Attack detection device and method for unmanned cluster system under false data injection attack
By using encryption modules and decryption modules in unmanned cluster systems, combining scalar multiplier and pseudo-random watermark signals, the Kullback-Leibler divergence between the system's real-time residual signal and the residual signal during normal operation is calculated, which solves the problem of false data injection attack detection and achieves a fast, flexible and low-energy-consuming attack detection effect.
Patent Information
- Application Number
- CN202510071544.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-16
Smart Images

Figure CN120074869A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to an attack detection device and method for an unmanned cluster system under false data injection attack. Background Art
[0002] According to the impact of network attacks on transmitted data, network attacks can be divided into two categories, namely, denial-of-service attacks and spoofing attacks. Among them, denial-of-service attacks disrupt the information interaction between the communication networks connecting sensors, actuators, and controllers by blocking or interfering with communication channels, thereby destroying the availability of data. Spoofing attacks can be further divided into false data injection attacks and replay attacks. False data injection attacks are cleverly designed by attackers based on system information and detector characteristics, and have a certain degree of concealment. In an unmanned cluster system, since multiple unmanned devices rely on sensor data and communication networks for cooperation and decision-making, these systems are vulnerable to false data injection threats. Therefore, false data injection attacks are highly destructive to unmanned cluster systems, which pose a huge challenge to the safe operation of unmanned cluster systems.
[0003] An unmanned cluster system usually includes unmanned aerial vehicles (UAVs), unmanned ground vehicles (UGVs), unmanned surface vehicles (USVs), etc. They execute complex tasks by sharing sensor data, location information, and instructions, such as environmental monitoring, search and rescue operations, and military missions. However, due to the high degree of automation and distributed structure of the unmanned cluster system, once a certain node is injected with false data, it may lead to misjudgment, decision-making errors, or abnormal execution of the entire system, thereby causing mission failure or system damage. For an unmanned cluster system, the feedback channel from a single agent's sensor to the controller and the forward channel from the controller to the controlled object transmit data through a communication network. The exposed network environment makes the transmitted information vulnerable to hijacking and even tampering by malicious attackers, thus affecting the stability and security of the network communication system. A successful attack will cause huge damage to the system, resulting in huge economic losses and even loss of life. Existing security protection measures mainly focus on communication encryption, access control, etc. Although they can prevent some network attacks to a certain extent, their defense effect against false data injection attacks is limited. False data injection attacks are characterized by strong concealment and high flexibility. Attackers can induce an unmanned cluster system to make wrong judgments by modifying or forging sensor data, and it is difficult to directly detect them through traditional means. In addition, false data injection may gradually penetrate the system in a short period of time, resulting in an imperceptible accumulation of errors, making the consequences of the attack more serious.
[0004] Attack detection aims to minimize the continuous impact of attacks on the system by promptly identifying the presence of attacks in the system and making timely adjustments to the system. A fast and accurate detection device is crucial for the secure operation of an unmanned cluster system. In this regard, some scholars have proposed a node capture attack detection method for unmanned clusters, which aims to detect and prevent node capture attacks at an early stage by monitoring the liveness of nodes and their collaborative decision-making mechanisms in an unmanned cluster, ensuring the security of the network. This method can implement the collaborative decision-making mechanism through neighbor node liveness monitoring. Each node independently conducts detection and reports abnormal nodes to the ground control station (GCS) through multi-hop routing. The GCS broadcasts the abnormal nodes based on the reported information and updates the neighbor list of the entire network, and takes isolation measures if necessary. This solution requires multiple nodes to collaborate in decision-making, which is relatively feasible in small-scale networks. However, in large-scale unmanned clusters, multiple inquiries and feedback between nodes may lead to an increase in communication overhead. Especially in the case of unstable network communication or interference, the complexity and accuracy of collaborative decision-making may be affected. Inspired by neural network technology, some scholars have proposed a blockchain consensus method based on multi-agent reinforcement learning, which is mainly applied to wireless node communication in the Internet of Things. Its basic idea is to optimize the consensus mechanism in the blockchain through a multi-agent reinforcement learning model to solve the communication problem between wireless nodes in the Internet of Things. Although this method has significantly improved fairness and efficiency, multi-agent reinforcement learning involves the tuning of multiple neural networks and parameters, and the training process may require a large amount of computing resources and time. The wireless channel environment in the Internet of Things is very complex and is affected by various factors such as interference and noise. The actual deployment of the model may face complex situations different from the simulation environment, resulting in the effect not meeting expectations.
[0005] In summary, the existing technologies lack a detection scheme that considers the existence of double-channel false data injection attacks and the attacks are concealed. Therefore, designing a new attack detection scheme to quickly detect false data injection attacks when they occur is an important way and the key to realizing the secure operation of networked control systems. Summary of the Invention
[0006] The present invention provides an attack detection device and method for an unmanned cluster system under false data injection attacks to solve the technical problem that the existing technologies cannot effectively detect double-channel false data injection attacks.
[0007] To solve the above technical problems, the present invention provides the following technical solutions:
[0008] On the one hand, the present invention provides an attack detection device for an unmanned cluster system under false data injection attacks, including: an encryption module, a decryption module, a data similarity calculation module, a threshold comparator, and an alarm;
[0009] The encryption module is used to encrypt the measurement output signal of a single agent in the unmanned cluster system and transmit the encrypted signal to the decryption module through a wireless communication network; wherein, the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller.
[0010] The decryption module is used to decrypt the encrypted signal to obtain the decrypted signal.
[0011] The data similarity calculation module is used to calculate the real-time residual signal of the system by using the decrypted signal and calculate the probability distribution difference between the real-time residual signal of the system and the residual signal during the normal operation of the system.
[0012] The threshold comparator is used to compare the probability distribution difference calculated by the data similarity calculation module with a preset threshold. If the probability distribution difference is greater than the preset threshold, the alarm is triggered, indicating that the system is under a false data injection attack. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
[0013] Further, the process of the encryption module encrypting the measurement output signal includes:
[0014] The measurement output signal to be encrypted is processed by a first scalar multiplier, and then a watermark signal is superimposed on the signal processed by the first scalar multiplier; wherein, the watermark signal is composed of a pseudo-random sequence with a Gaussian distribution; the encryption key is the seed of the pseudo-random sequence and is pre-stored on the on-board chip.
[0015] Further, the process of the decryption module decrypting the encrypted signal includes:
[0016] The watermark signal is extracted from the encrypted signal, and then based on the extracted watermark signal, the encrypted signal is decrypted by a second scalar multiplier to obtain the decrypted data and the extracted watermark signal.
[0017] Further, the pseudo-random sequence is generated by a cryptographically secure pseudo-random number generator.
[0018] Further, the watermark signal follows a normal distribution with a mean of zero and a variance of η∑ z ; wherein, ∑ z is the variance of the residual signal during the normal operation of the system, and η is a constant greater than 0.
[0019] Further, the encryption module and the decryption module implement an authentication and authorization mechanism through digital signatures to ensure that only authorized users can access the functions and data related to the watermark signal.
[0020] Further, when the parameter of the first scalar multiplier is b, the parameter of the second scalar multiplier is set to 1 / b; and the parameter settings in the encryption module and the decryption module satisfy
[0021] Further, the encryption algorithm adopted by the encryption module is the AES symmetric encryption algorithm.
[0022] Further, the data similarity calculation module is specifically used for:
[0023] Calculating the real-time residual signal of the system by using the decrypted signal, and calculating the Kullback-Leibler divergence between the real-time residual signal of the system and the residual signal of the system during normal operation, and using the Kullback-Leibler divergence to characterize the probability distribution difference between the real-time residual signal of the system and the residual signal of the system during normal operation.
[0024] On the other hand, the present invention also provides a method for detecting an attack on an unmanned cluster system under a false data injection attack implemented by using the above-mentioned attack detection device for an unmanned cluster system under a false data injection attack, including:
[0025] Encrypting the measurement output signal of a single agent in the unmanned cluster system by using the encryption module, and transmitting the encrypted signal to the decryption module through a wireless communication network; wherein, the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller;
[0026] Decrypting the encrypted signal by using the decryption module to obtain the decrypted signal;
[0027] Calculating the real-time residual signal of the system based on the decrypted signal by using the data similarity calculation module, and calculating the probability distribution difference between the real-time residual signal of the system and the residual signal of the system during normal operation;
[0028] Comparing the probability distribution difference calculated by the data similarity calculation module with a preset threshold by using a threshold comparator. If the probability distribution difference is greater than the preset threshold, the alarm is triggered, indicating that the system is under a false data injection attack. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
[0029] The beneficial effects brought by the technical solution provided by the present invention at least include:
[0030] The present invention uses a scalar multiplier and a pseudo-random number as watermarks to encrypt and decrypt data transmitted through a wireless network. Due to the strong coupling between the random watermark signal and the scalar multiplier, the encrypted signal cannot be recognized by an attacker for the coupling and mutual influence between the two. When the system is not under attack, the original data during normal operation of the system can be fully restored through the decryption module. When under attack, the data modified by the attacker is marked with a watermark, thereby changing the residual distribution, and the detection effect can be achieved based on this. The encryption module integrating the scalar multiplier and digital encryption technology integrates an encryption algorithm, a key management system, an access control mechanism, and a secure storage device. The decryption module integrates a decryption algorithm, a key management system, an access control mechanism, a watermark extraction algorithm, and an authentication mechanism. The secure communication protocol during the communication between the encryption / decryption module and the control system ensures the credibility during the communication process. When an attack exists, the threshold comparison module will trigger an alarm in a timely manner to achieve the attack detection effect.
[0031] In addition, the influence of the detection method based on the combination of the scalar multiplier and digital encryption technology on the residuals of the attacked system is determined by the ratio of the multiplier coefficient to the variance of the watermark signal. The Kullback-Leibler divergence between the residuals after being attacked and the residuals during normal operation of the system is proportional to the ratio of the multiplier coefficient to the variance of the watermark signal. Therefore, only by ensuring that the variance of the watermark signal is small enough can a good detection effect be achieved. It is simple to operate and less energy-consuming, which has significant advantages in energy saving and cost reduction, and improves the economic feasibility of the technology. The application prospect of the present invention is wide, including but not limited to the detection of false data injection attacks, and can also be extended to the detection of replay attacks. The originality of the present invention lies in providing an efficient, flexible, and low-energy-consuming false data injection attack detection method, which is still applicable to energy-constrained battery-powered sensors and unmanned cluster systems with limited communication bandwidth. It opens up new possibilities and new solutions for improving the secure operation of unmanned cluster systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0033] Figure 1 It is a system block diagram of the attack detection device provided by the embodiment of the present invention;
[0034] Figure 2 It is an execution flowchart of the attack detection method provided by the embodiment of the present invention;
[0035] Figure 3 This is the working principle diagram of the encryption module provided by the embodiment of the present invention;
[0036] Figure 4 This is the working principle diagram of the decryption module provided by the embodiment of the present invention. Detailed implementation manners
[0037] To make the objectives, technical solutions and advantages of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0038] First of all, it should be noted that in the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of the word "exemplarily" aims to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.
[0039] This embodiment provides an attack detection device for an unmanned cluster system under false data injection attacks, which is used to detect the existence of double-channel covert false data injection attacks in a timely manner. When there is a covert false data injection attack, it can give an alarm in a timely manner to solve the problem of detecting covert false data injection attacks. The system architecture of the attack detection device is as Figure 1 shown, and the process of using it to implement attack detection is as Figure 2 shown.
[0040] Specifically, the attack detection device includes an encryption module and a decryption module for encrypting and decrypting transmitted data, as well as a data similarity calculation module, a threshold comparator and an alarm; the attack detection device uses an encryption and decryption key to perform encryption and decryption processing on the transmitted data, and transmits the decrypted data to the data similarity calculation module, calculates the Kullback-Leibler divergence between the real-time collected residual signal and the normal system residual signal, and compares the result with a pre-set threshold to decide whether to trigger an alarm, so as to achieve the detection effect. Specifically as follows:
[0041] An actuator with a sensor component generates system output in real time, and the sensor collects and monitors the output data. The encryption module is used to encrypt the measurement output signal of the sensor. As Figure 3As shown, the encryption module consists of a scalar multiplier and a watermark signal. When the output signal passes through the encryption module, it first goes through a multiplier, and then a module that generates digital watermarks generates a specific watermark. A random watermark signal is superimposed, and the watermark embedder is responsible for embedding the generated watermark into the data to be transmitted or stored to ensure the security and robustness of the watermark. Among them, the watermark signal consists of a pseudo-random sequence with a Gaussian distribution. The encryption key is the seed of the pseudo-random sequence, which is generated, stored, and managed by the key module and pre-stored on the on-board chip to ensure the security of the key and prevent it from being obtained by attackers.
[0042] Furthermore, in the present invention, the encryption algorithm uses the AES (Advanced Encryption Standard) symmetric encryption algorithm, which supports key lengths of 128 bits, 192 bits, and 256 bits. In cyber-physical security, the key is generated based on the physical characteristics of the channel for encryption and decryption.
[0043] The output signal after the encryption operation reaches the decryption module through the wireless network transmission module. As Figure 2 shown, the decryption module consists of a scalar multiplier and the same watermark signal as the encryption module. The decryption module decrypts the received encrypted data and extracts the watermark. The decryption module includes a watermark extractor, key management, a decryption algorithm, and related security measures. The watermark extractor mainly locates, extracts, and decodes the embedded watermark information, and after being processed by the data processor in the decryption module, the decrypted data and the extracted watermark information are obtained. The key generation depends on a random number generator.
[0044] Specifically, in the present invention, a Cryptographically Secure Random Number Generator (CSPRNG) is used to ensure the unpredictability of the key. The CSPRNG generates high-quality random numbers based on physical phenomena or randomness data in the operating system (such as network traffic, mouse movement, hardware noise, etc.), avoids generating predictable keys, and uses a Hardware Security Module (HSM) to securely store and manage the keys to prevent them from being tampered with or attacked.
[0045] Among them, the sensor only samples the system output and analyzes a single unmanned system:
[0046]
[0047] Among them, A represents the time-invariant system matrix, B represents the influence matrix of process noise on the system state, C represents the time-invariant measurement matrix, k represents the sampling time, x(k + 1) is the state during normal operation, u(k) is the control input of the system, y(k) is the measured output of the system, w(k) is the process noise of the system, which follows a Gaussian distribution with a mean of 0 and a variance of Q, that is υ(k) is the measurement noise at the sensor end of the system, which follows a Gaussian distribution with a mean of 0 and a variance of R, that is w(k) and υ(k) are independent of each other.
[0048] When the system is operating normally, the measured output of the sensor will be sent to the Kalman filter of itself and the Kalman filter of the adjacent unmanned system through the wireless transmission module.
[0049] The encryption module performs the following encryption operations on the measured output collected by the sensor:
[0050] g(k) = by(k) + m(k) (2)
[0051] Among them, g(k) represents the result after encrypting the measured output, b is the parameter of the multiplier in the encryption module based on the scalar multiplier, and m k is the random watermark signal in the encryption module based on the scalar multiplier, which follows a normal distribution with a mean of zero and a variance of η∑ z where ∑ z is the variance of the residuals when the system is operating normally, and η is a constant greater than 0.
[0052] When there is a two-channel false data injection attack, the encrypted signal becomes:
[0053]
[0054] Among them, represents the estimated state when the system is under attack, and u a (k - 1) represents the control input signal used for the state estimator when the system is under attack, and ξ(k) is a random signal designed by the attacker, which follows a normal distribution with a mean of zero and a variance of ∑ z The existence of false data injection attacks in the feedback channel tamper with the encryption result of the original measured output data. It reaches the decryption module based on the scalar multiplier through the wireless network transmission module. The watermark encryption module of the unmanned cluster system incorporates the digital watermark technology in cryptography. Among them, the random seeds used in the encryption module and the decryption module are the same, thus ensuring that the random sequences of the encryption module and the decryption module are the same. After being processed by the decryption module, the output after decryption is:
[0055]
[0056] Among them, is the output obtained after decryption; based on this output, the system residual under attack is:
[0057]
[0058] Among them, is the predicted output of the Kalman filter when the unmanned cluster system is under attack, and z a (k) is the residual signal of the system when under attack and follows a normal distribution with a mean of and a variance of .
[0059] When the system is not under attack, the decrypted signal is:
[0060]
[0061] The watermark encryption and decryption module implements an authentication and authorization mechanism through digital signatures to ensure that only authorized users can access watermark-related functions and data. The encryption key is the seed of a pseudo-random sequence, which is pre-stored on the on-board chip, ensuring both the security of the key and that the encryption module and the decryption module have the same seed, so that m(k) in the encryption module and the decryption module is the same. In addition, when the scalar multiplier parameter in the encryption module is b, the multiplier parameter in the decryption module is set to 1 / b.
[0062] The data similarity calculation module is the core component of the detection device, used to detect the differences between data distributions. The Kullback-Leibler divergence can characterize the differences between two probability distributions. This module calculates the Kullback-Leibler divergence between the residual signal calculated from the decrypted output signal (calculated through the decrypted output signal) and the normal system residual signal to identify anomalies in the system data. The Kullback-Leibler divergence calculated by the data similarity calculation module is transmitted to the threshold comparator, where the calculated Kullback-Leibler divergence is compared with a preset threshold. If the calculated Kullback-Leibler divergence exceeds the preset threshold, the detector will generate an alarm.
[0063] When the system is operating normally, the system output passes through the encryption and decryption module without affecting its value and distribution. At this time, the Kullback-Leibler divergence between the real-time residual calculated by the data similarity calculation module and the normal system residual is zero, and the alarm cannot be triggered. The residual is normally sent to the central observer for system state estimation, and the controller is designed based on this state estimation. When the system is under attack, the attacker attacks the encrypted output signal in the wireless network transmission module at this time. After the attacked signal is sent to the decryption module, it cannot be restored to the original output signal, and thus the residual under normal system operation cannot be obtained. At this time, the residual signal calculated based on the output signal after decryption and the residual signal distribution under normal system operation are different. Furthermore, the Kullback-Leibler divergence calculated in the data similarity calculation module is not zero, and the alarm is triggered at this time to achieve the detection effect.
[0064] Specifically, when the system is under a two-channel false data injection attack, the residual calculated using the signal after decryption is sent to the detector, and the Kullback-Leibler divergence value between it and the normal residual is calculated:
[0065]
[0066] where p is the dimension of the system output y k Set the threshold δ of the threshold comparator to a sufficiently small positive number.
[0067] D(z a (k)|z(k))>δ (8)
[0068] When the parameter settings in the encryption and decryption module in the detection device satisfy and there is an attack, D(z a (k)|z(k))→∞, and the alarm of the device will surely alarm to achieve the detection effect. When there is no attack, regardless of the value of the encryption and decryption module, D(z a (k)|z(k))=0<δ, and the alarm cannot be triggered. Since the sensor output can be completely restored when there is no attack, the detection device of the present invention does not affect the system performance.
[0069] Based on the above, the process of using this detection device to achieve attack detection is as follows:
[0070] S11, send the measurement output at the sensor of a single agent system in the unmanned cluster system to the encryption module. The encryption module encrypts the measurement output using the random watermark signal generated by the random number generator and the scalar multiplier, and transmits the encrypted signal to the decryption module through the wireless communication network;
[0071] S12, the decryption module uses key management and the decryption algorithm corresponding to the encryption module to perform decryption operations to extract the watermark and recover the data. Among them, the random seeds for generating the random watermark signal by the encryption module and the decryption module are the same, thus ensuring the same extraction of the watermark signal.
[0072] S13, calculate the real-time residual signal of the system using the decrypted data and send it to the detector based on the Kullback-Leibler divergence. The detector has set corresponding thresholds in advance according to the detection accuracy, calculate the Kullback-Leibler divergence between the real-time obtained residual signal and the residual when the system is operating normally and compare it with the threshold.
[0073] S14, if the calculated Kullback-Leibler divergence is greater than the preset threshold, trigger the alarm, indicating that the system is under a false data injection attack; otherwise, do not trigger the alarm, proving that the system is in a normal operating state.
[0074] In summary, this embodiment provides an attack detection device for an unmanned cluster system under false data injection attack and an attack detection method for an unmanned cluster system under false data injection attack using the same. It adopts an encryption and decryption method combining a scalar multiplier and digital watermarking to perform encryption and decryption operations on the feedback channel from the sensor to the controller. Embed the hidden information into the original data to achieve the encryption and authentication of the information of the unmanned cluster system, improving the security and credibility of the data. The digital watermark-based encryption method involves an embedding algorithm (embedding the watermark into the original data), an extraction algorithm (extracting the hidden watermark information according to the characteristics of the watermark embedding method), and an encryption technology (protecting the security of the random sequence seed generating the watermark, preventing unauthorized access and tampering, and ensuring the consistency of the watermark signals of the encryption module and the decryption module). When there is a false data injection attack, after passing through the encryption and decryption modules, the Kullback-Leibler divergence of the system residuals before and after the attack is significantly different, thus triggering the residual-based detector to effectively detect the false data injection attack.
[0075] In addition, it should be noted that the present invention can be provided as a method, apparatus, or computer program product. Therefore, the embodiments of the present invention can take the form of all or part of a hardware embodiment, all or part of a software embodiment, or an embodiment combining software and hardware aspects. Moreover, when implemented in software, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center containing one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0076] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal device generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0077] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1the functions specified in one or more boxes. These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one Figure 1 process or multiple processes and / or boxes Figure 1 step of the functions specified in one or more boxes.
[0078] It should also be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising the said element. In addition, the term "and / or" is merely a description of the relationship between associated objects, indicating that three relationships may exist. For example, A and / or B may mean: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B may be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the associated objects before and after, but may also represent an "and / or" relationship, which can be understood specifically by referring to the context. "At least one" means one or more, and "multiple" means two or more. "At least one of the following (items)" or similar expressions refer to any combination of these items, including any combination of single (item) or plural items (items). For example, at least one of a, b or c may mean: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c may be single or multiple.
[0079] Furthermore, it can be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0080] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0081] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of functional modules / units is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms. The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can physically exist alone, or two or more units can be integrated in one unit.
[0082] If the method is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0083] Finally, it should be noted that the above description is only a preferred embodiment of the present invention. It should be pointed out that although the preferred embodiments of the present invention have been described, for those of ordinary skill in the art, once they know the basic creative concept of the present invention, without departing from the principle described in the present invention, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
Claims
1. An attack detection device for an unmanned cluster system under a false data injection attack, characterized in that: include: An encryption module, a decryption module, a data similarity calculation module, a threshold comparator and an alarm; The encryption module is used to encrypt the measurement output signal of a single intelligent agent in the unmanned cluster system, and transmit the encrypted signal to the decryption module through a wireless communication network; wherein the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller; The decryption module is used to decrypt the encrypted signal to obtain a decrypted signal; The data similarity calculation module is used to calculate the real-time residual signal of the system using the decrypted signal, and calculate the probability distribution difference between the real-time residual signal of the system and the residual signal when the system is operating normally; The threshold comparator is used to compare the probability distribution difference calculated by the data similarity calculation module with a preset threshold. If the probability distribution difference is greater than the preset threshold, an alarm is triggered, indicating that the system has been attacked by false data injection. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
2. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 1, characterized in that: The process of the encryption module encrypting the measurement output signal includes: The measurement output signal to be encrypted is processed by a first scalar multiplier, and then a watermark signal is superimposed on the signal processed by the first scalar multiplier; wherein the watermark signal is composed of a pseudo-random sequence of Gaussian distribution; the encryption key is the seed of the pseudo-random sequence and is pre-stored on an onboard chip.
3. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 2, characterized in that: The process of the decryption module decrypting the encrypted signal includes: A watermark signal is extracted from the encrypted signal, and then based on the extracted watermark signal, the encrypted signal is decrypted by a second scalar multiplier to obtain decrypted data and the extracted watermark signal.
4. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 3, characterized in that: The pseudo-random sequence is generated by a cryptographically secure pseudo-random number generator.
5. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 3, characterized in that: The watermark signal has a mean of zero and a variance of η∑ z The normal distribution of z is the variance of the residual signal when the system operates normally, and η is a constant greater than 0.
6. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 3, characterized in that: The encryption module and the decryption module implement authentication and authorization mechanisms through digital signatures to ensure that only authorized users can access functions and data related to the watermark signal.
7. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 5, characterized in that: When the parameter of the first scalar multiplier is b, the parameter of the second scalar multiplier is set to 1 / b; and the parameter settings in the encryption module and the decryption module satisfy 8. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 1, characterized in that: The encryption algorithm adopted by the encryption module is the AES symmetric encryption algorithm.
9. The attack detection device for an unmanned cluster system under a false data injection attack as claimed in claim 1, characterized in that: The data similarity calculation module is specifically used for: The decrypted signal is used to calculate the real-time residual signal of the system, and the Kullback-Leibler divergence between the real-time residual signal of the system and the residual signal when the system is operating normally is calculated. The Kullback-Leibler divergence is used to characterize the probability distribution difference between the real-time residual signal of the system and the residual signal when the system is operating normally.
10. A method for detecting an unmanned cluster system under false data injection attack using the attack detection device for an unmanned cluster system under false data injection attack as claimed in any one of claims 1 to 9, characterized in that: The attack detection method of the unmanned cluster system under the false data injection attack includes: The encryption module is used to encrypt the measurement output signal of a single intelligent agent in the unmanned cluster system, and the encrypted signal is transmitted to the decryption module through a wireless communication network; wherein the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller; Decrypting the encrypted signal using a decryption module to obtain a decrypted signal; Using the data similarity calculation module to calculate the real-time residual signal of the system based on the decrypted signal, and to calculate the probability distribution difference between the real-time residual signal of the system and the residual signal when the system is operating normally; A threshold comparator is used to compare the probability distribution difference calculated by the data similarity calculation module with a preset threshold. If the probability distribution difference is greater than the preset threshold, an alarm is triggered, indicating that the system has been attacked by false data injection. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
Citation Information
Patent Citations
Active attack detection method for improving detection rate
CN114063602A
Hidden attack detection method and device for industrial control system
CN114154146A
Elastic event trigger control method and device of random hopping information physical system
CN115314251A
False data injection attack detection method and device
CN116915513A
Industrial control system dual-channel false data injection attack detection method
CN117081780A