Unmanned vehicle safety control method and system resistant to hidden false data injection attack

By modeling autonomous vehicles as cyber-physical systems, constructing a differential closed-loop system model, and designing state feedback and robust model predictive controllers, the problem of covert false data injection attacks is solved, and the stability and security of the autonomous vehicle system under attack are achieved.

CN119937635BActive Publication Date: 2025-12-05HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510112761.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-12-05
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

When faced with covert spoofing attacks, existing technologies, particularly model predictive control methods, cannot provide effective active defense and attack detection in intelligent autonomous vehicle systems. Consequently, existing technologies are ineffective in protecting against covert spoofing attacks, and these ineffective protective measures cannot effectively address the problem of covert spoofing attacks.

Method used

The autonomous vehicle is modeled as a cyber-physical system, and closed-loop system models under normal and attack conditions are constructed. Through the differential closed-loop system model, the steady-state Kalman filter gain and controller gain are obtained, a linear matrix inequality is constructed, a state feedback controller is designed, and combined with robust model predictive control, augmented vectors and predictive equations are constructed to ensure the system is stable and secure under attack.

Benefits of technology

The system achieves state stability and security under covert fake data injection attacks. By designing a state feedback controller and a robust model predictive controller, the system remains stable and secure under the attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937635B_ABST
    Figure CN119937635B_ABST
Patent Text Reader

Abstract

The present application relates to unmanned vehicle safety control method and system resisting hidden false data injection attack. It includes: based on unmanned vehicle information physical system, constructing normal system not attacked and system attacked by hidden executor, constructing difference system with state difference value of two systems; obtaining steady state Kalman filter gain of normal system; constructing linear matrix inequality condition guaranteeing normal system stable and difference system state bounded based on non-escape set, and obtaining controller gain satisfying the condition; according to robust model prediction control, constructing augmented vector and prediction equation, and giving minimum maximum problem of difference system bounded and stable and converting into linear matrix inequality to obtain input signal of difference system, and finally obtaining input signal of attacked system and applying to attacked system, so that difference system is bounded and stable, and stable and safe when attacked. The present application can make the state of attacked system stable and the system safe.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method and system for the safety control of unmanned vehicles against covert fake data injection attacks, belonging to the field of security control of cyber-physical systems. Background Technology

[0002] Cyber-Physical Systems (CPS) refer to an architecture that tightly integrates computing resources with the physical world, playing an indispensable role in many key sectors such as energy, transportation, and manufacturing. By integrating sensors, actuators, communications, and control mechanisms, CPS enables real-time monitoring, manipulation, and response, thereby enhancing system efficiency, stability, and intelligence. With the advancement and widespread application of IoT technology, CPS faces increasingly complex and widespread security challenges. In particular, False Data Injection (FDI) attacks—a method by which attackers modify or introduce false data into CPS in an attempt to compromise the system's integrity, availability, and reliability—pose a significant risk to important industries such as intelligent transportation and smart logistics, which consist of intelligent unmanned systems like autonomous vehicles.

[0003] While traditional Model Predictive Control (MPC) methods can guarantee system stability to a certain extent, they have limitations in dealing with covert FDI attacks. MPC typically assumes that all inputs are trustworthy, and FDI attacks exploit this assumption by manipulating sensor data or control system commands to influence the decision-making process. Furthermore, most existing security measures focus primarily on detecting abnormal behavior rather than proactive defense, failing to provide sufficient protection to prevent the occurrence and development of attacks. Summary of the Invention

[0004] This invention provides a method and system for the safety control of unmanned vehicles that resists attacks that inject hidden false data, aiming to solve at least one of the technical problems existing in the prior art.

[0005] The technical solution of the present invention relates to a safety control method for unmanned vehicles. The method according to the present invention includes the following steps:

[0006] S100. Model the unmanned vehicle as a cyber-physical system; based on the above cyber-physical system, construct a normal closed-loop system model that is not subject to attack, and construct an attacked closed-loop system model that is attacked by a hidden actuator, so as to construct a differential closed-loop system model according to the state difference between the attacked closed-loop system and the normal closed-loop system; wherein, the actuator attack refers to an attack in which the attacker injects false data into the communication channel between the remote controller and the actuator.

[0007] S200. Based on the normal, unattacked closed-loop system model, obtain the steady-state Kalman filter gain of the system; construct the linear matrix inequality conditions that guarantee the stability of the normal system state and the bounded state of the differential system based on the non-escape set, and obtain the controller gain that satisfies the conditions.

[0008] S300. Based on the framework of the robust model predictive control model, an augmented vector and prediction equation are constructed. At the same time, a minimax problem is given to ensure that the state of the differential system is bounded and stable. The minimax problem is transformed into a linear matrix inequality and solved to obtain the differential input signal of the differential system. Finally, the input signal of the attacked system is obtained.

[0009] S400. Apply the obtained input signal of the attacked system to the attacked system so that the differential system is bounded and stable under the action of the non-escape set, and remains stable and safe when attacked.

[0010] Furthermore, in step S100: a normal, attack-resistant unmanned vehicle cyber-physical system is constructed. It can be represented by the following discrete-time system:

[0011]

[0012] In the formula, k represents time. Indicates the system status. Indicates control input, This represents the measurement output, where the initial state x0 has a mean. Covariance Σ0; Indicates process noise. Indicates measurement noise; and All are known covariance matrices; A, B, and C are all known real matrices.

[0013] The remote controller of the cyber-physical system includes features for state estimation. The state estimator ε is used to estimate the state x. k Feedback controller adjusted to the origin And fault detectors used to detect abnormal operations;

[0014] Wherein, the state estimator ε and the feedback controller They are represented as follows:

[0015]

[0016] In the formula, This represents the state estimate at time k; K and L represent the constant estimator gain and the controller gain, respectively.

[0017] Where, for χ 2 The detection value of the fault detector Set when g k An alarm is triggered when the threshold value is greater than α, where α is a preset threshold value, and Σ is a threshold value. k It is the covariance of the state estimation error at time k, and the estimated residual. And the estimation error is expressed as:

[0018]

[0019] e k+1 =(I-KC)(Ae k +ω k )-Kv k+1 .

[0020] In the formula, I represents the identity matrix and has an n×n dimension.

[0021] Furthermore, in step S100: the constructed physical system under executor attack is dynamically represented as follows: It is expressed as follows:

[0022]

[0023] Among them, the state estimator ε′ and feedback controller under actuator attack It is expressed as follows:

[0024]

[0025] In the formula, This represents the executor attack sequence injected at time k; x′ k u′ k y′ k and These represent the attacked a. k The system state affected, control commands implemented at the actuators, sensor measurements, and state estimates;

[0026] Among them, the estimation error e′ under executor attack k+1 and residual z′ k+1 It is expressed as follows:

[0027]

[0028] System states of a normally unaffected cyber-physical system and a cyber-physical system under an actuator attack. estimation error and estimated residuals The differences are expressed as follows:

[0029]

[0030] in, and The dynamic equation is expressed as follows:

[0031]

[0032] In the formula, and This represents the system state, estimation error, and estimation residual of the differential closed-loop system at time k, and the initial state.

[0033] Furthermore, in step S200: the state estimator is a Kalman filter, and the steady-state Kalman filter gain K is expressed as follows:

[0034]

[0035] In the formula, P represents the state estimation error covariance matrix;

[0036] Wherein, the covert attack sequence a k It is expressed as follows:

[0037]

[0038] In the formula, the matrix CB is set to have full column rank. Reversible, and It is the left inverse of matrix CB;

[0039] and then:

[0040]

[0041] Furthermore, in step S200, the linear matrix inequality is expressed as follows:

[0042] P2≤δI,

[0043]

[0044] In the formula, and ; where the set positive scalars α, β, γ, δ, λ, the set positive definite matrices P1>0, P2>0, and the set matrix U, make the linear matrix inequality hold.

[0045] Then set the controller gain. This limits the state difference of the closed-loop system to the following under a covert executor attack: And obtain and Each of their non-escapeable sets is represented as follows: and

[0046] Furthermore, in step S300,

[0047] Based on the obtained An inescapable set We can obtain:

[0048]

[0049] The augmented vector can then be obtained. The prediction equation Φ is expressed as follows:

[0050]

[0051] In the formula,

[0052]

[0053] L p = [L0], where L is the controller gain obtained in step S200.

[0054]

[0055] h k+j|k A new decision variable was introduced to adjust the control signal to achieve the desired effect.

[0056] Furthermore, in step S300,

[0057] Let positive scalars t, τ0, τ1, ..., τ N+2 The optimization problem that satisfies the following constraints holds true:

[0058]

[0059] In the formula, T N :=diag{τ1I,…,τ N I}, T Θ :=diag{τ N+1 I,τ N+2 I},

[0060] Furthermore, in step S400,

[0061] Based on H obtained from step S300 and the actual feedback controller used... Calculate the input signal u′ of the attacked closed-loop system at time k. k .

[0062] The present invention also relates to a computer-readable storage medium having program instructions stored thereon, which, when executed by a processor, implement the above-described method.

[0063] The present invention also relates to an unmanned vehicle safety control system, the system including a computer device that includes the aforementioned computer-readable storage medium.

[0064] The beneficial effects of this invention are as follows:

[0065] This invention focuses on a safety control method and system for unmanned vehicles (UGVs) to resist covert spoofed data injection (FDI) attacks. Specifically, it addresses the safety control methods and corresponding systems for UGVs when subjected to covert actuator spoofed data injection (FDI) attacks. This invention models the UGV as a cyber-physical system and designs a safety controller based on the concept of non-escape sets. The designed state feedback controller gain not only ensures the convergence and stability of the normally unattacked system's state but also, combined with a robust model predicting the controller's control signal using feedback prediction, ensures the stability of the attacked system's state and overall system security. Attached Figure Description

[0066] Figure 1 This is a basic flowchart of the unmanned vehicle safety control method according to an embodiment of the present invention.

[0067] Figure 2 This is a system block diagram of an unmanned ground vehicle (UGV) according to an embodiment of the present invention;

[0068] Figure 3 This is a schematic diagram of the open-loop state response results of the UGV system according to an embodiment of the present invention;

[0069] Figure 4 This is a schematic diagram of the closed-loop state response results of an unattacked UGV system according to an embodiment of the present invention;

[0070] Figure 5 This is a schematic diagram of the estimated residual difference results of the UGV system before and after being attacked, according to an embodiment of the present invention.

[0071] Figure 6 This is a schematic diagram illustrating the magnitude change and bounded limit result of the state difference of the UGV system before and after being attacked, according to an embodiment of the present invention.

[0072] Figure 7 This is a schematic diagram showing the squared change of the 2-norm of the state difference of the UGV system before and after being attacked, according to an embodiment of the present invention.

[0073] Figure 8 This diagram illustrates the closed-loop state response results of the UGV system in this embodiment of the invention, comparing the model predictive control that estimates the residual difference without considering the differential system with the method of this invention. Detailed Implementation

[0074] The following will provide a clear and complete description of the concept, specific structure, and technical effects of the present invention in conjunction with the embodiments and accompanying drawings, so as to fully understand the purpose, solution, and effects of the present invention.

[0075] It should be noted that, unless otherwise specified, when a feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to the other feature, or indirectly fixed or connected to the other feature. The singular forms "a," "described," and "the" used herein are also intended to include the plural forms, unless the context clearly indicates otherwise. Furthermore, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this specification is for the purpose of describing particular embodiments only and not for limiting the invention. The term "and / or" as used herein includes any combination of one or more of the associated listed items.

[0076] It should be understood that although the terms first, second, third, etc., may be used in this disclosure to describe various elements, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from one another. For example, a first element may also be referred to as a second element without departing from the scope of this disclosure, and similarly, a second element may also be referred to as a first element. Any and all instances or exemplary language (“e.g.,” “such as,” etc.) provided herein are intended only to better illustrate embodiments of the invention and, unless otherwise required, do not impose a limitation on the scope of the invention.

[0077] Reference Figures 1 to 8 In some embodiments, an unmanned vehicle safety control method according to the present invention is applied to an unmanned vehicle system subjected to a covert spoofing data injection attack, and the method includes at least the following steps:

[0078] S100. Model the unmanned vehicle as a cyber-physical system; based on the above cyber-physical system, construct a normal closed-loop system model that is not subject to attack, and construct an attacked closed-loop system model that is attacked by a hidden actuator, so as to construct a differential closed-loop system model based on the state difference between the attacked closed-loop system and the normal closed-loop system; wherein, the actuator attack refers to the attack in which the attacker injects false data into the communication channel between the remote controller and the actuator.

[0079] S200. Based on the normal, unattacked closed-loop system model, obtain the steady-state Kalman filter gain of the system; construct the linear matrix inequality conditions that guarantee the stability of the normal system state and the bounded state of the differential system based on the non-escape set, and obtain the controller gain that satisfies the conditions.

[0080] S300. Based on the framework of the robust model predictive control model, an augmented vector and prediction equation are constructed. At the same time, a minimax problem is given to ensure that the state of the differential system is bounded and stable. The minimax problem is transformed into a linear matrix inequality and solved to obtain the differential input signal of the differential system. Finally, the input signal of the attacked system is obtained.

[0081] S400. Apply the obtained input signal of the attacked system to the attacked system so that the differential system is bounded and stable under the action of the non-escape set, and remains stable and safe when attacked.

[0082] The present invention relates to a method and system for safe control of unmanned vehicles that can resist covert fake data injection attacks. The unmanned vehicle is modeled as a cyber-physical system, and a safety controller is designed based on the concept of non-escape sets. The designed state feedback controller gain not only enables the state of the normally unattacked system to converge and stabilize, but also, combined with the robust model of feedback prediction, predicts the control signal of the controller, which can make the state of the attacked system stable and the system safe.

[0083] In some embodiments, the autonomous vehicle is constructed as a cyber-physical system, the physical system of which is described by the following discrete-time system:

[0084]

[0085] In the formula, k represents time. It is the system status. It is a control input. It is the measurement output, where the initial state x0 has a mean. Covariance Σ0. Process noise. and measuring noise It is white noise, mutually independent, with zero mean, and each has a known covariance matrix. and A, B, and C are known real matrices with appropriate dimensions. Their specific parameters and dimension values ​​are derived from the actual system parameters of the autonomous vehicle.

[0086] Furthermore, a computer is used as the actual carrier of the remote control center to construct a network layer for remote control of the physical system. At the remote control center (i.e., the remote controller), state estimation is calculated by the state estimator ε, and the feedback controller... State x k Adjust to the origin (i.e., x) k =0):

[0087]

[0088] in, It is the state estimate at time k; K and L are the constant estimator gain and controller gain, respectively.

[0089] Furthermore, a χ² is deployed in the remote control center. 2 A fault detector is used to detect abnormal operations. Based on the estimated residual... At each time point k, χ 2 The fault detector first calculates In the formula Σ k It is the covariance of the state estimation error at time k, and then g k Compare with a preset threshold α. If g k If the value is greater than α, an alarm will be triggered. It should be noted that when the system is running normally (i.e., there is no network attack), g... k Satisfying χ 2 Distribution, thus g can be obtained k The probability of a larger one is low.

[0090] Let the estimation error be expressed as Then we have:

[0091] e k+1 =(I-KC)(Ae k +ω k )-Kv k+1

[0092] In the formula, I represents the identity matrix and has an n×n dimension.

[0093] It should be noted that the symbol := indicates that it is defined as.

[0094] The following settings are made for the designed cyber-physical system:

[0095] Setting 1: Matrix pair (A,C) is observable, and matrix pair (A,B) is controllable.

[0096] Setting 2: Rank(CB) = m, that is, the CB column of the matrix is ​​full rank.

[0097] In some embodiments, an attacker injects false data into the communication channel between a remote controller and an actuator; such an attack is referred to as an "actuator attack".

[0098] The physical system dynamics under an executor attack are represented as follows: It is expressed as follows:

[0099]

[0100] When attacked, the state estimator ε′ and the feedback controller as follows:

[0101]

[0102] in, This represents an executor attack injected at time k; x′ k u′ k y′ k and These represent the attacked a. k The impact affects the system state, control commands implemented at the actuators, sensor measurements, and state estimates. It is important to note the attacked state estimator ε′ and feedback controller. With an ideal state estimator ε and feedback controller They have the same gains K and L, but utilize different signals. Without loss of generality, the injected spoof data attack is set to begin at time k=1, with the initial system state and state estimate being x′0=x0 and respectively.

[0103] The estimation error and residual under an actuator spoof data injection attack are shown below:

[0104]

[0105] Considering the impact of actuator attacks on system dynamics, the differences between the system state, estimation error, and estimation residual of the physical system under no-attack and attacked conditions are defined, i.e., the system state of the differential closed-loop system. estimation error and estimated residuals It is expressed as follows:

[0106]

[0107] and The dynamics can be derived as follows:

[0108]

[0109] Among them, the initial state

[0110] In some embodiments of the covert executor attack model, the attacker initiates a "special" data injection sequence to degrade or even destabilize the system's dynamic performance, without being detected by X. 2 The detector detects that when the estimated residual of the differential closed-loop system... When it was very small, χ 2 The detector cannot distinguish z′ with high probability. k and z k Based on the above characteristics, in order to make the attack sequence covert, the injection of spoofed data should avoid causing differences in the estimated residuals. The significant changes mean that attackers can predetermine the "special" sequence that must satisfy... It should always be true, where ζ represents χ. 2 The tolerance level of the detector, thus the present invention sets The always true FDI attack sequence {a k It has the ability to be concealed.

[0111] Therefore, a similar security setting is proposed for covert executor attacks:

[0112] Security setting 1: At least one attack sequence exists {a k}, making the system state Differences satisfy:

[0113]

[0114] Under the condition of a covert executor attack, the system includes a state estimator ε′ and a feedback controller. system It is unsafe; otherwise, the decision is made with a state estimator ε′ and a feedback controller. system It is safe against covert executor attacks.

[0115] It should be noted that when using χ 2 When the detector performs attack detection, using a Kalman filter as a state estimator can make χ 2 The test statistic has the best detection capability. Understandably, only when the residuals are white noise can they be considered as independent samples at different sampling time points; otherwise, any correlation between the residuals at different time points will significantly reduce the detection performance.

[0116] In one application embodiment, the steady-state Kalman filter gain of the system is obtained based on a normal, unaffected closed-loop system model. Specifically, if a Kalman filter is used as a state estimator, the Kalman filter is applied from the observations y0,…,y k To obtain state estimation

[0117]

[0118] In the formula, This represents the state estimate before time 0, i.e., the initial state estimate; This represents the state estimate before time k+1, that is, the prediction of the state at time k+1 based on information from time k; K k P represents the Kalman filter gain at time k; k Let represent the state estimation error covariance matrix at time k, i.e., the uncertainty of the estimation.

[0119] Furthermore, although K k It changes over time, but after a few steps, K k It will converge, therefore this invention assumes that the Kalman filter is already in a steady state, and the steady-state Kalman filter gain K is expressed as follows:

[0120]

[0121] Based on the given matrix CB having full column rank, we can obtain... It is reversible, and It is the left inverse of matrix CB, thus the covert attack sequence a can be obtained. k It is expressed as follows:

[0122]

[0123] Therefore, we can conclude that:

[0124]

[0125] Based on the above equation, let positive scalars α, β, γ, δ, λ, positive definite matrices P1>0, P2>0, and a matrix U of appropriate dimension hold such that the following linear matrix inequalities all hold:

[0126] P2≤δI,

[0127]

[0128] In the formula, and

[0129] Set the controller gain to Under a covert executor attack, the state difference of the closed-loop system is limited to: At the same time, it can be obtained and Each has its own inescapable set, namely and Therefore, based on the non-escape set, we construct a linear matrix inequality condition that guarantees the stability of the normal system state and the bounded state of the difference system state, and obtain the controller gain that satisfies the condition.

[0130] In some embodiments, the present invention constructs augmented vectors and prediction equations based on the framework of robust model predictive control model, and provides a minimax problem that guarantees the bounded and stable state of the differential system. The minimax problem is transformed into a linear matrix inequality and solved to obtain the differential input signal of the differential system, and finally the input signal of the attacked system is obtained.

[0131] Specifically, according to and The dynamic equations are used to separate the control signals of the closed-loop differential system. and We can obtain:

[0132]

[0133] Define the estimated value Then we have:

[0134]

[0135] in:

[0136]

[0137] Given the number of prediction steps N, the optimization problem to be solved is:

[0138]

[0139] Here, matrices Ξ>0 and Υ>0 are given as performance weights. And defined as follows:

[0140]

[0141] The problem is effectively solved by introducing some conservatism to replace the original minimax problem.

[0142] Specifically, the objective function can be expressed as:

[0143]

[0144] in,

[0145]

[0146] Next, robust model predictive control (RMPC) considering estimation errors is applied, and the design of RMPC is introduced using a feedback prediction method. To adjust the control signal to achieve the desired effect, a new decision variable h is introduced. k+j|k Feedback controller The design is as follows:

[0147]

[0148] in

[0149] L p =[L0]

[0150] L is the controller gain obtained in step S200, since That is, the actual feedback controller used under an actuator FDI attack. It is expressed as follows:

[0151]

[0152] Then, the augmented vector of the control signal It is expressed as follows:

[0153]

[0154] In the formula,

[0155]

[0156] The prediction equation Φ can then be expressed as:

[0157]

[0158] in

[0159]

[0160] According to the above formula, we can solve for:

[0161]

[0162] For convenience, the following definition is provided:

[0163]

[0164] because And it can only obtain estimates of state variables. and so pass Calculation, in addition, By definition There is an estimated value φ k =φ k|k +η k ,in This is an estimate of time k. Therefore:

[0165]

[0166] The result has been obtained in step S200. An inescapable set definition:

[0167]

[0168] Substituting this into the prediction equation, we get:

[0169]

[0170] in

[0171] Based on the above derivation, solve for H, positive scalars t, τ0, τ1, ..., τ N+2 The optimization problem that satisfies the following constraints holds true:

[0172]

[0173] In the formula, T N := diag{τ1I,…,τ N I}, T Θ :=diag{τ N+1 I,τ n+2 I},

[0174] So, the controlled system In the steady-state Kalman filter ε′ and feedback controller Under the influence of [the system], it is stable and secure under covert FDI attacks, and the state of the differential system [is also secure]. satisfy

[0175] In some embodiments, the obtained input signal of the attacked system is applied to the attacked system, such that the differential system is state-bounded and stable under the action of the non-escape set, and remains stable and secure when attacked. Specifically, the first m rows of H obtained in step S300 are taken to form a column vector, i.e., h k|k And substitute it into the actual feedback controller form u′ k|k =Lx′ k|k +h k|k That is to say Calculate the input signal u′ of the attacked system at step k. k .

[0176] This section uses a specific embodiment to illustrate and verify the effectiveness of the intelligent unmanned vehicle cyber-physical security control method and system for resisting covert spoofed data injection attacks according to the present invention. Specifically, the invention is further described through an example of an unmanned ground vehicle (UGV) system, the system block diagram of which is shown below. Figure 2 As shown, the network layer is implemented through a wireless network connection.

[0177] Specifically, the physical system model in this application example is as follows:

[0178] Assume the UGV's motion is linear, and that this linear motion comes to a complete stop before rotation. Under this assumption, the dynamic equations for the UGV's linear and angular motion can be expressed as:

[0179]

[0180] In the formula: x — the position of the unmanned ground vehicle (m);

[0181] v — the linear velocity of the unmanned ground vehicle (m / s);

[0182] θ — Angle of the unmanned ground vehicle (rad);

[0183] ω — Angular velocity of the unmanned ground vehicle (rad / s)

[0184] M – Mass of the unmanned ground vehicle (kg);

[0185] J—Moment of inertia of the unmanned ground vehicle (kg·m2);

[0186] B—Coefficient of translational friction;

[0187] B r —Coefficient of rotational friction;

[0188] F — Input force (N);

[0189] T — Input torque (N·m).

[0190] Assuming the encoder performs the necessary processing to directly provide speed measurements, the resulting output equation can be expressed as:

[0191]

[0192] Where, ψ i Let be the measurement noise of the i-th sensor, assumed to be Gaussian white noise with zero mean and finite covariance. For ease of representation and to maintain consistency with the state vector of the output equation, let the new state variable be . The state equation can then be expressed as:

[0193]

[0194] Among them, the input signal .

[0195] In this application example, the sampling time is set to 0.1s to discretize the continuous system. Considering both process noise and measurement noise in the model, discrete state equations are obtained and rearranged into the cyber-physical system form in step S100, thus obtaining the UGV system requiring safety control. The initial state value of the UGV system is taken as... From this, we can obtain Figure 3 The open-loop response.

[0196] First, according to step S200, the steady-state Kalman filter gain of the system is calculated. It is assumed that the UGV's control signal is attacked during transmission to the actuator; in this experiment, the attack signal is sinusoidal. Next, according to step S200, a feasible solution for calculating the controller gain is found, yielding the values ​​of parameters α, β, γ, λ, and δ.

[0197] In the controller Under the influence of the attack, the closed-loop state response of an unattacked UGV system is as follows: Figure 4 As shown, the controller gain L allows the unattacked UGV system to converge to zero relatively quickly. The control objective of this invention is to use RMPC (Real-Time Control Programming) to enable the attacked system to track the state of the normal system, based on a controller gain of L for the normal system, thus obtaining the state of the differential system between the two. It can also stabilize at zero. In the following experiments, the method proposed in this invention will be compared with the method using MPC on both normal and attacked systems.

[0198] because Only with and a k This is relevant because, since the initial values ​​of the state estimates of the normal, unattacked system and the attacked system are the same and both are zero, the state errors of the two systems at time zero are also the same, i.e., e k =e′ k ,So Therefore, during the calculation process, Only with a k Relevant, then Only with a k Related to the difference between the estimated residuals of the attacked system and the unattacked system generated by the MPC method and the control method of this invention, under the condition that the FDI attack signal of the actuator is the same. The changes are the same, such as Figure 5 As shown. It is evident. Always satisfied In other words, the introduced FDI attack sequence is covert.

[0199] Based on feedback control, the optimal robust model predictive controller (RMPC) signal can be obtained by solving the optimization problem in step S300. Under the action of the RMPC controller signal, the differential states of the UGV system before and after the attack satisfy the following... The bounds and the squares of their 2-norms are as follows: Figure 6 and Figure 7 As shown. It can be seen that, It remains unchanged over time and Within the maintained boundaries. Therefore, by using the proposed method, the security and stability of the closed-loop system can be ensured under covert FDI attacks.

[0200] A comparison diagram of the closed-loop state response of the UGV system generated using the MPC method and the method used in this invention is shown below. Figure 8 As shown, both the MPC method and the method proposed in this invention can converge the UGV system to the origin after a certain period of time. However, in terms of convergence speed, the linear feedback plus RMPC method proposed in this invention can bring the system to the origin faster while ensuring the system's safety. This highlights the effectiveness of the method proposed in this invention to a certain extent.

[0201] It should be noted that, considering the often highly complex systems in actual production processes, accurately identifying their system parameters is nearly impossible. Therefore, a method based on iterative optimization to calculate the safety controller from data is essential. This invention proposes a safety control method and system for unmanned vehicles that resists covert spoofed data injection attacks. It allows the attacked system state to track the state of the unattacked normal system. By applying the relevant theorem of non-escape sets, the boundedness of the differential system state is guaranteed. Within the framework of robust model predictive control, state errors are effectively handled to ensure the accuracy of the prediction equations. Simultaneously, uncertain matrix constraints are transformed into tractable linear matrix inequalities. Finally, the control signal of the system is obtained, ensuring good performance even under attack, making the system not only safe but also stable.

[0202] It should be understood that the method steps in the embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable storage medium. The method can use standard programming techniques. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if necessary, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Furthermore, for this purpose, the program can run on a programmed application-specific integrated circuit (ASIC).

[0203] Furthermore, the procedures described herein may be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by the context. The procedures described herein (or variations and / or combinations thereof) may be executed under the control of one or more computer systems configured with executable instructions, and may be implemented by hardware or a combination thereof as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. The computer program comprises a plurality of instructions executable by one or more processors.

[0204] Furthermore, the method can be implemented in any suitable type of computing platform, including but not limited to personal computers, minicomputers, mainframes, workstations, networked or distributed computing environments, standalone or integrated computer platforms, or in communication with charged particle tools or other imaging devices, etc. Aspects of the invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, optical read and / or write storage medium, RSM, ROM, etc., such that it can be read by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the processes described herein. Furthermore, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. The invention described herein includes these and other different types of non-transitory computer-readable storage media when such media comprises instructions or programs that implement the steps described above in conjunction with a microprocessor or other data processor. When programmed according to the methods and techniques described in the invention, the invention may also include the computer itself.

[0205] A computer program can be applied to input data to perform the functions described herein, thereby transforming the input data to generate output data stored in non-volatile memory. The output information can also be applied to one or more output devices, such as a display. In a preferred embodiment of the invention, the transformed data represents physical and tangible objects, including specific visual depictions of physical and tangible objects generated on the display.

[0206] The above description is merely a preferred embodiment of the present invention. The present invention is not limited to the above-described embodiments. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention, as long as they achieve the technical effects of the present invention by the same means, should be included within the scope of protection of the present invention. Within the scope of protection of the present invention, the technical solutions and / or implementation methods can have various modifications and variations.

Claims

1. A method for safe control of an unmanned vehicle, characterized in that, The method comprises the following steps: S100, model the unmanned vehicle as an information-physical system; based on the information-physical system, construct a normal closed-loop system model of a normal system not under attack and a closed-loop system model of an attacked system under an invisible actuator attack, to construct a difference closed-loop system model according to the state difference between the attacked closed-loop system and the normal closed-loop system; wherein the actuator attack represents an attack in which an attacker injects false data into a communication channel between a remote controller and an actuator; S200, obtain a steady-state Kalman filter gain of the system according to the normal closed-loop system model not under attack; construct a linear matrix inequality condition guaranteeing that the state of the normal system is stable and the state of the difference system is bounded based on an inescapable set, and obtain a controller gain satisfying the condition; S300, construct an augmented vector and a prediction equation according to a framework of a robust model predictive control model, and meanwhile give a minimax problem guaranteeing that the state of the difference system is bounded and stable, convert the minimax problem into a linear matrix inequality, and solve to obtain a difference input signal of the difference system, and finally obtain an input signal of the attacked system; S400, apply the obtained input signal of the attacked system to the attacked system, so that the state of the difference system is bounded and stable under the action of the inescapable set, and the system remains stable and safe when under attack.

2. The method of claim 1, wherein, In the step S100, Constructed normal unattacked unmanned vehicle cyber-physical system is represented by the following discrete-time system: where k denotes the time instant, denotes the system state, denotes the control input, denotes the measurement output, where the initial state xo has a mean and a covariance Σ0; denotes the process noise, denotes the measurement noise; and are known covariance matrices; A, B and C are known real matrices. The remote controller of the cyber-physical system comprises a state estimator ε for state estimation a feedback controller for adjusting the state x k to the origin and a fault detector for detecting abnormal operation wherein the state estimator ε and the feedback controller are represented as follows, respectively: wherein x(k) represents the state estimate at time instant k; K and L represent the constant estimator gain and controller gain, respectively; where, for χ 2 Fault detector detection value Set to trigger an alarm when g k > a, where a is a pre-set threshold, ∑ k is the covariance of the state estimation error at time instant k, the estimation residual and the estimation error are expressed as: e k+1 = (I - KC) (Ae k + ω k )- Kv k+1 . wherein I represents a unit matrix and has a dimension of n x n.

3. The method of claim 2, wherein, In the step S100, The constructed dynamic representation of the physical system under actuator attack is which is represented as follows: wherein the state estimator ε' and the feedback controller under actuator attack is represented as follows: wherein represents the sequence of actuator attacks injected at time instant k; x' k , u' k , y' k and represent the system state, the control command implemented at the actuators, the sensor measurements and the state estimation affected by the attack a k , respectively. wherein the estimation error e' under actuator attack k+1 and the residual z' k+1 is represented as follows: System states of a normal unattacked cyber-physical system and a cyber-physical system under actuator attack estimated error and an estimated residual error The difference between the two is expressed as follows: wherein and The dynamic equation for is given by wherein and denote the system state, the estimation error and the estimation residual of the difference closed loop system at time k, the initial state 4. The method of claim 3, wherein, In the step S200, The state estimator is a Kalman filter, and the steady-state Kalman filter gain K is represented as follows: wherein P represents a state estimation error covariance matrix; wherein the covert attack sequence a k is represented as follows: where the set matrix CB has full column rank, is invertible, and is the left inverse of the matrix CB. Further, 5. The method of claim 4, wherein, In the step S200, The linear matrix inequality is represented as follows: P2≤δI, wherein and wherein positive scalars a, b, g, d, l are set, positive definite matrices P1>0, P2>0 are set, and a matrix U of dimension is set such that the linear matrix inequality holds. further setting the controller gain such that under covert actuator attack, the closed loop system state difference is bounded by and obtaining and each one of the non-escape sets is represented as and 6. The method of claim 5, wherein, In the step S300, According to the obtained One cannot escape the set Available: Further, the augmented vector and the prediction equation Φ, respectively, are given by wherein L p = [L 0], L is the controller gain obtained in step S200, h k+j|k A new decision variable is introduced to adjust the control signal to achieve the desired effect.

7. The method of claim 6, wherein, In the step S300, Set positive scalars t, τ0, τ1,..., τ N+2 such that the following optimization problem holds: In the formula, T N : = diag{τ1I,...,τ N I}, T Θ : = diag{τ N+1 I,τ N+2 I}, 8. The method of claim 7, wherein, In the step S400, H obtained from step S300 and the feedback controller actually used The input signal u' of the time k of the attacked closed loop system is calculated k .

9. A computer readable storage medium having program instructions stored thereon, the program instructions being executed by a processor to implement the method according to any one of claims 1 to 8.

10. An unmanned vehicle safety control system, characterized by, including: A computer device comprising the computer readable storage medium according to claim 9.

Citation Information

Patent Citations

  • Event-driven course safety control method for unmanned ship under network attacks

    CN113050630A

  • Control method and system for nonlinear system under false data injection attack

    CN117519096A