Anti-unmanned aerial vehicle detection method and system
By constructing environmental feature matrix and behavior topology diagram, combining game theory to construct dynamic threat vectors, and generating a multi-dimensional interference strategy set, the existing technology has solved the problem of insufficient defense measures when facing multi-objective, high-dynamic, low flight trajectory and hidden communication drones, and achieved accurate perception and interference of drone behavior.
Patent Information
- Application Number
- CN202510206578.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When facing drones with multi-objective, high dynamics, low flight trajectory and hidden communication, the defense measures have insufficient sensitivity, susceptibility to environmental interference, limited spectrum overlapping effects, and high physical interception accuracy and speed requirements.
Through wide-band cognitive radio, real-time scanning of target airspace, building an environmental feature matrix, extracting the physical layer fingerprint characteristics of the UAV communication protocol, generating protocol fingerprint vectors, activate group behavior analysis model, calculate the communication link tightness of the UAV cluster, constructing behavior topology maps, and combining motion parameters to build dynamic threat vectors to generate multi-dimensional interference strategy sets.
It realizes all-round and real-time perception of drone behavior in complex scenarios, identify potential threats and conducts precise interference, and improves the execution accuracy and efficiency of interference strategies.
Smart Images

Figure CN120034287A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of drone detection, and in particular to an anti-drone detection method and system thereof. Background Art
[0002] With the rapid development of drone technology, especially the popularity of low-cost drones, threats against drones have gradually become an important issue in various security fields. Drones are widely used in reconnaissance, transportation, and monitoring tasks, but they also bring certain security risks. Malicious drones may evade traditional defense measures through their covert communication channels, flexible flight paths, and intelligent behavior patterns.
[0003] At present, defense against drones mainly relies on traditional radar monitoring, radio frequency interference and physical interception technologies. However, these methods often have many shortcomings when facing multi-target, high-dynamic, low-flight-trajectory and covertly communicating drones. For example, traditional radars have low detection sensitivity for low-altitude or small drones and are easily affected by environmental interference; although radio frequency interference can shield some drone signals, it has limited effect when facing drones with spectrum overlap, frequency hopping or protocol encryption; although physical interception technology is effective, it has extremely high requirements on target capture accuracy and speed, and is prone to collateral damage. Summary of the invention
[0004] The present invention provides an anti-UAV detection method and a system thereof.
[0005] An anti-UAV detection method comprises the following steps:
[0006] S1, scans the target airspace in real time through wide-band cognitive radio and constructs an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient;
[0007] S2, based on the environmental feature matrix, performing dual-stream feature extraction, extracting the physical layer fingerprint features of the drone communication protocol, and generating a protocol fingerprint vector;
[0008] S3, activating the corresponding group behavior analysis model according to the protocol fingerprint vector, calculating the communication link density of the drone cluster through the topological potential energy algorithm, and constructing a behavior topology graph including leader nodes, relay nodes, and attack nodes;
[0009] S4, combining the behavior topology graph and the real-time motion parameters, using game theory to construct a dynamic threat vector, where the dynamic threat vector is synthesized by the threat values of all nodes in the target airspace:
[0010] Threat value T i =α·(node centrality) 2+β·(link hopping frequency)+γ·(encrypted payload entropy);
[0011] S5, generating a multi-dimensional interference strategy set according to the dynamic threat vector, including:
[0012] Implement protocol feature recurrence attacks on leader nodes;
[0013] Inject topology deception signals into relay nodes;
[0014] Implement Doppler frequency shift induction on the attacking node.
[0015] Optionally, the S1 specifically includes:
[0016] S11, configure a tunable filter bank to cover the 2.4 GHz to 6 GHz frequency band, divide it into N sub-bands with variable widths (N ≥ 64), and adopt an adaptive scanning strategy: when a suspicious signal is detected, start a dense scanning mode in the corresponding sub-band (the sampling rate is increased to 2 Gsps);
[0017] S12, signal feature extraction: perform the following parallel processing on the IQ data stream of each sub-band:
[0018] The power spectrum density of each sub-band is calculated by fast Fourier transform, and the channel occupancy C is calculated: Where T active is the duration that the power spectrum density exceeds the noise threshold of 110dBm, T total is the total observation time;
[0019] The Wigner-Ville time-frequency distribution is used to analyze the fuzzy characteristics of the signal and calculate the signal fuzzy entropy E1:
[0020] E1 = -∑P(t,f)logP(t,f), where P(t,f) is the time-frequency joint probability distribution;
[0021] The fading coefficient matrix F is extracted by multipath channel estimation: F = {f 1 ,f 2 ,...,f M},in Among them, h i is the impulse response of the ith path channel, f i is the fading coefficient of the ith path channel, h 0 is the impulse response of the reference channel, usually the straightest path;
[0022] S13, dynamic matrix construction: the characteristic parameters of each sub-frequency band are arranged in frequency order to generate a three-dimensional environmental characteristic matrix H.
[0023] Optionally, the environmental feature matrix is expressed as in:
[0024] The first dimension: N sub-band numbers;
[0025] The second dimension: three characteristic parameters: channel occupancy C, signal fuzzy entropy E1, and multipath fading coefficient F;
[0026] The third dimension: K continuous time windows (K ≥ 8, time window length 50ms).
[0027] Optionally, the S2 specifically includes:
[0028] S21, performing channel normalization processing on the input environment feature matrix H, and reconstructing the environment feature matrix into a two-dimensional feature map through a tensor folding operation Preserve the frequency band dimension and the time-feature joint dimension;
[0029] S22, dual-stream feature extraction: the two-dimensional feature map F is input into the spatial feature extraction stream and the temporal feature extraction stream in parallel:
[0030] The spatial feature extraction flow uses a dilated convolution layer group to extract cross-band correlation features with a multi-scale convolution kernel with a dilation factor d, and outputs a spatial feature vector
[0031] The time series feature extraction flow uses a gated recurrent unit chain to slide along the time window dimension to extract time-varying pattern features and output a time series feature vector
[0032] S23, feature fusion and compression: The spatial feature vector V s With the time series feature vector V t Input cross attention fusion; calculate V s V t The attention weight matrix Generate normalized attention distribution through Softmax function; perform feature weighted concatenation operation to obtain joint feature vector Using autoencoder to V l Perform dimension compression and output a 32-dimensional protocol fingerprint vector V p .
[0033] Optionally, the S2 further includes S24: fingerprint library comparison, the fingerprint library comparison includes:
[0034] Calculate V p Cosine similarity with the template vector in the pre-stored protocol fingerprint library;
[0035] When the maximum similarity exceeds the similarity threshold θ=0.85, the matching protocol type and confidence level are output;
[0036] If not matched, V p Store the new protocol feature library and update the protocol fingerprint library.
[0037] Optionally, the S3 specifically includes:
[0038] S31, according to the protocol fingerprint vector V p The protocol type identifier is used to load the corresponding group behavior analysis model from the pre-stored model library;
[0039] S32, topological potential energy calculation: extract the communication parameter set of each drone node in the target area, including:
[0040] Cross-node signal strength matrix
[0041] Communication time interval sequence T b =[Δt 1 ,Δt 2 ,...,Δt m ];
[0042] Packet Retransmission Rate Vector
[0043] Calculate the link density L between nodes ij ;
[0044] S33, role classification modeling: Construct a weighted directed graph G = (V, E, W), where V represents the set of nodes in the graph, node V represents each individual drone in the drone cluster, E represents the set of edges in the graph, representing the connection relationship between nodes, W is the edge weight matrix, representing the weight of the edge between nodes, and the edge weight W ij =L ij , calculate the topological characteristics of each node:
[0045] (1) Node centrality n represents the total number of nodes, j≠i means that j and i are different when summing, avoiding calculating the connection of node i itself;
[0046] (2) Betweenness centrality σ st represents the number of all shortest paths from node s to node t, σ st (i) represents the number of paths passing through node i among all the shortest paths from node s to node t;
[0047] (3) Eigenvector centrality Represents the adjacency matrix W and eigenvector of the computational graph The eigenvalue of the product of ;
[0048] The three-dimensional feature vector [C i ,Bi ,E i ] Input the pre-trained role classifier and output the node type label, which includes leader node, relay node and attack node;
[0049] S34, dynamic topology construction: Generates a behavioral topology graph based on node type labels, including leader nodes, relay nodes, and attack nodes.
[0050] Optionally, the S4 specifically includes:
[0051] S41, multi-source parameter fusion: extract the node centrality C of each node from the behavior topology graph i , betweenness centrality B i and role type labels; capture the UAV motion parameter set, including the three-dimensional velocity vector v, acceleration vector a, and heading angle deviation Δθ, monitor the communication link status, and count the jump frequency f of link topology changes per unit time h ;
[0052] S42, encrypted payload analysis: perform entropy analysis on the captured encrypted data packets and calculate the payload entropy value, including extracting the payload byte stream, converting each byte into an integer value of 0-255, calculating the Shannon entropy Q, and performing a sliding average of the entropy values of multiple consecutive data packets to obtain the encrypted payload entropy Q avg ;
[0053] S43, defines the strategy set of the defender and the attacker:
[0054] Defender strategy: {spectrum suppression intensity, interference resource allocation weight, response priority};
[0055] Attacker strategy: {topology reorganization period, communication encryption level, movement trajectory complexity};
[0056] Construct a double-matrix game model and generate a payoff matrix, including the defender's payoff function and the attacker's payoff function;
[0057] S44, solving the Nash equilibrium point through iterative virtual game, obtaining real-time weight coefficients α, β, γ, and normalizing the weights to satisfy: α+β+γ=1;
[0058] Calculate the threat value T of each node i , synthesize the threat values of all nodes in the target area into a dynamic threat vector T tatol .
[0059] Optionally, the S5 specifically includes:
[0060] S51, Threat Level Classification: Based on Threat Value T i Divided into three response intervals:
[0061] Level 1 Threat T i ≥0.7: marked as leader node;
[0062] Level 2 threat 0.4≤T i <0.7: marked as relay node;
[0063] Level 3 Threat T i <0.4: marked as attack node;
[0064] S52, interference strategy matching:
[0065] S521, implement protocol feature reproduction attack on the leader node: extract the physical layer parameter set of the corresponding protocol from the protocol fingerprint library, including carrier frequency, signal bandwidth and symbol period, generate a homologous interference signal through a direct digital frequency synthesizer (DDS), adopt a time slot interleaved transmission mode, and keep a 50% duty cycle overlap with the target signal;
[0066] S522, injecting a topology structure deception signal into the relay node: constructing a false topology control message, and transmitting the deception signal directionally through the MIMO beamforming array;
[0067] S523, implement Doppler frequency shift induction on the attacking node:
[0068] According to the horizontal and vertical coordinate components of the target velocity and the heading angle deviation, the predicted angle θ of the target motion direction is calculated. p ;
[0069] Predict angle θ based on target motion direction p The Doppler frequency shift signal Δf is generated by using the center frequency of the navigation signal, and a frequency agile transmitter is used to jump in a 10ms period.
[0070] Optionally, the false topology control message includes a forged neighbor node list, a false link quality indicator, and a virtual routing table entry.
[0071] An anti-UAV detection system, used to implement the above anti-detection method, includes the following modules:
[0072] Environmental perception module: Scans the target airspace in real time through wide-band cognitive radio to build an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient;
[0073] Protocol identification module: taking the environmental feature matrix as input, extracting the physical layer fingerprint features of the drone communication protocol, and generating a protocol fingerprint vector;
[0074] Group behavior analysis module: activates the corresponding group behavior analysis model according to the protocol fingerprint vector, calculates the communication link density of the drone cluster through the topological potential energy algorithm, and constructs a behavior topology map;
[0075] Dynamic threat modeling module: combining the behavior topology map with the UAV motion parameters, and using game theory to construct a dynamic threat vector;
[0076] Intelligent interference decision module: Generates a multi-dimensional interference strategy set based on the dynamic threat vector, including implementing a protocol feature reproduction attack on the leader node, injecting topology structure deception signals into the relay node, and implementing Doppler frequency shift induction on the attack node.
[0077] Beneficial effects of the present invention:
[0078] The present invention, through a multi-dimensional dynamic threat perception and modeling mechanism, constructs an all-round and real-time updated threat vector based on the multi-source fusion of environmental perception, communication protocol characteristics, and group behavior analysis. It calculates the node threat value through a non-cooperative game model and accurately evaluates it in combination with spatiotemporal information, effectively identifies potential threats, and achieves precise interference with drone groups. It enhances the perception ability of drone behavior in complex scenarios and significantly improves the execution accuracy and efficiency of interference strategies.
[0079] The present invention introduces a classification and adaptive adjustment mechanism based on protocol fingerprint vectors. It uses deep learning technology to extract and fuse three-dimensional feature vectors, which can identify and classify different types of drone communication protocols, improve the accuracy of protocol fingerprint recognition, and is adaptable to deal with unknown or changing communication protocol types. When encountering a new protocol, it will adaptively adjust the interference strategy through online learning and feature library updates to provide protection for subsequent countermeasures.
[0080] The present invention effectively addresses the hidden topology evolution problem in drone swarm intelligence, solves the problem of physical layer feature extraction in encrypted communications, and copes with strategic-level confrontation during coordinated attacks by multiple drones. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only for the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0082] Figure 1 A schematic diagram of a method flow of an embodiment of the present invention;
[0083] Figure 2Schematic diagram of system module composition according to an embodiment of the present invention. DETAILED DESCRIPTION
[0084] The present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. At the same time, it is explained here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments, and those skilled in the art may also adopt other alternatives to implement some known technologies; and the accompanying drawings are only for more specific description of the embodiments, and are not intended to specifically limit the present invention.
[0085] It should be noted that the references to "one embodiment", "an embodiment", "an exemplary embodiment", "some embodiments" and the like in the specification indicate that the embodiments described may include specific features, structures or characteristics, but not every embodiment may include the specific features, structures or characteristics. In addition, when a specific feature, structure or characteristic is described in conjunction with an embodiment, it should be within the knowledge of a person skilled in the art to implement such feature, structure or characteristic in conjunction with other embodiments (whether or not explicitly described).
[0086] In general, a term can be understood, at least in part, from its use in context. For example, depending, at least in part, on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in the singular sense, or can be used to describe a combination of features, structures, or characteristics in the plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey an exclusive set of factors, but can instead, depending, at least in part, on the context, allow for the presence of other factors that are not necessarily explicitly described.
[0087] like Figure 1 As shown, an anti-UAV detection method comprises the following steps:
[0088] S1, dynamic environment perception: Scan the target airspace in real time through wide-band cognitive radio to build an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient;
[0089] S2, hidden protocol identification: Based on the environmental feature matrix, dual-stream feature extraction is performed to extract the physical layer fingerprint features of the drone communication protocol and generate a protocol fingerprint vector;
[0090] S3, group behavior analysis: according to the protocol fingerprint vector, the corresponding group behavior analysis model is activated, the communication link density of the drone cluster is calculated through the topological potential energy algorithm, and a behavior topology graph including leader nodes, relay nodes, and attack nodes is constructed;
[0091] S4, dynamic threat modeling: Combining the behavior topology map with real-time motion parameters, game theory is used to construct a dynamic threat vector, where the dynamic threat vector is synthesized by the threat values of all nodes in the target airspace:
[0092] Threat value T i =α·(node centrality) 2 +β·(link hopping frequency)+γ·(encrypted payload entropy);
[0093] S5, intelligent jamming decision-making: Generates a multi-dimensional jamming strategy set based on dynamic threat vectors, including:
[0094] Implement protocol feature recurrence attacks on leader nodes;
[0095] Inject topology deception signals into relay nodes;
[0096] Implement Doppler frequency shift induction on the attacking node.
[0097] S1 specifically includes:
[0098] S11, configure a tunable filter bank to cover the 2.4 GHz to 6 GHz frequency band, divide it into N sub-bands with variable widths (N ≥ 64), and adopt an adaptive scanning strategy: when a suspicious signal is detected, start a dense scanning mode in the corresponding sub-band (the sampling rate is increased to 2 Gsps);
[0099] S12, signal feature extraction: perform the following parallel processing on the IQ data stream of each sub-band:
[0100] The power spectrum density of each sub-band is calculated by fast Fourier transform, and the channel occupancy C is calculated: Where T active is the duration that the power spectrum density exceeds the noise threshold of 110dBm, T total is the total observation time;
[0101] The Wigner-Ville time-frequency distribution is used to analyze the fuzzy characteristics of the signal and calculate the signal fuzzy entropy E1:
[0102] E1 = -∑P(t,f)logP(t,f), where P(t,f) is the time-frequency joint probability distribution;
[0103] Among them, x(τ) is the time domain representation of the signal, t is time, f is frequency, P(t,f) represents the joint probability density of the signal at time t and frequency f, and the fuzzy entropy measures the degree of chaos of the signal in the time-frequency domain. The higher the entropy value, the more complex and irregular the signal is.
[0104] The fading coefficient matrix F is extracted by multipath channel estimation: F = {f 1 ,f 2 ,...,f M},in Among them, h iis the impulse response of the ith path channel, f i is the fading coefficient of the ith path channel, h 0 is the impulse response of the reference channel, usually the straightest path;
[0105] S13, dynamic matrix construction: the characteristic parameters of each sub-frequency band are arranged in frequency order to generate a three-dimensional environmental characteristic matrix H.
[0106] The environmental feature matrix is expressed as in:
[0107] The first dimension: N sub-band numbers;
[0108] The second dimension: three characteristic parameters: channel occupancy C, signal fuzzy entropy E1, and multipath fading coefficient F;
[0109] The third dimension: K continuous time windows (K ≥ 8, time window length 50ms);
[0110] The sliding window mechanism is used to update the matrix, updating the latest time window data and removing the oldest data every 20ms.
[0111] S2 specifically includes:
[0112] S21, perform channel normalization processing on the input environment feature matrix H, so that the three-channel data of channel occupancy rate, signal fuzzy entropy and multipath fading coefficient of each sub-band are standardized to the interval [0,1] respectively, and the environment feature matrix is reconstructed into a two-dimensional feature map through tensor folding operation Preserve the frequency band dimension and the time-feature joint dimension;
[0113] S22, dual-stream feature extraction: The two-dimensional feature map F is input into the spatial feature extraction stream and the temporal feature extraction stream in parallel:
[0114] The spatial feature extraction flow uses a dilated convolution layer group to extract cross-band correlation features with a multi-scale convolution kernel with a dilation factor d, and outputs a spatial feature vector
[0115] The time series feature extraction flow uses a gated recurrent unit chain to slide along the time window dimension to extract time-varying pattern features and output a time series feature vector
[0116] Specifically, the feature map Two streams are input in parallel: spatial feature extraction stream and temporal feature extraction stream.
[0117] 1. The spatial feature extraction flow uses a dilated convolution layer group with a convolution kernel expansion factor of d = 2 m {m=0,1,2} extracts cross-band correlation features, and the specific convolution layer is set to:
[0118] Among them, w d It is a dilated convolution kernel, usually of size k×k, where k is the convolution kernel size and d is the dilation factor, d=2 m {m=0,1,2}, represents the convolution features of different scales. After completing the convolution operation, the spatial feature vector is output Where 256 represents the extracted feature dimension: V s =Flatten(Conv d (F)), Flatten means flattening the convolution output into a one-dimensional vector.
[0119] 2. The time series feature extraction flow uses a gated recurrent unit (GRU) chain to extract time-varying pattern features along the time window dimension K. The specific calculation process is: V t =GRU(F), where represents the time series feature vector, 128 is the dimension of the output feature, and GRU(F) means that the GRU network processes the feature map F according to the time dimension to extract the time series change pattern.
[0120] S23, feature fusion and compression: The spatial feature vector V s With the time series feature vector V t Input cross attention fusion; calculate V s V t The attention weight matrix Generate normalized attention distribution through Softmax function; perform feature weighted concatenation operation to obtain joint feature vector Using autoencoder to V l Perform dimension compression and output a 32-dimensional protocol fingerprint vector V p ;
[0121] Attention weight calculation: Where “·” represents matrix multiplication, Indicates V t Softmax(·) means to perform soft maximization operation on each row to obtain the attention weight matrix.
[0122] Use attention weights to the feature vector V s and V t Perform weighted concatenation to obtain the joint feature vector V l =[V s ⊕(A·V t )], ⊕ represents vector concatenation operation, A·V t Represents the attention weight matrix A and the time series feature V tMultiply them together to get the weighted time series features.
[0123] S2 also includes S24: fingerprint library comparison, the fingerprint library comparison includes:
[0124] Calculate V p Cosine similarity with the template vector in the pre-stored protocol fingerprint library;
[0125] When the maximum similarity exceeds the similarity threshold θ=0.85, the matching protocol type and confidence level are output;
[0126] If not matched, V p Store the new protocol feature library and update the protocol fingerprint library.
[0127] For each template vector V in the fingerprint library template and the current fingerprint vector V p , calculate their cosine similarity:
[0128] Among them, V p ·V template represents the dot product of two vectors, ‖V p ‖ represents the vector V p The modulus (Euclidean norm), ‖V template ‖ represents the modulus of the template vector.
[0129] S3 specifically includes:
[0130] S31, according to the protocol fingerprint vector V p The protocol type identifier is used to load the corresponding group behavior analysis model from the pre-stored model library. The model includes topological potential energy calculation, role classification modeling, and dynamic topology construction;
[0131] S32, topological potential energy calculation: extract the communication parameter set of each drone node in the target area, including:
[0132] Cross-node signal strength matrix
[0133] Communication time interval sequence T b =[Δt 1 ,Δt 2 ,...,Δt m ];
[0134] Packet Retransmission Rate Vector
[0135] Calculate the link density L between nodes ij : Among them, L ij represents the link density between node i and node j, R ijrepresents the signal strength between node i and node j, R max represents the maximum signal strength, σ represents the time attenuation factor, Δt avg represents the average communication interval, Q ij represents the packet retransmission rate between node i and node j;
[0136] S33, role classification modeling: construct a weighted directed graph G = (V, E, W), where V represents the node set in the graph, representing all vertices in the graph. In the anti-UAV detection method, node V represents each individual UAV in the UAV cluster, E represents the edge set in the graph, representing the connection relationship between nodes. In the present invention, the edge represents the communication link or mutual relationship between UAVs, and W is the edge weight matrix, representing the weight of the edge between nodes. The edge weight W ij represents the link tightness between UAV i and UAV j, that is, the quality or strength of the communication between them, and the edge weight W ij =L ij , calculate the topological characteristics of each node:
[0137] (1) Node centrality n represents the total number of nodes, j≠i means that j is different from i when summing, avoiding calculating the connection of node i itself. The centrality of node i is calculated by summing and normalizing the edge weights with other nodes to represent the communication importance between the node and other nodes;
[0138] (2) Betweenness centrality σ st represents the number of all shortest paths from node s to node t, σ st (i) represents the number of paths passing through node i among all the shortest paths from node s to node t, and calculates the betweenness centrality of node i. By calculating the ratio of all the shortest paths passing through node i, it reflects the importance of node i as an information transmission medium in the graph;
[0139] (3) Eigenvector centrality Represents the adjacency matrix W and eigenvector of the computational graph The eigenvalue of the product of is used to measure the structural characteristics of the graph; calculate the eigenvector centrality of node i, based on the graph adjacency matrix W and the eigenvector The importance of the node in the graph is obtained by eigenvalue decomposition.
[0140] Ci measures the connection importance of a node (based on its connections with other nodes);
[0141] Bi measures the ability of a node to act as an information intermediary in the network;
[0142] Ei measures the structural importance of nodes (based on the eigenvector decomposition of the graph);
[0143] The three-dimensional feature vector [C i ,B i ,E i ] Input the pre-trained role classifier and output the node type label. The role classifier can automatically identify and classify the role type of the drone based on the input feature vector. The classifier is built based on the support vector machine. During the training process, the behavior characteristics of drones of different roles are annotated according to the labeled data set. According to the three-dimensional feature vector [C i ,B i ,E i ], the classifier learns the association between these features and different roles (leader node, relay node, attack node), and makes classification predictions based on the input three-dimensional feature vector. The classifier analyzes these feature vectors and outputs a node type label, which includes leader node, relay node and attack node;
[0144] S34, dynamic topology construction: Generate a behavioral topology graph based on node type labels, including leader nodes, relay nodes, and attack nodes, where:
[0145] (1) Leader node: red octagonal icon (C i >0.7 and E i >0.6);
[0146] (2) Relay node: blue rectangle (B i >0.5 and C i >0.4);
[0147] (3) Attack node: Yellow triangle mark (Q i >0.3 and E i <0.2);
[0148] Update topology connection weights and node layout every 200ms.
[0149] S4 specifically includes:
[0150] S41, multi-source parameter fusion: extract the node centrality C of each node from the behavior topology graph i , betweenness centrality B i and role type labels; and captures the drone motion parameter set, including the three-dimensional velocity vector v = [v x ,v y ,v z ], acceleration vector a and heading angle deviation Δθ, monitor the communication link status, and count the jump frequency f of link topology changes per unit time h ;
[0151] S42, encrypted payload analysis: perform entropy analysis on the captured encrypted data packets and calculate the payload entropy value, including extracting the payload byte stream, converting each byte into an integer value of 0-255, and calculating the Shannon entropy Q: Q = -∑p(b)log 2 p(b), where p(b) is the probability of occurrence of each byte value. The entropy values of multiple consecutive data packets are averaged to obtain the encrypted payload entropy Q avg ;
[0152] S43, defines the strategy set of the defender and the attacker:
[0153] Defender strategy: {spectrum suppression intensity, interference resource allocation weight, response priority};
[0154] Attacker strategy: {topology reorganization period, communication encryption level, movement trajectory complexity};
[0155] Construct a double-matrix game model and generate a payoff matrix, including the defender’s payoff function and the attacker’s payoff function:
[0156] The defender's payoff function is:
[0157] The attacker’s profit function: U attacker =-U defendr +λ·(a·v);
[0158] Among them, w 1 ,w 2 ,w 3 is the weight coefficient of the defender's profit function, λ is the weighting factor in the attacker's profit function, a is the acceleration of the drone, and v is the three-dimensional velocity vector of the drone;
[0159] S44, solve the Nash equilibrium point through iterative virtual game and obtain the real-time weight coefficients α, β, γ:
[0160] Normalize the weights to satisfy:
[0161] α+β+γ=1;
[0162] Calculate the threat value T of each node i :T i =α·(C i ) 2 +β·f h +γ·H avg , synthesize the threat values of all nodes in the target area into a dynamic threat vector T tatol :T tatol =[T 1 ,T 2 ,...,Tn ], appending timestamp and spatial coordinate information to generate a four-dimensional threat tensor.
[0163] S5 specifically includes:
[0164] S51, Threat Level Classification: Based on Threat Value T i Divided into three response intervals:
[0165] Level 1 Threat T i ≥0.7: marked as leader node;
[0166] Level 2 threat 0.4≤T i <0.7: marked as relay node;
[0167] Level 3 Threat T i <0.4: marked as attack node;
[0168] S52, interference strategy matching:
[0169] S521, implement a protocol feature recurrence attack on the leader node: extract the physical layer parameter set of the corresponding protocol from the protocol fingerprint library, including carrier frequency, signal bandwidth and symbol period, expressed as: {f c ,BW,Δt symbol}, where f c is the carrier frequency, BW is the signal bandwidth (set at 1.25 times the original bandwidth), Δt symbol It is the symbol period (jitter is controlled within ±5ns), and the co-source interference signal is generated by direct digital frequency synthesizer (DDS), with phase noise ≤-100dBc / Hz, using time slot interleaved transmission mode, and maintaining 50% duty cycle overlap with the target signal;
[0170] S522, injecting topology deception signals into relay nodes: constructing false topology control messages, transmitting deception signals directionally through MIMO beamforming arrays, with beam width ≤ 3°, and adjusting the transmission power according to the exponential backoff strategy: P tx =P 0 2 k1 , where P tx represents the transmission power of a single node, k1 is the number of consecutive last responses, P 0 =10mW;
[0171] S523, implement Doppler frequency shift induction on the attacking node:
[0172] According to the horizontal and vertical coordinate components of the target velocity and the heading angle deviation, the predicted angle θ of the target motion direction is calculated. p : Among them, v x and v yare the horizontal and vertical components of the target velocity, Δθ is the heading angle deviation;
[0173] Predict angle θ based on target motion direction p And the navigation signal center frequency, generate the Doppler frequency shift signal Δf: Where v is the target speed, f 0 is the center frequency of the navigation signal, c is the speed of light, θ 0 Represents the initial motion direction angle of the target, that is, the angle between the motion direction of the target (UAV or other equipment) at the initial moment and the reference coordinate system. It refers to the heading angle or initial velocity direction of the target. A frequency agile transmitter is used at f 0 The frequency changes within the range of ±2Δf with a period of 10ms. This frequency change is used to induce Doppler frequency shift of the attacking node, interfere with the communication frequency of the target, and force the target to be misjudged or fail.
[0174] The fake topology control message includes a forged neighbor node list (randomly generated 6-8 virtual node IDs), a fake link quality indicator (RSSI value is set to 120%-150% of the real value) and a virtual routing table entry (the lifetime TTL is set to twice the real value).
[0175] like Figure 2 As shown, an anti-UAV detection system, used to implement the above method, includes the following modules:
[0176] Environmental perception module: Scans the target airspace in real time through wide-band cognitive radio to build an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient;
[0177] Protocol identification module: taking the environmental feature matrix as input, extracting the physical layer fingerprint features of the drone communication protocol, and generating a protocol fingerprint vector;
[0178] Group behavior analysis module: activates the corresponding group behavior analysis model according to the protocol fingerprint vector, calculates the communication link density of the drone cluster through the topological potential energy algorithm, and constructs a behavior topology map;
[0179] Dynamic threat modeling module: combining the behavior topology map with the UAV motion parameters, and using game theory to construct a dynamic threat vector;
[0180] Intelligent interference decision module: Generates a multi-dimensional interference strategy set based on the dynamic threat vector, including implementing a protocol feature reproduction attack on the leader node, injecting topology structure deception signals into the relay node, and implementing Doppler frequency shift induction on the attack node.
[0181] The present invention covers any substitution, modification, equivalent method and scheme made on the essence and scope of the present invention. In order to make the public have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention, but those skilled in the art can fully understand the present invention without the description of these details. In addition, in order to avoid unnecessary confusion about the essence of the present invention, well-known methods, processes, procedures, components and circuits are not described in detail.
[0182] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. An anti-UAV detection method, characterized in that: The following steps are involved: S1, scans the target airspace in real time through wide-band cognitive radio and constructs an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient; S2, based on the environmental feature matrix, performing dual-stream feature extraction, extracting the physical layer fingerprint features of the drone communication protocol, and generating a protocol fingerprint vector; S3, activating the corresponding group behavior analysis model according to the protocol fingerprint vector, calculating the communication link density of the drone cluster through the topological potential energy algorithm, and constructing a behavior topology graph including leader nodes, relay nodes, and attack nodes; S4, combining the behavior topology graph and the real-time motion parameters, using game theory to construct a dynamic threat vector, where the dynamic threat vector is synthesized by the threat values of all nodes in the target airspace: Threat value T i =α·(node centrality) 2 +β·(link hopping frequency)+γ·(encrypted payload entropy); S5, generating a multi-dimensional interference strategy set according to the dynamic threat vector, including: Implement protocol feature recurrence attacks on leader nodes; Inject topology deception signals into relay nodes; Implement Doppler frequency shift induction on the attacking node.
2. The anti-UAV detection method according to claim 1, characterized in that: The S1 specifically includes: S11, configure a tunable filter bank to cover the 2.4 GHz to 6 GHz frequency band, divide it into N sub-bands with variable widths, and adopt an adaptive scanning strategy: when a suspicious signal is detected, start a dense scanning mode in the corresponding sub-band; S12, signal feature extraction: perform the following parallel processing on the IQ data stream of each sub-band: The power spectrum density of each sub-band is calculated by fast Fourier transform, and the channel occupancy C is calculated: Where T active is the duration that the power spectral density exceeds the noise threshold, T total is the total observation time; The Wigner-Ville time-frequency distribution is used to analyze the fuzzy characteristics of the signal and calculate the signal fuzzy entropy E1: E1 = -∑P(t,f)logP(t,f), where P(t,f) is the time-frequency joint probability distribution; The fading coefficient matrix F is extracted by multipath channel estimation: F = {f1, f2, ..., f M },in Among them, h i is the impulse response of the ith path channel, f i is the fading coefficient of the i-th path channel, h0 is the impulse response of the reference channel; S13, dynamic matrix construction: the characteristic parameters of each sub-frequency band are arranged in frequency order to generate a three-dimensional environmental characteristic matrix H.
3. The anti-UAV detection method according to claim 2, characterized in that: The environmental feature matrix is expressed as in: The first dimension: N sub-band numbers; The second dimension: three characteristic parameters: channel occupancy C, signal fuzzy entropy E1, and multipath fading coefficient F; The third dimension: K continuous time windows.
4. The anti-UAV detection method according to claim 2, characterized in that: The S2 specifically includes: S21, performing channel normalization processing on the input environment feature matrix H, and reconstructing the environment feature matrix into a two-dimensional feature map through a tensor folding operation Preserve the frequency band dimension and the time-feature joint dimension; S22, dual-stream feature extraction: the two-dimensional feature map F is input into the spatial feature extraction stream and the temporal feature extraction stream in parallel: The spatial feature extraction flow uses a dilated convolution layer group to extract cross-band correlation features with a multi-scale convolution kernel with a dilation factor d, and outputs a spatial feature vector The time series feature extraction flow uses a gated recurrent unit chain to slide along the time window dimension to extract time-varying pattern features and output a time series feature vector S23, feature fusion and compression: The spatial feature vector V s With the time series feature vector V t Input cross attention fusion; calculate V s V t The attention weight matrix Generate normalized attention distribution through Softmax function; perform feature weighted concatenation operation to obtain joint feature vector Using autoencoder to V l Perform dimension compression and output a 32-dimensional protocol fingerprint vector V p .
5. The anti-UAV detection method according to claim 4, characterized in that: The S2 also includes S24: fingerprint library comparison, the fingerprint library comparison includes: Calculate V p Cosine similarity with the template vector in the pre-stored protocol fingerprint library; When the maximum similarity exceeds the similarity threshold θ=0.85, the matching protocol type and confidence level are output; If not matched, V p Store in the new protocol feature library.
6. The anti-UAV detection method according to claim 4, characterized in that: The S3 specifically includes: S31, according to the protocol fingerprint vector V p The protocol type identifier is used to load the corresponding group behavior analysis model from the pre-stored model library; S32, topological potential energy calculation: extract the communication parameter set of each drone node in the target area, including: Cross-node signal strength matrix Communication time interval sequence T b =[Δt1,Δt2,...,Δt m ]; Packet Retransmission Rate Vector Calculate the link density L between nodes ij ; S33, role classification modeling: Construct a weighted directed graph G = (V, E, W), where V represents the set of nodes in the graph, node V represents each individual drone in the drone cluster, E represents the set of edges in the graph, representing the connection relationship between nodes, W is the edge weight matrix, representing the weight of the edge between nodes, and the edge weight W ij =L ij , calculate the topological characteristics of each node: (1) Node centrality n represents the total number of nodes, j≠i means that j and i are different when summing, avoiding calculating the connection of node i itself; (2) Betweenness centrality σ st represents the number of all shortest paths from node s to node t, σ st (i) represents the number of paths passing through node i among all the shortest paths from node s to node t; (3) Eigenvector centrality Represents the adjacency matrix W and eigenvector of the computational graph The eigenvalue of the product of ; The three-dimensional feature vector [C i ,B i ,E i ] Input the pre-trained role classifier and output the node type label, which includes leader node, relay node and attack node; S34, dynamic topology construction: Generates a behavioral topology graph based on node type labels, including leader nodes, relay nodes, and attack nodes.
7. The anti-UAV detection method according to claim 6, characterized in that: The S4 specifically includes: S41, multi-source parameter fusion: extract the node centrality C of each node from the behavior topology graph i , betweenness centrality B i and role type labels; capture the UAV motion parameter set, including the three-dimensional velocity vector v, acceleration vector a, and heading angle deviation Δθ, monitor the communication link status, and count the jump frequency f of link topology changes per unit time h ; S42, encrypted payload analysis: perform entropy analysis on the captured encrypted data packets and calculate the payload entropy value, including extracting the payload byte stream, converting each byte into an integer value of 0-255, calculating the Shannon entropy Q, and performing a sliding average of the entropy values of multiple consecutive data packets to obtain the encrypted payload entropy Q avg ; S43, defines the strategy set of the defender and the attacker: Defender strategy: {spectrum suppression intensity, interference resource allocation weight, response priority}; Attacker strategy: {topology reorganization period, communication encryption level, movement trajectory complexity}; Construct a double-matrix game model and generate a payoff matrix, including the defender's payoff function and the attacker's payoff function; S44, solving the Nash equilibrium point through iterative virtual game, obtaining real-time weight coefficients α, β, γ, and normalizing the weights to satisfy: α+β+γ=1; Calculate the threat value T of each node i , synthesize the threat values of all nodes in the target area into a dynamic threat vector T tatol .
8. The anti-UAV detection method according to claim 7, characterized in that: The S5 specifically includes: S51, Threat Level Classification: Based on Threat Value T i Divided into three response intervals: Level 1 Threat T i ≥0.7: marked as leader node; Level 2 threat 0.4≤T i <0.7: marked as relay node; Level 3 Threat T i <0.4: marked as attack node; S52, interference strategy matching: S521, implement a protocol feature recurrence attack on the leader node: extract the physical layer parameter set of the corresponding protocol from the protocol fingerprint library, including carrier frequency, signal bandwidth and symbol period, generate a homologous interference signal through a direct digital frequency synthesizer, adopt a time slot interleaved transmission mode, and maintain a 50% duty cycle overlap with the target signal; S522, injecting a topology structure deception signal into the relay node: constructing a false topology control message, and transmitting the deception signal directionally through the MIMO beamforming array; S523, implement Doppler frequency shift induction on the attacking node: According to the horizontal and vertical coordinate components of the target velocity and the heading angle deviation, the predicted angle θ of the target motion direction is calculated. p ; Predict angle θ based on target motion direction p The Doppler frequency shift signal Δf is generated by using the center frequency of the navigation signal, and a frequency agile transmitter is used to jump in a 10ms period.
9. The anti-UAV detection method according to claim 8, characterized in that: The false topology control message includes a forged neighbor node list, a false link quality indicator and a virtual routing table entry.
10. An anti-UAV detection system, used to implement an anti-UAV detection method according to any one of claims 1 to 9, characterized in that: Includes the following modules: Environmental perception module: Scans the target airspace in real time through wide-band cognitive radio to build an environmental feature matrix including channel occupancy, signal fuzzy entropy, and multipath fading coefficient; Protocol identification module: taking the environmental feature matrix as input, extracting the physical layer fingerprint features of the drone communication protocol, and generating a protocol fingerprint vector; Group behavior analysis module: activates the corresponding group behavior analysis model according to the protocol fingerprint vector, calculates the communication link density of the drone cluster through the topological potential energy algorithm, and constructs a behavior topology map; Dynamic threat modeling module: combining the behavior topology map with the UAV motion parameters, and using game theory to construct a dynamic threat vector; Intelligent interference decision module: Generates a multi-dimensional interference strategy set based on the dynamic threat vector, including implementing a protocol feature reproduction attack on the leader node, injecting topology structure deception signals into the relay node, and implementing Doppler frequency shift induction on the attack node.
Citation Information
Cited By
Distributed low-altitude target passive cooperative localization and threat evaluation system
CN120468827A
Multi-frequency omnidirectional unmanned aerial vehicle active defense system and method
CN120896667A
Multi-frequency omnidirectional unmanned aerial vehicle active defense system and method
CN120896667B
Intelligent communication signal interference system based on mobile signal transmission
CN121150871A
Intelligent generation method and device of unmanned aerial vehicle countering strategy
CN121256715A