Drone Adaptive Sensing and Defense Method and Device Based on Dynamic Adversarial Training

Through dynamic adversarial training and multimodal data fusion, the problem of insufficient adaptability of the drone defense system to physical environment attacks is solved, and high robustness and accurate target recognition in complex environments are achieved.

CN119939365BActive Publication Date: 2025-07-08UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510436087.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-08
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

The existing drone defense systems lack the ability to adapt to physical environment attacks and are unable to effectively deal with complex and changeable environmental challenges, resulting in insufficient robustness and security.

Method used

Using a method based on dynamic adversarial training, attack modeling is carried out by quantifying physical environment factors, dynamic adversarial samples are generated, and a physical attack type detection model is established to realize adversarial training and adaptive defense.

Benefits of technology

Significantly improve the robustness and defense effect of drones in diverse physical environments, can accurately identify and detect abnormal attacks in complex environments, and improve the accuracy of target recognition and positioning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939365B_ABST
    Figure CN119939365B_ABST
Patent Text Reader

Abstract

The present application discloses a method and device for adaptive perception and defense of unmanned aerial vehicles based on dynamic adversarial training, belonging to the technical field of unmanned aerial vehicle system security. The method of the present application includes: quantifying different physical environment factors and conducting physical attack modeling; based on the established physical attack model, using a generative adversarial network to generate dynamic adversarial samples; constructing a physical attack type detection model based on the method of multi-modal data fusion; conducting physical attack detection based on the constructed attack type model detection. If a specific physical attack type is detected, target recognition and positioning are performed based on the target recognition model corresponding to the physical attack type; otherwise, target recognition and positioning are performed based on a general target recognition model. The present application also discloses an electronic device based on this method. The present application can significantly improve the robustness of unmanned aerial vehicles in diverse physical environments, enabling the system to accurately identify and detect abnormal attacks in complex environments, thus achieving more accurate target recognition and positioning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of unmanned aerial vehicle (UAV) system security, and particularly to a method and device for UAV adaptive perception and defense based on dynamic adversarial training. Background Art

[0002] With the wide application of UAVs in high-risk scenarios such as reconnaissance, patrol, and emergency rescue, their security and robustness have become important research directions. However, the physical attacks faced by UAVs (such as malicious occlusion, camouflage, perspective shift, etc.) are diverse in real environments and are strongly affected by natural conditions and target positions. Traditional defense methods are mostly static solutions and cannot cope with the challenges brought by physical environment changes. Most existing defense systems are based on digital-domain adversarial samples and lack the ability to adapt to physical environment attacks. Therefore, there is an urgent need to develop an adversarial training method that can dynamically adapt to diverse environments to enhance the UAV's response ability in complex environments. Summary of the Invention

[0003] The invention objective of this application is to provide a method and device for UAV adaptive perception and defense based on dynamic adversarial training to significantly improve the robustness of UAV system perception and defense effect.

[0004] The first aspect of this application provides a method for UAV adaptive perception and defense based on dynamic adversarial training, which includes the following steps:

[0005] Step 1, quantifying different physical environment factors and performing physical attack modeling;

[0006] Step 2, based on the established physical attack model, using a generative adversarial network (GAN) to generate dynamic adversarial samples;

[0007] Step 3, establishing a physical attack type detection model based on the method of multi-modal data fusion;

[0008] Step 4, performing physical attack type detection based on the established attack type model detection. If a specific physical attack type is detected, target recognition and positioning are performed based on the target recognition model corresponding to the physical attack type; otherwise, target recognition and positioning are performed based on the general target recognition model.

[0009] Further, the physical environment factors include: light, perspective, weather, and obstacles.

[0010] Further, the physical attack type detection model is used to output the posterior probability of each physical attack under multi-modal data fusion.

[0011] Further, in step 4, performing physical attack type detection based on the established attack type model detection includes:

[0012] Based on the attack type model detection, calculate the posterior probability under each physical attack type respectively;

[0013] Select the posterior probabilities that are greater than or equal to the specified threshold, and then detect the specific physical attack type based on the physical attack type corresponding to the maximum value among them; if all posterior probabilities are less than the specified threshold, it means that no specific physical attack type is detected.

[0014] Further, in step 2, during the training process of the generative adversarial network, the generated adversarial samples satisfy the physical constraints: , where, represents the generated adversarial sample feature distribution in the physical world, represents the feature distribution of the real sample in the physical world, represents the preset threshold.

[0015] Further, in step 3, the Bayesian inference method is used for multi-modal data fusion.

[0016] Further, the training of the physical attack type detection model adopts a dynamic adversarial training strategy, and the total loss function during training is set as:

[0017] Ltotal = Ltask + λ1Lrobust + λ2Ladaptive

[0018] where, L task represents the recognition loss of the target recognition model, L robust represents the robustness loss of adversarial training, L adaptive represents the adaptive loss in the dynamic environment, are respectively the weights of the robustness loss L robust of adversarial training and the adaptive loss L adaptive in the dynamic environment, which are used to balance the priorities of tasks, robustness, and adaptability.

[0019] Further, the recognition loss of the target recognition model is set as cross loss or mean square error loss.

[0020] The second aspect of this application provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the program to perform the drone adaptive perception and defense method based on dynamic adversarial training as described in the above application of this application.

[0021] The technical solution provided by this application at least brings the following beneficial effects:

[0022] The solution proposed in this application enables the UAV system to have dynamic adaptability under physical world attacks such as light changes, weather interference, and perspective conversion. Through multi-modal information fusion, an adaptive adversarial training framework, and a real-time attack detection module, the system can significantly improve the robustness and defense effect of the UAV perception system.

[0023] Based on the adversarial training strategy adopted in this application, the robustness of the UAV in diverse physical environments can be significantly improved, enabling the system to accurately identify and detect abnormal attacks in complex environments, thus achieving more precise target recognition and positioning. This technology has broad application prospects in high-risk scenarios such as disaster monitoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The above and / or additional aspects and advantages of this application will become apparent and be readily understood from the following description of the embodiments in conjunction with the drawings, where:

[0025] Figure 1 is a flowchart of the UAV adaptive perception and defense method based on dynamic adversarial training provided by an embodiment of this application;

[0026] Figure 2 is a schematic structural diagram of an electronic device provided by an embodiment of the application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this application will be described in detail and completely in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described by referring to the drawings are exemplary and are intended to explain this application, and should not be construed as limiting this application.

[0028] In one embodiment, this application provides a UAV adaptive perception and defense method based on dynamic adversarial training to improve the robustness and security of the UAV system in complex and dynamic physical environments.

[0029] Participate Figure 1 , the UAV adaptive perception and defense method based on dynamic adversarial training provided by the embodiments of this application includes the following steps:

[0030] Step 1, quantify different physical environmental factors (such as light, perspective, weather, obstacles, etc.) and conduct physical attack modeling;

[0031] Step 2, based on the established physical attack model, use the generative adversarial network GAN to generate dynamic adversarial samples;

[0032] Step 3, construct a physical attack type detection model based on the multi-modal data fusion method;

[0033] Step 4: Based on the constructed attack type model detection, perform physical attack detection. If a specific physical attack type is detected, perform target recognition and positioning based on the target recognition model corresponding to the physical attack type; otherwise, perform target recognition and positioning based on the general target recognition model.

[0034] In one embodiment, physical attack modeling is the basic part of the entire technical solution. By establishing a mathematical model, different physical environmental factors (such as light, perspective, weather, obstacles, etc.) are quantified as the degree of influence on the UAV system to help the system simulate various real physical attack scenarios during the training phase.

[0035] Specifically, the physical attack model constructed in this application is specifically a multi-factor weighted model , which is used to describe the change impact of attack samples in the physical environment. Its formula is as follows:

[0036]

[0037] Among them, represents the data collected by the sensors carried by the UAV (such as visual data), represents the light change function, which is used to simulate the impact of light intensity, light source angle, etc. on target recognition. Its expression is:

[0038]

[0039] Among them, represents the initial light intensity (Base Intensity) of the light source, which is usually quantified as a constant; represents the incident angle between the light source and the target (expressed in radians); represents the distance from the light source to the target (unit: meter).

[0040] In the actual calculation process, the obtained light change value can be normalized by using the maximum and minimum values method.

[0041] represents the perspective change function, which is used to describe the interference brought by the change of the UAV camera angle to target recognition. Its expression is:

[0042]

[0043] Among them, represents the interference coefficient, which can be used to adjust the sensitivity of the model; represents the actual size of the target (for example, the width of the target); represents the incident angle between the light source and the target (expressed in radians). During the calculation of the perspective change function, It can be the pitch angle or the yaw angle. Represents the distance between the target and the camera (which can also be denoted as dtarget). Similarly, the perspective change value can be normalized using the maximum and minimum values method.

[0044] Represents the weather change function, which is used to simulate the interference of weather factors such as fog, rain, and snow on visual data. Its expression is:

[0045]

[0046] Among them, f0 represents the intensity of the original visual data (the intensity under the condition of no weather interference); Represents the coefficient of attenuation caused by weather factors (related to the weather type, and fog, rain, and snow will have different values); d’ represents the distance between the target and the camera (unit: meter); Represents the weather condition factor, which is used to characterize the enhancement degree of the impact of weather on vision (can be used to total the impacts of fog, rain, snow, etc.); Represents the intensity of the weather condition (such as the normalized value of the fog concentration, the rain intensity, etc., with a range between 0 and 1).

[0047] Represents the obstacle occlusion function, which is used to simulate the possible occlusion effect in the scene. Its expression is:

[0048]

[0049] Among them, Represents the effective area of the occluder (which can be regarded as the size or projected area of the obstacle); Represents the total effective area within the field of view of the target camera (which can be set according to the scene); Represents the attenuation coefficient, which is related to the nature of the occluder and other factors in the scene. dtarget represents the distance between the target and the camera (unit: meter).

[0050] 、 、 、 、 、 、 、 respectively represent the influence factors of the four functions, and can also be called the weight parameters of the physical attack model. By adjusting

[0051] Furthermore, based on the generated diverse attack samples, corresponding target recognition models can be trained for various physical attack types. In the embodiments of the present application, the physical attack types mainly include: physical light attacks, physical perspective attacks, physical weather attacks, and physical obstacle attacks.

[0052] In one embodiment, the adversarial sample generation (i.e., dynamic adversarial sample generation) in step 2 of the present application is specifically as follows:

[0053] Based on physical attack modeling, a generative adversarial network (GAN) is used to generate adversarial samples that meet the conditions of the physical world, ensuring that the samples have physical adaptability, that is, they can trigger attack effects in the actual environment. For example, when generating adversarial samples under changing light conditions, the performance of the samples under different light intensities can be controlled to meet the requirements of the actual scenario.

[0054] In the embodiments of the present application, the generator G and the discriminator D in the generative adversarial network can be adversarially trained through the following loss functions:

[0055]

[0056] Among them, represents the adversarial loss function, represents the expectation, represents the real samples of the distribution, represents the output of the discriminator D, represents a random noise vector sampled from a prior distribution (which can be a Gaussian distribution or a uniform distribution), represents the distribution that the random noise vector follows, represents the output of the generator.

[0057] During the training process, the generator G and the discriminator D are alternately optimized until the Nash equilibrium is reached, that is, the adversarial samples generated by the generator can deceive the discriminator to the greatest extent.

[0058] The generated adversarial samples meet the following physical constraint conditions to ensure that the samples are not only virtual data but also entities that can be visible and operable in the physical world:

[0059]

[0060] Among them, represents the feature distribution of the adversarial samples in the physical world, represents the feature distribution of the real data (i.e., the data collected by the sensor) in the physical world, represents a set threshold for ensuring the closeness of the adversarial samples to the actual physical world;

[0061] Among them, the feature distribution can be expressed by the following formula:

[0062]

[0063] Among them, , , and respectively represent the impacts of illumination change, perspective change, weather change, and obstacle occlusion on the adversarial samples . Through this physical constraint condition, it is ensured that the generated adversarial samples can effectively trigger misjudgments of the model in the real scenario, and the UAV system encounters more realistic physical attack scenarios during training.

[0064] In one embodiment, in step 3, the multi-modal data fusion is specifically as follows:

[0065] Multi-modal data fusion is an important means to improve the effectiveness of the defense system in the physical environment. The multi-modal data comes from different sensors, such as vision, lidar, infrared sensors, etc., and each data type can provide supplementary information in different attack scenarios.

[0066] In the embodiment of the present application, the Bayesian inference method is used for multi-modal data fusion, and the formula is as follows:

[0067]

[0068] Among them, represents multi-modal data fusion, represents the data sources of different modalities (such as vision, lidar, etc.). represents the modality identifier of the data, represents the number of modalities. In the present application, it is assumed that are conditionally independent. H represents the hypothesis condition of a specific physical attack, that is, corresponding to different physical attack types, represents the conditional probability of each modality data under the physical attack condition. This formula can judge and evaluate the type and characteristics of the specific physical attack suffered by the UAV by fusing multi-modal data.

[0069] In addition, the Bayesian adaptive optimization method is also introduced to continuously adjust the parameters of the adversarial training according to the actual situation during training to optimize the overall loss function . The objective function is defined as:

[0070]

[0071] Among them, is the parameter vector of the adversarial training, , where are the weights of the robustness loss Lrobust for adversarial training and the adaptive loss Ladaptive in a dynamic environment, respectively.

[0072] In this application, a Gaussian process is used to model the objective function :

[0073]

[0074] where represents the Gaussian process, the mean function is initialized to 0, and the covariance function is selected as the squared exponential kernel function:

[0075]

[0076] where represents the set scale parameter.

[0077] Expected improvement ( ) is used as the acquisition function to select the next parameter combination to be evaluated:

[0078]

[0079] where is the currently known optimal objective function value. The calculation formula for expected improvement is:

[0080]

[0081] where the parameter . and are the cumulative distribution function and probability density function of the standard normal distribution, respectively, represents the mean.

[0082] In each iteration, the parameter combination that maximizes the expected improvement is selected .

[0083]

[0084] Then adversarial training is performed under , and the value of the objective function is evaluated .

[0085] The new evaluation result is fed back into the Gaussian process to update the mean and covariance functions. Assuming the existing evaluation results are , the updated mean and covariance functions are:

[0086]

[0087]

[0088] wherein, , wherein, is the covariance matrix, is the variance of the observation noise, is the identity matrix.

[0089] In the embodiment of the present application, a dynamic adversarial training framework is adopted to train the recognition model (the recognition model under various physical attacks and a general recognition model), and by dynamically adapting to environmental changes during the training process, real-time optimization of the adversarial sample generation and detection model is achieved. Its loss function consists of three parts:

[0090] For the training of the physical attack type detection model, a dynamic adversarial training strategy is adopted, and the total loss function during training is set as:

[0091]

[0092] wherein, represents the basic loss function of the main task, such as the standard loss of the object detection or recognition task, represents the robustness loss of the adversarial training, represents the adaptive loss in the dynamic environment, , are respectively , the weights of, used to balance the priorities of the task, robustness, and adaptability.

[0093] Among them, the standard loss of the object detection or recognition task can select the cross-entropy loss or the mean square error loss, such as:

[0094] or

[0095] wherein, is the predicted value, is the true label. represents the cross-entropy loss function, represents the mean square error loss function.

[0096] represents the robustness loss of the adversarial training , used to enhance the performance of the model on adversarial samples. Assuming the adversarial sample is , and its corresponding label is , then the robustness loss can be defined as:

[0097]

[0098] Adaptive Loss in a Dynamic Environment , which is used to guide the model's adaptability in different scenarios. Assuming the environmental parameter is , the adaptive loss can be defined as:

[0099]

[0100] where is the predicted value of the model under the environmental parameter , and is the corresponding true label.

[0101] In one embodiment, the physical attack type detection model constructed in step 3 of the present application is specifically:

[0102] To ensure that the drone can respond to various physical attacks in real time during actual missions, the present application designs a physical attack detection model and executes an adaptive defense mechanism based on the detection results. This detection model calculates whether there is an attack in the current environment through the conditional probability formula and activates corresponding defense measures according to the detection results.

[0103] According to Bayes' formula, the conditional probability formula for attack detection is as follows, where represents various data collected by sensor n (corresponding to a data modality):

[0104]

[0105] When the posterior probability is greater than or equal to a specified threshold ε, it is considered that an attack has occurred and corresponding defense measures are taken.

[0106] That is, in the embodiment of the present application, first, the posterior probabilities under each physical attack type are calculated respectively, and the posterior probabilities greater than or equal to the threshold ε are selected. Then, based on the physical attack type corresponding to the maximum value among them, the detection result of physical attack detection is obtained. If all the currently calculated posterior probabilities are less than the threshold ε, it is considered that no specific physical attack type is detected, and during target recognition processing, it is implemented based on the general model.

[0107] That is, in the embodiment of the present application, in multi-modal data fusion, the conditional probability represents the probability of observing a certain modality of data (a certain physical attack type) under a specific physical attack hypothesis . Calculating these conditional probabilities usually involves the following steps:

[0108] (1) Data collection: First, data from different sensors need to be collected (to obtain different modalities of data), and this data should cover various possible attack scenarios.

[0109] (2) Feature extraction: Extract useful features from the original data. These features should be able to represent the key information of the data and be helpful for the identification of attacks. Feature extraction can be implemented based on neural networks.

[0110] (3) Model training: Use machine learning or deep learning models to train the data. The goal of the model is to learn the probability distribution of various modal data under a given attack hypothesis.

[0111] (4) Probability estimation: During the training process, the model will learn the conditional probability . This is usually achieved through the output layer of the model. For example, in a classification problem, the softmax function of the output layer can give the probability of each class.

[0112] (5) Verification and adjustment: Verify the accuracy of the model through methods such as cross-validation, and adjust the model parameters as needed to improve performance.

[0113] (6) Bayesian update: In the Bayesian framework, Bayes' theorem can be used to update the prior probability, combine new evidence to calculate the posterior probability, and thus continuously optimize the estimation of the conditional probability.

[0114] In one embodiment, the method and device for adaptive perception and defense of unmanned aerial vehicles based on dynamic adversarial training provided by the embodiments of the present application include:

[0115] (1) Quantify different physical environment factors and perform physical attack modeling. The physical environment factors included are: light change, perspective change, weather change, and obstacle occlusion. Through experiments and data analysis, adjust the value of the weight parameter to control the influence degree of each physical factor.

[0116] (2) Use GAN to generate dynamic adversarial samples: Adopt a generative adversarial network (GAN) to generate dynamic adversarial samples. GAN includes a generator and a discriminator ; where is a random noise vector sampled from a prior distribution; the discriminator is used to distinguish real samples and generated samples.

[0117] (3) Establish a physical attack type detection model using the method of multi-modal data fusion and train it using a dynamic adversarial training framework. That is, based on the total loss function Implement the training of the physical attack type detection model. It is also possible to synchronously implement the fine-tuning of the target recognition models (the recognition models for different physical attack types and the general recognition model). The network structures of each recognition model can be set to be the same, such as the target recognition network based on the convolutional neural network, etc., and through transfer learning, it is used to achieve the target recognition and positioning of the collected data in the specific scenario of this application). During training, by inputting the generated adversarial samples into the model for training, optimize the recognition and detection performance of the model in different physical environments.

[0118] (4) During the training process, use the Bayesian adaptive optimization method to adjust the training parameters;

[0119] The objective function of the Bayesian adaptive optimization method is defined as: ;

[0120] Use Gaussian process to model the objective function, and initialize the mean function to 0, and select the covariance function as the squared exponential kernel function: ;

[0121] Calculate the expected improvement (EI): ;

[0122] Select the parameter combination that maximizes the expected improvement: ;

[0123] In each iteration, select for adversarial training and evaluate the value of the objective function . Feed the new evaluation result back into the Gaussian process to update the mean and covariance functions.

[0124] (6) Based on the calculated posterior probability, judge the attack and take corresponding defense measures:

[0125] Use Bayes' formula to calculate the conditional probability of attack detection:

[0126]

[0127] When the posterior probability is greater than the threshold ε, obtain the detection result based on the maximum posterior probability among the four physical attack types, and activate the corresponding defense mechanism, such as adjusting the sensor weights, switching the recognition mode, starting the emergency plan, etc. In practical applications, the drone system monitors the environmental changes in real time and dynamically adjusts the defense strategy according to the detection results to ensure robustness and security in complex environments.

[0128] Through the above steps, the drone adaptive perception and defense method based on dynamic adversarial training provided by the embodiments of this application can achieve dynamic adversarial training and real-time defense in diverse physical environments, significantly improving the robustness and security of the drone.

[0129] Exemplarily, the adaptive adversarial training of the embodiments of the present application under changing lighting conditions is as follows: When the UAV is performing tasks, the lighting conditions may change continuously. For example, the change in the sunlight irradiation angle, the conversion between cloudy and sunny days, and even the different lighting intensities between night and day. Such changes in lighting will interfere with the UAV's perception system, resulting in errors in the UAV's recognition and positioning of targets. In this embodiment, by introducing the dynamic simulation of lighting conditions and corresponding adaptive training, it is ensured that the UAV system can adapt to drastic changes in lighting. The specific implementation process includes:

[0130] 1) Lighting simulation: During the training process, a lighting change model is used to generate adversarial samples under different lighting conditions to simulate the scenarios that the UAV may encounter in various lighting environments. For example, different lighting conditions such as highlight, backlight, and shadow can be created by adjusting parameters such as the angle and brightness of the light source.

[0131] 2) Dynamically adjust training parameters: During the training process, the system will detect the lighting parameters of the samples in real time and adjust the adversarial parameters of the training according to the current lighting conditions. For example, when the lighting changes significantly, the model will increase the lighting compensation coefficient to ensure that the lighting effect generated by the adversarial samples is closer to the real scene.

[0132] 3) Model adaptive training: The generated lighting adversarial samples are input into the model for training to optimize the recognition and detection performance of the model under lighting changes. Through continuous adaptive training, the UAV perception system can enhance its adaptability to changing lighting environments and significantly improve the recognition accuracy.

[0133] Exemplarily, the multi-modal fusion defense of the embodiments of the present application in low visibility weather is specifically embodied as follows: In practical applications, the UAV sometimes faces low visibility weather such as fog, rain, and snow, which will affect the perception effect of its visual sensors, resulting in recognition and navigation errors. In this embodiment, by fusing the data of multiple sensors, the robustness of the UAV system is improved under harsh weather conditions. The specific implementation process includes:

[0134] 1) Multi-modal data acquisition: When the UAV is in low visibility weather, it uses visual sensors and lidar to obtain data of different modalities. For example, in a foggy environment, the image data of the visual sensor may be blurred, but the lidar can penetrate the haze and provide clear depth information.

[0135] 2) Data fusion and processing: The Bayesian inference method is used to fuse the visual data and lidar data to generate a more accurate environmental model. Specifically, when detecting obstacles, the fuzzy features of the visual data and the depth data of the lidar are jointly processed to identify the more accurate positions of the obstacles.

[0136] 3) Dynamic training and optimization: During the training phase, the system generates various adversarial samples with low visibility, including blurred images and clear depth data, and dynamically optimizes the model based on these to enable it to effectively identify obstacles in the environment under low visibility conditions.

[0137] Through this embodiment, the UAV system can maintain good sensing capabilities in harsh weather such as heavy fog, rain, and snow, improving its robustness and stability in low visibility scenarios.

[0138] Exemplarily, the multi-scenario dynamic adaptation and adaptive optimization in the embodiments of the present application are manifested as follows: When the UAV performs tasks in a complex environment, it may encounter various dynamically changing scenarios, such as fast-moving targets, areas blocked by obstacles, and even artificially set traps. To address the challenges of these changing scenarios, this embodiment enhances the defense and response capabilities of the UAV system through multi-scenario dynamic adaptation and adaptive optimization. The specific implementation process includes:

[0139] 1) Scenario diversification simulation: During the training process, various complex scenarios are simulated, including occluded targets, fast-moving objects, maliciously set obstacles, etc. Through adversarial sample generation technology, realistic and diverse adversarial samples are generated to enhance the robustness of the model in different scenarios.

[0140] 2) Real-time parameter adjustment: In actual applications, the UAV system dynamically adjusts the weight parameters of the model according to the current environmental characteristics. For example, when encountering occlusion, the system increases the weight of the lidar sensor to compensate for the deficiencies of the visual sensor; in fast-moving scenarios, the system accelerates the frame rate processing to ensure real-time tracking of the target.

[0141] 3) Model adaptive optimization: Through dynamic adversarial training of training samples in different scenarios, the model learns how to adapt to various environmental changes and gradually enhances its perception and defense capabilities in complex scenarios. This dynamic adaptive optimization mechanism enables the UAV system to maintain a high level of robustness and response capabilities even when facing unseen complex environments.

[0142] 4) Scenario detection and response: When the UAV system is actually operating, it monitors the changes in the current scenario through sensor data and selects appropriate response strategies using the previous adaptive training results. For example, when the system detects an obstacle occlusion, it can quickly switch to a lidar-dominated recognition mode to ensure precise positioning in the occluded environment.

[0143] Through this embodiment, the UAV system has the ability of adaptive defense and robustness detection in diverse scenarios, significantly improving the multi-scenario response effect of the UAV.

[0144] In an exemplary embodiment, the embodiment of the present application further provides an electronic device, which may include: a memory, a processor, and a computer program stored on the memory and executable on the processor; when the processor executes the program, it implements an optimization method for extending the battery life of an electric vehicle provided in the above embodiment.

[0145] Specifically, as Figure 2 shown, the electronic device includes:

[0146] A processor for executing a computer program stored on the memory to implement an optimization method for extending the battery life of an electric vehicle provided in the above embodiment;

[0147] A communication interface for communication between the memory and the processor;

[0148] A memory for storing a computer program executable on the processor.

[0149] The memory may include a high-speed random access memory (Random Access Memory, abbreviated as RAM), and may also include a non-volatile memory (non-volatile memory, abbreviated as NVM), such as at least one disk memory. If the memory, the processor, and the communication interface are implemented independently, the communication interface, the memory, and the processor can be interconnected through a bus and communicate with each other. Among them, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.

[0150] Optionally, in a specific implementation, if the memory, the processor, and the communication interface are integrated on a chip, the memory, the processor, and the communication interface can communicate with each other through an internal interface. The processor may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiment of the present application.

[0151] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0152] Any process or method description shown in a flowchart or otherwise described in this specification can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logic function or process. The scope of the preferred embodiments of the present application includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the functions involved, rather than in the order shown or discussed. This should be understood by those skilled in the technical field to which the embodiments of the present application belong.

[0153] It should be understood that each part of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following technologies well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0154] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the application and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An adaptive perception and defense method for unmanned aerial vehicles based on dynamic adversarial training, characterized in that Including the following steps: Step 1, quantifying different physical environment factors and performing physical attack modeling; Step 2, based on the established physical attack model, using a generative adversarial network to generate dynamic adversarial samples; Step 3, establishing a physical attack type detection model based on the method of multi-modal data fusion; Step 4, performing physical attack type detection based on the established attack type model detection. If a specific physical attack type is detected, target recognition and positioning are performed based on the target recognition model corresponding to the physical attack type; Otherwise, target recognition and positioning are performed based on the general target recognition model; Among them, in Step 1, the physical environment factors include: light, perspective, weather, and obstacles. The physical attack model is specifically: ; Among them, represents the illumination change function represents the viewing angle change function, represents the weather change function, represents the obstacle occlusion function; and and and respectively represent the influence factors of the four functions; In Step 3, the Bayesian inference method is used for multi-modal data fusion: Among them, represents multimodal data fusion, represents the data sources of different modalities, represents the modality identifier of the data, represents the number of modalities; H represents the assumed conditions of a specific physical attack, that is, corresponding to different types of physical attacks, represents the conditional probability of each modality data under the condition of physical attack. This formula can judge and evaluate the type and characteristics of the specific physical attack suffered by the drone by fusing multimodal data.

2. The method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to claim 1, wherein The physical attack type detection model is used to output the posterior probability of each physical attack under multi-modal data fusion.

3. The method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to claim 1, wherein In Step 4, performing physical attack type detection based on the established attack type model detection includes: Calculating the posterior probability under each physical attack type respectively based on the attack type model detection; Selecting the posterior probability greater than or equal to the specified threshold, and then detecting the specific physical attack type based on the physical attack type corresponding to the maximum value among them; if all posterior probabilities are less than the specified threshold, it means that no specific physical attack type is detected.

4. The method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to claim 1, wherein In step 2, during the training process of the generative adversarial network, the generated adversarial samples satisfy the physical constraints: , where represents the feature distribution of the generated adversarial samples in the physical world, represents the feature distribution of the real samples in the physical world, represents a preset threshold.

5. The method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to claim 1, wherein In Step 3, the Bayesian inference method is used for multi-modal data fusion.

6. The method for UAV adaptive perception and defense based on dynamic adversarial training according to claim 1, characterized in that The dynamic adversarial training strategy is adopted for the training of the physical attack type detection model, and the total loss function during training is set as: ; Among them, represents the recognition loss of the target recognition model, represents the robustness loss of adversarial training, represents the adaptive loss in a dynamic environment, , are respectively , the weights of 7. The method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to claim 6, wherein The recognition loss of the target recognition model is set as cross loss or mean square error loss.

8. An electronic device, characterized in that, Including: A memory, a processor, and a computer program stored on the memory and executable on the processor. The processor executes the program to execute the method for adaptive perception and defense of an unmanned aerial vehicle based on dynamic adversarial training according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Multi-stage network defense method and system based on signal game

    CN118827214A

  • Data security dynamic protection method based on artificial intelligence

    CN119382949A