Multi-modal GNSS deception detection method based on dynamic weighting
By adopting multimodal input and dynamic weighted feature extraction methods in GNSS spoof detection, the problems of limited detection effects and high computing resource requirements in the prior art are solved, and spoofed signal detection with high accuracy in complex environments is realized, and system security and reliability are enhanced.
Patent Information
- Application Number
- CN202510466747.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
The existing GNSS spoof detection methods have problems such as limited detection effect, inability to fully capture the characteristics of spoofed signals, and high computing resource requirements, especially in complex and changeable spoofed scenarios.
The multimodal GNSS spoof detection method based on dynamic weighting is adopted to improve the detection ability of dynamic spoof signals through multimodal input, space-time alignment preprocessing, lightweight dual-channel feature extraction and dynamic weight generation.
It significantly improves the accuracy of detection in complex environments, enhances the security and reliability of the system, and provides a more efficient and secure solution for GNSS applications.
Smart Images

Figure CN119986710A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of GNSS spoofing detection, and in particular to a multi-modal GNSS spoofing detection method based on dynamic weighting. Background Art
[0002] Global Navigation Satellite System (GNSS) signals are vulnerable to various spoofing attacks, such as signal forwarding, replay, and forgery. These spoofing attacks can seriously interfere with the normal operation of GNSS receivers, causing errors or even failures in positioning, navigation, and timing functions, thus posing a threat to the safety and stable operation of related fields.
[0003] At present, there are two main types of methods for GNSS spoofing detection. The first type is the traditional signal processing method, which is based on correlation function analysis, such as using signal quality monitoring (SQM) indicators, carrier-to-noise ratio, etc. for detection. However, this type of method relies on artificially designed features. For complex and changeable spoofing attack modes, its feature design is difficult and difficult to fully cover, so the detection effect is limited.
[0004] The second category is deep learning methods, which mainly use models such as convolutional neural networks (CNN) or Transformer for feature extraction and detection. However, existing deep learning methods have some obvious defects. First, most of them are single-modal processing, only processing one-dimensional time series or two-dimensional correlation functions, ignoring the complementarity between multimodal data, and unable to fully explore the information contained in different types of data, making it impossible for the detection model to fully capture the characteristics of deception signals, thereby reducing the accuracy and reliability of detection. Second, static weights are used in the feature fusion process, and the importance of features cannot be dynamically adjusted according to the real-time signal quality and changes in deception scenarios. It is difficult to adapt to complex and changeable deception scenarios, resulting in reduced detection performance in some special cases. Third, the traditional Transformer model has a large number of parameters, high computational complexity, and high demand for computing resources, resulting in slow inference speed and difficulty in effective deployment on embedded devices with high real-time requirements. Summary of the invention
[0005] The present invention aims to solve at least one of the technical problems existing in the related art. To this end, the present invention provides a multimodal GNSS spoofing detection method based on dynamic weighting, which significantly improves the detection capability of dynamic spoofing signals through multimodal input, spatiotemporal alignment preprocessing, lightweight dual-channel feature extraction and dynamic weight generation, significantly improves the accuracy of detection in complex environments, enhances the security and reliability of the system, and provides a more efficient and secure solution for the application of GNSS.
[0006] The present invention provides a multi-modal GNSS spoofing detection method based on dynamic weighting, comprising: S1: obtaining a one-dimensional SQM time series and a two-dimensional correlation function, and preprocessing the one-dimensional SQM time series and the two-dimensional correlation function to obtain a standardized one-dimensional SQM time series and a standardized two-dimensional correlation function; S2: extract features from the normalized two-dimensional correlation function through the Transformer channel to obtain global features; extract features from the normalized two-dimensional correlation function through the CNN channel to obtain local features; S3: Extract the time characteristics of the one-dimensional SQM time series through LSTM to obtain the Transformer channel dynamic weight matrix; extract the channel characteristics of the one-dimensional SQM time series through the squeeze and excitation network to obtain the CNN channel dynamic weight matrix; S4: Multiply the global features by the dynamic weight matrix of the Transformer channel to obtain the Transformer channel features, multiply the local features by the dynamic weight matrix of the CNN channel to obtain the CNN channel features, and perform feature fusion on the Transformer channel features and the CNN channel features to obtain fused features; S5: Perform global average pooling on the fused features and map them into deception probabilities through a fully connected network; S6: Detect deception based on the deception probability and the probability threshold.
[0007] Furthermore, step S1 includes: S11: obtaining a one-dimensional SQM time series by acquiring real-time measurement values of a GNSS receiver, where the real-time measurement values include carrier-to-noise ratio, code phase error, phase jitter, and multipath index; S12: by searching for the phase with the strongest correlation between the local code and the received signal in the GNSS receiver, the code phase is obtained, the frequency offset of the received signal is adjusted by Doppler frequency compensation, and the Doppler frequency is obtained. A two-dimensional correlation function is constructed with the code phase as the horizontal axis, the Doppler frequency as the vertical axis, and the correlation value as the pixel value; S13: Select the minimum time step of the one-dimensional SQM time series and the two-dimensional correlation function, and align the one-dimensional SQM time series and the two-dimensional correlation function in the time dimension through the minimum time step; S14: normalizing the aligned one-dimensional SQM time series to obtain a standardized one-dimensional SQM time series, and normalizing the aligned two-dimensional correlation function to obtain a standardized two-dimensional correlation function.
[0008] Furthermore, the Transformer channel is used to extract features from the standardized two-dimensional correlation function, and the global features obtained include: S211: Extract features of the standardized two-dimensional correlation function through a multi-head self-attention mechanism to obtain multi-head attention features; S212: retaining the order of the standardized two-dimensional correlation function through sinusoidal position coding to obtain position coding information; S213: Add the multi-head attention features and position encoding information to obtain the global features.
[0009] Furthermore, the standardized two-dimensional correlation function is subjected to feature extraction through the CNN channel, and the local features obtained include: S221: construct a residual block, where the residual block includes a 3×3 convolution layer, a batch normalization layer, and an activation function layer; S222: extracting local features of the normalized two-dimensional correlation function through a residual block.
[0010] Furthermore, step S3 includes: S31: Convert the standardized one-dimensional SQM time series into a high-dimensional feature vector through a one-dimensional convolutional layer; S32: Use LSTM to capture the temporal dynamic features of the high-dimensional feature vector to obtain the dynamic weight matrix, and use bilinear interpolation to adjust the dimension of the dynamic weight matrix to obtain the dynamic weight matrix of the Transformer channel; S33: Extract the channel features of the high-dimensional feature vector through the squeezing and excitation network, and obtain the CNN channel dynamic weight matrix. The calculation expression is: in, is the CNN channel attention weight, is a nonlinear activation function, is the second fully connected layer, Connect symbols for the order of operations, is a linear activation function, is the first fully connected layer, is the global average pooling function, is a high-dimensional feature vector.
[0011] Furthermore, in step S5, Perform global average pooling on the fused features to obtain the fused feature vector. in, is the fusion feature vector, To fuse the features time step, Row, No. The value of the column, H is the length, W is the width; Mapping the fused feature vector to the deception probability through a fully connected network; in, is the probability of cheating, is a nonlinear activation function, is the first weight matrix, is the second weight matrix, is a linear activation function, is the first bias term, is the second bias term, is the transpose of the matrix.
[0012] Furthermore, in step S6, If the deception probability is greater than or equal to the probability threshold, the current signal is a deception signal; If the deception probability is less than the probability threshold, the current signal is a true signal.
[0013] Furthermore, the deception probability of consecutive time steps is moved and averaged by the time series smoothing method to obtain the smoothed deception probability; If multiple consecutive smoothed deception probabilities are greater than or equal to the probability threshold, an alarm is triggered and the current signal is a deception signal; otherwise, the current judgment result is maintained.
[0014] Furthermore, the probability threshold selection conditions include false alarm rate, false negative rate and environmental parameters; Balance the false alarm rate and missed alarm rate through cross-validation or ROC curve to obtain the optimal probability threshold of false alarm rate and missed alarm rate. According to the optimal probability thresholds of false alarm rate and false negative rate and environmental parameters, the probability threshold is dynamically selected through linear regression or gating mechanism.
[0015] Furthermore, the false alarm rate is the probability that a real signal is misjudged as a spoofed signal, and the false alarm rate is the probability that a spoofed signal is misjudged as a real signal.
[0016] The above one or more technical solutions in the embodiments of the present invention have at least one of the following technical effects: The present invention significantly improves the detection capability of dynamic spoofing signals through multimodal input, spatiotemporal alignment preprocessing, lightweight dual-channel feature extraction and dynamic weight generation, significantly improves the accuracy of detection in complex environments, enhances the security and reliability of the system, and provides a more efficient and secure solution for GNSS applications.
[0017] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 It is a flow chart of a multi-modal GNSS spoofing detection method based on dynamic weighting provided by the present invention.
[0020] Figure 2 It is a comparison chart of detection accuracy between the present invention and the existing method under different signal-to-noise ratios. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical scheme and advantages of the present invention clearer, the technical scheme in the present invention will be clearly and completely described below. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present invention. The following embodiments are used to illustrate the present invention, but cannot be used to limit the scope of the present invention.
[0022] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiment of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0023] Combine the following Figure 1 to Figure 2 A multi-modal GNSS spoofing detection method based on dynamic weighting of the present invention is described.
[0024] like Figure 1 As shown, a multi-modal GNSS spoofing detection method based on dynamic weighting includes: S1: obtaining a one-dimensional SQM time series and a two-dimensional correlation function, and preprocessing the one-dimensional SQM time series and the two-dimensional correlation function to obtain a standardized one-dimensional SQM time series and a standardized two-dimensional correlation function; Use multi-correlators to generate one-dimensional SQM time series and two-dimensional correlation functions; S11: Obtain a one-dimensional SQM time series by acquiring real-time measurement values of the GNSS receiver, wherein the real-time measurement values include carrier-to-noise ratio, code phase error, phase jitter, and multipath index; the time step of the one-dimensional SQM time series is , the dimension is .
[0025] In some specific embodiments of the present invention, the one-dimensional SQM time series consists of 1000 time points, and the sampling rate is 100 Hz, that is, one sample is output every 10 ms.
[0026] S12: by searching for the phase with the strongest correlation between the local code and the received signal in the GNSS receiver, the code phase is obtained, the frequency offset of the received signal is adjusted by Doppler frequency compensation, and the Doppler frequency is obtained. A two-dimensional correlation function is constructed with the code phase as the horizontal axis, the Doppler frequency as the vertical axis, and the correlation value as the pixel value; The two-dimensional correlation function is the cross-correlation result between the local code and the received signal in the GNSS receiver. It reflects the matching degree of the signal in terms of code phase and Doppler frequency and is presented in the form of a two-dimensional heat map.
[0027] In some specific embodiments of the present invention, the local code is slid within a certain range (such as ±2 chips) to calculate the correlation value between the local code and the received signal. By continuously changing the phase of the local code, the position with the strongest correlation with the received signal is found to obtain the code phase; Due to the relative motion between the satellite and the receiver, the frequency of the received signal will shift. Therefore, it is necessary to adjust the frequency offset of the received signal to compensate for the influence of the Doppler effect. The frequency offset of the received signal is adjusted through Doppler frequency compensation to obtain the Doppler frequency.
[0028] With code phase as the horizontal axis, Doppler frequency as the vertical axis, and correlation value as pixel value, a The matrix of is the length, is the width, The time step of the two-dimensional correlation function is , the spatial dimension is , the number of channels is C, and the dimension is .
[0029] In some specific embodiments of the present invention, is 41×41, .
[0030] The correlation function of the real signal usually presents a unimodal symmetrical distribution, with the main peak corresponding to the code phase and Doppler of the real satellite signal; while the deceptive signal will cause the correlation function to have multiple peaks, offsets or distortions, for example, forwarding deception will form a bimodal structure.
[0031] S13: Select the minimum time step of the one-dimensional SQM time series and the two-dimensional correlation function, and align the one-dimensional SQM time series and the two-dimensional correlation function in the time dimension through the minimum time step; In order to ensure that the one-dimensional SQM time series and the two-dimensional correlation function are synchronized in the time dimension, the minimum time step of the two is selected. in, is the minimum time step, is the time step of the one-dimensional SQM time series, is the time step of the two-dimensional correlation function, To find the minimum function.
[0032] In some specific embodiments of the present invention, if the time step of the one-dimensional SQM time series is 1000 and the time step of the two-dimensional correlation function is 800, then This ensures that the two types of data correspond in time in subsequent processing, avoiding information mismatch problems caused by time inconsistency.
[0033] S14: normalizing the aligned one-dimensional SQM time series to obtain a standardized one-dimensional SQM time series, and normalizing the aligned two-dimensional correlation function to obtain a standardized two-dimensional correlation function.
[0034] S141: Normalize the aligned one-dimensional SQM time series to obtain a standardized one-dimensional SQM time series. The calculation expression is: in, For the time steps of the normalized one-dimensional SQM time series, For the One-dimensional SQM time series with time steps, is the mean of the one-dimensional SQM time series, is the standard deviation of the one-dimensional SQM time series.
[0035] Through standardization, the influence of dimension can be eliminated, making the data have a uniform distribution, which is convenient for subsequent model learning.
[0036] S142: normalize the aligned two-dimensional correlation function to obtain a standardized two-dimensional correlation function, and the calculation expression is: in, For the time step, Row, No. The normalized two-dimensional correlation function of the columns, For the time step, Row, No. The two-dimensional correlation function of the columns, is the minimum value of the two-dimensional correlation function, is the maximum value of the two-dimensional correlation function.
[0037] Normalization compresses pixel values to the range of [0,1], avoiding the problem of numerical overflow, and also helps to improve the training efficiency and stability of the model.
[0038] S2: extract features from the normalized two-dimensional correlation function through the Transformer channel to obtain global features; extract features from the normalized two-dimensional correlation function through the CNN channel to obtain local features; The Transformer channel is used to extract features from the standardized two-dimensional correlation function, and the global features obtained include: S211: The standardized two-dimensional correlation function is feature extracted through the multi-head self-attention mechanism to obtain the multi-head attention feature; the calculation expression of the multi-head attention feature is: in, Multi-head attention features, is the query matrix, is the key matrix, is the value matrix, is the first attention head, For the second attention head, For the A head of attention, is the concatenation function, is a learnable weight matrix used to linearly transform the concatenated multi-head attention results and map them back to the original feature dimension. The calculation expression is: in, is the query matrix of the mth attention head, is the key matrix of the mth attention head, is the value matrix of the mth attention head, is the dimension of the key, is the transpose of the matrix, is the normalized activation function.
[0039] In some specific embodiments of the present invention, , .
[0040] S212: retaining the order of the standardized two-dimensional correlation function through sinusoidal position coding to obtain position coding information; The position encoding calculation expression is: in, For the Time step The position encoding of the dimension feature, For the Time step The position encoding of the dimension feature, is the dimension index, is the dimension of the model.
[0041] In some specific embodiments of the present invention, .
[0042] S213: Add the multi-head attention features and position encoding information to obtain the global features.
[0043] The standardized two-dimensional correlation function is subjected to feature extraction through the CNN channel, and the local features obtained include: S221: construct a residual block, where the residual block includes a 3×3 convolution layer, a batch normalization layer, and an activation function layer; in, is the residual block, is a standardized two-dimensional correlation function, ReLU (Rectified LinearUnit) is a linear activation function, is a 3×3 convolutional layer, Connect symbols for the order of operations, (BatchNormalization) is the batch normalization operation; The use of batch normalization and linear activation functions helps improve the training effect and stability of the model. It is used to speed up the convergence of the model and improve the training stability. The linear activation function is used to introduce linear operations. stride 1, padding 1, It means that a 3×3 convolution operation is performed first, followed by a batch normalization operation, and then another 3×3 convolution operation.
[0044] S222: extracting local features of the normalized two-dimensional correlation function through a residual block.
[0045] S3: Extract the time characteristics of the standard one-dimensional SQM time series through LSTM to obtain the Transformer channel dynamic weight matrix; extract the channel characteristics of the standard one-dimensional SQM time series through the squeeze and excitation network to obtain the CNN channel dynamic weight matrix; S31: The standardized one-dimensional SQM time series is converted into a high-dimensional feature vector through a one-dimensional convolutional layer; the calculation expression is: in, is a high-dimensional feature vector, is a one-dimensional convolutional layer, To standardize the one-dimensional SQM time series, The kernel size is 3 and the output dimension is 128.
[0046] S32: Use LSTM to capture the temporal dynamic features of the high-dimensional feature vector to obtain the dynamic weight matrix, and use bilinear interpolation to adjust the dimension of the dynamic weight matrix to obtain the dynamic weight matrix of the Transformer channel; S33: Extract the channel features of the high-dimensional feature vector through the Squeeze-and-Excitation Networks (SE-Net) to obtain the CNN channel dynamic weight matrix. The calculation expression is: in, is the CNN channel attention weight, is a nonlinear activation function, is the second fully connected layer, Connect symbols for the order of operations, is a linear activation function, is the first fully connected layer, is the global average pooling function, is a high-dimensional feature vector, For dimensionality reduction to 32, Used to restore to channel number C.
[0047] SE-Net can automatically learn the importance of different channels and thus assign appropriate weights to the features of CNN channels.
[0048] S4: Multiply the global features by the dynamic weight matrix of the Transformer channel to obtain the Transformer channel features, multiply the local features by the dynamic weight matrix of the CNN channel to obtain the CNN channel features, and perform feature fusion on the Transformer channel features and the CNN channel features to obtain fused features; Multiply the global feature and the dynamic weight matrix of the Transformer channel to obtain the Transformer channel feature. The calculation expression is: in, is the Transformer channel feature, is a global feature, is the dynamic weight matrix of the Transformer channel; Multiply the local features and the CNN channel dynamic weight matrix to obtain the CNN channel features. The calculation expression is: in, is the CNN channel feature, is a local feature, is the dynamic weight matrix of the CNN channel; The Transformer channel features and CNN channel features are fused to obtain fused features. The calculation expression is: in, For fusion features; Through this weighted fusion approach, dynamic adjustments can be made based on the importance of features in different channels, thereby enhancing the model's ability to perceive deceptive signals.
[0049] S5: Perform global average pooling on the fused features and map them into deception probabilities through a fully connected network; Perform global average pooling on the fused features to obtain the fused feature vector. in, is the fusion feature vector, To fusion feature time step, Row, No. The value of the column; H is the length, W is the width, Mapping the fused feature vector to the deception probability through a fully connected network; in, is the probability of cheating, is a nonlinear activation function, is the first weight matrix, is the second weight matrix, is a linear activation function, is the first bias term, is the second bias term, is the transpose of the matrix.
[0050] S6. detecting deception according to a deception probability and a probability threshold; The probability threshold selection conditions include false positive rate (FPR), false negative rate (FNR) and environmental parameters; The false alarm rate is the probability that a real signal is mistakenly judged as a spoofed signal, and the false alarm rate is the probability that a spoofed signal is missed as a real signal.
[0051] Balance the false alarm rate and missed alarm rate through cross-validation or ROC curve (Receiver Operating Characteristic Curve) to obtain the optimal probability threshold of false alarm rate and missed alarm rate; According to the changes in the real-time signal environment, such as the noise level of the signal, reliability requirements, etc., the probability threshold is adjusted dynamically. Specifically, in a high-noise environment, in order to reduce missed reports, the threshold is appropriately lowered; in scenarios with high reliability requirements, in order to reduce the false alarm rate, the threshold is increased. To achieve this dynamic adjustment, environmental parameters (such as carrier-to-noise ratio) are introduced as auxiliary inputs, and the probability threshold is dynamically selected through linear regression or gating mechanisms.
[0052] If the deception probability is greater than or equal to the probability threshold, the current signal is a deception signal; If the deception probability is less than the probability threshold, the current signal is a true signal.
[0053] In order to suppress instantaneous noise interference and avoid single misjudgment, the output probability is post-processed and optimized. The deception probability of consecutive time steps is averaged by the time series smoothing method to obtain the smoothed deception probability. by is the window size, for the time step and before The probability of each time step is averaged to obtain the smoothed probability. The calculation expression is: To smooth the cheating probability, For the The probability of cheating in steps.
[0054] If the smoothed probabilities of multiple consecutive time steps (such as 3) exceed the threshold, an alarm is triggered and it is determined that there is a deceptive signal; otherwise, the current judgment result is maintained.
[0055] If multiple consecutive smoothed deception probabilities are greater than or equal to the probability threshold, an alarm is triggered and the current signal is a deception signal; otherwise, the current judgment result is maintained.
[0056] The present invention significantly improves the detection capability of dynamic spoofing signals through multimodal input, spatiotemporal alignment preprocessing, lightweight dual-channel feature extraction and dynamic weight generation, significantly improves the accuracy of detection in complex environments, enhances the security and reliability of the system, and provides a more efficient and secure solution for GNSS applications.
[0057] Example: Deception detection for vehicle navigation, data collection: GNSS receiver outputs 100 sets of SQM data per second, and the baseband processor generates a correlation function every 10ms. Data collection lasts for 24 hours, covering various scenarios such as urban roads, highways, and tunnels.
[0058] Real-time reasoning: The collected data is preprocessed and input into the dual-channel network. According to the characteristics of the SQM sequence and related functions, the weights are dynamically adjusted for feature fusion and deception detection.
[0059] Decision output: When the detection probability of three consecutive frames exceeds the set threshold, an alarm is triggered and the inertial navigation system is switched.
[0060] The deception detection accuracy of vehicle navigation in different scenarios is shown in Table 1.
[0061] Table 1 Deception detection accuracy of vehicle navigation in different scenarios Detection delay: In urban road scenarios, the average detection delay is 18ms; in highway scenarios, the average detection delay is 15ms; in tunnel entrance scenarios, the average detection delay is 20ms.
[0062] The method of the present invention, traditional CNN and pure Transformer are used to detect deception of vehicle navigation, and the performance comparison results are shown in Table 2.
[0063] Table 2 Performance comparison of the proposed method, traditional CNN and pure Transformer It can be seen from Table 2 that compared with the pure Transformer model, the model size, inference delay time, false alarm rate and false negative rate of the method of the present invention are significantly reduced.
[0064] In order to verify the anti-interference ability of the present invention in different noise environments, detection experiments under different signal-to-noise ratios were carried out. In the experiment, Gaussian white noise was artificially added to simulate different signal-to-noise ratio environments. The experimental data are shown in Figure 2As shown, the accuracy of the present invention is 95.3% at -20dB, while that of the pure Transformer model is only 82.1%. The present invention can still maintain a high detection accuracy in a low signal-to-noise ratio environment, and has significant advantages over the pure Transformer model.
[0065] The present invention significantly improves the anti-noise capability through multi-modal fusion and dynamic weighting, and adapts to complex electromagnetic environments.
[0066] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A multi-modal GNSS spoofing detection method based on dynamic weighting, characterized in that: include: S1: obtaining a one-dimensional SQM time series and a two-dimensional correlation function, and preprocessing the one-dimensional SQM time series and the two-dimensional correlation function to obtain a standardized one-dimensional SQM time series and a standardized two-dimensional correlation function; S2: extract features from the normalized two-dimensional correlation function through the Transformer channel to obtain global features; extract features from the normalized two-dimensional correlation function through the CNN channel to obtain local features; S3: Extract the time characteristics of the standardized one-dimensional SQM time series through LSTM to obtain the Transformer channel dynamic weight matrix; extract the channel characteristics of the standardized one-dimensional SQM time series through the squeeze and excitation network to obtain the CNN channel dynamic weight matrix; S4: Multiply the global features by the dynamic weight matrix of the Transformer channel to obtain the Transformer channel features, multiply the local features by the dynamic weight matrix of the CNN channel to obtain the CNN channel features, and perform feature fusion on the Transformer channel features and the CNN channel features to obtain fused features; S5: Perform global average pooling on the fused features and map them into deception probabilities through a fully connected network; S6: Detect deception based on the deception probability and the probability threshold.
2. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: The S1 step includes: S11: obtaining a one-dimensional SQM time series by acquiring real-time measurement values of a GNSS receiver, wherein the real-time measurement values include a carrier-to-noise ratio, a code phase error, a phase jitter, and a multipath index; S12: by searching for the phase with the strongest correlation between the local code and the received signal in the GNSS receiver, the code phase is obtained, the frequency offset of the received signal is adjusted by Doppler frequency compensation, and the Doppler frequency is obtained. A two-dimensional correlation function is constructed with the code phase as the horizontal axis, the Doppler frequency as the vertical axis, and the correlation value as the pixel value; S13: Select the minimum time step of the one-dimensional SQM time series and the two-dimensional correlation function, and align the one-dimensional SQM time series and the two-dimensional correlation function in the time dimension through the minimum time step; S14: normalizing the aligned one-dimensional SQM time series to obtain a standardized one-dimensional SQM time series, and normalizing the aligned two-dimensional correlation function to obtain a standardized two-dimensional correlation function.
3. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: The Transformer channel is used to extract features from the standardized two-dimensional correlation function, and the global features obtained include: S211: Extract features of the standardized two-dimensional correlation function through a multi-head self-attention mechanism to obtain multi-head attention features; S212: retaining the order of the standardized two-dimensional correlation function through sinusoidal position coding to obtain position coding information; S213: Add the multi-head attention features and position encoding information to obtain the global features.
4. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: The standardized two-dimensional correlation function is subjected to feature extraction through the CNN channel, and the local features obtained include: S221: construct a residual block, where the residual block includes a 3×3 convolution layer, a batch normalization layer, and an activation function layer; S222: extracting local features of the normalized two-dimensional correlation function through a residual block.
5. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: The S3 steps include: S31: Convert the standardized one-dimensional SQM time series into a high-dimensional feature vector through a one-dimensional convolutional layer; S32: Use LSTM to capture the temporal dynamic features of the high-dimensional feature vector to obtain the dynamic weight matrix, and use bilinear interpolation to adjust the dimension of the dynamic weight matrix to obtain the Transformer channel dynamic weight matrix; S33: Extract the channel features of the high-dimensional feature vector through the squeezing and excitation network, and obtain the CNN channel dynamic weight matrix. The calculation expression is: in, is the CNN channel attention weight, is a nonlinear activation function, is the second fully connected layer, Connect symbols for the order of operations, is a linear activation function, is the first fully connected layer, is the global average pooling function, is a high-dimensional feature vector.
6. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: In step S5, Perform global average pooling on the fused features to obtain the fused feature vector. in, is the fusion feature vector, To fuse the features time step, Row, No. The value of the column; H is the length, W is the width, Mapping the fused feature vector to the deception probability through a fully connected network; in, is the probability of cheating, is a nonlinear activation function, is the first weight matrix, is the second weight matrix, is a linear activation function, is the first bias term, is the second bias term, is the transpose of the matrix.
7. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 1, characterized in that: In step S6, If the deception probability is greater than or equal to the probability threshold, the current signal is a deception signal; If the deception probability is less than the probability threshold, the current signal is a true signal.
8. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 7, characterized in that: The deception probability of consecutive time steps is averaged by the time series smoothing method to obtain the smoothed deception probability; If multiple consecutive smoothed deception probabilities are greater than or equal to the probability threshold, an alarm is triggered and the current signal is a deception signal; otherwise, the current judgment result is maintained.
9. The multi-modal GNSS spoofing detection method based on dynamic weighting according to claim 7, characterized in that: The probability threshold selection conditions include false alarm rate, missed alarm rate and environmental parameters; Balance the false alarm rate and missed alarm rate through cross-validation or ROC curve to obtain the optimal probability threshold of false alarm rate and missed alarm rate. According to the optimal probability thresholds of false alarm rate and false negative rate and environmental parameters, the probability threshold is dynamically selected through linear regression or gating mechanism.
10. According to the multi-modal GNSS spoofing detection method based on dynamic weighting as described in claim 9, the false alarm rate is the probability that a real signal is misjudged as a spoofing signal, and the missed alarm rate is the probability that a spoofing signal is missed as a real signal.
Citation Information
Patent Citations
GNSS satellite navigation spoofing attack state cognition method and device and medium
CN118642132A
GNSS deception jamming detection method and system based on LSTM
CN119716921A
Forecasting of subject-related attributes using generative machine-learning models
WO2025021719A1
Cited By
GNSS deception jamming detection method and device, equipment and storage medium
CN120178273A
Unmanned aerial vehicle GPS deception detection method based on federal learning
CN120722393A
GNSS deception detection method, device and equipment based on LSTM-Transformer model and medium
CN121679627A