Attack detection device and method for unmanned cluster system under false data injection attack
By using scalar multipliers and digital watermarking encryption and decryption methods in unmanned cluster systems, embedding watermark signals and detecting differences in residual signal distribution, the problem of covert detection of fake data injection attacks in unmanned cluster systems is solved, achieving fast and low-energy attack detection.
Patent Information
- Application Number
- CN202510071544.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2045-01-16
AI Technical Summary
Existing technologies cannot effectively detect dual-channel spoofing attacks in unmanned swarm systems. Especially when the attacks are highly covert, they are difficult to detect and defend against in a timely manner, leading to system misjudgments and potential serious damage.
An encryption and decryption method based on scalar multipliers and digital watermarking is adopted. The feedback channel from the sensor to the controller is encrypted, a watermark signal is embedded, and the distribution difference of the residual signal of the Kullback-Leibler divergence detection system is used to trigger an alarm for attack detection.
It enables rapid and accurate detection of fake data injection attacks, reduces energy consumption and communication overhead, is suitable for unmanned cluster systems with limited energy and communication bandwidth, and improves system security and reliability.
Smart Images

Figure CN120074869B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and particularly relates to an attack detection device and method for unmanned cluster system under false data injection attack. BACKGROUND
[0002] According to the influence of network attack on transmission data, network attacks can be divided into two categories, namely denial-of-service attack and deception attack. Among them, the denial-of-service attack destroys the information interaction between the communication network connecting the sensor, the actuator and the controller by blocking or interfering the communication channel, and destroys the availability of data. And the deception attack can be further divided into false data injection attack and replay attack. The false data injection attack is designed by the attacker according to the system information and the characteristics of the detector, and has a certain concealment. In the unmanned cluster system, since multiple unmanned devices rely on sensor data and communication network for cooperation and decision-making, these systems are vulnerable to false data injection. Therefore, the false data injection attack has strong destructive power to the unmanned cluster system, which brings great challenges to the safe operation of the unmanned cluster system.
[0003] The unmanned cluster system usually includes unmanned aerial vehicles (UAVs), unmanned ground vehicles (UGVs), unmanned surface vehicles (USVs), etc., which perform complex tasks such as environmental monitoring, search and rescue operations and military tasks by sharing sensor data, location information and instructions. However, due to the high automation and distributed structure of the unmanned cluster system, once a node is injected with false data, it may lead to misjudgment, decision error or abnormal execution of the whole system, and thus cause task failure or system damage. For the unmanned cluster system, the feedback channel from the sensor to the controller and the forward channel between the controller and the controlled object are transmitted through the communication network, and the exposed network environment makes the transmitted information vulnerable to hijacking or even tampering by malicious attackers, thereby affecting the stability and security of the network communication system. A successful attack will cause great damage to the system, resulting in huge economic losses and even loss of life. The existing security protection measures are mainly concentrated in communication encryption, access control, etc., which can prevent some network attacks to a certain extent, but the defense effect on false data injection attack is limited. False data injection attack has the characteristics of strong concealment and high flexibility, and the attacker can modify or forge sensor data to induce the unmanned cluster system to make wrong judgments, which is difficult to be directly discovered by traditional means. In addition, false data injection may gradually penetrate the system in a short time, leading to the accumulation of errors that are not easy to detect, making the attack consequences more serious.
[0004] Attack detection aims to minimize the impact of attacks on the system by detecting the presence of attacks in the system in a timely manner and adjusting the system accordingly. A fast and accurate detection device is crucial for the safe operation of unmanned cluster systems. In this regard, some scholars have proposed a node capture attack detection method for unmanned clusters. The purpose is to detect and prevent node capture attacks as soon as possible in unmanned clusters by monitoring the survivability of nodes and the mutual decision-making mechanism, and to ensure the security of the network. This method can achieve the mutual decision-making mechanism through neighbor node survivability monitoring. Each node detects independently and reports abnormal nodes to the ground control station (GCS) through multi-hop routing. GCS broadcasts abnormal nodes according to the report information and updates the neighbor list of the entire network, and takes isolation measures if necessary. This scheme requires multiple nodes to make decisions collaboratively, which is feasible in small-scale networks, but in large-scale unmanned clusters, multiple inquiries and feedback between nodes may increase communication overhead, especially in unstable network communication or interference, the complexity and accuracy of collaborative decision-making may be affected. Inspired by neural network technology, some scholars have proposed a blockchain consensus method based on multi-agent reinforcement learning, mainly applied to wireless node communication in the Internet of Things field. The basic idea is to optimize the consensus mechanism in the blockchain through a multi-agent reinforcement learning model to solve the communication problem between wireless nodes in the Internet of Things. Although this method has significantly improved fairness and efficiency, multi-agent reinforcement learning involves multiple neural networks and parameter tuning, and the training process may require a large amount of computing resources and time. The wireless channel environment in the Internet of Things is very complex and is affected by interference, noise and other factors. The actual deployment of the model may face different complex situations from the simulation environment, resulting in less expected effect.
[0005] In summary, the existing technology lacks a detection scheme that considers the existence of double-channel false data injection attacks and the concealment of attacks, so a new attack detection scheme is designed to quickly detect false data injection attacks and achieve the safe operation of networked control systems. SUMMARY
[0006] The present application provides an attack detection device and method for unmanned cluster systems under false data injection attacks to solve the technical problem that existing technology cannot effectively detect double-channel false data injection attacks.
[0007] To solve the above technical problems, the present application provides the following technical solutions:
[0008] On the one hand, the present application provides an attack detection device for unmanned cluster systems under false data injection attacks, comprising: an encryption module, a decryption module, a data similarity calculation module, a threshold comparator and an alarm;
[0009] The encryption module is configured to encrypt a measurement output signal of a single agent in the unmanned swarm system, and transmit the encrypted signal to the decryption module through a wireless communication network; wherein the measurement output signal refers to a signal output by a sensor in a feedback channel from the sensor to a controller.
[0010] The decryption module is configured to decrypt the encrypted signal to obtain a decrypted signal.
[0011] The data similarity calculation module is configured to calculate a real-time residual signal of the system by using the decrypted signal, and calculate a probability distribution difference between the real-time residual signal of the system and a residual signal of the system in a normal operation state.
[0012] The threshold comparator is configured to compare the probability distribution difference calculated by the data similarity calculation module with a preset threshold, if the probability distribution difference is greater than the preset threshold, the alarm is triggered, indicating that the system is subjected to a false data injection attack, if the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
[0013] Further, the process of encrypting the measurement output signal by the encryption module includes:
[0014] The measurement output signal to be encrypted is processed by a first scalar multiplier, and then a watermark signal is superimposed on the signal processed by the first scalar multiplier; wherein the watermark signal is composed of a pseudo-random sequence with Gaussian distribution; the encryption key is the seed of the pseudo-random sequence, and is pre-stored on the on-board chip.
[0015] Further, the process of decrypting the encrypted signal by the decryption module includes:
[0016] The watermark signal is extracted from the encrypted signal, and then the encrypted signal is decrypted by a second scalar multiplier based on the extracted watermark signal to obtain the decrypted data and the extracted watermark signal.
[0017] Further, the pseudo-random sequence is generated by a cryptographically secure pseudo-random number generator.
[0018] Further, the watermark signal obeys a normal distribution with a mean of zero and a variance of η∑ z ; wherein ∑ z is the variance of the residual signal of the system in the normal operation state, and η is a constant greater than 0.
[0019] Further, the encryption module and the decryption module implement an authentication and authorization mechanism through digital signature to ensure that only authorized users can access the functions and data related to the watermark signal.
[0020] Further, when the parameter of the first scalar multiplier is b, the parameter of the second scalar multiplier is set to 1 / b; and the parameters in the encryption module and the decryption module are set to satisfy
[0021] Further, the encryption algorithm used by the encryption module is the AES symmetric encryption algorithm.
[0022] Further, the data similarity calculation module is specifically used for:
[0023] The real-time residual signal of the system is calculated by using the decrypted signal, and the Kullback-Leibler divergence between the real-time residual signal of the system and the residual signal of the system in normal operation is calculated, so that the probability distribution difference between the real-time residual signal of the system and the residual signal of the system in normal operation is represented by the Kullback-Leibler divergence.
[0024] In another aspect, the present application also provides an attack detection method for an unmanned cluster system under a false data injection attack, which is implemented by an attack detection device for an unmanned cluster system under a false data injection attack, and the attack detection method comprises the following steps:
[0025] The measurement output signal of a single intelligent agent in the unmanned cluster system is encrypted by using the encryption module, and the encrypted signal is transmitted to the decryption module through a wireless communication network; wherein the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller.
[0026] The encrypted signal is decrypted by using the decryption module to obtain a decrypted signal.
[0027] The real-time residual signal of the system is calculated by using the decrypted signal based on the data similarity calculation module, and the probability distribution difference between the real-time residual signal of the system and the residual signal of the system in normal operation is calculated.
[0028] The probability distribution difference calculated by the data similarity calculation module is compared with a preset threshold value by using the threshold value comparator, if the probability distribution difference is greater than the preset threshold value, the alarm is triggered, which indicates that the system is attacked by the false data injection attack, if the probability distribution difference is not greater than the preset threshold value, the alarm is not triggered, which indicates that the system is normal.
[0029] The technical scheme provided by the present application has at least the following beneficial effects:
[0030] The application uses scalar multiplier and pseudo-random number as watermark to encrypt and decrypt data transmitted through wireless network. The strong coupling of random watermark signal and scalar multiplier makes the encrypted signal unable to be recognized by attacker. When the system is not attacked, the decrypted module can completely restore the original data when the system is normally operated. When attacked, the data modified by attacker is identified by watermark and the residual distribution is changed, so that the detection effect is achieved. The encryption module based on the combination of scalar multiplier and digital encryption technology integrates encryption algorithm, key management system, access control mechanism and secure storage device. The decryption module integrates decryption algorithm, key management system, access control mechanism, watermark extraction algorithm and verification mechanism. The secure communication protocol when the encryption and decryption module and the control system communicate ensures the credibility in the communication process. When attack exists, the threshold comparison module triggers the alarm in time to achieve the effect of attack detection.
[0031] In addition, the influence of the detection method based on the combination of scalar multiplier and digital encryption technology on the residual of the attacked system is determined by the ratio of multiplier coefficient and watermark signal variance. The Kullback-Leibler divergence between the residual after attack and the residual when the system is normally operated is proportional to the ratio of multiplier coefficient and watermark signal variance. Therefore, only the variance of watermark signal is small enough, the good detection effect can be achieved. The operation is simple and the energy consumption is low. It has the advantages of significant energy saving and cost reduction, and improves the economic feasibility of the technology. The application prospect of the application is wide, including but not limited to the detection of false data injection attack, and can also be popularized to the detection of replay attack. The originality of the application lies in providing a high-efficiency, flexible and low-energy false data injection attack detection method, which is still applicable to energy-limited battery-powered sensors and communication bandwidth-limited unmanned cluster systems. It opens up new possibilities and new solutions for improving the safe operation of unmanned cluster systems. BRIEF DESCRIPTION OF DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0033] Figure 1 is the system block diagram of the attack detection device provided by the embodiment of the application;
[0034] Figure 2 is the execution flowchart of the attack detection method provided by the embodiment of the application;
[0035] Figure 3 is a working principle diagram of an encryption module provided by an embodiment of the present application;
[0036] Figure 4 is a working principle diagram of a decryption module provided by an embodiment of the present application. DETAILED DESCRIPTION
[0037] In order to make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0038] First of all, it should be noted that in the embodiments of the present application, the words such as "exemplarily", "for example" and the like are used to represent as an example, illustration or description. Any embodiment or design scheme described as "exemplary" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "exemplarily" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be either one of the two.
[0039] The present embodiment provides an attack detection device for unmanned cluster system under false data injection attack, which is used for detecting the existence of double-channel covert false data injection attack in time, and can timely alarm when the covert false data injection attack exists, thereby solving the detection problem of the covert false data injection attack. The system architecture of the attack detection device is as shown in Figure 1 , and the flow of attack detection achieved by using the same is as shown in Figure 2 .
[0040] Specifically, the attack detection device includes an encryption module and a decryption module for encrypting and decrypting transmission data, and a data similarity calculation module, a threshold comparator and an alarm; the attack detection device uses an encryption and decryption key to perform encryption and decryption processing on the transmission data, and transmits the data after decryption to the data similarity calculation module, calculates the Kullback-Leibler divergence of the real-time collected residual signal and the normal system residual signal, compares the result with the threshold set in advance, so as to determine whether to trigger an alarm, thereby achieving the detection effect. Specifically as follows:
[0041] The actuator with a sensor component generates a system output in real time, and the sensor collects and monitors the output data. The encryption module is used for encrypting the measurement output signal of the sensor. As Figure 3As shown, the encryption module is composed of a scalar multiplier and a watermark signal. The output signal first passes through a multiplier and then a module for generating a specific watermark when passing through the encryption module. A random watermark signal is superimposed and the generated watermark is embedded into the data to be transmitted or stored by the watermark embedder to ensure the security and robustness of the watermark. The watermark signal is composed of a pseudo-random sequence with Gaussian distribution. The encryption key is the seed of the pseudo-random sequence, which is generated, stored and managed by the key module and pre-stored on the on-board chip to ensure the security of the key and prevent it from being obtained by attackers.
[0042] Further, in the present application, the encryption algorithm uses the AES (Advanced Encryption Standard) symmetric encryption algorithm, which can support 128-bit, 192-bit and 256-bit key lengths. In information physical security, the key is generated through the physical characteristics of the channel for encryption and decryption.
[0043] The output signal after the encryption operation reaches the decryption module through the wireless network transmission module. As shown, Figure 2 The decryption module is composed of a scalar multiplier and the same watermark signal as the encryption module, which decrypts the received encrypted data and extracts the watermark. The decryption module includes a watermark extractor, a key management, a decryption algorithm and related security measures. The watermark extractor mainly locates, extracts and decodes the embedded watermark information, and then processes it through the data processor in the decryption module to obtain the decrypted data and the extracted watermark information. Key generation depends on the random number generator.
[0044] Specifically, in the present application, a cryptographically secure random number generator (CSPRNG) is used to ensure the unpredictability of the key. CSPRNG generates high-quality random numbers based on physical phenomena or random data in the operating system (such as network traffic, mouse movement, hardware noise, etc.), avoids generating predictable keys, and uses a hardware security module (HSM) to securely store and manage the key to prevent it from being tampered with or attacked.
[0045] Among them, the sensor only samples the system output and analyzes a single unmanned system:
[0046]
[0047] where A represents a time-invariant system matrix, B represents a matrix of the influence of process noise on the system state, C represents a time-invariant measurement matrix, k represents a sampling time, x(k+1) is a state in normal operation, u(k) is a control input of the system, y(k) is a measurement output of the system, and w(k) is process noise of the system, which is subject to a Gaussian distribution with a mean of 0 and a variance of Q, i.e. v(k) is measurement noise of a sensor end of the system, which is subject to a Gaussian distribution with a mean of 0 and a variance of R, i.e. w(k) and v(k) are independent of each other.
[0048] When the system is in normal operation, the measurement output of the sensor is sent to the Kalman filter of the system itself and the Kalman filter of the adjacent unmanned system through a wireless transmission module.
[0049] The encryption module performs the following encryption operation on the measurement output collected by the sensor:
[0050] g(k) = by(k) + m(k) (2)
[0051] where g(k) represents a result after the measurement output is encrypted, b is a parameter of a multiplier in the encryption module based on the scalar multiplier, m k is a random watermark signal in the encryption module based on the scalar multiplier, which is subject to a normal distribution with a mean of 0 and a variance of η∑ z , where ∑ z is a variance of a residual in normal operation of the system, and η is a constant greater than 0.
[0052] When there is a double-channel false data injection attack, the encrypted signal becomes:
[0053]
[0054] where x(k) represents an estimated state when the system is attacked, u a (k-1) represents a control input signal for a state estimator when the system is attacked, and ξ(k) is a random signal designed by an attacker, which is subject to a normal distribution with a mean of 0 and a variance of ∑ z . The existence of the false data injection attack of the feedback channel tampers with the encryption result of the original measurement output data. After being transmitted through the wireless network transmission module, the signal reaches the decryption module based on the scalar multiplier. The watermark encryption module of the unmanned cluster system includes a digital watermark technology in cryptography. The random seeds used by the encryption module and the decryption module are the same, so that the random sequences of the encryption module and the decryption module are the same. After being processed by the decryption module, the output after decryption is:
[0055]
[0056] wherein, is the decrypted output; based on this output, the system residual of the system under attack is:
[0057]
[0058] wherein, is the predicted output of the Kalman filter when the unmanned swarm system is under attack, z a (k) is the residual signal of the system when under attack and is subject to a normal distribution with mean and variance .
[0059] When the system is not under attack, the decrypted signal obtained is:
[0060]
[0061] The watermark encryption and decryption module realizes an authentication and authorization mechanism through digital signature to ensure that only authorized users can access the watermark-related functions and data. The encryption key is the seed of the pseudo-random sequence, which is pre-stored on the on-board chip, which ensures the security of the key and also ensures that the encryption module and the decryption module have the same seed, so that m(k) in the encryption module and the decryption module are the same. In addition, when the parameter of the scalar multiplier in the encryption module is b, the parameter of the multiplier in the decryption module is set to 1 / b.
[0062] The data similarity calculation module is the core component of the detection device, which is used to detect the difference between the data distribution. The Kullback-Leibler divergence can be used to represent the difference between two probability distributions. This module calculates the Kullback-Leibler divergence between the residual signal calculated by the output signal after decryption and the normal system residual signal (calculated by the decrypted output signal), in order to identify the abnormality of the system data. The Kullback-Leibler divergence calculated by the data similarity calculation module is transmitted to the threshold comparator, and the calculated Kullback-Leibler divergence is compared with the preset threshold value. If the calculated Kullback-Leibler divergence exceeds the preset threshold value, the detector will produce an alarm.
[0063] When the system is running normally, the system output passes through the encryption and decryption module without affecting its value and distribution, at this time the Kullback-Leibler divergence between the real-time residual calculated by the data similarity calculation module and the normal system residual is zero, which cannot trigger the alarm, and the residual is normally sent to the central observer for system state estimation, and the controller is designed based on the state estimation. When the system is attacked, at this time the attacker attacks the encrypted output signal in the wireless network transmission module, the signal after being attacked cannot be restored to the original output signal after being sent to the decryption module, and then the residual when the system is running normally cannot be obtained, at this time the residual signal calculated based on the output signal after decryption is different from the residual signal of the system when it is running normally, and then the Kullback-Leibler divergence calculated in the data similarity calculation module is not zero, at this time the alarm is triggered to achieve the detection effect.
[0064] Specifically, when the system is subjected to a double-channel false data injection attack, the residual calculated by the signal after decryption is sent to the detector, and the Kullback-Leibler divergence value of the normal residual is calculated:
[0065]
[0066] Wherein, p is the system output y k Dimension. The threshold value δ of the threshold value comparator is set to be a small positive number.
[0067] D(z a (k)|z(k))>δ (8)
[0068] When the parameter setting in the encryption and decryption module in the detection device satisfies And when the attack exists, D(z a (k)|z(k))→∞, the alarm of the device will certainly alarm, and the detection effect is achieved. When there is no attack, no matter how the encryption and decryption module takes value, D(z a (k)|z(k))=0<δ, which cannot trigger the alarm. Since the sensor output can be completely restored when there is no attack, the detection device does not affect the system performance.
[0069] Based on the above, the process of realizing attack detection by using the detection device is as follows:
[0070] S11, the measurement output at the sensor of the single intelligent agent system in the unmanned cluster system is sent to the encryption module, the encryption module uses the random watermark signal generated by the random number generator and the scalar multiplier to encrypt the measurement output, and the encrypted signal is transmitted to the decryption module through the wireless communication network;
[0071] S12, the decryption module uses the key management and the decryption algorithm corresponding to the encryption module to perform the decryption operation, to realize the extraction of the watermark and the recovery of the data; wherein the random seed for generating the random watermark signal by the encryption module and the decryption module is the same, thereby ensuring that the extraction of the watermark signal is the same;
[0072] S13, the residual signal of the system in real time is calculated by using the data after decryption and is sent to the detector based on Kullback-Leibler divergence, the detector sets the corresponding threshold value in advance according to the detection accuracy, the Kullback-Leibler divergence of the real-time residual signal and the residual of the system in normal operation is calculated and compared with the threshold value;
[0073] S14, if the calculated Kullback-Leibler divergence is greater than the preset threshold value, the alarm is triggered, indicating that the system is subjected to the false data injection attack, otherwise the alarm is not triggered, proving that the system is in normal operation.
[0074] In summary, the embodiment provides an attack detection device of the unmanned cluster system under the false data injection attack and an attack detection method of the unmanned cluster system under the false data injection attack using the same, an encryption and decryption method based on the scalar multiplier and the digital watermark is adopted to perform the encryption and decryption operation on the feedback channel from the sensor to the controller. The hidden information is embedded into the original data to realize the encryption and authentication of the information of the unmanned cluster system, and the security and the credibility of the data are improved. The digital watermark encryption method involves the embedding algorithm (embedding the watermark into the original data), the extraction algorithm (extracting the hidden watermark information according to the characteristics of the watermark embedding method), the encryption technology (protecting the security of the random sequence seed for generating the watermark, preventing unauthorized access and tampering, and ensuring the consistency of the watermark signal of the encryption module and the decryption module). When the false data injection attack exists, the Kullback-Leibler divergence of the system residual before and after the attack is significantly different after the encryption and decryption module, thereby triggering the residual-based detector, and the effective detection of the false data injection attack is achieved.
[0075] Moreover, it should be noted that the present application can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present application can take the form of an entirely or partially hardware embodiment, an entirely or partially software embodiment, or an embodiment combining software and hardware aspects. Furthermore, when implemented in software, the embodiments of the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, a computer diskette, an optical storage medium, a magnetic storage medium, and a semiconductor memory device). The computer program product includes one or more computer instructions that when loaded and executed by a computer, cause the computer to carry out the processes or functions described in the embodiments of the present application. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, such as from a website, a computer, a server, or a data center to another website, computer, server, or data center through a wired (for example, infrared, wireless, microwave, or the like) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device, such as a server, data center, or the like, including one or more collections of available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.
[0076] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, an embedded processor, or a processor of another programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate a device that implements the flow Figure 1 The flow or multiple flows and / or blocks Figure 1 The device that implements the functions specified in the flow or multiple flows and / or blocks.
[0077] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product that includes an instruction device that implements the flow Figure 1 The flow or multiple flows and / or blocks Figure 1The computer program instructions can also be loaded onto a computer or other programmable data processing terminal device to cause a series of operational steps to be performed on the computer or other programmable terminal device to generate a computer implemented process such that the instructions which execute on the computer or other programmable terminal device provide processes for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing terminal device to cause a series of operational steps to be performed on the computer or other programmable terminal device to generate a computer implemented process such that the instructions which execute on the computer or other programmable terminal device provide processes for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing terminal device to cause a series of operational steps to be performed on the computer or other programmable terminal device to generate a computer implemented process such that the instructions which execute on the computer or other programmable terminal device provide processes for implementing the functions specified in the flowchart block or blocks.
[0078] It should also be noted that, in the present text, the terms "comprising", "containing" or any other variant thereof are intended to cover non-exclusive inclusions, such that a process, method, article or terminal device that includes a list of elements is not limited to those elements, but can also include other elements not explicitly listed, or inherent to such process, method, article or terminal device. Without further limitations, an element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or terminal device that includes the said element. Furthermore, the term "and / or", merely describes an association relationship between associated objects, and means that there can be three relationships, for example, A and / or B, which means that A exists alone, A and B exist together, B exists alone, where A and B can be singular or plural. In addition, the character " / " in the present text generally represents an "or" relationship between the front and rear associated objects, but can also represent an "and / or" relationship, which can be understood in the context of the front and rear text. "At least one" means one or more, and "multiple" means two or more. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can mean a, b, c, a-b, a-c, b-c or a-b-c, where a, b and c can be singular or plural.
[0079] In addition, it can be understood that, in various embodiments of the present application, the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0080] Those of ordinary skill in the art can realize that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized in electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0081] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the above-described apparatus embodiments are merely schematic, and the division of the functional modules / units is merely a logical function division. In actual implementation, another division manner can be adopted, for example, a plurality of units or components can be combined or integrated into another device, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms. The units described as separate components can be or can not be physically separate, and the components shown as units can be or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be a physically independent unit, or two or more units can be integrated in one unit.
[0082] If the method is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0083] Finally, it should be noted that the above description is only a preferred embodiment of the present application. It should be pointed out that although the preferred embodiments of the present application have been described, for those skilled in the art, once the basic creative concept of the present application is known, without departing from the principles of the present application, some improvements and refinements can also be made, and these improvements and refinements should also be considered as the protection scope of the present application. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all modifications and modifications falling within the scope of the embodiments of the present application.
Claims
1. An attack detection device for an unmanned cluster system under a false data injection attack, characterized in that, include: Encryption module, decryption module, data similarity calculation module, threshold comparator, and alarm; The encryption module is used to encrypt the measurement output signal of a single intelligent agent in the unmanned swarm system, and transmit the encrypted signal to the decryption module through a wireless communication network; wherein, the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller; The decryption module is used to decrypt the encrypted signal to obtain the decrypted signal; The data similarity calculation module is used to calculate the real-time residual signal of the system using the decrypted signal, and to calculate the probability distribution difference between the real-time residual signal of the system and the residual signal when the system is running normally. The threshold comparator is used to compare the probability distribution difference calculated by the data similarity calculation module with a preset threshold. If the probability distribution difference is greater than the preset threshold, an alarm is triggered, indicating that the system has been subjected to a fake data injection attack. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal. The encryption module encrypts the measured output signal by performing the following process: The measurement output signal to be encrypted is processed by the first scalar multiplier, and then a watermark signal is superimposed on the signal processed by the first scalar multiplier; wherein, the watermark signal is composed of a pseudo-random sequence with a Gaussian distribution; the encryption key is the seed of the pseudo-random sequence and is pre-stored on the onboard chip. The decryption module's process for decrypting the encrypted signal includes: The watermark signal is extracted from the encrypted signal. Then, based on the extracted watermark signal, the encrypted signal is decrypted using a second scalar multiplier to obtain the decrypted data and the extracted watermark signal.
2. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 1, characterized in that, The pseudo-random sequence is generated by a cryptographically secure pseudo-random number generator.
3. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 1, characterized in that, The watermark signal follows a mean of zero and a variance of η∑. z ∑ z Let η be the variance of the residual signal when the system is running normally, and η is a constant greater than 0.
4. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 1, characterized in that, The encryption module and the decryption module implement authentication and authorization mechanisms through digital signatures to ensure that only authorized users can access the functions and data related to the watermark signal.
5. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 3, characterized in that, When the parameter of the first scalar multiplier is b, the parameter of the second scalar multiplier is set to 1 / b; and the parameter settings in the encryption module and the decryption module satisfy...
6. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 1, characterized in that, The encryption module uses the AES symmetric encryption algorithm.
7. The attack detection device for an unmanned cluster system under a false data injection attack as described in claim 1, characterized in that, The data similarity calculation module is specifically used for: The real-time residual signal of the system is calculated using the decrypted signal, and the Kullback-Leibler divergence between the real-time residual signal and the residual signal during normal operation is calculated. The Kullback-Leibler divergence is used to characterize the difference in probability distribution between the real-time residual signal and the residual signal during normal operation.
8. A method for detecting attacks on unmanned cluster systems under false data injection attacks, implemented using the attack detection device for unmanned cluster systems under false data injection attacks as described in any one of claims 1 to 7, characterized in that, The attack detection method for unmanned cluster systems under false data injection attacks includes: The measurement output signal of a single intelligent agent in the unmanned swarm system is encrypted using an encryption module, and the encrypted signal is transmitted to the decryption module via a wireless communication network; wherein, the measurement output signal refers to the signal output by the sensor in the feedback channel from the sensor to the controller; The encrypted signal is decrypted using the decryption module to obtain the decrypted signal; The data similarity calculation module is used to calculate the real-time residual signal of the system based on the decrypted signal, and to calculate the probability distribution difference between the real-time residual signal and the residual signal when the system is running normally. The probability distribution difference calculated by the data similarity calculation module is compared with a preset threshold using a threshold comparator. If the probability distribution difference is greater than the preset threshold, an alarm is triggered, indicating that the system has been subjected to a fake data injection attack. If the probability distribution difference is not greater than the preset threshold, the alarm is not triggered, indicating that the system is normal.
Citation Information
Patent Citations
Active attack detection method for improving detection rate
CN114063602A
Elastic event trigger control method and device of random hopping information physical system
CN115314251A