume positive scalar t,τ0,τ1,…,τ N+2 This makes the optimization problem satisfying the following constraints: where, T N : = diag{τ1I, …, τ N I}, T Θ : = diag{τ N+1 I, τ N+2 I}, 8. The method according to claim 7, characterized in that In the step S400, The H obtained by solving step S300 and the feedback controller actually used Calculate the input signal u′ of the closed-loop system under attack at time k k . 9 . A computer-readable storage medium having program instructions stored thereon, wherein the program instructions, when executed by a processor, implement the method according to any one of claims 1 to 8.

10. An unmanned vehicle safety control system, characterized in that: include: A computer device comprising a computer readable storage medium according to claim 9.

Citation Information

Patent Citations

  • Event-driven course safety control method for unmanned ship under network attacks

    CN113050630A

  • Control method and system for nonlinear system under false data injection attack

    CN117519096A

  • Method and apparatus for assessing risk of vehicle, and system for monitoring attack

    WO2024065283A1

Cited By

  • Robust FDI attack detection method for ship navigation system

    CN121396622A

  • Safe attitude control method and system for quad-rotor unmanned aerial vehicle system under hidden attack

    CN121501010A