Security estimation method and system for attack separation and reconstruction based on unknown input
By designing a fully symmetric multicellular unknown input observer, the detection problem of unknown input attacks in wireless communication systems is solved, and the separation and reconstruction of unknown input attacks is realized, which improves the security and stability of the system.
Patent Information
- Application Number
- CN202510721108.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-05-30
AI Technical Summary
The prior art is difficult to effectively detect and separate network attacks with unknown inputs, especially in wireless communication systems. Unknown input attack signals are similar to normal signals and are difficult to detect through traditional methods, affecting system stability and performance.
An unknown input observer based on a fully symmetric multicellular method is designed. By constructing a system model and determining an attack model, unknown input attack signals are separated and reconstructed, and multiple unknown input observers are constructed to achieve attack separation and reconstruction by using the injection attack of the input channel and the sensor output channel.
It realizes effective detection and separation of unknown input attacks, improves the stability and security of the system, and reduces the impact of unknown inputs on system performance.
Smart Images

Figure CN120277663A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of wireless communication encryption, and particularly relates to a security estimation method and system for attack separation and reconstruction based on unknown inputs. Background Art
[0002] With the development of communication networks, network attacks have attracted more and more attention from researchers. In network control systems, in the presence of network attacks, how to design secure control estimators and controllers is crucial, which is related to whether the system can operate stably. In addition, in practical systems, unknown inputs are inevitable and may even degrade system performance. For example, in existing research results, process disturbances, model errors, system failures, etc. can all be regarded as unknown inputs. To gain in-depth understanding of relevant information about network attacks, it is very important to separate and reconstruct them. Summary of the Invention
[0003] To solve the problems of secure state estimation, attack separation and reconstruction in the presence of network attacks, in a first aspect of the present invention, a security estimation method for attack separation and reconstruction based on unknown inputs is provided, including: Constructing a system model based on the state variables and system matrix of the target system; determining an attack model and unknown attacked actuator and sensor sets based on the system model and data injection attacks; Constructing a plurality of unknown input observers based on the fully symmetric polytope method, unknown attacked actuator and sensor sets; Determining an attack separation and reconstruction method based on each unknown input observer.
[0004] In some embodiments of the present invention, the determining an attack model and unknown attacked actuator and sensor sets based on the system model and data injection attacks includes: determining an attack model based on the injection attacks on the input channels and sensor output channels; determining unknown attacked actuator and sensor sets based on the number of attack channels on the input channels and sensor output channels.
[0005] Furthermore, the support sets of the injection attacks on the input channels and sensor output channels respectively belong to the unknown attacked actuator and sensor sets.
[0006] In some embodiments of the present invention, the constructing a plurality of unknown input observers based on the fully symmetric polytope method, unknown attacked actuator and sensor sets includes: determining the number of attack channels based on the unknown attacked actuator and sensor sets; determining the satisfaction conditions of the fully symmetric polytope according to the number of attack channels and the ranks of multiple system matrices in the attack model; constructing a plurality of unknown input observers according to the satisfaction conditions.
[0007] Further, the constructing of multiple unknown input observers according to the satisfied condition includes: if the condition is satisfied, constructing a first unknown input observer according to the satisfied condition; otherwise, constructing a second unknown input observer based on the unknown attacked actuator set and sensor set.
[0008] In the above embodiment, the determining of the attack separation and reconstruction method based on each unknown input observer includes: reconstructing the attack based on each unknown input observer; determining a reconstruction error based on the reconstruction result, and determining an attack separation method according to the reconstruction error.
[0009] In a second aspect of the present invention, there is provided a security estimation system for attack separation and reconstruction based on unknown inputs, including: A first determination module, configured to construct a system model based on the state variables and system matrix of the target system; determine an attack model and an unknown attacked actuator set and sensor set based on the system model and data injection attack; A construction module, configured to construct multiple unknown input observers based on the fully symmetric polytope method, the unknown attacked actuator set, and the sensor set; A second determination module, configured to determine an attack separation and reconstruction method based on each unknown input observer.
[0010] Further, the first determination module includes: a first determination unit, configured to determine an attack model based on the injection attack on the input channel and the sensor output channel; a second determination unit, configured to determine an unknown attacked actuator set and sensor set based on the number of attack channels of the input channel and the sensor output channel.
[0011] In a third aspect of the present invention, there is provided an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the security estimation method for attack separation and reconstruction based on unknown inputs provided in the first aspect of the present invention.
[0012] In a fourth aspect of the present invention, there is provided a computer-readable medium, on which a computer program is stored, wherein the computer program, when executed by a processor, implements the security estimation method for attack separation and reconstruction based on unknown inputs provided in the first aspect of the present invention.
[0013] The beneficial effects of the present invention are: The present invention aims at a linear discrete system with unknown but bounded noise. By designing an unknown input observer, it solves the problems of secure state estimation, attack separation, and reconstruction in the presence of cyberattacks. It also proposes a design method for an unknown input observer based on a fully symmetric polytope, solves the problem of secure estimation for a system with unknown but bounded noise, and determines the influence of system disturbances and noise on attack separation and reconstruction. The present invention is applicable to application scenarios that require secure state estimation and attack separation for systems with unknown inputs, and has high application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a schematic diagram of the basic process of a secure estimation method for attack separation and reconstruction based on unknown inputs in some embodiments of the present invention; Figure 2 It is a schematic diagram of the principle of a secure estimation method for attack separation and reconstruction based on unknown inputs in some embodiments of the present invention; Figure 3 It is a schematic diagram of the structure of a secure estimation device for attack separation and reconstruction based on unknown inputs in some embodiments of the present invention; Figure 4 It is a schematic diagram of the structure of an electronic device in some embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0015] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0016] Refer to Figure 1 and Figure 2 In the first aspect of the present invention, a secure estimation method for attack separation and reconstruction based on unknown inputs is provided, including: S100. Construct a system model based on the state variables and system matrix of the target system; based on the system model and data injection attacks, determine the attack model and the unknown sets of attacked actuators and sensors; S200. Construct multiple unknown input observers based on the fully symmetric polytope method, the unknown sets of attacked actuators and sensors; S300. Based on each unknown input observer, determine the attack separation and reconstruction method.
[0017] It can be understood that an unknown input attack refers to an attacker taking advantage of vulnerabilities in a wireless communication system to send input signals that are not recognized or expected by the system, thereby interfering with or disrupting the normal operation of the system. Such attacks are usually difficult to detect because their input signals are not predefined or recognized by the system. The signals of unknown input attacks are usually similar to normal communication signals and are difficult to discover through traditional detection methods. An attacker can generate unknown input signals in various ways, including forged source IP addresses, abnormal packet sizes, abnormal request frequencies, etc. The signals of unknown input attacks can change over time, increasing the difficulty of detection.
[0018] In step S100 of some embodiments of the present invention, determining the attack model and the unknown attacked actuator set and sensor set based on the system model and data injection attack includes: S101. Determine the attack model based on the injection attack on the input channel and the sensor output channel; Specifically, first establish the following discrete-time system model: (1) (2) Wherein, is the system state, is the system control input, is the measurement output of the sensor, is the system disturbance, is the noise of the sensor, A, B, C, D and F are known system matrices; and satisfy and , where and represent a fully symmetric polytope centered at the origin with a generating matrix of Hω and Hv , and Hω and Hv are given matrices; the initial values satisfy , p 0 and H 0 are the known center point and generating matrix respectively.
[0019] Considering that an attacker can launch a false data injection attack against the input channel and the sensor output channel, the attack model is: (3) (4) Wherein, is the output of the controller, , , and is the number of the corresponding attacked channels.
[0020] S102. Determine the unknown attacked actuator set and sensor set based on the number of attacked channels of the input channels and the sensor output channels.
[0021] Specifically, define , , then and respectively represent the unknown attacked actuator and sensor sets. The present invention assumes that and are time-invariant and satisfy and , supp represents the support set, for example .
[0022] In step S200 of some embodiments of the present invention, the constructing of multiple unknown input observers based on the fully symmetric polytope method, the unknown attacked actuator set and the sensor set includes: S201. Determine the number of attacked channels based on the unknown attacked actuator set and the sensor set; S202. Determine the satisfaction conditions of the fully symmetric polytope according to the number of attacked channels and the ranks of multiple system matrices in the attack model; Specifically, the present invention designs two different unknown input observers according to whether the condition is satisfied. If , then x is a vector with n elements. For example, if , , then there is .
[0023] S203. Construct multiple unknown input observers according to the satisfaction conditions.
[0024] Furthermore, the constructing of multiple unknown input observers according to the satisfaction conditions includes: if the condition is satisfied, construct the first unknown input observer according to the satisfaction conditions; otherwise, construct the second unknown input observer based on the unknown attacked actuator set and the sensor set.
[0025] The specific construction process of the first unknown input observer is: If the condition is satisfied, consider the subset of the measurement output set, and the corresponding unknown input observer can be designed as follows: (5) (6) Among them, and are the estimated state and the observer state respectively. The matrices and can be obtained through the following algorithm: (7) Among them, , , is an arbitrary matrix with appropriate dimensions, and are the dimensions of the state and output vectors respectively. By choosing , the following inequality can be solved to obtain the matrices and , and then the matrix : (8) Among them, , , , , , .
[0026] Define the estimation error . If , then through calculation, can be obtained, where: (9) (10) Among them, .
[0027] For each set , with potential , denoted as . Define and The maximum deviation between them is: ; Define , the estimated state of the output of the fully symmetric polytope observer can be obtained, that is, .
[0028] The specific construction process of the second unknown input observer is as follows: If the condition is not satisfied, the system after being attacked is rewritten in the following form: (11) (12) Among them, , . In this case, is regarded as an unknown input. The unknown input observer is designed as follows: (13) (14) Among them, is the observer state, is the estimated state; define , then the matrices , and need to make the matrix stable, and , . The matrices , are calculated by the following method: (15) (16) Among them, , , is an arbitrary matrix with appropriate dimensions, , . By choosing , the following inequality can be solved to obtain the matrices and , and then the matrix , (17) Among them, , , , , , , .
[0029] Define the estimation error , if , then can be obtained, where (18) (19) Among them, .
[0030] Assume at most qOne actuator and q one sensor are attacked, that is , , so there are at least sensors that are not attacked. Define (20) wherein, , , , . Therefore, the output of the fully symmetric polytope observer can be determined by the following formula: (21) that is , .
[0031] In step S300 of the above embodiment, the method for determining the attack separation and reconstruction based on each unknown input observer includes: S301. Reconstruct the attack based on each unknown input observer; Specifically, as Figure 2 shown, the input of the attack separation and reconstruction is the observer output , the center point of the observer error set. The attack reconstruction result is as follows: , (22) wherein, .
[0032] S302. Determine the reconstruction error based on the reconstruction result, and determine the attack separation method according to the reconstruction error.
[0033] Specifically, the attack reconstruction error satisfies the following conditions: , (23) wherein, , .
[0034] Based on this, the attack separation algorithm is as follows: (24) wherein, if , then , otherwise ; if , then , otherwise . and are the sets of the attacked actuators and sensors separated respectively.
[0035] Example 2 Reference Figure 3 , the second aspect of the present invention provides a security estimation system 1 for attack separation and reconstruction based on unknown inputs, including: A first determination module 11, configured to construct a system model based on the state variables and system matrix of the target system; determine an attack model and unknown attacked actuator and sensor sets based on the system model and data injection attacks; A construction module 12, configured to construct a plurality of unknown input observers based on the fully symmetric polytope method, the unknown attacked actuator set, and the sensor set; A second determination module 13, configured to determine an attack separation and reconstruction method based on each unknown input observer.
[0036] Furthermore, the first determination module 11 includes: a first determination unit, configured to determine an attack model based on the injection attacks of the input channel and the sensor output channel; a second determination unit, configured to determine the unknown attacked actuator set and sensor set based on the number of attack channels of the input channel and the sensor output channel.
[0037] Example 3 Reference Figure 4 , the third aspect of the present invention provides an electronic device, including: one or more processors; a storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the security estimation method for attack separation and reconstruction based on unknown inputs in the first aspect of the present invention.
[0038] The electronic device 500 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage device 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 are also stored. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.
[0039] Typically, the following devices can be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a hard disk, etc.; and a communication device 509. The communication device 509 can allow the electronic device 500 to communicate with other devices wirelessly or wireline to exchange data. Although Figure 4 the electronic device 500 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices can be implemented or included. Figure 4 Each block shown in
[0040] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowchart can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable medium, the computer program containing program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed. It should be noted that the computer-readable medium described in the embodiment of the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment of the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the embodiment of the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0041] The above computer-readable medium can be included in the above electronic device; or it can exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more computer programs, and when the above one or more programs are executed by the electronic device, the electronic device is caused to: Computer program code for performing the operations of the embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, Python, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it may be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0042] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0043] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A security estimation method for attack separation and reconstruction based on unknown input, characterized in that, including: constructing a system model based on the state variables and system matrix of the target system; determining an attack model, as well as the set of attacked actuators and the set of sensors that are unknown, based on the system model and data injection attacks; constructing a plurality of unknown input observers based on the fully symmetric polytope method, the set of attacked actuators that are unknown, and the set of sensors that are unknown; determining an attack separation and reconstruction method based on each unknown input observer.
2. The security estimation method for attack separation and reconstruction based on unknown input according to claim 1, characterized in that, The determining, based on the system model and data injection attacks, the attack model, as well as the set of attacked actuators and the set of sensors that are unknown, includes: determining an attack model based on the injection attacks on the input channels and the sensor output channels; determining the set of attacked actuators and the set of sensors that are unknown based on the number of attack channels of the input channels and the sensor output channels.
3. The security estimation method for attack separation and reconstruction based on unknown input according to claim 2, characterized in that, The support sets of the injection attacks on the input channels and the sensor output channels respectively belong to the set of attacked actuators and the set of sensors that are unknown.
4. The security estimation method for attack separation and reconstruction based on unknown input according to claim 1, wherein The constructing a plurality of unknown input observers based on the fully symmetric polytope method, the set of attacked actuators that are unknown, and the set of sensors that are unknown includes: determining the number of attack channels based on the set of attacked actuators and the set of sensors that are unknown; determining the satisfaction conditions of the fully symmetric polytope according to the number of attack channels and the ranks of multiple system matrices in the attack model; constructing a plurality of unknown input observers according to the satisfaction conditions.
5. The security estimation method for attack separation and reconstruction based on unknown input according to claim 4, characterized in that, The constructing a plurality of unknown input observers according to the satisfaction conditions includes: if the conditions are satisfied, constructing a first unknown input observer according to the satisfied conditions; otherwise, constructing a second unknown input observer based on the set of attacked actuators and the set of sensors that are unknown.
6. The security estimation method for attack separation and reconstruction based on unknown input according to claim 1, wherein The determining an attack separation and reconstruction method based on each unknown input observer includes: reconstructing the attack based on each unknown input observer; determining a reconstruction error based on the reconstruction result, and determining an attack separation method according to the reconstruction error.
7. A security estimation system for attack separation and reconstruction based on unknown inputs, characterized in that including: a first determination module for constructing a system model based on the state variables and system matrix of the target system; determining an attack model, as well as the set of attacked actuators and the set of sensors that are unknown, based on the system model and data injection attacks; a construction module for constructing a plurality of unknown input observers based on the fully symmetric polytope method, the set of attacked actuators that are unknown, and the set of sensors that are unknown; a second determination module for determining an attack separation and reconstruction method based on each unknown input observer.
8. The security estimation system for attack separation and reconstruction based on unknown input according to claim 7, wherein The first determination module includes: a first determination unit for determining an attack model based on the injection attacks on the input channels and the sensor output channels; a second determination unit for determining the set of attacked actuators and the set of sensors that are unknown based on the number of attack channels of the input channels and the sensor output channels.
9. An electronic device, comprising: one or more processors; a storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the security estimation method for attack separation and reconstruction based on unknown inputs as described in any one of claims 1 to 6.
10. A computer-readable medium having a computer program stored thereon, wherein, The computer program, when executed by a processor, implements the security estimation method for attack separation and reconstruction based on unknown inputs as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Liquid level safety control method based on unknown input observer
CN119165894A
Method For Estimating An Internal Effective Torque Of A Torque Generator
US20200333201A1
Method and apparatus for monitoring unmanned ground vehicle
US20220410913A1
Cyber resilience integrated security inspection system (crisis) against false data injection attacks
US20230315851A1