Unmanned aerial vehicle adaptive perception and defense method and equipment based on dynamic confrontation training
By adopting dynamic adversarial training methods in the UAV system, combining physical environmental factor modeling, adversarial sample generation and multimodal data fusion, the problem of insufficient defense capabilities of the UAV in complex environments is solved, and higher robustness and defense effects are achieved.
Patent Information
- Application Number
- CN202510436087.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-09
AI Technical Summary
Existing drone defense systems lack dynamic adaptability when facing physical attacks in complex physical environments, resulting in poor robustness and defense effectiveness.
Adaptive perception and defense methods based on dynamic adversarial training are adopted to establish an adaptive perception and defense system by quantifying physical environment factors, generating adversarial samples, multimodal data fusion and dynamic adversarial training strategies.
Significantly improve the robustness and defense effect of the UAV system in complex physical environments, can dynamically adapt to diverse environments, accurately identify and detect abnormal attacks, and achieve more accurate target recognition and positioning.
Smart Images

Figure CN119939365A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of drone system security technology, and in particular to a drone adaptive perception and defense method and device based on dynamic adversarial training. Background Art
[0002] As drones are widely used in high-risk scenarios such as reconnaissance, patrolling, and emergency rescue, their safety and robustness have become important research directions. However, the physical attacks faced by drones (such as malicious occlusion, camouflage, and perspective deviation) vary greatly in real environments and are strongly affected by natural conditions and target locations. Traditional defense methods are mostly static solutions that fail to cope with the challenges brought about by changes in the physical environment. Most existing defense systems are based on adversarial samples in the digital domain and lack the ability to adapt to physical environment attacks. Therefore, it is urgent to develop an adversarial training method that can dynamically adapt to diverse environments to enhance the ability of drones to cope with complex environments. Summary of the invention
[0003] The invention objective of the present application is to provide a method and device for adaptive perception and defense of unmanned aerial vehicles based on dynamic adversarial training, so as to significantly improve the robustness of perception and defense effect of unmanned aerial vehicle systems.
[0004] The first aspect of the present application provides a method for adaptively sensing and defending a drone based on dynamic adversarial training, which comprises the following steps:
[0005] Step 1: Quantify different physical environment factors and conduct physical attack modeling;
[0006] Step 2: Based on the established physical attack model, a generative adversarial network (GAN) is used to generate dynamic adversarial samples;
[0007] Step 3: Establish a physical attack type detection model based on multimodal data fusion;
[0008] Step 4: Perform physical attack type detection based on the established attack type model. If a specific physical attack type is detected, target identification and positioning are performed based on the target identification model corresponding to the physical attack type; otherwise, target identification and positioning are performed based on the general target identification model.
[0009] Further, physical environment factors include: lighting, viewing angle, weather and obstacles.
[0010] Furthermore, the physical attack type detection model is used to output the posterior probability of each physical attack under multimodal data fusion.
[0011] Furthermore, in step 4, performing physical attack type detection based on the established attack type model detection includes:
[0012] Based on the attack type model detection, the posterior probability of each physical attack type is calculated respectively;
[0013] The posterior probabilities that are greater than or equal to the specified threshold are selected, and then the specific physical attack type is detected based on the physical attack type corresponding to the maximum value; if all posterior probabilities are less than the specified threshold, it means that the specific physical attack type is not detected.
[0014] Furthermore, in step 2, during the training of the generative adversarial network, the generated adversarial examples satisfy the physical constraints: ,in, Represents the generated adversarial sample The distribution of features in the physical world, represents the characteristic distribution of real samples in the physical world, Indicates the preset threshold.
[0015] Furthermore, in step 3, the Bayesian reasoning method is used to perform multimodal data fusion.
[0016] Furthermore, a dynamic adversarial training strategy is used to train the physical attack type detection model, and the total loss function during training is set as:
[0017] Ltotal = Ltask + λ1Lrobust + λ2Ladaptive
[0018] Among them, L task represents the recognition loss of the target recognition model, L robust represents the robustness loss of adversarial training, L adaptive represents the adaptive loss in a dynamic environment, They are respectively the robustness loss L for adversarial training robust , adaptive loss L in dynamic environment adaptive The weights are used to balance the priorities of tasks, robustness, and adaptability.
[0019] Furthermore, the recognition loss of the target recognition model is set to cross loss or mean square error loss.
[0020] A second aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the program to execute the adaptive perception and defense method for drones based on dynamic adversarial training as described in the present application.
[0021] The technical solution provided by this application brings at least the following beneficial effects:
[0022] The solution proposed in this application enables the drone system to dynamically adapt to physical attacks such as lighting changes, weather interference, and perspective conversion. Through multimodal information fusion, adaptive adversarial training framework, and real-time attack detection module, the system can significantly improve the robustness and defense effect of the drone perception system.
[0023] Based on the adversarial training strategy adopted in this application, the robustness of UAVs in diverse physical environments can be significantly improved, enabling the system to accurately identify and detect abnormal attacks in complex environments, thereby achieving more accurate target identification and positioning. This technology has broad application prospects in high-risk scenarios such as disaster monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0025] Figure 1 A flowchart of a method for adaptively sensing and defending a drone based on dynamic adversarial training provided in an embodiment of the present application;
[0026] Figure 2 A schematic diagram of the structure of an electronic device provided for an application embodiment. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions of the embodiments of the present application will be described in detail and completely in conjunction with the drawings in the embodiments of the present application. Obviously, the embodiments described with reference to the drawings are exemplary and are intended to be used to explain the present application, and cannot be understood as limiting the present application.
[0028] In one embodiment, the present application provides a UAV adaptive perception and defense method based on dynamic adversarial training to improve the robustness and safety of the UAV system in a complex and dynamic physical environment.
[0029] join Figure 1 The method for adaptively sensing and defending a drone based on dynamic adversarial training provided in the embodiment of the present application includes the following steps:
[0030] Step 1: Quantify different physical environment factors (such as lighting, viewing angle, weather, obstacles, etc.) to perform physical attack modeling;
[0031] Step 2: Based on the established physical attack model, a generative adversarial network (GAN) is used to generate dynamic adversarial samples.
[0032] Step 3: Build a physical attack type detection model based on multimodal data fusion;
[0033] Step 4: Perform physical attack detection based on the attack type model detection. If a specific physical attack type is detected, target identification and positioning are performed based on the target identification model corresponding to the physical attack type; otherwise, target identification and positioning are performed based on the general target identification model.
[0034] In one embodiment, physical attack modeling is the foundation of the entire technical solution. By establishing a mathematical model, different physical environmental factors (such as lighting, viewing angle, weather, obstacles, etc.) are quantified as the degree of impact on the drone system, so as to help the system simulate various real physical attack scenarios during the training phase.
[0035] Specifically, the physical attack model constructed in this application is a multi-factor weighted model , which is used to describe the impact of changes in the attack sample in the physical environment. The formula is as follows:
[0036]
[0037] in, Describe the data collected by the sensors carried by the drone (such as visual data), Represents the illumination change function, which is used to simulate the influence of illumination intensity, light source angle, etc. on target recognition. Its expression is:
[0038]
[0039] in, Represents the initial light intensity of the light source (Base Intensity), which is usually quantified as a constant; represents the angle of incidence between the light source and the target (expressed in radians); Indicates the distance from the light source to the target (unit: meter).
[0040] In the actual calculation process, the maximum and minimum value method can be used to normalize the obtained illumination change values.
[0041] It represents the view angle change function, which is used to describe the interference of the change of the drone camera angle on target recognition. Its expression is:
[0042]
[0043] in, represents the interference coefficient, which can be used to adjust the sensitivity of the model; Indicates the actual size of the object (e.g., the width of the object); Represents the incident angle between the light source and the target (expressed in radians). In the calculation process of the viewing angle change function, It can be pitch angle or yaw angle, Indicates the distance between the target and the camera (also denoted as dtarget). Similarly, the maximum and minimum value method can be used to normalize the view change value.
[0044] Represents the weather change function, which is used to simulate the interference of weather factors such as fog, rain, and snow on visual data. Its expression is:
[0045]
[0046] Where f0 represents the original visual data intensity (intensity without weather interference); Indicates the attenuation coefficient caused by weather factors (related to the weather type, fog, rain, and snow will have different values); d' indicates the distance between the target and the camera (unit: meter); Indicates the weather condition factor, which is used to characterize the degree of enhancement of the visual impact of weather (can be used to total the impact of fog, rain, snow, etc.); Indicates the intensity of weather conditions (such as fog density, rain intensity, etc.) as a normalized value ranging from 0 to 1.
[0047] Represents the obstacle occlusion function, which is used to simulate the occlusion effect that may appear in the scene. Its expression is:
[0048]
[0049] in, Represents the effective area of the occluder (which can be regarded as the size or projected area of the obstacle); Represents the total effective area within the field of view of the target camera (can be set according to the scene); Represents the attenuation coefficient, which is related to the nature of the occluder and other factors in the scene. dtarget represents the distance between the target and the camera (unit: meter).
[0050] , , , They represent the influence factors of the four functions, which can also be called the weight parameters of the physical attack model. , , , , the influence degree of each physical factor can be controlled, so as to flexibly generate diverse attack samples to cover different physical attack scenarios that the drone may encounter.
[0051] Furthermore, corresponding target recognition models can be trained for various physical attack types based on the generated diverse attack samples. In the embodiments of the present application, the physical attack types involved mainly include: lighting physical attack, visual angle physical attack, weather physical attack and obstacle physical attack.
[0052] In one embodiment, the adversarial sample generation (i.e., dynamic adversarial sample generation) in step 2 of the present application is specifically as follows:
[0053] Based on the physical attack modeling, the Generative Adversarial Network (GAN) is used to generate adversarial samples that meet the conditions of the physical world, ensuring that the samples have physical adaptability, that is, they can trigger attack effects in actual environments. For example, when generating adversarial samples under conditions of changing light, the performance of the samples under different light intensities can be controlled to meet the needs of actual scenarios.
[0054] In the embodiment of the present application, the generator G and the discriminator D in the generative adversarial network can be trained adversarially using the following loss function:
[0055]
[0056] in, represents the adversarial loss function, Express expectations, Represents the real sample The distribution of represents the output of the discriminator D, represents a random noise vector sampled from a prior distribution (Gaussian distribution or uniform distribution can be selected), represents the distribution of the random noise vector, Represents the output of the generator.
[0057] During the training process, the generator G and the discriminator D are optimized alternately until the Nash equilibrium is reached, that is, the adversarial samples generated by the generator can deceive the discriminator to the maximum extent.
[0058] Generated adversarial examples The following physical constraints are met to ensure that the samples are not just virtual data, but entities that can be viewed and manipulated in the physical world:
[0059]
[0060] in, represents the characteristic distribution of adversarial samples in the physical world, Represents the characteristic distribution of real data (i.e., data collected by sensors) in the physical world. Represents the set threshold, which is used to ensure the closeness of the adversarial sample to the actual physical world;
[0061] Among them, the feature distribution It can be expressed by the following formula:
[0062]
[0063] in, , , and Respectively represent the adversarial samples of illumination change, perspective change, weather change and obstacle occlusion This physical constraint ensures that the generated adversarial samples can effectively trigger the model's misjudgment in real scenarios and allow the drone system to encounter more realistic physical attack scenarios during training.
[0064] In one embodiment, in step 3, multimodal data fusion is specifically:
[0065] Multimodal data fusion is an important means to improve the effectiveness of defense systems in physical environments. Multimodal data comes from different sensors, such as vision, lidar, infrared sensors, etc. Each data type can provide supplementary information in different attack scenarios.
[0066] In the embodiment of the present application, the Bayesian reasoning method is used for multimodal data fusion, and the formula is as follows:
[0067]
[0068] in, represents multimodal data fusion, Represents data sources of different modalities (such as vision, lidar, etc.). The modality identifier representing the data, In this application, it is assumed that H represents the assumptions of a specific physical attack, that is, corresponding to different types of physical attacks, represents the conditional probability of each modal data under the condition of physical attack. This formula can judge and evaluate the type and characteristics of specific physical attacks suffered by drones by fusing multimodal data.
[0069] In addition, the Bayesian adaptive optimization method is introduced to continuously adjust the parameters of adversarial training according to the actual situation in training to optimize the overall loss function. . Define the objective function as:
[0070]
[0071] in, is the parameter vector for adversarial training, ,in, They are the weights of the robust loss Lrobust for adversarial training and the adaptive loss Ladaptive in dynamic environments.
[0072] In this application, Gaussian process is used to model the objective function :
[0073]
[0074] in, represents a Gaussian process, the mean function Initialized to 0, covariance function Choose the squared exponential kernel function:
[0075]
[0076] in, Indicates the scale parameter of the setting.
[0077] Use expected improvement ( ) as the obtaining function to select the next parameter combination to evaluate:
[0078]
[0079] in, is the best objective function value known so far. The formula for the expected improvement is:
[0080]
[0081] Among them, the parameters . and are the cumulative distribution function and probability density function of the standard normal distribution, Represents the mean.
[0082] In each iteration, the parameter combination that maximizes the expected improvement is selected. .
[0083]
[0084] Then in Perform adversarial training under .
[0085] The new evaluation results Feedback to the Gaussian process to update the mean and covariance functions. Assume that the existing evaluation results are , then the updated mean and covariance functions are:
[0086]
[0087]
[0088] in, ,in, is the covariance matrix, is the variance of the observation noise, is the identity matrix.
[0089] In the embodiment of the present application, a dynamic adversarial training framework is used to train the recognition model (recognition models under various physical attacks and a general recognition model), and the adversarial sample generation and detection model are optimized in real time by dynamically adapting to environmental changes during the training process. Its loss function consists of three parts:
[0090] The dynamic adversarial training strategy is used to train the physical attack type detection model, and the total loss function during training is set to:
[0091]
[0092] in, represents the basic loss function for the main task, such as the standard loss for object detection or recognition tasks, represents the robustness loss of adversarial training, represents the adaptive loss in a dynamic environment, , They are , The weights are used to balance the priorities of tasks, robustness, and adaptability.
[0093] Among them, the standard loss for target detection or recognition tasks can be cross entropy loss or mean square error loss, such as:
[0094] or
[0095] in, is the predicted value, is the true label. represents the cross entropy loss function, represents the mean square error loss function.
[0096] represents the robustness loss for adversarial training , which is used to enhance the performance of the model on adversarial samples. Assume that the adversarial sample is , and its corresponding label is , then the robustness loss can be defined as:
[0097]
[0098] Adaptive loss in dynamic environments , which is used to guide the model's adaptability in different scenarios. Assume that the environmental parameters are , the adaptive loss can be defined as:
[0099]
[0100] in, is the model in the environment parameter The predicted value under is the corresponding true label.
[0101] In one embodiment, the physical attack type detection model constructed in step 3 of the present application is specifically:
[0102] To ensure that drones can respond to various physical attacks in real time during actual missions, this application designs a physical attack detection model and implements an adaptive defense mechanism based on the detection results. The detection model calculates whether there is an attack in the current environment through a conditional probability formula and activates corresponding defense measures based on the detection results.
[0103] According to the Bayesian formula, the conditional probability formula for attack detection is as follows: Represents the various data collected by sensor n (corresponding to a data modality):
[0104]
[0105] When the posterior probability is greater than or equal to a specified threshold ε, an attack is considered to have occurred and corresponding defensive measures are taken.
[0106] That is, in the embodiment of the present application, the posterior probability of each physical attack type is first calculated, and the posterior probability greater than or equal to the threshold ε is selected, and then the detection result of the physical attack detection is obtained based on the physical attack type corresponding to the maximum value. If all the posterior probabilities currently calculated are less than the threshold ε, it is considered that no specific physical attack type is detected, and the target recognition process is implemented based on the general model.
[0107] That is, in the embodiment of the present application, in the multimodal data fusion, the conditional probability Indicates that under certain physical attack assumptions (a certain type of physical attack), some modal data was observed Calculating these conditional probabilities usually involves the following steps:
[0108] (1) Data collection: First, data from different sensors needs to be collected (to obtain data of different modalities). These data should cover various possible attack scenarios.
[0109] (2) Feature extraction: Extract useful features from the raw data. These features should be able to represent the key information of the data and be helpful in identifying attacks. Feature extraction can be achieved based on neural networks.
[0110] (3) Model training: Use machine learning or deep learning models to train data. The goal of the model is to learn In the case of various modal data The probability distribution of .
[0111] (4) Probability estimation: During the training process, the model will learn the conditional probability This is usually achieved through the output layer of the model. For example, in classification problems, the softmax function of the output layer can give the probability of each category.
[0112] (5) Verification and adjustment: Verify the accuracy of the model through methods such as cross-validation, and adjust model parameters as needed to improve performance.
[0113] (6) Bayesian updating: In the Bayesian framework, we can use Bayes’ theorem to update the prior probability and combine new evidence to calculate the posterior probability, thereby continuously optimizing the estimate of the conditional probability.
[0114] In one embodiment, the method and device for adaptively sensing and defending drones based on dynamic adversarial training provided in the embodiment of the present application include:
[0115] (1) Quantify different physical environment factors and conduct physical attack modeling, including physical environment factors such as lighting changes, perspective changes, weather changes, and obstacles. Adjust the weight parameters through experiments and data analysis. to control the influence of each physical factor.
[0116] (2) Generate dynamic adversarial samples using GAN: Generate dynamic adversarial samples using generative adversarial networks (GANs). GANs include generators and the discriminator ;in is a random noise vector sampled from the prior distribution; the discriminator Used to distinguish real samples from generated samples.
[0117] (3) Use multimodal data fusion to establish a physical attack type detection model and use a dynamic adversarial training framework for training. That is, based on the total loss function Implement training for physical attack type detection models. It is also possible to simultaneously implement target recognition models (recognition models for different physical attack types and fine-tuning of general recognition models. The network structures of each recognition model can be set to be the same, such as a target recognition network based on a convolutional neural network, etc., which is used to implement target recognition and positioning of collected data in specific scenarios of this application through transfer training). During training, the generated adversarial samples are input into the model for training to optimize the recognition and detection performance of the model in different physical environments.
[0118] (4) During the training process, the Bayesian adaptive optimization method is used to adjust the training parameters;
[0119] The objective function of the Bayesian adaptive optimization method is defined as: ;
[0120] Use Gaussian process to model the target function, mean function Initialized to 0, covariance function Choose the squared exponential kernel function: ;
[0121] Calculate the expected improvement (EI): ;
[0122] Choose the parameter combination that maximizes the expected improvement: ;
[0123] In each iteration, choose Perform adversarial training and evaluate the value of the objective function The new evaluation results are fed back into the Gaussian process to update the mean and covariance functions.
[0124] (6) Judge the attack based on the calculated posterior probability and take corresponding defensive measures:
[0125] The conditional probability of attack detection is calculated using the Bayesian formula:
[0126]
[0127] When the posterior probability is greater than the threshold ε, the detection result is obtained based on the maximum posterior probability of the four physical attack types, and the corresponding defense mechanism is activated, such as adjusting the sensor weight, switching the recognition mode, and starting the emergency plan. In practical applications, the UAV system monitors environmental changes in real time and dynamically adjusts the defense strategy according to the detection results to ensure robustness and security in complex environments.
[0128] Through the above steps, the UAV adaptive perception and defense method based on dynamic adversarial training provided in the embodiment of the present application can realize dynamic adversarial training and real-time defense in a variety of physical environments, significantly improving the robustness and safety of the UAV.
[0129] Exemplarily, the adaptive adversarial training under changing lighting conditions in the embodiment of the present application is as follows: when the drone is performing a mission, the lighting conditions may change continuously, such as changes in the angle of sunlight, the transition between cloudy and sunny days, and even different light intensities at night and during the day. Such changes in lighting will interfere with the drone's perception system, causing errors in the drone's identification and positioning of targets. This embodiment introduces dynamic simulation of lighting conditions and corresponding adaptive training to ensure that the drone system can adapt to drastic changes in lighting. The specific implementation process includes:
[0130] 1) Lighting simulation: During the training process, the lighting change model is used to generate adversarial samples under different lighting conditions to simulate the scenarios that drones may encounter in various lighting environments. For example, different lighting conditions such as highlights, backlights, and shadows can be created by adjusting the angle and brightness of the light source.
[0131] 2) Dynamically adjust training parameters: During the training process, the system will detect the illumination parameters of the sample in real time and adjust the training adversarial parameters according to the current illumination conditions. For example, when the illumination changes significantly, the model will increase the illumination compensation coefficient to ensure that the illumination effect generated by the adversarial sample is closer to the real scene.
[0132] 3) Model adaptive training: The generated illumination adversarial samples are input into the model for training to optimize the model’s recognition and detection performance under illumination changes. Through continuous adaptive training, the drone perception system can enhance its ability to adapt to changing illumination environments and significantly improve recognition accuracy.
[0133] Exemplarily, the multimodal fusion defense in low-visibility weather of the embodiment of the present application is specifically embodied as follows: In actual applications, drones sometimes face low-visibility weather such as fog, rain and snow, which will affect the perception effect of their visual sensors and lead to recognition and navigation errors. This embodiment improves the robustness of the drone system under adverse weather conditions by fusing data from multiple sensors. Its specific implementation process includes:
[0134] 1) Multimodal data acquisition: In low-visibility weather, drones use visual sensors and lidar to acquire data in different modalities. For example, in a foggy environment, the image data from the visual sensor may be blurry, but the lidar can penetrate the haze and provide clear depth information.
[0135] 2) Data fusion and processing: Using Bayesian reasoning methods, visual data and lidar data are fused to generate a more accurate environmental model. Specifically, when detecting obstacles, the fuzzy features of visual data are processed together with the depth data of lidar to identify more accurate obstacle locations.
[0136] 3) Dynamic training and optimization: During the training phase, the system generates a variety of low-visibility adversarial samples, including blurred images and clear depth data, and dynamically optimizes the model on this basis, so that it can effectively identify obstacles in the environment even under low-visibility conditions.
[0137] Through this embodiment, the UAV system can maintain good perception capabilities in severe weather such as heavy fog, rain and snow, and improves the robustness and stability in low visibility scenarios.
[0138] Exemplarily, the embodiment of the present application is embodied in the dynamic adaptation and adaptive optimization of multiple scenarios: when the drone performs tasks in a complex environment, it may encounter a variety of dynamically changing scenarios, such as fast-moving targets, areas blocked by obstacles, and even man-made traps. In order to meet the challenges of these changing scenarios, this embodiment improves the defense and resilience of the drone system through dynamic adaptation and adaptive optimization of multiple scenarios. The specific implementation process includes:
[0139] 1) Diversified scene simulation: During the training process, a variety of complex scenes are simulated, including occluded targets, fast-moving objects, malicious obstacles, etc. Through adversarial sample generation technology, realistic and varied adversarial samples are generated to improve the robustness of the model in different scenarios.
[0140] 2) Real-time parameter adjustment: In actual applications, the UAV system will dynamically adjust the model's weight parameters according to the current environmental characteristics. For example, when encountering occlusion, the system will increase the weight of the lidar sensor to compensate for the shortcomings of the visual sensor; in fast-moving scenes, the system will accelerate the frame rate processing to ensure that the target can be tracked in real time.
[0141] 3) Model Adaptive Optimization: Through dynamic adversarial training of training samples in different scenarios, the model will learn how to adapt to various environmental changes and gradually improve its perception and defense capabilities in complex scenarios. This dynamic adaptive optimization mechanism enables the drone system to maintain a high level of robustness and responsiveness when facing complex environments that it has never seen before.
[0142] 4) Scene detection and response: When the UAV system is actually running, it monitors the changes in the current scene through sensor data and uses the previous adaptive training results to select the appropriate response strategy. For example, when the system detects an obstacle blocking the view, it can quickly switch to the lidar-dominated recognition mode to ensure accurate positioning in the blocked environment.
[0143] Through this embodiment, the UAV system has the adaptive defense and robust detection capabilities in a variety of scenarios, which significantly improves the multi-scenario response effect of the UAV.
[0144] In an exemplary embodiment, the embodiment of the present application also provides an electronic device, which may include: a memory, a processor, and a computer program stored in the memory and executable on the processor; when the processor executes the program, a method for optimizing the extension of the battery life of an electric vehicle provided in the above embodiment is implemented.
[0145] Specifically, Figure 2 As shown, the electronic device includes:
[0146] A processor, used to execute a computer program stored in the memory to implement a method for optimizing the extension of the battery life of an electric vehicle provided in the above embodiment;
[0147] A communication interface for communication between the memory and the processor;
[0148] Memory is used to store computer programs that can be run on the processor.
[0149] The memory may include high-speed random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage. If the memory, processor and communication interface are implemented independently, the communication interface, memory and processor can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0150] Optionally, in a specific implementation, if the memory, processor and communication interface are integrated on a chip, the memory, processor and communication interface can communicate with each other through an internal interface. The processor may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0151] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0152] Any process or method description described in a flowchart or otherwise in this specification may be understood to represent a module, fragment or portion of code that includes one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.
[0153] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0154] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. The UAV adaptive perception and defense method based on dynamic adversarial training is characterized by: The following steps are involved: Step 1: Quantify different physical environment factors and conduct physical attack modeling; Step 2: Based on the established physical attack model, a generative adversarial network is used to generate dynamic adversarial samples; Step 3: Establish a physical attack type detection model based on multimodal data fusion; Step 4: Perform physical attack type detection based on the established attack type model detection. If a specific physical attack type is detected, target identification and positioning are performed based on the target identification model corresponding to the physical attack type. Otherwise, target recognition and localization are performed based on the general target recognition model.
2. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: Physical environment factors include: lighting, viewing angle, weather, and obstructions.
3. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 2, characterized in that: The physical attack model is as follows: ; in, Represents the illumination change function represents the viewing angle change function, represents the weather change function, represents the obstacle occlusion function; , , , Represent the impact factors of the four functions respectively.
4. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: The physical attack type detection model is used to output the posterior probability of each physical attack under multimodal data fusion.
5. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: In step 4, the physical attack type detection based on the established attack type model detection includes: Based on the attack type model detection, the posterior probability of each physical attack type is calculated respectively; The posterior probabilities that are greater than or equal to the specified threshold are selected, and then the specific physical attack type is detected based on the physical attack type corresponding to the maximum value; if all posterior probabilities are less than the specified threshold, it means that the specific physical attack type is not detected.
6. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: In step 2, during the training of the generative adversarial network, the generated adversarial examples satisfy the physical constraints: ,in, Represents the generated adversarial sample The distribution of features in the physical world, Represents the characteristic distribution of real samples in the physical world, Indicates the preset threshold.
7. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: In step 3, the Bayesian reasoning method is used to perform multimodal data fusion.
8. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 1, characterized in that: The dynamic adversarial training strategy is used to train the physical attack type detection model, and the total loss function during training is set to: ; in, represents the recognition loss of the target recognition model, represents the robustness loss of adversarial training, represents the adaptive loss in a dynamic environment, , They are , The weight of .
9. The method for adaptively sensing and defending unmanned aerial vehicles based on dynamic adversarial training according to claim 8, characterized in that: The recognition loss of the target recognition model is set to cross loss or mean square error loss.
10. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to execute the method for adaptive perception and defense of unmanned aerial vehicles based on dynamic adversarial training as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Multi-stage network defense method and system based on signal game
CN118827214A
Data security dynamic protection method based on artificial intelligence
CN119382949A
Cited By
Defense method for robust enhanced intelligent system based on diffusion model and adversarial training
CN121527480A